The digital footprint of the ruble: “Digital ruble was not created for the sake of surveillance of people”
This fall, Russia began the widespread introduction of the digital ruble, an absolutely exotic form of national currency for the population

In particular, there is a fear in society that everyone will be driven around the concrete perimeter of the digital ruble system, that in the future only they will be paid pensions, benefits and even salaries. And that the ultimate goal of the authorities is to establish total control over financial transactions carried out at the level of each individual taxpayer. To clarify the situation with the security of the digital ruble, as well as a number of key tactical and technical features of the innovation, we asked the Chairman of the Financial Markets Security Commission of the Council of the CCI of Russia Timur Aitov.
Element of architecture
- Why does the government need a digital ruble? What is the main problem he really solves?
- Infrastructure. To understand its scale, you need to go back to 2022. Up to this point, the Russian financial system was deeply integrated into global accounting, SWIFT, and clearing. Everything worked for decades and seemed unshakable. But reliance on external algorithms has proven to be a structural vulnerability. And in 2022, it was implemented: in the wake of Western sanctions, the country’s largest banks were disconnected from SWIFT, correspondent accounts were blocked, settlements in dollars and euros became technically impossible. Yes, the Bank of Russia’s Financial Message Transfer System (SPFS) has been fully operational. But this is not a payment system and not clearing, but a channel for the delivery of payment data. The settlements themselves still require correspondence accounts between banks.
The digital ruble is the next step, and it is fundamentally different. Its key difference from the usual cashless lies in the architecture: it is an entry on the digital ruble account on the Central Bank platform. The bank performs only the role of an interface, emission and accounting are centralized. Settlements within the digital ruble do not pass through external clearing systems. But we should not overestimate the importance of innovation. It is possible to build a circuit that is technically invulnerable to disconnect from SWIFT, but this will not lift sanctions, open frozen reserves, and lift restrictions on technology exports.
- From the high rostrums, we are told that the digital ruble is just another method of payment along with cash and non-cash. Do you agree?
- No, and I think that's a dangerous oversimplification. The thesis of “another method of payment” usually means something like the Quick Payment System (SBP). Yes, it is convenient, fast, but fundamentally it is the same banking system, only operating at a different speed. The digital ruble is different. It's not a superstructure on the banks. This is a separate circuit, where the issue and accounting are focused on the Central Bank platform, and the bank performs only the role of an interface. The difference is huge. In classical banking, technical transaction data is a byproduct. They are scattered across banks and payment systems, stored for a limited time, often unstructured.
In the digital ruble, this data is recorded as an attribute of the operation. They are initially structured, presented in a single outline. From a byproduct, they become an architectural element. A system that sees its operations fully is more stable than one that sees them fragmentarily. This is not surveillance, as many believe, it is management. Surveillance is when data is collected for collection. Control is when they are built into the architecture and work on the sustainability of the system.
“A man is not a fraud, but he is being used.”
- Recently, news appeared: from July 1, 2027, the Federal Tax Service will be able to request IP addresses, device data, SIM card identifiers for a digital ruble. The headlines in the media went one another louder: “The Federal Tax Service will get access to wallets”, “Surveillance of the digital ruble is legalized”, “The state will see every payment you make”. Are the fears justified?
Panic is a bad help in any topic, especially financially. Let’s look at the wording itself. It says, "will be able to ask." And that's what "can" is all about. It's a right, not a mechanism. Between the law and the working procedure lies a huge amount of work, which is not yet available: regulations, retention periods, the list of operators, the procedure for appeal, liability for leaks. All of this needs to be formalized. And if you don’t get there by 2027 — or get it done quickly — you’ll get the worst possible thing: a law without a mechanism. When an agency has a right but no procedure, it creates uncertainty for everyone – for businesses, citizens, and banks themselves.
- But what is technically changing for the average user with the introduction of the digital ruble?
- Technically, three things, and all three are important. First, the technical attributes of the operation become available for query. IP address (the unique address of the device in the network). – “MK”), device identifier, SIM card data – all this turns from service information into an object that can be officially requested. Second, there is a single data point. Previously, to collect a picture of one person, you had to bypass dozens of banks, write queries, wait for answers. This is done centrally through the platform. And third, it's possible to link operations through devices. If two wallets were used from the same gadget, it becomes apparent. But there is an important nuance here: the bank sees the client’s IP address, not the Bank of Russia platform. The platform sees only the IP of the intermediary bank. In order for the FTS to receive end-user data, the bank must transfer them to the platform. Without it, the whole structure doesn't work.
- So the bank is the key link?
- Exactly. And that's where the fun starts. Not in technology, but in who and how will regulate this transfer. Because if a bank transfers data at the request of the Federal Tax Service, this is one story. If the bank is obliged to transfer them constantly, automatically, it is completely different. And until we see the rules, we will not understand what kind of world we live in.
- Can you give a concrete example where this very binding to the device really works and benefits – not the state, but an ordinary person or business?
- Take droppers, this is the most common story of the last two years. The person provided his electronic wallet for the transit of other people's money. Maybe he didn't even know why. He said, "Give me a card for a couple of days, we'll pay." And he did. And through his wallet went funds related to something illegal. For the state, he is now a defendant in a criminal case, and for the bank - a suspicious client. He just wanted to make some money. Linking to the device and SIM card in this situation shows that the operations are not managed by the owner, but by a third party. It is the protection of the infrastructure and the people themselves. He's not a fraud, but he's being used.
Another example is splitting up the business. The entrepreneur registers several individual entrepreneurs to stay on the special regime, pay less taxes. Formally, we have different faces, different accounts, different wallets. Legally, it's clear. But if the operations are from a single device, the digital fingerprint gives the connection. Previously, such connections had to be collected through interrogations, counter checks, seizures of documents. These are months of work, huge resources. They will now be seen automatically, not as evidence, but as a signal. It’s not that the government wants to catch someone. The system sees anomalies and reacts faster.
False positive generator
- But there's a downside here. We understand that behind one IP there can be an entire office or family. How reliable is this data as evidence? And where is the line between a signal for verification and a charge?
- Of course, IP or ID matching is a signal to verify, but not a proof. Indeed, the IP address is dynamic, that is, it changes with each connection. A single identifier can be used by multiple people on a single device – a family, a shared computer. Therefore, the conclusion should be made on the basis of a set of data, and not on one basis. If the system does not understand this, it becomes a false positive generator.
- And what does that mean in practice?
- I went through it myself, and it was very visual. Transferred a colleague 25 thousand rubles on SBP - it went well. I make a second transfer, 35 thousand, the same recipient is blocked. And not only translation, but all access to the application. I can't access the login, the map, or the phone. Came to the office with a passport. Employees spread their hands: the map must be reissued, in any other way. Re-released, right in front of their eyes trying to transfer the same 35 thousand — again the block. And the employees warned in advance that there are no guarantees: the system decides on its own, they cannot influence.
- You are the chairman of the CCI Financial Security Commission, and the system did not distinguish you from a fraudster?
- That's the irony. I have been explaining these topics for years, referring to my own publications, including in MK. It didn't help. The antifrode hammer was built, and we are carnations for it. The system does not distinguish a real attacker from a client who is sitting in a branch with a passport and a new card. The call center at this time reads a lecture about fake intelligence officers. Conditional girl "Svetlana" - without a surname and service number - speaks template, without enthusiasm. She just can't keep up the conversation on a professional level.
- Is this happening only in Russia or is it a global trend?
- Worldwide. We often present such innovations as something unprecedented, almost an invention of recent years. In fact, we do not invent any unique control. The FATF, an international financial anti-money laundering development group, revised Recommendation 16, the so-called Travel Rule, in June 2025. Now, cross-border transfers above $1,000 or euros require a standardized set of data: name, address, date of birth of the sender and recipient. The changes should come into force by the end of 2030.
According to the FATF, by mid-2026, 83% of the jurisdictions surveyed had passed Travel Rule legislation – 91 of the 109 countries that participated in the study. That is, the world is moving not towards the concealment of personal data, but towards disclosure. Russia is in a general trend, just with its own specifics. But the vector itself is global, and it is important to take this into account so as not to perceive what is happening as an exclusively Russian phenomenon.
- Are you concerned about how these mechanisms affect people’s daily lives?
- I'm concerned about trust. The architecture that is being built requires a high degree of trust in the state. Trust is not a technological category. It’s possible to build a perfect accounting system, but if people don’t trust how that data will be used, the system will be perceived as a threat, not a defense. Normative acts do not solve this. Just practice. And my personal story with the lockdown is just that. I am in the office, with my passport, with a new card, in front of the staff, and the system does not see me.
- If that's how the defense works, what's stopping it from making a mistake next time?
- To see a threat where there is no threat and not to see where there is a threat. And yet, it is not a fact that an adequate regulatory framework will have time by 2027. There is a right to request metadata. The mechanism seems to be there. But between these points there is a huge amount of work. What awaits the banking community? We can only hope that the mechanism will be made qualitatively. But there is a risk that technical control will become an end in itself. That the system created for sustainability will start working for control for control. This is not about the digital ruble in particular, this is about any infrastructure that gives the state a lot of data. We need checks and balances: independent audit, parliamentary control, judicial supervision. I have no confidence that they will be laid in the proper amount.
- What awaits us in the sphere of the digital ruble in five to ten years, given that the topic ceases to be purely economic?
- It has already stopped, and that is probably the main thing. There are several processes going on simultaneously. Cross-border scenarios – calculations with the EAEU, BRICS. Integration with SPFS: two circuits, messaging and money circulation, can be combined into a single infrastructure. The regulatory framework is the procedure for requesting technical data, storage periods, the list of operators. New services – smart contracts, targeted payments, automated calculations. All this is formed in parallel. But the point is not in the technological details: a financial system is being built that operates autonomously and does not depend on external decisions. The digital ruble was conceived as a modern payment tool. It is now becoming an autonomous infrastructure. Payment sovereignty is no longer an economic category, but a matter of national security.


