AI Policy Wiki
Dashboard

China — Internet Information Service Algorithmic Recommendation Management Provisions

high confidence · updated 2026-06-06

China's foundational regulation for algorithmic recommendation systems in internet services. The first layer of China's three-part AI regulatory stack.

The Internet Information Service Algorithmic Recommendation Management Provisions (互联网信息服务算法推荐管理规定) are a Chinese regulation governing the use of algorithmic recommendation technology in internet information services. Promulgated on 2021-12-31 and effective 2022-03-01, the Provisions establish an algorithm filing regime, a security-assessment requirement, content-orientation obligations, and a set of user rights covering personalization opt-out, minors, the elderly, gig workers, and price discrimination. They are the earliest of three Chinese AI-related regulations whose filing and security-assessment machinery later regulations reuse, alongside the China — Provisions on the Administration of Deep Synthesis Internet Information Services (2023-01-10) and the China — Interim Measures for the Management of Generative AI Services (2023-08-15).

Full title: Internet Information Service Algorithmic Recommendation Management Provisions (互联网信息服务算法推荐管理规定) Enacting body: Cyberspace Administration of China (CAC) together with MIIT, Ministry of Public Security, and SAMR (Joint Order No. 9). Promulgated: 2021-12-31 Effective: 2022-03-01

Scope and definitions

The Provisions apply to the use of algorithmic recommendation technology to provide internet information services within mainland China. The definition is broad, covering generative and synthetic algorithms, personalized recommendation, ranking and selection, search filtering, and dispatching and decision-making.

Key provisions

Governance (Arts. 3–5)

CAC holds overall coordination; MIIT, MPS, and SAMR share domain-specific authority. Industry self-discipline is encouraged.

Information service norms (Arts. 6–15)

Providers must uphold "mainstream value orientations" and "positive energy" (Art. 6). The provider bears primary responsibility for algorithmic security and must establish management systems for algorithm review, ethics review, user registration, security assessment, data security, and fraud prevention (Art. 7). Algorithm models that lead users to addiction or excessive consumption are barred (Art. 8), and algorithmically generated or synthetic content must be labeled before dissemination (Art. 9). Entering unlawful or harmful information into user tags or interest keywords is prohibited (Art. 10), and providers must present "mainstream value" content prominently on front pages, hot-search, and pop-ups (Art. 11).

Internet news information services require a permit, with no algorithmic generation of fake news and no dissemination of news outside state-determined sources (Art. 13). Providers may not use fake accounts, manipulated likes, comments, or reshares, rank manipulation, or hot-search control (Art. 14). Monopolistic acts and unfair competition via algorithms are barred under SAMR authority (Art. 15).

User rights (Arts. 16–22)

Providers must disclose the basic principles, purposes, and main operational mechanisms of their algorithms (Art. 16). Users have an opt-out right from personalized recommendation, including choice and deletion of user tags (Art. 17). The Provisions establish protections for minors against addiction-inducing pushes and harmful content (Art. 18) and for the elderly through anti-fraud monitoring and accessible services (Art. 19). Algorithms governing dispatch, pay, and rest time for gig workers must respect labor rights (Art. 20). Algorithmic price discrimination is barred under consumer fair-trading rights (Art. 21), and providers must offer complaint and reporting portals (Art. 22).

Supervision (Arts. 23–30)

A graded-categorized algorithm security management system scales regulatory intensity with public-opinion properties, social-mobilization capacity, content category, user scale, data sensitivity, and degree of user-behavior interference (Art. 23). Providers with public-opinion or social-mobilization capacity must complete algorithm filing within 10 working days via the Internet information service algorithm filing system, supplying provider name, service form, domain, algorithm type, a self-assessment report, and intended public content; modifications and cancellations follow 10- and 20-working-day cycles (Art. 24). Regulators respond within 30 working days (Art. 25). The filing number must be displayed on the provider's website or app (Art. 26), and a security assessment is required for covered providers (Art. 27).

Liability (Arts. 31–33)

Penalties include fines of 10,000–100,000 yuan, suspension of information updates, and filing cancellation for grave violations, with referral to public-order or criminal authorities where applicable.

Role in China's AI regulatory stack

The filing regime (Art. 24), the public-opinion-properties and social-mobilization-capacity trigger (Art. 23), and the security-assessment requirement (Art. 27) established here are reused by the China — Provisions on the Administration of Deep Synthesis Internet Information Services (Art. 19 cross-reference) and the China — Interim Measures for the Management of Generative AI Services (Art. 17 cross-reference). Combined, the three instruments form a layered sequence: general algorithmic governance in 2022, synthetic-media specifics in 2023, and generative-AI specifics in 2023, each layer reusing the filing and security-assessment machinery established in these Provisions. This architecture differs from the EU's single horizontal Act and from the voluntary and sectoral approach in the United States.

Comparison with other approaches

DimensionChina Algo RecommendEU AI Act (Regulation 2024/1689)[[us-aisi-strategic-visionUS AISI]]Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment)
Scope triggerAlgorithmic recommendation + "public opinion / social mobilization"Risk tier (unacceptable/high/limited/minimal)Voluntary frontier-lab participation"High-risk AI" in consequential decisions
Ex-ante filingYes (mandatory)No (high-risk conformity assessment instead)NoNo
Content-orientationHeavy (mainstream values, no fake news)Limited (transparency)NoneNone
Opt-out of personalizationYes (Art. 17)Partial (via GDPR/DSA interactions)NoConsumer notices only
Price discriminationBarred (Art. 21)Not directly addressedNot addressedNot directly
Gig-worker protectionsYes (Art. 20)NoNoNo
Fake-news generationBarred (Art. 13)Transparency labelsNoNo

Analysis

The consumer-protection provisions — personalization opt-out (Art. 17), gig-worker labor protections (Art. 20), the bar on price discrimination (Art. 21), and the bar on algorithmic monopolistic conduct (Art. 15) — in several respects extend further than comparable Western consumer-AI laws, while sitting alongside content-control provisions with no Western analogue. The filing system (Art. 24) gives the state a detailed register of deployed algorithmic systems, a form of ex-ante regulatory visibility not present in current Western regimes. The content-values requirements in Arts. 6, 11, and 13 are difficult to reconcile with US First Amendment norms (see AI and the First Amendment).

Between the draft and final texts, the explicit prohibition on "discriminatory or biased user tags" was removed from Art. 10, while elderly protections (Art. 19) and the fake-news licensing requirement (Art. 13) were added, and SAMR's antitrust interest (Art. 15) was strengthened. The translator characterizes these shifts as signals of bureaucratic balance of power among the enacting bodies.

Relationships