China AI Compliance & Filing · Clause-Level Self-Check
42 entries in total, covering 5 regulations. Agents can call the same data directly: https://savantcat.cn/mcp-compliance
AI-generated content labeling · 10 entries
- What counts as AI-generated or synthesized content?
Under Article 3 of the Measures, text, images, audio, video, virtual scenes and other information generated or synthesized with AI technology all count as AI-generated or synthesized content. There are only two kinds of labels: explicit labels and implicit la - How exactly do you add an explicit label to text and audio?
For text, add a text notice or a general symbol notice at an appropriate position at the beginning, the end or in the middle, and you may also add a prominent notice in the interactive interface or around the text; for audio, add it at an appropriate position at the beginning, the end or in the middle - How do you label images, video and virtual scenes explicitly?
For images, add a prominent notice label at an appropriate position; for video, add a prominent notice at the starting frame and at an appropriate position around the video playback, and you may strengthen it further at the end and at an appropriate position in the middle; for services presenting virtual scenes - What is an implicit label? What goes in file metadata?
An implicit label is added to the file data of generated or synthesized content by technical means and is not readily perceived by users. A service provider must, under Article 16 of the Provisions on the Administration of Deep Synthesis of Internet Information Services, - What must short-video platforms verify and prompt about AI content?
A platform providing internet information content dissemination services handles three situations: where the metadata clearly marks the content as generated or synthesized, it gives a prominent notice around the published content and clearly tells the public it is generated or synthesized content; where it has not verified - What labeling materials are needed when listing in an app store?
At listing or launch review, an application distribution platform shall require the application service provider to state whether it provides AI-generated or synthesized services; if it does, the distribution platform shall verify its materials relating to the labeling of generated or synthesized content - Do users have to declare the AI content they post themselves?
Yes. A user who publishes generated or synthesized content using an internet information content dissemination service shall proactively declare it and use the labeling function provided by the service provider. If you want to obtain generated or synthesized content without an explicit label, - Can AI content labels be removed? Is helping to remove them unlawful?
No. No organisation or individual may maliciously delete, tamper with, forge or conceal the labels for generated or synthesized content provided for in these Measures, nor provide tools or services for others to carry out such acts, nor harm the lawful rights and interests of others through improper labeling - What happens if AI content is not labelled?
Where these Measures are violated, the competent departments for cyberspace, telecommunications, public security and radio and television handle it according to their duties and under the relevant laws, administrative regulations and departmental rules. The Measures themselves do not set a separate - If a company uses AI for customer service and marketing copy, must it label?
Two situations: where the company itself provides AI-generated or synthesized services to the public (such as a publicly launched AI customer service or AI writing tool), it is a service provider regulated by the Measures and must implement explicit labeling under Articles 4, 5 and 8
Algorithmic recommendation and filing · 8 entries
- Our app has a recommendation feed — does this algorithmic recommendation regulation cover us?
It does. As long as you apply algorithmic recommendation technology to provide internet information services within the territory of the People's Republic of China, these Provisions apply, regardless of company size or whether you charge. Algorithmic recommendation technology is not only the "you may also like" style of information - Who must file an algorithm, when, and must it be published afterwards?
An algorithmic recommendation service provider with public opinion attributes or social mobilisation capacity shall complete filing formalities within ten working days from the date it starts providing the service; changes to filing information are handled within ten working days, and termination of service - If a user asks us to turn off algorithmic recommendation, must we? And how do we inform them?
Yes. Article 16 requires telling users in a prominent way about the provision of algorithmic recommendation services, and publishing the basic principles, purpose and intent, and main operating mechanisms. Article 17 requires providing an option that does not target personal characteristics, or - Giving different users different prices by algorithm — is that big-data price gouging?
When selling goods or providing services to consumers, a provider may not, based on characteristics such as the consumer's preferences or transaction habits, use algorithms to apply unreasonable differential treatment in transaction conditions such as the transaction price, or other unlawful conduct. In other - Recommendation algorithms keep users scrolling — what special requirements apply to minors?
Algorithm models must not be set up to induce users to become addicted or to overspend; a provider serving minors must perform its duty of online protection for minors, develop a mode suited to minors, and must not push information that may cause minors to imitate unsafe - Which systems must primary responsibility for algorithm safety actually cover? Who does the safety assessment?
You must implement primary responsibility for algorithm safety, and establish review of algorithm mechanisms, science and technology ethics review, user registration, information publication review, data security and personal information protection, anti-telecom and online fraud, safety assessment and monitoring, and safety - When the cyberspace administration inspects, what must we keep and how far must we cooperate?
The competent departments conduct safety assessments and supervision and inspection in accordance with law, and where problems are found they give rectification opinions and a deadline for rectification. Enterprises shall retain network logs in accordance with law, cooperate with inspection, and provide the necessary technical and data support and assistance. - What happens when algorithmic recommendation rules are breached, and how big is the fine?
For the violations listed in Article 31, where laws or administrative regulations provide for them, those provisions apply; where they do not, a warning, a public notice and an order to correct within a time limit are given; if the provider refuses to correct or the circumstances are serious, it is ordered to suspend information updates,
Deep synthesis · 8 entries
- What kind of algorithm counts as deep synthesis? Does our product?
Three things to look at: whether it uses generation-and-synthesis algorithms such as deep learning or virtual reality, whether the output is network information such as text, images, audio, video or virtual scenes, and whether it is used within China to provide internet information services - For a deep synthesis service, which obligations must the provider actually implement?
Overall it is a combination of systems, technical safeguards and bottom lines: implement primary responsibility for information security, and establish and improve user registration, review of algorithm mechanisms, science and technology ethics review, information publication review, data security, - Does AI-generated content have to be labelled? Can the label be removed?
Yes. Five categories of deep synthesis services that may cause public confusion or mistake must be prominently labelled at a reasonable position and in a reasonable area of the generated or edited content; services outside that scope must also provide a prominent labeling function and prompt users - Must a deep synthesis service verify real names? Can guests post content?
Yes. A provider shall verify the real identity information of users in accordance with law on the basis of mobile phone numbers, identity document numbers, unified social credit codes or the national public service for online identity authentication; for those who have not completed - Must a deep synthesis algorithm be assessed? How long must logs be kept?
Yes, it must be assessed. Providers and technical supporters shall periodically review, assess and verify the mechanisms of generation-and-synthesis algorithms; where they provide editing tools for biometric information such as faces and voices, or involve non-biometric - What must the user agreement say? What must users be prompted about?
A provider must formulate and publish management rules and platform conventions, improve the service agreement, and prominently prompt technical supporters and users to bear their information security obligations; where it provides editing functions for biometric information such as faces and voices - Deep synthesis rules and generative AI measures — how do the two sets apply together?
It is not either-or. The deep synthesis Provisions govern the application of deep synthesis technology to provide internet information services, and the technical definition covers text, images, audio, video and virtual scenes; the rules on generative artificial intelligence - Using AI face swap, AI dubbing or digital humans for marketing — what compliance steps are needed?
In a marketing setting there are five steps: obtain the edited individual's notice and separate consent for the material first; label prominently at a reasonable position and area on the page; provide users with a prominent labeling function and prompt them to perform their duty to inform
Filing in practice · 4 entries
- Do we count as having public opinion attributes or social mobilisation capacity?
The source documents do not give a determination list. What can be confirmed is that this judgment is one of the dimensions of tiered and classified algorithm management, and it directly triggers filing and safety assessment obligations. The approach can only be built from the dimensions the provisions list ( - Are algorithm filing and generative AI service filing the same thing?
Article 17 of the Interim Measures for the Administration of Generative AI Services points the filing formalities for generative AI services directly at the Provisions on the Administration of Algorithmic Recommendation of Internet Information Services: providing services with public opinion attributes or social mobilisation capacity - Before launching AI customer service or intelligent Q&A, is a safety assessment required first?
First judge whether the service has public opinion attributes or social mobilisation capacity. If it does, Article 27 of the algorithm recommendation Provisions requires a safety assessment under the relevant national rules; Article 17 of the Interim Measures for the Administration of Generative AI Services - What obligations besides filing must not be missed?
Filing is only one item. You also bear the responsibility of a network information content producer and must perform network information security obligations, establish and improve complaint and reporting mechanisms, publish the handling process and response time limits, and provide users under the algorithm recommendation Provisions
Interim Measures for Generative AI · 12 entries
- If we use a large model internally, does this measure cover us too?
The key is whether you provide services to the domestic public. Article 2 of the Measures limits its scope to using generative AI technology to provide text, images, audio, video and other content to the public within the territory of the People's Republic of China - Where must training corpus come from to be lawful?
Article 7 of the Measures requires providers to lawfully carry out pre-training, optimisation training and other training data processing activities, with three bottom lines: use data and foundation models of lawful provenance; do not infringe the lawful - How should a platform prevent AI from generating unlawful content?
Article 4 of the Measures prohibits generating content that endangers national security, incites separatism, promotes terrorism and extremism, promotes ethnic hatred or discrimination, is violent or pornographic, or is false and harmful information, as prohibited by laws and administrative regulations, - If AI-generated content causes trouble, is the platform or the user liable?
Both sides bear responsibility, with different obligations. Article 9 requires the provider to lawfully bear the responsibility of a network information content producer and network information security obligations, and the responsibility of a personal information processor where personal information is involved; Article 22 places users - What users discuss with AI — how long can it be kept, and can it be used for training?
Article 11 of the Measures provides that a provider shall lawfully perform protection obligations for users' input information and usage records: it may not collect unnecessary personal information, and may not unlawfully retain input information that can identify a user - If minors use an AI product, what extra work is needed?
Article 10 of the Measures requires the provider to make clear and public the audience, occasions and purposes of the service, guide users to understand generative AI technology scientifically and rationally and to use it lawfully, and take effective measures to prevent minors from using - After an AI service launches, how do you build the complaint and reporting mechanism?
Article 15 of the Measures requires the provider to establish and improve complaint and reporting mechanisms, set up convenient complaint and reporting entrances, publish the handling process and response time limits, and promptly accept and handle public complaints and reports and feed back the results. - If AI generates unlawful content, how should it be handled and reported?
Article 14 of the Measures has two paragraphs: where unlawful content is found, it shall promptly take disposal measures such as stopping generation, stopping transmission and eliminating it, take rectification measures such as optimised model training, and report to the competent departments; - Before launching a large model, are a safety assessment and algorithm filing required?
Look at whether there are public opinion attributes or social mobilisation capacity. Article 17 of the Measures provides that where generative AI services with public opinion attributes or social mobilisation capacity are provided, a safety assessment shall be carried out under the relevant national rules - What must an AI service user agreement state clearly?
Article 9 paragraph 2 of the Measures requires the provider to sign a service agreement with users who register for its service, making the rights and obligations of both sides clear; Article 10 requires making clear and public the audience, occasions and purposes of the service; Article 4 item 5 - What happens if you are non-compliant? Is rectification enough?
Article 21 of the Measures provides that where these Measures are violated, the relevant competent departments impose penalties under laws and administrative regulations such as the Cybersecurity Law, the Data Security Law, the Personal Information Protection Law and the Law on Scientific and Technological Progress; - If we use a third-party large model API for customer service, are the obligations still ours?
Yes. Article 22 of the Measures also lists organisations and individuals that provide generative AI services through programmable interfaces and other means as service providers. An enterprise that connects a third-party large model API and serves customers