Estonia Plans to Give AI Assistants Their Own Government ID Numbers
The Baltic nation wants AI agents to act inside government systems as semi-independent registered entities. Security experts say a registration number alone will not make that safe.

Key points
- Estonia's prime minister advisory council agreed in June 2026 to develop a system of official national ID numbers for artificial intelligence agents.
- The Eesti.AI initiative, launched in early 2026, aims to double Estonia's gross domestic product within ten years partly by automating government bureaucracy.
- Under the proposed scheme, an AI assistant would hold its own limited, regulated permissions rather than acting under its owner's full identity.
- Security experts warn that an ID number proves only that an agent exists, not that it behaves safely or follows instructions.
- The EU AI Act currently places legal responsibility on the human or company that puts an AI system into service.
Estonia wants to give artificial intelligence assistants their own government ID numbers, the same kind of unique identifier every Estonian citizen already carries. Your AI assistant could then interact with government systems directly, filing tax declarations or submitting reports, rather than you handing it the keys to your entire digital identity.
The country's advisory council, set up by Prime Minister Kristen Michal, agreed to the plan at a meeting on 16 June 2026. Michal had flagged the idea publicly earlier that month. "It must be clear who is acting, on whose behalf, with what rights, and who is responsible," he wrote.
Why does Estonia think AI agents need their own identity?
Right now they can't. Without a recognised legal identity, AI agents can't formally authenticate to government systems, can't sign documents with legal weight, and can't be held accountable for their actions in any meaningful way. That limits what they can do.
Petra Holm, a digital transformation adviser to the Estonian government's e-Estonia programme, put it plainly in a blog post this spring. Tools that can't be attributed, she argued, can't drive the productivity gains Estonia is counting on. She cited the government's goal of a 25 percent productivity increase over the next five years as something that legally unrecognised agents simply can't deliver.
The logic is neat. The practical problems are harder.
Creating a human identity takes roughly nine months and years of socialisation. Spinning up a new AI agent takes seconds. That gap could flood government ID registries with thousands of new registrants fast, each one potentially acting on behalf of a person or company.
We covered the initial proposal on 17 June 2026, when Estonia's AI Council first floated state-backed digital identities with spelled-out permission scopes; the governance questions raised then remain unanswered now.
There's also the question of accountability. Estonian law knows what to do when a citizen abuses a government system. It's less clear what happens when a registered AI agent does something it shouldn't. The EU AI Act offers a starting point: the person who puts a high-risk AI system into service carries responsibility for it, regardless of who built it. But that rule was written for AI products, not for agents behaving as semi-independent actors inside live government infrastructure.
Jason Soroko, a senior fellow at certificate-authority firm Sectigo, told Dark Reading that registration is necessary but far from sufficient. "An AI ID code will not prove that an agent followed instructions, understood context, resisted prompt injection" (where a criminal hides malicious instructions inside content an AI reads, hijacking its behaviour), "used valid data, or produced lawful output," he said. He called for short-lived credentials, tightly defined delegation standards, human override requirements and accessible audit logs.
Estonia hasn't published technical details of how the scheme will work. Eesti.AI didn't respond to requests for comment before publication.
Should you worry?
If you run a business that already uses AI assistants for government-facing tasks, review exactly what permissions those tools hold. Limit access to only what's needed for the specific task. Keep a record of every action they take. A human should review any output before it's submitted officially. The registration number Estonia is designing tells you an agent exists. It tells you nothing about what the agent will do next.



