Three Years of China's Generative AI Regulation
Three years ago today, on August 15, 2023, China's digital landscape for artificial intelligence underwent a significant transformation with the entry into force of the Interim Measures for the Administration of Generative AI Services. This landmark regulation immediately established a comprehensive framework for the development and deployment of generative AI technologies across mainland China.
What's changing
The Generative AI Services Management Interim Measures, as they are formally known, have been binding for all public-facing generative AI service providers in China since their effective date. At its core, the regulation aims to balance innovation with control, ensuring that AI development aligns with national values and security objectives.
A primary requirement for many providers is the need for a "permission slip" before launch. Specifically, if a generative AI service possesses "public-opinion attributes" or "social-mobilisation capabilities"—a category that encompasses most large public-facing chatbots, image generators, and similar tools—providers must complete a security assessment with the Cyberspace Administration of China (CAC) and file their algorithms. This pre-emptive scrutiny ensures that potentially influential AI systems are vetted for compliance before they reach the public.
Data governance forms another cornerstone of the Measures. Providers are explicitly prohibited from using data obtained illegally for training their models. Furthermore, the regulation mandates respect for intellectual property rights and personal information during the data acquisition and training process. Synthetic or labelled data used for training must also adhere to specified quality standards, underscoring a commitment to responsible data practices.
Content moderation is a continuous obligation. Service providers are required to implement mechanisms to prevent their models from generating illegal content. This includes a broad spectrum of prohibited material, notably content that "subverts state power" or undermines national security, alongside other categories like defamation, obscenity, and incitement to violence. Should illegal content be generated, providers must promptly take it down and report serious violations to the relevant authorities.
In line with China's broader cybersecurity framework, the Measures also mandate real-name user registration for generative AI services. This requirement ensures accountability and traceability, aligning AI services with existing national identity verification protocols.
Visibility and transparency are addressed through the requirement to label AI output. Synthetic images, videos, and other generated content must be visibly marked to distinguish them from human-created material. Where technically feasible, embedded metadata identifiers are also encouraged to provide a deeper level of provenance.
Finally, the regulation includes specific provisions for the protection of minors. Providers must implement anti-addiction measures and develop age-appropriate guardrails to ensure that generative AI services are used safely and responsibly by younger users.
It's important to note that while the rules are extensive for public-facing services with "public-opinion attributes," the regulatory burden is lighter for services primarily serving enterprise customers (B2B) or internal tools that lack such attributes. However, even these services are still obligated to ensure lawful training data and protect intellectual property and personal information.
Who is affected
The scope of the Generative AI Services Management Interim Measures is broad, encompassing any entity that provides generative AI services to the public within mainland China. This applies equally to domestic Chinese companies and foreign entities whose services are accessible to and used by individuals in China. The regulation's reach is not limited by the size of the provider, but rather by the nature and accessibility of the service.
From its effective date three years ago, the regulation has directly impacted a diverse range of sectors. Technology companies developing large language models (LLMs), image generation tools, video synthesis platforms, and other creative AI applications have all had to adapt their operations. This includes major tech giants, AI startups, and even smaller developers offering niche generative AI tools. The distinction between services with "public-opinion attributes" and those without is crucial, as it determines the intensity of compliance requirements, particularly regarding the mandatory security assessment and algorithm filing. Any service that could influence public discourse or mobilise social action falls under the stricter regime.
The impact extends beyond the immediate providers to the entire AI ecosystem. Data providers, cloud service providers, and even users themselves are indirectly affected by the requirements for lawful data, content moderation, and real-name verification. The regulation has fundamentally reshaped how generative AI is developed, deployed, and consumed in one of the world's largest digital markets, ensuring that all players operate within a clearly defined, if stringent, regulatory perimeter.
Three things to do this week
Even three years on, compliance with China's Generative AI Measures remains an ongoing process. For any entity providing or considering providing generative AI services in mainland China, particularly those with public-facing applications, these three actions are critically important:
- Complete a security assessment and file your algorithm with the CAC. If your service has "public-opinion attributes" or "social-mobilisation capabilities"—which applies to most large public-facing generative AI tools—this is a prerequisite for operation. Article 17 of the Measures explicitly states this requirement, making it a non-negotiable step before offering services to the public. Providers must ensure their algorithms and underlying data practices align with national security and public interest standards as assessed by the Cyberspace Administration of China.
- Ensure all training data is lawfully sourced and respects IP/PI. A foundational principle of the Measures, articulated in Article 7, is the requirement for training data to be obtained legally. This means rigorously vetting data sources to confirm they do not contain prohibited content, respect intellectual property rights, and adequately protect personal information. Companies must implement robust data governance frameworks to track data provenance and ensure ongoing compliance with these standards, avoiding any data obtained through illicit means.
- Implement robust content moderation and reporting mechanisms. Article 14 places a clear obligation on providers to identify and immediately stop the generation of illegal content, remove it, and report serious violations to the authorities. This requires sophisticated content filtering systems, human oversight, and clear internal protocols for handling prohibited outputs. Continuous monitoring and adaptation of these systems are essential, given the dynamic nature of generative AI and the evolving definitions of prohibited content.
Related context
The Generative AI Services Management Interim Measures do not operate in a vacuum; they are an integral part of China's broader and increasingly sophisticated digital governance framework. They build upon and interact with existing foundational laws such as the Personal Information Protection Law (PIPL) and the Cybersecurity Law. These earlier laws impose their own stringent requirements, including data localisation for critical information infrastructure operators and strict rules around cross-border data transfers, which generative AI providers must also navigate.
Furthermore, the Measures are complemented by more specific regulations targeting AI-driven content. The Provisions on the Administration of Deep Synthesis of Internet-based Information Services, which took effect in January 2023, already addressed synthetic media and deepfakes, setting precedents for content labeling and ethical use. The Generative AI Measures expand on this by specifically covering the generation aspect. Looking ahead, the Measures for the Identification of AI-Generated (Synthetic) Content (人工智能生成合成内容标识办法), which became effective in 2025, further solidifies the requirements for clear and consistent labeling of AI-generated content, reinforcing the transparency objectives outlined in the Generative AI Measures. Together, these regulations form a comprehensive and evolving regulatory landscape for artificial intelligence in China, reflecting a strategic approach to managing emerging technologies.
Note: this article was drafted by AI - Google Gemini