Library
China's Generative AI Rules: Filing, Labelling, Content Control
Public generative AI services in China need a CAC security assessment and algorithm filing before launch. Labelling of AI-generated content has been mandatory under the March 2025 Identification Measures and GB 45438-2025 since 1 September 2025. Selling into China is not the same as training or deploying a model there.
Last reviewed
MikeFounder & developer
- US & China
- AI governance
- Compliance
On this page
Who this is for
- Businesses offering a generative service to users in the PRC
- Businesses training or fine-tuning models on PRC territory or with PRC user data
- Exporters who only sell a non-AI product into China and need to know they are probably not in the filing gate
Two different businesses
Selling into China (a physical product, a site with no public generative service, a B2B tool with no PRC public content surface) is mostly product, contract, and, if you process personal information, PIPL. The generative-AI filing gate is not automatically yours.
Training or deploying a public generative service in China: a chatbot, image generator, or similar that the public in the PRC can use, is inside the CAC stack below. “Public opinion attributes or social mobilisation capability” is the phrase the filing duty uses. In practice, a consumer-facing generator is treated as in.
If you only call a China-hosted API from the UK for UK users, you are not thereby a PRC generative-AI provider. If you put a generator on a .cn site or a Chinese app store, you are.
The core instruments (as of 13 August 2026)
| Instrument | In force | What it does |
|---|---|---|
| Interim Measures for the Management of Generative AI Services | 15 August 2023 (promulgated 13 July 2023 by CAC with other departments) | Still the core “interim” regime: lawful training data, content controls, real-name users, labelling, security assessment and filing for services with public-opinion / social-mobilisation attributes. “Interim” has not meant temporary in practice. |
| Algorithm recommendation / algorithm filing provisions | 2022 onwards | Separate filing of recommendation and related algorithms on the CAC system. Generative services typically file here as well as under the Interim Measures. |
| Deep synthesis provisions | 2023 | Synthetic media: labelling and authenticity. The 2025 labelling measures tighten this. |
| Measures for the Identification of AI-Generated (Synthetic) Content | 1 September 2025 (issued March 2025 by CAC, MIIT, MPS, NRTA) | Dual labelling: explicit (visible to a person) and implicit (metadata / watermark). Platforms must verify and prompt. Users who post synthetic content must declare it. |
| GB 45438-2025 | 1 September 2025 (issued 28 February 2025) | Mandatory national standard for how to apply those labels. Technical, not optional. |
Enforcement is real. CAC has run labelling sweeps (including a widely reported February 2026 action). Do not treat “interim” as unenforced.
Filing and security assessment
Before a public generative service goes live in China:
- Security assessment, submitted through provincial CAC and, for national-reach or public-opinion services, central review.
- Algorithm filing on the CAC system. You receive a filing number. Display it.
- Training-data provenance, content filters, watermarking/traceability, real-name registration aligned with existing cybersecurity rules.
Timelines of several months are normal. Using a pre-filed third-party model via API can shorten local registration; it does not skip the analysis of whether your service still needs a filing.
No filing number, no lawful public operation. That is the filing gate.
Labelling
Since 1 September 2025:
- Explicit labels on generated text, image, audio, video and virtual scenes, visible in the content or the interface.
- Implicit labels in the file (provider, content id, generation data), to the GB 45438-2025 method.
- Distribution platforms check labels on upload and warn when content is generated or likely generated.
- Stripping labels to pass content off as human is a violation.
This is stricter and more technical than EU Article 50. Do not assume an Article 50 watermark satisfies GB 45438-2025.
Content control
The Interim Measures still require providers to keep generated output inside PRC content rules (a long prohibited list, including political and national-security categories). Illegal output must be stopped, and serious cases reported. That duty is why a model that is lawful in London can be unlawful on a Shanghai endpoint without a single line of GDPR changing.
Questions
We sell software to a Chinese company that runs the model. Who files?
Usually the provider of the public service in China. If your customer is the one offering the chatbot to the PRC public, they are in the filing seat. If you operate the service, you are. Contract for it. Do not assume the overseas parent can file “for” a PRC service without a PRC entity. Local presence is a practical requirement in most cases. Confirm with PRC counsel.
Does the Interim Measures’ “interim” label mean a replacement is coming?
The title has said 暂行 since 2023. Labelling measures and GB 45438-2025 have grown up around it. As of 13 August 2026 there is no replacement statute that retires the Interim Measures. A future AI law could. This page will say so when one is in force.
We only advertise a UK SaaS site to Chinese tourists. Filing?
A public generator used in the PRC can still be in scope even if the company is abroad, similar extra-territorial pattern to other CAC rules. A brochure site with no generative service is a different question. If the product is the generator, get PRC counsel before the first user in Beijing.
What changed
- 13 August 2026: First publication. Cadence: medium (90–180 days). Next review due 9 January 2027. Off-cycle if the Interim Measures are replaced or CAC issues a new labelling sweep that changes the practical duty.
Note: This is compliance consulting and training, not legal advice. We work alongside your legal counsel, translating regulation into operational reality rather than replacing them. For a structured pass, see AI compliance.
Was this helpful?
Also in the library
- US State AI Law TrackerThere is no federal AI Act. As of 13 August 2026 the live picture is a state patchwork, led by Colorado’s rewrite (SB 26-189, mostly effective 1 January 2027) and California’s AI Transparency Act (SB 942 / BPC Chapter 25, operative 2 August 2026). Treat every other state’s column as volatile.
- The AI Vendor Risk ChecklistA procurement list you can actually use. Data handling, training-on-your-data, sub-processors, audit rights, and model-change notifications: the clauses that decide whether a vendor is safe to put on a live path.
- What Counts as High-Risk Under Annex IIIAnnex III is a use-case list, not a model list. Most Lathestone clients who over-classify do it because the tool is 'AI'; most who under-classify miss internal HR and customer-decision systems. Article 6(3) exemptions exist. They are narrow, and profiling is not one of them.