Editor's Note: This article is based on reporting originally published by waag.org. All key details have been cross-referenced and verified for accuracy. View Original Source ↗

Lead Hook

The European Union's digital identity wallets are being rolled out to provide citizens with a secure way to access services and verify their age online. However, Waag reports that these wallets rely on safety services from Google and Apple, specifically Google's Play Integrity API and Apple's Managed Device Attestation. This raises concerns about the dependence on private companies and the potential violation of the Digital Markets Act.

Deep Dive

According to Waag, the Google Play Integrity API is not just a security feature, but also reinforces Google's control over the Android ecosystem. The API checks whether a device is running a Google-licensed version of Android and treats unlicensed alternatives as a potential security risk. This can exclude operating systems that are not licensed by Google and encourage installation through the Google Play Store, which may violate the Digital Markets Act.

The EU's Architecture Reference Framework recommends the use of Google and Apple attestation services, but does not mandate it. However, some member states, such as Italy, have interpreted this recommendation as mandatory, while others, like Switzerland, have dropped Play Integrity due to data protection and freedom-of-choice concerns.

Audit & Contradictions

The fact-check audit notes that the report's core assertions about EU member states using Google Play Integrity and Apple attestation in digital ID wallets are corroborated by independent outlets, such as Follow the Money and Kennedys Law LLP. However, claims about the Play Integrity API violating the DMA and the normative stance on vendor lock-in are only made by the primary source and lack external confirmation.

The contradiction level is marked as "Low", indicating that the report's factual core is supported by independent reporting. However, the single-source claims about the DMA violation and policy stance on interoperability and lock-in must be hedged.

Future Outlook

The implications of the EU's digital ID wallets relying on Google and Apple safety services are significant. If Europe is serious about digital autonomy, it should rule out Google and Apple attestation entirely from the Architecture Reference Framework and mandate open, hardware-based attestation mechanisms. This would allow for greater interoperability and reduce dependence on private companies.

As the EU continues to roll out its digital identity wallets, it must consider the deeper implications of relying on Google and Apple safety services. The use of these services may undermine the EU's goal of promoting digital autonomy and may violate the Digital Markets Act.