AI Regulation Tracker / Regulation signed
Russia's first AI statute lands on September 1 and it is a localisation law, not a safety law
President Putin signed Federal Law No. 1271570-8 on July 29, 2026. Thirteen articles, framework in character, aimed at supporting development rather than restricting deployment. Its operative bite for foreign firms is the sovereign and national model classification, both of which require servers and data inside Russia.
Russia now has an artificial intelligence statute, and its shape is worth reading carefully because it inverts the assumption most Western compliance teams bring to national AI law. The EU AI Act is a risk-tiered restriction regime. Russia's Draft Law No. 1271570-8 is titled "On Supporting the Development of Artificial Intelligence Technology in the Russian Federation," and both its title and its structure point at industrial policy.
The legislative sequence was quick. The State Duma adopted the amended draft on July 8, 2026. The Federation Council approved it on July 17. President Putin signed it on July 29. It enters into force on September 1, 2026, with a second tranche of provisions following on March 1, 2027.
Thirteen articles, and a narrower text than the first draft
The enacted act consists of thirteen articles and is framework in character. Reporting on the passage notes that the version adopted by the Duma was narrower than the original draft and describes it primarily as an incentive to developers rather than a compliance burden.
That matters for anyone building a global AI regulation matrix. Compared with the EU AI Act, Korea's AI Framework Act, or Kazakhstan's AI law, Russian reporting and legal commentary describe this statute as closer to a sectoral development measure with a localisation condition attached.
The parameter threshold
The act defines, for the first time in Russian law, the concept of a large foundation model as reported in Russian and international coverage. Reports describe it as a computer program designed to perform intellectual tasks at a level comparable or superior to the results of human intellectual activity, and they agree that the statute applies only to foundation models containing at least one billion parameters and designed to perform a large number of tasks.
A quantitative parameter threshold is a design choice worth noting because it is becoming a pattern. The EU uses training compute as its GPAI systemic-risk trigger. Russia has chosen a parameter count. Both approaches share the same weakness, which is that the number is a proxy for capability that ages quickly, and both will require amendment as architectures change.
Given the verified one-billion-parameter threshold and focus on foundation models, reports agree that the statute is aimed at model developers rather than ordinary applied AI tools used inside businesses.
Sovereign and national models
The provision with the clearest potential cross-border consequence is the two-tier classification. The act introduces the concepts of "sovereign" and "national" large foundation AI models. A sovereign model must be developed entirely in Russia using exclusively Russian components. A national model may incorporate foreign components. Both types must keep their servers and data in Russia.
Commentary describes the distinction as relevant to state procurement, giving the state a vocabulary for preferring domestically built systems and making the degree of foreign componentry a visible attribute of a model.
The shared requirement is an operative one for any developer seeking to qualify under either classification. The server and data localisation requirement for both classes is reported as preventing qualifying models in those classes from being served into the Russian market from infrastructure abroad. For an international developer, that is an architectural decision rather than a policy one, and it interacts with the existing Russian personal data localisation regime rather than replacing it.
The values provision
Several accounts of the law emphasise a requirement that domestic AI align with traditional Russian spiritual and moral values. That framing appears in contemporaneous reporting and commentary on the legislative process, and it is described as sitting alongside the development-support provisions rather than functioning as a technical standard.
For a compliance reader the significant feature is not the content of the standard but its indeterminacy. If implemented as a statutory alignment obligation expressed in values language without a defined conformity assessment, such a provision would give regulators broad discretion. Firms assessing Russian market entry may wish to treat any such values-based alignment language as a potential area of discretionary enforcement rather than as a technical specification to engineer against.
What this means outside Russia
For the majority of TLY's audience the direct compliance impact is limited. Few US or EU professional services firms will deploy a qualifying foundation model into Russia. The relevance is indirect and runs in three directions.
First, the localisation requirement adds another jurisdiction to the growing list where model hosting is legally constrained, which matters for any firm maintaining a global map of where AI workloads may run. Second, the parameter-count threshold is a data point in an emerging international divergence over how to scope the largest models, and firms tracking EU GPAI obligations will want the comparison. Third, for sanctions and export control teams, a statutory preference architecture that formally distinguishes models by the nationality of their components is a new classification to monitor.
Russia joins Kazakhstan, whose AI law came into force on January 18, 2026, as another post-Soviet state with a dedicated AI statute. The two took different routes. Kazakhstan built a risk-based framework with prohibited practices and synthetic content labelling. Russia has built a development statute with a localisation condition.
Questions this raises
Is Russia's AI law comparable to the EU AI Act?
No. The EU AI Act is a risk-tiered restriction regime with prohibited practices and high-risk obligations. Russia's act is framework legislation oriented toward supporting development, running to thirteen articles, with its main operative requirements attaching to large foundation models rather than to AI use generally.
Which systems does it actually cover?
Large foundation models containing at least one billion parameters and designed to perform a large number of tasks. Applied AI tools deployed inside ordinary businesses generally fall outside that definition.
What is the difference between a sovereign and a national model?
A sovereign model must be developed entirely in Russia using exclusively Russian components. A national model may incorporate foreign components. Both must keep their servers and data inside Russia.
When does it take effect?
September 1, 2026, with some provisions taking effect March 1, 2027.
Sponsored Training
- AI governance training for executives and advisors, covering cross-border data and model hosting questions.
Browse the full AI Regulation Tracker →
Drafted with AI assistance and verified against the legislative record by a human editor. Informational only, not legal advice.