Estonia - AI Expert Group Report (2019)

Report of Estonia’s AI Expert Group

Eesti tehisintellekti kasutuselevõtu ekspertrühma aruanne

Estonia

RAI-EE-NA-REAEGXX-2019
Adopted(Adopted)
PolicyGovernance and OversightAccountability and DocumentationRisk Management
Export PDF

The 2019 Report of Estonia’s AI Expert Group, prepared by the State Chancellery together with the Ministry of Economic Affairs and Communications, sets out a national framework of recommendations to accelerate safe and societally beneficial AI adoption in Estonia. The report recommends governance structures, pilot projects (the Kratt programme), legal and administrative changes, and alignment with EU and OECD principles while emphasising human oversight, transparency and data protection.

Overview

The Report of Estonia’s AI Expert Group (2019) was produced by an inter‑institutional expert group convened by the State Chancellery (Riigikantselei) in cooperation with the Ministry of Economic Affairs and Communications to analyse opportunities and risks of AI deployment in Estonia and to propose actions for national implementation under the "Kratt" initiative. The publication is archived in the national digital archive (DIGAR) and is cited by official government pages presenting the Kratt programme and the 2019–2021 AI activity plan. The expert group’s recommendations were prepared as input for a national AI action plan (the 2019–2021 Kratt plan) and informed coordinated ministerial activities and pilot projects in the public sector. Full text of the report is available as an official State Chancellery PDF and an archived copy is available via DIGAR. (Report PDF (State Chancellery), DIGAR archive.)

Definitions

The report frames "Kratt" as a communicative metaphor for AI systems: software agents or algorithmic systems that automate tasks, learn from data, and can assist or replace human operators in narrow domains. It distinguishes between conventional software automation and learning‑based AI capable of adaptation and data‑driven decision‑making, and it highlights the need for clear terminology in law and procurement so that legal and administrative frameworks properly capture the characteristics of different types of algorithmic systems. The report therefore recommends defining terms and clarifying the boundaries between ordinary automated processing and adaptive, data‑driven systems for purposes of regulation, procurement and oversight. (DIGAR archive.)

Governance and Institutional Framework

The report proposes an institutional framework with responsibilities distributed across the State Chancellery, the Ministry of Economic Affairs and Communications, and participating line ministries, supported by expert and stakeholder groups to steer pilots, standardisation and legal proposals. The expert group itself was created by government decision in March 2018 and reported in 2019. Recommendations envisage coordinated ministerial actions under the Kratt programme, establishment of oversight and governance mechanisms to steer public‑sector pilots, and the creation of cross‑cutting expert/advisory groups to develop guidance, standards and procurement practices. The report emphasises that governance should enable ministerial coordination, stakeholder engagement and capacity building rather than relying on a single central regulator to manage all AI matters. (Riigikantselei: expert group coordination, DIGAR archive.)

Key Focus Areas

  • Legal clarity for AI use in public administration, including terminology, procurement rules and the need for legal or administrative adjustments.
  • Piloting AI solutions (Kratt pilots) in public services to validate use cases, procedures and safeguards before wide deployment.
  • Governance and oversight mechanisms distributed across ministries with support from expert and stakeholder groups.
  • Investment in education, skills and research & development to ensure public‑sector capacity and a talent pipeline.
  • Promotion of public–private cooperation and open data initiatives to spur innovation while observing legal constraints.
  • Protection of fundamental rights and compliance with data protection rules (GDPR), including lawful processing, purpose limitation and safeguards against discriminatory profiling.
  • Operational safeguards for public bodies: transparency of automated processes, avenues for contestation or human review, and organisational accountability for outcomes of AI‑assisted decisions.
  • Risk management across the AI lifecycle: privacy‑by‑design, security‑by‑design, documentation and audit trails for models and datasets.

Implementation Framework

Implementation is envisaged through the Kratt programme and the national AI activity plan for 2019–2021. The report recommends piloting concrete use cases in e‑government services, healthcare, transport, agriculture and administrative decision‑making to test legal, organisational and technical arrangements. Implementation actions include developing procurement guidance for AI systems, creating standards and guidance material to assess safety and fairness, establishing documentation and recordkeeping practices for models and datasets, and defining responsibilities for contracting authorities. The report emphasises cross‑ministerial coordination to ensure consistent approaches to procurement, oversight and legal adjustments required for responsible deployment. The publication and dissemination of the report in spring 2019 preceded and informed the presentation of the 2019–2021 activity plan in May 2019. (Ministry of Economic Affairs and Communications announcement, DIGAR archive.)

Monitoring and Evaluation

The report calls for guidance and standards to help contracting authorities and regulators assess safety, fairness and legal conformity, and recommends maintaining documentation and audit trails for models and datasets so that oversight and ex post review are feasible. It foresees that existing supervisory bodies (for example, the data protection authority) and sectoral regulators would monitor compliance within their mandates, supported by standardised risk assessment practices and documentation requirements for public procurement. Monitoring includes lifecycle risk assessments, conformity checks during procurement, and continued evaluation of pilot outcomes to inform scaling decisions. The report additionally recommends developing evaluation criteria and indicators tied to pilot objectives and legal/ethical guardrails to evaluate whether solutions should be scaled across the public sector. (DIGAR archive.)

Penalties, Liability, and Appeals

The expert group’s report does not itself establish new enforcement powers or penalties. Instead, it recommends legal and regulatory adjustments where necessary so that existing supervisory bodies (for example, the data protection authority) and sectoral regulators can oversee AI deployments within their mandates. The report foregrounds the need to align any enforcement mechanisms with the GDPR and existing administrative law principles, and it emphasises procedural safeguards such as transparency, documentation, human review and avenues for contestation to enable appeal and redress against automated or AI‑assisted decisions. For liability and penalties, the report points to adapting existing legal frameworks and supervisory practices rather than creating a separate enforcement regime within the report itself. (DIGAR archive.)

Relationship to Other Instruments

The report situates national actions within the EU regulatory context and stresses compliance with the EU data protection framework (GDPR). It recommends that national legal proposals, procurement guidance and oversight mechanisms be developed with a view to EU‑level instruments and international cooperation so Estonia’s approach remains interoperable with EU standards. The expert group explicitly recommends aligning national measures with EU policy orientations and the EU data protection framework as a primary legal constraint and orientation for national action. (DIGAR archive.)

International Alignment

While focused on the national ecosystem, the report stresses alignment with international policy orientations to ensure interoperability and consistency. It highlights the importance of following EU‑level developments and aligning with international principles that guide trustworthy and human‑centric AI adoption (including those promoted at EU and OECD levels) so that Estonia’s national frameworks remain interoperable with broader European and international approaches. The report emphasises cooperation with international partners in standardisation, research and policy development. (DIGAR archive.)

Implementation Timeline

DateEvent
2019-05-01Expert Group report published (year) — the Report of Estonia’s AI Expert Group was published and disseminated in spring 2019 and served as input to the national AI activity plan (Kratt plan).
2018-03-27Riigikantselei press announcement of AI strategy project — government decision to create the expert group and coordinate inter‑institutional work leading to the 2019 report.
2019-07-01Influence on national AI action plan (2019–2021) — the expert group’s recommendations informed the national AI activity plan for 2019–2021 and related Kratt pilots and implementation tasks presented publicly in mid‑2019.

Compliance Checklist

RequirementDescription
Risk assessmentsConduct risk assessments across the AI lifecycle to identify legal, ethical and security risks prior to deployment and during operation.
Privacy‑by‑design & security‑by‑designIntegrate privacy and security principles into system design, procurement and implementation to ensure GDPR compliance and data protection safeguards.
Documentation and audit trailsMaintain documentation for models, training datasets, decision logic and changes to enable auditability and oversight by supervisory authorities.
Procurement proof of complianceRequire evidence of compliance with safety, fairness and legal conformity in public procurement of AI systems; develop procurement guidance and standards.
Transparency and contestabilityEnsure transparency of automated processes used by public bodies, provide avenues for human review and contestation of AI‑assisted decisions, and define organisational accountability.
Stakeholder engagementEngage private sector, researchers and civil society in pilots, open data initiatives and standardisation efforts to support responsible innovation.

Sources and References

SourceURL
Report PDF (State Chancellery)https://www.riigikantselei.ee/sites/default/files/riigikantselei/strateegiaburoo/eesti_tehisintellekti_kasutuselevotu_eksperdiruhma_aruanne.pdf
DIGAR archive of the expert group reporthttps://www.digar.ee/viewer/et/nlib-digar%3A945441
Riigikantselei — expert groups and coordinationhttps://www.riigikantselei.ee/valitsuse-too-planeerimine-ja-korraldamine/valitsuse-too-toetamine/rakke-ja-ekspertruhmad
Ministry of Economic Affairs and Communications — announcement of Kratt planhttps://www.mkm.ee/uudised/riik-avalikustas-plaani-eesti-krattide-jaoks?utm_source=openai
Plain English

This policy document provides recommendations for how Estonia’s public sector should safely and beneficially adopt artificial intelligence, influencing national strategy and pilot projects.

Published in 2019, this report by Estonia’s AI Expert Group offers a strategic framework for the country's public administration, including ministries and other government bodies, to integrate AI responsibly. While not a law, its recommendations directly shaped Estonia's national AI action plan for 2019-2021, known as the "Kratt" programme, which aims to pilot AI solutions in public services.

For any product manager or founder developing AI for the Estonian public sector, several key principles emerge. You must ensure: - Your AI systems are clearly defined, distinguishing them from simpler automation, as this clarity is crucial for future regulation and procurement. - All deployments uphold strong human oversight, transparency in decision-making, and strict compliance with data protection rules like the General Data Protection Regulation (GDPR). This includes safeguards against discriminatory profiling and clear avenues for human review of AI-assisted decisions. - Robust risk management is embedded from the start, following privacy-by-design and security-by-design principles, along with thorough documentation and audit trails for models and datasets.

The report itself does not introduce new penalties. Instead, it advises adapting existing legal frameworks and relying on current supervisory bodies, such as the data protection authority, to oversee AI use within their existing mandates. This means that while there isn't a dedicated "AI police," existing regulators will be expected to enforce relevant laws on AI applications. A practical pitfall to note is the emphasis on precise terminology; what you call "AI" might be interpreted differently by regulators, affecting how existing laws apply. Therefore, understanding and aligning with the evolving definitions and governance structures is crucial for navigating Estonia's AI landscape.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 9 marked complete

Plain-English obligations under Estonia - AI Expert Group Report (2019). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalProtection of fundamental rights and compliance with data protection rules (GDPR)Before processing personal data

    Applies to: Public bodies processing personal data with AI.

    Protection of fundamental rights and compliance with data protection rules (GDPR), including lawful processing, purpose limitation and safeguards against discriminatory profiling.
  2. #2ImportantRisk management across the AI lifecycleThroughout AI system lifecycle

    Applies to: Public bodies deploying AI systems.

    Conduct risk assessments across the AI lifecycle to identify legal, ethical and security risks prior to deployment and during operation.
  3. #3ImportantRisk management across the AI lifecycleBefore system design and procurement

    Applies to: Public bodies procuring and deploying AI systems.

    privacy‑by‑design, security‑by‑design, documentation and audit trails for models and datasets.
  4. #4ImportantMonitoring and EvaluationThroughout AI system lifecycle

    Applies to: Public bodies deploying AI systems.

    Maintain documentation and audit trails for models and datasets so that oversight and ex post review are feasible.
  5. #5ImportantImplementation FrameworkBefore AI system procurement

    Applies to: Contracting authorities procuring AI systems.

    developing procurement guidance for AI systems, creating standards and guidance material to assess safety and fairness
  6. #6ImportantOperational safeguards for public bodiesBefore AI system deployment

    Applies to: Public bodies using AI systems.

    transparency of automated processes, avenues for contestation or human review, and organisational accountability for outcomes of AI‑assisted decisions.
  7. #7ImportantKey Focus AreasBefore wide deployment

    Applies to: Public bodies deploying AI systems.

    Piloting AI solutions (Kratt pilots) in public services to validate use cases, procedures and safeguards before wide deployment.
  8. #8RecommendedDefinitions

    Applies to: Government bodies developing legal and administrative frameworks.

    recommends defining terms and clarifying the boundaries between ordinary automated processing and adaptive, data‑driven systems
  9. #9RecommendedPromotion of public–private cooperation

    Applies to: Government bodies implementing AI strategy.

    Promotion of public–private cooperation and open data initiatives to spur innovation

© Regulations.AI — created on 13-Jun-2026