China does not yet regulate artificial intelligence through one consolidated AI act. A China-facing product may instead fall within rules for generative AI, algorithmic recommendations, deep synthesis, AI-generated-content labeling, personal information, cybersecurity and a regulated sector.
This guide gives product, legal and compliance teams a launch map current to 31 August 2026. It distinguishes public-facing providers, content-distribution platforms, enterprise deployers and overseas vendors, then identifies when filing, safety assessment, labeling, training-data and user-protection workstreams need specialist confirmation.
Start with the service, role and China connection
Do not begin with the word “AI.” Document what the product does, who receives it, where those users are located, who controls the model and interface, whether outputs are published, and which entity operates the China-facing service.
| Role | First compliance question | Typical evidence |
|---|---|---|
| Public generative-AI provider | Is a service generating text, images, audio, video or other content for the public in China? | Service map, model and provider chain, filing analysis, safety controls and terms |
| Algorithmic-recommendation provider | Does an internet information service use generation, personalisation, ranking, filtering or scheduling algorithms? | Algorithm inventory, governance review, user controls and filing analysis |
| Deep-synthesis provider or technical supporter | Can the service generate or materially alter voices, faces, video, virtual scenes or human-like content? | Identity and consent controls, model review, logs, labels and assessment analysis |
| Content-distribution platform | Does the platform receive or disseminate content made by another AI service or its users? | Metadata detection, user declaration, visible notices and provenance records |
| Enterprise deployer | Is the tool internal, or does it become part of a public, employment, customer or regulated decision? | Use-case approval, privacy assessment, vendor diligence, human review and incident plan |
An API label or B2B contract does not settle the analysis. Confirm the actual recipients and functions. The 2023 generative-AI measures focus on services offered to the public in mainland China and state that industry organisations, enterprises, research and education bodies, and public cultural institutions are outside those measures when they develop or use generative AI without offering services to the domestic public. Other privacy, security, employment, IP and sector rules can still apply.
The operative rule stack
- Generative AI: provider duties for lawful training inputs, personal information, intellectual property, output governance, user protection, complaints and regulatory cooperation.
- Algorithmic recommendations: governance, transparency, user-choice and filing duties for covered internet information services.
- Deep synthesis: training-data and technical management, identity and consent controls, safety assessment for specified functions, logs and synthetic-content notices.
- AI-generated-content labels: from 1 September 2025, explicit and implicit labels, propagation-platform handling, user declarations and anti-tampering rules operate with mandatory GB 45438-2025.
- Anthropomorphic interaction: from 15 July 2026, dedicated duties apply to continuing emotional-interaction services that simulate a natural person's personality, thinking and communication style.
- Horizontal and sector rules: PIPL, Data Security Law, Cybersecurity Law, advertising, consumer, employment, copyright, product safety, healthcare, finance and other vertical rules remain separate workstreams.
China's 2026 legislative work plan calls for advancing comprehensive AI legislation. That is a legislative programme, not a basis to describe a consolidated “China AI Law” as already enacted.
Public-facing generative AI provider controls
- Training inputs: establish lawful sources, respect IP, obtain consent or another valid basis for personal information, and improve training-data quality, accuracy, objectivity and diversity.
- Output and service governance: prevent prohibited content, address unlawful content found in operation, improve transparency and reliability, and avoid discrimination based on protected characteristics.
- User framework: use service agreements, protect input and usage records, provide complaint and reporting channels, and avoid collecting unnecessary personal information.
- Filing and assessment: determine whether a service with public-opinion attributes or social-mobilisation capacity requires security assessment and algorithm filing. Do not promise a filing result before the competent authority's process is complete.
- Model and API chain: identify the filed or registered base-model capability, operator, hosting, moderation and downstream allocation. CAC's living announcement says online applications or functions should display the model name and filing number used.
Algorithm filing is trigger-based
The algorithmic-recommendation provisions cover generation and synthesis, personalised push, ranking and selection, search and filtering, and scheduling and decision-making technologies used to provide internet information services. Providers with public-opinion attributes or social-mobilisation capacity must complete the prescribed filing within ten working days after providing the service, display the filing number and public-information link, and address changes or cancellation under the rules.
Maintain a filing memo that records the service, covered entity, algorithm type, public-facing functions, launch date, public-opinion or mobilisation analysis, security-assessment position, filed materials, changes and public display. A filing is not a general government endorsement of product accuracy, safety or legality.
AI-generated and synthetic content labeling
The 2025 labeling measures distinguish an explicit label, visible or audible to a user, from an implicit label placed technically in file metadata. For covered generated or synthetic text, images, audio, video and virtual scenes, product design must follow both the measures and GB 45438-2025.
- Place explicit labels in the required position or interface for the relevant medium and preserve them in download, copy or export functions.
- Insert the required provenance information in metadata, including generated-content attributes and production identifiers.
- For a propagation platform, inspect metadata, accept user declarations, identify visible labels or other synthesis traces, add an appropriate public notice, and write propagation information into metadata where required.
- Explain labeling methods and user obligations in the service agreement.
- If a provider offers output without an explicit label under the limited user-request route, document the agreement, user obligations and responsibility, and retain the required recipient information and logs for at least six months.
- Do not provide tools or workflows that maliciously remove, alter, forge or conceal required labels.
Label compliance should be tested across the entire export path, including screenshots, copied text, API responses, compressed files, editing, reposting and third-party distribution. A watermark alone does not necessarily satisfy the metadata requirement.
Anthropomorphic emotional-interaction services
The 2026 measures apply to continuing emotional-interaction services offered to the public in China that simulate natural-person personality traits, thinking patterns and communication styles. They expressly exclude ordinary customer service, knowledge Q&A, work assistants, education and scientific-research services when those services do not involve continuing emotional interaction.
Covered providers need lifecycle safety governance, privacy and interaction-data controls, safeguards against excessive dependence and emotional manipulation, minor and older-user protections, clear AI identity notices, exit functions, complaints, algorithm filing and event-triggered safety assessment. The rules include a reminder after each period of more than two hours of continuous use. They also restrict virtual intimate relationships for minors and require guardian consent for other covered services supplied to children under 14.
Do not generalise these duties to every chatbot. Record why the use case is or is not continuing emotional interaction and revisit the conclusion when persona, memory, companionship or engagement functions change.
Training data, prompts and enterprise deployment
- Map dataset, prompt, retrieval, fine-tuning, feedback and log data separately.
- Identify personal and sensitive personal information, notices, consent or other processing basis, retention, deletion and cross-border paths through the Data Privacy guide.
- Record licences, terms, source restrictions and opt-outs for training and retrieval material. Route ownership questions to the China copyright protection guide.
- Prevent staff from placing trade secrets, privileged material, personal information or controlled technical data into unapproved tools.
- Require human review for consequential employment, health, safety, financial, legal and customer decisions; define who may override and how the record is preserved.
- Assess output claims under advertising and consumer rules and route physical or software safety issues to the Product Liability hub.
China-facing AI launch gate
- [ ] Service, entity, users, geography and operator roles mapped
- [ ] Generative AI, algorithmic recommendation, deep synthesis and emotional-interaction triggers recorded
- [ ] Filing and security-assessment conclusion documented with change triggers
- [ ] Explicit and implicit labels tested through creation, export and dissemination
- [ ] Training-data, IP, personal-information and cross-border-data reviews complete
- [ ] Content moderation, complaints, incident response and regulatory contacts operational
- [ ] Vendor, base-model, hosting and API-chain evidence retained
- [ ] Human review and prohibited-use policy deployed for enterprise users
- [ ] Marketing claims match the assessed and tested service
- [ ] Regulatory tracker and change-control owner assigned
Use the China AI Regulation Tracker for instrument dates and update monitoring.
Official sources
- Interim Measures for Generative Artificial Intelligence Services
- Provisions on Algorithmic Recommendations in Internet Information Services
- Provisions on Deep Synthesis in Internet Information Services
- Measures for Labeling AI-Generated and Synthetic Content
- GB 45438-2025 labeling standard
- CAC generative-AI filing and registration announcement
- Interim Measures for Anthropomorphic AI Interaction Services
General information only, not legal advice. Official-source currency checked on 31 August 2026. The existing legal-review attribution is preserved; this editorial update does not represent a new legal review.






