Quantum-vulnerable evidence
Eligibility receipts signed with RSA or ECDSA today may still be relied on after classical public-key algorithms are deprecated. The NCSC PQC migration timelines set discovery and planning by 2028, highest-priority migration by 2031 and completion by 2035. Long-lived attestations become migration debt if they are issued on schemes that will not survive those dates.
PII on the verification path
Age gates, KYC and agent permission checks often ship names, dates of birth and document images to a vendor. That widens the breach surface, complicates DPIAs and works against the data minimisation outcomes many CAF and board-level reviews expect. The problem is architectural, not a policy memo.
Implicit trust in the network
NCSC zero trust architecture design principles assume the network is hostile and require every request to be authenticated and authorised against policy. A verification service that trusts callers by subnet, or that returns soft answers without a checkable record, does not help that model.