Report

16. Sep 2026

Armenia: Digital Transformation and Governance Gaps

Challenges for German Foreign and Development Policy
Alena Epifanova
Visual DGAP Report_No-9_SEP-2026

Digital transformation is reshaping governance worldwide, yet technical modernization does not automatically translate into more democratic institutions. Artificial intelligence is changing how bureaucracy functions, how public debates are shaped, and how decisions are made – against a backdrop of strengthening digital authoritarianism, as surveillance and online-censorship technologies increasingly penetrate Germany’s partner countries, posing not only a risk to democracy but security threats. These developments raise new and urgent challenges for German and European foreign and development policy.

PDF

Share

This report is the first in a series examining digital transformation and the governance structures emerging around it through single case studies in the South Caucasus, the Western Balkans, and Central Asia. The series begins with Armenia, a country shifting its foreign policy toward strategic alignment and a closer partnership with the European Union, and moving fast on digital infrastructure while its governance frameworks struggle to keep pace.

Please download the PDF version to access all Input Papers and citations. 


Armenia’s Tech Hub ­Ambition: Fast Infrastructure, Slow ­Governance

Germany and the European Union Should Support ­Closing the Gap

Armenia has the ambition to become a tech hub connecting the South Caucasus with Europe and Asia. The government has placed digital transformation at the center of its national development strategy. Adopting emerging technologies such as artificial intelligence (AI) promises economic growth and a brighter exports perspective. Digital technologies bring also the democratic promise of more transparent public services, broader citizen access to information and participation, and a government more accountable to the people. Under Prime Minister Nikol Pashinyan and the Civic Contract party, Armenia has achieved significant results and advanced swiftly in securing major infrastructural projects as well as in digitizing dozens of public services and introducing e-participation platforms. However, success in these areas does not fully match what is needed for sustainable democratic digital governance: personal data protection, digital literacy, and cybersecurity. Germany and the European Union are well placed to support Armenia and to ensure it achieves its ambition of regional technological leadership without compromising its political choice of democratic and open governance.

Armenia’s Technological Ambition and Success

Armenia strives to become a leading regional tech hub by building an advanced digital infrastructure and modernizing its public administration. The 2021 Digitalization Strategy set as a national goal comprehensive transformation across government, economy, and society, with the aim to modernize public administration, drive economic growth, and ensure inclusive access to digital technology for all citizens. It also set internationally benchmarked targets. One was climbing from 67th place in the UN’s e-Government Development Index to be among the top 25 countries by 2025. This target has not yet been met, but there has been substantial progress: in 2024, Armenia reached 48th place, putting it in the “Very High” tier.

The establishment of the unified e-government services platform (e-gov.am) was one of the key initiatives that contributed to this achievement. It is the central gateway to online public services, including tax filing, property registration, and requests or complaints to state bodies. Various administrative bodies have also launched dozens of specialized official electronic platforms, such as the Ministry of Justice’s e-draft.am for public consultation on draft legislation. Subsequently, between 2022 and 2024, Armenia rose

from 64th to 27th place in the UN’s E-Participation Index, which measures the extent to which governments enable citizens to access information and engage in public consultations. However, this ranking captures the availability of participatory tools more than the quality of participation they enable and people’s trust in them.

Armenia has moved from digitizing services to building its computational capacity. The government’s principal achievements in this regard include the Nvidia-powered AI supercomputer at Yerevan State University, a partnership with Mistral AI, and the Nvidia-backed data center rank in Hrazdan. The largest of its kind in the South Caucasus, the latter is the result of a $500 million public-private partnership with the Armenian-American AI cloud company Firebird.ai and is built on Nvidia’s DSX platform. It was launched in August 2026 with the aim to deploy more than 70,000 most-advanced Nvidia Rubin and Blackwell graphics processing units (GPUs). When it was first announced in June 2025, the aim for the capacity of the data center was 100 MW, but it is now expected to reach 300 MW by the end of 2027.

Another signature project is the Virtual Institute of Artificial Intelligence. Launched in July 2025 by the Ministry of High-Tech Industry, it is supported by Amazon Web Services (AWS) and Mistral AI. It is designed as an open platform for researchers, startups, and technology companies. Combined with mentorship and funding support, the institute aims to foster domestic innovation and to integrate Armenian talent into the global networks of AWS and Mistral AI, positioning the country as a regional AI hub.

The government strongly prioritizes AI and has increased its ambition in this field. The new five-year program for 2026–2031 sets the goal of building AI computing capacity equivalent to at least 100,000 advanced GPUs, with 10 percent made accessible to research, education, startups, and the public sector. It also enshrines “AI first” as a core principle of public-administration reform, alongside “zero bureaucracy” and “digital by design.” Under this principle, state bodies must consider AI applications as a first option when addressing administrative tasks. In another clear institutional signal, the Ministry of High-Tech Industry had “Artificial Intelligence” added to its name in August 2026.

Governance Gaps and Vulnerabilities

Armenia’s government is going to deploy AI in public administration and has committed itself to the “AI first” principle under a framework that contains no requirement for impact assessment and no provision governing algorithmic decision-making yet. An independent assessment of the country’s public administration by the SIGMA program of the Organisation for Economic Co-operation and Development and the EU, published in late 2025, noted the absence of legal acts regulating the use of algorithms in administrative decision-making or of strategies for the uptake of AI and emerging technologies in the public sector. This shows that the digital infrastructure is being built faster than the rules to govern it are being written.

This matters because of the democratic logic and promise attached to digitalization: digital services are supposed to reduce barriers for citizens to participate in decision-making, and open data to allow journalists, civil society, and citizens to see what government does and to hold it accountable. In this context, the protection of personal data is a cornerstone of democracy as it safeguards privacy, free expression, and trust in public institutions. Secure data rights and adequate governance prevent surveillance, ensure electoral integrity, and increase public trust.

Three foundations play a crucial role in realizing digitalization’s democratic promise: the framework for governing data, human capacity, and the security of systems. In Armenia, each is currently lagging the technology.

Data

Armenia’s solid data governance framework has become outdated due to the rapid adoption of technologies, and it has significant institutional limits. In 2015, the protection of personal data was given constitutional status as part of fundamental rights and freedoms. That same year, the Law on the Protection of Personal Data was adopted and the Personal Data Protection Authority was created to oversee its implementation. The law declares the authority independent, but its structure is set by government decision and its head is appointed by the prime minister following nomination by the justice minister, albeit from a list of people recommended by at least five nongovernmental organizations. The accountability and independence of the Personal Data Protection Authority remain limited. It operates under the Ministry of Justice, through which it receives state funding. It is also constrained by its limited human resources, which is due mostly to the lack of specialists in the field of data protection in Armenia.

The 2015 Law on the Protection of Personal Data was an important milestone and is a solid base for data protection. However, while it provides a broad framework for data protection in the country, data processing in individual sectors is regulated by sector-specific legislation. In many cases, this legislation has failed to keep pace with the speed of digitalization, and it was not compliant from the outset with the data protection principles established by the 2015 law and comparable to those under the EU’s General Data Protection Regulation (GDPR). SIGMA’s assessment points out that, while there has been notable progress in digitalizing public services and in digital availability, there is insufficient alignment with the EU’s standards, including the GDPR. Harmonizing sector-specific legislation governing personal data processing is therefore emerging as one of the central challenges at the intersection of digitalization and data protection.

So far, no systematic use of AI tools across state bodies has been documented. However, there has been a case of the State Revenue Committee using AI to detect fraud, improve tax compliance, and determine taxpayers’ risk levels. A report on AI use in the public sector in 2025 indicated that AI adoption by public administration bodies is likely to grow quickly, inevitably involving personal data processing. The adoption of the “AI first” principle will accelerate this.

People

SIGMA has identified limits in human capacity and the lack of a structured approach to developing or retaining IT talent in the public sector. Only about 42 percent of surveyed public servants reported having received sufficient training on cybersecurity skills to understand risks and gain the know-how to avoid them. There is a structural mismatch at the core of Armenia’s digital transformation: the political will to adopt new technology is clear and consistently demonstrated but the public administration’s capacity to implement it is inadequate. Human resources in the public sector remain insufficient in number and staff are inadequately trained to apply new technologies, and capacity-building has not kept pace. As a result, the government’s ambitious decisions are not fully grounded in state capacity – a gap likely to persist in the coming years of reforms and to limit the government’s success, regardless of the strength of its intentions.

There has been no comprehensive quantitative assessment of the population’s level of digital literacy. This leaves the government without a baseline for targeted strategies on digital literacy, digital hygiene, or cybersecurity in formal or informal education. A further problem highlighted by Armenian practitioners in the digital field is the lack of awareness about data protection. A general understanding of privacy and the risks of digital surveillance is not fully internalized across society. While the government recognizes the problem and addresses it in its action plans, attention to data protection across the public and private sectors is insufficient and not fully addressed.

Cybersecurity

Armenia has begun to address the cybersecurity challenge systemically only in the last few years. In December 2025, after a long and intensive consultation process between the Ministry of High-Tech Industry, business, civil society, and the IT community, the first Law on Cybersecurity was adopted. It aims to set unified standards, given that until now every business and state body has developed its information systems independently while often neglecting cybersecurity altogether. The law defines critical information infrastructure, mandates incident reporting, and creates an independent regulatory authority, addressing the fragmentation that SIGMA identified in Armenia’s digital governance.

Armenia’s exposure to cyber threats has increased amid geopolitical tensions as the country’s pivots toward the EU and the United States, and as it integrates Western technologies into its infrastructure while decoupling from security institutions led by and long-standing dependencies on Russia. The digital domain has become the primary theatre for hybrid pressure and intelligence collection within Armenia. State-aligned actors, reportedly Russia’s APT28 (Fancy Bear) and cluster UNC5792, have intensified their attacks against government institutions and other targets, and shifted their operations from email to encrypted messaging platforms, exploiting the public’s trust in Signal and WhatsApp.

Given their role in strengthening democracy, human right defenders, independent media, and civic activists are strategic targets for such authoritarian actors. Civil society and independent media are the most heavily targeted sector in Armenia, and they experienced “at least eight” significant documented incidents in 2025. They are also the least prepared. Severely limited resources when it comes to hardware and software, backups, and clouds make civil society highly vulnerable.

Commitments for Good Governance

In the 2026 elections, Pashinyan and his party secured a mandate for their drive for Armenia’s technological leadership in the region. The government has started to close the gaps in digital governance and is trying to catch up with regard to regulations for securing digital democracy. But most of the responses so far have remained at the level of stated commitments and implementation of new legislation will be crucial.

Armenia has taken first steps toward meeting international standards by signing the Council of Europe’s Framework Convention on AI, Human Rights, Democracy and the Rule of Law in January 2026. The convention is the world’s first legally binding international treaty of its kind. It requires that AI systems be compatible with human rights, democracy, and the rule of law throughout their entire lifecycle: from design and development through deployment and retirement. It also obliges signatories to prevent algorithmic discrimination and unfair treatment, and to apply a risk-based approach to AI oversight, with obligations extending across the public and private sectors.

The government’s 2026–2031 program aims for a unified, secure AI environment for the public sector and a separate regulatory framework for the state’s AI use, to be grounded in risk assessment, data protection, cybersecurity, and mandatory human oversight, which closely tracks the Council of Europe convention. Implementing this quickly and creating an implementation and oversight body is as crucial as strengthening the protection of personal data, which will be inevitably impacted by the “AI first” principle.

Success regarding this commitment will significantly depend on the implementation of a parallel reform already underway: the transformation of the Personal Data Protection Authority. This is driven by the Visa Liberalization Action Plan that the European Commission presented in November 2025, which conditions progress toward visa-free travel with the EU on deliverables that include data protection. This requires a genuinely independent authority with adequate powers and the human and financial resources to exercise its mandate, effective implementation of data protection legislation across the public and private sectors, and training and awareness-raising programs for public institutions and officials. Given how politically salient the issue of visa liberalization is in Armenia, this is the strongest conditionality attached to any digital-governance reform currently available.

A package of draft legislative acts for ensuring the independence of the Personal Data Protection Authority has been presented for public consultation. One of these would introduce mandatory data protection impact assessments (DPIAs) where processing involves special categories of personal data or biometric data; where the nature, scope, purposes, or technology of processing may pose a high risk to rights and freedoms; or where the authority’s criteria classify processing as high risk. In principle, this could apply to AI use in public administration: such processing may qualify as high-risk under the criteria, which the authority has yet to define. But the legislation regarding DPIAs is still at the draft stage, and it is not yet clear to what extent it will cover the use of AI. Moreover, the time legislating and implementing will likely take means such a mechanism might not be in place before 2028.

Another key area is the capacity to enforce the Cybersecurity Law. Its provisions defining vital sectors for the country’s normal functioning. It aims for the adoption of international standards and introduction of a regulatory authority. These provisions are designed to bring clarity to sectors now rapidly adopting digital solutions and to end the fragmentation of responsibility across ministries. Together, they are intended to build a more resilient foundation for Armenia’s efforts to become a tech hub. However, the authority has yet to be established, while the shortage of specialists that constrains the Personal Data Protection Authority applies also here. The law’s provisions are sound but the capacity to implement them still needs to be built.

Recommendations

  • The EU should address through the Partnership Council with Armenia and in the implementation of the Visa Liberalization Action Plan the need for aligning an independent and well-resourced Personal Data Protection Authority with an up-to-date legislation on data protection and algorithmic accountability.
  • Through its Federal Ministry for Economic Cooperation and Development and Federal Foreign Office, Germany should support a sustained training program in data protection and AI law to address shortages in human resources in the public sector and civil society.
  • Germany and the EU should support the capacity of Armenia’s civil society to shape and monitor the country’s digital and AI governance. Funding for targeted legal and technical training in AI governance and data protection is needed now as the “AI first” regulatory framework is being drafted and civil society can contribute its perspective through the e-draft.am platform and consultations with the government. Additionally, civil society needs the technical capacity to monitor deployed systems for transparency, non-discrimination, and meaningful human oversight.
  • Given that civil society and independent media face the greatest volume of cyberattacks and remain poorly equipped technically, the European External Action Service should establish a long-term (five-year minimum) technical and institutional support package for them, directed at capacity-building, raising awareness about data protection, and cybersecurity.
  • Germany and the EU should fund public-awareness work on data rights alongside their technical assistance, and they should encourage Armenia’s government to build capacity based on genuine feedback and response data for its e-participation platforms, which will make the state’s performance visible and increase societal acceptance for reforms in this area.
  • European and German international cooperation organizations should support Armenia’s government in measuring the population’s digital literacy and developing a baseline for a targeted strategy in formal and informal education.
  • European and German international cooperation organizations should embed data-protection safeguards with clear rules and responsibilities in all stages of their projects in Armenia. European companies involved with Armenia should likewise be encouraged to require the standards of data protection and algorithmic accountability that Armenian law has not yet established, exporting EU-equivalent practice through commercial relationships while the domestic legislation is being shaped.

The publication was supported by the ­Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH.

The opinions expressed in this publication are those of the author(s) and do not necessarily reflect the views of the German Council on Foreign Relations (DGAP) or the Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH.

Bibliografische Angaben

Epifanova, Alena. “ Armenia: Digital Transformation and Governance Gaps.” DGAP Report 9 (2026). German Council on Foreign Relations. September 2026. https://doi.org/10.60823/DGAP-26-44043-en.
Lizenz

Themen & Regionen