Exploring Why Trust Has to Become Infrastructure (GDC 2026)
In just a few days, I’ll be heading to Geneva for the Global Digital Collaboration 2026 Conference, where I’ll have the opportunity to lead and participate in a number of sessions on behalf of the FIDO Alliance.

The GDC is deliberately built around collaboration across governments, international organizations, standards bodies, open-source communities, industry and civil society. Its stated goal is not simply to talk about digital transformation, but to advance trusted and interoperable digital infrastructure, and to turn collaboration into practical outcomes. The FIDO Alliance has been a member of the GDC Council since it was conceived, reflecting our belief that the next generation of digital services cannot be built as a collection of disconnected national or corporate silos, and requires collaborating with a vast cross-section of the global digital ecosystem (many of whom will be in Geneva).
As one of the co-organizers of the conference, the FIDO Alliance has been working diligently to ensure that the agenda at GDC 2026 helps in achieving that goal. In putting together our proposals for the GDC 2026 conference, a theme emerged that I wanted to share with all of you: Trust as Infrastructure.
Trust as Infrastructure
We tend to think of trust as something that sits on top of technology, something established through policies, contracts, reputation or regulation. I think we increasingly need to think about it differently.
Trust itself is becoming infrastructure.
Just as the internet depends on foundational protocols, digital society depends on foundational mechanisms for establishing who or what can be trusted, how credentials can be verified, how authorization can be expressed, and how different systems can interoperate securely. This is where I believe the work of the FIDO Alliance is particularly important. We have spent more than a decade working on one of the most fundamental problems in digital trust: how do we establish confidence that the person accessing a service is really the person they claim to be, without relying on credentials that can simply be stolen or phished?
The success of passkeys demonstrates what happens when strong security, open standards, interoperability and good user experience come together. The same principles increasingly need to extend across digital credentials, wallets, payments and (increasingly) interactions involving AI agents. That is why the FIDO Alliance has expanded its mission beyond authentication.
The Discussions We’re Driving in Geneva
At GDC 2026, we’ll be exploring questions around digital credential and wallet certification, authentication, agentic identity and agentic commerce. These are areas that may appear distinct, but are actually connected by the same fundamental question:
How do we make trust something that digital systems can establish, verify and rely upon — rather than something we simply assume?
The sessions we’ve proposed at GDC are deliberately designed around this broader idea of Trust as Infrastructure. We’ll explore the lessons countries are learning as they build national digital identity ecosystems and what it takes to make those ecosystems genuinely interoperable and trustworthy. We’ll look at the standards, architectures, and frameworks that can be used to build the digital solutions and services to power these ecosystems, and the governance and certification programs needed to ground that trust is validated reality. Plus we’ll tackle emerging questions posed by agentic AI and agentic commerce.
DAY 1 (September 1)
1) Keynote Panel on Agentic Commerce [4 – 4:20 pm]
FIDO Alliance Executive Director & CEO Andrew Shikiar will join representatives from Google, EMVCo, Samsung and Mastercard for a panel conversation on Agentic commerce to explore the global partnerships to scale secure, trusted AI-driven payments globally, enabling transparency, consumer control, and frictionless experiences.
DAY 2 (September 2)
1) Delivering the Digital Identity We Were Promised [3 – 3:50 pm]
In a dynamic back-and-forth presentation that sets the stage for the deep-dive sessions that follow, Heather Flanagan (W3C Technical Advisory Group member and Co-Chair, W3C Federated Identity Working Group) and I will explore the remarkable progress being made in the global identity ecosystem, and the equally significant risks that could prevent its promise from being realized. We will then be joined for a fireside chat by Paolo De Rosa, CTO for the European Digital Identity Wallet, on the challenge of aligning policy and regulatory support for technology enablement efforts across the digital credentials space.
2) Lessons from Around the World on Building Digital Identity that Citizens Trust [5 – 5:50 pm]
In this panel discussion, Elizabeth Garber (Director of Marketing and Strategy, OpenID Foundation) and I will chat with representatives involved in the rollout of digital identity in Estonia, Japan, Brazil, and India to provide a truly global real-world perspective on building trusted digital identity ecosystems. Drawing on lessons from countries with different digital identity journeys, they will discuss how cybersecurity, standards, governance, and public policy must work together to establish lasting trust.
Panelists: Vinicius Silva (Digital Technologies Advisor, Ministry of Management and Innovation in Public Services, Brazil), Joe Carson (Cybersecurity Advisor, Govts. of Estonia and Ireland), Tatsuji Shimoe (Digital Agency of Japan), Barada Prasad Sabut (Head of Engineering, UIDAI, Govt. of India)
DAY 3 (September 3)
1) Trusted Agentic Payments: Building on Digital Identity with AP2, Verifiable Intent, Intent Services, DPC, and Digital Wallets [10 – 10:50 am]
Succeeding with agentic payments requires building on the same foundations of trust that are transforming digital identity. This session, co-organized with EMVCo, explores how the Agent Payments Protocol (AP2), Verifiable Intent (VI), Intent Services, Digital Payment Credentials (DPC), and standards-based digital wallets, like the EUDI Wallet, could work together to create a secure, interoperable architecture for agentic commerce.
Presenters: Lee Campbell (Identity and Authentication Lead for the Android Platform, Google), Arman Aygen (Director of Technology, EMVCo), Jonathan Grossar (Senior Vice President, Mastercard)
2) Delivering Secure Digital Credentials with Great User Experiences Using DC API, CTAP, and OpenID4VC [12 – 12:50 pm]
Building a secure, interoperable digital wallet ecosystem requires multiple standards to be profiled into a cohesive architecture that enables seamless interoperability across devices, platforms, and implementations. This introductory technical session, co-organized with OpenID Foundation, explains how the W3C Digital Credentials API (DC API), FIDO CTAP, and the OpenID Foundation’s OpenID4VC protocol family combine to enable secure, privacy-preserving credential issuance and presentation.
Presenters: Tim Cappalli (Sr. Architect, Identity Standards, Okta), Christian Bormann (Architect Digital Identity and Cryptography, SPRIN-D)
3) Certification: The Foundation of Trust for a Global Digital Identity Ecosystem [2 – 2:50 pm]
Open standards make interoperability possible. Certification makes it dependable. It provides independent assurance that implementations conform to standards, interoperate consistently, and meet defined security and privacy requirements. This session, co-organized with CSC and IEEE, explores why certification is the critical enabler for global adoption, and describes industry-wide efforts underway to elevate certification above mere compliance.
Presenters: Roland Atoui (Security Secretariat, FIDO Alliance), Evgenia Nikolouzou (Cybersecurity Expert, ENISA), Purva Rajkotia (Director, Connectivity and Telecom, IEEE)
4) CTAP Hybrid Evolves into PXP (now with offline support) [4 – 4:50 pm]
Originally developed as the cross-device transport protocol for passkeys, CTAP Hybrid has evolved into a far more versatile protocol that can also be used for exchanging verifiable digital credentials across devices and platforms. Reflecting this broader role, the protocol has been renamed the Proximity Exchange Protocol (PXP) and now introduces a robust peer-to-peer offline transport, enabling secure credential presentation and issuance even without Internet connectivity. This technical session, co-organized with the Linux Foundation Group, uses protocol walkthroughs and live demonstrations to provide a deep dive into the architecture, capabilities, and evolution of PXP, explaining why it has become a foundational component of the emerging digital identity ecosystem.
Presenters: Tim Cappalli (Sr. Architect, Identity Standards, Okta), Lee Campbell (Identity and Authentication Lead for the Android Platform, Google)
FIDO Alliance representatives will also be participating in a number of other sessions at the conference on connected topics around trust registries, conformance, payments, and identity verification. You can see full agenda here.
The Importance of the GDC Agenda
We need to be able to establish identity, authenticate entities, express authority, protect privacy, verify credentials, and create evidence that can be trusted across organizational and national boundaries. That is trust infrastructure. If we get that infrastructure right, we can enable an enormous amount of innovation on top of it. If we get it wrong, we’ll end up building increasingly sophisticated digital systems on foundations that are fragmented, difficult to verify and ultimately difficult to trust.
And that is precisely why I think GDC is so important. One of the most encouraging things about GDC is that collaboration isn’t simply part of the conference branding. It is built into the structure of the organization. Not collaboration for collaboration’s sake, but collaboration built around the hard problems that become impossible to solve when every ecosystem builds its own answer.
The technologies are advancing rapidly. Passkeys are scaling. Digital wallets and credentials are moving from pilots into real-world deployment. AI agents are beginning to act on our behalf. Governments are developing new digital identity frameworks. Standards organizations are working to make these ecosystems interoperable. But technology alone won’t create a trusted digital society. We need to (collectively) build the infrastructure of trust underneath it. I’m looking forward to being in Geneva with colleagues, partners and, hopefully, a few people who will challenge our assumptions and make us think differently as we work on this.
See you at GDC 2026. If you’re there, come find us. There will be plenty to talk about