Back to AI Regulations Review
Binding Rules - Already In Force China

China AI Regulation

// Binding Verticals - Filed, Assessed, Labelled

China never waited for an omnibus AI law. Binding vertical regulations stack per technology: algorithms must be filed with the CAC, generative services must pass security assessment before launch, and every piece of AI-generated content now carries visible and embedded labels.

GenAI measures eff. Aug 2023Labelling eff. Sep 1, 2025CAC filing + assessment
// Key Highlights

Key Highlights

Which rules already bite, and what they demand before launch day.

  1. 01

    China already operates the world’s most prescriptive AI rulebook. Instead of one omnibus act, binding vertical regulations stack per technology: recommendation algorithms, deep synthesis, generative AI, and content labelling.

  2. 02

    The Algorithmic Recommendation Provisions (effective March 2022) require filing significant algorithms with the Cyberspace Administration of China, publishing algorithm summaries, honoring opt-outs from personalization, and protecting gig-worker scheduling rights.

  3. 03

    The Deep Synthesis Provisions (effective January 2023) mandate consent for manipulating biometric features and conspicuous labels on AI-generated media.

  4. 04

    The Interim Measures for Generative AI Services (effective August 2023) require a security assessment plus algorithm filing before any public-facing generative service launches, along with lawful training data, IP respect, content controls, and minors protection.

  5. 05

    Content labelling went national on September 1, 2025: Measures for Labeling AI-Generated Content force explicit visible marks and implicit metadata labels across generation, upload, and dissemination platforms, backed by the GB 45438-2025 standard.

  6. 06

    Security assessments follow the TC260 generative AI security requirements, including corpus contamination limits and multi-thousand-question red-team test sets, making evaluation infrastructure a launch dependency rather than an afterthought.

  7. 07

    Network Data Security Regulations (effective January 2025) extend training-data compliance duties, and a horizontal Artificial Intelligence Law sits in the legislative pipeline to consolidate the stack.

  8. 08

    Enforcement is real: the CAC suspends and removes non-compliant apps, so filing status and labelling fidelity are availability issues, not paperwork.

// Governance & Compliance Playbook

Action Items for Governance and Compliance

How to make filing, assessment, and labelling launch dependencies instead of fire drills.

Inventory algorithms and file early

A01
Governance

Own a central registry of algorithms meeting filing characteristics with submission deadlines.

Compliance

Generate filing dossiers (mechanism, purpose, data types) directly from system documentation.

Gate launches on security assessment

A02
Governance

Make CAC assessment completion a hard release criterion for public-facing generative features.

Compliance

Automate TC260-style red-team suites and corpus scans so assessment evidence is pipeline output.

Implement dual-layer content labels

A03
Governance

Standardise explicit label formats and implicit metadata schemas platform-wide.

Compliance

Apply visible marks at generation time and embed compliant metadata through every export path.

Prove training-data legality

A04
Governance

License sources and maintain provenance logs with named approvers per corpus.

Compliance

Keep contamination ratios measurable and reproducible against TC260 thresholds.

Ship user rights controls

A05
Governance

Productize opt-out, label toggles, and targeting-off switches required by the 2022 provisions.

Compliance

Serve algorithm summaries and objection channels as user-facing endpoints, not support tickets.

Watch the framework AI law

A06
Governance

Track consolidation drafts and re-map obligations as the horizontal law lands.

Compliance

Keep the obligation register config-driven so new duties attach to releases without re-architecture.

// From Rulebook to Build

Engineering Translation

High-level capabilities that turn CAC obligations into pipeline outputs.

[REGULATION_BUILD_PLAN] HIGH LEVEL

>_Algorithm registry auto-generating CAC filing dossiers per system.

>_Red-team and corpus-contamination suites running in CI with immutable evidence.

>_Explicit watermarking plus metadata labelling enforced at generation and export.

>_Training-data licence and provenance ledger queryable per model version.

>_User-facing opt-out and algorithm-summary endpoints shipped by default.

>_Obligation register keyed to regulation IDs so new rules map onto existing pipelines.

Delivered as capabilities, not paperwork

Each obligation above is translated into product-level engineering capabilities. The underlying stack and internal tooling are intentionally abstracted here; they are covered in technical briefings.

Educational summary only. This is not legal advice. Confirm obligations with qualified counsel for your jurisdiction.

Ship Filing-Ready AI Systems

Book a technical briefing to wire algorithm filing, security assessment, and dual-layer content labelling into your China delivery pipeline.