Interviews
Amit Sharma – Rethinking Digital Identity in the Age of AI and Verifiable Credentials

Ben Cejvan
·
·
2 min read

In this episode of The Future of Identity Podcast, I’m joined by Amit Sharma, Global Head of Digital Strategy at IDEMIA Public Security, to explore a more foundational question than usual: why digital identity matters right now. Rather than focusing on a single deployment or ecosystem, this conversation zooms out to examine how accelerating AI capabilities, data exploitation, and digital-first lives are reshaping the role of identity in society.
Our discussion connects big-picture philosophy with real-world infrastructure - covering everything from verifiable credentials and mobile driver’s licenses to identity acceptance networks and the economics of data. Amit shares a compelling perspective on why the current model of identity - built around detection, data aggregation, and exploitation - is breaking down, and what needs to replace it.
In this episode we explore:
Why AI and agentic systems are breaking traditional fraud detection models - and forcing a shift toward proving authenticity instead of detecting bad actors.
How verifiable digital credentials enable trust-first identity, reducing reliance on data brokers and improving both security and user experience.
The role of identity acceptance networks in unlocking real-world utility for credentials like mDLs across industries.
Why today’s data economy is fundamentally misaligned, and how user-controlled identity could reshape incentives around privacy and monetization.
The importance of incremental progress over perfection, and why deploying imperfect digital ID systems today is critical to driving adoption and learning.
This episode is essential listening for anyone thinking about the future of identity beyond just technology - spanning business models, regulation, AI, and the fundamental question of how we build a more trustworthy digital world. Amit brings a rare combination of policy, security, and commercial perspective to one of the most important shifts happening in identity today.
I hope you enjoy the conversation and if it resonates, feel free to share it with others interested in where identity is headed.
Learn more about IDEMIA.
Reach out to Riley (@rileyphughes) and Trinsic (@trinsic_id) on Twitter. We’d love to hear from you.
Listen to the full episode on Apple Podcasts or Spotify, or find all ways to listen at trinsic.id/podcast.
Related from Trinsic: see how Trinsic verifies identity in the United States, or explore digital identity verification by country.
Full Transcript
Transcript lightly edited for clarity.
Riley Hughes: Welcome to the Future of Identity podcast, a show that highlights the world’s most innovative digital ID ecosystems and the people behind them. I’m Riley Hughes, co-founder of Trinsic, and we’re the first identity acceptance network. Our product is a gateway that helps businesses accept dozens of digital IDs through one seamless integration. Today, I spoke with Amit Sharma, Global and Digital Strategy Head at IDEMIA Public Security. We had a great conversation that I really enjoyed. It ended up a little bit different than our usual content here on the podcast, but the takeaway of the conversation is basically why verifiable digital credentials matter for the world, and in particular this moment in time as AI capabilities accelerate faster than most organizations’ ability to keep up. So I’d love your feedback if you thought this episode was interesting, and if you prefer the more concrete or tactical content we usually do, I’d also love to hear that.
Riley Hughes: But ultimately, the best feedback you can give us is to share the podcast with friends or colleagues, as it’s the best way to show us the time we’re spending on the podcast is valuable and that we should keep doing it. And now to my conversation with Amit. Amit, welcome.
Amit Sharma: Hey, great to be with you today.
Riley Hughes: I’m excited for this one, and today I wanted to do something a little different. You’re going to be my guinea pig or experiment here to open the show. Normally we end each episode by asking the question, Tell me what the future of identity looks like to you and why that matters for the world. But given the recent panels we were on together and things like that, and how you have spoken so eloquently about why the things that we’re doing matter for the world and the next generation and things like that, I just wanted to ask you this question right up front. Could you frame the discussion for us by telling me why does the future of identity matter to you?
Amit Sharma: It’s a great question. I’m glad you start this way. I really look at this whole space through the lens of my kids. I’ll give you a quick anecdote. I’ve got a senior in college. He spent the last year applying to a number of schools where he provided, through online intermediaries, his entire academic and educational background. His biometric health data, because he’s being recruited for athletics, and his entire family’s financial and economic picture for student aid, grants, scholarships, tuition, and the like, through online intermediaries he doesn’t control. We did not give him a cell phone until he was about 16, 16 and a half, when he started driving. He’s never been on social media, and within an hour after he turned 18, he had targeted ads with his likeness knowing where he lived, his preferences having been gleaned from the data that he had been sharing, and going through online intermediaries where the predominant business model has been the exploitation of personal data and identity information.
Amit Sharma: You couple that with the fact that Gen Zers moving forward are all digitally native, whether they like it or not. They are all digitally native, so their personal identifying information, their behavioral data, is entirely digital. And if we think about those two fact patterns, and if we think about the future we want for our kids, do we want our identity and the exploitation thereof to be driven into algorithmically elevated content that is, in fact, addicting them to online engagements, when the online universe is increasingly where we engage for health, finance, education, peer-to-peer engagement, buying, selling, etc.? So I think about the entirety of online and web nativity through my kids, and nothing comes closer to the central throughline than identity. We are not going to put the internet cat back in the bag, nor should we. We’re not going to stop or slow down the advent of agentic AI. We’re not going to stop the increase of engagement that requires that we prove who we are engaged with when. Right now, more than 50% of the online traffic we engage in are bots or agents.
Amit Sharma: If that is all true, we need to look at the central nature of engagement online, especially in critical or highly regulated spaces where personal data, including our identity data, is exposed or vulnerable. That’s the entirety of my mission here at IDEMIA. That’s the entirety of why I like the digital identity space, and that’s entirely why we try and push this technology forward, insofar as making sure that future generations, starting now, have the ability to own their identity and be able to permission the verification elements such that they can access critical services but not be fully exploited online as we see today.
Riley Hughes: Yeah, that is a tremendous intro. Thank you for that. I knew it would be a good choice to start with that instead of finally visiting that at the end. And the next thing I want to do is connect the dots between that vision and framing and the real-world stuff we’re doing right now. So we recently announced a partnership between IDEMIA and Trinsic, which I think we’re both excited about. Why don’t you share from your point of view maybe how the partnership with Trinsic, and you’ve certainly announced other partnerships in the ecosystem as well, right, to progress this vision forward. Talk about it from your perspective, right? What do these partnerships enable, and how do they get us closer to the world that you’re describing?
Amit Sharma: So given the future state that we want to see, which I just described, we want to ensure that we can enable acceptance in a broader network of use cases with issuance. And that’s really what I’m excited about what our partnership does, right? The issuance backed by high assurance, biometrically bound, high root of trust identity, combined with the broader acceptance layer, allows for the utility of digital identity credentials like mDLs to actually matter in the world. If you think about the issuers of the mDLs from the DMV perspective, what incentive do they really have to drive adoption? Very little. They’re issuing a credential that effectively affirms your right to drive. That’s it. That’s the whole purpose of the DMV. But we use our driver’s licenses for a whole slew of other things, to access services, to get through a TSA PreCheck line. or just get through the airport to board a flight. We use it to affirm identity when we’re buying a beer at a pub.
Amit Sharma: We do this all in the broader world without understanding that, quite frankly, we now have mobile form factors that are more secure, verifiable on the spot, in ways that are more protective against vulnerabilities for identity theft. It also allows us to share only what we need at the time we need to share them. If I’m buying a beer, they don’t need to know where I live, that I’m an organ donor, my eye color and the like. Why am I presenting all of these pieces? And we do this online every day. So what I’m excited about this partnership is this larger picture. It enables and represents a model where high-assurance, root-of-trust, biometrically bound identity can drive adoption of a mobile, secure form factor of identity that’s usable in a broader acceptance network in those use cases for health, education, travel, worker mobility, financial services in ways that we intend. That’s what the basis of that partnership is. That’s what I get excited about this beyond just a simple right-to-drive use case.
Riley Hughes: And it’s funny that so many of the digital IDs around the world are pretty restrictive or whatever, right? They’re pretty locked down. There’s a lot of control imposed by the wallet provider or by the issuer or something on, like, the use cases that are allowed, which is interesting because in the same breath as talking about these controls and protections, a lot of these players will also mention their desire to have this more widely adopted. I think the insight here is that the more places you can use your…
Amit Sharma: Digital ID, the more utility there is.
Riley Hughes: Correct. The more reason there is for a consumer to adopt, and then the more consumers, the more relying parties, the more relying parties, the more issuers will want to get involved, and all of a sudden you sort of break the gridlock. And that’s, I think, what we’re trying to do at Trinsic, is where the market is. It remains quite fragmented. If you look at the landscape in the United States alone, there are 16 different mDL wallets. And by sort of trying to consolidate that and make it a little simpler, hopefully we can break the gridlock, at least on the acceptance side, to at least one of those three parties in that three-party triangle will have an easier time doing their part, and then hopefully we’ll unlock the rest of the ecosystem.
Amit Sharma: 100% right. And I think what it also does is it demonstrates that cooperative engagement between issuers, verifiers, relying parties, and the broader network begets more business because more services are unlocked. That’s really the idea. And I think what it also does is it breaks this misconception, and I believe it is a misconception of, I have to win the wallet war because I become the funnel and choke point. I have to win the explicit data standard because I become the only one that makes it usable within a particular use case or a particular sector. What this partnership enables is, look, we can accommodate multiple formats, multiple wallets, in ways that unlock the services. But the core is really what we’re getting at: can I prove you with high assurance in a way to unlock services that may be web-native, but also do so in an offline context? And the answer to that is yes. The technology now exists.
Amit Sharma: So what I do get excited about, the business opportunities that are afforded by our enablement together in partnership, I am very interested in how this unlocks new business models for service providers against that triangle of issuers, verifiers, and relying parties in ways that now unlock services, and that should be the commercial model. So we can now drive that commercial model in a way that expands the pie. And importantly, reinforce security, because there’s been this false binary that I either am secure or I’m frictionless. That is not true. We can actually combine frictionless with high security, and that’s what this new technology enables. And it’s proven. This isn’t just proof of concept stuff. This is, we do this. We’ve done this in a whole slew of other industries. We can do this unlock in a broader digital identity set of use cases.
Riley Hughes: Yeah, I love talking to you because I always have new insights. I just had an idea here from you that I want to pressure test and see if you agree. Last time we were on a panel together in Houston, I got an insight, which was that one of the people in the audience asked a question about shared fraud signals between service providers or whatever, relying parties. And I proposed an answer, which was basically saying that verifiable credentials, rather than being a shared fraud signal, are actually a shared trust signal, right? That a trusted institution gives to a user to allow them to prove authenticity to a relying party, rather than the relying party needing to strictly rely on detecting bad behavior, right? I can prove I’m authentic, as opposed to you trying to detect if I’m inauthentic. And your point about this false tradeoff between security and friction, the reason that’s been such a prevalent concept, or people talk about that tradeoff so much, is because historically, with a lot of fraud prevention, it’s just, it’s all about detecting inauthenticity.
Riley Hughes: It’s all about detecting bad. And if that’s your only tool, then the only way to increase your effectiveness of detection is to layer on more and more detection things, which inherently add friction, right? And so maybe the only way to get out of that tradeoff is to flip the script and think about it in terms of proving authenticity as opposed to detecting inauthenticity. Okay, what do you think about that? That’s the first time it’s ever come out of my mouth. Do you think that works?
Amit Sharma: It’s great. I’ll offer a little bit of historical perspective. You see the gray hair here, right? In an analog world, in a post- 9/11, 2001 environment, where the biggest financial crimes threat were like stored value cards, right? This is pre-fintech and pre-decentralized financial services and tokenization, Web3 finance, et cetera, et cetera. Pre that, right? We anointed financial services and intermediaries. to effectively say, Hey, Riley, I’m going to tell you if you are you. That seems inherently backwards. Why are you anointing an organization that has neither the training, background, et cetera, to effectively make the determination that you are inherently you are? The reason for that is because it’s a deliberately anti-crime, anti-illicit activity, anti-person trying to exploit the system strategy, which is not incorrect.
Amit Sharma: But when we use that as the core, we create a false binary, and that means the incentive structure for an anti-fraud control person at a bank is more incented to reject people to prevent potential fraud at the expense of including people that are in fact right and good. We need to flip the model from a business and commercial incentive perspective that pays dividends to security when I want to incentivize acceptance of trust. If I can now say you’re a trusted party, I can include you in the business in ways that are risk mitigating equally, if not more effectively, if I’m just trying to look for the illicit needles in that haystack. I can actually shrink the hay such that I’m literally much more targeted. And if I also put that identity back to you, I’m actually throwing it back to the edge. I’m not the honeypot. I don’t hold the legal liability risk. All of those dividends play out. And so that’s the model.
Amit Sharma: Now, in a post-9/11 world where hair on fire and you’re going, Oh my gosh, the banks are being exploited by illicit actors, weapons proliferators and terrorist groups and organized crime, et cetera, drug traffickers. Yes, they exploit people. And now we’re moving into a web-native context where fraud as a service is a growing industry, right? It pays to be the bad guy. Why not create a model that’s flipped and instead of chasing the bad guys who are innovating two, three generations above, by flipping the script and saying, No, if you’re a trusted party that can be assured, I’m going to let you in the tent all day long because it will inherently incentivize the pushout by inclusion. The current Know Your Customer financial crimes compliance regime set is a deliberately financially exclusionary model. It does not, by design, incentivize, from a business or security perspective, financial inclusion. So we wrap our minds around this doesn’t have to be the tradeoff. It is inherently the tradeoff.
Amit Sharma: But if you are now sending trust signals because I know that the universe of good is much bigger, I can wrap my hands around that, which not only reduces the controls, i.e., costs, for anti-fraud, but it increases the business opportunity because I’m providing the service. Why? Because we’ve embedded identity at the infrastructure level and we’ve given it back to the user. And that’s the model that we can provide with this partnership. So I think you’re spot on. I think what we need to do is move the industry, especially highly regulated ones, into a trust-first model instead of a I don’t trust anyone model.
Riley Hughes: Yeah. And I know we’re just ერთმან here and preaching to the choir here, and I want to get into more of my agenda here that I had. But don’t you think that when the rate-limiting factor for bad actors was their labor, the tool at our disposal is, like, detection? Okay, maybe that’s, like, sort of adequate or whatever. Like, maybe that tradeoff you’re describing, somebody could reasonably say, I’m going to have this false positives, right, for this set of good users, but in exchange, I’m keeping out these bad actors over here. And a reasonable person could make a tradeoff like that. But in a world where the bad actors now, the rate-limiting factor is no longer their labor, but it is the capabilities of the frontier when they can spin up 1,000 sub-agents, each of whom can call tools and recursively self-improve toward an outcome, how are you going to plan on relying on just detecting bad actors when now the tools at their disposal… are just completely asymmetric relative to the good actors.
Riley Hughes: Like you’re either going to have to just exclude way more people, good people, or you’re going to need to open up another path. And so my—this may be a little bit radical—but I think the paradigms of yesterday are completely broken by AI, and I don’t see another way through it besides enabling good users to prove they’re good with signals of their authenticity, which are cryptographically verifiable. And this brings us back to verifiable digital credentials and the work that we’ve each been doing for a while. But yeah, what’s your reaction to that?
Amit Sharma: That’s exactly right. That’s exactly right. I would—I agree with everything you just said there, and I would just add that AI and agentics exacerbate this at incredible logarithmic scale for all the reasons you just pointed out. But the additional ones, if we move to more deterministic fraud signals to detect bad actors, I can create, through AI, engines that in fact make fraudsters look so much like the legitimate human that now even those signals are diluted in the space. So the human not present actually becomes an easier way for a fraudster to get through because I can have agents that are literally mimicking what good looks like at scale, and any vulnerability that is an exposure for an identity attribute I can grab. And if I can do that at scale where I am now a criminal, that it’s literally costing me less to do that. We used to have a saying at the U.S. Treasury Department when we were driving financial crimes compliance, international sanctions, the FATF, the Financial Action Task Force on International Standards, right?
Amit Sharma: We had this quote constantly: We want to make it riskier, costlier for a criminal to exploit. A financial services system. AI radically reduces the risk and radically reduces the cost. So. we are already losing, and now you’re going to make it such that we still have to determine the bad when the bad has so many more tools. If we look at using those same tools to flip the script and say, No, that is going to enable and reinforce positive trust signals for licit actors, I inherently flip the model both from a business perspective and a security perspective to be higher efficacy because I will not, in fact, bring people on that are not highly trusted. That’s the inherent goal of verifiable digital credentials. That’s the goal here. So it is as much a business model shift as it is a paradigm cultural shift to understand what good looks like to disrupt the bad. And we have been a much more enforcement-centric model—Republican, Democrat, left, conservative, liberal, privacy hawks to more libertarian. All of those are still like, Go after more bad guys.
Amit Sharma: Give me more tools to identify the bad. Their tools are going up to look like good. So why don’t we go the other way? Because we’ve not had the efficacy that we’ve needed. So let’s go the other way and, in fact, inherently reinforce trust, because licit and good can be brought in. That’s the model we need to change.
Riley Hughes: Yeah, I totally agree. And the tools to accept a user’s shared authenticity signal, right? They’re, for example, mobile driver’s license. These are here. Maybe they’re not widely distributed. There’s still less than 50% of U.S. states that are issuing mDLs, for example. I’m going to ask you, having experience in both the public sector as a public servant and shaping policy, as well as in the private sector and in the commercial world, if you would have asked me 10 years ago, who do you think will be adopting mDLs first? Would it be the Department of Homeland Security through TSA, or would it be commercial organizations? I certainly would have bet on commercial being the first use case. I guess, what are your thoughts on how did it end up being that TSA is the headline use case for mDLs and not something commercial? And what do you think needs to happen to accelerate the relying party ecosystem on the commercial side?
Amit Sharma: Yeah, that’s a great question. I think first at a high level is that I think I’m not at all surprised that the first use cases have been government-led because it dispels the broader myth that, oh my gosh, the corporate and commercial sectors are going to be the leads in enablement for these new technologies. You need the imprimatur of governments to say, yeah, this is great. Why? One, they’re dealing with highly sensitive use cases, passing through a critical space like an airport because we’ve seen vulnerabilities there from a terrorist perspective. We have government benefits programs that are in the billions and trillions that need to be protected. Am I making sure that I send that benefit to actually Riley? So that does not surprise me. Some of our largest customers, partners, are the Department of Defense, law enforcement community and the FBI, DHS, and multiple stakeholders within DHS like TSA, the broader homeland and national security landscapes. These are critical spaces that need highly sensitive, individualized information to be affirmed so that they can undertake those.
Amit Sharma: Guess what? The government employs private sector actors for that tech. Right. And so IDEMIA is a private sector actor that has put hundreds of millions of dollars in AI deepfake detection and deterministic and probabilistic tooling, high assurance models for biometric assurance, identity issuance. These are all elements of that. The second is that you’ve got an equally, if not more emphatic, fractured market in the government space. We’ve got 50 states, we’ve got a federal government, we’ve got these different rules that have to comport, and you’ve got sovereignty within each one of those. The lack of coordination between the states is a challenge, and therefore they all compete with private sector actors that are saying, again, back to the very first thing we talked about, if I can own and control the funnel for a particular state, especially one of the big fours, the Californias and the New Yorks and the Floridas and the Texases, oh my gosh, I’m going to win that battle. And that’s the wrong battle. The battle should be, how do I unlock and enable as many use cases there?
Amit Sharma: But we’re doing the choke point at the state level because, again, that buyer is the state of California. But if you actually unpack it, the vast majority of the providers to each one of these individual states are already collaborating on the back end. It could be a biometric provider over here, a root of trust identity credential over here, an issuer over here. We issue actual physical driver’s licenses for the vast majority of the states, and then an increasing number of mDLs in that way. I would be happy to work with other providers for high assurance identity attributes, whether it’s a biometric, a selfie liveness capture, a fingerprint capture, and the like. These are the kinds of things that we have to start unlocking those services. So I’m not at all surprised by that momentum. What I am very surprised with is that the technology is here. Why are we not seeing more corporate enterprises enable that technology as an example to the regulators? And then the final piece is that we have…
Amit Sharma: This sort of regulatory Damocles hanging over half of us, whether it’s healthcare, it’s education, we see this in financial services all the time. And traditional financial services, you’ve got the unlock with fintechs and crypto and digital asset companies and the like, but traditional banks are sheep. Like, they’re sheep. At the end of the day, it’s like they don’t want to undertake an innovative new technology without an absolute stamp of approval from the regulator. If the regulator is still trying to figure out what’s the best tech, etc., then we’re in this sort of logjam. The other piece of this, and this is part and parcel to large organizations, and I want to be really clear here, this isn’t just an issue of government. This is an issue in private industry with large organizations. Our organization struggles with some of this too. It’s like trying to figure out what the right hand… and the left hand is doing.
Amit Sharma: We have had to educate the federal financial regulators on all of the deployments IDEMIA has with Homeland National Defense buyers of our tech, and they don’t know what it is. And once we explain, here’s what we’re doing for the Defense Department, for TSA, for Global Entry, for your passport issuance, et cetera, it’s, oh yes, folks, we can enable it here too. So we have to break down the silos in private industry that are just as big, if not bigger, as we see in the government space. And so private industry can start breaking down the silos that now enable unlock of services by service providers in ways that can be a demonstrable set of efficacy principles and technology to meet those principles in ways that haven’t been before. So that’s the paradigm shift that we’re trying to drive here.
Riley Hughes: Yeah, I appreciate that, and I wonder, the default for everywhere is status quo, right? It takes some catalyst or catalyzing person or something to come in somewhere and make a change. And this is just a universal kind of statement. But if we zoom into our specific scenario we’re talking about here, the elephant in the boardroom, we’ll say, is always AI right now. That’s all anybody wants to talk about, it seems, and honestly, for good reason. It’s unbelievable right now how much the world is changing and how quickly, and— If I go back to our conversation about detecting bad actors versus enabling good actors, I run into this with AI agents all the time, right? When websites are strictly trying to detect if I’m using my agent, and basically what I see there is just a cat and mouse, right? Like the website adds some detection, the agent adds some, you know, oh, it’s going to move the mouse around now so the detection thing stops working.
Riley Hughes: And then now that’s going to like catch on to that, and so now the agent’s going to do a different— So that cat and mouse is going on to prevent bad actors, and that’s fine. But the thing I don’t see almost any of is the enablement of good actors. If I want my agent to book my ticket to the conference for me because I don’t want to spend 10 minutes filling out forms and whatever, I want to be able to give that agent authority. I want the conference or whatever to be able to know that it is actually my agent and that it’s not someone else pretending to be me. Even— ignore agents for a second. Even just think about us as people, it’s challenging for me to prove who I am to begin with. Just to prove my name is Riley Hughes on the internet is like a lot of websites will make me photograph my passport to do that. It’s not exactly straightforward.
Riley Hughes: And now just to add on another delegation layer and say, okay, we’re going to make this like twice as complicated or whatever, or I get concerned about how this is going to really truly roll out, and I wonder if it’s just going to default to some crappier solution, basically. It’s just easier for people to wrap their heads around. At the same time, AI is just consuming so much of the air and the oxygen in the room that maybe we do have an opportunity right now to, if it’s something adoptable and useful, to make a difference. So what is your take on this? Is this an angle to help accelerate commercial sector sort of adoption of deterministic identity signals?
Amit Sharma: I think it is very much a catalyst for it because the technology is proven, and the technology builds and shares underlying attributes that modern digital new financial market infrastructure, health infrastructure, education infrastructure that is native to the web relies. That’s why I’m positive and optimistic about it. Where I grow weary or concerned is that the bigger paradigm we need to shift is that right now there’s still so much overwhelming money and economics in the exploitation of Riley’s underlying identity data. I mean, that’s just a reality. I’m an equal opportunity antagonist here. I equally want regulators to say, I am open to the technology to fulfill the intent and not regulate by enforcement such that innovation doesn’t cool. Innovation never cools. There are application and transparent channels to regulators. That’s what cools. You still have innovation. We still have all that innovation in the private sector. And guess what? If we don’t have that enablement with regulatory support, that innovation is going to happen.
Amit Sharma: It’s going to just happen underground in areas that are not going to be as transparent. My bigger concern are those platforms that control the internet. They are so incentivized to capture my kids’ data and monetize it and exploit it. That’s what we need to attack. And the ability to create verifiable digital credentials that are user-controlled, permissioned by the owner, is not only first step, but it’s a healthy, important step to get to that reality. Because then what we can do is actually put both the onus as well as dispel the liability risk. You put the onus back to the user to prove and now create trust as the signal versus the illicit actor or the fraud signal. And when we can do that, we re-incentivize the structure to you’re paying for access to something versus I am exploiting your underlying data because I’m capturing it in every space I can. And that’s the push that we need.
Amit Sharma: We need to go to the broader technology infrastructure providers, the network providers, the core banks, the cloud companies, those that in fact are the rails through which sensitive data is moving forward. But ask them, let’s see what are the conversations with some of the biggest social media platforms. It’s about the monetization of your data, right? We need to get out of that mindset. So, like I said, when I claimed equal opportunity antagonism, okay, venture capitalists and private equity and institutional money. Where are you putting your dollars? Are you putting them in business models that exploit data and identity, or are you going to actually invest in areas that reinforce privacy? I get very tired of being in conferences where some of the VCs and the PEs, especially in fintech and crypto and some of these other industries, Oh yes, I’m a privacy hawk. BS. Two-thirds or more of your portfolio is built and monetized on monetized. personal data. Get out of that business. Then we can have a conversation about it.
Amit Sharma: But don’t wax poetically in a public setting or testify in Congress about how you love privacy and go back to a billion-dollar portfolio that effectively is inherently driven by the exploitation of personal data. That’s the problem.
Riley Hughes: Yeah, I hear you, but if I push back just a little bit, I’m thinking about I’m proving my age or whatever using a picture of a plastic card and a liveness selfie, or I’m doing it with a digital credential of my, like a digital version of the plastic card or whatever. The same data is going over the same rails, the same opportunity to exploit me or the same opportunity for the relying party to extract that data and then correlate me against other things, other data sources or whatever, is still there, right? So imagine we have a privacy-preserving digital credential. I selectively disclose only my above 18, yes, and, oh, but it turns out I’m using an IP address that they can correlate some other data sets, or oh, it turns out I also shared my name, and they correlated my name and above 18 status with my transaction history, my credit card, and lock the credit card companies are mining and selling all of our data anyway or whatever. Like, is that actually what this is about? How does the digital credential really move the needle on this, like, underlying data economy necessarily?
Riley Hughes: Because a lot of times when I think about it, I just think about it like, look, that’s all happening, but the fact still exists that right now I can’t prove that my legal name is Riley Hughes on the internet, even when I really want to. Because I don’t want to have to go in person to the branch or something like that. That’s sort of what I’m thinking about, but what’s your reaction?
Amit Sharma: No, look, your last point there is part of the response, which is it’s very hard for you to ensure that proof that you are Riley on the internet. And this is the power of verifiable digital credentials, because what are we really asking? If I take myself back to the conversations we were having at the U.S. Treasury Department across all of the federal financial regulators with our international counterparts on international standards for financial crimes compliance and know your customer and the like, we were having that conversation in an analog world before verifiable digital credentials, where underlying attributes associated with your identity can be affirmed with you never, ever exposing that attribute. You can say to a verifier that you are above 18 without having to explicitly disclose the month, day, and year that you were born. So if I take myself back to those conversations, it was we were really asking an institution to verify that you are who you say you are.
Amit Sharma: The application tactically to do it was, let me get all of your information and bring it in, and then I will go do the verification. But the intent was not to go get all that information; it was to verify the information. There was just no way to do it in an analog world. With digitally verifiable credentials, where you can permission it, that’s the case. And the second piece, very quickly, is I am not claiming, therefore, verifiable credentials in this format, in the manner that we’re talking about, therefore solves the exploitation problem broadly, right, vis-a-vis business models. No. If I or you want to permission underlying data to be monetized, have at it. That’s the point. Give the user the ability to do it. Right now I have no choice. My kid had no choice. My kid’s underlying data—he never permissioned his underlying data other than for the purpose of affirming X, Y, Z to a university because he was applying to go there. He didn’t permission them to then take that data and sell it to data brokers so that he can be targeted. That’s the thing we’re trying to change here.
Riley Hughes: Yeah, and lawyers would say, Oh, there was a line on paragraph 87 at the bottom of the privacy policy that said that that was okay and that was a permissioned or whatever. But that’s, as we know, a ridiculous answer to that.
Amit Sharma: It’s a ridiculous answer, and copious amounts of beer will be needed to have the conversation around what consent and informed consent really means. That’s the rabbit hole.
Riley Hughes: So it sounds like what you’re saying, which is actually a really legitimate point, is that you’re not saying we solve this whole exploitation of personal data and monetization of data challenge writ large. What you’re saying is that right now, so many businesses, the only way that they have to verify a user is to try to detect if the user is lying. We’re back to this detection versus proof of authenticity. If I say that I am Riley Hughes and that my social security number is whatever and that my date of birth and address are whatever, the only way that institution has—I shouldn’t say only way, but just like by and large, right?—the old way of doing it is, okay, now Riley’s given us this data. Now we need to detect if he’s lying. Let’s go buy data from over here and buy data from over here and buy data from over here and buy data from this other place to try to correlate, okay, are there enough sources of data that we’ve just bought that correlate these, like, data points together? And that’s how they would verify it.
Riley Hughes: So what you’re saying is what verifiable digital credentials enable is we cut off—like, the goal would be to cut off a source of demand for the data economy and actually give—and I’m sure that these institutions, in fact we have customers and stuff, and so do you, that would affirm this and are showing it with their dollars—that these institutions would rather just get that proof from the user in five seconds of, like, I consent to share the data with you or whatever, and it’s cryptographically shared and it’s trustworthy and whatever, rather than having to do this whole mess of buying data in the background anyway.
Amit Sharma: That’s exactly right. If the average traditional financial services company is spending somewhere between, what was it, two, three bucks, upwards of $30 and seven to 10 days to verify and validate one human, couldn’t I speed-route the legitimate humans because I got the trust and authenticity into accounts that I can monetize that client with a product or service legitimately versus the loss? From the inefficiencies, redundancies, then you add your anti-fraud and financial. crimes compliance side, who are saying, my logic setting is at 90-plus percent. If you can’t prove above that, I’m going to reject you, so that my numbers are met, meaning that from last year I have a 10, 20 percent higher efficacy rate in terms of catching fraudsters, but that did not add any more business to me, right? So the two need to come through, because the through line here is trust and authenticity. That’s the through line. So that’s the shift that we’re trying to say. So it’s not a panacea.
Amit Sharma: It doesn’t solve that full exploitation problem, but it does solve the challenge of the original intent, which is I really am simply just trying to verify and validate that Riley is who he says he is with the right technology, which I believe verifiable digital credentials enable, the application of mDLs enable, is that Riley can tell me that better than anyone else. I don’t have to purchase all this other data. I don’t have to do all these correlative and causative proofs. I don’t have to look at all this other data and then put it together and go, oh man, I’m now making the assessment, and 10 days later I can therefore maybe give Riley an account. I can do that on the spot.
Riley Hughes: Yeah. And I can only do that if the institutions that I rely on let me.
Amit Sharma: Correct.
Riley Hughes: I can only do that if my state government gives me the opportunity to get that proof on my phone or whatever, or I can only do that if my operating system vendor opens this system up for the use cases that matter to me or something, right? And this kind of gets back to the ID Act manifesto, right? The Digital ID Acceleration Manifesto that we put out there, which basically says, look, by trying to protect users from themselves or something like that, right, by locking things down, like for example, in my state of Utah, I have an mDL, but I’m not allowed to use it online because the functionality is not enabled because of— Ostensibly a privacy risk. But the worst privacy risk is the fact that all the time now when I’m interacting with institutions, they just have to, like, buy my data from all these sources and/or ask me to upload a high-resolution photograph of my vendor’s servers to validate me and also train the vendor’s AI model on me or whatever. Okay, come on.
Riley Hughes: If these institutions, you know, I guess the call to action, right, is for jurisdictions, states, federal governments around the world. I know that our podcast has a broad base of listeners, and if you’re in the position of influence here to influence the issuance and deployment of digital IDs, I think even an imperfect digital ID is an order of magnitude better than the status quo. And these digital IDs are digital. Guess what you can do to digital things? Push a software upgrade. Push the next version, right, in three months, but don’t delay deploying now to wait until you have the perfect thing, because what we’ve seen over time is that just that’s not the way that these things get adoption. So anyway, sorry for my rant there.
Amit Sharma: No, you’re actually right. In summary, I would say that, one, the identity community, or at least identity-related technology elements that have been considered, have struggled with the perfect has been constantly the enemy of the good. Even though incremental progress is exactly what we want to see, innovation happens when we deploy those capabilities. We know are incrementally better, and we learn what the holes are. But if we’re going to wait till we have identity proofing in the quantum age before we roll out a digital identity, we’ll never get there. We have to move those pieces forward. And the POCs, proof of concepts, are out there. Minimum viable products are more than just minimally viable. We have capabilities at scale that we’ve been deploying. We need to do more of them so that we can not only prove out efficacy, drive enhanced security, because it’s much better than it is today in analog environments. And thirdly, we learn from them. And as new threat vectors evolve, we can then adapt digital identity in ways to address those.
Amit Sharma: Instead, the incentive is, okay, I know there are bad guys. There will always be bad guys. So therefore, let’s throw money, time, and energy at that versus why don’t we reinforce the good guys? Let’s make sure good guy access, good guy and good gal access is inherently enabled, and that’s where trust and authenticity should be the driver and not just catching the fraudster.
Riley Hughes: Yeah. I guess the takeaway from the podcast is we agree violently about all this stuff.
Amit Sharma: That’s why we’re in partnership.
Riley Hughes: That’s right. That’s right. If I take a step back, we’re getting close here to time, just as an administrative point, anything you wanted to cover?
Amit Sharma: I’ll just add one more thing, and it gets to this sort of very upfront question, and then the dialogue around practical use cases or the technologies there. It’s really about will and… I’ve thought about this a lot, and just 30 seconds on it, which is, if we’re constantly looking at what’s the right business model when we inherently think about user-controlled identity, we’re really talking about what’s the value of privacy. And it’s one of these, I forget what the psychological term is, and you and I have chatted about this, is how do you value or price a good whose inherent value is either unknown or unpriceable until it’s gone, right? And there’ve been a lot of these studies out there. It’s like, what’s the average price you’re going to pay for protecting your privacy? And the average is around four to five dollars a month until you’re hacked, and then you’re willing. A lot of respondents will come back and say, Actually, I’ll pay upwards of 90 to 100 dollars to protect my privacy. That demand signal goes up because my privacy is gone.
Amit Sharma: It has been taken from me and now I’ve been exploited, so I’m going to inherently… So it’s the same as selling insurance, right? Do I really need that insurance? Oh crap, my house just burned. Now I’m going to grab it. So we need to get to a place where we understand that we don’t live in a privacy-laden world right now. We’ve got surveillance and tracking and tracing and data brokers and all that stuff. So now it’s, hey guys, if we value as an inherent good your privacy, then we have to now put identity as an infrastructure component, as a value asset and throw capital at that versus the tools that go after the bad guys that exploit it. We still need to do that, but we need to inherently change that business model. So that’s the sort of existential question that I would just put out there. And as we think about identity as the through line and these technologies, we’ve got to pivot to that space, and I think that’s what this partnership will hopefully showcase.
Riley Hughes: Yeah. Yeah, that’s great. I appreciate that. Amit, this has been an awesome conversation. I want to ask, do you have anything to plug, right? Is there anything that you are working on that you would hope our listeners would check out, or if they want to get in touch and work with IDEMIA, if they want to get in touch with you, where would you point them?
Amit Sharma: Great. I’d certainly point to this partnership because of the enablements that we’ve talked about and the unlocking and interoperability elements that it brings to the table. Secondly, IDEMIA has a whole slew of hardware, on-prem, physical, logical identity access management tooling that’s fully interoperable with the web-based tooling. And we need to start thinking about not only future-proofing from a modernization perspective, but the interconnectivity of accessing physical and logical spaces the same as accessing digital spaces, because identity is the through line there. And then thirdly, yes, I can say with some arrogance that, look, IDEMIA is playing in a lot of spaces as issuer for some of the highly sensitive spaces around defense, law enforcement, homeland and national security globally. We want to learn from folks too and work with more organizations, whether they be identity providers, biometrics providers, issuers, and highly regulated industries, to deploy this technology. So those are the three things. Those are the three plugs.
Amit Sharma: So we’re looking at identity-embedded payments, identity enablement across agentics and know your agent. We’re looking at high assurance biometrically bound credentials that are digital, that can then be the digital equivalent of your hard credential and your passkey to access those elements. And then infrastructure. We launched with Microsoft late last year as an identity partner in their Microsoft Marketplace. Now across the entire Microsoft ecosystem, you can have a single account recovery with an ultra-verified ID powered by some of the capabilities that we have from IDEMIA. So these are the things I’d encourage folks to look at. We’re in a number of different industries, especially highly regulated spaces, and we’d love to talk to anyone that’s looking at some of these solutions.
Riley Hughes: Awesome. Great. Thanks so much, Amit, for joining. This has been awesome, and thank you for listening. Thanks so much for listening. If you enjoyed this content, the best way to signal to us that the content is valuable is to share it with others who will benefit from it. Meanwhile, if your organization is interested in accepting digital IDs, you can find me or Trinsic on LinkedIn or X or on our website at trinsic.id. And if you haven’t already, visit trinsic.id/podcast to subscribe to the Future of Identity newsletter and listen to any of our prior episodes. Thanks so much for listening.

Ben Cejvan
Marketing @ Trinsic
Ben Cejvan leads marketing and content at Trinsic, where he writes about digital identity and the shift toward a global identity acceptance network. He is focused on making the case for why businesses should start accepting digital IDs today.
Newsletter
Subscribe to weekly insights and updates in the digital ID ecosystem.
