China AI Regulation
// Binding Verticals - Filed, Assessed, Labelled
China never waited for an omnibus AI law. Binding vertical regulations stack per technology: algorithms must be filed with the CAC, generative services must pass security assessment before launch, and every piece of AI-generated content now carries visible and embedded labels.
Key Highlights
Which rules already bite, and what they demand before launch day.
- 01
China already operates the world’s most prescriptive AI rulebook. Instead of one omnibus act, binding vertical regulations stack per technology: recommendation algorithms, deep synthesis, generative AI, and content labelling.
- 02
The Algorithmic Recommendation Provisions (effective March 2022) require filing significant algorithms with the Cyberspace Administration of China, publishing algorithm summaries, honoring opt-outs from personalization, and protecting gig-worker scheduling rights.
- 03
The Deep Synthesis Provisions (effective January 2023) mandate consent for manipulating biometric features and conspicuous labels on AI-generated media.
- 04
The Interim Measures for Generative AI Services (effective August 2023) require a security assessment plus algorithm filing before any public-facing generative service launches, along with lawful training data, IP respect, content controls, and minors protection.
- 05
Content labelling went national on September 1, 2025: Measures for Labeling AI-Generated Content force explicit visible marks and implicit metadata labels across generation, upload, and dissemination platforms, backed by the GB 45438-2025 standard.
- 06
Security assessments follow the TC260 generative AI security requirements, including corpus contamination limits and multi-thousand-question red-team test sets, making evaluation infrastructure a launch dependency rather than an afterthought.
- 07
Network Data Security Regulations (effective January 2025) extend training-data compliance duties, and a horizontal Artificial Intelligence Law sits in the legislative pipeline to consolidate the stack.
- 08
Enforcement is real: the CAC suspends and removes non-compliant apps, so filing status and labelling fidelity are availability issues, not paperwork.
Action Items for Governance and Compliance
How to make filing, assessment, and labelling launch dependencies instead of fire drills.
Inventory algorithms and file early
A01Own a central registry of algorithms meeting filing characteristics with submission deadlines.
Generate filing dossiers (mechanism, purpose, data types) directly from system documentation.
Gate launches on security assessment
A02Make CAC assessment completion a hard release criterion for public-facing generative features.
Automate TC260-style red-team suites and corpus scans so assessment evidence is pipeline output.
Implement dual-layer content labels
A03Standardise explicit label formats and implicit metadata schemas platform-wide.
Apply visible marks at generation time and embed compliant metadata through every export path.
Prove training-data legality
A04License sources and maintain provenance logs with named approvers per corpus.
Keep contamination ratios measurable and reproducible against TC260 thresholds.
Ship user rights controls
A05Productize opt-out, label toggles, and targeting-off switches required by the 2022 provisions.
Serve algorithm summaries and objection channels as user-facing endpoints, not support tickets.
Watch the framework AI law
A06Track consolidation drafts and re-map obligations as the horizontal law lands.
Keep the obligation register config-driven so new duties attach to releases without re-architecture.
Engineering Translation
High-level capabilities that turn CAC obligations into pipeline outputs.
>_Algorithm registry auto-generating CAC filing dossiers per system.
>_Red-team and corpus-contamination suites running in CI with immutable evidence.
>_Explicit watermarking plus metadata labelling enforced at generation and export.
>_Training-data licence and provenance ledger queryable per model version.
>_User-facing opt-out and algorithm-summary endpoints shipped by default.
>_Obligation register keyed to regulation IDs so new rules map onto existing pipelines.
Delivered as capabilities, not paperwork
Each obligation above is translated into product-level engineering capabilities. The underlying stack and internal tooling are intentionally abstracted here; they are covered in technical briefings.
Educational summary only. This is not legal advice. Confirm obligations with qualified counsel for your jurisdiction.
Ship Filing-Ready AI Systems
Book a technical briefing to wire algorithm filing, security assessment, and dual-layer content labelling into your China delivery pipeline.