An EU sovereignty project whose root of trust is two American corporations’ key ceremonies, subject to US jurisdiction, is like reading The Onion. But it’s real.
How stupid of the EU?
The EU already owns a sovereign root of trust and has suspiciously declined to use it. The German eID chip is Common Criteria certified by BSI, runs on silicon from Infineon and NXP, and has shipped in every Personalausweis since 2010. Smartcard-based eIDAS notified schemes exist across member states. Choosing American smartphone TEEs over that installed base was a particularly non-sovereign decision dressed up falsely as an architecture requirement.
Both attestation roots are supposed to terminate in key infrastructure operated by companies subject to US legal process, so the admission decision for an EU citizen’s identity credential runs through jurisdiction that the EU spent the last decade claiming to escape.
Schrems I and II were litigated over less.