CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
biometricsBy Cara Candelario

Future of Digital Identity: Trust Gaps Behind Every Selfie

Why You Keep Photographing Your Face for Every App — and Who's Really to Blame
A person takes a verification selfie, illustrating the future of digital identity and the trust gaps behind it.

Quick answer

Why do apps keep asking for a selfie to verify my identity?

Each app or bank runs its own selfie check because it has no binding agreement to accept another organization's result. The camera and face-matching software usually work. What is missing is shared responsibility for who audited the first check, so every service repeats it and stores another copy of your data.

You open a new app. It wants to verify you. You take a selfie, photograph your driver's license front and back, wait for the little spinner, and finally, you're in. Three weeks later, you sign up for something else and do the whole thing again. Same face. Same license. Same you. So why are you starting from zero?

Here's the thing: your phone's camera is not the problem. The face-matching software is not the problem. According to a new study from researchers at the University of Warwick and the Alan Turing Institute, the problem is that the banks, governments, and apps involved in verifying your identity simply do not trust each other's homework. And until they agree on whose ID check counts, and write that agreement somewhere binding, you are going to keep posing for selfies until the end of time.

TL;DR

Digital ID technology works fine, what's broken is the trust between the institutions that are supposed to accept each other's identity checks, and that's why you keep being asked to prove who you are from scratch.

The Study That Names Selfie Verification's Root Issue

Researchers looked at three countries that have built real, working digital ID systems: Brazil, Nigeria, and the Philippines. These aren't countries with half-baked experiments. They have sophisticated national identity infrastructure. And yet, as Biometric Update reports, even those mature systems kept running into the same wall when anyone tried to make them work across borders or across different services: the technical pieces fit together, but nobody could agree on who was responsible for checking the checker.

CaraComp DailyEP.75
3 stories · 3:01
Starts at 01:05 — this story
3:01

Watch this story, in under a minute

Plays right here · jumps to 01:05
In this episode

A new briefing every weekday — three stories, three minutes.

Subscribe on YouTube

That's not a software bug. That's a political and institutional problem. And it's expensive, not in the obvious way, but in the way where ordinary people pay with their time, their patience, and their privacy every single time they hand over their biometric data (their face, fingerprints, or voice, the body stuff that's uniquely them) to yet another organization that refused to accept someone else's verification.

"The approach of having standalone identity programs, fragmented governance, and retrofitting interoperability, rather than designing it from the beginning, creates problems that become very difficult to fix." University of Warwick / Alan Turing Institute study findings, as reported by Biometric Update

Read that again. They didn't say the technology failed. They said building things in isolation and then trying to stitch them together afterward is almost impossible to fix. That's worth sitting with, because it describes almost every digital ID system on earth right now. This article is part of a series, start with Face Match Not Proof Biometric Assurance Deepfakes.


What "Trust" Actually Means Here (And Why It's Harder Than It Sounds)

When a bank verifies your identity, it's not just confirming your name and birthday. It's also making a legal bet, a commitment that, if something goes wrong, it can defend its process in court. That's why they can't just say "oh, that other app already checked this person, we're good." Because if fraud happens later, the question becomes: who is on the hook? Who audited the original check? What rules did they follow? What happens if those rules don't match ours?

This is what researchers mean by "governance", not bureaucracy for bureaucracy's sake, but the actual agreements between organizations about who is responsible for what, who trained the auditors, and what the rules mean when things go wrong. Right now, most of the world's digital ID systems have excellent face-matching technology and almost no shared answers to those questions.

2026
The year formal digital identity wallet frameworks, with real legal accountability built in, begin scaling globally, but only in regions where governance is already aligned

The friction isn't "do we have your document." The friction, as the study puts it, is "can we trust it quickly, safely, and in a way that stands up to our local rules." No face-matching algorithm can answer that question alone. That's a treaty problem, not a software problem.

Switzerland just delayed its national digital ID rollout specifically to sort out this kind of trust infrastructure first, because they watched other countries build the tech and then get stuck exactly here. (Smart move, honestly, even if it's frustrating for Swiss residents still waiting.)

Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

Why Deepfakes Complicate Selfie ID Verification

Here's where it gets genuinely uncomfortable. This week, the news has been full of AI impersonation stories, deepfake videos, cloned voices, synthetic faces. And those stories connect to the digital ID problem in a way nobody is talking about loudly enough. Previously in this series: That Prove Youre 18 Pop Up Just Cost Roblox 6 7 Billion Here.

When institutions don't trust each other's identity checks, they each have to run their own. That means more systems collecting your face and your documents. More databases. More targets. Every silo of identity data that exists because two organizations couldn't agree on a shared trust framework is a new place for your biometric information to live, and potentially to be stolen, faked, or misused.

Reusable digital ID, the kind where you verify once and carry that credential like a card in your wallet, only works when every institution on the receiving end trusts the check that was done. That means trusting each other's fraud defenses, including each other's deepfake detection. Right now, most don't. So instead of one secure vault, your face lives in twenty places. The governance problem isn't just an inconvenience. It's a security risk hiding in plain sight.

Why This Matters to You Right Now

  • ⚡ Every new verification is another copy of your dataeach organization that won't accept another's check stores its own version of your face and documents, multiplying the number of places that data can be exposed
  • 📊 The EU is the closest thing to a working modelEurope's digital identity framework (called eIDAS, basically an EU-wide rulebook for who has to accept whose digital ID) is the most advanced attempt at binding governance, but it took decades of political negotiation and still isn't fully operational
  • 🔮 Big tech is filling the gap, carefullyApple Wallet and Google Wallet now support government-issued digital IDs in select U.S. states, which works because Apple and Google negotiated the trust agreements that governments couldn't figure out themselves
  • 🛡️ This is a privacy issue, not just a convenience issuefragmented identity systems mean more organizations hold more of your most sensitive data, with less accountability for what happens to it

The Selfie Verification Problem Nobody Wants to Admit

Governance is genuinely harder than building technology. The study is careful about this. Weak institutions, internal political pressures, and low public trust in government create structural barriers that no framework document alone can fix. Some countries have every incentive to keep their systems separate, control over identity data is control over people, and not every government is eager to hand a piece of that to a supranational body.

That's the dark underbelly of this conversation. The researchers at Warwick and the Alan Turing Institute call out something specifically uncomfortable: digital ID systems in some countries carry real political risk, because the same infrastructure that makes your life easier could also make it very easy to track and exclude certain populations. That's not a hypothetical. It has happened. It's happening now in places where facial recognition technology has outpaced any law to govern it, India is one prominent example making headlines right now, where the technology is deployed and the legal framework to constrain it simply does not exist yet.

According to the Secure Identity Alliance's 2026 outlook, the organizations pushing hardest for international standardization, like the ITU, the UN's technology arm, are making progress, but the binding definitions that would actually make mutual recognition work are still being written. Meanwhile, the EU Digital Identity regulation is the world's most ambitious attempt to mandate that Member States actually accept each other's digital IDs. It's imperfect and behind schedule, but it's the only model on earth that has legal teeth. Up next: That 99 Face Match Unlocking Your Bank Fraudsters Just Found.

The analysis from RightCheck on cross-border digital credential barriers puts it plainly: the friction isn't about whether the technology can read your document. It's about whether the organization on the other end has any legal reason to believe the person who checked it before them did it right.

Key Takeaway

Your identity verification keeps starting over not because the technology is broken, but because the institutions checking you don't trust each other's rules, and until they do, every new service will ask you to prove yourself from scratch while collecting another copy of your most sensitive data in the process.

Here's the one practical thing to watch for right now: when a service asks you to verify your identity, look for whether they offer a "reuse" option, something like "verify with your existing government wallet" or a sign-in through a state digital ID. In states where Apple Wallet or Google Wallet support it, that's the governance-aligned path. It's not perfect, but it's the closest thing to "prove it once" that actually exists outside of Europe today. Fewer redundant copies of your face floating around is always better.

If you've ever paused and wondered whether handing your face to yet another app is actually necessary, or whether there's a smarter way to know that the person on the other side of a screen really is who they claim to be, those are exactly the right questions. They're the questions the entire identity industry is trying to answer. And they're the questions CaraComp exists to think hard about on your behalf.


The researchers at Warwick and the Alan Turing Institute have given the world a useful gift: a name for the thing that's been frustrating everyone. It's not a technical failure. It's a trust failure between institutions that should have figured this out before they built their silos. The technology is ready. It has been for years. The uncomfortable question now is whether banks, governments, and app platforms are willing to give up a little control in exchange for a system that actually works for the people using it, or whether you'll still be photographing your driver's license in 2030, wondering why nothing has changed.

Identity Verification in Cybersecurity: The Bigger Picture

Identity verification in cybersecurity isn't just about letting the right person into an app, it's about keeping attackers out of every system that trusts that first check. When digital identity verification fails at the front door, the damage doesn't stop there; stolen credentials and forged documents move downstream into banking, healthcare, and government systems that assumed the first check was solid. That's why security teams increasingly treat identity verification as the actual perimeter, not the login screen or the firewall.

Digital Verification and the Reusability Problem

Digital verification only saves you time if the place checking your ID actually accepts a result someone else already produced. Right now, most digital verification happens in a walled garden, one bank, one app, one government portal at a time, because nobody has agreed on a shared standard for what "verified" means. Until that changes, every new sign-up will keep asking you to redo work you already did somewhere else.

Customer Onboarding Without the Repeated Friction

Customer onboarding is where most people first feel this problem: a new account, a new selfie, a new copy of your driver's license, all before you've even used the product. Businesses lose real customers at this stage, people abandon signups rather than dig up documents for the fifth time this month. A shared trust framework would let customer onboarding lean on a verification that already happened, cutting drop-off without cutting security.

Identity Authentication Versus Identity Verification

Identity authentication and identity verification sound alike but do different jobs. Verification proves who you are the first time, usually with a document and a selfie; authentication proves it's still you on every visit after that, often with a password, a code, or a fingerprint. The governance gap the study describes lives mostly in verification, institutions don't trust each other's initial check, so authentication never gets the chance to simply pick up where verification left off.

Customer Identity Data Multiplies With Every Silo

Customer identity data gets copied every time an organization refuses to accept someone else's check, which is exactly the pattern this study describes. Each fresh copy of your face, your document, and your personal details is stored somewhere new, audited by different rules, and protected to a different standard. Fewer, better-trusted checks would mean fewer places holding your customer identity data in the first place, which is good for you and cheaper for the businesses storing it.

The Process Behind a Trustworthy Check

The process that turns a selfie and a document into a trusted digital identity involves more steps than most people realize: capturing the image, matching it against the document, checking the document against a government or bank record, and then logging that decision so it can be audited later. When two organizations don't agree on that process, neither one can safely skip a step just because the other already did it. Standardizing the process, not just the software, is what the researchers say is actually missing.

Digital identity verification depends on more than accurate face-matching; it depends on institutions agreeing to honor each other's work. A single instance of digital identity verification, done once and trusted broadly, would eliminate most of the repeated selfies and document uploads people deal with today. Until banks, governments, and platforms build that shared trust layer, digital identity verification will keep resetting to zero every time you switch services, no matter how good the underlying technology gets.

Identity Systems Built for Retrofitting Rarely Hold Up

Identity systems that get bolted together after the fact almost always cost more to fix than identity systems designed for interoperability from day one. That is the core warning in the Warwick and Alan Turing Institute research: retrofitting trust onto standalone identity systems is far harder than building shared rules in from the start. Any country hoping to avoid this trap needs to treat governance as part of the architecture, not an afterthought bolted onto working identity systems once the cracks already show.

Identity Security Depends on Fewer, Not More, Copies

Identity security gets weaker every time a new organization stores its own copy of your face and documents instead of trusting a check someone else already did. Real identity security means fewer databases holding your most sensitive information, each one built to a shared, auditable standard. Until institutions agree on those standards, identity security will keep losing ground to sheer duplication, no matter how strong any single system's defenses are.

Digital Identities Still Live in Too Many Places

Most people now hold several digital identities scattered across banking apps, government portals, and workplace logins, each one verified separately because nobody trusts the others' work. Consolidating digital identities into one reusable, trusted credential is the whole promise of a digital wallet, but it only works if every institution on the receiving end agrees to honor it. Right now, digital identities multiply faster than the governance needed to unify them.

The Future Nobody Is Quite Ready For

The future of identity checking depends less on better cameras and more on institutions agreeing to trust each other's paperwork. That future arrives fastest in places like the EU, where a binding rulebook already forces Member States to accept each other's digital IDs. Everywhere else, the future stays stuck exactly where it is today, one redundant selfie at a time, until governments and companies write down who is responsible for what.

Digital Identity Needs Shared Rules, Not Just Shared Standards

Digital identity only becomes reusable once the organizations checking it agree on what "verified" actually means and who is liable if that verification turns out to be wrong. A strong digital identity framework, like the EU's, spells out those responsibilities in law instead of leaving them to informal trust between companies. Without that kind of binding digital identity agreement, every new app will keep treating your identity as unproven until it checks for itself.

The path toward a workable digital identity future runs through governments, banks, and platforms sitting down and agreeing on shared liability, not through better facial recognition algorithms. Every digital system that skips that step ends up trapped in the same retrofit problem the Warwick and Alan Turing Institute researchers describe: technology ready to go, and no agreement on who can vouch for whom. Exploring how the EU built its framework, slowly and imperfectly, offers the clearest roadmap available for any country trying to avoid starting from scratch.

Fraud prevention improves when fewer organizations hold fraud-relevant data, because each additional copy of your identity information is one more target for attackers. When institutions agree to trust each other's fraud checks, they also inherit each other's blind spots, which is exactly why the study stresses shared standards for identity proofing and identity governance, not just shared technology. Getting that right at a national level, and eventually across borders, is what actually shrinks the fraud surface instead of just moving it around.

Access to services should not require rebuilding your identity from zero every time, yet that is exactly what happens without a shared identity federation model. Better access depends on institutions recognizing identity proofing done elsewhere, provided the rules behind that proofing are transparent and auditable. Until access to reusable, trusted identity becomes the norm, people will keep handing over the same information again and again, and each new copy of that information becomes another place fraud can start.

Understanding why this matters starts with understanding that identity information is not just a login credential; it is a permanent record of your face, your documents, and your history, held by whoever last asked to see it. The importance of getting identity governance right is not abstract, because every unnecessary copy of your data is a future breach waiting to happen. Explore the sources behind this reporting, and the pattern is consistent: identity-centric security only works when institutions agree to share the burden of trust, not just the technology that makes checking possible.

The future identity landscape will likely look less like today's patchwork of one-off checks and more like a small number of trusted credentials that many organizations recognize at once. Building that future identity system means governments and companies agreeing, in writing, on who is liable when a shared check turns out to be wrong. Without that agreement, every promising pilot program stays a pilot, and the future identity most people actually experience stays exactly as repetitive as it is now.

An identity system that individuals can actually trust needs to do two things at once: reduce how many places hold a copy of their data, and make it clear who answers for a mistake. Right now, most identity system designs solve the first problem technically and ignore the second problem entirely, which is precisely the gap the Warwick and Alan Turing Institute study identifies. A workable identity system treats legal accountability as a feature, not a footnote added after the first embarrassing breach.

Digital signing of documents faces a version of the same trust gap that plagues identity verification generally. A digitally signed contract or form is only as trustworthy as the identity check behind the signature, so if two organizations don't trust each other's verification, they often can't trust each other's digital signing either. That's one more quiet reason digital signing adoption lags in places where identity governance hasn't been sorted out, even though the underlying cryptography works perfectly well.

A genuinely passwordless solution depends on the same trust chain as everything else in this story: something has to vouch for you the first time so a fingerprint, face scan, or security key can stand in for a password later. Where a passwordless solution is backed by a government-issued digital ID that other services actually recognize, it can replace years of repeated logins with one strong initial check. Where it isn't, a passwordless solution just becomes another silo, convenient for one app but useless everywhere else.

The way digital identity has grown over the past decade tells its own story: better cameras, better matching algorithms, and near-universal smartphone access, paired with almost no growth in the legal agreements that let one check count somewhere else. Digital identity has grown technically much faster than digital identity has grown institutionally, and that mismatch is the entire subject of the Warwick and Alan Turing Institute research. Closing that gap, not adding more sensors, is what actually moves this forward.

None of this fully resolves until fraud itself is treated as a shared cost rather than something each organization tries to solve alone behind its own walls. Fraud that slips through one weak, isolated check can move on to the next institution just as easily as a legitimate customer can, because fragmented systems rarely share warning signs quickly enough. Reducing fraud at scale means treating identity governance the way the EU treats it: as a binding rulebook everyone has to follow, not a best practice everyone quietly ignores.

Digital trust, in the end, is the real product being built here, more than any single app or wallet. Digital systems that ask you to verify yourself repeatedly aren't broken by design; they're operating exactly as expected in a world where digital institutions haven't agreed to trust each other yet. The countries and companies that figure out digital governance first will be the ones whose users stop noticing verification altogether, because it will finally have been done once, correctly, and accepted everywhere it needs to be.

Frequently asked questions

What is holding back the future of digital identity?

The future of digital identity is held back not by technology but by trust between institutions. Research from the University of Warwick and the Alan Turing Institute found that banks, governments, and apps have working face-matching and verification tools, yet they refuse to accept each other's identity checks, forcing people to reverify from scratch every time.

Why do I have to keep verifying my identity with a selfie for different apps?

You keep submitting selfies and license photos because each app or institution does not trust another's prior identity check. The camera and face-matching software work fine; the missing piece is a binding agreement between organizations about whose verification counts, so every service starts the process over.

Do countries with advanced digital ID systems still have verification problems?

Yes. Researchers examined Brazil, Nigeria, and the Philippines, all of which have sophisticated national identity infrastructure. Even these mature systems hit the same wall when used across borders or services: the technical pieces connect fine, but no one agrees on who is responsible for checking the checker.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search