Go to Content
RUEN中文

Information security21 min of readingAuthor: The SystemsLab command

Is it possible to upload client data to ChatGPT and other neural networks?

Employees are increasingly inserting customer uploads into ChatGPT and Claude. Let's look at what 152-FZ says about this, what fines are in effect from May 30, 2025, and how to use AI without sending data to someone else's cloud.

Небольшая серверная стойка в офисе, на переднем плане руки менеджера за ноутбуком с открытым чатом нейросети

Briefly

  • It is risky to insert full names, phone numbers, subscriptions and medical marks of clients into ChatGPT, Claude and other foreign neural networks. The data goes to foreign servers, and from July 1, 2025, 152-FZ prohibits the collection of Russians' data from storing and processing them in foreign databases. There is no official explanation of how this applies to AI chats yet.
  • From May 30, 2025, the company's fine for personal data leakage ranges from 3 to 20 million rubles, for repeated leakage — up to 3% of revenue, but not more than 500 million rubles.
  • According to "Solar", in the first half of 2026, about 38% of calls from employees of Russian companies to public AI services contained confidential data.
  • There are three working options: rules for employees, a Russian cloud model under a contract with disabled logging, or your own model on your server.
  • The local model is also considered an information system of personal data, so it needs to be protected according to the same rules as CRM and the accounting system.

The fitness club administrator asks the neural network to compose a polite letter to the debtor and inserts an upload into the chat: last name, phone number, subscription number, amount of debt. The manager of the thermal spa complex loads the guest table so that the AI will divide them into segments for distribution. Both want to save half an hour and hardly think where the data will end up.

Let's look at what the law says for September 2026 and how to use neural networks without risk.

What is private AI?

A private AI is a neural network that processes your data in a circuit controlled by you: on your server or at a Russian provider under a contract that specifies who stores requests and how. The opposite of it is a public chatbot, where an employee logs in from a personal account.

Other concepts that will be needed next:

  • Personal data (PD) is any information that can be used to identify a person: full name, phone number, customer card number, photo, visit history.
  • ISPDn is an information system of personal data, that is, any program or database where such data is stored and processed: 1C, CRM, club accounting system and neural network on your server too.
  • Cross—border transfer is the transfer of personal data to the territory of another state, for example, to the servers of a foreign AI service.
  • The local model is a neural network whose files are downloaded and run on your own hardware. Requests to it do not go beyond your network.

Is it possible for employees to upload customer data to ChatGPT or Claude?

The short answer is: do not upload personal customer data there. There are three reasons: the localization law, fines for leaks, and how the services themselves store correspondence.

The first reason is that the services do not officially work with Russia. Russia and Belarus are not included in the list of countries where OpenAI supports the API. The company explicitly warns that access from other countries may result in account blocking. Russia is not in the list of supported countries of Anthropic either for the API or for Claude.ai . This means that employees log in via VPN or intermediaries, and the company does not have a contract that describes what happens to the data.

The second reason is the fact of sending. When the last name with the phone goes into the chat, the data ends up on servers abroad. We did not find a direct explanation from Roskomnadzor specifically about AI chats. Many lawyers consider such a shipment to be a cross-border transfer with all the ensuing responsibilities, and it is safer to proceed from this.

The third reason is that services store correspondence and sometimes learn from it.

Impersonal tasks are easier. You can ask the neural network to rewrite the text of the action, explain the formula in Excel, or create a letter template without names without these risks if there are no clients or trade secrets in the request.

What does 152-FZ say about data storage abroad?

Since July 1, 2025, the law prohibits the collection of data of Russian citizens to record and store them in foreign databases. Amendments were made by Law No. 23-FZ of 02/28/2025. Now Part 5 of Article 18 152-FZ sounds like a ban: when collecting personal data of Russians, their recording, systematization, accumulation, storage and retrieval " using databases located outside the territory of the Russian Federation are not allowed" (review of the "Lidings" law firm).

At the same time, the law does not prohibit transferring data that was first collected to the Russian database abroad. So, according to the retelling comply.ru The new norm is interpreted by Roskomnadzor (letter dated 03/24/2025 No. 08-134789) and the Ministry of Finance (letter dated 05/12/2025 No. P25-44929). But such a transfer has conditions. According to Article 12 152-FZ, the operator notifies Roskomnadzor in advance and indicates:

  • purpose and legal basis of the transfer;
  • categories of transmitted data;
  • countries where the data goes;
  • the results of an assessment of how the recipient protects the data.

How these rules apply to AI chats has not been officially explained: the letters from Roskomnadzor and the Ministry of Digital Services relate to localization in general, not neural networks. If we consider sending data to a foreign neural network as a cross-border transfer, the company needs a notification, a basis (as a rule, the client's consent) and an assessment of a foreign service. If the client's data immediately enters a foreign service, bypassing the Russian database, there is a risk of violating part 5 of Article 18. When an employee copies a table to a chat from his phone, the company usually has none of this. The specific scheme should be checked with a lawyer.

The fine for violation of localization for a legal entity under part 8 of Article 13.11 of the Administrative Code is from 1 to 6 million rubles, for repeated violation — from 6 to 18 million rubles.

What penalties for the leakage of personal data are in effect in 2026?

From May 30, 2025, companies pay from 3 to 20 million rubles for a leak, and a turnover fine for a second one. The amounts were introduced by Law No. 420-FZ of 11/30/2024 (ConsultantPlus review), they are recorded in Article 13.11 of the Administrative Code.

Violation (for legal entities)Part of Article 13.11 of the Administrative CodePenalty
Data leakage from 1 to 10 thousand peoplePart 123-5 million rubles.
Data leakage from 10 to 100 thousand peoplePart 135-10 million rubles.
Data leakage of more than 100 thousand peoplePart 1410-15 million rubles.
Leakage of special categories (for example, health information)Part 1610-15 million rubles.
Biometrics LeakPart 1715-20 million rubles.
Repeated leakagePart 151-3% of revenue, from 20 to 500 million rubles.
Repeated leakage of special categories or biometricsPart 181-3% of revenue, from 25 to 500 million rubles.
Did not notify Roskomnadzor about the leakPart 111-3 million rubles.

For fitness clubs and thermal baths, the line about special categories is important. Health information, such as contraindications in the guest questionnaire or doctor's notes, refers specifically to them. If the club is logged in by person, this data is most likely biometric.

A turnover penalty is imposed not for any leakage, but only for repeated. The courts are already applying the new rules: according to "Garant", in March 2026, the Arbitration Court of Moscow and the Court of St. Petersburg and the Leningrad Region made the first decisions on major leaks.

There is also a criminal side. Since December 11, 2024, Article 272.1 of the Criminal Code of the Russian Federation has been in effect: if illegally obtained personal data has been transferred abroad, it faces up to 8 years in prison (part 4). The article is directed against trading in merged databases, and not against an employee who mistakenly inserted a table into a chat.

The leaks have not gone away. According to Roskomnadzor, 118 leaks of personal data databases were recorded in 2025, there were more than 52 million records in them.

How does customer data leak through AI chats?

Most often, the data goes away not because of hacking, but because the employee himself inserted it into the request. Studies from 2025-2026 show that this is a massive phenomenon.

  • According to "Solar" ( "Rostelecom" Group of Companies), in 2025, Russian companies sent 30 times more corporate data to public AI services than a year earlier. We studied the traffic of 150 organizations, and about 60% of them do not have a formal policy for working with AI.
  • In the first half of 2026, "Solar" sorted out 12 thousand employee requests to neural networks. About 38% of them contained confidential data. Of these, 30% accounted for personal, financial and other sensitive data, 41% — for program code and settings, 11% — for passwords and access tokens.
  • The American company Cyberhaven in a report for 2026 counted sensitive data in 39.7% of AI calls. On average, an employee enters such data once every three days. 32.3% of ChatGPT usage and 58.2% of Claude usage go through personal accounts.

It happens that correspondence becomes public without any malicious intent. In the summer of 2025, shared links to ChatGPT dialogs began to appear in Google and Bing search results. On July 31, 2025, OpenAI removed this feature and admitted that it created too many opportunities to accidentally share too much.

Correspondence can also be requested through the court. In the New York Times dispute with OpenAI, on January 5, 2026, the judge confirmed the company's obligation to transfer 20 million impersonal ChatGPT logs to the plaintiffs.

Are ChatGPT and Claude trained on your data?

In free and personal paid tariffs — by default, yes, until the user himself disables this setting. There is no default in business rates and APIs.

ProductTraining on default dataHow much data is stored
ChatGPT Free, Plus, ProUsed until the user disables the "Improve the model for everyone" setting (OpenAI help)
Claude Free, Pro, MaxUsed if the user has not opted out (Anthropic, 08/28/2025)5 years with consent to study, 30 days without it
ChatGPT Business, Enterprise, OpenAI APIDisabled; for API — from 03/01/2023 (OpenAI documentation)API — up to 30 days to control abuse
Claude for Work, APIDisabled, except for reviews that the user sent himself (help Anthropic)

A paid subscription by itself does not protect. If a Plus or Pro user has not logged into the settings, their dialogs can be used to train the model. OpenAI writes that in services for individuals it can train models on user content, and Malwarebytes clarifies that the setting is enabled by default. In addition, the business tariffs and APIs of these companies are officially unavailable to Russian legal entities, so this option is closed for a company in Russia.

Has the AI Law of 2026 banned ChatGPT in Russia?

No, there is no direct prohibition in the law. Law No. 243-FZ " On Supporting the Development of Artificial Intelligence Technologies in the Russian Federation" was signed on July 26, 2026. The basic rules apply from September 1, 2026 (Habr), and the rules on sovereign and national models — from March 1, 2027.

The law introduces the concepts of "sovereign" and "national" models: data for them must be processed in Russia by Russian legal entities. The government will be able to identify objects, primarily state information systems, where only such models are allowed. There is no obligation for private business to use only Russian models in the sources we have verified.

In the March project of the Ministry of Finance, the restrictions were tougher. Then it was proposed to limit "cross-border AI technologies" from September 1, 2027, and ChatGPT, Claude and Gemini fell under this definition. According to available data, these restrictions were not included in the final edition. But the main thing for business does not change from this: the law on personal data operates independently of the law on AI.

What are the rules for working with neural networks to introduce for employees?

We need a short written policy: what can be sent to neural networks, what is not allowed and what services to use. According to "Solar", about 60% of companies do not have such a policy, although this is the cheapest measure of all.

Checklist for policy:

  1. List the prohibited data: full names and contacts of clients, card and subscription numbers, health information, photos, downloads from 1C and the accounting system, contracts with details, passwords and access.
  2. Name the allowed services and ban personal accounts for work tasks.
  3. Explain how to depersonalize data: instead of "Ivanova Maria, +7..." write "client A". Neural networks do not need a surname to compose a letter.
  4. Appoint a responsible person to whom the employee can come with the question " can I send this?".
  5. Familiarize employees with the signature policy and add it to the instructions for beginners.
  6. Check the technical side: leak protection systems (DLP) and traffic filtering are able to track access to public AI services.

If an employee needs an assistant, but there is no legal option, they will open a chat on their phone. Therefore, together with the policy, it is worth giving an authorized tool. This is a cloud model by agreement or its own model on its own server.

We draw up such a policy together with a risk assessment as part of information security work.

Are Russian cloud neural networks safe?

They remove the issue of a foreign database, but the data is still transferred to a third party. Therefore, we need a contract and the right settings.

For example, Yandex claims that the Yandex Cloud platform complies with the requirements of 152-FZ and provides the first, most stringent level of personal data security (UZ-1). But the Yandex AI Studio documentation says: " By default, models save all query data", and this data is used to improve the service. Logging is disabled by a separate parameter "x-data-logging-enabled: false", and Yandex itself advises you to do this if the requests contain personal or confidential data.

What to check before connecting any cloud model:

  • is there a contract with a legal entity and an order for the processing of personal data;
  • in which country and in which data center requests are processed;
  • are requests logged and are they used to learn how to disable this;
  • what level of security does the provider confirm;
  • what happens to the data after the termination of the contract.

We did not find direct answers to these questions on the GigaChat API from Sber on the documentation review page, so they should be clarified with the provider before signing the contract.

Руки инженера устанавливают графический ускоритель в серверное шасси
For your neural network, the main thing is the video memory of the accelerator. According to our estimates, models with 30 billion parameters in compressed form need about 24 GB, and 70 billion — about 48 GB.

Is it possible to install a neural network on your server?

Yes. In 2025-2026, many models with open weights were released, that is, with files that can be downloaded and run at home without accessing someone else's cloud. Requests to such a model do not leave your network.

There are several open models that are worth considering for September 2026. The quality of the answers in Russian is different for them, so check the model on your tasks before purchasing equipment:

ModelDeveloperSizeWhat is important
YandexGPT 5 Lite 8B InstructYandex8 billion parametersThe compressed file weighs 4.92 GB, runs through Ollama and llama.cpp . Own license, with restrictions
T-Pro 2.0"T-Technologies"32 billionApache 2.0 license, released on 07/18/2025
Qwen3.8-27BAlibaba27 billionApache 2.0 license, works with images, was released on 08/14/2026
GigaChat 3.5 UltraSberVery large, by the name of the repository about 432 billionOpen weights from 07/06/2026. Too heavy for an office server

Before launching, read the license: not all models allow commercial use without restrictions.

Its own model covers tasks well, in which personal data cannot be dispensed with. These are answers to the administrator on the client's history, analysis of appeals, drafts of letters to debtors, search for internal regulations. Based on this model, you can also assemble an AI agent that works with data from 1C and the accounting system without sending them outside.

What hardware is needed for a local neural network?

The main parameter is the amount of video memory of the graphics accelerator: the model must fit completely into it, and you also need a stock. Models are usually compressed (quantized), that is, they store numbers with less accuracy. So the model takes up several times less memory at the cost of some loss of accuracy.

File sizes according to the Ollama catalog: the 8 billion-parameter Qwen3 model occupies 5.2 GB in 4-bit compression and 16 GB without compression. Qwen3 by 32 billion in compressed version is 20 GB by default. Llama 3.3 by 70 billion takes 43 GB in 4-bit compression and 141 GB without compression. According to the Hugging Face documentation, the model may need up to 20% of memory in excess of its own size to work, and long documents in the request increase consumption even more.

Below is our benchmark calculated from this data. This is a SystemsLab estimate, not a manufacturer's specification: the exact amount depends on the model, the compression method, the length of the context and the number of simultaneous requests.

Model sizeVideo memory (reference point, our estimate)For what tasks
7-8 billion, 4 bitsabout 6-8 GBDrafts of letters, classification of requests, simple responses by template
7-8 billion, 8 bitsabout 10-12 GBThe same, with more precise wording
about 30 billion, 4 bitsabout 24 GBAnswers to regulations, document analysis, AI agent for staff
70 billion, 4 bitsabout 48 GB: two 24 GB cards or one 48 GBComplex reasoning, long documents
70 billion without compressionfrom 160 GBServer class, usually redundant for small businesses

If several employees use the model at the same time, you need more memory and computing power: each request takes up its own part. Therefore, the configuration is considered to match the number of users and the typical length of requests.

In addition to the accelerator, the server needs sufficient RAM, fast SSD, backup power and cooling. A server with several accelerators heats up and makes noise, so it needs a server room with normal ventilation, not a utility room next to the reception.

Do I need to protect the local neural network as ISPDn?

Yes. If the model processes clients' personal data, it becomes part of the personal data information system, and the requirements of the law apply to it in the same way as to CRM.

The basic rules are set by Government Decree No. 1119 of 01.11.2012. It establishes 3 types of threats and 4 levels of security. The level is selected by threat type, data category, and number of people in the database. Specific measures for each level are listed in FSTEC Order No. 21 dated 02/18/2013. Since March 1, 2026, a separate FSTEC order No. 117 has been in force for government systems, in which, according to available data, there are provisions on AI. It does not directly concern private business, but it shows where the requirements are moving.

In practice, for a local model, you need:

  • restrict access: the model is accessible only from the internal network and only to the right employees, everyone has their own account;
  • keep a log of requests and keep it protected, because it also contains personal data;
  • give the model access only to the data that is needed for the task, and not to the entire customer database;
  • update the system and encrypt disks;
  • set up backup and check recovery;
  • to reflect the new system in the documents on personal data and, if necessary, in the notification of Roskomnadzor.

The legal side depends on what data, whose and for what purpose you are processing. This article is not legal advice: a specific data processing scheme with a neural network should be checked with a lawyer.

Where to start a company that wants to use AI without risk?

Start with an inventory: find out which neural networks employees already use and which data goes there.

  1. Interview department managers and check traffic logs: which AI services are used and for which tasks personal data is needed.
  2. Approve the policy: what is prohibited, which services are allowed, and who is responsible.
  3. For tasks without personal data, select the cloud service under the agreement and disable logging.
  4. For tasks with personal data, run a local model pilot in one department or one facility.
  5. If the pilot was justified, implement the solution and protect it as ISPDn.

How we do it

  1. Audit: what data goes into the neural network

    We look at what AI services employees use, what data gets there and where personal customer data is stored: in 1C, accounting system, CRM. We assess the risks and the level of security.

    Risk map and list of tasks for which AI is needed

  2. Circuit selection and pilot

    For each task, select the option: cloud model by contract or your own model on the server. We check the models for your real tasks and consider the necessary equipment for the number of users.

    Proven model and calculation of server configuration

  3. Implementation and protection

    We prepare the server room, install and configure the server with accelerators, connect the model to the necessary systems. We configure accesses, logs, backup, and ISPDn protection measures.

    A working private AI inside your network

  4. Policy and staff training

    We help you create rules for working with neural networks, explain to employees what can be sent and how to depersonalize data, and show you how to use the allowed tool.

    Employees know the rules and use a safe service

  5. Support

    We update the system and models, monitor the load and security, and finalize scenarios when new tasks appear.

    The system works stably and grows with the tasks

Discuss the task

Let's check where your customers' data goes

Tell us what neural networks employees use and what data they send there. We will propose a secure scheme: rules, a Russian cloud model, or our own model on the server.

What will happen after the application

  1. We will respond within a working day
  2. Let's clarify the task and limitations
  3. We will offer a solution and pilot terms

Is it more convenient in the messenger?

+79262103289Employees respond from 9:00 to 23:00 Moscow time, every day

We will answer where it is more convenient for you

Diagram, photo, or technical specification — up to 10 MB

We use contacts only to respond to a request

Frequent questions

Is it possible to upload a customer database to ChatGPT?

You should not do this. From July 1, 2025, 152-FZ prohibits the collection of Russians' data from storing them in foreign databases, and the transfer of data already collected abroad requires notification of Roskomnadzor, the legal basis and the recipient's assessment. There is no official explanation about AI chats, so it is safer to consider such a shipment as a cross-border transfer. In addition, OpenAI does not officially support Russia, and the company will not have a data processing agreement.

What kind of fine does a company face for leaking personal data in 2026?

Since May 30, 2025, a legal entity pays from 3 to 20 million rubles for a leak, depending on the number of victims and the category of data. For repeated leakage, a turnover fine is imposed — 1-3% of revenue, but not less than 20 or 25 million and not more than 500 million rubles. For failure to notify Roskomnadzor about the leak — from 1 to 3 million rubles.

Was ChatGPT banned in Russia by the AI law?

No, it's not. Law No. 243-FZ on supporting the development of AI was signed on July 26, 2026 and does not contain a direct ban on foreign services. It introduces "sovereign " and "national" models (these norms have been in effect since March 1, 2027), which the state will be able to demand primarily in state systems. The rules on personal data apply independently of the law on AI.

Does ChatGPT learn from data if I have a paid subscription?

In the ChatGPT Free, Plus and Pro personal tariffs, OpenAI can train models on dialogs until the user disables the "Improve the model for everyone" setting in the Data Controls section. Claude's Free, Pro and Max chats are also used for training, if the user has not refused. By default, business rates and APIs are not trained, but logs are stored in them for some time.

Is it safe to use Russian cloud neural networks for customer data?

They solve the problem of a foreign database, but the data still goes to a third party. We need a contract with an order for processing personal data and checking settings. For example, Yandex AI Studio saves query data by default to improve the service, and logging should be disabled using a separate parameter.

What hardware is needed to run a neural network on your server?

The main thing is the video memory of the graphics accelerator. According to our estimates, models with 7-8 billion parameters in compressed form have 6-8 GB, models with 30 billion — about 24 GB, models with 70 billion - about 48 GB. If several people use the model at the same time, more memory is needed, and the server needs cooling and backup power.

Do I need to protect the local neural network under 152-FZ?

Yes, if it processes personal data. Such a neural network becomes part of the personal data information system, and Government Decree No. 1119 and FSTEC Order No. 21 apply to it. We need access restrictions, secure logs, backup and reflection of the system in personal data documents.

Sources

  1. Federal Law No. 152-FZ of 27.07.2006 "On Personal Data", Article 12 — ConsultantPlus, edition of 26.07.2026.
  2. Changes in the requirements for the localization of personal data — "Lidings", 03/25/2025.
  3. Localization and cross-border transfer of personal data — comply.ru , 07/25/2025.
  4. Code of Administrative Offenses of the Russian Federation, Article 13.11 — ConsultantPlus, current edition as of September 2026.
  5. Review of Law No. 420-FZ on negotiable fines for leaks — ConsultantPlus, 12/02/2024.
  6. 272.1 — ConsultantPlus, current edition as of September 2026.
  7. The first court decisions on the new compositions of Article 13.11 of the Administrative Code — "Garant", 03/23/2026.
  8. Roskomnadzor recorded a decrease in the number of leaks in 2025 — ComNews, 01/22/2026.
  9. Supported countries and territories — OpenAI, verified on 09/17/2026.
  10. Supported countries — Anthropic, verified on 09/17/2026.
  11. Employees of Russian companies sent 30 times more data to AI services - CNews, 02/04/2026.
  12. "Solara" research on appeals to public AI services — Habr, "Solara" blog, 08/14/2026.
  13. 2026 AI Adoption & Risk Report — Cyberhaven, 11.02.2026.
  14. Your public ChatGPT queries are getting indexed by Google — TechCrunch, 31.07.2025.
  15. OpenAI must turn over 20 million ChatGPT logs — Bloomberg Law, 05.01.2026.
  16. How your data is used to improve model performance — OpenAI help, verified 09/17/2026.
  17. How to opt out of AI chatbot training — Malwarebytes, 15.09.2026.
  18. Updates to our consumer terms — Anthropic, 28.08.2025.
  19. Your data — OpenAI documentation, checked on 09/17/2026.
  20. Is my data used for model training? — Anthropic Privacy Center, verified on 09/17/2026.
  21. Putin signed a law to support the development of AI technologies — "Vedomosti", 07/26/2026.
  22. The Law on supporting the development of AI technologies — Habr, 07/26/2026.
  23. The law on AI in Russia — "Code ", 07/26/2026.
  24. The draft of the Ministry of Digital Economy on the regulation of AI — RIA Novosti, 03/20/2026.
  25. Yandex Cloud Security — Yandex, verified on 09/17/2026.
  26. Disable query logging — Yandex AI Studio documentation, verified on 09/17/2026.
  27. GigaChat API Review — Sber documentation, checked on 09/17/2026.
  28. YandexGPT 5 Lite 8B Instruct GGUF — Hugging Face, verified on 09/17/2026.
  29. "T-Technologies" released T-Pro 2.0 — CNews, 07/18/2025.
  30. Qwen 3.8 models with open weights — The Decoder, 14.08.2026.
  31. GigaChat 3.5 Ultra from Sber — vc.ru , 07/06/2026.
  32. Qwen3 tags and Llama 3.3 tags — Ollama catalog, checked on 09/17/2026.
  33. Model memory estimator — Hugging Face Accelerate documentation, checked on 09/17/2026.
  34. Decree of the Government of the Russian Federation dated 01.11.2012 No. 1119 — Kaspersky RegulHub, current edition.
  35. Order of the FSTEC of Russia dated 02/18/2013 No. 21 — ConsultantPlus, ed. from 05/14/2020.
  36. Order of the FSTEC of Russia dated 04/11/2025 No. 117 — ConsultantPlus, ed. from 05/08/2026.

Read also

Development · 17 September 2026 · 11 min of reading

MicroSaaS in 2026: How to Choose a Niche: Market, Economy, Risks and Opportunity Map based on Stripe Index, Stack Overflow, Carta and industry research data (Part 3)

Based on the selection criteria — money in the niche is already paid through Stripe, low saturation with competitors at the same time, verticality (the solution is tailored to a specific profession, and not " for everyone ") and quick payback for the client — seven areas can be identified with different ratios of risk and potential profitability.

Development · 17 September 2026 · 6 min of reading

MicroSaaS in 2026: How to Choose a Niche: Market, Economy, Risks and Opportunity Map based on Stripe Index, Stack Overflow, Carta and industry research data (Part 2)

An "AI wrapper " is a product that simply adds a user interface on top of someone else's neural network model - for example, GPT from OpenAI — by calling it through the API, but without creating its own technology, data, or embedding in the client's workflow.

Development · 17 September 2026 · 14 min of reading

MicroSaaS in 2026: How to Choose a Niche: Market, Economy, Risks and Opportunity Map based on Stripe Index, Stack Overflow, Carta and industry research data (Part 1)

MicroSaaS is one of the few segments of the software market where an individual developer or a team of two or three people can still build a profitable business without venture capital money. Over the past two years, artificial intelligence has been added to this, which has sharply reduced the cost of development, and at the same time, the cooling of seed investments (the first external financing that a startup attracts from investors), forcing founders to look for a quick way to profit, rather than scale.

Name the code in the first message

This way we will find your question faster and understand where you came from.