← News
Policy

Ministers scrapped compulsory digital ID in January. The infrastructure kept growing

January: ministers retreated from compulsory digital ID. September: the statutory verification framework came into force, the GOV.UK Wallet opened to certified providers, and phone age checks were announced. The infrastructure kept expanding anyway.

Vicky Richter · 11 September 2026

Ministers scrapped compulsory digital ID in January. The infrastructure kept growing

A statutory framework for digital verification came into force on Wednesday. The GOV.UK Wallet opened its testing sandbox to certified providers. A consultation on letting AI handle your data closed on Monday. Phone age checks were announced this week. For the individual, none of it is compulsory. Yet.

The first week of September was a busy one in Whitehall, though you would not know it from the news. On Wednesday 2 September the government's statutory framework for digital verification came into force. On 1 September it opened the GOV.UK Wallet testing sandbox to certified identity firms. On Monday night a consultation on letting third parties, including autonomous AI, handle your personal data closed, after ministers put the deadline back in late August. This week came the announcement of age checks for phones and tablets sold in Britain. In three weeks new rules governing digital right to work and right to rent checks take effect. Ministers insist digital ID is voluntary. The scaffolding says otherwise.

A framework in force

What changed on 2 September is the legal skeleton. The Data (Use and Access) Act 2025 creates the statutory regime under which the Office for Digital Identities and Attributes (OfDIA) maintains a trust framework and certifies private companies to prove who you are, how old you are and what you are entitled to. Certification is carried out by independent conformity assessment bodies, and the 1.0 framework came into force on 2 September, the moment the first of those bodies was accredited to certify against it.

Certified and registered providers now qualify for UK CertifID, the government's trust mark, each carrying a unique identifying number that links it to the provider's entry on the public register of digital verification services. The components were already in place: One Login, the GOV.UK Wallet, the digital driving licence, with the checking work increasingly carried out by certified firms.

The guidance updated at the start of the month sets out what those firms will be allowed to do with government data. A provider certified as an identity or attribute service can use the information in the wallet to help someone prove something about themselves digitally. One certified as a holder service can go further: it can take information from the wallet and create a new reusable identity document, known as a derived credential. The government's own description is that it could prove specific things, such as age, or carry a range of identity or eligibility information. The wallet currently holds the armed forces veteran card, with the digital driving licence to follow, and users choose whether to share a document with a provider.

In practical terms, a certified private provider could create a derived credential from information shared through the GOV.UK Wallet, proving attributes such as age or eligibility without relying on the original document. Government-backed identity attributes would come to be held and issued by certified private firms. That is the shape of the thing: the state supplies the attributes, the private sector presents them.

The first date with teeth

The first date that binds is 1 October. Under a statutory instrument laid in June, any employer carrying out a right to work check, or landlord in England carrying out a right to rent check, through a digital service must use a provider certified against the trust framework and listed on the register, or lose the statutory excuse the check would otherwise provide. The obligation falls on the employer or landlord who chooses the digital route; nobody is required to prove anything about themselves by app. The same changes allow recently expired passports to be used where the chip can be read, and let employers re-verify a worker's right to work over time.

The framework was never written for employment checks alone. The same legal changes brought the rules for Disclosure and Barring Service identity checks into force, and the Treasury and the Department for Science, Innovation and Technology have told firms they may rely on certified providers for anti-money-laundering checks. A verified identity is designed to be reused, across sectors, again and again.

Claire Bullivant, founder of Great British PAC, says that is precisely why the parts need to be looked at together.

"What concerns me is the direction of travel. We now have a statutory verification framework, certified private providers, an expanding government wallet and further proposals for age and identity checks. Each individual measure may be presented as voluntary or reasonable, but Parliament and the public need to look at the architecture being created as a whole."

The phone in your pocket

The bigger fight is the one ministers opened this week. Lisa Nandy, the Digital, Culture, Media and Sport Secretary, announced legislation requiring tech companies and app developers to introduce age-assurance measures on phones, tablets and platforms, with what the government calls "highly effective age assurance", such as a credit card or a government ID, acceptable as proof. The stated purpose is to make it impossible for anyone under 18 to take, view or send nude images. The Prime Minister, Andy Burnham, said it would be "for the companies to prove a user is an adult, not for a child to keep themselves out of harm's way", and promised the strongest child safety laws of any country. Details have not been published, including how the checks would work on end-to-end encrypted messaging, where the government says it is exploring "a number of potential solutions". Apple has already begun rolling out age checks to iPhone and iPad users in the UK, and a separate social media ban for under-16s is due to take effect in spring 2027.

The strongest privacy objections are coming from outside government. Big Brother Watch argues that a requirement to prove adulthood at device level amounts to population-wide ID: unless adults submit to identity checks when setting up a phone or computer, they face a chokehold on their software and internet access, "leaving you with a child-locked device". Silkie Carlo, its director, said: "The Government mandating that all phones in Britain require ID and surveillance software is a crossing of the Rubicon that would make the UK one of the most authoritarian internet regimes in the world." James Baker of the Open Rights Group warns that millions of adults could face "either compromising their privacy or having a phone they paid for restricted by blocking software".

Those are campaigners' readings of where the proposal leads, not the government's description of it. The government has not yet said what happens to a device when an adult declines the check.

Bullivant argues that the default for ordinary lawful life should be no identity check at all. "Britain is a free country. People should not have to identify themselves to the state, or to a state-approved system, simply to go about ordinary lawful life. Any expansion of digital verification must be transparent, genuinely voluntary and subject to proper democratic scrutiny, with strong safeguards for privacy and civil liberties."

The consultation you never heard of

And then there is the consultation that closed on Monday night, having attracted little attention beyond the industry that stands to benefit. Empowering People Through Data Intermediaries, published in June by the Department for Science, Innovation and Technology, asks how third parties should be allowed to exercise your data rights on your behalf: data wallets, personal data stores, data unions. It is a consultation, not settled policy. But its own language is striking. It envisages AI-enabled services managing access to a person's data in line with that person's specified consent, and says that as the technologies develop, "data intermediaries could be enabled to act more autonomously on an individual's behalf through Agentic AI, managing permissions and data access within agreed boundaries". The examples run across the economy: health records, shopping habits, workplace data.

An information gateway already sits in the legislation. Section 45 of the Data (Use and Access) Act allows a public authority to disclose information about you to a registered provider, where you have asked that provider for its service; the power overrides obligations of confidence, though not the data protection legislation or the Investigatory Powers Act, and OfDIA is drafting the code of practice that will govern its use. The consultation is concerned with how intermediaries act on behalf of individuals. It does not rewrite the separate statutory powers under which public authorities may already obtain or disclose data. The new regime sits alongside those powers, not in their place.

The European backdrop

The European side of the story is a separate system, worth holding up as comparison rather than part of the same architecture. On 31 August the European Commission designated OpenAI's ChatGPT as a very large online search engine under the Digital Services Act, the first chatbot to fall under the EU's strictest platform rules, with until January 2027 to show how it will manage systemic risks, including the spread of illegal content. Under the DSA, illegal content means anything that breaches EU law, or the law of any single member state. Privacy campaigners have long argued that a definition that wide pushes platforms towards the strictest common denominator, because it is cheaper to filter everyone than to filter one market. That is an argument about how the regulation will operate, not a legal link to anything in Britain.

The two systems are separate, but they point to the same wider argument about the future of the internet: who may use it, what they may see, and how much those who run the networks should know about the person behind the screen.

What happened in January

In November the government announced plans for a national digital ID, held on phones, with digital ID to be mandatory as the means of proving right to work by the end of the Parliament. The word "mandatory" lasted two months. On 13 January the government dropped the compulsory element, confirming that workers could prove their right to work by other means. After the change of prime minister in July, the incoming government announced that the national scheme would not continue. None of that stopped the framework coming into force last week.

Richard Thomson, National Director of Great British PAC, argues that the distinction between abandoning the compulsory scheme and continuing to expand the infrastructure is precisely the point.

"This is precisely how mission creep works. The government may say compulsory digital ID has been abandoned, but it is quietly building the legal and technological infrastructure that makes digital identification increasingly unavoidable." He adds: "This is also how Westminster seems to operate: when public opinion is against something, it is officially scrapped, but in the background the machinery continues to be built."

Nothing this week contradicted those reversals in so many words. For the individual, the framework is voluntary. The wallet is voluntary. The consultation is built on consent, and the trust framework itself states that it does not set out the design for a centralised or mandatory national digital identity system.

Bullivant makes the same point about the gap between the words and the work.

"The Government can scrap the words ‘mandatory digital ID’, but that means very little if it quietly builds an infrastructure that could make proving who we are digitally increasingly difficult to avoid."

She adds:

"The British people were very clear that they did not want compulsory digital ID, and ministers should respect both the letter and the spirit of that rejection. Digital technology can make life easier and help tackle fraud, but convenience must never become coercion by the back door."

Bullivant says the January reversal should not end the debate.

"We stopped compulsory digital ID once. We must make sure it is not reconstructed piece by piece under another name."

What has changed is everything around the edges. The statutory framework is in force. Providers are being certified against it, with a trust mark and a public register to tell them apart. Certified firms can build derived credentials from the wallet. From 1 October, employers using digital right to work checks, and landlords in England using digital right to rent checks, must rely on certified firms or lose their legal protection. Age checks are promised for phones and tablets. And the consultation on AI handling your data has closed.

The word "mandatory" was dropped. The infrastructure kept expanding anyway.

Graphics and AI-generated illustrations created by Great British PAC. Created for editorial and illustrative purposes.

More news