Bank of Russia Publishes Methodological Recommendations No. 3-MR on AI Security for Financial Market Participants
The Bank of Russia has issued Methodological Recommendations No. 3-MR dated 16 June 2026 on ensuring information security when developing and applying artificial intelligence systems on the financial market. The document targets credit organizations, branches of foreign banks in Russia, non-credit financial institutions, professional market participants, and subjects of the national payment system.
Status and Relation to Existing Regulation
Although the recommendations carry a non-binding status, they represent a clear direction of regulatory travel. The document builds directly on the Code of Ethics in the sphere of AI development and application on the financial market (information letter of the Bank of Russia dated 9 July 2025 No. IN-016-13/91). It integrates seamlessly with the sector’s existing foundations in risk management, operational reliability, outsourcing controls, and personal data protection under 152-FZ, rather than creating a separate regulatory universe.
Key Innovations in Terminology and Risk Categories
The recommendations introduce official definitions for AI-specific concepts previously found mainly in expert literature and national standards, including AI hallucinations, data drift, direct and indirect prompt injection, and poisoned datasets. Terms such as AI system, explainability, predictability, reliability, and quality are drawn from GOST R 71476-2024 and GOST R 59898-2021. Risks are grouped into six categories: data management risks, confidentiality breaches, model malfunction including hallucinations and drift, insufficient explainability, supplier and open-source risks, and operational resilience threats. Potential consequences range from violations of citizens’ rights and financial losses to threats to the stability of the entire financial system.
Human Oversight and Threat Modeling
For critical automated processes such as payment operations and accounting systems assessed as high-risk, the document recommends human validation of AI outputs with the ability to override decisions. Threat modeling should follow the FSTEC Methodology for Assessing Information Security Threats dated 5 February 2021. The AI system lifecycle is divided into four stages: data preparation, development, training and testing, and operation. Specific threats include model evasion, poisoning of training data, model extraction, dataset theft, model modification, denial of service, and behavior manipulation, with attack techniques such as fuzzing, backdoors, data extraction, malicious injections, sponge attacks, and adversarial examples.
Supply Chain and Open Source Controls
Chapter 5 addresses practical realities of using external services and open-source components. Organizations should apply existing outsourcing rules from STO BR IBBS-1.4-2018 and build trust in external data and models according to GOST R 59276-2020. A dedicated methodology for assessing trust in third-party data, models, and open-source elements is recommended, covering factors such as Bug Bounty participation, software specifications including SBOM/MLBOM, vulnerability analysis reports, penetration testing results, secure development processes, data provenance tracking, and internal risk evaluation. Integrity of external components must be verified using tools certified by the FSTEC certification system. When a supplier trains a model, only cleaned, synthetic, or anonymized data should be transferred, and contracts must include liability provisions and incident notification obligations.
Practical Implementation Steps
The recommendations include a detailed policy template covering red-team testing, minimal use of personal data, output labeling, reduction of model information in public repositories, emergency shutdown plans, and periodic policy reviews. Practical steps for organizations begin with inventorying all AI components, followed by risk assessment across the six categories, construction of a threat model, implementation of controls at each lifecycle stage, placement of human oversight in critical processes, strengthening of supply-chain due diligence, and formalization of an AI security policy with assigned responsibility and continuous improvement cycles.
Related articles
Multiple Ozon Apps Removed from Google Play Following Sanctions on Ozon Bank
Several Ozon applications have been removed from the Google Play store, affecting Android users who can no longer download the main Ozon client along with Ozon Fresh, Ozon Seller, Ozon Job and Ozon Travel. Ozon stated that the company did not violate Google Play rules, yet the exact reasons for the removals remain undisclosed. The action follows the earlier disappearance of the Ozon Bank app after the bank was placed under European Union sanctions, although no official connection has been confirmed. Apple users continue to access Ozon services through the App Store, while Android users are directed to alternative stores including RuStore, AppGallery and Galaxy Store. The company also warned against downloading APK files from unverified sources due to security risks. The removals come amid a broader wave of app store purges that also affected Yandex Pay on the App Store. Already installed applications generally continue to function, but users may face difficulties with future updates and reinstalls.
Ruthenium: Custom Chromium Build for Android Adds Russian Trusted Root CA Support
A developer has released Ruthenium, a modified Chromium browser for Android that embeds the Russian Trusted Root CA certificate issued by the Ministry of Digital Development. The build restricts trust to .ru and .рф domains only, avoiding changes to the system-wide Android certificate store. The project patches four Chromium source files to include the root with DNS constraints via CertWithConstraints, disables Google sign-in by default, and removes XR-related code for successful compilation. Ruthenium uses the official Chromium TLS verification logic without introducing a custom verifier. The APK is distributed with SHA-256 checksums, build metadata, and reproducible release tags tied to the exact Chromium revision and certificate digest. Users can install it alongside stock Chrome and use it selectively for Russian government and banking sites that rely on the state root.
US Federal Judge Orders Google to Simplify Installation of Third-Party App Stores on Android
A federal judge has directed Google to remove extra warnings and confirmation steps when users install competing app stores through Google Play on Android devices. The ruling stems from the ongoing antitrust litigation between Epic Games and Google, where a jury previously found that Google illegally maintained a monopoly over Android app distribution and in-app payments. Judge James Donato criticized the current multi-screen process as an intentional barrier designed to discourage ordinary users from choosing alternatives. Google must implement the changes within one week, making the installation of third-party stores as straightforward as any other Android application. The decision acknowledges that while Android has long permitted sideloading, the layered security prompts and hidden permission toggles effectively steered most users back to Google Play. Aptoide has already appeared in the US Google Play store as the first third-party marketplace to benefit from the eased process. Google argued the warnings protect users from malware, but the court rejected the notion that security should serve as a shield for market dominance.
Why Russia Needs Specialized Circumvention Tools Beyond Standard VPNs
The developers of Tunnel Kitten explain why another circumvention project is necessary despite the availability of numerous VPN services and solutions like AmneziaWG. A prolonged outage affected many long-term users, damaging trust and requiring ongoing fixes. Standard VPNs do not address the core issue: creating and maintaining tools to bypass internet blocks has been criminalized in Russia. This legal asymmetry makes public VPN services and self-hosted solutions risky or insufficient for users facing state-level censorship. Tunnel Kitten positions itself as a project focused on a different task that accounts for these legal realities. The team emphasizes that the problem is not merely technical but tied to the criminalization of circumvention efforts.