Interim Measures for Generative AI
If we build customer service on a third-party large model API, are the duties still ours?
Basis: Interim Measures for the Administration of Generative AI Services (《生成式人工智能服务管理暂行办法》)
Conclusion: Yes. Article 22 of these Measures lists an organisation or individual that “provides generative AI services by providing programmable interfaces and other means” as a service provider. Where an enterprise connects to a third-party large model API and provides generative services to its own customers, it falls within the provider definition: it bears the network information content producer responsibility under Article 9, protects input information under Article 11, disposes of illegal content and reports under Article 14, and builds a complaint and reporting mechanism under Article 15.
What you may need to do
- Confirm whether you fall within the definition of a service provider
- Agree the supplier's data processing and compliance duties in the procurement contract
- Build content review and interception on the customer-facing output side
- Provide end users with a complaint and reporting entry point and a response time limit
- Define the retention rules for input information and disclose them externally
- Establish who handles the required security assessment and filing
Provisions relied on
Interim Measures for the Administration of Generative AI Services, Article 22
(2) A generative AI service provider means an organisation or individual that uses generative AI technology to provide generative AI services (including providing generative AI services by providing programmable interfaces and other means).
Interim Measures for the Administration of Generative AI Services, Article 9
A provider shall bear the responsibility of a network information content producer in accordance with the law and perform network information security obligations.
Interim Measures for the Administration of Generative AI Services, Article 14
Where a provider finds illegal content, it shall promptly take disposal measures such as stopping generation, stopping transmission and eliminating the content, take measures such as model optimisation training to rectify the situation, and report to the competent authorities.
One-line conclusion
“The model is not ours to train” is not an automatic exemption. The definition of a provider in Article 22 expressly includes “providing generative AI services by providing programmable interfaces and other means”. When an enterprise takes a third-party API and builds a customer-facing AI customer service or copywriting tool, it becomes a service provider on that chain, and content safety, input information protection and complaint handling remain its own duties.
Basis
Article 22, item (2) provides: a generative AI service provider means an organisation or individual that uses generative AI technology to provide generative AI services (including providing generative AI services by providing programmable interfaces and other means). Note the parenthetical wording: it specifically closes off the argument “I am only the caller”.
Article 9, paragraph 1 sets the nature of the liability: a provider shall bear the responsibility of a network information content producer in accordance with the law and perform network information security obligations; where personal information is involved, it shall bear the responsibility of a personal information processor and perform personal information protection obligations. You face end users, and what those end users receive is output from your product, so the content producer responsibility sits here.
Article 11 protects the user's input information and usage records: no collection of unnecessary personal information, no unlawful retention of input information and usage records that can identify a user, and no unlawful provision of them to others. Forwarding customer conversations to the model vendor is a case of providing them to others and needs a basis.
Article 14 requires prompt disposal, rectification and reporting when illegal content is found online, and disposal in accordance with the law and the agreement, with records kept and a report made, when a user is found to be engaging in illegal activities.
The security assessment and algorithm filing obligations in Article 17 are also judged by the attributes of the service and are not automatically waived because someone else's model sits underneath. Who handles them must be confirmed against the service form and local practice.
What you need to do
- Make the entity judgement first: do you provide a generative service to the domestic public? If so, perform the provider duties.
- Write into the procurement contract: how the supplier processes data, whether it is used for training, the retention period, the duty to notify security incidents, and its commitment on content safety capability. Keep the supplier's compliance credentials, but they do not replace your own duties.
- Build content review and interception on the customer-facing output side. Do not rely entirely on the model vendor's default policy, because your scenario and user base differ.
- Build a complaint and reporting entry point and a handling time limit, and publish them as Article 15 requires.
- Define the retention rules for input information and disclose them externally, controlling unnecessary collection and unlawful retention as Article 11 requires.
- Decide whether a security assessment and an algorithm filing are needed, confirm which party is responsible, and preferably write the cooperation duty into the contract.
- Prepare a supplier switching plan. A change of model service may affect content safety performance and the filing status.
Common pitfalls
- Pushing all compliance liability onto the model vendor. The definition in Article 22 writes you into the provider scope.
- Signing only a commercial contract without agreeing data processing and content safety duties.
- Relying entirely on the model vendor's default safety policy without hardening it for your own industry scenario.
- Forwarding customer conversations to the vendor for optimisation, which exceeds what is necessary and was not disclosed.
- Ignoring the filing status after launch, and failing to assess whether a supplier's model change or shutdown triggers an amendment.
Common follow-up questions
Our chatbot only calls an API; do we need a security assessment and filing? The trigger in Article 17 is whether the service has public opinion attributes or social mobilisation capacity, regardless of who provides it. The basis for the judgement follows the local cyberspace administration authority, and the contract should state each party's cooperation duties.
Can customer conversation records be passed to the model vendor? Article 11 prohibits unlawfully providing a user's input information and usage records to others. Forwarding needs a legal basis, a notice to the user, and contractual limits on how the vendor may use them.
The vendor says it is already filed, so does that mean we need not bother? The vendor's filing corresponds to the service the vendor itself provides. When you provide a generative service to your own end users, the duties under Article 9 and the rest rest on you and must be judged independently.
If we connect models from several vendors, do we handle each separately? We suggest assessing each vendor's data processing and content safety capability and putting them in a supplier management ledger, in particular whether the data is used for training.
Common follow-up questions
- If we only do internal enterprise knowledge Q&A and nothing external, are we a provider?
- Under Article 2, paragraph 3, where generative AI services are not provided to the domestic public, these Measures do not apply. But where employee input involves personal information or trade secrets, other laws still apply.
- Can content safety capability be contracted out to the vendor?
- You can agree the vendor's technical capability and cooperation duties, but the responsible subject under Article 9 is the provider that offers the service, and that cannot be transferred by contract.
- What material should we ask a third-party model vendor for when procuring?
- We suggest collecting: the source of the corpus and the base model, a statement of content safety capability, data processing and retention rules, whether data is used for training, and the security assessment and filing status. The exact list follows your business risk and local practice.