Estonian experts develop cyber defence doctrine for the AI era

16.09.2026 | 13:18

Experts and researchers from Estonian government agencies, universities, technology companies and banks have developed a comprehensive cyber defence policy paper setting out recommendations for countries seeking to protect digital society in the age of artificial intelligence.

Initially conceived with smaller countries in mind, the doctrine has also attracted interest from larger states. It builds on Estonia’s experience as a highly digital society and on solutions already implemented in the country.

According to Tõnu Grünberg, Deputy Secretary General for Digital Infrastructure and Cybersecurity at the Ministry of Justice and Digital Affairs, AI has fundamentally changed both the nature of cyberattacks and the way countries must defend against them. It allows attacks to be launched faster, more cheaply, at far greater scale and against large numbers of targets simultaneously.

“An attacker, including one who is politically motivated, can afford thousands or even millions of failed attempts because the marginal cost of each additional attempt is close to zero. Sophisticated offensive capabilities are also increasingly accessible to people without advanced technical skills,” said Grünberg, one of the authors of the policy paper.

The authors note that AI can continuously search for new vulnerabilities, potentially reducing the time available to address them from weeks to just days or even hours. The doctrine therefore does not aim for complete invulnerability. Instead, it advocates an asymmetric approach to cyber defence: lowering the cost of defence, increasing the cost of attack and ensuring that cyber incidents do not become decisive in disrupting a country’s digital services.

The policy paper, "National Cyber Resilience in the Age of AI“, sets out six key recommendations for securing national digital services in the AI era.

First, countries should define what constitutes a minimum viable state. This means identifying the critical digital services and government functions that must remain operational even during the most severe cyberattack, while also ensuring that they regularly rehearse the fallback.

“The first step is to define the core perimeter that must be defended under all circumstances. Alongside this, countries should establish second- and third-tier services that can, if necessary, be temporarily suspended to conserve resources,” Grünberg explained. “Not everything can be protected to the same level. Countries therefore need to identify the services and functions whose disruption they simply cannot afford – whether digital identity, communications, electricity or core government functions. For these critical services, it is not enough to know how to prevent an attack; countries must also know how to continue operating when a system or service provider fails.”

Second, countries should harden their national trust backbone. Digital trust should be anchored in services protected to such a high standard that compromising them becomes economically irrational for an attacker. The doctrine also emphasises the use of zero-trust architecture, under which no external device or data request is trusted by default.

Third, security must become a prerequisite for systems to operate, backed by enforceable standards. National regulation should raise the overall baseline level of security and eliminate low-cost entry points for attackers.

Fourth, the automation of cyberattacks means that defenders must be able to act at machine speed while remaining within the law.

“Humans alone can no longer respond quickly enough to attacks generated with the help of AI. AI must be countered with AI,” Grünberg said.

Countries need real-time visibility across their digital environments, fewer unmanaged devices and the ability to respond within an attacker’s window of opportunity rather than only after the damage has been done.

Grünberg also said that public-sector organisations should make more confident use of secure public cloud services offered by global providers.

Fifth, the doctrine calls for a whole-of-society approach to cyber defence. Cyber resilience cannot rest solely on specialist teams: citizens and organisations across society need to be better equipped to recognise threats such as phishing and deepfakes.

Sixth, democratic trust must be protected through proactive transparency. Governments need to communicate openly and quickly and tell the truth first, because public trust is strengthened by openness rather than concealment.

The importance of cyber defence will increase further as AI agents begin to use digital services autonomously on people’s behalf. Their actions will also need to be secure, accountable and subject to appropriate control. The safe operation of such proactive digital services will depend on strong and asymmetric cyber defence.

“In the age of AI, cyber defence cannot be limited to preventing every possible attack. A digital state must be designed to continue performing its most important functions even under severe attack,” said Joonas Heiter, Director General of the Estonian Information System Authority (RIA) and one of the authors of the policy paper.

“To achieve this, we need to know what must be protected at all costs, reduce critical dependencies and be prepared to recover quickly. Cyber resilience must be built into the architecture of the digital state itself. And once an incident has been resolved, it should be explained to society as openly as possible in order to preserve public trust.”

The policy paper „National Cyber Resilience in the Age of AI“ was developed with contributions from experts and researchers across a range of organisations. Its authors are Andres Raieste, Tõnu Grünberg, Joonas Heiter, Andri Rebane, Taavi Viilukas, Madis Tapupere, Toomas Vaks, Priit Liivak, Andres Kütt and Rain Ottis.

Press release by the Ministry of Justice and Digital Affairs, 15 September 2026

Ministry of Justice and Digital Affairs

open graph imagesearch block image