FSTEC's Proposed Data Protection Overhaul

Russia’s Federal Service for Technical and Export Control (FSTEC) published a draft order on July 24 that will replace the rigid 2013 rules for protecting personal data. The new framework, expected to take effect on September 1, 2026, extends to all information systems that handle personal data—a pool of more than 2.6 million registered operators.

The core change is a flexible three-tier scheme. Instead of a fixed checklist, operators can select a base set of measures for each tier and then adapt them to their own IT architecture and threat landscape. Companies must then verify that the chosen measures genuinely address the risks relevant to their systems. For the first time, the order explicitly lists protective measures for artificial intelligence, the Internet of Things (IoT), virtualization, cloud computing, mobile devices, and remote access.

A mandatory “maturity level” assessment will be required before data processing can begin, repeated at least every three years, and performed after any computer incident. Operators of critical information infrastructure are also required to maintain continuous interaction with the state cyber-threat monitoring system (GosSOPKA).

What the Adaptive Framework Means for Russian Businesses and AI Security

The New Focus on AI and IoT Protection

Regulating AI in the context of personal data is still an undeveloped field globally, notes Denis Poladyev, information security director at RTK‑TsOD. The new requirements will largely force companies to document and restrict how AI is used—for example, banning the upload of personal data to external models—while also hardening defenses against cyber attacks. Albina Askerova of Swordfish Security explains that AI models are increasingly trained on personal data, and prompts and responses become new attack surfaces, making a standalone measure in data protection rules logical.

Alexey Postrigailo, a senior partner at IT integrator Ensign, warns that many organizations have no formal description of their AI usage; it often lives as employee‑driven, undocumented initiatives. Tackling those risks with a single technical tool will be pointless, he says.

From Rigid Lists to Threat-Linked Adaptation

The three‑tier, risk‑based model could make security more rational in the long run, argues Nikolay Goncharov of Security Vision. However, the shift demands far more than ticking boxes: operators must justify every security measure by linking it to a specific threat. Companies with well‑maintained documentation will gain freedom, but those where the IT infrastructure exists only in an administrator’s memory will face serious difficulties, Postrigailo notes. The workload is unlikely to shrink, because the burden of explaining each control is new and substantial.

Maturity Checks: Genuine Audit or Paper Compliance?

The effectiveness of the mandatory maturity assessment hinges on implementation. If it becomes a documentation‑only exercise, firms will quickly learn to pass without making real system improvements, Goncharov cautions. Postrigailo adds that a large part of the market is poorly prepared for a substantive, technical evaluation. The difference between a checklist audit and an actual penetration test will determine whether the regulation raises security levels or merely generates extra paperwork.

Preparing for Compliance: Concrete Steps for Personal Data Operators

Organizations that handle personal data in Russia should begin preparing now for the September 2026 deadline. Concrete steps tied directly to the draft order include:

  • Map all AI and cloud personal‑data usage. Conduct a full inventory of systems where employees may be uploading personal data to external AI tools or cloud services, and enforce clear policies to block unauthorized transfers.
  • Document the link between threats and controls. The adaptive framework requires a justification for every chosen security measure. Start cataloguing threat scenarios per system and map existing controls to them, filling gaps where necessary.
  • Design maturity assessments to be technical, not just documentary. Plan for actual security testing—such as vulnerability scans or penetration tests—aligned with the “maturity level” indicator. This avoids the trap of superficial compliance while also satisfying regulatory checks.

Risk & Opportunity Assessment

Commercial RiskMediumThe adaptive framework and new AI/IoT mandates will require significant effort to map threats, implement controls, and conduct periodic maturity assessments, potentially raising compliance costs for all personal data operators.
Competitive RiskLowThe regulation applies uniformly across all registered operators, so it is unlikely to create direct competitive advantages or disadvantages; differentiation may come from speed of adaptation rather than from the rules themselves.
Regulatory RiskHighMandatory compliance from September 2026 means any operator failing to meet the new adaptive requirements or maturity assessments risks enforcement action from FSTEC, including possible fines or restrictions on data processing.
Reputation RiskMediumPublic disclosure of a low maturity score or a personal data breach under the new regime could damage trust in consumer‑facing businesses, especially if the incident reveals gaps in AI or IoT safeguards.
Technology DisruptionHighThe explicit inclusion of AI, IoT, virtualization, and cloud mandates forces rapid adaptation of security architectures. Organizations that are behind in managing these technologies will face operational and technical upheaval.
Commercial OpportunityMediumThe regulation will increase demand for cybersecurity consulting, AI protection tools, maturity assessment platforms, and managed security services as operators seek efficient paths to compliance.