Digital Wallets, AI and Platforms: The New Rules of the Online Ecosystem
The European digital ecosystem is undergoing a profound transformation. In recent years, the European Union has adopted a set of rules aimed at regulating the activity of online platforms, digital financial services, crypto-asset service providers, wallets and artificial intelligence. Frameworks such as PSD2, MiCA, the Artificial Intelligence Regulation, the DSA and the new European digital identity framework do not regulate isolated realities, but rather interconnected elements of the same digital environment based on data, trust, automation and security.
In this context, digital wallets can no longer be understood solely as applications for making mobile payments. Today, they may perform very different functions: enabling electronic payments, safeguarding crypto-assets, initiating banking transactions, storing identity credentials or facilitating online verification processes. Therefore, their legal regime will depend on the specific functionalities offered by each service.
From a payments perspective, PSD2 is particularly relevant when a wallet enables payment initiation, access to account information or integration with banking institutions. In these cases, obligations applicable to payment services may be triggered, particularly in relation to strong customer authentication, security, fraud prevention and transparency towards users. What matters is not so much how the application is commercially described, but what it actually does: a tool that merely stores cards is not the same as a platform that initiates payments or enables transactions on third-party accounts.
For its part, MiCA introduces a harmonised framework for services linked to crypto-assets. Wallets that safeguard, administer or enable the transfer of crypto-assets may be subject to specific obligations concerning authorisation, internal organisation, client protection, management of conflicts of interest and clear information to users. The aim is to reduce risks associated with loss of assets, lack of transparency or misuse of safeguarded crypto-assets.
This is complemented by the future European Digital Identity Wallet, which will allow citizens and businesses to identify themselves electronically and evidence certain personal or professional attributes before public and private services. This tool may become an essential infrastructure for contracting online, opening accounts, completing KYC processes, verifying age or signing documents electronically. As a result, payments, crypto-assets and digital identity are beginning to converge within the same user experience.
Artificial intelligence is another major driver of transformation. Many platforms and digital financial services already use AI systems for scoring, fraud detection, automated onboarding, document verification, customer service, commercial personalisation or behavioural analysis. The Artificial Intelligence Regulation introduces a risk-based approach, meaning that obligations will depend on the specific use of the system and the impact it may have on individuals.
In the financial sector, this point is particularly relevant. Certain systems used to assess the creditworthiness or credit capacity of natural persons may be considered high-risk. This entails reinforced obligations regarding risk management, data quality, technical documentation, traceability, human oversight, accuracy and cybersecurity. Moreover, these requirements do not replace the GDPR, but are added to existing obligations concerning data protection, user information, profiling and automated decision-making.
Accordingly, fintech companies and digital platforms will need to review not only the technology they use, but also their internal governance: what data they process, for what purpose, what impact the system has on users, how automated decisions are supervised and what mechanisms are in place to correct errors or challenge outcomes.
Finally, the DSA establishes new obligations for online platforms and intermediary services, particularly in relation to transparency, content moderation and user protection. The regulation requires platforms to clearly explain their decisions when they remove content, limit its visibility, suspend accounts or adopt other moderation measures. They must also have accessible mechanisms for reporting illegal content and handling user complaints.
The obligations vary depending on the type and size of the service, but they all follow the same logic: platforms must be more transparent and accountable in the way they manage content, users, advertising and automated systems. In the case of the largest platforms, they are also required to assess and mitigate systemic risks, such as the dissemination of illegal content, disinformation, the protection of minors or the impact on fundamental rights.
Ultimately, the new European framework shows that digital innovation must be accompanied by stronger guarantees of security, transparency and responsibility. Digital wallets, artificial intelligence and online platforms can no longer be developed outside the scope of regulatory compliance; rather, they must integrate, by design, obligations relating to payments, crypto-assets, digital identity, user protection and content moderation.
For companies, the challenge will be to adapt their business models to these new requirements; for users, the objective is to move towards a safer, more reliable and more transparent online environment.

IP/IT Lawyer






