March 2026 was an extremely busy month: even just among the meetings I was involved in, standards-related meetings included JTC 1/SC44, SC27, IETF .


ISO/IEC JTC 1

There are many things about ISO that cannot be disclosed, so this is only a broad overview.

SC27 International Meeting (Information security, cybersecurity and privacy protection)

  • a) Plenary: March 16, 2026/17; b) WG meetings: March 9, 2026/13 days
  • Location: Nuremberg, Germany

SC27 is the subcommittee that develops and maintains standards foundational to modern IT, including ISMS, cryptography, Common Criteria, cybersecurity, identity and privacy, and biometric evaluation.

In digital identity, the following work is underway:

  • ISO/IEC 29115 Entity authentication assurance framework is under discussion. It brings together threats and controls relating to human and non-human identities.
  • ISO/IEC 27566-1 Age assurance systems Part 1:Framework was published free of charge.
  • ISO/IEC 29184 Online privacy notices and consent is undergoing systematic review.

These and other items are under consideration. Incidentally, SC 27/WG 5 alone, which handles digital identity, currently has 53 standards and work items.


SC44 International Meeting (Consumer protection—privacy by design for consumer goods and services)

  • Dates: March 4, 2026/5
  • Location: Virtual

SC 44 builds on the already published “ISO/IEC 31700-1 (high-level requirements)” and “ISO/TR 31700-2 (use cases),” and currently has about 4 work items underway for specific fields and other areas. Their contents cannot yet be disclosed, however; perhaps more can be made public in September.


OpenID Foundation

Specification and Standardization Developments

  • 3/16 OpenID Connect Advanced Syntax for Claims (ASC) 1.0 public review opened.
  • 3/22 International Government Assurance (iGov) Profile for OAuth 2.0 Implementer’s Draft voting opened.
  • 3/26 OpenID Connect Relying Party Metadata Choices 1.0 Final Specification approved.

Other

  • 3/11 The AIIM threat-modeling subgroup submitted information to NIST’s RFI on AI agent security.
  • 3/18 TrustID Solutions announced BixeLab, FIDO Alliance, Inc., Fime, and Raidiam as the first OpenID Conformance Testing Providers.BixeLab, FIDO Alliance, Inc., Fime, Raidiam

Open Wallet Foundation

Recent OWF activity has become harder to see because status is no longer public, but the following developments could be observed externally.

EUDIPLO

EUDIPLO is open-source middleware that connects existing business systems and backends with the EUDI Wallet (EU Digital Identity Wallet).

  • 3/23 v4.0.0 released. It includes an /api prefix for the management API, separation of management and protocol OpenAPI definitions, an AWS KMS adapter, persistent session logs, and a unified management model for keys and certificates.

identity-credential / Multipaz

  • 3/19 0.98.0 released, adding translation infrastructure and support for 21 languages.

Credo

  • 3/12 The Migration Guide added “Credo 0.5.x to 0.6.x.” 9/1 through 3 introduced GDC.
  • 3/26 The DIDComm ext repository was transferred to OWF.

IETF 125

  • Dates: 2026-03-14/20
  • Location: Shenzhen, China

This time, SC27 overlapped with another meeting, so I could not attend. There seem to have been many AI-agent proposals. Many were still just ideas, however, and apparently quite a few were rejected with the question, “Are there any other implementations trying to do the same thing?”

The main points from the working groups that interest me appear to be as follows.

  • OAuth WG — Authorization extensions for AI agents increased rapidly. Multi-AI Agent Collaboration、A2A Profile for OAuth Transaction Tokens、Agent Operation Authorization and several other drafts were proposed. OAuth 2.1 continued to be updated through v15.
  • JOSE WG — The focus was migration to post-quantum cryptography (PQC). PQ/T Hybrid Composite Signatures, PQ KEMs, and HPKE integration into JWE were discussed, and JSON Web Proof (JWP) progress was reported. Discussion also continued toward deprecating the “none” algorithm and RSA1_5.
  • WIMSE WG — After 2 years since establishment, the group is moving into the specification-completion phase. HTTP Signatures introduced the WIMSE-Audience header; wimse:// defined the URI scheme; and Workload Identity Practices is undergoing WGLC.
  • WebBotAuth WG — IETF 125 had no session. IETF 124 featured active discussion of the adverse ecosystem effects of mandatory bot authentication—including impediments to anonymous browsing and the risk of favoring large providers—suggesting that the direction should be reconsidered.
  • CFRG — 2 sessions were held. “Two-Lane Publication Model」 proposed reform of the cryptographic standardization process; Longfellow ZK (PQ-safe zero-knowledge proofs) progressed; FHE potential IETF standardization of FHE; and ARKG progress were discussed.

March 2026 Digital Identity Trends and News Summary

March 2026 saw notable progress in legislation and pilot projects across countries, wider adoption of passkeys, and new identity-management challenges accompanying the rise of AI agents. The principal developments are summarized below by field.

1. Progress in National Digital ID Policies and Legislation

  • European Union: Progress on eIDAS 2.0 and the EUDI Wallet
    • Ahead of the December 2026 deadline for full deployment of the EUDI (European Digital Identity) Wallet, interoperability testing among member states was conducted in Romania from March 17 through 18 [1].
    • For financial institutions and fintech firms, EUDI Wallet readiness has moved from “whether it will be introduced” to “whether they are prepared” [1]。
  • United States: Utah passes the nation’s first “Digital Identity Bill of Rights”
    • The Utah Legislature passed a bill concerning state-approved digital ID programs (SB 275), scheduled to take effect on May 6, 2026[2]。
    • This landmark bill requires participating companies to obtain explicit user consent, provide only the minimum necessary attributes through selective disclosure, and limit the purposes of data retention and sharing [2]。
  • Update to the UK’s Digital ID Trust Framework
    • The UK government released a prerelease of version UK digital verification services trust framework of the “1.0” and began a public consultation on the national digital ID scheme [3]。
    • This updated certification criteria for digital verification service (DVS) providers, introduced a new trust mark, and added rules for orchestration service providers [3]。
  • Full Launch of Spain’s MiDNI App
    • Spain announced that “MiDNI the mobile version of its national digital ID, would enter full operation on April 2, 2026[4]。
    • The digital DNI on a smartphone will consequently have the same legal effect as a physical ID and can be used for hotel check-in, age verification, and other purposes [4]。

2. Developments in Japan: My Number and Verifiable Credentials

  • Publication of FSA Pilot Results on Identity Verification Using Verifiable Credentials(VC)
    • The Financial Services Agency published results from a pilot using Verifiable Credentials (verifiable credentials) for identity verification (KYC) by financial institutions [5]。
    • The pilot tested issuing a completed identity-verification result to a user as a VC for reuse at another financial institution, indicating a new direction for identity proofing in a digital society [5]。
    • The Bank of Japan also published a report that month on VC fundamentals and standards-development trends, discussing potential financial applications of tamper-resistant VCs with selective disclosure [6].
  • Expansion of Identity Verification (eKYC) Using the My Number Card
    • LY Corporation introduced identity verification with the My Number Card through the Digital Agency’s Digital Authentication App for Yahoo! JAPAN ID account recovery and other procedures [7].
    • PayPayIdentity verification using the My Number Card’s Japanese Public Key Infrastructure (JPKI) is also spreading rapidly in private services such as [8]。

3. Passkey Adoption and Accelerating Passwordless Authentication

  • MicrosoftAutomatic Passkey Enablement by Microsoft
    • Microsoft began automatically enabling passkey profiles for all Microsoft Entra ID tenants on March 2026 [9]。
    • This forced millions of enterprise users toward passwordless authentication and marked a major tipping point for passkey adoption [9]。
  • RedditUse of Passkeys by Reddit as “Proof of Humanness”
    • Reddit announced a system using passkeys, including biometric authentication such as Face ID and Touch ID, to verify that users are “real humans” as a bot countermeasure [9].
    • This is attracting attention as a new passkey use case that proves human presence without identifying the individual, thereby preserving anonymity [9].

4. Managing AI Agents and Non-Human Identities (NHI)

  • Agentic AI Identity-Management Challenges
    • As Agentic AI—AI that autonomously performs tasks—spreads, identity and access management (IAM) for AI agents has become urgent [10]。
    • Cloud Security Alliance (CSA) research found that many organizations cannot clearly distinguish AI-agent actions from human actions [11].
    • Ping Identity, Saviynt, and other security companies have successively announced new products for managing and monitoring AI-agent identities [12].

5. Age Verification and Privacy Protection

  • Adoption and Challenges of Online Age-Verification Tools
    • As the United States, United Kingdom, and other countries introduce age-verification laws for children’s online safety, use of biometric and AI-based age-estimation technology is expanding [13]。
    • Experts, however, strongly warn that these technologies could violate adults’ privacy and lead to a surveillance society [13]。

References

[1] Zyphe. “eIDAS 2.0 & EU Digital Identity Wallet: KYC Guide 2026”. https://www.zyphe.com/resources/blog/eidas-2-eu-digital-identity-wallet-kyc-compliance-guide

[2] Byte Back. “Utah SB 275’s “Digital Identity Bill of Rights”: What It Could Mean for Businesses”. https://www.bytebacklaw.com/2026/03/utah-sb-275s-digital-identity-bill-of-rights-what-it-could-mean-for-businesses/

[3] Bird & Bird. “UK Digital IDs Early Updates for 2026”. https://www.twobirds.com/en/insights/2026/uk/uk-digital-ids-early-updates-for-2026

[4] Biometric Update. “Spain’s national digital ID going live with full legal status”. https://www.biometricupdate.com/202603/spains-national-digital-id-going-live-with-full-legal-status

[5] VESS Labs. “FSA Publishes Results of Identity-Verification Pilot Using Verifiable Credentials”. https://note.com/vesslabs/n/n0fd0ff625e97

[6] Bank of Japan. “Overview of Verifiable Credentials Supporting Identity Proofing in a Digital Society and Trends in Standards Development”. https://www.boj.or.jp/research/wps_rev/rev_2026/rev26j02.htm

[7] Nikkei. “LY Corporation Uses My Number Card Digital Authentication App for Identity Verification”. https://www.nikkei.com/article/DGXZQOUC108FL0Q6A310C2000000/

[8] PayPay. ““PayPay” Users with Completed Identity Verification (eKYC) Exceed 40 million!”. https://about.paypay.ne.jp/pr/20260318/02/

[9] Security Boulevard. “Passkeys Hit Critical Mass: Microsoft Auto-Enables for Millions, 87% of Companies Deploy as Passwords Near End-of-Life”. https://securityboulevard.com/2026/03/passkeys-hit-critical-mass-microsoft-auto-enables-for-millions-87-of-companies-deploy-as-passwords-near-end-of-life/

[10] Security Boulevard. “Agentic AI Governance: How to Approach It”. https://securityboulevard.com/2026/04/agentic-ai-governance-how-to-approach-it/

[11] Cloud Security Alliance. “More Than Two-Thirds of Organizations Cannot Clearly Distinguish AI Agent from Human Actions”. https://cloudsecurityalliance.org/press-releases/2026/03/24/more-than-two-thirds-of-organizations-cannot-clearly-distinguish-ai-agent-from-human-actions

[12] THINK Digital Partners. “Digital Identity: Global Roundup”. https://www.thinkdigitalpartners.com/news/2026/03/30/digital-identity-global-roundup-261/

[13] CNBC. “Online age-verification tools for child safety are surveilling adults”. https://www.cnbc.com/2026/03/08/social-media-child-safety-internet-ai-surveillance.html

Related posts