AI for business in 2026: what it can take on and what you must never hand it
AI for business means language and recognition models built into a company's working process. They answer routine requests from your knowledge base, pull fields out of a delivery note, draft a commercial proposal, find the right clause in an archive of contracts. The value comes from the perimeter around the model: the data source, access rights, handover to a human, and verification of the result. A browser chat subscription has nothing to do with that perimeter — nothing changes inside your systems, while the legal status of the data that went in there does change.
Below: which tasks AI closes in Russian companies in 2026 and what makes a task the right one to start with. Where the model breaks predictably: invented answers, the ceiling on recognition accuracy, the missing handover to a human. Which data must not go to an external service, and what Federal Law 152-FZ — Russia's personal data protection law — requires once a client ends up in the request. And how AI in a browser differs from AI inside your own perimeter, in cost, in liability and in law.
Which business tasks does AI close in 2026?
In short: work with text and documents where there is a lot of repetition and the correct answer is already written down somewhere.
Lists titled "30 AI tools for business" are built around the tool: the name, the interface, the pricing plan. An owner benefits from the opposite order — starting from the task. Demand is already broad: according to a study by SberAnalytics and Sber Business Soft (a November 2025 survey of 559 respondents), 39% of organizations use AI agents and assistants for various tasks (summary on ComNews, January 22, 2026). The same survey names document flow and request handling most often, followed by accounting and financial records, HR processes and customer support.
| Task | What the model does | What stays with a human |
|---|---|---|
| First-line support | answers from the knowledge base, passes non-standard cases to an operator | complex cases, updating the base |
| Processing incoming accounting documents | extracts fields, matches them against the 1C reference data | reconciling disputed items, posting |
| Drafts of proposals, emails, descriptions | assembles text from a template and deal data | figures, terms, signature |
| Search across internal documents | finds a fragment of a policy or contract and explains it | the decision on the merits |
| Transcribing meetings and calls | text, summary, list of tasks | checking wording, assigning owners |
| Lead qualification | a checklist interview, a record in the CRM | the sale |
Three things are common to every row: the flow of repetitions is visible, the answer exists in writing, and the mistake is caught before it reaches the client. A process with no written policy is first described in words and only then automated. The model will not reconstruct logic that exists nowhere on paper — it will invent it.
How do you tell whether a task suits AI?
In short: the task has a written standard for the correct answer, a visible flow of repetitions, and a person who checks the result before it goes outside.
The check takes half an hour and is done before you talk to a contractor. Four questions, in order:
- Where is the correct answer written down? A policy, a price list, contract terms, a reference book in 1C, the accounting and ERP platform most Russian businesses are built on, an archive of correspondence. If there is no written source, the process is described in words first, and that is separate work no AI will do for you.
- How many times a month does this repeat? Two figures count: the number of operations and the minutes per operation. Twenty documents a month will not pay back either the integration or the support, however irritating manual entry may be.
- Who will see the mistake, and when? A mistake in an email draft surfaces before it is sent. In a posting or in an answer to a client it surfaces months later and costs money, so that kind of task needs output control from day one.
- How is the result measured? The share of requests closed without a human. Minutes per document. The number of manual operations per month. A task with nothing to measure cannot be formally accepted.
The fifth question is asked least often, and it decides the fate of the project six months in: who maintains the knowledge base after launch. Prices change, policies grow, new exceptions appear. Without a living owner the system quietly answers on last year's terms, and you find out from a client complaint.
After that, one line is written for each task about its boundaries: what the model does on its own, what it shows a human for confirmation, and where it must stop and call an operator. That line takes a minute and removes the most expensive class of incidents — where the system confidently sees through something it should never have started.
Where does AI break consistently?
In short: at the edge of its own data, on poor input material, and wherever nobody described the handover to a human.
The demo always goes smoothly: it is shown on clean data and standard questions. The problems live in three places, and they are the same from company to company.
Invented answers. By its nature the model continues text, so a question outside the knowledge base produces a fluent and wrong result. The price is known from Moffatt v. Air Canada: a bot on the airline's site told a passenger that a discounted fare could be claimed retroactively, although company policy forbade it. The tribunal found negligent misrepresentation and awarded compensation (analysis by McCarthy Tétrault). Separating the bot from the brand did not work legally: "the AI said it" reads as "the company said it".
The recognition ceiling. Vendors quote accuracy "up to 98%", and it is counted per character. Practitioners who have built such systems put the realistic bar at around 85% of fields recognized correctly (analysis on Habr), and 100% without a human is unreachable: quality is destroyed by photos taken on a phone, stamps, handwriting and forwarding through messengers. A detailed look at this ceiling is in the article on document recognition for accounting in 1C.
No handover to a human. Without a described refusal scenario, the model sees through conversations it was obliged to pass to an operator. The share of requests closed without human involvement is noticeably lower than the promised 80–90%, even for teams with their own in-house work on language models. Percentages like that at the start of a project deserve scepticism — more on this in the analysis of a chatbot for a website.
The one check that gets skipped most often is a run on dirty data. Take a month's export of real requests and documents, with typos, half-finished phrases and call transcripts, and watch what the system does with that flow.
Which data must not go to an external model?
In short: personal data of clients and employees, trade secrets, access keys, and anything protected by a sector-specific regime.
Data leaves the company routinely and with no ill intent. A manager pastes in a contract with full company details "to shorten it". An accountant uploads a spreadsheet with bank details for analysis. HR sends over a CV with passport data. The scale has been measured: according to a study by the Solar group of companies (February 2026), the volume of data employees send to public AI services grew 30-fold over 2025 (CNews, February 4, 2026).
Four classes of information have no business appearing in a request to an external service: third parties' personal data (names, phone numbers, addresses, passport data of clients, employees and candidates); trade secrets (cost prices, purchase prices, contract terms, the client base); access keys and connection strings that travel along with a settings file "for context"; and information under a sector-specific regime such as banking or medical confidentiality.
The service's own terms are read on equal footing with the law. In the GigaChat user agreement for individuals this is clause 8.7:
As part of the functioning of the Service and the provision of the Services, the Client undertakes not to provide or upload to the Service any personal data of third parties, nor their own biometric personal data and/or personal data of a special category — GigaChat user agreement.
A client is a third party in relation to you, so their name and phone number in a request to a public service are inadmissible even with technically flawless code. For a company, processing terms are fixed in a separate contract with the service operator, and it needs to be read before you connect.
Banning the tool outright works badly: the team works around it quietly, and the manager is the last to find out. What works is drawing the line — what goes out, what stays in, what must not exist even in test environments. The full framework, with a policy, team training and hosting options, is covered in the article on AI without data leaks and 152-FZ.
What does 152-FZ require once a client ends up in the request?
In short: the initial recording of Russian citizens' data inside Russia, and notifying the regulator before any cross-border transfer begins.
The moment a client's name or phone number appears in a request, the company acts as a personal data operator with all the duties that entails. Part 5 of article 18 requires recording, systematizing and storing the data of Russian citizens in databases located in Russia; transfer abroad is possible after that and in the manner established by law.
"Before commencing activity involving the cross-border transfer of personal data, the operator is obliged to notify the authorized body for the protection of the rights of personal data subjects of its intention to carry out cross-border transfer of personal data" — part 3 of article 12 of Federal Law 152-FZ.
The procedure is notification-based, but it is not a formality: the same article gives the regulator the right to restrict or prohibit the transfer, and sets stricter conditions for countries that do not provide adequate protection of subjects' rights. The law offers no way to notify after the fact. Fines for a leak and what to do in an incident are covered separately, in the article on AI without data leaks.
There is also a practical layer that has nothing to do with the law. With some foreign vendors a Russian company simply has no contractual relationship: Anthropic does not include Russia in its list of supported countries, and GitHub names it among the destinations where Copilot is not supplied. No invoice, no closing documents, no confidence that access will still be there tomorrow.
How does AI in a browser differ from AI inside your perimeter?
In short: in how much data it reaches, in who sets the rules, and in who will be held responsible for the consequences.
The difference looks technical, yet it changes both the budget and the legal status of what is happening.
| Criterion for the owner | Chat in a browser | Model inside the perimeter |
|---|---|---|
| Whose rules apply | the service's user agreement, accepted by an employee | your contract and your policy |
| What the model sees | everything a person pasted into the box | only the fields you decided to hand over |
| Visibility for the company | none, the accounts are personal | a log of requests and actions |
| Personal data | forbidden by the service's terms, with no enforcement | the processing regime is described in advance |
| Access to your systems | none, everything is moved by hand | read and write according to rights |
| Cost structure | a subscription per person | integrations, data, support |
| Who answers for a mistake | the company; the service's liability is capped at the subscription | the company, but with a log and defined limits of autonomy |
The visibility row is the key one. "Shadow AI" on personal accounts leaves no traces: you do not know what went out, or when, or which client it concerned. A perimeter reverses the situation: the decision on whether specific data may be shown is made by your system.
There are three hosting options within Russian jurisdiction today, and the choice is made before design starts:
- A Russian cloud provider. Yandex Cloud states that the platform holds a certificate of compliance with personal data security requirements, and immediately adds that part of the law's requirements are met on the client's side (the 152-FZ compliance page). A cloud certificate does not by itself make your system lawful: the provider covers the infrastructure, while consent, notification, policy and retention periods are on you.
- An enterprise offering from a Russian vendor. Sber offers an enterprise version of GigaChat, including deployment on the organization's own servers. What exactly is included and on what processing terms is clarified with the vendor for your particular data profile.
- An open-weights model on your own servers. The data never leaves the company's perimeter at all. More expensive in infrastructure, and it removes almost every localization question.
De-identification before sending remains a fourth and cheapest route for some tasks: what reaches the model is the substance of the question without names, phone numbers or contract numbers. Two things then have to be checked — that the replacement is complete, and that the question still makes sense afterwards.
How much does AI cost inside a company?
In short: calls to the model cost pennies; the money goes into data, integrations and support.
The official GigaChat price list for legal entities has been in force since February 1, 2026; prices include VAT, per 1,000 tokens:
| GigaChat model | Synchronous mode | Asynchronous mode |
|---|---|---|
| Lite | 0.065 rubles | 0.0325 rubles |
| Pro | 0.5 rubles | 0.25 rubles |
| Max | 0.65 rubles | 0.325 rubles |
The minimum service cost is 600 rubles per month. Against one employee's salary that is a rounding error, and a budget calculated from tokens is always too low.
The real money goes elsewhere. The Banki.ru team, in their write-up of their own RAG bot, call knowledge base preparation the most underestimated stage: a page looks perfectly logical to a human and then, after automatic parsing, turns into scraps of phrases and structural junk. Bringing the documents into machine-readable form took more effort there than building the bot itself.
Three cost items are absent from any subscription and almost always from the first estimate: preparing documents and data, integrating with the systems where that data lives, and support — re-indexing the base, analysing bad answers, updating policies. The full stage-by-stage breakdown is in the article on the stages and cost of adopting AI, and the integration layer is covered in the piece on how to connect 1C, CRM, your bank and Telegram into a single perimeter.
Why do AI projects fail to produce an effect?
In short: because they were launched without measuring the "before" state, without an owner and without access to the real working systems.
The figures for the Russian market this year are sobering. The consultancy Intellectual Analytics surveyed around 50 of the largest companies in IT, industry, financial services, public administration, transport and logistics; the survey ran from December 2025 to February 2026. Only 7–10% of the 2025 pilots reached full adoption, while 30–40% were shut down for lack of the expected financial effect (CNews, March 24, 2026).
The effect may well have been there — there was simply nothing to show the finance director. Measuring the "before" state is skipped more often than any other step: how many operations a month, how many minutes per operation, how much an employee's hour costs. Without those three numbers there is no baseline for calculating savings later, and the conversation with the owner comes down to how the team feels.
The second reason is choosing the tool before choosing the task. The right order of questions to ask of a system is this: what does it read, what does it write into, what does it do without a human, and what must it hand to an operator. The brand of the model comes last on that list, because it can be swapped in an evening, whereas integrations and access rights take months to build. The differences between a scripted scenario, an assistant and an agent are covered in the article AI agents for business: what they are.
The market is growing, meanwhile: according to Naumen's study “The evolution of conversational AI” (October 14, 2025), the Russian conversational AI market reached 8 billion rubles in 2024 and approached 11 billion in 2025, growing by around 30%. For 2026 the same study forecasts a slowdown to 20–25% and a rising share of mature solutions at the expense of experiments. A forecast should be read as a forecast, but it points the same way: experiments with no effect are gradually being washed out.
Where do you start if you need AI?
In short: with a single task, counted in hours, and with a decision about where the data is processed.
An order of steps you will not have to redo:
- Pick one task. Many repetitions a month, a written standard for the answer, a tolerable cost of error, a measurable result. Weakness in any of the four moves the task to the back of the queue.
- Measure the "before" state. How many operations, how many minutes each, how much a person's hour costs. This is your future basis for comparison and half of your future acceptance certificate.
- Settle the data question before choosing a tool. What goes out to an external model, what never goes out, where personal data is physically processed, how long conversations are stored. This decision rules out whole options, which is why it is made first.
- Describe the boundaries. What the system does on its own, what only with an operator's confirmation, what it must hand to a human immediately. Plus the log: what it read and what it changed.
- Write rules for the team. One page: what must not be pasted into a request, which test data is acceptable, who signs off on the result. Without it employees decide for themselves, and they decide in favour of convenience.
- Budget for review and support. An hour of generation without an hour of review just pushes the cost into the next quarter.
The first three steps need no development budget, yet they remove the sharpest risk and make the conversation with a contractor concrete. Projects most often fall apart in the reverse order: first the tool is bought, then a process is sought to fit it.
The line between an experiment and a system is where AI starts working with your clients' data and speaking to them on your behalf. INCUBE AI works under a contract, keeps data in Russia and builds a solution around your own rules — with integrations, access control and support after handover. A chat subscription covers one-off tasks but does not embed into a process: every company has its own policies, reference data and access rights, and they are what the answer rests on when you ask what the model may do on its own. We covered the fork between an off-the-shelf product and a system built around your process separately — your own system or a boxed product. If you are measuring this against your own task, book a consultation: we will look at the process and say plainly where an ordinary subscription is enough and where you need a perimeter.
Sources
- ComNews, January 22, 2026: study by SberAnalytics and Sber Business Soft — a November 2025 survey, 559 respondents, 39% of organizations use AI agents and assistants
- CNews, February 4, 2026: study by the Solar group — a 30-fold growth over 2025 in the volume of data employees send to public AI services
- CNews, March 24, 2026: survey by Intellectual Analytics — around 50 of the largest companies, 7–10% of pilots reached adoption, 30–40% were shut down for lack of financial effect
- GigaChat user agreement for individuals, clause 8.7 — the ban on uploading third parties' personal data
- Sber, official GigaChat API tariffs for legal entities — prices per 1,000 tokens, in force since February 1, 2026
- Yandex Cloud, 152-FZ compliance page — the platform's certificate and the split of responsibility with the client
- Part 3 of article 12 of Federal Law 152-FZ "On personal data" — notifying the regulator before cross-border transfer begins
- The Banki.ru team on adopting a RAG bot, Habr — knowledge base preparation as the most underestimated stage of a project
- Habr: document recognition systems, what to know before you start — a practical analysis, a realistic bar of around 85% of fields recognized correctly
- McCarthy Tétrault on Moffatt v. Air Canada — a company's liability for its chatbot's answer
- Naumen, "The evolution of conversational AI" study, October 14, 2025 — 8 billion rubles in 2024, around 11 billion in 2025, a forecast slowdown for 2026
- Anthropic's list of supported countries and GitHub and trade controls — the absence of contractual relationships with Russian customers
Frequently asked questions
Which business tasks do AI models genuinely handle in 2026?+
The ones with many repetitive cases, where the correct answer already exists in writing and the result can be checked before it goes outside. That means first-line support answered from your knowledge base, processing incoming accounting documents, drafts of proposals and emails, search across internal documents, meeting transcription, and qualifying leads before they reach the CRM. According to a study by SberAnalytics and Sber Business Soft (a November 2025 survey of 559 respondents), 39% of organizations already use AI agents and assistants. The areas named most often in that survey are document flow and request handling, accounting and financial records, HR processes and customer support. Tasks where a mistake costs money or carries legal consequences are handed over last, and always with a human check.
Which data must never be sent to an external AI service?+
Personal data of clients and employees, information covered by trade secret rules, access keys and database connection strings, and data under sector-specific regimes such as banking or medical confidentiality. For personal data this is no longer a matter of caution: sending it to an external model counts as processing it, and with a foreign service you also get cross-border transfer, which obliges you to notify the regulator under part 3 of article 12 of Federal Law 152-FZ, Russia's personal data protection law. The service's own terms are read just as carefully: clause 8.7 of the GigaChat user agreement for individuals explicitly forbids uploading third parties' personal data. For a company, processing terms are fixed in a separate contract with the service operator, and that text is read before you connect anything.
How does AI in a browser differ from AI inside your own perimeter?+
In how much data it reaches and in the legal status of what happens. In a browser an employee acts under their own account and the service's user agreement, and the company has no visibility into what went out. Inside your perimeter, requests run through your own system, where it has been decided in advance which fields reach the model and which never leave. The cost structure changes too: a subscription is a fixed sum per person, while a perimeter requires integrations, access control and ongoing support — but it settles the questions of data localization and logging. The practical rule is simple: drafts and texts with no one else's data can live in a browser; anything touching clients, money and obligations belongs inside the perimeter.
How much does it cost to use AI in a company's work?+
Calls to the model are the cheapest line in the budget. The official GigaChat price list for legal entities has been in force since February 1, 2026: 1,000 tokens cost 0.065 rubles for Lite, 0.5 rubles for Pro and 0.65 rubles for Max in synchronous mode; asynchronous mode is half the price, and the minimum service cost is 600 rubles per month including VAT. The real money goes into data preparation, integration with your record-keeping systems and ongoing support: the knowledge base has to be turned into a machine-readable form and then re-indexed every time a price list or a policy changes. A budget calculated from token prices is always too low, because it contains neither that preparation nor the human review of the output.
Why does AI invent answers, and how is that fixed?+
The model continues text, and when the data is missing the continuation comes out fluent and wrong. The fix is architectural, not a matter of persuading it in the prompt: the answer is assembled only from your documents, the system says it does not know and hands the conversation to a human when no suitable fragment exists, and prices and terms are pulled from your record-keeping system. The price of ignoring this requirement is known from Moffatt v. Air Canada: a chatbot promised a passenger a discount that was not in the company's policy, and the tribunal ordered the airline to pay compensation. It pays to measure the share of "I don't know" answers from day one — it shows where the knowledge base has holes.
Can you use a foreign AI service over a VPN for work tasks?+
Technically it works; legally and organizationally it creates two problems. The first is cross-border transfer if personal data ends up in the request: the law requires notifying the authorized body before such transfer begins, and it offers no way to do that retroactively. The second is the absence of a contractual relationship: Anthropic does not list Russia among its supported countries, and GitHub names it among the destinations where Copilot is not supplied. That means no invoice, no closing documents, and no guarantee of access tomorrow. For a draft with no one else's data this is tolerable; for a process that clients and money depend on, it will not do.