Kazakhstan – A Pioneer in Artificial Intelligence Regulation: Balancing Fintech Development and Consumer Rights Protection

Kazakhstan – A Pioneer in Artificial Intelligence Regulation: Balancing Fintech Development and Consumer Rights Protection

Authors: Marina Kahiani, Yasmin Rashidova, Sakzhan Kanafin, Zhan Jumaliyev, Balaussa Auyezova

1. KAZAKHSTAN 2026: AI AS A NEW REGULATORY IMPERATIVE FOR THE BANKING SECTOR

Kazakhstan entered 2026 with unprecedented regulatory and political momentum in the field of digital technologies. 

On 6 January 2026, the President of the Republic of Kazakhstan, Kassym-Jomart Tokayev, signed a Decree declaring 2026 the “Year of Digitalisation and Artificial Intelligence”. According to the President of the Republic, artificial intelligence (“AI”) “has created a kind of dividing line between those countries that will manage to enter the future and those that will remain in the past”. It is for this reason that AI and digital technologies have been designated as priority areas for the country’s development.

In June 2026, the President of the Republic of Kazakhstan approved by Decree the Nationwide Strategy “Digital Qazaqstan” through 2029 (“Strategy”). The Strategy marks Kazakhstan’s transition from fragmented automation to an integrated digital-state model in which AI becomes a fundamental tool for managing the economy, the social sphere and public administration. The Strategy encompasses three key areas: human capital (personalised education, predictive medicine and proactive social services), the economy and business (digitalisation of industries, “invisible” tax administration and development of IT exports), and public administration (platform-based architecture, adaptive regulation and cybersecurity). Particular emphasis is placed on attracting private investment and replacing fragmented, agency-specific approaches with unified data standards. By 2029, the Strategy is expected to deliver sustainable productivity growth, technological sovereignty and Kazakhstan’s emergence as one of the world’s leading digital economies. 

In August 2026, the President of the Republic of Kazakhstan emphasised in his address that Kazakhstan had already completed the first stage of building a digital state - the establishment of a digital public services system and that it was now necessary to move towards the practical application of new technologies and put digitalisation and AI at the service of the people.

Kazakhstan has recently taken a number of systemic measures in this area. A dedicated Ministry of AI and Digital Development has been established, the national AI center alem.ai has commenced operations, and AI technologies are being actively deployed in the provision of public services.

Kazakhstan’s computing system Alem. Cloud, developed at the instruction of the President of the Republic of Kazakhstan in cooperation with the international technology company Presight, has entered the global TOP500 ranking, reaching 86th place among the world’s most powerful supercomputers. The system is designed to perform AI-related tasks, complex mathematical computations and the processing of extremely large datasets.

Kazakhstan is steadily positioning itself as a key regional hub for data hosting and processing. One of the instruments supporting this policy is the “Data Centre Valley” project, a cluster of high-capacity computing centers designed to serve both domestic needs and partners from Central Asia, the Russian Federation and international corporations. This cluster model is intended to create an advanced infrastructure environment, enhance network connectivity and offer attractive regulatory conditions to foreign investors. Kazakhstan enjoys a number of natural and strategic advantages: a favourable location at the crossroads of transport and digital routes between Europe and Asia, affordable energy resources and a temperate climate, reducing equipment cooling costs, and a policy focused on digital sovereignty and geopolitical neutrality. Combined with government programmes, tax incentives available through Astana Hub and user-data localisation requirements, these factors generate sustainable demand and lay the groundwork for Kazakhstan to become a competitive jurisdiction in which both domestic and international companies can access high-quality services, competitive pricing and convenient access to the growing markets of Central Asia. 

Against this background, Kazakhstan continues to consolidate its position as Central Asia’s leading fintech hub. The Astana International Financial Centre (“AIFC”), established in 2018, operates on the basis of the principles of English common law and provides registered companies with an exemption from corporate income tax until 2066, as well as access to a regulatory sandbox for testing financial innovations. Internet penetration in Kazakhstan stands at approximately 92%, exports of IT services reached approximately USD 1 billion in 2025, and the Astana Hub innovation cluster comprises approximately 2,000 companies. These indicators provide the foundation for the large-scale expansion of AI across the financial sector. 

The development of AI technologies in Kazakhstan’s domestic financial market takes place against the backdrop of pronounced jurisdictional dualism resulting from the AIFC’s special legal status. While Kazakhstan companies are subject to the mandatory laws of the Republic, including, most notably, the Digital Code of the Republic of Kazakhstan No. 255-VIII dated 9 January 2026 (“Digital Code”), the Law of the Republic of Kazakhstan on Personal Data and their Protection No. 94-V dated 21 May 2013 (“Personal Data Law”) and the Law of the Republic of Kazakhstan on Artificial Intelligence No.230-VIII dated 17 November 2025 (“AI Law”), the AIFC operates under an autonomous legal regime based on the principles and precedents of English common law. The Constitutional Law of the Republic of Kazakhstan on AIFC No. 438-V dated 7 December 2015 empowers the AIFC to adopt its own regulatory acts, which take precedence over generally applicable national legislation. By virtue of this legal autonomy, the Astana Financial Services Authority (“AFSA”) and the AIFC Commissioner of Data Protection independently establish the compliance framework applicable to authorised fintech companies, relying on the specialised Data Protection Regulations 2017 and Data Protection Rules 2018. The Law of the Republic of Kazakhstan on Informatisation No. 217 dated 11 January 2007 (is no longer in force), which previously governed the IT sector in Kazakhstan, had been superseded by the unified Digital Code, while the AIFC retains an independent framework of direct regulation, providing international investors with a transparent and predictable environment for the deployment of algorithmic solutions. 

The practical implementation of security standards governing the use of algorithms within the AIFC is facilitated by the dedicated Guidance on Data Protection and Artificial Intelligence, published by the AIFC Commissioner of Data Protection. Unlike the stringent mandatory standards applicable in the rest of Kazakhstan, this framework is advisory in nature and represents a classic example of facilitative soft law. The guidance calls upon fintech organisations to implement comprehensive internal strategies governing the use of algorithms, conduct regular risk assessments and exercise strict control over the processing of sensitive personal information, including customers’ biometric data. This approach seeks to strike a balance between consumer rights protection and technological progress, as confirmed by regulatory data. According to an official study published by the AFSA at the end of 2025, almost half of the AIFC’s authorised participants already use machine-learning tools in their operations, predominantly relying on solutions supplied by reputable third-party providers. 

A principal competitive advantage of the AIFC legal regime for digital platform developers is the absence of stringent restrictions on cross-border data transfers and server localisation requirements. In the rest of Kazakhstan, the Personal Data Law imposes a strict requirement that databases containing citizens’ personal data be physically located within the country. This materially restricts commercial banks’ ability to use advanced foreign large language models due to the risk of disclosure of bank secrecy. The AIFC legal framework, aligned with the international standards reflected in the European data protection regime, does not impose similarly stringent requirements tying data storage to domestic infrastructure. AIFC participants may lawfully transfer information across borders to trusted jurisdictions and use advanced cloud services through secure application programming interfaces. Compliance oversight therefore focuses not on the physical location of servers but on outsourcing risk management and ensuring cybersecurity in accordance with international standards. 

Kazakhstan’s banking sector is more advanced in terms of digitalisation than most neighbouring markets. Key players - Kaspi Bank, Halyk Bank, Jusan Bank and Freedom Bank - have evolved from traditional financial institutions into digital ecosystems and super-apps. Halyk Bank’s digital ecosystem, for example, is used by more than 8 million people each month, while Kaspi Bank has effectively transformed into a financial and e-commerce platform dominating the QR-payment segment. AI has been integrated into banks’ key operational processes, including credit scoring, fraud prevention (anti-fraud), service personalisation, KYC identification and AML monitoring. According to experts cited in professional publications, “when an account is opened, facial identification is performed using AI, while lending decisions are no longer made by people but by algorithms”. 

A major milestone in the institutional development of this field was the adoption of the Digital Code, followed by the entry into force AI Law. The AI Law became Kazakhstan’s first comprehensive legislative act directly regulating AI-related matters and established a uniform regulatory framework for developers, businesses and the state.

2. LEGISLATIVE BREAKTHROUGH: LAW “ON ARTIFICIAL INTELLIGENCE”

2.1. Background to Adoption and Place in the Legislative Framework
 
The development of the legal framework governing AI in Kazakhstan began well before the adoption of the AI Law. In April 2024, National Payment Corporation of the National Bank of the Republic of Kazakhstan JSC published an analytical report entitled “Artificial Intelligence in Kazakhstan’s Financial Market: Current State, Prospects and Analysis of Regulatory Approaches”. In the foreword to the report, Timur Suleimenov, Governor of the National Bank, noted that “Kazakhstan’s financial market was already actively using machine learning and advanced modelling technologies across a wide range of use cases, from credit scoring to computer vision for identification”. The regulator’s stated objective was to create a “sustainable AI ecosystem in the financial market” capable of translating technological potential into tangible benefits for individuals and businesses.

In parallel, the Agency of the Republic of Kazakhstan for Regulation and Development of the Financial Market (the “ARDFM”) stated in its Banking Sector Policy for 2025 that it intended to introduce into its supervisory process a framework for managing model risks and risks associated with the use of AI. In doing so, the ARDFM proceeded from the need to supervise banks’ use of AI in forecasting financial performance and managing risks, “as model risk arises when models used by banks prove insufficiently accurate or are incorrectly interpreted”.

Despite the evident maturity of the market and the regulators’ position, no comprehensive legislative act existed until autumn 2025. The AI Law, became the first specialised legislative act of the Republic of Kazakhstan dedicated to AI and ranks among the pioneering legislative initiatives in the Eurasian region.

2.2. Risk-Based Approach: Three-Tier Classification of AI Systems
 
The conceptual core of the AI Law is a risk-based approach implemented through a three-tier classification of AI systems ( “AI systems”) according to the degree of their impact on the safety of users, society and the state (Article 17.1 of the AI Law):

- Minimal-risk systems – systems whose malfunction or cessation of operation would have a minimal impact on their users;

- Medium-risk systems – systems whose malfunction or cessation of operation may reduce the efficiency of users’ activities, cause non-pecuniary harm or result in material damage;

- High-risk systems – systems whose malfunction or cessation of operation may result in a social and/or technological emergency and/or significant adverse consequences for the defence, security, economy or infrastructure of the Republic of Kazakhstan or the vital activities of individuals.

The classification of a particular system into a specific risk category is carried out by its owner and/or holder in accordance with the rules for classification of informatisation objects. High-risk AI systems classified as critical information and communications infrastructure facilities, as well as those intended for the formation of state electronic information resources, are treated as state systems for the purposes of compliance with information security requirements (Article 17.1 of the AI Law). This is a fundamentally important provision, as it means that private banks using high-risk AI systems automatically assume state-level information security obligations.

In addition to classification by risk level, the AI Law provides for classification of AI systems according to their degree of autonomy: low-autonomy systems (where a decision is made by a human), medium-autonomy systems (autonomous decisions that may be adjusted by a human) and high-autonomy systems (where human adjustment is completely excluded or technically impossible). The specific requirements governing the development and operation of high-autonomy systems are determined by separate laws of the Republic of Kazakhstan (Article 17.2 of the AI Law).

2.3. High-Risk AI Systems in the Financial Sector
 
For the banking and fintech sectors, the key issue is which AI systems automatically fall within the high-risk category. The AI Law does not contain an exhaustive list of such systems. Risk classification is carried out by the system holder in accordance with the applicable classification rules. Nevertheless, based on the functional definition of high-risk systems, a number of financial applications of AI are highly likely to fall within this category:

- Credit scoring systems (creditworthiness assessment algorithms that make or materially determine lending decisions): their malfunction or systematic bias may cause significant material damage to users and destabilise the credit market;

- AML/financial monitoring: anti-money laundering systems that make autonomous decisions to block accounts or suspend transactions affect citizens’ constitutional rights to dispose of their property and may have significant adverse consequences for the economy;

- Biometric identification systems (online KYC) used for account opening and customer verification: failures or discriminatory patterns may result in widespread denial of access to financial services;

- Highly autonomous anti-fraud systems: automatic blocking of transactions as a result of false positives causes direct material damage to bona fide customers.

For high-risk systems, the AI Law establishes the following set of obligations:

1) Risk management. Pursuant to Article 18 of the AI Law, the owner and/or holder shall implement a continuous risk management process throughout the entire lifecycle of the AI system, including: identification and analysis of known and foreseeable risks associated with intended use; assessment of risks arising from reasonably foreseeable misuse; implementation of measures to prevent and eliminate identified risks; and regular updating of the risk assessment, at least once a year. Where risks associated with prohibited functionalities are identified, the holder shall immediately take appropriate measures, up to and including suspension or complete termination of the system’s operation. 

2) Audit of AI systems. Article 20 of the AI Law provides for a mandatory audit of AI systems for holders seeking to have their systems included in the “list of trusted high-risk AI systems”. The audit additionally assesses the quality and lawfulness of the use of data libraries employed to train AI models and the presence of prohibited functionalities. 

3) Lists of trusted AI systems. Pursuant to Article 19 of the AI Law, sector-specific state authorities establish and publish on their websites lists of trusted high-risk AI systems. For the financial sector, the relevant authority is the ARDFM. Inclusion in the list is voluntary, but provides legal recognition and a competitive advantage in the market. 

4) Maintenance of documentation. Article 15.3 of the AI Law requires owners and holders to maintain documentation for an AI system “depending on the degree of its impact on the safety, rights, freedoms and legitimate interests of individuals and on public order”, in accordance with the list of documentation approved by the authorised body. 

5) Ensuring transparency. Article 21 of the AI Law requires users to be informed that goods, works and services are produced or provided using AI systems, while synthetic outputs generated by AI systems may be disseminated only if they are labelled in machine-readable form. 

2.4. Prohibited Practices and Their Significance for the Financial Sector
 
Article 17.3 of the AI Law expressly prohibits the development and operation of AI systems possessing certain functionalities. In the financial sector, the following prohibitions are of particular relevance:

- Behavioural manipulation (Article 17.3.1): a prohibition on “the use of subliminal, manipulative or other methods that distort an individual’s behaviour and impair their ability to make informed decisions or compel them to make decisions that may cause harm”. For banks, this means that algorithms may not be used to psychologically induce customers to make disadvantageous financial decisions, including taking out loans on terms that are objectively unsuitable for them.

- Exploitation of vulnerabilities (Article 17.3.2): a prohibition on “the exploitation of an individual’s mental and/or physical vulnerability due to age, disability, social status... for the purpose of causing harm or creating a threat of harm”. This prohibition is directly relevant to so-called predatory lending practices involving algorithmic systems specifically designed to identify vulnerable groups.

- Social scoring (Article 17.3.3): a prohibition on “the assessment and classification of individuals... based on their social behaviour or known, inferred or predicted personal characteristics” for discriminatory purposes. The boundary between permissible credit scoring and prohibited “social scoring” will be determined through law enforcement practice. The key distinguishing criterion should be the purpose for which the system is used: assessment of financial risk is permissible, whereas classification of individuals for discriminatory purposes is prohibited.

- Covert biometrics (Article 17.3.6): a prohibition on “determining an individual’s emotions without their consent”. This rule restricts banks’ ability to use systems analysing customers’ emotional states during consultations or negotiations concerning lending terms without the customer’s express consent.

- Covert biometric classification (Article 17.3.5): a prohibition on “the classification of individuals on the basis of their biometric data in order to draw inferences about their race, political views, religious affiliation... for discriminatory purposes”. This requirement protects customers against the use of covert discriminatory algorithms in lending decisions.

2.5. Rights and Obligations of Participants in the Financial Sector
 
The AI Law regulates relations between owners and holders of AI systems (banks and fintech companies), users (customers), and authorised state bodies. In the financial sector, the following key user rights established by Article 16 of the AI Law should be highlighted:

- the right to review the user agreement of an AI system;

- the right to protection of personal data and confidential information processed by an AI system;

- the right to receive explanations concerning the outputs of an AI system affecting the user’s rights and legitimate interests;

- the right to request information regarding the data on the basis of which the AI system made a decision;

- the right to refuse to interact with an AI system unless such interaction is mandatory under the legislation of the Republic of Kazakhstan.

In relation to fully automated lending decisions, the latter right raises significant practical issues regarding the possibility of reviewing an automated refusal by referring the loan application to an authorised bank employee for consideration. The answer will largely depend on the extent to which banks restrict this right by relying on the “mandatory nature of interaction” stipulated in the user agreement. Article 21 of the AI Law expressly provides that requirements applicable to decisions based solely on automated processing of personal data are established by the legislation on personal data and their protection.

As regards owners and holders of AI systems (banks), the AI Law imposes, inter alia, the following obligations:

- to manage risks associated with AI systems (Article 15.2.1);

- to take measures to ensure the security and reliability of AI systems, including protection against unauthorised access and failures (Article 15.2.2);

- to maintain documentation for AI systems (Article 15.2.3);

- to provide user support in relation to the operation of AI systems (Article 15.2.4);

- to provide users with an opportunity to review the user agreement before commencing use of an AI system (Article 15.2.5).

ARDFM Resolution No. 38 dated 20 August 2025, effective from 1 November 2025, supplemented these obligations with cybersecurity requirements applicable to financial institutions, including mandatory biometric authentication and two-factor authentication for customer-facing services. Together with the AI Law, these requirements establish a multi-layered regulatory architecture for the financial sector, in which information security requirements, personal data protection requirements and AI regulation form an interconnected framework of obligations.

2.6. Practical Implications for Banks and Fintech Companies
 
The entry into force of the AI Law creates a number of specific legal and operational tasks for participants in Kazakhstan’s financial market.

First, banks are required to conduct an inventory and classify all AI systems they use according to their respective risk levels. For high-risk systems (which are highly likely to include scoring and AML models), banks shall develop or update the relevant documentation, implement risk management processes and ensure that such processes are reviewed and updated annually.

Second, banks seeking to strengthen market confidence and regulatory certainty may apply for their high-risk systems to be included in the ARDFM’s list of trusted systems. This will require an audit and disclosure of information concerning the quality and lawfulness of the use of training data.

Third, in terms of compliance with the applicable prohibitions, particular attention should be paid to personalised marketing of credit products: where targeting algorithms use behavioural data to generate pricing offers directed at vulnerable groups, they may conflict with the prohibition on exploitation of vulnerabilities. Accordingly, a legal review of the data used and the underlying decision-making logic is required.

Fourth, fintech companies with European shareholding structures or European customers need to establish a “dual compliance” framework: taking into account the phased application of the EU AI Act (prohibitions applicable from 2 February 2025, obligations relating to general-purpose AI systems applicable from 2 August 2025, and requirements for high-risk systems applicable from 2 August 2026), while simultaneously adapting to the Kazakhstan regulatory model.

Finally, from an enforcement perspective, it should be borne in mind that 2026 is the first year in which the AI Law is being applied in practice. According to Kazakhstan lawyers, this is the period in which actual practice concerning the application of the risk-based approach will emerge: “Kazakhstan’s experience will be useful not only for CIS and post-Soviet countries, but also for other partners”. The development of secondary legislation specifying the classification criteria and documentation requirements will continue throughout 2026.

 3. DIGITAL CONSTITUTION OF KAZAKHSTAN
 
On 9 January 2026, an event took place in Kazakhstan that can only be compared to the adoption of a new Constitution, but for the world of technology. The Digital Code entered into force, the first comprehensive law of its kind, one that changes, once and for all, our relationship with gadgets, data, and the state.

Previously, digital rules were scattered across dozens of different laws. Now the country has a single “digital constitution” - a document that clearly answers three main questions: what belongs to us on the internet, how we are protected from AI and how we will interact with the authorities in the future.

3.1. The Concept of Fully Automated Decisions (FAD) in Banking

The Digital Code introduces into Kazakh law the concept of Fully Automated Decisions (“FAD”) decisions made entirely without direct human involvement. This category is directly borrowed from European regulation: Article 22 of the General Data Protection Regulation established a similar right of data subjects not to be subject to decisions based solely on automated processing. The Kazakh legislator adapted this approach to the specifics of the domestic financial-services market.

In the banking context, FAD manifests most clearly in credit-scoring systems. Modern second-tier banks widely apply machine-learning models to assess borrowers’ creditworthiness: within a fraction of a second, the system analyzes hundreds of parameters, from credit history to behavioral patterns in mobile banking, and automatically produces a decision to approve or deny a loan. It is precisely such decisions that fall within the scope of the Digital Code as fully automated.

3.2. The Requirement of Human Involvement: Architecture of a Protective Mechanism

The central element of the FAD legal regime in the Digital Code is the citizen’s mandatory right to human review. This requirement is structured across several levels and forms a coherent protective mechanism.

First and foremost, the Digital Code establishes an obligation for a financial organisation to inform the borrower of the fact that a decision was made through FAD. The notification shall be given in an understandable form, contain the main factors that influenced the decision, and explain the right to challenge it. This requirement is of fundamental importance: it obliges banks to open up the algorithm’s “black box”, even if only in a simplified form accessible to the consumer.

If AI scoring denies a loan, the borrower is entitled to demand that the decision be reviewed with the involvement of an authorised bank employee. The Digital Code establishes essential requirements for such a review: the specialist shall carry out an independent assessment rather than simply confirm the algorithmic conclusion. Thus, “human involvement” within the meaning of the Digital Code is not a formal procedure but a substantive check.

Practical mechanism for challenging a decision

  • The applicant sends the bank a written request for review of the decision within 30 days of receiving the denial;
  • The bank shall appoint a specialist who was not involved in the original data processing to carry out an independent assessment;
  • The period for reviewing the complaint may not exceed 10 business days;
  • The decision on review shall contain a statement of reasons citing specific grounds;
  • If denied again, the applicant is entitled to apply to the authorised body for the protection of the rights of consumers of financial services. 

3.3. Algorithmic Transparency and Explainability Requirements
 
The Digital Code introduces requirements for the explainability of algorithmic systems, which in the financial sector are implemented through several mechanisms. First, banks shall maintain registries of the FAD systems they use and disclose key parameters of their operation to the regulator. Second, when reviewing complaints about automated denials, the bank shall provide the borrower with information about exactly which factors had a decisive influence on the scoring outcome.

This requirement creates practical difficulties for banks using complex neural-network models, whose nature is inherently opaque (the so-called “black box” problem). The Digital Code thus indirectly encourages financial organisations to use interpretable models or to develop post-hoc explainability tools (SHAP, LIME, and similar methods).

The Digital Code’s explainability requirements for FAD correlate with the approaches of the European AI Act, which classifies credit-scoring systems as “high-risk” and requires operators to ensure their transparency, auditability, and documentation. Kazakhstan is thus aligning itself with the global trend toward responsible AI.
 
3.4. Protecting the Rights of Financial-Services Consumers: A Comprehensive Approach
 
In addition to the right to challenge a decision, the Digital Code establishes an expanded set of consumer rights in relations with financial organisations that use FAD systems.

A key protective tool is the prohibition on discriminatory algorithms. The Digital Code directly establishes that FAD systems in the financial sphere may not make decisions based on data directly related to protected characteristics (nationality, sex, religious beliefs, etc.) or serving as proxies for them. This requirement obliges banks to conduct regular audits of their scoring models for discriminatory patterns.

Equally significant is the data-minimization requirement: FAD systems may process only the personal data that is necessary and proportionate to the purposes of the decision. With respect to credit scoring, this means a prohibition on using excessive data, for example, information about a borrower’s religious preferences or political views, even if such data theoretically correlates with credit behavior.
 
3.5. Institutional Oversight
 
The Digital Code establishes a multi-level system of oversight over the application of FAD in the financial sector. At the sectoral level, ARDFM is granted authority to supervise compliance with FAD requirements in the activities of second-tier banks and other supervised organisations. The authorised body in the field of informatization ensures horizontal regulation of data-processing and algorithmic-explainability requirements.

This architecture creates a risk of regulatory fragmentation: gaps and conflicts of supervisory authority may arise between ARDFM and the authorised AI body. Enforcement practice will show how effective interagency cooperation proves to be in this area. There is already an evident need for coordination mechanisms, along the lines of the European joint AI supervisory bodies.
 
4. AI IN ACTION: APPLICATION PRACTICE IN THE FINANCIAL SECTOR AND MARKET TRENDS
 
This section explains how AI is already being applied in Kazakh banks today, and what this means from the standpoint of law and everyday life. We will examine three examples: how a bank uses AI to decide whether to grant you a loan, how the state uses technology to combat tax evasion, and how banks use AI to catch fraudsters.

4.1. Credit Scoring

Scoring is the assessment a bank makes of a person or company before extending a loan, to determine how much they can be trusted with borrowed money and on what terms. Previously, banks mainly looked at five basic borrower parameters, the so-called “5C” model (character, capacity, capital, collateral and general economic conditions). This simple model is now being replaced by AI-based systems that take into account far more information: geolocation (where the person is), behavior in mobile apps, purchase history on marketplaces (online platforms such as Kaspi.kz, where goods can be bought and installment plans arranged). Such information is called alternative data, as opposed to the traditional income certificates and credit history. Around 75% of Kazakhstani banks already use AI not only in credit scoring but also for fraud protection, marketing, and customer service. Previously this remained an internal matter for each bank, but as of 16 January 2026 it has been enshrined in law: the new Law “On Banks and Banking Activity in the Republic of Kazakhstan” No. 258-VIII dated 16 January 2026 (the “Banking Law”) expressly permits banks to use AI in their operations, risk assessment, and risk management, while at the same time establishing that the bank itself, not the software developer, is liable for decisions made with the help of AI. In simple terms, if AI mistakenly denies someone a loan or, conversely, approves one for an unreliable borrower, the bank will be held responsible. This is logically connected to the fact that the separate AI Law classifies financial scoring as a “high-risk” system, one requiring special state oversight. The same Banking Law requires that, when opening an account or obtaining a loan, a client undergo biometric authentication, that is, confirm their identity via a facial scan or fingerprint, through a special National Bank system called the Identification Data Exchange Center

Where do banks get all this alternative data? The basis for this is Open Banking: a model in which a bank, only with the client’s consent, shares data about their accounts with other companies via an API, a technical interface that allows different computer programs to exchange data securely. The first such pilot project in Kazakhstan was launched in November 2023 with the participation of five banks (Bank RBK, Altyn Bank, Home Credit Bank, Bank CenterCredit and Otbasy Bank), and by 2025 the idea had been expanded into full-fledged services. In the future, the digital tenge is also planned to be connected to this system. While there is not yet any confirmed public case of a specific bank striking a direct deal with a specific mobile operator for scoring data, this is more a general direction of development than an established fact. However, it is clearly visible how alternative data is accumulating within banks’ own ecosystems: for example, Kaspi.kz - a service that combines a marketplace, payments, and installment purchases, has more than 13 million active monthly users, while Halyk Bank is developing a similar set of services (Halyk Market, Halyk Travel, the Halyk Bonus loyalty program), reviews also list Freedom Bank Kazakhstan among the banks actively deploying such tools. E-commerce in Kazakhstan is growing rapidly: in the first half of 2025 its turnover reached 1.7 trillion tenge, or already 17% of all retail trade in the country - meaning banks will have ever more data for such models.

4.2. SupTech and the Digital Tenge

SupTech (from “supervisory technology”) refers to technologies applied not by businesses but by the market regulator itself, to automatically, rather than manually, identify risks, violations, and suspicious transactions. In Kazakhstan this role is performed by the FinAI platform, developed by the country’s main financial regulator, ARDFM. ARDFM monitors banks, microfinance, insurance, and investment organisations in near-real time.

Separately, on the side of the Ministry of Finance, an even larger-scale system is being developed the Smart Data Finance platform. The Ministry of Finance has been officially designated the lead state body for combating the shadow economy, and its platform combines data from 78 state and private sources to identify tax-evasion schemes using AI. Several specific tools operate around it: a system that now processes a tax payment within one minute; the “E-tamga” project, which automatically checks whether companies are correctly paying value-added tax (“VAT”) based on electronic invoices, a biometric-verification system and a large product catalogue with a price database that helps detect inflated prices in government procurement.

One of the most illustrative examples is the “Digital VAT” pilot project. Exporter companies voluntarily purchase “digital tenge”, issued and fully controlled by the National Bank of Kazakhstan, from the National Bank through ordinary banks. The distinctive feature is that this money is “tagged”: it can only be spent on settlements with suppliers under official invoices or on paying VAT itself. This is enforced by a smart contract, a computer program that automatically verifies the terms of a transaction and prevents the funds from being transferred for anything else. Thanks to this transparency, VAT refunds to companies now take 15 business days and no longer require an on-site tax audit. Since January 2026, a similar system has begun to be applied in government procurement as well, so that budget funds cannot be illegally siphoned off through shell companies. By mid-2026, approximately 339 billion digital tenge had been issued under more than 20 such pilot projects. In January 2026, the authorities announced the creation of a unified plan based on Smart Data Finance that will combine data from the tax service, customs, and other agencies, so that AI can track how gray schemes “flow” from one industry to another.

4.3. Combating Fraud: Droppers, Phishing and Banks’ New Obligations

Fraudsters steal around USD 70 million annually from Kazakh banks and their clients. Over the first 11 months of 2025, more than 26,000 fraud-related crimes were registered - 20% more than a year earlier, but in early 2026 their number began to decline for the first time. The most common scheme is vishing, phone calls from fraudsters posing as bank or police employees, sometimes even using deepfake technology (fake video or voice generated by AI that looks and sounds like a real person), as well as classic phishing: fake websites or messages that steal passwords and card data.

In March 2025, ARDFM required the largest “systemically important” banks to deploy AI-based systems specifically to detect “droppers.” A dropper is a person who, for a small fee, hands over their bank card or account to fraudsters so that stolen money can be “run through” it. Banks were instructed to scrutinize clients more closely based on clear indicators: five or more cards from different banks held by one person; a card issued in a border region, a foreigner without a residence permit, a teenager or young person aged 14-25 with no official income but large incoming transfers and mandatory checks on any transfer exceeding 500,000 tenge. Criminal liability of up to seven years’ imprisonment with confiscation of property, is now provided for “dropping” itself. The new Banking Law also, for the first time, expressly allowed banks, telecom operators, the police, and the National Bank to exchange data on suspicious transactions through a special Anti-Fraud Center (a system uniting banks to track fraud schemes in real time); previously, banking secrecy could stand in the way of this.

In practice, these tools are already working. In November 2025, the Prosecutor General’s Office presented two AI tools, Crypto Trace and ProkAi, which were used to identify more than 15,000 suspicious dropper accounts, open more than 100 criminal cases, and discover crypto-assets worth around USD 5 million held by the ultimate recipients of stolen funds. Technically, such systems are typically structured on two levels: they analyze how a person behaves within the app while simultaneously monitoring the money transfers themselves, their volume, frequency, and direction. By comparison, a similar system deployed in the United Kingdom by Mastercard together with major banks helped prevent nearly £100 million in fraudulent transactions in a single year. In Kazakhstan, by contrast, an estimated 24 billion tenge in criminal proceeds have already been laundered through “drop cards”, precisely the sum that the new technologies and laws are aimed at combating.

4.4. Judicial and Administrative Practice in the Application of AI

An important factor in the development of Kazakhstan’s legal environment in 2026 has been the emergence of real judicial and administrative practice relating to artificial-intelligence technologies. The first breakthrough in this area was the Supreme Court of Kazakhstan’s completion of a large-scale rollout of the “Digital Assistant to the Judge” AI system across all courts in the country for civil disputes. This system processes an array of more than 15 million court rulings and is able to automatically draft a statement of claim, structure the parties’ arguments, and forecast the likely outcome of a dispute based on analogous precedents. AI is used exclusively as an auxiliary analytical assistant, and the final decision is made by the judge. Technologization has also reached the AIFC Court, where — for the first time in world judicial practice, a real-time AI transcription system for hearings was introduced, instantly translating participants’ speech into several languages to support the prompt compilation of the evidentiary record.

Finally, the courts of Astana and Almaty are actively developing case law on the protection of honor, dignity, and business reputation against the unlawful use of deepfakes and AI-generated content. While in 2024-2025 such claims were isolated, by mid-2026, thanks to the introduction of criminal liability for creating deepfakes without consent and the AI Law’s requirement to label AI content, proving such cases in court has become significantly easier. A telling case arose in Astana, where competitors used AI to generate a fake video of a company director renouncing obligations; the court needed only three days to issue an order blocking the resource and awarding substantial compensation, relying on digital-footprint forensics and the absence of mandatory machine-readable labeling on the video.

5. KEY RISKS, ETHICS AND DIGITAL SOVEREIGNTY

5.1. Data Localisation: Requirement to Store Banking Secrecy and Personal Data Domestically, Limiting the Use of Foreign Cloud-Based LLMs (ChatGPT, Claude) without a Special Gateway

Kazakhstan enters 2026 as Central Asia’s premier fintech hub, where the banking sector has effectively transformed into high-tech digital ecosystems. The President's declaration of 2026 as the “Year of Digitalisation and Artificial Intelligence”, coupled with the entry into force of the AI Law on 18 January 2026, has created a fundamentally new regulatory landscape. However, this very landscape has exposed a fundamental contradiction between financial institutions' desire to leverage cutting-edge generative models (Large Language Models or LLMs) and the imperative requirements of national data protection legislation.

The central legal barrier to the direct use of foreign cloud platforms and large language models such as ChatGPT (OpenAI) or Claude (Anthropic) is the national data localisation regime. Its legal nature is complex and rests on at least two key legislative acts.

First, Article 12.2 of the Personal Data Law establishes the mandatory requirement that personal data shall be stored by the owner and/or operator, as well as by third parties, in a database located within the territory of the Republic of Kazakhstan. In turn, Article 1.2 of the Personal Data Law defines personal data as “data, including biometric data, relating to a specific or identifiable data subject, recorded on electronic, paper and/or other tangible media”. Therefore, by direct operation of law, the localisation requirement extends to all information falling within this definition.

Moreover, this definition is formulated extremely broadly and includes any information allowing identification of the data subject: from surname, first name and individual identification number to information on their property status, transactions and contractual obligations.

Second, for the financial sector, this regime is significantly tightened by Article 69.2 of the Banking Law. Under this provision, banks guarantee the confidentiality of their clients’ transactions, accounts and other information, the disclosure of which could harm the client. Since any information about transactions and accounts is inevitably linked to a specific identifiable person, it simultaneously falls within the legal definition of personal data and automatically receives dual protection: both as banking secrecy and as personal data subject to localisation.

Thus, the direct transmission of raw client data to foreign public clouds via standard APIs becomes legally impossible. The servers of foreign AI providers lie outside the legal framework and jurisdiction of the Republic of Kazakhstan, meaning that any transfer to them of information enabling client identification or revealing the content of their banking transactions qualifies as a direct violation of both personal data legislation and banking secrecy laws.

The practical response to this conflict has been the implementation of so-called Sovereign Data Gateways. These function as an intelligent insulating buffer at the boundary between a financial institution's internal perimeter and external LLM providers. The gateway's operating principle involves three sequential operations performed in real time before the request is sent outside the Kazakhstani perimeter:

  • First, masking and depersonalisation: the gateway algorithms automatically detect personal data within the request text (IIN, names, payment card numbers, etc.) and replace them with synthetic equivalents that prevent reconstruction of the original identity.
  • Second, tokenisation: all sensitive financial indicators are replaced with unique tokens, with the mapping table required for reverse depersonalisation stored exclusively on the bank's local server within Kazakhstan.
  • Third, context anonymisation: the original prompt is reformulated so that the external model can solve a mathematical or logical task without being able to identify either the specific data subject or the specific financial institution.

The implementation of such gateways formally ensures compliance, yet simultaneously significantly complicates the IT architecture of financial organisations. Response latency increases, additional computational infrastructure is required domestically, and data fragmentation during depersonalisation inevitably reduces the accuracy of contextual perception by large language models. Nevertheless, within a stringent regulatory environment, it is precisely such multi-layered isolation that becomes the only legal means of combining the cognitive potential of advanced LLMs with the requirements of Kazakhstani law.

5.2. Mandatory Labelling of Synthetic Content in Financial Communications

The intensive integration of artificial intelligence technologies into Kazakhstan’s banking activities transforms transparency in algorithm-consumer interaction from a mere ethical aspiration into a strict legal imperative. According to official data from the National Bank and statements by the ARDFM, 75% of the country’s banks already employ AI solutions in their operations, covering key areas from credit scoring and underwriting to anti-fraud systems, voice assistants and personalised marketing campaigns. Notably, initial client queries in chatbots and call centers are now handled without human intervention, making AI interaction an everyday financial reality for millions of Kazakhstanis. It is against this pervasive technological backdrop that the requirements of Article 21 of the AI Law take effect.

This provision elevates user notification to the status of a mandatory condition for the lawful use of AI. Article 21.1 of the AI Law stipulates that consumers shall be informed that goods, works and services are produced or provided using artificial intelligence systems. Furthermore, the dissemination of synthetic results from such systems is permitted exclusively on condition that they are labelled in machine-readable form and accompanied by a visual or other warning that ensures human perception without any obstructive methods. Responsibility for this notification rests not with developers or operators, but directly with the owners and operators of AI systems, that is, with the banks and fintech companies themselves. Collectively, these provisions mean that any client interaction with an algorithm, whether a loan approval, a chatbot response or a marketing offer, shall, from a legal standpoint, be accompanied by a visible, legible and technically detectable indication of its machine origin.

The problem of unlabelled AI use in financial communications has both formal-legal and substantive dimensions. The deliberate concealment of algorithmic involvement constitutes a violation of the imperative of Article 21 of the AI Law, but at a deeper level it undermines the very notion of informed consumer choice. When a client receives a credit recommendation or investment advice without knowing that a generative model lies behind it, they are deprived of the opportunity to critically assess the reliability, bias and logic of the information received. In an environment where scoring algorithms are already classified as high-risk, such an information vacuum directly contradicts the risk-oriented philosophy of the new regulatory framework and risks generating widespread distrust of digital services. To comply with legal requirements, financial organisations shall embed transparency mechanisms across all significant communication channels.

Non-compliance with the above requirements constitutes an administrative offence and attracts penalties under Article 641.1 of the Code of Administrative Offences No.235-V dated 5 July 2014. The scale of fines is strictly differentiated by entity category: for large businesses, which include second-tier banks, the primary fine amounts to 100 Monthly Calculation Indices (“MCI”), with a repeat offence within one year attracting 200 MCI. By comparison, the fine for individuals is 15 MCI, for small businesses 20 MCI, and for medium-sized businesses 30 MCI. However, the financial loss from the fine itself is far from the most critical consequence. Upon a repeat violation, the competent authority is empowered to suspend or completely prohibit the operation of the AI system. For a bank, such a measure would mean the immediate suspension of critically important business processes, from credit application processing and scoring to real-time fraud transaction monitoring. Given that these algorithms now form the operational backbone of retail and corporate banking services, their forced shutdown could result not only in direct losses but also in a complete loss of competitive capacity. Thus, the labelling of synthetic content ceases to be a technical formality and becomes one of the central elements of the compliance architecture of a modern Kazakh bank.

5.3. Talent Shortage: Acute Lack of Data Engineers with Fintech-Specific Expertise

Alongside the regulatory constraints discussed above, Kazakhstan’s financial sector faces an internal structural barrier - a shortage of specialists capable of developing and operating AI solutions under stringent industry requirements. The shortage primarily affects data engineers, AI system architects and MLOps specialists, precisely the roles on which the transition of algorithms from prototype to production environment depends.

Financial institutions’ demand for such professionals significantly exceeds the market average, as basic Data Science competencies shall be supplemented by an understanding of the nature of banking risks and regulatory requirements. The development of scoring models, anti-fraud monitoring algorithms and client service systems shall account for mandatory authentication and data protection standards, as well as supervisory expectations regarding model risk management. Professionals combining engineering skills with such a breadth of industry context remain rare, and this directly constrains the pace of new AI product deployment.

An additional layer of complexity arises from the linguistic factor. To ensure proper operation of services in the state language within banking applications, solutions in Natural Language Processing (NLP/NLU) are required, adapted to the Kazakh language and taking into account the specificities of financial and legal terminology. The development of such models demands competencies at the intersection of computational linguistics, data engineering and banking regulation, further narrowing the pool of available specialists.

The limited talent pool drives up recruitment costs, delays time-to-market for AI products and forces reliance on external developers, including international teams. The latter, in turn, creates additional risks to personal data protection and banking secrecy. Consequently, the talent shortage is not an isolated labour market problem, it has become one of the significant barriers to the large-scale deployment of artificial intelligence within Kazakhstan's financial system.

6. PRACTICE OF REGULATED INNOVATIONS IN THE FINANCIAL SECTOR
 
The legal innovations of the Digital Code create a regulatory framework for fintech development, yet real progress is determined by the quality of regulatory instruments available to market participants. In this respect, Kazakhstan demonstrates a consistent and ambitious policy: through regulatory sandbox mechanisms and pilot CBDC projects, the state is building an ecosystem of managed innovation that reduces systemic risks while preserving technological dynamism.

6.1. Digital Asset Sandbox (4 Key Directions)
 
On 25 July 2025, the Board of the National Bank of the Republic of Kazakhstan adopted Resolution No. 42 (“Resolution No. 42”), officially launching the first pool of pilot projects for testing crypto-technologies jointly with second-tier banks and fintech companies. The Resolution No. 42 structures the experimental space along four strictly delineated directions, each addressing a distinct regulatory and market challenge.

The participants in the special regulatory regime (regulatory sandbox) are defined as:

  • second-tier banks;
  • organisations carrying out certain types of banking operations;
  • payment organisations;
  • other legal entities that are residents of the Republic of Kazakhstan.

6.1.1. Fiat-Backed Stablecoins Denominated in Tenge

The first sandbox direction concerns digital assets strictly backed by actual funds held in the issuer's accounts. Tenge-denominated stablecoins are being developed as an alternative to dollar-denominated instruments (USDT, USDC), capable of enhancing the attractiveness of the national currency in the digital economy and reducing domestic crypto-market participants’ dependence on foreign stablecoins.

The most notable project within this direction is the development of the KZTE stablecoin on the Solana blockchain in partnership with the payment system Mastercard. The choice of Solana is driven by its technical characteristics: high throughput (up to 65,000 transactions per second) and low transaction costs make it an optimal platform for payment stablecoins. The partnership with Mastercard provides access to the global payment infrastructure and opens prospects for cross-border use of the tenge-denominated stablecoin.

From a legal standpoint, this direction requires resolution of several issues: the classification of stablecoins under existing payment systems legislation, reserve requirements, the prudential supervision regime for the issuer, and protection mechanisms for holders in the event of issuer bankruptcy.

6.1.2. Tokenisation of Real Estate

The second sandbox direction opens the real estate market to a broad range of retail investors by converting square metres into digital tokens. The fundamental innovation lies in fractionating ownership rights in commercial properties to a level accessible to investors with limited capital.

In February 2026, the National Bank reported the launch of a pilot project on the Apartchain platform - a joint development with the Nazarbayev University Impact Foundation. The project’s architecture is extremely straightforward: one token corresponds to one square metre of commercial property. By acquiring tokens, an investor obtains digital confirmation of a share in the ownership right and the right to a proportional share of the income from the property's operation.

The legal complexity of this direction lies in the need to ensure a seamless link between the digital token and the ownership right registered in the state real estate register. Resolving this issue will require either recognising the token as an independent title-establishing document or creating a mechanism for automatic synchronisation between the register and the blockchain platform.

6.1.3. Tokenisation of Real-World Assets (RWA)

The third direction extends beyond real estate to encompass a broad spectrum of real-world assets (“RWA”): business equity stakes and claims arising from commercial receivables. The tokenisation of RWA enables companies to raise working capital without navigating the cumbersome procedures of traditional bank lending.

The economic logic of this direction is clear: a significant portion of Kazakh business assets - accounts receivable, trade claims, stakes in non-public companies, remains illiquid precisely due to the absence of infrastructure for their circulation. Tokenisation creates such infrastructure, transforming illiquid assets into tradable digital instruments.

From a regulatory perspective, the key question is the classification of RWA tokens: are they securities (with corresponding prospectus and registration requirements), other financial instruments, or a separate category of digital assets? The answer to this question will predetermine the applicable supervisory regime and requirements for market participants.

6.1.4. Legal Cryptocurrency Exchange (Crypto Cards)

The fourth direction is dedicated to assessing the risks associated with converting traditional money into unbacked digital assets. It is within this direction that commercial bank crypto cards linked to balances on AIFC crypto-exchanges are being tested. The key objective is the legalisation of digital assets for the broad consumer and the removal of retail investors from the “grey zone”.

In this context, a crypto card functions as a bridge between the traditional banking system and the digital asset ecosystem: the cardholder gains the ability to fund an account on an AIFC crypto-exchange through a familiar banking interface and pay for goods and services with converted funds. At the same time, the bank serves as the KYC/AML checkpoint, ensuring that transactions comply with financial monitoring requirements.

The regulatory complexity of this direction stems from the volatility of unbacked crypto-assets and the need for adequate risk disclosure to retail consumers. Resolution No. 42 requires pilot participants to develop risk warning standards and establish limits on transactions involving unbacked assets.

6.2. Digital Tenge (CBDC) Implementation Projects
 
In parallel with the development of the private crypto-market, the National Bank is consistently implementing its own state project in the field of central bank digital currencies. The Digital Tenge is being designed as programmable money with built-in targeted use restrictions - a quality fundamentally unattainable within the traditional monetary system.

6.2.1. Government Procurement and Infrastructure Financing Block

The first and most extensive application of the Digital Tenge covers the financing of infrastructure projects: road construction, modernisation of public utility facilities, and government procurement of medical and IT equipment.

The operating model differs fundamentally from traditional budget financing. State-allocated funds are credited through the National Bank's blockchain platform in the form of programmable tokens, which technically cannot be used other than for their intended purpose. The smart contract automatically blocks any attempt to transfer funds to accounts not linked to a specific contract or category of expenditure.

By the end of 2025, the volume of Digital Tenge issuance had exceeded KZT 336 billion. This is comparable to the volumes that central banks in other countries consider the threshold of “systemic significance” for CBDC pilots.

The legal and practical value of this model is exceptionally high. The misappropriation of budget funds is one of the most acute problems in public administration. The Digital Tenge offers a technological solution that makes misappropriation physically impossible, not merely legally prohibited: the smart contract acts as a “built-in controller” requiring neither supervisory resources nor procedural costs.

6.2.2. Social Block: Targeted Assistance Through Digital Vouchers

The second CBDC pilot direction concerns the system of targeted social assistance. Funds disbursed to citizens are programmed as digital vouchers with a limited range of permissible uses: food products, medicines, and payment for educational services.

This model addresses the long-standing problem of “dilution” of social assistance: disbursed funds are often spent on purposes inconsistent with the intended purpose of the payment. The Digital Tenge in the form of a targeted voucher technically ensures that social assistance reaches its recipients in precisely the form intended by the legislator.

At the same time, this model raises serious questions in the area of human rights and the dignity of recipients. The programmable restriction on the use of funds effectively deprives citizens of autonomy in managing their own income, even where state assistance is concerned. The ethical dimension of the issue requires careful assessment: the line between “targeting” and “paternalism” in this context is not self-evident.

From a legal standpoint, it is also necessary to assess the compatibility of the voucher model with constitutional guarantees of property rights: upon the voucher being credited to the recipient's account, does the recipient acquire ownership of the funds and, if so, is it permissible to restrict that right on a targeted basis? The answer to this question remains the subject of doctrinal debate.

7. CONCLUSION AND DEVELOPMENT PROSPECTS

In conclusion, it can be stated that by 2026 Kazakhstan had developed a distinct model for regulating artificial intelligence in the financial sector, based on the principle of technological neutrality. The National Bank and ARDFM do not seek to impose administrative restrictions on the choice of specific architectural solutions. Instead, the regulators primarily focus on overseeing the outcomes of technology deployment and ensuring non-discriminatory access of market participants to infrastructure.

The central constraining and guiding instrument in this framework is the Digital Code of the Republic of Kazakhstan, together with the specialised AI Law and personal data legislation. These legislative acts establish a robust framework for the protection of consumer rights, comprising three fundamental elements: unconditional data sovereignty, preventing the uncontrolled transfer of bank secrecy outside the national jurisdiction, the prohibition of discriminatory practices, ranging from social scoring to biometric classification, and the right to transparency, implemented through mandatory labelling of synthetic content. Accordingly, the protection of citizens’ interests does not impede technological development, but rather establishes clear legal boundaries within which such development may take place.

Kazakhstan’s approach demonstrates that consistent risk-based regulation, supported by meaningful sanctions for non-compliance, can move the market from a stage of fragmented experimentation towards the deliberate development of reliable and accountable AI systems. The resulting balance between openness to innovation and digital sovereignty is of practical relevance to other jurisdictions across the Eurasian region facing similar challenges at the intersection of financial regulation and technological progress.

 

SOURCES

1. “The Data Center Valley in Kazakhstan: What It Is and Why It Matters” URL: https://akashi.cloud/ru/resources/guide/valley-of-data-centers-kazakhstan/; “Kazakhstan Enters the World’s Top 100 Supercomputers” URL: https://www.gov.kz/memleket/entities/maidd/press/news/details/1107339?lang=ru

2. “Racing Ahead: How Kazakhstan Became a Global Leader in AI Adoption” // Ulysmedia.kz. URL: https://ulysmedia.kz/analitika/79455-gonka-na-operezhenie-kak-kazakhstan-stal-mirovym-liderom-po-vnedreniiu-ii/

3. “10 Fintech Industry Trends and Facts in Kazakhstan” // Digitalbusiness.kz. 14 November 2025. URL: https://digitalbusiness.kz/2025-11-14/10-trendov-i-faktov-finteh-industrii-kazahstana/.

4. “2026 Declared the Year of Digitalisation and AI Development in Kazakhstan” // Ito.qr-pib.kz. URL: https://ito.qr-pib.kz/ru/p/53910.

5. “339 Billion Digital Tenge Issued in Kazakhstan” // 24.kz. URL: https://24.kz/ru/news/economyc/776843-339-milliardov-tsifrovykh-tenge-vypustili-v-kazakhstane.

6. “ARDFM to Take Up Regulation of Fintech and Telecom Companies” // Kursiv.media. 14 November 2025. URL: https://kz.kursiv.media/2025-11-14/fvfv-arrfr-budet-regulirovat-kompanii-kotorye-vydayut-kredity-no-ne-soblyudayut-trebovaniya/.

7. ARDFM. “Banking Sector Policy for 2025: Managing Model Risk and AI Risk” // Bizmedia.kz. 6 March 2025. URL: https://bizmedia.kz/2025-03-06-arrfr-budet-kontrolirovat-ispolzovanie-bankami-ii/.

8. “AI Law Enters into Force in Kazakhstan” // Gov.kz (Ministry of Digital Development, Innovations and Aerospace Industry). 18 January 2026. URL: https://www.gov.kz/memleket/entities/maidd/press/news/details/1143060?lang=ru.

9. “Kazakhstan Launches Real-Estate Tokenisation Pilot: How It Works” // Kursiv.media. URL: https://kz.kursiv.media/2026-02-11/zhzh-v-kz-zapustili-pilot-po-tokenizacii-nedvizhimosti/.

10. “Kazakhstan to Pilot the Digital Tenge for Controlling State Spending” // Kursiv.media. URL: https://kapital.kz/economic/149395/v-kazahstane-protestiruyut-cifrovoj-tenge-dlya-kontrolya- gosrashodov.html.

11. “Kazakhstan to Create a Digital Data-Analytics Platform to Combat the Shadow Economy” // Primeminister.kz. 14 January 2026. URL: https://primeminister.kz/ru/news/v-kazaxstane-sozdadut-cifrovuiu-platformu-analitiki-dannyx-dlia-borby-s-tenevoi-ekonomikoi-30962.

12. “Halyk Bank Explains How It Uses Robots” // Digitalbusiness.kz. 6 February 2025. URL: https://digitalbusiness.kz/2025-02-06/mi-stali-masterami-sporta-po-robotizatsii-top-menedzher-halyk-bank-ob-ispolzovanii-robotov-i-perspektivah-ii-v-otrasli/.

13. “Will Banking Services Return Offline Amid Rising AI Fraud in Kazakhstan?” // Zakon.kz. 15 April 2026. URL: https://www.zakon.kz/obshestvo/6514607-vernut-li-bankovskie-uslugi-v-oflaynformat-na-fone-rosta-iimoshennichestva-v-kazakhstane.html.

14. “Attention, Fraudsters: How Digital Crime Is Changing” // 24.kz. URL: https://24.kz/ru/news/polezno-znat/761072-vnimanie-moshenniki-kak-menyaetsya-tsifrovaya-prestupnost.

15. “The Year of Digitalisation and AI in Kazakhstan: How the New AI Law and Financial Regulation Are Changing the Game for Banks and Big Tech” // Toppress.kz. 15 February 2026. URL: https://toppress.kz/article/god-cifrovizacii-i-iskusstvennogo-intellekta-v-kazahstane-kak-novii-zakon-ob-ii-i-finregulirovanie-menyayut-igru-dlya-bankov-i-bigtech.

16. “The Year of Digitalisation and AI: Kazakhstan Accelerates Its Digital Leap” // El.kz. 5 March 2026. URL: https://el.kz/ru/god-tsifrovizatsii-i-ii-kazahstan-uskoryaet-tsifrovoy-ryvok_400044826/.

17. “The Year of Digitalisation and AI: What Is Really Changing in Kazakhstan” // Kazinform (Inform.kz). 17 January 2026. URL: https://www.inform.kz/ru/god-tsifrovizatsii-i-ii-chto-na-samom-dele-menyaetsya-v-kazahstane-c53f2a.

18. “The Year of Digitalisation and Artificial Intelligence” // Kursiv.media. 22 April 2026. URL: https://kz.kursiv.media/2026-04-22/god-czifrovizaczii-i-iskusstvennogo-intellekta/.

19. Gumar N.A. “The Impact of AI and Voice Technologies on the Efficiency of Banking Operations in Kazakhstan” // Statistics, Accounting and Audit. 2025. Vol. 4. No. 99. Pp. 167–179. DOI: 10.51579/1563-2415.2025.-4.12. URL: https://sua.aesa.kz/main/article/view/398.

20. “The AI Law in Kazakhstan: What You Need to Know” // Informburo.kz. 24 February 2026. URL: https://informburo.kz/cards/zakon-ob-ii-v-kazaxstane-cto-vazno-znat-vsem-kazaxstancam-o-pravilax-i-strafax-v-2026-godu.

21. Law of the Republic of Kazakhstan dated 21 May 2013 No. 94-V “On Personal Data and Their Protection” // Adilet Legal Information System. URL: https://adilet.zan.kz/rus/docs/Z1300000094/z13094.htm.

22. Law of the Republic of Kazakhstan dated 6 February 2023 No. 193-VII “On Digital Assets in the Republic of Kazakhstan” // Adilet Legal Information System. URL: https://adilet.zan.kz/rus/docs/Z2300000193.

23. Law of the Republic of Kazakhstan dated 17 November 2025 No. 230-VIII “On Artificial Intelligence” // Adilet Legal Information System. URL: https://adilet.zan.kz/rus/docs/Z2500000230.

24. Law of the Republic of Kazakhstan dated 16 January 2026 No. 258-VIII “On Banks and Banking Activity in the Republic of Kazakhstan” // Adilet Legal Information System. URL: https://adilet.zan.kz/rus/docs/Z2600000258.

25. “Kazakhstan Launches Its First Real-Estate Token Issuance, Apartchain” // Nazarbayev University. URL: https://nu.edu.kz/news-ru/zapushhena-pervaya-v-kazahstane-emissiya-tokenov-nedvizhimosti-apartchain/.

26. “AI in Kazakhstan: Why 2026 Will Be a Turning Point for the Country’s Digitalisation” // Tengrinews.kz. 6 January 2026. URL: https://tengrinews.kz/article/etot-god-perelomnym-eksperty-daiut-prognozy-razvitiiu-ii-3530/.

27. “Artificial Intelligence and the Digital Tenge: The Ministry of Finance Introduces New Tools to Combat the Shadow Economy” // Primeminister.kz. 7 October 2025. URL: https://primeminister.kz/ru/news/iskusstvennyi-intellekt-i-cifrovoi-tenge-minfin-vnedriaet-novye-instrumenty-dlia-borby-s-tenevoi-ekonomikoi-30583.

28. National Payment Corporation of the National Bank of the Republic of Kazakhstan. Report “Artificial Intelligence in Kazakhstan’s Financial Market: Current State, Prospects and Analysis of Regulatory Approaches”. April 2024. URL: https://prg.kz/document/?doc_id=33467322.

29. “Artificial Intelligence Against Financial Fraudsters” // Ibagroup.kz. URL: https://ibagroup.kz/insights/iskusstvennyj-intellekt-protiv-finansovyh-moshennikov/.

30. Kazakhstan Launches Its First Tenge-Pegged Stablecoin on the Solana Blockchain // Superteam. URL: https://superteam.kz/ru/highlights/esi5x9b1oy5amynb3bkfke0k/.

31. “Kazakhstani AI Developments Identify More than 15,000 Dropper Accounts” // Kapital.kz. 10 November 2025. URL: https://kapital.kz/tehnology/142208/kazahstanskie-ai-razrabotki-vyyavili-bolee-15-tysyach-dropperskih-schetov.html.

32. “How AI Is Changing Kazakhstan’s Banks: Lending, Security and the Future” // Finance.kz. 8 May 2026. URL: https://finance.kz/articles/kak-ai-menyaet-banki.

33. “How the ARDFM Will Regulate the Adoption of AI in Banks” // Prodengi.kz. URL: https://prodengi.kz/post/kak-arrfr-budet-regulirovat-vnedrenie-ii-v-bankax.

34. “How Artificial Intelligence Affects Loan Approval at Banks” // KMF.kz. URL: https://kmf.kz/news-inner/kak-iskusstvennyj-intellekt-vliyaet-na-odobrenie-kreditov-v-bankah/.

35. “How Kazakhstan Is Conquering Artificial Intelligence in 2025” // Tengrinews.kz. 20 December 2025. URL: https://tengrinews.kz/kazakhstan_news/buduschee-nastupilo-kak-myi-vlyubilis-v-ii-v-etom-godu-588387/.

36. “How Fintech Is Developing in Kazakhstan” // Banker.kz. URL: https://www.banker.kz/news/kak-razvivaetsya-fintekh-v-kazakhstane-/.

37. Code of the Republic of Kazakhstan dated 5 July 2014 No. 235-V “On Administrative Offences” // Adilet Legal Information System. URL: https://adilet.zan.kz/rus/docs/K1400000235.

38. “Major Banks Will Be Required to Use AI to Identify Droppers” // Kapital.kz. 31 March 2025. URL: https://kapital.kz/finance/135675/krupnye-banki-dolzhny-budut-ispolzovat-ii-dlya-vyyavleniya-dropperov.html.

39. “The Best Banks in Kazakhstan in 2026” // Finance.kz. 2026. URL: https://finance.kz/articles/luchshie-banki-kazahstana-v-2026-godu---reyting-sravnenie-i-kak-vybrat-bank.

40. “Kazakhstan’s Ministry of Finance Introduces AI, Big Data and the Digital Tenge into the Public Finance System” // Rus.baq.kz. 15 June 2026. URL: https://rus.baq.kz/v-minfine-rasskazali-o-masshtabnoy-tsifrovoy-transformatsii-gosfinansov-320031100/.

41. “The National Bank Reveals the Scale of the Digital Tenge Pilot” // Inbusiness.kz. URL: https://inbusiness.kz/ru/news/nacbank-raskryl-masshtaby-pilota-cifrovogo-tenge.

42. “On Approval of the Rules and Timeline for Implementing the Pilot Project to Modernise and Improve the Provision of the Public Service ‘Refund of Value-Added Tax from the Budget’ (‘Digital VAT’)”: Joint Order of the Minister of Finance of the Republic of Kazakhstan dated 16 September 2024 No. 628 and the Minister of Digital Development, Innovations and Aerospace Industry of the Republic of Kazakhstan dated 23 September 2024 No. 575/NK // Adilet Legal Information System, Reg. No. G24E0000628. URL: https://adilet.zan.kz/rus/docs/G24E0000628.

43. “Proceeds of Crime Laundered Through Drop Cards in Kazakhstan Reach 24 Billion Tenge” // Kapital.kz. URL: https://kapital.kz/gosudarstvo/133232/oborot-otmytykh-cherez-drop-karty-prestupnykh-dokhodov-v-rk-dostig-24-mlrd-tenge.html.

44. “Banks in Kazakhstan Lose Around USD 70 Million a Year to Fraudsters” // Nur.kz. URL: https://www.nur.kz/nurfin/banks/2355093-okolo-70-mln-dollarov-v-god-teryayut-banki-iz-za-moshennikov-v-kazahstane/.

45. Oralbayev Ch. “Key Aspects of the Law of the Republic of Kazakhstan ‘On Artificial Intelligence’ No. 230-VIII” // Paragraf Information System. 18 January 2026. URL: https://prg.kz/document/?doc_id=33297881.

46. “From Big Data Analysis to AI: How Bank Supervision Is Changing” // Dknews.kz. URL: https://dknews.kz/ru/finansy/386742-ot-analiza-bolshih-dannyh-do-ai-kak-menyaetsya-nadzor.

47. “The ‘Digital VAT’ Pilot Project Extended to 31 December 2026” // Pro1c.kz. URL: https://pro1c.kz/news/zakonodatelstvo/pilotnyy-proekt-tsifrovoy-nds-planiruetsya-prodlit-do-31-dekabrya-2026-goda-opublikovan-proekt/.

48. Resolution of the ARDFM Board dated 20 August 2025 No. 38 (on banking sector policy and AI risks).

49. Resolution of the Board of the National Bank of the Republic of Kazakhstan dated 11 November 2019 No. 178 “On Approval of the Rules for the Introduction and Termination by the National Bank of the Republic of Kazakhstan of a Special Regulatory Regime for Carrying Out Activities Related to Digital Assets and/or Payment Services Within a Special Regulatory Regime, of the Selection Criteria Applied by the National Bank of the Republic of Kazakhstan, and of the Rules for Reviewing Documents for Concluding an Agreement to Carry Out Activities Within a Special Regulatory Regime” // Adilet Legal Information System. URL: https://adilet.zan.kz/rus/docs/V1900019608.

50. Resolution of the Board of the National Bank of the Republic of Kazakhstan dated 25 July 2025 No. 42 “On Amendments to Resolution of the Board of the National Bank of the Republic of Kazakhstan dated 11 November 2019 No. 178” // Adilet Legal Information System. URL: https://adilet.zan.kz/rus/docs/V2500036574.

51. “Why AI in Kazakhstan’s Banking Sector Is Concentrating Among Major Players” // Fintech-retail.com. 24 February 2026. URL: https://fintech-retail.com/2026/02/24/sektor-5/.

52. “AI Regulation in the Financial Sector Will Be Built on OECD Principles” // Gov.kz (ARDFM). URL: https://www.gov.kz/memleket/entities/ardfm/press/news/details/1105035?lang=ru.

53. Joint Report of the National Bank of the Republic of Kazakhstan and the National Payment Corporation of Kazakhstan “Digital Tenge: 2025 Final Report”. URL: https://npck.kz/tsifrovoj-tenge-itogovyj-doklad-2025/ and https://npck.kz/wp-content/uploads/2026/03/DT_WP_2025_RUS_FINAL-2.pdf

54. Decree of the President of the Republic of Kazakhstan “On Approval of the Nationwide Strategy for Large-Scale Digitalisation and Comprehensive Implementation of Artificial Intelligence Technologies ‘Digital Qazaqstan’ through 2029” // Kazpravda.kz. URL: https://kazpravda.kz/n/ukaz-prezidenta-respubliki-kazahstan-02-jw/.

55. Decree of the President of the Republic of Kazakhstan dated 6 January 2026 “On Declaring 2026 the Year of Digitalisation and Artificial Intelligence” // Akorda.kz. URL: https://www.akorda.kz/ru/ob-obyavlenii-goda-cifrovizacii-i-iskusstvennogo-intellekta-601222.

56. Decree of the President of the Republic of Kazakhstan dated 7 July 2026 No. 1347 “On Measures to Stimulate and Develop the Digital Asset Industry in the Republic of Kazakhstan” // Adilet Legal Information System. URL: https://adilet.zan.kz/rus/docs/U2600001347.

57. “Rules and Timeline for the ‘Digital VAT’ Pilot Project Approved” // Inbuh.kz. URL: https://inbuh.kz/ru/news/696-utverzhdeny-pravila-i-sroki-realizatsii-pilotnogo-proekta-tsifrovoy-nds/.

58. “Digital Maturity of Kazakhstan’s Banking Sector: How Open Banking and the Digital Tenge Are Changing the Fintech Market” // Bluescreen.kz. 30 July 2025. URL: https://bluescreen.kz/tsifrovaia-zrielost-bankovskogho-siektora-v-kazakhstanie-kak-open-banking-i-tsifrovoi-tienghie-mieniaiut-fintiekh-rynok/.

59. “Central Bank Digital Currency (CBDC): From Global Challenges to Implementation in Kazakhstan”. URL: https://npck.kz/wp-content/uploads/2026/05/CBDC_ru_0505.pdf

60. Digital Code of the Republic of Kazakhstan dated 9 January 2026 No. 255-VIII // Adilet Legal Information System. URL: https://adilet.zan.kz/rus/docs/K2600000255.

61. “Digitalisation of Kazakhstan’s Financial System: Cloud Solutions for Banks and Fintech” // VK Cloud Kazakhstan (Vkcloud.kz). 23 March 2026. URL: https://vkcloud.kz/blog/ysifrovizatsiya-finansovoi-sistemi-lazakhstana-oblachnie-resheniya-dlya-bankov-i-fintekha/.

62. “VAT-Tagged Digital Tenge to Be Used in Public Procurement” // Forbes.kz. URL: https://forbes.kz/articles/tsifrovoy-tenge-s-markirovkoy-nds-budut-ispolzovat-v-goszakupkah-74af84.

63. “VAT-Tagged Digital Tenge for Public Procurement” // Zakon.kz. 28 January 2026. URL: https://www.zakon.kz/pravo/6505895-tsifrovoy-tenge-s-markirovkoy-nds-dlya-goszakupok-nachinaetsya-pilotnyy-proekt.html.

64. “The Financial Regulator Moves to Digital Supervision” // 24.kz. URL: https://24.kz/ru/news/social/740012-finregulyator-pereshel-k-tsifrovomu-nadzoru.

65. “FinTech FinEthics: Kazakhstan”. Issue No. 5 // ICT Moscow. July 2025. URL: https://ict.moscow/projects/ai/research/fintekh-finetikh-kazakhstan/.

66. “What Are Depersonalisation, Masking and Tokenisation – Is There a Difference Between These Terms?” // Cisoclub.ru. URL: https://cisoclub.ru/chto-takoe-obezlichivanie-maskirovanie-i-tokenizacija-est-li-raznica-v-jetih-terminah/.

67. “What Is a Gateway? An Easy-to-Understand Explanation” // Alotceriot.com. URL: https://www.alotceriot.com/ru/%D1%87%D1%82%D0%BE-%D1%82%D0%B0%D0%BA%D0%BE%D0%B5-%D1%88%D0%BB%D1%8E%D0%B7%D1%88%D0%BB%D1%8E%D0%B7-alotcerоpredelenie-%D1%88%D0%BB%D1%8E%D0%B7/.

68. “What Are Security Gateways and What Functions Do They Perform” // Dtu.kz. URL: https://www.dtu.kz/blog-post/chto-takoe-shlyuzy-bezopasnosti-i-kakie-funkczii-oni-vypolnyayut/.

69. “The Era of ‘Smart’ Money” // Znamya Truda, Zhambyl Regional Newspaper. URL: https://ztgzt.kz/88670/era-umnyh-deneg.

70. AirAsia MOVE, Intebix and Solana Explore Stablecoin Integration in Kazakhstan // Kursiv.media. URL: https://kapital.kz/finance/148467/airasia-move-intebix-i-solana-izuchayut-integraciyu-stejblkoinov-v-kazahstane.html.

71. “AI Credit Scoring in 2026: 7 Rules Under EU AI Act” // Decodethefuture.org. 19 April 2026. URL: https://decodethefuture.org/en/ai-credit-scoring/.

72. “EU AI Act for FinTech: Is Your Credit Scoring System High-Risk?” // Euaiact.pro. 24 February 2026. URL: https://euaiact.pro/en/blog/ai-act-fintech/.

73. “EU AI Act Impact on FinTech: Credit Scoring High-Risk AI” // Letsaskclaire.com. 25 February 2026. URL: https://www.letsaskclaire.com/finance/eu-ai-act-fintech.

74. “Freedom Finance – The Largest Fintech Business in Central Asia” // Habr.com. URL: https://habr.com/en/articles/890578.

75. Global ESG Risk Survey 2025: Kazakhstani Banks // KPMG. 2025. URL: https://assets.kpmg.com/content/dam/kpmg/kz/pdf/2025/10/2025-KPMG-Global-ESG-Risk-Survey-Kazakh-Banks-rus.pdf.

76. “Halyk Bank Actively Applies Artificial Intelligence in Banking” // LSM.kz. URL: https://lsm.kz/halyk-bank-aktivno-primenyaet-iskusstvennyj-intellekt-v-bankinge.

77. Kaspi.kz – Financial Information // Investor Relations, Kaspi.kz. URL: https://ir.kaspi.kz/financial-information/.

78. “Mastercard Transforms the Fight Against Fraud with the Latest Artificial Intelligence Technology” // Mastercard.com. 24 April 2024. URL: https://www.mastercard.com/uz/ru/news-and-trends/press/2024/april/mastercard-transforms-the-fight-against-scams-with-latest-ai-tech1.html.

79. Open API, Open Banking // Official Website of the National Bank of the Republic of Kazakhstan. URL: https://nationalbank.kz/ru/page/Digital-Financial-Infrastructure.

80. Open API and Open Banking: Results of the Pilot Project // National Bank of the Republic of Kazakhstan. 5 January 2024. URL: https://nationalbank.kz/file/download/97962.

81. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). 27 April 2016. URL: https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng.

82. Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets, and amending Regulations (EU) No 1093/2010 and (EU) No 1095/2010 and Directives 2013/36/EU and (EU) 2019/1937. 31 May 2023; URL: https://eur-lex.europa.eu/eli/reg/2023/1114/oj/eng.

83. Regulation (EU) 2024/1689 of the European Parliament and of the Council (EU AI Act). 12 July 2024. URL: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1689.

84. “Features of the Legal Regulation of the AIFC” // Akyl-kenes.kz. 25 March 2019. URL: https://akylkenes.kz/cases/osobennosti-pravovogo-regulirovaniya-mfcza/.

85. AIFC Data Protection Regulations No. 10 of 2017 // Official Website of the AIFC. URL: https://aifc.kz/legal-framework/aifc-data-protection-regulations/.

86. AIFC Data Protection Rules No. 1 of 2018 // Official Website of the AIFC. URL: https://aifc.kz/legal-framework-cat/data-protection/.

87. Law of the Republic of Kazakhstan dated 24 November 2015 No. 418-V “On Informatisation” // Adilet Legal Information System. URL: https://adilet.zan.kz/rus/docs/Z1500000418.

88. “Guidance on Data Protection and Artificial Intelligence in the AIFC” // Official Website of Ernst & Young (EY). 20 February 2025. URL: https://www.ey.com/en_kz/technical/tax-alerts/ey-guidance-on-data-protection-and-artificial-intelligence-in-the-aifc.

89. “AFSA Publishes Report on the Use of Generative AI in Financial Services in the AIFC” // Official Website of the AIFC. 25 December 2025. URL: https://aifc.kz/ru/novosti/afsa-opublikoval-otchet-o-primenenii-generativnogo-ii-v-finansovyh-uslugah-v-mfcza/.

90. Law of the Republic of Kazakhstan dated 21 May 2013 No. 94-V “On Personal Data and Their Protection” // Adilet Legal Information System. URL: https://adilet.zan.kz/rus/docs/Z1300000094.

91. “Deepfake and the Law in Astana 2026: How to Protect Your Reputation” // Femida Justice. 2026. URL: https://femida-justice.com/uslugi/yurist-po-kriptovalyute/yuridicheskaya-otvetstvennost-za-deepfake-zashhita-v-2026/.

92. “Kazakhstan Introduces Administrative and Criminal Liability for the Unlawful Use of Artificial Intelligence” // UAPZ.kz. 23 January 2026. URL: https://www.uapz.kz/v-kazahstane-vvoditsya-administrativnaya-i-ugolovnaya-otvetstvennost-za-nezakonnoe-ispolzovanie-iskusstvennogo-intellekta/.

93. “Kazakhstan Seeks to Connect an AI Assistant for Judges to Administrative Cases” // BES.media. 17 August 2026. URL: https://bes.media/news/ii-pomoschnika-dlya-sudey-hotyat-podklyuchit-k-administrativnym-delam-v-kazahstane/.

94. “Artificial Intelligence Deployed in All Courts of Kazakhstan: What It Can Do” // Ak Zhayik. 26 May 2026. URL: https://azh.kz/ru/news/view/128243.

95. “Artificial Intelligence Reviewed 665,000 Court Cases in Kazakhstan” // Kursiv.media. 21 January 2025. URL: https://kz.kursiv.media/2025-01-21/smrd-aisud/?utm_source=google.com&utm_medium=organic&utm_campaign=google.com&utm_referrer=google.com.

96. “How AI Is Rewriting the Rules of Copyright in Kazakhstan” // Forbes.kz. 19 January 2026. URL: https://forbes.kz/articles/kak-ii-perepisyvaet-pravila-avtorskogo-prava-v-kazahstane.

97. “The AIFC Court Deploys AI and Changes Global Judicial Practice” // 24.kz. 20 December 2025. URL: https://24.kz/ru/news/social/745815-sud-mftsa-vnedril-ii-i-izmenil-mirovuyu-sudebnuyu-praktiku.

Kazakhstan
Banking & Finance Technology, Media & Telecommunications Data Protection & Privacy