Source basis
Official source basis
Last reviewed on 2026-06-09.
This profile is grounded in official laws, policy documents, regulator guidance, standards, and public-sector source materials listed below.
- Interim Measures for Generative AI Services
- Algorithm Recommendation Provisions
- Deep Synthesis Provisions
- AI-Generated and Synthetic Content Labeling Measures
- GB 45438—2025 Labeling Method Standard
- GB/T 45654—2025 Generative AI Service Security Basic Requirements
- Cybersecurity Law of the PRC
- Data Security Law of the PRC
Executive summary
China’s AI governance model is best understood as a layered regulatory architecture rather than a single comprehensive AI statute. Its foundation comes from cybersecurity, data security, personal information protection, network data governance, and internet information service regulation. AI-specific governance is added through the Algorithm Recommendation Provisions, Deep Synthesis Provisions, Interim Measures for Generative AI Services, and AI-generated/synthetic content labeling measures. Technical standards, including GB 45438—2025 and generative AI security requirements, translate parts of this regulatory architecture into operational controls. For enterprises, the practical burden is operational rather than only legal. A company deploying AI in China must examine whether its service is public-facing, whether it uses algorithm recommendation or deep synthesis technologies, whether generated or synthetic content requires explicit or implicit labels, whether personal information or important data is processed, whether data leaves China, whether security assessment or filing obligations are triggered, and whether sector-specific regulators are involved. China’s model therefore combines AI safety, cybersecurity, data security, content governance, platform accountability, and industrial development priorities.
Governance architecture
China’s AI governance architecture is led primarily through cyberspace, data, standards, industrial-policy, market-supervision, and sectoral authorities. The Cyberspace Administration of China is the central regulator for many AI-relevant internet information service rules, including algorithm recommendation, deep synthesis, generative AI services, AI-generated content labeling, data export security assessment, and network data governance. NDRC and MIIT are important for industrial strategy, digital infrastructure, AI+ deployment, and sectoral implementation. SAMR and SAC connect AI governance to the national standards system, while TC260 provides cybersecurity and AI security technical standards. MOST contributes responsible AI and ethics principles. MPS and sectoral regulators become relevant where AI systems implicate cybersecurity, public security, finance, healthcare, education, transport, or other regulated sectors.
Major policies and frameworks
| Policy | Issuer | Year | Status | Summary |
|---|---|---|---|---|
| Cybersecurity Law of the PRC | National People’s Congress / CAC official source | 2016 / amended version to verify | Law - Binding | Foundational cybersecurity law establishing baseline network security obligations and supervisory powers. AI relevance comes through cybersecurity duties for platforms, networks, online services, and AI-enabled systems. |
| Data Security Law of the PRC | National People’s Congress / CAC official source | 2021 | Law - Binding | Foundational data security law covering data processing, data classification, important data governance, risk monitoring, and national-security-oriented data controls relevant to AI training data and AI deployment. |
| Personal Information Protection Law of the PRC | National People’s Congress / CAC official source | 2021 | Law - Binding | Core personal information law relevant to AI systems that process personal information, profiling, automated decision-making, recommendation, model training, and cross-border personal information handling. |
| Network Data Security Management Regulation | State Council / CAC official source | 2024 | Administrative regulation - Binding | Operationalizes network data processing obligations and links personal information protection, important data, platform obligations, and cross-border data governance. |
| Internet Information Service Measures | State Council | Source year to verify | Administrative regulation - Binding | Baseline regulation for internet information services. Relevant because many AI services in China are governed through the internet information service framework. Official URL pending source-register verification. |
| Algorithm Recommendation Provisions | CAC and other departments | 2022 | Departmental rule - Binding | Core rule for algorithm recommendation services, including provider responsibilities, user rights, algorithm filing, minors, content governance, and platform accountability. |
| Deep Synthesis Provisions | CAC, MIIT, MPS | 2022 | Departmental rule - Binding | Core rule for deep synthesis technology services, covering synthetic media, content management, labeling, technical security, filing, and provider and technical-support roles. |
| Interim Measures for Generative AI Services | CAC and six other departments | 2023 | Interim measure - Binding | Core rule for public-facing generative AI services in China, including provider obligations, training data governance, generated content management, user rights, minor protection, complaints, security assessment, and filing-related duties. |
| AI-Generated and Synthetic Content Labeling Measures | CAC and other departments | 2025 | Departmental measure - Binding | Establishes labeling obligations for AI-generated and synthetic content, including explicit and implicit labels and platform transmission responsibilities. |
| GB 45438—2025 Cybersecurity Technology — Labeling Method for AI-Generated/Synthetic Content | SAMR / SAC | 2025 | Mandatory national standard | Technical standard specifying methods for AI-generated and synthetic content labeling. Operationalizes labeling requirements through explicit and implicit label methods. |
| GB/T 45654—2025 Cybersecurity Technology — Basic Security Requirements for Generative AI Services | TC260 / national standards system | 2025 | Recommended national standard / technical standard | Provides security requirements for generative AI services, including training data, model safety, output safety, testing, security measures, and assessment-oriented controls. |
| Data Export Security Assessment Measures | CAC | 2022 | Departmental rule - Binding | Governs security assessment for regulated outbound data transfers. Relevant to AI deployments involving personal information, important data, cross-border model access, or overseas processing. |
| Provisions on Promoting and Regulating Cross-Border Data Flows | CAC | 2024 | Data regulation / implementation rule | Provides updated cross-border data flow rules and exemptions. Relevant for multinational AI deployment and data-transfer planning. |
| New Generation Artificial Intelligence Development Plan | State Council | 2017 | Policy plan / industrial strategy | Foundational national AI strategy setting long-term development, governance, innovation, industrial, and social-management objectives. |
| Opinion on Deeply Implementing the “AI+” Action | State Council | 2025 | Policy opinion / industrial strategy | Recent national strategy for AI deployment across industry, public services, science, consumption, governance, and international cooperation. Treat as strategy, not binding AI compliance law. |
| AI Agent Standardized Application and Innovation Development Opinion | CAC and related authorities | 2026 | Policy opinion / implementation signal | Emerging policy signal for AI agents and safe deployment. Use as watchlist and strategy layer, not as the main legal foundation unless the source register confirms binding force. |
Policy timeline
2017
New Generation AI Development Plan issued
State Council issued the foundational national AI development strategy.
2019
Responsible AI governance principles issued
MOST-linked responsible AI principles set out early official governance values for responsible AI.
2021
Data Security Law and Personal Information Protection Law
China’s data and personal information legal foundation became central to AI governance.
2022-01
Algorithm Recommendation Provisions issued
China created a dedicated governance regime for internet information service algorithm recommendation activities.
2022-07
Data Export Security Assessment Measures issued
CAC established assessment requirements for certain outbound data transfers relevant to AI deployment and multinational operations.
2022-12
Deep Synthesis Provisions issued
China introduced a dedicated governance framework for deep synthesis and synthetic media services.
2023-07
Interim Measures for Generative AI Services issued
China issued core rules for public-facing generative AI services.
2024
Network Data Security Management Regulation issued
The regulation strengthened the operational data governance layer relevant to AI services.
2025
AI-generated and synthetic content labeling measures issued
China added a dedicated labeling layer for AI-generated and synthetic content.
2025
GB 45438—2025 labeling standard issued
The mandatory national standard created technical implementation methods for AI-generated and synthetic content labeling.
2025
GB/T 45654—2025 generative AI security requirements
The recommended standard translated generative AI safety and security expectations into operational technical requirements.
2026
AI agent implementation opinions
Emerging policy signal for standardized AI agent application and innovation development.
Enterprise implications
For enterprises, China’s AI governance system creates a multi-layer compliance burden. Companies should not treat AI compliance as only a model-safety issue. They need to assess service scope, public-facing deployment, platform status, algorithm recommendation functions, deep synthesis functions, generated or synthetic content labeling, training data governance, personal information processing, important data exposure, cross-border data transfer, cybersecurity obligations, security assessment, algorithm or service filing, user rights, complaint handling, minor protection, and content safety controls. The operational center of gravity is documentation and control. Enterprises deploying AI in China should build evidence around data provenance, model and output testing, labeling implementation, user notices, complaint channels, human review, cybersecurity management, content moderation, risk monitoring, vendor allocation, and readiness for regulatory review or filing. Multinational companies should pay special attention to cross-border data flows, model access from outside China, overseas API calls, and whether personal information or important data is processed in a way that triggers outbound data requirements.
Observatory interpretation
Observatory interpretation: China’s model is best described as a state-led, security-sensitive, platform-and-data governance model. It governs AI through the same institutional logic used for internet information services, cybersecurity, data governance, and platform accountability. Observatory interpretation: The most important compliance feature is the connection between AI governance and content/data controls. Algorithm recommendation, deep synthesis, generative AI, and labeling rules are not isolated AI policies; they sit inside a broader governance architecture concerned with public opinion, social mobilization, cybersecurity, data security, personal information protection, and platform responsibility. Observatory interpretation: China’s approach is operationally demanding for enterprises because obligations may arise from multiple layers at once: laws, administrative regulations, departmental rules, interim measures, technical standards, filing notices, security assessments, and sectoral requirements. The profile should therefore emphasize compliance architecture, not only legal taxonomy.
Official resources
| Resource | Source | Type | Date | Legal force | Why it matters |
|---|---|---|---|---|---|
| Interim Measures for Generative AI Services | CAC and six other departments | Guidance | 2023 | Binding | Main source for China’s generative AI service obligations. |
| Algorithm Recommendation Provisions | CAC and other departments | Guidance | 2022 | Binding | Main source for algorithm governance and filing. |
| Deep Synthesis Provisions | CAC, MIIT, MPS | Guidance | 2022 | Binding | Main source for deep synthesis governance. |
| AI-Generated and Synthetic Content Labeling Measures | CAC and other departments | Guidance | 2025 | Binding | Main legal source for labeling. |
| GB 45438—2025 Labeling Method Standard | SAMR / SAC | Standard | 2025 | Binding | Operationalizes labeling requirements. |
| GB/T 45654—2025 Generative AI Service Security Basic Requirements | TC260 / national standards system | Standard | 2025 | Guidance | Useful for security assessment and operational controls. |
| Cybersecurity Law | NPC / CAC official source | Law | 2025 amended version | Binding | Core cybersecurity layer for AI services. |
| Data Security Law | NPC / CAC official source | Law | 2021 | Binding | Core data governance layer for AI. |
| Personal Information Protection Law | NPC / CAC official source | Law | 2021 | Binding | Relevant to AI profiling, recommendation, and automated decision-making. |
| Network Data Security Management Regulation | State Council / CAC official source | Public-sector rule | 2024 | Binding | Bridges data, platform, and AI service obligations. |
| Data Export Security Assessment Measures | CAC | Guidance | 2022 | Binding | Important for multinational AI deployment. |
| Cross-Border Data Flow Provisions | CAC | Guidance | 2024 | Guidance | Important for data transfer planning. |
| New Generation AI Development Plan | State Council | Strategy | 2017 | Guidance | Explains the state-led development context. |
| AI+ Action Opinion | State Council | Strategy | 2025 | Guidance | Explains industrial and public-sector implementation direction. |
| AI Agent Implementation Opinion | CAC and related authorities | Strategy | 2026 | Guidance | Watchlist source for next-stage AI governance. |
| New Generation AI Ethics Norms | MOST | Guidance | 2021 | Guidance | Supports responsible AI layer. |
Downloadable artifacts
Comparative brief - planned
China AI Governance Compliance Matrix
Matrix mapping China’s AI obligations across generative AI, algorithm recommendation, deep synthesis, labeling, cybersecurity, data security, personal information, and cross-border data.
Comparative brief - planned
China AI Governance Timeline
Timeline of China’s AI governance evolution from the 2017 AI plan through algorithm, deep synthesis, generative AI, labeling, standards, and AI agent policy signals.
Comparative brief - planned
China AI Institutional Architecture Map
Map of CAC, NDRC, MIIT, MPS, SAMR, SAC, TC260, MOST, and sectoral regulators in China’s AI governance architecture.
Comparative brief - planned
Generative AI Service Provider Obligation Map
Practical map of provider obligations under China’s generative AI service regime, including data, output, user rights, complaints, minors, filing, and safety controls.
Comparative brief - planned
Algorithm Recommendation Governance Explainer
Explainer on algorithm recommendation obligations, user rights, filing, minors, content governance, and platform duties.
Comparative brief - planned
Deep Synthesis and Synthetic Media Compliance Map
Compliance map for deep synthesis services, synthetic media, labeling, filing, technical security, and service-provider roles.
Comparative brief - planned
AI-Generated Content Labeling Technical Explainer
Explains explicit labels, implicit labels, metadata, platform transmission obligations, and GB 45438—2025 implementation logic.
One-pager - planned
Explicit vs. Implicit Labeling Diagram
Visual diagram showing how visible labels and metadata-based implicit labels work under China’s labeling regime.
Comparative brief - planned
China AI Cross-Border Data Decision Tree
Decision tree for AI deployments involving personal information, important data, offshore model access, data export security assessment, and cross-border data flow rules.
Comparative brief - planned
Enterprise AI Deployment Readiness Checklist for China
Enterprise checklist for public-facing AI services, platform functions, data processing, labeling, safety assessment, filing, complaints, user rights, and monitoring.
Report - planned
China AI Source Inventory
Auditable source inventory for China AI governance profile development.
Report - planned
China AI Claim Register and Citation Map
Claim-level traceability file linking profile claims to source IDs, Chinese originals, working translations, official URLs, and caveats.
Update log
2026-06-09: Initial China profile content added using uploaded official source library and China official link register. Status set to initial / profile being expanded pending article-level claim register and citation-map verification.
