HomeAnswersChina AI Compliance and Filing

Deep synthesis

Do deep synthesis algorithms have to be assessed? How long are logs kept?

Basis: Provisions on the Administration of Deep Synthesis of Internet Information Services (互联网信息服务深度合成管理规定)
Conclusion: Yes. Providers and technical supporters shall periodically review, assess and verify the mechanism of generative and synthesized algorithms. Anyone offering tools to edit biometric information such as faces and voices, or tools involving special objects and scenes that are not biometric, shall carry out a security assessment in accordance with law, either themselves or through a professional institution. They must also review both input data and synthesized results, build a feature library for identifying illegal and harmful information, and record and retain network logs.

What you may need to do

  1. Turn review of the algorithm mechanism into a recurring action and keep the records
  2. Run security assessments for tools involving faces, voices or special scenes
  3. Review input and output in both directions, with clear entry criteria for the feature library
  4. Set up a log retention policy so records can be traced and retrieved

Provisions relied on

Provisions on the Administration of Deep Synthesis of Internet Information Services (互联网信息服务深度合成管理规定) Article 15
Deep synthesis service providers and technical supporters shall strengthen technical management, and periodically review, assess and verify the mechanism of generative and synthesized algorithms.
Provisions on the Administration of Deep Synthesis of Internet Information Services Article 10
A deep synthesis service provider shall establish and improve a feature library for identifying illegal and harmful information, improve the entry criteria, rules and procedures, and record and retain the relevant network logs.
Provisions on the Administration of Deep Synthesis of Internet Information Services Article 16
For information content generated or edited using its service, a deep synthesis service provider shall take technical measures to add a label that does not affect users’ use of the service, and shall preserve log information in accordance with laws, administrative regulations and relevant state provisions.

One-line conclusion

Technical management is not a one-off action: the algorithm mechanism must be periodically reviewed, assessed and verified; tools involving biometric information such as faces and voices, or special objects and scenes bearing on national security and national image, must go through a security assessment; on the content side both input data and synthesized results must be reviewed, with a feature library for identifying illegal and harmful information; and both network logs and labeling-related logs must be recorded and retained so they can be traced.

Basis

Article 15: “Deep synthesis service providers and technical supporters shall strengthen technical management, and periodically review, assess and verify the mechanism of generative and synthesized algorithms.” It also requires a security assessment for two kinds of tools: “(1) those that generate or edit biometric information such as faces and voices; (2) those that generate or edit non-biometric information such as special objects and scenes that may involve national security, national image, national interests and public interests.”

Article 10: “A deep synthesis service provider shall strengthen the management of deep synthesis content, and review the input data and synthesized results of deep synthesis service users by technical or manual means. A deep synthesis service provider shall establish and improve a feature library for identifying illegal and harmful information, improve the entry criteria, rules and procedures, and record and retain the relevant network logs.”

Article 16 adds the log requirement: take technical measures to add a label that does not affect users’ use, “and preserve log information in accordance with laws, administrative regulations and relevant state provisions.”

What you need to do

Common pitfalls

Frequently asked follow-ups

Q: How long do logs have to be kept? A: These Provisions require “recording and retaining the relevant network logs” and “preserving log information in accordance with laws, administrative regulations and relevant state provisions”, without specifying a number of days. The number of days follows the applicable laws, regulations and relevant state provisions, and the local cyberspace administration office sets the operative reading.

Q: If an external institution does the security assessment, does the provider still bear responsibility? A: Article 15 allows a security assessment to be carried out “either by itself or through a professional institution”, but the duty holder remains the deep synthesis service provider and technical supporter, and the assessment conclusions and remediation actions still have to be accounted for internally.

Frequently asked follow-ups

What if a small team cannot run a security assessment?
It can commission a professional institution, or set up a traceable assessment process internally as required by Article 15; what matters is that the object, method, conclusion and remediation records are all complete.
Is the feature library mandatory?
Article 10 explicitly requires building and improving a feature library for identifying illegal and harmful information, with entry criteria, rules and procedures — a legal duty, not an option.

This entry belongs to the “China AI Compliance and Filing” cluster (42 entries in total): View all · Answers home

Who we are: a knowledge base and AI customer service team serving small and micro businesses, delivering implementations that take AI customer service through the national standard and the filing process.

Content on this site is compiled from publicly released regulatory texts for enterprises’ own self-check reference; the specific filing requirements of the local cyberspace administration authorities prevail, and this is not legal advice.

This page is generated from the China AI compliance and filing MCP corpus — agents can call the same data directly.