Bank of Russia Publishes Methodological Recommendations No. 3-MR on AI Security for Financial Market Participants
The Bank of Russia has issued Methodological Recommendations No. 3-MR dated 16 June 2026 on ensuring information security when developing and applying artificial intelligence systems on the financial market. The document targets credit organizations, branches of foreign banks in Russia, non-credit financial institutions, professional market participants, and subjects of the national payment system.
Status and Relation to Existing Regulation
Although the recommendations carry a non-binding status, they represent a clear direction of regulatory travel. The document builds directly on the Code of Ethics in the sphere of AI development and application on the financial market (information letter of the Bank of Russia dated 9 July 2025 No. IN-016-13/91). It integrates seamlessly with the sector’s existing foundations in risk management, operational reliability, outsourcing controls, and personal data protection under 152-FZ, rather than creating a separate regulatory universe.
Key Innovations in Terminology and Risk Categories
The recommendations introduce official definitions for AI-specific concepts previously found mainly in expert literature and national standards, including AI hallucinations, data drift, direct and indirect prompt injection, and poisoned datasets. Terms such as AI system, explainability, predictability, reliability, and quality are drawn from GOST R 71476-2024 and GOST R 59898-2021. Risks are grouped into six categories: data management risks, confidentiality breaches, model malfunction including hallucinations and drift, insufficient explainability, supplier and open-source risks, and operational resilience threats. Potential consequences range from violations of citizens’ rights and financial losses to threats to the stability of the entire financial system.
Human Oversight and Threat Modeling
For critical automated processes such as payment operations and accounting systems assessed as high-risk, the document recommends human validation of AI outputs with the ability to override decisions. Threat modeling should follow the FSTEC Methodology for Assessing Information Security Threats dated 5 February 2021. The AI system lifecycle is divided into four stages: data preparation, development, training and testing, and operation. Specific threats include model evasion, poisoning of training data, model extraction, dataset theft, model modification, denial of service, and behavior manipulation, with attack techniques such as fuzzing, backdoors, data extraction, malicious injections, sponge attacks, and adversarial examples.
Supply Chain and Open Source Controls
Chapter 5 addresses practical realities of using external services and open-source components. Organizations should apply existing outsourcing rules from STO BR IBBS-1.4-2018 and build trust in external data and models according to GOST R 59276-2020. A dedicated methodology for assessing trust in third-party data, models, and open-source elements is recommended, covering factors such as Bug Bounty participation, software specifications including SBOM/MLBOM, vulnerability analysis reports, penetration testing results, secure development processes, data provenance tracking, and internal risk evaluation. Integrity of external components must be verified using tools certified by the FSTEC certification system. When a supplier trains a model, only cleaned, synthetic, or anonymized data should be transferred, and contracts must include liability provisions and incident notification obligations.
Practical Implementation Steps
The recommendations include a detailed policy template covering red-team testing, minimal use of personal data, output labeling, reduction of model information in public repositories, emergency shutdown plans, and periodic policy reviews. Practical steps for organizations begin with inventorying all AI components, followed by risk assessment across the six categories, construction of a threat model, implementation of controls at each lifecycle stage, placement of human oversight in critical processes, strengthening of supply-chain due diligence, and formalization of an AI security policy with assigned responsibility and continuous improvement cycles.
Related articles
Bill Gates Calls for Stronger External Oversight and Regulation of AI
Bill Gates stated in an NBC News interview that self-regulation by AI developers is no longer sufficient and urged Congress to pass binding laws on artificial intelligence. He warned that AI tools in the hands of malicious actors could trigger catastrophic events capable of causing up to a billion deaths, emphasizing the unprecedented power of combining bad intentions with modern AI systems. Gates advocated for mandatory rules, audits, and monitoring, particularly in critical sectors such as medicine, finance, and government infrastructure, while acknowledging that some added bureaucracy would be necessary. Leaders from Anthropic and OpenAI have similarly suggested slowing AI development, with former Anthropic employee Jacob Coxon publicly accusing companies of playing roulette with lives by pursuing self-improving superintelligence. House Speaker Mike Johnson prefers to wait for industry proposals, whereas Mark Zuckerberg opposes coordinated oversight and believes individual labs should decide on pace. Several U.S. states including California, Maryland, and New York have already begun launching their own AI regulatory initiatives and expert panels.
Implementing DevSecOps in Unprepared Teams: A Practical Three-Month Roadmap
Many development teams face resistance when security tools are introduced without proper process changes, leading to bypassed checks and unresolved findings. The article outlines a structured approach for small teams of five to eight developers without a dedicated security specialist, focusing on one service as a pilot. It emphasizes assigning clear roles including a Security Champion, selecting initial checks such as secret scanning with Gitleaks and dependency analysis, and converting scanner reports into actionable tasks with owners and deadlines. The plan covers the first eight weeks of setup, including baseline handling for legacy issues, automated blocking rules, and incident rehearsal exercises. Metrics recommended include time to first triage, age of open critical defects, and false positive rates, aligned with DORA indicators for release performance. The guidance draws on OWASP SAMM practices and stresses that security requirements must be integrated into daily workflows rather than added as extra gates.
Why Technically Strong CISOs Lose to Weaker Peers: The Hidden Role of Internal Politics
A new analysis from independent expert Andrey Biryukov explains why technically proficient CISOs frequently fail to secure budgets and executive support while less technical peers succeed. The core issue lies not in technical knowledge but in the ability to translate security risks into business language that resonates with CFOs, CEOs, and boards. Biryukov details how influence, rather than formal authority, determines whether security initiatives gain traction or stall in endless approvals. He emphasizes building coalitions in advance, crafting compelling narratives, and preparing concrete business cases that quantify revenue impact and regulatory exposure. The article also highlights common pitfalls such as relying on fear-based arguments or ignoring stakeholder KPIs. Ultimately, the piece argues that selling security internally is essential for any CISO who wants both resources and long-term survival in the role.
Bybit Restricts Transfers to Sanctioned Entities Including Lazarus Group and CryptoPro
Cryptocurrency exchange Bybit has notified users that transfers to or from entities on its Restricted Counterparties list are prohibited, regardless of amount or whether conducted directly or through intermediaries. The list includes the North Korean state-sponsored Lazarus group and Russian cryptographic software developer CryptoPro due to their presence on sanctions lists from the United States, European Union, and United Kingdom. Bybit will automatically reject outgoing transfers to listed counterparties and may freeze incoming funds from them or related addresses, with potential account suspension or closure for users involved. The exchange emphasizes that blockchain transparency allows tracing of funds without user confessions and reserves the right to block transactions even with counterparties not yet explicitly listed. These measures are embedded in Bybit's terms of service to ensure compliance with international sanctions regimes.