Every brief.
The full run, most recent first.
- § 01 · SPC
Fa Fa [2026] No. 10: How the Supreme People's Court Explains Its First Adjudication Rules for AI Disputes
On 7 September 2026 the Supreme People's Court released the Opinions of the Supreme People's Court on Trying Cases Involving Artificial Intelligence Disputes in Accordance with Law (最高人民法院关于依法审理涉人工智能纠纷案件的意见), document number Fa Fa [2026] No. 10 (法发〔2026〕10号) — the first adjudication-rules document on AI from China's highest court. This brief translates the Court's own release note in full: the drafting background (the April 2025 Politburo study session, the 15th Five-Year Plan's call for rules on AI-generated output, the State Council's IP plan), the four drafting considerations (including the Court's statement that China has no dedicated AI law, so the Opinions work through the Civil Code, PIPL, Copyright Law, AUCL, Consumer Protection Law and Civil Procedure Law), and the part-by-part summary of the 24 articles. DCC then maps every article for overseas counsel — the fault-based default under Civil Code Art. 1165(1); the Article 4 rules on AI face-swapping, voice cloning and 'AI resurrection'; the Article 5 doxxing rule; Article 6 on training with lawfully public personal information; Article 7's notice-and-takedown rule for generative-AI providers; Article 8 injunctions; Article 9's physical-carrier limit on 'AI product'; Article 10 on algorithmic price discrimination and celebrity-impersonation fraud; Article 11 on autonomous and assisted driving; the IP articles 12–16 (training-data disclosure by developers, open-source exemption, AI-assisted inventions, technology contracts, data use under copyright, trade secrets and AUCL Art. 13); the procedure articles 17–20 (adverse inference, evidence review of AI output, sanctions for AI-fabricated evidence, the duty to verify and disclose AI-generated filings); and the working-mechanism articles 21–24 — and explains what a 法发 document is and is not.
- § 02 · SPC
'Inclusiveness Is Not Indulgence': The Supreme People's Court Takes Five Questions on Its AI Disputes Opinions
Full translation of the Supreme People's Court's press-conference Q&A on the Opinions on Trying Cases Involving Artificial Intelligence Disputes in Accordance with Law (关于依法审理涉人工智能纠纷案件的意见, Fa Fa [2026] No. 10), released 7 September 2026. Five questions, answered by the SPC's senior officials. On rights versus innovation: fault-based liability is the default to avoid over-burdening an early-stage industry, 'AI product' is strictly limited to products with a physical carrier (robots, autonomous cars — not AI services), training on lawfully public personal information is generally not an infringement, and algorithmic price discrimination and AI celebrity-impersonation fraud are actionable. On AI-generated content and IP: liability must match control capability and duty of care, a developer raising a non-infringement defense must produce training-data sources, training process and operating mode, and AI-enabled fake reviews and false advertising are unfair competition — while copyrightability of AI output and unlicensed training remain deliberately unaddressed. On personality rights: 'inclusiveness is not indulgence' — Article 4 on face-swapping, voice cloning and 'AI resurrection', Article 5 on doxxing, and Article 8 on personality-rights injunctions against providers. On the 'safe harbor': why Civil Code Article 1195's notice-and-takedown rule applies by analogy to generative-AI providers for both hallucinated and user-induced infringing output. On the courts themselves: AI-fabricated evidence, sham litigation, and the duty to verify and disclose AI-generated pleadings and case-search reports after courts found hallucinated case citations in filings.
- § 03 · COMPUTE-CENTERS
One Machine Room, Five Regulatory Identities: MaaS Compliance for China's AI Compute Centers
AnJie Broad partners Cai Hang and Yao Ting and associate Liu Zeqiang argue that the IDC-era compliance checklist no longer fits the AI compute center. Their thesis: one machine room now carries five regulatory identities at once — domestic IDC operator, cross-border AI service provider, service exporter under the Export Control Law, supplier of self-deployed model capability, and responsible entity for the agents it ships — each with its own logic, and each transmitting obligations to the others. The brief works through value-added telecom licensing (B11/B12), energy-conservation review and PUE caps, the continuing duties under the Regulation on Network Data Security Management (State Council Decree No. 790), the token-export exemptions in CAC Decree No. 16 and what they do not exempt, the territorial limits of the GenAI Interim Measures, the Export Control Law catch-all, the unsettled line between large-model filing (备案) and large-model registration (登记), open-weight license trigger clauses, and the criminal exposure that follows an agent's tool calls under Criminal Law Article 285.
- § 04 · ENFORCEMENT
公安部网安局 Publishes 10 Typical Cases of Infringing Citizens' Personal Information — Insiders, Order Decryption, and Article 253a in Practice
On 11 August 2026 the MPS Cyber Security Bureau (公安部网安局) published ten typical cases (典型案例) of the crime of infringing upon citizens' personal information, brought under the Clean Net special campaign (净网专项行动). Across the batch: 123 suspects, more than 9.6 million items of personal information, and roughly 23.6 million yuan in case value. The striking feature is not the volume but the access route — in at least half the cases the data came out through someone with legitimate access: an employee, a planted hire, a service vendor, a hotel partner, or a school and hospital staffer. This DCC brief translates all ten fact patterns, sets them against Criminal Law Article 253a and the 2017 PI Criminal Interpretation thresholds, and draws out what the batch signals for companies whose exposure runs through their own staff and vendors.
- § 05 · PERSONAL-INFORMATION
China Finishes the Other End of PIPL: The Draft Provisions for Large Personal Information Handlers, Read Against Order No. 25
On 7 August 2026 the CAC published the Provisions on Personal Information Protection for Large Personal Information Handlers (Draft for Comment), consolidating its September 2025 supervision-committee draft and its November 2025 large-network-platform draft into one 50-article instrument, with comments due 7 September 2026. DCC has translated the full text and reads it against CAC/MPS Order No. 25, the small-handler regime published sixteen days earlier — because the pair is the story. Three shifts matter most. The subject changes from 'large network platform' to 'large personal information handler,' and the old registered-user and monthly-active-user tests give way to a three-factor test starting at 10 million data subjects, which reaches banks, insurers, carriers, hospitals and automakers that never thought of themselves as platforms. Designation is declared rather than automatic: a qualifying handler must self-declare through its provincial CAC and the national CAC publishes a public list, which puts the burden of self-identification on the company. And the obligations that follow are structural rather than procedural — absolute domestic storage under Article 13, a nationality requirement for data center controllers under Article 14, a protection officer drawn from management with a direct reporting line to the provincial CAC, and a supervision committee that is not a committee of the board. DCC sets out the full comparison table, the designation trap, and what the newly visible middle band means for foreign-invested subsidiaries.
- § 06 · METEOROLOGICAL-DATA
The CMA Keeps the Keys: China's First Sectoral Rules for Public Meteorological Data Authorized Operation
In March 2026 the Office of the China Meteorological Administration issued the Measures for the Administration of the Authorized Operation of Public Meteorological Data (Trial) — 公共气象数据授权运营管理办法(试行), Qi Ban Fa [2026] No. 23 — the first complete sector-specific implementation of the NDRC/NDA authorized-operation framework inside a national vertical system that DCC has recorded. DCC has translated the full 39-article text. The design departs from the national baseline in one consistent direction: control. Operating terms are capped at three years against the national five; operating institutions pass a provincial review, a CMA maturity assessment and the CMA's own 'three majors and one large' deliberation before they may even bid; downstream developers become a third catalogued and supervised tier; nobody but an implementing institution may sub-authorize data, even disguised as cooperative development; and no product trades without a CMA-issued meteorological-data identity tag registered on the CMA's circulation supervision platform. Read against the National Data Administration's Data Property Rights Registration Work Guide — whose public-data clause lets products formed through authorized operation take property-rights registration and circulate as certificated market assets — the meteorological version keeps the development right inside the system: what a market entity gets is a term-limited, contract-based service role inside CMA infrastructure, not a registrable right over what it builds.