• About Us
  • People
    • Matthew Murphy
    • Ellen Wang
    • Yu Du
    • Xia Yu
    • Sarah Xuan
  • Practice Areas
    • Intellectual Property
    • Technology
    • Corporate
    • International Trade
    • International Arbitration
  • Insights
  • Accolades
  • Locations
  • Contact Us
  • 中文

China’s AI Legal Framework As At August 2026

Published 7 August 2026 Sarah Xuan
In recent years, China’s artificial intelligence (AI) industry has developed rapidly and has had a profound impact on the economy and society. According to a statistical report issued by the China Internet Network Information Center, the scale of China’s AI industry exceeded RMB 700 billion in 2024 and has maintained annual growth of more than 20% for several consecutive years. At the same time, the widespread application of AI technology has also created new challenges relating to data security, privacy protection and ethical risks, which require ex ante prevention and ongoing supervision through improved laws and regulations. Accordingly, a systematic review of China’s current AI-related laws and regulations and the relationships among them is of considerable significance in guiding the compliant development of the industry.
At the national level, China currently attaches great importance to the development of artificial intelligence and has designated it as a national strategy. The New Generation Artificial Intelligence Development Plan issued by the State Council in 2017 proposed that China become one of the world’s leading AI innovation centres by 2030. In 2025, the State Council issued the Opinions on Deepening the Implementation of the “Artificial Intelligence Plus” Initiative, which expressly called for a model whereby innovation drives application and application promotes innovation, so as to advance the deep integration of AI with the real economy. Such policy arrangements emphasize, at the level of top-level planning, both the direction of AI development and the need for regulation, thereby establishing an approach that gives equal weight to technological breakthroughs and governance.
As regards the legal framework, China has not yet enacted a dedicated “Artificial Intelligence Law”. Instead, governance is advanced through a multi-level body of norms comprising foundational laws, administrative regulations, departmental rules, administrative normative documents and national standards. The Cybersecurity Law, the Data Security Law, and the Personal Information Protection Law - establish the basic legal framework from the respective perspectives of cybersecurity, data processing and personal information protection; the Regulations on the Administration of Cyber Data Security further refine, at the level of administrative regulations, security requirements for cyber data processing activities; and the cyberspace, industry and information technology, public security, market regulation and other authorities have formulated specialized rules for specific scenarios such as algorithmic recommendation, deep synthesis, generative artificial intelligence, the labelling of AI-generated and synthetic content, and anthropomorphic interaction. At the same time, ethical review of artificial intelligence science and technology and relevant national standards have begun to make ethical, security and labelling requirements increasingly procedural and technical. The resulting framework is therefore not merely a collection of rules characterized by the absence of a single AI statute and the presence of multiple supporting measures, but a composite regulatory system in which different levels of legal norms and different governance tools operate in coordination.
Against this background, this article reviews China’s multi - level and composite regulatory system for artificial intelligence, the responsibilities of enterprises, and compliance in relation to business activities involving artificial intelligence.
I. China’s Multi-Level and Composite Regulatory System for Artificial Intelligence China’s current governance of artificial intelligence may be described as a multi-level structure in which foundational laws establish the framework, administrative regulations refine data governance, specialized rules allocate responsibilities according to application scenarios, ethical review expands the dimensions of governance, and national standards promote technical implementation.
At the foundational level are the Cybersecurity Law, the Data Security Law and the Personal Information Protection Law. In particular, the Cybersecurity Law, as revised in 2025 and effective from 1 January 2026, added Article 20, which expressly provides that the State supports research into the foundational theories of artificial intelligence and the research and development of key technologies such as algorithms, advances the development of training data resources, computing power and other infrastructure, improves ethical norms for artificial intelligence, strengthens risk monitoring, assessment and security supervision, promotes the application and sound development of artificial intelligence, and supports the use of artificial intelligence and other new technologies to enhance cybersecurity protection. This is the first time that artificial intelligence has received a dedicated and systematic expression in the Cybersecurity Law, a foundational statute in the field of cybersecurity. It should be noted that Article 20 primarily sets out the responsibilities and policy direction of the State in promoting the development of artificial intelligence and governing its security, and does not itself create a separate set of corporate conduct obligations or penalty mechanisms. Its more significant legal implication lies in bringing requirements relating to AI development, security, ethics and risk governance, which had previously been dispersed mainly across policies, departmental rules and technical standards, further into the framework of a foundational law. The Data Security Law establishes systems for data classification and grading, protection of important data, risk monitoring and emergency response, directly affecting data processing activities involved in AI training, fine-tuning, evaluation and inference. The Personal Information Protection Law regulates the collection and use of information relating to natural persons by AI systems. User prompts, chat records, voice data, facial images, location data, device identifiers and behavioural preferences may all constitute personal information, and some may further constitute sensitive personal information. AI enterprises must therefore determine an appropriate lawful basis according to the specific processing activity and comply with requirements including purpose specification, data minimization, openness and transparency, and security safeguards.
Between these foundational laws and the specialized rules on artificial intelligence, the Regulations on the Administration of Cyber Data Security constitute an important layer of administrative regulation. Effective from 1 January 2025 and formulated pursuant to, among other laws, the Cybersecurity Law, the Data Security Law and the Personal Information Protection Law, the Regulations apply to cyber data processing activities within China and the security supervision and administration of such activities. Although they are not AI-specific regulations, the training, fine-tuning, deployment and user interaction of AI models generally involve cyber data processing. Accordingly, their requirements concerning data classification and grading, personal information processing, protection of important data and data security risk management constitute general data governance rules that AI enterprises must take into account. Including the Regulations in the analysis helps accurately demonstrate that China’s AI governance does not move directly from foundational laws to specialized departmental rules, but instead contains a hierarchical linkage of “laws - administrative regulations - specialized rules - technical standards”.
Above these foundational laws and administrative regulations, China has formulated specialized rules for AI applications presenting particular risks, including the Provisions on the Administration of Algorithmic Recommendations in Internet Information Services, the Provisions on the Administration of Deep Synthesis in Internet Information Services, the Interim Measures for the Management of Generative Artificial Intelligence Services, the Measures for the Labelling of Artificial Intelligence-Generated and Synthetic Content, and the Interim Measures for the Administration of Artificial Intelligence Anthropomorphic Interactive Services. Rather than defining their regulatory scope by technical concepts such as “large models”, “machine learning” or “neural networks”, these rules allocate obligations according to specific functions, risks and social impacts. The algorithmic recommendation rules focus on information distribution, user profiling and risks of platform manipulation; the deep synthesis rules focus on identity impersonation, false content and deepfake risks; the generative AI rules focus on training data, model outputs and security responsibilities in the provision of services to the public; the content labelling regime focuses on the identification, dissemination and traceability of generated content; and the anthropomorphic interaction rules extend further to risks involving emotional dependence, mistaken perceptions of personhood, protection of minors and intervention in extreme situations.
The resulting structure is not a simple hierarchy of superior and subordinate legal norms, but one in which foundational obligations and scenario-specific obligations apply cumulatively. A single AI service may be subject to multiple sets of rules simultaneously. For example, a generative-AI platform with personalized recommendation functions may qualify both as a provider of algorithmic recommendation services and as a provider of generative-AI services. When generating images or videos, it must also comply with the deep-synthesis and content-labelling rules. If it processes users’ personal information or transfers data overseas, the personal information protection and cross-border data-transfer regimes will also apply.
II. Specialized AI Governance Rules and Their Technical Implementation (1) Governance of Algorithmic Recommendations The Provisions on the Administration of Algorithmic Recommendations in Internet Information Services, which came into effect on 1 March 2022, constitute an important starting point for China’s specialized regulation of artificial intelligence. The Provisions expressly require providers to assume primary responsibility for algorithm security, establish management systems for reviewing algorithmic mechanisms, ethical review, information review, data security and personal information protection, publish their service rules, and allocate dedicated personnel. Operators must also safeguard users’ rights to be informed and to make choices, such as by providing an option to disable algorithmic recommendations, and may not deploy algorithms that induce user addiction. Algorithmic products with the capacity to influence public opinion are also required to complete filing and assessment procedures. Overall, the Provisions require platform operators to implement the principles of fairness and transparency in algorithm design and operation, and to strengthen security, controllability and social responsibility.
(2) Governance of Deep Synthesis The Provisions on the Administration of Deep Synthesis in Internet Information Services, which came into effect on 10 January 2023, impose comprehensive requirements on deep-synthesis services, including AI face-swapping and voice synthesis. The Provisions emphasize that providers may not engage in activities prohibited by laws and regulations, must assume primary responsibility for information security, and must establish real-name authentication, rumour-refutation and user-complaint mechanisms. They also impose compliance requirements in relation to training data and algorithm research and development, including safeguarding data security, respecting personal information and intellectual property rights, and conducting regular algorithm audits. For generated or edited synthetic content, providers are required to embed implicit labels in the content and to apply conspicuous labels to certain functions, including intelligent dialogue, facial-image generation and realistic scene generation, so as to avoid public confusion. The Provisions further specify that deep-synthesis services possessing attributes of public opinion or the capacity for social mobilization must complete filing procedures and undergo security assessments, and that regulatory authorities may require higher-risk services to suspend functional updates. In summary, through labelling requirements and primary responsibility, the deep-synthesis rules bring AI-generated synthetic content within the regulatory framework for online information content.
(3) Governance of Generative Artificial Intelligence The Interim Measures for the Management of Generative Artificial Intelligence Services, which took effect on 15 August 2023, marked China’s entry into a stage of specialized governance of generative artificial intelligence. The Interim Measures apply to entities that provide generative services for text, images, audio and video to the public. They require service providers to comply with laws, regulations and ethical requirements; prohibit the generation of content involving, among other things, incitement to subvert State power, terrorism or pornography; require providers to prevent discriminatory outputs and infringements of rights in algorithm design and service provision; and require the protection of user privacy and trade secrets. Providers must ensure the security and stability of their services, establish mechanisms for handling unlawful content and reporting users’ unlawful conduct, and report to the competent authorities in a timely manner. Generative AI services having significant social impact must undergo security assessment and complete registration in accordance with the algorithm filing rules. The Interim Measures embody the principles of promoting innovative development and exercising prudent regulation in accordance with law, and establish express requirements concerning content compliance, technical transparency and security assessment for generative AI services.
(4) Labelling of Generated and Synthetic Content The Measures for the Labelling of Artificial Intelligence-Generated and Synthetic Content (effective from 1 September 2025) further refine the labelling requirements for AI-generated and synthetic content. Jointly issued by the Cyberspace Administration of China, the Ministry of Industry and Information Technology, the Ministry of Public Security and the National Radio and Television Administration, the Measures establish a dual system of explicit and implicit labelling. Explicit labels directly inform ordinary users that content has been generated or synthesized by artificial intelligence, while implicit labels use technical means such as file metadata to record relevant generation attributes and service information. GB 45438-2025, Cybersecurity Technology - Labelling Methods for Artificial Intelligence-Generated and Synthetic Content, which took effect on the same date as the Measures, is a mandatory national standard specifying the technical methods for labelling AI-generated and synthetic content. Accordingly, the field of generated and synthetic content labelling has developed a coordinated structure in which the rules establish the responsibilities of relevant actors and labelling obligations, while a mandatory national standard implements the technical methods, enabling requirements of identifiability and traceability to be further embedded in products and dissemination systems.
(5) Governance of Anthropomorphic Interaction The Interim Measures for the Administration of Artificial Intelligence Anthropomorphic Interactive Services (effective from 15 July 2026), jointly issued by the Cyberspace Administration of China, the National Development and Reform Commission, the Ministry of Industry and Information Technology, the Ministry of Public Security and the State Administration for Market Regulation, are China’s first departmental rules specifically regulating AI anthropomorphic interactive services. The Interim Measures apply to continuing emotional interaction services provided to the public within China that simulate the personality traits, modes of thinking and communication styles of natural persons, and expressly exclude intelligent customer service, knowledge-based question answering, work assistants, education and learning, scientific research and other services that do not involve continuing emotional interaction. Their regulatory focus goes beyond general content security to encompass emotional dependence, influence on user behaviour, the rights and interests of minors and elderly persons, personal information protection, and risks to life and health. They strengthen full-lifecycle management through mechanisms including security assessment, algorithm filing, risk monitoring and emergency response. The emergence of rules on anthropomorphic interaction indicates that the object of China’s AI regulation is extending from “what a system generates” to “how a system continuously influences people”.
(6) Proceduralisation of Ethical Review of Artificial Intelligence Science and Technology
In 2026, ten authorities, including the Ministry of Industry and Information Technology, the National Development and Reform Commission, the Ministry of Education, the Ministry of Science and Technology, the Ministry of Agriculture and Rural Affairs, the National Health Commission, the People’s Bank of China, the Cyberspace Administration of China, the Chinese Academy of Sciences and the China Association for Science and Technology, jointly issued the Measures for the Ethical Review and Services of Artificial Intelligence Science and Technology (Trial). The Measures are officially classified as an administrative normative document, and their level of legal effect therefore differs from that of laws, administrative regulations and departmental rules. They should not therefore be assigned the same normative status as the Provisions on the Administration of Algorithmic Recommendations or the Interim Measures for the Administration of Artificial Intelligence Anthropomorphic Interactive Services. Their institutional significance is nevertheless substantial: AI ethics governance is beginning to move from statements of principle towards procedural governance involving designated review bodies, review procedures and service mechanisms. Ethical requirements are thus no longer expressed solely as abstract values such as fairness, justice, privacy protection and a human-centred approach, but are beginning to enter internal review procedures and external service systems for research, development and application activities.
(7) From Legal Obligations to Technical Standards: The Engineering of Regulatory Requirements
In addition to the mandatory GB 45438-2025, GB/T 45654-2025, Cybersecurity Technology - Basic Security Requirements for Generative Artificial Intelligence Services; GB/T 45652-2025, Cybersecurity Technology - Security Specification for Pre-training and Optimization Training Data of Generative Artificial Intelligence; and GB/T 45674-2025, Cybersecurity Technology - Security Specification for Generative Artificial Intelligence Data Labelling, all of which took effect on 1 November 2025, are currently effective recommended national standards. The three standards respectively provide technical requirements and evaluation criteria concerning the security of generative AI services, pre-training and optimization training data, and data labelling. Because they are recommended national standards, they should not, as a matter of principle, simply be described as having the same generally mandatory effect on all enterprises as laws and regulations. Nevertheless, together with the regulatory rules governing generative artificial intelligence, they demonstrate an important trend: regulatory requirements are being translated from principle-based obligations into engineering specifications covering training data, data labelling, model and service security, and generated-content labelling. This body of standards also provides more specific technical references for enterprise security self-assessments, third-party assessments and regulatory reviews.
III. A Coordinated System of Regulatory Authorities China’s regulation of artificial intelligence is characterized by governance involving multiple authorities. Within the current system, the national cyberspace authority performs an overall coordinating role and is principally responsible for online information content, algorithm filing, generative-AI services, data security and governance of the online ecosystem. The industry and information-technology authorities are responsible for administration of the telecommunications and internet sectors, network and information-technology security, and industrial development. Public security authorities investigate and punish, in accordance with law, fraud, unlawful acquisition of data, cyberattacks and other unlawful or criminal activities carried out using artificial intelligence. Market-regulation authorities are responsible for consumer-rights protection, advertising regulation, enforcement against unfair competition and antitrust enforcement. Authorities responsible for radio and television, press and publication, education, finance, healthcare and other sectors establish special requirements within their respective fields. This regulatory structure means that AI enterprises generally do not deal with a single licensing authority. A particular AI product may simultaneously involve cyberspace filings, value-added telecommunications-service regulation, personal information protection, consumer rights, intellectual property rights and sector-specific market access.
The regulatory tools employed by the competent authorities are also diverse. First, governance requirements are allocated at different levels through laws, administrative regulations, departmental rules and administrative normative documents, while national standards provide a basis for technical implementation and evaluation. Second, filing and registration requirements establish traceable regulatory records by requiring enterprises to submit information concerning algorithms, models, services and risk-control measures. Third, security assessments provide for risk review of services with public opinion attributes, social mobilization capabilities or significant public risks. Fourth, ethical review of science and technology brings ethical risks into AI research, development and application through internal ethical review and related service mechanisms. Fifth, supervisory inspections and administrative interviews may require enterprises to explain matters including data sources, algorithmic mechanisms, content review and rectification. Sixth, administrative penalties and service-related measures may include orders for rectification, warnings, fines, suspension of relevant functions, cessation of services or referral to public security authorities.
From the perspective of the allocation of powers, the current system does not centralize AI regulation in a newly established specialist authority. Instead, through overall coordination by the cyberspace authority and division of responsibilities among sectoral authorities, AI risks are incorporated into the existing regulatory frameworks for networks, data, markets and public security. This model facilitates a rapid response to technological change, but may also result in regulation by multiple authorities, overlapping rules and fragmented compliance interfaces for enterprises.
IV. Differentiated Responsibilities of Different Market Participants (1) Artificial Intelligence Platforms Providing Services to the Public Platforms providing services to the public are the principal responsible entities under the current rules. Because they directly control service interfaces, user relationships, content output and dissemination channels, they are generally required to assume comprehensive obligations relating to algorithm filing, content review, personal information protection, labelling of generated content, complaint handling and protection of minors. A platform cannot transfer all responsibility to the provider of the foundation model. Even where a model is developed by a third party, the platform must still conduct risk testing in light of its own service scenarios, configure filtering rules, and expressly allocate responsibility for model defects, data compliance and security incidents in its contracts.
(2) Foundation-Model Developers and Technology Providers Although foundation-model developers may not provide services directly to the public, they control training data, model architecture and underlying capabilities and may therefore still bear corresponding liability for model defects, intellectual property infringement, unlawful data processing and security vulnerabilities. Technology suppliers should maintain training-data records, model-version records, risk-assessment documentation and interface-use rules, and provide downstream customers with necessary security information. Contracts between enterprises may allocate compliance work, but cannot exclude liabilities directly imposed by law.
(3) Dataset Providers and Data-Service Providers Data providers must demonstrate that data have been obtained from lawful sources and ensure that they are entitled to use the data for the agreed purposes of AI training, testing or evaluation. A simple representation that “the data are lawful” is generally insufficient to control risk. Providers must also disclose the data sources, scope of authorization, legal basis for personal information processing, de-identification measures and cross-border restrictions. For datasets containing personal information, copyright works, trade secrets or important data, contracts should specify permitted uses, prohibited uses, retention periods, restrictions on further authorization and responsibility for security incidents.
(4) Users of Artificial Intelligence Services Users do not merely enjoy rights without bearing responsibilities. A person who uses artificial intelligence to generate false information, commit fraud, or infringe another person’s reputation, likeness, privacy, copyright or trade secrets may incur civil, administrative or even criminal liability. Users may not remove or alter labels attached to generated or synthetic content without authorization, or use technical means to circumvent platform security measures. However, user responsibility does not displace platform responsibility. Where a platform knows or ought to know that a user repeatedly uses its services to engage in unlawful activities and fails to take reasonable measures, the platform may still bear corresponding legal consequences.
(5) Government Departments and Public Institutions Government procurement and use of AI systems involve the exercise of public power and therefore present greater risks than ordinary commercial scenarios. In addition to reviewing price and technical performance, procuring entities should consider the sources of training data, model explainability, data localization, supply-chain security, human-review mechanisms and arrangements for system exit. Important decisions affecting administrative management, public services or individual rights and interests should not rely entirely on inexplicable AI outputs. Contracts should also expressly require suppliers to cooperate with audits, remediate vulnerabilities, return data and provide recourse in respect of liability.
V. Advantages of the Current System and Matters Requiring Further Resolution The first feature of China’s AI regulation is its ability to formulate targeted rules rapidly in response to risks arising from new technologies. Rules on algorithmic recommendation, deep synthesis, generative artificial intelligence, content labelling and anthropomorphic interaction have been introduced successively, reflecting a flexible and responsive governance approach focused on specific risk scenarios. The second important development is the elevation of the legal level of AI governance. Article 20, added to the revised Cybersecurity Law effective in 2026, brings key AI technology research and development, training data, computing infrastructure, ethical norms, risk monitoring and assessment, and security supervision into the institutional expression of a foundational cybersecurity statute, while the Regulations on the Administration of Cyber Data Security further implement cyber data governance at the level of administrative regulation. Third, ethical governance is becoming increasingly procedural, with the Measures for the Ethical Review and Services of Artificial Intelligence Science and Technology (Trial) moving ethical requirements from statements of principle into concrete review mechanisms. Fourth, the linkage among legal rules, administrative regulation and technical standards is strengthening. In the field of AI-generated and synthetic content labelling, specialized rules determine the responsibilities of relevant actors, while the mandatory national standard GB 45438-2025 provides technical implementation methods; in relation to training data, data labelling and service security for generative artificial intelligence, a series of recommended national standards provides technical evaluation criteria. Fifth, responsibility is increasingly allocated across the industrial chain, with the current framework bringing model developers, service providers, application distribution platforms, dissemination platforms and users within governance arrangements at different stages.
Nevertheless, there remains scope for further systematization of the current framework. First, rules formulated at different levels and by different authorities overlap in scope. The same AI service may simultaneously trigger multiple regimes governing algorithmic recommendation, generative artificial intelligence, deep synthesis, content labelling, data and personal information protection, requiring enterprises to undertake complex assessments of applicability. Second, the boundaries of responsibility among foundation-model developers, model deployers, application platforms and end users remain to be further clarified through subsequent rules as well as enforcement and judicial practice. Third, mandatory national standards, recommended national standards, administrative normative documents and departmental rules carrying direct legal consequences differ in legal effect. In practice, care must be taken not to treat all “standards” or “guidelines” as having the same mandatory force. Future improvements should focus not merely on increasing the number of norms, but on strengthening coordination among different rules, clarifying risk classifications and boundaries of responsibility, and improving the enforceability and predictability of the rules through auditable technical standards, assessment mechanisms and enforcement guidance.
VI. Key Points for Corporate Compliance As AI regulation continues to deepen, the mere adoption by enterprises of privacy policies, user agreements and internal policies is increasingly insufficient to demonstrate actual fulfilment of legal obligations. AI compliance needs to be incorporated into technical architecture, product design and operational processes:
Enterprises should first establish an inventory of AI systems, identifying the models, algorithms, datasets, interfaces and application scenarios used internally or provided externally, and classify risks according to factors including whether the relevant services are provided to the public, possess attributes of public opinion, process sensitive personal information, provide generative or synthetic capabilities, or involve minors.Second, enterprises should establish mechanisms for reviewing data provenance and authorization. The source, rights status, personal-information attributes, processing purpose and retention period of training data, fine-tuning data and evaluation data should be recorded separately. Where cyber data processing is involved, enterprises should also consider the Regulations on the Administration of Cyber Data Security together with the data security and personal information protection regimes in determining whether data classification and grading, important-data protection or other security-management requirements are triggered. Third-party datasets should not be accepted solely on the basis of formal assurances; sampling verification or specialized due diligence should be conducted according to the level of risk.
Third, legal requirements should be translated into technical controls. Content-security obligations should be implemented through model testing, keyword and semantic detection, human review and emergency shutdown mechanisms; personal information protection should be implemented through access controls, de-identification, encryption and deletion functions; and the labelling of generated and synthetic content should be implemented in interface notices, file metadata and dissemination chains in accordance with the Measures for the Labelling of Artificial Intelligence-Generated and Synthetic Content and the mandatory technical requirements of GB 45438-2025. For generative AI training data, data labelling and service security, enterprises may also use recommended national standards such as GB/T 45652-2025, GB/T 45674-2025 and GB/T 45654-2025 in internal security design and self-assessment, while distinguishing their status as recommended standards from the mandatory effect of laws, administrative regulations and departmental rules.
Enterprises should also establish model-change management systems. Model upgrades, data updates, plug-in integration, internet-connected retrieval and the addition of anthropomorphic functions may all alter the level of risk. Material functional changes should trigger renewed legal and security assessments, rather than indefinite reliance on the review conclusions reached when the product was first launched. For AI science and technology activities involving higher ethical risks, enterprises should also determine whether they need to establish or improve ethical review mechanisms for science and technology, and, with reference to the Measures for the Ethical Review and Services of Artificial Intelligence Science and Technology (Trial), incorporate procedures such as ethical-risk identification, review opinions and re-review of material changes into research, development and deployment processes. Because the Measures are an administrative normative document, enterprises should also determine the specific scope of their obligations by reference to the type of business concerned, requirements of the competent authorities and other directly applicable laws and regulations. Finally, enterprises should retain evidence capable of demonstrating the compliance process, including data-review records, model-assessment reports, security-incident records, complaint-handling records, filing materials, version-change records and management decision-making documents. In the event of a regulatory inspection or infringement dispute, the ability to demonstrate that reasonable, continuous and risk-proportionate measures have been taken is often more important than whether the enterprise has adopted a policy document stating general principles.
Conclusion China has developed a composite AI governance framework in which foundational laws such as the Cybersecurity Law, the Data Security Law and the Personal Information Protection Law provide the underlying legal framework; administrative regulations such as the Regulations on the Administration of Cyber Data Security implement general data governance; departmental rules concerning algorithmic recommendation, deep synthesis, generative artificial intelligence, content labelling and anthropomorphic interaction constitute scenario-specific regulatory pillars; and ethical review of science and technology, filing, security assessment, national standards and multi-agency enforcement provide further support. The addition of a dedicated AI provision to the Cybersecurity Law in its 2026 revision demonstrates a further elevation in the legal level of AI governance. At the same time, mandatory and recommended national standards are beginning, in different ways, to translate requirements relating to content labelling, security assessment, training data and data labelling into more specific technical methods and evaluation criteria. China’s AI regulation therefore displays three interrelated trends: the regulatory hierarchy is extending from specialized departmental rules towards foundational laws; the regulatory object is moving upstream from output content to training data, models and the entire process of human-AI interaction; and regulatory methods are evolving from principle-based obligations towards controls that are assessable, auditable and capable of engineering implementation.
For enterprises, AI compliance is no longer a formal legal review conducted by a traditional legal department before product launch, but a systematic undertaking involving research and development, data, products, security, operations and management. In the future, regardless of whether China enacts a unified foundational law on artificial intelligence, data lawfulness, algorithmic controllability, model and service security, content identifiability, ethical review of science and technology, protection of user rights and interests, and traceability of responsibility will continue to form important themes of AI governance. More importantly, enterprises must accurately distinguish the levels of legal effect of different normative instruments: laws, administrative regulations and departmental rules constitute directly binding normative constraints; administrative normative documents perform functions of institutional refinement and governance guidance; mandatory national standards impose standards requirements that must be complied with in relation to specified technical matters; and recommended national standards principally provide references for technical design, evaluation and compliance implementation. The ability to translate these requirements at different levels into engineering controls, organizational processes and auditable evidence will increasingly become an important governance capability for sustained compliance and market trust among AI enterprises.

© 2026 - All rights reserved.

We use cookies to enable essential functionality on our website, and analyze website traffic. By clicking Accept you consent to our use of cookies. Cookies and Privacy Policy.

Your Cookie Settings

We use cookies to enable essential functionality on our website and analyze website traffic. For more information, read our Cookies and Privacy Policy below..

Cookie Categories
Essential

These cookies are strictly necessary to provide you with services available through our websites.

Analytics

These cookies collect information that is used in aggregate and in an anonymized form to help us understand how our website is being used and how effectively our site is performing.