top of page
Image by LYCS Architecture

Interoperability, Trust, and the Limits of Credentials

17 hours ago
5 min read

- Dr. Charles Wu shares perspectives from GDC26


Flags at Global Digital Collaboration Conference, 2026 - Geneva, Switzerland
Global Digital Collaboration Conference, 2026 - Geneva, Switzerland

This was my first Global Digital Collaboration (GDC) conference, and I went ready to listen.


With a seat among people who've been playing this game far longer than I have, three themes kept surfacing: interoperability, trust, and cross-border recognition.


PKI has been mature for thirty years. So why are these still open questions?


Here's how it looks from where I sit. (There's good news and bad news!)


Within the scope of credentials


The good news first. Inside the scope of credentials, I think most of the ambiguity is removable. It takes three steps, in order.


One: agree on a shared vocabulary for assurance.


What's missing here is a common language.


ISO/IEC 29115 defines four levels of entity authentication assurance, from low to very high, and gives everyone a way to describe how much confidence an identity claim actually earns.


If we can all state the risk level of a use case and the assurance level of a credential in the same terms, the conversation stops being a translation exercise.


I'd suggest ISO 29115 over eIDAS here, for one reason: reach.


eIDAS 2.0 is stronger on legal enforceability, but it's scoped to the EU. ISO 29115 is weaker on enforcement and far broader in adoption, and for cross-border work beyond Europe, reach is the constraint that binds.


Both are solid foundations. Both have real gaps. That debate deserves its own discussion, and I'll leave it there.


Two: decide who produces the assurance report.


A shared vocabulary is worth little if every issuer grades its own homework. Somebody neutral has to assess a given credential against a given use case and publish the result.


GDC strikes me as well positioned for this, because it's one of the few bodies in this space that is neither national nor commercial. It could establish independent auditing bodies for this purpose.


Three: recognise trust roots that share the same risk and assurance level.


This is what interoperability actually looks like in practice. Not one root for everyone. Mutual recognition between roots that have been measured the same way.


That sequence, I think, is tractable. What follows is not.


People at Global Digital Collaboration Conference, 2026 - Geneva, Switzerland

Beyond the scope of credentials


A credential is a proxy. By design, it stands in for a person. And every hard limit I heard discussed last week is a version of the same problem: the proxy and the person can come apart.


There are five ways this happens, and we treat them very differently.


The credential can come apart from the person.


Most credentials aren't bound to biometrics. Whoever holds the credential and its PIN is the person, as far as the system is concerned.


Even FIDO Alliance's biometric matching runs locally on the device, and the binding between that biometric and a real human is established at enrollment. If enrollment is weak, the credential is bound to the wrong person from the very start, and every downstream verification inherits that error.


Verifying a credential without verifying biometrics is like checking a passport without looking at the face in front of you.


It's also the common path, and for good reason. It's the fastest, the most private, and the "best experience". Riding a bus doesn't require a photo ID. Crossing a border does.


What we lack is any agreement on where that stops being true.


The credential can come apart from intent.


Credentials aren't only used to verify identity. They're used to sign. And here the gap widens, because whoever holds your credential can sign on your behalf, and nothing in the transaction confirms it was you who meant to.


This is the core difference between a handwritten signature and a digital one. The handwritten signature carries biometric information about the act of signing. The digital signature carries none.


The credential can come apart from capacity.


This one is rarely raised, and it should be. A credential only works while the holder is conscious, capable, and remembers the password or the seed phrase, and while the instrument itself is intact.


Crypto has a saying for this: not your keys, not your coins.


Possession of the private key is everything. Lose it, and the asset is gone. Hand it over, and you've handed over control.


Health, memory, and hardware are all single points of failure, and no assurance level currently describes any of them.


The credential can come apart from time.


Apply credentials or tokens to real-world asset tokenization and a lifecycle mismatch appears immediately. A thirty-year government bond or a piece of real estate persists for decades. Very likely longer than the device, the key material, the algorithm, or the issuer standing behind the token.


The asset outlives the instrument that proves the claim to it.


The credential can come apart from the human when an AI agent holds it.


A credential is already a proxy for a person. Hand it to an AI agent, and it becomes a proxy for a proxy.


Agents are already booking, filing, and signing for the people who deploy them, and they need credentials to do it. Normally we treat that distance as a bug. Someone other than the owner is holding the credential, and the system can't tell.


But with an agent, the distance is intentional. You give it your credentials so it can act without you.


That makes the problems above harder to solve. Was it really you? Did you intend the action? Were you able to make that decision?


With an agent, a credential alone can't answer these questions, even when everything goes right.


Charles Wu ID card Global Digital Collaboration Conference, 2026 - Geneva, Switzerland

Where the model hands the problem back


There's one more case, and it sits outside the model entirely.


Some rooms still require a wet (paper-based) signature. A courtroom. A hospital. A land registry counter.


A digital signature doesn't work here. It isn't convenient at the moment, and it doesn't prove who was holding the key.


So, people reach for an e-signature instead. But that's difficult to subject to forensic analysis, and it proves nothing about identity either.


I mention it here only because it's where the credential model hands the problem back rather than solving it.


GDC's mission


The real mission, I think, has two halves.


The visible half is unifying countries and breaking down silos. There are two ways to get there. Every country negotiates digital identity treaties bilaterally and multilaterally. Or a global institution like GDC sets standards workable enough that joining becomes the obvious choice, and staying out means your citizens are locked out of the interoperable system everyone else is using.


The less visible half is agreeing where assurance stops. Assurance levels tell us how much to trust a credential. They don't tell us at what point a credential is the wrong instrument, and something else has to carry the weight.


That half is easy to skip, because only the first produces visible progress. Skip it, and we'd interoperate beautifully right up to the point where it matters most.


So I'd argue for the harder half. First, a clearer understanding of where credentials stop. Then, through the same open discussion that got us this far, a framework for what lies beyond that line. Not to replace credentials, but to cover the real-world cases they were never designed to hold.


About SelfieSign


SelfieSign is a dynamic biometric signature platform built for high-stakes agreements. Our patented selfie video signing technology (.SVS) captures face, voice, handwriting, geolocation, IP address, and timestamp at the moment of signing and cryptographically binds it to the document.


Trusted by over 80% of hospitals in Taiwan, processing 3 million documents every month, SelfieSign is fully compliant with eIDAS 2.0 AES, GDPR, and ISO 27001.


Comments


bottom of page