Governments are continuing to move from broad statements about artificial intelligence to detailed rules, and this week brought some of the most concrete shifts yet. Russia has now put its first AI statute on the books, South Korea has clarified how aggressively it will enforce its new AI framework, and Saudi Arabia has revealed a more constrained approach to AI training under copyright law. Each of these changes is narrowly framed, but in combination they sketch a more granular, duty‑driven regulatory environment for anyone building or deploying advanced models.
In Russia, Federal Law No. 243‑FZ on supporting the development of artificial intelligence technologies marks a deliberate choice to regulate only large foundational models rather than the full spectrum of AI applications. The law applies to systems with not fewer than one billion parameters that are general‑purpose and designed to serve as the basis for other software, effectively carving out more modest or highly specialized tools. Its commencement date has been widely reported as early September, but only the subject matter, aims, definitions, principles, coordination mechanisms, support powers and a bare liability referral start then; the substantive duties that most directly affect developers and platforms are pushed back to March of the following year.
Those deferred obligations in Russia are split across several articles, each binding different actors in the AI ecosystem. Article 8 imposes security measures, operating rules and technical documentation duties specifically on developers whose models have been granted sovereign or national status, tying heavier responsibilities to an elevated designation rather than to all large models. Article 9(3) targets platforms accessed by more than 500,000 users in Russia within twenty‑four hours, requiring them to give users the means to place an AI warning—a design obligation rather than a strict labelling mandate. Article 10(1) extends transparency requirements to anyone providing the ability to use such models, obliging them to tell users who owns rights in the outputs and on what terms those outputs may be accessed, used and retained.
Notably, Russia’s new AI law is silent on penalties and instead relies on existing legal infrastructure to give its obligations teeth. The statute contains no bespoke sanction regime for large foundational models, with Article 11 referring only to general legislation and the Code of Administrative Offences, which currently carries no dedicated article tailored to these systems. That omission sits alongside a longer‑standing rule in Russian data protection law: since early 2007, Article 16 of Federal Law No. 152‑FZ has barred solely automated decisions that produce legal consequences or otherwise affect a person’s rights and legitimate interests, subject only to written, identity‑linked consent or a specific federal law with protective measures. Operators must explain the procedure and legal consequences of such decisions, offer a chance to object, and respond within thirty days, but they are not compelled to change the decision or disclose the logic behind it.
South Korea, meanwhile, has clarified how quickly its new AI Basic Act will bite financially. The country’s Ministry of Science and ICT has now confirmed in an English‑language notice that there will be a grace period of at least one year from the Act’s in‑force date before administrative fines are imposed. That window runs from late January, covering transparency and labelling obligations and high‑impact AI duties, with only cases involving loss of life or fundamental human‑rights violations exempted from the pause. For developers and deployers working under the Korean framework, the announcement turns what had been practitioner‑sourced guidance into an official enforcement timeline.
Saudi Arabia has also updated the picture on what AI developers can and cannot do with copyrighted works when training models. A fresh read of the Implementing Regulation in the country’s official gazette shows that Article 30 subjects the Article 26(4) AI‑training exception to six cumulative controls, far more than the single record‑keeping duty that had previously been highlighted. Two of those controls materially narrow scope: one withholds the exception when a work is used within a purely commercial frame unless the use is insubstantial or does not affect normal exploitation, and another bars adaptation, republication, making the work available to the public, and unnecessary inclusion of the work in final products without the right holder’s permission. Even the record‑keeping requirement is more limited than initially recorded, as developers must produce records only to a competent body examining a dispute, not to any authority on demand.
Why this matters
These changes matter because they turn high‑level AI policy into operational constraints for companies and developers, and they do so in markedly different ways. Russia’s focus on very large foundational models and sovereign or national status underscores a state‑centric approach, where burdens like security measures and detailed documentation attach to a select class of systems, while platforms are nudged to enable AI warnings rather than enforce labelling across the board. South Korea’s confirmed fine grace period gives firms a defined runway to align with transparency and high‑impact AI duties, but the carve‑outs for severe harms signal that regulators expect immediate accountability when life or fundamental rights are at stake. Saudi Arabia’s six‑part control regime around AI training narrows how broadly developers can lean on copyright exceptions, especially in commercial settings, forcing more careful curation of training data and downstream products.
Looking ahead, the absence of explicit penalties in Russia’s new AI law, coupled with longstanding bans on solely automated decisions that affect rights, suggests enforcement will lean heavily on existing statutes and judicial interpretation rather than bespoke AI offences. In South Korea, firms now have a clearer sense of when fines might start, but the substantive obligations on transparency, labelling and high‑impact systems will still require significant internal overhaul before the grace period ends. Saudi Arabia’s tightened exception is likely to drive closer collaboration between AI teams and legal departments as they map training workflows against the six cumulative controls and the commencement rule that ties the Regulation’s force to the underlying Law rather than its own publication date. As more jurisdictions refine their AI rules with this level of specificity, the practical challenge for global AI companies will be not just keeping up with new laws, but translating fragmented, highly technical requirements into coherent engineering and product strategies.