On 8 July 2026, the State Duma passed, at its third reading, draft federal law No. 1271570-8 “On Supporting the Development of Artificial Intelligence Technologies in the Russian Federation” (hereinafter referred to as “the Act” / “the AI Act”). The Act consists of just 13 articles and is of a framework nature. We expect the first subordinate legislation to be adopted in autumn 2026.
1. Overview of the New Requirements for Artificial Intelligence
Scope of regulation
The Act introduces a definition of artificial intelligence (hereinafter referred to as “AI”), however, it links the main obligations and restrictions to large foundational AI models (hereinafter referred to as “LFM AI”). The scope of the Act is limited to matters relating to the development, deployment and use of LFM AI.
|
Definition |
Examples |
|
“LFM AI” are computer programs (or their components) that simultaneously meet the following criteria:
|
|
Thus, models that do not meet all the criteria specified in the definition should not fall within the scope of the Act.
Sovereign and national large AI models
Article 6 of the Act introduces two new, but not the only possible, categories of models:
|
|
Sovereign |
National |
|
Developer |
A Russian legal entity[1] |
|
|
Components |
Produced entirely by a Russian developer |
May be produced outside the Russian Federation, provided they are distributed under an open licence |
|
Localisation |
The processing of user enquiries and the storage of data are carried out in data centres located within the Russian Federation and owned by Russian legal entities |
|
|
Further assessment of the model |
Compliance of the model with Russian legislation and traditional Russian spiritual and moral values[2] |
|
Support for sovereign and national models
According to the text of the Act, developers of sovereign and national AI models are entitled to support measures, which are to be established by the Government of the Russian Federation and may include, among other things, financial, property, guarantee and information support.
Restrictions
The Government of the Russian Federation may specify cases in which only sovereign or national AI models may be used.
According to the explanatory note, this primarily concerns sensitive areas – state information systems. Nevertheless, the list of restricted cases to be adopted in the future may prove to be broader, which would entail a mandatory obligation to switch to the specified AI models and abandon foreign ones.
Labelling of content created using AI
A separate article of the Act is devoted to providing information warnings regarding the use of AI technologies (labelling). The provision is discretionary in nature: labelling is a right of the person using the AI model, rather than an obligation.
2. AI and Personal Data
Risks relating to localisation
The requirement for the localisation of sovereign and national AI models under Article 6 of the Act differs from the requirements of Part 5 of Article 18 of Federal Act No. 152-FZ of 27 July 2006 “On Personal Data” (hereinafter the “Personal Data Act”) (see the comparison in the table below).
|
|
The AI Act |
The Personal Data Act |
|
|
Composition of data |
Any data, including personal data |
Personal data |
|
|
Data subject |
User (any individual) |
Citizens of the Russian Federation |
|
|
Location |
Data center within the Russian Federation |
Database within the Russian Federation |
|
|
Owner |
The owner of the Data center is a Russian legal entity |
No country-specific association |
|
In practice, data centres serve as the physical infrastructure where servers containing databases are located.
The requirements of both laws apply in parallel. For example, if a developer seeking sovereign or national model status processes the personal data of Russian citizens, they are obliged to ensure that such data is initially collected in databases located within the Russian Federation. However, simply localising the database within the Russian Federation does not in itself qualify the developer for sovereign or national model status if the data centre is not owned by a Russian legal entity.
Consequently, entities seeking to be recognised as developers of sovereign and national AI models must verify that their existing data centres comply with the requirements of the new AI Act, including ensuring that such data centres are owned by Russian legal entities and are free from foreign control.
What about other AI models, including foreign ones?
The Act does not prohibit the use of other AI models, including foreign ones. Restrictions on access to foreign models are possible only indirectly – through cases specified by the Government of the Russian Federation where exclusively sovereign and/or national models must be used (see above).
When using foreign AI models, there are risks under the Personal Data Act. For instance, the processing of personal data using foreign artificial intelligence may be considered a cross-border transfer of personal data, which must be reported to Roskomnadzor in accordance with the established procedure[3] .
The requirement for the localisation of personal data in relation to AI models means that the initial collection of personal data during operation must take place via a database in the Russian Federation. If collection takes place on foreign servers in foreign databases, there is a risk of breaching the requirements for database localisation.
To minimise risks, we do not recommend uploading personal data to AI systems.
Following the entry into force of the AI Act, which is expected on 1 September 2026, we recommend developing a company policy on the use of AI that regulates the permissibility of specific AI services and restricts the transfer of personal data to them, particularly in relation to foreign models.
3. Current Status and Date of Entry into Force of the Act
At present, the AI Act has been passed at its third reading but has not yet been signed by the President of the Russian Federation and formally retains the status of a bill. Once signed by the President, the following dates should be noted:
-
1 September 2026 – the main provisions of the Act come into force.
-
1 March 2027 – the provisions on the labelling of content created using AI, as well as those concerning the powers of the Government of the Russian Federation (including the determination of cases where exclusively sovereign and national models must be used), come into force.
-
1 September 2032 – end of the transition period: until this date, the requirement to use exclusively sovereign and national models does not apply to information systems in which LFM AI created or in operation as at 1 March 2027 have been implemented, provided that data is processed and stored within the territory of the Russian Federation.
***
We will monitor the adoption of subordinate legislation on AI and keep you informed of changes relevant to your business.
We are also ready to assist with the development of AI policies and the application of personal data protection requirements in relation to the use of LFM AI (localisation, cross-border transfers).
[2] The procedure for determining compliance must be approved by the Government of the Russian Federation.
[3] Please note that certain rules governing the cross-border transfer of personal data will shortly be updated following the adoption, on 8 July 2026, of Bill No. 951518-8 at its third reading.