Habr•August 21, 2026•🇷🇺Translated from Russian

Rospotrebnadzor and FAS to Extend Oversight to Websites: Automating Foreign Word Replacement Using LLM

Russian compliance specialists have created an automated system to help websites comply with Federal Law No. 168-FZ on protecting the Russian language ahead of expected enforcement actions by Rospotrebnadzor and the Federal Antimonopoly Service.

The law prohibits the use of foreign words when common Russian equivalents exist and bans both Latin script and transliterations written in Cyrillic. It requires identification of prohibited borrowings by comparing text against four official dictionaries approved by the Russian Academy of Sciences: orthographic, orthoepic, explanatory, and the dictionary of foreign words.

The developed microservice, named Normograph, implements a five-stage pipeline that significantly reduces the volume of text sent to the language model. First, HTML pages are cleaned of markup and tokenized. Second, primary filtering removes words present in normative dictionaries, user-defined white lists, and registered trademarks. Third, the system flags potential issues including words absent from dictionaries, known anglicisms, and Latin-script terms.

Only after these algorithmic filters does the LLM receive small relevant fragments. The model determines whether a word qualifies as an impermissible borrowing, considers context, and proposes accurate Russian synonyms that match in gender, number, and case. The pilot uses GigaChat API but the architecture allows easy substitution with other models such as YandexGPT.

An additional OCR module based on Yandex Cloud Vision extracts text from images collected by a crawler. The same multi-stage filter is applied to recognized text, with caching and size-based filtering to control costs. Logos and registered trademarks are automatically excluded from checks.

Testing showed that manual review of one page previously took about one hour, while the automated system reduces the process to between two and ten minutes. The solution is positioned as a corporate compliance tool for pharmaceutical, fintech, and large e-commerce platforms that must adapt hundreds of pages before regulatory inspections begin.

Related articles

Habr•Policy & Regulation

RWB Deploys Enterprise-Wide Database Access Control with Trino and Open Policy Agent

RWB has replaced fragmented manual database access processes with a centralized architecture built on Trino as the single entry point and Open Policy Agent for policy enforcement. The system enforces least-privilege access, mandatory auditing, and automated revocation tied to HR records while eliminating anonymous and password-based logins. Access requests now complete in 3–10 minutes instead of an average of four days, with 92 percent handled automatically. Key components include Keycloak for OIDC authentication, Vault for secrets, Kafka for security event streaming to SOC, and Kubernetes orchestration. Responsibility is split across AI & Data Security, Core DevOps, Access Management, SOC, and Trust & Safety teams. More than 1,250 PostgreSQL clusters and 90 projects are now connected, with real-time dashboards tracking adoption and policy health.

AntiMalware•Policy & Regulation

Russia Moves to Allow Biometric Data Processing for Suspects and Convicts Without Consent

Russian law enforcement agencies may soon gain the legal right to process biometric data of suspects, accused individuals, and convicted persons without requiring their personal consent. A corresponding draft bill has already been submitted to the government and is scheduled for review at the next cabinet meeting, according to TASS. The measure covers fingerprints, facial images, voice recordings, and other physiological or behavioral characteristics used for identification. If approved, prior permission from the individual will no longer be needed when biometrics are used in criminal proceedings. The change applies not only to those already convicted but also to suspects and accused persons whose guilt has not yet been established by a court. For ordinary citizens, enrollment in the Unified Biometric System remains voluntary and is used for remote identity verification when accessing financial and government services.

AntiMalware•Policy & Regulation

FAS Clears Russian Operators on 'Unlimited' Internet Claims Despite Speed Throttling to 128 Kbit/s

The Federal Antimonopoly Service has declined to investigate complaints regarding promises of unlimited internet and unrestricted roaming access made by major Russian mobile operators. The Association of Professional Users of Social Networks and Messengers argued that operators including Vimpelcom, MegaFon, MTS, and T2 Mobile mislead customers by advertising unlimited plans while throttling speeds to 128-512 Kbit/s after data caps are reached. FAS determined that information on official company websites does not qualify as advertising under Russian law. Operators maintain that the term unlimited remains accurate because no total data volume limit exists, only speed reductions detailed in service descriptions. The complainants and legal experts contend that FAS reviewed only technical parameter pages and ignored banners, promotional news, search ads, SMS, and push notifications that may meet legal criteria for advertising. The decision leaves consumers facing slow connections unsuitable for video or file downloads after initial allowances are exhausted.

Habr•Policy & Regulation

Merkle Tree Certificates Proposed to Enable Lightweight Post-Quantum HTTPS in Chrome

Google Chrome developers, together with industry partners and the IETF PLANTS working group, are introducing Merkle Tree Certificates (MTC) as the first HTTPS change designed to address performance challenges of post-quantum cryptography. The new format replaces parts of traditional X.509 certificate chains with compact inclusion proofs inside a Merkle tree whose root is signed by a certificate authority. This approach significantly reduces the size of authentication data exchanged during TLS handshakes while preserving strong post-quantum security properties. MTC also enforces Certificate Transparency by design, making it impossible to issue a public certificate without recording it in a publicly verifiable log. Performance evaluations are currently underway with Cloudflare, and initial public MTC logs operated by experienced CT log providers are planned for early 2027. A dedicated post-quantum Chrome Root Store supporting only MTC is scheduled for the third quarter of 2027 and will run in parallel with the existing root store.