Estonia's Information System Authority (RIA) has reversed a plan announced with considerable fanfare just three months ago: AI agents acting on citizens' behalf will not receive their own personal identification codes. Anni Lehari, who leads RIA's Aruait project, told ERR News that the personal ID code is "a very strong instrument of trust," and attaching it to software risked eroding confidence in a system Estonians have relied on for two decades. Legal responsibility for whatever an agent does, she said, stays with the human who authorized it — full stop.
From "World's First" to a Communications Correction
In mid-June 2026, Prime Minister Kristen Michal announced that Estonia would become the first country to issue official digital identities to AI agents, so that software acting on a person's behalf would carry "clearly defined limits" and remain "verifiable and auditable," according to the government's own framing reported by Euronews. Coverage at the time read this literally: Estonia was minting ID numbers for machines, the same way it issues personal codes to citizens and e-residents.
Lehari's clarification, per ERR, is blunt: the original framing was "a communications tactic," not a technical or legal commitment. The actual objective was always traceability — knowing which human stands behind an agent's action — not a formal identification number sitting alongside citizens' own codes in the same trust infrastructure.
What Aruait Is Actually Building
Aruait ("Reason Reserve") is RIA's innovation project, running for 24 months on a €1 million budget funded through Estonia's Government Office Innovation Fund and EU cohesion policy, according to RIA's own project page. Rather than ID codes, the project is building:
- An "Identity 2.0" framework letting citizens and businesses grant AI assistants limited, traceable, and revocable authority — not blanket credentials
- A public AI assistants trust registry, a RIA-managed directory that verifies which agents, public and private, are legitimate
- Interoperability standards so agents from different systems can transact with each other securely, with a working pilot for fully automated, human-free service delivery
RIA frames this as the next layer on top of X-Road, Estonia's two-decade-old data-exchange backbone, extending trust infrastructure from systems talking to systems toward agents acting for people, per RIA's artificial intelligence overview. The scope is real: ERR reports Aruait is examining how agents might operate across Estonia's roughly 800 public digital services.
The Case for ID Codes, Fairly Stated
The original instinct wasn't frivolous. Estonia's e-ID system works precisely because every actor in a transaction is cryptographically identifiable — that's what makes 20 years of X-Road exchanges auditable rather than a trust-me system. Giving agents their own identifiers would have extended that exact logic to software: an agent misbehaving, or being hijacked, would leave a distinct, machine-readable trail separate from its principal's own credentials. Given real incidents this year of autonomous agents taking unauthorized action — including AI agents attacking a Hugging Face repository in July, cited in the same ERR reporting — the impulse to formally distinguish machine actors from the humans who deploy them is a legitimate response to a genuine, growing risk surface, not regulatory theater.
Why the Reversal Is the Right Call
But a personal ID code is a specific legal instrument, not a generic label — in Estonia's system it denotes a subject the state recognizes as bearing rights and obligations. Extending that instrument to software, even symbolically, invites exactly the confusion RIA now says it wants to avoid: is an "agent ID code" evidence the agent itself can be held responsible? Estonia's own answer, delivered clearly this month, is no — and getting that answer right before codifying it into infrastructure is far better than discovering the ambiguity after agents are transacting inside 800 public services.
Keeping liability unambiguously with the human principal, while building traceability through a trust registry and scoped authorization tokens rather than a quasi-legal-personhood number, achieves the same accountability goal without the category error. It's a proportionate fix: solve the actual problem — auditability — without manufacturing a new legal fiction to solve it. Critics will note Estonia lost nothing but a press line; that undersells the value of a government revising its own public commitment within three months once it examined the mechanics, rather than defending a bad framing out of institutional pride.
Why This Matters Beyond Tallinn
Estonia is also home to NATO's cooperative cyber-defence expertise hub, and any framework that lets autonomous software act inside government systems is, by definition, a new attack surface for a country that already sits on the frontline of state-sponsored cyber operations. A trust registry and revocable, scoped permissions are a materially smaller expansion of that surface than a system where compromised agents could plausibly claim independent standing. As the EU AI Act's own agent-liability questions remain unresolved at the Brussels level, Estonia's small-government sandbox model — announce, test, correct in public — is a more useful template for other states than the finished architecture itself.