How to comply with China's generative AI rules
China: generative AI, deep synthesis, algorithm and labelling measures
- Status
- In force
- Binding
- Yes
- Object analysed
- AI system
- Requirements
- 6
- Next milestone
- 2027
In short
Stack of CAC rules: algorithm filing, security assessment before public launch, lawful training data, explicit and implicit content labelling.
Steps to compliance
- Qualify each AI systemAxes to decide: Service type.
- Determine your roleDuties vary by role: Service provider.
- Apply the 6 requirementsThey focus on: Authorities & registration, Risk management, Accuracy & robustness and Data governance.
- Prove it with checks8 checks to document, 6 of which also serve AI Act, PL 2338 and NIST AI RMF.
- Track the deadlinesNext milestone: 2027, Comprehensive AI Law (State Council legislative plan) (potential).
Scope and penalties
- Kind
- Implementing rules
- Scope
- Providers of generative AI, deep synthesis or recommendation services to the public in China.
- Territorial reach
- Services available to the public in mainland China.
- Penalties
- Penalties under the cybersecurity, data and PIPL laws; service suspension.
- Jurisdiction
- China
Timeline
Qualifying a system
Classification axes and possible verdicts
Service type
Requirements
6 requirements
| Code | Article | Requirement | Applies to | Checks |
|---|---|---|---|---|
| CN-01 | Recommendation Art. 24 | Algorithm filing with the CAC | ||
| CN-02 | GenAI Art. 17 | Security assessment before public launch | ||
| CN-03 | GenAI Art. 7, 8 | Lawfulness, quality and IP of training data | ||
| CN-04 | Labelling Art. 4, 5 | Explicit and implicit (metadata) labelling of generated content | ||
| CN-05 | GenAI Art. 14 | Handle illegal content and correct the model | ||
| CN-06 | GenAI Art. 10, 15 | User protection: minors, complaints, reporting |
Checks to document
Evidence collected for a check counts for every regulation that uses it.
| Code | Check | Scope | Themes | Also used by |
|---|---|---|---|---|
| NEW-CN-01 | Algorithm filed with the CAC (filing number) proposed | System | ||
| VER-009-02 | Accuracy and robustness verified and documented | System | ||
| NEW-CN-02 | CAC security assessment completed proposed | System | ||
| VER-004-01 | Documented data governance (collection process, bias, quality) | System | ||
| VER-031-G-03 | Documented copyright compliance policy | Organisation | ||
| VER-018-D-03 | AI-generated content marked as such | System | ||
| VER-021-D-03 | Operation monitoring | System | ||
| CHK-STAKEHOLDER-FEEDBACK | Mechanisms collect, adjudicate and integrate external stakeholder / user feedback | Organisation |
Themes covered
Frequently asked questions
Who is in scope of China GenAI?
Providers of generative AI, deep synthesis or recommendation services to the public in China. Services available to the public in mainland China.
What penalties does China GenAI carry?
Penalties under the cybersecurity, data and PIPL laws; service suspension.
When do the China GenAI obligations apply?
Sep 1, 2025: Labelling measures and GB 45438-2025 standard; Jan 1, 2026: Amended Cybersecurity Law with AI provisions; 2027: Comprehensive AI Law (State Council legislative plan).
Is China GenAI binding?
Yes. Kind: implementing rules. Status: in force.
How does China GenAI relate to other regulations?
The same checks serve several texts. Shared checks: AI Act (5), PL 2338 (5) and NIST AI RMF (2).
Related regulations
Official sources
Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.