What is behind the scenes of the new law passed by State Duma with exceptional speed?
On July 8, 2026, the State Duma (the lower chamber of Russia’s parliament) passed a government bill titled “On Supporting the Development of Artificial Intelligence Technologies in the Russian Federation” in its second and third readings. The first reading had taken place a day earlier, so the entire path through the lower chamber took two days. The bill must be approved by the Federation Council (the upper chamber) and signed by the president. It is set to take effect on September 1, 2026, with certain provisions starting March 1, 2027.
The key points that get lost in the news headlines:
- This is a framework law. It introduces definitions and principles but hands most of the specifics (criteria, procedures, lists) over to the government’s implementing regulations. The real rules of the game will be written later and outside the parliament.
- “Sovereign” and “national” models appear. Both must be developed in Russia and store data in Russian data centers; the difference lies in whether foreign components may be used. The government will be able to prescribe areas where only such models are allowed.
- A model has to pass a “traditional values” check. To obtain the status, and with it state support, a neural network must confirm that it complies with “traditional Russian spiritual and moral values,” through a procedure the government will define.
We sincerely hope this does not mean a religious consecration rite, although such a rite was in fact performed once before, on March 5, 2011, when a Russian Orthodox Church priest, Father Viktor, blessed the servers of the RuTube video portal.
- AI can be trained on someone else’s publicly available content without the author’s consent, as long as the rights holder has not locked the material with technical means. Publishers, musicians, and animators came out against this provision.
Behind the facade of “supporting domestic technology,” the law does the same thing as previous digital initiatives: it expands the state’s ability to decide which technology to permit and which not.
What’s happening
The law’s history did not begin yesterday. The Ministry of Digital Development (Mintsifry) published a draft titled “On the Foundations of State Regulation of the Application of Artificial Intelligence Technologies” on the regulatory acts portal back in mid-March 2026. In that first version there were three categories of models: alongside the “sovereign” and “national” ones there was also a “trusted” category, which faced the strictest requirements. The largest Russian companies and business associations criticized the first draft, and some of their comments were taken into account, but only partially.
By the final reading the “trusted” category had been removed and several of the most contested provisions had been softened. The ideological framing, however, the requirement to comply with “traditional values,” remained. The passage through the State Duma itself took a record-short time: the first reading on July 7, the second and third on July 8.
Vyacheslav Volodin, the speaker of the State Duma, called the law a framework one and said the government would prepare the necessary implementing regulations. “The State Duma retains oversight for itself. Before the end of the year we will definitely have to return to reviewing the main provisions,” he said. Mintsifry was named the regulator for AI; the government adopted the corresponding decree in early July 2026. Before that, Russia had no dedicated agency for this area.
The “framework nature” means that the most essential matters (exactly how models will be checked for “values,” which areas will be closed to foreign AI, what will fall under the definition of “significant” data) will be decided not in the law but in government decrees, which are adopted without public debate in parliament.
AI joins the ranks of “digital sovereignty”
The AI law fits logically into the line of initiatives from the past year that we have covered in this section. First the state took on communication channels and messengers: the forced promotion of Max, the blocking of calls in WhatsApp and Telegram, and the ban on authorization through foreign services on Russian websites. Then came identification and the subscriber’s “hardware”: restrictions on eSIM and M2M cards, and a unified IMEI database. Now it is the turn of the computing layer, of the AI models themselves.
The logic is the same in every case: replace open, cross-border infrastructure with controlled “domestic” infrastructure, and route the points where a citizen touches the technology through structures the state can regulate directly. With AI, this approach reaches the top level of the digital stack, the algorithms that increasingly determine what information a person sees and receives.
The mechanics
The subject of regulation is large foundation models (LFMs). The law concerns not just any algorithms but specifically large models like Russia’s YandexGPT, the ones trained on enormous volumes of data that underpin chatbots and text and image generators. For the first time, Russian legislation introduces a legal definition of artificial intelligence and related concepts.
Two categories of models. The key division is into sovereign and national:
- A sovereign model must be developed entirely by a Russian legal entity, with all stages of creation, training, and data storage carried out only on Russian territory and by Russian citizens and companies. According to RBC’s sources on the IT market, only Sber’s model (from the Sberbank group) fits these criteria.
- A national model is also developed by a Russian company and stores data in Russia, but it is allowed to use foreign components under an open license. The example named by the same sources is Yandex.
The “values” check. Both categories receive their status, and with it benefits and state support, only after “confirmation of compliance with the legislation of the Russian Federation and with traditional Russian spiritual and moral values, in a manner established by the government of the Russian Federation.” What will be the procedure? Who will assess a neural network’s “spiritual and moral” compliance, and by what criteria? The law does not answer these questions. The government will determine this in a separate act.
Certification by security agencies. To obtain status, models will have to pass a security review at FSTEC (the Federal Service for Technical and Export Control) and the FSB (the Federal Security Service). The approved are to be gathered into a separate registry.
The power to prescribe a model. The law separately establishes that the government will be able to set out cases where only sovereign or national models may be used (in the financial sector, in coordination with the Central Bank of Russia). In practice this means that in the public sector, banking, and probably a number of other industries, the use of any models other than “domestic ones with status” may turn out to be directly prohibited.
Principles of regulation. Among the official principles are technological independence, protection of human rights and freedoms, “respect for human free will,” safety, and, on the same list, “taking into account and respecting traditional Russian spiritual and moral values.” That last point raised the most questions and remained in the final version despite the criticism.
Why this matters: the censorship core
The law has several places where “support” turns into a tool of control.
“Traditional values” as an admission filter. The requirement to comply with “spiritual and moral values” is stated right away as a condition for obtaining the status on which cooperation with government agencies depends. A legal mechanism will appear through which the government can influence what a model tells a user, for example, through compliance with “values.” For a technology that increasingly acts as an intermediary in access to information, this is a direct lever of content control, in essence an ideological quality-control checkpoint for neural networks.
Priority for domestic models. The government’s power to prescribe the use of only sovereign or national models in certain areas means that foreign systems’ access to entire industries can be closed by an administrative decision, without a separate law. Today it is banks and the public sector; tomorrow the list may expand, and there are no limits to that expansion.
All details outside parliament. The law’s framework nature is also a method of regulation. Everything that defines the real boundaries (the “values” criteria, the lists of closed areas, the certification procedures) is moved into implementing regulations. These are adopted without public readings, quickly, and with the option to change them just as quickly.
None of these provisions is called “censorship” in the text, and censorship is officially banned in Russia under the Constitution anyway. But being combined together they build a system in which the state gains the ability to decide which AI models are permissible for mass use and within what ideological corridor they must operate. This is censorship in its purest form.
Copyright: training on someone else’s content
The second problem of this law is training data. Article 10 of the draft establishes that using objects of copyright and related rights to train AI models is not a violation if the material was made publicly available and accessible for analysis without circumventing technical restrictions, or if the developer lawfully obtained a copy of the work.
What does it mean: if your text, music, image, or code is publicly available and you have not technically closed it off from collection, a neural network can be trained on it without your consent and payment.
A broad front of rights holders came out against the provision. The Russian Book Union (RBU), the National Music Industry Federation, the Animated Film Association and the Association of Software Product Suppliers sent appeals to Anton Vaino, the head of the presidential administration, Vyacheslav Volodin, the State Duma speaker, Mikhail Mishustin, Prime Minister, and Sergey Boyarsky, the head of the relevant Duma committee. Their main argument: “The model proposed by the bill will discourage the creativity of domestic authors and turn Russia into a free hub for training AI models.” The RBU particularly pointed out that free access to protected works undermined the economics of book publishing. The RBU proposed mandatory licensing of training on books with a transparent payment system.
Mintsifry, in response, insists that the law is a framework law and does not repeal the current legislation on intellectual property. The office of Deputy Prime Minister Dmitry Grigorenko promised to refine the copyright provisions “in dialogue with the industry.” Even so, in the adopted version the provision remained almost unchanged: for the second reading, the only edit was removing the disjunctive “or” from the wording for consistency.
The scale of the problem is already visible. According to Habr (a major Russian tech blogging platform), Yandex Music hosts more than 140,000 AI performers who upload around 100,000 new tracks every month. An AI-generated track based on Yesenin’s verses topped the charts earlier this year. The authors of the tracks (that services like Suno trained on) have received no royalties at all.
Global landscape
To assess Russia’s regulatory design, it helps to look at how the question is handled around the world. The differences are fundamental, above all in the approach to training on someone else’s content.
The European Union took the path of “opt-out by default in the author’s favor.” Under the Directive on Copyright in the Digital Single Market (CDSM) and the AI Act now taking effect, text and data mining for training is allowed, but rights holders can reserve their rights, and in this case their content cannot be used. The reservation is made in a machine-readable way: through robots.txt, meta tags, HTTP headers, or the dedicated TDM Reservation Protocol. On top of that, the European AI Act requires developers to publish a summary of the training data used and to label generated content, including deepfakes. Critics note that this system is imperfect too: there is no single opt-out standard yet, and an author often does not know whether their work was used. But the principle is the reverse of Russia’s in any case: by default the right is on the author’s side. In Germany, the rights-management society GEMA sued Suno over the use of protected songs.
The United States handles the question through the fair use doctrine, and does so in the courts. Over the course of 2025, a first cluster of decisions took shape: in some cases training was recognized as transformative use, while in others everything came down to exactly how the data was obtained. For example, pirated copies became an aggravating factor. Music labels sued the AI generators Suno and Udio. By the end of 2025, Warner Music had settled its dispute with Suno and moved to a licensing partnership with an option for artists to consent. The general vector: the disputes lead not to a ban but to building a licensing system.
The general principle in developed jurisdictions: either the right is on the author’s side by default (the EU), or the question is resolved adversarially in court with an emphasis on the origin of the data (the US), and everywhere, in parallel, the requirements for transparency of training sets are growing. The Russian law is built the opposite way: the burden of protection is shifted onto the author (if you did not lock it technically, you agreed), and there are no requirements to disclose training data.
“Sovereign AI” and harsh reality
Is Russia even capable of building a competitive “sovereign” AI at all? The experts we draw on below agree that the technological gap is wide and is becoming structurally entrenched.
Russian models are absent from world benchmarks. In international rankings (LMArena, MMLU-Pro, SWE-bench, GPQA), the top spots go to models from OpenAI, Anthropic, and Google, as well as the open Chinese DeepSeek and Qwen. Russia’s GigaChat, YandexGPT, and Cotype (from MTS) are practically not represented in these tables; they are compared mainly on Russian-language benchmarks (MERA, SLAVA). A technical breakdown of the GigaChat family published by its developers shows that the smaller models lag even behind the open Qwen 2.5 7B and Llama 3.1 8B in mathematics and programming.
The lag is partly acknowledged at the very top of the industry. Alexander Vedyakhin, first deputy chairman of the board of Sberbank, told Reuters about plans to promote Russian “sovereign AI” in Global South countries. He admitted that such systems “may fall short of the leading foreign counterparts in capabilities,” but that they will take into account the “local mentality and traditions” and align with the values of a specific country. In other appearances Vedyakhin insisted that GigaChat was equal to or better than foreign models on a number of metrics and that Russia was capable of becoming one of the leaders, so there is no single public assessment even within Sber. Vedyakhin’s argument itself is telling: the competitive advantage is sought not so much in the model’s quality as in its “values-based” and linguistic tuning to a specific country.
The bottleneck is the computing hardware. The key constraint is access to advanced graphics processors. After Russia’s invasion of Ukraine, Nvidia stopped any shipments to Russia, and gray-market imports have become the workaround. The outlet T-invariant found out how this works in practice. An AI development center exists at Moscow State University (MSU), its core is the “MSU-270” supercomputer, and the infrastructure increasingly depends on China. As the outlet notes, “these technologies are sovereign only on paper and in officials’ speeches, while in reality Russia is deeply dependent on the world leaders in AI, more and more on China.” According to T-invariant, “MSU-270” was assembled from Nvidia chips purchased through a Chinese intermediary. In the tender documentation, meanwhile, the equipment was labeled with a nonexistent brand, SOLAR PEAK. VTB, for its part, has moved to “pilot industrial operation of graphics processors from China,” probably analogues from Huawei Ascend, which (according to the Wall Street Journal) China has positioned as a replacement for the banned Nvidia.
An engineer familiar with the assembly of top-tier supercomputers in Russia explained to T-invariant the limits of this path. He stated that it was possible to get Chinese GPUs to work in production workflows but it was more difficult to develop their own models.” In other words, fine-tuning someone else’s work on Chinese hardware is possible, while training a competitive model from scratch is a task of a different level.
Access restrictions appear from above. Access to the leading Western models for Russian users is restricted from two sides. On the companies’ side: OpenAI does not serve Russia, and Anthropic blocks access to Claude (including through a VPN). But the primary source of the restrictions is the Russian government itself. This government, through blocks and laws, builds a perimeter in which legal access to foreign AI has been narrowed. Mintsifry’s March draft envisioned the possibility of banning foreign models outright. The combined effect pushes Russian developers toward the open Chinese models (Qwen, DeepSeek). This step ensures the same dependency on China, now at the level of the models rather than the hardware.
Recommendatons to the developers
This law is a framework law and it still has to be approved by the Federation Council and signed the president. It will take effect in stages, but it is worth building in room to maneuver already: the basic provisions will take effect on September 1, 2026, and the industry-specific restrictions on March 1, 2027.
- If you train models. The provision about training on open content looks like an easing, but it is fragile. The copyright provisions are promised to be refined, and the international trend is toward tightening and transparency. Keep a documented record of the origin of your training data (data provenance) now. This will serve both as insurance in case the rules change in case the rules change and something you will be required to have anyway when you enter external markets.
- If you are a rights holder and do not want your content used for training. The law has shifted protection onto you: by default, open content is considered available for training. Lock your content with machine-readable means: robots.txt with directives for AI crawlers, meta tags, HTTP headers, watermarks. This is not a perfect form of refusal, but it is the only one the law provides.
- If you build a product on someone else’s base model. A model can obtain “national” status even on the basis of an open foreign one (Llama, Mistral, Qwen) with fine-tuning. But a legal foundation controlled by a foreign corporation is a risk: the rights holder of the base model can change the license or introduce regional restrictions. For serious deployments, it is safer to use models with Apache 2.0 or MIT licenses, where the options for revoking rights are minimal.
- If you work in regulated areas. Prepare for the appearance of lists in the public sector, banking, and fintech where only sovereign or national models with status are allowed. Build into your architecture the ability to migrate to a “domestic model with status” as a fallback scenario.
- Watch the implementing regulations, not the law. Everything essential will be in the government decrees: the criteria for “values” compliance, the FSTEC/FSB certification procedures, the lists of closed areas. It is these that will define the real requirements. We will update this analysis when the first implementing regulations appear.
How the state will be able to control AI users
The law has no specific provision on surveillance of users. It places its main obligations on those who create and provide AI (the model developers, system operators, service owners) rather than on those who use it. But the law does not exist on its own. It overlays mechanisms that are already functioning, and together they make all user’s actions noticeably more transparent to the state.
The first and main lever is the status of an information dissemination organizer (ORI). The owners of AI services with a daily audience of more than 500,000 users from Russia are labeled as ORIs. This means storing data about users and their queries and handing this data over to law enforcement on request. The state does not need to monitor a person directly; it obtains the history of their queries from the service.
Next is the requirement to restrict the creation of content that violates the law. To meet it, a service is forced one way or another to look at what the user enters and what they receive in response. The obligation to filter unlawful output means, in practice, analyzing the conversation with the model.
Another distinct aspect is labeling. Starting March 1, 2027, large platforms must provide the technical means to mark generated content. On top of that, as developers themselves report, Russia is preparing a technology for hidden marking of images, video, and sound, a kind of provenance trace embedded in the file that lets the material be traced back to the service, and therefore potentially to the author.
Finally, identification. The law does not separately identify an AI user, but they have already learned to identify them beforehand: logging into large services increasingly goes through a verified account (Gosuslugi, the government services portal; a Russian phone number; VK ID; or Yandex ID), all the more so after the ban on authorization through foreign services (we covered this in one of our previous posts). There is little chance to anonymously access any significant service nowadays.
The most sensitive part is omitted in the law. Its provisions do not apply to defense, security, and law enforcement. RKS Global observes that excluding defense is standard practice, but taking security and law enforcement out from under regulation is far more troubling. This is exactly where facial recognition, predictive analytics, and social media monitoring happen. In their assessment, the law in its current form regulates the AI market and its players rather than protecting users.
The law, to repeat, does not introduce direct surveillance of the user. However, a person who turns to a Russian AI service ends up inside a ready-made perimeter. The service identifies them, stores their queries, reviews them for prohibited material, and marks the result.
Conclusion
On paper, this is a law about supporting technological progress, with definitions, benefits, and a national strategy. But its construction lays down a framework in which the state gains the right to decide which AI models are “correct”: through the “traditional values” filter, through certification by the security agencies, and through the ability to close entire areas to foreign systems. All the specifics, meanwhile, are moved into implementing regulations, meaning outside public debate.
At the same time, the law has legalized training on someone else’s content, shifting protection onto the authors themselves, which the rights holders opposed as a united front. And behind the loud words about “sovereign AI” stands a technology that, by the market participants’ own admission, falls short of the world leaders and runs on Chinese hardware.
For now this is a framework, and the main part lies ahead, in the government decrees. But the direction reads clearly: artificial intelligence is being built into the same perimeter of digital control as the messengers, communications, and authorization before it. We are watching the implementing regulations.