China Cybersecurity Law (2025 Amendments)
Amendments adopted 28 October 2025 and in force 1 January 2026: dedicated AI governance provisions (ethics review, risk assessment, training data), fines up to RMB 10 million or 5 percent of turnover for serious violations, and explicit extraterritorial reach over conduct that harms Chinese network security.
| Jurisdiction | China |
|---|---|
| Category | Cybersecurity |
| Status | Active |
| Effective date | |
| Latest development |
Analysis
The 2025 Amendment to the Cybersecurity Law of the People’s Republic of China (CSL) was adopted by the Standing Committee of the 14th National People’s Congress (NPCSC) on 28 October 2025 and took effect on 1 January 2026, introducing new AI governance provisions, higher penalties, and broader extraterritorial reach for cybersecurity violations.China approves amendment to cybersecurity law – Xinhua Decision of the NPCSC to Amend the Cybersecurity Law (LawInfoChina) China: Amended Cybersecurity Law Takes Effect – Library of Congress
Key Requirements
1. AI Governance and State Support (New Article 20)
- State support for AI research and key technologies (algorithms): The amendment adds Article 20, under which the state supports research on basic theories of artificial intelligence and R&D of key technologies such as algorithms.Decision of the NPCSC to Amend the Cybersecurity Law (LawInfoChina) China approves amendment to cybersecurity law – Xinhua China: Amended Cybersecurity Law Takes Effect – Library of Congress
- Development of AI training data resources and computing power infrastructure: Article 20 promotes the construction of training data resources, computing power, and other infrastructure to support AI and cybersecurity.Decision of the NPCSC to Amend the Cybersecurity Law (LawInfoChina) Regulating AI and Strengthening Legal Liability – EU IP Helpdesk China approves amendment to cybersecurity law – Xinhua
- AI ethical norms and risk/safety governance obligations: Article 20 requires improvement of AI ethics norms, strengthened risk monitoring and assessment, and enhanced safety supervision to ensure the “sound development of artificial intelligence.”Decision of the NPCSC to Amend the Cybersecurity Law (LawInfoChina) CAC Issues Amendment to the Cybersecurity Law of China – Hunton Andrews Kurth China’s Cybersecurity Law Amendments Increase Penalties, Broaden Extraterritorial Enforcement – Latham & Watkins
- Use of AI and new technologies to improve cybersecurity: Article 20 encourages the application of AI and other new technologies to improve the level of cybersecurity protection and to innovate cybersecurity management methods.Strictest Amendment to China's Cybersecurity Law In Effect – Haynes Boone China Finalises Amendments to the Cybersecurity Law – Mayer Brown Key Revisions and Compliance Recommendations of the PRC Cybersecurity Law – Bird & Bird
Compliance implication: While Article 20 is largely “programmatic” (state-support language), it establishes expectations for AI ethics, lifecycle risk management, and safety oversight that authorities can reference in enforcement and subsequent implementing rules.Regulating AI and Strengthening Legal Liability – EU IP Helpdesk Cybersecurity Law of the PRC – CSET translation
2. Increased Fines and Legal Liability
- Higher maximum administrative fines (up to RMB 50 million or 5% of turnover for certain violations): The amendment increases penalties for serious cybersecurity violations, bringing the CSL closer to the Personal Information Protection Law (PIPL) penalty framework (percentage of turnover for serious violations).China: Amended Cybersecurity Law Takes Effect – Library of Congress China's Cybersecurity Law Amendment – Fangda Partners China’s Cybersecurity Law Amendments Increase Penalties, Broaden Extraterritorial Enforcement – Latham & Watkins
- Expanded scope of “serious circumstances” and cumulative penalties: Commentaries highlight that amended provisions broaden the notion of “serious circumstances” and allow for higher fines and stricter corrective orders, including business suspension and revocation of business licenses.China's Cybersecurity Law Amendment – Fangda Partners China Finalises Amendments to the Cybersecurity Law – Mayer Brown Strictest Amendment to China's Cybersecurity Law In Effect – Haynes Boone
- Alignment with other data/cyber laws (PIPL, Data Security Law): The amendment’s penalty structure and enforcement mechanisms are explicitly designed to align the CSL with the PIPL and DSL, reducing gaps and harmonizing sanctions.China's Cybersecurity Law Amendment – Fangda Partners Regulating AI and Strengthening Legal Liability – EU IP Helpdesk China’s Cybersecurity Law Amendments Increase Penalties, Broaden Extraterritorial Enforcement – Latham & Watkins
Note: Public English-law firm summaries indicate fines up to RMB 50 million or 5% of turnover for certain violations; that exact figure should be checked against the official NPCSC text in Chinese.Decision of the NPCSC to Amend the Cybersecurity Law (LawInfoChina) China’s Cybersecurity Law Amendments – Latham & Watkins
3. Broadened Extraterritorial Application
- Explicit extraterritorial reach over conduct harming Chinese network security: The amendments expand the extraterritorial effect of the CSL, allowing enforcement against overseas network operators whose activities harm China’s network security or the rights and interests of Chinese citizens.China: Amended Cybersecurity Law Takes Effect – Library of Congress China’s Cybersecurity Law Amendments Increase Penalties, Broaden Extraterritorial Enforcement – Latham & Watkins China Finalises Amendments to the Cybersecurity Law – Mayer Brown
- Coverage of foreign operators offering services to Chinese users or affecting Chinese networks: Commentaries explain that foreign entities providing network products or services in China, or processing data that impacts Chinese network security, may fall under CSL jurisdiction even without a physical presence.Strictest Amendment to China's Cybersecurity Law In Effect – Haynes Boone China’s Cybersecurity Law Amendments – Latham & Watkins China's Cybersecurity Law Amendment – Fangda Partners
4. Reinforced Core Cybersecurity Obligations (Existing CSL + Amendments)
- Network operators’ security obligations: The 2016 CSL imposes obligations on “network operators” to take technical and organizational measures to safeguard network operations and data security, which remain in force and are reinforced by increased penalties.Cybersecurity Law of the PRC – CSET translation Cybersecurity Law (original Chinese text) – NPC
- Critical Information Infrastructure (CII) operators: CII operators must comply with heightened cybersecurity requirements, including security assessments and data localization for certain data, with the amendments tightening enforcement.Cybersecurity Law of the PRC – CSET translation China Finalises Amendments to the Cybersecurity Law – Mayer Brown
- Coordination with sectoral regulations: The amendment emphasizes coordination and alignment between the CSL and other laws/regulations on cybersecurity and data compliance.China approves amendment to cybersecurity law – Xinhua China's Cybersecurity Law Amendment – Fangda Partners
Compliance Challenges
1. Interpreting AI Governance Obligations
- Ambiguous operationalization of AI ethics and risk assessment: Article 20 sets high-level goals for AI ethics and risk monitoring rather than detailed technical rules, creating uncertainty for organizations about what constitutes adequate AI risk assessment and ethical governance.Decision of the NPCSC to Amend the Cybersecurity Law (LawInfoChina) Key Revisions and Compliance Recommendations of the PRC Cybersecurity Law – Bird & Bird Regulating AI and Strengthening Legal Liability – EU IP Helpdesk
- Integrating CSL AI obligations with existing AI rules: Organizations must reconcile the CSL Article 20 framework with China’s existing AI-related regulations (e.g., algorithm recommendation rules, generative AI measures), leading to overlapping requirements.Cybersecurity Law of the PRC – CSET translation Regulating AI and Strengthening Legal Liability – EU IP Helpdesk
2. Managing Higher Penalty Exposure
- Risk of multi-law enforcement (CSL, PIPL, DSL) for single incidents: Legal analyses warn that a single cybersecurity or data incident may now trigger parallel investigations under CSL, PIPL, and DSL, increasing overall penalty risk.China's Cybersecurity Law Amendment – Fangda Partners China Finalises Amendments to the Cybersecurity Law – Mayer Brown
- Challenges for global firms in determining “serious circumstances”: Because the determination of “serious circumstances” can be fact‑specific, global firms often struggle to predict enforcement exposure, especially when operating cross‑border cloud or AI services.Strictest Amendment to China's Cybersecurity Law In Effect – Haynes Boone China’s Cybersecurity Law Amendments – Latham & Watkins
3. Extraterritorial Compliance for Foreign Operators
- Determining when overseas operations “harm” Chinese networks: Foreign companies must assess whether their global infrastructure or AI systems could be deemed to harm Chinese network security or the rights of Chinese users, which is not precisely defined.China: Amended Cybersecurity Law Takes Effect – Library of Congress China’s Cybersecurity Law Amendments – Latham & Watkins
- Complex cross‑border data and network architecture: Global companies operating distributed cloud and AI pipelines face difficulty mapping which nodes, data flows, and AI training environments fall within CSL extraterritorial scope.Strictest Amendment to China's Cybersecurity Law In Effect – Haynes Boone China Finalises Amendments to the Cybersecurity Law – Mayer Brown
4. Harmonizing CSL with Internal Governance Structures
- Aligning CSL AI risk management with enterprise AI governance frameworks: Companies that already follow global AI governance frameworks (e.g., NIST AI RMF, ISO/IEC AI guidelines) must tailor them to address CSL‑specific requirements on ethics norms and risk monitoring.Cybersecurity Law of the PRC – CSET translation Key Revisions and Compliance Recommendations of the PRC Cybersecurity Law – Bird & Bird
Implementation Best Practices
1. Establish a CSL‑Aligned AI Governance Framework
- Create an AI ethics and risk committee covering China operations: Organizations should set up cross‑functional AI governance committees specifically tasked with ensuring compliance with Article 20’s ethics, risk monitoring, and safety supervision requirements.[Decision of the NPCSC to Amend the Cybersecurity Law (LawInfoChina)](https://www.lawinfochina.com/display.aspx?lib=
Recent developments
- — Overview of the **2025 amendments** to China’s Cybersecurity Law, noting the NPC Standing Committee’s 28 October 2025 decision and the **effective date of 2026-01-01**, and summarizing how the law is now supplemented by detailed subordinate regulations and standards.[12] (source)
- — Analytical report on the **2025 amendments**, highlighting new language on **state support for AI**, use of AI to bolster cybersecurity defenses, and requirements to improve the security of AI systems themselves, situating the changes within China’s broader cyber and AI governance strategy.[9] (source)
- — Annual review of **China data protection and cybersecurity developments**, emphasizing the 28 October 2025 decision amending the Cybersecurity Law, and discussing expected **enforcement trends and compliance priorities for 2026** across the cybersecurity industry.[14] (source)
- — Alert describing the 2025 amendment as the **“strictest” version** of China’s Cybersecurity Law now in force, stressing significantly **increased fines and enforcement risks** for both critical information infrastructure operators and ordinary businesses, and warning of heightened regulatory scrutiny for cybersecurity incidents.[5] (source)
- — Client alert on China’s **Amended Cybersecurity Law** taking effect on 1 January 2026, detailing the **expanded extraterritorial enforcement powers**, clarified penalty framework for different obligations, and references to policy goals for **AI governance**, with an emphasis on risks for multinational cyber and tech operators.[2] (source)
- — Detailed note on “**Key updates on the amended cybersecurity law of China**,” explaining the **new tiered penalty regime**, stricter fines for material cybersecurity violations, expanded regulatory powers, and the practical compliance implications for network operators and critical infrastructure providers.[1] (source)
- — Analysis of **key revisions** and **compliance recommendations**, outlining the comprehensive revision that took effect on 1 January 2026, summarizing major changes (higher penalties, clarified obligations, extraterritorial reach) and offering **industry-focused guidance** on how companies should update cybersecurity programs.[6] (source)
- — Insight piece on how the **2025 amendments increase penalties and broaden extraterritorial enforcement**, explaining that overseas activities endangering PRC cybersecurity can now be targeted, and assessing the **impact on foreign cybersecurity, cloud, and tech service providers** operating or serving customers in China.[4] (source)
- — Legal monitor note announcing that the **amended Cybersecurity Law came into force on 2026-01-01**, summarizing the 14-article amendment: stronger support for AI development, **higher fines** (up to RMB 10 million for especially grave CIIO violations), and expanded **extraterritorial effect** of the law.[10] (source)
- — Official-style in‑depth article on the NPC Standing Committee’s approval of the amendment to the Cybersecurity Law, describing the added article on **safe and sound AI development**, priority areas for AI (research, infrastructure, ethics), and strengthened **AI safety risk monitoring and regulation**, signaling strategic direction for the cybersecurity and AI industries.[13] (source)
Related regulations
- China Measures for Labeling AI-Generated Content — China, Active, effective 2025-09-01
- NYDFS Cybersecurity Regulation — New York, Active, effective 2025-11-01
- Law on Cybersecurity of Vietnam — Vietnam, Active
- Austria NIS2 Act — Austria, Upcoming
- Luxembourg NIS2 Transposition — Luxembourg, Active
- EU Cyber Resilience Act (CRA) — European Union, Phased, effective 2027-12-11
- EU Cyber Resilience Act - Vulnerability and Incident Reporting (11 Sep 2026) — European Union, Active, effective 2026-09-11
- Netherlands NIS2 Transposition (Cyberbeveiligingswet) — Netherlands, Active, effective 2026-08-15
Put it into practice
- Generate the policy: China PIPL policy generator (generatepolicy.com)
- Buy the policy pack: Privacy Program Bundle (cyberpolicy.shop)
- Build it yourself: GDPR & DPIA Compliance Workbook (ciso.diy)
Browse all regulations · Compliance deadlines · Latest updates