AI regulation in Russia is governed by a combination of federal legislation, presidential decrees and sector-specific rules that together form a framework unlike the EU or US approaches. Russia has chosen a largely permissive, state-led model: the government promotes AI adoption aggressively while retaining strong oversight over data, critical infrastructure and public-sector applications. For international businesses operating in or with Russia, understanding this framework is essential before deploying AI-driven products, processing personal data or entering into AI-related contracts. This guide covers the foundational legal instruments, the competent authorities, sector-specific obligations, recent legislative updates and the practical compliance picture for foreign companies.
Russia does not yet have a single comprehensive AI statute equivalent to the EU AI Act. Instead, the framework rests on several interlocking instruments.
The primary definitional and policy document is Federal Law No. 123-FZ "On Conducting an Experiment on Establishing a Special Regulation for the Creation and Implementation of Artificial Intelligence Technologies in the City of Moscow." Enacted to govern the Moscow AI regulatory sandbox, it introduced the first statutory definition of artificial intelligence in Russian law: AI is defined as a set of technological solutions enabling machines to perform tasks associated with human intelligence, including perception, prediction, recommendation and decision-making. This definition has since been referenced across subsequent regulatory instruments.
Alongside this, the National Strategy for AI Development - approved by Presidential Decree No. 490 - sets the policy direction through the end of this decade. It identifies AI as a strategic priority, mandates state support for AI research and deployment, and calls for the gradual development of a comprehensive legal framework. The Strategy is not directly enforceable but shapes how ministries and regulators draft subordinate rules.
Federal Law No. 149-FZ "On Information, Information Technologies and Information Protection" provides the broader digital infrastructure within which AI systems operate. It governs data processing, information security requirements and the obligations of operators of information systems - categories that frequently apply to AI platforms. Violations of this law carry administrative and, in serious cases, criminal liability.
The Civil Code of the Russian Federation also intersects with AI regulation in areas such as intellectual property generated by AI, liability for autonomous systems and contractual arrangements involving algorithmic decision-making. Courts have not yet produced a settled body of case law on AI-generated works, but the Ministry of Economic Development has circulated draft proposals to address authorship and liability gaps.
Several federal bodies share responsibility for AI oversight in Russia, and their mandates frequently overlap.
The Ministry of Economic Development (Minekonomrazvitiya) leads AI policy coordination. It chairs the working group responsible for drafting the national AI regulatory roadmap and oversees the implementation of the National AI Strategy. For foreign companies seeking to engage with the regulatory process, the Ministry is the primary point of contact on policy questions.
Roskomnadzor - the Federal Service for Supervision of Communications, Information Technology and Mass Media - is the data protection authority. Because most AI systems process personal data, Roskomnadzor';s rules under Federal Law No. 152-FZ "On Personal Data" apply directly to AI operators. The law requires data localisation for Russian citizens'; personal data, meaning that AI systems processing such data must store it on servers located in Russia. This is a hard legal requirement, not a recommendation, and non-compliance has resulted in significant fines and access restrictions for foreign platforms.
The Federal Service for Technical and Export Control (FSTEC) regulates AI systems used in critical information infrastructure. Under Federal Law No. 187-FZ "On the Security of Critical Information Infrastructure," operators of critical systems - including energy, transport, finance and healthcare - must certify that their AI components meet specific security standards. FSTEC issues the relevant certification requirements and conducts inspections.
The Bank of Russia (Central Bank) has issued guidance on the use of AI in financial services, covering algorithmic trading, credit scoring and fraud detection. Its regulatory sandbox allows financial institutions to test AI-driven products under a lighter-touch regime before full deployment.
The Federal Antimonopoly Service (FAS) monitors AI-driven pricing and recommendation algorithms for potential competition law violations. Algorithmic collusion - where competing firms'; pricing algorithms converge without explicit coordination - is an area of active FAS interest.
Russia';s AI regulatory obligations vary significantly by sector, and companies must map their activities carefully before assuming a uniform compliance standard applies.
Financial services. The Bank of Russia';s guidance requires financial institutions using AI for credit decisions to maintain explainability: customers must be able to receive a meaningful explanation of an automated credit refusal. Institutions must also document model governance procedures, including validation, testing and ongoing monitoring. The sandbox regime allows fintech companies to pilot AI tools with reduced documentation requirements for a defined period, typically up to one year.
Healthcare. AI-based medical devices and diagnostic tools are regulated by Roszdravnadzor (the Federal Service for Healthcare Supervision) under the rules governing medical devices. An AI diagnostic system must obtain registration as a medical device before commercial deployment. The registration process involves clinical evaluation, technical documentation and, in some cases, clinical trials conducted in Russia. This process can take from several months to over a year depending on the risk class of the device.
Critical infrastructure. Operators of critical information infrastructure who deploy AI must comply with FSTEC';s security requirements, which include mandatory incident reporting, penetration testing and, for the highest-risk categories, use of certified domestic software components. In practice, this requirement creates a significant barrier for foreign AI vendors whose products have not undergone Russian certification.
Public procurement and government use. Federal and regional government bodies are required by government directives to prioritise domestically developed AI solutions when procuring AI-based services. Foreign companies wishing to supply AI tools to Russian public-sector clients must typically partner with a Russian legal entity and, in many cases, ensure that the software is listed in the Russian Software Registry maintained by the Ministry of Digital Development.
Biometric data. The Unified Biometric System (EBS), operated by a state-owned entity under the supervision of the Central Bank and the Ministry of Digital Development, governs the collection and use of biometric data including facial recognition. Companies wishing to use facial recognition commercially must comply with specific consent, storage and processing rules under both Federal Law No. 152-FZ and the rules governing the EBS. Facial recognition in public spaces by private entities is subject to heightened scrutiny.
Russia';s AI regulatory landscape has evolved rapidly, and several significant developments have occurred in recent periods.
The Moscow AI sandbox, originally a time-limited experiment, has been extended and expanded to additional regions. The sandbox allows participating companies to test AI applications under a modified legal regime, with certain data protection and licensing requirements relaxed. Participation requires an application to the relevant regional authority and approval by a designated expert council. The sandbox model is widely seen as the template for Russia';s eventual comprehensive AI law.
Draft legislation on a federal AI framework has been circulated by the Ministry of Economic Development. The draft proposes a risk-based classification of AI systems - broadly analogous in structure, though not in content, to the EU approach - with higher-risk systems subject to mandatory registration, conformity assessment and ongoing monitoring. The draft has not yet been enacted, but its provisions are being applied informally by regulators in their guidance and enforcement priorities.
The personal data localisation requirement under Federal Law No. 152-FZ has been enforced with increasing consistency. Roskomnadzor has demonstrated willingness to restrict access to foreign platforms that fail to comply. For AI companies processing Russian users'; data, this means that cloud infrastructure decisions - specifically, where training data and inference outputs are stored - carry direct legal consequences.
Intellectual property rules for AI-generated content remain unsettled. The Civil Code currently requires a human author for copyright protection, meaning that purely AI-generated works may not be protected. The Ministry of Economic Development';s draft proposals suggest introducing a neighbouring right for the organiser of AI-generated creation, but this has not yet been adopted. Companies relying on AI-generated content in their commercial activities should document human creative input carefully to preserve copyright claims under current law.
Liability for AI-related harm is addressed only partially in existing law. The general tort provisions of the Civil Code apply, but there is no specific AI liability statute. In practice, liability tends to be allocated contractually, and well-drafted AI service agreements are essential for managing risk in the Russian market.
If your business involves AI deployment in Russia and you need to map your obligations across these frameworks, contact info@vlolawfirm.com. We can help structure the compliance approach correctly from the outset.
Foreign companies face a distinct set of challenges when navigating AI regulation in Russia, and several obligations apply regardless of whether the company has a local legal entity.
The data localisation requirement is the most immediate concern. Any company offering services to Russian users and processing their personal data - including through AI-driven platforms - must store that data on Russian territory. This applies to the original database, not merely a copy. Companies that route data through international cloud infrastructure without a Russian node are in breach of Federal Law No. 152-FZ. Roskomnadzor maintains a register of violators and has the authority to require Russian internet service providers to block access to non-compliant services.
Foreign AI vendors supplying to Russian financial institutions must comply with the Bank of Russia';s model governance expectations. In practice, this means providing documentation on model architecture, training data provenance, validation methodology and explainability mechanisms. Financial institutions are responsible for their vendors'; compliance, which means they will contractually require this documentation before deployment.
Companies in the healthcare AI space must engage with Roszdravnadzor';s medical device registration process early. A common mistake is to assume that a CE mark or FDA clearance obtained in another jurisdiction provides any recognition in Russia - it does not. Russian registration is a standalone process with its own documentation requirements, and the timeline should be factored into market entry planning from the beginning.
For AI systems touching critical infrastructure, FSTEC certification is non-negotiable. Foreign vendors should assess at the outset whether their products can realistically meet Russian certification requirements, which often include source code review and, in some cases, requirements to use domestically produced cryptographic modules.
A non-obvious requirement for many foreign companies is the obligation to appoint a local representative for personal data purposes. Under Federal Law No. 152-FZ, foreign operators processing Russian citizens'; personal data must designate a representative in Russia who can receive communications from Roskomnadzor and be held accountable for compliance. This representative can be an individual or a legal entity but must be resident or registered in Russia.
Many underestimate the contractual dimension of AI compliance. Russian law does not have specific AI contract templates, but courts will apply general civil law principles to disputes involving AI services. Contracts should clearly allocate liability for model errors, define the scope of permitted data use, address intellectual property ownership of outputs and specify the governing law and dispute resolution mechanism. Arbitration clauses referencing international arbitration institutions remain enforceable in commercial disputes, though the practical landscape for enforcement has changed in recent periods.
Scenario one: a European fintech deploying a credit-scoring AI for Russian users. The company must localise personal data in Russia, comply with Bank of Russia model governance guidance, appoint a local data representative and ensure its credit decision process meets explainability requirements. It should also assess whether its product qualifies for the Bank of Russia';s sandbox, which could reduce the initial compliance burden while the product is being validated.
Scenario two: a global healthcare technology company offering an AI diagnostic tool. The company must register the tool as a medical device with Roszdravnadzor before any commercial use. It must localise any personal health data processed through the tool. If the tool is intended for use in public hospitals, it must also comply with public procurement rules favouring domestic software, which may require a partnership with a Russian entity or listing in the Russian Software Registry.
For international businesses, the Russian AI regulatory environment presents a distinctive risk profile that requires careful strategic assessment before market entry or continued operation.
The regulatory framework is evolving quickly, and the gap between formal law and enforcement practice is significant. Regulators have broad discretionary powers, and enforcement priorities can shift. Companies should monitor guidance documents, regulatory sandbox developments and draft legislation continuously, rather than treating compliance as a one-time exercise.
The data localisation requirement is the single most operationally disruptive obligation for most foreign AI companies. Decisions about cloud architecture, data residency and vendor selection must be made with this requirement in mind from the earliest stages of product design. Retrofitting compliance after deployment is significantly more costly and complex.
Intellectual property strategy requires adaptation. Given the unsettled state of AI authorship rules, companies should ensure that human creative and technical contributions to AI outputs are documented, that contracts with Russian counterparties clearly address IP ownership, and that trade secret protection is considered as an alternative or supplement to copyright where AI-generated content is commercially sensitive.
Contractual risk allocation is more important in Russia than in many other jurisdictions, precisely because the statutory framework for AI liability is underdeveloped. Well-drafted service agreements, data processing agreements and technology licensing contracts are the primary tools for managing exposure. Russian-language versions of contracts are advisable for enforceability, and Russian law is often the preferred governing law for contracts with Russian counterparties.
The regulatory sandbox mechanism offers a genuine opportunity for companies willing to engage with it. Sandbox participation provides legal certainty for the testing period, access to regulatory dialogue and, in some cases, relaxed data protection requirements. The application process requires preparation, but for companies with innovative AI products, it is worth considering as part of the market entry strategy.
Does Russia have a comprehensive AI law, and when is one expected?
Russia does not currently have a single comprehensive AI statute. The existing framework is built from sector-specific laws, presidential decrees and regulatory guidance, with the Moscow sandbox legislation providing the only statutory AI definition. The Ministry of Economic Development has circulated a draft federal AI law proposing a risk-based classification system, but it has not been enacted. The timeline for adoption remains uncertain. In the interim, companies must navigate the existing patchwork of laws, and compliance strategies should be built around the current framework rather than anticipated future legislation. Monitoring the draft law';s progress is advisable, as its provisions are already influencing regulatory practice informally.
How long does it take to comply with data localisation requirements for an AI platform?
The timeline depends heavily on the company';s existing infrastructure. For a company already using cloud providers with Russian data centres, compliance can be achieved relatively quickly - often within a few months - by reconfiguring data routing and storage. For a company that must establish a new Russian infrastructure presence, the process typically takes longer, involving vendor selection, contractual arrangements, technical migration and testing. The appointment of a local data representative is a separate, faster step that can be completed within weeks. Roskomnadzor does not provide a formal grace period, so companies should treat localisation as an immediate obligation upon commencing services to Russian users.
Can a foreign company use an international arbitration clause in an AI services contract with a Russian counterparty?
Arbitration clauses referencing international arbitration institutions are generally enforceable in commercial contracts between Russian and foreign entities under Russian civil procedure law, provided the dispute is of a commercial nature and the parties have expressly agreed to arbitration. Russian courts have historically respected such clauses in B2B contracts. However, the practical enforceability of arbitral awards has become more complex in recent periods, and companies should take legal advice on the specific arbitration institution, seat and governing law before finalising contract terms. For contracts involving critical infrastructure or state-related entities, additional restrictions may apply.
Russia';s AI regulatory framework is state-led, sector-specific and evolving rapidly. The absence of a single comprehensive AI law means that compliance requires mapping obligations across multiple statutes, regulatory bodies and sector-specific rules. Data localisation, model governance, medical device registration and critical infrastructure security are the most operationally significant requirements for most foreign companies. The regulatory sandbox offers a structured path for testing innovative AI products, and engagement with the Ministry of Economic Development';s draft legislation process is advisable for companies with a long-term interest in the Russian market.
VLO Law Firms advises international clients on AI regulation in Russia. We can assist with compliance mapping, data localisation structuring, regulatory sandbox applications, AI contract drafting and engagement with Russian regulatory authorities. To request a consultation, contact: info@vlolawfirm.com