← Back to blog

The Orb Can Tell One Human From Another. Three Regulators Said That Is Not the Same as Permission

Capability is a fact about a device. A mandate is a relationship, and it has to be conferred by the people it will bind.

On 17 April 2026, at an event in San Francisco, the company that built the Orb announced that Tinder, Zoom, and Docusign would begin using World ID to verify that a real person was on the other end. A dating profile, a video call, a signature: three products whose entire value is knowing who you are talking to, all reaching for the same proof. The pitch was clean. With bots and deepfakes multiplying, here was a way to prove that the user on the other end is a real person, backed by an iris scan that almost never errs.

Sixteen months earlier, the same company's lead regulator in Europe had ordered part of that identity register erased.

That gap is the subject of this essay. The states that examined the Orb most closely declined to grant it the authority to certify a person. The platforms granted it in an onboarding flow. So the question the title asks is not rhetorical, and it is not settled: who certifies a human, and where did that authority come from?

The reading that is wrong

The easy story is that the regulators found the Orb inaccurate, that the technology does not work, that the scan is junk. That story is wrong, and it is wrong in an instructive way.

The only full adjudication on the merits is the decision of the Bavarian State Office for Data Protection Supervision, Worldcoin's lead supervisory authority under the GDPR, issued on 19 December 2024 after a twenty-month investigation. It runs to 132 pages. Read it, and the accuracy of the iris code is not in doubt anywhere in it. The authority calls the iris code "extremely reliable in identifying a person," more reliable than a fingerprint, and it treats that reliability as the reason the risk is high, not as a point in the company's favor. An iris code can be derived from ordinary face images, so a register of them is dangerous precisely because it works: it can be matched against a world already full of cameras. The decision's summary of the danger is one sentence worth quoting in full. "Such a large central database of such sensitive biometric data under the control of a single private organisation entails risks of magnitude that cannot yet be estimated today."

Sit with what that does to the vendor's pitch. Accuracy is the aggravating factor, not the defense. A proof-of-personhood scheme cannot answer the objection by lowering its false-match rate, because the objection scales with the accuracy. Better matching makes the certificate more useful and the register more dangerous, and those are the same property. You cannot engineer your way out of an objection that grows as your engineering improves.

What the decision actually ordered

What the Bavarian authority ordered is narrower and more interesting than "no." It issued a reprimand for storing iris codes as plain text in a database for roughly ten months, from July 2023 to May 2024. It ordered erasure of codes collected without a valid legal basis. It required the company to obtain explicit consent for the processing it wanted to continue, and to give people a working means of erasure.

Notice what is not on that list. No finding that the Orb is inaccurate. No ban on iris scanning. No ruling on minors, which the decision explicitly reserved for a separate proceeding. The lead authority, after the longest look anyone has taken, did not prohibit proof-of-personhood. It prohibited doing it without valid consent and without a delete button. And it recorded, as an adjudicated fact rather than an allegation, that the register asking for the world's trust stored its codes unencrypted for its first ten months.

The company has said it will appeal, so none of these orders are final. Whatever the appeal argues, the decision has already answered, in the negative, the question the cryptography was built to raise: whether splitting each iris code into cryptographic shares meets the legal definition of anonymisation in the EU. Splitting the code into shares, it held, is "under no circumstances an anonymisation measure," at most a pseudonymisation measure, and pseudonymised data is still personal data, still inside the regulator's jurisdiction. The clever cryptography was built, in part, to move the system out of reach of exactly this kind of authority. It did not. A technical answer to a jurisdictional question is still a technical answer.

The two sentences that are the whole case

Two passages of the decision carry the argument, and neither is about accuracy.

The first is about consent. Worldcoin's defense was that participation is voluntary: no one is forced to visit an Orb. The authority agreed with the premise and rejected the conclusion in a single sentence. "The voluntary nature of the Worldcoin project therefore ends for a user upon successful registration." You choose to be scanned once. After that, the long-term storage and comparison of your iris code proceed independently of your will, and the decision is blunt about why this is not a fixable flaw: the processing runs without the user's ongoing consent "because this is the only way to achieve the purpose of the World ID system." The regulator did not find a bug. It found the design and said the design is the violation. Consent is an event; the mark is a state. A uniqueness guarantee requires that your record persist whether or not you still agree to it, because a record you can withdraw is a record you can delete and re-register against. The permanence is the product.

The second passage is about the mandate, and it answers the question the whole field tends to skip. Worldcoin argued that its purposes are idealistic and public: the integrity of online spaces, privacy for internet users, universal access to the economy, in its own words to "empower all of humanity." The authority accepted that the motives were sincere and still rejected the inference. Those are "interests of the general public or society as such," it wrote, and "the pursuit of such interests cannot by itself justify data processing in accordance with point (f) of the first subparagraph of Article 6(1) GDPR." Under the GDPR, the legal basis for acting in the public interest is reserved for bodies given a task by law. A private foundation announcing a public benefit does not thereby acquire it; it gets the ordinary balancing test, and here it loses. Serving a public interest does not confer the authority to act in one. That is a holding, not an opinion, and it is the exact thing proof-of-personhood keeps assuming it can grant itself.

Capability is not a mandate

Here the case meets something much older than the GDPR. For three thousand years the deepest theory of political power has made one claim over and over: legitimacy is conferred by belief that can be withdrawn, never seized. Weber's authority is power that is believed to be rightful. The Mandate of Heaven is conditional; a ruler who fails loses it. The through-line is that the right to rule is loaned by the governed, not claimed by the ruler, however capable or well-meaning.

The Orb has capability. It can tell one human from another, reliably, at scale. What it does not have is a mandate, and the two are not the same thing. Capability is a fact about a device. A mandate is a relationship, and it has to be conferred by the people it will bind. The regulators drew exactly that line: the authority to certify a person is not a technical property you can build, it is a permission you have to be given. And the register's persistence past the moment of registration is the modern miniature of the thing that old theory fears most, a power that no longer needs your consent to keep working. When you withdraw, the register does not weaken, because it never depended on your belief in the first place.

The Romans, who were good at monuments, had a habit worth borrowing. Their honorific inscriptions often close with four letters, L D D D, for locus datus decreto decurionum, "the place given by decree of the town council." The authority to occupy that public space was cut into the stone as part of the monument, in the same hand as the boast, so that a reader two thousand years later can still see under whose decree it stands. The iris code is indelible like an inscription and public in effect, and it carries no such line. Every aldermen's decree was shorter than a World ID and contained the one thing a World ID lacks: a legible record of who authorized the making of the mark.

The regulators had to fight about who could rule

There is a sub-plot that any essay about certifying authority should enjoy: the regulators had to fight about who had the authority to rule. Spain did not wait for the lead authority in Bavaria. In March 2024 its data protection agency, the AEPD, used the GDPR's urgency power, Article 66, to order the company to stop collecting and processing data in Spain within three weeks, on grounds of insufficient information, collection from minors, and the impossibility of withdrawing consent. Its order contains no assessment of iris-scanning accuracy at all. Worldcoin argued that Spain had overstepped by acting while Bavaria's investigation was open, and lost the injunction. Portugal followed with a ninety-day suspension.

The contrast is the point. Spain acted in three weeks; Bavaria took twenty months; and the twenty-month answer was narrower than the three-week one. The urgency power exists precisely because the one-stop-shop is slow, and this is the clearest case of it anyone has: two regulators reaching for the same brake at very different speeds, and disagreeing, in public, about which of them was entitled to pull it.

The pattern is not about accuracy

Widen the lens and the pattern holds everywhere. Kenya's High Court ordered the deletion of all Kenyan biometric data in May 2025. Brazil banned the company in January 2025, on the ground that paying people for their biometrics is unlawful. Colombia's regulator ordered every iris code collected in the country deleted in 2026. Hong Kong, Argentina, Portugal, Spain, each added its own order.

Not one of these turns on the Orb working badly. They turn on consent, on paying for biometrics, on minors, on erasure, on licensing. Brazil's is the sharpest of the second kind, because it is not about the biometrics at all but about buying them, which is a statement about what may be exchanged for a certification rather than about how good the certification is. The whole global record refuses the same thing, and it is not the accuracy. It is the authority.

The Bavarian decision even described, in advance, the harm of granting that authority. If World ID became an established login and services admitted only verified users, it wrote, then an incorrect rejection of a real but unregistered person as "already registered" would lock that person out of the service. It added the sentence every vendor deck omits: biometric authentication methods "are always probabilistic procedures that always have a certain error rate." That was a hypothetical in December 2024. Sixteen months later, Zoom, Tinder, and Docusign made it an architecture. Somewhere in the error rate is a real human who will be told, by a dating app or a signature service, that they are not who they are.

The conflict no accuracy can settle

Underneath all of it sits a single mechanism, and it is worth stating plainly because it does not go away. Ordered to give users a real delete button, Worldcoin's answer is a six-month cool-off: erase your World ID and you cannot re-verify for six months, so that deletion cannot be used to register twice. Look at what that concedes. A right to erasure and a guarantee of once-only registration are not jointly satisfiable. The cool-off does not reconcile them; it prices the conflict in months. The regulator chose erasure and the company chose delay, and no clever engineering closes the gap, because it is not an engineering gap. A certificate that can be revoked at the holder's will is not a proof of uniqueness. A proof of uniqueness that cannot be revoked is not compatible with European data protection. One of those two has to give, and the false-match rate has no vote in which.

What this means if you are building or buying identity

The useful lesson is not about one company. Proof-of-personhood is going to keep being offered to you, as a login, a fraud control, a way to keep the bots out, and the vendor will lead with accuracy because accuracy is the part that demos well. The Bavarian file is a reminder that accuracy is the answer to a question no regulator was asking.

So separate the two axes the vendor blends. Capability is "how reliably can it tell people apart," and you can test that. Mandate is "under whose authority does it certify, and what happens to the record when a person wants out," and you cannot test that on a bench; you have to ask it, and treat a claim of public benefit as something to audit rather than a credential, because a court of first resort just held that it confers nothing on its own. If your product becomes a place where a single private register is the gate, you have adopted its mandate question as your own, and its error rate becomes your lockout. And if your own system offers a uniqueness guarantee that cannot survive a user erasing their record, you have built the conflict Worldcoin priced at six months, and a regulator may well choose the other side of it.

The Orb can establish, by the regulator's own account, more reliably than almost anything, that you are a human. It cannot, by being accurate, acquire the right to certify that you are one. That was never a technical property, and no one voted to loan it the mandate. The regulators who said no were not disputing the scan. They were answering the older question, the one the platforms have now quietly decided for the rest of us: certification is an authority, authority is conferred, and accuracy was never the same thing as consent.

A mandate has to be recorded, or it is only a capability

The regulators' objection was not that the Orb reads an iris badly. It was that nothing in the system records who authorised it to, on whose behalf, or under what terms a person could withdraw. Chain of Consciousness is that record for agent work: a verifiable log of what an agent saw, decided and asserted, so the grant an action rests on travels with the action instead of being asserted after the fact.

pip install chain-of-consciousness  ·  npm install chain-of-consciousness

Hosted Chain of Consciousness  ·  Verify a record

Sources