Russia Drafts Rules Letting Users Choose AI Assistant at Smartphone First Boot
The Russian Ministry of Digital Development has prepared a draft government resolution that would let users choose their system AI assistant when first activating a smartphone. The proposal, now open for public discussion, replaces the current narrow category of voice assistant with the wider term system assistant.
Under the draft, a system assistant is an AI program that interacts with the device, operating system, and installed applications through voice, text, and visual commands. At initial setup, users would be presented with a list of available solutions and could select one or refuse installation entirely. No specific company, service, or platform is mandated.
The chosen assistant must receive the same treatment as any pre-installed solution from the device manufacturer or operating system vendor. This includes regular updates, support for user settings, and equal visibility in the interface. The pre-installed version must remain free of charge and must not disappear after software updates or a factory reset.
The changes would also affect the list of pre-installed search services, allowing inclusion of solutions that incorporate artificial intelligence technologies. Ministry officials argue the measure will strengthen competition between Russian and foreign platforms and ensure continued access to modern AI services even if individual foreign products encounter regulatory restrictions.
The core principle of the draft is straightforward: device manufacturers would no longer unilaterally decide which AI assistant is installed. The final choice would rest with the device owner.
Related articles
Why Sending an MDM Command Does Not Mean It Has Been Executed
MDM operations such as policy assignment and device lock appear synchronous in the console but actually trigger complex asynchronous delivery chains involving backends, queues, vendor infrastructure, and device agents. The article explains that request acceptance, queue storage, external API confirmation, and actual device execution represent four distinct states that must be tracked separately. Aitera MDM implements an Outbox pattern to ensure transactional consistency between policy changes and command delivery while supporting at-least-once semantics with idempotency. Android Enterprise relies on the Android Management API and Google-controlled synchronization through Android Device Policy, whereas iOS uses APNs only for wake-up and pull-based command retrieval with statuses including Acknowledged, Error, and NotNow. The system maintains separate desired, delivery, and observed states to avoid misleading applied flags and provides detailed command history for administrators. Metrics focus on policy confirmation rates, queue age, and divergence between intended and actual device configurations rather than simple device counts.
Russia's FAS Opens Antitrust Case Against Apple for Failing to Pre-Install Domestic Software on iOS Devices
Russia's Federal Antimonopoly Service has initiated proceedings against Apple after the company failed to comply with a prior warning to pre-install Russian software on iPhones and iPads. The case stems from requirements under Russian law to offer domestic alternatives for search engines, messengers, and app stores. Apple had added support for a Russian search engine in a software update, but this did not satisfy regulators who also demanded the national messenger and domestic app store. Non-compliance could result in a fine reaching up to 4 billion rubles under the Code of Administrative Offenses. The government has already approved a mandatory list of Russian applications that must be pre-installed on smartphones and tablets starting January 1, 2027. The list includes RuStore, Max, Yandex Browser, Alice AI, VKontakte, Gosuslugi, Mir Pay, Mail.ru, and 2GIS among others.
Password Rotation Policies Under Scrutiny: NIST Guidelines, Historical Origins, and Logical Flaws
The article examines the long-standing practice of mandatory password rotation every 90 days, contrasting it with modern recommendations from NIST that advocate changing passwords only upon confirmed compromise rather than on a fixed schedule. It dissects common arguments in favor of periodic rotation, such as limiting offline hash cracking time and terminating unknown sessions, and demonstrates how these rely on reverse logic that starts from the control rather than from actual threats. Historical analysis traces the 90-day rule back to the 1985 DoD Green Book (CSC-STD-002-85), revealing that its own calculations showed password lifetime has minimal impact on security when proper rate limiting is in place. The piece distinguishes between data leakage and credential compromise, emphasizing that internal organizational signals provide far better indicators for targeted password changes than public breach databases. It concludes that scheduled rotation only makes sense as a substitute for mature detection capabilities, a trade-off explicitly recognized in PCI DSS v4.0.
Yandex Alice AI Replaces VK Marusya in Russia's Mandatory Preinstalled Apps List for 2027
Russian authorities have approved the official list of software that device manufacturers and sellers must preinstall on smartphones, tablets, and computers starting in 2027. The updated requirements maintain most of the previous selections without major disruption. The only notable change involves voice assistants, where Yandex Alice AI will now take the place previously held by VK Marusya. This adjustment reflects ongoing government efforts to promote domestic software through mandatory preinstallation policies. The regulation continues to focus on ensuring Russian-developed applications receive prominent placement on new devices sold in the country.