Binding law — in force
AI-content labels must follow the methods of mandatory national standard GB 45438-2025 (China)
The Labeling Measures require labelling by generation and synthesis service providers and by content distribution platforms to also meet mandatory national standards (Art. 11). GB 45438-2025, Cybersecurity technology - Labeling method for content generated by artificial intelligence, is that standard: issued by SAMR and SAC on 2025-02-28 and in force since 2025-09-01, it sets the methods for explicit labels (text, sound, graphics and similar forms users can perceive) and implicit labels (information embedded in the file metadata) for providers of generation and synthesis services and of content distribution services. TwinEthos cites the standard as a whole and does not reproduce it; which forms, positions and metadata fields it fixes for each content type is to be read in the standard itself (counsel flag). Detect a labelling implementation with no record of conformance to the standard's explicit and implicit label methods.
Trust and provenance not reviewed by a lawyer · audit-grade · source verified 2 Oct 2026 · release 2026.10.03.3
- Lane
- Binding law — in force In force: applies since 1 Sep 2025
- Official source
- GB 45438-2025 网络安全技术 人工智能生成合成内容标识方法 (whole standard: explicit and implicit labelling methods) · captured 2 Oct 2026 · 5 more anchors in the data release
- Verification
- Licensed standard: cited, never quoted; the citation and public scope are checked, not text. Source last verified 2 Oct 2026: public scope of the licensed standard re-read (its text is never stored); cited only.
- Data release
- Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
- Legal review
- Not reviewed by a lawyer. The source is a licensed standard: TwinEthos cites it and works from its public scope, never its text, so check the standard itself. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
- Audit standard
- Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
1 detector (missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Who it applies to
- Duty falls on: provider
- Generation and synthesis service providers and content distribution service providers subject to the Labeling Measures (Art. 2, Art. 11). In force 2025-09-01.
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Add both a visible AI-generated label and implicit metadata naming the provider and a content ID to synthetic content before the file is saved, returned, or exported.
A labeling step between the generator call and every save, return, or download path does two things: it adds an explicit label users can perceive (text drawn onto images or video frames, an audible notice in audio, a label beside generated text in the UI), and it writes implicit metadata into the file (a PNG text chunk, XMP block, or C2PA manifest) carrying the AI-generated attribute, the provider's name or code, and a unique content ID. Export and download routes go through the same step so files leave with both labels; a digital watermark can complement the metadata.
Where it goes: 9 AI output handling, 1 application source code.
What this provision adds:
- Implement explicit and implicit labels to the methods of GB 45438-2025 for every content type you generate or distribute, and keep a test per content type that checks the output against the standard.
Example (OpenAI Images + Pillow), before:
b64 = client.images.generate(model='gpt-image-1', prompt=prompt).data[0].b64_json
img = Image.open(io.BytesIO(base64.b64decode(b64)))
img.save(path)After:
b64 = client.images.generate(model='gpt-image-1', prompt=prompt).data[0].b64_json
img = Image.open(io.BytesIO(base64.b64decode(b64))).convert('RGB')
font = ImageFont.truetype('NotoSansCJK-Regular.ttc', 24)
ImageDraw.Draw(img).text((12, img.height - 36), 'AI生成 / AI-generated', fill=(255, 255, 255), font=font)
meta = PngInfo()
# implicit label: AI-generated attribute, provider name or code, content reference (Art. 5);
# take the exact metadata field names from the national standard GB 45438-2025 (not encoded here)
meta.add_text('ai_generated_label', json.dumps({'ai_generated': True, 'provider': PROVIDER_CODE,
'content_id': str(uuid.uuid4())}))
img.save(path, format='PNG', pnginfo=meta)Control: GenAI content lacking explicit and implicit labels. The same guard addresses 4 items with binding law in 3 jurisdictions. Engineering guidance, not legal advice.
Rule id cn-gb-45438.labelling-methods · review status: tier c citation only