
European digital ID wallets lean on Google and Apple safety services
A Waag analysis argues that European digital identity wallets depend on Google Play Integrity and Apple device attestation, tying public infrastructure to private platform policies and breaching the EU Digital Markets Act.
The problem: wallets depend on attestation
European governments are rolling out digital identity wallets that citizens will use to access services and verify their age online. According to an analysis published by the research organisation Waag, the rollout has a serious flaw: the wallets rely on safety services from Google and Apple — the Google Play Integrity API and Apple's Managed Device Attestation. These remote attestation services are meant to ensure that wallet apps run on hardware that has not been tampered with. By embedding them in public infrastructure, Europe risks making society dependent on private companies while serving those companies' interests.
Play Integrity API is free software that Google offers developers to check whether an app runs on a genuine certified Android device. At the same time it checks whether a device runs a Google-licensed version of Android and treats unlicensed alternatives as a potential security risk. Google uses the Play Store as the source of truth, checking both whether the app has been modified and whether it was installed through the store. As a result, the service is designed to exclude operating systems that are not licensed by Google, to encourage installation through the Play Store and to require users to sign in with a Google account — which Waag calls a clear violation of the Digital Markets Act (DMA).
An open alternative exists, and it is being ignored
A more open alternative already exists but is being ignored: Android's Hardware Attestation API, which provides hardware-based security checks without enforcing Google's ecosystem policy.
Wallet developers in the Netherlands and Italy have already implemented Play Integrity. That means users of de-Googled operating systems such as /e/OS and GrapheneOS can be excluded from these services. In effect, governments become enforcers of a private company's platform policies, in tension with Europe's stated ambition to build digital public infrastructure on openness, inclusiveness and technological sovereignty.
Fragmented approach and public accountability
Part of the problem lies in the governance of the wallet design process. The EU provides a general technical framework, the Architecture Reference Framework, which does not require governments to use Google attestation but does recommend it. Italy has interpreted the recommendation as mandatory, while Switzerland relies on Android's attestation mechanism and dropped Play Integrity over data protection, data sovereignty and freedom-of-choice concerns. The Netherlands and Italy use Play Integrity unconditionally.
The authors argue that if Europe is serious about digital autonomy, it should rule out Google and Apple attestation entirely from the Architecture Reference Framework and mandate open, hardware-based attestation mechanisms, since Switzerland shows that alternatives are available. Because wallets are public infrastructure, their design should be subject to public participation and accountability: citizens and developers are raising concerns in national repositories, though those channels reach only a narrow technical audience.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.