The next generation of digital identity standards is being written right now, in working sessions and task forces. There, engineers, cryptographers, business leaders, and legal and academic experts tackle the hard problems before they become specifications.
Scott Jones, Chief Product Officer at Realeyes, was in the room for one of the year’s most consequential conversations, the kind of session that could reshape how an entire industry proves someone is human.
At the Internet Identity Workshop (IIW) on April 30, Scott joined a session on zero-knowledge proofs (ZKP) and personhood credentials. Drummond Reed of Trust Over IP (ToIP) and Leif Johansson of the SIROS Foundation led it. Reed co-chairs ToIP’s Decentralized Trust Graph Working Group, which is specifying the personhood credential at the center of this effort.
Why Zero-Knowledge Proofs Matter Now
The urgency traces back to the EU Digital Identity (EUDI) wallet. EU regulation requires credential presentations to stay unlinkable. So an issuer and verifier can’t collude to identify a user across different presentations of the same credential.
The industry’s first fix was batch issuance, but it hit a wall fast. It was prohibitive at population scale, and impractical for reissuing hardware-bound credentials to an entire country. As a result, European cryptographers now see zero-knowledge proofs as the only viable path to privacy-preserving credentials at scale.
For instance, Linux Foundation and Berkeley researchers are working on it, alongside the SIROS Foundation, founded by a Yubico co-founder. Google and Ethereum have their own implementations too, and all of them are converging on similar cryptographic approaches.
Underneath all of it sits a deeper insight: at population scale, the user is often the adversary. The EU’s own age verification app has already shown this. And standard approaches like OAuth simply weren’t built to withstand someone actively trying to game the protocol. So ZKP may offer the most credible path to systems that resist cheating by design.
“At population scale, the user is often the adversary and standard approaches like OAuth aren’t built to survive that.”
Proving Humanness Without Exposing Identity
One question from the session cuts directly to what Realeyes builds, and to the promise underneath every “privacy-preserving biometrics” claim.
Realeyes says its biometrics preserve privacy, but that claim only holds if people choose to trust it. A model generates every face embedding, and in theory, someone could reverse that embedding to reveal identity. So the real problem for ZKP to solve isn’t protecting Realeyes’ model. It’s proving humanness without ever exposing who the person is. That way, users don’t have to simply take a privacy claim on faith.
The task force raised this as an open problem at IIW. It resolved the problem at its first working session in July. Here’s the key insight: the cryptography carries the privacy. The zero-knowledge proof reveals nothing about the model, the biometric, or the person’s identity. Instead, the issuer’s accreditation and governance provide the assurance that the “live human” call was correct. Neither the cryptography nor the model does.
“How do you prove someone is human without exposing or asking the world to simply trust – the proprietary model doing the determining?”
At the IIW kick-off session, Scott showed the room the Realeyes browser wallet. It’s a live example of the credential this working group is trying to build privacy-preserving infrastructure for. It turned an abstract problem into something concrete. The wallet lets someone attest they’re a real, unique human who is 18 or older. It does this without revealing their exact age or identity. On top of that, the zero-knowledge proof adds a further layer of privacy.
Realeyes is positioned to help build a blinded assertion of humanness that doesn’t depend on identifying someone. For ToIP’s Decentralized Trust Graph Working Group, that distinction is central. The goal is to prove humanness rather than identity, and make it interoperable rather than tied to one vendor.
(Click to view larger)
“Humanness, not identity, interoperable, not owned by one vendor. That distinction is the whole point.”
Scott’s Second Seat at a Standards Table
This isn’t Scott’s first time at a standards table. Earlier this year, the W3C Invited Expert on the Verifiable Credentials Working Group. There, he’s contributing to the Verifiable Credentials Confidence Method specification. He’s also working on privacy-preserving age verification for convenience stores. That would let a customer attest they’re 21+ without showing a clerk personal information like a driver’s license.
Standards organizations are tackling some of the hardest unresolved problems in digital identity. Scott keeps finding a seat at these tables. That’s because Realeyes is already shipping the technology their specifications are trying to define.
Meanwhile, VerifEye’s privacy-preserving biometrics and architecture give the company a practical foundation for putting ZKP-style principles into practice. That experience matters while these standards are still taking shape.