Centre: AI & Technology Knowledge Centre · Privacy: Data Privacy · Transfers: Cross-border roadmap.
Who should treat themselves as in scope?
- Providers of generative AI services to the public in China (including via apps, APIs, and platforms).
- Providers of deep synthesis / deepfake-capable tools (voice, face, video, virtual humans).
- Internet platforms using recommendation algorithms that may trigger filing / transparency duties.
- Enterprise deployers embedding models into China-facing HR, customer service, or content tools—duties differ from pure providers but are not “zero.”
- Overseas model vendors targeting China users or partnering with China distributors—map extraterritorial and local-partner responsibilities.
If unsure, run a product inventory: models, prompts logs, user content, moderation, and where inference runs.
Rule families (business map)
| Family | Business theme | Typical owners |
|---|---|---|
| Generative AI measures | Service provision, content safety, training data legitimacy, security measures, updates/reporting themes | Product + Legal + Security |
| Deep synthesis rules | Labelling synthetic content; identity verification themes; misuse prevention | Product + Trust & Safety |
| Algorithm recommendation | Filing/transparency for certain recommendation services; user controls | Platform product + Compliance |
| PIPL / DSL / CSL | Personal information, important data, network security baselines | Privacy + Cyber |
| Sector rules | Finance, health, education, autonomous systems, advertising | Vertical compliance |
| Trade / export | Chips, tools, model weights movement, overseas collaboration | Trade counsel + Supply |
Exact instrument names and thresholds evolve. Use this as a control agenda; confirm current text with counsel before filings.
Generative AI — operator duties (plain language)
Providers commonly need a program covering:
- Training data and foundational model hygiene — lawful sources; IP and personal information risk; documentation of data governance.
- Content safety — refuse illegal content; moderation for user prompts and outputs; human review escalation.
- Accuracy / non-discrimination themes — avoid knowingly generating false content as fact; bias risk management for decision tools.
- User onboarding — real-identity themes where required; clear service rules.
- Transparency — disclose AI use; synthetic media labelling (see below).
- Security — model and data security; abuse monitoring; incident handling.
- Updates & cooperation — change management when models or policies shift; regulatory cooperation channels.
Enterprise “internal only” tools still need security and employment/privacy design if staff or candidates are affected.
Labelling & user-facing controls
- Synthetic content labels for deep synthesis outputs where rules require visible or embedded marks.
- In-product notices that the user is interacting with AI—not a human agent—when relevant.
- User rights interfaces aligned with PIPL (access, deletion of personal inputs where applicable).
- Minor protection if the product reaches children.
Training data, prompts & logs
- Personal information in datasets, chat logs, and fine-tunes → PIPL guide.
- Cross-border training or inference outside China → transfer roadmap.
- IP — scraped content, licensed corpora, open-source licences, output ownership in customer contracts.
- Trade secrets — protecting weights and proprietary datasets with partners (trade secrets, NNN for hardware/robotics vendors).
Security assessment & filing themes
Certain generative AI and algorithm services may require security assessment and/or filing before or during public provision—especially where public opinion attributes or large-scale public services are involved. Treat “we will file later” as a launch risk.
- Identify whether you are public-facing in China or only B2B through a licensed partner.
- Budget calendar time for assessment materials, model cards, and content taxonomies.
- Align marketing claims with what was assessed (feature creep triggers re-work).
Global products: China lane vs overseas lane
| Scenario | Priority controls | Portal anchors |
|---|---|---|
| Foreign AI company entering China | Local partner/entity, content/ localisation, privacy, possible filings | Inbound centre · this guide |
| Chinese model vendor selling abroad | Host privacy/AI rules, export controls, contracts, IP | Outbound playbook · export controls |
| Dual-region SaaS | Data residency, transfer pathways, separate moderation policies | Transfer roadmap · PIPL vs GDPR |
Go-live checklist (China-facing GenAI)
- [ ] Product role classified (provider / platform / enterprise deployer)
- [ ] Content safety policy + blocked categories implemented and tested
- [ ] Synthetic content labelling where required
- [ ] User notice / terms updated in Chinese
- [ ] Training data & IP legitimacy memo
- [ ] PI inventory for prompts, uploads, logs; PIPL notices live
- [ ] Cross-border inference/storage reviewed
- [ ] Security assessment / filing path confirmed or documented N/A with counsel
- [ ] Human review / abuse reporting channel staffed
- [ ] Incident response for model misuse and data leakage
- [ ] Vendor/API chain diligence (base model, hosting, moderation vendors)
- [ ] Marketing claims reviewed (capabilities, “autonomous agents,” accuracy)
Common mistakes
- Shipping a global model UI to China users with only GDPR paperwork.
- No labelling on deep synthesis demos used in marketing.
- Logging full chat histories overseas without a transfer design.
- Assuming open-source weights = no compliance program.
- Partner “white-labels” your API into a public China app without contractual safety allocation.
FAQ
Does internal employee copilot need the same filings as a public chatbot?
Not always identical—but privacy, employment, secrecy, and security duties still apply. Classify use cases with counsel.
Are robotics and industrial AI covered?
Product safety, standards, and sector rules may dominate; generative content rules apply when synthesis/consumer interfaces appear. Use the tech centre journey and manufacturing NNN for hardware partners.
Where is the AI vs EU AI Act comparison?
See China AI rules vs EU AI Act; use host-market counsel for EU launches via the outbound centre.
Get counsel
General information only—not legal advice. AI, algorithm, and cyber measures are amended frequently. Confirm current obligations before launch or filing. Last reviewed: August 2026 · China Legal Portal Editorial