Russia to Require Independent Lab Testing of Sovereign AI Models for Legal and Traditional Values Compliance
Russian developers will soon be able to submit large generative AI models to independent testing laboratories that will check compliance with Russian legislation and traditional spiritual-moral values. The scheme is being prepared by MinTsifry as part of subordinate legislation and will apply exclusively to models seeking the status of national or sovereign systems.
Such status grants access to state support, government datasets, public procurement and priority deployment in selected sectors, with education and public services expected to be among the first areas. Developers must perform an initial self-assessment using a risk-oriented methodology and provide detailed documentation on model architecture, content-filtering mechanisms and other technical aspects.
Accredited laboratories will then validate the submitted results, execute specialised benchmarks and attempt to bypass restrictions through prompt-injection techniques, effectively conducting a “spiritual-moral penetration test”. Multiple accredited laboratories may issue conclusions, but the final decision on compliance and status assignment will rest with MinTsifry.
Security evaluation of models intended for state systems will be conducted separately by the FSB and FSTEC Russia. The list of traditional values will not be newly created; it is already established by presidential Decree 809. The main challenge lies in translating abstract concepts such as justice, citizenship and historical memory into measurable technical criteria.
Industry experts warn that the evaluative nature of the requirements could lead to selective enforcement and therefore recommend transparent test procedures, reproducible results, defined validity periods for certificates and mandatory re-assessment after model updates. The final package of documents is still under coordination within the ministry.
Related articles
Why Separate Corporate and Personal Email Accounts: Risks of Mixing Work and Private Communications
Mixing corporate and personal email accounts creates serious security, compliance, and operational risks for both employees and organizations. When employees forward contracts or client data to personal mailboxes to bypass size limits or convenience, copies proliferate beyond company control in phones, backups, and cloud services. After termination, the employer loses any ability to revoke access or audit the data, while personal accounts often lack multi-factor authentication and strong password practices. Russian legislation including Federal Law No. 152-FZ on personal data, the Labor Code, and Federal Law No. 98-FZ on trade secrets requires proper protection of sensitive information. Using work email for shopping, banking, or password recovery exposes the corporate domain to phishing and leaks, while the reverse creates dependency on private accounts for business continuity. The recommended practice is strict separation with unique passwords, MFA on both accounts, and approved corporate channels for file transfer.
Yandex Pay App Permanently Removed from App Store Across All Regions Due to Sanctions
The Yandex Pay application has been fully removed from the App Store in every region worldwide. Existing installations continue to operate normally, and the company has confirmed that all client funds remain secure. However, users can no longer download the app or receive updates, prompting Apple device owners to avoid deleting the application. Yandex recommends disabling automatic app updates through iOS settings to prevent any potential loss of functionality. If the app is accidentally removed, the service remains accessible through the web version at pay.yandex.ru, which can be added to the home screen via Safari. The removal occurs amid broader sanctions and information-related restrictions affecting Russian technology services.
NSPK Warns of Potential Online Payment Disruptions for Visa and Mastercard Holders Due to Russian Certificate Transition
The National System of Payment Cards (NSPK) has issued a warning that holders of Russian-issued Visa and Mastercard cards may encounter difficulties when making online purchases. The issues stem from NSPK's ongoing transition to Russian security certificates required for authenticating internet resources and establishing secure connections. NSPK recommends that users proactively replace their existing cards with Mir-branded alternatives to avoid payment failures at critical moments. The move aligns with broader efforts toward import substitution and ensuring stable access to payment services amid international sanctions imposed on Russia since 2022. Mir cards will remain fully functional for both in-store and online transactions without any changes. Foreign browsers may display security warnings when encountering the new Russian certificates, though NSPK stresses that these alerts do not indicate compromised resources or data leaks. The transition is described as standard practice among Russian organizations and will not affect payment security, data protection, or overall service operations.
Astra Cloud Launches Attested Secure Cloud to Accelerate FSTEC Compliance for Russian Government Systems
Astra Cloud, part of the Astra Group, has introduced a new "Protected Attested Cloud" service designed for hosting state information systems, personal data systems, medical platforms, and other sensitive environments. The infrastructure has received official attestation under FSTEC Russia Order No. 117 for protection class K1 and Order No. 21 for protection level UZ-1. Customers can leverage the pre-certified platform to speed up their own system attestation procedures by three to five times, although each organization's information system must still undergo separate certification. The service includes certified security tools such as firewalls, antivirus solutions, intrusion detection and prevention systems, trusted boot mechanisms, and SIEM, with all connections required through certified cryptographic channels. The cloud is hosted in a Tier IV data center built on domestic hardware and targets organizations that must meet FSTEC requirements without building their own protected infrastructure. From March 2026, Order No. 117 replaces Order No. 17 and extends obligations to subordinate institutions and companies interacting with the state segment, including 24-hour remediation of critical vulnerabilities.