TRUST · REGULATIONS
Most of this law binds a government. Not a company.
Regulators write obligations for specific parties — a member state, a bank, a "very large online platform," a firm already required to authenticate its users strongly. This page names each instrument, who it actually binds, and the correction against the reading that usually gets repeated. Where nothing here binds us, we say so rather than borrow the authority of a law that was never written with us in mind.
A Regulation and a Directive are not the same promise.
A Regulation applies directly, the same day, in every member state — the EU Anti-Money Laundering Regulation is one. A Directive binds only after each state passes its own law to match it, on its own timeline — the European Accessibility Act is one, and it runs through twenty-seven separate transposing laws that differ in scope and penalty. The table below says which is which, because the difference decides whether a date is a deadline or a starting gun.
Instrument by instrument.
| instrument | jurisdiction | what it requires | who it actually binds — and the correction |
|---|---|---|---|
| eIDAS 2.0 — very large online platforms | European Union | Very large online platforms must accept the wallet where users are required to authenticate for access to an online service. | Designated very large online platforms. Gatekeepers are a different matter and are widely misreported. There is no gatekeeper acceptance duty anywhere in the amended eIDAS. What Art 12b does is oblige gatekeepers to give wallet providers interoperability and access to operating-system, hardware and software features, free of charge — a duty owed to wallet providers, which is the mirror image of the one usually described. Regulation (EU) 2024/1183, Art 5f(3) |
| European Accessibility Act | European Union | An enumerated, closed list of products and services sold to consumers in the EU must meet the Act's accessibility requirements. | Economic operators dealing in the listed products and services — and only through 27 national transposing laws, which differ in scope, enforcement and penalty. It is a Directive: it never applies to anybody directly. Four qualifiers are usually dropped. Microenterprises providing services are exempt (Art 4(5)); there is a disproportionate-burden defence (Art 14); transitional regimes run to 28 June 2030, with existing service contracts and a twenty-year allowance for self-service terminals (Art 32); and Art 2(4) carves out some content. "The Accessibility Act applies to private businesses" is not a true sentence. Directive (EU) 2019/882 — Arts 2(4), 4(5), 14, 32 |
| EU Anti-Money Laundering Authority | European Union | The AMLA Regulation has applied since this date. | The Authority itself, and the framework around it. Its direct supervision of selected obliged entities does not begin until 2028. This one is routinely listed as a 2027 date; it is not. Regulation (EU) 2024/1620, Art 108 |
| Australia AML/CTF Amendment Act 2024 | Australia | Schedule 3 commenced 31 March 2026, but programs, customer due diligence, reporting and record-keeping were disapplied until 1 July 2026 — so that is when obligations actually bit for the newly regulated cohorts. | Real estate, precious metals and stones, and professional services under tranche 2; and virtual asset services. Only pre-existing digital currency exchanges were genuinely caught in March. AUSTRAC's own guidance site was unreachable when this row was checked, so we cannot tell you whether any forbearance or supervisory-priorities statement has been published since. The row rests on the two controlling primary instruments, which outrank guidance in any case — but we are not going to imply an enforcement posture we have not read. Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth), No. 110 of 2024, Sch. 3 incl. Pt 4 item 11; Transitional Rules F2026L00393, s.12 |
| UK digital verification services trust framework v1.0 — no earlier than | United Kingdom | Version 1.0 comes into force on the date the first conformity assessment body is accredited to certify against it. | Providers seeking certification against v1.0. Existing gamma (0.4) certified providers get at least fifteen months to uplift, on a bespoke per-service cycle. Two things this material commonly gets wrong, both of which the first draft of this row got wrong too. The framework was renamed in March 2026 — "Digital Identity and Attributes", DIATF, is retired. And the 31 March 2026 date usually attached to v1.0 belongs to a different version entirely: that is when beta (0.3) certificates expired. DVS trust framework v1.0, finalised 9 June 2026; Data (Use and Access) Act 2025 |
| eIDAS 2.0 — the wallet obligation | European Union | Each member state must provide at least one European Digital Identity Wallet to all natural and legal persons in the Union. | Member states, and only member states. No obligation whatsoever falls on a private vendor here, including on us. A state without a wallet is in breach; a company without one is not. Note the Article’s own words: at least one wallet, for all natural and legal persons. Legal persons are in scope, and the popular paraphrase about citizens and residents is both narrower and not what the text says. Regulation (EU) 2024/1183, Art 5a(1) |
| CCPA/CPRA — automated decision-making technology | California, United States | Full compliance with the ADMT rules is required. | Businesses subject to the CCPA that use ADMT for significant decisions about a person. Two qualifiers, and both cut against urgency, which is exactly why they are here. The risk-assessment duty that began on 1 January 2026 applies to newly initiated processing (§ 7155(a)(1)); processing already underway has until 31 December 2027 (§ 7155(b)), which for most businesses is the operative deadline. And the 1 April 2028 event (§ 7157) is an attestation plus summary metadata, not submission of the assessment itself. California Consumer Privacy Act as amended by the CPRA; CPPA regulations §§ 7155, 7157 |
| UK Money Laundering and Terrorist Financing (Amendment) Regulations 2026 | United Kingdom | Commencement is staged. The general body came into force on 30 June 2026. Regs 20 and 36(b) — including the new reg. 34A enhanced due diligence for cryptoasset exchange and custodian wallet providers — apply from 1 February 2027, and reg. 37 for remaining purposes from 25 October 2027. | UK firms regulated under the Money Laundering Regulations 2017. The cryptoasset provisions most firms are actually asking about land on 1 February 2027, not on the June 2026 in-force date. A rebutter will not attack the date on this row; they will attack the name, so it carries the SI number. SI 2026/621 — regs 20, 34A, 36(b), 37 |
| Swiss e-ID (swiyu) — trust infrastructure, expected first half of | Switzerland | The trust infrastructure is expected to be operational, which the office states holds regardless of when the e-ID itself is introduced. | Nobody. This is the Swiss Confederation's own schedule for its own programme. There is currently no announced launch date for the Swiss e-ID at all. The 1 December 2026 date was abandoned on 30 June 2026, and the reason given was not money: it was the risk that machine-generated forgeries pose to the online issuance process. Federal Office of Justice, revised timetable for the e-ID and the trust infrastructure, 30 June 2026 |
| AMLD6 — the next transposition tranche | European Union | Member states must transpose the Directive into national law across four staggered dates. Two of them have already elapsed; the last is 2029. | Member states, which then bind firms through national law. This one is a Directive and does require transposition — it is routinely, and wrongly, described as directly applicable alongside the Regulation. Directive (EU) 2024/1640 |
| EU Anti-Money Laundering Regulation | European Union | The Regulation applies directly across the Union, with no national transposition step in between. | Obliged entities across the EU. Football agents and clubs are deferred to 10 July 2029 under the same Article. Regulation (EU) 2024/1624, Art 90 |
| eIDAS 2.0 — the private-sector acceptance obligation | European Union | Private relying parties already required — by Union or national law, or by contract — to use strong user authentication must accept the wallet, and only when the user asks them to. | Those relying parties, with microenterprises and small enterprises excluded. Banking, telecom and healthcare appear in the text as examples, not as the operative trigger: a firm under no strong-authentication requirement is outside this Article whatever sector it trades in. The commercially significant one, and the one most often collapsed into the wallet date. They run on two clocks a year apart. Collapsing them moves the acceptance date a full year early. Regulation (EU) 2024/1183, Art 5f(2) |
12 instruments, each carrying the citation printed beside it and the date it was last checked against a primary source.
Before you go any further.
No conformity assessment against eIDAS 2.0 or the EUDI reference architecture has been undertaken. That is a decision, on the record, not an oversight — and it means nothing on this page should be read as a compliance claim for this platform, only as a plain reading of what the law itself says.
- PLANNED A wallet a person installs from an app store. wallet-native You cannot hold a credential on a phone you own. Everything a person would do with a proof waits behind this.
The register holds 17 live · 2 partial · 2 planned · 5 not yet.
1 of the 2 capabilities this page depends on have no row in the register yet, so this page will not print a state for them. They are named rather than dropped, because a slice that silently shortens itself is the same defect as a claim with no receipt.
- eidas-conformity
The register route serves, but it carries no row for these yet. List what it does carry:
curl -s https://id.orbis.id/api/site/register | jq -r '.entries[].slug' Straight answers.
- Does any of this bind ORBIS directly?
- Mostly not. Almost every row above binds a member state, a designated large platform, or a firm already under a strong-authentication duty — categories we are not in today. Where a row does eventually reach a private vendor, the table names the trigger rather than leaving it implied.
- Has an outside body signed off on ORBIS against any of these?
- No. Conformity assessment, where one of these instruments even has a formal scheme for it yet, has not been undertaken for this platform. What we do and do not hold is on the security page.
- Why no GDPR row?
- Asserting a blanket data-protection label is a pattern this site's own voice rules forbid: it names a demand rather than an implemented answer. Where a GDPR-adjacent capability is measured, it belongs in the register, with an endpoint behind it — not in a prose claim on this page.
- Is there an anti-money-laundering or know-your-customer sign-off behind any of this?
- No, and nothing on this page states or implies one. Nothing here has sought a KYC or AML determination from anybody, and a wallet obligation or an acceptance duty appearing on this table is not the same claim as this platform having cleared a financial-crime review — the two are different processes and this page will not let one borrow the other's authority.
Do not trust us. Check us.