A discussion is heating up around the voice assistant "Alisa AI", triggered by plans from the Ministry of Digital Development of the Russian Federation. The agency is considering expanding the assistant's functionality on devices of Russian users, which has spawned a wave of rumors about potential access to sensitive data, including banking information. Yandex hastened to set the record straight, categorically denying such assumptions.

Official position: access strictly limited

The head of the security group for "Alisa AI" and Yandex's self-driving transport, Boris Ryutin, stated that the assistant's capabilities on mobile devices have always been strictly limited by the operating system's security mechanisms. According to him, "Alisa" does not receive and cannot receive unrestricted access to user data, including banking applications. All operations are based solely on the explicit permission of the device owner, which they grant in the settings.

Ryutin emphasized that "Alisa AI" has no advantages over foreign assistant models. It only has access to basic functions typical of any similar service. The company also noted that the user is always free to choose which assistant to use—domestic or foreign—and this right of choice is fundamental.

The essence of the Ministry of Digital Development's initiative

The discussion in the ministry concerns refining the rules for pre-installing domestic software on devices imported into Russia. The draft, which appeared on the regulatory acts portal in early August but was then withdrawn for revision, proposes expanding "Alisa's" rights. It involves granting the assistant the status of a "system assistant" with access to system functions, notifications, authorization, and other applications.

It is precisely this wording that has caused concern. After all, banking applications store not only account data and CVC codes, but also passport information, and allow transactions to be carried out. Experts fear that combining the status of a pre-installed application with expanded rights could create a unique position for "Alisa" on the market and lead to its monopolization by Yandex. The ministry itself explains the initiative as a need to create transparent rules for all AI assistants and eliminate the advantages of built-in solutions from device manufacturers.

My view: This situation is a vivid example of how regulatory initiatives, even with good intentions, can be perceived by the market as an attempt to create preferences for a single corporation. Issues of cybersecurity and data protection in the banking sector are critically important. The key here will be not so much the very fact of expanding rights, but the implementation of control mechanisms and user consent. If they are transparent and reliable, risks can be minimized, but the residue from an attempt to "push through" such a decision without broad discussion will remain.