Regulatory primer
eIDAS + eIDAS 2
Regulation (EU) 910/2014 (eIDAS) + Regulation (EU) 2024/1183 (eIDAS 2) · European Union · eIDAS in force since 1 July 2016; eIDAS 2 in force May 2024
eIDAS sets the EU framework for electronic identification + trust services — e-signatures, e-seals, time stamps, qualified websites, and cross-border identity. eIDAS 2 (Reg. 2024/1183) introduces the European Digital Identity Wallet (EUDIW) with mandatory issuance by member states by end-2026.
What it is
eIDAS (the original 910/2014 regulation) harmonised the legal recognition of electronic identification + trust services across the EU. It introduced three Levels of Assurance (LoA: low / substantial / high) for electronic identification schemes used by public services, and a framework for cross-border recognition.
The 2024 revision (eIDAS 2, Regulation (EU) 2024/1183, in force May 2024) is the European Digital Identity Wallet (EUDIW) overhaul. By end-2026, every EU member state must offer EUDIW to citizens. By November 2027, mandatory acceptance by relying parties (banks, telcos, public services). The wallet holds verifiable credentials (ID, driving licence, education credentials, medical credentials, professional credentials) under user control.
Govtech AI deployments touching identity verification are most directly affected. Healthcare + financial-services KYC workflows also integrate with eIDAS LoA frameworks.
Who's in scope
- Trust service providers offering: qualified electronic signatures, qualified electronic seals, qualified time stamps, qualified electronic registered delivery services, qualified website authentication certificates.
- Identity providers operating notified electronic identification schemes for public-service access (e.g. national eID schemes — Italy's SPID, Belgium's itsme, Germany's eID).
- eIDAS 2: EUDIW issuers (typically member-state appointed entities), relying parties (must accept the wallet), and personalisation/credential issuers.
- Public services accepting electronic identification under Art. 6 (mandatory recognition obligations).
Key obligations
eIDAS Art. 8 — Levels of Assurance (LoA)
Electronic identification schemes notified by member states must specify LoA (low / substantial / high) based on identity-proofing rigour + authentication strength + management of the scheme. Public services define minimum LoA per transaction risk.
eIDAS Chapter III — trust services
Qualified trust service providers face supervision by national supervisory bodies. Conformity assessment + EU trusted list maintenance. Liability framework + audit obligations.
eIDAS 2 Art. 5a — EUDIW design + interoperability
Wallet must support: storage of attestations, presentation under user control, selective disclosure, cross-border interoperability via the EU trust framework. Privacy-by-design + unlinkability requirements.
eIDAS 2 Art. 5b — mandatory acceptance
Large platforms (gatekeepers under DMA), regulated entities (banks, telcos, healthcare providers, transport), and public services must accept the EUDIW from November 2027.
Timeline + applicability
- 1 Jul 2016eIDAS (Reg. 910/2014) became applicable.
- May 2024eIDAS 2 (Reg. 2024/1183) entered into force.
- End of 2026Member states must offer the EUDIW to citizens (Art. 5a wallet-issuance deadline).
- 21 Nov 2027Mandatory acceptance of EUDIW by gatekeepers + regulated relying parties.
What's still being worked out
Areas where the regulation's interpretation is genuinely unsettled. Vendor pages skip this; we don't. Your counsel is the right venue for definitive guidance on your deployment.
- Wallet attestation issuance + revocation infrastructure — operational details continue via implementing acts.
- Cross-border interoperability of national eID schemes vs the new EUDIW.
- Privacy + linkability protections in practice — selective disclosure + unlinkability are mandated by the regulation but technical specifications continue.
- What 'mandatory acceptance' actually means for relying parties in practice — penalties for non-compliance vary by member state.
- Treatment of biometric attestations + biometric identification within the wallet — overlap with AI Act Art. 5 prohibitions + Annex III §1 biometrics needs to be worked through.
Sectors most affected
Govtech & Public Sector
Identity-verification + citizen-services AI integrating with eIDAS LoA frameworks + EUDIW.
Fintech & Payments
KYC workflows integrating with eIDAS-recognised identity proofs. Mandatory EUDIW acceptance from Nov 2027 for regulated banks.
Healthtech
Patient identity verification + medical-credential attestations in the wallet.
Primary sources
Where Promethean fits
For identity-verification AI in govtech + fintech KYC contexts, Promethean's L12 chain records each verification decision with the LoA claimed + the model identity + the reviewer verdict where edge cases trigger human review. The chain provides per-decision audit evidence for eIDAS supervisory inquiries + cross-border identity-verification disputes. EUDIW integration: where AI is used to evaluate credential authenticity or attribute-claim plausibility, those decisions become L12 entries.
What Promethean does NOT solve
- Issue trust services or qualified credentials — that's a qualified trust service provider role.
- Operate the EUDIW or its attestation infrastructure — that's member-state + designated-issuer responsibility.
- Replace cryptographic identity-proofing — Promethean is the audit-trail layer on top of identity systems.
- Address biometric capture or matching directly — operator's biometric SDK + processes.
FAQ
When does the EUDIW become available?
Member states must offer the wallet by end of 2026 (Art. 5a). Practical timing varies by member state — some are running pilots already, some are tracking later. Mandatory acceptance by gatekeepers + regulated relying parties applies from 21 November 2027.
Does eIDAS apply to non-EU service providers?
Trust services are EU-based. Mandatory EUDIW acceptance applies to gatekeepers (DMA-designated, often US-headquartered) operating in the EU, plus EU-regulated banks + telcos + healthcare providers. A US bank with EU operations must accept EUDIW for its EU customers.
What's a 'Level of Assurance' and which is required?
Three levels under Art. 8 + Implementing Regulation 2015/1502: Low (limited degree of confidence, single-factor authentication), Substantial (substantial degree, two-factor authentication, recommended for most public-service access), High (high degree, biometric or qualified electronic signature, required for sensitive transactions). Public service operators choose the minimum LoA per transaction risk.
How does eIDAS interact with GDPR?
Concurrent regulation. GDPR governs personal-data processing in identity-verification flows; eIDAS governs the legal recognition + trust framework. Wallet attestations are typically personal data; selective-disclosure + unlinkability requirements in eIDAS 2 align with GDPR data-minimisation. The Italian Garante + other DPAs are coordinating with national eID authorities on enforcement.