AI in China Update: Beijing Mandates AI Safety Testing for All Commercial Models — Key Takeaways
Definition: On March 1, 2025, the Cyberspace Administration of China (CAC) issued a sweeping mandate requiring all commercial AI models — including large language models, computer vision systems, and generative AI platforms — to undergo mandatory safety testing and obtain a Model Safety Certificate (模型安全证书, móxíng ānquán zhèngshū) before public deployment. This policy affects an estimated 340+ AI models currently in development or already operating across China, covering everything from chatbots to industrial automation.
Why This Matters: For foreign companies operating or planning to launch AI products in China — whether through a WFOE (外商独资企业, waishang duzi qiye) or a joint venture — this regulation introduces a mandatory pre-market gate that directly impacts product timelines, R&D costs, and compliance strategies. The new rules signal Beijing’s intent to centralize AI governance while maintaining its competitive edge in the global AI race.
1. Policy Scope and Enforcement Timeline
The CAC’s new rule, titled “Interim Measures for Safety Assessment of Commercial AI Models”, applies to all providers offering AI services to the Chinese public — including foreign-invested entities. The testing regime covers four critical areas: content safety (political and social stability), data privacy compliance, model robustness against adversarial attacks, and algorithmic transparency.
Enforcement begins in two phases: Phase 1 (immediate) applies to all new models submitted for approval after March 1, 2025. Phase 2 (deadline: September 1, 2025) requires existing deployed models to be retroactively certified. Non-compliance carries penalties including fines of up to ¥5 million (approx. US$690,000) and service suspension.
| Metric | Value | Context / Comparison |
|---|---|---|
| Models affected (estimated) | 340+ | Up from ~120 in 2023; includes 80+ foreign-backed models |
| Testing fee per model (range) | ¥80,000 – ¥250,000 | Higher than EU AI Act conformity assessment costs for SMEs |
| Certification validity | 2 years | Renewable; requires updated safety report every 12 months |
| Non-compliance fine (max) | ¥5,000,000 | ~3x the penalty under China’s 2023 deep synthesis regulation |
| Testing labs accredited | 7 (initial) | Expanding to 14 by Q4 2025; current bottleneck |
The table above illustrates a sharp escalation in regulatory rigor. For context, the EU AI Act (2024) imposes conformity assessments for high-risk systems but does not require pre-market certification for general-purpose AI. China’s approach is closer to a medical device-style pre-approval model, with ongoing surveillance.
2. Key Requirements for Commercial AI Models
The mandate introduces a structured testing framework. Below are the five core pillars that every commercial AI provider must address:
- Political & Content Safety Filter — Models must pass a stress test with more than 2,000 benchmark prompts covering topics related to national security, territorial integrity, social stability, and historical narratives. Failure rate threshold: <0.5% unsafe outputs.
- Data Privacy & Personal Information Protection — Compliance with the Personal Information Protection Law (PIPL) and the Data Security Law. Training data must be audited for inclusion of sensitive personal data without consent. A penalty of up to ¥50 million or 5% of annual revenue applies for severe violations.
- Model Robustness & Adversarial Testing — Models must demonstrate resistance to jailbreak attacks, prompt injection, and data poisoning. Minimum accuracy retention of 92% under adversarial perturbation is required.
- Algorithmic Transparency Documentation — Providers must submit a detailed Model Card (模型卡, móxíng kǎ) in Chinese, including training data sources, bias mitigation steps, and intended use limitations. This must be updated annually.
- Human Oversight Mechanism — Real-time monitoring dashboards with human-in-the-loop escalation for high-risk outputs. Logs must be retained for 3 years and made available to regulators within 48 hours of request.
These requirements go beyond the 2023 Interim Measures for Generative AI, which focused primarily on content legality. The new rules add technical robustness and systemic transparency, raising the bar for both domestic and foreign players.
3. Implications for Foreign Companies in China
Foreign AI providers — including those operating through a WFOE (外商独资企业, waishang duzi qiye) or a cooperative venture — face a dual challenge: adapting to the new testing regime while managing cross-border data restrictions. Key impacts include:
- Longer time-to-market: Estimated 4–8 months for certification, compared to ~2 months previously for generative AI filing. This delays revenue generation and competitive positioning.
- Higher R&D costs: Testing fees + compliance engineering = estimated ¥1.5–4 million per model (US$200k–$550k), a 3–5x increase over 2023 compliance costs.
- Data localization requirements: Training data and inference logs must be stored onshore. Cross-border transfer requires security assessments, adding complexity for global model architectures.
- IP exposure risk: The Model Card submission requires detailed disclosure of training data sources and model architecture, which some foreign companies consider proprietary.
For context, the European Union’s AI Act does not require pre-market certification for general-purpose AI models (only for those deemed high-risk). China’s approach is more prescriptive and interventionist, similar to its approach to cloud services and autonomous driving.
4. Comparison with Global AI Governance Approaches
To help executives benchmark, the table below summarizes key differences between China’s new mandate and other major AI governance frameworks:
| Jurisdiction | Pre-market Testing Required? | Maximum Penalty | Model Transparency Obligations |
|---|---|---|---|
| China (new rules) | Yes – all commercial models | ¥5M + service suspension | Detailed Model Card + annual update |
| EU (AI Act, 2024) | Only for high-risk systems | €35M or 7% of global revenue | Technical documentation for high-risk only |
| USA (Executive Order, 2023) | No – voluntary standards | No direct penalty (FTC actions apply) | Reporting for foundation models (draft stage) |
The data underscores that China’s approach is currently the most extensive in terms of scope (all commercial models) and immediacy. The EU relies on risk-classification, while the US leans on voluntary guidance. For a company like OpenAI or Meta, which does not formally operate in China, the rules primarily affect their Chinese partners and enterprise customers. For companies with a WFOE (外商独资企业, waishang duzi qiye) selling AI services locally, the mandate is non-negotiable.
5. Key Pitfalls and How to Avoid Them
5.1 Underestimating the Certification Timeline
The CAC has accredited only 7 testing labs as of March 2025, with plans to expand to 14 by late 2025. This creates a bottleneck. Foreign companies often assume they can use overseas testing results, but the CAC requires onshore testing using Chinese-language benchmarks. Recommendation: Engage a local compliance partner (e.g., a Chinese law firm or testing agency) at least 3 months before planned launch to secure a testing slot.
5.2 Overlooking Model Card Requirements
The Model Card must include training data provenance — including whether any data from foreign jurisdictions was used. Several early applicants in 2024 (under the interim generative AI rules) were rejected because they could not adequately document training data sourcing. Recommendation: Prepare a comprehensive data inventory now, even if your model is still in development. Use the CAC’s published template (available in Chinese only) as a reference.
5.3 Assuming “Grandfathering” for Existing Models
Phase 2 requires all models deployed before March 1, 2025 to obtain certification by September 1, 2025. There is no automatic exemption. A major Chinese LLM provider, Baidu’s Ernie Bot, is currently undergoing retroactive testing at a reported cost of ¥3.8 million. Recommendation: If you have a model already live in China, initiate the testing process immediately. Budget for both direct testing fees and engineering remediation (estimated 1.5x the testing fee).
6. Strategic Considerations for Market Entry
The mandate reinforces a trend that foreign executives must internalize: AI in China is now a regulated utility, not an unconstrained technology playground. However, the rules also create a level playing field — all providers, domestic and foreign, must meet the same standards. Companies that invest early in compliance infrastructure (onshore data storage, Chinese-language model cards, local testing partnerships) can turn this into a competitive moat.
For companies considering a WFOE (外商独资企业, waishang duzi qiye) structure for AI deployment, the new rules add a layer of fixed cost but do not fundamentally alter the viability of the WFOE model. In fact, having a locally incorporated entity simplifies the certification application, as the CAC requires the applicant to be a Chinese legal person.
Remote China market entry support, built around execution.
Official Sources
- State Administration for Market Regulation: 2026 registration forms and submission-material standards
- Ministry of Commerce and SAMR: Measures for Foreign Investment Information Reporting
- State Administration for Market Regulation: Company Law of the People’s Republic of China
- National Development and Reform Commission: 2024 foreign-investment negative list
