When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Design decisions in the EU Digital ID (EUDI) wallet have drawn criticism for relying on hardware attestation, locking users into closed ecosystems.

Paul Hill

Neowin
·

Aug 3, 2026 03:36 EDT

EU flags
Image via Pexels

Collaborators working on the EU Digital Identity Wallet (EUDI) app have confirmed that hardware-bound attestation is a mandatory project requirement, creating concern for people who run custom ROMs as the wallet may not support their devices properly.

The supposed requirement was mentioned by @manecke on a GitHub issue on the project’s repository. He stated that “Hardware-bound attestation is a requirement of this project, not an implementation detail we can simply drop.” To help explain this position in more depth, @manecke said that a dedicated security review and threat model addressing the hardware attestation trade-off will soon be published.

The worry from the community is that this requirement will push people towards using stock Android installs, rather than privacy-friendly alternatives like GrapheneOS that support hardware attestation, but fail proprietary validation like Google Play Integrity. This is ironic as it comes at a time when the European Union is trying to enforce more digital sovereignty now that relations with the US are more strained.

User @ddpasa noted, “This makes no sense. Your interpretation of the requirements is forcing EU citizens to be customers of American companies. There is no trade-off here, just terrible engineering.”

Community members in the issues thread also highlighted contradictions in the project’s documentation, saying that they say hardware capabilities are only needed “when they are available.” The docs also say that the project should promote “seamless integration across diverse device operating systems,” yet, the actual implementation is doing the opposite.

National variants of the EUDI wallet are expected to be launched by the end of this year or early next year. We will then see the public and private sector start to support it later in 2027. Hopefully, the impending security review will give some much-needed clarity on hardware attestation, otherwise it could be quite bad for GrapheneOS users.