China - Generative AI Services Management

Interim Measures for the Administration of Generative AI Services

生成性人工智能服务管理暂行措施

China

RAI-CN-NA-IMAGAXX-2023
Effective: August 15, 2023
In Force(In Force)
RegulationGovernance and OversightData Protection and PrivacyConformity Assessment and Registration
Export PDF

Promulgated jointly by the Cyberspace Administration of China and six other ministries on July 10, 2023 (effective August 15, 2023), the Measures establish requirements for providers of generative AI services in China, covering lawful data use, personal information protection, content management, transparency, labeling of AI-generated content, risk assessments, and filing/record-keeping with authorities. The Measures apply to services that generate text, images, audio, video and other content for the public within China.

Summary

The Interim Measures for the Administration of Generative AI Services (issued July 10, 2023; effective August 15, 2023) are a joint regulatory instrument issued by the Cyberspace Administration of China (CAC) together with the National Development and Reform Commission (NDRC), Ministry of Education (MOE), Ministry of Science and Technology (MOST), Ministry of Industry and Information Technology (MIIT), Ministry of Public Security (MPS), and the National Radio and Television Administration (NRTA). They establish a cross-sectoral, administrative framework for the development, deployment and oversight of generative artificial intelligence services that produce text, image, audio, video, code or other synthetic content and are offered to the public within China. The Measures present high-level principles (development and security balanced, inclusive prudent and classified oversight), and a set of operational obligations for providers. Key regulatory obligations require lawful sourcing of training data (respecting intellectual property rights and data protection), protection of users' input content and usage records, technical and organizational measures to mitigate risks such as bias, discrimination, and misinformation, and explicit labeling of AI-generated or deep-synthesized content where required. Providers of services that possess public-opinion attributes or social-mobilization capabilities are subject to additional requirements, including security assessments and filing/registration procedures with CAC (or with local internet information authorities for territorially governed services). The Measures require providers to establish governance systems — including algorithm governance, ethical review mechanisms, data governance and personnel training — and to maintain transparent complaint and remediation channels. Where applicable, providers are treated as producers of internet information content and processors of personal information under Chinese law, thereby subjecting them to obligations and penalties under the Cybersecurity Law, Data Security Law, Personal Information Protection Law and relevant sectoral statutes. Enforcement tools comprise administrative orders, fines, temporary suspension, revocation of service, and referral to criminal liability where relevant. The Measures have been followed by technical guidance, standards and a recording/filing system administered by national and local internet information offices that track registered generative AI models and services. They are complemented by other Chinese regulatory instruments addressing deep synthesis, algorithm recommendation, content labeling, and scientific-ethical review, and form a central piece of China’s generative AI governance architecture.

Full article

Read full text ↗

Overview

The "Interim Measures for the Administration of Generative AI Services" ("Measures") were promulgated on July 10, 2023 by the Cyberspace Administration of China together with six other ministries and came into force on August 15, 2023. The Measures apply to services that use models and related technologies to generate text, images, audio, video and other content for the public within the territory of the People's Republic of China. They adopt a principles-based approach (development and security balanced) and impose specific operational obligations on providers relating to lawful training data usage, personal information protection, content governance, transparency and labeling, and risk mitigation. The Measures also require filing/registration for certain services and empower internet information authorities to conduct inspections and enforcement actions. The authoritative published text is available via the State Council Gazette and the national internet information office; see the full text and official announcements at State Council Gazette: Interim Measures and official CAC notices at Cyberspace Administration of China announcement.

Definitions

The Measures define "generative artificial intelligence services" as services that use algorithms, models and related technologies to provide the public with generated content such as text, images, audio and video. The Measures also clarify that the rules apply specifically to offerings to the public within PRC territory; R&D activities that do not provide public-facing services are outside the scope. Providers are defined broadly to include entities that develop, train, deploy or operate generative models and make generated content available to the public. The Measures reference other statutory definitions in the Cybersecurity Law, the Data Security Law and the Personal Information Protection Law for terms such as "personal information processor" and "internet information service".

Governance and Institutional Framework

The Measures establish a cross-ministerial governance model: the CAC leads administration, coordinated with the NDRC, MOE, MOST, MIIT, MPS and NRTA. This multi-agency approach aligns technical, security, content and broadcast supervision. Providers must establish internal governance systems including algorithm governance, scientific and ethical review mechanisms, content review and emergency response capabilities. Authorities maintain recording and filing systems for generative AI services and periodically publish lists of recorded models and services; local internet information offices handle filings for services with territorial "public opinion" attributes. The Measures also require cooperation with technical standard-setting and testing bodies — for example, national standards and technical guidelines issued by committees such as TC260 and related agencies — to operationalize obligations. For official promulgation and ongoing supervisory notices see the CAC portals and government gazette entries at Cyberspace Administration of China and Chinese Government (State Council).

Key Focus Areas

The Measures concentrate regulatory attention on several interlocking areas: (1) Data legality and provenance — models must be trained on lawful data that respect IP and privacy rights; (2) Personal information protection — providers are treated as personal information processors and must comply with PIPL; (3) Content safety and management — providers must prevent and remove content that endangers national security, undermines social stability, propagates terrorism, ethnic hatred, obscenity or misinformation; (4) Labeling — AI-generated and deep-synthesized content must be marked so users can identify synthetic material; (5) Risk mitigation — providers must take measures to avoid bias, discrimination, and harmful use, including in algorithm design and model training; (6) Transparency and user rights — providers must publish basic principles, service descriptions, and provide complaint and redress channels; (7) Registration and oversight — services with public opinion attributes must undergo security assessments and filing with CAC or local internet authorities; (8) Accountability — record-keeping, audit trails and designated responsible personnel are required to enable supervision and incident investigation. These focus areas are reinforced by follow-on technical standards and guidance documents issued by relevant national standardization and security bodies that help translate obligations into operational controls.

Implementation Framework

Implementation is a combination of provider obligations, technical standards and administrative oversight: providers must set up organizational structures (compliance officers, safety and ethics review panels), adopt data governance (data sourcing audits, IP clearance, consent management), perform security and risk assessments (particularly for services with social mobilization potential), and implement technical mitigations (watermarking, content filters, safety-aligned model tuning). The Measures call for filing/record-keeping with CAC for models made available as services; local filings are required for services with localized public-opinion impact. Government agencies (CAC and cooperating ministries) publish guidance and maintain registries; standards bodies publish technical specifications (e.g., content-marking methods, data-security practices) to support consistent compliance. Providers are expected to integrate compliance across the model lifecycle—pre-training, fine-tuning, deployment, and update management—and to maintain logs and complaint handling mechanisms to support inspections and audits.

Monitoring and Evaluation

The Measures authorize internet information authorities to inspect providers, demand rectification, and require reports on compliance measures. Authorities publish periodic registries of recorded generative AI services and may require providers to self-report incidents, security assessments or material changes (e.g., model updates that affect capabilities). Monitoring is both proactive (record/filing systems, technical testing, standards conformance) and reactive (complaint channels, takedown and incident reporting). Authorities coordinate cross-agency review where content, public security or broadcasting concerns intersect and may commission conformity assessment or certifications aligned to national technical standards to evaluate safety and reliability.

Penalties, Liability, and Appeals

The Measures tie enforcement to the broader PRC legal framework: violations may trigger administrative penalties under the Cybersecurity Law, Data Security Law, and PIPL, including fines, suspension of services, revocation of permits, public announcements of violations, and, where criminal conduct is involved, referral for criminal investigation. Providers are recognized as producers of online content and personal information processors for statutory liability purposes. The Measures foresee administrative orders for rectification, requirement to suspend provision of services, and other administrative sanctions. Appeals and administrative reconsideration follow applicable administrative procedure laws; affected entities can seek review through the administrative review and litigation channels prescribed by PRC law.

Relationship to Other Instruments

The Measures operate alongside and reference multiple existing instruments: the Cybersecurity Law, Data Security Law, Personal Information Protection Law, the "Deep Synthesis" rules for synthesized media, algorithm recommendation provisions, and sector-specific rules (e.g., publication or broadcasting regulations). They are supplemented by national standards, technical guidelines and subsequent ministerial measures addressing content labeling, pre-training data security, safety baseline requirements, and ethical review procedures — together forming a layered governance regime. Where sectoral laws (e.g., for news publishing or film production) contain special rules for content produced using generative AI, those sectoral rules take precedence as provided in the Measures.

International Alignment

China’s Measures emphasize development-security balance, national security and social stability, and align with international trends toward transparency, labeling and risk management for AI while reflecting China’s domestic legal priorities (data localization/controls, content management, and swift administrative oversight). The Measures have been discussed in multilateral AI governance fora and are complemented by standards and technical guidance intended to operationalize obligations. While sharing common themes with approaches in other jurisdictions (transparency, safety, data protection), the Measures are implemented within China’s administrative enforcement architecture and are coordinated across multiple ministries to address national-level public order, security and broadcasting concerns. Providers offering services internationally must consider extraterritorial compliance where services target or serve users within China.

Implementation Timeline

DateEvent
2023-05-23Measures reviewed and approved at CAC meeting (12th meeting, 2023). Source: CAC meeting records.
2023-07-10Measures promulgated jointly by CAC, NDRC, MOE, MOST, MIIT, MPS and NRTA. Source: State Council Gazette.
2023-08-15Measures came into effect.
2023-08 to 2024Follow-on technical standards, guidance and filing systems developed by standards bodies and CAC; filing of numerous generative AI services began.

Sources and References

SourceType
State Council Gazette: "Interim Measures for the Administration of Generative AI Services" (Promulgation and full text)Primary Source
Cyberspace Administration of China: Announcement and Q&APrimary Source

Read this article-by-article

Plain-English breakdown of 10 key articles, with cross-jurisdiction equivalents where applicable.

Open breakdown →

Requirements for a company

What an organisation has to do under China - Generative AI Services Management, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

7
  • Complete a security assessment with the Cyberspace Administration of China (CAC) and file the algorithm before providing services with public-opinion or social-mobilisation attributes.Providers of public-facing generative AI services in mainland China.
  • Use only training data from lawful sources, respect intellectual property and personal information, and avoid data containing prohibited content.All providers training generative AI models offered in China.
  • Identify and immediately stop generation, then remove, illegal content; report serious violations to authorities.All providers.
  • Verify users' real identities before providing services.Providers offering services to users in China.
  • Add prominent marks to AI-generated images, video, and other content; embed identifiers in metadata where feasible.All providers.
  • Publish service agreements clarifying user rights and obligations, complaint channels, and content rules.All providers.
  • +1 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under China - Generative AI Services Management, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Providers of public-facing generative AI services in mainland China.Complete a security assessment with the Cyberspace Administration of China (CAC) and file the algorithm before providing services with public-opinion or social-mobilisation attributes.Article 17Critical
2All providers training generative AI models offered in China.Use only training data from lawful sources, respect intellectual property and personal information, and avoid data containing prohibited content.Article 7Critical
3All providers.Identify and immediately stop generation, then remove, illegal content; report serious violations to authorities.Article 14Critical
4Providers offering services to users in China.Verify users' real identities before providing services.Article 9 (via PIPL & Cybersecurity Law)Critical
5All providers.Add prominent marks to AI-generated images, video, and other content; embed identifiers in metadata where feasible.Article 12Important
6All providers.Publish service agreements clarifying user rights and obligations, complaint channels, and content rules.Article 10Important
7Providers whose services are accessible to minors.Adopt measures to prevent minors from over-reliance on or addiction to generative AI services.Article 10Important

Real enforcement actions

1 action recorded

Public enforcement actions where regulators cited China - Generative AI Services Management. Helps you see how the law is actually applied in practice.

  1. Enforcement orderAug 31, 2023

    Cyberspace Administration of China (CAC) vs Multiple Chinese generative-AI service providers

    Sector: Generative AI

    Following the Generative AI Measures taking effect on 15 Aug 2023, the CAC required all public-facing generative AI services in mainland China to complete an algorithm filing and a security assessment before launch. The first wave (Aug 2023) cleared 11 services — Baidu's Ernie Bot, Alibaba's Tongyi Qianwen, ByteDance's Doubao, iFlytek's Spark, Sensetime, Baichuan, Zhipu, MiniMax and others — to operate publicly. Services that failed to file were ordered offline or removed from app stores. This is the most active enforcement regime for AI-specific law anywhere in the world to date, though most actions are filing-based rather than fine-based.

    Source ↗

© Regulations.AI · updated on 13-Jun-2026