Skip to main content
TECH_SCIENCE15 / 18 · scéal an lae3 nóim · 811 focal · 24 foinsí

Estonia Plans IDs for AI Agents

Scríofa ag ISto brief AI · 7 Iúil 2026, 02:50
Conas a scríobhadh é

Estonia seeks to separate the software deputy from the citizen's wholesale digital identity.

Cumadóireacht íomhá · tobrief
an téacs · 3 nóim léitheoireachta

Every time software acts for you online, it tends to borrow your whole digital self. Your login, your permissions, your legal name. It is the online version of giving a courier your passport, house keys and bank card because you need one parcel delivered. Estonia, which has spent three decades turning the state into something citizens can actually use online, thinks that arrangement is too crude for the age of AI.

An advisory council called Eesti.ai, set up at the initiative of prime minister Kristen Michal, has agreed that Estonia should develop a separate digital identity for AI agents. Local press have called it an "AI-isikukood", borrowing the term for the personal identification code at the centre of Estonia's digital state (ERR). The idea is less dramatic than the name sounds. It would not turn software into a legal person. It would stop software having to pretend to be you.

The digital deputy

The proposal is easiest to understand in three parts. First, a badge says which software agent has arrived. Second, a permission slip says what it is allowed to do, for whom, and within what limits. Third, a receipt records what actually happened. Most AI tools today have only the first layer, if they have even that. An agent filing a tax return or checking a government record often does so using the person's full credentials, with access to far more than the task requires.

The technology entrepreneur Kaspar Korjus has given a practical example: an AI agent with its own identity could prepare tax declarations for someone, while sensitive actions such as moving money would remain under human control (Äripäev). The model is not autonomy in the science-fiction sense. It is a tightly limited deputy, allowed to read this record and draft that form, while the citizen remains the legal principal and can withdraw the delegation at any point (Global Relay).

Estonia can make this argument because the pipes are already in the ground. Its eID system handles national identification (e-Estonia), while X-Road allows secure data exchange between public services and registries (e-Estonia). An AI-agent identity would sit on top of that machinery rather than replace it. But there is no law yet, and no published technical specification. For now, this is a direction of travel, not a working system.

The permission slip Europe hasn't written

The strongest criticism is that identity answers only the first question. The Estonian commentator Peeter P. Mõtsküla put the issue plainly: the harder question is not "who is the agent?" but "what may it do, and who is responsible for it?" (ERR). Claudia Plattner, Germany's federal cybersecurity chief, has warned that standards for managing AI-agent identities are still missing, especially where agents act for companies in email or online services (FAZ). German security analysts already class AI agents as "non-human identities": machine accounts whose credentials are often poorly monitored and gradually gather wider access than anyone intended (Security-Insider).

Europe has rules for proving who a person is (eIDAS 2.0), limiting the data they disclose, logging AI systems (AI Act), protecting personal data (GDPR) and securing network access (NIS2). What it does not yet have is one rulebook for a software deputy operating across all of them. No single regulation covers the full chain: identifying the agent, defining its mandate, recording its actions and assigning liability when something goes wrong.

That liability gap is where the neatness of the Estonian idea runs into politics and law. A digital badge does not decide who pays when a delegated task causes damage: the company that built the model, the business that deployed it, or the organisation that authorised the agent to act (FAZ). The EU's AI Liability Directive was meant to deal with precisely that sort of problem. It is still only a proposal (AI Liability Directive).

Whose badge, whose rules

Member states are already coming at the same problem from different directions. Denmark's AI sandbox is testing delegation on top of MitID, its national login system (Datatilsynet). The Netherlands has built a public register of government AI systems, treating accountability as a matter of administrative practice (Algoritmeregister). Sweden is working through how to certify the digital wallets envisaged by eIDAS 2.0: tamper-proof phone apps that can prove one fact about a person, such as age or residency, without handing over the full identity file (DIGG).

That patchwork is the real European test. An AI agent authorised in Estonia may have to be trusted by a Danish login system, audited under Dutch accountability rules and secured against the machine-account risks worrying German regulators. Estonia can build the badge. The harder job falls to European regulators and standards bodies: making sure a deputy authorised in one country can be checked, limited and held accountable in another.

How was this article?

Help us get better

Details about this article
Model:
claude-opus-4-6
Generated:
7/7/2026, 3:07:10 AM
Pipeline run:
eu_pipeline_20260707_005006
Watermark:
SynthID (Google's invisible watermark)
Human review:
None before publication
Learn more about our methodology