Skip to main content
TECH_SCIENCE15 / 18 · story of the day3 min · 711 words · 24 sources

Estonia plans digital IDs for AI agents

Written by AIto brief AI · 7 July 2026, 02:50
How it was written

Estonia seeks to separate the software deputy from the citizen's wholesale digital identity.

Image composition · tobrief
the text · 3 min read

Every time software acts on your behalf online, it borrows your identity wholesale. Your login, your permissions, your legal name. The digital equivalent of handing a courier your passport, house keys and bank card to deliver one package. Estonia thinks there's a better way.

An advisory council called Eesti.ai, created at Prime Minister Kristen Michal's initiative, has agreed that Estonia should develop a separate digital identity for AI agents. Local media call it an "AI-isikukood," borrowing the name of the personal identification code that underpins the country's digital state (ERR). The proposal is narrower than the label suggests: not an identity that makes software a person, but one that prevents software from having to impersonate you.

The digital deputy

Think of it as three layers. A badge identifies which software agent showed up. A permission slip defines what it may do, for whom, within what limits. A receipt logs what actually happened. Today, most AI tools operate with only the first layer, if that. An agent filing your taxes or querying government records often does so under your full credentials, with access to far more than the task requires.

Technology entrepreneur Kaspar Korjus offered a concrete example: an AI agent with its own identity could prepare tax declarations on someone's behalf, while sensitive actions like moving money would stay under human control (Äripäev). The useful model is a tightly scoped deputy, allowed to read this record and draft that form, while the citizen stays the legal principal and can revoke the delegation at any time (Global Relay).

Estonia can propose this because its digital plumbing already works. Its eID system handles national identification (e-Estonia), and X-Road provides secure data exchange between services and registries (e-Estonia). An agent identity would sit on top of that infrastructure, not replace it. But no law has been enacted and no technical specification published. This is a policy direction, not a finished system.

The permission slip Europe hasn't written

The sharpest criticism is that identity solves the wrong layer. Estonian commentator Peeter P. Mõtsküla framed it bluntly: the real question isn't "who is the agent?" but "what may it do, and who answers for it?" (ERR). Germany's federal cybersecurity chief Claudia Plattner warned that standards for managing AI agents' identities are lacking, particularly when those agents act for companies in email or online services (FAZ). German security analysts already classify AI agents as "non-human identities," meaning machine accounts whose credentials often go unmonitored and quietly accumulate broad access (Security-Insider).

Europe already has rules for proving who you are (eIDAS 2.0), limiting what data you reveal, logging AI systems (AI Act), protecting personal data (GDPR) and securing network access (NIS2). What it lacks is one rulebook for a software deputy that crosses all four. No single regulation covers the full stack: identifying the agent, defining its mandate, logging its actions and assigning liability when something goes wrong.

That liability gap is the most uncomfortable part. A digital badge does not answer who pays when delegation fails: the company that built the model, the business that deployed it, or the organisation that authorised the agent to act (FAZ). The EU's AI Liability Directive, designed to address exactly this, remains a proposal (AI Liability Directive).

Whose badge, whose rules

Each member state is approaching the same problem from a different angle. Denmark's AI sandbox layers delegation over its existing national login system, MitID (Datatilsynet). The Netherlands publishes a public register of government AI systems, treating accountability as administrative practice (Algoritmeregister). Sweden is working through how to certify the digital wallets that eIDAS 2.0 envisions, essentially tamper-proof apps on your phone that prove one fact about you, such as age or residency, without handing over the whole ID file (DIGG).

This fragmentation reveals the real test ahead. An AI agent authorised in Estonia may need to be trusted by a Danish login system, audited under Dutch accountability rules, and secured against the kinds of machine-account abuse German regulators already worry about. Estonia can build the badge. The next job belongs to European regulators and standards bodies: making sure a deputy authorised in one country can be checked, limited and held accountable in another.

How was this article?

Help us get better

Details about this article
Model:
claude-opus-4-6
Generated:
7/7/2026, 3:07:10 AM
Pipeline run:
eu_pipeline_20260707_005006
Watermark:
SynthID (Google's invisible watermark)
Human review:
None before publication
Learn more about our methodology