Tallinn University of Technology

Nino Panjakidze, a TalTech Student Ambassador from Georgia studying E-Governance Technologies and Services (MSc) interviewed Dr. Silvia Lips. She is a lecturer and researcher in the e-Government Technologies and Services curriculum at the Department of Software Science. Silvia has a distinguished background in law and recently defended her Ph.D. in Information and Communication Technology at TalTech. Her primary research focus is Electronic Identity (eID), authentication solutions, and their cross-border applicability.

Silvia Lips

Parallel to her academic work, she serves as an eID expert at the Information System Authority (RIA) and is the EUDI cooperation Group member at a EU level. My aim is to discuss the importance of this program and why this profession matters to you personally. How do you see your various roles in this domain?

Silvia: While I hold multiple roles, they are all deeply connected through the concept of Electronic Identity (eID). Essentially, eID is what enables access whether to an e-service, our own computers, or our personal data.

My research focuses on this, but the impact goes beyond the technical. People rarely think about access management until something stops working. That is exactly where I feel I can be useful. Whether through research or the projects I work on, I want to spread knowledge about the importance of identity management. I try to stay updated on practical trends through my work at the Information System Authority (RIA) and then bring those insights back to the academic world through research papers, seminars, and teaching. In the IT sector, there is a constant lack of personnel, particularly e-government specialists. I feel I am contributing by helping to prepare these experts for the market.

For me, sharing experience isn’t limited to Estonia; I am glad to work with international delegations. Whether I am meeting with experts or high-level policymakers such as ministers from Asian, European and African countries, my mission is to help them understand that digital progress cannot happen without these foundational elements.

 Your international experience is significant. From your work with global policymakers, what aspects of the Estonian digital model tend to surprise them the most?

Interestingly, the challenges are quite similar across different countries. Many policymakers assume that digital transformation is purely a technological task, that they can simply take a technical solution, implement the same legal framework, and achieve the same success as Estonia.

When we explain that it doesn’t work that way, it often comes as a surprise. You cannot achieve success without assessing your own country’s maturity level and specific context; there is no “one-size-fits-all” solution in digital governance. This is why we need experts who can recognize the specific points that need to be addressed in a concrete local context.

Perhaps the most difficult realization for them is that while you can run a procurement for a technical solution, you cannot run a procurement for Trust. Building trust between the government and its citizens is a complicated mechanism that requires significant investment. While some parties start with great enthusiasm, they still prefer to invest in infrastructural changes, rather than building trust, as it is taking too much time and resources. But even if they only implement 30% or 40% of their initial plan, it is still a step forward. Each step builds a bit more trust and makes life easier for the citizens.

Estonia is often seen as a fully realized digital society. Have there been moments where the dependencies we’ve created on these digital services revealed significant risks?

That is a critical point. In Estonia, we are currently strengthening our resilience because of what we learned from the 2017 “ROCA vulnerability” (a vulnerability discovered in the chips used for Estonian ID cards). We realized how many deep dependencies we had created. When your life is dependent on having an eID, it is no longer just a “click” on a computer; it is a matter of practical survival.

For example, during that crisis, we handled cases where an emergency brigade could not hand over a patient to a hospital because they could not log into the portal. We saw risks where a diabetic patient might not be able to access life-saving medicine because the pharmacist could not verify a digital prescription. These are not just “risk scenarios” they are real cases.

Because of this, the Estonian government now treats authentication and digital signing as Vital Services, just like electricity or water supply. My advice to other countries is to think about prevention from the start. You will end up in this situation eventually, and if you don’t have a “Plan B” or “Plan C,” the risks can materialize in very human ways.

Moving from local resilience to the future, are there any major upcoming projects that you are particularly excited about?

We are already in the middle of a very challenging transition toward the EU Digital Identity Wallet. This is an initiative for all European countries, and it is a bit like writing a song that the whole “European orchestra” hasn’t played together yet. We don’t know exactly how the music will sound once all these different ecosystems try to work together.

I am very curious to explore the potential for interoperability and a digital common market. Currently, I am keeping myself updated by contributing to these developments daily, not just in Estonia, but also through my research with the University of Luxembourg on their own digital wallet implementation.

 Looking ahead, what do you believe will define the next generation of digital states over the next decade?

Silvia Lips

Predicting a decade out is challenging because of how fast Artificial Intelligence is accelerating development. However, in my domain of authentication, I see two major shifts coming in the next two to five years.

First, I expect to see Adaptive Authentication solutions. These are “smart” systems that adapt to user behavior. If you log in from your usual IP address, the system might allow easy access. If you are traveling and logging in from a different country, the system would automatically require more credentials.

Second, I believe we will see a surge in Biometrics (such as facial recognition or fingerprints) for government services. We already use these features with major tech companies, but the question for governments is defining the Level of Assurance (LoA). How do we ensure these systems are secure against AI-driven threats like injection attacks or deepfakes? It is a constant “chase” between governments and those who wish to misuse the systems, but I already see biometrics coming to Estonia.

We’ve discussed the power of technology, but that brings the risk of unethical implementation. How do we ensure that both governments and tech giants remain responsible and keep AI human-centric?

That’s a very interesting question, as Europe has taken a historic step with the Artificial Intelligence Act (AI Act). It is a strong statement that we are defining risk levels for AI-based systems. Interestingly, the field moves so fast that although the Act was finalized in 2024, the European Commission already proposed amendments by the end of 2025. This shows the need and urgency of development.

On one hand, this regulation is beneficial because it makes discrimination visible. In the physical world, if you are rejected for a job, you might never know why or have the evidence to prove discrimination. With AI in high-risk domains like (HR), we can build processes to audit the system’s decisions. It brings these issues into the light.

On the other hand, countries with “borderless” or less regulated environments might have more freedom to experiment by bypassing data protection and security concerns. However, I believe boundaries are necessary. The Netherlands’ child benefits scandal is a “textbook” example of what happens when technology goes unchecked. The government used an AI-based approach to detect fraud, which misidentified thousands of innocent families, leading to devastating human consequences and the fall of the government. This is why we need rules; we are often not ready for the consequences that unmanaged technology can bring.

As a successful alumna of this program, what advice would you give to students who want to work at this intersection of technology, governance, and public policy?

The most valuable thing this program gives you is interdisciplinarity. We have many technical people and many policy people, but putting them in the same room is often a tricky thing because they don’t speak the same language.

The most valued professionals today are the “translators” , the people who understand what the technical teams are saying and can explain its importance to policymakers in a way they process the data. I encourage anyone with big dreams of making an impact to fill this gap. Every country needs people who can bridge these domains to support responsible digitalization.

Do you want to study an international programme?

You can get more information about TalTech study programmes, admissions, and deadlines on the international admissions page. Also, You can learn more about studying at TalTech during the upcoming Online Info Session on May 7 at 18:00 (EEST). This is a great opportunity for all future students to e-meet TalTech staff and international students and ask them questions.

Bänner