• About Us
  • People
    • Matthew Murphy
    • Ellen Wang
    • Yu Du
    • Xia Yu
    • Sarah Xuan
  • Practice Areas
    • Intellectual Property
    • Technology
    • Corporate
    • International Trade
    • International Arbitration
  • Insights
  • Accolades
  • Locations
  • Contact Us
  • 中文

China’s TC260 Releases Draft National Standard on Security Classification and Grading of AI Applications for Public Comment

Published 17 July 2026 Yu Du
On 15 July 2026, the National Technical Committee 260 on Cybersecurity of the Standardization Administration of China (“TC260”) released the draft national standard Cybersecurity Technology – Security Classification and Grading Methods for Artificial Intelligence Applications (the “Draft Standard”) for public comment by 13 September 2026.
TC260 is China’s national technical committee responsible for the development and revision of national standards concerning cybersecurity technologies, mechanisms, services, management and assessment. It also serves as China’s counterpart organization for ISO/IEC JTC 1/SC 27, which develops international standards in information security, cybersecurity and privacy protection.
Against the backdrop of the rapid deployment of artificial intelligence in areas such as content generation, decision support and autonomous control, the same underlying AI technology may present materially different risks depending on its users, deployment environment, business function, scale and level of autonomy. The Draft Standard seeks to provide a common, application-level methodology for identifying relevant security risks and assigning an overall security grade according to the likelihood and potential impact of those risks. It applies principally to developers, operators and other entities carrying out security classification and grading of AI applications.
The key provisions of the Draft Standard are summarized below.
1. Scope and Definition
The Draft Standard defines an “AI application” by reference to the use of functionally capable AI operating in a stakeholder context to achieve an intended outcome. This application-focused definition, which is derived from ISO/IEC 5339:2024, places emphasis on the actual deployment and use of an AI system rather than examining a model or technology only in the abstract.
2. Classification Is Based on a Set of Applicable Risk Entries
Under the Draft Standard, “classification” is not intended to result in a single descriptive label for an AI application. Instead, the organization should first analyze the application across the three prescribed dimensions and then identify all relevant risk-type entries.
Risk entries should generally be organized by industry sector, overarching risk category and specific risk category. For example, a risk entry could be recorded as “Education / AI technology-application security risk / information security risk / data and personal-information leakage.”
Where an industry-specific AI security risk list or similar document has already been issued, the organization should use that document to identify the relevant risk entries. In the absence of an applicable sector-specific document, the general risk catalogue in Appendix A of the Draft Standard may be used. An application spanning several sectors should be assessed against the relevant materials for each sector. The complete set of applicable risk entries constitutes the application’s security classification.
3. Application Scenario Attributes
The first classification dimension concerns the context in which the AI application is deployed. The Draft Standard identifies six principal factors.
These include the persons or organizations directly or indirectly served by the application; whether the application involves critical information infrastructure or important areas such as social governance, public security, automatic control, medical information services, psychological counselling or financial information services; and the technical and physical environment in which the application operates.
The assessment should also consider whether the system is deployed online or offline, in an open or closed network, under controlled or uncontrolled conditions, and whether it is deeply integrated with other information or physical systems. Other relevant factors include the number and geographical coverage of users, the frequency and continuity of use, and whether an incident could spread across interconnected systems or produce wider systemic effects.
4. Application Task Attributes
The second dimension concerns the purpose and functional characteristics of the AI application. The Draft Standard divides AI application functions into three broad categories.
 Content-generation applications generate content or provide conversational services, such as intelligent writing tools, chatbots and systems generating music, images or videos. Decision-support applications make data-based decisions or provide analysis and recommendations for human decision-making. The Draft Standard gives product recommendations, financial risk control, medical diagnosis and judicial assistance as examples. Autonomous-control applications possess automated decision-making capabilities and directly control the operation of real-world systems. Examples include autonomous driving, intelligent industrial control, robotics and intelligent traffic scheduling.
5. Level of AI Capability
The third dimension examines the application’s level of AI capability through four factors.
1) its ability to understand complex information, respond to complex scenarios and manage uncertainty;2) its degree of operational autonomy, including whether it merely provides recommendations, participates in part of a decision-making process, or independently makes and executes decisions throughout an entire process;3) whether the application can continuously learn, optimize itself or dynamically adjust its strategies;4) the transparency and controllability of the system, including whether its decision-making process and outputs are sufficiently transparent and whether human intervention, correction and emergency takeover are available.
6. Grading Based on Probability and Impact
After identifying the applicable risk entries, the organization should assess the probability of occurrence and the severity of impact for each entry. Both factors are divided into low, medium and high levels. Relevant national or sector-specific standards should be used where available; in their absence, the Draft Standard permits the use of expert judgment.
The Draft Standard provides a nine-cell risk matrix. Where impact severity is low, a low probability produces a low security risk level, while medium or high probability produces a general security risk level. Where impact severity is medium, a low probability produces a general risk level, while medium or high probability produces a relatively high risk level. Where impact severity is high, low, medium and high probability respectively produce relatively high, major and particularly major security risk levels.
Once each risk entry has been graded, the application’s overall grade is determined by the highest individual grade under the “highest-risk and most stringent” principle. The Draft Standard therefore does not permit high-risk items to be averaged down by a larger number of lower-risk items.
The organization should subsequently compare the result with the general descriptions of the five security levels. If there is a clear mismatch, the assessment may be recalibrated. This calibration mechanism reflects both the unpredictability of AI development and the unavoidable degree of judgment involved in estimating probability and impact. The grade should also be reviewed periodically and adjusted when circumstances change.
7. Five Security Levels
The Draft Standard establishes five application security levels.
 A low security risk level applies where the threat and affected scope are minimal, the application has essentially no impact on national security, social stability or citizens’ rights and interests, and any potential harm is minor. A general security risk level applies where there is some degree of threat but the affected scope is limited, the potential impact is relatively small and the harm remains controllable. A relatively high security risk level applies where the application presents an evident threat and localized impact and may cause significant effects on national security, social stability or citizens’ rights and interests, including localized societal harm. A major security risk level applies where the application presents a major threat with regional impact and may cause serious effects and substantial societal harm. A particularly major security risk level applies where the threat is catastrophic or systemic and may cause disruptive or irreversible, particularly serious effects on national security, social order or citizens’ rights and interests.
8. General Catalogue of AI Application Risks
Appendix A contains an informative and non-exhaustive general risk catalogue. The catalogue divides risks into two broad groups: risks arising from the application of AI technology and derivative risks resulting from the misuse, abuse or broader social effects of AI.
Technology-application risks include four categories. Network-system risks include vulnerabilities or backdoors in development frameworks, computing platforms and infrastructure; malicious consumption of computing resources; an expanded attack surface resulting from local deployment, agents and tool use; supply-chain instability associated with factors such as geopolitical developments and export controls; and the use of AI to lower the threshold for cyberattacks or defeat identity-verification systems through deepfakes.
Information-security risks include leakage of data and personal information retained in model parameters, the generation of fraudulent, violent, pornographic or extremist material, difficulties in identifying the provenance and authenticity of AI-generated content, and deterioration or pollution of the online information ecosystem.
Real-world security risks include hallucinations, erroneous decisions or operational deviations affecting critical infrastructure and service continuity; the use of AI to facilitate criminal activities; and the improper use of knowledge or capabilities relating to sensitive areas such as nuclear, biological, chemical, missile or weapons-related fields.
Cognitive-security risks include the narrowing of users’ information exposure through highly personalized services and the use of AI-generated content or social bots to manipulate information dissemination, public perceptions and value judgments.
Derivative risks include social and environmental risks, such as changes to employment structures and the consumption of electricity, land and water by AI infrastructure, as well as ethical risks relating to social fairness, overdependence on AI in learning and creative work, research ethics, emotional dependence arising from anthropomorphic interaction, changes to established social norms and uncertainty concerning AI systems operating beyond their intended design boundaries.
Comment
The Draft Standard is significant because it proposes a common, cross-sector framework for evaluating AI security risks at the level of the actual application. In practical terms, the same underlying model could receive different grades when used for internal document drafting, public-facing medical advice or autonomous industrial control. Organizations would therefore need to assess individual use cases rather than relying solely on a model-level or enterprise-wide assessment.
Businesses developing or operating AI applications in China should monitor the consultation process, consider whether to submit comments, and begin evaluating whether their existing AI inventories and risk-management procedures can support the application-level, evidence-based and dynamically updated assessment contemplated by the Draft Standard.

© 2026 - All rights reserved.

We use cookies to enable essential functionality on our website, and analyze website traffic. By clicking Accept you consent to our use of cookies. Cookies and Privacy Policy.

Your Cookie Settings

We use cookies to enable essential functionality on our website and analyze website traffic. For more information, read our Cookies and Privacy Policy below..

Cookie Categories
Essential

These cookies are strictly necessary to provide you with services available through our websites.

Analytics

These cookies collect information that is used in aggregate and in an anonymized form to help us understand how our website is being used and how effectively our site is performing.