Sber Updates Cybersecurity Threat Model for AI Systems
Sber has released AI 2.0, an updated cybersecurity threat model for artificial intelligence systems. The framework reflects the growing use of generative models, retrieval-augmented generation (RAG), AI agents and multi-agent architectures. It is designed for developers, MLOps engineers, solution architects and cybersecurity professionals.

The AI 2.0 model identifies 37 threats and 51 attack scenarios, detailing their potential impact, the information security properties they affect, targeted assets, threat actor profiles and the stages of the AI lifecycle where they apply. The risks include data leakage and manipulation, service disruptions, model and infrastructure compromise, and unauthorized actions performed by AI agents.
Reducing the Risk of Data Breaches
The AI 2.0 document can serve as a practical framework for designing security controls for AI products used in banking, government information systems, industrial operations, healthcare, telecommunications and other sectors.
For the public, applying threat models like AI 2.0 could help reduce the risk of personal data breaches, errors in automated services and unauthorized actions by autonomous AI agents. For Russia as a whole, the publication establishes a domestic methodological foundation for secure AI deployment while reducing reliance on foreign approaches to AI security.

Building Enterprise Threat Models
Organizations in both the public and private sectors can use the document when developing or modernizing AI systems across the entire lifecycle, from data preparation and model training to deployment and ongoing operations. It can also support the creation of enterprise threat models, security assessments of generative AI and agent-based systems, development of protection and monitoring tools, workforce training, and adaptation of AI systems to the requirements of government platforms and critical infrastructure.
The importance of these approaches is increasing alongside tighter regulation. Since March 2026, FSTEK Rossii (Federal Service for Technical and Export Control) Order No. 117 has required information security measures for AI used in government information systems. The regulation specifically addresses risks associated with AI models, datasets and RAG components.

Growing Focus on Risks from Autonomous AI
Sber introduced its first comprehensive AI threat model in 2025. It identified 70 risks affecting predictive and generative AI systems, covering data, models, software components and supporting infrastructure. During the same period, Yandex Cloud published practical guidance on securing AI agents, including protections against prompt injection, attacks targeting RAG components and unauthorized command execution.
During 2025 and 2026, the regulatory framework also began to take shape. The previously mentioned FSTEK Rossii Order No. 117 established information security requirements for AI deployed in government systems, while the national Threat Data Bank expanded to include vulnerabilities related to machine learning models. Meanwhile, OWASP updated its list of the most significant security risks affecting large language models and generative AI, helping standardize both threat categories and defensive practices.
Attention to the risks posed by autonomous AI tools also increased in 2026. According to cybersecurity experts, AI is increasingly serving both as a target for attackers and as a tool used by threat actors, including for vulnerability discovery and automation of individual stages of cyberattacks.

A Foundation for Security Audits and Testing
The release of AI 2.0 reflects the Russian market's shift from discussing AI risks in principle toward developing practical security mechanisms. The model addresses modern AI architectures, including RAG, AI agents, multi-agent systems and LLM adapters, all of which interact with enterprise data and external services.
The model is expected to evolve over the coming years as AI technologies advance and new attack techniques emerge, providing a foundation for auditing, testing and continuous monitoring of AI systems.
Making the framework publicly available establishes a common methodological approach for the market. Its effectiveness, however, will ultimately depend on practical implementation through technical safeguards, access controls, continuous monitoring and regular updates to security mechanisms.









































