Yandex AI Vendor Risk Profile
Russian technology company operating the YandexGPT family of large language models. Russia's largest search engine and internet services provider, offering AI across search, assistant, cloud, and consumer products.
Risk overview
Risk score: 63/100
Risk tier: High
Safety rating: 37/100 (higher is better)
Lower risk scores indicate lower assessed risk.
Last verified: Apr 19, 2026 Aging
Risk dimensions
| Dimension | Risk score |
|---|---|
| Data Handling | 62/100 |
| IP Exposure | 58/100 |
| Jurisdiction | 87/100 |
| Security | 48/100 |
| Regulatory Compliance | 80/100 |
| Transparency | 70/100 |
| Business Stability | 53/100 |
| Dependency Chain | Not assessed |
| Agent Governance | Not assessed |
Analyst summary
Rating: Avoid
Yandex's Russian operating businesses (including YandexGPT and Yandex Cloud) operate under Russian Federation jurisdiction following the July 2024 $5.2B divestiture. Subject to the Yarovaya law and SORM system, Yandex is legally obligated to store user metadata and provide access to Russian security services (FSB). US OFAC Russia sanctions create material compliance exposure for any US-connected engagement. Off-limits for virtually any Western enterprise.
Bottom line: Avoid. Russian jurisdiction, mandatory state access, sanctions exposure, and confirmed internal security breach make Yandex unfit for Western enterprise use.
Strengths
- Strong technical capability in Russian-language AI and search
- Large domestic deployment base inside the Russian Federation
- YandexGPT benchmarks competitively against open-source models on Russian-language tasks
Concerns
- Russian Federation jurisdiction with mandatory FSB data access under Yarovaya and SORM laws
- Material US OFAC sanctions exposure for any US-connected engagement
- No realistic GDPR-compliant path for EU personal data processing (EDPB flagged risk)
- 2023 leak of 44.7 GB of internal Yandex source code undermines security assurance
- Former executives have publicly described Kremlin pressure on search and content moderation
- No US-recognized compliance attestations (SOC 2, FedRAMP, HIPAA all absent)
Best for
- Workloads operating entirely within the Russian Federation (domestic-only use)
Avoid if
- You operate in US or EU jurisdictions in any capacity
- You face sanctions compliance scrutiny under US OFAC, UK OFSI, or EU sanctions regimes
- Any material data under your control would be processed or stored by Yandex
- You are a US government contractor, critical infrastructure, or defense-adjacent organization
- You process EU personal data subject to GDPR
- You have any cross-border data exposure reachable by Russian legal process
Citations
- Data Handling — Data Residency Options
Yandex Cloud operates data centers primarily in the Russian Federation; following international sanctions, EU-region services and some international availability have been restricted.
- Data Handling — Third Party Data Sharing
Under the Russian Yarovaya law and SORM system, Yandex is required to store user metadata and provide access to the FSB and other Russian security services on request.
- Data Handling — Trains On User Data
Yandex aggregates user interactions across search, Alice voice assistant, and cloud services to improve YandexGPT models; opt-out is limited for consumer services.
- Governance — Government Contracts
Multiple former Yandex executives have publicly stated the company faces direct Kremlin pressure on search results, content moderation, and strategic direction.
- Governance — Government Scrutiny
US Treasury OFAC maintains extensive Russia-related sanctions; engaging Yandex services raises material sanctions-compliance risk for US persons and US-controlled entities.
- Governance — Security Incidents
In January 2023 a 44.7 GB trove of Yandex source code was leaked online, exposing ranking algorithms and internal systems; the company confirmed authenticity of the code.
- Jurisdiction Profiles — Incorporation Country
Following the July 2024 divestiture, Yandex's Russian operating businesses (including search, cloud, YandexGPT) are owned by a Russia-domiciled consortium and operate under Russian jurisdiction; the former Dutch-incorporated Yandex N.V. was renamed Nebius Group and no longer operates the Russian Yandex businesses.
- Security Compliance — Gdpr Compliant
Following Russia's invasion of Ukraine, EU data protection authorities have flagged material GDPR risk with data transfers to Russia; Yandex does not offer a realistic GDPR-compliant path for EU personal data processing.
- Security Compliance — Soc2 Type2
Yandex Cloud holds Russian-regulated certifications (ISO 27001, PCI DSS) but does not hold US SOC 2 Type II, FedRAMP, or US-recognized attestations.