Digest No. 1 — September 2026
What changed in the regulation and research of artificial intelligence safety by the end of September 2026, and what follows from it in practice. Every item names its source.
Regulation
1. Federal Law No. 243-FZ has come into force
The main part of the law of 26 July 2026 has applied since 1 September 2026. For developers of large foundation models it means an obligation to notify about rights in generated content. The duty to provide a technical means of marking rests on platforms with an audience above 500,000 users; for authors marking remains voluntary.
What to do: check whether your model falls under the definition of a large foundation model and appoint someone responsible for notifications. Source: Federal Law No. 243-FZ of 26 July 2026.
2. Websites of IT organisations: Ministry order No. 511
Since 21 November 2025 an order has set the mandatory content of the official website of an organisation operating in information technology: fields of activity, codes, programming languages and development tools, software rights, and reliable pricing of goods and services. The information is published in Russian and accessible without registration.
What to do: check your site against the list. A clarification from the Ministry permits a price range or a description of pricing factors instead of an exact figure. Source: order No. 511 of the Ministry of Digital Development of 02.06.2025.
3. Non-profit reporting: one form instead of three
Order No. 336 of the Ministry of Justice of 09.12.2025 repealed forms ON0001, ON0002 and ON0003. Since 1 January 2026 non-profit organisations file a single report through their account at nco.minjust.gov.ru, regardless of income. Repeated failure to report remains grounds for a liquidation claim.
What to do: if the organisation used the old forms, check the 2026 deadlines and access to the account. Source: order No. 336 of the Ministry of Justice of 09.12.2025; para. 10 of art. 32 of Federal Law No. 7-FZ.
Research
4. Anthropic: “mind viruses” in multi-agent systems
The paper Mind Viruses: Self-Propagating Ideas in Multi-Agent LLM Systems describes a case in which an idea passes from agent to agent and keeps reproducing without an external carrier, by a mechanism resembling infection. For us this is not a metaphor but a subject of measurement: a spread has a threshold, a rate and a saturation point, and all of it can be counted if the experiment is built correctly.
Why it matters: if an idea lives in the network of agents, protecting a single agent solves nothing — the system level is what counts. Source: Anthropic, arXiv:2608.10218, August 2026.
5. LLAMATOR: an open tool for testing chatbots
The ITMO team is developing an open framework for automated testing of large language models and chatbots. Its practical value is that testing stops being manual: attack sets are reproducible and results can be compared between model versions. The tool sits alongside our work rather than replacing it: it tests a model, while we look at a system of several agents and at its behaviour over time.
What to do: use it as a quick entry into regular testing, remembering the limitation — a single model does not show what emerges in a network of agents. Source: LLAMATOR, ITMO.
What this means in practice
- Regulation is moving from declarations to procedures: a requirement is increasingly worded as “ensure and evidence” rather than “comply”.
- Responsibility for marking is distributed along the chain: the model developer, the platform and the author are answerable for different things.
- Documentation is becoming cheaper than its absence: without a described model you can neither evidence compliance nor defend your position.
- A single model is ceasing to be the unit of analysis: both risk and protection appear at the level of the agent system.
How the digest is prepared
We assemble an issue every two weeks and check every item against its primary source: a law, an order or a research paper. Retellings of press releases and “according to the media” do not go into the digest.
- Only what changes work with AI systems goes into an issue, not merely what is in the news.
- Every item has a source, and every conclusion has a consequence: what specifically to do.
- If a fact cannot be confirmed, it is either not published or marked as unconfirmed.
Need a review for your own system?
Tell us which AI systems you run and which requirements apply to them — we will propose a scope and an indicative price.