A sandboxed pilot with real stakes
On July 16, 2026, the European Commission's EU Digital Identity Wallet initiative and Japan's Digital Agency published a joint report on a pilot that did something no prior EU external interoperability exercise had done: it moved a European Digital Identity Wallet (EUDIW) prototype and a Japanese wallet built on the My Number Card system through a full credential lifecycle, across each other's borders. A Japanese student presented a learning credential to a European university verifier; a European student presented one to a Japanese verifier; issuers on each side issued credentials the other side's wallet could store and present. The report frames the scenarios around opening a bank account and enrolling in a student exchange — the everyday moments where a foreign national's paperwork becomes someone else's compliance problem.
The pilot traces back to the Memorandum of Cooperation on Digital Identities and Trust Services that the EU and Japan's Digital Agency signed on April 30, 2024, at the second EU-Japan Digital Partnership Council in Brussels, committing both sides to pursue "Data Free Flow with Trust" by aligning the EUDI Wallet with Japan's digital identity architecture. Two years on, the report's headline finding is that the plumbing works: credentials issued under eIDAS 2.0 rules and credentials issued under Japan's My Number framework can be issued, stored, presented, and verified across jurisdictions with materially different governance models and technical architectures, using shared international standards rather than a single unified system.
Steelmanning the caution
The report itself supplies the reason not to celebrate too fast: mutual recognition of identity systems is a legal problem, not just a technical one, and it will require international agreements and aligned liability rules before any of this becomes legally binding. That caution deserves to be taken seriously rather than waved off as bureaucratic foot-dragging. A university checking a diploma is low stakes; a bank relying on a foreign-issued credential to open an account is not. If a bank onboards a customer using a credential issued by a foreign authority under different data-protection and revocation rules, and that credential later proves fraudulent, stale, or improperly revoked, who is liable — the issuer, the wallet provider, or the relying party? Europe's own privacy advocates have spent two years pressing similar questions about eIDAS 2.0's domestic rollout, and extending an unfinished domestic trust framework internationally before those questions are settled would be a genuine regulatory gap, not a hypothetical one.
Why the pilot's design gets this right
That is precisely why the pilot's narrow scope should be read as a feature, not a limitation. The report picked academic credentials — arguably the lowest-stakes, most standardized identity artifact available — and built the test around selective disclosure, letting a wallet holder prove a specific attribute without exposing a full identity record. That is the correct sequencing: validate the cross-border plumbing on a narrow, low-risk credential class before extending mutual recognition to banking KYC or health data. Trade policy already has a template for this — equivalence and mutual-recognition agreements are built sector by sector, not granted in one sweep — and there is no reason digital identity should skip that discipline just because the underlying technology is new. Reading the July report as proof that liability and privacy questions are solved would be premature; reading it as evidence that a phased, sector-specific path to legally binding recognition is achievable is exactly what the data supports.
The bigger risk is at home, not the border
What the pilot does not fix is the more pressing problem: the EU's own wallet is not ready. Regulation (EU) 2024/1183, which overhauled the original eIDAS framework, requires every member state to make at least one certified EUDI Wallet available to citizens by the end of 2026, with banks and large platforms required to accept it roughly a year later. A Biometric Update survey of French and German citizens, published the same month as the pilot report, found that 51% had never heard of the EU wallet and 73% feared that different national implementations would not interoperate with each other — inside the EU, before Japan enters the picture at all. That is a sharper warning than anything in the cross-border pilot: a wallet citizens do not know exists or trust cannot anchor a global interoperability strategy, however well the sandbox test performed.
The right sequencing
None of this argues against the EU-Japan track. A credible, rules-based path to cross-border digital identity recognition serves an open internet and frictionless cross-border commerce — infrastructure that makes remote banking, academic mobility, and digital trade cheaper without forcing every country onto identical domestic systems. But sequencing matters. Brussels should keep expanding narrow, sector-specific pilots like this one — education first, then perhaps professional qualifications — while resisting pressure to fast-track binding mutual recognition ahead of settled liability rules. And it should treat the December 2026 domestic deadline, not the Japan pilot, as the metric that actually determines whether any of this becomes usable. A working bridge to Tokyo is not worth much if the EU side of it is still under construction.