Global AI Regulation: From Strict School Bans to Unregulated AI Havens
Artificial intelligence has entered nearly every sphere of human activity, prompting governments worldwide to introduce restrictions, especially concerning younger users. Approaches vary widely: some nations impose strict bans, others create detailed risk classifications, and a few deliberately avoid regulation altogether.
United States follows a fragmented model with no single federal AI statute. Instead, regulation comes through presidential orders, agency actions, and state laws. Texas enacted TRAIGA on 1 January 2026, limiting development and deployment of high-risk AI systems. Arizona banned AI use for denying medical insurance claims. New York City introduced the broadest U.S. school restriction to date: a one-year moratorium on generative AI for students in grades 2–8, with chatbot bans extending to high school. The measure aims to restore critical-thinking skills required for graduation.
Europe leads with the strictest comprehensive framework via the EU AI Act adopted in August 2024, which classifies systems into four risk levels. Italy added national rules emphasizing human decision-making in healthcare, justice, and public administration, plus criminal liability for AI misuse. Belgium, Germany, and the Netherlands assigned supervision to telecom regulators. Norway went further by banning generative AI in primary schools (grades 1–7) from late August, allowing limited supervised use only for older students.
China pursues centralized control focused on concrete risks. Since September 2025 all AI-generated content must carry visible or embedded identifiers. Generative services require security assessments and algorithm registration. Authorities have removed over 5.61 million pieces of illegal AI content, deleted 49,000 accounts, and blocked 2,400 websites and apps.
Russia brought its first baseline AI law into force on 1 September 2026. The statute defines core terms including “artificial intelligence,” “large foundational models,” and distinguishes sovereign models built entirely on domestic technology from national models that may incorporate foreign components. The government will set support measures and determine when organizations must use only sovereign or national solutions.
Direct service bans complement these laws. ChatGPT is officially unavailable in China, Russia, Belarus, Iran, and North Korea. At least nine countries, including Italy, South Korea, Australia, the Netherlands, and Canada, have restricted or blocked DeepSeek. In January 2026 Indonesia, Malaysia, and the Philippines temporarily blocked Grok.
While regulators tighten controls, companies continue deploying AI in practical domains. FinamX offers an integrated workspace combining portfolio data, charts, notes, and multi-model chat for market analysis, connected to brokers and exchanges including MOEX, Bybit, and KuCoin.
Related articles
How Russian Companies Can Legally Transfer Personal Data to Contractors Under 152-FZ
The article explains the legal distinction between data processors and independent operators when outsourcing tasks involving personal data. It details that the role of a contractor is determined by who sets the processing purpose, not by the service contract itself. For processors, a detailed data processing instruction under Article 6 of 152-FZ is required, while independent operators need a separate legal basis such as consent or contract performance. Special rules apply to employee data under Article 88 of the Labor Code, mandating written employee consent for transfers to third parties. The guidance also covers sub-processing risks, transparency obligations, and penalties under Article 13.11 of the Code of Administrative Offenses. Practical checklists help organizations classify contractors and prepare the correct documentation.
Russian Data Centers May Face Temporary State Management Under Decree 604 for Protection Shortfalls
Large Russian data centers could be placed under temporary government administration if they fail to meet security requirements outlined in presidential decree No. 604. The measure targets critical infrastructure operators that neglect physical and cyber protections, create operational risks, or respond slowly to incidents such as drone strikes. Rosimushchestvo would typically assume management duties by default. Market participants note that Tier III and higher facilities generally maintain strong cyber defenses, shifting the main compliance burden to physical safeguards for generators, cooling systems, and network nodes. Operators including RTK-DC and RUVDS have already begun reviewing and upgrading external equipment protection. Additional costs for redundant communications, DDoS mitigation, vulnerability management, and faster recovery are expected to be passed on to clients in government, finance, and telecom sectors. First Deputy Prime Minister Denis Manturov stated that decisions will remain targeted and will not trigger widespread nationalization.
iMazing 3.6.3 Restores Sideloading of Removed iOS Apps via macOS After Apple Authentication Changes
Developers of iMazing have released version 3.6.3 that restores the ability for users to download and install applications previously removed from the App Store onto iPhone devices. The update currently functions only through macOS, with Windows support still pending further development. The changes address authentication and download errors that appeared in macOS 26 and earlier versions following modifications by Apple to its CommerceKit system. Apple began returning HTTP 403 Forbidden responses to tools including iMazing, ipa_downloader, and 3uTools by deactivating legacy tokens and revoking certificates used for app authentication. The restrictions have particularly affected Russian users who relied on these tools to reinstall banking and other applications removed due to sanctions. Support for macOS 27 Golden Gate and Windows remains unavailable and requires additional engineering work.
FSTEC Order 60 Expands Attestation Rules to Municipal Systems, Defense Industry and Personal Data Operators
Russia's FSTEC Order No. 60, effective 1 September 2026, rewrites the list of entities subject to information system attestation under the updated Order No. 77. The changes reach far beyond state information systems to cover municipal information systems, industrial control systems at defense enterprises, protected premises for confidential talks, and any commercial personal data operators that voluntarily included attestation in their policies. New clauses introduce mandatory vulnerability analysis and penetration testing as explicit control methods, tighten reporting deadlines to five working days, and require FSTEC-licensed organizations with specific rights for testing. Parallel FSB Order No. 297 obliges every state institution, including schools and hospitals, to report incidents to NKTSKI within 24 hours via a personal cabinet established only after a formal interaction regulation is signed. Government Decree No. 1024 permits cloud services for state systems but keeps full compliance responsibility with the user organization. The combined rules take effect on 1 September 2026, with one provision delayed until March 2027.