HabrJuly 28, 2026🇷🇺Translated from Russian

Bank of Russia Publishes Methodological Recommendations No. 3-MR on AI Security for Financial Market Participants

The Bank of Russia has issued Methodological Recommendations No. 3-MR dated 16 June 2026 on ensuring information security when developing and applying artificial intelligence systems on the financial market. The document targets credit organizations, branches of foreign banks in Russia, non-credit financial institutions, professional market participants, and subjects of the national payment system.

Status and Relation to Existing Regulation

Although the recommendations carry a non-binding status, they represent a clear direction of regulatory travel. The document builds directly on the Code of Ethics in the sphere of AI development and application on the financial market (information letter of the Bank of Russia dated 9 July 2025 No. IN-016-13/91). It integrates seamlessly with the sector’s existing foundations in risk management, operational reliability, outsourcing controls, and personal data protection under 152-FZ, rather than creating a separate regulatory universe.

Key Innovations in Terminology and Risk Categories

The recommendations introduce official definitions for AI-specific concepts previously found mainly in expert literature and national standards, including AI hallucinations, data drift, direct and indirect prompt injection, and poisoned datasets. Terms such as AI system, explainability, predictability, reliability, and quality are drawn from GOST R 71476-2024 and GOST R 59898-2021. Risks are grouped into six categories: data management risks, confidentiality breaches, model malfunction including hallucinations and drift, insufficient explainability, supplier and open-source risks, and operational resilience threats. Potential consequences range from violations of citizens’ rights and financial losses to threats to the stability of the entire financial system.

Human Oversight and Threat Modeling

For critical automated processes such as payment operations and accounting systems assessed as high-risk, the document recommends human validation of AI outputs with the ability to override decisions. Threat modeling should follow the FSTEC Methodology for Assessing Information Security Threats dated 5 February 2021. The AI system lifecycle is divided into four stages: data preparation, development, training and testing, and operation. Specific threats include model evasion, poisoning of training data, model extraction, dataset theft, model modification, denial of service, and behavior manipulation, with attack techniques such as fuzzing, backdoors, data extraction, malicious injections, sponge attacks, and adversarial examples.

Supply Chain and Open Source Controls

Chapter 5 addresses practical realities of using external services and open-source components. Organizations should apply existing outsourcing rules from STO BR IBBS-1.4-2018 and build trust in external data and models according to GOST R 59276-2020. A dedicated methodology for assessing trust in third-party data, models, and open-source elements is recommended, covering factors such as Bug Bounty participation, software specifications including SBOM/MLBOM, vulnerability analysis reports, penetration testing results, secure development processes, data provenance tracking, and internal risk evaluation. Integrity of external components must be verified using tools certified by the FSTEC certification system. When a supplier trains a model, only cleaned, synthetic, or anonymized data should be transferred, and contracts must include liability provisions and incident notification obligations.

Practical Implementation Steps

The recommendations include a detailed policy template covering red-team testing, minimal use of personal data, output labeling, reduction of model information in public repositories, emergency shutdown plans, and periodic policy reviews. Practical steps for organizations begin with inventorying all AI components, followed by risk assessment across the six categories, construction of a threat model, implementation of controls at each lifecycle stage, placement of human oversight in critical processes, strengthening of supply-chain due diligence, and formalization of an AI security policy with assigned responsibility and continuous improvement cycles.

Related articles

HabrPolicy & Regulation

Web Certificate Trust Chains and State Access Risks Explained Amid Russian Banking Sanctions

The article explains the hierarchical structure of web certificates used for site authentication and traffic encryption, starting from highly protected root certificates stored in air-gapped facilities with Shamir's secret sharing for key protection. Intermediate certificates extend the chain of trust down to leaf certificates deployed on websites. Russian banks have turned to certificates issued under the MinTsifry root after Western and Chinese CAs refused service due to sanctions. The piece highlights that any nation-state with access to a root private key, whether FSB, NSA, or others, could theoretically issue fraudulent certificates for any domain. It notes the limitations of the X.509 standard, which lacks native support for multi-CA signatures, and suggests that separate browsing environments or PGP-style web-of-trust models could mitigate risks. The author concludes that security is already reduced by reliance on any state-controlled CA and that the choice is ultimately which intelligence agency one prefers to trust.

AntiMalwarePolicy & Regulation

MAX Messenger to Open Source Code and Launch Developer Program for Alternative Clients

The Russian messenger MAX is preparing to open its platform to third-party developers by launching a dedicated developer program and providing API access. Approved participants will receive the official client's source code, design system, technical documentation, and access tokens to integrate with the platform infrastructure. The initiative targets IT companies from Russia and friendly countries that demonstrate experience with large-scale projects and adherence to strict security standards. All selected developers must implement secure development practices, robust encryption mechanisms, and undergo code audits to protect user data. The program supplies ready-made user registration and anti-fraud tools, while alternative clients remain bound by API usage terms focused on security compliance. Applications will be accepted via the official developer portal, although exact launch dates have not yet been disclosed.

HabrPolicy & Regulation

InfoWatch Details ARMA Wall NGFW Development for Industrial Systems Under Russian Import Substitution Rules

InfoWatch has published the second part of its interview series describing the ongoing development of the ARMA Wall next-generation firewall for industrial control systems. The product prioritizes on-premise processing without cloud agents to meet strict customer security policies and certification requirements. Engineers combine proprietary detection feeds with external sources, including indicators from NKCKI, while maintaining hundreds of thousands of signatures without disabling legacy rules for older Siemens controllers. Migration support relies on manual pre-project audits rather than automated tools, and the company works closely with domestic SCADA vendors to embed NGFW capabilities inside long-lifecycle OT environments. ARMA Wall is positioned as a more flexible and cost-effective alternative to data diodes because it allows granular command-level filtering and can emulate one-way traffic when required. The solution is already deployed at Roscosmos subsidiary RKK Energia after full certification and categorization.

AntiMalwarePolicy & Regulation

WhatsApp Developing AI Content Labeling Feature for Channel Admins to Meet EU Transparency Rules

WhatsApp, owned by Meta, is rolling out a new function that allows channel administrators to mark posts containing AI-generated or AI-edited media. The feature appears in the latest Android beta and stems directly from European Union requirements for transparency around artificial intelligence content. Administrators can long-press a message after publication and select an option to add an AI content label, which then displays a visible tag informing subscribers that the material was created or modified by neural network tools. The requirement applies specifically to images, videos, and other media files, while generated text remains exempt from mandatory labeling. WABetaInfo researchers spotted the change, noting that the label may become permanent once applied and that the rollout could initially target only jurisdictions with relevant legislation. Broader availability for iOS users and global deployment remain under consideration.