AI without data leaks: how to adopt neural networks and stay within Federal Law 152-FZ
Since 2025 the price of a mistake with personal data has gone up by an order of magnitude: a first leak costs millions, a repeat one costs a percentage of annual revenue. And the data does not leak through hackers — it leaks through ordinary employees who paste the customer base into public ChatGPT. The good news: keeping AI in a way that data never leaves the company is a solvable problem, and it is solved at the design stage.
Below: what exactly a business faces for a leak in 2026; why a public neural network breaks Federal Law 152-FZ, Russia's personal data protection law; what "AI inside the company perimeter" means; and how to adopt AI without exposing yourself to a fine.
What does a business face for leaking customer data in 2026?
Millions for a first leak and a share of turnover for a repeat one. Since May 30, 2025, Federal Law No. 420-FZ has been in force, rewriting Article 13.11 of the Code of Administrative Offences. A first leak of personal data now costs between 3 and 15 million rubles depending on the number of people affected, and a leak of biometric data up to 20 million. Failing to notify Roskomnadzor — Russia's communications and data protection regulator — of the incident within 24 hours is itself another 1 to 3 million.
The key novelty is the revenue-based fine for a repeat leak: from 1 to 3% of total annual revenue for the previous year, but no less than 20 million (up to 25 million for certain offences) and no more than 500 million rubles. The discount for paying quickly has been abolished for these offences — paying half is no longer possible. In parallel, since December 2024 Article 272.1 of the Criminal Code has been in force: transferring personal data abroad carries up to eight years in prison. According to the Interior Ministry, the article was applied 923 times between January and October 2025.
Anastasia Kuzmina, adviser at i-Legal, puts the risk bluntly: "A couple of wrong clicks by an employee, and the company risks losing several million, and sometimes tens or hundreds of millions." The figures are given as of the publication date; legislation changes, so check against the primary source — ConsultantPlus.
Who is legally responsible for personal data?
Almost any business — as soon as it has a customer base. Under Federal Law 152-FZ, a personal data operator is any legal entity or sole trader that processes such data and determines the purposes of processing. The practical test is simple: if you have a CRM, a contact form on your website, a chatbot, a mailing list or HR records, you store names, phone numbers and email addresses — which already makes you an operator with all the duties that come with it.
There are three duties, and all three surface when you adopt AI. The first is to notify Roskomnadzor of your intention to process data before processing begins. The second is localization: the collection and storage of data on Russian citizens must take place on servers in Russia (Article 18, part 5). The third is the data subject's consent, given through a separate action rather than buried in the text of an offer. By adopting a neural network you add one more channel through which that data is processed — and it too has to fit within the law.
What happens when data ends up in public ChatGPT?
It goes to foreign servers and leaves your control. When an employee pastes a customer base or a contract into a public neural network, a cross-border transfer of personal data outside Russia takes place. On consumer plans the data entered may be used to train the model — which means it could in theory surface in an answer given to another user. Deleting it from someone else's infrastructure and logs is practically impossible.
This has long since stopped being hypothetical. Back in 2023 Samsung engineers uploaded internal source code and meeting transcripts to ChatGPT — after several such cases the company banned generative AI on work devices outright. In Russia the scale is visible from a recent study by the Solar group of companies (February 2026): the volume of data employees send to public neural networks grew 30-fold over 2025, while around 60% of organizations have no AI usage policies at all and almost two thirds do not monitor such leaks in any way.
The key point is that data is most often leaked by ordinary employees out of ignorance, with no ill intent whatsoever. Andrey Zakharov, an expert at Jet Infosystems, puts it this way: "Any data users upload to public LLMs can be considered exposed to leakage" (LLM stands for large language model). As long as there is neither a ban nor a clear alternative, managers will keep "just rewriting the contract" in whatever chat they open first.
Why does this break Federal Law 152-FZ?
Because two requirements are breached at once — localization and the procedure for cross-border transfer. Localization was tightened on July 1, 2025, by Federal Law No. 23-FZ: when collecting data on Russian citizens, using databases located outside the country is explicitly prohibited. The primary copy of the data must be held in Russia. Uploading customer data to a foreign service contradicts that requirement by design.
Cross-border transfer is a separate procedure. Under Article 12 of Federal Law 152-FZ, before transferring data abroad an operator must file a separate notification with Roskomnadzor, and according to the regulator's guidance transfers to countries deemed to offer inadequate protection may be restricted. In practice, when an employee pastes data into a cloud neural network there is no notification at all — it is a transfer without legal grounds. One further subtlety: the customer's consent to processing must be given as a standalone action, and including it in the text of other documents is, in the view of legal experts, not permissible.
A breakdown of how to organize work with customer data inside a system properly is in the article on the first-line AI agent — there the perimeter holding personal data sits on servers in Russia under contract. The logic here is the same, just applied to any neural network in the company.
Keeping AI inside the company perimeter is part of designing the system, not an optional extra. At IncubeAi we write into the contract that hosting is in Russia, that access is segregated, and that sensitive data does not leave the client's perimeter. If you are planning to adopt AI and would rather not learn Federal Law 152-FZ through fines — tell us about your task, and we will design a secure perimeter around your process.
What does "AI inside the company perimeter" mean?
It is a neural network that runs on your infrastructure, with working data physically never going outside. The "perimeter" is your server or a private cloud in Russia that no outside foreign company can reach. The model processes requests inside that space instead of sending them to someone else's servers.
For an owner the practical meaning comes down to three things. Employees can upload work data to such an AI freely — they do not have to guess what is allowed and what is not. The security team sees the data flow and controls access. The risk of a leak and of breaching Federal Law 152-FZ drops sharply, because the data stays within your jurisdiction and under your control. That is what "data stays in Russia" actually stands for: a specific way of managing risk, not a marketing slogan.
Where should you host the neural network so the data does not go anywhere?
There are three realistic options — from full control to a fast start. The choice depends on how sensitive the data is, on your budget, and on how quickly you need results.
| Option | What it is | Who it suits |
|---|---|---|
| Your own hardware (on-prem) | an open model on the company's servers, data never leaves at all | maximum data sensitivity, budget available for GPUs and support |
| Russian on-prem / enterprise | GigaChat Enterprise, YandexGPT delivered into the perimeter | you need Russian-language AI with vendor support and data in Russia |
| Private Russian cloud | a model in an isolated segment of a Russian provider's cloud | a balance between launch speed and Russian jurisdiction |
Your own hardware means open models (DeepSeek, Qwen, Llama and others) on your servers. Mid-range models with 7–14 billion parameters take roughly 16–24 GB of video memory and, by practitioners' estimates, cover most office tasks, deploying on a single server within a day. The upside is that data never leaves the company at all; the downside is that you need graphics cards, in-house expertise and support.
Russian on-prem solutions take part of that burden off you. Sber's GigaChat Enterprise is also delivered in local and hybrid configurations, where data is stored on the company's servers and the model does not retain it after answering. YandexGPT in Yandex Cloud states compliance with Federal Law 152-FZ and storage of data within Russian jurisdiction. According to Yandex B2B Tech, only about a third of Russian companies run AI in the cloud — the rest deploy it on their own infrastructure.
Your own hardware or a Russian cloud — which to choose?
Your own hardware gives maximum control, a Russian cloud gives speed and price. Both fit within Federal Law 152-FZ as long as the data stays in Russia; the difference is who runs the infrastructure and what it costs.
| Factor | Your own hardware (on-prem) | Russian cloud |
|---|---|---|
| Control over data | maximum, data never leaves the company | high, data sits with a provider under Russian jurisdiction |
| Cost | expensive — graphics cards required | more affordable, pay as you go |
| Time to launch | longer and more complex | fast |
| Scalability | limited by your own hardware | effectively unlimited |
| Compliance with 152-FZ | yes, data is in Russia by definition | yes, if the provider is in Russia |
A practical rule: the more sensitive your data and the stricter the regulator in your industry, the stronger the case for your own hardware or a local deployment. For most tasks a Russian cloud or hybrid setup is enough — it is cheaper and launches faster. There is no universal answer; there is your data and risk profile, and the perimeter is designed around it.
How do you adopt AI safely: where to start?
With an audit of where data is already leaking, not with buying a model. The order of the steps matters more than the choice of a particular neural network — first you close the hole, then you build the alternative.
- Check the current flows: which employees are already uploading work data and to which services. "Shadow AI" on personal accounts is often an active leak channel already.
- Introduce an AI usage policy: what may be sent to external services and what may never be sent under any circumstances. Without rules, employees decide for themselves.
- Decide where sensitive data will live: your own server, Russian on-prem or a Russian cloud — based on the data profile from the sections above.
- Deploy AI inside the perimeter and give people a convenient, legal alternative to a public chat. A ban without a replacement does not work — employees will go back to the service they are used to.
- Train the team: a short briefing on why customer data must not be pasted into an external chat closes most of the cases caused by ignorance.
The first two steps require no development budget, but they remove the sharpest risk. After that comes designing the perimeter around your data, and here it matters that compliance with Federal Law 152-FZ is built into the architecture rather than bolted on after launch.
How do employees leak data out of ignorance?
In the same predictable ways — by pasting sensitive material into public services, because it is faster. These scenarios repeat in companies of every size, and almost never involve ill intent.
- Managers paste full contracts, payment details included, into a public chat "to rewrite or shorten them".
- Accountants upload spreadsheets with banking details to cloud models for analysis.
- HR sends résumés containing passport data to search-enabled neural networks.
- "Shadow AI": employees use personal neural network accounts for work tasks, and the security team never sees it.
All these cases share one root cause: there is neither a clear ban nor a convenient legal alternative. That is why the technical solution (AI inside the perimeter) and the organizational one (a policy plus training) only work together. The problem of "managers not filling in the system" and the problem of "employees pouring data outside" are cured the same way — by a properly designed process, as we discussed in the article on why a CRM fails to take root.
If you are planning to adopt AI and would rather not build it through trial and fines — tell us about your task. We will design a perimeter where neural networks work on your data and the data itself stays in Russia: under contract, with segregated access and support after handover. The team has 300+ automation and AI projects behind it.
Sources
- ConsultantPlus — Personal data: new fines from May 30, 2025 (Article 13.11 of the Code of Administrative Offences, Federal Law No. 420-FZ)
- Rossiyskaya Gazeta — official publication of Federal Law No. 23-FZ tightening data localization
- RAPSI — revenue-based fines for personal data leaks from May 30, 2025
- CNews — Solar group study: data sent to neural networks grew 30-fold over 2025
- CISOCLUB — Article 272.1 of the Criminal Code on illegal trafficking in personal data is applied ever more actively (Interior Ministry figures)
- Yandex Cloud — YandexGPT and compliance with Federal Law 152-FZ
- Inc. Russia — how businesses deploy AI on their own infrastructure (expert commentary)
Frequently asked questions
Can you use ChatGPT at work without breaking the law?+
For tasks that involve no personal data — text, ideas, learning — yes. The problem starts when an employee pastes customer data into a public neural network: names, phone numbers, contracts, payment details. That is a cross-border transfer of personal data to foreign servers, usually without notifying Roskomnadzor and without legal grounds, which means a breach of Federal Law 152-FZ. The safe route is to keep AI for such tasks inside the company perimeter.
What is the fine for a personal data leak in 2026?+
Since May 30, 2025, a first leak costs between 3 and 15 million rubles depending on its scale, and a leak of biometric data up to 20 million. For a repeat leak there is now a revenue-based fine: from 1 to 3% of annual revenue, no less than 20 million and no more than 500 million rubles. The discount for paying quickly has been abolished for these offences. The figures are given as of the publication date, the law changes — check against the primary source.
What does "AI inside the company perimeter" mean?+
It means the neural network runs on your own infrastructure — your server or a private cloud in Russia — and working data physically never leaves your perimeter. No outside foreign company has access to it. Employees can upload work information freely, and the risk of a leak and of breaching Federal Law 152-FZ drops sharply.
Do we have to buy an expensive server with graphics cards?+
No. Your own hardware is only one of three options. There are Russian on-prem and cloud solutions (GigaChat Enterprise, YandexGPT in Yandex Cloud) where the data stays within Russian jurisdiction and the vendor runs the infrastructure. The choice depends on how sensitive the data is, on your budget and on how fast you need to launch: your own hardware gives maximum control, a Russian cloud is faster and cheaper to start with.
We are a small company — are we a personal data operator at all?+
Almost certainly yes. Under Federal Law 152-FZ an operator is anyone who processes personal data and determines the purposes of that processing. If you have a CRM, a customer base, a contact form on your website, a chatbot or HR records, you already store names, phone numbers and email addresses — which puts you under the law and its requirements.