Russia's inaugural comprehensive legislation on large foundation models came into force on September 1, following President Vladimir Putin's signature on July 26. The law emerged after a substantially more expansive initial draft underwent public consultation in spring before being replaced in June with a narrower measure focused specifically on large foundation models and state backing for their creation.
Rather than addressing the dangers posed by AI systems, the law constructs a mechanism for supporting and controlling the developers who build large foundation models. It provides qualifying developers with state backing, participation in policy formation and potentially exclusive market access in return for meeting conditions around Russian ownership, data storage within Russia and alignment with Russian law and what the statute describes as "traditional Russian spiritual and moral values."
Moscow has spent decades consolidating state authority over its digital infrastructure: data centers, telecommunications, network systems. Developers faced restrictions on personal information and content, yet AI remained largely unregulated. The 2019 National AI Strategy and regulatory testing grounds offered some direction, but no legislation addressed the sector directly. The new statute fills this gap at the most consequential level: foundation models, which serve as the underlying technology for other AI applications.
The sector itself remains quite limited. Sber, T-Bank, Yandex and MTS lead development efforts. None operates as a startup; all four rely on state licenses, government contracts and state approval. Sber, the state-controlled savings bank that transformed itself into a technology conglomerate, anchors the group. Yandex, once Russia's largest independent technology firm, was sold to government-approved investors, as was T-Bank.
The technical foundations come largely from abroad, predominantly from China. Sber claims to train GigaChat from the ground up, yet its engineers acknowledge the architecture draws from China's DeepSeek, incorporating Qwen-style attention mechanisms in recent iterations.
Computing hardware similarly originates overseas. Western export restrictions prevent Russia from accessing cutting-edge accelerators; domestic alternatives remain years from deployment. The computational infrastructure supporting these models combines Chinese accelerators with Western GPUs acquired before sanctions or obtained through intermediaries. YandexGPT 5 Pro relies on Qwen-2.5-32B weights, while T-Bank's T-Pro and T-Lite and MTS AI's Cotype build on successive Qwen iterations. Absent from worldwide benchmarks, they appear on Russian-language rankings such as MERA and LLM Arena, though well outside the top tier.
From regulation to support for model development
The initial version circulated for feedback in March 2026 took a different approach, attempting to address the entire domain: individual protections, institutional design, responsibility distribution from model creators to system and service operators, and creative works. Russian legal professionals, commercial entities and even state-affiliated organizations raised substantial objections, citing inadequate drafting and problematic provisions. The document appeared to reflect separate groups working independently on distinct sections. Additionally, it failed to resolve existing legal questions within the sector while granting government agencies expanded authority.
By June, the approach and designation shifted fundamentally. The broad framework was abandoned. The legislature instead advanced the On Support for the Development of AI Technologies in the Russian Federation law. This version narrows its focus: large foundation models and measures encouraging their advancement. The State Duma approved it in July, the Federation Council followed later that month, and Putin signed on July 26.
A narrow subject, a wide reach
The enacted legislation no longer addresses AI systems broadly. Rather, it targets "large foundation models," characterized as systems containing at least "1 billion parameters," sufficiently general to function as a foundation for software creation and diverse applications.
The parameter threshold represents a relatively simple metric. The EU's AI Act instead employs training compute—the computational resources expended during model training—alongside additional measures to identify general-purpose AI models and those carrying systemic dangers. European Commission guidance designates 10²³ FLOPs (floating-point operations) as an indicative benchmark for GPAI models, while those trained with more than 10²⁵ FLOPs are presumed to pose systemic risk, subject to challenge.
A 1-billion-parameter ceiling encompasses both modest open-source models operating on personal computers and substantially larger systems; it therefore does not align precisely with the frontier of commercial AI. The legislation additionally covers large foundation models made accessible to Russian users, potentially bringing foreign developers serving that market within its jurisdiction.
The bargain
The statute centers on two model classifications: "sovereign" and "national." Requirements for each substantially coincide: the creator must be a Russian legal entity; model outputs must be generated and retained in Russian-owned data facilities within Russia; the system must undergo evaluation for compliance with Russian legislation and "traditional Russian spiritual and moral values," though the law specifies no assessment method and implementing rules await a government order.
The statute does not identify which organizations will perform the evaluation: procedures and status-granting criteria remain to be established through government resolution. According to Vedomosti, the Ministry of Digital Development is collaborating with the FSB and the FSTEC, the export-control and technical-security agency, on the framework. The proposed process would require developers to reveal model design and filtering systems, accredited testing facilities would examine responses and attempt to circumvent protections, and the ministry would render the ultimate determination.
The values, already enumerated in a presidential order, would be converted into a specialized assessment tool, created jointly with the sector, for model evaluation. This resolution has not yet been finalized.
The values are typically interpreted as "patriotism, service to the Fatherland, high moral ideals, a strong family, the priority of the spiritual over the material, humanism, collectivism," among others.
Russian models currently appear to implement content filtering aligned with these principles. A 2025 examination of 14 systems found that the two Russian models tested, Sber's GigaChat and YandexGPT, most frequently declined requests when prompted in Russian and concerning Russian historical figures. The researchers contend the filtering targets a domestic audience. The statute codifies for the AI field what existing law already mandates.
The distinction between the two classifications concerns origin. A sovereign model must be created entirely by the Russian developer and technically reproducible by that entity. A national model may derive from a foreign model under an open license, provided the Russian developer modifies and determines its core characteristics.
Given the gap between Russian developers and the cutting edge, the national classification appears to function as a legal mechanism enabling Russian developers to build upon open foreign models, including Chinese systems like Qwen, particularly since major Western vendors restrict Russian access.
The requirements remain broadly framed: protective measures, usage guidelines, safety documentation. The advantages are precisely articulated. Under provision 5 of Article 5, status holders gain state backing, involvement in government policy development and entry to state information repositories, contingent on FSB clearance. The administration will also designate contexts in which only sovereign or national models may operate, making the status a prerequisite for market participation.
Text and data mining as a gift
The most significant advantage concerns intellectual property protections. Starting March 2027, the law establishes that certain computational applications of protected and related-rights content do not constitute violation. It explicitly permits temporary storage in computing systems solely for training a sovereign or national large foundation model, provided the developer possesses a legitimately obtained version of the work or the work is publicly accessible without technical barriers.
The distinctive aspect ties the training exception to the model's regulatory classification. The identical form of copying therefore qualifies as a statutory exemption when training a sovereign or national model but not necessarily when training other models.
Jurisdictions handle AI training information differently. The EU permits certain text-and-data-mining activities under copyright law, encompassing exceptions for scholarly work and broader training datasets unless creators object. The AI Act mandates that general-purpose AI providers maintain a copyright approach and observe EU copyright law, including respecting such reservations. In the United States, courts continue evaluating whether particular training applications constitute fair use, while the US Copyright Office has separately examined licensing and policy matters.
Russia has adopted a more direct statutory method for sovereign and national models, without establishing payment for creators in the training exception. Nevertheless, the exemption could be restricted before implementation; it remains under active discussion.
Regarding disclosure, the law does not mandate that all AI-produced audio or visual content carry a label. Rather, beginning March 1, 2027, anyone employing a large foundation model to generate audio or visual material must receive the option to append an AI notice, which they may choose not to use. The appearance, substance and location of the notice are to be determined through agreement between the user and the model access provider.
What the law leaves to decrees
The statute is brief—13 articles—and delegates crucial implementation specifics to subsequent government directives. These encompass the standards and methods for sovereign and national classification, the evaluation process for Russian law and values compliance, and the mechanism for accessing information held in federal and other government databases.
Federal statutes and presidential orders may establish guidelines for large foundation model deployment in military defense, state protection, investigative operations, public safety, counterinsurgency and governmental functions. This enumeration encompasses numerous domains where AI presents the gravest human rights concerns: facial identification, algorithmic law enforcement, digital platform surveillance and location monitoring.
The statute provides no guidance on regulating these applications: no restrictions, no rights-impact assessment, no autonomous monitoring, no notification of impacted individuals, no mechanism to contest decisions. This leaves unaddressed procedural issues the European Court of Human Rights identified in Glukhin v. Russia. Nikolay Glukhin was identified by Moscow's surveillance system after traveling the metro with a cardboard representation of a political detainee. The tribunal determined that facial recognition targeting a nonviolent demonstrator breached his entitlements to confidentiality and expression.
One provision extends further than the carve-out. It grants the president expansive control over AI technologies generally, not merely large foundation models, encompassing an unrestricted capacity to exercise "other powers." The statute nowhere clarifies which matters must be addressed through legislation and which through executive order. A regulatory domain has been transferred to administrative rulemaking without clear constraints.
Monitoring mandates extend to AI offerings as well. They fall under existing regulations for information distribution facilitators, meaning platforms enabling user-to-user or user-to-service communication. This encompasses conversational interfaces, intelligent assistants and comparable systems accepting user queries, irrespective of scale. They must retain interaction records, encompassing message text, in Russia and grant the FSB entry.
Borrowed vocabulary, different purpose
The constituent elements are recognizable from other frameworks: a danger-based structure, disclosure obligations, a specialized category for foundation model creators, and technological independence. However, the EU AI Act integrates them within a distinct regulatory architecture. It establishes duties for general-purpose AI providers and heightened requirements for models presenting systemic dangers, while the broader AI Act employs danger classifications for AI applications and encompasses measures meant to encourage innovation, encompassing regulatory testing grounds.
The EU AI Act organizes them across two dimensions. AI applications, the systems individuals engage with, are categorized by danger level, ranging from forbidden uses to elevated-risk contexts such as employment or lending, with obligations for both creators and implementers. For general-purpose AI models, the Act establishes foundational duties on general-purpose AI creators and supplementary ones on providers of models carrying systemic dangers.
The frameworks serve distinct functions. In the EU, the GPAI structure primarily distributes obligations: creators must preserve technical records, follow a copyright approach and disclose a summary of training information, while providers of models with systemic dangers face heightened requirements for danger evaluation, incident notification and data protection.
In Russia, the sovereign and national designation additionally determines qualification for designated state-support initiatives and can establish which models may be deployed in domains reserved for those categories.
Russia has borrowed terminology from contemporary AI governance but employs the classifications to merge regulation with economic development and technological independence. The outcome is a framework in which legal designation can shape both the duties imposed on a model creator and the advantages or market access available to it.
Numerous significant provisions activate March 1, 2027, encompassing the frameworks governing sovereign and national models, creator obligations, AI-content notices and the copyright exceptions. The administration may additionally designate sectors in which only sovereign or national models may be deployed. Until September 1, 2032, this constraint does not apply to information systems using large foundation models that were created or managed as of March 1, 2027, provided the information is handled and retained in Russia.
Russia's answer to the AI race
Russia's approach to the AI competition is to advance at the frontier while controlling the gateway. Foundation models represent the point where the technology stack narrows to a handful of organizations, and a government distributing the certifications they require to access protected markets can govern all downstream applications without supervising individual systems.
Sovereignty in this context denotes authority rather than technical capacity: models functioning with Russian information, under Russian legal constraints and, in several instances, on foreign—especially Chinese—model designs and computing infrastructure.
For nations unable to finance frontier model development, the framework presents an alternate option: domestic infrastructure and developers, foreign open-source models where permitted, a domestic authorization mechanism and preferential entry to designated markets.
Russia has established that framework, and it is already being promoted: Sber has suggested a BRICS initiative for AI independence, indicating it is pursuing nations in Africa, Asia, Latin America and Oceania seeking indigenous AI without the resources to construct it. The accompanying element is the regulatory structure surrounding the models: classifications, domestic enrollment and market protections. The exportable component is therefore not merely AI capacity, but a governance system for technological oversight.



