HomeAnswersChina AI Compliance and Filing

Interim Measures for Generative AI

What happens if we are non-compliant, and is rectifying first enough?

Basis: Interim Measures for the Administration of Generative AI Services (生成式人工智能服务管理暂行办法)
Conclusion: Article 21 of these Measures provides that where a provider violates these Measures, the competent authorities shall impose penalties in accordance with the Cybersecurity Law of the People's Republic of China (中华人民共和国网络安全法), the Data Security Law of the People's Republic of China (中华人民共和国数据安全法), the Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法), the Science and Technology Progress Law of the People's Republic of China (中华人民共和国科学技术进步法) and other laws and administrative regulations; where no law or administrative regulation so provides, the competent authorities shall, within their duties, give a warning or a public notice of criticism and order rectification within a time limit; where rectification is refused or the circumstances are serious, they shall order suspension of the provision of the relevant service. Where the conduct constitutes a violation of public security administration or a crime, liability is pursued separately.

What you may need to do

  1. Self-check clause by clause against these Measures and produce a rectification list.
  2. Assign an owner and a completion deadline for each issue found.
  3. Keep evidence of the rectification process to explain it to the competent authorities.
  4. Cooperate with supervision and inspection, preparing explanations of training data and mechanisms.
  5. Where rectification falls short, assess the business impact of a service suspension.

Provisions relied on

Interim Measures for the Administration of Generative AI Services, Article 21
Where a provider violates these Measures, the competent authorities shall impose penalties in accordance with the Cybersecurity Law of the People's Republic of China, the Data Security Law of the People's Republic of China, the Personal Information Protection Law of the People's Republic of China, the Science and Technology Progress Law of the People's Republic of China and other laws and administrative regulations
Interim Measures for the Administration of Generative AI Services, Article 21
Where laws and administrative regulations do not so provide, the competent authorities shall, within their duties, give a warning or a public notice of criticism and order rectification within a time limit; where rectification is refused or the circumstances are serious, they shall order suspension of the provision of the relevant service.
Interim Measures for the Administration of Generative AI Services, Article 21
Where the conduct constitutes a violation of public security administration, a public security administrative penalty shall be imposed in accordance with the law; where it constitutes a crime, criminal liability shall be pursued in accordance with the law.

One-line conclusion

Rectifying first is not absolute safety. The ladder under Article 21 is: where a superior law applies, penalise under that law; where none applies, warn, criticise publicly and order rectification within a time limit; where rectification is refused or the circumstances are serious, order suspension of the provision of the relevant service. Public security penalties and criminal liability apply separately.

Basis

Article 21, paragraph 1 is a layered set of rules. The first layer: where a provider violates these Measures, the competent authorities shall impose penalties in accordance with the Cybersecurity Law of the People's Republic of China, the Data Security Law of the People's Republic of China, the Personal Information Protection Law of the People's Republic of China, the Science and Technology Progress Law of the People's Republic of China and other laws and administrative regulations. In other words, many violations land directly on the penalty provisions of superior laws, not only on the measures in these Measures.

The second layer: where laws and administrative regulations do not so provide, the competent authorities shall, within their duties, give a warning or a public notice of criticism and order rectification within a time limit; where rectification is refused or the circumstances are serious, they shall order suspension of the provision of the relevant service. The signal is clear: the attitude towards rectification and its effect directly shape the outcome, and suspension is on the list.

The third layer is Article 21, paragraph 2: where the conduct constitutes a violation of public security administration, a public security administrative penalty shall be imposed in accordance with the law; where it constitutes a crime, criminal liability shall be pursued in accordance with the law. Once content violations or data violations reach a certain level, the risk does not stop at administrative penalty.

Article 19 sits alongside: the competent authorities carry out supervision and inspection of generative AI services within their duties, and providers shall cooperate in accordance with the law, explain the source, scale and type of training data, the labelling rules, the algorithm mechanism and so on as required, and provide the necessary technical and data support and assistance. Failing to cooperate is itself a problem.

What you need to do

  1. Self-check clause by clause against these Measures and produce a rectification list: description of the issue, responsible department, completion deadline, verification method.
  2. Handle immediately closable risks technically first, for example turning off unnecessary personal information collection and supplementing content safety policy.
  3. Keep a rectification ledger and preserve evidence from before, during and after rectification, to explain to the competent authorities.
  4. Prepare supervision and inspection material in advance: the source and scale of training data, the types of data, the labelling rules, the algorithm mechanism.
  5. Assess your own risk profile: whether the service has public opinion attributes or social mobilisation capacity, and whether the security assessment and algorithm filing under Article 17 are complete.
  6. Where personal information processing or cross-border data transfer is involved, self-check against the Personal Information Protection Law and the Data Security Law at the same time.

Common pitfalls

Common follow-up questions

What happens if we refuse to rectify? Under Article 21, where rectification is refused or the circumstances are serious, the competent authorities shall, within their duties, order suspension of the provision of the relevant service, which directly affects business continuity.

Will there be a fine straight away? The route in Article 21 is to penalise in accordance with the Cybersecurity Law, the Data Security Law, the Personal Information Protection Law and other laws and administrative regulations; whether a fine applies depends on the specific superior provision the conduct breaches.

What material must we hand over when cooperating with supervision and inspection? Under Article 19, explanations of the source, scale and type of training data, the labelling rules and the algorithm mechanism as required, plus the necessary technical and data support and assistance. The specific list follows the requirements of the competent authorities.

Common follow-up questions

After receiving an order to rectify within a time limit, what is the priority?
Stop the non-compliant conduct immediately, submit a rectification plan, complete it on time and keep records. Article 21 lists refusal to rectify as grounds for escalation.
Do these Measures contain a fine provision?
The handling route in Article 21 is to penalise in accordance with the Cybersecurity Law, the Data Security Law, the Personal Information Protection Law, the Science and Technology Progress Law and other laws and administrative regulations; where no superior law so provides, the measures are a warning, a public notice of criticism and an order to rectify within a time limit.
What are the consequences of not cooperating with supervision and inspection?
Article 19 requires providers to cooperate in accordance with the law and to provide the necessary technical and data support and assistance. Failing to cooperate is itself a breach of these Measures and may be handled under Article 21.

This entry belongs to the “China AI Compliance and Filing” cluster (42 entries in total): View all · Answers home

Who we are: a knowledge base and AI customer service team serving small and micro businesses, delivering implementations that take AI customer service through the national standard and the filing process.

Content on this site is compiled from publicly released regulatory texts for enterprises' own self-check reference; the specific filing requirements of the local cyberspace administration authorities prevail, and this is not legal advice.

This page is generated from the China AI compliance and filing MCP corpus — agents can call the same data directly.