Russia’s first law on artificial intelligence has been signed: what players in the AI field need to be prepared for

On July 26, 2026, Russian President Vladimir Putin signed Federal Law № 243-FZ «On Supporting the Development of Artificial Intelligence Technologies in the Russian Federation» (the Law“). The Law is framework in nature and establishes the basic concepts and general principles of AI regulation in Russia.

The primary objective of the Law is to create economic conditions that make AI development and deployment in Russia both profitable and secure for businesses. To this end, the government plans to roll out a support framework encompassing tax incentives, financing, and streamlined procedures for engaging with the public sector. This is intended to help companies build competitive AI products, integrate them across real-world industries, and eventually expand into international markets.

The Law shall enter into force on September 1, 2026. The provisions governing the requirements for sovereign and national AI models, the obligations of their developers, the labeling of AI-generated content, and certain powers of the Government in this area shall take effect on March 1, 2027.

Nordic Star and ICC Russia have jointly produced a comprehensive review of the major legal updates, designed to help companies identify potential risks and capitalize on opportunities without delay.

Below, we examine the key regulatory innovations.

  1. WHAT IS A LARGE FUNDAMENTAL AI MODEL

The law introduces legal definitions of artificial intelligence and large fundamental AI models into Russian legislation.

The legislative definition of artificial intelligence is based on several key characteristics: it is a technological solution capable of independently learning from data, finding solutions without a rigidly defined algorithm, and producing results comparable to or exceeding human performance. Simply put, it is a system that does not merely follow instructions but analyzes information, identifies patterns, and adapts to new inputs.

However, the key concept around which the entire law is built is the large fundamental model of AI (“LFM“). LFM is a subcategory of artificial intelligence, but not any AI falls under this definition; only the one that simultaneously meets three criteria, namely:

  • Universal nature – the model performs a wide range of intellectual tasks at a level comparable to or exceeding that of a human.

The LFM includes precisely those models that are aimed at solving an unlimited range of tasks. Based on this logic, specialized AI models, for example, those designed only for music generation or only for facial recognition, cannot be classified as LFM, even if their parameter count exceeds 1 billion – a criterion that will be discussed below.

  • Parametric complexity – the model must contain at least 1 billion parameters.

Examples of models that meet this scale include GigaChat (Sber), YandexGPT (Yandex), and DeepSeek. It is also worth noting that for a number of commercial models, including Claude and Gemini, the exact number of parameters is not publicly disclosed, but there is reason to believe that they also meet the parametric complexity criterion.

  • Infrastructural nature – the model must serve as a foundation for the development and refinement of various types of software. This means that an LFM provides a ready-made intellectual platform that enables the creation of application-level solutions without the need to build an AI core from scratch.

It is important that the Law regulates exclusively LFM – other specialized models and small neural networks are not subject to its provisions.

It should be noted that the separate designation of «large models» in the law is a common practice worldwide. For example, the European AI Act uses the term General-Purpose AI Model (GPAI) – a broadly applicable model that can have a significant impact on society, the economy, and security in general, regardless of which product it is embedded in. At the same time, the AI Act presumes the possibility of such a significant impact if the amount of computation spent on training the model exceeds 10^25 FLOP.

Thus, the European AI Act focuses on the consequences of using AI systems and combines subjective criteria, such as «may have a significant impact», with objective computational indicators that help distinguish GPAI from highly specialized AI systems.

The need to establish a special regime for universal models stems from the fact that they serve as the foundation for many applied AI solutions and therefore create a broader regulatory effect than highly specialized systems. Therefore, both the Russian law and the European AI Act single out such models separately, linking them to objective technical criteria and imposing a special level of responsibility on developers.

In this regard, given the framework nature of the Law, there are grounds to believe that in the future, separate regulatory acts will establish a set of obligations for such developers, including requirements related to technical documentation, reporting, risk management, and cybersecurity measures.

  • KEY PRINCIPLES OF WORKING WITH LFM

The Law establishes nine principles of regulation, including: technological independence, ensuring human rights and freedoms, respecting human autonomy and free will, taking into account traditional Russian spiritual and moral values, supporting Russian developers, security, and the development of international cooperation.

Special attention among the principles of regulating LFM should be paid to technological independence. The Law defines it as the development of LFM and the creation of products using them, while maintaining national control over critical and cross‑cutting technologies, relying on the country’s own development lines, with the ultimate goal of exporting competitive products or replacing outdated and foreign analogues on the domestic market with them.

For businesses, this means that the state expects serious investment in scientific research and in‑house engineering developments, especially in areas such as defense and security, energy, finance and critical infrastructure. Such projects receive priority state support, but they require full control over the technology throughout the entire development and use cycle.

  • INTRODUCTION OF THE «SOVEREIGN» AND «NATIONAL» AI MODELS

In addition to the definition of LFM, the Law introduces two key categories of LFM: sovereign LFM and national LFM.

Both categories must be developed by a Russian legal entity. The difference between them lies in the level of use of domestic components: sovereign LFMs are created exclusively based on Russian technologies, whereas national LFMs may include foreign elements.

Below, we provide a comparative table with the characteristics of both categories.

CriteriaSovereign LFMNational LFM
DeveloperA Russian legal entity that is under the control of the Russian Federation, its constituent entities, municipal entities, or a citizen of the Russian Federation (without foreign citizenship). Control means the ability to determine the company’s decisions through direct or indirect ownership of more than 50% of the voting shares or stakes. It is important to note: the list includes individuals (citizens of the Russian Federation without dual citizenship). This means that a private business owned by such citizens may also meet the definition of a «Russian legal entity» and, consequently, qualify for the status of a LFM developer.
Lifecycle controlFull developer control at all stages: defining and modifying the model’s characteristics throughout the entire lifecycle.The developer defines and modifies only the essential characteristics established by the Government of the Russian Federation (structure, software, customizable parameters).
Technological reproducibilityFull technical and technological reproducibility of the development cycle (including training) from scratch is ensured on the territory of the Russian Federation.Full reproducibility is not required; the use of foreign components is permitted.
Using componentsAll components must be created and controlled by the developer (the explicit requirement for reproducibility excludes the use of external components other than one’s own).The use of components developed outside the Russian Federation, including other LFMs distributed under open‑license terms, is permitted.
Data processing and storageResponses to requests and data storage are provided by data processing centers located on the territory of the Russian Federation and owned by Russian legal entities.
Confirmation of compliancePassing the mandatory confirmation of compliance with the legislation of the Russian Federation and traditional Russian spiritual and moral values (the procedure is established by the Government of the Russian Federation).

Thus, the sovereign model requires full local reproducibility and exclusive control by the Russian developer, whereas the national model allows the use of open foreign components but maintains requirements for data localization and confirmation of compliance with traditional Russian spiritual and moral values.

According to estimates by the Ministry of Digital Development, Sber’s GigaChat is considered a sovereign model, while YandexGPT from Yandex is a national model.

For businesses, the introduction of these categories is significant, as each of them grants the right to state support, including training for models. At the same time, the Law does not specify the concrete measures, but we assume that they will be distributed based on the principle of technological independence: developers of sovereign LFMs will be able to claim the maximum amount of preferences.

  • DISTRIBUTION OF POWERS REGARDING THE REGULATION OF THE LFM

The law is of a framework nature, and its application will require the adoption of a number of regulatory legal acts.

The law provides for the following distribution of powers between federal and regional government bodies.

Federal level:

  • The Government of the Russian Federation has been granted the authority to establish a list of cases in which the use of exclusively sovereign and/or national LFMs is permitted. As an example, the Law specifies the banking sector and other areas of the financial market (in coordination with the Central Bank of the Russian Federation).
  • The Government of the Russian Federation also has the right to establish requirements for preventing risks associated with the use of LFMs in the relevant sectors.
  • The Government of the Russian Federation, in coordination with the Federal Security Service, establishes the procedure for granting access to information contained in federal information systems for the training of sovereign and national LFMs.
  • The Government of the Russian Federation determines measures of state support for developers of LFM and coordinates the activities of federal bodies in this area.

Regional level:

  • The highest executive body of a constituent entity of the Russian Federation, in coordination with the Federal Security Service, has the right to establish the procedure for granting access to information contained in regional state information systems, state unitary enterprises, institutions, and organizations controlled by the constituent entity of the Russian Federation, for the training of sovereign and national LFMs.

For businesses, the clause is particularly important, according to which the Government will establish cases in which the use of only sovereign or national LFMs is permissible. This means that, for example, in the banking sector, the use of other AI solutions will be significantly restricted.

  • RESPONSIBILITIES OF LFM DEVELOPERS

The Law establishes the basic obligations of developers of sovereign and national LFMs:

  • take organizational and technical measures to ensure the security of the model;
  • define the rules for using the model, establishing limitations, conditions for application, updates, and decommissioning;
  • maintain technical documentation describing the key parameters and limitations of the model.

It appears that in the foreseeable future, by‑laws will be adopted that establish clear requirements for developers of sovereign and national LFMs. These by‑laws will, among other things, define the content of documentation, minimum cybersecurity standards, audit procedures, and other practical details that have so far existed only in the form of industry standards and advisory documents.

  • MARKING OF CONTENT CREATED USING AI

The Law does not introduce mandatory labeling of AI-generated content. Instead, it provides for the following:

  • users are given the opportunity to voluntarily post an informational warning about the use of AI technologies;
  • the format, content, and procedure for posting the warning are determined by an agreement between the parties;
  • owners of online platforms with an audience of more than 500,000 users per day are required to provide users with the technical capability to post such a warning.

It is important that in this case the legislator has chosen a more lenient approach to regulation than in previously proposed draft laws. The contrast with the November 2025 draft law is particularly striking: it placed the responsibility for recognizing and labeling AI content directly on the owners of social networks, video hosting platforms, and other internet resources.

The March version of the draft law proposed making labeling mandatory for authors of AI content. In the final text, both approaches were abandoned: labeling is voluntary, and large platforms (with more than 500,000 users per day) are only required to provide users with the technical capability to apply it.

  • INTELLECTUAL PROPERTY ISSUES

The Law regulates the issue of copyright when training LFMs. Developers of national and sovereign models are permitted to use copyrighted works for training without obtaining additional consent and without paying remuneration, provided that the following conditions are met:

  • the works have been made available to the public and are accessible for analysis without technical restrictions; or
  • a copy of the work was lawfully obtained by the developer.

It is worth noting separately that this regulation applies exclusively to developers of national and sovereign LFMs – in other words, the use of intellectual property results by foreign developers (for example, Open AI or Anthropic) would constitute a violation of exclusive rights.

The Law also introduces an obligation for LFM developers to inform users about the ownership rights to the results created using the model, as well as about the terms of access, use, and preservation of such results. It is important to note that this concerns information provision: if there is no technical possibility of preservation, the developer simply notifies the user about this.

  • CONCLUSIONS AND RECOMMENDATIONS

The Law creates a new reality for the Russian AI business: on the one hand, it opens up opportunities for state support and access to data; on the other hand, it introduces requirements for technological independence, security, and documentation.

  • Limited scope of the Law. The Law regulates only LFMs, for which objective requirements have been established (e.g., the need to contain more than 1 billion parameters). This excludes from its scope narrowly specialized AI models designed to perform a specific function, such as text recognition or music composition, recommendation systems, chatbots, and resume analysis systems. We therefore recommend checking whether the solutions used by your business fall under the Law’s requirements.
  • Training AI on copyrighted works. The Law permits the use of copyrighted works only for training national and sovereign LFMs – in this regard, training of other systems (both those that are not LFMs and those that do not meet the conditions for national or sovereign models) will constitute an infringement of exclusive rights. We recommend conducting an audit of the objects used to train AI systems in order to minimize intellectual property risks.
  • Unsettled issue of ownership of AI-generated content. The Law does not regulate the ownership of rights to content created with the help of AI, but it does provide for an obligation to inform users on these matters. We recommend addressing the ownership of rights to AI‑generated content in the user agreement, and to include wording that is clear and obvious to users.
  • Inventory of technical solutions and data used within the AI model. If a company is interested in obtaining the status of a developer of a sovereign or national LFM, we recommend conducting an audit of the technological components used, including assessing the share of foreign solutions, verifying the model’s compliance with the LFM criteria (universality, parameter volume, foundational nature), and determining which components will require import substitution to meet the «sovereign» (fully Russian) or «national» (with permissible foreign elements) category.
  • Preparing to meet safety and documentation requirements. The law obliges developers of sovereign and national LFMs to ensure the safety of models, establish operating rules, and maintain technical documentation. We recommend implementing internal cybersecurity standards now, developing documentation templates, and defining the procedure for updating and decommissioning models in order to be ready for the entry into force of by‑laws that specify these requirements. Participating in industry discussions on these issues will also be a proactive step.

The material was prepared by Anna Zabrotskaya, a Managing Partner at Nordic Star Law Offices and Head of the Dispute Resolution Practice, Daria Bitkina, an Associate in the Intellectual Property Practice, Elena Lebets, a Senior Associate in the Dispute Resolution Practice, and Ana Radoja, a Junior Associate in the Dispute Resolution Practice, with the participation of Olga Prokaeva, an Executive Secretary of the ICC Russia Intellectual Property Commission.

 
Anna Zabrotskaya
Managing Partner, Attorney-at-Law

+7 921 951 39 18
St. Petersburg