During our recent Identity Day at Hippo, I opened with a simple idea: the internet was not designed with identity in mind. That may sound surprising, but it explains a lot about the security and privacy challenges we face today. In the early days of the web, it did not really matter who you were. That is why a famous cartoon from 1993 still rings true: “On the internet, nobody knows you’re a dog.”

Today, that assumption no longer holds. We expect to be able to access our finances, health records, government services and workplaces online. We expect these systems to know who we are, keep our data safe, and stop bad actors from pretending to be us. But to do that seamlessly and securely,  digital identity systems need to evolve fast.

 

A system under strain

The traditional tools we rely on, like usernames and passwords, are decades old – going as far back as the 1960’s. They were not built for the scale or complexity of today’s online world. As a result, identity fraud, phishing and impersonation are more common than ever. Data breaches, scams and synthetic identities have become regular headlines. And while individuals bear the brunt of these risks, the impact spans businesses, governments and the global economy.

The direction of travel

The good news is that we are moving towards something better. We have already moved from managing multiple logins to single sign-on models like signing in to apps and services using a Google or Apple ID. But that only gets us so far. Those models still place control in the hands of major platforms. The future lies in decentralisation: digital identity and personal data that is owned by the individual, not the provider.

This is where concepts like digital wallets and verifiable credentials come in. Rather than handing over all your personal data every time you access a service, you will be able to store your credentials securely and choose exactly what to share and with whom. That could mean confirming your age without revealing your date of birth, or proving your qualifications without exposing unrelated personal details. It is a model rooted in control, consent and trust.

Breaking identity down

To understand what digital identity really means, it helps to explore its core components. These are the basic functions that make identity systems work.

  • Verification is the first step. It is how you prove who you are when you first register for a service. This might involve scanning a passport or driver’s licence, submitting a utility bill or using biometric methods like facial recognition. The goal is to match the identity you claim with evidence that confirms it is valid.
  • Authentication happens every time you come back. It is the process of proving it is still you. This used to mean entering a password. Increasingly, it involves more secure and user-friendly options like passkeys, multi-factor authentication or biometrics. These make it harder for someone else to access your accounts and easier for you to do so.
  • Authorisation is what determines what you can do once you are inside a system; what you can access. It is not just about your identity but also your role, device, location, and other attributes. A teacher and a student might both access the same platform but see very different things. This control ensures users only reach the information and features they are meant to.
  • Consent and privacy are about who gets access to your data and under what conditions. You should be able to say yes or no to how your data is shared. Regulations like GDPR exist to ensure that identity data stays under your control and that organisations handle it responsibly.
  • Federation is what lets a single identity be used across multiple services. For instance, you might use your school login to access a learning platform or a government ID to sign in to a healthcare portal. This reduces duplication and can simplify the experience for users.

Types of digital identity

Alongside these functions, there are different types of identity that reflect the wide range of interactions we have in the digital world.

  • Personal identity is the one we use to access services as individuals. It is how we interact with banks, healthcare systems, shops and social platforms. It often draws from official documents and must be carefully protected.
  • Staff identity is used inside workplaces. It gives employees access to systems and tools based on their responsibilities. This kind of identity is crucial for maintaining internal security and productivity.
  • Organisational identity represents a company, institution or public body. It allows these entities to access systems, submit data and participate in secure transactions. Verifying who an organisation is can be just as important as verifying individuals.
  • Non-Human Identity (often referred to as Machine Identity) is about devices and software being able to identify themselves. As more of our world becomes connected, from smart speakers to hospital monitors, ensuring each of these can be trusted is increasingly important.

As our lives move online, the boundaries between these identity types begin to overlap. A single user might engage as a consumer, a staff member, a citizen and through their devices, all in one day. That is why understanding how these elements work together is vital. It is not just about having an identity. It is about making sure that identity can be trusted, protected and used securely.

A matter of risk

One thing that often gets overlooked in identity conversations is risk. Not every service needs the same level of assurance. Ordering office supplies is not the same as accessing bank records. That is why good identity systems are all about balance between security, usability, cost, and compliance. Get that balance wrong and you end up with either too much friction or too little protection.

What is next

The identity space is moving quickly, and not everything is settled. Passkeys, for instance, have been hailed as the solution to password fatigue, but adoption has been slower than expected. Meanwhile, decentralised identity is gaining momentum, but questions remain about how we make it work at scale. The last thing we want is to recreate the chaos of parking apps, with a different identity wallet for every service.

Interoperability, standards and thoughtful design will be key. It will also be essential to keep identity inclusive. That means designing for people with limited access to devices, documentation or digital confidence, not just those already well supported by digital systems.

At its core, identity is not just a technical problem. It is a human one. The goal is to make digital life safer, simpler and more trustworthy for everyone. Something that I talked about in our most recent whitepaper, Seamless and Secure.