AI models in Russia will undergo verification for "traditional values" to gain access to government procurement.
Russia's artificial intelligence market is on the brink of tectonic shifts. Developers claiming the status of a "sovereign" or "national" model will soon be required to confirm not only technical compliance with legislation, but also adherence to traditional spiritual and moral values. This procedure will be carried out through a network of independent testing laboratories, with key parameters discussed in late July at the platform of the ANO "Digital Economy."
With the framework law on AI taking effect on July 26, a new era of regulation has begun. However, the basic act is just the tip of the iceberg: detailed rules of the game are yet to be outlined in subordinate legislation, and that is where the main work is currently underway.
Testing Mechanics: From Benchmarks to Prompt Injections
The legislation introduces two special statuses for large foundational models—sovereign and national. To obtain one of them, a developer must prove that their creation does not violate the law and does not contradict traditional values. At the same time, no separate act listing these values is planned—instead, the list is already enshrined in Presidential Decree No. 809.
Instead of abstract declarations, businesses and regulators are preparing concrete benchmarks—sets of tests for evaluating models. The procedure will look like this: the developer submits an application to the laboratory, along with an architecture description and data on request filtering mechanisms. Experts then check the model's responses against the benchmarks and, crucially, test its resilience to prompt injections—attempts to "hack" the AI by hiding malicious instructions in input data.
The final conclusion is sent to the digitalization commission. A positive verdict grants access to state support, including preferences in government procurement. This is not about a total inspection of all models on the market—only those vying for high status. The first implementation areas are education and government services.
Who Will Be the Judge?
Expertise can be conducted not by one, but by several accredited laboratories that have passed verification by a state body. The scheme is being built in two stages: first, the developer independently tests the model using a general risk-oriented methodology, then an accredited laboratory evaluates these findings and may selectively check the model's resilience. The final decision rests with the Ministry of Digital Development, while security for state systems is overseen by the FSB and FSTEC.
However, the pitfalls are obvious. Alexey Borshchov, business architect of AI projects in the "Avandok" ecosystem, rightly notes that categories such as civic consciousness, justice, and historical memory are difficult to translate into technical specifications. The only possible consensus is procedural: a unified report format, a set of provocative queries, and reproducibility of results.
Dmitry Galantsev, managing partner of the law firm "Propositum," sees the key risk in the "evaluative nature" of the criteria, which could lead to selective application. He proposes a working scheme with an accrediting body, several competing laboratories, and an appeals board. The introduction of certificate validity periods and a public registry of conclusions is also being discussed.
My view: this is a historic precedent where ethical and ideological categories are being formalized into algorithmic tests. The market faces a difficult adaptation period, but in the long term, this could become a unique experiment in embedding value orientations into the technology stack. The question is how objective the benchmarks will be and whether the procedure will turn into a tool for selecting loyal players.