The listing is part of a standalone cyber package, 11 individuals and 5 entities, adopted in coordination with Britain while the EU’s 21st sanctions package remains stuck. Brussels’ stated grounds: VK’s cooperation with the Russian state, including handing over data on users who posted banned or war-critical content, and its role in restricting circumvention tools; Max, the state-pushed messenger, is cited for its integration with state services and its reach into user data. Personal sanctions on the group’s previous chief executive have existed since 2022; the holding itself had never been designated until now.
The Kazakh end of the story surfaced as a customer question. VK Cloud Kazakhstan, which sells cloud infrastructure to businesses digitalizing in the country, answered publicly that the sanctions do not affect the service’s operation. Operationally that is accurate. Commercially it is incomplete: a Kazakh company whose data and workloads sit on a directly designated Russian platform now carries a compliance question in every conversation with a European partner, bank or auditor, and Kazakh banks screening for secondary-sanctions exposure will read the same list.
The precedent for how this goes is one month old. Apple removed VK’s applications from the App Store in late June, before any direct designation existed, citing sanctions compliance; installed apps kept working, updates stopped. Infrastructure decays in that order: nothing breaks on day one, and the exits begin. For CAW’s sanctions-transmission file the listing is a clean specimen: a measure aimed at Moscow’s information machine arrives in Almaty as a procurement question, and the quiet migrations to other clouds, if they start, will be visible in contracts long before anyone announces them.
