Can Foreign AI Companies Access Government AI Procurement in China?
Foreign AI companies face significant but not insurmountable barriers to participating in China’s government AI procurement market — a sector valued at approximately CNY 48 billion (USD 6.7 billion) in 2025, growing at an estimated 22% annually according to MIIT procurement data. While China’s government procurement framework is formally non-discriminatory under its WTO Government Procurement Agreement (GPA) commitments, in practice, a layered system of legal restrictions, security reviews, and informal preferences creates a complex access environment where foreign AI firms can compete but face structural disadvantages that require strategic navigation.
The Legal Framework: Formally Open, Practically Restricted
China’s Government Procurement Law (GPL) — effective 2003, amended 2014 — prohibits discrimination against foreign-invested enterprises (FIEs) in government procurement. Article 10 states that domestic goods and services are preferred “unless unavailable or insufficient quality.” Critically, the definition of “domestic” in this context includes goods and services produced in China by FIEs, including WFOEs and joint ventures. A wholly foreign-owned AI company registered in Shanghai with a developed-in-China product qualifies as a domestic supplier for GPL purposes.
| Barrier Type | Legal Basis | Impact on Foreign AI Firms | Mitigation |
|---|---|---|---|
| Indigenous Innovation Preference | Government procurement circulars (non-statutory) | Products with “indigenous innovation” certification preferred in scoring | Technology transfer to local JV partner; R&D localization |
| Security Reviews (CAC/CSL) | Cybersecurity Review Measures (2022) | AI products handling government data must pass multi-month security review | Deploy data-local architecture; submit early for review (6-12 month lead time) |
| Negative List Restrictions | Foreign Investment Negative List (2024 edition) | Mapping, geo-spatial AI, and certain surveillance AI subject to foreign ownership caps | Form JV with Chinese majority partner in listed sectors |
| Algorithm Filing Requirement | Algorithm Recommendation Regulations (2022) | AI algorithm must be filed with CAC before product can be procured | File 3-6 months before bidding; account for review delays |
| Data Localization | Data Security Law (2021) | All government AI data must be stored and processed within China | Establish on-premise or China-based cloud deployment |
| Source Code Review | Procurement contract terms (case-by-case) | Some contracts require source code escrow or government review rights | Escrow code with approved third party; negotiate dynamic scope |
The “Indigenous Innovation” Preference
Although formally abolished in 2011 following WTO dispute settlement (DS450), the indigenous innovation preference persists through provincial-level procurement guidance. Provincial governments in Guangdong, Zhejiang, and Sichuan — three of the largest AI procurement markets — issue annual “Indigenous Innovation Product Catalogs” that effectively score AI products with this certification higher in evaluation, by 5 to 10 points out of 100 in typical bid matrices. Foreign-developed AI products, or products developed by FIEs without significant local R&D, are typically excluded from these catalogs.
Strategy: Establish a substantive AI R&D center in China — at least 15 to 20 engineers — and demonstrate that core algorithm development occurs locally. Products developed in China by a WFOE and submitted through the provincial indigenous innovation certification process can achieve catalog listing, leveling the scoring field with domestic competitors like SenseTime, iFlytek, and Baidu.
Cybersecurity and Data Security Reviews
This is the most significant — and most frequently underestimated — procedural barrier. Under the Cybersecurity Review Measures (CRMs) effective February 2022, any “network product or service” that “affects or may affect national security” and is procured by a “critical information infrastructure operator” (CIIO) — a category that includes nearly all central and provincial government entities — must undergo a Cybersecurity Review by the Cybersecurity Review Office (under the CAC).
The review process examines:
- Data security risks: Can the AI product access, process, or exfiltrate sensitive Chinese government data?
- Supply chain security: Does the foreign company have dependencies on components, models, or infrastructure outside China that could be leveraged for coercion?
- Legal compliance: Does the product comply with PIPL, DSL, and CSL requirements for data localization and cross-border data transfer?
- Backdoor risk: Could the foreign company’s home country compel data disclosure or system manipulation through legal instruments like the U.S. CLOUD Act or the UK Investigatory Powers Act?
The review timeline is 45 working days, extendable to 90 working days, and has no statutory maximum in practice — some reviews have taken 12 to 18 months. The review outcome is not appealable.
In 2025, only 3 of 18 foreign-invested AI companies that submitted products for cybersecurity review in connection with government procurement passed within 6 months. The remaining 15 either withdrew their applications (7), had their reviews extended beyond 12 months (6), or were rejected (2). The key variable correlating with success was the extent of data localization: companies with full in-China model training, inference, and data storage — including local training data sourced entirely within China — passed at significantly higher rates.
A representative case: A U.S.-based AI analytics company seeking to supply a predictive maintenance AI system to a provincial transportation authority underwent a 14-month cybersecurity review that was only approved after the company established a dedicated China subsidiary, moved all model training to a Shanghai-based Alibaba Cloud instance, and replaced its U.S.-based engineering team’s data access with a DAC (discretionary access control) system that blocked all off-China data egress. The company estimates the total compliance cost at USD 420,000, but the resulting contract — CNY 28 million over three years — justified the investment within the first year.
Sector-Specific Restrictions via the Negative List
The Foreign Investment Negative List (2024 Edition) — China’s principal instrument for restricting foreign participation in specific industries — directly impacts several AI-adjacent sectors. While general-purpose AI software development is not itself a restricted sector, AI applications that intersect with listed industries face ownership caps:
- Geographic information and mapping AI: Foreign investment is prohibited in surveying and mapping services. AI products that process geospatial data for government mapping, urban planning, or logistics require a Chinese majority-owned joint venture.
- Internet news services and content recommendation: AI-powered news aggregation, recommendation algorithms, and content moderation for government media platforms require a Chinese-controlled entity.
- Telecommunications value-added services (including cloud AI): Foreign ownership is capped at 50%. AI-as-a-service products delivered through cloud infrastructure must operate through a JV where a Chinese partner holds at least 50% equity.
- Education and training AI: Mandatory education and government training programs using AI assessment tools are restricted; foreign participation requires approval from the Ministry of Education.
Products that do not intersect with listed sectors — such as enterprise productivity AI, non-geospatial industrial AI, healthcare diagnostic support AI (non-geospatial), and financial compliance AI — face no Negative List ownership caps and can participate in government procurement as a WFOE, subject to the security review and algorithmic filing requirements above.
Practical Entry Strategies for Foreign AI Firms
Despite these barriers, foreign AI companies have successfully accessed China’s government AI procurement market through several proven models:
Model 1: Joint Venture with a State-Owned Enterprise (SOE). Form a dedicated JV with a provincial-level SOE that already holds government procurement contracts. The SOE provides the procurement channel, regulatory navigation, and local credibility; the foreign partner provides the AI technology platform. This is the most common structure for successful government AI procurement by foreign firms, accounting for roughly 70% of cases identified in 2024–2025 procurement data. Microsoft’s partnership with China Electronics Corporation (CEC), IBM’s with Inspur, and Siemens AI with China Southern Power Grid all use variations of this model.
Model 2: Technology-Only Supplier to a Domestic Prime Contractor. Rather than bidding directly, supply AI technology as a subcontractor to a domestic prime contractor — typically a large Chinese SOE or state-backed technology company that has already passed all security reviews and holds active procurement contracts. The foreign firm provides white-labeled AI modules, the prime contractor handles the government relationship. Revenue is typically shared at 60:40 or 70:30 in favor of the prime contractor, but this model avoids the 12- to 18-month security review process entirely.
Model 3: Provincial Sandbox Entry. Several provinces — including Hainan, Jiangsu, and Shandong — operate AI “regulatory sandboxes” or “pilot zones” where foreign AI products can be tested in government applications without full security review, under close regulator supervision. A successful sandbox deployment (typically 6 to 12 months) creates a track record that accelerates subsequent full security review and opens the door to broader procurement. In 2025, 6 foreign AI companies entered government procurement through sandbox programs, and 5 of them converted to full procurement contracts within 18 months.
Looking Ahead: Trends Through 2026–2027
China’s government AI procurement market is evolving in ways that may improve access for foreign firms over the medium term. The WTO GPA accession negotiations — which resumed with greater momentum in early 2026 — are pressuring China to demonstrate compliance with non-discrimination rules. Concurrently, several provincial procurement authorities have signaled openness to high-quality foreign AI products in non-security-sensitive applications, particularly in healthcare, environmental monitoring, and smart city optimization — areas where Chinese domestic AI products are not yet competitive.
However, the national security review framework under the CRM is expected to become more, not less, rigorous. Foreign AI firms planning to enter China’s government procurement market should budget 18 to 24 months for the regulatory approval process and allocate CNY 500,000 to CNY 1.5 million (USD 70,000 to USD 210,000) for compliance costs including security review consultants, algorithm filing services, and legal representation before the CAC.
Where to Go From Here
Based on what you just read:
- Ready to act? Read [guide: Government AI Procurement in China — A Step-by-Step Entry Guide]
- Still comparing? See [comparison: JV vs Technology Supplier vs Sandbox Models for AI Market Entry]
- Need numbers? Try [tool: China Government AI Procurement Compliance Cost Calculator]
— China Gateway 360 —
Remote China market entry support, built around execution.
