eIDAS 2European UnionIdentity

eIDAS 2 and the EU Digital Identity Wallet for KYC

eIDAS 2 and the EU Digital Identity Wallet reshape KYC from late 2026. What the wallet verifies, relying-party rules, and why you still need a fallback.

At least one certified EU Digital Identity Wallet (the EUDI Wallet) must be offered to citizens and residents of every EU Member State by the end of 2026. Iceland, Liechtenstein, and Norway — the EEA countries — receive one extra year. Regulation (EU) 2024/1183, better known as eIDAS 2, set that deadline. It entered into force on 20 May 2024 and rewrote the 2014 eIDAS framework.

Customer onboarding in Europe is not waiting on a distant standards project. By law, an identity presented from a wallet at assurance level "high" equals meeting the customer face to face. Anyone whose work is identity verification will be expected to take it.

Vendors skip this next point. Accepting the wallet is required; it is not enough. A usable wallet will still be missing for most of the people you onboard in 2027. Both halves sit in this guide: what the wallet forces you to do, and what it cannot yet do for you.

Why eIDAS 2 lands directly on KYC

Qualified signatures and trust services arrived with eIDAS 1 (2014). Customer onboarding barely featured. eIDAS 2 does, because a bridge was written into a separate statute.

AMLR — the EU's Anti-Money Laundering Regulation, Regulation (EU) 2024/1624 — names the EUDI Wallet as a valid way to identify and verify a customer during customer due diligence. The wallet is not a polite extra path beside your KYC flow. It is a regulator-endorsed method for the identification step itself. AMLA, the new EU anti-money laundering authority, will start direct supervision later this decade from Frankfurt. Wallet-based identification will sit in the baseline, not at the edge.

Payments, crypto under MiCA, lending, gambling: if you onboard in those regulated EU verticals, eIDAS 2 and AMLR now form one connected duty. Split them and teams rebuild onboarding twice.

What the EUDI Wallet actually lets you verify

Two things sit in the wallet that a business can request:

  • Person Identification Data (PID) — the core identity set (name, date of birth, nationality, a unique identifier) issued and guaranteed by the Member State itself. That is the high-assurance backbone.
  • Electronic Attestations of Attributes (EAA / QEAA) — verifiable claims from trusted parties: a diploma, a bank account, a professional licence, proof of address, an "over 18" flag.

Verification design turns on three properties:

  • Assurance level "high". The wallet sits at the strictest eIDAS assurance tier. For most KYC, a valid PID presentation removes separate document capture and liveness on that user.
  • Selective disclosure. One attribute can be proven — "over 18", "resident in Spain" — without handing over the full document. Age-gating regimes already demand that, and it trims the personal data you store.
  • Cross-border by default. A relying party in Germany must accept a wallet issued in Portugal. One integration covers all 27 Member States, the same passporting logic that makes MiCA attractive.

New to the underlying concepts? Our primer on what KYC is walks through the identification and verification steps the wallet is built to satisfy.

You have to register as a relying party — and you can't over-ask

Wallet credentials are not a free-for-all. A business that wants data from a wallet must register as a relying party with the supervisory body in its Member State and declare, in advance, exactly which attributes it will request and why.

Two results follow:

  • Data minimisation is enforced at the protocol, not left to your conscience. Register to check "age over 18" and you cannot quietly pull the full date of birth. Over-collection is a registration breach, not a grey area.
  • Users can refuse and still transact. The holder controls each disclosure. Your flow must handle a partial or declined presentation without breaking — so a fallback path is mandatory, not optional.

The reality check: the wallet will not replace your KYC stack in 2027

This is the contrarian piece, and the piece that protects your roadmap.

"Wallet-ready KYC" pitches imply you can retire document and biometric verification. You cannot — not for years. Watch how the rollout actually arrives:

  • Member States are launching with limited functionality. Several wallets will ship at the deadline carrying only PID, or PID plus a mobile driving licence, with private-sector attestations arriving later. The full attribute ecosystem does not switch on at once.
  • Citizen adoption starts near zero. A legal right to a wallet is not a population that holds and uses one. Card-based eID schemes needed a decade to reach majority use in the countries that led on them.
  • Non-EU customers have no wallet at all. Travellers, expat applicants, and anyone outside the EU still need document-and-selfie verification. For most cross-border businesses that is a large share of new users.

Hybrid is the right 2027 architecture: take the EUDI Wallet when a customer presents one, then fall back to AI-driven document and biometric verification for everyone else — without making the user notice which path they are on. Teams that bet everything on the wallet will fail to onboard the majority who do not yet have one.

How Joinble fits

Joinble's AI-powered identity platform is built for exactly this split. It sits as the verification and orchestration layer in front of your onboarding:

  • Accept and validate EUDI Wallet presentations as a registered relying party, requesting only the attributes you declared.
  • Fall back automatically to document recognition, certified liveness, and biometric matching when no wallet is present or a presentation is declined.
  • Run sanctions and PEP screening on the resulting verified identity, whichever path produced it.

Joinble's identity agents handle the routing decision — wallet versus document, what to request, when to escalate — rather than hard-coding it into your application. As wallet adoption rises across fintech and other regulated verticals, the same integration moves more traffic onto the wallet path without a rebuild on your side.

How to prepare before the deadline

  • Map which onboarding steps a high-assurance PID presentation would replace, and which (screening, ongoing monitoring) it never will.
  • Decide the minimum attribute set you genuinely need, then register as a relying party for that set — nothing more.
  • Build the fallback path first. It carries most of your volume in 2027 and is the part eIDAS 2 does not solve.
  • Align the wallet work with your AMLR customer due diligence duties so identification is implemented once, not twice.

FAQ

Does eIDAS 2 force my business to accept the EU Digital Identity Wallet?

Member States must provide wallets under eIDAS 2, and very large platforms plus several regulated sectors must accept them. Even where your sector is not strictly required to accept the wallet, the AML Regulation treats it as a valid customer due diligence method, so refusing it leaves you at a competitive and supervisory disadvantage.

When do EU Digital Identity Wallets become available?

By the end of 2026, every EU Member State must make at least one certified EUDI Wallet available to citizens and residents. Iceland, Liechtenstein, and Norway — the EEA countries — have until the end of 2027. Functionality expands after launch; it does not arrive complete.

Can the EUDI Wallet replace document and biometric verification?

For EU users who hold a wallet and present a high-assurance PID, it can replace document capture and liveness for that identification step. Non-EU customers, users without a wallet, and declined presentations sit outside that coverage — which is why a document and biometric fallback stays necessary well beyond 2027.

What is a relying party under eIDAS 2?

Any business that requests and relies on data from a user's wallet is a relying party. Registration with your Member State's supervisory body is required, along with an advance declaration of which attributes you will request. Data minimisation is enforced by the framework, so attributes beyond your registered purpose cannot be collected.

How does eIDAS 2 relate to the EU AML Regulation?

The AML Regulation (Regulation (EU) 2024/1624) names the EUDI Wallet as a valid means of identifying and verifying customers during due diligence. eIDAS 2 creates the wallet; AMLR makes wallet-based identification a recognised way to meet your KYC duty. Plan the two together.

Automate your compliance with AI Agents

Joinble's Agentic Identity platform reduces manual KYC reviews by up to 80%. Book a demo to see it in action.

Book a demo