Article-by-article breakdown
China - Generative AI Services Management
Interim Measures for the Administration of Generative AI Services (Generative AI Services Management Interim Measures)
Article 1 — Scope and General Principles
Applies to
- ›Providers of generative AI services
Plain English
The "Interim Measures for the Administration of Generative AI Services" apply to services that use algorithms, models, and related technologies to generate content like text, images, audio, and video, and make these available to the public within the People's Republic of China. The regulation adopts a balanced approach, aiming to promote the healthy development of generative AI while ensuring national security and social public interest.
It explicitly clarifies that research and development activities that do not provide public-facing services are outside the scope of these Measures. Providers are broadly defined to include entities that develop, train, deploy, or operate generative models and make generated content available to the public.
Key points
- •Applies to public-facing generative AI services within China.
- •Covers text, images, audio, video, and other generated content.
- •Balances AI development with security and public interest.
- •R&D activities not offered to the public are excluded.
What you need to do
- 1.Determine if your AI service is public-facing and operates within China.
- 2.Understand the broad definition of "generative AI services" to assess applicability.
- 3.Ensure your internal R&D is clearly separated from public offerings if you wish to remain out of scope.
Article 2 — Internal Governance and Regulatory Coordination
Applies to
- ›Providers of generative AI services
Plain English
The Measures establish a multi-ministerial governance framework, with the Cyberspace Administration of China (CAC) taking the lead, in coordination with six other ministries. Providers of generative AI services are required to establish robust internal governance systems.
These systems must include mechanisms for algorithm governance, scientific and ethical review, content review, and effective emergency response capabilities to manage risks and incidents. Furthermore, authorities maintain recording and filing systems for generative AI services, and providers may need to cooperate with technical standard-setting and testing bodies to operationalize their obligations.
Key points
- •Multi-agency regulatory oversight led by CAC.
- •Providers must establish internal governance systems.
- •Required internal systems include algorithm governance, ethical review, content review, and emergency response.
- •Services may be subject to official recording and filing.
What you need to do
- 1.Implement an internal AI governance framework, including a dedicated compliance team or officer.
- 2.Develop and document policies for algorithm design, ethical considerations, and content moderation.
- 3.Establish clear procedures for incident response and reporting.
- 4.Monitor for technical standards and guidelines to ensure operational compliance.
Article 3 — Lawful Training Data and Intellectual Property Rights
Applies to
- ›Providers of generative AI services
Plain English
Providers of generative AI services are obligated to ensure that the data used for training their models is legally sourced and compliant with relevant laws and regulations. This includes respecting intellectual property rights and obtaining necessary consents for data usage.
The Measures emphasize the importance of data provenance, requiring providers to take effective measures to enhance the legitimacy, accuracy, objectivity, and diversity of training data, thereby preventing discrimination in generated content.
Key points
- •Training data must be legally sourced.
- •Respect intellectual property rights (IPR).
- •Obtain necessary consents for data use.
- •Ensure data legitimacy, accuracy, objectivity, and diversity.
- •Prevent discrimination through data quality.
What you need to do
- 1.Conduct thorough due diligence on all training datasets to verify legal provenance and IP clearance.
- 2.Implement a robust consent management system for personal data used in training.
- 3.Establish processes for handling IP infringement claims related to training data or generated content.
- 4.Regularly audit training data for bias and representativeness.
Cross-jurisdiction equivalents
Article 4 — Personal Information Protection Obligations
Applies to
- ›Providers of generative AI services
Plain English
Under these Measures, providers of generative AI services are treated as "personal information processors" and must strictly comply with China's Personal Information Protection Law (PIPL). This entails adhering to principles such as obtaining individual consent for processing personal information, implementing data minimization practices, and ensuring the security of personal data.
Providers must also respect individuals' rights regarding their personal information, including the right to access, correct, or delete their data, and establish channels for users to exercise these rights.
Key points
- •Providers are considered "personal information processors."
- •Strict compliance with China's PIPL is mandatory.
- •Requires individual consent for personal information processing.
- •Implement data minimization and robust security measures.
- •Uphold individuals' rights over their personal information.
What you need to do
- 1.Review and update privacy policies to reflect PIPL and generative AI service specifics.
- 2.Implement PIPL-compliant consent mechanisms for data collection and processing.
- 3.Establish secure data handling protocols and data breach response plans.
- 4.Develop procedures for users to exercise their rights (e.g., data access, deletion).
Cross-jurisdiction equivalents
Article 5 — Content Safety and Governance
Applies to
- ›Providers of generative AI services
Plain English
Providers bear primary responsibility for the content generated by their generative AI services. They are required to take effective measures to prevent the generation of illegal or harmful content and to promptly remove such content if it appears.
The Measures specifically prohibit content that endangers national security, undermines social stability, propagates terrorism, ethnic hatred, obscenity, or misinformation. Providers must also establish mechanisms to filter and manage content that is not compliant with socialist core values.
Key points
- •Providers are responsible for generated content.
- •Must prevent and remove illegal/harmful content.
- •Prohibits content endangering national security, social stability, terrorism, hatred, obscenity, misinformation.
- •Requires content management aligned with socialist core values.
What you need to do
- 1.Develop and implement robust content moderation systems, including pre-generation filtering and post-generation review.
- 2.Establish clear content policies and guidelines for AI model training and deployment.
- 3.Implement rapid response and takedown procedures for prohibited content.
- 4.Continuously monitor and update models to minimize the generation of undesirable content.
Article 6 — Transparency and Content Labeling
Applies to
- ›Providers of generative AI services
Plain English
To ensure user awareness and trust, providers must maintain transparency regarding their generative AI services. This includes publishing basic principles, service descriptions, and rules of use. A key requirement is the clear labeling or marking of AI-generated and deep-synthesized content.
This ensures that users can easily identify when content, such as text, images, or videos, has been created or significantly altered by artificial intelligence, preventing confusion or deception.
Key points
- •Publish basic principles and service descriptions.
- •Clearly label all AI-generated content.
- •Deep-synthesized content must also be marked.
- •Aims to prevent user confusion or deception.
What you need to do
- 1.Integrate technical solutions for watermarking or embedding metadata in AI-generated content.
- 2.Ensure user interfaces clearly indicate when AI is used to generate or modify content.
- 3.Update terms of service and user guides to explain labeling practices.
- 4.Educate users on how to identify AI-generated content.
Cross-jurisdiction equivalents
Article 7 — Risk Mitigation and Bias Prevention
Applies to
- ›Providers of generative AI services
Plain English
Providers are mandated to take proactive measures to mitigate various risks associated with generative AI services. This includes actively working to prevent algorithmic bias, discrimination, and other potential harms that could arise from the use of their systems.
Risk mitigation efforts must be integrated throughout the AI lifecycle, from the initial design of algorithms to the training and deployment of models, ensuring that fairness, safety, and ethical considerations are paramount.
Key points
- •Proactively mitigate risks from generative AI.
- •Prevent algorithmic bias and discrimination.
- •Avoid other harmful uses of AI.
- •Integrate safety and ethics into algorithm design and model training.
What you need to do
- 1.Conduct regular bias audits and fairness testing on models and datasets.
- 2.Implement safety-aligned model tuning and red-teaming exercises.
- 3.Develop and adhere to internal ethical guidelines for AI development.
- 4.Establish mechanisms for identifying and addressing algorithmic harms post-deployment.
Article 8 — Service Registration and Security Assessments
Applies to
- ›Providers of generative AI services
Plain English
Generative AI services that possess "public opinion attributes" or "social mobilization capabilities" are subject to mandatory security assessments. Following these assessments, providers must complete a filing or registration process with the Cyberspace Administration of China (CAC) or relevant local internet information authorities.
The authorities are responsible for maintaining and periodically publishing lists of recorded generative AI services, providing transparency regarding regulated services and enabling public oversight.
Key points
- •Mandatory security assessments for services with "public opinion attributes."
- •Required filing/registration with CAC or local internet authorities.
- •Authorities publish lists of recorded services.
- •Applies to services with "social mobilization capabilities."
What you need to do
- 1.Evaluate if your service's nature or scale triggers "public opinion attributes" or "social mobilization capabilities."
- 2.Prepare for and undergo required security assessments.
- 3.Complete the necessary filing and registration procedures with the appropriate authorities.
- 4.Monitor official announcements and lists of recorded services.
Article 9 — Accountability, Record-Keeping, and User Redress
Applies to
- ›Providers of generative AI services
Plain English
Providers are held accountable for the operation of their generative AI services and must maintain comprehensive records and audit trails. These records are essential for enabling regulatory supervision, facilitating incident investigations, and demonstrating compliance.
Furthermore, providers must establish clear and accessible channels for users to submit complaints and seek redress for any issues or harms experienced due to the service, ensuring that user rights are protected and grievances can be addressed effectively.
Key points
- •Maintain comprehensive records and audit trails.
- •Enable regulatory supervision and incident investigation.
- •Provide clear channels for user complaints.
- •Establish mechanisms for user redress.
- •Ensure accountability for service operation.
What you need to do
- 1.Implement robust logging and data retention policies for model inputs, outputs, and user interactions.
- 2.Develop a user-friendly complaint system and a clear process for handling grievances.
- 3.Designate responsible personnel for managing accountability and user redress.
- 4.Regularly review and update record-keeping and complaint handling procedures.
Article 10 — Monitoring, Evaluation, and Enforcement
Applies to
- ›Providers of generative AI services
Plain English
The Measures grant internet information authorities broad powers to monitor and evaluate compliance. They can conduct inspections, demand rectification of non-compliant practices, and require providers to submit reports on their compliance measures.
Non-compliance can lead to significant administrative penalties under existing PRC laws, including the Cybersecurity Law, Data Security Law, and Personal Information Protection Law. These penalties may range from fines and suspension of services to revocation of permits. In cases involving criminal conduct, authorities are empowered to refer matters for criminal investigation.
Key points
- •Authorities can inspect, demand rectification, and require reports.
- •Violations lead to administrative penalties under existing laws.
- •Penalties include fines, service suspension, and permit revocation.
- •Criminal conduct may result in criminal investigation.
- •Emphasizes coordination across multiple ministries for enforcement.
What you need to do
- 1.Be prepared for potential inspections and audits by regulatory authorities.
- 2.Establish internal processes for responding to official inquiries and rectification orders.
- 3.Understand the potential legal and financial liabilities for non-compliance.
- 4.Ensure robust internal compliance to avoid enforcement actions.
Need help applying this to your case?
The wizard takes 60 seconds and tells you which articles you actually need to worry about based on your jurisdictions, use case, and data.
Start the wizard →