How to Comply with China’s Generative AI Rules: 2026 Guide
China’s generative AI rules are the regulatory framework administered by the Cyberspace Administration of China (CAC / 国家互联网信息办公室, Guójiā Hùliánwǎng Xìnxī Bàngōngshì) that governs the development, training, and deployment of generative AI services — including large language models (LLMs), image generation models, text-to-video systems, and multimodal AI — within the People’s Republic of China. The framework, codified in the Interim Measures for the Management of Generative Artificial Intelligence Services (生成式人工智能服务管理暂行办法, Shēngchéngshì Réngōng Zhìnéng Fúwù Guǎnlǐ Zànxíng Bànfǎ) effective August 15, 2023, and its 2025 amendments, applies to any organization providing generative AI services to the Chinese public, regardless of whether the organization is domestic or foreign-owned. As of January 2026, the CAC had registered 284 generative AI services for public release, rejected 37 registration applications, and de-registered 12 services for non-compliance with content safety requirements — including two operated by foreign-invested companies.
Why This Matters
China’s generative AI regulations are substantially more stringent than the EU AI Act or the US Executive Order on AI in three critical areas. First, content safety: all AI-generated content must pass through a government-approved content safety audit that screens for 17 prohibited content categories including material that “undermines national unity and social stability,” “harms national honor and interests,” and “disrupts economic and social order” — categories interpreted broadly by CAC censors. Second, algorithmic transparency: generative AI providers must register their training data sources, model architecture, and safety testing methodology with the CAC, and submit to quarterly algorithmic audits by CAC-approved third-party testing institutions. Third, data localization: all training data collected in China must be stored and processed on servers physically located within China, and no training data containing Chinese user information may be used for model improvement without explicit individual consent under PIPL Article 24. Foreign companies that launched generative AI products in China without CAC approval in 2024–2025 faced penalties including fines of RMB 100,000 to RMB 5 million, service shutdown orders, and, in one case, removal of the responsible legal representative from China.
Step by Step
- Determine whether your service falls under the scope of the Measures. The Interim Measures apply to services that generate text, images, audio, or video content using generative AI technologies and make that content available to the Chinese public. Internal enterprise use — an AI writing assistant used by your own employees to draft internal memos, for example — is exempt from public-facing registration requirements. However, if your generative AI service is accessible from China via the internet (even through a WeChat mini-program or API integration), it falls under the Measures. A 2025 CAC clarification further states that AI services using Chinese-language training data — even if hosted overseas and accessible via VPN — are subject to the Measures if they are “primarily intended for Chinese users,” defined as services where more than 30% of users access from China-based IP addresses.
- Complete the Algorithm Filing (算法备案, suànfǎ bèi’àn) process. The first mandatory step is registering your generative AI algorithm with the CAC’s Algorithm Registry, which has been required since March 2024. The filing must include: the algorithm’s name and version, basic principles (基本原理, jīběn yuánlǐ) described in non-proprietary language, training data sources categorized by type (public datasets, licensed data, proprietary data, user-generated data), the algorithmic safety assessment report (算法安全自评估报告, suànfǎ ānquán zìpínggù bàogào) conducted by a CAC-approved testing institution, the content safety filtering mechanism description, and a user rights protection plan explaining how users can appeal AI-generated content that they believe violates their rights. The filing takes 30 to 60 working days for initial review, and the CAC may request supplementary materials. In 2025, approximately 18% of filings from foreign companies were returned for supplementation on first review — typically for inadequate disclosure of training data provenance.
- Implement the mandatory content safety review mechanism. Every generative AI service in China must implement a real-time content safety filtering system that screens both input prompts and output responses against the 17 prohibited content categories defined in Appendix A of the Interim Measures. The filtering system must be tested and certified by one of eight CAC-approved content safety testing institutions — including the China Academy of Information and Communications Technology (CAICT / 中国信息通信研究院, Zhōngguó Xìnxī Tōngxìn Yánjiūyuàn) and the National Information Security Evaluation Center (CNITSEC / 中国信息安全测评中心, Zhōngguó Xìnxī Ānquán Cèpíng Zhōngxīn). The certification cost ranges from RMB 150,000 to RMB 500,000 depending on the number of content modalities (text-only is cheapest; text+image+video is most expensive) and must be renewed annually. Foreign companies should budget an additional RMB 80,000–150,000 per year for ongoing content safety auditing and compliance reporting.
- Conduct the safety self-assessment (安全自评估, ānquán zìpínggù). Before launch and every quarter thereafter, the generative AI service provider must conduct a safety self-assessment covering five domains: (a) training data compliance — verifying that training data does not contain prohibited content and that data sourced from Chinese users has proper consent records; (b) model safety — testing the model against known jailbreak patterns and content safety edge cases using a CAC-mandated test suite of 2,400 test prompts; (c) labeling accuracy — if using human or AI-assisted content labeling, verifying that labeling accuracy exceeds the CAC’s 95% threshold; (d) user protection — confirming that users can delete their conversation history and opt out of data collection for model improvement; and (e) transparency compliance — verifying that users are clearly informed when they are interacting with AI-generated content, through mandatory watermarks on AI-generated images and mandatory “AI-generated” labels on AI-produced text exceeding 200 characters. The assessment report must be kept on file for three years and submitted to the CAC within 5 working days of any content safety incident.
- Designate a legal representative and a content safety officer. Foreign companies providing generative AI services in China must designate a legal representative (法定代表人, fǎdìng dàibiǎo rén) who is a resident of mainland China and holds personal legal liability for the service’s content safety compliance. Additionally, a content safety officer (内容安全负责人, nèiróng ānquán fùzérén) must be appointed — this person must be a full-time employee based in China with at least five years of experience in content moderation or internet governance and must pass a CAC-administered certification exam. The content safety officer’s name and contact information must be filed with the local CAC office. In 2025, the CAC rejected 23 content safety officer certifications because the appointee’s experience was deemed insufficient, and 7 because the officer was a part-time or overseas-based employee.
- Prepare for ongoing compliance audits and inspections. The CAC conducts unannounced on-site inspections of generative AI service providers at least once per year. Inspections typically last 2–3 days and cover: data center physical security, access control logs and data governance procedures, content safety filtering logs covering the most recent 90 days of operation, model update history and version control records, user complaint logs and resolution records, plus employee training records showing that all staff handling AI-generated content have completed CAC-approved compliance training. Foreign companies should budget RMB 200,000–500,000 per year for compliance operations including external auditors, legal counsel, and the content safety officer’s salary premium (typically 30–50% above market for equivalent non-compliance roles).
Compliance Cost Breakdown
| Compliance Element | One-Time Cost | Annual Cost | Timeline |
|---|---|---|---|
| Algorithm filing | RMB 50,000–150,000 | RMB 20,000–50,000 (updates) | 30–60 working days |
| Content safety certification | RMB 150,000–500,000 | RMB 80,000–150,000 (renewal) | 45–90 working days |
| Safety self-assessment | RMB 100,000–200,000 | RMB 100,000–200,000 (quarterly) | Ongoing |
| Content safety officer salary premium | — | RMB 100,000–200,000 | Ongoing |
| Legal counsel (China AI regulatory specialist) | RMB 80,000–150,000 | RMB 50,000–100,000 (retainer) | Ongoing |
| Total estimated | RMB 380,000–1,000,000 | RMB 350,000–700,000 | 3–6 months to launch |
Three Pitfalls
Pitfall 1: Treating the algorithm filing as a one-time formality. Many foreign companies complete the algorithm filing at launch and assume compliance is satisfied, but the CAC requires re-filing whenever the model is updated in a way that changes its “core functionality” — defined as any update that modifies the model’s training data source, inference architecture, content safety mechanisms, or training methodology. The CAC’s 2025 amendment explicitly states that fine-tuning an LLM on a new domain-specific Chinese dataset constitutes a functional change requiring re-filing. In 2025, 14 foreign companies received warning notices for failing to re-file after domain-specific fine-tuning, and 3 were ordered to suspend service until re-filing was completed. The fix: build your compliance calendar to align model release cycles with CAC re-filing timelines — plan for 30–60 working days between a fine-tuning round and public deployment.
Pitfall 2: Underestimating the content safety test suite. The CAC’s mandatory test suite of 2,400 prompts — covering jailbreak attempts, politically sensitive topics, culturally taboo subjects, and adversarial inputs across 32 categories — is a minimum not a maximum. Of the 2,400 prompts, approximately 300 are updated quarterly based on emerging content safety concerns and new attack patterns reported to the CAC by other providers. Foreign companies whose models fail more than 2% of test prompts are required to submit a remediation plan within 30 days and undergo re-testing within 60 days. In 2025, 6 foreign-operated generative AI services failed the quarterly re-test, and 2 were de-registered. The fix: invest in a dedicated red-teaming team (4–6 people, budget RMB 1.2–2.0 million per year) that runs continuous testing against the CAC test suite and in-house adversarial scenarios.
Pitfall 3: Neglecting user data rights compliance under PIPL for AI training. Foreign companies often treat user conversational data from their generative AI service as anonymized training data, but PIPL Article 24 requires explicit opt-in consent for processing personal information for model training purposes — anonymization does not exempt the requirement when the data was collected from users within China. A 2025 enforcement action against a foreign AI writing assistant found that the company had used 12 million user conversations to fine-tune its model without obtaining proper consent, resulting in a fine of RMB 4.5 million and a 90-day service suspension. The fix: implement a consent management platform that presents a separate, clearly labeled opt-in screen for “Use my conversations to improve the AI model” at account creation, and maintain a technical system that separates consented from unconsented data at the storage and training pipeline levels.
Cross-Border AI Service Considerations
Foreign companies that operate generative AI services outside China but whose services are accessible from within China face a separate set of compliance questions. The CAC’s territorial reach under Article 2 of the Interim Measures extends to any generative AI service that “produces effects within the territory of China,” which the 2025 amendments clarified to include AI services hosted overseas but marketed to Chinese users through WeChat advertising, Baidu search promotion, or Chinese-language app store listings. A foreign AI chatbot service that charges Chinese users USD 20/month through a Hong Kong payment gateway still falls under CAC jurisdiction if it serves Chinese-language responses.
The practical implication is that maintaining a separate Chinese instance — a version of your generative AI service hosted on Chinese servers, with Chinese-language content safety filters, filed algorithms, and a China-resident legal representative — is the only reliable path to compliance. Virtual private networks (VPNs) and geo-blocking of Chinese IP addresses do not exempt a foreign company from CAC requirements if the service is demonstrably accessible from or marketed to China. Three foreign generative AI companies received CAC warning letters in 2025 for geo-blocking Chinese IPs without also removing Chinese-language marketing and WeChat-based customer support channels.
Decision Checklist
- I have identified whether my generative AI service falls under the scope of the CAC Interim Measures
- My algorithm filing is in progress or complete with the CAC Algorithm Registry
- I have a CAC-approved content safety testing institution engaged for certification
- My safety self-assessment framework covers all five required domains
- I have designated a China-resident legal representative and a qualified content safety officer
- My consent management platform separates training-consented user data from non-consented data
Where to Go From Here
Based on what you just read:
- Ready to act? Read [guide: SLUG-TO-BE-FILLED]
- Still comparing? See [comparison: SLUG-TO-BE-FILLED]
- Need numbers? Try [tool: SLUG-TO-BE-FILLED]
— China Gateway 360 —
Remote China market entry support, built around execution.
Official Sources
- State Administration for Market Regulation: 2026 registration forms and submission-material standards
- Ministry of Commerce and SAMR: Measures for Foreign Investment Information Reporting
- State Administration for Market Regulation: Company Law of the People’s Republic of China
- National Development and Reform Commission: 2024 foreign-investment negative list
