AI Policy Wiki
Dashboard

Cyberspace Administration of China (CAC)

high confidence · updated 2026-07-07

Chinese central-government regulator for internet and cyber affairs; lead author and enforcer of China's AI regulatory stack.

国家互联网信息办公室 / 国家网信办. The Cyberspace Administration of China is the central-government body with overall responsibility for internet governance, cybersecurity, data, and online content in the People's Republic of China. It is the lead drafter and enforcement coordinator for China's layered AI regulatory stack.

Overview

CAC holds primary coordination authority over China's AI rules, sharing domain-specific powers with MIIT, the Ministry of Public Security, SAMR, NDRC, and others. Three stacked regulations together form China's operating AI regulatory regime:

  1. China — Internet Information Service Algorithmic Recommendation Management Provisions (2022-03-01) — general algorithmic governance; establishes the core algorithm filing regime and the "public opinion properties or social mobilization capacity" trigger.
  2. China — Provisions on the Administration of Deep Synthesis Internet Information Services (2023-01-10) — synthetic-media specific obligations (real-name verification, biometric consent, dual-tier labeling). Reuses the filing regime from (1).
  3. China — Interim Measures for the Management of Generative AI Services (2023-08-15) — capability-specific generative AI rules. Reuses filing from (1) and labeling from (2).

The filing system ("Internet information service algorithm filing") operated by CAC ties the stack together: any service deemed to have public-opinion properties or social-mobilization capacity must file within 10 working days, submit a self-assessment, and pass security assessment.

On July 3, 2026, CAC proposed a comprehensive revision of China's foundational internet information services rules, expanding the regulation from 27 to 94 articles and consolidating obligations covering recommendation algorithms, generative AI, and livestreaming into a single framework; public comments were open until August 2, 2026 (Source: mlex.com). The proposal would fold the stacked instruments above into one unified regime.

Regulatory posture

The rules are built on top of the Cybersecurity Law, Data Security Law, and Personal Information Protection Law (PIPL). Providers are treated as "producers of online information content" and are legally liable for model outputs.

All services must uphold Core Socialist Values and prohibit content "inciting subversion," "endangering national unity," "promoting ethnic hatred," and similar categories. Regulatory intensity follows a graded-categorized management approach, scaling with a service's public-opinion reach. Non-compliant services provided from outside mainland PRC may be subject to technical measures under Article 20 of the Generative AI Interim Measures.

Enforcement campaigns

On April 30, 2026, CAC launched a four-month campaign titled Clean Up the Internet: Rectifying the Chaos in AI Applications, targeting unregistered AI models (services that bypassed the filing regime), AI data poisoning (training-data manipulation by adversaries), and improper synthetic-content labeling (failures to comply with the deep-synthesis provisions). The campaign is the operational follow-on to the CAC Rectifying the Chaos 2026 regulatory document, with enforcement emphasis on provenance and labeling. (Source: cac.gov.cn) See also Synthetic Media / Deepfakes and Distillation (data-poisoning context).

Co-regulators

  • MIIT (Ministry of Industry and Information Technology) — telecommunications and industrial aspects.
  • MPS (Ministry of Public Security) — public security and criminal enforcement.
  • SAMR (State Administration for Market Regulation) — antitrust and consumer protection.
  • MoST, MoE, NRTA (generative AI interim measures co-issuers) — sector-specific oversight of science, education, and broadcast.

Relationships