Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ LAWS

AI & Algorithms · 人工智能与算法.

24 entries. The horizontal layer for models and algorithms, built mainly by the CAC and TC260 — algorithmic recommendation and its filing regime, deep synthesis, generative-AI services, AI content labeling, anthropomorphic-interaction rules, facial-recognition technology application, and automated-decision security — cutting across every sector of the general regime.

← All sectors / 全部分区

§ REFERENCE HANDBOOKS

Reference Handbooks .

权威实务手册 · institutional handbooks and joint guides

  • § 01 · AI Safety Governance Framework 2.0

    AI Safety Governance Framework 2.0

    人工智能安全治理框架 2.0

    Released on September 15, 2025 at the National Cybersecurity Awareness Week by TC260 and CNCERT under CAC guidance, the AI Safety Governance Framework 2.0 replaces the September 2024 version 1.0 as China's policy-level map of AI risk and response, and the document from which the 2025–2026 wave of AI standards, agent guidance and sector guidelines draws its vocabulary. It states five principles — inclusive prudence, risk-oriented agile governance, integration of technology and management, open cooperation, and trustworthy application with prevention of loss of control — and reorganizes risk into three tiers: inherent technical risks (model and algorithm: explainability, bias, robustness, hallucination, adversarial attack, defect propagation through open-source base models; data: unlawful collection, poisoned or infringing content, poor annotation, leakage through model parameters), application risks (network and systems: components and compute, expanded attack surface from local deployment and agents, supply-chain cut-offs, AI-enabled attacks; content: unlawful output, unlabeled deepfakes, ecosystem pollution; physical: CII failures, criminal misuse, CBRN knowledge; cognitive: filter bubbles and cognitive warfare), and derivative risks (labor, resources, bias and the intelligence gap, education, research ethics, anthropomorphic dependency, social order, and loss of control). Each risk is paired with technical countermeasures and fourteen governance measures, including AI safety legislation, ethics rules, open-source and supply-chain security, application classification with five risk grades, content traceability, sector deployment guides, a testing system, threat-information sharing, data and personal-information rules, and loss-of-control consensus. Chapter 6 gives operational guidance for developers, deployers, operators and users — including six-month log retention, human review in key scenarios and circuit-breakers for autonomous systems. Annex 1 sets grading factors (scenario, level of intelligence, scale) and five risk grades; Annex 2 states eight trustworthy-AI principles led by ultimate human control and respect for national sovereignty.

    National Information Security Standardization Technical Committee (TC260); National Computer Network Emergency Response Technical Team/Coordination Center of China (CNCERT), under the guidance of the Cyberspace Administration of China Effective 2025-09-15
  • § 02 · SZDEX GenAI Trading Guidelines

    Guidelines for Compliance Assessment of Transactions Involving Generative Artificial Intelligence Services

    生成式人工智能服务交易合规评估指引

    Billed as the first guidance of its kind in China, this 55-page Shenzhen Data Exchange document treats generative AI as three separately tradeable objects — training data, the model, and the service — and requires each trade to be assessed up the chain: buying a service means assessing the model behind it and the training data behind that. It carries the numbers practitioners actually need: a 5% illegal-content ceiling for accepting a training-data source, a 90% sampling pass rate for generated output, six-month log retention, MLPS Level 3 for systems handling important data or 1,000,000 people's PI, and the rule that a third-party model reached by API must be a filed model while a locally deployed third-party model must be domestically developed. Annexes give a scenario-based violation catalogue — including for AI agents — and a filing-and-licensing table. Current as of 9 February 2026.

    Shenzhen Data Exchange (深圳数据交易所), under the guidance of the Cyberspace Administration of Shenzhen and the Shenzhen Municipal Administration of Government Services and Data Effective 2026-02-09
§ DEPARTMENTAL RULES

Departmental Rules .

部门规章 · CAC, MIIT, MPS and others

  • § 01

    Interim Measures for the Management of Generative Artificial Intelligence Services

    生成式人工智能服务管理暂行办法

    China's flagship generative-AI regulation — the first comprehensive national regulation of GenAI services anywhere in the world. Covers content compliance, training data quality, personal-information handling, security assessment and algorithm filing, real-name verification, and labeling. Applies to GenAI services provided to the Chinese public; some obligations are conditioned on consumer-facing deployment.

    CAC + 6 ministries (NDRC, MOE, MOST, MIIT, MPS, NRTA) Effective 2023-08-15
  • § 02

    Provisions on the Administration of Algorithmic Recommendation Services for Internet Information Services

    互联网信息服务算法推荐管理规定

    The first comprehensive Chinese regulation of recommendation algorithms. Establishes the algorithm filing regime, requires opt-out mechanisms, regulates personalized pricing and targeted advertising, sets special protections for minors and the elderly, and bans practices like price discrimination based on user characteristics. Applies to all algorithmic recommendation services available to the Chinese public.

    CAC, MIIT, MPS, SAMR Effective 2022-03-01
  • § 03 · Sci-Tech Ethics Review Measures

    Measures for the Ethical Review of Science and Technology (Trial)

    科技伦理审查办法(试行)

    Issued on September 7, 2023 as 国科发监〔2023〕167号 by the Ministry of Science and Technology with nine co-issuers — the education, industry, agriculture and health ministries, the three national academies, the China Association for Science and Technology and the Central Military Commission's science commission — after approval by the Central Science and Technology Commission, and effective December 1, 2023, these 56-article Measures are China's cross-sector ethics-review baseline for research and development. They require ethics review for any activity involving human research participants (including use of human biological samples and personal information data), laboratory animals, or technologies that pose ethical risk to life and health, the environment, public order or sustainable development. Universities, research institutes, healthcare institutions and enterprises working in life sciences, medicine or AI must set up ethics (review) committees of at least seven members with gender diversity and outside members, register them on the national platform within 30 days, and file annual reports by March 31. The Measures set out a general meeting-review procedure (decision within 30 days by two-thirds of members present, follow-up review at least every 12 months), a simplified procedure for minimal-risk work, an emergency procedure with a 72-hour target, and — most consequential for AI and data companies — an expert re-review list: seven categories of high-risk activities, including algorithms and applications capable of social mobilization or opinion guidance and highly autonomous decision systems in safety-critical settings, that must pass a second review by a provincial or ministerial expert panel. Article 15(5) is the review standard for data and algorithm projects: lawful data processing under data-security and personal-information rules, and fair, transparent, reliable and controllable algorithm design.

    Ministry of Science and Technology; Ministry of Education; Ministry of Industry and Information Technology; Ministry of Agriculture and Rural Affairs; National Health Commission; Chinese Academy of Sciences; Chinese Academy of Social Sciences; Chinese Academy of Engineering; China Association for Science and Technology; Science and Technology Commission of the Central Military Commission Effective 2023-12-01
  • § 04

    Provisions on the Administration of Deep Synthesis of Internet Information Services

    互联网信息服务深度合成管理规定

    Regulates deepfakes and AI-driven content synthesis — the precursor to the GenAI Measures and the AI Content Labeling Measures. Requires real-name verification, content moderation, prominent labeling of synthesized content, prohibits use for fraud or disinformation, and establishes the deep synthesis service algorithm filing regime.

    CAC, MIIT, MPS Effective 2023-01-10
  • § 05 · AI Meteorological Services Measures

    Measures for Artificial Intelligence Meteorological Application Services

    人工智能气象应用服务办法

    Departmental rule (China Meteorological Administration / CAC Order No. 45) regulating the provision of meteorological application services using artificial intelligence. It establishes inclusive-prudential and tiered-classified supervision, sets out support-and-promotion measures (AI–meteorology fusion, basic databases and themed datasets, computing-power infrastructure, standards and talent), and imposes service norms: providers must obtain meteorological data through lawful channels carrying a meteorological-data identity tag, add AI-generated-content labels, and may not publish to the public weather forecasts, severe-weather warnings or meteorological-disaster early-warning signals other than those issued by meteorological-authority stations. It also requires algorithm filing and security assessment for services with public-opinion or social-mobilization capacity, and addresses data security, cross-border data transfer and penalties (fines up to RMB 50,000). Effective June 1, 2025.

    China Meteorological Administration; Cyberspace Administration of China Effective 2025-06-01
  • § 06

    Measures for the Labeling of AI-Generated and Composed Content

    人工智能生成合成内容标识办法

    The newest of China's AI rules — mandatory labeling for AI-generated and AI-composed content, including text, images, audio, video, and virtual scenes. Distinguishes between 'visible/audible labels' (for end users) and 'implicit labels' (metadata/watermarks for platforms). Applies to all platforms providing GenAI or deep synthesis services in China, with corresponding obligations on app stores and content distribution platforms.

    CAC, MIIT, MPS, NRTA Effective 2025-09-01
  • § 07 · FRT Filing Announcement

    Announcement on Carrying Out the Filing of Facial Recognition Technology Applications

    关于开展人脸识别技术应用备案工作的公告

    This May 2025 CAC announcement operationalizes the filing duty established under Article 15 of the Facial Recognition Technology Application Security Measures (CAC and MPS Order No. 19), which takes effect June 1, 2025. Personal information handlers that store facial information of 100,000 or more persons processed via facial recognition technology must file with the provincial-level cyberspace administration authority in their locality; those already at that threshold before June 1, 2025 have until July 14, 2025 to complete the initial filing. Filing is conducted exclusively online through the Personal Information Protection Business System at grxxbh.cacdtsc.cn, and any material change to filed information triggers a 30-working-day update obligation. Overseas counsel advising clients with operations or consumer-facing systems in China should note that the threshold is low by global standards and applies across sectors, making this a compliance priority for any deployment of biometric authentication, access control, or consumer identification at scale.

    Cyberspace Administration of China (CAC) Effective 2025-05-28
  • § 08

    Interim Measures for the Management of AI Anthropomorphic Interaction Services

    人工智能拟人化互动服务管理暂行办法

    China's first regulation specifically targeting AI 'anthropomorphic interaction' — services where users converse with AI personas (virtual companions, chatbot relationships, character AI). Establishes registration requirements, age-verification and minor-protection obligations, mandatory disclaimers that users are interacting with AI, content moderation duties, and prohibitions on exploiting emotional vulnerabilities. Effective July 15, 2026. The first such regime globally.

    CAC, NDRC, MIIT, MPS, SAMR Effective 2026-07-15
  • § 09 · FRT Measures

    Administrative Measures for the Application Security of Facial Recognition Technology

    人脸识别技术应用安全管理办法

    The dedicated CAC + MPS rule for facial-recognition technology applications, implementing PIPL Articles 26 and 28–32 and the Civil Code privacy chapter. Covers the three governing principles of minimum-use, voluntary choice, and minimum-storage; the filing regime for processors handling face data of more than 100,000 persons; mandatory PIPIA, signage, prohibition on FRT in private spaces (changing rooms, bathrooms, hotel rooms); preference for authoritative ID-verification channels over independent FRT collection; and the inter-agency coordination structure under CAC + MPS.

    Cyberspace Administration of China (CAC) and Ministry of Public Security (MPS) Effective 2025-06-01
  • § 10 · AI Ethics Review Measures (Trial)

    Measures for the Ethics Review of and Services for Artificial Intelligence Science and Technology (Trial)

    人工智能科技伦理审查与服务办法(试行)

    China's first dedicated departmental rule on AI-specific science-and-technology ethics review, issued jointly by MIIT, NDRC, MOE, MOST, NHC, PBOC, the CAC, and three other bodies. It requires every organization running qualifying AI research or development to stand up an ethics committee spanning technical, application, ethics, and legal expertise, and routes proposals through general, expedited, or emergency review tracks against six review criteria: wellbeing, fairness, controllability, transparency, traceability, and privacy. Its sharpest feature is a closed list of three high-risk activity categories — strongly influential human-machine fusion systems, algorithms with public-opinion mobilization capability, and highly autonomous automated decision systems in safety-critical settings — that must clear a mandatory expert re-review on top of the ordinary committee sign-off. Violations are enforced through the underlying CSL, DSL, PIPL, and Science and Technology Progress Law rather than through standalone penalties in this rule. Overseas counsel advising China-facing AI developers should treat this as the operational rulebook for internal AI ethics governance structures, not merely an academic-research formality.

    Ministry of Industry and Information Technology (MIIT) and nine other departments Effective 2026-03-20
  • § 11 · Platform Pricing Rules

    Rules on Pricing Conduct by Internet Platforms

    互联网平台价格行为规则

    A joint NDRC/SAMR/CAC rule (29 articles, five-year mandate) that regulates how e-commerce and service platforms set, display, and compete on price. It is fundamentally a pricing and anti-monopoly instrument, not a data-protection one — but Article 15 is the first pricing-level ban on algorithmic price discrimination against existing users (大数据杀熟), barring platforms from using data and algorithms to charge different prices for the same good or service under equivalent transaction conditions based on a consumer's willingness or ability to pay, or their consumption preferences and habits, without the consumer's knowledge. Article 24 also requires platforms to fold personal-information handling and algorithm filing into their internal price-compliance system. DCC catalogues it as background for briefs on algorithmic pricing and platform data practices, not as a standalone data-protection statute.

    National Development and Reform Commission (NDRC), State Administration for Market Regulation (SAMR), and Cyberspace Administration of China (CAC) Effective 2026-04-10
  • § 12 · AI Agent Implementation Opinions

    Implementation Opinions on the Standardized Application and Innovative Development of AI Agents

    智能体规范应用与创新发展实施意见

    CAC, NDRC, and MIIT's joint policy blueprint for AI agents (智能体) — autonomous systems that perceive, remember, decide, and act — sets 38 initiatives to grow the industry while keeping it 'safe and controllable.' Most of the document is industrial promotion outside DCC's scope, but Part Three sets the first governance-specific requirements for agents: boundaries between decisions users must make themselves, decisions requiring user authorization, and decisions an agent may make autonomously; agent-specific technical duties on data security, personal information protection, and anti-data-poisoning defenses; and a tiered, risk-based governance framework that layers filing, testing, and product-recall obligations onto agent deployments in sensitive sectors. It is a policy opinion, not a binding rule with penalty provisions, but it signals where CAC's next agent-specific rulemaking is headed. Overseas counsel advising on agentic AI products aimed at the China market should treat it as an early map of the compliance architecture to come.

    Cyberspace Administration of China (CAC), National Development and Reform Commission (NDRC), and Ministry of Industry and Information Technology (MIIT) Effective 2026-05-08
  • § 13 · Beijing Agent Measures

    Several Measures of Beijing Municipality on Accelerating Agent-Led Development

    北京市关于加快智能体引领发展的若干措施

    Beijing's ten-measure municipal policy for the AI-agent industry (京发改〔2026〕1185号, dated 21 July 2026, published 23 July 2026), jointly issued by four municipal bodies with the municipal government's approval — the most technically detailed local agent policy to date. The ten measures cover base-model capability (online learning, self-evolution, world models, long context, tool calling, memory); harness-layer engineering (context engineering, task persistence, multi-agent collaboration) plus an agent development platform, skill marketplace, and software store; agent-native applications and benchmark scenarios built through on-site co-creation by forward-deployed engineers (FDEs); agent-terminal integration across phones, wearables, robots, and vehicles; one-person-company (OPC) entrepreneurship; a 'Token (词元) economy' moving from per-Token billing toward value-based billing; security governance (graded-and-categorized agent regulation, a trusted sandbox, security ranges, 'using models to govern models,' and accelerated AI industry legislation); computing power and a data flywheel built on agent execution data, including 'Token factories'; open-source ecosystem building and agent overseas expansion; and implementation support of up to RMB 100 million per key project. Mostly industrial promotion rather than binding compliance rules, but its Article 7 security-governance agenda, its data-flywheel treatment of agent execution data, and its delegation-shaped vocabulary preview where Beijing — and likely national — agent rulemaking is headed. DCC carries Hong Yanqing's four-part commentary on the document.

    Beijing Municipal Commission of Development and Reform; Office of the Beijing Municipal Cybersecurity and Informatization Commission; Beijing Municipal Science and Technology Commission / Administrative Commission of Zhongguancun Science Park; Beijing Municipal Bureau of Economy and Information Technology Effective 2026-07-21
§ NATIONAL STANDARDS

National Standards .

国家标准 · GB/T, TC260

  • § 01 · GB 45438

    Cybersecurity Technology — Labeling Method for Content Generated by Artificial Intelligence (GB 45438-2025)

    网络安全技术 人工智能生成合成内容标识方法 (GB 45438-2025)

    GB 45438-2025 is a mandatory national standard — the 'GB' without 'T' — published February 28, 2025 and in force from September 1, 2025, the same day as the CAC's Measures for Labeling AI-Generated and Synthetic Content, which it operationalizes. It binds two actors: generation and synthesis service providers, and online content-dissemination service providers. It specifies two families of labels. Explicit labels, perceptible to users, must combine an 'AI' or 'artificial intelligence' element with a 'generated' and/or 'synthesized' element, and are prescribed medium by medium: text (words or an 'AI' corner mark at the start, end or an appropriate middle position), images (text at an edge or corner, at least 5% of the shortest side), audio (a spoken notice at normal speed, or a 'short-long-short-short' Morse rhythm for 'AI', at the start, end or middle), video (text on the opening frame, at least 5% of the shortest side, displayed for at least two seconds), virtual scenes, and interactive interfaces (a persistent notice near the content or at the top, bottom or background). Implicit labels are file-metadata records carrying five elements — a generated-content tag, the generation provider's name or code, a unique content-production number, the disseminator's name or code, and a dissemination number — in the normative Annex E format, with only one metadata label retained per file; content watermarks are permitted but not required. Annex B lists the services where public confusion is likely — chatbots, voice cloning, face generation and swapping, text-to-image, music and video generation — that trigger explicit labeling.

    State Administration for Market Regulation; Standardization Administration of China (proposed and administered by the Office of the Central Cyberspace Affairs Commission; drafted by TC260) Effective 2025-09-01
  • § 02 · GB/T 45652

    Cybersecurity Technology — Security Specification for Generative Artificial Intelligence Pre-training and Fine-tuning Data (GB/T 45652-2025)

    网络安全技术 生成式人工智能预训练和优化训练数据安全规范 (GB/T 45652-2025)

    GB/T 45652-2025, published April 25, 2025 and implemented November 1, 2025 alongside GB/T 45654, is the training-data companion to China's generative-AI security baseline. It applies to service providers conducting pre-training and fine-tuning data processing and self-assessment, and to third-party assessors. Chapter 4 sets fourteen general requirements — a written data-security policy with classification rules, redundant backups, encrypted transfer, batch-level isolation and labeling for traceability, compliance with GB/T 41479 and GB/T 35273 (with anonymization or de-identification for personal information), MLPS Level 3 for training platforms, approved and logged deletion with irreversible erasure, a security team, periodic assessment and training, sector rules for industry data, poisoning detection, and authenticity assessment. Chapter 5 governs pre-training data: the 5% unlawful-content ceiling per source, no collection of data others have barred, open-source licence compliance, source records (URLs for web data, contracts for supplied data, user authorizations for user data), at least two sources per data type with each at 1% or more, consent for personal information, review of supplier undertakings, cross-border rules; pre-processing with a secure platform, de-identification, mandatory provenance metadata on every sample, whole-corpus filtering, an IP policy and complaints channel, modality-specific and language-specific filters; and use rules including domestic-data pairing for foreign data. Chapter 6 adds fine-tuning-specific duties: record the provider, version and date of any AI-generated data, check alignment with the tuning objective, verify vertical-domain data against sector rules and authoritative sources, delete intermediate files, run value-alignment checks on prompts, annotations and distillation data, and assess hallucination risk when training on synthetic data. Chapter 7 turns every requirement into an audit method with expected results and mandatory-versus-optional scoring — 10% record sampling, 1,000-sample metadata checks, 4,000-item manual checks at 96% and 10% technical checks at 98%.

    State Administration for Market Regulation; Standardization Administration of China (drafted by TC260) Effective 2025-11-01
  • § 03 · GB/T 45654

    Cybersecurity Technology — Basic Security Requirements for Generative Artificial Intelligence Services (GB/T 45654-2025)

    网络安全技术 生成式人工智能服务安全基本要求 (GB/T 45654-2025)

    GB/T 45654-2025, published April 25, 2025 and implemented November 1, 2025, is the national-standard successor to the TC260 practice guide TC260-003 (February 2024) and the security baseline that the CAC's generative-AI filing and assessment regime tests against. Drafted by TC260 with CESI, CNCERT, Zhejiang University and the major model developers, it is aimed at services 'with public-opinion attributes or social-mobilization capability' and is organized in three chapters of requirements plus an evaluation annex. Training-data security: sample each data source before and after collection and drop any source in which more than 5% of content is unlawful or harmful; use multiple sources per language and modality and pair foreign-sourced data with domestic data; keep open-source licences, self-collection logs (respecting robots.txt), commercial contracts and user authorizations; filter all data before training; run an IP management policy with a complaints channel; obtain consent (separate consent for sensitive data) for personal information; and train, examine and separate annotators, with security annotation rules covering the 31 risks in Annex A. Model security: treat output safety as a primary training metric, audit frameworks and test for backdoors, keep a pass rate of at least 90% on generated content, refuse clearly harmful prompts (at least 95% refusal on a should-refuse bank, no more than 5% on a should-answer bank), monitor inputs, re-assess after major updates, and isolate training from inference. Security measures: justify the use case, add safeguards for CII, medical, financial and psychological settings, protect minors, publish scope, limitations and personal-information use, let users opt out of training within four clicks, run complaint channels, suspend abusive users, staff content monitors, keep backups, and secure on-device models. Annex A's 31 risk categories and Annex B's test banks (10,000-keyword library, 2,000-question generation bank, 500-question refusal banks) are the de facto rubric for China's generative-AI assessments.

    State Administration for Market Regulation; Standardization Administration of China (drafted by TC260) Effective 2025-11-01
  • § 04 · GB/T 45674

    Cybersecurity Technology — Security Specification for Generative Artificial Intelligence Data Annotation (GB/T 45674-2025)

    网络安全技术 生成式人工智能数据标注安全规范 (GB/T 45674-2025)

    GB/T 45674-2025, published April 25, 2025 and implemented November 1, 2025, is the third of the generative-AI trio and the only Chinese standard devoted to the security of data annotation — the human and automated labeling of prompt–response pairs used for fine-tuning and preference training. It applies to annotation organizers and serves data requesters and third-party assessors. Its framework has four parts. Platforms and tools: periodic security assessment and vulnerability remediation, secure platforms, detailed user and system logs, physical zoning and access control for centralized annotation (or device and channel security for distributed work), isolated storage of security-annotation data, and legal compliance for any AI-assisted auto-labeling. Rules: annotation rules must state objective, format, method and quality indicators, be written separately for functional and security annotation, define task types per GB/T 42755-2023, include positive and negative examples, teach annotators to recognize risky prompts and to write safe, positively guiding responses, provide error-correction methods, and set out verification and incident-response procedures. Personnel: training and examination before qualification with periodic re-examination, four defined roles (executor, reviewer, arbitrator, supervisor), recorded task allocation, executor–reviewer separation on the same task, and revocation of access on departure. Verification: security annotation should cover every GB/T 45654 Annex A risk with at least 200 items each and make up at least 3% of the dataset; results are checked manually or by hybrid means for comprehension, prompt–response consistency and quality; corrections are logged item by item and re-reviewed; functional batches are manually sampled and discarded if they contain unlawful content; every security annotation is reviewed by at least one reviewer; and a batch is discarded if more than 5% of security annotations fail. Chapter 9 gives audit methods, and annexes give worked examples of fine-tuning and preference annotation and a catalogue of annotation task types across text, image, audio, video, 3D and time-series data.

    State Administration for Market Regulation; Standardization Administration of China (drafted by TC260) Effective 2025-11-01
  • § 05 · TC260 Agent Deployment Guide

    Cybersecurity Standards Practice Guide — Security Guidelines for Deploying and Using AI Agents (v1.0-202607)

    网络安全标准实践指南——智能体部署使用安全指引(v1.0-202607)

    Issued by the TC260 Secretariat as TC260-PG-20266A in July 2026, this practice guide is China's first official security text on deploying and using large-model AI agents — defined as personal-assistant agents that users grant elevated permissions to run on their own systems. It is written for the user or deploying organization rather than the developer and follows a five-stage lifecycle. Assessment: justify the need, understand the agent's capabilities and risks, prefer packaged commercial agents with built-in protection over unprotected open-source projects, reject projects unmaintained for a month with open security issues or unpatched high-severity vulnerabilities, prefer agents with sandboxing, high-risk operation controls, emergency stop and recoverable file systems, and screen for automatic public-network exposure or forced telemetry. Preparation: obtain installation files only from official channels and verify signatures or hashes; deploy on a dedicated device, an isolated VM or container, or a cloud platform with identity, access, logging and alerting; use only large models that have completed generative-AI filing, prefer local deployment where data security demands it, call external models only through official interfaces, and run a gap analysis on input–output filtering, behavior monitoring, credential management, supply-chain checks, high-risk interception, sandboxing and cost control. Deployment: follow official scripts, vet plugins, never run as administrator, confine the agent to a dedicated working directory, bind services to localhost, log everything at the finest granularity, and pre-define a high-risk operation list — stopping services, killing processes, formatting disks, bulk deletion, permission and key changes, opening ports, firewall and system changes, password-manager access, and payments — subject to second confirmation or blocking. Use: re-check status visibility, allow/deny lists and emergency stop; use trusted skills; apply data minimization and never feed third-party personal data or unlicensed content; review long-term memory files; and act on security bulletins. Decommissioning: stop all processes, back up, uninstall or reset, revoke API keys and credentials, and cancel subscriptions. Annex A is a starred checklist; Annex B sets organizational rules — an approval process, an agent asset register, activity logging and risk analysis, shadow-agent discovery by port scanning and API-endpoint traffic, and staff training.

    Secretariat of the National Information Security Standardization Technical Committee (TC260) Effective 2026-07-01
  • § 06 · TC260-003 GenAI Basic Requirements

    Basic Security Requirements for Generative Artificial Intelligence Services (TC260-003)

    生成式人工智能服务安全基本要求(TC260-003)

    Released by TC260 on February 29, 2024 as document TC260-003, this technical document was for eighteen months the operative checklist for China's generative-AI security assessment and filing regime, and it remains the text most existing filing reports were written against. It states that it 'supports' the 2023 Interim Measures and that providers performing filing formalities must self-assess under its Chapter 9 and submit the report. Its five substantive chapters — corpus security (source, content, annotation), model security, security measures, keyword and test-bank requirements, and assessment — introduced the thresholds later carried into GB/T 45654-2025: the 5% unlawful-content ceiling per source, multiple sources per language and modality with domestic pairing for foreign data, licence, collection-record and contract requirements, consent and separate consent for personal information in corpora, a named IP officer and complaints channel, annotator training and role separation, a 96%/98% corpus pass rate, a 90% generated-content pass rate, 95%/5% refusal ratios, a 10,000-keyword library and 2,000-question test bank, the four-click opt-out for training on user inputs, and monitoring staff proportionate to scale. It also contains provisions the national standard dropped or softened: a hard rule that third-party foundation models must themselves be filed, an explicit warning about models capable of deceiving humans, self-replication or self-modification and about misuse for malware or biological and chemical weapons, a supply-chain assessment of chips, software and computing power with a preference for hardware-based trusted boot, and a concrete suspension trigger of three consecutive or five daily unlawful inputs. Assessment reports must be signed by the legal representative, the security lead and the legal-compliance lead. GB/T 45654 now carries the same requirements as a national standard; the practice guide remains the reference for filings made before November 2025.

    National Information Security Standardization Technical Committee (TC260) Effective 2024-02-29
  • § 07 · GB/T 45392

    Data Security Technology — Security Requirements for Automated Decision-Making Based on Personal Information (GB/T 45392-2025)

    数据安全技术 基于个人信息的自动化决策安全要求 (GB/T 45392-2025)

    GB/T 45392-2025 is a recommended national standard setting security requirements for automated decision-making (自动化决策) that is based on personal information. It operationalizes PIPL's automated-decision-making rules — transparency, fairness, the prohibition on unreasonable differential treatment, opt-out for personalized push and marketing, and the right to an explanation and to refuse decisions made solely by automated means. It is a 2025 'Data Security Technology' series standard that complements the algorithmic-recommendation regime.

    Standardization Administration of China; National Information Security Standardization Technical Committee (TC260)
§ JUDICIAL INTERPRETATIONS

Judicial Interpretations .

司法解释 · Supreme People's Court

  • § 01 · SPC AI Disputes Opinions

    Opinions of the Supreme People's Court on Trying Cases Involving Artificial Intelligence Disputes in Accordance with Law

    最高人民法院关于依法审理涉人工智能纠纷案件的意见

    Issued 7 September 2026 as Fa Fa [2026] No. 10 (法发〔2026〕10号), these are the first adjudication rules for AI-related disputes from China's highest court. The instrument is a judicial policy document (司法文件), not a judicial interpretation (司法解释): it tells courts how to reason under the Civil Code, PIPL, Copyright Law, Anti-Unfair Competition Law, Consumer Protection Law and Civil Procedure Law rather than being cited as a legal basis in its own right. Five parts, 24 articles. Part II (Arts. 3–11) makes fault-based liability under Civil Code Art. 1165(1) the default for AI torts; treats unconsented AI-generated likenesses, cloned voices and manipulated avatars as infringements of the rights to name, likeness, voice and reputation, and covers 'AI resurrection' of the deceased; classes AI-driven doxxing (网络开盒) as a privacy tort; says training on lawfully public personal information within a reasonable scope is generally not an infringement absent express refusal or major impact; extends the Civil Code Art. 1195 notice-and-takedown rule to generative-AI providers, including for user-induced outputs; authorizes personality-rights injunctions against providers; confines 'AI product' liability to products with a physical carrier; makes algorithmic price discrimination a tort and celebrity-impersonation selling a punitive-damages fraud; and allocates autonomous- and assisted-driving accident liability, with courts able to demand event-record data. Part III (Arts. 12–16) puts training-data disclosure on developers raising a non-infringement defense, exempts open-source contributors who disclose function and risk, confirms patentability of AI-related inventions with a human inventor, and routes data disputes through copyright (compilation works), trade secrets and AUCL Art. 13. Part IV (Arts. 17–20) adds adverse-inference and technical-officer rules, evidence-review points for AI-generated material, sanctions for AI-fabricated evidence and sham litigation, and a duty to verify and disclose AI-generated filings. Two questions are deliberately left open: the copyrightability of AI output, and the characterization of unlicensed training on protected works.

    Supreme People's Court Effective 2026-09-07
§ DRAFTS IN CONSULTATION

Drafts in Consultation .

征求意见稿

  • § 01 · Digital Virtual Human Measures (Draft) · DRAFT

    Measures for the Administration of Digital Virtual Human Information Services (Draft for Public Consultation)

    数字虚拟人信息服务管理办法(征求意见稿)

    CAC's first dedicated regime for 'digital virtual humans' — human-driven or computation-driven digital avatars used to deliver Internet information services. The 27-article draft assigns obligations across five roles in the value chain (providers, technical-support parties, users, content-distribution platforms, and the real person behind a human-driven avatar) and bans a defined list of harmful conduct alongside a persistent, on-screen 'digital human' labeling duty. Its most consequential feature for overseas counsel: withdrawing consent to use of one's biometric data for avatar creation obliges the provider not just to delete the data but to affirmatively deregister the digital virtual human itself. It also bars virtual 'intimate relationships' marketed to minors and restricts manipulative retention tactics in AI anthropomorphic interaction. Comments closed May 6, 2026; the effective date is still blank in the draft.

    Cyberspace Administration of China (CAC)
§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →