AI regulation in China is among the most comprehensive and rapidly evolving in the world. Over the past several years, Chinese authorities have built a layered framework covering generative AI, algorithmic recommendations, deepfakes, and cross-border data flows - each with its own compliance obligations. For international businesses operating in or entering the Chinese market, understanding these rules is not optional: non-compliance carries real operational and reputational risk. This guide maps the current regulatory landscape, explains the key laws and authorities, and identifies the practical steps companies must take to stay on the right side of Chinese AI law.
China does not have a single omnibus AI statute equivalent to the European Union';s AI Act. Instead, ai regulation china is built from a stack of overlapping regulations, each targeting a specific AI application or risk category. This modular approach means that a single AI product may fall under two or three separate regulatory instruments simultaneously.
The three foundational instruments are:
Alongside these, the Personal Information Protection Law (PIPL), the Data Security Law (DSL), and the Cybersecurity Law (CSL) form the data governance backbone that underpins all AI compliance in China. Any AI system that processes personal data - which most do - must simultaneously satisfy PIPL requirements, including lawful basis for processing, data minimisation, and cross-border transfer restrictions.
The State Council';s New Generation Artificial Intelligence Development Plan, while primarily a policy document rather than binding law, signals the government';s long-term ambitions and shapes how regulators interpret and apply the binding rules. Businesses should read the binding regulations in light of this broader policy direction.
The Interim Measures for the Management of Generative Artificial Intelligence Services represent the most consequential recent development in Chinese AI law. They apply to organisations that provide generative AI services to the public within China - including text, image, audio, video, and code generation. Foreign companies whose services are accessible in China are within scope.
The Interim Measures impose several categories of obligation.
Content and safety requirements. Providers must ensure that generated content does not violate Chinese law, does not contain prohibited content categories (including content that undermines state authority or spreads disinformation), and reflects "socialist core values." In practice, this means building content filtering and moderation systems before launch, not as an afterthought.
Security assessments and filing. Before making a generative AI service available to the public in China, providers must complete a security assessment with the CAC and, in most cases, file an algorithm record. The security assessment process involves submitting technical documentation, sample outputs, and risk mitigation measures. Timelines for assessment completion are not fixed by statute but typically run several weeks to a few months depending on the complexity of the system and the regulator';s workload.
Labelling obligations. AI-generated content must be clearly labelled as such. This applies to text, images, audio, and video. The labelling requirement is not merely a disclosure formality - it has technical implications for how content is watermarked or tagged at the system level.
Training data governance. Providers must ensure that training data was lawfully obtained and does not infringe intellectual property rights or contain unlawfully collected personal information. This creates a due diligence obligation that reaches back into the supply chain of data used to train models.
A common mistake among foreign companies is assuming that if their AI model is trained and hosted outside China, the Interim Measures do not apply. The CAC';s position is that the measures apply based on where the service is provided and where users are located, not where the infrastructure sits.
Before the Interim Measures arrived, China had already enacted two significant sector-specific instruments that remain fully in force and apply to a wide range of AI-driven products.
Algorithmic recommendation rules. The Provisions on the Management of Algorithmic Recommendations apply to any service that uses algorithms to push content, products, or information to users - covering news feeds, e-commerce recommendation engines, search ranking, and social media curation. Covered entities must register their algorithms with the CAC if they have significant influence on public opinion or social mobilisation. They must also provide users with a meaningful option to opt out of personalised recommendations and must not use algorithmic systems to engage in price discrimination based on user characteristics.
In practice, the registration requirement catches many more companies than initially expected. The CAC has published lists of entities required to register, and the threshold for "significant influence" has been interpreted broadly. A non-obvious requirement is that even B2B platforms that surface content to business users may fall within scope if the content has potential public reach.
Deep synthesis rules. The Provisions on the Management of Deep Synthesis Internet Information Services cover AI-generated or AI-manipulated audio, video, images, and text that could be mistaken for real content. Providers of deep synthesis technology - including those who supply the underlying tools to third parties, not just end-user applications - must implement user verification, content labelling, and content moderation. Providers must also retain logs of deep synthesis activities for a minimum period specified by the regulation.
A practical scenario: a foreign company provides a video dubbing tool that uses AI to replace audio tracks. Even if the company';s servers are outside China, if Chinese users access the service, the deep synthesis rules apply. The company must label outputs, verify user identities in line with Chinese real-name registration requirements, and maintain records.
No AI compliance programme in China is complete without addressing the three core data laws: PIPL, DSL, and CSL. These laws interact with AI regulation in ways that create compounding obligations.
Personal Information Protection Law. PIPL governs the collection, processing, storage, and transfer of personal information. For AI systems, the most significant PIPL obligations are: obtaining a lawful basis for processing (consent is the default for most commercial AI applications), providing clear privacy notices, and restricting cross-border transfers of personal information. Cross-border transfers require either a CAC security assessment, a standard contract filing, or certification by an approved body - depending on the volume and sensitivity of data involved.
Data Security Law. The DSL introduces a data classification system under which "important data" and "core data" are subject to stricter controls. AI training datasets that contain information about Chinese citizens, critical infrastructure, or key industries may qualify as important data, triggering additional security obligations and restrictions on transfer outside China.
Cybersecurity Law. The CSL requires critical information infrastructure operators to store data locally and subjects them to security reviews when procuring network products and services. AI systems deployed by operators in critical sectors - finance, energy, healthcare, telecommunications - face the most stringent requirements.
Many underestimate the interaction between these laws. A company that has completed a generative AI security assessment under the Interim Measures may still need a separate PIPL cross-border transfer assessment if its model processes personal data and sends outputs or logs outside China. These are parallel processes, not substitutes for each other.
If your organisation is navigating these overlapping obligations, structured legal advice can prevent costly missteps. Contact info@vlolawfirm.com - we can help structure the compliance programme correctly from the outset.
Understanding who enforces Chinese AI law - and what the consequences of non-compliance are - is essential for risk assessment.
The Cyberspace Administration of China is the primary regulator for generative AI, algorithmic recommendations, deep synthesis, and internet information services generally. The CAC has the authority to order rectification, suspend services, revoke licences, and impose fines. Under the Interim Measures, fines for violations can reach into the hundreds of thousands of RMB for individual infractions, with higher penalties for serious or repeated violations. The CAC can also require a service to be taken offline pending compliance.
The Ministry of Industry and Information Technology (MIIT) plays a role in AI standards development and in regulating AI applications in industrial and telecommunications contexts. MIIT has published AI-related standards that, while technically voluntary, are treated as de facto compliance benchmarks by regulators.
The National Internet Information Office and provincial-level CAC offices share enforcement responsibilities. In practice, enforcement actions have targeted both domestic companies and the Chinese operations of foreign firms. Several high-profile enforcement actions have resulted in apps being removed from Chinese app stores and services being suspended.
Penalties for data law violations under PIPL can reach up to RMB 50 million or five percent of the prior year';s annual turnover - whichever is higher - for serious violations. The DSL and CSL carry their own penalty regimes. Responsible individuals, including senior managers, can face personal fines and, in serious cases, criminal liability.
A practical scenario: a multinational company launches an AI-powered customer service chatbot in China without completing the required algorithm filing or security assessment. The CAC identifies the service during a routine inspection. The company faces an order to suspend the service, a fine, and a requirement to complete the filing before relaunch - causing significant commercial disruption. This scenario has played out for several companies in recent enforcement cycles.
For international businesses, the path to compliance with ai regulation china involves several concrete steps that should be sequenced carefully.
Map your AI systems against the regulatory framework. Identify which of your AI products and services are accessible in China or process data about Chinese users. Determine which regulatory instruments apply - the Interim Measures, the algorithmic recommendation rules, the deep synthesis rules, or some combination. This mapping exercise is the foundation of any compliance programme.
Conduct a data flow analysis. Understand what personal data your AI systems collect, where it is processed, and whether it crosses China';s borders. This analysis will determine whether you need a PIPL cross-border transfer mechanism and whether your data qualifies as "important data" under the DSL.
Complete required filings and assessments before launch. The security assessment and algorithm filing requirements are pre-market obligations, not post-launch remediation steps. Building compliance into the product development timeline - rather than treating it as a legal formality to be addressed after launch - avoids the disruption of having to suspend a service.
Implement technical controls. Content filtering, output labelling, user verification, and log retention are not purely legal obligations - they require engineering work. Legal and technical teams must collaborate early to ensure that compliance requirements are built into the system architecture.
Establish a local compliance presence. The CAC and other regulators expect to be able to communicate with a responsible entity in China. Foreign companies without a local entity or representative face practical difficulties in completing filings, responding to regulatory inquiries, and managing enforcement interactions.
Monitor regulatory developments continuously. The Chinese AI regulatory framework is evolving rapidly. New rules, implementation guidelines, and enforcement priorities emerge regularly. A compliance programme that was adequate at launch may require updating within months.
What is the difference between the security assessment and the algorithm filing under Chinese AI law?
These are two distinct processes with different scopes and purposes. The security assessment, administered by the CAC, applies specifically to generative AI services before they are made available to the public. It involves a substantive review of the AI system';s technical architecture, content moderation capabilities, and risk mitigation measures. The algorithm filing requirement, which predates the Interim Measures, applies to a broader range of algorithmic systems - including recommendation engines and search ranking systems - that have significant influence on public opinion or social mobilisation. A generative AI service may need to complete both processes: the security assessment because it generates content, and the algorithm filing because it influences what users see. The two processes are run in parallel but are not interchangeable.
How long does it take to complete the CAC security assessment for a generative AI service, and what does it cost?
The CAC does not publish a fixed statutory timeline for completing security assessments. In practice, the process has taken anywhere from several weeks to several months, depending on the complexity of the AI system, the completeness of the documentation submitted, and the regulator';s current workload. Preparation time - assembling technical documentation, conducting internal safety testing, and drafting the submission - typically adds further weeks. Professional fees for legal and technical advisory support during the assessment process vary significantly based on the scope of the system and the level of preparation required; they generally start from the low tens of thousands of USD for straightforward cases and rise for complex systems. There are no published government fees for the assessment itself, but indirect costs - including engineering time and potential system modifications required by the regulator - can be substantial.
Can a foreign company provide AI services in China without establishing a local entity?
In principle, the Chinese AI regulations apply based on where services are provided and where users are located, not on the corporate structure of the provider. However, in practice, completing the required filings and assessments is extremely difficult without a local entity or a designated local representative. The CAC';s filing systems are designed for entities registered in China, and regulators expect a local point of contact for ongoing compliance matters and enforcement interactions. Foreign companies typically address this by establishing a wholly foreign-owned enterprise (WFOE) in China, partnering with a local entity that holds the necessary licences, or appointing a local compliance representative. Each approach has different legal and commercial implications, and the right structure depends on the nature of the AI service and the company';s broader China strategy.
China';s AI regulatory framework is detailed, layered, and actively enforced. International businesses must engage with it seriously - mapping their AI systems against the applicable rules, completing pre-market filings, and building technical compliance controls before launch. The framework continues to develop, and staying current requires ongoing monitoring.
VLO Law Firms advises international clients on AI regulation in China. We can assist with regulatory mapping, CAC security assessment preparation, algorithm filing, PIPL cross-border transfer mechanisms, and ongoing compliance monitoring. To request a consultation, contact: info@vlolawfirm.com