eIDAS 2.0 Compliance for AI Products and Digital Services
eIDAS 2.0 applies to your product if it handles identity verification, electronic signatures, authentication, or trust services. The December 2026 wallet deadline is closer than most teams have planned for.

WHAT IS eIDAS 2.0 AND WHO NEEDS IT
eIDAS 2.0 — Regulation (EU) 2024/1183 — is the EU’s complete overhaul of its digital identity and trust services framework. It entered into force on 20 May 2024, replacing the original 2014 eIDAS regulation with a significantly expanded scope.
Its flagship component is the European Digital Identity Wallet — a government-issued digital identity application that every EU citizen and resident will be able to use to prove their identity, store credentials, and sign documents across the Union. Every EU member state must make a EUDI Wallet available by December 2026. Large online platforms and organisations in regulated sectors must accept it for authentication within one additional year — by late 2027.
For AI and digital product companies, eIDAS 2.0 is not a distant infrastructure project. It is an immediate compliance obligation if your product touches any of the following:
- Identity verification or authentication for EU users
- Electronic signatures — simple, advanced, or qualified
- Trust service provision — certificates, timestamps, registered delivery, electronic seals
- Onboarding or KYC processes relying on identity documents
- B2C platforms serving EU users that fall within the mandatory acceptance category
- AI systems processing identity data or making identity-related decisions
If any of these apply, eIDAS 2.0 reaches your product — and the December 2026 wallet availability deadline is already running.
eIDAS 2.0 Compliance Assessment for Your Product
A lawyer-built assessment of your product’s eIDAS 2.0 obligations — role determination, mandatory wallet acceptance threshold, electronic signature tier, Electronic Attestation of Attributes processing obligations, GDPR and EU AI Act interaction mapping, and a documented compliance record your legal team, enterprise buyers, and supervisory authorities can rely on.
How eIDAS 2.0 works for AI products
Five obligation areas. One regulation. Direct requirements for any product touching digital identity, authentication, or trust services.

eIDAS 2.0 organises its requirements across five core areas. Each creates specific obligations for AI and digital products used to deliver, verify, or rely on electronic identity and trust services.
EUDI Wallet acceptance
Large online platforms and organisations in regulated sectors — banking, telecoms, healthcare — must accept the EUDI Wallet as a valid authentication method for EU users from late 2027. AI products used in these sectors, or operating as platforms at relevant scale, must assess whether they fall within the mandatory acceptance category and plan the technical integration accordingly. The wallet uses W3C Verifiable Credentials — a specific technical standard that must be implemented correctly. An AI onboarding or authentication system that cannot process EUDI Wallet credentials after the mandatory acceptance deadline is non-compliant regardless of how sophisticated its existing identity verification is.
Electronic signature obligations
eIDAS 2.0 extends and strengthens the three-tier signature framework — simple, advanced, and qualified electronic signatures. AI products that generate, process, or validate electronic signatures must satisfy the applicable tier’s requirements. Qualified electronic signatures retain their cross-border legal equivalence to handwritten signatures — but only where the underlying certificate and signing process meet eIDAS 2.0’s technical standards. AI-generated or AI-processed signatures that do not meet the applicable tier requirements have no legal standing in EU proceedings regardless of the technology behind them.
Trust service provider obligations
Qualified Trust Service Providers face updated conformity assessment requirements, new certification obligations, and technical integration with the EUDI Wallet architecture. eIDAS 2.0 introduces two new categories of qualified trust service — electronic registers and electronic archiving — that may bring previously unregulated services within scope. AI products that operate or rely on these services must assess their obligations under both the new and existing categories before assuming their current trust service arrangements remain compliant.
Electronic Attestations of Attributes
eIDAS 2.0 introduces Electronic Attestations of Attributes — verifiable credentials issued by qualified providers confirming specific facts about an individual or organisation, such as professional qualifications, licences, or account status. AI products that issue, verify, or rely on professional credentials, regulatory licences, or identity attributes in automated workflows must assess how EAAs interact with their processing logic and what obligations apply. An AI system making access or eligibility decisions based on EAAs faces both eIDAS 2.0 obligations and GDPR Article 22 automated decision-making questions simultaneously.
Cross-border recognition and enforcement
eIDAS 2.0 strengthens the cross-border enforceability of qualified signatures and trust services — including financial penalties of up to 4% of global turnover for national authorities that wrongly refuse a qualified signature issued in another member state. For AI products operating across EU jurisdictions, this creates both an opportunity and a risk: properly structured electronic signatures have unassailable legal standing across the Union, but improperly structured ones are challengeable in any member state court and expose the organisation to liability for the consequences of invalid signatures in regulated transactions.
Who eIDAS 2.0 applies to
eIDAS 2.0 applies directly to trust service providers and imposes mandatory acceptance obligations on a defined category of relying parties. AI companies whose products interact with identity, authentication, or trust services face obligations through both direct requirements and their clients’ compliance frameworks.
| Entity type | In scope of eIDAS 2.0? | Key obligation |
|---|---|---|
| Large online platform (VLOP) with EU users | Yes — mandatory acceptance | Must accept EUDI Wallet for authentication by late 2027 |
| Bank or financial institution | Yes — mandatory acceptance | Must accept EUDI Wallet for strong customer authentication |
| Healthcare provider with EU patients | Yes — mandatory acceptance | Must accept EUDI Wallet for identity verification |
| Telecom provider with EU subscribers | Yes — mandatory acceptance | Must accept EUDI Wallet for authentication |
| Qualified Trust Service Provider | Yes — re-certification required | Updated conformity assessment, EUDI Wallet integration, new service categories |
| AI KYC or identity verification platform | Yes — directly | Must assess EUDI Wallet compatibility and EAA processing obligations |
| E-signature platform | Yes — directly | Must satisfy updated tier requirements and EUDI Wallet integration |
| AI onboarding or authentication system | Yes — directly | Must assess mandatory acceptance threshold and integration obligations |
| Non-EU company serving EU users in covered categories | Yes — extraterritorial | Same mandatory acceptance obligations as EU-established entities |
| Small platform below mandatory threshold | Likely no — voluntary acceptance encouraged | No mandatory obligation — but document this determination |
| AI product with no identity or signature function | No | Not in scope — but document this determination |
eIDAS 2.0 obligations AI system providers miss
eIDAS 2.0’s Electronic Attestations of Attributes provision is creating the most immediate compliance gaps for AI products — and the one almost no compliance team has mapped against their system.
AI systems that make decisions based on professional credentials, regulatory licences, age verification, or other identity attributes are increasingly processing information that will exist as EAAs in the EUDI Wallet infrastructure. Three things AI product teams consistently misunderstand:
An EAA issued by a qualified provider has legal standing equivalent to the underlying document — a verifiable credential confirming a medical licence is legally equivalent to the paper licence for regulatory purposes. AI systems that process these credentials in automated workflows must handle them with the same legal weight as physical documents, with the same consequences for errors in processing or verification.
The automated processing of EAAs by AI systems raises GDPR Article 22 questions that most identity AI has not addressed. Where an AI system makes a decision based solely on an EAA — access granted, transaction approved, licence verified — without meaningful human review, the automated decision-making obligations apply to the credential processing as much as to the underlying decision. A system that was GDPR-compliant before EAAs existed may not be after they are integrated into its decision flow.
Non-EU AI companies serving EU users face the same EUDI Wallet acceptance obligations as EU-established entities where they fall within the mandatory acceptance categories. A US identity verification platform serving EU banks, or an Indian KYC platform onboarding EU customers, must accept the EUDI Wallet by late 2027 regardless of where it is incorporated — the obligation follows where the service is consumed.
What eIDAS 2.O compliance requires from your AI product
These are the eIDAS 2.0 requirements that apply most directly to AI products handling identity verification, authentication, electronic signatures, and trust services.
Cross-framework mapping — identification of where eIDAS 2.0 obligations interact with EU AI Act high-risk classification for biometric identification AI, GDPR Article 22 automated decision-making obligations for AI processing EAAs, and DORA ICT risk management requirements for AI systems used by financial entities subject to mandatory wallet acceptance.
Role determination — confirmation of whether your product operates as a relying party, a trust service provider, a qualified trust service provider, or a combination across different product functions — the starting point for every subsequent compliance obligation.
Mandatory acceptance threshold assessment — determination of whether your platform falls within the categories required to accept the EUDI Wallet for authentication, from what date the obligation applies, and what the technical integration requires before that deadline.
Electronic signature tier determination — assessment of which signature tier applies to your product’s use case — simple, advanced, or qualified — and whether your current implementation satisfies the applicable tier’s technical and legal requirements under eIDAS 2.0.
EAA processing assessment — assessment of how your AI system interacts with Electronic Attestations of Attributes — whether it issues, verifies, or relies on them — and what obligations that triggers under eIDAS 2.0, GDPR Article 22, and the EU AI Act.
Trust service scope assessment — determination of whether your product’s trust service functions — certificate issuance, timestamping, registered delivery, electronic seals — fall within eIDAS 2.0’s qualified trust service categories and whether re-certification is required.
Technical integration readiness — assessment of whether your current architecture can accommodate EUDI Wallet acceptance and W3C Verifiable Credentials processing before the mandatory deadline, and what the integration gap requires.
Record-keeping and audit trail — assessment of your product’s record-keeping obligations for identity verification, signature creation, and trust service delivery against eIDAS 2.0’s requirements and the intersection with GDPR retention obligations.
Living Compliance File™ — audit-ready compliance record structured by obligation area and product function, formatted so a supervisory authority, notified body, enterprise buyer, or investor’s legal team can open it and find what they need.
One engagement. Every eIDAS 2.0 obligation mapped for your product.
A lawyer-built eIDAS 2.0 assessment covering role determination, mandatory wallet acceptance threshold, electronic signature tier assessment, EAA processing obligations, trust service scope review, technical integration readiness, record-keeping architecture, and cross-framework mapping against your EU AI Act, GDPR, and DORA position where all apply.
Frequently Asked Questions About eIDAS 2.0 Compliance
What is eIDAS 2.0 and how is it different from the original eIDAS?
eIDAS 2.0 — Regulation (EU) 2024/1183 — entered into force on 20 May 2024. It amends rather than replaces the original 2014 eIDAS framework, retaining the three-tier electronic signature structure while adding the European Digital Identity Wallet, two new qualified trust service categories — electronic registers and electronic archiving — and mandatory acceptance obligations for large platforms and regulated sector organisations. The original eIDAS created cross-border legal recognition for qualified signatures. eIDAS 2.0 makes the infrastructure to deliver them available to every EU citizen and requires a defined category of organisations to accept it.
What is the EUDI Wallet and when must organisations accept it?
The European Digital Identity Wallet is a government-issued application allowing EU citizens and residents to store identity credentials, Electronic Attestations of Attributes, and qualified electronic signatures in a standardised format accepted across the Union. Every EU member state must make a EUDI Wallet available to citizens by December 2026. Large online platforms, banks, telecoms providers, and healthcare organisations must accept the wallet for authentication from late 2027 — approximately one year after wallet availability.
Does eIDAS 2.0 apply to non-EU companies?
Yes, where those companies serve EU users and fall within the mandatory acceptance categories. A US identity verification platform serving EU banks, an Indian e-signature provider offering services to EU enterprises, or a UK KYC platform onboarding EU customers faces the same EUDI Wallet acceptance obligations as an EU-established entity in the same category. The regulation follows where your service is consumed, not where your company is incorporated.
What are Electronic Attestations of Attributes and why do they matter for AI?
Electronic Attestations of Attributes are verifiable credentials issued by qualified providers confirming specific facts — professional qualifications, regulatory licences, age, account status. They are stored in the EUDI Wallet and can be presented to relying parties without disclosing unnecessary additional data. AI systems that make decisions based on professional credentials, age verification, or licence status will increasingly encounter EAAs in user authentication and KYC workflows. How AI systems process and act on EAAs creates both GDPR Article 22 automated decision-making questions and EU AI Act high-risk classification considerations where the decisions are consequential.
What is the difference between a simple, advanced, and qualified electronic signature under eIDAS 2.0?
Simple electronic signatures include any electronic data attached to or logically associated with a document — a typed name, a checkbox, a click. Advanced electronic signatures are uniquely linked to the signatory, capable of identifying them, and linked to data in a way that detects subsequent changes. Qualified electronic signatures are advanced signatures created with a qualified electronic signature creation device and based on a qualified certificate — they have the legal equivalent of a handwritten signature in all EU member states. The tier that applies to your use case depends on the legal requirements of the underlying transaction and the jurisdiction in which it has effect.
How does eIDAS 2.0 interact with the EU AI Act?
AI systems used in identity verification, biometric authentication, and access control decisions are subject to EU AI Act obligations — including high-risk classification under Annex III for biometric identification systems — alongside eIDAS 2.0’s trust service and wallet acceptance requirements. A biometric AI system used to verify identity against a EUDI Wallet credential sits under both regimes simultaneously. A cross-framework assessment maps where the obligations overlap and where they impose distinct requirements on the same product.
How does eIDAS 2.0 interact with GDPR for AI systems processing identity data?
Identity data — credentials, attributes, biometric data used for verification — is personal data subject to GDPR. eIDAS 2.0 processing typically relies on legal obligation or legitimate interests as the lawful basis where identity verification is required by regulation. However, GDPR’s data minimisation, retention, and data subject rights obligations still apply — including the right of access and the right to erasure, which interact with eIDAS 2.0’s record-keeping requirements in ways that must be specifically mapped. Where AI systems make automated decisions based on EAA processing, GDPR Article 22 obligations apply alongside eIDAS 2.0’s requirements.
What are the penalties for eIDAS 2.0 non-compliance?
Penalties for non-compliance with eIDAS 2.0 are determined by member states as part of their implementation frameworks. The regulation introduces specific financial penalties — up to 4% of global turnover — for national supervisory authorities that wrongly refuse recognition of qualified signatures or trust services issued in other member states. For organisations failing to accept the EUDI Wallet after the mandatory acceptance deadline, member state enforcement mechanisms apply, with penalty levels varying by jurisdiction.
How do I know if my platform must accept the EUDI Wallet?
Mandatory acceptance applies to very large online platforms within the scope of the Digital Services Act, to organisations in regulated sectors — banking under PSD3, telecoms, healthcare — and to public service providers. The threshold determination is not always straightforward, particularly for AI platforms that straddle sector categories or operate at scale without meeting VLOP designation. The compliance assessment establishes whether mandatory acceptance applies to your specific product and from what date.
How do I start eIDAS 2.0 compliance for my product?
First, determine your role — relying party, trust service provider, qualified trust service provider, or a combination across different product functions.
Second, assess whether your platform falls within the mandatory EUDI Wallet acceptance categories and establish the timeline that applies to you.
Third, map how your product currently handles electronic signatures and trust services against eIDAS 2.0’s updated tier requirements.
Fourth, assess how Electronic Attestations of Attributes interact with your AI system’s decision-making workflows and what GDPR and EU AI Act obligations that triggers. A lawyer-built assessment covers all four steps and delivers a documented compliance position specific to your product — mapped against your EU AI Act, GDPR, and DORA position where all apply.
