Measures for Managing Generative Artificial Intelligence Services
· About Measures for Managing Generative Artificial Intelligence Services
Key Takeaways
- The Interim Measures for the Management of Generative AI Services apply to providers offering generative AI services to the public in mainland China and took effect on 15 August 2023.[2][3]
- Providers must ensure generated content respects core socialist values, does not endanger national security or social order, and does not produce illegal content that could subvert state power or disclose state secrets.[3][5]
- The regime is enforced by the Cyberspace Administration of China (CAC) together with other state authorities, and it sits alongside China’s algorithm, deep-synthesis, personal-information, and AI-content-labeling rules.[2][5][9]
- Providers must conduct security assessments, complete relevant filings where required, and maintain content, data, and user-protection controls before and during service launch.[2][5][11]
- China added a separate AI labeling regime in 2025, requiring visible or embedded identifiers for AI-generated and synthesized content from 1 September 2025, which now works with the generative AI rules.[9][15]
- Since 2026, China has also introduced a separate regime for AI anthropomorphic interactive services, effective 15 July 2026, which may overlap with generative AI chatbot or companion-style services.[1][12][15]
What It Is
The rule set is the Interim Measures for the Management of Generative AI Services, China’s first binding national regulation specifically targeting public-facing generative AI services.[2][3] It is a sectoral administrative regime focused on content governance, data governance, safety assessment, and provider accountability for text, images, audio, and video generation services offered to users in China.[2][5][11]
The Measures were jointly issued by the CAC and six other ministries on 10 July 2023 and took effect on 15 August 2023.[2][3][11] They remain in force in 2026; no later amendment or replacement of the 2023 text was identified in the sources reviewed.[2][3][10]
The Measures are enforced primarily by the CAC, with supporting roles from other relevant ministries and local regulators depending on the service and underlying sector.[2][11] In practice, the Measures operate within a larger Chinese AI governance stack that also includes algorithm filing rules, deep-synthesis rules, AI labeling rules effective 1 September 2025, and the 2026 anthropomorphic-interaction measures effective 15 July 2026.[9][12][15]
Who Must Comply
The Measures apply to service providers that use generative AI technology to provide services to the public within the territory of the PRC.[3][11] The practical focus is on public-facing services, not purely internal enterprise use, although internal use may still trigger other Chinese rules such as cybersecurity, data, and algorithm controls.[2][5]
Extraterritorial reach is broad in effect because a provider outside China that makes a generative AI service available to users in China can fall within scope if it is serving the public in Chinese territory.[3][11] The rule is therefore relevant to offshore SaaS operators, model vendors, app developers, and platform providers that localize or distribute services into China.[2][3]
The Measures do not create a general exemption for foreign entities, but applicability may depend on whether the service is actually offered to the public in China and whether the provider is subject to local filing, security, and content obligations.[3][5] Separate Chinese rules may apply depending on whether the system also qualifies as an algorithmic recommendation service, deep-synthesis service, or anthropomorphic interactive service.[9][12][15]
Core Requirements
- Content legality and value control — Providers must ensure generated content complies with laws and administrative regulations, does not endanger national security or social order, and aligns with core socialist values.[3][5]
- Training-data legality and quality — Providers must use lawful sources for training data, improve data quality, and avoid infringement of intellectual property, personal information, or other lawful rights in the data pipeline.[2][5][11]
- Personal information protection and user rights — Providers must protect personal information, respect users’ lawful rights and interests, and publish clear service rules, complaint channels, and appropriate content handling mechanisms.[2][5][11]
- Security assessment and filing — Providers must conduct security assessments and complete required filings or registration-style compliance steps before launch when applicable under the broader Chinese algorithm and generative AI regime.[2][9][11]
- Content moderation and incident handling — Providers must establish mechanisms to stop illegal content generation, respond to user reports, and remedy risks promptly when outputs violate law or policy.[3][5]
- Transparency and labeling — Providers must disclose that content is AI-generated where required and, from 1 September 2025, comply with China’s separate AI labeling regime for visible or embedded identifiers on synthetic content.[9][15]
- User protection and anti-abuse controls — Providers must prevent misuse, protect minors and vulnerable users, and implement safeguards against harmful prompt injection, fraud, and other illegal use cases as part of platform governance.[3][5][11]
Deadlines and Penalties
| milestone | date | what applies | |---|---:|---| | Measures issued | 10 July 2023 | CAC and six ministries promulgated the interim generative AI framework.[2][11] | | Measures enter into force | 15 August 2023 | Providers offering public generative AI services in China must comply.[2][3] | | AI labeling rules take effect | 1 September 2025 | AI-generated and synthesized content must carry required identifiers under the separate labeling regime.[9][15] | | Anthropomorphic interactive AI measures take effect | 15 July 2026 | Separate obligations apply to AI services with human-like interactive features.[1][12][15] |
The sources reviewed did not identify a single standalone fine schedule in the Measures text summary, but they indicate that violations can lead to enforcement under China’s broader cyber, content, data, and algorithm laws, including corrective orders, service suspension, and administrative penalties under related statutes and regulations.[2][5][11] In practice, sanctions may also include removal of content, rectification orders, algorithm or filing non-compliance consequences, and other sectoral penalties depending on the underlying breach.[2][9][15]
How to Comply
- Map scope and service lines — Determine whether each product is a public-facing generative AI service in China, and whether any adjacent regime also applies, including labeling, algorithm filing, deep synthesis, or anthropomorphic-interaction rules.[2][9][12]
- Build a governance owner model — Assign legal, security, product, and content-accountability roles with a clear approval workflow for model launch, update, incident handling, and regulator responses; this maps well to ISO 27001 governance and risk controls.[5][11]
- Harden the training-data pipeline — Document lawful data provenance, filtering, retention, and rights-clearance controls for training and fine-tuning data, with records suitable for audits and security reviews.[2][5]
- Implement content safety controls — Add policy filters, refusal logic, human review, and escalation paths for sensitive categories such as national security, extremism, fraud, privacy, and IP infringement; align operational controls to NIST CSF 2.0 protect/detect/respond functions.[3][5]
- Prepare pre-launch filings and assessments — Complete required security assessments, internal testing, and submissions before public release where the broader Chinese AI filing regime requires it.[2][9][11]
- Adopt labeling and provenance controls — Apply visible or embedded markers for synthetic content where required, and design output pipelines so downstream users can retain provenance metadata.[9][15]
- Create user-facing notices and complaint handling — Publish service terms, risk notices, and complaint channels, then track remediation timing and repeat-offender behavior.[2][5]
- Run continuous audit and model-risk reviews — Use periodic testing, red-teaming, logging, incident response, and change management; ISO 42001 is a strong fit for an AI management system because it formalizes policy, impact, lifecycle, and improvement controls.[5][11]
Related Regulations
China’s algorithm recommendation rules overlap because many generative AI services also use ranking, personalization, or recommendation systems that trigger separate filing and governance obligations.[9][11]
China’s deep synthesis rules overlap because synthetic text, image, audio, and video outputs may also be treated as deep-synthesis content requiring provenance and platform controls.[9][15]
China’s AI labeling rules conflict only operationally, not legally, because they add a later and more specific identification obligation for synthetic content from 1 September 2025.[9][15]
China’s PIPL overlaps because generative AI systems that ingest or produce personal information must still satisfy personal-information processing, notice, minimization, and rights-handling duties.[2][5]
China’s Cybersecurity Law and related data-security rules overlap because service availability, security assessments, logging, and content controls often depend on the same technical and organizational safeguards.[5][11][15]
FAQ
Does this apply to companies outside China?
Yes, if the company offers a generative AI service to the public in mainland China, the Measures can apply even if the provider is incorporated elsewhere.[3][11] The practical test is service availability to users in China, not just the location of headquarters or servers.[3][5]
Does it cover internal enterprise AI tools?
Usually not as the primary target, because the Measures focus on services provided to the public.[3][11] However, internal tools can still trigger other Chinese rules if they process personal information, use regulated algorithms, or connect to public-facing services.[2][9]
What content is most sensitive under the rule?
Content that could endanger national security, social order, or state interests is most sensitive, including material that subverts state power, incites disorder, or discloses state secrets.[3][5] Providers are expected to prevent such outputs through both preventive and reactive controls.[3][5]
Are there new labeling obligations after 2023?
Yes. China’s separate AI-content labeling regime took effect on 1 September 2025 and requires identifiers for AI-generated and synthesized content.[9][15] That means providers now have to manage both the 2023 generative AI obligations and the later provenance-labeling obligations together.[9][15]
What happens if a provider does not comply?
The Measures themselves sit within a broader administrative enforcement ecosystem, so non-compliance can lead to corrective orders, content takedown, service restriction, and other administrative penalties under related Chinese laws and regulations.[2][5][11] The exact sanction depends on the specific violation and the statute invoked by regulators.[2][9][15]
Sources
- Cyberspace Administration of China and related ministries, Interim Measures for the Management of Generative AI Services (official Chinese text)
- Cyberspace Administration of China
- China Law Translate, Interim Measures for the Management of Generative AI Services (English translation)
- Future of Privacy Forum, China’s Interim Measures for the Management of Generative AI Services
- White & Case, AI Watch: Global regulatory tracker — China
- Chambers Practice Guides, AI & Intellectual Property 2026 — China
- Bird & Bird, China’s new regulations on AI anthropomorphic interactive services
- Regulations.AI, China - Generative AI Services Management
Put it into practice
- Generate the policy: NIST AI RMF policy generator (generatepolicy.com)
- Buy the policy pack: NIST AI RMF Implementation Policy (cyberpolicy.shop)
- Build it yourself: Pillar 06 Companion — The 2026 AI Risk Register (ciso.diy)