Deep synthesis
Must deep synthesis services verify real identity? Can guests publish content?
Basis: Provisions on the Administration of Deep Synthesis of Internet Information Services (互联网信息服务深度合成管理规定)
Conclusion: Yes. A provider shall, on the basis of a mobile phone number, identity document number, unified social credit code or the national online identity authentication public service, verify the real identity information of users in accordance with law; it may not provide the information publishing service to users that have not completed real identity information verification. In other words, unverified users may try generation, but they cannot publish the content.
What you may need to do
- Add verification to the registration flow, matching the method to individuals and organizations respectively
- Turn verification status into tiered permissions, with publishing closed to unverified users
- Keep verification records so they can be checked
- Include unverified accounts in periodic inspection and cleanup
Provisions relied on
Provisions on the Administration of Deep Synthesis of Internet Information Services (互联网信息服务深度合成管理规定) Article 9
A deep synthesis service provider shall, on the basis of a mobile phone number, identity document number, unified social credit code or the national online identity authentication public service, verify the real identity information of deep synthesis service users in accordance with law, and may not provide the information publishing service to deep synthesis service users that have not completed real identity information verification.
One-line conclusion
A deep synthesis service provider must lawfully verify the real identity information of users, using methods that include a mobile phone number, identity document number, unified social credit code or the national online identity authentication public service. It may not provide the information publishing service to users that have not completed real identity information verification. Real-name verification answers the question of who is publishing, and it is not a substitute for content review — both must be done at the same time.
Basis
Article 9: “A deep synthesis service provider shall, on the basis of a mobile phone number, identity document number, unified social credit code or the national online identity authentication public service, verify the real identity information of deep synthesis service users in accordance with law, and may not provide the information publishing service to deep synthesis service users that have not completed real identity information verification.”
Read together with the user registration management system required by Article 7, verification is not an isolated checkbox but part of the registration-stage system, and has to be seen alongside account management, content review and handling measures.
What you need to do
- Match the method to the subject: individual users can use a mobile phone number or identity document number, organizational users a unified social credit code, and the national online identity authentication public service can also be integrated.
- Grant access in tiers: in an unverified state, allow generation, preview and draft saving, but close the outward-facing entrances such as publishing, commenting and sharing.
- Record and check: the verification result, time and basis should be retained and checkable, so they can be produced during a regulatory inspection.
- Inspect periodically: clean up abnormal accounts that remain able to publish long after verification lapsed, and look for interfaces or legacy switches that bypass verification.
- Link handling to verification: measures against offending accounts — warnings, functional restrictions, service suspension, account closure — rest on verification information as a traceable basis.
Common pitfalls
- Treating email registration as completed verification. Email is not among the verification methods listed.
- Showing a front-end pop-up asking users to verify, with no back-end status control, so unverified users can still publish.
- Confusing real-name verification with content review. Verification governs identity and review governs content; neither can be skipped.
- When retrofitting an existing product, changing only the new registration flow and leaving the verification status of legacy accounts blank.
- Running separate registration logic for the public API, the H5 page, the client and the open platform, so verification standards diverge.
Frequently asked follow-ups
Q: If it is only a self-use authoring tool, must users still verify their real identity? A: The duty holder under Article 9 is a provider of deep synthesis services, and the threshold is set at the “information publishing service”. If a product opens outward-facing publishing, real identity information verification should be completed; whether a given case counts as providing an internet information service to the public is a boundary question on which the local cyberspace administration office sets the operative reading.
Q: For B2B customers whose accounts are opened by the enterprise, how is verification done? A: An institutional subject can complete verification by statutory means such as the unified social credit code, and that must be carried down to the individual user, so there is no gap where the enterprise is verified but the actual user cannot be traced.
Frequently asked follow-ups
- Can unverified users use the generation features?
- The restriction in the Provisions is on the “information publishing service”. Features that do not amount to publishing, such as generation, editing and local saving, can be designed per product strategy, but the publishing entrance must be closed to unverified users.
- How long must verification information be kept?
- These Provisions require real identity information verification in accordance with law and the preservation of log information in accordance with laws, administrative regulations and relevant state provisions; the specific retention period follows the applicable laws, regulations and relevant state provisions.