UK, Switzerland Want Digital IDs. What Could Possibly Go Wrong? | Yana Afanasieva

Yana Afanasieva discusses proposed digital-identification systems in the UK and Switzerland.

Watch this video on YouTube

What if the first 80% of users flocking to a new digital ID system are hackers and fraudsters? Is this technology the dawn of a dystopian future, or are the risks just overhyped? In this episode,...

Summary

Yana Afanasieva contends that digital ID rollouts demand nuanced scrutiny beyond binary optimism or alarmism. Drawing on her Big Tech compliance experience, she argues that storing IDs on phones does not guarantee safety: device ecosystems, app stores, and user behavior create multiple attack surfaces. Afanasieva stresses legal design is as important as technology, proposing digital IDs be treated as public‑service contracts with clear operator liability and quantifiable property‑style remedies rather than abstract rights alone. She warns against linking IDs to continuous access to sensitive domains—notably banking and health—advocating strict legal and technical firewalls to prevent large‑scale fraud and state abuse. Early adoption phases, she predicts, will attract fraudsters probing vulnerabilities, mirroring fintech launches. While technical flaws can be patched, she sees government overreach during emergencies as the greater risk. Responsible deployment therefore requires robust statutory limits, mandatory safeguards for validators, and careful delineation of permissible uses.

Article

## Introduction The rush to digitize identity is no longer speculative: national projects are rolling out across Europe and beyond, promising convenience, streamlined services, and an end to paper-based bureaucracy. Yet the conversation around digital IDs in recent debates has been painfully binary—either utopian convenience or Orwellian surveillance. The exchange captured in this conversation offers a more useful middle path. It insists we stop asking whether digital IDs are categorically good or bad, and start asking how they will be designed, governed, and limited. If policy-makers get those details wrong, the consequences will be technical, social, and legal—not hypothetical. If they get them right, digital IDs could deliver public value without turning the phone in your pocket into the single point of catastrophic failure for your financial and medical life. ## Building a Legal Framework for Digital IDs A digital identity system without a comprehensive legal framework is not merely incomplete; it is dangerous. The discussion foregrounds a key reorientation: treat a digital ID not as a sovereign property object like a passport (which passports legally are in many jurisdictions), but as a public service with clearly articulated operator obligations and liability rules. That reframing demands several components. First, a service agreement must exist before deployment. Citizens should be able to review, challenge, and litigate the obligations and liabilities of the issuing authority—what happens when data are lost, when the system is unavailable, or when a faulty verification incorrectly denies access. In practice, that means statutes or administrative rules that spell out uptime guarantees, incident response timelines, and compensation regimes for harm. Absent these, the default legal posture tends to place responsibility on users—their consent, their devices, their behavior—rather than on the institution that designed and controls the system. Second, “data as property” language needs careful application. Declaring that an individual owns their identity attributes creates the intuitive appeal of control, but ownership alone does not solve problems of access, portability, or misuse. More useful is a bundle-of-rights approach: rights to access, correct, port, and revoke consent; statutory limits on secondary uses; and clear rules on when erasure or revocation is required. This bundle should be enforceable against both public and private actors who act as validators, verifiers, or service integrators. Third, the governance architecture must include strict onboarding rules for third-party validators and verifiers. The conversation highlights the multiplicity of participants—operating systems, app stores, device manufacturers, and non-governmental service providers—that can affect security. Licensing, auditing, and transparency obligations for these intermediaries should be statutory. They must be subject to independent security reviews and public reporting on breaches and remedial actions. Finally, the law should establish technical and procedural firewalls around especially sensitive domains. Financial and medical data carry disproportionate harms from misuse. Legislators should consider categorical prohibitions (or at least very high barriers) to using digital ID credentials for routine, continuous access to bank accounts or health records. Instead, the law should make clear that identity verification is a one-time—or tightly constrained—operation for onboarding, after which control passes to the receiving service’s own authentication regime. ## The Core Fears: Mass Fraud vs. Government Control Two distinct dangers dominate public anxiety: mass fraud facilitated by digitization, and governmental overreach enabled by centralized credentialing and communication channels. The conversation dissects both fears and shows why they cannot be collapsed into one another. The fraud worry stems from a simple arithmetic: digital systems scale. Where physical fraud requires possession and often a high threshold of effort, digital fraud can be automated, replicated, and parallelized. If identity credentials are re-usable across services, attackers who breach or co-opt a credential can impersonate a person at dozens of institutions before detection. The problem is compounded by human behavior: consent screens, convenience features like “remember me,” and password reuse all make ordinary users vulnerable. The policy response centers on technical limits to reuse, strict authentication lifecycles, and legal liability for service operators that fail to build robust protections. The government-control worry is different in kind. Once citizens install an official identity app on their phones, that app can become a direct channel for official communications and updates. Mandatory software updates, push notifications, and the ability to change app functionality remotely mean that control over the app can translate into control over what citizens can access and when. This is not an abstract vulnerability: it opens the possibility of selective denial of services, targeted information campaigns, or worse—coercive restrictions tied to political nonconformity. The proper legal remedy is not merely technical obfuscation, but institutional constraints: strict rules about what the state may and may not do with the ID, independent oversight, emergency-use exception criteria, and strong judicial review. Importantly, policy design must avoid pitting these fears against one another. Measures to prevent fraud—such as centralized logging and more intrusive monitoring—can exacerbate the risk of state surveillance. Conversely, excessive decentralization intended to thwart state misuse can create gaps attackers will exploit. The challenge is to combine strong, auditable constraints on state-side functionality with technical designs that limit broad data aggregation by third parties. ## Why Hackers Will Be the First Users One of the most provocative but empirically grounded claims in the discussion is that new financial or identity services attract disproportionate usage from bad actors in their early life. Experience from digital financial products suggests that when a new onboarding loop or credential system launches, many early users are those who have been excluded or banned from existing services. They exploit fresh loopholes before fraud-prevention controls harden. Applied to national digital IDs, that dynamic implies a high initial concentration of fraudulent registrations, credential co-option, and stress-testing by malicious actors. This reality matters for two reasons. First, early adoption patterns drive public perception and political contestation. If rollouts experience an early wave of high-profile fraud incidents, the social license for the project can evaporate quickly—even if later controls would have mitigated most harm. Second, attackers behave as rational opportunists: they continuously probe new systems for weaknesses and share intelligence rapidly. Without robust “red team” testing, bounty programs, and staged rollouts that restrict high-risk functionalities, the system will be weaponized before safeguards are complete. The conversation recommends anticipating this behavior with three practical measures. Stage deployments by sector and function: begin with low-risk uses (e.g., age verification for entertainment) before enabling access to higher-stakes services. Mandate bug-bounty and independent adversarial testing with mandatory remedial timelines. And impose legal exposure on the issuer: if the operator is liable for damages from breaches of the ID system, it creates a market incentive to invest in security and to resist aggressive expansion into high-risk realms until the system is demonstrably resilient. ## Conclusion Digital identity is not a singular technological choice but a suite of policy decisions about who controls identity, how much of i

Transcript

UK, Switzerland Want Digital IDs. What Could Possibly Go Wrong? What if the first 80% of users flocking to a new digital ID system are hackers and fraudsters? Is this technology the dawn of a dystopian future, or are the risks just overhyped? In this episode, I’m talking to Yana Afanasieva, an expert in financial regulation, FinTech and data privacy. Yana led regional compliance teams at Amazon and PayPal in Europe, where she gained extensive experience and inside knowledge of Big Tech. Today we want to discuss Digital IDs, not least because the UK has rolled out a project and the Swiss also just voted for a digital ID to become a reality. We explore why the current debate is far too simplistic and what's really at stake. Yana draws on her Big Tech experience to explain why our data is never truly safe, even when stored on our own phones. We discuss the critical need for a new legal framework that treats our data as property and argue for strict firewalls around our financial and medical information. Links: Yana's Linkedin: https://www. linkedin.com/in/yanaafanasieva/ Yana's X (Twitter) profile: https://x.com/YanaAfanasieva. Neutrality Studies substack: https://pascallottaz.substack.com Goods Store: https://neutralitystudies-shop. fourthwall.com Timestamps: 00:00:00 Introduction 00:01:51 Why the Digital ID Debate is Too Binary 00:06:56 Building a Legal Framework for Digital IDs 00:11:53 The Risk of Linking IDs to Finance & Health 00:21:45 The Core Fears: Mass Fraud vs. Government Control 00:28:59 A Lesson from Switzerland's Failed E-Voting 00:35:52 Why Hackers Will Be the First Users 00:36:50 What's More Worrying: The Tech or the Government? 00:44:55 Conclusion #Yana Afanasieva If we go back to the example of financial services, the moment you launch a new app, a new credit card service, whatever—a new wallet—about 90% of your first users will be fraudsters, because they’ ve been banned from previous services. They have nowhere else to go. They see an announcement that a new startup is launching a card, a wallet, whatever, and they all rush in to see how they can take advantage of it before all the loopholes are fixed. So we can fully expect the same behavior with the digital ID—the first 80% of the users will be hackers. #Pascal Hello, everybody. This is Pascal Lottaz from Neutrality Studies, and today I'm talking to Yana Afanasieva, an expert in financial regulation, fintech, and data privacy. Yana led regional compliance teams at Amazon and PayPal in Europe, where she gained extensive experience and inside knowledge of big tech. Today, we want to discuss digital IDs—not least because the UAE has rolled out a project, and the Swiss, too, just voted in favor of digital IDs. Is this the beginning of a dystopian future, or are the risks just overhyped? Let's discuss. Yana, welcome to the channel. -- 1 of 12 -- #Yana Afanasieva Thank you for having me. So, yes, I think it’s obvious that digital IDs are coming, and they’re here to stay. And I feel like, as with many projects and initiatives, the devil is in the details. So I wanted first to outline what’s normally being proposed in Switzerland, in the EU, and also in the UK. #Pascal Just very quickly, I want to say that you wrote to me about this and said, “Look, there’s a problem with the discussion—it’s a little too binary. Either it’s super bad, or it’s going to be fantastic and make everything easier.” And there’s more nuance to it. So that’s where you’d want to bring in what you’ve been working on over the past couple of years in big tech, right? #Yana Afanasieva Yes. So there’s a camp of people saying, “We have to stop it. We have to protest against it. It’s going to be terrible because we’ll all be surveilled, and it’ll be this Orwellian, dystopian future.” And then there are people saying, “This is convenient. This is the future. We want to get rid of paper. It’s going to be great—the data will be stored on your phone, so everything’s fine, nothing to worry about.” And, as always, both extremes don’t give us the full picture, so to speak. So maybe let’s start with the notion that if it’s stored on your phone, it’s therefore safe. So I think we have to understand that what they’re actually saying is that if the data are stored on our phone, then the security of our data basically equals the security of our phone. And we know that, first of all, a lot of people are a bit careless about how they choose passwords and how careful they are in protecting their phones. Secondly, there are operating systems, device manufacturers, and other apps on our phones. The app itself is going to be downloaded from Google Play or the App Store. So there are many, I would say, intermediaries and participants who can affect how secure our data really are. That’s the first thing to keep in mind. Yes, it’s true that, let’s say, if I’m going to a nightclub or identifying myself somewhere else, this exchange—this script—is not necessarily going to some kind of central database where it’s being recorded. It’s just between the service and my phone, which is great, but that’s not the whole story, so to speak. And to add to this conversation, even 12 years ago, or however long it’s been since Ed Snowden revealed the surveillance situation, it was already possible to monitor phone information back then. I think the capabilities have become more sophisticated, not less, since that time. So this is the first, I would say, notion that we have to understand and keep in mind. Another important aspect here is that we’re being told we, as people, will be able to decide what information is shared with the services because we’re informed that the government is the issuer of this digital ID solution. However, there would be validators, verifiers, and services that are non-governmental, which would be interacting with us. And based on many privacy laws, we have to understand that -- 2 of 12 -- privacy is all about consent. If you agree to share your data, the recipient of your data is kind of safe because you agreed to share certain data with them. However, I don't think I need to remind people that we’re being asked to agree to so many cookies, so many pop-up screens, so many emails asking us, “Please agree that you consent to this privacy policy, this data sharing.” We don’t read it. Even I, as someone who tries to be careful, don’t always read it. So the fact that we may agree to something without fully understanding the consequences is very likely. And then, technically speaking, from a legal perspective, the blame is on us as users—the responsibility. Are we really giving our informed consent to what’s going to happen? I would question that assumption, so to speak. #Pascal Yeah. So what do we make of that? Just for a bit of political context—in Switzerland, we had a digital ID proposal by the government a few years ago, maybe three or four. That one was structured around the digital ID being developed by third parties—the technology—and then the distribution. It was resoundingly rejected at the ballot box. Now the government came back and said, “Hi, guys, okay, we learned our lesson. We’re not going to outsource this. The government’s going to do it, the government’s going to run it, and the government’s going to be responsible for the implementation. So, do you want it?” And this time, 50.4% said, “Yeah, okay, sure, let’s go for it.” Because at the end of the day, the idea behind a digital ID is to have an online version of, you know, a driver’s license—or like in Japan, my little ID, right? If I want to enter a club where I need to show that I’m over 18, I show the ID. The guy looks at my picture, realizes, okay, this is you. He checks my birth date and then decides, okay, you’re legal to enter, or I can sell you a cigarette, right? You have the right to purchase this according to the laws of the land. Now, we want the same thing in the digital realm, but we’d really hate it if that were then used to regulate people’s access to services, right? And in the email you wrote me, you made this very important point about how we need to differentiate between legitimate uses of this technology and illegitimate uses, rather than just saying “technology, yes or no.” #Yana Afanasieva Yes. So actually, this is a very interesting point. I specifically checked because I’m a national of Luxembourg, and before that, I was a national of Russia. If you open your passport, somewhere it says, “This passport is the property of this state.” Yeah. So the passport is not your property; it’s the property of the state. And in the context of digital IDs, I don’t believe that’s the right concept to use, because a better, in my opinion, framework to understand how a digital ID could operate would be the notion of a public service. In that case, we would give certain data to the operator—to the state— and they would have to promise us that they’re going to keep it safe. -- 3 of 12 -- And if something goes wrong—say, a hacking attack or some other interruption in the service that causes damage, risks, or any kind of quantifiable negative impact to us—the service operator should be liable. If we come from that perspective, I believe we could eliminate, or at least address, many potential risks or consequences for users. We’d place the responsibility on the service operator, which I assume would be a governmental agency, to keep our data safe, not share it excessively, and also introduce certain warnings or safeguards about who can become a validator or verifier, how the app will run, and what the responsibilities are for the various providers integrated into the service. So, essentially, if we can sue the service operator for damages they cause us, chances are they’ll be more responsible. That’s the first notion I think is important to understand. Currently, it’s not being addressed at all. There isn’t even a draft service agreement you could read and understand. How reliable is the service? What happens if it’s not available? When can they deny you access to it? And what happens if access is denied? How quickly do they need to respond and fix the issue? What happens if the data are wrong, and so on? It's not possible right now to review the service agreement to assess how protected our data or our rights really are. So that's the first concept I think needs to be publicly discussed before the services go live. Secondly, I have a particular concern about these digital IDs being used as credentials to access services—financial services and medical information. The idea, which is publicly advertised, is that you’ll be able to use these credentials to access financial services, open bank accounts, and contract insurance. You can find that in all the materials shared about the Swiss ID project, as well as the European and UK initiatives. So it sounds good, but I do feel that because there are so many risks that can arise if your access to your financial or medical information is compromised—if somebody hacks your data, even if you’ve been reckless—still, we should, at least in the beginning, prohibit these credentials from being used by service providers or even by individuals to access medical and financial information. The consequences are really critical and hard to assess at this point. So that’s where I would place my concerns, and that’s where I would put the safeguards. #Pascal Yeah, but those safeguards are actually legislative safeguards, right? Like, you’d say, okay, for certain things this ID is not allowed to be used, because access to these services must not be linked to the ID system. Otherwise, you’d have to share data back and forth constantly. If we take the example of how things work now—if you want to open a bank account in most countries, at the moment of opening the account you need to prove your identity. That’s when you prove to the bank that you are who you claim to be. And once that’s done, they never look at that data again. They might be required to sh