Intelligence

Estonia Wants an Identity for the Agent. The Human's Authority Is a Separate Question.

On 17 June 2026, at the second meeting of its Eesti.ai advisory board, the Government of Estonia agreed to move forward with what it calls AI ID codes, a distinct digital identity for an AI agent acting on behalf of a person, company or organization. Prime Minister Kristen Michal backed the proposal. Moona Intelligence surfaces this now, more than nine weeks later, as newly surfaced historical evidence, and verifies it against a strict Agent Authority and Authority Provenance standard rather than against the world first claim attached to it.

Event analysed: . This analysis was published on 22 August 2026.

When Estonia's Eesti.ai advisory board proposed AI ID codes on 17 June 2026 and Prime Minister Kristen Michal backed the proposal, what did the Government of Estonia actually commit to, and does the proposal establish that a person delegating authority to an agent was entitled to delegate it in the first place?

It committed to a development direction, not a built system. On 17 June 2026, at the second meeting of the Eesti.ai advisory board, the board agreed Estonia should move forward with creating digital identities for AI agents, AI ID codes, and Prime Minister Kristen Michal backed the proposal. The government's stated objective is a solution that lets AI act on behalf of people, companies or organizations within clearly defined limits, in a manner that is verifiable and auditable, specifically to avoid situations where a person or organization has to give an AI assistant access to all of its rights, services and data. Michal framed the requirement directly: it must be clear who is acting, on whose behalf, with what rights, and who is ultimately responsible. Current official material describes potential bounded tasks as examples of the intended model, not as a published technical specification: viewing specific data, preparing a document, initiating a payment, or using only a predefined amount of money. What the proposal establishes, read strictly, is an identity layer, separate from the human, company or organization an agent represents, meant to carry a bounded, revocable scope rather than the principal's full credentials. What it does not establish, in the material verified here, is a technical specification, enacted legislation, an operational credential, a deployed identity infrastructure or demonstrated enforcement. Nor does it establish the harder Authority Provenance question underneath its own stated goal: even once an agent's identity and a delegated scope are recorded and auditable, nothing in the primary material specifies how Estonia would confirm that the human or organizational representative who granted that scope actually held the underlying mandate, a corporate role, an account ownership right, a legal representation basis, to delegate it. Estonia describes itself as aiming to be the first country to do this. That is the government's own ambition, reported consistently across independent coverage of the announcement. It is recorded here as Estonia's claim, not as independently verified fact that no other government has done the same.

On 17 June 2026, Estonia's Eesti.ai advisory board met for the second time and agreed the country should move ahead with a specific idea: an AI agent acting on behalf of a person, a company or an institution should get its own digital identity, separate from theirs. Prime Minister Kristen Michal backed the proposal. Moona Intelligence is reading it now, more than nine weeks after the fact, and wants to be direct about that gap before anything else. This is not a report of something Estonia announced today. It is newly surfaced historical evidence, verified against the primary material and against a strict Agent Authority and Authority Provenance standard, not against the world first framing that has followed it since June.

What the Eesti.ai board actually agreed

Eesti.ai is a government initiative, established on Michal's own initiative earlier in 2026 and chaired by Bolt chief executive Markus Villig, with a membership drawn mostly from outside government: Skype co founder Jaan Tallinn and the Future of Life Institute's Risto Uuk sit on it, alongside other Estonian entrepreneurs and technologists. Its stated purpose is to increase the value of Estonian work and the Estonian economy through the systematic application of artificial intelligence. At its second meeting, held in Tallinn, the board's recommendation was specific: Estonia should build what officials are calling an AI ID code, a digital identity for an agent acting on behalf of a person, company or organization, distinct from the identity of whoever it represents.

Michal's backing is political and directional, not a signature on a finished design. The government's own framing of why this matters, read across its material and consistent independent reporting, is that an AI assistant carrying out a task today often has to act as the person who set it running, which in practice can mean inheriting that person's passwords, accounts and reach across services. Estonia's stated aim is to replace that with delegated authority that is limited, controllable and auditable, specifically so that granting an AI agent any capability at all does not require granting it everything.

Nothing in this record treats 17 June 2026 as the date Estonia shipped anything. It is the date a government advisory board recommended a direction and the head of government backed it. Every claim below is scoped to that.

The objective, in the government's own words

The stated policy objective, as Estonia's own material and consistent independent coverage describe it, is a solution that would let AI act on behalf of people, companies or organizations within clearly defined limits, in a manner that is both verifiable and auditable. The government is explicit about what it is trying to avoid: situations where a person or an organization has to give an AI assistant access to all of its rights, services and data just so the assistant can do one narrow thing.

Michal's own statement, quoted consistently across the primary announcement and the reporting that followed it, states the requirement plainly: it must be clear who is acting, on whose behalf, with what rights, and who is ultimately responsible. That sentence is the central factual anchor for everything else in this record, and it is worth reading slowly, because it names four different questions rather than one.

Four things this proposal keeps separate

Who is acting is a question of identity. An AI ID code is meant to answer it: this specific agent, distinguishable from the human, company or organization it represents. With what rights is a question of delegated authority: what this agent has actually been given permission to do, not what the principal it represents could do on their own. On whose behalf is attribution: which principal this agent's action traces back to. Who is ultimately responsible is accountability, and it is explicitly not the same question as any of the first three. An agent can be correctly identified, correctly scoped and correctly attributed to a principal, and the question of who answers for what it did can still be a separate determination.

Moona Intelligence keeps these apart on purpose, because the easiest way to overstate a proposal like this one is to let identity stand in for all four. An AI ID code, on the government's own framing, identifies the agent. It does not, by itself, decide what the agent may do, prove that a given action happened, or settle who bears responsibility for it. Those are three additional pieces of infrastructure a working identity system would still need, and Estonia's own June material describes the ambition for all four without yet publishing how the last three would work.

The examples the government gave, and what they are examples of

Current official material describes the kind of bounded delegation Estonia has in mind through specific, small examples: an agent might be permitted to view specific data, prepare a document, initiate a payment, or spend only a predefined amount of money. Those examples appear consistently across the primary material and the reporting that followed it, and this record preserves them as examples rather than rounding them up into more than they are. They illustrate the shape of the intended model, a task bounded by a resource and, where relevant, an amount. They are not a published technical policy language, a schema, a permission taxonomy or an implemented control. Nothing in the material verified here describes how a scope like initiating a payment up to a predefined amount would actually be encoded, checked at the moment an agent tries to act, or enforced against a real payment rail. The government has stated the shape of the model it wants. It has not, in the material available to this record, published the mechanism.

What stage this is actually at

It is worth being exact about what 17 June 2026 is, because a specific, well quoted proposal is exactly the kind of material that gets cited later as though it were something more finished. This is a government advisory board's recommendation, backed by the head of government. It is not enacted legislation. It is not a published technical specification. It is not an operational government credential anyone can be issued today. It is not an existing technical standard other systems could implement against. It is not deployed authorization infrastructure, and nothing in the material verified here describes a working prototype, a pilot deployment or any instance of an AI ID code actually being issued, checked or relied upon in production. It is a development direction, stated with unusual specificity for a proposal this early, and specificity is not the same thing as implementation.

Estonia already operates real digital government infrastructure that a system like this would plausibly connect to. X-Road is the country's data exchange layer connecting public and private registries, and Bürokratt is an existing state built AI assistant helping institutions deliver services. Some secondary commentary describes AI ID codes as an extension of X-Road's existing least privilege model, with agents receiving only the rights explicitly granted and audit trails naming the agent separately from its principal. This record does not adopt that as established, because it comes from commentary interpreting the proposal rather than from Estonia's own primary material, which does not itself specify, in what has been verified here, that AI ID codes would be built on X-Road, how they would relate to Bürokratt, or what the underlying technical architecture would actually be. Estonia's existing digital identity infrastructure is the plausible foundation such a system would draw on. It is not, on the primary record, the specification for one yet.

The Authority Provenance ledger, as it stands today

This is the part a government announcement is not built to state explicitly, and it is the reason this record exists rather than a shorter one repeating the world first framing. Moona Intelligence separates identity, delegated scope, and the legitimacy of whoever granted that scope, because collapsing them into one claim that Estonia is making agent authority verifiable is exactly the promotion this record is built to resist.

Authority grantor. Estonia's own framing names three kinds of principal an agent could represent: a person, a company or an organization. What the material verified here does not establish is whether the eventual design distinguishes the principal whose authority is being represented from the individual human who technically creates the delegation on a company's or organization's behalf. A company does not click a consent screen. An employee, an officer or an administrator does, on the company's behalf, and nothing in Estonia's current material specifies whether an AI ID code's grantor field would record the represented organization, the individual who acted for it, or both. This record does not assume they are always the same party, and treats the distinction as unresolved.

Mandate or basis. Undocumented. Estonia's own e-ID system already authenticates who a person is with strong assurance, and nothing here questions that. Authentication is a separate fact from entitlement. Proving that Alice is who her digital identity says she is does not, on its own, prove that Alice held the organizational, contractual, statutory or account level right to delegate a particular capability, a company's payment authority, a colleague's records, an institution's filing obligation, to an agent. The material verified here does not describe any treatment of representation rights, company registry authority, powers of attorney, organizational roles or another upstream basis for confirming a grantor's mandate before a delegation is accepted. Until Estonia publishes one, this record records mandate as unknown rather than inferring it from the strength of Estonia's existing authentication infrastructure.

Delegated scope and explicit limits. Documented at the level of stated intent and illustrative example, not as a technical policy language. The government's own examples, viewing specific data, preparing a document, initiating a payment, spending up to a predefined amount, describe the shape of what a scope could bound: a task, a resource, and where relevant an amount. What is not documented is a published schema, a set of standard scope dimensions, or any description of how a scope like these examples would actually be expressed, checked or enforced at the moment an agent attempts an action. This record treats the examples as exactly what they are, illustrations of the intended model, and does not read a technical specification into them.

Inherited permissions and assumptions. This is the design question the proposal is explicitly built to avoid, and it is also, on the material verified here, unresolved. Estonia states directly that it wants to prevent situations where an AI assistant needs access to all of a principal's rights, services and data. What the current material does not specify is the derivation model: how a narrower, agent specific set of rights is meant to be carved out of a principal's existing rights in the first place, whether that derivation happens automatically from an underlying account or registry entry, or whether every scope has to be manually specified by whoever creates the delegation. Stating the goal of avoiding full inheritance is not the same as publishing how narrower authority is actually produced, and this record preserves that as an open design question rather than assuming Estonia has already solved it.

Revocation and modification. Estonia's own framing, read across the primary material and consistent independent coverage, describes the intended model as revocable, alongside limited, controllable and auditable. What is not documented, in the material verified here, is the mechanism: whether revoking a delegated scope is instantaneous or takes effect on a schedule, whether it is distinct from revoking or suspending the agent's identity itself, who is permitted to initiate a revocation, and what happens to an action already in flight when one occurs. Revocable is a stated property of the intended design. How revocation actually works is undocumented.

Challenge authority. Undocumented. Nothing in the primary material specifies who could dispute, suspend or invalidate a delegation once it exists, whether that is limited to the original grantor, extends to an organizational administrator, a represented company, a government authority, a counterparty relying on the agent's action, or some other party. Auditability is not the same guarantee as a defined challenge mechanism. Being able to see what happened does not, by itself, establish who is entitled to contest it, and this record does not infer one from the other.

Recovery. Undocumented. Nothing in the material verified here describes what happens when an agent's action was technically authorized under a valid AI ID code and delegated scope, but turns out to have been mistaken, harmful, or outside what the human principal actually intended, a payment sent to the wrong recipient inside an authorized amount, for instance, rather than an unauthorized one. A future ability to revoke or narrow an agent's authority is not the same thing as a rollback, compensation or dispute path for an action that has already completed. This record does not treat the one as evidence of the other.

Provenance evidence quality. Layered rather than collapsed into one claim, what exists in the material verified here is a stated intent to make three things auditable together: the agent's identity, the principal it represents, and the scope it was given. What does not yet exist, in anything verified here, is evidence that a delegation's scope would be independently checkable by a party outside the system that issued it, evidence describing how a delegation's continued validity would be confirmed at the moment an agent actually acts rather than only at the moment it was granted, or any account of how a challenge or recovery process would attribute and unwind a completed action. The hardest question sits underneath all of it, and Estonia's current material does not answer it. Even if a future system can prove that Alice authorized an agent to spend ten thousand euros, nothing published so far establishes what would prove Alice was legitimately entitled to delegate that ten thousand euros of authority in the first place.

Whether this is actually a first

Estonia's own government material and Michal's own statements describe the ambition to be the first country to create official digital identities for AI agents, and that framing is reproduced with unusual consistency across independent coverage of the 17 June announcement, from wire and technology press to specialist identity outlets. Moona Intelligence has not independently verified that no other government has proposed or built a comparable system, and the claim is recorded here as Estonia's own stated ambition, reported consistently by others, rather than as an independently established global first. Consistency of coverage is evidence that the claim was made and repeated. It is not, on its own, evidence that the claim is true.

Where this sits against what we have already tracked

China's implementation opinion, issued jointly by three central bodies in May 2026, allocates decision rights into three classes and bounds autonomous execution by the scope a user authorized, but it does not propose a distinct identity for the agent itself, and it is policy guidance about decision rights rather than a proposal to build an identity layer. Singapore's companion report decomposes agent control into ten principles produced by a research consensus, not a national government proposal with a head of government's political backing behind it. Estonia's contribution, distinct from both, is narrower and more specific: a government proposing that the agent itself should carry a separate, bounded identity, rather than acting under the identity of whoever it represents.

GitLab's composite identity is a shipped product mechanism authorizing the intersection of a human role and a service account role at execution time, a vendor implementation, not a national identity proposal, and it authorizes actions rather than establishing who was entitled to delegate in the first place. BIND is a research prototype binding a human's biometric to an agent's identity and a delegated scope at the moment of delegation, evaluated in one setting, with no deployment claim at all. Nuggets is a vendor platform that documents an agent's authority as cryptographically linked to a specific human, while leaving that grantor's own mandate to grant it undocumented, the same gap this record finds in Estonia's proposal. Rain's Agentic Payments Alliance is 26 companies agreeing the authorization problem is serious enough to convene over, without yet publishing a shared answer. None of those four is a government proposing to build a national identity layer for agents. Estonia is the first record in this set where a head of government has publicly backed the idea that an agent should carry its own official identity, distinct from the identity of the person, company or organization it acts for, as a matter of national policy direction. That is a genuinely distinct contribution, and it survives verification as exactly that: a proposal and a political commitment, not a working system, and one that leaves the mandate question every other record in this set also leaves open.

What we could not verify

Every primary and secondary destination for this record, the Government of Estonia's own site, ERR, Bloomberg, Global Government Forum, Biometric Update, Identity Week, Euronews and the Non Human Identity Management Group, was blocked at the network egress policy for the session in which this piece was researched. No page could be fetched directly. Everything above rests on repeated, independently phrased searches whose results were consistent with each other across separate queries, including the exact wording of Michal's quotation, the 17 June meeting date, the board's composition and the four bounded task examples, all of which returned matching detail across multiple independent passes. The full basis for each claim is recorded in the source notes below. An editor with unblocked network access should read the Government of Estonia's own announcement directly before any claim beyond what is verified here is added to this record.

One further limit deserves stating plainly. The specific claim that AI ID codes would extend Estonia's X-Road infrastructure, with audit trails naming the agent separately from its principal, was found in secondary commentary interpreting the proposal, not in the primary government material corroborated across searches. This record declines to adopt it as established and states so directly in the section above, rather than letting a plausible technical guess read as a government commitment.

The question that stays open

Estonia's own framing is unusually precise for a proposal this early. Who is acting, on whose behalf, with what rights, and who is ultimately responsible names four separate questions, and naming them clearly is itself a meaningful contribution to how this problem gets discussed. What the 17 June material does not yet do is answer the question underneath its own framing. An AI ID code, if built as described, would identify the agent. A delegated scope, if built as described, would bound what it can do. Neither one, on the material verified here, establishes that the human or organizational representative who created the delegation actually held the right to grant the authority being delegated. That is not a criticism of what Estonia proposed. It is the same gap this desk has found underneath every other agent identity and delegation system it has verified so far, and Estonia's own material does not close it either.

Sources

This analysis interprets third-party reporting, research and announcements. Moona is not the original reporter of the underlying events.

[3]
Estonia to Grant AI Bots Digital IDs to Control Access
Bloomberg · 17 June 2026 · Journalism
[4]
Estonia set to be first country to create digital identities for AI agents
Global Government Forum · 18 June 2026 · Journalism
[5]
[7]
Estonia creates AI ID codes to govern autonomous agents
Euronews · 19 June 2026 · Journalism
[8]
Estonia's digital ID proposal exposes the governance gap for AI agents
Non Human Identity Management Group · 22 June 2026 · Source

Related Intelligence

All Intelligence Records →