Vision 2030: Identity, Trust & the Digital Economy

Why the next digital economy will compete on something more fundamental than AI: trust

By 2030, I believe one of the most important questions facing business leaders will not be how intelligent our technology is.

It will be:

Can we trust the identities, transactions and decisions operating inside our digital economy?

For years, we have treated digital identity primarily as an authentication problem.

That thinking is becoming outdated.

The enterprise of 2030 will contain employees, customers, partners, machines, applications, APIs and autonomous AI systems. Governments are building national digital identity infrastructure. Businesses are moving toward passwordless authentication and verifiable credentials. Regulators are increasingly connecting digital identity with privacy, cybersecurity and cross-border commerce.

The implications are much larger than cybersecurity.

Identity is becoming an economic infrastructure.

And from a CXO perspective, that changes how we should think about investment, governance, risk and growth.

The 2030 Economy Will Be Built on Verifiable Trust

Consider what is already happening.

The European Union is requiring every Member State to provide citizens, residents and businesses with at least one European Digital Identity Wallet by the end of 2026. These wallets are designed to work across public and private services, allowing people to authenticate, store credentials and selectively share verified information.

This is not simply a government technology project.

It represents a different model for digital commerce.

Imagine being able to prove:

  • your age without revealing your date of birth;
  • your qualification without sending a physical certificate;
  • your identity to a bank without repeatedly submitting documents;
  • your right to work or study across borders;
  • your credentials to a business without surrendering unnecessary personal information.

That is digital trust becoming infrastructure.

And the business implications are significant.

The Shift From “Who Are You?” to “What Can You Prove?”

Traditional digital identity often asks:

Who are you?

The next generation increasingly asks:

What can you prove, and how much information actually needs to be disclosed?

This distinction matters.

The EU Digital Identity Wallet framework is explicitly designed around user control and selective disclosure. A person could, for example, prove a particular attribute without necessarily revealing their complete identity.

That creates an important opportunity for business.

Instead of collecting everything and trying to protect everything, organisations can increasingly move toward:Verified information → minimum necessary disclosure → trusted transaction.

That can reduce friction while improving privacy.

For CXOs, this should trigger a different conversation:

Can we redesign customer journeys around verified trust rather than excessive data collection?

Why This Matters to the Digital Economy

Every digital transaction has a trust problem underneath it.

A bank needs to know who is opening an account.

A marketplace needs to know whether a seller is legitimate.

A healthcare provider needs confidence in patient information.

An employer needs to verify qualifications.

A platform needs to distinguish legitimate users from fraudulent ones.

An enterprise needs to know whether an AI agent or machine is authorized to perform an action.

As digital commerce expands, the cost of getting identity wrong also expands.

Poor identity infrastructure can create:

  • Fraud losses
  • Customer abandonment
  • Regulatory exposure
  • Operational friction
  • Reputational damage
  • Slower onboarding
  • Higher authentication costs

Strong identity infrastructure can create the opposite:

  • Faster transactions
  • Lower friction
  • Better fraud prevention
  • More portable credentials
  • Stronger customer confidence
  • Easier cross-border interactions

This is why I see Digital Identity as a business infrastructure question, not simply an IAM question.

AI Changes Everything

If digital identity was becoming strategically important before AI, it becomes significantly more important with AI.

The enterprise of 2030 will not consist only of humans interacting with software.

It will increasingly include software interacting with software.

AI agents may search, negotiate, purchase, schedule, analyse, recommend and execute actions on behalf of organisations and individuals.

That introduces a new question:

How do we establish trust when the actor isn’t human?

This is where AI Governance, Identity Governance and Machine Identity converge.

A future enterprise may need to know:

  • Which AI agent initiated the action?
  • Who authorised it?
  • What data was it allowed to access?
  • What decisions could it make autonomously?
  • What limits were placed on it?
  • Can its actions be traced?
  • Can its permissions be revoked immediately?

These aren’t hypothetical governance questions.

They are design requirements for an increasingly autonomous economy.

The Rise of Non-Human Identity

This is one area I believe executives need to take much more seriously.

Organisations have historically designed identity systems around employees.

That model is becoming insufficient.

The digital enterprise now includes:

Human identities

Employees, customers, contractors and partners.

Machine identities

Servers, workloads, devices and applications.

Service identities

APIs, service accounts and automated processes.

AI identities

Agents and autonomous systems acting on behalf of people or organizations.

The challenge isn’t simply having more identities.

It is having more identities capable of taking action.

That changes the risk equation.

If an employee has excessive access, the risk is significant.

If an autonomous system has excessive access and can operate continuously, the consequences can scale much faster. That is why Non-Human Identity Management should become an executive conversation before 2030; not after the first major failure.

Digital Trust Will Become a Competitive Advantage

I don’t believe trust will remain merely a compliance outcome.

It will increasingly become a differentiator.

Think about two businesses.

Both offer the same digital service.

One requires customers to repeatedly upload documents, enter passwords and complete cumbersome verification.

The other allows customers to present verified credentials quickly, share only what is necessary and complete the transaction securely.

Which business creates more confidence?

Which one converts faster?

Which one has lower operational friction?

Which one is more likely to earn repeat business?

Trust can become part of the customer experience. That is a powerful shift.

The Geopolitics of Digital Identity

By 2030, digital identity will also have a geopolitical dimension.

Different regions are developing different approaches to:

  • Digital sovereignty
  • Privacy
  • Digital credentials
  • Data governance
  • Cybersecurity
  • Cross-border identity
  • Digital public infrastructure

The European model is one example.

The EU’s framework is explicitly designed around interoperability across Member States, common standards and user control over identity data.

For multinational organisations, this creates a strategic challenge.

You cannot assume that one identity model will work everywhere.

Global businesses will increasingly need to understand:

Which identities are trusted?

Under which jurisdiction?

Using which standards?

For which transaction?

With what level of assurance?

Identity strategy could therefore become part of international expansion strategy.

What CXOs Should Start Doing Now

Waiting until 2030 would be a mistake.

The infrastructure is being designed today.

I would start with six priorities.

1. Put Identity on the Strategic Agenda

If identity appears only in the CISO’s technology roadmap, you’re probably looking at it too narrowly.

Connect it to:

  • Customer experience
  • AI strategy
  • Fraud
  • Digital transformation
  • Regulatory strategy
  • Business resilience

2. Map Every Identity That Can Act

Don’t stop with employees.

Identify:

  • Machines
  • Applications
  • APIs
  • Service accounts
  • Vendors
  • AI agents
  • Autonomous workflows

If it can act, it needs governance.

3. Move From Authentication to Continuous Trust

Authentication answers:

“Who are you?”

Modern identity strategy needs to answer:

“Should you still be trusted to do this right now?”

That requires context, risk signals and continuous assessment.

4. Prepare for Verifiable Credentials

Digital credentials are moving from experimentation toward real-world infrastructure.

The EU's large-scale pilots involve more than 550 companies and public authorities across 26 Member States plus Norway, Iceland and Ukraine, testing use cases for the wallet ecosystem.

Businesses should begin asking where verified credentials could simplify:

  • Customer onboarding
  • Employee verification
  • Partner onboarding
  • Professional credentials
  • Age verification
  • Cross-border transactions

5. Design AI With Identity from Day One

Don’t bolt identity controls onto AI after deployment.

Before an AI agent goes into production, ask:

Who owns it?

What can it access?

What can it change?

What decisions can it make?

How is it monitored?

How quickly can its access be revoked?

That is AI Governance in practice.

6. Measure Trust, Not Just Security

Cybersecurity metrics traditionally focus on:

  • Incidents
  • Vulnerabilities
  • Detection time
  • Response time
  • Compliance

Those remain important.

But I believe the next generation of executives should also ask:

How confident are we in the identities operating across our business?

That could eventually become a meaningful executive metric:

Identity Confidence

A measure of how confidently an organisation can establish:

who or what is acting → what it is allowed to do → why it is allowed → whether it should continue.

The Leadership Challenge

The technology is not the hardest part.

The harder challenge is organisational.

Identity touches:

  • Security
  • IT
  • Product
  • Legal
  • Compliance
  • HR
  • Customer experience
  • Finance
  • Procurement
  • AI teams

That means identity cannot be effectively owned by a single department.

It requires executive sponsorship. The leaders who understand this early will have an advantage because they can turn identity from a collection of controls into an enterprise capability.

My Vision for 2030

I don’t believe the digital economy of 2030 will be defined simply by who has the best AI.

AI will become increasingly accessible.

The differentiator will be what organisations can trust AI to do. Similarly, digital identity won’t simply be about logging in.

It will determine whether people, machines and autonomous systems can participate safely in economic activity.

The winning organisations will build ecosystems where identity is:

Portable.

Verifiable.

Privacy-aware.

Continuously governed.

Machine-readable.

Trusted across boundaries.

That is a very different vision from the password-and-permission model we inherited.

The Final Question for Business Leaders

By 2030, I expect many organisations to look back at identity in the same way we now look at cloud infrastructure.

At first, it was treated as an IT capability.

Then it became essential infrastructure.

Eventually, it became impossible to imagine modern business without it.

I believe digital identity is undergoing the same transition.

And the most important question for leaders isn’t:

“Are we ready for digital identity?”

It is:

“What kind of digital economy are we building, and can people, businesses and machines trust each other enough to participate in it?”

Because the next decade will not simply be about making the economy more digital.

It will be about making the digital economy more trustworthy.

And identity may be the infrastructure that makes that possible.

Table of Contents

More Related