China - Internet Information Synthesis Regulation

Provisions on the Administration of Deep Synthesis of Internet-based Information Services

互联网信息服务深度合成管理规定

China

RAI-CN-NA-PADSIXX-2022
Effective: January 10, 2023
In Force(In Force)
RegulationGovernance and OversightData Protection and PrivacyTransparency and Disclosure
Export PDF

The Provisions on the Administration of Deep Synthesis of Internet-based Information Services (issued jointly by the Cyberspace Administration of China, the Ministry of Industry and Information Technology and the Ministry of Public Security) set binding requirements for providers and technical supporters of ‘‘deep synthesis’’ (generative AI) services in China. They require identity verification, content review, visible labeling of synthetic content, training-data safeguards, security assessments for sensitive functions, recordkeeping and cooperation with regulators, and prohibit use for activities forbidden by law, including producing or spreading fake news or information that endangers national security or public interests.

Summary

Background and Purpose: The Provisions on the Administration of Deep Synthesis of Internet-based Information Services (《互联网信息服务深度合成管理规定》) were adopted by the Cyberspace Administration of China after coordination with the Ministry of Industry and Information Technology and the Ministry of Public Security and published on November 25, 2022. They entered into force on January 10, 2023. The rules are framed to implement and complement China’s Cybersecurity Law, Data Security Law, Personal Information Protection Law and existing rules on internet information services and algorithmic recommendation. The Provisions are aimed at identifying and mitigating the harms presented by ‘‘deep synthesis’’ technologies (commonly called deepfakes and other generative AI techniques) — including threats to national security, social order, public interests, personal rights and public trust.

Scope and Definitions: The Provisions apply to application of deep synthesis technologies inside the People’s Republic of China that provide internet information services. Deep synthesis technology is broadly defined to include any generative or synthetic algorithm — including deep learning and virtual reality techniques — that produces or edits text, images, audio, video, virtual scenes, 3D reconstructions and related network information. Distinct roles are defined: deep synthesis service providers (those offering services), technical supporters (entities offering technical support or models), and users (who use services to create, publish, or disseminate content). Training data is defined, and special categories such as immersive realistic virtual scenarios and biometric editing functions are expressly covered.

Main Duties and Prohibitions: The Provisions place primary responsibility on service providers to implement information-security duties: establish systems for user registration and real-name verification, algorithm mechanism review, ethics review, content review and publishing controls, data security measures and personal information safeguards, anti-telecom and online fraud controls, emergency response and logging. Providers must publish management rules and platform agreements, provide prominent notices of obligations to technical supporters and users, and maintain complaint, appeals and rumor-refutation mechanisms. The Provisions expressly prohibit any use of deep synthesis services to create, reproduce, publish or disseminate information forbidden by law (including false news) and activities endangering national security, harming national image, infringing public interests or disrupting social or economic order.

Labeling, Review and Technical Requirements: Deep synthesis outputs must include technical measures that add a non-disruptive mark identifying content as generated or edited by synthesis technology. Certain categories of services that can alter biometric features or that may implicate national security or the nation’s image must undergo security assessments (internal or by qualified third parties). Providers must establish feature libraries and rules to detect illegal or harmful content and retain relevant network logs. The Provisions forbid removal or tampering with required marks.

Registration, Filing and Supervision: Services that have public-opinion attributes or social mobilization capability must follow the algorithm-recommendation filing rules (record-filing with the Cyberspace Administration) and may be subject to security assessment for new products or features carrying those attributes. The Cyberspace Administration, MIIT and Ministry of Public Security (and local counterparts) are assigned coordination and supervisory roles. Supervisory authorities are empowered to require suspension of updates, account registration and other services if a service poses significant information security risks; providers must cooperate and carry out rectification.

Enforcement and Legal Consequences: Violations are subject to penalties under existing laws and administrative regulations; severe consequences may lead to more substantial administrative penalties, public-security punishments, or criminal liability where facts constitute crimes. The Provisions therefore act as a sectoral regulation channeling enforcement through established cybersecurity, data protection and public-order legal frameworks.

Relationship to other policy measures: The Provisions complement China’s Administrative Provisions on Algorithmic Recommendation for Internet Information Services and later measures governing generative AI services. They are an early, binding sectoral regulation addressing generative AI’s content and operational risks and form part of a broader domestic regulatory architecture focused on algorithm governance, data security and personal information protection.

Practical effects: Service providers (including platforms, application stores, model vendors and technical-support entities) operating in China must implement compliance programs (identity verification, labeling, content policing, training-data controls, assessments), document decisions and be prepared to support regulatory inspections. The rules shape product design, deployment and go-to-market planning for generative AI services in sectors including finance and health, where privacy, security and public-order risks are magnified.

Full article

Read full text ↗

Overview

The Provisions on the Administration of Deep Synthesis of Internet Information Services were jointly issued by the Cyberspace Administration of China, the Ministry of Industry and Information Technology and the Ministry of Public Security on November 25, 2022, and came into force on January 10, 2023. The regulation establishes a cross-sectoral governance framework for so-called deep synthesis (generative) technologies used to produce or edit text, images, audio, video and virtual scenes, placing primary compliance obligations on service providers and technical supporters while defining supervisory roles for national and local authorities. The policy objective emphasizes safeguarding national security and social public interests, protecting personal and property rights, promoting ethical use and preventing misuse (e.g., fraud, defamation, politically sensitive manipulation and dissemination of false information). The Provisions intersect with the Cybersecurity Law, Data Security Law and Personal Information Protection Law and are a foundational element of China’s algorithmic and AI governance architecture.

Definitions

The Provisions use explicit definitions to set the regulatory perimeter. Key definitions include "deep synthesis technology" — encompassing deep learning, virtual reality and other generative/synthetic algorithms that create or edit network information such as textual generation, text-to-speech, music generation, face generation and replacement, image enhancement, three-dimensional reconstruction and immersive virtual scenarios. "Deep synthesis service providers" refers to entities or individuals offering such services. "Technical supporters" are organizations or persons providing technical support (e.g., models, templates, APIs). "Training data" denotes datasets used to train models. These definitions are deliberately broad, covering tools, models, templates and services which create or materially alter content in ways that could mislead or harm observers.

Governance and Institutional Framework

The regulatory architecture assigns national coordination to the Cyberspace Administration of China while giving the Ministry of Industry and Information Technology and the Ministry of Public Security supervisory responsibilities according to their remits. Local counterparts mirror these responsibilities within their administrative regions. The Provisions require collaboration across agencies for inspection and enforcement and make explicit that telecom regulators, public-security organs and internet-administration bodies may exercise powers (including ordering suspension of updates, user registrations or other services where significant information-security risks are identified). The rule also encourages industry self-regulation and standard-setting by trade bodies. For the official text see the Cyberspace Administration of China commentary and expert materials and the promulgation notice on the MIIT website. These institutional assignments ensure both centralized policy coordination and locally actionable enforcement.

Key Focus Areas

The Provisions concentrate on several risk vectors. First, content and dissemination risks: providers must prevent and respond to unlawful or harmful uses—explicitly forbidding creation, reproduction or dissemination of information prohibited by law, including false news that could mislead the public. Second, identity and trust: providers must implement real-identity verification (via mobile number, ID number, social credit code or national network identity authentication) before allowing publishing privileges. Third, technical transparency and marking: generated or edited content must carry technical marks that identify synthesis origin; providers must not permit these marks to be removed or tampered with. Fourth, data governance: training datasets must be protected, and where they include personal or biometric data (face, voice), providers must comply with personal-information protections and obtain consent for editing others’ biometric features. Fifth, higher-risk functionality (face/voice editing, content implicating national image or security) is subject to mandatory security assessments. Sixth, content governance operations: providers must maintain feature libraries to identify illegal or undesirable content, carry out manual or automated reviews of inputs and outputs, retain logs, and establish complaint and rumor-refutation mechanisms. These focal points reflect a blend of content, privacy, safety and national-security priorities.

Implementation Framework

Operational requirements are framed as mandatory duties for providers and technical supporters. Providers must publish management rules, platform conventions and service agreements and prominently remind users and technical supporters of their security obligations. Identity verification must be used to gate publishable content; providers must not enable content publication for users without real-identity authentication. Providers must implement technical or manual review of user inputs and synthesis outputs, maintain and update a feature library of markers for illegal or harmful content, preserve logs and records, and set up a complaint/reporting channel with publicized processing timelines. Application distribution platforms (app stores) also share responsibilities to vet and remove non-compliant deep synthesis applications. For products with public-opinion attributes, filing and recordation obligations under the algorithm-recommendation rules apply. When regulators identify material information-security risks, they may order suspension of updates or registration and require rectification; providers must cooperate and take corrective steps.

Monitoring and Evaluation

The Provisions mandate recordkeeping and cooperation with regulatory inspections. Providers and technical supporters should be prepared to provide technical, operational and log data to the cyberspace, telecom and public-security authorities. Security assessments are mandated for new products or features with public-opinion attributes or social mobilization capability; similarly, models and templates that perform biometric editing or generate content touching on national security or public image are required to undergo safety evaluations (internally or by accredited third parties). The rules thus create both ex ante assessment duties and ex post inspection and supervisory pathways, enabling authorities to monitor compliance and evaluate systemic risks across the internet ecosystem.

Penalties, Liability, and Appeals

The Provisions do not set detailed monetary fines within the text but provide that violations will be punished in accordance with applicable laws and administrative regulations; serious consequences will receive heavier sanctions. Where conduct constitutes public-security offenses or crimes, public-security punishments or criminal liability will follow. Regulatory authorities can order measures such as suspension of services, account closures, removal of content, or other administrative actions. Providers who fail to cooperate with inspections or to implement required safeguards risk escalated administrative action, public-order penalties, or criminal referral. The regime therefore leverages the broader Chinese legal system (Cybersecurity Law, Data Security Law, PIPL, and administrative rules) for enforcement and sanctioning.

Relationship to Other Instruments

The Provisions are expressly linked to and implemented under the Cybersecurity Law, Data Security Law and Personal Information Protection Law. They dovetail with the Administrative Provisions on Algorithmic Recommendation for Internet Information Services and later measures governing generative-AI services (e.g., the interim Measures for the Administration of Generative Artificial Intelligence Services published in 2023). Where deep synthesis intersects with regulated sectors (news, publishing, culture, broadcasting), providers must also meet sector-specific regulatory requirements. The instrument therefore functions as a sector-specific expression of broader cybersecurity, data and privacy legal obligations and is part of a connected suite of algorithm and content regulation instruments.

International Alignment

China’s approach emphasizes national security, public-order and ideological conformity alongside privacy and data security. While the Provisions share commonalities with international best practices on labeling, risk assessment and data protection, they place greater emphasis on preventing content that affects national image or public opinion and on strict identity verification prior to publishing. International stakeholders assessing China’s policy landscape should read the Provisions alongside other domestic measures (e.g., algorithmic recommendation requirements) to understand how generative-AI services must be adapted for the Chinese market. For official commentary see the Cyberspace Administration analysis: CAC expert explanations.

Implementation Timeline

EventDate
Regulation reviewed and adopted at CAC office meeting2022-11-03
Joint promulgation by CAC, MIIT and MPS2022-11-25
Effective date2023-01-10
Subsequent generative AI provisional measures (multi-agency)2023-07-10 (promulgation); 2023-08-15 (effective)

Sources and References

SourceType
互联网信息服务深度合成管理规定 (Provisions on the Administration of Deep Synthesis of Internet Information Services) - MIIT (official text)Primary Source
CAC expert explanations and commentary on the ProvisionsPrimary Source

Requirements for a company

What an organisation has to do under China - Internet Information Synthesis Regulation, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

14
  • Prevent and respond to unlawful or harmful uses of deep synthesis services.Deep synthesis service providers.
  • Implement real-identity verification before allowing publishing privileges.Deep synthesis service providers.
  • Ensure generated or edited content carries technical marks identifying synthesis origin.Deep synthesis service providers.
  • Protect training datasets and comply with personal information protections, obtaining consent for biometric editing.Deep synthesis service providers and technical supporters.
  • Conduct mandatory security assessments for new products, features, or models with higher-risk functions.Deep synthesis service providers and technical supporters.
  • Cooperate with regulators and take corrective steps when ordered.Deep synthesis service providers and technical supporters.
  • +8 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under China - Internet Information Synthesis Regulation, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Deep synthesis service providers.Prevent and respond to unlawful or harmful uses of deep synthesis services.
providers must prevent and respond to unlawful or harmful uses—explicitly forbidding creation, reproduction or dissemination of information prohibited by law.
OngoingCritical
2Deep synthesis service providers.Implement real-identity verification before allowing publishing privileges.
providers must implement real-identity verification... before allowing publishing privileges.
Before allowing publishingCritical
3Deep synthesis service providers.Ensure generated or edited content carries technical marks identifying synthesis origin.
generated or edited content must carry technical marks that identify synthesis origin; providers must not permit these marks to be removed.
OngoingCritical
4Deep synthesis service providers and technical supporters.Protect training datasets and comply with personal information protections, obtaining consent for biometric editing.
training datasets must be protected, and where they include personal or biometric data... providers must comply with personal-information protections.
OngoingCritical
5Deep synthesis service providers and technical supporters.Conduct mandatory security assessments for new products, features, or models with higher-risk functions.
Security assessments are mandated for new products or features... models and templates... are required to undergo safety evaluations.
Before deploymentCritical
6Deep synthesis service providers and technical supporters.Cooperate with regulators and take corrective steps when ordered.
providers must cooperate and take corrective steps.
OngoingCritical
7Deep synthesis service providers.Maintain feature libraries to identify illegal or undesirable content.
providers must maintain feature libraries to identify illegal or undesirable content.
OngoingImportant
8Deep synthesis service providers.Carry out manual or automated reviews of deep synthesis inputs and outputs.
carry out manual or automated reviews of inputs and outputs.
OngoingImportant
9Deep synthesis service providers.Retain logs and records of deep synthesis operations.
retain logs, and establish complaint and rumor-refutation mechanisms.
OngoingImportant
10Deep synthesis service providers.Establish complaint and rumor-refutation mechanisms.
establish complaint and rumor-refutation mechanisms.
OngoingImportant
11Deep synthesis service providers.Publish management rules, platform conventions, and service agreements.
Providers must publish management rules, platform conventions and service agreements.
OngoingImportant
12Application distribution platforms.Vet and remove non-compliant deep synthesis applications.
Application distribution platforms... share responsibilities to vet and remove non-compliant deep synthesis applications.
OngoingImportant
13Deep synthesis service providers.Fulfill filing and recordation obligations for products with public-opinion attributes.
For products with public-opinion attributes, filing and recordation obligations under the algorithm-recommendation rules apply.
Before placing on marketImportant
14Deep synthesis service providers and technical supporters.Be prepared to provide technical, operational, and log data to authorities.
Providers and technical supporters should be prepared to provide technical, operational and log data to the cyberspace, telecom and public-security authorities.
OngoingImportant

© Regulations.AI · updated on 13-Jun-2026