Home

Donate
Analysis

Russia’s AI Law Puts Control Ahead of Capability

Dmitry Kuteynikov, Lyubov Popovets / Oct 2, 2026

Men use their laptops in a cafe on Arbat street, in Moscow, Russia. Vladimir Astapkovich / Sputnik via AP

Republish

Russia's first comprehensive law governing large foundation AI models took effect this month on Sept.1. The law was signed on July 26 after a substantially broader draft went through public consultation in the spring and was replaced in June by a narrower bill focused on large foundation models and state support for their development.

The law does less to manage the risks of AI than to establish a framework for supporting and controlling developers of large foundation models. The framework offers qualifying developers state support, a role in shaping AI policy and potentially protected markets in exchange for meeting requirements on Russian ownership, data localization and conformity with Russian law and what the statute calls “traditional Russian spiritual and moral values.”

Russia has spent decades extending state control over its digital space: data storage, communications, network infrastructure. Developers were bound by personal data and content rules, but AI largely fell outside that framework. Direction came from the 2019 National AI Strategy and regulatory sandboxes, but no law addressed the industry itself. The new law closes that gap at the layer that matters most: foundation models, the "brains" other AI systems are built on.

The layer is rather thin.

Development is led by Sber, T-Bank, Yandex and MTS. None is a startup, and all four depend on state licenses, contracts and goodwill. Sber is the state-controlled savings bank that rebuilt itself as a technology group; Yandex was the country's largest private tech company until sold to government-approved investors — the fate befallen T-Bank as well.

The layer's foundations are largely foreign, and mostly Chinese. Sber says it trains GigaChat from scratch, but on an architecture its own engineers describe as modeled on China's DeepSeek, with Qwen-style attention in the latest version.

The hardware is foreign too. Export controls bar Russia from advanced Western accelerators; its own designs are years away, and the compute behind these models mixes Chinese accelerators with Western GPUs bought before the controls or smuggled in through third countries. YandexGPT 5 Pro was built using Qwen-2.5-32B weights, while T-Bank's T-Pro and T-Lite and MTS AI's Cotype are built on top of successive Qwen generations. Absent from international leaderboards, they appear on Russian-language ones such as MERA (industry-backed) and LLM Arena, but well outside the top ten.

From regulation to support for model development

The first version of the law was published for public comment in March 2026. It was a different document, which tried to cover the whole field: the rights of individuals, governance structure, the allocation of obligations from model providers to system and service deployers, and intellectual property.

Russian lawyers, businesses and even government-related organizations heavily criticized it for poor drafting and controversial content. It appeared that several interest groups had drafted separate parts independently. Furthermore, it did not resolve any of the sector's legal issues, yet it granted government bodies a wide range of additional powers.

By June, both the concept and the title had changed. The comprehensive approach was dropped. Instead, the legislature passed the On Support for the Development of AI Technologies in the Russian Federation law. Its subject is narrower: large foundation models and measures supporting their development. The State Duma passed the bill in July, the Federation Council approved it later that month, and President Vladimir Putin signed it on July 26.

A narrow subject, a wide reach

The adopted law no longer regulates AI systems in general. Instead, it applies to "large foundation models,” defined as models with at least “1 billion parameters,” general enough to serve as a basis for software development and a wide range of tasks.

The parameter count is a relatively crude threshold. By comparison, the EU’s AI Act uses training compute — the amount of computing power used to train a model —alongside other criteria to identify general-purpose AI models and models with systemic risk. The European Commission’s guidelines use 10²³ FLOPs (floating-point operations) as an indicative criterion for identifying GPAI models, while models trained using more than 10²⁵ FLOPs are presumed to have systemic risk, subject to rebuttal.

A 1-billion-parameter threshold can encompass both relatively small open models that run on local hardware and models far larger than the threshold; it therefore does not map neatly onto the frontier of commercial AI. The final text also covers large foundation models made available to users in Russia, meaning that foreign developers serving the Russian market may fall within its scope.

The bargain

The law is built around two models’ statuses: "sovereign" and "national". The requirements for both largely overlap: the developer must be a Russian legal entity; responses to user queries must be generated and stored in Russian-owned data centers in Russia; the model must be assessed for conformity with Russian legislation and "traditional Russian spiritual and moral values," although the law sets no procedure and the rules for this assessment await a decree.

The law does not name the bodies that will conduct the assessment: the procedure, like the rules for granting the statuses, is to be set by a government resolution. According to Vedomosti, the Ministry of Digital Development is drafting it with the FSB and the FSTEC, the export-control and technical-security service. Under the proposed scheme, developers would disclose the model's architecture and filtering mechanisms, accredited laboratories would test its answers and try to bypass its safeguards, and the ministry would make the final decision.

Since the values are already listed in a presidential decree, the plan is to turn them into a dedicated benchmark, developed together with industry, against which models will be tested. The resolution has not yet been adopted.

The values are generally understood as "patriotism, service to the Fatherland, high moral ideals, a strong family, the priority of the spiritual over the material, humanism, collectivism," etc.

Russian models already appear to apply content moderation in that direction. A 2025 study of 14 models found that the two Russian models tested, Sber's GigaChat and YandexGPT, refused most often when prompted in Russian and about Russian-born figures. Its authors argue the moderation is tailored to a domestic audience. The law formalizes for the AI industry what general legislation already requires.

The difference between the two statuses is provenance. A sovereign model must be developed end-to-end by the Russian developer and technically reproducible by it. A national model may be built on a foreign model under an open license, provided the Russian developer determines and changes its essential characteristics.

Given the distance between Russian developers and the frontier, we read the national status as a legal pathway for Russian developers to build on open foreign models, including Chinese models such as Qwen, especially since prominent Western providers block Russian IPs.

The obligations are written in general terms: security measures, rules of use, safety documentation. The privileges are specific. Under provision 5 of Article 5 of the new law, status holders receive state support, a role in shaping state policy and access to state datasets, subject to FSB agreement. The government will also designate cases in which only sovereign or national models may be used, making the status a condition of market access.

Text and data mining as a gift

The most valuable concession is in copyright. Under provisions that take effect in March 2027, the law provides that certain computational uses of copyrighted and related-rights material do not constitute infringement. It specifically permits short-term reproduction in computer memory solely to train a sovereign or national large foundation model, provided the developer uses a lawfully obtained copy of the work or the work has been made publicly available and is accessible for analysis without technical restrictions.

The unusual feature is that the training provision is tied to the model's legal status. The same type of copying can therefore fall within the statutory exception when it is used to train a sovereign or national model but not necessarily when it is used to train a model outside those categories.

The treatment of AI training data differs sharply across jurisdictions. In the EU, copyright law permits certain text-and-data-mining uses, including exceptions for scientific research and broader training data unless rightsholders reserve their rights. The AI Act requires providers of general-purpose AI models to maintain a copyright policy and comply with EU copyright law, including respecting such reservation. In the United States, courts continue to consider whether particular AI-training uses qualify as fair use, while the US Copyright Office has separately examined licensing and other policy questions.

Russia has chosen a more explicit statutory approach for sovereign and national models, without establishing remuneration for rightsholders in the training provision. However, the exemption may still be narrowed before it applies; it is being actively discussed.

In terms of transparency, the law does not require every piece of AI-generated audio or visual material to carry a notice. Instead, beginning March 1, 2027, a person using a large foundation model to create audio or visual material must be given the ability to attach an AI notice, which they might not use in practice. The format, content and placement of the notice are to be agreed between the user and the provider of access to the model.

What the law leaves to decrees

The law is short — 13 articles — and leaves important implementation details to subsequent government rules. These include the criteria and procedures for sovereign and national status, the conformity assessment against Russian law and the procedure for access to data held in federal and other state information systems.

Federal laws and presidential acts may establish rules for the use of large foundation models in national defense and state security, operational-search activity, public order, counterterrorism and public administration. The list covers many of the areas where AI poses the greatest human rights risks: biometric identification, predictive policing, social media monitoring and movement tracking.

The law says nothing about how these uses should be regulated: no prohibitions, no human rights impact assessment, no independent oversight, no notification of affected persons, no route to challenge a decision. That leaves unresolved some of the procedural concerns the European Court of Human Rights identified in Glukhin v. Russia. Nikolay Glukhin was identified by Moscow's cameras after riding the metro with a cardboard cut-out of a political prisoner. The Court held that facial recognition against a peaceful protester violated his rights to private life and free expression.

One clause goes further than the carve-out. It grants the president broad authority over AI technologies as a whole, not merely large foundation models, including an open-ended power to exercise "other powers." The law nowhere specifies which questions must be settled by statute and which by decree. A policy domain has been handed to executive rulemaking with no boundary drawn around it.

Surveillance obligations apply to AI services as well. They are subject to the existing rules for information dissemination organizers, meaning services that let users exchange messages with each other or with the service. This includes chatbots, AI assistants and other interfaces that accept user input, regardless of audience size. They must store interaction data, including message content, in Russia and give the FSB access.

Borrowed vocabulary, different purpose

The individual elements are recognizable from elsewhere: a risk-based approach, transparency requirements, a distinct regime for foundation model developers, and technological sovereignty. But the EU AI Act attaches them to a different regulatory structure. It imposes obligations on general-purpose AI providers and additional requirements on models with systemic risk, while the broader AI Act uses risk tiers for AI systems and includes provisions intended to support innovation, including regulatory sandboxes.

But the EU AI Act arranges them on two levels. AI systems, the applications people actually use, are regulated by risk tier, from prohibited practices to high-risk uses such as hiring or credit scoring, with duties for both providers and deployers. For general-purpose AI models, the Act sets separate baseline obligations on general-purpose AI providers and additional ones on providers of models with systemic risk.

The categories also do different work. In the EU, the GPAI framework primarily allocates obligations: providers must maintain technical documentation, follow a copyright policy and publish a summary of training content, while providers of models with systemic risk face additional requirements for risk assessment, incident reporting and cybersecurity.

In Russia, the sovereign and national status also determines eligibility for specified state-support measures and can determine which models may be used in areas reserved for those categories.

Russia has adopted some of the vocabulary of contemporary AI regulation but uses the categories to combine regulation with industrial policy and technological sovereignty. The result is a system in which legal status can affect both the obligations imposed on a model developer and the benefits or markets available to it.

Several major provisions take effect March 1, 2027, including the rules governing sovereign and national models, developer obligations, AI-content notices and the copyright provisions. The government may also designate areas in which only sovereign or national models can be used. Until Sept. 1, 2032, that restriction does not apply to information systems using large foundation models that were created or operated as of March 1, 2027, provided the data is processed and stored in Russia.

Russia's answer to the AI race

Russia’s answer to the AI race is to build at the frontier but to own the checkpoint. Foundation models are where the stack narrows to a few companies, and a state that hands out the statuses they need to reach protected markets governs everything built on top of them without regulating a single application.

Sovereignty here means jurisdiction rather than capability: models that operate with data in Russia, under Russian legal requirements and, in some important cases, on foreign — particularly Chinese — model weights and hardware.

For countries that cannot afford to train a frontier model, the model offers a different proposition: domestic hosting and developers, foreign open weights where permitted, a domestic approval regime and preferential access to selected markets.

Russia has written that template, and it is already being marketed: Sber has proposed a BRICS platform for AI sovereignty, and says it is targeting states in Africa, Asia, Latin America and Oceania that want their own AI but cannot afford to build it. What travels with the models is the legal design around them: statuses, domestic registration and reserved markets. The exportable product is therefore not just AI capability, but a model of technological control.

Support Tech Policy Press
If you've found our work helpful, consider supporting us.

Authors

Dmitry Kuteynikov
Dmitry Kuteynikov is a lawyer specializing in AI governance and digital regulation. He holds a PhD in law and has published more than 60 papers on AI and digital law. He researches AI regulation across Eurasia with RKS Global and has taken part in AI policy work in several jurisdictions.
Lyubov Popovets
Lyubov Popovets is a data journalist, writing research papers and explainers on Russia’s digital policy, digital rights oppression and state-corporations relations at RKS Global.

Topics

Related

Perspective
AI and the Dangerous Fiction of ‘All Lawful Use’April 16, 2026
News
Vietnam’s New AI Law Balances Innovation Push With Tight State ControlMarch 23, 2026