A white paper by Roland Fadrany, Chief Operations Officer, and Christoph Strnadl, Chief Technology Officer at Gaia-X, published in the June edition of Gaia-X Magazine, details how the updated Trust Framework enables ecosystems to build compliant data spaces without centralised control.

Framework expansion and core challenges

The Gaia-X Trust Framework now accommodates Domain and Geographical Extensions, allowing vertical industries and regional bodies to establish data spaces under a shared trust architecture. The Trust Protocol operationalises trust-building between different ecosystems and jurisdictions in a fully interoperable manner.

As data space deployments expand across sectors and regions, several recurring obstacles have surfaced. Multiple ecosystems resist depending on a single centralised operator, regions demand locally controlled Participant IDs and Trust Anchors, and cross-ecosystem interoperability remains critical along complex value chains. Credentials must be universally verifiable, data spaces must rapidly establish trust with peers and participants, and onboarding systems must scale automatically to support expansion.

Domain Extensions: enabling ecosystem autonomy

Gaia-X addresses these issues through a layered extension model supporting multiple coexisting configurations. Domain Extensions permit individual ecosystems to designate a custodian—typically an industry or regional governance body—that sets domain-specific rules, certifications, trust anchors, and labels while maintaining mandatory use of the Gaia-X Participant ID and optional use of Gaia-X Label Levels 1–3.

Many established ecosystems align structurally with the Domain Extension model. Their existing governance bodies function effectively as domain custodians. Under Gaia-X 3.0 ("Danube"), a domain custodian no longer requires Gaia-X Label Levels 1–3, substantially lowering adoption barriers. Domain Extensions can be processed through any Gaia-X Digital Clearing House (GXDCH), or through dedicated, ecosystem-operated GXDCHs that remain fully interoperable with the broader GXDCH network.

Benefits of domain extensions

  • Universal recognition: ecosystem participants gain acceptance across all cooperating Gaia-X ecosystems
  • Simplified global expansion: Geographical Extensions and distributed GXDCHs enable multi-region verification without architectural complexity
  • Ecosystem growth: operators can accelerate onboarding of adjacent industries such as manufacturing, logistics, energy, healthcare, and finance
  • Clean architectural separation: a clear boundary between the common Trust Framework and specific functions such as the data space connector, which executes access and usage control policies

The Trust Protocol and cross-ecosystem verification

When an ecosystem relies on a single, nationally based clearing house for issuing credentials as its trust framework foundation, resistance emerges during interaction with other ecosystems, which typically will not accept a single foreign clearing house as a trust service provider. National restrictions may also prevent non-local clearing houses from accessing and verifying foreign identity certificates—for instance, where only national IP addresses or registered national companies can query company registries.

The Gaia-X Trust Protocol allows any ecosystem to accredit entities as trust service providers for arbitrary trust scopes, not limited to identity or services, nor to any single nationality. Examples include IoT devices, AI agents, data space connectors, machine standards such as OPC UA, digital product passports, and any identifiable entity. By exposing an ecosystem's list of trust service providers and their respective trust scopes and credentials in ecosystem trust profiles within the Gaia-X Meta-Registry, one ecosystem (the trustor) can establish selective trust relationships with other ecosystems (the trustee).

Strategic benefits of the Trust Protocol

  • An ecosystem can keep or extend its current trust profile
  • Other ecosystems can establish and keep their own trust profiles
  • An ecosystem can establish unidirectional trust for selected trust scopes with other ecosystems complying with the Gaia-X Trust Protocol
  • Other ecosystems can establish unidirectional trust for selected trust scopes in return
  • Mutual trust can be established between two ecosystems for selected trust scopes
  • Seamless interoperation with other ecosystems at the trust plane

Implementation roadmap

Gaia-X proposes a co-creation initiative targeting readiness for the Gaia-X Summit in November. The effort focuses on three credential types: Membership Credential, Participant Identification Credential, and Framework Agreement Credential.

  1. Deploy a Domain Extension Engine on Danube. Implement a dedicated extension engine on the Gaia-X 3.0 "Danube" platform, enabling GXDCHs to simultaneously issue and verify both Gaia-X and domain-specific credentials within a single, unified workflow.
  2. Decouple Verification from Access Management. Separate credential verification (handled by a dedicated clearing house) from access and rights management (handled by the connector). This architectural decoupling improves modularity and cross-ecosystem interoperability, and significantly simplifies the onboarding of new participants through automation.
  3. Demonstrate Cross-Ecosystem Trust using the Gaia-X Trust Protocol. Use the Danube platform to illustrate how the Gaia-X Meta-Registry and its Ecosystem Trust Profiles enable cross-ecosystem trust—building on proven precedents such as the IMXC use case, the Myrtus data space, available regional company-number extensions, and the generic company-number AI-agent.

Gaia-X AISBL is committed to supporting this approach and will provide active technical and governance assistance to ensure readiness in time for the Gaia-X Summit.

Conclusion

Integrating Domain Extensions and the Gaia-X Trust Protocol into any vertical or regional ecosystem represents a natural and strategically sound evolution. By formally adopting the Gaia-X Domain Extension model, ecosystem participants gain global interoperability without surrendering existing governance structures or credential frameworks. The proposed Domain Extension Engine on Danube provides a technically sound, standards-compliant implementation path that positions any data space for scalable, trusted, cross-industry and cross-region collaboration.