Making Sense of China’s AI Regulations
AI Regulations

Making Sense of China’s AI Regulations

August 22, 2023

Key Takeaways

  • Worth $23.196 billion USD in 2021, China’s Artificial Intelligence (AI) market is expected to triple to $61.855 billion by 2025.
  • Deep Synthesis Provisions: to strengthen its supervision over ‘deep fake’ technologies and services, these provisions will significantly change how AI-generated content is produced for 1.4 billion people due to their comprehensive scope.
  • Internet Information Service Algorithmic Recommendation Management Provisions: considered parallel to the EU’s enacted Digital Markets Act (DMA) and Digital Services Act (DSA), the aim of this is to address monopolistic behaviour by platforms and require that providers of AI-based personalised recommendations in mobile applications uphold user rights.
  • There is contention as to whether China’s agile approach to AI regulation is rooted in a power play or a genuine effort to curb the harms associated with the development and deployment of AI systems.
  • China’s Algorithmic Registry includes a security assessment of registered algorithms, however, the extent to which this registry will be able to provide meaningful insight into black box technologies is yet to be determined.
  • With China seemingly ahead of the curve, it will be interesting to see how others may borrow from its precedent, how East-West relations on AI continue to converge, and who will set the gold AI standard in the East.
EU and China Timeline

Worth $23.196 billion USD in 2021, China’s Artificial Intelligence (AI) market is expected to triple to $61.855 billion by 2025 and the Chinese government expects for AI to create $154.638 billion USD in annual revenue by 2030. China, however, is not just focused on the proliferation of AI and its innovative use cases; the country has also been silently leading the pack and making its mark on the AI regulatory landscape. In 2022, China passed and enforced three distinct regulatory measures on the national, regional and local levels. This momentum has carried into 2023, where in January alone, China has already cracked down on deepfake technology through a national level legislation.

In this blog, we survey China’s AI regulatory endeavours, highlighting interesting enforcement mechanisms and comment on wider implications for AI governance best practises on a global scale.

China's national level AI regulation

In the last year alone, China has enforced two major pieces of national regulation. Focusing on digital platforms and AI generated content such as deep fakes, the Chinese government is paving the way to have a stronghold on the harms associated with AI and associated technologies.

While there is concern about the implications of China’s far-reaching regulations and their potential to hamper free speech, it would be imprecise to fully negate the important precedent and best practices these laws are setting. It is also significant to note the impact of these regulations on international firms which employ these technologies in China, as they will be expected to already be complying. This section looks at national level initiatives in the AI regulatory space.

China’s Deep Synthesis Provisions

On 10 January 2023, China’s Deep Synthesis Provisions came into effect as part of the Chinese government’s efforts to strengthen its supervision over deep synthesis technologies and services. The provisions apply to both ‘deep synthesis service providers’ –companies that offer deep synthesis services and those that provide them with technical support – and ‘deep synthesis service users’ –organisations and people that utilise deep synthesis to create, duplicate, publish or transfer information.  The provisions define deep synthesis as “technology utilising generative and/or synthetic algorithms, such as deep learning and virtual reality, to produce text, graphics, audio, video, or virtual scenes.”

The provisions are centred on four key verticals:

Four Key Verticals

Ultimately, these provisions will significantly change the way that AI-generated content is produced for 1.4 billion people due to their comprehensive scope. While the UK is also intending to ban the creation and dissemination of deepfake videos without consent, China’s law goes beyond this. The regulation creates rules for every stage of the process involved in the use of deepfakes, from creation to labelling to dissemination, leaving room for the potential suppression of organically captured content as well.

There are speculations as to whether China will use this law as a means of further policing the freedom of expression too broadly, however as one of the first countries to enforce a deepfake regulation, conversations are re-igniting about what can be done to address the harms espoused by this technology. Thus, with the potential to influence the development of deepfake regulation in other jurisdictions, this year will provide the opportunity to see how exactly these provisions are enforced.

Internet Information Service Algorithmic Recommendation Management Provisions

Considered parallel to the EU’s enacted DMA and DSA, on 1 March 2022, the Internet Information Service Algorithmic Recommendation Management Provisions went into effect. Drafted by the Cyberspace Administration of China, the provisions require that providers of AI-based personalised recommendations in mobile applications uphold user rights, including protecting minors from harm and allowing users to select or delete tags about their personal characteristics.

For example, companies are banned from offering different users different prices based on personal characteristics collected and would have to notify users if a recommendation was made based on an algorithm, giving users the option to opt out.  The aim of this is to address monopolistic behaviour by platforms (similar to the DMA) and issues of dynamic pricing which contribute to precarious working conditions for delivery workers.

The regulation’s provisions are grouped into three main categories: general provisions, information service norms and user rights protection. The provisions affect US and international companies that use algorithms and/or machine learning in their applications or websites which operate in China, as they are already expected to comply.

Key provisions:

  • Article 13 prohibits the algorithmic generation of fake news and requires that online service providers that also operate in online news seek special licensing.
  • Article 19 offers special protection to the elderly by requiring online service providers to address the needs of older users, specifically in the context of fraud prevention.

Among many things, the regulation prohibits:

  • Fake accounts
  • Manipulating traffic numbers
  • Promoting addictive content

Other not-so-straightforward provisions that are presumed to be reflective of China’s approach to AI ethics in practice, orders companies to:

  • Uphold mainstream value
  • Vigorously disseminate positive energy
  • Prevent or reduce controversies or disputes

Like the DSA, China’s recommender law also mandates increased transparency and audits of recommendation algorithms. To learn how algorithms work, and ensure that they do so within acceptable parameters, China has created an algorithm registry as part of this regulation. The registry includes a security assessment of registered algorithms, however, the extent to which this registry will be able to provide meaningful insight into black box technologies is yet to be determined. In the interim, such efforts for documentation and understanding are similar to that of the DSA and other EU legislation such as the EU AI Act.

Personal Information Protection Law

China’s Personal Information Protection Law (PIPL) is a federal data privacy law targeted at personal information protection and addressing the problems with personal data leakage. Adopted on 20 August 2021 and filed into force on 1 November 2021, the PIPL is designed to protect the privacy and personal information of Chinese citizens and imposes obligations on Chinese organisations and foreign companies operating in China.

The law defines the term “personal information” (PI) as any kind of information, electronically or otherwise recorded, related to an identified or identifiable natural person within the People’s Republic of China. Like the EU’s GDPR, PI excludes anonymised information that cannot be used to identify a specific natural person and is not reversible after anonymisation. Among the main contributions of the PIPL are as follows, with specific requirements in relation to automated decision making and impact assessments:

  • Data subjects are given more rights over the use of their own data. They can request to edit, remove, restrict the use of their data, or withdraw consent given previously.
  • More stringent requirements on data sharing and data transfer, which your organization and any third-party joint data controllers may need to pass data related assessments.
  • Mandatory security controls to be applied when storing and processing the PI and training to be provided to responsible personnel who handles the PI.
  • Mandatory data localisation when the amount of PI exceeds the threshold set by the Cybersecurity Administration of China (CAC).
Personal Information Protection Law

These requirements are applicable to organisations and individuals involved in the processing of personal information in China, or outside of China if any of the following conditions are fulfilled:

  • Personal information is processed for the purpose of providing products or services to natural persons in China;
  • Personal information is used when analysing and assessing the behaviour of natural persons in China; or
  • Other circumstances stipulated by laws and administrative regulations.

Exemptions from the Law include natural persons’ processing of personal information for the purposes of personal or family affairs. This includes emergency circumstances to protect natural persons’ lives, health, or security and that of their property.  Outside of these exemptions, personal information handlers that fail to comply with the requirements of the PIPL face penalties of us to 50 million RMB, revenue confiscation (up to 5% annual revenue) and business cessation.

In the context of AI regulation, the PIPL is significant to mention as there is no AI without data. Similar to how recent cases are highlighting that the GDPR applies to AI in the EU, the PIPL does as well. This is seen clearly in China’s deepfake regulation, where provisions of this law state that entities which use deepfakes must be in abidance with existing PIPL laws.

New Generation AI Ethics Specification

In addition to these laws, on 25 September 2021, China’s Ministry of Science and Technology published a New Generation Artificial Intelligence Code of Ethics. Released by the National New Generation Artificial Intelligence Governance Professional Committee, which was established by China’s Ministry of Science and Technology to research policy recommendations for AI governance, the Ethics Code covers the entire life cycle of AI and provides guidance for natural and legal persons, as well as other relevant institutions.

The main contributions of the general provisions of the Specification are:

  • Improvement of human well-being: AI systems should follow common values, respect human rights and the fundamental interests of society, promote harmony, improve livelihoods, and take a sustainable approach to economic, social, and ecological development.
  • Promotion of fairness and justice: AI systems should be inclusive and effectively protect the rights and interests of those that interact with the system while sharing the benefits of AI across society to promote fairness, justice, and equal opportunities. Vulnerable groups should be respected, and accommodations should be provided where necessary.
  • Protection of privacy and security: AI systems should respect the privacy of users and ensure that consent is obtained to process personal information. Personal privacy should be protected and obtained legally, and data should be handled securely.

As seen above, the general provisions of the Specification are centred around the verticals of safety, privacy, and fairness, with management standards being encouraged to focus on the appropriate governance and exercises of power to prevent AI risks. Additionally, the Specification outlines R&D specifications concerning data storage and use, with a focus on security provisions and fairness, and supply specifications that focus on following market regulations and ensuring there are emergency provisions in place. Further, the organisation and implementation provisions encourage organisational management to build on the Ethics Code and develop guidelines that are in line with the specifications of the systems they are using.

China’s AI regulation vs other jurisdictions

In April 2023, China's internet regulator penned another set of draft regulations focusing on Generative AI. If approved, developers would be mandated to undergo a security evaluation before their AI systems go live. The proposed legislation would also compel businesses to ensure that their product's output aligns with Chinese socialist principles.

Some commentators have suggested that the draft bill goes further than, for example, the EU's AI Act in terms of its emphasis on data protection and intellectual property. The bill would prevent developers from training their AI systems using copyrighted content altogether, whereas the EU AI Act only requires developers to disclose the use of copyrighted training data.

It was confirmed in June 2023 that there are also designs to introduce another new state-wide AI law, although at this stage there are no specific details of the substance of the would-be legislation, which will be reviewed by the Chinese legislature before the end of the year.

Provincial and local level regulation

Efforts towards AI regulation are not just concentrated from the central government, but from provincial and local levels as well. Focused on the intersection of innovation and regulation, regional level regulation allows for a balancing act between stringent national level regulation and fostering best practises for promoting the development of AI in industry and government. This section looks at provincial and local AI regulations in Shanghai and the Shenzhen Special Economic Zone, respectively.

Shanghai Regulations on Promoting the Development of the AI Industry

The Shanghai Regulations to promote the development of the AI industry, is a provincial-level regulation which was passed in September 2022 and has been in effect since 1 October 2022. The regulation is considered a piece of industry promotion legislation, with respect to the innovative development of AI. However, keeping in mind future implications of AI, the regulation introduces a graded management system and enforces sandbox supervision, where companies are given a designated space to test and explore technologies.

Uniquely, the Shanghai AI Regulation stipulates that there is a certain degree of flexibility regarding minor infractions. This is to continue to encourage the development of AI without burdening companies or developers with the fear of stringent regulation and instead shows a deeper commitment to fostering innovation. This is done so through a disclaimer clause where relevant municipal departments will oversee creating a list of infraction behaviours and making it clear that there will be no administrative penalty for minor infractions. To create checks and balances to the innovation-centric approach, the regulation also establishes an Ethics Council to increase ethical awareness in this field.

Regulations on Promoting Artificial Intelligence Industry in Shenzhen Special Economic Zone

Similar to the Shanghai Regulations, a Shenzhen AI Regulation to promote the AI industry was passed in September 2022 and went into effect on November 1, 2022. The regulation aims to encourage governmental organisations in China, specifically in the Shenzhen Special Economic Zone, to be at the forefront of AI adoption and development, by increasing financial support for these endeavours.

A risk-management approach towards AI is adopted by the regulation to foster this growth by allowing Shenzhen-based AI services and products that have been assessed as “low-risk” to continue in their trials and testing even without local norms if international standards are being complied with. Article 72 of the regulation emphasises the importance of AI ethics and encourages risk assessments to identify adverse effects of products and systems. The Shenzhen government will be responsible for the development and management of the risk classification system.

Despite being a local-level regulation, this is a significant development as Shenzhen is home to many AI and tech-related businesses, where an estimated $108 billion USD will be invested into this space from 2021 to 2025.

China AI legislation: global and local impact

A swathe of Generative AI products – including Baidu's ChatGPT-like service Ernie Bot – have been launched in China since the state accelerated the introduction of AI regulation.

Regarding China’s AI regulations in 2023, th legislative agenda does not appear to have stifled innovation, with China still pursuing its stated mission of becoming a global leader in AI by 2030. Most academics agree that, while the United States still leads the AI race, China is rapidly closing the gap.

In June 2023, OpenAI CEO Sam Altman called for collaboration between US and Chinese AI researchers, raising questions about how the countries' respective regulatory landscapes would facilitate such cooperation.

China’s AI regulations: balancing power and mitigating harms?

There is contention as to whether China’s agile approach to AI regulation is rooted in a power play or a genuine effort to curb the harms associated with the development and deployment of AI systems. One view is that China has taken note of how regulations are becoming a way to set global norms and standards. Wanting to set that precedent itself, China has been involved in some of the earliest enforcement of AI regulation in the world.

However, such a black-and-white view of China’s motivations in the AI regulatory space would be misaligned. There is no doubt that China’s efforts are motivated by a desire to set global standards, but this is integrated with a multi-pronged approached which seeks to regulate AI harms, and to understand, rather than just document, “high-risk” algorithms. For example, where focus has been placed on bias and transparency in other parts of the world, similar to the aims of the DSA, China is also focusing on the technical implications of digital services. Doing so by attempting to delve into the complexity of recommender systems and black box technology through their algorithmic registry, making a head start.

With China seemingly ahead of the curve, it will be interesting to see how others may borrow from its precedent, how East-West relations on AI continue to converge, and who will set the gold AI standard in the East.

To find out how Holistic AI can help you get ahead of the upcoming AI regulations, get in touch at

FAQs related to China AI regulations 2023

What is the AI guidance in China?

The Chinese authorities have published multiple guidance documents regarding AI, among which is the National Artificial Intelligence Development Plan (2017-2030). This plan outlines the nation's objectives for AI progression, highlighting the importance of utilising AI for societal good and advocating for the establishment of ethical AI guidelines. This guidance has since been followed up with a number of concrete regulations, some of which are enforced already and others which are still in the legislative pipeline.

Are there any AI regulations in China?

A number of regulations have been handed down by the Chinese government. China's AI policy spans a number of key areas, including national laws, local rules, ethics, industry growth, user rights, and transparency. China's generative AI regulations meanwhile, which were enforced in August 2023, include requirements for service operators to register and undergo privacy, copyright, and security reviews.

Is China taking the lead in AI?

China is making significant investments in AI research and development. Although many experts argue that they still trail the United States by some distance, it has also been suggested that China has taken the lead in some areas such as facial recognition systems.

What year will China lead the world in AI?

Opinion among academics and industry analysts differs as to whether China will in fact lead the world in AI, but their stated aim is to become a global leader by 2030.

Authored by Ashyana-Jasmine Kachra, Public Policy Associate at Holistic AI.

DISCLAIMER: This blog article is for informational purposes only. This blog article is not intended to, and does not, provide legal advice or a legal opinion. It is not a do-it-yourself guide to resolving legal issues or handling litigation. This blog article is not a substitute for experienced legal counsel and does not provide legal advice regarding any situation or employer.

Manage risks. Embrace AI.

Our AI Governance, Risk and Compliance platform empowers your enterprise to confidently embrace AI

Get Started