China Issues New AI Application Security Guidelines for Education, Healthcare and Audiovisual Services
Published 17 September 2026
Yu Du
On 15 September 2026, China’s National Technical Committee 260 on Cybersecurity of the Standardization Administration of China (“TC260”) the national technical committee responsible for developing and coordinating China’s cybersecurity standards, issued four Cybersecurity Standards Practice Guidelines addressing the safe use of artificial intelligence (“AI”). The four documents comprise a general guideline applicable across industries and three sector-specific guidelines covering education, healthcare, and radio, television and online audiovisual services.
The new guidelines were developed against the backdrop of rapidly expanding AI deployment across industries. Their stated purpose is to address emerging security risks while enabling the safe use of AI. The framework follows a two-level structure: the General Guidelines provide common security guidance applicable across sectors, while the three sector-specific documents address risks and practices particular to their respective industries.
1. General Guidelines for AI Application Security
The Guidelines for AI Application Security — General Principles provide the baseline framework for AI applications across industries. Rather than focusing only on the security of an AI model itself, the Guidelines take a full life-cycle approach, covering planning, design and development, validation, deployment, operation and monitoring, continuous assessment, and eventual retirement. They apply broadly to organizations deploying AI and may also serve as a reference for regulators and third-party assessment bodies.
Five basic principles underpin the framework: human-centered and controllable AI, risk identification and tiered protection, security throughout the life cycle, testing and objective verification, and dynamic adjustment as technology and risks evolve. At the planning stage, organizations are expected to identify and classify AI-related risks, assess the maturity of their security capabilities, assign security responsibilities, and establish monitoring and emergency-response arrangements. Where an AI application may affect personal safety or property, the Guidelines specifically contemplate safeguards such as human takeover, version rollback and emergency shutdown.
The Guidelines also address practical risks arising during development and operation. These include security reviews of open-source frameworks and code, traceability and security of training-data sources, protection against data poisoning and other attacks, testing before deployment, monitoring of inputs and outputs, and maintaining records of important decisions and operations. The overall approach is therefore not simply to require a compliant AI product at launch, but to establish an ongoing governance process throughout the AI application’s life cycle.
2. AI Application Security in Education
The education guideline applies to AI use by educational institutions at different levels and distinguishes five principal scenarios: AI-assisted teaching, learning, research, management and assessment. It requires educational institutions to establish rules for AI use according to factors such as the user's role, age, educational stage, subject and task, and contemplates measures including approved-use lists, algorithm filing where applicable, security assessment, and classification of educational data.
A central theme is that AI should remain an assistant rather than a substitute for educators or educational decision-makers. AI-generated recommendations, judgments or assessments should be subject to human review and should not directly replace final decisions by educational institutions. The guideline also provides for mechanisms allowing affected persons to receive notice, challenge results, request human review and seek correction. Special protections apply to minors, including age-appropriate notices and settings, parental authorization where required, supervision by teachers or guardians, and restrictions on duration and functionality.
The document goes further by setting different expectations for particular educational stages and activities. For example, primary-school students should not independently use open-ended content-generation functions, while use may gradually expand at later educational stages. In teaching, AI should preferably provide reasoning, methods and step-by-step guidance rather than simply producing complete answers in inappropriate situations. In research, the guideline draws a clearer boundary between routine assistance and core academic work, with key elements such as research design, data interpretation and substantive arguments expected to remain the researcher's own work.
3. AI Application Security in Healthcare
The healthcare guideline applies to healthcare institutions and technology providers and covers areas such as clinical support, patient services, public health and emergency response, health education and research, and healthcare administration. Its framework is expressly risk-based and multidimensional: the appropriate level of protection depends on the use scenario, the relevant stage of the AI application's life cycle and the level of risk involved.
Given the sensitivity of healthcare data and decisions, the guideline places particular emphasis on privacy and data security. Health and medical data should be subject to controls throughout collection, storage, transmission, use and destruction, supported by measures such as encryption and de-identification. It also calls for transparency and explainability and for efforts to identify and reduce bias that could result in unequal outcomes for different groups.
Most importantly, the guideline maintains a clear division between AI assistance and medical decision-making. Doctors remain the decision-makers in medical activities: AI-generated diagnoses or treatment recommendations should be reviewed and confirmed by medical professionals and should not replace professional judgment. Patients should also be informed of the extent to which AI is involved in diagnosis or treatment and should have the right to refuse AI assistance. This makes human oversight and patient autonomy central elements of healthcare AI governance.
4. AI Application Security in Radio, Television and Online Audiovisual Services
The fourth guideline addresses AI applications in radio, television, IPTV, internet television and online audiovisual services, covering activities such as content planning and creation, production and broadcasting, transmission, and aggregation and distribution. In addition to the requirements under the General Guidelines, relevant institutions are expected to maintain human confirmation, manual-priority, rapid-switching and rollback mechanisms.
A major focus is the interaction between AI technology and existing content-management obligations. AI-generated, produced or distributed audiovisual programs remain subject to the same applicable content and broadcasting rules. The guideline also states that AI should not be used to generate current-affairs news; where AI is used in non-current-affairs news, appropriate disclosure should be provided in accordance with the applicable AI-generated-content labeling standard. Digital humans are also specifically addressed, including registration or record-filing, authorization for the use of a person's image or synthesized voice, and clear disclosure to viewers.
The guideline is also particularly relevant from an intellectual property perspective. It states that images, videos, audio and other materials used by AI, as well as generated content, should comply with applicable IP laws and be properly licensed where necessary. Notably, it distinguishes permission to use material for AI training from permission to reproduce, adapt, publish or disseminate resulting content: a training licence should not automatically be treated as granting downstream exploitation rights. This distinction may be useful more broadly when businesses structure licences for AI training and generated content.
Comment
The four guidelines illustrate a developing feature of China’s AI governance framework: general AI rules are increasingly being supplemented by sector-specific requirements based on the risks of particular applications. Education, healthcare and audiovisual services are areas where AI output can directly affect minors, individual rights, medical decisions or public information, which helps explain why they have been addressed first.
Although TC260’s Practice Guidelines are technical guidance rather than legislation in themselves, they can provide useful benchmarks for organizations designing internal AI governance and security controls. Businesses deploying AI in China may therefore increasingly need to consider not only general cybersecurity, data and AI requirements, but also whether their particular industry requires additional safeguards, human oversight and risk-management measures.
The new guidelines were developed against the backdrop of rapidly expanding AI deployment across industries. Their stated purpose is to address emerging security risks while enabling the safe use of AI. The framework follows a two-level structure: the General Guidelines provide common security guidance applicable across sectors, while the three sector-specific documents address risks and practices particular to their respective industries.
1. General Guidelines for AI Application Security
The Guidelines for AI Application Security — General Principles provide the baseline framework for AI applications across industries. Rather than focusing only on the security of an AI model itself, the Guidelines take a full life-cycle approach, covering planning, design and development, validation, deployment, operation and monitoring, continuous assessment, and eventual retirement. They apply broadly to organizations deploying AI and may also serve as a reference for regulators and third-party assessment bodies.
Five basic principles underpin the framework: human-centered and controllable AI, risk identification and tiered protection, security throughout the life cycle, testing and objective verification, and dynamic adjustment as technology and risks evolve. At the planning stage, organizations are expected to identify and classify AI-related risks, assess the maturity of their security capabilities, assign security responsibilities, and establish monitoring and emergency-response arrangements. Where an AI application may affect personal safety or property, the Guidelines specifically contemplate safeguards such as human takeover, version rollback and emergency shutdown.
The Guidelines also address practical risks arising during development and operation. These include security reviews of open-source frameworks and code, traceability and security of training-data sources, protection against data poisoning and other attacks, testing before deployment, monitoring of inputs and outputs, and maintaining records of important decisions and operations. The overall approach is therefore not simply to require a compliant AI product at launch, but to establish an ongoing governance process throughout the AI application’s life cycle.
2. AI Application Security in Education
The education guideline applies to AI use by educational institutions at different levels and distinguishes five principal scenarios: AI-assisted teaching, learning, research, management and assessment. It requires educational institutions to establish rules for AI use according to factors such as the user's role, age, educational stage, subject and task, and contemplates measures including approved-use lists, algorithm filing where applicable, security assessment, and classification of educational data.
A central theme is that AI should remain an assistant rather than a substitute for educators or educational decision-makers. AI-generated recommendations, judgments or assessments should be subject to human review and should not directly replace final decisions by educational institutions. The guideline also provides for mechanisms allowing affected persons to receive notice, challenge results, request human review and seek correction. Special protections apply to minors, including age-appropriate notices and settings, parental authorization where required, supervision by teachers or guardians, and restrictions on duration and functionality.
The document goes further by setting different expectations for particular educational stages and activities. For example, primary-school students should not independently use open-ended content-generation functions, while use may gradually expand at later educational stages. In teaching, AI should preferably provide reasoning, methods and step-by-step guidance rather than simply producing complete answers in inappropriate situations. In research, the guideline draws a clearer boundary between routine assistance and core academic work, with key elements such as research design, data interpretation and substantive arguments expected to remain the researcher's own work.
3. AI Application Security in Healthcare
The healthcare guideline applies to healthcare institutions and technology providers and covers areas such as clinical support, patient services, public health and emergency response, health education and research, and healthcare administration. Its framework is expressly risk-based and multidimensional: the appropriate level of protection depends on the use scenario, the relevant stage of the AI application's life cycle and the level of risk involved.
Given the sensitivity of healthcare data and decisions, the guideline places particular emphasis on privacy and data security. Health and medical data should be subject to controls throughout collection, storage, transmission, use and destruction, supported by measures such as encryption and de-identification. It also calls for transparency and explainability and for efforts to identify and reduce bias that could result in unequal outcomes for different groups.
Most importantly, the guideline maintains a clear division between AI assistance and medical decision-making. Doctors remain the decision-makers in medical activities: AI-generated diagnoses or treatment recommendations should be reviewed and confirmed by medical professionals and should not replace professional judgment. Patients should also be informed of the extent to which AI is involved in diagnosis or treatment and should have the right to refuse AI assistance. This makes human oversight and patient autonomy central elements of healthcare AI governance.
4. AI Application Security in Radio, Television and Online Audiovisual Services
The fourth guideline addresses AI applications in radio, television, IPTV, internet television and online audiovisual services, covering activities such as content planning and creation, production and broadcasting, transmission, and aggregation and distribution. In addition to the requirements under the General Guidelines, relevant institutions are expected to maintain human confirmation, manual-priority, rapid-switching and rollback mechanisms.
A major focus is the interaction between AI technology and existing content-management obligations. AI-generated, produced or distributed audiovisual programs remain subject to the same applicable content and broadcasting rules. The guideline also states that AI should not be used to generate current-affairs news; where AI is used in non-current-affairs news, appropriate disclosure should be provided in accordance with the applicable AI-generated-content labeling standard. Digital humans are also specifically addressed, including registration or record-filing, authorization for the use of a person's image or synthesized voice, and clear disclosure to viewers.
The guideline is also particularly relevant from an intellectual property perspective. It states that images, videos, audio and other materials used by AI, as well as generated content, should comply with applicable IP laws and be properly licensed where necessary. Notably, it distinguishes permission to use material for AI training from permission to reproduce, adapt, publish or disseminate resulting content: a training licence should not automatically be treated as granting downstream exploitation rights. This distinction may be useful more broadly when businesses structure licences for AI training and generated content.
Comment
The four guidelines illustrate a developing feature of China’s AI governance framework: general AI rules are increasingly being supplemented by sector-specific requirements based on the risks of particular applications. Education, healthcare and audiovisual services are areas where AI output can directly affect minors, individual rights, medical decisions or public information, which helps explain why they have been addressed first.
Although TC260’s Practice Guidelines are technical guidance rather than legislation in themselves, they can provide useful benchmarks for organizations designing internal AI governance and security controls. Businesses deploying AI in China may therefore increasingly need to consider not only general cybersecurity, data and AI requirements, but also whether their particular industry requires additional safeguards, human oversight and risk-management measures.