A conversation with Neil Garner on why digital identity won’t be solved by picking a single winner
As governments, platforms, and technology providers race to define the future of digital identity, the debate is increasingly framed as a battle of wallets. But according to Neil Garner, this framing misses the point. Wallets are not identity systems in themselves — they are containers for very different kinds of credentials, each with their own trust boundaries, governance models, and expectations around security and usability.

Neil Garner is Chief Strategy Officer at Dot Origin, where he works on large-scale mobile wallet and NFC-based identity infrastructure. He has spent over two decades working across mobile payments, digital wallets, retail systems, and digital identity.
Neil was previously Founder and CEO of Proxama, one of the early pioneers in proximity marketing and mobile wallets, and later Founder and CEO of Things.
Setting the frame
Mobile wallets are often discussed as if they represent a single technological direction of travel: one interface that will eventually hold everything from payment cards and travel tickets to passports and digital identities. In that framing, the future becomes a competition between platforms — Apple versus Google, OS wallets versus government wallets, consumer ecosystems versus sovereign systems.
Garner’s starting point is that this framing is already flawed. Before debating who should “own” the wallet, we first need to understand what a wallet actually is.
What a wallet actually is
The term “wallet” carries a lot of implicit meaning. It suggests ownership, security, and control. But as Garner points out, it is still fundamentally a metaphor borrowed from the physical world.
Neil Garner:
“Ultimately what we’re talking about is taking all the things that used to be in a physical wallet or purse and transposing them into something digital that works on a smartphone. That can include bits of paper, coupons, ID documents, loyalty cards, credit cards — all those things.
The fundamental shift is simply the migration of paper and plastic into software.”
The problem is that digital form creates a false sense of uniformity. When everything appears as a “card” inside a single interface, it becomes easy to assume that everything can be governed in the same way.
In reality, the only thing these items have in common is where they are stored. They do not share the same security requirements, trust models, or legal consequences.
Credentials are not equal
Much of the current confusion around digital identity comes from treating all credentials as variations of the same object. In practice, they serve very different purposes.
Neil Garner:
“A credential is just a piece of information about you or an attribute you’ve got. It might be something like ‘over 21’. That doesn’t necessarily identify you — it just proves a status.
But a government identity document is completely different. That’s used for national security, for travel, and as the root identity that banks and financial services rely on for regulatory checks.
From a government perspective, how that credential is issued, registered, managed, and reissued is absolutely critical.”
This distinction is central. Some credentials exist purely to enable convenience. Others exist to anchor legal identity. The fact that both can now live inside the same app does not collapse that difference.
What changes in digital form is not the nature of the credential, but the visibility of the infrastructure behind it.
Why mixing these worlds causes problems
The practical consequences of this confusion become obvious when identity is compared directly with payments.
Neil Garner:
“In payments, the bank doesn’t really care that it’s you, Steve Atkins, who owns the card. They care that the card works, the funds exist, and the transaction isn’t fraudulent.
But if you’re applying for a mortgage or insurance, they absolutely need to know who you are, where you live, and that nobody is impersonating you. Those are completely different security problems.”
In other words, payments are transactional. Identity is foundational.
Treating them as the same type of problem simply because they share a user interface leads to brittle systems. You end up over-securing low-risk interactions and under-thinking high-risk ones.
This is where many “wallet wars” become conceptually hollow. They focus on who controls the app, rather than on how trust is actually constructed.
On derived identity
One of the most significant developments in this space is the rise of so-called derived identity. These are digital credentials created by examining existing high-assurance documents, rather than being issued directly by a government authority.
Garner points to Apple’s implementation as a useful reference.
Neil Garner:
“What Apple does is get you to scan your passport, read the chip using NFC, verify the cryptographic data, and then use Face ID to check that you’re the person in the photo.
All of that happens behind the scenes. Then you get a digital identity that’s derived from your passport, but signed by Apple’s certificates.”
From a user experience perspective, this is almost ideal. The process is fast, familiar, and embedded in devices people already trust.
From a governance perspective, however, it introduces a quiet but significant shift. Identity is no longer issued directly by the state. It is mediated through a platform.
The result feels official, but the trust chain is no longer purely sovereign.
Who carries the liability?
This shift becomes particularly visible when the question of accountability arises.
If a derived identity is misused, who is responsible? The original issuer? The platform? The relying party?
Neil Garner:
“Apple won’t take liability for how a derived ID is used. Google won’t either. Governments probably wouldn’t want to take liability for misuse of digital IDs either.
What you end up with is a system where the root certificates are trusted, but responsibility for outcomes is very unclear.”
This ambiguity is not accidental. It reflects a deeper reality of digital infrastructure: trust is distributed, but liability is rarely aligned with control.
In practice, this means that identity systems may become widely adopted long before their legal and regulatory foundations are fully settled.
OS wallets versus sovereign wallets
The tension between operating system wallets and government-led wallets is often framed as competition. Garner sees it more as a structural mismatch.
Neil Garner:
“From the phone vendor’s point of view, the goal is to make the phone more useful for more services so the platform becomes more sticky.
From a government point of view, especially in Europe, there’s concern about platform power and data sovereignty. That’s why sovereign wallets exist at all.
But any government wallet still has to run on Apple or Google’s operating systems. It still has to use their APIs, their secure enclaves, their biometric systems.”
In other words, sovereignty in software is constrained by hardware reality. Governments may control issuance, but they do not control the devices in people’s pockets.
This creates an unavoidable dependency: even the most carefully designed sovereign wallet ultimately operates inside someone else’s platform.
Why infrastructure matters more than ideology
Garner’s background in early contactless payments offers a useful historical parallel.
Neil Garner:
“When Apple Pay launched, it completely changed the industry. The old model was that identity and payment credentials lived on SIM cards controlled by network operators. Apple flipped that overnight.
They made onboarding simple, aligned incentives with banks, and suddenly payments scaled globally. Infrastructure followed user behaviour.”
Digital identity today lacks an equivalent moment. Border control has scanners. Airports have biometric gates. But everyday retail environments do not yet have identity-native infrastructure.
Until identity verification becomes as simple as tapping a phone, it will remain a specialist activity rather than a mass behaviour.
The real inflection point
For Garner, the most likely trigger for large-scale adoption is not passports or public services. It is age verification.
Neil Garner:
“Retailers hate checking IDs. It’s slow, inconsistent, and legally risky.
If you can just tap your phone and prove you’re over 21, without giving away any other data, that’s a massive win. It reduces liability, speeds up transactions, and removes fake IDs from the equation.”
This mirrors the trajectory of mobile payments. Adoption did not start with high-stakes financial instruments. It started with coffee and train tickets.
Once behaviour changes at the edges, expectations shift at the centre.
The TQS Takeaway
Digital identity will not be solved by choosing a single wallet.
It will be shaped by how credentials are issued, combined, and governed across different trust domains — and by how infrastructure quietly determines what is usable at scale.
Wallets are just interfaces. The real system lives underneath: in cryptographic roots, platform power, regulatory alignment, and institutional responsibility.
The question for Europe is not whether it can build a sovereign wallet.
The question is whether it can build one that fits into the reality people already live in — rather than the one policymakers wish existed.





Leave a Reply