This is the fourth post in a series exploring the idea of skills you earn vs. skills you learn. The previous posts can be found in my archives.
If the design principles were clear by 2014 — individual agency, selective disclosure, the person in control of their own data — then an obvious question follows. Why did it take another decade for this idea to go mainstream?
The honest answer is that the technical gap was real but it wasn’t the only gap, and arguably it wasn’t even the primary one. The deeper barriers were human ones: incumbency, familiarity, existing business models, and a set of powerful economic interests that had every reason to keep the existing architecture in place.
The structural problem
The enterprise graph work of 2013 and 2014 ran into a hard boundary that no amount of good design philosophy could dissolve: the organization itself.
The data lived inside systems the employer controlled. The analytics ran on infrastructure the employer provided. When an employee left, the picture of their contribution stayed behind. It belonged to the system, not to them. There was no standard mechanism — no portable, verifiable, cryptographically secure format — for a person to carry a trusted claim about their own professional contribution across an organizational boundary in a way that another party could verify independently.
That was a genuine technical problem, and it took years of painstaking standards work to solve. But it’s worth being clear about why the technical problem persisted as long as it did. It wasn’t primarily because the engineering was hard. It was because the people with the resources to solve it had little incentive to do so.
The incumbency problem
The centralized model — where data aggregators, background check companies, HR platforms, and identity verification vendors sit between individuals and the systems that make decisions about them — is not just a technical architecture. It is a business model. Data is power. Data is revenue. The ability to aggregate, enrich, and gate access to personal data is the foundation on which entire industries are built.
A decentralized model, where individuals hold and present their own verified credentials, is a direct threat to that model. It disintermediates the aggregator. It makes the background check company redundant for the claims it can verify. It removes the leverage of the platform that currently sits between the worker and the employer, charging for the connection. There will be winners and losers in this transition, and the incumbents know it.
This isn’t unique to identity. Large technology shifts almost always face the same pattern: established players with profitable models built on the existing architecture resist the new one, not necessarily through bad faith, but through the entirely rational defense of what works for them today. The transition to the internet saw exactly this dynamic — companies deeply invested in client-server models initially fought to protect their position, until the inflection point became impossible to ignore and the smart ones threw their weight behind the new paradigm instead.
The decentralized identity ecosystem is navigating the same transition now. Some incumbents are adapting. Others are still resisting. The outcome isn’t settled.
The chicken-and-egg problem
Even setting aside incumbent resistance, decentralized systems face a structural adoption challenge that centralized ones don’t: they require a network to work.
A verifiable credential is only useful if there are issuers willing to issue it, holders willing to carry it, and verifiers willing to accept it. In the early stages, none of those populations exists at scale — and each group is waiting for the others to move first. Issuers won’t invest in issuing credentials that verifiers don’t yet accept. Verifiers won’t build acceptance infrastructure for credentials that aren’t yet in circulation. Individuals won’t adopt wallets that carry credentials nobody is asking for.
This problem is further compounded by the fact that the business model for decentralized identity is still being worked out. Who pays? The issuer, the verifier, the holder, or some combination? What’s the revenue model for the wallet provider? For the trust registry? For the governance framework? These are not resolved questions, and the absence of clear answers makes institutional adoption slower and more cautious than the technology alone would warrant.
What broke the deadlock
Two things moved the needle, and they worked differently.
The first was an unexpected forcing function: COVID-19. When governments around the world needed to exchange verifiable health data at scale — vaccination records, test results, recovery status — the decentralized model turned out to have properties that the centralized alternative couldn’t match: privacy preservation, resilience, low latency, no single point of failure. Countries that went the decentralized route found the architecture worked. In 2020, I was part of the team at IBM that built the Digital Health Pass — a decentralized credential system for verifiable health data. It subsequently became the platform on which the New York State Excelsior Pass was built, helping to reopen the economy for tens of millions of New Yorkers. For me personally, seeing that system operate at scale was the proof of concept the whole approach had always needed. The architecture wasn’t theoretical anymore.
The second was regulatory. When the European Union put eIDAS 2.0 into law — mandating that every EU citizen have access to a digital identity wallet and that member states build the infrastructure to support it — the chicken-and-egg problem acquired a forcing function on the issuer and verifier side. Governments became mandatory participants in the network. Standards bodies responded: ISO mDLs, IETF SD-JWTs, OpenID for Verifiable Credential Issuance and Presentation. The interoperability layer that had been assembling slowly in standards committees suddenly had a regulatory deadline behind it.
Where we are today
The gap has not fully closed. It’s important to say that clearly, because the story of decentralized identity is littered with premature declarations of arrival.
The standards are largely in place. The regulatory framework in Europe is real and moving. An ecosystem of adopting countries, industries, and technology providers is growing. But the business model questions aren’t resolved. The adoption curve is still shallow in most sectors. Incumbent resistance hasn’t disappeared — it has adapted. And the network effects that will make this genuinely ubiquitous require a scale of participation we haven’t yet reached.
What has changed is that the direction is no longer in doubt. The question is no longer whether a decentralized, individual-controlled model for trusted data exchange is technically feasible or legally supportable. It is both. The question now is how quickly the adoption curve accelerates — and what it will take to bring the workers, employers, and institutions whose participation the network needs.
That’s what the final post in this series is about.
Marie Wallace leads the Digital Identity Innovation practice at Accenture. She has been writing about the human side of data at allthingsanalytics.com since 2011. All opinions expressed are her own.