China Cybersecurity Law (2025 Amendments)

Amendments adopted 28 October 2025 and in force 1 January 2026: dedicated AI governance provisions (ethics review, risk assessment, training data), fines up to RMB 10 million or 5 percent of turnover for serious violations, and explicit extraterritorial reach over conduct that harms Chinese network security.

JurisdictionChina
CategoryCybersecurity
StatusActive
Effective date
Latest development

Analysis

The 2025 Amendment to the Cybersecurity Law of the People’s Republic of China (CSL) was adopted by the Standing Committee of the 14th National People’s Congress (NPCSC) on 28 October 2025 and took effect on 1 January 2026, introducing new AI governance provisions, higher penalties, and broader extraterritorial reach for cybersecurity violations.China approves amendment to cybersecurity law – Xinhua Decision of the NPCSC to Amend the Cybersecurity Law (LawInfoChina) China: Amended Cybersecurity Law Takes Effect – Library of Congress


Key Requirements

1. AI Governance and State Support (New Article 20)

Compliance implication: While Article 20 is largely “programmatic” (state-support language), it establishes expectations for AI ethics, lifecycle risk management, and safety oversight that authorities can reference in enforcement and subsequent implementing rules.Regulating AI and Strengthening Legal Liability – EU IP Helpdesk Cybersecurity Law of the PRC – CSET translation


2. Increased Fines and Legal Liability

Note: Public English-law firm summaries indicate fines up to RMB 50 million or 5% of turnover for certain violations; that exact figure should be checked against the official NPCSC text in Chinese.Decision of the NPCSC to Amend the Cybersecurity Law (LawInfoChina) China’s Cybersecurity Law Amendments – Latham & Watkins


3. Broadened Extraterritorial Application


4. Reinforced Core Cybersecurity Obligations (Existing CSL + Amendments)


Compliance Challenges

1. Interpreting AI Governance Obligations

2. Managing Higher Penalty Exposure

3. Extraterritorial Compliance for Foreign Operators

4. Harmonizing CSL with Internal Governance Structures


Implementation Best Practices

1. Establish a CSL‑Aligned AI Governance Framework

  • Create an AI ethics and risk committee covering China operations: Organizations should set up cross‑functional AI governance committees specifically tasked with ensuring compliance with Article 20’s ethics, risk monitoring, and safety supervision requirements.[Decision of the NPCSC to Amend the Cybersecurity Law (LawInfoChina)](https://www.lawinfochina.com/display.aspx?lib=

Recent developments

  • — Overview of the **2025 amendments** to China’s Cybersecurity Law, noting the NPC Standing Committee’s 28 October 2025 decision and the **effective date of 2026-01-01**, and summarizing how the law is now supplemented by detailed subordinate regulations and standards.[12] (source)
  • — Analytical report on the **2025 amendments**, highlighting new language on **state support for AI**, use of AI to bolster cybersecurity defenses, and requirements to improve the security of AI systems themselves, situating the changes within China’s broader cyber and AI governance strategy.[9] (source)
  • — Annual review of **China data protection and cybersecurity developments**, emphasizing the 28 October 2025 decision amending the Cybersecurity Law, and discussing expected **enforcement trends and compliance priorities for 2026** across the cybersecurity industry.[14] (source)
  • — Alert describing the 2025 amendment as the **“strictest” version** of China’s Cybersecurity Law now in force, stressing significantly **increased fines and enforcement risks** for both critical information infrastructure operators and ordinary businesses, and warning of heightened regulatory scrutiny for cybersecurity incidents.[5] (source)
  • — Client alert on China’s **Amended Cybersecurity Law** taking effect on 1 January 2026, detailing the **expanded extraterritorial enforcement powers**, clarified penalty framework for different obligations, and references to policy goals for **AI governance**, with an emphasis on risks for multinational cyber and tech operators.[2] (source)
  • — Detailed note on “**Key updates on the amended cybersecurity law of China**,” explaining the **new tiered penalty regime**, stricter fines for material cybersecurity violations, expanded regulatory powers, and the practical compliance implications for network operators and critical infrastructure providers.[1] (source)
  • — Analysis of **key revisions** and **compliance recommendations**, outlining the comprehensive revision that took effect on 1 January 2026, summarizing major changes (higher penalties, clarified obligations, extraterritorial reach) and offering **industry-focused guidance** on how companies should update cybersecurity programs.[6] (source)
  • — Insight piece on how the **2025 amendments increase penalties and broaden extraterritorial enforcement**, explaining that overseas activities endangering PRC cybersecurity can now be targeted, and assessing the **impact on foreign cybersecurity, cloud, and tech service providers** operating or serving customers in China.[4] (source)
  • — Legal monitor note announcing that the **amended Cybersecurity Law came into force on 2026-01-01**, summarizing the 14-article amendment: stronger support for AI development, **higher fines** (up to RMB 10 million for especially grave CIIO violations), and expanded **extraterritorial effect** of the law.[10] (source)
  • — Official-style in‑depth article on the NPC Standing Committee’s approval of the amendment to the Cybersecurity Law, describing the added article on **safe and sound AI development**, priority areas for AI (research, infrastructure, ethics), and strengthened **AI safety risk monitoring and regulation**, signaling strategic direction for the cybersecurity and AI industries.[13] (source)

Related regulations

Put it into practice

Browse all regulations · Compliance deadlines · Latest updates