Sharing chemistry data without leaking your recipe: zero-knowledge proofs for batteries
From 18 August 2031, new EV and industrial batteries must contain at least 16% recycled cobalt, and manufacturers must prove it to readers they do not fully trust. Zero-knowledge proofs let a passport verify a claim like "over 16% recycled cobalt" while the formulation stays sealed. An NDA promises silence; cryptography enforces it.
From 18 August 2031, every new industrial and EV battery placed on the EU market must contain at least 16% recycled cobalt, 6% recycled lithium, 6% recycled nickel and 85% recycled lead, with the shares rising again in 2036. Those percentages must be declared and verifiable, yet the data behind them, exact cathode formulation, supplier batches, material masses, is among the most commercially sensitive information a battery maker owns. The battery passport puts that tension on a deadline: from 18 February 2027 composition and dismantling data must be readable by recyclers, some of whom are owned by competitors. This article explains, without any mathematics, how zero-knowledge proofs let a passport verify a claim like "contains over 16% recycled cobalt" while the recipe itself stays sealed.
What data does the regulation force manufacturers to share?
Regulation 2023/1542 attaches more than 90 mandatory data attributes to the passport of every EV, LMT and industrial battery above 2 kWh. Several of them sit uncomfortably close to trade secrets:
- Composition and chemistry. Critical raw materials, hazardous substances, cathode and anode chemistry. Recyclers need this to sort packs safely and price the recoverable material.
- Dismantling and safety information. Disassembly sequences, fastener types, hazmat warnings. Indispensable on the intake line, and a detailed map of how your pack is engineered.
- Recycled content shares. The percentage of recycled cobalt, lithium, nickel and lead, which from 18 August 2031 becomes a legal minimum, not a marketing claim.
The regulation also decides who reads what. Access comes in three tiers: the public, persons with a legitimate interest (explicitly including recyclers and second-life operators), and market-surveillance authorities plus the Commission. A manufacturer cannot pick its readers. Any facility that ends up handling the pack, fifteen years and three owners later, qualifies for the professional tier, and that facility may well be a subsidiary of a rival.
Why don't NDAs and data rooms solve this?
The traditional answer to sensitive data sharing is legal and procedural: sign a non-disclosure agreement, open a data room, log who saw what. For the passport's problem, that toolbox has three structural flaws.
- NDAs are remedies, not controls. A contract does not prevent disclosure; it prices it after the fact. Enforcement means litigation, often across jurisdictions, and proving that a competitor's improved formulation came from your leaked data is close to impossible.
- Data rooms restrict copying, not learning. A controlled viewing room stops downloads, but the value of a formulation transfers the moment a competent chemist reads it. Once seen, it cannot be unseen.
- Bilateral agreements do not scale to an open reader class. The passport follows the pack for its whole life. You would need an NDA with every recycler, second-life operator, auditor and importer who might ever scan it, most of whom you cannot name today. The regulation defines an access tier; you cannot put a tier under contract.
There is also a quieter cost. Every audit under the NDA model is another full disclosure: the notified body verifying your 2031 recycled-content declaration reads the same sensitive inputs again, and your exposure grows with every verification cycle.
How can you prove a claim without revealing the data?
A zero-knowledge proof separates two things we normally bundle together: the claim and the data behind it. The everyday analogy is age verification. To prove you are over 18, you hand over an identity card that also reveals your exact birth date, address and ID number. A zero-knowledge version would confirm the single fact "over 18" and nothing else. The verifier ends up certain, and no wiser.
Applied to battery data, the mechanics have three parts, none of which require the reader to see the secrets:
- A commitment. The confidential data (formulation masses, supplier batch records) is locked into a short cryptographic fingerprint published in the passport. Like a sealed, tamper-evident envelope: it fixes the data at a point in time without showing it, and it cannot be quietly swapped later.
- A proof. From the sealed data, the manufacturer generates a small file demonstrating that a precise statement holds, for example "the recycled share of cobalt in this committed formulation is at least 16%". The proof is derived from the data but reveals nothing about it beyond the statement itself.
- A verification. Anyone holding the proof and the fingerprint can run a public check that passes only if the statement is true. No callback to the manufacturer, no access request, no trust required. Forging a proof for a false statement is computationally out of reach.
That last property is the important one. The verifier is not trusting the manufacturer's honesty, an auditor's signature or a contract's deterrence. The check either passes or it does not. This family of techniques has been running in production payment and identity systems for years; it needs standard servers, not exotic hardware.
What does a recycled-content proof look like in practice?
Follow one kilogram of cobalt through the loop. A recycler shreds end-of-life packs and produces a batch of recovered cathode material, with certified mass and provenance recorded at the facility. That batch record links, passport to passport, into the new cell's production data. At declaration time the manufacturer's confidential inputs, batch certificates on one side and exact formulation masses on the other, feed the computation "recycled cobalt divided by total cobalt is at least 0.16", and a proof of that statement is attached to the new battery's passport.
Now look at who sees what. The notified body verifies the proof in seconds and signs off the declaration required from 18 August 2031, without ever opening the formulation. A competitor scanning the passport sees a verified "at least 16%" badge and nothing more. That granularity matters: even the exact figure is competitive information, because a manufacturer running at 24% recycled cobalt is telling the market something about its sourcing position that one running at 16.5% is not. The threshold proof discloses neither.
The same pattern covers other claims the passport carries: a hazardous substance below its limit, a carbon footprint below a performance-class ceiling, due diligence coverage across cobalt, lithium, nickel and natural graphite suppliers ahead of the 2027 obligation. Wherever the requirement is a threshold and the evidence is a secret, a proof fits.
How do zero-knowledge proofs fit the passport's access tiers?
The access tiers and the proofs answer two different questions. The tiers decide who may read which fields. The proofs shrink what each tier needs to read in the first place.
On the public tier, sustainability claims stop being assertions: recycled-content and footprint statements ship with proofs any browser can check. On the legitimate-interest tier, a recycler receives exactly the operational data the job requires, disassembly sequence, hazmat flags, chemistry class and expected material yield, while formulation-level detail stays sealed behind commitments, with proofs guaranteeing that the sealed data supports every claim made about it. Authorities keep their full powers: a market-surveillance body can still compel the underlying records in a dispute. But the routine case, thousands of declarations verified per year, runs proof-first, and each verification adds zero disclosure.
That is the design principle in one line: minimum disclosure per reader, full verifiability for every reader.
Conclusion: prove it, don't publish it
The regulation forces a choice that contracts were never built to arbitrate: recyclers and auditors must be able to rely on your chemistry and recycled-content data, and your competitors must not learn your recipe from it. Zero-knowledge proofs dissolve the dilemma by making claims verifiable without making data visible. The manufacturers who adopt them will meet the 2031 recycled-content mandate with their formulations exactly as private as they were the day before.
Passoria's zero-knowledge vault issues these proofs on top of our recycled-content chain of custody, so the claim, the lineage and the verification travel with the passport. If you would rather prove your quotas than publish your recipe, our pilot program is open to manufacturers, resellers and recyclers.