- What: Estonia plans to assign government ID numbers to AI agents.
- Impact: Potential implications for AI regulation and governance.
Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBERSECURITY OPERATIONS CYBER RISK IDENTITY & ACCESS MANAGEMENT SECURITY DATA PRIVACY NEWS Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa, Asia Pacific, and Latin America. State IDs for AI Agents: Will Estonia Set a Precedent? The world's digital testing ground plans to help people use AI agents for government purposes. Nate Nelson,Contributing Writer July 8, 2026 4 Min Read SOURCE: AKINBOSTANCI VIA GETTY IMAGES Estonia's government will soon assign official government ID numbers to artificial intelligence (AI) agents. Questions remain, though, about how such a system would work in practice, and whether it might expose the state to new cyber-risks. An advisory council established by Estonia's prime minister agreed to establish this novel idea in June. The point of it is to enable organizations and individuals to use AI when engaging government systems, but in a way that's limited and auditable. "In the future, artificial intelligence will carry out digital actions on behalf of a person, company, or institution: compiling reports, preparing declarations, or communicating with information systems," Estonian Prime Minister Kristen Michal wrote on X in June. "But it must be clear who is acting, on whose behalf, with what rights, and who is responsible." Government IDs for AI Agents In recent decades, Estonia has been leagues ahead of other countries when it comes to digital transformation. Its government is a testing ground for responsible and forward-thinking digital programs, like its centralized "Data Tracker" that provides visibility and agency over one's personal information in government systems, and its "Data Embassy" in Luxembourg — a backup of critical government data in case its big, bad neighbor to the East feels like attacking again. Related:Apple Reverses Age-Old Patch Policy to Keep Up With AI At the beginning of 2026, the small Baltic nation established an avant garde initiative called Eesti.AI, aimed at integrating AI across all sectors of its economy and government. The project set out no less ambitious a goal than doubling national gross domestic product (GDP) in a decade. Among other ideas, some involved with the initiative have argued that Estonia should develop a way for businesses and individuals to safely use personal AI agents for bureaucratic purposes. "We built our digital state on the assumption that humans are the only actors with identity, agency, and responsibility," wrote e-Estonia digital transformation adviser Petra Holm earlier this spring in a blog post. "[AI] cannot authenticate, sign, take responsibility, or explain their reasoning in ways that match legal standards. In practice, this means they cannot perform tasks that would meaningfully change productivity or service delivery." "Eesti.ai outlines ambitious economic goals that depend on automating high‑value processes across the state and the private sector. But legally meaningful automation is impossible without legally recognised actors. As long as AI agents cannot be attributed, delegated authority, or held accountable, they remain tools rather than participants in the administrative ecosystem. And tools cannot drive a 25% increase in national productivity," she argued, referring to the government's goal to get halfway to its 50% dream in the next five years. Related:Why Identity Security Is Your Cyber Career Entry Point At Eesti.AI's second meeting on June 16, the group agreed to develop a new system for registering AI agents as semi-independent entities with their own national ID numbers. The idea is that, instead of having to assign all of your rights and identity to an AI assistant before using it for government-related purposes, your assistant can itself have some regulated rights and permissions. Then, within some clearly defined and limited scope, it can engage government systems and perform administrative functions. For now, Eesti.ai has not articulated how the idea will work in practice. Dark Reading reached out to the board for more details, but it has yet to reply as of the time of publication. Questions Around Estonia's Plan Plenty of questions remain about how Estonia's policy will work in practice. For example, it takes nine months to create a person — and dozens more to work out the bugs — but spinning up an agent is so quick and low effort that it could invite a glut of new government ID registrants. Related:AI Decline? Confidence in Autonomous Penetration Testing Falls Then there are legal matters to be clarified. Should a human Estonian abuse a government system, there's a whole legal system built to hold them accountable. New rules might be required to define how exactly a human proprietor might be held responsible if their registered AI agent violates rules or guidelines. For now, the European Commission's AI Act might provide a baseline: it states that a person "takes responsibility for the placing on the market or the putting into service of a high-risk AI system, regardless of whether that natural or legal person is the person who designed or developed the system," and does not distinguish between AI agents and AI more generally. "Registration is important, but it is not enough," says Jason Soroko, senior fellow at Sectigo. "An AI ID code will not prove that an agent followed instructions, understood context, resisted prompt injection, used valid data, or produced lawful output. It also creates hard governance problems, including revocation, key compromise, impersonation, agent chaining, cross-border trust, audit log integrity, and privacy." He suggests that Estonia's government should pair AI IDs with cybersecurity controls like short-lived credentials and sender-constrained tokens, administrative rules around procurement, auditing, and incident reporting, and tightly defined delegation standards. "They should also require that high-risk agents disclose their authority limits before acting, preserve human override, and make logs available to affected parties and regulators," he says. "That would make AI ID codes a useful accountability control, rather than a false signal of trust." Read more about: Europe About the Author Nate Nelson Contributing Writer Nate Nelson is a journalist and award-winning scriptwriter. In addition to Dark Reading he writes for Darknet Diaries, the most popular show in cybersecurity across all media. He began his career as a freelancer, ghostwriting Forbes and CNBC op-eds for executives in tech and finance. Then he transitioned to journalism at Threatpost, where he covered cybersecurity news and trends. Throughout those years he co-created a cybersecurity podcast, Malicious Life, which in its day climbed into the Top 20 technology podcasts charts on Apple Podcasts and Spotify. He holds degrees from New York University and Bard College. As a born and bred New Yorker, he enjoys a superiority complex, but is polite enough to keep it to himself. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges The total economic impact™ of Snyk How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Access More Research Webinars Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything Practical Zero Trust Implementation on a Budget in the Age of Mythos Building a Risk Based Vulnerability Management Program Threat Hunting That Gets Big Results Despite Small Budgets Say Yes to AI: Securing Innovation Without Compromise More Webinars You May Also Like CYBERSECURITY OPERATIONS Hand CVE Over to the Private Sector by Brian Martin JAN 27, 2026 CYBERSECURITY OPERATIONS China Imposes One-Hour Reporting Rule for Major Cyber Incidents by Robert Lemos, Contributing Writer OCT 01, 2025 CYBERSECURITY OPERATIONS CISA, FBI, NSA Warn of Chinese 'Global Espionage System' by Alexander Culafi AUG 28, 2025 CYBERSECURITY OPERATIONS Women Who 'Hacked the Status Quo' Aim to Inspire Security Careers by Elizabeth Montalbano, Contributing Writer JUL 16, 2025 Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices