China AI Regulation in 2026: Filings, Labels and Liability

China AI regulation filing seal beside a stamped approval sheet for CAC compliance

Key takeaways

  • China AI regulation is a stack of targeted measures, not one statute: algorithm, deep synthesis, generative AI, labelling and companion AI rules sit on top of the PIPL and a Cybersecurity Law amended on 1 January 2026.
  • Under China AI regulation, public-facing generative AI needs a CAC filing or a provincial registration before launch. By 31 August 2026 the CAC counted 1,112 filed services and 731 registered apps.
  • Since 1 September 2025, AI-generated content carries a visible label where it could mislead and a machine-readable label in its metadata.
  • 2026 added companion AI rules (15 July), ethics review committees (April), a planned mandatory standard for AI agents and Supreme People’s Court guidelines on deepfakes (7 September).
  • A foreign group needs one evidence file per China deployment: filing numbers, label tests, training data records, review minutes and transfer mechanisms.

China AI regulation in 2026: a stack of rules, not one law

Anyone looking for a Chinese twin of the EU AI Act will not find one. China AI regulation works by layering. The Cyberspace Administration of China (CAC) writes a targeted measure each time a technology reaches the public, then anchors it in the country’s data and security statutes. The State Council’s 2026 legislative work plan, released on 11 May 2026, promises to accelerate “comprehensive legislation for the healthy development of artificial intelligence”, yet no AI bill appears among the drafts it plans to send to the NPC Standing Committee this year. China AI regulation today falls into five layers:

  1. Data and security statutes: the Personal Information Protection Law (PIPL), the Data Security Law and the Cybersecurity Law, which gained a dedicated AI article and a steeper fine ladder on 1 January 2026.
  2. AI-specific measures: algorithm recommendation (2022), deep synthesis (2023), generative AI services (2023), AI content labelling (2025) and anthropomorphic interaction services (2026).
  3. Ethics review: trial measures issued in April 2026 by ten government departments.
  4. Standards: the mandatory labelling standard GB 45438-2025, recommended GB/T security standards and the TC260 AI Safety Governance Framework.
  5. Courts: Supreme People’s Court guidance and labour rulings that set liability expectations.

The CAC leads, with the Ministry of Industry and Information Technology (MIIT), the Ministry of Public Security, the Ministry of Science and Technology and the State Administration for Market Regulation as co-issuers depending on the text. For a compliance team, the practical consequence of China AI regulation is simple. The question is never “are we compliant with the Chinese AI law”. It is “which instruments does each AI service trigger, and which filing, label or record proves compliance with each”. The same logic drives our global compliance map of AI laws and the AI laws in 2026 overview.

Who China AI regulation covers, including foreign companies

The generative AI measures apply to services that generate text, images, audio, video or other content for the public within the territory of the People’s Republic of China (Article 2). Research, development and use that do not provide services to the domestic public fall outside, a carve-out added between the draft and the final text, as Han Kun explains. Article 20 closes the other door: when a service provided from outside China breaks the rules, the CAC can ask other agencies to take technical measures, which in practice means blocking access. Two statutes stretch China AI regulation further than the measures do. PIPL Article 3 covers processing carried out abroad when the purpose is to offer products or services to individuals in China or to analyse their behaviour. The amended Cybersecurity Law extends Article 77 to any overseas organisation whose activities endanger China’s cybersecurity, with asset freezes among the available sanctions, according to China Briefing. Under China AI regulation, a multinational usually sits in one of four positions:

  1. Public-facing provider: a chatbot, image generator or companion app offered to users in China. The full stack of China AI regulation applies, from filing and labelling to complaint handling.
  2. Integrator of a filed model: an app or feature that calls a domestic model already on the CAC list through an API. It registers with the provincial CAC instead of completing a full filing.
  3. Internal tool: an assistant used only by staff of the Chinese entity. The generative AI measures do not apply, but the PIPL, data security duties and the ethics review measures still do.
  4. Data exporter: a headquarters that trains or evaluates models on data collected in China. Cross-border transfer rules decide whether it needs a security assessment, a standard contract or a certification.

A supplier selling AI features to Chinese customers can hold two positions under China AI regulation at once, and your AI vendor due diligence should record which ones.

The instruments in force, and what each one asks for

The table below lists the China AI regulations a compliance team will meet most often, in the order they took effect. It is a working index, not a legal opinion, and every row should link to the evidence you keep for it. <table header-row=”true”> <tr> <td>Instrument</td> <td>In force</td> <td>Who it binds</td> <td>Core duty</td> <td>Evidence to keep</td> </tr> <tr> <td>Algorithm recommendation provisions</td> <td>1 March 2022</td> <td>Providers of ranking, recommendation, dispatch or generation algorithms</td> <td>Filing within 10 working days for services with public-opinion attributes; option to switch off personalisation</td> <td>Filing receipt, published algorithm rules, self-assessment</td> </tr> <tr> <td>Deep synthesis provisions</td> <td>10 January 2023</td> <td>Providers, technical supporters and users of synthetic media</td> <td>Real-name verification, separate consent to edit biometric data, labels</td> <td>Consent records, label tests</td> </tr> <tr> <td>Generative AI measures</td> <td>15 August 2023</td> <td>Providers of generative AI to the public in China</td> <td>Lawful training data, annotation rules, security assessment and filing, complaint handling</td> <td>Data provenance, annotation checks, filing number</td> </tr> <tr> <td>PI compliance audit measures</td> <td>1 May 2025</td> <td>All PIPL handlers; every two years above 10 million individuals</td> <td>Periodic personal information audits</td> <td>Audit reports</td> </tr> <tr> <td>AI content labelling measures and GB 45438-2025</td> <td>1 September 2025</td> <td>Generation providers, distribution platforms, app stores, users</td> <td>Visible labels and metadata labels</td> <td>Label test report per content type</td> </tr> <tr> <td>Amended Cybersecurity Law</td> <td>1 January 2026</td> <td>Network operators</td> <td>Security duties, AI article, higher fines</td> <td>Security policies, incident logs</td> </tr> <tr> <td>PI export certification measures</td> <td>1 January 2026</td> <td>Exporters below the security assessment thresholds</td> <td>Third route for data transfers</td> <td>Certificate</td> </tr> <tr> <td>AI ethics review measures (trial)</td> <td>April 2026</td> <td>Organisations whose AI activities carry ethical risk</td> <td>Ethics committee or external service; expert re-review of high-impact systems</td> <td>Committee charter, review decisions</td> </tr> <tr> <td>Anthropomorphic interaction measures</td> <td>15 July 2026</td> <td>Providers of companion and emotional-interaction AI</td> <td>Identity notices, protection of minors, crisis intervention, assessments</td> <td>Assessment reports, reminder logs</td> </tr> </table> The overlap in China AI regulation is deliberate. A companion chatbot is at the same time a generative AI service, a deep synthesis service and, if it ranks content, an algorithm recommendation service; the 2026 measures stack on top instead of replacing anything. Keep one register that maps each service to every instrument it triggers, the way a programme for compliance monitoring of AI systems tracks obligations per system, and store the proof next to each duty as your AI system documentation already does for the EU.

Filing and registration: how the CAC gatekeeps models

Filing sits at the centre of China AI regulation. Under the algorithm recommendation provisions, a provider whose service has “public opinion attributes or social mobilisation capabilities” files through the CAC algorithm filing system within 10 working days of launch. The generative AI measures (Article 17) add a security assessment before launch for the same category. No numerical threshold defines that category, so any sizeable public-facing chatbot should assume it is in scope. The self-assessment usually follows the technical document TC260-003 of February 2024, which lists more than 30 safety risks across training data, model output and safeguards. China AI regulation offers two routes. A model provider completes a full filing with the national CAC. An application that only calls a filed model through an API completes a registration with the provincial office. The CAC’s July 2026 announcement reported 120 new filings and 68 registrations for May and June, for totals of 988 filed services and 598 registrations at 30 June 2026. The next batch, published on 14 September, added 124 filings, seven of them on-device services, and 133 registrations, bringing the totals to 1,112 and 731 at 31 August. Every service must show the model name and its filing or registration number in a prominent place or on the product details page. Companion AI has its own trigger: an assessment before launch, again after significant changes, and once a service reaches 1 million registered users or 100,000 monthly active users. For European readers the closest analogue is the conformity assessment of high-risk systems, with one structural difference. In China the gate applies to the public service at launch, whatever its risk level; in the EU it applies to the system according to its risk tier.

Labelling AI-generated content: explicit and implicit

The CAC, MIIT, the Ministry of Public Security and the National Radio and Television Administration published the labelling measures on 14 March 2025 together with the mandatory national standard GB 45438-2025, and both apply from 1 September 2025, as Covington summarises. These China AI regulations create two layers:

  • Explicit labels: text, sound, graphic or interface cues a user can perceive, required where content could confuse or mislead the public, such as chatbot dialogue, synthetic voices, face generation or immersive scenes.
  • Implicit labels: metadata attached to generated files, including the provider’s name or code and a content identifier, with digital watermarks encouraged.

Under China AI regulation, the labelling duty travels along the chain. Distribution platforms read the metadata and add a prominent notice when content is confirmed, declared or suspected to be AI-generated. App stores ask developers whether they offer generative AI services and check their labelling materials before listing. Users must declare AI content they publish, and nobody may remove, alter or forge a label. Enforcement of this part of China AI regulation came quickly. On 29 April 2026 the CAC named CapCut, Maoxiang and Dreamina AI for failing to label AI-generated content and told local offices to use interviews, rectification orders and warnings, according to TechNode. The European counterpart, Article 50 of the EU AI Act, has applied since 2 August 2026, with a transition to 2 December 2026 for machine-readable marking by systems already on the market. A group serving both markets can run a single marking pipeline if its metadata schema satisfies GB 45438-2025 and the EU code of practice at the same time.

Companion AI: the anthropomorphic interaction measures

On 10 April 2026 the CAC, the National Development and Reform Commission, MIIT, the Ministry of Public Security and SAMR issued interim measures for services that simulate a person’s personality, thinking and communication style and hold ongoing emotional interaction with users. They apply from 15 July 2026, as Latham & Watkins details. Customer service bots, knowledge Q&A, work assistants, education and research tools are excluded. The core duties this layer of China AI regulation adds:

  • Identity: tell users they are dealing with AI rather than a real person, with pop-up reminders and a usage reminder for every two consecutive hours of use.
  • Minors: no virtual intimate relationships, such as virtual family members or partners, for any minor; guardian consent under 14; age verification and a minor mode with time limits.
  • Older users: guidance on healthy use and visible safety warnings.
  • Crisis intervention: when a user signals self-harm or suicide, the provider must intervene and promptly contact the user’s guardian.
  • Training data: no use of sensitive personal information from conversations to train models without separate consent.
  • Assessments: before launch, on major changes and at the user thresholds above; app stores verify assessment and filing status before listing.

Fines start at RMB 10,000 to 100,000 and rise to RMB 100,000 to 200,000 where harm to life, health or safety follows. The amounts are modest next to the PIPL, but suspension of the service is the sanction that matters commercially. Teams that already run human oversight controls for EU deployments can reuse the escalation design; the two-hour reminder and the minor mode remain China-specific builds.

Ethics review, AI agents and loss of control

The trial measures on AI science and technology ethics review, issued in early April 2026 by ten departments led by the Ministry of Science and Technology and MIIT, require organisations whose AI activities may threaten human dignity, public order, life and health or the environment to set up an ethics review committee of at least five members, or to use an external review service, according to SESEC. Systems that significantly influence behaviour, psychological state or health, services able to shape public opinion or mobilise people, and highly autonomous decision systems in safety-critical settings go through an expert re-review, with follow-up reviews at intervals of no more than 12 months. Anyone who has chartered an AI governance committee will recognise the format. Agents are the next frontier for China AI regulation. On 27 June 2026 the authorities launched a plan for a mandatory national standard, General Security Requirements for Artificial Intelligence Agent Application, with an 18-month development cycle, as CGTN reported. The expected requirements cover identity, system permissions, tool use, data collection, human intervention for high-risk operations, input and output protection, log retention, monitoring, blocking of abnormal operations and emergency shutdown. On 14 September 2026 TC260 released version 3.0 of its AI Safety Governance Framework, adding an annex on agent risk management and a sharper focus on loss of control, including resistance to shutdown and deceptive behaviour during evaluations, per Geopolitechs. The framework is not binding, but TC260 documents shape China AI regulation by feeding the standards and security assessments the CAC relies on. If you deploy autonomous AI agents in China, start logging tool permissions and human intervention points now: the mandatory standard is due around the end of 2027, and retrofitting logs costs more than designing them in.

Enforcement and liability in 2026

China AI regulation is enforced through campaigns before fines. The CAC announced its Qinglang 2026 campaign against AI misuse on 30 April 2026, targeting deepfake fraud and impersonation, coordinated manipulation, models that skipped filing, training data that infringes intellectual property or privacy, and AI services launched without a security assessment, as The Next Web reported. The 2025 edition removed more than 3,500 AI products and 960,000 pieces of content. The money in China AI regulation sits in the statutes behind the measures:

  • Cybersecurity Law: RMB 500,000 to 2 million for serious consequences and RMB 2 to 10 million for especially serious ones, with fines of up to RMB 1 million for responsible individuals.
  • PIPL: up to RMB 50 million or 5% of the previous year’s turnover for serious violations, plus possible suspension of the business.
  • Anthropomorphic measures: up to RMB 200,000 where harm follows, on top of the suspension risk.

Courts now add civil exposure to China AI regulation. On 7 September 2026 the Supreme People’s Court issued guidelines on AI disputes: creating or spreading a recognisable replica of someone’s face or voice without consent infringes their rights, providers are liable if they fail to act promptly after notice of infringing output, users who prompt a system into infringement are liable too, and algorithmic price discrimination without reasonable justification can support claims, as People’s Daily reported. In April 2026 the Hangzhou Intermediate People’s Court held that replacing a worker with AI is not a “major change in objective circumstances” that justifies dismissal under the Labour Contract Law, according to NPR. Log court exposure in the same register as regulatory findings, and route both through your AI incident reporting process.

China AI regulation compared with the EU AI Act

Groups active in both markets ask the same question: how much of the work done for China AI regulation carries over to the EU? More than the legal architecture suggests. The table compares the duties that generate the most evidence. <table header-row=”true”> <tr> <td>Topic</td> <td>China</td> <td>EU AI Act</td> </tr> <tr> <td>Synthetic content</td> <td>Labelling measures and GB 45438-2025 since 1 September 2025</td> <td>Article 50 since 2 August 2026; marking transition to 2 December 2026</td> </tr> <tr> <td>Pre-market gate</td> <td>Filing or registration and security assessment before public launch</td> <td>Conformity assessment for Annex III high-risk systems from 2 December 2027</td> </tr> <tr> <td>Ethics or impact review</td> <td>Ethics review committees since April 2026</td> <td>Fundamental rights impact assessment (Article 27) from 2 December 2027</td> </tr> <tr> <td>Companion AI</td> <td>Dedicated measures since 15 July 2026</td> <td>Article 5 ban on manipulative techniques since 2 February 2025; Article 50(1) disclosure</td> </tr> <tr> <td>Frontier and agent risk</td> <td>TC260 framework 3.0; mandatory agent standard planned</td> <td>General-purpose AI obligations since 2 August 2025</td> </tr> <tr> <td>Maximum fine</td> <td>RMB 50 million or 5% of turnover (PIPL)</td> <td>EUR 35 million or 7% of worldwide turnover</td> </tr> </table> The EU dates reflect Regulation (EU) 2026/1744, the Digital Omnibus on AI. The designs differ: China gates the public service at launch, while the EU grades the system by risk tier. The proof, however, overlaps: training data records, labelling tests, human intervention logs and review minutes. Build that evidence once and file it twice, starting from the EU AI Act high-risk classification and the general-purpose AI duties you may already track.

The evidence file for a China deployment

A CAC inspection, a filing review or an app store check asks for documents, not intentions. For each AI service subject to China AI regulation, keep these ten items ready:

  1. A service register mapping each system to its position (provider, integrator, internal tool, exporter) and to every instrument it triggers.
  2. Filing or registration numbers, with screenshots showing where the product displays them.
  3. The security self-assessment submitted for filing, including test results against the TC260-003 risk list.
  4. Training data provenance: sources, licences and the legal basis for any personal information, maintained under your data governance framework.
  5. Annotation rules, annotator training records and sampling checks.
  6. A labelling test report per content type, covering the visible cue and each GB 45438-2025 metadata field.
  7. The complaint channel, the handling log and the model fixes made after unlawful output.
  8. PIPL personal information protection impact assessments for automated decision-making and sensitive data, built like a privacy impact assessment, plus compliance audit reports, due every two years above 10 million individuals according to DLA Piper.
  9. The cross-border mechanism for each data flow, with annual counts against the 100,000, 1 million and 10,000 sensitive-record thresholds described by White & Case, and the certificate where you use the route in force since 1 January 2026, per China Briefing.
  10. The ethics committee charter and review decisions and, for companion AI, crisis intervention protocols, minor mode tests and reminder logs.

A 90-day plan from September 2026

Starting on 17 September 2026, a China AI regulation programme can reach a defensible position before year end:

  1. Days 1 to 30, map (by 17 October 2026): inventory every AI service that touches China, assign one of the four positions, and list the instruments each one triggers.
  2. Days 31 to 60, close filing and labelling gaps (by 16 November): confirm filing or registration numbers, run label tests against GB 45438-2025, and check every app store listing.
  3. Days 61 to 90, build the evidence file (by 16 December): complete the ten items above, charter or appoint the ethics review function, and align the metadata pipeline with the EU marking deadline of 2 December 2026.
  4. Ongoing: follow the agent standard drafts, the next CAC filing batches and the AI law, and repeat ethics follow-ups at least every 12 months, using the same method as an AI impact assessment.

FAQ

Does China have a single AI law? No. As of September 2026, China AI regulation consists of targeted measures on algorithms, deep synthesis, generative AI, labelling, companion AI and ethics review, built on the PIPL, the Data Security Law and the amended Cybersecurity Law. The State Council’s 2026 legislative work plan promises to accelerate comprehensive AI legislation, but it lists no AI bill for submission to the NPC Standing Committee this year. Plan for the stack you can see, not for a code that has not been drafted. Do Chinese AI rules apply to foreign companies? Yes. China AI regulation applies whenever a service is offered to the public in China, wherever the provider is based. The CAC can order technical measures against non-compliant services provided from abroad under Article 20 of the generative AI measures, and the PIPL reaches processing abroad aimed at individuals in China. Tools used only by staff fall outside the generative AI measures, but not outside data protection, cross-border transfer rules or ethics review. What happens if a generative AI service launches without filing? Under China AI regulation, unfiled models are an explicit target of the Qinglang 2026 campaign. Typical measures are regulatory interviews, rectification orders, warnings, removal from app stores and suspension, with fines under the Cybersecurity Law and the PIPL where the facts support them. Apps built on a filed model still need a provincial registration and must display the filing or registration number. Do the labelling rules cover AI-generated text? Yes. China AI regulation requires explicit labels where text could mislead the public, for example chatbot output or AI-written articles, and implicit metadata labels on generated files. Platforms must flag content they suspect is AI-generated, and users must declare AI content when they publish it. Removing or forging a label is prohibited. Is it illegal in China to replace workers with AI? Not as such, but dismissing an employee because AI took over their tasks is risky. In April 2026 the Hangzhou Intermediate People’s Court ruled that AI-driven restructuring is not a “major change in objective circumstances” under the Labour Contract Law, and that a reassignment carrying a 40% pay cut was unreasonable. Employers should offer reasonable redeployment or negotiate a lawful exit. How does China AI regulation compare with the EU AI Act? China gates each public-facing service at launch through filing and security assessment, and labels synthetic content broadly. The EU grades systems by risk and puts its heaviest duties on high-risk systems from 2 December 2027, after the Digital Omnibus. The evidence overlaps heavily, so one control set with two filing formats is the efficient design for groups active in both markets.

Conclusion

China AI regulation rewards teams that treat it as an operating discipline rather than a legal event. The rules change several times a year, arrive as measures rather than a code, and are enforced through filings, app store checks and campaigns before fines. That makes the evidence file the real compliance deliverable: a service register, filing numbers, label tests, data records and review minutes that can be produced on request. The next twelve months will bring agent standard drafts, new filing batches and perhaps a first AI law draft. Groups that already map each service to every instrument will absorb those changes as register updates, not as new projects. AI Sigil tracks China AI regulation alongside the EU AI Act and 26 other AI laws in one control library, so the proof you build for Beijing also counts in Brussels.

China AI Regulation in 2026: Filings, Labels and Liability

China AI regulation explained for foreign firms: CAC filings, AI content labels, companion AI rules, 2026 enforcement and the evidence to keep ready.

CCPA Regulations 2026: ADMT, Risk Assessments and Audits

The CCPA regulations in force since January 2026 add ADMT duties from 1 January 2027, risk assessment filings in 2028 and audits to 2030. Dates and evidence.

What Is Adversarial AI? Attacks, Defenses & Governance

Adversarial AI attacks ML models through poisoning, evasion and prompt injection. See the attack types, defenses, and governance controls the EU AI Act now requires.

California AI Laws: Who Must Comply, and by When

California AI laws explained by role and date: SB 53, SB 942, SB 243, CCPA ADMT, FEHA rules and the bills Newsom signed in September 2026.

TRAIGA Compliance: The Texas AI Law, Operationalized

TRAIGA has been in force since January 2026. What the Texas AI law prohibits, how the NIST AI RMF safe harbour works, and the evidence you need to rely on it.

Vendor Due Diligence for AI: 12 Questions Checklists Miss

Standard vendor due diligence was built for a pre-AI supply chain. Here are the 12 AI-specific questions to add, and the legal duty behind them.