LegalTech leader in conversation

George Dimitrov on building digital Europe, looking beyond the textbook, and the art of asking why

Chairman of the Board of Directors at Evrotrust | Lawyer, lecturer, and expert in digital identity and trust services | Contributor to Europe's digital identity framework

George Dimitrov on LinkedIn
Illustrated portrait of George Dimitrov surrounded by digital trust and identity artwork

Growing up in Bulgaria, George Dimitrov was always drawn to the questions that didn't have easy answers. As a law student, he never imagined that one day he would help draft the rules behind Europe's digital future. Yet curiosity has a way of opening unexpected doors. Over the years, he has worked on electronic signatures, digital identity, and the legal frameworks that help people prove who they are online.

In our conversation, George talks about the idea behind Evrotrust and shares his thoughts on the European Digital Identity Wallet, why AI makes accountability more important, his hope of seeing Bulgaria become a place where digital trust can grow, and the advice he has for young people starting out in legal tech.

Decorative pillar artwork

Quick glance

A collage of George's favourites - Travelling, Exotic island, Got Talent, and Sir Isaac Newton

Q1. Hello George, it's an honor to connect with you.

You've spent so much of your career working on questions around digital identity, trust, and regulation, and you were doing this long before most people realized how important those conversations would become. Over the years, your work has gone on to contribute to some of the laws and systems that now govern digital Europe.

But behind every decorated career is a beginning that looked nothing like what we see today. Before all the recognition and responsibility, there was just a young law student with ambition, curiosity, and the willingness to go wherever opportunity took him.

When you look back at that younger version of yourself, what do you remember most? What did he think life was going to look like?

If someone had told him back then that, one day, he would help write the laws behind digital Europe instead of simply studying them, would he have believed it?

Honestly, what I remember most is the curiosity - and a certain impatience with it.

The very early school version of me was the IT guy fascinated with the magic of the first personal computers and software development. I was really amused by how people could make technology execute commands and make technological magic happen.

After graduation from school, that young version of me imagined a fairly classical path: a good lawyer, perhaps an academic. What I didn't imagine was that the field I was drawn to barely existed yet, and that "digital law" would become a discipline I'd help define rather than inherit. The law fascinated me, but I kept noticing that the most interesting questions were the ones the textbooks hadn't caught up with yet. Technology was beginning to reshape how people transacted, identified themselves, and trusted one another, and the law was several steps behind. That gap was exactly where I wanted to stand.

Would younger me have believed that he'd one day sit in working groups drafting the rules behind digital Europe rather than studying them? No - and not because he lacked ambition, but because that role simply wasn't visible from where he stood. You can't aspire to a chair that hasn't been built yet. What he did have was the willingness to walk toward the empty parts of the map. If I could tell him one thing, it would be this: The questions that don't yet have answers are not a problem to avoid; they are the whole opportunity.

Q2. Let's talk about your brainchild, Evrotrust. Within nine months of launching, you had signed contracts with 90% of the banks in the local market. And in banking, trust usually takes time.

From what we've read, the idea for Evrotrust stemmed from the uncomfortable truth that, for all the things the internet made easier, proving identity online still felt difficult and unreliable.

At what point did this become more than just an idea to you? Was there a moment when you felt, "Alright, this is worth building something around," and what gave you the confidence to commit so much of your life to solving it?

The idea didn't arrive as a single flash, rather it accumulated. For years, while I was dealing with legal issues related to internet and use of technologies, I had watched the internet make almost everything easier, except the one thing everything else quietly depends on: proving, reliably and remotely, that you are who you say you are. We had digitized documents, payments, communication. Identity was still stuck in the physical world, tied to a branch visit, a paper ID, a witnessed signature.

The moment it stopped being an idea and became a conviction was when I realized this wasn't just a feature gap but a barrier to participation. Identity is, in a very real sense, a basic human right. It is the key that lets a person take part in the economy, open an account, and access health, education, and public services. If verifying identity could be done as easily and as securely on a phone as it could in person, an enormous amount of human and economic potential would be unlocked.

Evrotrust birthday celebration 2026

What gave me the confidence to commit was that I wasn't approaching it from only one side. My world was the law and the rules that govern trust; my co-founder Konstantin understood finance and the realities of business. Evrotrust was built precisely in that overlap: Legal precision joined to technological innovation. We also made a deliberate, almost contrarian choice: The service would be free for the end user, with the party that receives the value covering the cost. The principle that identity should never be a paywall for the individual is a large part of why, within nine months, we were the contracted provider for roughly ninety percent of the banks in our market. Trust does usually take time. It moves faster when you have clearly solved a problem that everyone already knew was real.

George Dimitrov at Identity Week 2026

Q3. The EU Digital Identity Wallet is one of the most ambitious identity projects in European history, and Evrotrust has been closely involved through the WE BUILD Consortium.

As part of the project, you've been entrusted with strengthening the EUDI Wallet ecosystem so that businesses can prove who they are, manage signatory and representation rights, exchange verified data, and simplify KYC compliance processes in Europe.

What does it mean to carry that kind of responsibility? And if the EUDI Wallet develops in the way you hope it will, how do you think it will impact businesses operating across Europe?

European Digital Identity Wallet

Carrying that responsibility means remembering that we are not building a product feature. We are helping lay a piece of public infrastructure that millions of people and businesses will one day rely on without ever thinking about it. Infrastructure earns trust slowly and loses it instantly. So through the WE BUILD Consortium and the large-scale pilots, our discipline has been to get the foundations right: interoperability, security and genuine user control, rather than shortcuts that look impressive in a demo.

If the EUDI Wallet develops the way I hope, the change for businesses operating across Europe will be quietly profound. Today, a company expands into another Member State and re-encounters the same friction: re-verifying identities, reconciling incompatible national eID systems, rebuilding KYC for each jurisdiction. In a wallet-based ecosystem, a business will be able to prove who it is, demonstrate who is authorized to sign and represent it, and exchange verified attributes across borders with the same legal certainty everywhere. Onboarding that takes days could take minutes; compliance that is a cost center could become a built-in property of the transaction itself.

The principle I care about most is that this happens with data minimization at its core. The user, whether an individual or a company, shares only what a given transaction actually requires, and nothing more. If we achieve that, the wallet won't merely be more convenient. It will help make the single market genuinely single in the digital realm, which, after all, is the spirit behind Europe's goal of bringing key public services online for citizens and businesses by 2030.

Prof. D. Sc. George Dimitrov

Q4. Qualified electronic signatures carry the same legal weight as handwritten ones across the EU. But even now, many organizations still treat e-signatures as a final step instead of building processes with them in mind from the beginning.

As someone who's helped write the rules and built products that had to work within them, where do you see this going?

Could you give us a few cases where businesses underestimated the legal or compliance side of e-signatures and later ran into issues, compared to companies that approached it correctly from the beginning? What are the mistakes you see most often in this space? And what usually changes for businesses once they get this right?

You've put your finger on the single most common mistake: treating the signature as the last click rather than as a property of the whole process. A qualified electronic signature carries, by law, the same legal effect as a handwritten one across the Union. That is its power. But a signature is only ever as strong as the identity and the process behind it. If you bolt it on at the end, you inherit every weakness of the steps that came before.

I'll describe the patterns rather than name names. The first is the "final-step" company. Everything is digital except onboarding, which still drags the customer back to a branch or a courier, so an elegant signature sits on top of an analogue identity check. The second is the "wrong-level" company. It deploys a simple or advanced signature where the risk and the regulatory context actually called for a qualified one, and discovers the gap only when a transaction is challenged. The third is the "archive blind spot." The document is signed validly today, but no one asked how the integrity of the document and the validity of the signature will be demonstrable years later, which is precisely when it tends to matter most.

The companies that get it right do something deceptively simple: They design identity and trust in from the first line of the process, not the last. And what changes for them is not only compliance. The friction disappears for the customer, legal certainty rises, disputes fall, and processes that used to require human handling scale almost without limit. They stop treating trust services as a compliance tax and start treating them as part of the product. That shift in mindset is usually worth far more than the technology itself.

An illustration of electronic signatures in a digital workflow

Q5. When eIDAS first came into effect, it was the big step forward for digital trust in Europe, but the way businesses work today is completely different.

Businesses are now operating across the globe, cross-border transactions have become more prevalent, and people expect online systems to just work wherever they are.

What do you think eIDAS 2.0 gets right that the original framework couldn't quite achieve? And where do you think European businesses will notice the biggest change?

eIDAS 2.0

The original eIDAS, Regulation (EU) 910/2014 was historic. For the first time it gave electronic signatures, seals, and trust services a harmonized legal foundation across the Union, and it established mutual recognition between Member States. It deserves enormous credit. But it was written for the world of 2014, and it carried two structural limits: National electronic identity schemes remained fragmented and poorly interoperable in practice, and the private sector was largely left outside the room. Citizens often held a public eID they couldn't actually use with their bank, their insurer, or a platform.

What eIDAS 2.0 gets right is that it shifts from harmonizing back-end rules to putting a usable instrument directly into people's hands: the European Digital Identity Wallet, which every Member State must make available and which regulated private services will be required to accept. It also extends the trust-services toolbox in ways practitioners had been waiting for: qualified electronic attestation of attributes, remote qualified signing without a physical token, qualified electronic archiving, all built around selective disclosure, so the user shares only what is needed.

Where will European businesses feel it most? In the disappearance of the identity "border." The biggest practical change is that proving identity and authorization becomes portable, across the Union and across the public-private divide. A company will verify a customer or prove its own representatives' authority once, and have it recognized everywhere. For anyone operating cross-border, that is the difference between 27 integration problems and one.

Q6. Legal operations already look very different because of AI. Contracts can now be drafted, reviewed, and processed at a scale that simply wasn't possible before, but accountability still matters.

If AI helps produce a document, a qualified electronic signature is added at the end, and the audit trail looks perfect, who is actually responsible for what happened in the middle?

And when you look at how quickly AI is changing legal work, do you think Europe's careful approach is right? Or do you worry it could make it harder for legal teams and businesses to keep up with how fast everything is progressing?

This is the question I find most important, because it goes straight to the difference between automation and accountability. AI can now draft, review, and process contracts at a scale that was simply impossible a few years ago. But a qualified electronic signature at the end and a flawless audit trail only tell you that a document was signed and was not altered. They say nothing about whether the judgment in the middle was sound. Integrity of the file is not the same thing as integrity of the reasoning.

My answer is unambiguous: Responsibility cannot be delegated to a model. The professional who relies on the output: the lawyer, the institution; remains accountable for it. AI is an extraordinarily capable assistant, but it bears no duties. It cannot be admitted to a bar, and it cannot stand behind its own advice. So the "middle" must always contain a human being who reviewed, understood, and owns what was produced. In my own work the rule is simple and non-negotiable: no fabricated sources or citations, explicit flagging of uncertainty, and mandatory human review of anything an AI helped generate.

Do I think Europe's careful approach is right? On balance, yes, but with one caveat. In domains built on trust, moving carefully is not the opposite of progress; it is the precondition for it. People will only hand serious decisions to digital systems if those systems are demonstrably trustworthy, and that is exactly what a risk-based framework tries to secure. The real danger is "careful" curdling into "slow" when rules are written without the people who have to implement them. The answer is better-designed regulation, built together with practitioners, so the guardrails enable speed rather than smother it.

Q7. You've spoken before about problem solving and problem framing. That way of thinking is very relevant in regulated industries, where companies can spend years building something well only to realize they were solving the wrong problem to begin with.

Where did that mindset come from for you? Can you think of a time in your career when changing the question changed the direction you took or led to a better result than the one you originally planned for?

The mindset came, I think, from living at the seam between two disciplines. A lawyer is trained to ask "Is this permitted?" An engineer asks "Can this be built?" When you spend your career in the overlap, you learn that the most expensive mistakes happen when everyone answers their own question correctly, and no one asks whether it was the right question to begin with. In regulated industries especially, you can build something beautifully and lawfully and still discover, years later, that the problem itself was framed wrong at the start.

Here's a concrete example from Evrotrust. The industry had accepted a particular framing: "Users pay for certificates." That was simply how trust services had always worked. The reframing that changed our direction was to ask who actually receives the value when an identity is verified or a document is signed. Put that way, the answer is obvious. Usually it's the bank, the institution, or the relying party, not the individual. So we inverted the model to be free for the end user, with the party that captures the value covering the cost. That single change of question turned a fee the user resented into infrastructure the user benefited from, and it was a major reason adoption moved as fast as it did.

The lesson I keep returning to is that speed applied to the wrong question only gets you to the wrong place faster. Time spent framing the problem is never time lost.

Q8. Every year, Sofia hosts Digitalization360, Evrotrust's flagship event, bringing together people from law, technology, policy, and business under one roof. Over time, it has become an important meeting point for conversations around digital trust in Southeast Europe.

When you look around the room at an event like that, what makes you feel all the effort has been worth it? And years from now, what would you love to see come out of the community you're building?

What makes it worth it is a very specific kind of moment. You look around the room of this event, organized by Evrotrust and you see a banker, a regulator, a software engineer, a policymaker, and an academic actually talking with one another, not past one another. For most of my career those worlds spoke different languages and tended to meet only when something had already gone wrong. To see them in the same room, by choice, working out the future of digital trust together is the thing I find moving. It tells me the conversation has matured from "Is this legal?" to "How do we build this well, together?"

There's also a national dimension I won't pretend not to care about. These gatherings are part of a deliberate effort to position Bulgaria as a genuine innovation hub, to show that serious, standard-setting work in digital identity and trust can come from here and be recognized across Europe. Evrotrust plays a key role in this digital transformation.

Years from now, what I'd love to see come out of the community is that it has outgrown any single company, including ours. The real measure of success is not how many people attend an event. It's whether the network keeps producing trust: interoperable systems, sensible rules, young professionals who move easily between law and technology, long after, and independently of, whoever convened the first meeting. If the community we're building ends up needing none of us in particular, then we will have built something that actually lasts.

Digitalization360 event in Sofia

Q9. You received a Changemaker Award at Webit 2025, a People of the Future recognition by BGLOBAL, and a Global Elite Thought Leader ranking by Lexology Index, and we're sure that's only part of the story.

Your work has earned respect across the industry over the years, but even the most accomplished careers come with periods of uncertainty. Was there ever a phase where you found yourself wondering how things would turn out?

For young professionals entering legal tech today, still finding their feet and maybe feeling a little overwhelmed by how much still remains unsolved, what would you want them to remember?

Thank you, though I'd gently say that awards are lagging indicators. They recognize work that was mostly done years earlier, often in conditions that felt nothing like recognition at the time.

Was there uncertainty? Constantly. When you choose to work at the edge of a field that doesn't fully exist yet, uncertainty is the working environment. There were long stretches when we were betting that the world would move toward digital trust before it was at all obvious that it would; when the regulation we were building products against was still being written; when "too early" and "simply wrong" look identical from the outside. Conviction in those moments comes from being certain about the problem, and the problem of trusted digital identity was always real, whatever the timing.

To a young professional entering legal tech today and feeling overwhelmed by how much is still unsolved, I'd say this: The unsolved part is not a sign that you're late, rather the reason there's a place for you at all. My generation got to help write some of the first rules. Yours will work in a world where law, technology, and ethics are inseparable, and that demands a new kind of professional who is fluent in all three. Don't wait to feel ready, because in a new field, no one ever does. Pick a real problem, learn it more deeply than anyone around you, and stay honest, especially about what you don't yet know. Reputations in this space are built slowly, and on exactly that honesty. Pay particular attention to the legal effects of AI and quantum computing. These will change the world in the forthcoming years. Keep dreaming, but be brave to make the dreams come true without hesitation.

George Dimitrov's Global Elite Thought Leader ranking by Lexology Index

Q10. George, you've given thoughtful answers throughout this conversation, but we're afraid the professor hat comes off now.

Please give us the first thing that comes to mind for each of these:

An activity outside work you'd drop everything for: Traveling

Your idea of a perfect vacation: Exotic island in the middle of the ocean

A TV show you've watched more times than you'd like to admit: Bulgaria/America/Britain's Got Talent

One historical figure you'd love to have dinner with: Sir Isaac Newton

Thank You

Our heartfelt thanks to Prof. D. Sc. George Dimitrov for his time and for sharing the stories and lessons behind his work, and filling this conversation with the kind of wisdom that comes only from years of experience, resilience, and conviction.

His belief that good ideas begin with asking the right questions and taking the time to solve the right problems is something we'll carry with us. We also hope he never loses his willingness to keep walking toward the empty parts of the map.

We deeply appreciate his contributions to digital identity, trust services, and the foundations of digital Europe, and wish him continued success in everything that lies ahead.