The Inverted Podcast · 2026-07-01 · 32 min
Key moments - from our scoring
Substance score
60 / 100
Five dimensions, 20 points each
The original four hosts of The Inverted Podcast discuss the accelerating transformation of identity security driven by three major forces: AI agents acting on behalf of users, increasingly prescriptive regulatory mandates from bodies like the EU, and technological innovations in authentication and authorization. Dana notes the shift from authentication-focused work to smarter authorization and signal-sharing between identity providers. Tom highlights the "identity debt" problem - organizations still deploying basic MFA while needing to solve agent governance simultaneously. Dario emphasizes regulators moving from asking companies to prevent bad outcomes (showing their efforts) to holding them accountable for actually preventing breaches, pushing adoption of phishing-resistant authentication methods like YubiKeys. The conversation covers design-time controls (role models, governance processes) versus runtime controls (contextual, device-aware, risk-based access decisions), the Signal AI model of just-in-time privilege access acquired by CrowdStrike, and the EU's eIDAS initiative for digital identity wallets. Key challenge: scaling modern identity practices across organizations still catching up on foundational security while managing the complexity of AI agents that need their own identity framework similar to human assistants.
Phishing-resistant authentication uses methods like hardware security keys (YubiKeys) that prevent credential theft, as opposed to SMS or email-based methods. Regulators now mandate it because showing effort to prevent phishing over 20 years hasn't worked; they want proof of actual prevention, not just intentions.
eIDAS is an EU scheme requiring member countries to issue digital identity wallets to citizens. Users link their government-issued passport or citizen card to a software application, creating a portable digital representation of identity that can be used across services without sharing the original document.
Most organizations haven't fully deployed MFA and modern authorization systems, so adding agent governance forces them to make security compromises like embedded credentials or impersonation instead of proper delegation, creating what Tom calls 'identity debt.'
Agents should receive delegation with minimal necessary information, temporary time-limited access, spending caps for financial transactions, and clear intent statements - similar to onboarding a human assistant - rather than impersonating the user account.
Design-time controls are static processes like role models and annual access reviews; runtime controls are dynamic, contextual checks during active sessions that react to risk signals like impossible travel or unusual device behavior.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains solid, practitioner-grounded observations about identity's evolution - regulatory shifts toward prescriptive outcomes, the challenge of deploying agents without baseline controls, runtime vs. design-time security paradigms - that a B2B operator would find useful. However, it mixes substantial insights with considerable throat-clearing, tangential banter about weather, and repetitive restatement of ideas without driving them to concrete conclusions or actionable specifics.
identity was plodding along, evolving. Things like pass keys were coming up. Um, there was a switch from authentication focus to more on smart authorization
companies are just trying to get strong authentication under their belt and modernize their identity systems and uh, to modernize their authorization systems are going to take a while
The discussion covers genuinely useful frames - design-time vs. runtime controls, agents as delegated access problems, regulatory shift from effort-demonstration to outcome-guarantee - but these are not particularly novel to identity professionals. The eIDAS / digital wallet discussion is informative but largely descriptive of existing EU initiatives rather than contrarian or first-principles thinking. The framing of agents as 'assistants on steroids' is intuitive but not counterintuitive.
Most of the LLMs in usage in Europe are kind of like from a sovereign governance perspective, based out of the United States, maybe in China. But I think the question of who owns the compute
the path to go is you give the agent as little information as they need in as clear way. Especially when it's about financial transactions. You limit the time they can make those financial
The four speakers appear to be identity practitioners and advisors with real client exposure and regulatory visibility (particularly Dario in financial services, Tom in enterprise identity governance). However, the transcript does not clearly state their titles, company affiliations, or specific scale of operations they've managed, making it difficult to assess seniority with certainty. They speak with credibility but lack explicit credentials or evidence of having shipped/scaled major identity systems.
I spend a good part of my time with technology providers and professional services provider who cater to like financial services for example
clients and um, what I expect to be the trend in the next 12 months will be, people will say, yeah, we need to. Yes, you know, our board, our C suite are really kind of like being blasted
The episode lacks concrete numbers, named companies, or detailed case studies. Signal AI / CrowdStrike is mentioned briefly, but no specifics on implementation timelines, adoption rates, or measurable outcomes. eIDAS rollout is discussed in vague terms (end of year, end of next year) with no hard deadlines cited. No data on regulatory penalties, actual agent failures, or enterprise modernization spend is provided. Mostly abstracted discussion of trends.
I think it's a company, I'm not sure if you've heard of them. They're called Signal AI. They sold to CrowdStrike
like they're supposed to be ready at the end of this year and fully up and running at the end of next year
The host asks follow-up questions and occasionally pushes for clarification (e.g., asking Dario to explain eIDAS, probing single-point-of-failure risks in central ID systems). However, questions often don't dig deep; many are softball setup lines that let guests riff without being challenged or pressed for evidence. There's little productive disagreement - speakers mostly build on each other's points. Multiple instances of 'you're muted' and tangential weather chat detract from substantive exchange.
Yeah. Dario, you just said a term called idas or something. Would one of you be able to maybe. Dario, can you explain to the audience what that means
So great central government ID system. I can upload my passport and then hook up all my things and then I want to travel or get married or do something and then the system is down like single point of failure
Computed from the transcript - who did the talking, and the words that came up most.
Identity is Changing Fast: AI Agents, Passkeys & Digital ID Explained | Inverted Podcast Digital identity is evolving rapidly - from passwords to passkeys, from users to AI agents. In this episode of the Inverted Podcast, we break down the biggest trends in identity security, authentication, and authorization , including the rise of AI agents , phishing-resistant login methods , and government-backed digital identity systems like the EU Digital Identity Wallet . We explore how identity is shifting from static accounts to dynamic, real-time access control , why Zero Trust and runtime security are becoming essential, and what organizations must do to keep up with increasing regulatory pressure and cyber threats. If you're interested in cybersecurity, identity management (IAM), Zero Trust, AI security, or privacy , this episode gives a clear view of where the industry is headed.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Foreign.
Speaker B: Welcome, everybody, to another episode of the Inverted podcast. And you're back with the original four. Welcome back, Tom. How have you been?
Speaker A: Yes, I was a couple months ago. So it is, uh, a pleasure to be with you.
Speaker B: Yes. And we are very, very happy to have you back today and to hear what you've been hearing. Um, and, uh, welcome also to Dario and Dana. I think, Dana, it's not so hot where you are, right?
Speaker C: No, it's probably about 65 degrees, 60 degrees here. But I just got back from LA and LA was hot.
Speaker B: Yeah, yeah, some people are really suffering, and I think it's also still heating up. In the world of identity security abuse. That's the stuff we cover on this podcast. For us, uh, success is where nothing happens. Um, and we cover those products, services, and things that, uh, have that unique characteristic that success is when nothing happens. And today we want to talk about the state of identity. And for those of you who don't know what we mean with that, Identity is basically the way you are represented in the digital world. This could be your Google account, this could be your Microsoft account, but this could also be, uh, some agent or some app, or it could be your passport number. There's many ways you can be represented in the digital world, and that comes with lots of opportunities, um, and problems. And so I want to start with you today, Dana, like, um, what is some of the latest things you've been seeing and how identity is changing? And then I want to toss it to Tom and Dario also to hear what you guys are hearing from clients.
Speaker C: I was thinking about this the other day, and it's kind of like identity was plodding along, evolving. Things like pass keys were coming up. Um, there was a switch from authentication focus to more on smart authorization and communication between relying parties in the central idp, uh, with signal sharing and. And a lot of this work was ongoing. You know, um, the use of passkeys and making passkeys stronger, the adoption. And then things like agent AI agents came along and, like, really accelerated things because it threw the issues right in the face of the both, not corporations and customers. It's like, all right, well, now how does an agent who's acting on your behalf authenticate and then get access to resources and, and what happens if that goes awry? Um, and now you have governments, there's some government mandates coming on board that are causing pressure to adopt certain standards and, um, certain technology. All of which is great. But things seem to be accelerating and the change seems to be happening extremely fast to a Lot of services and a lot of technology. So that was my observation.
Speaker B: Yeah. And it seems like the acceleration is accelerating. Uh, I'm not sure where I heard that right. And I think Tom, you're with clients a lot. Uh, obviously we represent ourselves here, not our employers or clients. But what are some of the things you. And also Dario, what have you been hearing? What have you been encountering in the market?
Speaker A: Yeah, I agree with everything Dana said. And the only caveat I would add is that for all that clients are interested in putting their hands around like agent discoverability and guardrails from an identity, identity and governance perspective, they still haven't solved a lot of the other basic stuff as well. So I think one of the things that's interesting about the kind of technology acceleration that we see around, that we see around agentic at the moment is that regulators haven't forgotten about also kind of like the appropriate governance of warm bodied identities, uh, of generic users. Uh, and still we see really varying levels of maturity out there in the market. So what I see a little bit from conversations with clients and um, what I expect to be the trend in the next 12 months will be, people will say, yeah, we need to. Yes, you know, our board, our C suite are really kind of like being blasted from all sides with, with information and um, I'm not going to say scaremongering, but they are definitely hearing a lot of kind of like uh, risk signals from risk awareness. Sure, yeah. Um, but ultimately I think then the people who are making like day to day investment decisions with regard to identity are still going to be balancing very much their time with kind of more bread and butter issues of making sure that like people can do strong authentication, um, wherever they are, whatever device they're using and um, making sure the thing kind of like some form of um, least privilege is still applicable to all of your war bodies while you try to figure out what you're doing with your agents. Um, that's where the market is I would say.
Speaker B: Dario, what are you hearing from the places where you walk through during the week?
Speaker D: Yeah, I mean I spend a good part of my time with technology providers and professional services provider who cater to like financial services for example. And there we really see a shift in how the regulatory bodies are pushing companies like banks, for example, to build safer and also more privacy preserving services. Previously we really saw that regulators were more about or push the companies to demonstrate their efforts of preventing bad outcome. Like, show your efforts in preventing um, privacy breaches. Show your efforts in preventing um, account compromise. Show Your efforts in detecting these issues. Now the regulatory bodies are becoming much more like almost aggressive. Like they want the companies to show that they are actually preventing the outcome and they hold the companies much more accountable. I mean there are subtle shifts. Like the companies having like if you get scammed out of money, for example, previously you had to prove that the company did something wrong or didn't the bank didn't do fulfill their um, responsibility. Now the bank has to show that you really um, didn't meet a reasonable level of awareness or of protection. So it really shows like one of the things I see is um, regulatory body saying you have to deploy phishing resistant authentication. Rather than to say you should reduce phishing as a risk factor, which hasn't worked really well in the last 20 years. They now go and say in order to be compliant, the only thing that makes you compliant is a uh, phishing resistant authentication method, amongst other things. Obviously, I mean just a yubikey doesn't make you make a bank compliant. But like they really are more prescriptive than they used to be towards the outcome rather than the effort of it. And that's I think a big change.
Speaker A: Can I ask you a question here? And Jeroen and Daria, uh, Dana in this context. So I actually in work yesterday, my last day of work for a couple of months, uh, I had a technical workshop with a couple of colleagues and we were talking about how we think about defining on a paradigm level what identity security controls look like and how they're evolving for clients. And one of the big distinctions that we drew was like the distinction between like quote unquote design time controls, which is things like, you know, an enterprise role model and kind of like classic identity governance. Like you know, you apply for a role or an entitlement, you get it, it's reviewed in a year, it's aligned with the organization. But then, and then contrasting that with kind of like runtime uh, identity security, which is kind of authentication, it's just in time privilege escalation, um, uh, it's kind of like step up authentication in case of um, a risk on the account. And what I see at the moment from a regulatory perspective is that most of your regulations are focused on design time, um controls. But where technology is pushing us very much and where attackers are pushing us is towards higher efficacy of runtime controls that are contextual, that um, take account of like uh, things like the device you're using, things like the IP address you're coming from, things like the risk that's associated with Your user object in general. And my question is, because I do have a question. To what extent do you guys think then that the regulatory environment will start to catch up with this, uh, let's say this trend or this emphasis from an identity security perspective and stop saying like, you know, for example, you know, ensure you have some form of role model and start saying ensure that you are able to react, you know, in good time to what appears to be a compromise session.
Speaker C: I think it goes back to what Dario was saying is before they're prescribing, hey, you should have stronger authentication, and now they're saying, hey, you should have, uh, credentials that are fish resistant. Um, but I think there's kind of a tail there, like it will, as things progress in terms of wanting this runtime, more runtime controls, the governing bodies need to catch up to that. And you'll probably see the same thing as, like, you should have, um, more dynamic, uh, controls on resource, uh, access. It'll be more generic. And then eventually they'll come back and be specific. But we know the government and the regulations take time. And going back to something you said, Tom, which is like, it takes these organizations a long time to adopt.
Speaker A: Right.
Speaker C: And companies are just trying to get strong authentication under their belt and modernize their identity systems and uh, to modernize their authorization systems are going to take a while as well.
Speaker A: It worries me also this.
Speaker C: Yes. And money. And that's part of the reason it takes a long time because they have to upgrade their infrastructure. Um, it worries me though, because things like agents, which are basically service counts, service principles, if you think of it like that, are going to force these companies to make bad decisions because they're not in the right place. So you'll have agents with embedded credentials. Right. And you'll, um, you'll have agents that are doing impersonation instead of delegation because that's what they need to do to get the systems to run. And that's not, I mean, it's a bad thing. But companies have to balance that, like getting like make evolving and making things work versus using what they have to to get it done. And it does lead to bad choices. I think that's the challenge for these organizations is how do you manage this stuff and evolve in this kind of new world you're going through?
Speaker A: I think.
Speaker B: Yeah. And so basically we've talked about this accelerated acceleration. Right. Um, and that's what we just talked about. There's an identity depth, Tom. That's what you said. Like, uh, hey, people want to do all these Agent stuff. But they don't even have MFA deployed. And then there's this. Even if they do that, it's not enough because it needs to happen after that. And then there's an accelerated acceleration that then makes it very hard to take decisions. But I want to ask you Dario, do you have an example of one of those sort of uh, continuous privilege management for less technical people that are listening to this? Like what does it mean for me as a user if we're not just after sign in giving me all the access? But
Speaker D: I mean I think in the identity world we used to call this risk based signals, risk based scoring, um, trust signals, whatever you want to call it, like as a continuous consumption of information that either indicates that a session that has been established by what we believe to be the right person or the right agent, um, to be, not to be used by that entity anymore. So like a continuous check. If like does anything change in the environment that make you believe that the entity and would wanted to say person, but it doesn't have to be a person anymore, controlling the session, um, is not the same anymore. And that could be um, I mean simple things like uh, impossible travel like this location just change from um, from the city center of Zurich to um, like um, Jakarta, Um, that's one of them. But I think there's a lot of more complex signals there and the expectations from customers and regulators to use signals like that on a continuous basis to really detect that something is going wrong, uh, is increasing. So in the past we usually would use those signals when at re authentication time because we said m that the risk that something happens between authentication and I don't know how many hours later when you have to re authenticate. It's a risk to accept. But that risk is not acceptable anymore because of the dynamics in the attack journeys.
Speaker B: Yeah, and I think one other thing that this is a company, I'm not sure if you've heard of them. They're called Signal AI. They sold to CrowdStrike, I think, uh, Eric Gustafsson, one of Eric Gustafsson's launches. And what they did was they basically let you sign in, but then you don't have access to everything. So. And then if you would go to Salesforce for example, to manage your customers, they would give you access at that moment to Salesforce while you were at it. And when you would leave Salesforce they would just take away that access again. So if someone was able to hack, they wouldn't have. It's like stopping standing access, moving to basically allowing you to have access for the things you need only when you need them. And so maybe at midnight you won't need access to Salesforce. And if you do, then you have to do a bit more work like touch your security key again or solve an SMS challenge. And I think that was a, uh, pretty interesting early take on this because with agents we're probably going to have to do exactly the same thing.
Speaker C: Right? Right.
Speaker B: It's implication an agent and I wanted to act in the world on my behalf, which is already a weird idea. Do I get a second identity or does it just really impersonate me or somewhere in the middle? Then what would we do? Uh, how do we make sure that that agent then can't just do everything on my account, but only has that little bit of thing that they can do for me for that task?
Speaker C: Right. It's like Dana's trying to access his travel info should at this point can he only see his itinerary and not his travel ID documents? Right. Because it's, it's this point in time and like he's not in his house. So he should only access this specific document. And the authorization checks that companies like signals are doing, signal does, uh, allows you to make these micro decisions that you haven't in the past. Right. Um, that's the strength and that's what we need with, with agents as well, because they're doing things on your behalf. Right. And um, so it's all, it's all coming much more rapidly, I think, than people thought as they started this journey with authorization. Right.
Speaker B: The way I try to look at it is, uh, for these agents, right. Like if I would get like an employee or a service provider that would act on my behalf, this could be a travel agent that's booking on my behalf. Bigger, uh, companies, senior people have assistants that do a whole bunch of things on your behalf. And you onboard them and you tell them and they get to know you. They kind of know which types of hotels you want when you're flying to, I don't know, Bangkok versus when you're flying to New York. You have different optimization criteria. Or they know that if they book you a place for dinner that you don't like spicy food. So then you probably shouldn't be booked into some sort like these, these service providers, let's call it like these, these humans, they know how to work for you. Right. So how do we build that into agents and how do we make sure that this sort of common sense that humans have goes into agents and should we give them their Own identity. So then it goes out and says, hey, I'm Dana's agent, I'm trying to book a restaurant. Or hey, I'm Tom's agent. Uh, and even when it emails this emails, or should we say no, here's Tom, he might speak a little bit different than he normally does. Or here's Dario, he clicks like 10 times as fast on the UI than he normally does, but it's still him. Right. Like how do we think about this agent identity versus human identity? Dario, uh, you are muted.
Speaker D: It had to happen eventually. Um, it's a good question. To me, it really depends on the type of service. I think for most services, probably a type of delegation where we say these agents have access to a subset of the information that I have, maybe even temporarily and because of that they can act on my behalf. They can get in touch with the uh, I know, restaurant booking system OpenTable and say, uh, they're booking a table on my behalf. Um, and I think that's the part where a lot of effort is being invested in currently to build these things. I think there's also going to be use cases where maybe I want to disguise that it's an agent doing something on my behalf. Like when I think about airlines, for example, Airlines have no interest in me engaging an agent to find the cheapest airline. So the moment it's an agent they will say, well, we can't give you a good price. Um, so I think there will be different situations. But in general, um, I think the path to go is you give the agent as little information as they need in as clear way. Especially when it's about financial transactions. You limit the time they can make those financial, financial transactions. You name the amount they can spend and you also give them a level of some information of intent on what you want to spend them the money for. Um, and then they do that with their own identity rather than just running wild with your Gmail account.
Speaker B: So you're saying onboard your agent assistant the way you would onboard a human assistant, basically. Tell me.
Speaker D: Yeah, I think there's a lot of parallels there. I mean the dynamics in which you onboard and offboard assistants AI assistance is hopefully faster than how you hire and fire your team staff. I mean probably because it could be one off agents, but in general, I think, uh, it's an HR process on steroids. Mhm.
Speaker B: And so we have these agents that are new to the identity space. We've said identities are no longer just an account that you have, but it's actually a collection of things you're allowed to do. And it should probably change dynamically based on a whole bunch of things. We've also talked a bit about. Dana, you said in the beginning the authentication space changing, so now we all use passkeys and stuff like that. But what is the role for governments? And Tom, I want to bring it back to you. How can governments support their basically society to be safe online in a storm, uh, of digital space, cyberspace? That's changing. I cannot imagine less tech savvy people like for example, my parents have to navigate this world where they're talking to AIs all the time without knowing they're approached by AIs without knowing they like. It's so complex for them. How can governments help here?
Speaker A: I think it's a super interesting question. Right. And there's for my mind an even more fundamental question here in terms of the role of governments even before you get into kind of like safety of uh, practices and models and things. But it's also like ownership. Right. So um, as we know, like Most of the LLMs in usage in Europe are kind of like from a sovereign governance perspective, based out of the United States, maybe in China. But I think the question of who owns the compute and the IP associated with those models is one thing that governance I know are looking at very closely. Um, because to a certain extent, um, LLM based services, but also cloud computing, cloud infrastructure, are now at a tier of criticality towards the functioning of general society, uh, on the same level as water, electricity, public transport and roads. Right. So I think that's why you see, um, things like Eidas and things like um, kind of greater focus on uh, let's say indigenous um, technologies in this space. So the first things that they're concentrating on, apart from kind of empowering people as users, citizen users, let's say, is making sure that they have their hands around kind of the regulatory and kind of like uh, sovereignty questions of uh, generative AI and large cloud compute before they're able to solve the more complex technical questions, let's say. But I'm interested very much in uh, the other guys opinions.
Speaker B: Yeah. Dario, you just said a term called idas or something. Would one of you be able to maybe. Dario, can you explain to the audience what that means and some of the other stuff that's going on right now in this space. You're muted again. It had to happen a second time.
Speaker D: It had to, yes. It will happen a third time and then never again. Uh, so it's basically a European like it's A European scheme or the European Union has decided they want their member countries to issue electronic identities to their, to their citizens and people living in the European Union. Which means in parallel to your citizen card, uh, to your passport, to your driver's license, you have a digital representation of who you are, um, what educations you have, what, like, yeah, the driver's license, all of those things. Visas and things that you then can use for a variety of services. So instead of um, having every company bridge the world between physical documents and electronic documents, the European Union decided that the member countries need to make that bridge so you can identify yourself. And this has a lot of implications,
Speaker B: like how this is going to work. Like am I, am my parents going to get like a security key sent in the mail or will it be tied to the passport? What do you know about how this is going to work for people?
Speaker D: Yeah, so your parents are going to get, uh, an invitation that they can now use their passport or citizen card or whatever the daily method of identification is in the physical world to onboard into, uh, an identity wallet, which is like a container of credentials. It's a software, it's an application that you would then install. Uh, every member country for the European Union. Union will have to be forced to provide at least one wallet application to their citizens. Um, so we'll probably see one per country, um, or we certainly see one per country at least. And then you can identify yourselves using the passport. Usually, um, there's other mechanisms also to onboard. And then you have a representation of your passport or driver's license in a digital format which you then can link to email addresses, phone numbers, um, university credentials, things like that. So it's not a physical, um, token that your parents probably in the Netherlands will receive, but, um, it's a digital representation, um, that is rooted to your government issued identification. I hope I didn't butcher it up too much. I'm sure there's UID people who think I missed out on a lot of things, but I think that's it.
Speaker B: But they're not on this podcast so too bad for them. If you're listening to this and you're one of those, we would love to have you, but maybe Tom, a question or Dana, question for you. So great central government ID system. I can upload my passport and then hook up all my things and then I want to travel or get married or do something and then the system is down like single point of failure. Like how are we going to deal with that then?
Speaker C: I think it leveraged on um, decentralized identity practices, which is itself made to, you know, the system should be able to keep up and, and like one piece of infrastructure failing shouldn't impact the rest of it. So I'm not, I mean there might be like point in time issues for authentication but, or um, verification but I don't think I, I think this technology is maturing enough that it'll be useful. What I, what I was looking at and was thinking about is recovery. Like what happens if the single pointer failure is you losing your phone or your wallet is um. And uh, but they, they seem to have captured that in what they're doing. And like you can recover your wallet just by getting another phone and then uploading your government uh, issued ID or whatever they're using for the original identity bootstrap and you get a new wallet. And not only that they give you a wallet, they don't clone your wallet. It's not stored it, so it's always stored on the local device. But they'll give you a new, like a V2 or a V3 of your wallet. And so um, it seems like it's, I mean it's an interesting design. It seems like it's very useful. It definitely helps with privacy because the wallet, like you can present your wallet and it only tells the site are you over 18 or not. It doesn't give them your birthday. It answers questions and makes um, claims about you that, or provides claims about you that don't give away the underlying data. So privacy wise it seems like a great um, way to do this as well. I just worry about lagging of implementation for that because a lot of systems have to update to support this wallet and make it work.
Speaker B: But it will be a standard like an OpenID like standard, something like that that everybody can use. So there's a lot of people behind the scenes working on this.
Speaker D: I mean there's a bunch of standards, there's probably a dozen or two dozens of standards that need to align here. Like there's a handful of standard bodies with each of them has probably like a dozen standards that they need to combine. So I mean it's a typical European approach is engineer perfection and then, and then legislate it and push it out. And I think that's why we see so much more activity in Europe than for example in the us. I mean in the US we have state by state digital driver's licenses, um, but every state does it slightly different. Um, so you have to make multiple implementations if you want to depend on it. But it makes it significantly simpler in the eu, it's a construct, it's a big construct of complexity. Yes.
Speaker C: Not being an EU citizen, I thought you were going to say the reverse, which is they write the legislation, then you have to figure out the technology. Because if you look at the milestones that are published for this id, it's like they're supposed to be ready at the end of this year and fully up and running at the end of next year. But then you're saying these standards are still evolving. Um, so it seems very aggressive on their end for this.
Speaker D: I think it is, yes. I think um, it caused a lot of headaches and somebody mentioned the word about adoption. Um, and the adoption comes also through regulation. Like for example today if you're a bank, you have to provide, you have to show that you can do strong customer authentication. So like strong customer authentication is a feel, I always feel like it's too generic as a description to reflect what it actually is. But it's a limited type of multi factor authentication like that you use multiple aspects to authenticate the user, uh, for example when they want to make a payment. So we have banks now who are forced to meet those regulations if they want to offer payment capabilities and those will, at uh, whatever the time frame is, I don't know it by heart, will have to integrate with European digital wallets. So that adoption is forced by legislation where you say, okay, you already have to meet this requirement to do strong customer authentication. Now one of those methods to do that will have to be a, uh, digital identity or a digital wallet.
Speaker B: Um, yeah. Tom, how are you hearing the industry preparing for this or aren't they yet?
Speaker A: They are definitely preparing for sure, but certainly more in the realm of theory than practice as it currently stands. Uh, specifically the banks, uh, uh, as Dario already said, want to make sure that they are in line then with the requirements that are going to come to kind of have this incorporated in their client dicing business. Right. Um, but at the moment we're seeing certainly in Switzerland and not necessarily any kind of, uh, I don't see any deadlines for people going live in production yet, but certainly involved in the working groups and certainly thinking about kind of what they're going to need from a budgetary perspective in a year or two to uh, integrate this then into their consumer facing solutions.
Speaker B: So if you're a software engineer in identity, send your CVS to everybody that's legislated, like banks or whatever to implement this European digital ID wallet. Um, yeah, we covered a lot again as always and we could go on for a long time, but we all have to take a break from this heat, including the identity heat, digital identity heat. We've talked about how identities have been evolving from a simple username, passwords that's stored into dynamic thing, which is privileges that can be shared. We've talked about how agents is changing that constantly. And we've talked a bit about, you know, the role of government that can make sure that stuff happens safe, but also in, at least in Europe, is now pushing a centrally defined standard of how people will be represented digitally to their banks, to their healthcare providers and everything else that's regulated. So I think we've covered a lot. Uh, thank you so much for three of you. Always a big pleasure to have you on. Tom, great to have you back and for everybody. Yeah, and for everybody listening or watching us from wherever you are in the world, thank you so much as always connect with us on LinkedIn. And remember, stay safe. And, uh, success is when nothing happens and when you have an air conditioning in this heat.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.