ARTICLE / IT, TELECOMS AND DIGITAL
AI regulation: what to check inside your company
Companies adopt AI faster than they write it into their paperwork: the model is already taking decisions about customers while the contracts and policies say nothing about it.
- Published
- 5 October 2026
- Author
- Vladimir Kovalev
- Topic
- IT, telecoms and digital
- Reading
- 5 min
The regulation of artificial intelligence in Russia is assembled from several sources: the personal data law, the information law, sector-specific requirements of the Bank of Russia, and experimental legal regimes. There is no separate code, but the duties already exist, and the regulators come not to the developer of the model but to the company using it. Here is what is worth checking inside your own company before anyone asks.
Where the risk arises for a business
The risk does not arise where the model sits; it arises where the model's output affects a person.
Scoring applications, automatic refusal of a service, allocating orders between contractors, screening CVs, assessing employee performance, setting tariffs — wherever a decision is taken without human involvement and affects someone's rights, the law requires special handling.
The key provision is Article 16 of the personal data law: it is prohibited to take decisions producing legal consequences solely on the basis of automated processing without the data subject's consent. The consent must be separate and informed, and the individual must have the right to require the decision to be reviewed by a human being.
Five questions for an internal review
First. Where in the company is a model running, and who knows about it. In practice there is no register of systems, and models appear from the bottom up: the sales team has connected a service, marketing is using a text generator, HR is running CVs through a scoring tool. You have to start with an inventory: which systems, which supplier, which data leaves the company.
Second. What data goes into the model. If employees enter customers' personal data into a cloud service, that is a transfer of data to a processor. You need a contract with confidentiality terms, a statement in the policy, and a check on where the data is stored. Russian databases must remain on Russian territory — that is part 5 of Article 18 of the law.
Third. Is the decision taken automatically. If it is, then either a human is added into the loop, or a separate consent and an appeal procedure are put in place. The line "the decision was taken by the system", with no possibility of review, is a plain breach.
Fourth. What the documents say. The personal data processing policy, the consents, the terms of use and the customer contracts must describe reality. If the model analyses user behaviour, that has to be stated.
Fifth. Who answers for the outcome. A contract with an AI service provider usually excludes their liability for decisions taken on the basis of the model's output. That means the liability stays with you, and it has to be covered by procedures: checking the output, logging, and the ability to explain a decision.
Explainability as a legal problem
When a customer challenges a refusal, the court does not ask about the architecture of the neural network; it asks about the basis for the decision. "That is what the model calculated" does not work as an answer.
The practical way out is to record the factors that influenced the outcome and store them with the decision. This is not an express statutory requirement, but it is what turns a hopeless dispute into a workable one: the company shows which data was taken into account, that a human checked the result, and that the customer had a chance to object.
Copyright in what has been generated
The second frequent question is who owns the output of the model. Russian law recognises only a human being as an author, so a purely machine-produced result is not an object of copyright.
Practice follows the line of creative contribution: if a person set the parameters, selected and reworked the output, their contribution is protected. For a business this means that a logo or a text generated entirely by a model is hard to protect against copying. If the output matters, it needs to be developed further by a person, and that process needs to be recorded.
A separate point is other people's rights on the input side. If the model was trained on protected material, or an employee uploaded someone else's text into it, the risk of a claim falls on whoever published the result.
What to do about employees
This is the most underrated part. Leaks happen not through hacking but through ordinary correspondence: an employee pastes a contract with its commercial terms, or personal data, into a public chatbot in order to "draft a quick reply".
The minimum that closes off most of the risk: a written rule on what data may not be entered into third-party services, a list of approved tools, training, and a signature confirming the employee has read it. This is cheap and it removes the question of the company's fault if an incident does happen after all.
Where this is heading
Regulation is tightening in one direction: from general principles towards duties to label content, maintain registers of systems and assess risks before deployment. Companies whose models are already in live use will find it easier to prepare in advance — inventory, documents, procedures for reviewing decisions — than to rework everything to fit finished requirements and an inspector's questions.
This material is for information only and is not a substitute for advice on a specific matter.
If you are introducing AI into your processes and want to understand what needs to be covered by documents, write to us — the first consultation is free when an engagement is signed.
Vladimir Kovalev — lawyer, founder and managing partner of Kovalev & Partners LLC
NEXT STEP
Facing a similar situation?
Describe it in two or three sentences and we will tell you which scenario is realistic and where to start.