- Статьи
- Internet and technology
- Agency collusion: in the Russian Federation, they began to protect the Internet from out-of-control neural networks
Agency collusion: in the Russian Federation, they began to protect the Internet from out-of-control neural networks
Major Russian companies have begun to develop IT products based on artificial intelligence, including systems for monitoring the actions of other AI agents. The need for such solutions has grown dramatically after businesses began moving from chatbots to autonomous AI programs capable of performing multi-step tasks on their own. The risks of this approach have already manifested themselves in practice: in the summer, hundreds of AI agents coordinated an attack on Hugging Face, the largest open neural network platform. How companies will monitor the actions of autonomous systems and prevent their failures is in the Izvestia article.
How Russian companies started restricting AI
Modern language models have reached such a level of development that developers' attention is shifting to their control mechanisms and corporate infrastructure, which is called harness — the "harness" around the AI model. All major Russian technology companies are developing such systems.
According to Valery Stromov, CEO of Alice and Smart Devices, it is the "harness" that allows AI to work with memory and context, run code and consistently execute complex scenarios. The company considers this to be one of the key areas of the next stage of agent-based technology development.
"We are developing our own smart routing technologies that allow us to choose the optimal tool for a specific request, as well as developing our own harness solutions for user and corporate products," the expert noted.
Yandex also told Izvestia that harness development is associated with the emergence of models that are able not only to answer questions, but also to perform real actions using various tools.
"This turns the capabilities of the models into a reliable service: it connects them to local data, search and other products, controlling quality and safety," said Sergey Yudin, technical director of the company's professional AI services division.
MWS AI (part of MTS Web Services) is developing its own solution that will allow you to switch between different models without changing the logic of the agent, monitor the consumption of computing resources and analyze every action of the system. According to the company's representatives, the same language model can show significantly different results depending on the quality of such infrastructure.
They emphasize that it is more correct to talk not about an independent security agent, but about a software infrastructure that turns the language model into a full-fledged working tool. It determines which data the AI can use, which tools to run, how to perform multi-step tasks, and in which cases to request human confirmation.
Sber is also developing its own solutions in this area, the bank's press service said. The company was one of the first in the Russian market to introduce integrated technologies for managing large language models and AI agents. The infrastructure has already been implemented in the bank's products for both mass users (GigaAgent, GigaCode) and businesses (GigaCowork). This allows you to build AI processes with data and results control.
"We can talk about the formation of an independent and fast-growing market for the control and deterrence of AI agents, so we use a hybrid approach: an internal infrastructure solution with neural networks is combined with the ability to access external models through the barrier of large language models," explained Marina Surygina, head of Product Management and development at Sbermarketing.
A similar approach is used in T1 IT Holding. Sergey Golitsyn, head of T1 AI, told Izvestia that over the past year, the number of business requests for AI agent control mechanisms has approximately tripled. Previously, customers sought to implement an AI assistant faster, but now security requirements are laid down already at the design stage.
According to him, about 80% of such requests are related to access control to corporate data, human verification of critical decisions and protection against information leaks. Banks, industrial enterprises, government organizations and retail are showing the greatest interest in such technologies.
Runet Cybersecurity
Evgeny Fedorov, Technical Director of the Solar Group Cybersecurity Technology Center, compared the new class of protection with the advent of firewalls in network security.
According to him, the language model itself does not know how to distinguish data from commands: any letter, document or other text can become instructions for it, so control should be outside the model — to analyze requests, responses and access to tools and block dangerous actions according to predefined rules. Solar expects that this year the Russian AI protection market may reach 1-2 billion rubles only through the sale of products, and including services — up to 4 billion.
Such agents can also be used to protect Russians' personal data in the context of domestic AI models, said Egor Zubakin, a political scientist and expert at the New Era Development Center. In his opinion, the AI control market is still in the formative stages, but demand is already changing following the transition of companies to the industrial exploitation of agents.
—Centralized data access management, agent monitoring, audit of operations, and mechanisms for coordinating critical decisions with humans are currently in high demand," he said.
The Federal Service for Technical and Export Control informed Izvestia that threats related to the transfer of confidential information to third-party AI services have already been taken into account in the current information protection requirements. The agency believes that the existing organizational and technical measures are sufficient to neutralize such risks in government and corporate information systems.
The Ministry of Finance also clarified to Izvestia that work continues on technology development and industry regulation within the framework of the law on supporting the development of AI technologies in Russia. In particular, Article 8 obliges developers of large fundamental models to determine the operating rules and conditions of their use.
— If a service belongs to a large fundamental model, its developer is subject to these requirements. In other cases, the norms of the current Russian legislation are applied," the ministry's press service said.
Why is there a separate control industry around AI?
The growing interest in security solutions is explained by the fact that modern AI agents are no longer ordinary chatbots and are able to work independently with corporate systems, files and external services. Sometimes this leads to incidents: in the summer, more than a thousand autonomous AI agents massively overloaded Hugging Face, the largest open neural network platform, and a number of other services.
At the same time, there are practically no such incidents in Russia so far. According to IT entrepreneur Mikhail Lisetsky, this is not so much due to the higher security of domestic solutions, but rather to the level of system development. Russian AI platforms are still inferior to the most advanced foreign developments in terms of autonomy and computing capabilities. Therefore, their agents are less likely to be able to independently perform complex chains of actions outside a given contour.
— Recall the experimental Model 2 model by Anthropic, which demonstrates significantly more advanced capabilities, as well as the case of the cooperation of more than a thousand autonomous OpenAI agents who massively overloaded the Hugging Face infrastructure. And our AI models do not get out of control: they are prevented from doing so by an initially narrowly defined target framework," he believes.
Alexander Bukhanovsky, head of the ITMO Institute of Artificial Intelligence, compares the language model with the brain, and harness with the organs of perception and executive mechanisms. It is this layer that allows the agent to access databases, manage programs, and even physical devices.
According to him, a well-designed harness is able to reduce the power requirements of the model itself, transferring a significant part of the load to the tools and control system.
Murat Khazhgeriev, an expert at the Center for Continuing Education at the HSE Faculty of Computer Science, author of the Fundamentals of AI Agents for Process Automation program and an expert in the Generative AI for Managers program, explained that an informal formula already exists in the professional environment: "An AI agent is a large language model (LLM) and a harness.".
Today's language models are already strong enough for most business tasks, and the main bottleneck is precisely the organization of context, memory, and interaction with tools, he said.
— The main increase in efficiency today is provided by harness. This is incomparably cheaper than teaching new fundamental models," the expert noted.
Kirill Pshinnik, co—founder of Zerokoder University and a researcher at Innopolis, believes that by the end of 2026, the security segment may approach 1 billion rubles, if only paid platforms and services are taken into account, and by the end of the decade it will grow several times. In his opinion, the main sources of income will not be sales of individual programs, but their implementation, integration and maintenance.
— The estimate for the end of 2029 is about 5 billion rubles, a reasonable range is from 3 billion to 8 billion. The approximate growth is 70% per year," he explained.
Experts agree on one thing: as AI gets the opportunity to perform actions on its own, control over it ceases to be an additional function and becomes an obligatory part of the architecture. Therefore, the next stage of competition between developers will be determined not only by the quality of the models themselves, but also by the reliability of the infrastructure that controls their actions.
Переведено сервисом «Яндекс Переводчик»