Only 20% of CII entities' data infrastructure fully ready for AI law requirements, says K2Tekh
A study by K2Tekh shows that only 20% of critical information infrastructure (CII) entities have data infrastructure fully ready for new Russian AI legislation. The law, adopted in July 2026, mandates specific requirements for large foundation models used in state systems and CII, including security, quality, and data processing in Russia. Most companies require improvements or significant transformation to comply.
According to K2Tekh, only 20% of CII entities have sufficient maturity in data infrastructure and management to meet new AI law requirements, with 55% needing refinement and 25% requiring significant transformation. The research analyzed over 80 pre-project surveys and audits plus a poll of 150 respondents. The law, adopted on July 8, 2026, introduces concepts of sovereign and national AI models and imposes requirements on large foundation models used in state information systems and significant CII facilities, including security, quality, and data processing in Russia. A key obstacle is data quality: only 20.3% have fully ready and labeled data, 42.6% need cleaning or consolidation, and 25% cite poor data quality as a main barrier. Over a quarter of organizations lack a data management strategy, leading to data staleness, unverifiable results, and semantic gaps. Additionally, 40% of companies have no centralized AI responsibility, resulting in uncontrolled use of public neural networks and risks of corporate data leakage through prompts and integrations. Gosha Shatirov, AI and innovation director at K2Tekh, emphasizes the need for comprehensive AI governance, not just model selection, to manage the entire AI lifecycle.
- Abbreviations
- CII = Critical Information Infrastructure — критическая информационная инфраструктура
- LLM = Large Language Model — большая языковая модель
Source: CNews —
original
