Latest post

Sweden's Quiet Plan B for Digital Identity

 After years of relying on one private app for nearly everything, the government is finally building a state-backed alternative to BankID.

 

I forgot my phone at home on a Tuesday in March and spent the whole day locked out of my own life. No BankID meant no login to my bank, no Swish to split lunch with a colleague, no way into Skatteverket, and not even the visitor system at the office, since it runs on a code tied to the same app. I borrowed a laptop and realized that every digital door in Sweden, professional and personal, opens with the same single key. That afternoon felt like a preview of something I later read had already happened to millions of people, just not by accident.

 

The news.

Sverige-id, Sweden's forthcoming state-backed electronic identity, is heading toward its December 1 start date. Digg, the Agency for Digital Government, approved the technical solution together with the Swedish Police Authority back in April, and unless something derails the timeline, citizens and foreign residents registered here from age nine will be able to apply from December 1, when the underlying law takes effect. The application runs alongside a compatible national ID card, not separately, and the whole thing lives in a mobile app. It's built to meet the highest assurance level under the EU's eIDAS framework, which means it can be used to log into services, sign documents electronically, and share personal data across borders. The Riksbank has already floated a further use: as a backup rail for payments, sitting next to, not replacing, BankID.

 

The dependency.

To understand why this matters, you need to see how far BankID's reach already extends. More than 8.5 million people use it, and it is the only e-ID accepted for authenticating payments in Sweden. There has never been a state-run alternative at the top trust tier, which is unusual among EU countries and something Digg, Finansinspektionen, and the Riksbank have all criticized in different reports over the past two years. Their argument is straightforward: when a single privately owned system becomes the login for banking, tax filing, healthcare, and government services all at once, its failure stops being a company problem and becomes a financial stability problem.

 

The wake-up call.

That warning stopped being theoretical in March, when a hacker group calling itself ByteToBreach broke into CGI Sverige's infrastructure, the IT contractor behind parts of BankID and the Tax Agency's login systems. They walked out with source code, encryption keys, and personal data tied to citizens who never chose CGI as a vendor and had no way to opt out. The material ended up for sale on the dark web. Nobody's bank account emptied overnight, but the exposure of live encryption keys means the risk didn't end when the headlines did.

 

My read.

I don't think Sverige-id fixes the dependency problem on day one, and I doubt most people will bother applying for it in December. Adoption of a second, optional ID card requires a reason, and 'just in case BankID has a bad month' isn't a strong one for most households. What it does is give the state a lever it currently doesn't have: a fallback that works whether or not a single IT contractor's servers are configured correctly. That's worth building even if hardly anyone uses it for years.

 

Watch this.

The real test comes after December 1, when we see whether banks, Skatteverket, and healthcare portals actually bother integrating Sverige-id as an accepted login, or let it sit unused while BankID keeps its monopoly by default.

 

FAQs:

1. Do I need to get Sverige-id, or can I just keep using BankID?

A: You don't need it. BankID keeps working as before; Sverige-id is an optional backup you can apply for from December 1, 2026.

 

2. Wasn't BankID good enough? Why does Sweden need a second system?

A: Because BankID runs on infrastructure built by a private contractor, CGI, and the March 2026 breach of CGI Sverige showed that a single point of failure at one vendor can expose tens of millions of identity records at once.

 

3. How does Sverige-id compare to eID systems in other EU countries?

A: Most EU states already offer a state-backed eID at the top eIDAS trust level; Sweden has been an outlier in leaving that role entirely to a private, bank-owned system until now.

 

4. Will I be able to use Sverige-id to pay for things, like I do with BankID and Swish?

A: The Riksbank has proposed using it as a backup payment rail, but that isn't confirmed for the December 2026 launch. Initially it's built for logins, e-signatures, and sharing personal data.

 

5. What happens if hardly anyone signs up for it?

A: Then it functions as insurance rather than a replacement, sitting unused unless BankID has a serious outage or another breach, which is exactly the scenario it's designed for. 

Comments