Russia's Top Investigator Proposes AI, VPN and Other Technologies as Aggravating Circumstances in Criminal Code
Alexander Bastrykin, Chairman of the Investigative Committee of Russia, has proposed amending the Criminal Code to classify the use of artificial intelligence, VPN services and other information technologies as an aggravating circumstance in criminal cases.
The committee has already drafted the corresponding bill, Bastrykin told Interfax. At present, the Criminal Code contains no universal norm that would allow courts to take into account the application of such tools when determining punishment.
According to Bastrykin, these technologies are increasingly helping offenders achieve their objectives, from fraud and illegal circulation of personal data to terrorism, murder and sexual offences.
The head of the Investigative Committee considers it ineffective to insert separate references to AI, proxy servers and similar tools into dozens of individual articles of the Criminal Code. By the time legislators list specific technologies, the IT sector will have changed several times and the wording will have become outdated.
Instead, the committee advocates a systemic solution: recognising the use of technology as a standalone aggravating factor. The new provision would apply only when the technology served as the principal instrument of the crime or enabled a substantial increase in the harm inflicted, for example by scaling cyber fraud or organising the illegal trade in personal data.
Bastrykin emphasised that the measure would not punish citizens for simply having a VPN enabled, carrying a smartphone or running a neural network on their computer. The norm is intended solely for situations in which digital tools materially facilitate or intensify criminal activity.
Related articles
Russian Ministry Clarifies No Plans to Disable Apple iPhones Despite New Device Registry
The Russian Ministry of Digital Development has officially stated that no government body or telecom operator has the authority to remotely disable iPhones or other devices from specific manufacturers. The clarification was issued in response to an inquiry from deputy Vladimir Plyakin regarding rumors of potential restrictions if Apple fails to comply with Russian legislation. Current laws do not permit turning user devices into non-functional bricks through any centralized mechanism. However, amendments to the law On Communications will introduce a national registry of user equipment identifiers starting March 1, 2027. The ministry is still developing the regulatory framework for this database, including what data will be collected and which agencies will have access. Officials emphasized that the existence of the registry does not imply any capability for mass device deactivation at this stage.
Bank of Russia Publishes Methodological Recommendations No. 3-MR on AI Security for Financial Market Participants
The Bank of Russia has released methodological recommendations No. 3-MR dated 16 June 2026, providing detailed guidance on ensuring information security during the development and use of artificial intelligence systems in the financial sector. The document builds on the earlier Code of Ethics for AI in finance and integrates with existing risk management, operational resilience, and data protection frameworks already familiar to credit institutions and other market participants. It introduces standardized terminology for AI-specific threats such as hallucinations, data drift, and poisoned datasets while outlining six risk categories and a four-stage AI system lifecycle model. Organizations are advised to apply threat modeling based on FSTEC methodology, implement proportional controls across data preparation, development, training, and operation phases, and maintain human oversight for high-risk automated processes. Special attention is given to supply chain risks involving third-party vendors and open-source components, requiring due diligence, provenance tracking, and contractual safeguards aligned with existing outsourcing standards. The recommendations remain non-binding yet signal clear regulatory expectations that are likely to influence future compliance checks and audits.
Aladdin Obtains New FSB Certificate for CryptoFlash Encrypted USB Drive Valid Until 2029
Aladdin has received a new FSB Russia certificate for its Aladdin CryptoFlash hardware-encrypted USB drive. The certificate number СФ/124-5574 confirms compliance with cryptographic protection requirements for classes KS1 and KS2 and remains valid until 16 July 2029. The device now supports additional Russian Linux distributions including RED OS 7.3 and 8, Alt 8 SP Workstation, Alt Workstation 10, and the OS of the Moscow Electronic School. Read and write speeds have been increased to 11 MB/s while the graphical interface received improvements. The product uses the Magma encryption algorithm in hardware and operates as a clientless solution that requires no additional drivers or software. The previous certificate remains active until December 2028, allowing both versions of the device to be used in parallel for storing and transferring official and confidential information marked DSP.
Microsoft Tightens Corporate Windows Activation with TPM-Bound KMS Servers
Microsoft is strengthening its corporate Windows licensing controls by introducing new requirements for KMS servers used in volume activation. The changes will bind KMS hosts to TPM hardware attestation, preventing cloned or fake servers from issuing licenses to unlicensed devices. Warnings will begin appearing in Windows Server 2025 in August 2026, with mandatory enforcement planned for the next LTSC release. Existing KMS systems will continue operating normally until the new rules take effect. The update targets enterprise environments with on-premises KMS infrastructure and does not affect individual consumer devices or common non-KMS activation bypass methods. Administrators can already verify TPM support on physical servers using the Get-TpmSupportedFeature command.