The question of how deeply artificial intelligence can integrate into everyday life has once again come into focus. Amid active discussions in the Ministry of Digital Development regarding expanding the functionality of domestic AI assistants, Yandex has issued an important clarification. Boris Ryutin, head of the security group for Alice and the company's self-driving transport, categorically denied information that the voice assistant could gain unrestricted access to users' personal data, including banking applications.
According to Ryutin, the assistant's capabilities on mobile devices are always strictly limited by the security architecture of the operating system. Alice can only interact with the data and functions for which the user has given explicit and informed consent. It has no "hidden" privileges or background access to sensitive information, whether account balances or payment data, and never will. The company representative also emphasized that the device owner always retains the right to choose their assistant—whether a domestic or foreign solution—and this is a fundamental principle.
The essence of the regulatory initiative
The cause for concern was an initiative discussed at the Ministry of Digital Development regarding refining the rules for pre-installing software on devices imported into Russia. The discussion concerns the potential expansion of Alice's rights on par with other system applications. In the draft document, which had already appeared on the regulatory acts portal but was withdrawn for revision, it was mentioned that the AI assistant could become a "service" with access to system functions, applications, and notifications. It was precisely this wording that sparked a wave of speculation that Alice would gain access to banking utilities and other programs handling confidential data.
The ministry explained that the goal of the changes is to ensure transparent rules for all market participants and eliminate the advantages of built-in solutions from device manufacturers. However, analysts see this primarily as an attempt to limit the influence of foreign AI models and voice assistants on the Russian market.
Risks and reality
The situation raises legitimate questions. On the one hand, the pre-installation of Alice has been the norm since 2021, and it is included in the list of mandatory software. On the other hand, the simultaneous pre-installation and potential expansion of rights could indeed place Yandex in a unique position among competitors. This is precisely why the company so persistently emphasizes that it receives no special privileges, and all authority is limited by user permissions and the framework of the operating system.
My view: Yandex's statements are a competent step in managing reputational risks, but they do not resolve the core issue. The very framing of the task of granting an AI assistant expanded system rights, even within "sovereign" models, creates a dangerous precedent. The question is not whether Alice has access today, but what legal and technical mechanisms guarantee that it will not gain access tomorrow. The market needs clear, not declarative, security guarantees.