• About Us
  • People
    • Matthew Murphy
    • Ellen Wang
    • Yu Du
    • Xia Yu
    • Sarah Xuan
  • Practice Areas
    • Intellectual Property
    • Technology
    • Corporate
    • International Trade
    • International Arbitration
  • Insights
  • Accolades
  • Locations
  • Contact Us
  • 中文

China’s MIIT Issues Notice on Special Action to Foster AI Application Service Providers

Published 2 September 2026 Xia Yu
On 31 August 2026, the Ministry of Industry and Information Technology (“MIIT”) issued the Notice on Carrying out the Special Action for Cultivating Artificial Intelligence Application Service Providers (MIIT Science and Technology Letter [2026] No. 414). The Notice is formulated pursuant to the Opinions of the State Council on Deepening the Implementation of the “AI+” Action (State Council Document [2025] No. 11). As a national-level policy document specifically targeting “artificial intelligence application service providers”, the Notice marks a pivotal shift in China’s AI governance from a “technology R&D-driven” approach towards “application services and industrial deployment”. The Notice reveals a regulatory philosophy that substitutes “cultivation” for “control”, “resource pools” for “licensing”, and “service chains” for “compliance chains”. This governance paradigm stands in sharp contrast to the risk-based tiered regulation under the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) and the US model centered on export controls and industry self‑regulation, and thus merits close attention.
Core Contents of the Notice
The Notice explicitly defines “artificial intelligence application service providers” as enterprises or institutions that offer services such as consulting and planning for AI solutions, delivery and implementation, operational management, and security governance, in response to the intelligentisation needs of user entities. This definition covers the entire service chain from consulting to maintenance, implying that the legal liabilities of service providers will run through the full life cycle of AI applications. The Notice sets clear phased targets: by the end of 2026, the number of service providers in the national service provider resource pool shall exceed 2,000; by the end of 2027, no fewer than 3,000. The resource pool is to be established through surveys and registration organized by local industry and information technology authorities, and the MIIT will consolidate the data to form a national resource pool for publication in due course.
The Notice outlines four core tasks: (1) establishing the service provider resource pool; (2) enhancing the level of service supply; (3) promoting large‑scale application; and (4) strengthening support and safeguards for service providers. Task 1 is a procedural qualification survey and registration, primarily involving information reporting and admission review. Task 2 focuses on “internal governance compliance”, explicitly requiring service providers to embed requirements concerning cybersecurity, data security, ethical governance, and business compliance “into the entire process of R&D, deployment, and application”. This in effect establishes a de facto reference standard for the duty of care and compliance management system requirements – in the event of disputes, the provisions of this Notice may be relied upon by judicial authorities as an important reference for determining whether a service provider has fulfilled its reasonable duty of care, directly affecting the provider’s internal control structures and liability for negligence. Task 3 focuses on “external transaction liabilities”, involving the “service cluster” consortium model, first‑purchase and risk compensation mechanisms. These elements directly determine the allocation of legal liabilities of service providers in external contracting, supply chain collaboration, and government procurement – particularly the risks of joint and several liability under the consortium model and the design of risk‑sharing clauses in new‑type procurement contracts, all of which derive from this task. Task 4 concerns government‑supporting policies and public services and does not directly impose legal obligations on service providers.
Key Analytical Points
First, the Notice places “security and compliance capabilities” at its core. The action objectives explicitly state the aim to “targetedly enhance service providers’ technological innovation, integrated delivery, and security and compliance capabilities”. Throughout the four tasks, security and compliance requirements run through the entire framework rather than being treated as peripheral provisions. In particular, the requirement in Task 2 to “guide service providers to embed cybersecurity, data security, ethical governance, and business compliance management requirements into the entire process of R&D, deployment, and application, shifting from passive response to proactive prevention” carries far‑reaching legal implications. It means that service providers cannot treat compliance as a matter of “after‑the‑fact remediation” or “the sole responsibility of the external legal department”; rather, compliance requirements must be integrated into every link of product development, system deployment, and operational services. This “embedded compliance” requirement effectively transforms legal compliance from a cost center into a core competitive advantage – the legal compliance capabilities of service providers will become a key metric for resource pool selection and ongoing evaluation. This approach is conceptually similar to the EU Artificial Intelligence Act’s requirement to “integrate compliance into the design and development process”, but the Notice places greater emphasis on proactive prevention throughout the entire process rather than passive ex‑post compliance reporting.
Second, how should liability risks be allocated under the “service cluster” model? Task 2 of the Notice explicitly requires local authorities to organize service providers to take the lead in forming “artificial intelligence application service clusters”, each consisting of one leading service provider and no fewer than two upstream/downstream entities. This “1+N” consortium model, while promoting collaborative innovation, also raises complex issues of legal liability allocation: for example, what liability does the leading service provider bear for the acts of consortium members? If the solution delivered by the consortium involves data breaches, algorithmic discrimination, or intellectual property infringement, how should liability be apportioned among the members? Although the Notice does not define the legal nature of the “service cluster”, given that this organizational model lacks legal personality and the Notice does not specify external liability rules among members, the parties in effect form a contractual collaborative relationship based on specific projects. Under this framework, the rights and obligations among participants are determined by agreement rather than by law. Accordingly, the leading service provider and the participating entities must, in their cooperation agreement, clearly address the following three core clauses: (1) rules for external liability (specifying whether the parties bear several or joint and several liability towards clients or third parties); (2) internal recourse and fault‑sharing mechanisms (stipulating specific standards under which a party that has borne liability beyond its share may seek recourse from other parties); and (3) dispute resolution clauses (designating competent courts or arbitration institutions to avoid jurisdictional disputes arising from the different locations of members).
Third, the “push” mechanism for security risk information may constitute a new reference standard for the duty of care. The Notice requires that “security risk information and risk incidents concerning various AI software and hardware products be pushed to service providers in a timely manner”. When read together with the requirement to “embed ... management requirements into the entire process”, this “push” mechanism may serve as an important reference for the duty of care of service providers – a service provider that fails to take reasonable responsive measures after receiving risk pushes may face a higher risk of being found negligent in the event of damage. It should be noted that the risk information pushed under the Notice falls into two categories: one is product security risks (such as vulnerabilities, backdoors, and other technical defects), and the other is compliance risk events (such as data breach notifications and other regulatory incidents). The responsive measures and legal liabilities corresponding to these two categories differ, and service providers should establish separate response procedures within their internal control mechanisms.
Fourth, first‑purchase and risk compensation represent an important innovation in the field of government procurement. The Notice proposes to “explore models such as first‑purchase and risk compensation to increase procurement of services including large models, agents, and tokens”. This is a significant innovation in government procurement law and public procurement practice. Traditional government procurement emphasizes “mature technology” and “lowest‑price bidding”, whereas the “first‑purchase” model encourages procuring entities to be the first to adopt AI services that have not yet been fully validated. The “risk compensation” mechanism implies that the government and procuring entities will jointly share the risks associated with the application of new technologies. This will have profound implications for the drafting of AI service procurement contracts – risk‑sharing mechanisms, intellectual property ownership, and remedies for non‑performance will all become core issues in contract negotiations.
Fifth, compliance challenges in supporting “going global” initiatives. The Notice explicitly requires that “qualified regions establish and improve comprehensive ‘going global’ service systems, and leverage cooperation mechanisms such as the Belt and Road, BRICS, and China‑ASEAN to promote the overseas deployment of quality AI application projects”. This policy direction will generate a large number of cross‑border AI service projects, but at the same time brings complex multi‑jurisdictional compliance challenges. These include compliance obligations under Chinese law (such as security assessments for cross‑border data transfers, technology export licensing, and personal information protection certifications), requirements of destination jurisdictions (such as the EU General Data Protection Regulation (Regulation (EU) 2016/679) [ https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679 ] and the Artificial Intelligence Act, US export controls and specific state laws, and data protection regulations in emerging markets such as the Middle East and Southeast Asia), and the fact that different jurisdictions impose inconsistent requirements on cross‑border data transfers.
International Comparisons
The EU Artificial Intelligence Act adopts a risk‑based tiered regulatory approach – classifying AI systems by risk level and imposing stringent compliance requirements on high‑risk systems. By contrast, China’s Notice adopts a cultivation and guidance approach – establishing resource pools, providing policy support, and organizing supply‑demand matching, effectively “giving a leg up” to the industry. These two paths reflect different governance philosophies: the EU focuses more on preventing harms caused by AI, while China places greater emphasis on unlocking the economic value of AI.
Notably, the EU Artificial Intelligence Act was amended in July 2026 through the “Digital Omnibus on AI” package (Regulation (EU) 2026/1744) [ https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%253A32026R1744 ], which entered into force on 27 July 2026. The amendment postpones the obligations for high‑risk AI systems from 2 August 2026 to 2 December 2027, and adjusts certain other compliance timelines. This “simplification and delay” adjustment reflects, to some extent, the EU’s effort to rebalance strict regulation with industrial competitiveness. China’s Notice, however, has chosen from the outset to promote industrial development through a “cultivation” approach – the phased adjustments along these two paths merit continued tracking and comparison.
Since 2026, the pace of federal AI legislation in the United States has accelerated markedly. On 20 March, the White House released the National Policy Framework for Artificial Intelligence [ https://www.whitehouse.gov/wp-content/uploads/2026/03/03.20.26-National-Policy-Framework-for-Artificial-Intelligence-Legislative-Recommendations.pdf ], setting out six core principles including federal pre‑emption of state laws, child safety, and freedom of speech; in June, the President signed an executive order focusing on AI innovation and safety; and on 4 June, a discussion draft of the “Great American AI Act” was introduced in the House of Representatives. Nevertheless, compared with China’s path of centrally cultivating thousands of service providers through industrial policy, the US still relies primarily on a combination of framework legislation, executive orders, and industry self‑regulation, lacking a dedicated national policy for cultivating service providers.
How will the tension between quality control and quantitative expansion be resolved when the resource pool grows from zero to 3,000 service providers within two years? The Notice’s provisions for “routine tracking and evaluation mechanisms” and the development of “relevant standards” may provide part of the answer, but the actual effectiveness of implementation remains to be seen. China’s arrangement of using policy instruments (such as computing power vouchers, first‑purchase and risk compensation) to lower market entry barriers and trial‑and‑error costs may enable China to form a first‑mover agglomeration advantage in the AI application service sector – when 3,000 service providers collaborate and innovate under a unified policy framework, the resulting network effects and data flywheel effects should not be underestimated.
Conclusion
In 2026, as the global AI regulatory landscape evolves rapidly – with the EU delaying compliance deadlines through the Digital Omnibus and the US accelerating federal legislative processes – China has chosen a distinctive path of “cultivation” in place of “control”. The Notice’s governance approach, substituting “resource pools” for “licensing” and integrating “compliance chains” through “service chains”, offers a different paradigm reference for global AI industry governance. For international legal practitioners, understanding the internal logic and potential risks of this paradigm is not only fundamental to serving cross‑border AI clients, but also a critical entry point for grasping the direction of global AI governance.
© 2026 - All rights reserved.

We use cookies to enable essential functionality on our website, and analyze website traffic. By clicking Accept you consent to our use of cookies. Cookies and Privacy Policy.

Your Cookie Settings

We use cookies to enable essential functionality on our website and analyze website traffic. For more information, read our Cookies and Privacy Policy below..

Cookie Categories
Essential

These cookies are strictly necessary to provide you with services available through our websites.

Analytics

These cookies collect information that is used in aggregate and in an anonymized form to help us understand how our website is being used and how effectively our site is performing.