Russia to Introduce Requirements for Personal Data Protection When Using AI
Russia's Federal Service for Technical and Export Control (FSTEC) updated in July 2026 its requirements for personal data security, including separate measures for AI, IoT, and virtualization. A mandatory maturity level assessment is introduced, and a flexible three-tier system replaces the rigid 2013 list.
Russia's FSTEC published a draft order on July 24, 2026, updating organizational and technical measures for personal data protection in information systems. The document is expected to take effect on September 1, 2026. New measures include separate protection for AI, IoT, virtualization, cloud computing, mobile devices, and remote access. A three-tier flexible system allows operators to adapt basic measures to their IT architecture, followed by a mandatory maturity level assessment before data processing and every three years, as well as after IT incidents. For critical information infrastructure, continuous interaction with the state system GosSOPKA is required. Experts note that AI protection standards remain immature globally, and the new requirements will likely focus on regulating AI use and preventing personal data leaks to external models.
- Сокращения
- FSTEC = Federal Service for Technical and Export Control — Федеральная служба по техническому и экспортному контролю
- IoT = Internet of Things — Интернет вещей
- IT = Information Technology — Информационные технологии
- GosSOPKA = State System for Detection, Prevention and Elimination of Computer Attack Consequences — Государственная система обнаружения, предупреждения и ликвидации последствий компьютерных атак
Source: CNews —
original
