[UTC+3]

FSTEC order on AI: what to prepare before September 1

July 30, 2026 · 1 minNewsRussian market

FSTEC has posted a draft order on personal data protection to regulation.gov.ru. It replaces Order No. 21, the basis for data protection practice for more than a decade, and takes effect on September 1, 2026.

What has changed

Controls are matched to the system's protection level, of which there are four. Virtualization, containers, IoT, cloud computing, email, web services and APIs each get their own section. For the first time, information security in the use of artificial intelligence and in work with contractors is treated as a separate area. A maturity rating for controls has been added. Effectiveness must be assessed at least once every three years — and after every incident at the operator or the processor.

September 1, 2026
date the order takes effect
Once every 3 years
minimum frequency of effectiveness assessments
1–4
protection levels the set of controls is matched to
Source: forbes.ru, draft order on regulation.gov.ru

What this means

The regulator is looking at the entire data lifecycle: collection, processing, transfer, and use in analytics and algorithms. Any scenario in which personal data leaves for a third-party service through an API now falls inside the compliance perimeter.

A pilot built on large language models before the autumn needs groundwork. The rules for passing data to contractors and AI services are written down in advance, and someone is named to own this area. Doing that while the solution is still being chosen costs less than rebuilding the setup after launch.

What is still unknown

The order's number, the final wording after public consultation, and whether the requirements apply to cloud AI services hosted outside Russia. The document puts no figure on the cost. That can be estimated for a specific setup — for example, through a budget estimate.

Source: forbes.ru