Published
Jul, 21 2026
Iryna Berenstein
Researched by

AI-Powered Cybercrime: Liability in Russia and the EU in 2026

Russia plans to introduce criminal liability of up to 15 years’ imprisonment for cybercrimes committed using AI. However, there will be no unified federal law on artificial intelligence until 2026. The specific bill No. 885494-8, which proposed treating the use of AI as an aggravating circumstance, was returned for revision in April 2024 due to constitutional inconsistencies. In the EU, the AI Act has been in force since 2024, with fines of up to €35 million or 7% of a company’s worldwide annual turnover for operating systems that pose an unacceptable risk.

What Are AI-Powered Cybercrimes and What Types Exist?

AI-powered cybercrimes are unlawful acts committed in the digital environment in which artificial intelligence is used to enhance, automate or conceal criminal activity.

The main categories of such crimes include:

Deepfakes and synthetic media — creating fake videos, audio recordings or images for fraud, blackmail, the discrediting of public figures or the spread of disinformation.

Automated phishing — generating personalised fake emails, messages and websites using language models to steal data.

Security system hacking — using AI to guess passwords, identify software vulnerabilities and bypass biometric protection.

Market manipulation and automated fraud — using algorithms to carry out stock market manipulation, artificially inflate ratings and falsify reviews.

Distribution of harmful content — automatically creating extremist materials, child pornography and propaganda promoting violence.

The key difference between AI-powered crimes and traditional crimes is their scalability and the difficulty of detecting them. A single offender with access to a language model can generate thousands of unique phishing emails per hour. A deepfake video can be created in minutes with minimal technical skills.

In a legal context, artificial intelligence is a system capable of processing data, learning from patterns and making decisions without direct human involvement at every stage. According to the Russian draft law “On the Foundations of State Regulation…”, AI is defined through a combination of machine-learning algorithms and neural networks. The new framework law will enter into force on September 1, 2027, but the draft was published for public discussion in 2024–2025.

What Criminal Liability Is Provided in Russia for Using AI for Criminal Purposes?

The Criminal Code of the Russian Federation does not yet clearly identify crimes involving artificial intelligence as a separate category. The technology is too new for the current legislation.

Current situation:

Bill No. 885494-8 proposed introducing the use of AI as an aggravating circumstance, increasing the maximum sentence to 15 years.

In April 2024, the bill was returned for revision because of constitutional inconsistencies. The future of the bill has not been determined.

Until a new provision is adopted, courts classify AI-powered cybercrimes under the general articles of the Russian Criminal Code: fraud under Article 159, defamation under Article 128.1, unlawful circulation of payment instruments under Article 187 and unlawful access to computer information under Article 272.

Problems of proof:

The detection rate for cybercrimes involving AI remains low. Investigators find it difficult to establish whether content was generated by an algorithm or created manually by a person. There are no standardised forensic methods for examining synthetic data.

The Ministry of Digital Development, the Ministry of Internal Affairs and Roskomnadzor are developing an algorithm for identifying the use of AI in cybercrimes. Work on the methodology is scheduled to be completed in the first quarter of 2028.

Who is liable:

In Russia, only a natural person can be recognised as the author of a work under Article 1257 of the Civil Code of the Russian Federation. A neural network is not a legal person and cannot be held liable.

The developer, operator and owner of an AI service are liable for an unlawful result if they knowingly knew or should have known that such a result was possible. The burden of proving a lack of knowledge lies with the defence unless the investigation proves otherwise.

What Laws Regulate the Use of Artificial Intelligence in Russia in 2024–2027?

Until 2026, Russia has no unified federal law on artificial intelligence. Regulation is carried out through industry standards, experimental legal regimes and subordinate legislation.

Timeline for the adoption of legislation:

Document Status Entry into force
Bill No. 757734-8 “On the Regulation of AI Systems” Under development by the Ministry of Digital Development Final version expected by the end of February 2026
Law “On the Foundations of State Regulation…” Draft under discussion in 2024–2025 September 1, 2027
Amendment No. 885494-8 regarding an aggravating circumstance Returned for revision Not determined
New measures to control deepfakes and disinformation In force since 2024 Since 2024

 

Labelling of synthetic content:

Mandatory labelling of synthetic video and deepfakes is planned to be introduced by the end of February 2026. Until that date, there is no universal requirement to label all AI-generated content — texts, images and advertisements remain outside mandatory labelling rules.

Companies that knowingly distribute unlabelled, high-risk synthetic content, including disinformation, pornography and insults, may face fines of up to RUB 4 million and the blocking of their accounts. Repeated violations may result in criminal liability.

Experimental legal regimes:

Special regimes operate in certain sectors, including healthcare, transport and finance, allowing the use of AI systems subject to additional safety and transparency requirements.

The AI Act, the world’s first comprehensive law regulating artificial intelligence, has been fully in force in the EU since 2024. The full implementation phase will begin on August 2, 2026, 24 months after its entry into force.

Risk classification system:

Unacceptable risk — social scoring systems for citizens, behavioural manipulation and real-time biometric identification in public places. Their use is completely prohibited.

High risk — systems used for recruitment, credit scoring and law enforcement. Mandatory certification, data-quality control and algorithmic transparency are required.

Limited risk — chatbots and content generators. Users must be informed that they are interacting with AI.

Minimal risk — video games and spam filters. Self-regulation applies.

Amounts of fines:

€35 million or 7% of worldwide annual turnover, whichever is higher — for operating systems that pose an unacceptable risk, failing to comply with prohibitions or using manipulative practices.

€15 million or 3% of turnover — for violating requirements for high-risk systems, insufficient transparency or failing to conduct a risk assessment.

€7.5 million or 1% of turnover — for providing false information to regulators or incompletely disclosing documentation.

Fines are calculated based on the severity of the violation, whether the conduct was intentional, the amount of damage caused and the level of cooperation with supervisory authorities.

Examples of prohibited systems:

Algorithms that assess the trustworthiness of citizens based on their social behaviour.

Emotion-recognition technologies used in workplaces or educational institutions, except for medical purposes.

Predictive policing systems that forecast crime based on ethnic or social characteristics.

Who Is Liable for the Actions of AI: the Developer, Operator or User?

The question of who should be held liable remains one of the most difficult issues in the legal regulation of AI-powered cybercrime.

Russian liability model:

A neural network is not a legal person. Only a natural person is recognised as the author of a work under Article 1257 of the Civil Code of the Russian Federation. This means that AI cannot own copyright or bear property or criminal liability.

Liability is divided between:

The developer of the AI system — if the algorithm contains functions that enable unlawful actions.

The operator or owner of the service — if the system is made publicly available without proper controls over its use.

The end user — if the person intentionally uses AI to commit a crime.

The developer and operator are liable if they knowingly knew or should have known that an unlawful result could be produced. In practice, this means that if a company has not introduced filters to prevent the generation of illegal content, it may be held liable together with the user.

European liability model:

The AI Act introduces the principle of a chain of responsibility. Each participant in the life cycle of an AI system, from the developer to the distributor, must comply with specific requirements at their respective stage.

Providers of high-risk systems must:

Conduct a conformity assessment before placing the system on the market.

Introduce risk-management systems.

Ensure the quality and representativeness of training data.

Maintain technical documentation for 10 years.

Appoint a person responsible for monitoring the system after its deployment.

The use of AI does not exempt a business from liability. If content created by a neural network infringes the rights of third parties, including copyright, honour and dignity or commercial secrets, claims are directed against the operating company.

How Can Companies Protect Themselves Against AI-Powered Cybercrime?

Technical measures:

Two-factor authentication and biometrics — protection against automated attacks on employee accounts.

Anomaly detection systems — machine learning used to identify unusual behaviour within a company’s network.

Sandboxing — an isolated environment for testing suspicious files and links.

Verification of media sources — introducing tools to verify the authenticity of video and audio received from partners and customers.

Organisational measures:

Training employees to recognise AI-powered phishing. Modern phishing emails are generated without grammatical errors and are personalised for their recipients.

A policy governing the use of public AI services. Employees should be prohibited from uploading confidential company information to ChatGPT, Midjourney and similar platforms.

Auditing providers of AI solutions. This includes checking conformity certificates, algorithmic transparency and privacy policies.

Legal measures:

Including provisions in contracts with contractors and partners establishing liability for the use of unlabelled AI-generated content.

Obtaining cyber-risk insurance covering losses caused by deepfakes and automated attacks.

Documenting internal control processes for the use of AI — in the event of litigation, this can serve as evidence that the company acted in good faith.

Incident response:

If a deepfake involving the company’s management or a phishing campaign using the company’s brand is detected:

Preserve the evidence, including screenshots, metadata and copies of messages.

Notify customers and partners through official communication channels.

File a report with law enforcement authorities, including Department K of the Russian Ministry of Internal Affairs.

Consult lawyers to assess the possibility of bringing civil claims against platforms hosting the content.

What International Standards and Initiatives Exist in the Field of AI Security?

OECD AI Principles (2019):

The Organisation for Economic Co-operation and Development issued the first international principles for the responsible use of AI. The recommendations cover transparency, accountability, security and respect for human rights.

UNESCO Recommendation on the Ethics of Artificial Intelligence (2021):

The 193 Member States adopted recommendations on AI ethics covering data protection, the prevention of discrimination and environmental sustainability.

Council of Europe Framework Convention on Artificial Intelligence (2024):

The first international convention establishing binding standards for the protection of human rights when AI is used. Russia has not signed the document.

NIST AI Risk Management Framework, United States:

The National Institute of Standards and Technology developed an AI risk-management methodology for organisations. Its application is voluntary, but many companies have adopted it as a de facto standard.

ISO/IEC 42001:2023:

An international standard for AI management systems. It defines requirements for the development, deployment and monitoring of AI systems. Certification under the standard increases the confidence of customers and regulators.

Singapore’s AI Verify framework:

A tool for testing AI systems for compliance with ethical standards. It assesses transparency, fairness and resistance to attacks. It is used in the financial and healthcare sectors.

Russia participates in the Global Partnership on Artificial Intelligence international research group, but the practical implementation of its recommendations is limited by the absence of framework legislation until 2027.

Cross-border nature of crimes:

A server containing a deepfake generator may be located in one jurisdiction, the developer in a second and the victim in a third. The absence of unified international rules makes investigations and the imposition of liability more difficult.

Anonymity and decentralisation:

Many AI tools are distributed through open repositories such as GitHub and Hugging Face without control by their creators. Once a model has been published, its developer loses the ability to restrict its use.

Speed of technological development:

Legislation takes years to adopt. During the discussion of a bill, new AI models emerge that circumvent the proposed prohibitions. For example, the labelling of synthetic video does not resolve the problem of audio deepfakes.

Lack of expertise:

Judges, investigators and lawyers rarely possess the technical knowledge required to assess the operation of neural networks. Expert examinations are expensive, starting at RUB 150,000 for the analysis of a single deepfake, and waiting times may reach six months.

Balance between security and innovation:

Excessively strict regulation slows the development of legitimate AI services. Regulation that is too lenient opens the door to abuse. The search for an optimal approach continues.

Book a call
Your message send!
Interpol Stop Law Firm logo white