Part of the AI Regulation News hub.
Estonia's TTJA has published guidance describing the AI Act supervision role it says it will take on, and the documents it expects to be able to demand
The interesting thing about Estonia's AI supervision guidance is its grammar. TTJA says it will become the competent authority, will supervise these products, will monitor transparency. Not yet, on its own telling.
Bottom line: Guidance on an authority's website. It binds nobody, creates no new obligation, and describes TTJA's supervisory role in the future tense throughout.
Who this affects: Estonian product compliance managers, CE-marking and conformity leads, importers and distributors of AI-enabled equipment, and general counsel at companies deploying AI in high-risk domains.
Issue date: Page last updated 3 August 2026. The transparency deadline it cites is 2 August 2026; the high-risk deadline row on its own table reads as still being clarified.
What changed: TTJA put its expectations in one public place: the categories of product and domain it says will fall under it, the eight prohibited practices, and an itemised list of what it says it can require from a provider.
Analysis: Read the list of demands, not the reassurance. Training, validation and testing datasets, automatically generated logs and access to source code are things most vendors cannot produce on short notice for a system they resell rather than build. The contractual time to secure those rights is before an authority asks, and the guidance is a free preview of the ask.
Primary sources: TTJA, Tehisintellektisusteemid · Regulation (EU) 2024/1689 on EUR-Lex
- Instrument (EN)
- Guidance page: Artificial intelligence systems (Tehisintellektisusteemid)
- Authority
- Tarbijakaitse ja Tehnilise Jarelevalve Amet (TTJA), Estonian Consumer Protection and Technical Regulatory Authority
- Jurisdiction
- Estonia
- Status
- Published guidance, described by TTJA as covering a role it will hold in future
- Bindingness
- None. Website guidance; the binding instrument is Regulation (EU) 2024/1689
- Issue date / next deadline
- Last updated 3 August 2026; transparency obligation cited as applying from 2 August 2026
- Contact route
- info@ttja.ee, given on the page for questions on applying the new requirements
- Primary source
- https://ttja.ee/ariklient/ohutus/tooted-teenused/tehisintellektisusteemid
Guidance written in the future tense
TTJA states that it will in future fulfil the role of competent authority in the supervision of AI systems. The same construction runs through the page: products that will fall under TTJA supervision, domains that will fall under it, transparency requirements TTJA will begin to monitor.
That grammar is the most load-bearing thing on the page. An Estonian company reading it should not conclude that TTJA is currently exercising AI Act market surveillance powers over it, and the page does not say so.
TTJA describes the role as similar to ordinary product and service safety control, with a specific focus added for AI components and systems.
The list of things TTJA says it can ask for
The page sets out what TTJA, as a supervisory authority, has the right to request, and states plainly that the list is not exhaustive and that other materials may be required depending on the situation and the law.
It names documentation and datasets used to train, validate and test the system, and automatically generated logs. It names access to the system's source code. It names information needed to assess conformity of a high-risk system, including personal data where that touches law enforcement, border control or the administration of justice. And it names the power to require corrective measures from the provider: withdrawal from the market, retraining, or recall.
On cooperation, the page reproduces the substance of Article 21: providers of high-risk systems must, on a reasoned request from a competent authority, supply all information and documentation needed to demonstrate conformity, in a language the authority readily understands and which the member state has indicated; must where relevant give access to the automatically generated logs under their control; and the information received is treated as confidential.
Scope, as TTJA draws it
On the product side the page lists machinery, toys, lifts and lift safety components, cableways, equipment and protective systems for explosive atmospheres, radio equipment, pressure equipment, personal protective equipment, gas-burning appliances and rail system interoperability.
On the domain side it lists critical infrastructure, education and vocational training, occupational safety, worker management and self-employment, access to and use of essential private and public services, law enforcement, migration, asylum and border control management, and the administration of justice and democratic processes.
Eight prohibited use cases are enumerated for developers: deliberate manipulation of people using AI, exploitation of vulnerability, social scoring, criminal risk profiling, large-scale downloading of facial-recognition data, emotion recognition in the workplace and in educational institutions, biometric categorisation by sensitive characteristics, and real-time remote biometric identification by law enforcement.
The dates on TTJA's own table
TTJA gives a three-row risk table. Prohibited systems: placing on the market and putting into service prohibited from 2 February 2025. Limited-risk systems such as chatbots and AI assistants: transparency obligation applies from 2 August 2026. High-risk systems: the deadline column reads as still being clarified.
That last cell is a fair reflection of where the EU calendar sat when the page was updated, and it is more honest than a table that asserts a firm high-risk date.
The page also points readers to the European Commission's AI Act Compliance Checker and service desk, to the Commission guidelines on prohibited practices in Estonian, and to a study on AI and machine learning technology risks prepared by Cybernetica AS for the Estonian Information System Authority.
What we did not verify
We opened the TTJA guidance page in full, in Estonian, and took every item above from it, including the risk table, the request powers, the product and domain lists and the eight prohibited practices. The page's own footer gives 3 August 2026 as the last update.
We did not open the Cybernetica study, the Commission's Estonian-language guidelines PDF, the Compliance Checker, or Regulation (EU) 2024/1689 itself for this piece. We did not check Estonian national legislation to see whether TTJA has been designated as market surveillance authority in law.
We do not claim TTJA currently holds AI Act market surveillance powers, that Estonia has completed its national designation, or that any of the request powers listed can be exercised today. TTJA's own page puts them in the future tense and we are not going to put them in the present.
Treat this page as a published scope of inspection rather than as a new obligation. The categories TTJA lists are the ones where an AI component turns an ordinary product file into an AI Act file, and the evidence it says it can demand includes training data, logs and source code. If your supplier contracts do not already give you access to those, the gap is contractual, and it is easier to close before an authority is on the phone than after.
Source File
https://ttja.ee/ariklient/ohutus/tooted-teenused/tehisintellektisusteemid
Open the TTJA page Tehisintellektisusteemid and confirm the sentence placing TTJA's competent-authority role in the future, the three-row risk table with 2 February 2025, 2 August 2026 and an unresolved high-risk date, and the bulleted list of documents and access TTJA says it may require.
TTJA will in future fulfil the role of competent authority in the supervision of artificial intelligence systems. ยท TTJA guidance page, last updated 3 August 2026, translated from Estonian
FAQ
Is TTJA now Estonia's AI Act market surveillance authority?
The page does not say that. It says TTJA will in future fulfil the role of competent authority in AI system supervision. We did not verify any Estonian legal act making the designation.
What can TTJA ask a provider for?
Per the page: documentation and datasets used for training, validation and testing, automatically generated logs, access to source code, information needed for high-risk conformity assessment including personal data in law enforcement, border and justice contexts, and corrective measures such as withdrawal, retraining or recall. The page states the list is not exhaustive.
Which deadline does the page treat as firm?
Two. Prohibited systems from 2 February 2025, and the transparency obligation for limited-risk systems from 2 August 2026. The high-risk row of its table is left as still being clarified.
Does the guidance change what a company must do?
No. It is guidance on an authority's website and binds nobody. The obligations it describes come from Regulation (EU) 2024/1689.
Related briefings
Sponsored Training
Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.