Spherity

Spherity Research

Research for the systems we need to trust.

Evidence-led work on Digital Product Passports (DPPs), organizational identity, verifiable credentials, European Business Wallets (EBW), trusted AI, and the cryptographic infrastructure behind the real economy.

Research by Dr. Carsten Stöcker Spherity GmbH

DPP & DBP Identity Data sharing Resilience Trusted AI

Research scope

Identity, evidence and trusted execution across the real economy.

Spherity Research examines how organizations, products, AI agents and machines can establish identity, authority, provenance and trustworthy evidence across regulated digital systems. The current agenda spans Digital Product Passports (DPPs), Digital Battery Passports (DBPs) and Cyber Resilience Act (CRA) product-evidence infrastructure; European Business Wallets (EBW), Data Spaces and governed data sharing; Trusted AI, Industrial AI and Physical AI, including functional-safety and cyber assurance for robots; post-quantum resilience; and European AI competitiveness through trusted execution and industrial renewal.

Open-access papers, executive briefs and policy roadmaps connect architecture, regulation and operating models for policy makers, industry leaders, researchers and technology teams.

Research library

Current publications

Long-form papers, executive briefs, roadmaps and visual explainers for decision-makers building trustworthy digital ecosystems.

Social preview for the energy data-X journal article on European Business Wallets, market-role credentials, BESS data exchange, and controlled DPP access. HTML + PDF
Journal article

European Business Wallet and Market Role Credentials for DPP Access Control: The energy data-X Reference Case

An energy data-X case study showing how European Business Wallets, governed market roles, and policy engines enable controlled DPP, DBP, and BESS data access.

  • European Business Wallet
  • energy data-X
  • DPP & DBP
Cover of European Business Wallets as the Legal Control Plane for Zero Trust AI Agents HTML + PDF
Featured paper

European Business Wallets as the Legal Control Plane for Zero Trust AI Agents

The control-plane architecture for proving who an AI agent represents, which mandate applies, and whether each cross-company action is permitted.

  • European Business Wallet
  • Zero-Trust AI
  • Organizational identity
Preview of Quantum-Resilient Organizational Identity HTML + PDF
Research paper

Quantum-Resilient Organizational Identity

A governance and systems architecture for organizational identity, quantum-safe trust infrastructure, business wallets, and repeatable PQC Corridors.

  • Organizational identity
  • PQC Corridors
  • Trust infrastructure
Spherity Research preview for securing digital identity and verifiable credential wallets against quantum risk. HTML
Research paper

Securing Digital Identity and Verifiable Credential Wallets against Quantum Vulnerabilities

An attack taxonomy, macro-economic risk model, and migration strategy for post-quantum identity corridors.

  • Post-quantum cryptography
  • Digital identity
  • Verifiable credentials
Spherity Research preview for the legal and operational European Business Wallet roadmap toward EU-wide acceptance by 2029. HTML
Roadmap

Legal & Operational EBW Roadmap Toward EU-Wide Acceptance

Milestones, dependencies, standards, and adoption gates for the European Business Wallet under eIDAS 2.0.

  • European Business Wallet
  • eIDAS 2.0
  • EU adoption
Spherity Research preview for the cross-domain AI, cyber, quantum, hybrid-warfare and Physical AI risk model for Germany and Europe. HTML
Policy paper

AI-Cyber, Quantum Risk, Hybrid Warfare, and Physical AI

A cross-domain escalation and operational-readiness model for German and European decision-makers.

  • AI risk
  • Cyber resilience
  • Hybrid warfare

Market position

Spherity in the Gartner® Emerging Market Quadrant for Digital Product Passport — Established Vendors

Read the strategy paper

Gartner® published the Emerging Market Quadrant for Digital Product Passport — Established Vendors on 6 July 2026. Spherity is positioned as the sole vendor in the Pioneers quadrant. [1]

At Spherity, we see our identity-first strategy as the foundation for a wider trust architecture that extends from physical-product DPPs to AI Service Passports for AI systems and services. This extension reflects our own strategic outlook and was not part of Gartner's DPP evaluation.

Spherity treats the Gartner placement as one independent market perspective. Spherity's own view is that its technology leadership in identity-first and cyber-secure DPP infrastructure rests on its architecture, regulated production experience and partner ecosystem. The strategic objective is to make product data trustworthy, usable across company boundaries and suitable for automated decisions.

[1] Emerging Market Quadrant for Digital Product Passport — Established Vendors, 6 July 2026, Gartner document 8098797.

Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.

GARTNER is a trademark of Gartner, Inc. and/or its affiliates.

DPP & DBP infrastructure

Product evidence is useful only when access and authority are verifiable.

Digital Product Passports and Digital Battery Passports need more than a product record. They need trustworthy evidence, governed disclosure and accountable actors across the product lifecycle.

Read Verifiable, Access-Controlled Digital Product Passports
01 · Product plane

Verify the product and its evidence.

Product-linked identity connects identifiers, provenance, lifecycle claims, conformity data, SBOM and VEX records, and evidence-graph relationships.

02 · Authority plane

Verify the organization and its right to act.

European Business Wallets connect legal-person identity, roles, mandates, authorization policies and action evidence to each disclosure or transaction.

03 · Controlled exchange

Release the right evidence to the right party.

Machine-readable policy evaluates role, purpose, context and current status before product data crosses company, sector or jurisdictional boundaries.

Trusted Industrial AI

Two trust planes. One accountable system.

Regulated AI needs separate, interoperable evidence for legal authority and for the facts supporting a decision.

01 · Control plane

Who is authorized to act?

European Business Wallets connect legal-person identity, agent identity, bounded mandates, current status, policy decisions, and action receipts.

Read the control-plane paper
02 · Data plane

What evidence supports the action?

Evidence graphs connect provenance, validation, freshness, transformations, conflicts, uncertainty, issuer status, and auditable evidence paths.

Read the data-plane paper

A valid mandate does not prove that an AI output is factually supported. Reliable evidence does not prove that an AI agent was legally authorized to act. Regulated AI systems require both layers.

Quantum-resilient trust

Organizational identity is infrastructure.

B2B, B2G, G2G, machine, and AI-agent ecosystems depend on proving which organization is acting, under which authority, and whether the complete trust chain remains valid as cryptography changes.

01 · Establish authority

Prove the organization and its mandate.

Bind legal existence, representation rights, roles, licenses, delegated authority, purpose, and validity periods into reusable organizational credentials.

02 · Map the trust fabric

Inventory every dependency that makes the proof reliable.

Cover issuers, wallets, verifiers, trust anchors, status, revocation, registries, qVDR functions, DNSSEC, WebPKI, semantics, vendors, and long-term evidence.

03 · Launch a PQC Corridor

Migrate a bounded high-value ecosystem together.

Align actors, assurance, evidence horizons, trust boundaries, hybrid or post-quantum profiles, downgrade rules, lifecycle controls, and reusable conformance evidence.

Algorithm replacement alone cannot preserve legal reliance when counterparties, trust anchors, status services, lifecycle controls, and evidence do not migrate coherently.

Read the PQC Corridor paper

Research FAQ

What questions does Spherity Research answer?

Concise answers with direct links to the underlying open-access research, executive briefs and policy roadmaps.

01

Europe, AI and industrial renewal

Strategy and policy questions about trusted execution, competitiveness and coordinated transformation.

How can Europe turn trust into a production factor for AI productivity and industrial renewal?

Europe can convert its legal, institutional and industrial strengths into trusted execution capital: reusable identity, authorization, evidence and accountability infrastructure that lets organizations act faster without weakening control.

Read Europe’s Fundamental AI Opportunity

How can Deutschland AG 2.0 connect metropolitan regions, Industrial AI, sustainability, security and resilience?

The proposed model treats Germany as a federated transformation system in which metropolitan regions, industry, the Mittelstand, research and government share missions, interoperable infrastructure, decision rights and measurable outcomes.

Read the Deutschland AG 2.0 paper

How do China, Europe and the United States compare in trusted agentic AI deployment capability?

The three regions combine scale, regulation, industrial capacity and digital infrastructure differently. Europe’s opportunity is to make verifiable authority, evidence provenance and accountable execution a practical advantage for Industrial AI and Physical AI.

Read the China–EU–US comparative analysis

Which German companies form a strategic stack for Industrial AI, Physical AI and trusted agentic commerce?

The research identifies ten emerging companies and complementary corporate anchors across AI, automation, robotics, energy, autonomous systems and cross-company trust infrastructure, using an explicit selection method rather than a valuation ranking.

Read the German technology outlook
02

DPP, DBP, wallets and data sharing

Implementation questions about product evidence, regulated access and reusable organizational authority.

How can CRA-capable Digital Product Passports turn static compliance into continuous cyber assurance?

A CRA-capable DPP can connect signed SBOM, VEX, vulnerability, conformity and lifecycle evidence in an access-controlled evidence graph, giving manufacturers and authorized parties current, verifiable product-security information.

Read the CRA-capable DPP research

How can DPP and DBP transactions verify both product evidence and the legal authority to act?

The architecture links product-bound identity and evidence with legal-person identity, verifiable credentials, mandates and policy checks, so a relying party can verify both what is claimed about a product and who is authorized to disclose or act on it.

Read Verifiable, Access-Controlled Digital Product Passports

How can European Business Wallets and market-role credentials control DPP, DBP and BESS data access?

European Business Wallets can present verifiable company and market-role credentials to a policy engine, which evaluates purpose, role, mandate and context before granting access to sensitive product or energy data.

Read the energy data-X reference case

How does Spherity connect its Gartner® Pioneers position to DPP, DBP, EBW and Trusted AI execution?

Spherity treats the Gartner placement as one independent market perspective and describes an identity-first strategy that connects cyber-secure DPP and DBP infrastructure with European Business Wallets, governed data sharing and a longer-term AI Service Passport outlook.

Read Spherity’s DPP and DBP strategy paper

Which legal and operational gates shape European Business Wallet adoption?

Adoption depends on legislation, implementing acts, standards, wallet and trust-service readiness, governance, conformance testing, procurement and viable cross-border use cases progressing in a coordinated sequence.

Read the European Business Wallet roadmap
03

Identity, evidence and resilience

Architecture questions about accountable AI, provenance and migration of the trust fabric.

How can verifiable safety and cyber evidence graphs accelerate compliant Physical AI deployment?

PACE binds product identity and the current configuration to scoped safety, cybersecurity, AI and lifecycle evidence. This helps qualified parties find affected claims, tests and missing evidence faster after a change while deterministic safety controls and human assessment remain authoritative.

Read the PACE Physical AI research

How can Industrial AI trace provenance, validation, freshness and conflicting evidence across organizations?

Evidence graphs represent claims, sources, issuers, transformations, validation status, timestamps, conflicts and uncertainty as connected evidence paths that people and machines can inspect and audit.

Read the Industrial AI evidence-graph paper

How can organizations establish a governed, PQC-resilient digital corridor?

Organizations first establish accountable identity and mandates, then map issuers, wallets, verifiers, trust anchors and lifecycle dependencies before coordinating assurance levels, cryptographic profiles, downgrade rules and migration evidence within a bounded ecosystem.

Read the PQC Corridor paper

Which digital-identity dependencies must migrate for post-quantum readiness?

Migration must cover more than algorithms: keys, certificates, trust anchors, wallets, registries, status and revocation services, protocols, vendors, governance and long-lived evidence all need crypto-agile transition plans.

Read the quantum-vulnerability research

How can Germany and the EU test readiness across coupled technology risks?

Decision-makers can use cross-domain scenarios to test how cyber, AI, quantum, hybrid and physical risks reinforce one another, then assign indicators, owners, thresholds and coordinated response actions.

Read the integrated threat model

Open research

Read it. Test it. Build on it.

The publication source is maintained openly on GitHub for stable linking, transparent revision, and long-term discoverability.

Open the repository