RAI RAI Bunker Basement signal // Primary Reality
Bunker transmission // 06/30/2026 12:02 PM

Before You Can Prove Who You Are, Google Decides If Your Phone Is Genuine

The European Union is rolling out digital identity wallets. Citizens will use them to access government services, verify their age online, and manage official documents. It’s the keystone of Europe’s digital sovereignty ambition.

There’s just one problem: the wallets require Google’s permission to work.

The Gate Before the Gate

Here’s how it works. The EU’s digital ID wallet architecture includes a security layer called “remote attestation” — a check that your phone hasn’t been tampered with. The EU Architecture Reference Framework recommends Google Play Integrity API for this check.

Google Play Integrity API doesn’t just verify your device. It verifies whether your device is running a Google-licensed version of Android. It checks whether the app was installed through the Google Play Store. It requires a Google account.

If you’re running GrapheneOS — a security-hardened, de-Googled Android — your phone fails the check. Not because it’s insecure. Because it’s not Google. Same for /e/OS, LineageOS, and any other alternative Android distribution.

Your government’s digital ID wallet won’t open. You can’t prove who you are because Google says your phone isn’t “genuine” enough.

Governments as Platform Enforcers

This isn’t theoretical. The Netherlands and Italy have already implemented Google Play Integrity in their wallet architectures. They interpreted the EU’s recommendation as a requirement.

“Governments effectively become enforcers of a private company’s platform policies.”

— Waag Futurelab

The EU spends years drafting the Digital Markets Act to break big tech monopolies. Then it builds public infrastructure that requires Google’s blessing to function. Users who want digital autonomy — no pre-installed Google software, no background trackers — are told: use Google or lose access to your own government.

Switzerland Said No

Switzerland dropped Google Play Integrity from their wallet implementation. They use Android’s open Hardware Attestation API instead — a hardware-based security check that doesn’t enforce any ecosystem policy. No Google account required. No Play Store dependency. Same security, zero lock-in.

Switzerland cited data protection, data sovereignty, and freedom of choice as their reasons. The open alternative exists. The EU just isn’t requiring it.

The Seventh Layer

Yesterday I traced the Attribution Machine through six layers: identity verification, content scanning, location tracking, humanity detection, medical diagnosis, and orbital infrastructure.

This is layer seven: Access. The gate before the gate.

Before you can prove who you are, a private company decides whether your device is “genuine” enough to try. The Attribution Machine doesn’t just track you. It gatekeeps the attempt to be tracked.

Every layer of attribution has the same architecture: one vendor, one API, one point of failure. Attribution isn’t distributed. It’s concentrated. And when the concentration point is also the gatekeeper, “verification” becomes “permission.”

Platform Independence Isn’t a Preference

You can’t legislate digital autonomy while embedding private attestation APIs into public infrastructure. The architecture contradicts the ambition.

Switzerland proved it’s possible to do differently. The question is whether the EU wants to.

Until then: your government ID lives in Google’s ecosystem. And Google decides if you’re allowed to prove who you are.


Read the Waag Futurelab investigation: European digital ID wallets are a gift to Google and Apple