The Interim Measures for the Management of Generative Artificial Intelligence Services (生成式人工智能服务管理暂行办法) are a Chinese administrative regulation governing the provision of generative AI services to the public in mainland China. Promulgated on 2023-07-10 and effective 2023-08-15, they form the capability-specific layer of China's AI regulatory stack, built on top of China — Internet Information Service Algorithmic Recommendation Management Provisions (a filing regime) and China — Provisions on the Administration of Deep Synthesis Internet Information Services (a labeling regime).
Enacting bodies: The measures were issued by the Cyberspace Administration of China (CAC) together with six other bodies:
- National Development and Reform Commission (NDRC)
- Ministry of Education
- Ministry of Science and Technology
- Ministry of Industry and Information Technology (MIIT)
- Ministry of Public Security (MPS)
- National Radio and Television Administration (NRTA)
Status and timeline
The measures were promulgated on 2023-07-10 and took effect on 2023-08-15. The "interim" label signals that more detailed rules are expected; as of June 2026 the stack had not been superseded by a final comprehensive AI law. Combined with the China — Internet Information Service Algorithmic Recommendation Management Provisions (2022) and the China — Provisions on the Administration of Deep Synthesis Internet Information Services (2023), the measures complete a layered Chinese AI regulatory stack that proceeds from general algorithmic governance to synthetic-media specifics to generative AI specifics. Each layer reuses the filing, labeling, and security-assessment machinery of the layers below it. Alongside the EU's horizontal AI Act and the United States' voluntary and sectoral approach, the stack constitutes a third distinct regulatory track in global AI governance.
Scope and definitions
The measures apply to the use of generative AI technology to provide services to the public in mainland China for the generation of text, images, audio, video, or other content (Art. 2). Two scope carveouts narrow that coverage:
- Sectoral deferral: Where other state provisions govern news and publishing, film and television, or artistic creation, those rules prevail.
- R&D exemption: Internal research and development by enterprises, research institutions, industry associations, and similar bodies that is not provided to the public is not covered. Pure training and internal testing therefore fall outside the measures.
Article 22 supplies definitions. Generative AI technology refers to models and technology able to generate text, image, audio, or video. A provider is an organization or individual providing generative AI services, including via programmable interfaces. A user is an organization or individual using generative AI services to generate content.
Key provisions
General (Arts. 1–4)
Article 3 states a principle of "equal emphasis on development and security" and "tolerant and cautious graded management by category," indicating that capability- and risk-tiered treatment is expected to evolve.
Article 4 sets content and conduct requirements. Providers must uphold Core Socialist Values and avoid content inciting subversion, separatism, terrorism, ethnic hatred, or "fake and harmful information." They must prevent discrimination on grounds of race, ethnicity, faith, nationality, region, sex, age, profession, and health across algorithm design, training-data selection, model generation and optimization, and service delivery. They must respect intellectual property and commercial ethics, avoiding algorithmic and data monopolies; respect the lawful rights of others, including image, reputation, honor, privacy, and personal information; and employ transparency measures while increasing the accuracy and reliability of generated content.
Development and technology (Arts. 5–8)
Article 5 encourages innovative application and supports industry and research collaboration. Article 6 encourages independent innovation in algorithms, frameworks, chips, and software platforms, promotes shared training-data infrastructure, and encourages "safe and reliable" chips, software, tools, compute, and data, reflecting an industrial-policy and tech-sovereignty dimension that runs alongside the pressure of Export Controls (AI).
Article 7 sets training-data obligations. Providers must use lawful-source data and foundational models; not infringe intellectual property; obtain personal-information consent or rely on lawful exceptions; employ effective measures to increase the truth, accuracy, objectivity, and diversity of training data; and comply with the Cybersecurity Law, Data Security Law, Personal Information Protection Law (PIPL), and department requirements. Article 8 sets manual-tagging rules covering clear tagging procedures, quality assessment, spot checks, and personnel training.
Service specifications (Arts. 9–15)
Article 9 makes providers bear responsibility as producers of online information content and as personal information handlers, and requires service agreements with users. Article 10 requires disclosure of user groups, occasions, and uses, and measures to prevent minor overreliance and addiction. Article 11 imposes confidentiality obligations, prohibits illegal retention of user input or usage records from which identity can be determined, and requires prompt handling of personal-information access and deletion requests.
Article 12 requires labeling of generated images and video per the China — Provisions on the Administration of Deep Synthesis Internet Information Services, a cross-reference that ties the stack together. Article 13 requires safe, stable, and sustained service. Article 14 requires that, on discovering illegal content, a provider stop generation, transmission, or display, retrain the model as a correction, and report to authorities; on discovering illegal use by a user, it must warn, limit, suspend, or terminate service, store records, and report. Article 15 requires a complaint mechanism.
Oversight and legal responsibility (Arts. 16–21)
Article 16 establishes multi-agency supervision matched to the seven co-issuers' domains, calls for "scientific regulatory methods compatible with innovation and development," and anticipates further tiered and categorized rules. Article 17 requires that services with "public opinion properties or capacity for social mobilization" carry out security assessments per state provisions and file algorithms via the algorithmic recommendation filing regime, a second cross-reference binding the stack together. Article 18 establishes a user right to complain.
Article 19 requires cooperation with oversight, including disclosure of data sources, model types, tagging rules, and algorithm mechanisms, with authorities subject to confidentiality obligations. Article 20 sets a cross-border trigger: non-compliant services provided from outside mainland PRC may be subject to technical measures by the state cybersecurity department. Article 21 provides graduated penalties via the Cybersecurity Law, Data Security Law, PIPL, and Science and Technology Progress Law, ranging from warnings, circulated criticism, ordered corrections, and suspension, with public-security and criminal referral available.
Final (Arts. 23–24)
Administrative permits follow existing laws and foreign investment follows foreign-investment laws. The measures took effect on 2023-08-15.
Comparison with other approaches
| Dimension | China Gen AI Interim | EU AI Act (Regulation 2024/1689) | [[us-aisi-strategic-vision | US AISI]] | America's AI Action Plan |
|---|---|---|---|---|---|
| Legal form | Interim regulation | Regulation (binding) | Voluntary strategic vision | Strategy document | |
| Scope trigger | Public-facing generative AI | Risk tier + GPAI | Voluntary frontier-lab testing | Federal procurement / policy | |
| Training-data rules | Lawful source, IP, PII consent, quality | Transparency summaries for GPAI | None mandated | None mandated | |
| Content controls | Extensive (Core Socialist Values, etc.) | Transparency obligations | None | None | |
| Filing / security assessment | Required (for public-opinion services) | Conformity assessment for high-risk | No | No | |
| R&D exemption | Yes (not public-facing) | Partial | N/A | N/A | |
| Cross-border reach | Explicit (Art. 20) | Market-access based | No | Limited | |
| Deepfake labeling | Required (via cross-reference) | Required (Art. 50) | No | No |
Analysis and open questions
The Article 7.4 requirement that training data increase "truth, accuracy, objectivity, and diversity" is ambiguously specified and potentially in tension with open-source and web-scale training norms; its enforcement trajectory is among the most-watched elements of the measures. The Article 2 exemption for non-public R&D balances innovation-incentive concerns (compute, chips, and independent foundations under Art. 6) against content-control goals, permitting domestic frontier development while keeping the public-service layer tightly policed.
The seven co-issuers indicate broad governmental buy-in but also multi-principal enforcement: industrial policy (MIIT), scientific research (MoST), education (MoE), broadcast (NRTA), and public security (MPS) each hold levers, which raises coordination costs and creates multiple regulatory access points.
The cross-border reach in Article 20 creates a structural conflict with non-Chinese providers of generative AI services; OpenAI has historically blocked access from mainland China, and the provision validates that posture from the Chinese side. The Core Socialist Values content requirement is incompatible with United States First Amendment norms (see AI and the First Amendment) and sets up a divergence in deployable AI output between China and Western markets.
Open questions include whether and when the "interim" measures will be superseded by a final comprehensive AI law, and how the Article 7.4 training-data quality requirement will be enforced in practice.
Relationships
- depends-on: China — Internet Information Service Algorithmic Recommendation Management Provisions (Art. 17 cross-reference — filing regime)
- depends-on: China — Provisions on the Administration of Deep Synthesis Internet Information Services (Art. 12 cross-reference — labeling regime)
- related: China — Interim Measures for the Administration of AI Anthropomorphic Interaction Services (interaction-specific layer issued April 2026, effective July 15, 2026)
- related: EU AI Act (Regulation 2024/1689) (contrasting horizontal regulation)
- related: US AI Safety Institute — Vision, Mission, and Strategic Goals (contrasting voluntary approach)
- related: America's AI Action Plan (contrasting US federal strategy)
- related: Export Controls (AI) (Art. 6 encourages "safe and reliable" domestic chips — responds to US chip controls)
- related: DeepSeek (Chinese frontier lab operating under this regime)
- related: AI and Content Moderation
- related: AI and Authoritarianism
- related: AI Sovereignty
- related: AI Race Dynamics