Trust the system
Russia is preparing a federal law on arti- ficial intelligence
Из выпуска мониторинга No. 3 (27), March 2026 · выпуск целиком, PDF · на сайте Института Гайдара

According to OECD, today, there are 31 legal acts in force worldwide regulating areas related to AI. The first such acts were adopted back in 1999 (no doubt in response to the release of the movie "The Matrix").
In March 2026, the RF Ministry for Digital Technology, Communication and Mas Media has published a draft law “On regulating the use of AI in Russia.” Thus, a concept of “trusted AI models” is introduced, and only these systems can be used in public systems and at critical infrastructure facilities.
The trusted model must meet a number of requirements, such as ensuring that data is processed exclusively within Russia. In fact, this requires data localization.
This can create challenges for performance of the models: data storage capacity is limited, and AI models require very large amounts of data to perform well.
However, if only data that is originally located in Russia is processed, this will lead to the AI “knowing” only a limited set of data (training on a narrow and less representative sample), which is fraught with distortions in the generated results, including discrimination on the part of the algorithms.
At the same time, the developer is obliged to exclude functional features of AI that may result in discrimination.
The Russian project partially mirrors foreign approaches. It includes principles for protecting privacy and personal data, a duty to notify people when decisions regarding them are made without human participation and label the AI-generated content. However, these similarities are largely superficial.
1 The bill stipulates that requirements for the use of AI should be established taking into account the likelihood of
political initiatives , associated with AI have been adopted worldwide
Restrictions are introduced internationally (EU and G20/OECD) for AI according to level of risk and the scope of AI application.
There is an unacceptable use of AI systems (for mass social profiling of people), high-risk systems (AI in medicine or in drones) and everything else. A separate category is distinguished, that is, “general purpose” AI, generative AI. Depending on the risk degree, different requirements are established for reporting, disclosure of information about AI, etc. Russia’s bill sets the principle of a risk-based approach to AI2 regulation, but does not identify AI risk categories
Also, the owner of an AI service with more than 500.000 users from Russia per day becomes an “organizer of information dissemination” is obliged to store information about users and their messages in Russia (for 6 months).
A message means any piece of information transmitted or received by a user. This raises the question: can messages include requests from all AI users? Will all requests need to be stored for six months? Will large international providers like Qwen, DeepSeek, Perplexity, and character.ai waste resources storing messages in Russia? This entails high costs given the large number of user requests.
What else is happening in the world? risks of harm and the scale of damage caused to life and health, business reputation and property, etc.
The EC adopted recommendations on protection of works “in the AI era”: to use protected IP for training AI is proposed only with the consent of the copyright holder and upon payment of remuneration. Creation of a license market for AI training is being considered, including through collective licenses, when many authors and companies allow their works to be used for a fee without the need to enter into a separate agreement with each copyright holder.
By the way, the US is also considering the possibility to introduce collective licenses. In Russia, according to the AI draft masterpiece that meets criteria for protectability, including the requirement of a human personal creative contribution. Content generated entirely by AI will not be protected, as is the case in the EU. In the US, however, this is permitted in certain states, such as Arkansas.
What is next?
censes. In Russia, according to the AI draft
If the localization requirement for AI services with more than 500.000 Russian users per day is adopted, it is likely that services that do not formally operate in Russia (for example, OpenAI) will not be able to enter the market, and those that do can be blocked by Roskomnadzor for failing to comply with infor- mation transfer requirements.
Which foreign services will store messages in Russia?
Thus, the DeepSeek website h ad approximately 350,8 mn visits for month in March 2026, w hile Russia’s share in the traffic evidences 10.35% . This means 36.3 mn visits from Russia for month, more than 1.1 mn visits per day .
law, the use of materials in AI development is permitted only under an agreement with the copyright holder or if a "legally valid copy" is obtained.
Interestingly, in Russia, the AI-generated content can be recognized as an intellectual property object if it represents a
3 To make an assessment, it is necessary to take the site's total monthly traffic, multiply it by Russia's share of traffic, and convert the result to a daily average. If the result is 500.000 or more, the company is required to store messages from users in Russia for six months.
- 36.3078 mn ÷ 31 = 1.171 mn visits per day. This is more than twice the threshold of 500.000. Even if we assume very roughly that one Russian user on average visits the service twice a day, we get 1.171 mn ÷ 2 = 585.6 users per day. ↑
From the monitoring issue No. 3 (27), March 2026. Download the full issue (PDF) · issue page at the Gaidar Institute