.jpg)
What Estonia Decided Not to Legislate
A software agent gains access to a corporate account. It executes a transfer, accepts the terms of another service, contracts a second system, and triggers damage. No person pressed "confirm" at that moment.
When the affected party asks who pays, they will discover that the decisive question is not whether the machine thought. It will be another: under whose authority it acted and where the proof remained.
In July 2024, the United Nations Commission on International Trade Law adopted the Model Law on Automated Contracting. The General Assembly welcomed it in December of that year. Its article 7 provides that, among the parties to a contract, the attribution procedure they have agreed to governs first; if none exists, the action of the system is attributed to whoever employed it for that purpose. The unexpected result, by itself, does not allow that attribution to be disregarded.
It is a useful reference, not a complete answer. This Model Law has not been adopted by Costa Rica. Furthermore, the text governs the formation and execution of automated contracts; it does not create a universal regime for repairing damage caused by agents.
But Costa Rica does not start from scratch either. The article 35 of Law 7472, the Law for the Promotion of Competition and Effective Consumer Protection, makes the producer, supplier and merchant jointly and severally liable within consumer relations, regardless of fault. The article 190 of the General Law of Public Administration establishes the objective liability of the Administration for its lawful or unlawful operation, normal or abnormal, except for force majeure, fault of the victim, or act of a third party.
That matters, but it does not work magic. Objective liability eliminates the obligation to prove fault; it does not eliminate the need to demonstrate damage and its connection to a specific action.
That is where the Costa Rican gap appears.
There is no uniform, interoperable way today—verifiable by citizens—to reconstruct across the entire public sector what system acted, under what version, with what permissions, on what data, by order of whom, and at what time. There may be logs in specific institutions. The National Code of Digital Technologies of 2026 already speaks of documenting, monitoring, auditing, and reporting artificial intelligence incidents. These are the right verbs. They have not yet formed a common memory of the State.
Legal attribution without an architecture of evidence looks too much like a promise no one can execute.
Estonia arrived at this discussion earlier and by the long way around.#
In 2017, its digital advisor opened public debate on a kratt law —a law of the kratt, a name taken from a creature of Estonian mythology that comes to life to serve its master—. In March 2018, the Government formalized a group of experts that studied, among other possibilities, whether autonomous systems should receive their own legal personality. It was one of the earliest and boldest state debates on the subject.
In May 2019 came the conclusion: Estonia did not need to turn the kratt into a person or rewrite the foundations of its legal system. Nor did it consider it wise to create a central registry of all autonomous technologies; it judged that a form of anticipatory regulation.
The report proposed something more sober. Attribute the actions of systems used in public functions to the State and those of private systems to the user; clarify responsibility; review evidentiary barriers in product safety; consider aggravated risk in sensitive applications; and adjust criminal imputation when a person uses or creates a system to produce an unlawful result.
Costa Rica has already possessed part of that framework since 1978 and 1994. Not all of it. General rules do not by themselves resolve automated contracting, the chain between developer, integrator, and operator, proof locked in foreign software, or the preservation of evidence after a model update.
Seven years later, the question returned with far more capable agents. In June 2026, Prime Minister Kristen Michal announced that Estonia would be the first country to assign personal identification codes to artificial intelligence agents. The announcement sounded like a passport for machines. It did not last long.
On September 8, Anni Lehari, head of the public Aruait project, clarified to ERR that agents will not receive those codes. The announcement, she said, had served as a communications resource. The technical objective is different: to allow an agent to act on state portals and to link each of its actions to the person in whose name it operates. According to the line described by the project, the person would still be liable; the exact legal architecture remains under discussion.
The correction is not merely semantic. A unique number would have suggested separate identity. Linking proposes a chain of mandate: person, authorization, agent, action. Instead of creating a new responsible party, Estonia is trying to prevent the one who already exists from disappearing.
The same article contains an even more valuable admission. Estonia does not have today a complete vision nor a safe way to open its 800 direct public services to agents. Aruait, funded with one million euros and scheduled through the end of 2028, is barely working on authentication, information security, data protection, and legal rules. Europe's most admired digital laboratory has not solved the problem either. It has managed to formulate it better.
The Estonian lesson is elsewhere.#
On X-Road, its distributed infrastructure for data exchange, Estonia mounted andmejälgija, the data tracker. From the state portal, a person can consult operations performed on their data: what agency intervened, when it happened, and, depending on the service, for what purpose. Participating databases implement a common protocol and maintain records in a distributed architecture.
The tracker does not necessarily cover all records in the country. Nor does it explain by itself the reasoning of a model or prove the causal link of harm. It does something prior and essential: it converts an invisible operation into a dateable and attributable fact.
Estonia avoided registering each machine and began registering what the State did with the data. For the age of agents, that distinction is worth gold. An inventory ages every time a model changes. A log of actions preserves the history of what actually happened.
The 2026 discussion adds two requirements: revocable authorization and verifiable link to the principal. A permanent credential for the agent would be a poor copy of human identity. What is useful is a digital power limited by purpose, time, amount, data, and tools, capable of expiring or being revoked in seconds. Each use of that power should appear in the log.
The United Kingdom added another piece: assigning legal functions before the accident. The Automated Vehicles Act received royal assent on May 20, 2024. For each authorized vehicle it provides an authorised self-driving entity, a legal entity responsible for ensuring the vehicle continues to meet the autonomous driving standard. When the service operates without a user in charge, a different figure appears: the authorized operator, responsible for supervising the operation and addressing problems unrelated to the driving task. The law also makes it possible to identify a natural person responsible for the information delivered to the regulator.
Concealing or falsifying relevant safety information can lead to five years in prison. The aggravated form reaches fourteen years when the information would have revealed a high risk, an incident of that kind occurs, and the result is death or serious injury.
One must resist the temptation to sell this design as a done deal. As of September 2026, the central authorization procedure is still not in force and full implementation is projected for the second half of 2027. Insurance and civil indemnification, moreover, rest mainly on British legislation from 2018. The British contribution, for now, is a regulatory grammar: each autonomous function must have behind it an identifiable legal entity, defined duties, and capacity to respond.
California incorporated the clock. Law SB 53, signed on September 29, 2025, requires developers of frontier models to report critical safety incidents. The ordinary timeframe is fifteen days to the state emergency office; in the face of an imminent risk of death or serious physical injury, initial notice must be given within twenty-four hours to the competent authority. Loss of control appears in the definition when it causes death or bodily injury. It is a narrow regime, designed for catastrophic risks of frontier models, not a template to be copied unchanged for any digital assistant.
South Korea added jurisdiction. Its Framework Act on Artificial Intelligence, in force since January 22, 2026, reaches conduct carried out outside the country when it affects its market or its users. Foreign operators without local establishment that exceed the regulatory thresholds must appoint a representative in Korea. The absence of a representative never makes all cross-border execution impossible, but it can make it slow, expensive, and in practice useless for an individual victim.
With these experiences on the table, Costa Rica can move forward without waiting for an encyclopedic law.
First is a public inventory based on capacity and risk, not a census of every tool bearing the label "AI". It should cover systems capable of exercising a public power, moving money, modifying a file, accessing sensitive data, communicating on behalf of an institution, or ordering actions by other systems. Each deployment would have to identify the owning institution, the provider, the model and its version, the tools and permissions granted, the responsible person, the supervision mechanism, and the emergency switch.
The Central Administration can initiate pilots and inventories through administrative instructions. Extending a homogeneous obligation to autonomous institutions and municipalities will require more careful regulatory architecture. The objective liability of the State does not by itself create a register.
Second is to move from inventory to log. Each action with legal consequences should generate a tamper-resistant record: transaction identifier, time, institution, system and version, authority under which it acted, permissions used, sources consulted, calls to other services, human approval when appropriate, and result. Citizens do not need to see security secrets or internal reasoning chains. They need to know what automated action affected them, what data it used, and who is responsible for it.
That would be the true leap over andmejälgija: to evolve from "who consulted my data" to "what automated power acted on my life".
Third is to create an operator of registration for high-impact deployments. Not an electronic personality. An identified company or institution, with local contact, solvency proportional to the risk, duty to preserve evidence, obligation to keep the system within declared parameters, and a natural person responsible for the information delivered to the regulator. In some sectors insurance will be needed; in others, financial guarantee or repair fund. The answer should follow the risk, not legislative fashion.
Fourth is to impose a tiered duty to report incidents. Twenty-four hours for initial notice when there is an imminent threat or ongoing harm; a full report after preserving evidence and investigating. For common agents, the catalog must include unauthorized material actions, privilege escalation, irreversible transfers or publications, improper data access, inability to resume human control, and propagation of orders to other systems. Copying California's catastrophic definition would leave out nearly all the everyday harms that matter in a small state.
Fifth begins in public procurement. Contracts must require audit access, log portability, prior notice of model changes, incident notification, evidence preservation, subcontractor traceability, shutdown mechanism, and a valid address for notifications. Article 42 of Law 7472 can already override certain exemptions in adhesion contracts; the challenge is not solved by declaring every AI clause valid or invalid. It is solved by preventing the contractual distribution of risks from erasing evidence or leaving the public operator without remedy.
Sequence matters. In ninety days, three institutions could pilot a common inventory scheme and select a high-impact procedure. In six months, they could test an interoperable log and simulate an incident with evidence preservation. In a year, Costa Rica could open an initial version of the citizen tracker and send Congress a bill built on observed failures, not imported fears.
That would not automatically produce "the first litigable case". It would do something more serious: increase the likelihood that the next case reaches a judge with reconstructible facts.
The country that governs agents best will not be the one that writes the longest definition of artificial intelligence. It will be the one that can reproduce, minute by minute, what a system did, under whose authority and with what consequences.
Law without memory is rhetoric. In the age of agents, power must leave receipts.
Sources#
- UNCITRAL, Model Law on Automated Contracting (2024) and official text in Spanish.
- Government of Estonia, Report of Estonia's AI Taskforce (May 2019).
- Marten Kaevats, Estonia considers a "kratt law" to legalise Artificial Intelligence (2017).
- ERR, AI agents will not get Estonian ID codes and responsibility will stay with humans (September 8, 2026).
- Estonia Information System Authority, Data tracker and official system repository.
- e-Estonia, X-Road.
- United Kingdom, Automated Vehicles Act 2024 and Department for Transport, implementation program.
- California, official text of SB 53 and governor's signature announcement.
- Republic of Korea, Framework Law on Artificial Intelligence Development and Establishment of a Trust Foundation.
- Costa Rica, Law 7472, articles 35 and 42.
- First Chamber of the Supreme Court of Justice, objective liability of the Administration and article 190 of the LGAP.
- MICITT, National Code of Digital Technologies, 2026 version.
- Office of the Attorney General, scope of guidelines regarding administrative autonomy.
.jpg)
.jpg)
.jpg)