Filing practice
The precondition for a security assessment is still that the service has public-opinion attributes or social-mobilisation capacity. AI customer service and intelligent question answering that meet this condition should first carry out a security assessment in accordance with the relevant national provisions, then handle algorithmic filing and the modification and deregistration procedures under the Provisions on the Administration of Algorithmic Recommendation in Internet Information Services; they must also implement the primary responsibility for algorithmic security.
Article 17 of the Interim Measures for the Management of Generative AI Services: providers of generative AI services with public-opinion attributes or social-mobilisation capacity shall carry out a security assessment in accordance with the relevant national provisions, and shall carry out algorithmic filing and the procedures for modification and deregistration of the filing in accordance with the Provisions on the Administration of Algorithmic Recommendation in Internet Information Services.
Article 27 of the algorithmic recommendation provisions: providers of algorithmic recommendation services with public-opinion attributes or social-mobilisation capacity shall carry out a security assessment in accordance with the relevant national provisions. The two sets of provisions are identical on the assessment requirement, and identical in how they state the trigger condition.
Article 7 of the algorithmic recommendation provisions sets out the duties that sit alongside the assessment: providers of algorithmic recommendation services shall implement the primary responsibility for algorithmic security, and shall establish and improve management systems and technical measures covering the review of algorithmic mechanisms, science and technology ethics review, user registration, information publication review, data security and personal information protection, countering telecom and online fraud, and emergency handling of security incidents; shall formulate and publish the rules relating to the algorithmic recommendation service; and shall assign professional personnel and technical support commensurate with the scale of the service. For a consumer-facing scenario such as AI customer service, two of these in particular — data security and personal information protection, and countering telecom and online fraud — have to exist as actual system capabilities.
One clarification: the text says to carry out a security assessment in accordance with the relevant national provisions, but it gives no assessment template, scoring sheet or submission format. The source documents contain no filing URL either, and no description of the process beyond the time limits. Anything that turns on the concrete route to filing follows the position of the cyberspace administration authority with jurisdiction over your locality.
Treating the fact that the AI assistant only answers after-sales questions as sufficient reason to conclude it has no public-opinion attributes. Skipping the security assessment and going straight to filing, so that the materials cannot support the case. Turning the security assessment into a plain written statement with no test or verification record at all. After launch, connecting the knowledge base to a new public data source without triggering a re-assessment. Ignoring the counter-fraud requirement in Article 7 — when AI customer service is precisely the kind of scenario that is often used for impersonation and fraudulent inducement.
Who organises the security assessment and who receives the result: the source documents go only as far as carrying out the assessment in accordance with the relevant national provisions. The concrete position follows the cyberspace administration authority with jurisdiction over your locality.
This entry belongs to the China AI Compliance & Filing cluster (42 entries in total): View all · Answers home
Who we are: a knowledge base and AI customer service team serving small and micro enterprises, doing hands-on delivery for AI customer service — meeting GB/T 47746-2026 and completing filing.
Content on this site is compiled from publicly released regulatory texts and is provided for enterprise self-check reference. The filing position of the cyberspace administration authority in your locality governs; nothing here is legal advice.
This page is generated from the China AI Compliance & Filing MCP corpus — agents can call the same dataset directly.