China Issues Draft Measures for Digital Virtual Human Information Services
Published 10 April 2026
Xia Yu
On 3 April 2026, the Cyberspace Administration of China issued the Administrative Measures for Digital Virtual Human Information Services (Exposure Draft) (“Draft Measures”), with a public comment period ending on 6 May 2026. The Draft Measures applies to the provision of internet information services to the public within the territory of China through digital virtual humans (“Digital Virtual Human Services”). This is a sector-specific departmental rule targeting digital virtual human services, marking the transition of virtual digital images from “technological exploration” to the era of “compliance regulation”.
Overview of the Draft Measures
The Draft Measures defines a digital virtual human as “a virtual digital image existing in a non-physical world, using technologies such as computer graphics, digital image processing or artificial intelligence, driven by real persons or computing, simulating human appearance, and possessing characteristics such as voice, behavior, interaction ability or personality”.
The Draft Measures consists of five chapters and 27 articles (including General Provisions, Protection of Rights and Interests, Service Standards, Supervision, Inspection and Legal Liability, and Supplemental Provisions), systematically establishing a governance system covering protection of rights and interests, service standards, and supervision and legal liability. The Draft Measures emphasizes “AI for good” from the outset and encourages technological R&D and innovation, standard-setting and international cooperation, reflecting a balanced approach of “development and security”.
The Protection of Rights and Interests chapter focuses on personality rights and personal information protection. Using sensitive personal information of natural persons for modelling, image generation or scene construction requires separate consent and prominent notification; using minors’ information requires separate consent from parents; it prohibits infringement of portrait rights, reputation rights, privacy rights, and prohibits distorting or defaming personality rights. It also explicitly prohibits providing “virtual relatives” or “virtual partners” and other intimate relationship services to minors.
The Service Standards chapter details eight categories of prohibited activities (including endangering national security, distorting heroes and martyrs, false advertising, bypassing identity authentication, etc.), and imposes obligations such as continuously displaying a “digital human” indicator throughout the service, data security protection, security risk monitoring and emergency response, and signing service agreements. In addition, it specifically requires that when using virtual humans in government services, public administration and judicial activities, human supervision and review mechanisms must be established, and users have the right to refuse the service.
The Supervision, Inspection and Legal Liability chapter establishes a dual-track supervision mechanism. Providers of digital virtual human services and providers of online information content dissemination services are required to set up user complaint and public reporting mechanisms. Providers of digital virtual human services with public opinion attributes or social mobilization capabilities, as well as technical supporters, are required to perform algorithm registration, amendment and cancellation registration under the Administrative Provisions on Algorithmic Recommendations for Internet Information Services [ https://www.cac.gov.cn/2022-01/04/c_1642894606364259.htm ], and to conduct security assessments. In terms of legal liability, warnings, criticism by circular, and orders to rectify may be imposed; if rectification is refused or circumstances are serious, service may be ordered to stop and a fine of RMB 10,000 to RMB 200,000 (approximately US$ 1,400 to 28,000) may be imposed.
Protection of Rights and Interests
The protection of rights and interests chapter focuses on the dual protection of sensitive personal information and personality rights. Article 7 requires that any organization or individual using sensitive personal information of natural persons (e.g., facial data, voiceprints) for modelling, image generation or scenario construction must satisfy three conditions: (1) obtain separate consent from the natural person and prominently notify the purpose of processing, necessity and impact on personal rights and interests; (2) after the natural person withdraws consent, delete the relevant personal information and deregister the digital virtual human; (3) not infringe upon others’ portrait rights, reputation rights, honor rights, privacy rights and personal information rights and interests. Article 8 explicitly prohibits infringing personality rights by distorting, defaming or other means; without the consent of a specific natural person, it is prohibited to provide digital virtual human services that are sufficient to identify the specific natural person – particularly targeting pen names, stage names, online aliases, trade names, abbreviations with certain social visibility, as well as highly similar portraits or voices. Article 9 requires that when using others’ written, artistic, photographic, musical, audiovisual works or products to create virtual humans, and during the use of digital virtual human services, intellectual property rights of others must not be infringed. Article 10 prohibits inducing minors to become addicted to digital virtual human services, including prohibiting the provision of virtual relative, virtual partner and other virtual intimate relationship services to minors, and prohibiting the provision of services that induce excessive consumption, induce religious belief, or may trigger imitation of unsafe behavior, anti-social behavior, extreme emotions, etc.
The most prominent highlight of the protection of rights and interests’ chapter is the close integration of sensitive personal information processing rules with personality rights (especially portrait rights and voice rights). Under traditional law, whether a “virtual image” constitutes an infringement of a real person’s portrait rights was ambiguous. Article 8 of the Draft Measures directly stipulates that “using a portrait or voice highly similar to a specific natural person” requires consent, effectively taking the “identifiability” of virtual images as the trigger for personality rights protection – a highly practical guidance. Moreover, the prohibition on “virtual intimate relationships” for minors in Article 10 is forward-looking on a global scale, directly responding to the risk of psychological dependence that AI companionship services may cause.
Service Standards
The service standards chapter specifies eight categories of prohibited activities and a full-process labelling obligation. Article 11 lists eight categories of prohibited activities. Among them, using digital virtual humans to bypass facial recognition, voice recognition and other identity authentication mechanisms directly responds to real-world risks such as “AI face-swapping fraud” and “virtual humans bypassing real-name authentication”; infringing upon the personal information and right to free choice of occupation of the real-person driver of a real-person-driven digital virtual human (i.e., a virtual digital image that uses motion capture technology to map a real person’s expressions, movements and voice in real time) protects the labor rights of the “person behind the character”; illegally registering or trading internet accounts is intended to prevent virtual humans from being used for “account farming” or “fake engagement”.
Article 13 imposes a highly operational “labelling obligation”. From the commencement of the service, providers and users of digital virtual human services and dissemination platforms must continuously display a prominent identification mark containing the words “digital human” in the display area of the virtual human, and comply with relevant national regulations on the labelling of AI-generated synthetic content. This means that when users watch virtual human live streams or short videos, a brief notice in a corner is insufficient – the label must be visible throughout. This requirement is stricter than existing AI-generated content labelling rules (which mostly require a “prominent position” or “capable of being clearly recognized by users”). For live streaming, real-time interaction and similar scenarios, the technical implementation cost is relatively high, but it can effectively prevent users from being misled.
Articles 14 and 15 provide for data security safeguards and risk monitoring mechanisms. They require that upon discovering illegal activities, measures such as dynamic identity verification, warnings, function restrictions and service termination be taken promptly; upon discovering significant risks, the digital virtual human service must be immediately suspended or terminated, the digital virtual human deregistered, and the impact eliminated. Article 18, targeting “anthropomorphic interactive services” (such as AI companions and virtual partners), prohibits deceiving or excessively inducing users to continue using the service; it also encourages active intervention and professional assistance for tendencies such as user suicide or self-harm.
International Comparison
The Draft Measures is currently one of the few national-level norms that systematically regulates the entire chain of virtual humans in the form of departmental rules. Globally, specialized legislation targeting digital virtual humans (or deep synthesis/AI-generated content more broadly) is still in its early stages.
The European Union has not yet adopted unified rules specifically for “digital virtual humans”, focusing instead on risk classification and transparency requirements for general AI systems. The EU AI Act [ https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689 ] classifies “deepfake” as an AI system subject to transparency obligations. Specifically, generating or manipulating images, audio or video content that is likely to deceive the public requires disclosure that the content is artificially generated or manipulated. In addition, biometric classification, emotion recognition and other scenarios are classified as “high-risk” or “prohibited”.
The United States has no federal law specifically targeting deep synthesis or digital virtual humans. Currently, California, Texas, Virginia and other states have enacted laws prohibiting the publication of deceptive deepfake content within 30 days before an election (especially targeting candidates), and requiring disclosure of synthetic images in pornographic content. At the federal level, proposals such as the DEEPFAKES Accountability Act have not yet been passed. Overall, US regulation is characterized by “fragmentation, ex post enforcement, and a focus on political and pornographic scenarios”.
Japan amended its Unfair Competition Prevention Act in 2023 [ https://www.wipo.int/wipolex/en/legislation/details/22619 ] to bring the provision or possession of “falsified real-person image data” within the scope of unfair competition regulation, but this mainly targets non-consensual deepfake pornographic content. For general digital virtual humans (such as virtual streamers and virtual idols), Japan relies more on industry guidelines (e.g., the Ministry of Internal Affairs and Communications’ AI Utilization Guidelines and corporate self-discipline, and has not yet introduced mandatory special regulations.
Conclusion
The Draft Measures represents a systematic legislative attempt by China in the fields of AI-generated content, the metaverse and digital virtual humans. It no longer remains at the level of principled advocacy, but provides a concrete list of behaviors, technical compliance requirements and a gradient of legal liability, offering strong guidance to the industry. Against the global backdrop where deep synthesis governance remains largely “principles plus ex post enforcement”, China has chosen a path of “ex ante registration + full-process labelling + personality rights reinforcement”. Its experience and challenges will provide an important reference for international digital governance.
Overview of the Draft Measures
The Draft Measures defines a digital virtual human as “a virtual digital image existing in a non-physical world, using technologies such as computer graphics, digital image processing or artificial intelligence, driven by real persons or computing, simulating human appearance, and possessing characteristics such as voice, behavior, interaction ability or personality”.
The Draft Measures consists of five chapters and 27 articles (including General Provisions, Protection of Rights and Interests, Service Standards, Supervision, Inspection and Legal Liability, and Supplemental Provisions), systematically establishing a governance system covering protection of rights and interests, service standards, and supervision and legal liability. The Draft Measures emphasizes “AI for good” from the outset and encourages technological R&D and innovation, standard-setting and international cooperation, reflecting a balanced approach of “development and security”.
The Protection of Rights and Interests chapter focuses on personality rights and personal information protection. Using sensitive personal information of natural persons for modelling, image generation or scene construction requires separate consent and prominent notification; using minors’ information requires separate consent from parents; it prohibits infringement of portrait rights, reputation rights, privacy rights, and prohibits distorting or defaming personality rights. It also explicitly prohibits providing “virtual relatives” or “virtual partners” and other intimate relationship services to minors.
The Service Standards chapter details eight categories of prohibited activities (including endangering national security, distorting heroes and martyrs, false advertising, bypassing identity authentication, etc.), and imposes obligations such as continuously displaying a “digital human” indicator throughout the service, data security protection, security risk monitoring and emergency response, and signing service agreements. In addition, it specifically requires that when using virtual humans in government services, public administration and judicial activities, human supervision and review mechanisms must be established, and users have the right to refuse the service.
The Supervision, Inspection and Legal Liability chapter establishes a dual-track supervision mechanism. Providers of digital virtual human services and providers of online information content dissemination services are required to set up user complaint and public reporting mechanisms. Providers of digital virtual human services with public opinion attributes or social mobilization capabilities, as well as technical supporters, are required to perform algorithm registration, amendment and cancellation registration under the Administrative Provisions on Algorithmic Recommendations for Internet Information Services [ https://www.cac.gov.cn/2022-01/04/c_1642894606364259.htm ], and to conduct security assessments. In terms of legal liability, warnings, criticism by circular, and orders to rectify may be imposed; if rectification is refused or circumstances are serious, service may be ordered to stop and a fine of RMB 10,000 to RMB 200,000 (approximately US$ 1,400 to 28,000) may be imposed.
Protection of Rights and Interests
The protection of rights and interests chapter focuses on the dual protection of sensitive personal information and personality rights. Article 7 requires that any organization or individual using sensitive personal information of natural persons (e.g., facial data, voiceprints) for modelling, image generation or scenario construction must satisfy three conditions: (1) obtain separate consent from the natural person and prominently notify the purpose of processing, necessity and impact on personal rights and interests; (2) after the natural person withdraws consent, delete the relevant personal information and deregister the digital virtual human; (3) not infringe upon others’ portrait rights, reputation rights, honor rights, privacy rights and personal information rights and interests. Article 8 explicitly prohibits infringing personality rights by distorting, defaming or other means; without the consent of a specific natural person, it is prohibited to provide digital virtual human services that are sufficient to identify the specific natural person – particularly targeting pen names, stage names, online aliases, trade names, abbreviations with certain social visibility, as well as highly similar portraits or voices. Article 9 requires that when using others’ written, artistic, photographic, musical, audiovisual works or products to create virtual humans, and during the use of digital virtual human services, intellectual property rights of others must not be infringed. Article 10 prohibits inducing minors to become addicted to digital virtual human services, including prohibiting the provision of virtual relative, virtual partner and other virtual intimate relationship services to minors, and prohibiting the provision of services that induce excessive consumption, induce religious belief, or may trigger imitation of unsafe behavior, anti-social behavior, extreme emotions, etc.
The most prominent highlight of the protection of rights and interests’ chapter is the close integration of sensitive personal information processing rules with personality rights (especially portrait rights and voice rights). Under traditional law, whether a “virtual image” constitutes an infringement of a real person’s portrait rights was ambiguous. Article 8 of the Draft Measures directly stipulates that “using a portrait or voice highly similar to a specific natural person” requires consent, effectively taking the “identifiability” of virtual images as the trigger for personality rights protection – a highly practical guidance. Moreover, the prohibition on “virtual intimate relationships” for minors in Article 10 is forward-looking on a global scale, directly responding to the risk of psychological dependence that AI companionship services may cause.
Service Standards
The service standards chapter specifies eight categories of prohibited activities and a full-process labelling obligation. Article 11 lists eight categories of prohibited activities. Among them, using digital virtual humans to bypass facial recognition, voice recognition and other identity authentication mechanisms directly responds to real-world risks such as “AI face-swapping fraud” and “virtual humans bypassing real-name authentication”; infringing upon the personal information and right to free choice of occupation of the real-person driver of a real-person-driven digital virtual human (i.e., a virtual digital image that uses motion capture technology to map a real person’s expressions, movements and voice in real time) protects the labor rights of the “person behind the character”; illegally registering or trading internet accounts is intended to prevent virtual humans from being used for “account farming” or “fake engagement”.
Article 13 imposes a highly operational “labelling obligation”. From the commencement of the service, providers and users of digital virtual human services and dissemination platforms must continuously display a prominent identification mark containing the words “digital human” in the display area of the virtual human, and comply with relevant national regulations on the labelling of AI-generated synthetic content. This means that when users watch virtual human live streams or short videos, a brief notice in a corner is insufficient – the label must be visible throughout. This requirement is stricter than existing AI-generated content labelling rules (which mostly require a “prominent position” or “capable of being clearly recognized by users”). For live streaming, real-time interaction and similar scenarios, the technical implementation cost is relatively high, but it can effectively prevent users from being misled.
Articles 14 and 15 provide for data security safeguards and risk monitoring mechanisms. They require that upon discovering illegal activities, measures such as dynamic identity verification, warnings, function restrictions and service termination be taken promptly; upon discovering significant risks, the digital virtual human service must be immediately suspended or terminated, the digital virtual human deregistered, and the impact eliminated. Article 18, targeting “anthropomorphic interactive services” (such as AI companions and virtual partners), prohibits deceiving or excessively inducing users to continue using the service; it also encourages active intervention and professional assistance for tendencies such as user suicide or self-harm.
International Comparison
The Draft Measures is currently one of the few national-level norms that systematically regulates the entire chain of virtual humans in the form of departmental rules. Globally, specialized legislation targeting digital virtual humans (or deep synthesis/AI-generated content more broadly) is still in its early stages.
The European Union has not yet adopted unified rules specifically for “digital virtual humans”, focusing instead on risk classification and transparency requirements for general AI systems. The EU AI Act [ https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689 ] classifies “deepfake” as an AI system subject to transparency obligations. Specifically, generating or manipulating images, audio or video content that is likely to deceive the public requires disclosure that the content is artificially generated or manipulated. In addition, biometric classification, emotion recognition and other scenarios are classified as “high-risk” or “prohibited”.
The United States has no federal law specifically targeting deep synthesis or digital virtual humans. Currently, California, Texas, Virginia and other states have enacted laws prohibiting the publication of deceptive deepfake content within 30 days before an election (especially targeting candidates), and requiring disclosure of synthetic images in pornographic content. At the federal level, proposals such as the DEEPFAKES Accountability Act have not yet been passed. Overall, US regulation is characterized by “fragmentation, ex post enforcement, and a focus on political and pornographic scenarios”.
Japan amended its Unfair Competition Prevention Act in 2023 [ https://www.wipo.int/wipolex/en/legislation/details/22619 ] to bring the provision or possession of “falsified real-person image data” within the scope of unfair competition regulation, but this mainly targets non-consensual deepfake pornographic content. For general digital virtual humans (such as virtual streamers and virtual idols), Japan relies more on industry guidelines (e.g., the Ministry of Internal Affairs and Communications’ AI Utilization Guidelines and corporate self-discipline, and has not yet introduced mandatory special regulations.
Conclusion
The Draft Measures represents a systematic legislative attempt by China in the fields of AI-generated content, the metaverse and digital virtual humans. It no longer remains at the level of principled advocacy, but provides a concrete list of behaviors, technical compliance requirements and a gradient of legal liability, offering strong guidance to the industry. Against the global backdrop where deep synthesis governance remains largely “principles plus ex post enforcement”, China has chosen a path of “ex ante registration + full-process labelling + personality rights reinforcement”. Its experience and challenges will provide an important reference for international digital governance.