Ukraine's Ministry of Digital Transformation has given its government AI agent a voice. As of July 15, 2026, Diia.AI — the chat assistant embedded in the Diia app and portal — lets citizens speak instead of type to retrieve registry records, check sole-proprietor and insurance data, and generate documents like income certificates (Minfin). The feature, built with voice-AI startup ElevenLabs, is activated with a sound-wave button on the Diia homepage or inside an open chat, and it works, per the ministry's own description, even in noisy public spaces like transit (dev.ua).
This is an incremental step, not a relaunch. Diia.AI itself debuted in September 2025 as what the Ministry and its development partner Kitsoft describe as the world's first national AI agent that executes government services rather than merely explaining them — filing for an income certificate, walking a user through eRestoration compensation, or guiding a car sale through Diia (Digital State Ukraine). Kitsoft CEO Oleksandr Iefremov has framed the ambition plainly: "The world is moving toward a model where AI agents perform everyday actions instead of the user." Voice is the next input layer on that same architecture, and the wider Diia ecosystem it plugs into now serves more than 24 million users across over 170 digital public services (Biometric Update).
The case for caution
Critics of rapid state digitalization have a genuinely strong argument here, and it isn't hypothetical. In December 2024, Russian hackers breached Justice Ministry databases underpinning Diia, forcing weeks of outages across vehicle registration, marriage registration, and property services, and exposing biometric data, tax records, and addresses. The intrusion group XakNet, tied to Russian intelligence, claimed it had also destroyed backup servers hosted in Poland — undercutting the assumption that offsite redundancy alone would protect the system (Kyiv Independent). Cybersecurity specialists quoted in that reporting, including a former SBU cyber officer, described Ukraine's digitalization drive as having outpaced its security architecture, producing exactly the kind of centralized single point of failure that a determined state-linked adversary is built to exploit. Registries and app access weren't fully restored until January 20, 2025 — roughly a month of degraded service for a country at war.
Against that backdrop, adding a conversational voice layer that ingests live speech, pulls registry data mid-conversation, and generates official documents is a legitimate thing to scrutinize. Every new integration point — a third-party voice vendor, a new API surface between the assistant and government databases — is, in principle, one more thing to secure and one more thing that can fail during an active cyber campaign against the same government running it.
Why the upgrade is still the right call
That argument, though, conflates two different risks: the risk of centralizing more data and the risk of adding a new interface to data that is already centralized. Diia.AI's voice mode doesn't create a new registry or duplicate sensitive records elsewhere — it changes how citizens who are already entitled to pull an income certificate or check a pension record do so. The underlying attack surface is the same Justice Ministry and social-registry infrastructure that was breached in 2024; voice access is a UX layer on top of it, not a new datastore beneath it. The Ministry's own framing of the rollout — an open beta for the AI-issued income certificate, a per-response user rating that feeds model corrections — suggests a deliberately staged deployment rather than a wholesale swap of legacy systems (Digital State Ukraine).
There's also a real accessibility case that shouldn't be waved away as marketing. Elderly citizens, displaced people navigating unfamiliar bureaucracy from a new city, and Ukrainians with injuries that make typing difficult are precisely the population a wartime digital state should be designing for, and voice interfaces measurably lower that barrier. Blocking useful accessibility features because the underlying registries were breached eighteen months ago punishes the wrong layer of the stack.
The right regulatory response to the December 2024 breach was never "freeze feature development" — it was "fix the redundancy failures the breach exposed," including the fact that a Polish backup server was apparently reachable and destroyable by the same intrusion. Ukraine's parliament and the Ministry should pair every expansion of Diia.AI's capabilities with a public, auditable commitment to multi-region, tamper-resistant backups and a standing incident-disclosure timeline — not slower feature velocity. A government AI agent that can talk to its citizens is a genuine governance advance for a country running a wartime bureaucracy under constant cyber pressure. The vulnerability that matters is the one under the hood, and that's a backup-architecture problem, not a microphone problem.