The generative-AI gauntlet: measures, standards, enforcement
Lesson 4 of 5 in China: The World’s Most Developed Binding AI Rulebook.
China answered ChatGPT faster than any other jurisdiction. The Interim Measures for the Management of Generative AI Services were issued in July 2023 and took effect on 15 August 2023 — the first binding, dedicated generative-AI regulation in the world, in force while the EU was still negotiating its GPAI chapter.
The word Interim (暂行) is doing real work: it signals rules meant to be revised as the technology and the state’s understanding evolve — the iterative philosophy in a single word. So is the scope line: the measures govern services offered to the public in mainland China, and expressly exempt organisations developing or using generative AI internally without offering it to the public. Industrial policy shows here too — the final text is notably softer than the ferocious April 2023 draft, dropping demands like ensuring all training data is “true and accurate” after industry pushback.
For a public-facing service, the substantive duties stack up like this:
- Content: uphold core socialist values; do not generate content endangering national security, promoting terrorism, violence, or obscenity; take measures against discriminatory outputs.
- Training data: use data and foundation models from lawful sources; respect intellectual-property rights; obtain consent where personal information is involved; improve data quality, authenticity, accuracy, objectivity, and diversity.
- Labeling: mark generated content per the deep-synthesis rules — now operationalised by the 2025 Labeling Measures.
- Users: verify identities, handle complaints, prevent minors’ overuse and addiction, protect input data and usage records.
- Gatekeeping: services with public opinion attributes or social mobilization capability — the same trigger you met in the algorithm lesson — must pass a security assessment before launch and complete algorithm filing.
Penalties route through existing statutes (Cybersecurity Law, Data Security Law, PIPL): warnings, rectification orders, suspension, and — the sanction platforms fear most — removal from app stores.
Launching a public generative-AI service in China
- GenAI service ready for the Chinese market
- Public-facing?
The GenAI Measures govern services offered to the public in mainland China. Internal enterprise tools and pure R&D are exempt (though PIPL/DSL still apply).
- Ethics review (if in scope)
Under the 2023 Science & Technology Ethics Review Measures, research in sensitive areas — including algorithms with strong social-mobilisation potential — passes an ethics committee first.
- Training-data legality check
Lawful sources, IP respected, consent for personal information, documented data-quality measures (GenAI Measures Art 7).
- Security assessment (TC260 benchmark)
For services with public opinion attributes or social mobilization capability: pre-launch assessment tested against the Basic Security Requirements — prompt banks, refusal rates, output thresholds.
- Algorithm filing with the CAC
File within the statutory window; the filing appears on the public registry. Large models effectively need this before public launch.
- Implement labeling
Explicit + implicit labels per the 2025 Labeling Measures and GB 45438-2025, across all output modalities.
- Launch
Ongoing duties continue: content moderation, complaint handling, minor protection, incident response.
- CAC oversight: rectification campaigns, spot checks
Non-compliance draws rectification orders, suspension of new-user registration, app-store removal, and fines under existing statutes.
- Exempt from the GenAI Measures
Internal/R&D use falls outside the service rules — but data-protection and ethics-review law still applies.
Enforcement is where China’s regime feels most different from anywhere else. The CAC runs periodic rectification campaigns (the Qinglang — “Clear and Bright” — series) sweeping platforms for unfiled algorithms, unlabeled synthetic content, and prohibited outputs. Consequences arrive fast and publicly: named-and-shamed rectification lists, suspension of new-user registration, and app-store removal — a de facto death sentence for a consumer product. The public filing registry doubles as an enforcement surface: if your model is not on the list, regulators and competitors alike can see it.
Alongside enforcement sits a maturing safety apparatus: the AI Safety Governance Framework (version 1.0 in September 2024, 2.0 in 2025) issued under TC260 maps risks to technical countermeasures, and Chinese institutions participate in the international safety-institute conversation on their own terms — China signed the Bletchley Declaration in 2023, and CNCERT/TC260-linked bodies function as its safety-institute equivalents.
Interactive sorting exercise: Which regulation imposes each obligation? Drag each duty to its source.
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.