One of your customers has done everything by the book. They carry a government identity wallet proofed to the highest assurance level European law recognizes, and sign in to your app with nothing but a glance. One afternoon their phone rings. Then comes the call. The number, the hold music, the script are all convincingly your fraud team’s, and a patient voice explains that their account is under attack. Twenty minutes later the account is empty, and every transfer bears the customer’s own verified approval.
Run the session back and nothing flags: real identity, familiar device, strong authentication, recorded consent. The wallet proved the one thing it was built to prove – that this was the customer. Whether they were acting in their own interest was never its department.
The wallet in that story has a name and a timetable: the EU Digital Identity (EUDI) Wallet, which every member state must issue by the end of 2026. A year later, regulated businesses must accept it – banks, telecoms, the largest online platforms among them. Before you file that under “compliance, 2027,” look at what happened the last time Europe raised the authentication bar.
Europe Already Ran This Experiment
In 2019, the EU began requiring Strong Customer Authentication (SCA) for Europe’s logins and payments: MFA, in effect, but with stricter rules about what counts as proof. It worked. Card and credential fraud fell. Total payment fraud didn’t: the European Banking Authority and the European Central Bank now report that payment fraud across the European Economic Area jumped 20% in a single year to reach €4.2 billion in 2024, after strong authentication became law. The regulators’ own analysis names the mechanism: fraud turned to social engineering and payer manipulation, persuading verified customers to authorize fraudulent payments themselves and steering toward the moments where SCA doesn’t apply.
That is the lesson: hardening the credential is a dam, not a drain. The fraud changes course,, from the credential to the person holding it. The EUDI Wallet is about to harden the credential further than SCA ever did. The question it leaves is not whether fraud finds the next low point; it is whether your stack sees it when it does.
Now the Bar Rises Again – on a Date You Don’t Control
The EUDI Wallet is the centerpiece of eIDAS 2.0: a state-issued identity credential, interoperable across all 27 member states, proofed to Level of Assurance “High” and bound to the secure hardware in the customer’s phone. It does two jobs: it verifies identity – onboarding, KYC, age checks – and it authenticates, serving as a compliant SCA method for login and transaction approval.
The deadlines come in two steps. By the end of 2026, every member state must offer its citizens a compliant wallet. By the end of 2027, relying parties bound by the regulation – banks and payment providers, the essential-service sectors, public services, the very large online platforms – must accept it, for the strong-authentication step itself, not merely as one way to prove identity at sign-up. And the mandate marks where adoption starts, not where it stops. The EU’s stated target is 80% of citizens using a digital identity by 2030, and once one-tap verified identity is what customers expect, businesses outside the mandate will feel the pull too, from the conversion and cost upside.
Supply is slipping: as of mid-2026, fewer than a third of member states meet the readiness benchmark, and several have signaled delayed or limited launches. The demand obligation doesn’t move with them. In this rollout, the governments building the wallet are allowed to be late. You are not.
And if you’re reading this from outside the EU, consider it a preview. The UK, the United States, and programs across Asia-Pacific are converging on the same verifiable-credential model. Europe simply arrives first, with dates written into law. Chip cards followed the same script: a European requirement first, the global standard a decade later.
So what does “accept the wallet” take? You register as a relying party and declare, in advance, which attributes you need and why. You integrate the presentation protocol, validate the credentials customers present against the official trust list, and align wallet-based authentication with your existing SCA obligations. None of it is trivial, but all of it is knowable: a checklist with a deadline, the kind of work regulated institutions are built for. Knowable does not mean small. For a legacy stack with no native support for verifiable credentials, accepting the wallet means real engineering: an OpenID4VP verifier to receive and parse credential presentations, cryptographic validation of issuer trust and credential status using the applicable trust lists and status mechanisms, and mapping wallet attributes into existing identity and SCA flows. An orchestration layer absorbs that work once, where a bespoke build wires it into every flow. Compliance is the easy half.
The Harder Half: Fraud Your Stack Can’t See
The hard half has no deadline in the regulation, because it isn’t a regulation problem. Every system that accepts the wallet will lean on one assumption: a person verified at the highest assurance level is a person acting legitimately. The wallet makes “verified” true to a degree nothing before it managed. It leaves “acting legitimately” exactly where it has always been.
Go back to the opening scene. That scam defeats no cryptography. The credential is genuine, the device is trusted, the biometric is the customer’s own. Authorized push payment scams, coerced approvals, a phone call steering a customer through your own real flows: each ends in a transaction the account holder never truly wanted, inside a session that looks, on every identity signal, clean. Nor is the phone call the only route in: a presentation request can be relayed into a session an attacker controls, a wallet can be enrolled on a stolen identity, and a compromised credential keeps its assurance until revocation catches up.
And this challenge extends beyond human social engineering with the rise of agentic AI. As customers hand routine actions to AI agents, sessions opened by a verified person are increasingly driven by software acting on their behalf. An agent that has been hijacked, off its goal, or past its granted scope still looks, to every identity control, like the account holder at work: same credential, same device, same session. The wallet can prove a human started the session; it cannot say whether what is acting in it now still answers to them.
The controls a fraud team would normally reach for answer the wrong question: who is acting, not what they intend. They fail structurally, not tactically. Behavioral biometrics and device fingerprinting hunt for an impostor, and here there is none. Anomaly and velocity rules score each step, and every step is unremarkable — the fraud lives in the sequence. The assumption they all stand on is.
The Layer You’ll Still Need
If a verified identity no longer tells you a session is safe, the missing capability isn’t a better credential. The wallet already is one. What’s missing is a different question, asked continuously: not “who is this?” at a single moment, but “should this verified person, in this session, be doing this?” Answering it means reading the chain of actions as a whole – the first-time payee, the out-of-pattern amount, the automation this account has never run before – against what the account holder’s own history would predict, whether the session is human-driven or delegated to an AI agent.
This is what Transmit Security’s Mosaic platform is built to do. Mosaic fuses customer identity management, identity verification, and fraud prevention into a single decisioning layer powered by Predictive AI. Its Identity Orchestration dynamically routes global journeys, normalizes cross-border wallet claims, and turns complex compliance into a simple drag-and-drop workflow; the wallet plugs in as one more high-assurance method, the shortcut through the first deadline. Predictive AI answers the question the wallet cannot, scoring every session against the account holder’s own baseline. And for the session driven by software rather than a person, Mosaic adds AI Agent Discovery and Visibility to classify agent activity in real time, and Just-in-Time authorization to keep an autonomous agent within the authority of the verified human behind it.
Transmit Security is a Leader in the 2025 Gartner Magic Quadrant for Access Management and in KuppingerCole’s 2025 Leadership Compass for Fraud Reduction Intelligence Platforms – the identity side and the fraud side of one problem, validated independently.
Two Deadlines
The one in the regulation is fixed and knowable: roughly eighteen months, a checklist, work your institution knows how to scope. The second one nobody set and nobody will announce: the day fraud targets your verified customers and walks in carrying the strongest ID Europe has ever issued. Europe’s last experiment says the second deadline follows the first as surely as €4.2 billion in fraud followed SCA. The question is the same one that experiment left: not whether fraud finds the next low point, but whether your stack sees it when it does.
Meet the first deadline. Prepare for the second. At every moment that matters in your customer journey, ask the harder question: when the credential is genuine but the intent is not, can our stack still tell? If the answer isn’t obvious, talk to our team.



