China - AI Regulation Overview
China AI Regulation Overview
中国人工智能法规概述
China
RAI-CN-NA-SUMMARY-2026China is rapidly developing a comprehensive AI regulatory framework, balancing innovation with stringent controls on content, data security, and national interests. This involves a mix of foundational laws and specific regulations for generative AI and deep synthesis, emphasizing transparency, accountability, and risk mitigation through a multi-agency governance model.
Overview
China's approach to artificial intelligence regulation is a dynamic and comprehensive one, driven by a national strategy to become a global leader in AI innovation by 2030, as outlined in the New Generation Artificial Intelligence Development Plan (2017). This ambition is balanced with a strong emphasis on maintaining national security, social stability, and protecting public interest and individual rights. The regulatory philosophy is characterized by a top-down, state-led approach that seeks to both foster rapid technological development and implement robust controls over its societal implications. This dual objective is evident in the rapid promulgation of a series of interconnected laws, regulations, and guidelines that cover various aspects of AI, from data governance and content generation to ethical principles and industry standardization. The maturity level of China's AI regulatory framework is rapidly advancing, moving from initial broad policy statements to increasingly detailed and enforceable legal instruments.
The regulatory environment reflects a proactive stance towards emerging AI challenges, such as deepfakes, algorithmic bias, and the impact of anthropomorphic AI. China's regulators, particularly the Cyberspace Administration of China (CAC), have demonstrated a willingness to issue specific rules for novel AI applications, often in draft form for public comment, allowing for iterative refinement. This approach aims to create a "healthy" online environment that aligns with socialist core values and national strategic objectives, while also encouraging innovation within defined ethical and legal boundaries. The overarching goal is to establish a holistic governance framework that ensures AI development is responsible, controllable, and beneficial to society, reflecting a sophisticated understanding of the technology's potential and risks.
Regulatory Approach
China's AI regulatory approach is distinctly hybrid, combining both horizontal and sectoral elements, and utilizing a mix of binding laws and soft law instruments. At its core, the framework is horizontal, with foundational laws like the Cybersecurity Law, Data Security Law, and Personal Information Protection Law providing overarching principles and obligations that apply to all data processing and network activities, including those involving AI. These foundational laws establish general requirements for data security, personal information protection, and network integrity, which are then elaborated upon by more specific AI-focused regulations. This horizontal base ensures a consistent baseline of compliance across the digital ecosystem, regardless of the specific AI application.
Complementing this horizontal approach are increasingly targeted regulations that address specific AI technologies or applications, demonstrating a risk-based and often prescriptive methodology. Regulations such as the Interim Measures for the Administration of Generative AI Services, the Provisions on the Administration of Deep Synthesis of Internet-based Information Services, and the Administrative Measures for the Labeling of AI-Generated Content are examples of binding rules that impose detailed obligations on providers of specific AI services. These measures often include explicit requirements for transparency (e.g., mandatory labeling of AI-generated content), content moderation, security assessments, and algorithm filing, particularly for services deemed to have "public opinion attributes or social mobilization capabilities." This tiered approach allows for greater scrutiny and more prescriptive controls on AI applications with higher potential societal impact or risk, reflecting a pragmatic balance between fostering innovation and mitigating harm.
Key AI Legislation
China's AI regulatory landscape is built upon a series of foundational laws and specific AI-focused regulations:
- 《数字虚拟人信息服务管理办法(征求意见稿)》 (Administrative Measures for Digital Virtual Human Information Services (Exposure Draft)): A proposed regulation aimed at standardizing digital virtual human services, protecting rights, and balancing innovation with oversight.
- 人工智能拟人化互动服务管理暂行办法(征求意见稿) (Interim Measures for the Administration of Anthropomorphic AI Interaction Services (Draft for Comments)): A draft regulation governing AI services that simulate human personality and communication for emotional interaction, focusing on transparency, content moderation, and user protection.
- 人工智能生成内容标识管理办法 (Administrative Measures for the Labeling of AI-Generated Content): Mandates explicit and implicit labeling for AI-generated content across various media types to enhance transparency and prevent misinformation.
- Measures for the Identification of AI-Generated (Synthetic) Content (人工智能生成合成内容标识办法): Provides a nationwide legal and technical baseline requiring AI-generated content to be identified using explicit (visible) and implicit (machine-readable) labels.
- Regulations on Network Data Security Management (网络数据安全管理条例): Implements and harmonizes provisions of the Cybersecurity Law, Data Security Law, and Personal Information Protection Law, establishing a comprehensive framework for network data processing, classification, and cross-border transfers.
- Interim Measures for the Administration of Generative AI Services (Generative AI Services Management Interim Measures): Establishes a cross-sectoral administrative framework for the development, deployment, and oversight of generative AI services offered to the public, focusing on lawful data sourcing, content safety, and transparency.
- Provisions on the Administration of Deep Synthesis of Internet-based Information Services: Addresses the harms presented by "deep synthesis" technologies (deepfakes), requiring identification marks, security assessments for certain services, and content prohibitions.
- Security Assessment Measures for Outbound Data Transfers (Measures for the Security Assessment of Outbound Data Transfers): Operationalizes cross-border data transfer provisions, defining scope, criteria for assessment, and responsibilities for data processors and regulatory offices.
- Data Security Law of the People's Republic of China: Provides a comprehensive statutory framework for the governance, protection, and lawful use of data, establishing a classification and graded protection regime and a national data security review system.
- Provisions on the Administration of Algorithmic Recommendation in Internet Information Services: Regulates algorithmic recommendation services, requiring transparency, user choice (e.g., ability to turn off personalized recommendations), protection for vulnerable groups, and algorithm filing for high-impact services.
- Personal Information Protection Law of the People's Republic of China (PIPL): China's comprehensive standalone personal data protection statute, codifying core principles, creating robust individual rights, and setting detailed obligations for personal information processors, including for cross-border transfers.
- Guidance on Building the National New Generation Artificial Intelligence Standardization System: A high-level, non-legislative framework guiding the development of an AI standardization ecosystem in China, focusing on safety, security, interoperability, and ethical concerns.
- Guidance on the Construction of National New Generation Artificial Intelligence Open Innovation Platforms: Provides an implementing framework to accelerate AI innovation, strengthen industry connections, and promote open, shared resources and services.
- Governance Principles for the New Generation of Artificial Intelligence (Developing Responsible Artificial Intelligence): A high-level, non-binding framework articulating eight core governance principles for responsible AI development.
- Notice of the State Council on Issuing the Development Plan for the New Generation of Artificial Intelligence (New Generation Artificial Intelligence Development Plan): A national strategy document laying out China’s top-level approach to AI development through 2030, defining strategic objectives and priority task areas.
- Promoting the Development of the New Generation Artificial Intelligence Industry: Three‑Year Action Plan (2018–2020): An operational, industry-focused policy document translating the national AI plan into concrete industrial objectives and measures.
- Cybersecurity Law of the People's Republic of China: The principal national statute for cybersecurity, network operation safety, and cross-sector information governance, establishing a graded protection regime and special safeguards for Critical Information Infrastructure.
Governance & Enforcement Bodies
China employs a multi-layered and collaborative governance structure for AI, with several key national agencies playing distinct yet coordinated roles. The Cyberspace Administration of China (CAC) stands as the primary regulatory authority, holding central responsibility for coordinating overall AI governance, internet information content, cybersecurity, and data protection. The CAC is instrumental in drafting, issuing, and enforcing regulations related to AI, including algorithm filing, security assessments, and content moderation for generative AI and deep synthesis services. Its broad mandate ensures a consistent national approach to the rapidly evolving digital landscape, often acting as the lead agency for new AI-specific rules.
Other ministries and state departments contribute to this comprehensive oversight. The Ministry of Industry and Information Technology (MIIT) plays a crucial role in industrial policy, telecommunications, and technical standards, actively supporting the development of China's AI industry while also overseeing cybersecurity and data security within its remit. The Ministry of Public Security (MPS) is responsible for public security, criminal enforcement, and investigating illegal activities involving AI, such as fraud or the dissemination of prohibited content. The National Radio and Television Administration (NRTA) supervises broadcast and audiovisual distribution, particularly relevant for AI-generated media. Furthermore, the National Development and Reform Commission (NDRC) contributes to macroeconomic planning and major AI project alignment, while the Ministry of Science and Technology (MOST) focuses on scientific research, establishing innovation platforms, and guiding ethical AI development through expert committees. The State Administration for Market Regulation (SAMR) oversees market supervision, including anti-monopoly and consumer protection, and the Standardization Administration of China (SAC), which operates under SAMR, leads national standardization efforts. This coordinated framework, often involving local counterparts, ensures that AI governance is integrated across technological, economic, security, and social dimensions.
Penalties & Enforcement
The penalties and enforcement mechanisms for AI-related violations in China are significant and are primarily derived from the foundational cybersecurity, data security, and personal information protection laws, which are then applied and supplemented by specific AI regulations. Violations can trigger administrative penalties, including warnings, public criticism, orders to rectify, suspension of information updates, and substantial fines. For instance, under the Personal Information Protection Law (PIPL), serious violations can lead to administrative fines of up to RMB 50 million or 5% of the previous year’s business turnover, along with confiscation of illegal gains, suspension of business, and revocation of permits or licenses. The Cybersecurity Law, particularly after its 2025 amendment, also imposes significant fines and sanctions for network operators and critical information infrastructure operators failing to meet security obligations.
Beyond administrative sanctions, responsible personnel can face personal fines, and in severe cases, criminal liability may be pursued under the PRC criminal law if the conduct constitutes a crime. Regulations like the Interim Measures for the Administration of Generative AI Services and the Provisions on the Administration of Deep Synthesis of Internet-based Information Services explicitly state that violations will be handled according to existing laws, providing a clear pathway for enforcement through established legal frameworks. The multi-agency enforcement approach, involving the CAC, MIIT, MPS, and other competent departments, ensures that a wide range of violations, from data breaches and content dissemination to algorithmic manipulation and national security threats, can be addressed effectively.
Data Protection Framework
China's data protection framework, which forms a critical backbone for AI regulation, is primarily anchored by three landmark laws: the Personal Information Protection Law (PIPL), the Data Security Law (DSL), and the Cybersecurity Law. The PIPL, effective November 1, 2021, is China's comprehensive privacy statute, akin to GDPR, establishing core principles such as lawfulness, purpose limitation, necessity, and transparency for personal information processing. It grants robust individual rights, including access, correction, deletion, and the right to object to automated decision-making. Critically for AI, PIPL mandates explicit consent for processing personal information, especially sensitive personal information (including biometrics and data of minors), and requires separate consent for cross-border transfers. It also imposes obligations on personal information processors to conduct impact assessments for high-risk processing activities, including automated decision-making and cross-border transfers.
The Data Security Law (DSL), effective September 1, 2021, establishes a comprehensive framework for data governance, protection, and utilization, applying to all data (personal and non-personal) within China. It introduces a data classification and graded protection regime, requiring data processors to categorize data by importance and implement corresponding security measures. The DSL also mandates a national data security review for activities affecting national security and reinforces controls on cross-border transfers, particularly for "important data." Complementing these, the Cybersecurity Law, effective June 1, 2017 (and amended in 2025), provides the foundational legal basis for network security, including data localization requirements for Critical Information Infrastructure (CII) operators and security assessments for cross-border data transfers. The Regulations on Network Data Security Management (effective January 1, 2025) further operationalize and harmonize these laws, providing detailed administrative rules for network data processing, important data identification, and cross-border transfer security assessments, creating a robust and interconnected data governance ecosystem for AI development and deployment.
Sector-Specific Rules
While China's AI regulatory framework largely adopts a horizontal approach, several regulations and policy documents demonstrate an increasing focus on sector-specific applications or types of AI with particular societal implications. The Administrative Measures for Digital Virtual Human Information Services (Exposure Draft) and the Interim Measures for the Administration of Anthropomorphic AI Interaction Services (Draft for Comments) are highly specialized, targeting AI services that simulate human characteristics for interaction and companionship. These proposed regulations impose specific requirements for content moderation, protection of minors, prevention of addiction, and transparency, directly impacting sectors like entertainment, customer service, and social media where virtual humans and anthropomorphic AI are deployed. Such targeted rules reflect a proactive effort to address the unique ethical and social challenges posed by these advanced AI applications.
Beyond these specific AI types, broader policy documents like the Promoting the Development of the New Generation Artificial Intelligence Industry: Three‑Year Action Plan (2018–2020) explicitly identify priority intelligent products and application domains. These include intelligent connected vehicles, service robots, UAVs, medical image assisted diagnosis systems, video image identity recognition, intelligent speech interaction, intelligent translation, and smart home products. While not strictly "regulations" with direct penalties, these plans guide industrial development, funding, and standardization efforts within these sectors, influencing future regulatory directions. The foundational data protection laws (PIPL, DSL, Cybersecurity Law) also have significant implications across all sectors handling data, such as finance and healthcare, by imposing stringent requirements for data security, personal information protection, and cross-border data transfers, thereby indirectly shaping AI development and deployment within these sensitive industries.
International Alignment
China's AI governance framework, while primarily focused on domestic objectives and national security, also acknowledges and engages with international efforts in AI regulation. The Governance Principles for the New Generation of Artificial Intelligence (2019) explicitly call for "openness and collaboration" and promote "international cooperation" in building a "community of common destiny for humanity". Similarly, the Guidance on Building the National New Generation Artificial Intelligence Standardization System (2020) encourages Chinese participation in international standards organizations, aiming to align domestic standardization activities with global norms where practicable. This indicates a strategic intent to contribute to and potentially influence global AI governance discussions, rather than operating in complete isolation.
However, China's approach also exhibits distinct differences from frameworks like the EU AI Act or OECD AI Principles, particularly in its strong emphasis on state control, content censorship, and national security. While there are overlaps in principles such as fairness, transparency, and safety, China's implementation often prioritizes national interests and social stability, leading to more prescriptive requirements for algorithm filing, security assessments, and content moderation. While direct "adoption" or explicit "influence" by the EU AI Act is not evident in the provided documents, China's ongoing engagement in international AI forums and its own rapid development of comprehensive AI regulations suggest a parallel evolution, where global best practices might be considered, but ultimately adapted to fit China's unique governance model and strategic priorities.
Future Developments
China's AI regulatory landscape is continuously evolving, with several key developments and pending legislation indicating a trajectory towards more comprehensive and granular oversight. Two significant proposed regulations are currently undergoing public consultation: the Administrative Measures for Digital Virtual Human Information Services (Exposure Draft), with its public comment period ending on May 6, 2026, and the Interim Measures for the Administration of Anthropomorphic AI Interaction Services (Draft for Comments), which had a public feedback deadline of January 25, 2026. The finalization and implementation of these measures will significantly shape the governance of highly interactive and human-like AI applications, introducing specific rules for content, user protection, and ethical considerations in these rapidly advancing domains.
Furthermore, while already in force, the implementation of several recent regulations will continue to unfold. The Regulations on Network Data Security Management, effective January 1, 2025, requires ongoing work in coordinating important-data catalogues by national and local authorities, which will further define data protection obligations for AI systems. The Administrative Measures for the Labeling of AI-Generated Content and the Measures for the Identification of AI-Generated (Synthetic) Content, both effective September 1, 2025, are in their early stages of compliance and enforcement, with audits commencing in October 2025 and first enforcement actions expected in January 2026. This indicates a period of active monitoring and evaluation by regulatory bodies to ensure adherence to labeling requirements. The 2025 amendment to the Cybersecurity Law, effective January 1, 2026, also explicitly references AI research and governance, signaling ongoing integration of AI considerations into China's foundational cybersecurity framework and potentially leading to further implementing rules or guidance in this area. These developments collectively point towards a sustained effort to refine and expand China's AI governance architecture.
Key Regulations
All 19 regulations currently tracked for China at national level.
Enforcement Bodies
| Agency | Mandate | Key Powers | Website |
|---|---|---|---|
| Cyberspace Administration of China (CAC) | Overall coordination and supervision of internet information services, cybersecurity, data protection, and AI governance. | Drafting and enforcing AI regulations, conducting security assessments, managing algorithm filing, content moderation, imposing administrative penalties. | www.cac.gov.cn |
| Ministry of Industry and Information Technology (MIIT) | Industrial policy, telecommunications, technical standards, supporting AI industry development, cybersecurity. | Formulating industrial policies, overseeing telecom operations, developing technical standards for AI, enforcing cybersecurity and data security within its remit. | www.miit.gov.cn |
| Ministry of Public Security (MPS) | Public security, criminal investigation, maintaining social order. | Investigating illegal and criminal activities related to AI misuse (e.g., fraud, illegal content dissemination), enforcing cybersecurity laws, cooperating in national security reviews. | www.mps.gov.cn |
| National Radio and Television Administration (NRTA) | Regulating broadcast and audiovisual content, media policy. | Supervising content generated or disseminated by AI in broadcast and online video, ensuring compliance with media regulations. | www.nrta.gov.cn |
| National Development and Reform Commission (NDRC) | Macroeconomic planning, industrial development, major project approval. | Guiding AI industrial development, aligning AI projects with national economic plans, influencing funding and resource allocation. | www.ndrc.gov.cn |
| Ministry of Education (MOE) | National education policy and administration. | Developing AI-related curricula, fostering AI talent, promoting AI research in educational institutions. | www.moe.gov.cn |
| Ministry of Science and Technology (MOST) | National science and technology policy, innovation strategy. | Guiding AI research and development, establishing AI innovation platforms, formulating AI ethical guidelines, coordinating major AI science projects. | www.most.gov.cn |
| State Administration for Market Regulation (SAMR) | Market supervision, anti-monopoly, consumer protection, intellectual property. | Enforcing market competition rules, addressing unfair practices related to AI (e.g., algorithmic discrimination in pricing), overseeing product quality and safety. | www.samr.gov.cn |
| Standardization Administration of China (SAC) | National standardization work. | Leading the formulation, revision, and implementation of national AI standards, coordinating international standardization efforts. | www.sac.gov.cn |
Real enforcement actions
2 actions recordedPublic enforcement actions where regulators cited China - AI Regulation Overview. Helps you see how the law is actually applied in practice.
- OtherFeb 25, 2025
Cyberspace Administration of China (CAC) vs Apps/mini-programs offering generative AI without security assessment
In its 2024 enforcement summary, the CAC reported taking down apps and mini-programs with opinion-influencing capacity that launched generative-AI services without the required security assessment, restored only after remediation.
Source ↗ - Enforcement orderNov 24, 2024
Cyberspace Administration of China (CAC) vs Online platform algorithm-recommendation providers
The CAC launched the 'Qinglang' special enforcement campaign on typical algorithmic problems, ordering platforms to self-inspect and rectify six categories of algorithmic abuse including information cocoons, ranking manipulation and big-data price discrimination.
Source ↗
Related Regulations
China - State AI Legislation Summary
China95% similar
Germany AI Regulation Overview
Germany93% similar
Interim Measures for the Administration of Generative AI Services (Generative AI Services Management Interim Measures)
China92% similar
South Korea AI Regulation Overview
South Korea92% similar
Australia AI Regulation Overview
Australia92% similar
© Regulations.AI — created on 05-Aug-2026 using Gemini 2.5 Flash