CountryProfile being expanded

AI Governance Profile

China AI Governance Profile

Initial Observatory profile for China AI governance, covering algorithm recommendation regulation, deep synthesis regulation, generative AI services, AI-generated content labeling, data and cybersecurity links, technical standards, platform governance, and enterprise compliance implications.

Last reviewed 2026-06-09
China flag

Profile at a glance

Executive overview

Key signals for China AI governance, structured for quick institutional review before the full profile analysis below.

Region

Asia-Pacific

Governance model

Public-sector-led governance

Regulatory maturity

Advanced

Enterprise impact

High

Public-sector readiness

Advanced

Enforcement maturity

Active

Major policy and regulatory signals

  • Cybersecurity Law of the PRC
  • Data Security Law of the PRC
  • Personal Information Protection Law of the PRC
  • Network Data Security Management Regulation
  • Internet Information Service Measures

Enterprise implications

For enterprises, China’s AI governance system creates a multi-layer compliance burden.

Workforce and education implications

They need to assess service scope, public-facing deployment, platform status, algorithm recommendation functions, deep synthesis functions, generated or synthetic content labeling, training data governance, personal information processing, important data exposure, cross-border data transfer, cybersecurity obligations, security assessment, algorithm or service filing, user rights, complaint handling, minor protection, and content safety controls.

Last updated

2026-06-09

Key institutions

  • Cyberspace Administration of China
  • National Development and Reform Commission
  • Ministry of Industry and Information Technology
  • Ministry of Public Security
  • State Administration for Market Regulation
  • Standardization Administration of China
  • National Information Security Standardization Technical Committee TC260
  • Ministry of Science and Technology
  • sectoral regulators

Watchlist

  • Updates to generative AI service filing practice
  • updates to algorithm filing disclosures
  • implementation of AI-generated/synthetic content labeling measures
  • implementation of GB 45438—2025
  • publication or update of GB/T 45654—2025 generative AI service security requirements
  • updates to AI Safety Governance Framework
  • new rules for AI agents
  • updates to cross-border data transfer guidance
  • sector-specific AI rules in finance healthcare education and public services
  • enforcement signals from CAC and sectoral regulators

Executive summary

China’s AI governance model is best understood as a layered regulatory architecture rather than a single comprehensive AI statute. Its foundation comes from cybersecurity, data security, personal information protection, network data governance, and internet information service regulation. AI-specific governance is added through the Algorithm Recommendation Provisions, Deep Synthesis Provisions, Interim Measures for Generative AI Services, and AI-generated/synthetic content labeling measures. Technical standards, including GB 45438—2025 and generative AI security requirements, translate parts of this regulatory architecture into operational controls. For enterprises, the practical burden is operational rather than only legal. A company deploying AI in China must examine whether its service is public-facing, whether it uses algorithm recommendation or deep synthesis technologies, whether generated or synthetic content requires explicit or implicit labels, whether personal information or important data is processed, whether data leaves China, whether security assessment or filing obligations are triggered, and whether sector-specific regulators are involved. China’s model therefore combines AI safety, cybersecurity, data security, content governance, platform accountability, and industrial development priorities.

Governance architecture

China’s AI governance architecture is led primarily through cyberspace, data, standards, industrial-policy, market-supervision, and sectoral authorities. The Cyberspace Administration of China is the central regulator for many AI-relevant internet information service rules, including algorithm recommendation, deep synthesis, generative AI services, AI-generated content labeling, data export security assessment, and network data governance. NDRC and MIIT are important for industrial strategy, digital infrastructure, AI+ deployment, and sectoral implementation. SAMR and SAC connect AI governance to the national standards system, while TC260 provides cybersecurity and AI security technical standards. MOST contributes responsible AI and ethics principles. MPS and sectoral regulators become relevant where AI systems implicate cybersecurity, public security, finance, healthcare, education, transport, or other regulated sectors.

Major policies and frameworks

PolicyIssuerYearStatusSummary
Cybersecurity Law of the PRCNational People’s Congress / CAC official source2016 / amended version to verifyLaw - BindingFoundational cybersecurity law establishing baseline network security obligations and supervisory powers. AI relevance comes through cybersecurity duties for platforms, networks, online services, and AI-enabled systems.
Data Security Law of the PRCNational People’s Congress / CAC official source2021Law - BindingFoundational data security law covering data processing, data classification, important data governance, risk monitoring, and national-security-oriented data controls relevant to AI training data and AI deployment.
Personal Information Protection Law of the PRCNational People’s Congress / CAC official source2021Law - BindingCore personal information law relevant to AI systems that process personal information, profiling, automated decision-making, recommendation, model training, and cross-border personal information handling.
Network Data Security Management RegulationState Council / CAC official source2024Administrative regulation - BindingOperationalizes network data processing obligations and links personal information protection, important data, platform obligations, and cross-border data governance.
Internet Information Service MeasuresState CouncilSource year to verifyAdministrative regulation - BindingBaseline regulation for internet information services. Relevant because many AI services in China are governed through the internet information service framework. Official URL pending source-register verification.
Algorithm Recommendation ProvisionsCAC and other departments2022Departmental rule - BindingCore rule for algorithm recommendation services, including provider responsibilities, user rights, algorithm filing, minors, content governance, and platform accountability.
Deep Synthesis ProvisionsCAC, MIIT, MPS2022Departmental rule - BindingCore rule for deep synthesis technology services, covering synthetic media, content management, labeling, technical security, filing, and provider and technical-support roles.
Interim Measures for Generative AI ServicesCAC and six other departments2023Interim measure - BindingCore rule for public-facing generative AI services in China, including provider obligations, training data governance, generated content management, user rights, minor protection, complaints, security assessment, and filing-related duties.
AI-Generated and Synthetic Content Labeling MeasuresCAC and other departments2025Departmental measure - BindingEstablishes labeling obligations for AI-generated and synthetic content, including explicit and implicit labels and platform transmission responsibilities.
GB 45438—2025 Cybersecurity Technology — Labeling Method for AI-Generated/Synthetic ContentSAMR / SAC2025Mandatory national standardTechnical standard specifying methods for AI-generated and synthetic content labeling. Operationalizes labeling requirements through explicit and implicit label methods.
GB/T 45654—2025 Cybersecurity Technology — Basic Security Requirements for Generative AI ServicesTC260 / national standards system2025Recommended national standard / technical standardProvides security requirements for generative AI services, including training data, model safety, output safety, testing, security measures, and assessment-oriented controls.
Data Export Security Assessment MeasuresCAC2022Departmental rule - BindingGoverns security assessment for regulated outbound data transfers. Relevant to AI deployments involving personal information, important data, cross-border model access, or overseas processing.
Provisions on Promoting and Regulating Cross-Border Data FlowsCAC2024Data regulation / implementation ruleProvides updated cross-border data flow rules and exemptions. Relevant for multinational AI deployment and data-transfer planning.
New Generation Artificial Intelligence Development PlanState Council2017Policy plan / industrial strategyFoundational national AI strategy setting long-term development, governance, innovation, industrial, and social-management objectives.
Opinion on Deeply Implementing the “AI+” ActionState Council2025Policy opinion / industrial strategyRecent national strategy for AI deployment across industry, public services, science, consumption, governance, and international cooperation. Treat as strategy, not binding AI compliance law.
AI Agent Standardized Application and Innovation Development OpinionCAC and related authorities2026Policy opinion / implementation signalEmerging policy signal for AI agents and safe deployment. Use as watchlist and strategy layer, not as the main legal foundation unless the source register confirms binding force.

Policy timeline

2017

New Generation AI Development Plan issued

State Council issued the foundational national AI development strategy.

2019

Responsible AI governance principles issued

MOST-linked responsible AI principles set out early official governance values for responsible AI.

2021

Data Security Law and Personal Information Protection Law

China’s data and personal information legal foundation became central to AI governance.

2022-01

Algorithm Recommendation Provisions issued

China created a dedicated governance regime for internet information service algorithm recommendation activities.

2022-07

Data Export Security Assessment Measures issued

CAC established assessment requirements for certain outbound data transfers relevant to AI deployment and multinational operations.

2022-12

Deep Synthesis Provisions issued

China introduced a dedicated governance framework for deep synthesis and synthetic media services.

2023-07

Interim Measures for Generative AI Services issued

China issued core rules for public-facing generative AI services.

2024

Network Data Security Management Regulation issued

The regulation strengthened the operational data governance layer relevant to AI services.

2025

AI-generated and synthetic content labeling measures issued

China added a dedicated labeling layer for AI-generated and synthetic content.

2025

GB 45438—2025 labeling standard issued

The mandatory national standard created technical implementation methods for AI-generated and synthetic content labeling.

2025

GB/T 45654—2025 generative AI security requirements

The recommended standard translated generative AI safety and security expectations into operational technical requirements.

2026

AI agent implementation opinions

Emerging policy signal for standardized AI agent application and innovation development.

Enterprise implications

For enterprises, China’s AI governance system creates a multi-layer compliance burden. Companies should not treat AI compliance as only a model-safety issue. They need to assess service scope, public-facing deployment, platform status, algorithm recommendation functions, deep synthesis functions, generated or synthetic content labeling, training data governance, personal information processing, important data exposure, cross-border data transfer, cybersecurity obligations, security assessment, algorithm or service filing, user rights, complaint handling, minor protection, and content safety controls. The operational center of gravity is documentation and control. Enterprises deploying AI in China should build evidence around data provenance, model and output testing, labeling implementation, user notices, complaint channels, human review, cybersecurity management, content moderation, risk monitoring, vendor allocation, and readiness for regulatory review or filing. Multinational companies should pay special attention to cross-border data flows, model access from outside China, overseas API calls, and whether personal information or important data is processed in a way that triggers outbound data requirements.

Observatory interpretation

Observatory interpretation: China’s model is best described as a state-led, security-sensitive, platform-and-data governance model. It governs AI through the same institutional logic used for internet information services, cybersecurity, data governance, and platform accountability. Observatory interpretation: The most important compliance feature is the connection between AI governance and content/data controls. Algorithm recommendation, deep synthesis, generative AI, and labeling rules are not isolated AI policies; they sit inside a broader governance architecture concerned with public opinion, social mobilization, cybersecurity, data security, personal information protection, and platform responsibility. Observatory interpretation: China’s approach is operationally demanding for enterprises because obligations may arise from multiple layers at once: laws, administrative regulations, departmental rules, interim measures, technical standards, filing notices, security assessments, and sectoral requirements. The profile should therefore emphasize compliance architecture, not only legal taxonomy.

Official resources

ResourceSourceTypeDateLegal forceWhy it matters
Interim Measures for Generative AI ServicesCAC and six other departmentsGuidance2023BindingMain source for China’s generative AI service obligations.
Algorithm Recommendation ProvisionsCAC and other departmentsGuidance2022BindingMain source for algorithm governance and filing.
Deep Synthesis ProvisionsCAC, MIIT, MPSGuidance2022BindingMain source for deep synthesis governance.
AI-Generated and Synthetic Content Labeling MeasuresCAC and other departmentsGuidance2025BindingMain legal source for labeling.
GB 45438—2025 Labeling Method StandardSAMR / SACStandard2025BindingOperationalizes labeling requirements.
GB/T 45654—2025 Generative AI Service Security Basic RequirementsTC260 / national standards systemStandard2025GuidanceUseful for security assessment and operational controls.
Cybersecurity LawNPC / CAC official sourceLaw2025 amended versionBindingCore cybersecurity layer for AI services.
Data Security LawNPC / CAC official sourceLaw2021BindingCore data governance layer for AI.
Personal Information Protection LawNPC / CAC official sourceLaw2021BindingRelevant to AI profiling, recommendation, and automated decision-making.
Network Data Security Management RegulationState Council / CAC official sourcePublic-sector rule2024BindingBridges data, platform, and AI service obligations.
Data Export Security Assessment MeasuresCACGuidance2022BindingImportant for multinational AI deployment.
Cross-Border Data Flow ProvisionsCACGuidance2024GuidanceImportant for data transfer planning.
New Generation AI Development PlanState CouncilStrategy2017GuidanceExplains the state-led development context.
AI+ Action OpinionState CouncilStrategy2025GuidanceExplains industrial and public-sector implementation direction.
AI Agent Implementation OpinionCAC and related authoritiesStrategy2026GuidanceWatchlist source for next-stage AI governance.
New Generation AI Ethics NormsMOSTGuidance2021GuidanceSupports responsible AI layer.

Downloadable artifacts

Comparative brief - planned

China AI Governance Compliance Matrix

Matrix mapping China’s AI obligations across generative AI, algorithm recommendation, deep synthesis, labeling, cybersecurity, data security, personal information, and cross-border data.

Comparative brief - planned

China AI Governance Timeline

Timeline of China’s AI governance evolution from the 2017 AI plan through algorithm, deep synthesis, generative AI, labeling, standards, and AI agent policy signals.

Comparative brief - planned

China AI Institutional Architecture Map

Map of CAC, NDRC, MIIT, MPS, SAMR, SAC, TC260, MOST, and sectoral regulators in China’s AI governance architecture.

Comparative brief - planned

Generative AI Service Provider Obligation Map

Practical map of provider obligations under China’s generative AI service regime, including data, output, user rights, complaints, minors, filing, and safety controls.

Comparative brief - planned

Algorithm Recommendation Governance Explainer

Explainer on algorithm recommendation obligations, user rights, filing, minors, content governance, and platform duties.

Comparative brief - planned

Deep Synthesis and Synthetic Media Compliance Map

Compliance map for deep synthesis services, synthetic media, labeling, filing, technical security, and service-provider roles.

Comparative brief - planned

AI-Generated Content Labeling Technical Explainer

Explains explicit labels, implicit labels, metadata, platform transmission obligations, and GB 45438—2025 implementation logic.

One-pager - planned

Explicit vs. Implicit Labeling Diagram

Visual diagram showing how visible labels and metadata-based implicit labels work under China’s labeling regime.

Comparative brief - planned

China AI Cross-Border Data Decision Tree

Decision tree for AI deployments involving personal information, important data, offshore model access, data export security assessment, and cross-border data flow rules.

Comparative brief - planned

Enterprise AI Deployment Readiness Checklist for China

Enterprise checklist for public-facing AI services, platform functions, data processing, labeling, safety assessment, filing, complaints, user rights, and monitoring.

Report - planned

China AI Source Inventory

Auditable source inventory for China AI governance profile development.

Report - planned

China AI Claim Register and Citation Map

Claim-level traceability file linking profile claims to source IDs, Chinese originals, working translations, official URLs, and caveats.

Update log

2026-06-09: Initial China profile content added using uploaded official source library and China official link register. Status set to initial / profile being expanded pending article-level claim register and citation-map verification.