
FSTEC order on AI: what to prepare before September 1
FSTEC has posted a draft order on personal data protection to regulation.gov.ru. It replaces Order No. 21, the basis for data protection practice for more than a decade, and takes effect on September 1, 2026.
What has changed
Controls are matched to the system's protection level, of which there are four. Virtualization, containers, IoT, cloud computing, email, web services and APIs each get their own section. For the first time, information security in the use of artificial intelligence and in work with contractors is treated as a separate area. A maturity rating for controls has been added. Effectiveness must be assessed at least once every three years — and after every incident at the operator or the processor.
What this means
The regulator is looking at the entire data lifecycle: collection, processing, transfer, and use in analytics and algorithms. Any scenario in which personal data leaves for a third-party service through an API now falls inside the compliance perimeter.
A pilot built on large language models before the autumn needs groundwork. The rules for passing data to contractors and AI services are written down in advance, and someone is named to own this area. Doing that while the solution is still being chosen costs less than rebuilding the setup after launch.
What is still unknown
The order's number, the final wording after public consultation, and whether the requirements apply to cloud AI services hosted outside Russia. The document puts no figure on the cost. That can be estimated for a specific setup — for example, through a budget estimate.
Let’s discuss your project?
Tell us about your process — we’ll suggest where AI pays off fastest.
Related articles

What a company perimeter is, and when data never leaves it
A company perimeter is the boundary inside which data and computation stay under the company's control: its own servers, its own networks, its own accounts.

AI law signed: regulatory threshold set at 1 billion parameters
Russia signed its first standalone federal AI law on 26 July. It introduces a threshold of 1 billion parameters and requires companies to appoint someone accountable for compliance.