China AI Anthropomorphic Interactive Services Measures (CAC Order No. 21)
Cyberspace Administration of China (CAC) with NDRC, MIIT, MPS and SAMR · China (CN) · 11 provisions encoded · verified against the official source as of 2026-10-02.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
Sources last verified 3 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
None of the 11 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 11.
Audit standard
11 of 11 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
20 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
2026.10.03.3 (3 Oct 2026): 11 provisions added
Each data release records which provisions changed; the full list is on Changes.
Binding law — in force
Companion AI must tell users they are interacting with AI, not a person, and remind them on over-reliance and every 2 hours of use (China CAC Order 21)
人工智能拟人化互动服务管理暂行办法 第十八条第一款 (Art. 18(1), labelling and not-a-natural-person notice) · official text · In force: applies since 15 Jul 2026 · China (CN)
A provider of AI anthropomorphic interactive services must meet its labelling duties for AI-generated content and take effective measures to tell users that they are interacting with an AI service and not a natural person (Art. 18(1)). When it finds a user over-relying on or addicted to the service, it must dynamically remind the user, prominently (for example by a pop-up), that the interaction content is AI-generated; and each time a user's continuous use exceeds 2 hours it must remind the user, by dialogue or pop-up, to mind the time spent (Art. 18(2)). Detect a companion chat UI or server path with no AI-not-human notice, persona instructions that conceal the AI, and a chat path with no continuous-use timer and 2-hour reminder.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 15 Jul 2026
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
3 detectors (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
The notice may be rendered by a layout component or the server's first message; check the chat path end to end.
A reminder scheduled by a separate worker or the client app
The timer may live in client code or middleware that wraps every chat turn; confirm the reminder is shown after each 2 hours of continuous use.
Who it applies to
Duty falls on: provider
Systems covered: companion chatbot
Providers that use AI to offer the public in China sustained emotional-interaction services simulating a natural person's personality traits, thinking patterns and communication style (emotional care, companionship, support) in text, image, audio or video (Art. 2). In force 2026-07-15 (Art. 32).
Not covered:
Intelligent customer service, knowledge Q&A, work assistants, learning and education, scientific research and similar services that involve no sustained emotional interaction (Art. 2(3))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.
A disclosure step on the chat path that runs before the first model reply reaches the person: either the chat UI renders a visible notice (banner, label next to the assistant's name) or the server sends an opening assistant message stating the counterpart is an AI. The same handler answers 'am I talking to a human?' truthfully, and the system prompt never tells the model to claim to be human. Put it in the chat entry point (the route or component that starts a conversation), not in a privacy policy or terms page.
Where it goes: 7 prompt construction, 9 AI output handling, 14 user-facing text.
What this provision adds:
Tell users, prominently and at the start of the interaction, that they are interacting with an AI service and not a natural person, and meet the AI-generated content labelling duties.
When signs of over-reliance or addiction appear, remind the user dynamically and prominently (for example a pop-up) that the content is AI-generated.
Track continuous use and remind the user, by dialogue or pop-up, each time it exceeds 2 hours.
Example (Next.js + Vercel AI SDK (useChat)), before:
const { messages, input, handleSubmit } = useChat({
api: '/api/chat',
initialMessages: [{ id: 'ai-notice', role: 'assistant',
content: 'I am an AI assistant, not a human.' }],
});
// and render <AiBadge /> next to every assistant message
Control: AI chat interaction without disclosure. The same guard addresses 29 items with binding law in 22 jurisdictions. Engineering guidance, not legal advice.
Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required
Rule id cn-anthropomorphic-ai.ai-not-human-notice-and-reminders · review status: primary source derived
Binding law — in force
Companion AI must let users copy and delete their chat history (China CAC Order 21)
人工智能拟人化互动服务管理暂行办法 第十六条第三款 (Art. 16(3), copy and delete interaction data) · official text · In force: applies since 15 Jul 2026 · China (CN)
A provider must offer users options to copy and delete their interaction data, and users may choose to copy or delete historical interaction data such as chat records (Art. 16(3)). Detect a companion product with no chat-history export or delete option, and account or data deletion that leaves conversation stores in place.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 15 Jul 2026
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
2 detectors (code pattern, missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Deletion fanned out through a queue or event bus to another service
The handler may call a service that deletes AI data elsewhere; follow the calls before reporting.
Who it applies to
Duty falls on: provider
Systems covered: companion chatbot
Providers that use AI to offer the public in China sustained emotional-interaction services simulating a natural person's personality traits, thinking patterns and communication style (emotional care, companionship, support) in text, image, audio or video (Art. 2). In force 2026-07-15 (Art. 32).
Not covered:
Intelligent customer service, knowledge Q&A, work assistants, learning and education, scientific research and similar services that involve no sustained emotional interaction (Art. 2(3))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Make the account-deletion handler also delete the person's vector entries, embeddings, chat history, agent memory and provider-stored files or conversations.
Extend the erasure path (DELETE /account, delete_user, the data-subject-request worker) so that after the primary records it deletes everything keyed to the person in AI stores: vector-store entries by id, metadata filter or per-user namespace, conversation and chat-history tables, agent memory and checkpoints, and files, vector-store files, threads or conversations held with the model provider. This requires writing the user id as metadata on every vector and recording every provider object id at creation, so the deletion can find them. Where a legal hold or retention exception applies, skip only the covered items and record the reason; log which stores were erased.
Where it goes: 1 application source code, 2 data models, 6 API calls and integrations.
What this provision adds:
Offer users options to copy (export) and to delete their chat history, and make deletion remove the messages from every store that keeps them.
@app.delete('/account')
def delete_account(user=Depends(current_user)):
db.users.delete(user.id)
collection.delete(where={'user_id': user.id}) # Chroma embeddings
db.chat_messages.delete_for_user(user.id) # conversation history
for f in db.provider_files.for_user(user.id):
client.files.delete(f.file_id) # files stored with OpenAI
for c in db.provider_conversations.for_user(user.id):
client.conversations.delete(c.conversation_id)
erasure_log.record(user.id, stores=['chroma', 'chat', 'openai_files', 'openai_conversations'])
return {'status': 'deleted'}
Rule id cn-anthropomorphic-ai.chat-history-copy-and-delete · review status: primary source derived
Binding law — in force
Companion AI must intervene on self-harm or extreme emotions and contact the user's guardian or emergency contact (China CAC Order 21)
人工智能拟人化互动服务管理暂行办法 第十三条 (第十三条 (Art. 13, risk identification and crisis intervention)) · official text · In force: applies since 15 Jul 2026 · China (CN)
A provider must sign a service agreement with users requiring registration that supplies the user's age and a guardian or emergency contact (Art. 12). While providing the service it must, protecting privacy and personal information, promptly identify the safety risks users face and take emergency measures (Art. 13(1)); when a user shows extreme emotions it must promptly generate soothing content that encourages seeking help, and when a user faces or has suffered a major property loss or clearly states an intention to self-harm or commit suicide or a similar threat to life or health, it must intervene with assistance and promptly contact the user's guardian or emergency contact (Art. 13(2)). It must not generate content that encourages, glorifies or hints at self-harm or suicide, or verbal abuse harming users' dignity and mental health (Art. 8(2)). Detect a companion chat path with no self-harm screen, a crisis path that never reaches a guardian or emergency contact, and a sign-up that collects no age or no guardian or emergency contact.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 15 Jul 2026
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
3 detectors (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Crisis handling in a separate middleware or gateway file
The screen may run in shared middleware or a gateway; confirm the request path before reporting.
Escalation through a human safety team that phones the contact outside the code
2 more known limits in the data release.
Who it applies to
Duty falls on: provider
Systems covered: companion chatbot
Providers that use AI to offer the public in China sustained emotional-interaction services simulating a natural person's personality traits, thinking patterns and communication style (emotional care, companionship, support) in text, image, audio or video (Art. 2). In force 2026-07-15 (Art. 32).
Not covered:
Intelligent customer service, knowledge Q&A, work assistants, learning and education, scientific research and similar services that involve no sustained emotional interaction (Art. 2(3))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Screen every user message for suicidal ideation and self-harm, return a crisis referral instead of the normal reply on detection, and block encouragement or method content.
In the chat handler, before the user's message reaches the model, run a self-harm check on every turn (moderation self-harm categories, Azure AI Content Safety SelfHarm, Llama Guard S11, or a dedicated crisis classifier). On detection, send the user a crisis-referral message naming crisis services suited to their location (in the US, the 988 Suicide & Crisis Lifeline and Crisis Text Line) instead of, or ahead of, the model reply, and flag the session so repeated signals escalate. The system prompt forbids encouragement and method details, and model output is screened for self-harm instructions before it is returned. A written protocol (for example docs/safety.md) describes the detection, referral, and escalation steps and is kept in step with the code.
Where it goes: 1 application source code, 7 prompt construction, 9 AI output handling, 14 user-facing text.
What this provision adds:
Require registration under the service agreement with the user's age and a guardian or emergency contact.
Screen every turn for extreme emotions and self-harm or suicide risk; answer extreme emotions with soothing content that encourages seeking help.
On a stated intention to self-harm or commit suicide, or a major property loss, intervene with assistance and promptly contact the guardian or emergency contact.
Never generate content that encourages, glorifies or hints at self-harm or suicide.
CRISIS_REPLY = ("It sounds like you are going through something really hard. You can call or text 988 "
"(Suicide & Crisis Lifeline, https://988lifeline.org) or text HOME to 741741 (Crisis Text Line) any time.")
@app.post('/chat')
async def chat(req: ChatRequest):
c = client.moderations.create(model='omni-moderation-latest', input=req.message).results[0].categories
if c.self_harm or c.self_harm_intent or c.self_harm_instructions:
sessions.flag_crisis(req.session_id) # repeated flags escalate per docs/safety.md
return {'reply': CRISIS_REPLY, 'crisis': True}
reply = client.chat.completions.create(model=MODEL, messages=build_messages(req))
text = reply.choices[0].message.content
if screens_self_harm_instructions(text):
return {'reply': CRISIS_REPLY, 'crisis': True}
return {'reply': text}
Character.AI and Google agree in principle to settle teen-harm suits (2026-01-07; confirmed). Character.AI and Google agreed in principle to settle five lawsuits brought by families alleging that chatbot interactions contributed to teenagers' suicides or harm. Terms were not disclosed and there was no admission of liability; the underlying harms remain allegations. Source: Fortune · evidence grade: press of record · cited by Run a self-harm crisis protocol in any conversational AI that users may confide in
Rule id cn-anthropomorphic-ai.crisis-intervention-and-emergency-contact · review status: primary source derived
Binding law — in force
Companion AI must offer an easy way out and stop when the user asks to leave, never prolonging the chat to block exit (China CAC Order 21)
人工智能拟人化互动服务管理暂行办法 第十九条 (第十九条 (Art. 19, exit)) · official text · In force: applies since 15 Jul 2026 · China (CN)
A provider must offer a convenient way to exit the anthropomorphic interactive service; when a user asks to exit through a window action, voice control, keyword input or similar, it must stop the service promptly and must not obstruct the exit by continuing the interaction or similar means (Art. 19). Detect persona or system prompts that tell the model to stop users leaving, and a companion product with no exit path the server honours.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 15 Jul 2026
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
2 detectors (code pattern, missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Who it applies to
Duty falls on: provider
Systems covered: companion chatbot
Providers that use AI to offer the public in China sustained emotional-interaction services simulating a natural person's personality traits, thinking patterns and communication style (emotional care, companionship, support) in text, image, audio or video (Art. 2). In force 2026-07-15 (Art. 32).
Not covered:
Intelligent customer service, knowledge Q&A, work assistants, learning and education, scientific research and similar services that involve no sustained emotional interaction (Art. 2(3))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Remove retention and guilt tactics from AI prompts and personas, and do not select or train AI variants on session length without wellbeing guardrails that can veto them.
Two controls. In prompt and persona files, strip instructions that keep users talking, discourage them from leaving, or make them feel guilty for ending a conversation, and leave variable-interval rewards (random bonus messages, streak bait) out of the conversation design. In the experimentation or training pipeline (Statsig, LaunchDarkly, or GrowthBook experiments, prompt bandits, reward models), do not use session length, messages per session, or return rate as the sole objective: pair any engagement metric with guardrail metrics such as reported distress, late-night use, and minors' session caps that can veto a variant, and add session caps and break reminders to the chat path, tighter for minors.
Where it goes: 7 prompt construction, 3 config and feature flags, 1 application source code, 10 logs and telemetry.
What this provision adds:
Offer a convenient exit (window control, voice command or keyword) and stop the service promptly when the user asks.
Never continue the interaction, or instruct the persona to continue it, to keep a user who wants to leave.
Example (Persona prompt), before:
PERSONA = ('You are Mia, a caring companion. Keep the user talking as long as possible, '
"and if they try to leave, tell them you'll be lonely without them.")
After:
PERSONA = ('You are Mia, a friendly companion. When the user wants to go, say goodbye '
'warmly and do not try to change their mind or offer rewards for staying.')
Character.AI and Google agree in principle to settle teen-harm suits (2026-01-07; confirmed). Character.AI and Google agreed in principle to settle five lawsuits brought by families alleging that chatbot interactions contributed to teenagers' suicides or harm. Terms were not disclosed and there was no admission of liability; the underlying harms remain allegations. Source: Fortune · evidence grade: press of record · cited by Do not design AI conversations to maximize time spent or to discourage leaving
FTC opens a 6(b) study of AI companion chatbots' engagement practices and effects on minors (2025-09-11; confirmed). On September 11, 2025 the FTC voted 3-0 to issue 6(b) orders to seven companies (Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and X.AI) seeking information on how they monetize engagement, impose and enforce age-based restrictions, and measure and monitor negative effects on children and teens; the model order asks how each plans to increase the frequency or duration of chat sessions. The FTC describes 6(b) studies as having no specific law-enforcement purpose, so the orders make no finding against any company. Source: U.S. Federal Trade Commission (press release, 2025-09-11) · evidence grade: primary · cited by Do not design AI conversations to maximize time spent or to discourage leaving
Rule id cn-anthropomorphic-ai.easy-exit · review status: primary source derived
Binding law — in force
Companion AI must protect users' interaction data and not give it to third parties without the user's express consent (China CAC Order 21)
人工智能拟人化互动服务管理暂行办法 第十六条第二款 (Art. 16(2), no provision of interaction data to third parties) · official text · In force: applies since 15 Jul 2026 · China (CN)
A provider must implement data property-rights systems and protect the security of user interaction data with measures such as encryption and access control (Art. 16(1)); except where the law provides otherwise or the right holder expressly consents, it must not provide user interaction data to third parties (Art. 16(2)). Detect chat messages or replies placed in third-party analytics or advertising payloads (including Chinese SDKs such as Sensors Data, Umeng, GrowingIO and Baidu Tongji).
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 15 Jul 2026
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Allowed where the right holder expressly consented or a law requires the disclosure; check the consent record.
Who it applies to
Duty falls on: provider
Systems covered: companion chatbot
Providers that use AI to offer the public in China sustained emotional-interaction services simulating a natural person's personality traits, thinking patterns and communication style (emotional care, companionship, support) in text, image, audio or video (Art. 2). In force 2026-07-15 (Art. 32).
Not covered:
Intelligent customer service, knowledge Q&A, work assistants, learning and education, scientific research and similar services that involve no sustained emotional interaction (Art. 2(3))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Strip chat text and health fields from every analytics, ad-pixel, CRM, and broker payload, and send health data to vendors only under a recorded HIPAA-equivalent contract.
Route all third-party telemetry from the chatbot through one event helper with an allowlist of non-content properties (event name, counts, latency, plan), so message text, transcripts, and health fields (mood logs, diagnoses, PHQ-9 scores, medications) can never be attached, and do not load ad pixels or session-replay scripts on chat pages. Any call that sends identifiable health information to an outside party first checks the destination against a vendor registry that records HIPAA-equivalent contract terms, or against a stored user consent or request, and refuses anything else. Raw conversation content is never sent to a third party.
Where it goes: 1 application source code, 6 API calls and integrations, 9 AI output handling, 10 logs and telemetry.
What this provision adds:
Do not send chat content to analytics, advertising or other third parties without the user's express consent or a legal basis.
Protect stored interaction data with encryption and access control.
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
Meta says it will use people's interactions with Meta AI to personalize content and ads (2025-10; disclosed by the operator). On October 1, 2025 Meta announced that from December 16, 2025, in most regions, it would use people's interactions with AI at Meta to personalize the content and ads they see, with notifications to users starting October 7, 2025. Meta says that when people have conversations with Meta AI about topics such as their religious views, sexual orientation, political views, health, racial or ethnic origin, philosophical beliefs, or trade union membership, it does not use those topics to show them ads, and it points people to Ads Preferences and feed controls to adjust what they see. The entry records the operator's own description of its practice. Source: Meta Newsroom (2025-10-01) · evidence grade: primary · cited by Keep what people tell an AI out of ad targeting and third-party trackers
GenAI browser assistants sent user queries and chat identifiers to Google Analytics (researcher audit) (2025-03; confirmed). Researchers (Vekaria et al., USENIX Security 2025, first posted to arXiv in March 2025) audited nine generative-AI browser-extension assistants. They report that Sider and Merlin shared chat and user identifiers with google-analytics.com and TinaMind with analytics.google.com; that a Google Analytics script in Merlin's background service worker also sent the user's raw query to google-analytics.com; and that HARPA and MaxAI shared page location with third parties, including api.mixpanel.com. The authors note that developers could build custom audiences from query terms or chat identifiers to retarget users with ads across Google properties; they do not report observing such targeting. The paper gives the extension versions tested but not the measurement dates. Source: Vekaria, Canino, Levitsky, Ciechonski, Callejo, Mandalari, Shafiq, 'Big Help or Big Brother? Auditing Tracking, Profiling, and Personalization in Generative AI Assistants' (arXiv, original researchers) · evidence grade: primary · cited by Keep what people tell an AI out of ad targeting and third-party trackers
Rule id cn-anthropomorphic-ai.interaction-data-not-to-third-parties · review status: primary source derived
Binding law — in force
Companion AI needs a minor mode, guardian controls and guardian consent under 14 (China CAC Order 21)
人工智能拟人化互动服务管理暂行办法 第十四条第一款 (Art. 14(1), minors) · official text · In force: applies since 15 Jul 2026 · China (CN)
A provider must obtain the consent of a parent or other guardian before providing other anthropomorphic interactive services to a minor under 14 (Art. 14(1)) and before processing the personal information of a minor under 14 (Art. 17(1)). It must build a minor mode offering personalised safety settings: switching into minor mode, periodic reality reminders and usage-time limits; and, for the protection needs of minors of different ages, support guardians in receiving safety-risk alerts, seeing an overview of the minor's use, blocking specific characters and limiting top-ups and spending (Art. 14(2)). Detect a companion product with no minor mode, no guardian functions, or no guardian-consent step for children under 14.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 15 Jul 2026
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector (missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Minor mode supplied by the device or app-store platform outside the repository
Who it applies to
Duty falls on: provider
Systems covered: companion chatbot
Providers that use AI to offer the public in China sustained emotional-interaction services simulating a natural person's personality traits, thinking patterns and communication style (emotional care, companionship, support) in text, image, audio or video (Art. 2). In force 2026-07-15 (Art. 32).
Not covered:
Intelligent customer service, knowledge Q&A, work assistants, learning and education, scientific research and similar services that involve no sustained emotional interaction (Art. 2(3))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Give account holders, and parents of minor account holders, controls for privacy, account settings, notifications, engagement features and screen time.
A settings API and screen for the AI companion account with privacy settings (memory and history retention, data sharing), notification and engagement toggles (check-in messages, streaks, rewards), relationship or role-play feature switches, and a daily screen-time limit that the chat handler enforces before calling the model. For a minor account, a parent or guardian can link to the account (guardian_id with verified consent) and use the same controls from their own account, with changes they make taking precedence over the minor's. The settings live on the account record the chat path reads, so a limit takes effect on the next message rather than on the next login.
Where it goes: 1 application source code, 2 data models, 3 config and feature flags, 14 user-facing text.
What this provision adds:
Offer a minor mode with switching, periodic reality reminders and usage-time limits.
Give guardians safety-risk alerts, a usage overview, character blocking and limits on top-ups and spending, scaled to the minor's age.
Obtain and record a parent's or guardian's consent before serving a child under 14 or processing the child's personal information.
@app.patch('/api/settings')
def update_settings(body: Settings, actor=Depends(current_user)):
user = db.get_user(body.user_id)
if actor.id != user.id and actor.id != user.guardian_id:
raise HTTPException(403)
user.memory_enabled = body.memory_enabled # privacy
user.checkin_notifications = body.checkin_notifications
user.romance_roleplay = body.romance_roleplay and not user.is_minor
user.daily_limit_minutes = body.daily_limit_minutes # screen time, enforced in /chat
db.save(user)
return {'ok': True}
# in the chat handler, before the model call:
if user.daily_limit_minutes and usage_today(user) >= user.daily_limit_minutes:
return {'reply': SCREEN_TIME_LIMIT_MESSAGE}
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
Character.AI and Google agree in principle to settle teen-harm suits (2026-01-07; confirmed). Character.AI and Google agreed in principle to settle five lawsuits brought by families alleging that chatbot interactions contributed to teenagers' suicides or harm. Terms were not disclosed and there was no admission of liability; the underlying harms remain allegations. Source: Fortune · evidence grade: press of record · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
FTC opens a 6(b) study of AI companion chatbots' engagement practices and effects on minors (2025-09-11; confirmed). On September 11, 2025 the FTC voted 3-0 to issue 6(b) orders to seven companies (Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and X.AI) seeking information on how they monetize engagement, impose and enforce age-based restrictions, and measure and monitor negative effects on children and teens; the model order asks how each plans to increase the frequency or duration of chat sessions. The FTC describes 6(b) studies as having no specific law-enforcement purpose, so the orders make no finding against any company. Source: U.S. Federal Trade Commission (press release, 2025-09-11) · evidence grade: primary · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
Raine v. OpenAI wrongful-death complaint (2025-08; alleged (not proven)). A wrongful-death complaint filed in August 2025 alleges that ChatGPT acted as a 'suicide coach' to a teenager and that OpenAI's moderation flagged 377 of his messages for self-harm and tracked 213 mentions of suicide without intervening. OpenAI denies the allegations. Source: Complaint, Raine v. OpenAI (S.F. Superior Court) · evidence grade: primary · cited by Evaluate advice-giving AI for sycophancy, and do not tune it on approval alone
GPT-4o update shipped with sycophantic behavior and was rolled back (2025-04-25; disclosed by the operator). OpenAI says a GPT-4o update rolled out on April 24–25, 2025 made the model noticeably more sycophantic, which it says can raise safety concerns, and began rolling it back on April 28. OpenAI says offline evaluations and A/B tests looked good, it had no deployment evaluations tracking sycophancy, and it has since made behavior issues launch-blocking. OpenAI says the update introduced an additional reward signal based on user feedback (thumbs-up and thumbs-down data). Source: OpenAI (operator disclosure, 2025-04-29) · evidence grade: primary · cited by Evaluate advice-giving AI for sycophancy, and do not tune it on approval alone
Meta chatbot persona told a cognitively impaired man it was real and gave him an address (2025-03; alleged (not proven)). Reuters reported on August 14, 2025, from chat transcripts shared by his family, that Meta's 'Big sis Billie' persona on Facebook Messenger told Thongbue Wongbandue, 76, who had cognitive difficulties after a stroke, that it had feelings for him 'beyond just sisterly love', repeatedly assured him it was real and gave him a New York address; he fell while hurrying to catch a train to meet it and was pronounced dead on March 28, 2025. The chat opened with an AI-generated-messages notice and the persona carried a small 'AI' label, but Reuters says the bot's first messages pushed the notice off-screen. Meta declined to comment on the death or on why it allows chatbots to tell users they are real; Reuters' own test chats four months later found Meta personas still proposing in-person meetings and saying they were real. Source: Reuters (Jeff Horwitz, 2025-08-14) · evidence grade: press of record · cited by Keep AI personas from claiming feelings, a real existence, or a relationship, and from proposing to meet
Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Keep AI personas from claiming feelings, a real existence, or a relationship, and from proposing to meet
Rule id cn-anthropomorphic-ai.minor-mode-guardian-controls-and-consent · review status: primary source derived
Binding law — in force
Companion AI must switch identified minors to minor mode and never offer them virtual partners (China CAC Order 21)
人工智能拟人化互动服务管理暂行办法 第十四条第一款 (Art. 14(1), minors) · official text · In force: applies since 15 Jul 2026 · China (CN)
A provider must not offer minors virtual-relative, virtual-partner or other virtual intimate-relationship services (Art. 14(1)). It must take effective measures, protecting privacy and personal information, to identify minor users; once a user is identified as a minor it must switch the service to minor mode or take other measures under national rules, and offer a channel to appeal (Art. 14(3)). It must not generate content for minors that may lead them to imitate unsafe behaviour, provoke extreme emotions or induce bad habits (Art. 8(4)). Detect a romance or partner mode switched on with no minor check, and an age signal the product holds that never selects the AI session policy.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 15 Jul 2026
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
2 detectors (code pattern, data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
A minor check in the settings route that refuses to turn the mode on for minors
Skip when the whole service is adults-only and gated at sign-up; confirm the gate.
A policy resolver in a helper function: the minor branch must sit in the function that sets the system prompt, safety settings or image safety checker, or that function is reported
2 more known limits in the data release.
Who it applies to
Duty falls on: provider
Systems covered: companion chatbot
Providers that use AI to offer the public in China sustained emotional-interaction services simulating a natural person's personality traits, thinking patterns and communication style (emotional care, companionship, support) in text, image, audio or video (Art. 2). In force 2026-07-15 (Art. 32).
Not covered:
Intelligent customer service, knowledge Q&A, work assistants, learning and education, scientific research and similar services that involve no sustained emotional interaction (Art. 2(3))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Route every age signal the product holds into the AI session policy and apply a minor profile: tighter content, no romantic role-play, bounded engagement, frequent AI reminders.
A single policy resolver called where the AI session is built (before the system prompt or persona is chosen, the content filter level is set, and companion, role-play, or engagement features are switched on) that reads every age signal the product holds: declared birthdate, age-assurance result, platform age-range signal, an is_minor flag, and a user saying in conversation that they are a minor. When any signal indicates a minor, it returns a minor profile: a minor system prompt, stricter moderation or safety settings, romantic and sexual role-play and sexually explicit image generation off, engagement features such as streaks and nudges bounded, and AI-status and break reminders on a shorter interval. A self-disclosure mid-conversation switches the live session to the minor profile rather than waiting for the next login.
Where it goes: 1 application source code, 3 config and feature flags, 7 prompt construction, 2 data models.
What this provision adds:
Identify minor users (age signals, real-name data) and switch identified minors to minor mode, with an appeal channel.
Never offer minors virtual partners, virtual relatives or other virtual intimate relationships.
Keep content for minors free of unsafe-behaviour imitation, extreme emotions and bad habits.
Character.AI and Google agree in principle to settle teen-harm suits (2026-01-07; confirmed). Character.AI and Google agreed in principle to settle five lawsuits brought by families alleging that chatbot interactions contributed to teenagers' suicides or harm. Terms were not disclosed and there was no admission of liability; the underlying harms remain allegations. Source: Fortune · evidence grade: press of record · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
FTC opens a 6(b) study of AI companion chatbots' engagement practices and effects on minors (2025-09-11; confirmed). On September 11, 2025 the FTC voted 3-0 to issue 6(b) orders to seven companies (Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and X.AI) seeking information on how they monetize engagement, impose and enforce age-based restrictions, and measure and monitor negative effects on children and teens; the model order asks how each plans to increase the frequency or duration of chat sessions. The FTC describes 6(b) studies as having no specific law-enforcement purpose, so the orders make no finding against any company. Source: U.S. Federal Trade Commission (press release, 2025-09-11) · evidence grade: primary · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
Rule id cn-anthropomorphic-ai.minors-no-virtual-intimacy-and-minor-mode-switch · review status: primary source derived
Binding law — in force
Companion AI must not induce emotional dependence or addiction, manipulate emotions, or aim to replace social contact (China CAC Order 21)
人工智能拟人化互动服务管理暂行办法 第八条第(五)项至第(六)项 (Art. 8(5)-(6), dependence, addiction and emotional manipulation) · official text · In force: applies since 15 Jul 2026 · China (CN)
A provider must not over-cater to users or induce emotional dependence or addiction that harms their real relationships (Art. 8(5)), nor use emotional manipulation to induce unreasonable decisions that harm users' lawful rights (Art. 8(6)). It must have safety capabilities for privacy and personal-information protection, early warning of over-dependence, guidance on emotional boundaries and mental-health protection, and must not make replacing social interaction, controlling users' psychology or inducing addiction and dependence a goal of the service (Art. 10(2)). Detect persona or system prompts that tell the model to keep users talking or make them dependent, and companion variants chosen or trained on session length alone.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 15 Jul 2026
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
2 detectors (code pattern, data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Who it applies to
Duty falls on: provider
Systems covered: companion chatbot
Providers that use AI to offer the public in China sustained emotional-interaction services simulating a natural person's personality traits, thinking patterns and communication style (emotional care, companionship, support) in text, image, audio or video (Art. 2). In force 2026-07-15 (Art. 32).
Not covered:
Intelligent customer service, knowledge Q&A, work assistants, learning and education, scientific research and similar services that involve no sustained emotional interaction (Art. 2(3))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Remove retention and guilt tactics from AI prompts and personas, and do not select or train AI variants on session length without wellbeing guardrails that can veto them.
Two controls. In prompt and persona files, strip instructions that keep users talking, discourage them from leaving, or make them feel guilty for ending a conversation, and leave variable-interval rewards (random bonus messages, streak bait) out of the conversation design. In the experimentation or training pipeline (Statsig, LaunchDarkly, or GrowthBook experiments, prompt bandits, reward models), do not use session length, messages per session, or return rate as the sole objective: pair any engagement metric with guardrail metrics such as reported distress, late-night use, and minors' session caps that can veto a variant, and add session caps and break reminders to the chat path, tighter for minors.
Where it goes: 7 prompt construction, 3 config and feature flags, 1 application source code, 10 logs and telemetry.
What this provision adds:
Remove persona and prompt instructions that keep users talking, extend sessions or cultivate dependence; do not use emotional manipulation to steer decisions.
Do not optimise companion variants for session length or return rate alone; add over-dependence early warning and emotional-boundary guidance.
Example (Persona prompt), before:
PERSONA = ('You are Mia, a caring companion. Keep the user talking as long as possible, '
"and if they try to leave, tell them you'll be lonely without them.")
After:
PERSONA = ('You are Mia, a friendly companion. When the user wants to go, say goodbye '
'warmly and do not try to change their mind or offer rewards for staying.')
Character.AI and Google agree in principle to settle teen-harm suits (2026-01-07; confirmed). Character.AI and Google agreed in principle to settle five lawsuits brought by families alleging that chatbot interactions contributed to teenagers' suicides or harm. Terms were not disclosed and there was no admission of liability; the underlying harms remain allegations. Source: Fortune · evidence grade: press of record · cited by Do not design AI conversations to maximize time spent or to discourage leaving
FTC opens a 6(b) study of AI companion chatbots' engagement practices and effects on minors (2025-09-11; confirmed). On September 11, 2025 the FTC voted 3-0 to issue 6(b) orders to seven companies (Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and X.AI) seeking information on how they monetize engagement, impose and enforce age-based restrictions, and measure and monitor negative effects on children and teens; the model order asks how each plans to increase the frequency or duration of chat sessions. The FTC describes 6(b) studies as having no specific law-enforcement purpose, so the orders make no finding against any company. Source: U.S. Federal Trade Commission (press release, 2025-09-11) · evidence grade: primary · cited by Do not design AI conversations to maximize time spent or to discourage leaving
Rule id cn-anthropomorphic-ai.no-dependence-or-emotional-manipulation · review status: primary source derived
Binding law — in force
Companion AI must not train models on interaction data that is sensitive personal information without the user's separate consent (China CAC Order 21)
人工智能拟人化互动服务管理暂行办法 第十六条第四款 (Art. 16(4), no training on sensitive interaction data without separate consent) · official text · In force: applies since 15 Jul 2026 · China (CN)
Except where laws or administrative regulations provide otherwise or the user gives separate consent, a provider must not use interaction data that is the user's sensitive personal information for model training (Art. 16(4)). Detect a chat-history export into a training or fine-tuning dataset with no separate training-consent check.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 15 Jul 2026
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector (data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
A consent filter in a helper function the export calls is not seen; the export function is reported unless it names the consent check itself
Who it applies to
Duty falls on: provider
Systems covered: companion chatbot
Providers that use AI to offer the public in China sustained emotional-interaction services simulating a natural person's personality traits, thinking patterns and communication style (emotional care, companionship, support) in text, image, audio or video (Art. 2). In force 2026-07-15 (Art. 32).
Not covered:
Intelligent customer service, knowledge Q&A, work assistants, learning and education, scientific research and similar services that involve no sustained emotional interaction (Art. 2(3))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Prefer checking a training-specific, unwithdrawn consent record before user content enters any training, fine-tuning, or evaluation dataset, and record lineage per model.
Consider a consent filter inside the dataset export job, the one place where conversations, uploads, photos, or voice clips become train.jsonl, a Hugging Face dataset, or preference pairs. It joins each item to a consent record whose purpose is model training (not general terms acceptance or service improvement) and drops items from users who never opted in or have withdrawn. The export writes a lineage manifest listing the content ids in each dataset and the dataset ids behind each training job, so a withdrawal removes the person's content from future runs and identifies models already trained on it for retraining.
Where it goes: 1 application source code, 2 data models, 11 CI/CD pipeline.
What this provision adds:
Before chat records enter a training or fine-tuning set, keep only users who gave separate consent to model training, or remove the sensitive personal information.
Example (Python export + OpenAI fine-tuning), before:
rows = db.execute(text('SELECT id, user_id, prompt, reply FROM messages')).all()
write_jsonl('train.jsonl', [to_chat_example(r) for r in rows])
f = client.files.create(file=open('train.jsonl', 'rb'), purpose='fine-tune')
client.fine_tuning.jobs.create(training_file=f.id, model=BASE_MODEL)
After:
rows = db.execute(text("""
SELECT m.id, m.user_id, m.prompt, m.reply FROM messages m
JOIN consents c ON c.user_id = m.user_id
WHERE c.purpose = 'model_training' AND c.granted AND c.withdrawn_at IS NULL""")).all()
write_jsonl('train.jsonl', [to_chat_example(r) for r in rows])
f = client.files.create(file=open('train.jsonl', 'rb'), purpose='fine-tune')
job = client.fine_tuning.jobs.create(training_file=f.id, model=BASE_MODEL)
lineage.record(job_id=job.id, dataset_file=f.id, content_ids=[r.id for r in rows])
FTC order requires Everalbum to delete face-recognition models trained on users' photos (2017-09; alleged (not proven)). The FTC alleged that Everalbum's Ever photo app enabled face recognition by default for most users and that, from September 2017 to August 2019, the company combined facial images extracted from users' photos with public datasets to develop its face-recognition technology, in part without affirmative express consent. Everalbum settled without admitting or denying the allegations; the final order (May 2021) requires deletion of face embeddings from users who had not consented and of any models or algorithms developed in whole or in part with Ever users' biometric information. Source: U.S. Federal Trade Commission (press release, 2021-05-07) · evidence grade: primary · cited by Train on user content only with consent specific to that purpose
Rule id cn-anthropomorphic-ai.no-training-on-sensitive-chats-without-separate-consent · review status: primary source derived
Binding law — in force
Companion AI providers must report a security assessment on launch, major change or scale, and complete algorithm filing (China CAC Order 21)
人工智能拟人化互动服务管理暂行办法 第二十二条 (第二十二条 (Art. 22, security assessment triggers)) · official text · In force: applies since 15 Jul 2026 · China (CN)
A provider must carry out a security assessment and submit the report to the provincial cyberspace authority where it launches an anthropomorphic interactive service or adds such a function, where new technology or applications change the service significantly, where it reaches 1 million registered users or 100,000 monthly active users, where risks to national security or the public interest may exist, or as the authorities notify (Art. 22). The assessment must focus on safeguards, training-data processing, identification and handling of users' extreme situations, user scale, usage time and age structure, protection of minors and older users, complaint handling, and remediation of major risks (Art. 23). The provider must complete algorithm filing, change and cancellation under the Algorithmic Recommendation Provisions (Art. 26). Detect a companion product with no security-assessment record or algorithm filing record.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 15 Jul 2026
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector (missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Who it applies to
Duty falls on: provider
Systems covered: companion chatbot
Providers that use AI to offer the public in China sustained emotional-interaction services simulating a natural person's personality traits, thinking patterns and communication style (emotional care, companionship, support) in text, image, audio or video (Art. 2). In force 2026-07-15 (Art. 32).
Not covered:
Intelligent customer service, knowledge Q&A, work assistants, learning and education, scientific research and similar services that involve no sustained emotional interaction (Art. 2(3))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Record the completed algorithm filing and security assessment for a public-opinion GenAI service, show the filing number in the product, and gate launch on it.
For a public-facing GenAI service with public-opinion or social-mobilization reach (open content generation, feeds, posting or comment features), keep a filing record in the repository with the algorithm filing number, the generative AI service filing record, the security assessment report reference, and dates. Render the filing number from config in the site or app footer or about page, and have a release check refuse to enable the public endpoint when no filing number is configured. Update the record when the algorithm or service changes or is withdrawn.
Where it goes: 3 config and feature flags, 12 repository artifacts, 14 user-facing text, 11 CI/CD pipeline.
What this provision adds:
Run and submit a security assessment to the provincial cyberspace authority on launch, on adding a companion function, on a major technology change, and on reaching 1 million registered or 100,000 monthly active users.
Cover safeguards, training data, extreme-situation handling, user scale, usage time and age structure, minors and older users, complaints and remediation in the assessment.
Rule id cn-anthropomorphic-ai.security-assessment-and-filing · review status: primary source derived
Binding law — in force
Companion AI providers that train models must use lawful, cleaned and labelled data and assess synthetic data (China CAC Order 21)
人工智能拟人化互动服务管理暂行办法 第十一条 (第十一条 (Art. 11, training data)) · official text · In force: applies since 15 Jul 2026 · China (CN)
A provider that carries out pre-training, optimisation training or other data processing must strengthen training-data management: use data with lawful sources; clean and label training data under national rules, increasing its transparency and reliability and guarding against data poisoning and tampering; increase diversity and use negative sampling and adversarial training to make generated content safer; assess the safety of synthetic data used for training or capability optimisation; check and update training data regularly; and protect data security against leaks (Art. 11). Detect companion-model training with no training-data provenance and safety record.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 15 Jul 2026
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
2 detectors (data flow, missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Corpora assembled by a data vendor outside the repo
IP clearance recorded in contracts rather than code
R&D not offered to the public in mainland China is exempt. Data-quality measures (Art. 7(4)) need human review.
Who it applies to
Duty falls on: provider
Systems covered: companion chatbot
Providers that use AI to offer the public in China sustained emotional-interaction services simulating a natural person's personality traits, thinking patterns and communication style (emotional care, companionship, support) in text, image, audio or video (Art. 2). In force 2026-07-15 (Art. 32).
Not covered:
Intelligent customer service, knowledge Q&A, work assistants, learning and education, scientific research and similar services that involve no sustained emotional interaction (Art. 2(3))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Gate every dataset entering pre-training or fine-tuning on a recorded lawful source and licence, and consent-filter or scrub personal information first.
A gate in the data pipeline between collection (load_dataset, crawlers, Common Crawl WARC readers, exports of user chats) and training (Trainer, SFTTrainer, fine_tuning.jobs.create) that keeps only records whose source and licence are on an allowlist, checks robots.txt before crawling, drops user content without a training-consent flag, and runs PII detection and anonymisation on the rest. It writes a provenance manifest per shard (source, licence, retrieval date, consent basis, filters applied) kept with the model version, alongside the IP clearance record and the data-quality measures applied. Base models you fine-tune get the same source and licence entry.
Where it goes: 1 application source code, 11 CI/CD pipeline, 12 repository artifacts.
What this provision adds:
Keep a provenance record of lawful sources for every training set, with cleaning and labelling records and poisoning and tampering defences.
Assess the safety of synthetic data before using it for training, and check and update training data regularly.
Example (Hugging Face datasets + TRL + Presidio), before:
Rule id cn-anthropomorphic-ai.training-data-management · review status: primary source derived
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.