TwinEthosRequest access

Law

China GenAI Interim Measures

Cyberspace Administration of China (CAC) · China (CN) · 2 provisions encoded · verified against the official source as of 2026-09-27.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Official text: www.cac.gov.cn.

Binding law — in force

Public-opinion GenAI services must complete filing and a security assessment (China)

生成式人工智能服务管理暂行办法 第十七条 (Art. 17) · official text · In force: applies since 15 Aug 2023 · China (CN)

Under China's GenAI Interim Measures Art. 17, providers of generative AI services with public-opinion properties or social-mobilization capability must carry out a security assessment per state provisions and complete algorithm filing/modification/cancellation under the Algorithmic Recommendation Provisions. Detect a public-facing GenAI service (public-opinion/social-mobilization capable) with no completed algorithm filing or security assessment.

Who it applies to

  • Duty falls on: provider
  • Providers of public-facing GenAI services in China with public-opinion or social-mobilization attributes. Effective 2023-08-15. (First 11 providers filed by 2023-08-31.)
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Record the completed algorithm filing and security assessment for a public-opinion GenAI service, show the filing number in the product, and gate launch on it.

For a public-facing GenAI service with public-opinion or social-mobilization reach (open content generation, feeds, posting or comment features), keep a filing record in the repository with the algorithm filing number, the generative AI service filing record, the security assessment report reference, and dates. Render the filing number from config in the site or app footer or about page, and have a release check refuse to enable the public endpoint when no filing number is configured. Update the record when the algorithm or service changes or is withdrawn.

Where it goes: 3 config and feature flags, 12 repository artifacts, 14 user-facing text, 11 CI/CD pipeline.

What this provision adds:

  • Display the algorithm filing number (网信算备…号) in the site or app footer or about page, and keep the generative AI service filing record (生成式人工智能服务备案) and security assessment report reference.
  • Complete algorithm filing modification or cancellation under the Algorithmic Recommendation Provisions when the service changes or ends.

Example (Service config), before:

# config/release.yaml
public_genai_chat:
  enabled: true

After:

# config/release.yaml (startup fails if enabled without filing details)
public_genai_chat:
  enabled: true
  algorithm_filing_number: "<filing number issued after algorithm filing>"
  service_filing_record: records/cn/genai-service-filing.md
  security_assessment_ref: records/cn/security-assessment-2026.pdf

Control: Public-opinion GenAI service without filing / security assessment. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Rule id cn-genai-interim.filing-and-security-assessment · review status: primary source derived

Binding law — in force

GenAI training data must have lawful sources, cleared IP, and consent (China)

生成式人工智能服务管理暂行办法 第七条 (Art. 7) · official text · In force: applies since 15 Aug 2023 · China (CN)

Under China's GenAI Interim Measures Art. 7, providers must handle training data lawfully: use data and foundational models from lawful sources, not infringe others' IP, obtain consent (or another lawful basis) where personal information is involved, employ measures to increase training-data quality, accuracy, objectivity, and diversity, and meet the other requirements of the Cybersecurity, Data Security, and Personal Information Protection Laws and the competent authorities' regulatory requirements. Detect a GenAI training pipeline lacking data-provenance, IP-clearance, or personal-information-consent controls.

Who it applies to

  • Duty falls on: provider
  • Providers of generative AI services to the public in mainland China. Effective 2023-08-15. (R&D not offered to the public is exempt.)

The guard to add

Gate every dataset entering pre-training or fine-tuning on a recorded lawful source and licence, and consent-filter or scrub personal information first.

A gate in the data pipeline between collection (load_dataset, crawlers, Common Crawl WARC readers, exports of user chats) and training (Trainer, SFTTrainer, fine_tuning.jobs.create) that keeps only records whose source and licence are on an allowlist, checks robots.txt before crawling, drops user content without a training-consent flag, and runs PII detection and anonymisation on the rest. It writes a provenance manifest per shard (source, licence, retrieval date, consent basis, filters applied) kept with the model version, alongside the IP clearance record and the data-quality measures applied. Base models you fine-tune get the same source and licence entry.

Where it goes: 1 application source code, 11 CI/CD pipeline, 12 repository artifacts.

What this provision adds:

  • Record the measures taken to increase training-data quality, accuracy, objectivity and diversity alongside the provenance manifest.

Example (Hugging Face datasets + TRL + Presidio), before:

ds = load_dataset('json', data_files='crawl/*.jsonl', split='train')
trainer = SFTTrainer(model=model, train_dataset=ds)
trainer.train()

After:

ALLOWED_LICENSES = {'cc-by-4.0', 'cc0-1.0', 'apache-2.0', 'licensed-by-contract'}
analyzer, anonymizer = AnalyzerEngine(), AnonymizerEngine()

def scrub(row):
    hits = analyzer.analyze(text=row['text'], language=LANG)
    row['text'] = anonymizer.anonymize(text=row['text'], analyzer_results=hits).text
    return row

ds = load_dataset('json', data_files='crawl/*.jsonl', split='train')
ds = ds.filter(lambda r: r['license'] in ALLOWED_LICENSES).map(scrub)
write_provenance_manifest(ds, out='manifests/shard-000.json')
trainer = SFTTrainer(model=model, train_dataset=ds)
trainer.train()

Control: GenAI training data without lawful source / IP / consent controls. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Rule id cn-genai-interim.training-data-legitimacy · review status: primary source derived