What is the difference between China’s AI Law and EU AI Act?

Date:

Share post:

What is the difference between China’s AI Law and EU AI Act?

Definition: China’s evolving AI regulatory framework—centered on the draft Artificial Intelligence Law (人工智能法草案, rengong zhineng fa cao’an) and the binding Generative AI Measures (生成式人工智能服务管理暂行办法, shengchengshi rengong zhineng fuwu guanli zanxing banfa)—differs fundamentally from the EU’s AI Act in scope, risk classification, and enforcement philosophy. While the EU divides AI applications into 4 risk categories, China’s approach emphasizes state security and content control across 73 articles and 9 chapters. Over 40 countries are drafting AI laws, but these two regimes will govern the largest markets and affect 85% of global AI investment flows.

Why This Matters

For foreign executives making China market decisions, the choice of compliance strategy directly impacts market access, liability, and operational cost. Non-compliance with the EU AI Act can result in fines of up to €35 million or 7% of global annual turnover. In China, violations of the Generative AI Measures can lead to service suspension, removal of illegal content, and administrative penalties affecting all cross-border AI deployments. Understanding the differences is not academic—it determines whether your AI product can be sold in Shanghai or Shenzhen, and how much localization investment is required.

Frequently Asked Questions

1. What is the legal status of China’s AI Law vs the EU AI Act?

The EU AI Act was adopted by the European Parliament in March 2024 and is expected to enter into force in phases from 2025 to 2027. It is a single, binding regulation directly applicable in all EU member states.

China does not yet have a comprehensive AI law. The draft Artificial Intelligence Law was released for public comment in August 2023, but a final version is expected no earlier than 2025. In the meantime, many provisions are enforced through the Generative AI Measures (effective August 15, 2023) and sector-specific rules (e.g., for deep synthesis, recommendation algorithms, and autonomous driving). Foreign companies must comply with these existing regulations now, not wait for the final law.

2. What are the key differences in scope and application?

The EU AI Act applies to any provider or deployer of AI systems that place products or services on the EU market, regardless of where the provider is established. China’s framework applies to all AI services that “serve the public” within its territory—including foreign providers whose services are accessible in China. However, China’s regulations exclude purely internal use (e.g., in-house manufacturing AI) unless it involves personal data or content generation that reaches the public.

A major difference: China’s Generative AI Measures only cover generative AI that produces text, images, audio, or video. The EU AI Act covers all AI systems as defined in the OECD classification, including traditional predictive models and logic-based systems.

Dimension EU AI Act China’s AI Framework
Scope All AI systems (broad OECD definition) Primarily generative AI + algorithm recommendation + deep synthesis
Risk classification 4 tiers: Unacceptable, High, Limited, Minimal No formal risk tiers; obligations linked to “public interest” and “national security”
Target entity Provider & deployer in EU Provider & “service user” that serves Chinese public
Enforcement body National competent authorities + European AI Board Cyberspace Administration of China (CAC) + sector regulators

3. How do they define “AI”?

The EU AI Act uses the OECD definition: “a machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.” This covers everything from simple linear regression to large language models.

China’s draft AI Law defines AI as “systems that possess human-like intelligence and can perform tasks such as perception, reasoning, learning, and decision-making.” However, the Generative AI Measures only define “generative AI” as “technology that generates text, images, audio, video, or other content based on algorithms, models, or rules.” This narrower definition means many traditional AI systems (e.g., credit scoring models) currently fall outside the special generative AI rules—but they are still subject to the overall Cybersecurity Law and Data Security Law.

4. What are the risk classification approaches?

The EU AI Act establishes a clear four-tier risk system:

  • Unacceptable risk (banned): social scoring, real-time biometric surveillance, exploitation of vulnerabilities
  • High risk (stringent conformity assessment): AI in critical infrastructure, education, employment, law enforcement, migration
  • Limited risk (transparency obligations): chatbots, emotion recognition, biometric categorization
  • Minimal risk (no obligations): spam filters, AI-enabled video games

China’s framework does not have a comparable risk pyramid. Instead, obligations are tied to the “content” produced and the “service provider’s responsibility”. For example, generative AI providers must ensure outputs align with “socialist core values,” avoid discrimination, prevent false information, and label AI-generated content. There is no list of prohibited AI uses per se, but any use that threatens national security or social stability can be shut down immediately under the Cybersecurity Law. For foreign executives, this means compliance is more about content moderation and data localization than about pre-market risk assessment.

5. What are the compliance requirements for foreign companies?

Under the EU AI Act, foreign providers of high-risk AI systems must appoint an authorized representative in the EU, maintain technical documentation, implement risk management, and undergo conformity assessment by a notified body. For general-purpose AI models (e.g., GPT-4), providers must implement transparency measures and copyright policies.

In China, foreign companies that offer AI services to the Chinese public—even through an API or a cross-border service—must:

  • Conduct a security assessment with the CAC if the service is considered “having public opinion attributes” (which most large language models do)
  • Store all training data and user logs within China using a WFOE (外商独资企业, waishang duzi qiye) structure
  • Label AI-generated content
  • Ensure training data does not contain sensitive personal information or illegal content

Failure to comply can result in service suspension, removal of models, and fines calculated based on revenue from the service.

6. What are the penalties for non-compliance?

The EU AI Act has a tiered penalty system: up to €35 million or 7% of global annual turnover (whichever is higher) for violations related to prohibited AI practices; up to €15 million or 3% for other obligations; up to €7.5 million or 1.5% for supplying incorrect information. Fines are capped per incident.

China’s Generative AI Measures do not specify fixed amounts. Penalties can include warnings, confiscation of illegal gains, suspension of services, or revocation of licenses. Under the Cybersecurity Law, violations can also lead to fines of up to 500,000 RMB for entities and 100,000 RMB for responsible individuals—but in practice, the biggest risk is not the fine but the operational halt. Many foreign AI products have been blocked entirely in China because they failed to complete the required security assessments. The draft AI Law proposes fines of up to 10 million RMB (approx. USD 1.4 million) plus disqualification from public procurement for serious breaches.

7. How do they address generative AI specifically?

The EU AI Act includes a new chapter on “General Purpose AI” (GPAI) added during final negotiations. GPAI models must meet transparency requirements, and if they present a systemic risk (based on computing power >1025 FLOPs), they are subject to code of practice, incident reporting, and model evaluations.

China has already implemented the Generative AI Measures which are more detailed and prescriptive. Key requirements:

  • All generated content must be labeled (e.g., with digital watermarking).
  • Providers must conduct algorithm filing with the Alibaba Algorithm Filing System (for recommendation algorithms) or CAC for generative models.
  • Training data must be “lawfully obtained” and must not contain content that violates Chinese laws or socialist core values.
  • Personal data used for training requires explicit consent (if identifiable).
  • Models must not “generate” content that subverts state power, divides the nation, incites terrorism, or promotes obscenity.

For foreign AI startups entering China, these rules mean you cannot simply launch an LLM trained on Western datasets—you must retrain or fine-tune on China-compliant data and likely host the model on a local server.

8. What are the timelines for implementation?

EU AI Act phasing: 6 months after entry into force (expected late 2024) – bans on prohibited AI practices apply; 12 months – obligations for GPAI models; 24 months – majority of high-risk obligations apply; 36 months – high-risk AI systems used as safety components of regulated products apply.

China’s timeline is less structured. The Generative AI Measures are already in effect. The draft AI Law is under revision; a second reading is expected in 2025. However, industry regulators like the People’s Bank of China and the Ministry of Public Security are already issuing guidelines that de facto enforce many draft law provisions. Foreign companies should assume that the current regulatory stance is the baseline for the next 12–18 months.

Common Pitfalls and Misconceptions

Pitfall 1: Assuming China’s AI Law mirrors the EU’s risk-based approach.
Many executives expect a clear tier system like the EU. Instead, China’s obligations depend on the “nature of the content” and “public impact.” There is no “low risk” exemption—any AI service accessible to the Chinese public could be subject to security assessments.

Pitfall 2: Believing the draft AI Law is not enforceable yet.
While not formally passed, the CAC enforces the Generative AI Measures and the Cybersecurity Law aggressively. Foreign AI apps have been removed from Chinese app stores for non-compliance even without a comprehensive AI law.

Pitfall 3: Overlooking data localization requirements.
Even if your AI model runs overseas, if the output is consumed in China, you may still need to store training data and user logs within China. Many companies mistakenly think “cloud-based API” avoids this.

Pitfall 4: Confusing “AI Law” with “algorithm filing.”
China’s algorithm filing is a separate requirement under the Algorithm Recommendation Provisions (2022). Even if your AI is not generative, if it uses a recommendation or deep synthesis algorithm, registration is mandatory.

Where to Go From Here

Based on your company’s market presence, choose one of three paths:

  1. Dual-market player (China + EU): Conduct a dual-compliance mapping of your AI portfolio. Prioritize the highest-risk systems in each regime. Invest in a local legal team in both regions. Expect to maintain separate technical documentation and possibly separate models for China (compliant content) and EU (compliant risk management).
  2. China-only focus: Begin the CAC security assessment process immediately. Review all training data for content compliance. Set up a WFOE with a dedicated server for data storage. Budget for ongoing algorithm filing and content moderation tools. Engage with a Chinese cloud provider (e.g., Alibaba Cloud, Tencent Cloud) to host AI services.
  3. EU-only focus: Review the EU AI Act’s high-risk categories to see if your product qualifies. Appoint an authorized representative. Start preparing conformity assessment documentation. For GPAI models, calculate your FLOPs threshold and engage with the European AI Office early.
– China Gateway 360 – Remote China market entry support, built around execution.

Official Sources

Related articles

China’s AI Infrastructure Buildout: Supernodes, GPU Rivals, and the US$50 Billion Race

Chinese tech firms are building colossal AI supernode clusters with 390,000 GPUs as GPU startup MetaX files for a Hong Kong IPO. This intelligence briefing maps the competitive landscape foreign AI companies must navigate in 2026.

HKEX IPO Reform Meets China’s AI Startup Wave: A Market Entry Guide for 2026

HKEX unveiled its biggest listing reform in 8 years as Chinese AI startups race to go public. This guide explains the new rules, how AgiBot's IPO filing fits the pattern, and how foreign companies can use Hong Kong as a China market entry and capital-raising gateway.

Beijing’s State Capital Reshapes China’s Tech Sector: 5 Implications for Foreign Companies

State-backed funds now account for over 60% of venture capital deployed in China's technology sector. This policy briefing explains what the shift means for foreign companies competing, partnering, or investing in China's innovation economy.

Trip.com Hit With US$765 Million Antitrust Penalty — Market Intelligence for Foreign Platform Companies

China's antitrust regulator fined Trip.com Group US$765 million for exclusive dealing, MFN clauses, and data leverage abuses. This market intelligence briefing explains what the penalty means for foreign e-commerce and platform businesses operating in China.