Algorithmic recommendation and filing
Which systems must the primary responsibility for algorithmic security cover, and who needs a security assessment?
Based on: Provisions on the Administration of Algorithmic Recommendation in Internet Information Services
In short: the primary responsibility for algorithmic security must be implemented through management systems and technical measures covering the review of algorithmic mechanisms, science and technology ethics review, user registration, information publication review, data security and personal information protection, countering telecom and online fraud, security assessment and monitoring, and emergency handling of security incidents; the rules of the algorithmic recommendation service must be published and professional personnel assigned. Where the service has public-opinion attributes or social-mobilisation capacity, a security assessment must also be carried out in accordance with the relevant national provisions.
What you may need to do
- Fill in each of the management systems and technical measures listed in Article 7
- Publish the rules relating to the algorithmic recommendation service and keep the versions
- Assign professional personnel and technical support commensurate with the scale of the service
- Where the service has public-opinion attributes or social-mobilisation capacity, carry out a security assessment in accordance with the relevant national provisions
- Keep written records of the results of periodic review, assessment and verification
Statutory basis
Provisions on the Administration of Algorithmic Recommendation in Internet Information Services (《互联网信息服务算法推荐管理规定》), Article 7
Providers of algorithmic recommendation services shall implement the primary responsibility for algorithmic security, and shall establish and improve management systems and technical measures covering the review of algorithmic mechanisms, science and technology ethics review, user registration, information publication review, data security and personal information protection, countering telecom and online fraud, security assessment and monitoring, and emergency handling of security incidents…
Provisions on the Administration of Algorithmic Recommendation in Internet Information Services, Article 27
Providers of algorithmic recommendation services with public-opinion attributes or social-mobilisation capacity shall carry out a security assessment in accordance with the relevant national provisions.
Provisions on the Administration of Algorithmic Recommendation in Internet Information Services, Article 8
Providers of algorithmic recommendation services shall periodically review, assess and verify the mechanisms of the algorithm, the model, the data and the application results, and shall not set up algorithmic models that induce users to become addicted or to overspend, or that otherwise violate laws and regulations or ethics.
One-sentence conclusion
The primary responsibility for algorithmic security is not a slogan: Article 7 lists a series of management systems and technical measures that have to be established, and requires the rules of the algorithmic recommendation service to be published and professional personnel commensurate with the scale of the service to be assigned; where the service has public-opinion attributes or social-mobilisation capacity, a security assessment must also be carried out in accordance with the relevant national provisions.
Basis
Article 7 sets out a checklist of duties: providers of algorithmic recommendation services shall implement the primary responsibility for algorithmic security, establish and improve management systems and technical measures covering the review of algorithmic mechanisms, science and technology ethics review, user registration, information publication review, data security and personal information protection, countering telecom and online fraud, security assessment and monitoring, and emergency handling of security incidents, formulate and publish the rules relating to the algorithmic recommendation service, and assign professional personnel and technical support commensurate with the scale of the algorithmic recommendation service. In practice this passage can be broken into four blocks — the list of systems, the technical measures, the publication of the rules and the staffing — and checked item by item.
Article 8 adds a continuing duty: providers of algorithmic recommendation services shall periodically review, assess and verify the mechanisms of the algorithm, the model, the data and the application results, and shall not set up algorithmic models that induce users to become addicted or to overspend, or that otherwise violate laws and regulations or ethics.
Article 27 is the trigger clause for assessment: providers of algorithmic recommendation services with public-opinion attributes or social-mobilisation capacity shall carry out a security assessment in accordance with the relevant national provisions. Note that the wording is in accordance with the relevant national provisions, so the concrete form and content of the assessment follow the current national provisions; this knowledge base does not presume a particular template.
What you need to do
- Turn each of the nine categories listed in Article 7 into a system document, naming the responsible person and the execution frequency for each.
- Pair every technical measure with a system, so that the file does not exist without the corresponding system capability.
- Publish the rules relating to the algorithmic recommendation service, and keep historical versions when the rules are updated.
- Staff the algorithm, security and review roles in proportion to the scale of the service, and keep job descriptions on file.
- Where the service has public-opinion attributes or social-mobilisation capacity, complete the security assessment before advancing to filing.
- Put the conclusions of the periodic review, assessment and verification in writing, so they can be explained during supervision and inspection.
Common pitfalls
Copying template system documents that do not correspond to the algorithms actually used, so that no explanation is possible when one is requested. Publishing rules that read like marketing copy and say nothing about the basic logic of the recommendation mechanism. Treating the security assessment as a one-off action and not re-assessing after the algorithm is replaced. Reading professional personnel as a part-time name on a form.
Follow-up questions
The concrete materials template for the security assessment is not prescribed by the provisions; the relevant national provisions and the position of the cyberspace administration authority for your locality govern.
Follow-up questions
- Are the security assessment and algorithmic filing two separate things?
- Article 27 provides separately for the security assessment duty, while the filing information includes an algorithm self-assessment report. How the two fit together in practice follows the position of the cyberspace administration authority for your locality.
- How is science and technology ethics review, the ninth category of system, actually implemented?
- The provision requires a science and technology ethics review system to be established and improved, but does not prescribe a particular organisational form; industry practice plus consultation with the cyberspace administration authority for your locality is the recommended route.