HomeAnswersChina AI Compliance & Filing

Algorithmic recommendation and filing

Which systems must the primary responsibility for algorithmic security cover, and who needs a security assessment?

Based on: Provisions on the Administration of Algorithmic Recommendation in Internet Information Services
In short: the primary responsibility for algorithmic security must be implemented through management systems and technical measures covering the review of algorithmic mechanisms, science and technology ethics review, user registration, information publication review, data security and personal information protection, countering telecom and online fraud, security assessment and monitoring, and emergency handling of security incidents; the rules of the algorithmic recommendation service must be published and professional personnel assigned. Where the service has public-opinion attributes or social-mobilisation capacity, a security assessment must also be carried out in accordance with the relevant national provisions.

What you may need to do

  1. Fill in each of the management systems and technical measures listed in Article 7
  2. Publish the rules relating to the algorithmic recommendation service and keep the versions
  3. Assign professional personnel and technical support commensurate with the scale of the service
  4. Where the service has public-opinion attributes or social-mobilisation capacity, carry out a security assessment in accordance with the relevant national provisions
  5. Keep written records of the results of periodic review, assessment and verification

Statutory basis

Provisions on the Administration of Algorithmic Recommendation in Internet Information Services (《互联网信息服务算法推荐管理规定》), Article 7
Providers of algorithmic recommendation services shall implement the primary responsibility for algorithmic security, and shall establish and improve management systems and technical measures covering the review of algorithmic mechanisms, science and technology ethics review, user registration, information publication review, data security and personal information protection, countering telecom and online fraud, security assessment and monitoring, and emergency handling of security incidents…
Provisions on the Administration of Algorithmic Recommendation in Internet Information Services, Article 27
Providers of algorithmic recommendation services with public-opinion attributes or social-mobilisation capacity shall carry out a security assessment in accordance with the relevant national provisions.
Provisions on the Administration of Algorithmic Recommendation in Internet Information Services, Article 8
Providers of algorithmic recommendation services shall periodically review, assess and verify the mechanisms of the algorithm, the model, the data and the application results, and shall not set up algorithmic models that induce users to become addicted or to overspend, or that otherwise violate laws and regulations or ethics.

One-sentence conclusion

The primary responsibility for algorithmic security is not a slogan: Article 7 lists a series of management systems and technical measures that have to be established, and requires the rules of the algorithmic recommendation service to be published and professional personnel commensurate with the scale of the service to be assigned; where the service has public-opinion attributes or social-mobilisation capacity, a security assessment must also be carried out in accordance with the relevant national provisions.

Basis

Article 7 sets out a checklist of duties: providers of algorithmic recommendation services shall implement the primary responsibility for algorithmic security, establish and improve management systems and technical measures covering the review of algorithmic mechanisms, science and technology ethics review, user registration, information publication review, data security and personal information protection, countering telecom and online fraud, security assessment and monitoring, and emergency handling of security incidents, formulate and publish the rules relating to the algorithmic recommendation service, and assign professional personnel and technical support commensurate with the scale of the algorithmic recommendation service. In practice this passage can be broken into four blocks — the list of systems, the technical measures, the publication of the rules and the staffing — and checked item by item.

Article 8 adds a continuing duty: providers of algorithmic recommendation services shall periodically review, assess and verify the mechanisms of the algorithm, the model, the data and the application results, and shall not set up algorithmic models that induce users to become addicted or to overspend, or that otherwise violate laws and regulations or ethics.

Article 27 is the trigger clause for assessment: providers of algorithmic recommendation services with public-opinion attributes or social-mobilisation capacity shall carry out a security assessment in accordance with the relevant national provisions. Note that the wording is in accordance with the relevant national provisions, so the concrete form and content of the assessment follow the current national provisions; this knowledge base does not presume a particular template.

What you need to do

Common pitfalls

Copying template system documents that do not correspond to the algorithms actually used, so that no explanation is possible when one is requested. Publishing rules that read like marketing copy and say nothing about the basic logic of the recommendation mechanism. Treating the security assessment as a one-off action and not re-assessing after the algorithm is replaced. Reading professional personnel as a part-time name on a form.

Follow-up questions

The concrete materials template for the security assessment is not prescribed by the provisions; the relevant national provisions and the position of the cyberspace administration authority for your locality govern.

Follow-up questions

Are the security assessment and algorithmic filing two separate things?
Article 27 provides separately for the security assessment duty, while the filing information includes an algorithm self-assessment report. How the two fit together in practice follows the position of the cyberspace administration authority for your locality.
How is science and technology ethics review, the ninth category of system, actually implemented?
The provision requires a science and technology ethics review system to be established and improved, but does not prescribe a particular organisational form; industry practice plus consultation with the cyberspace administration authority for your locality is the recommended route.

This entry belongs to the China AI Compliance & Filing cluster (42 entries in total): View all · Answers home

Who we are: a knowledge base and AI customer service team serving small and micro enterprises, doing hands-on delivery for AI customer service — meeting GB/T 47746-2026 and completing filing.

Content on this site is compiled from publicly released regulatory texts and is provided for enterprise self-check reference. The filing position of the cyberspace administration authority in your locality governs; nothing here is legal advice.

This page is generated from the China AI Compliance & Filing MCP corpus — agents can call the same dataset directly.