AI Regulation Tracker / China
China is drafting AI labelling and tracing duties into primary law, and comments close August 28
The Cyberspace Administration of China put the Anti-Cyberviolence Law of the PRC out for public comment on July 29, 2026. It is a draft and binds no one today. What is new is the rank: duties that have lived in departmental rules would sit in a national statute, with statutory fines behind them.
What did the CAC actually publish on July 29?
A notice, a full draft statute and a drafting explanation on one page, timestamped 18:00 on July 29, 2026 and signed by the CAC with the same date. Comment goes by email to fanwangbaofa@cac.gov.cn or by post to the Bureau of Cyberspace Law in Beijing, deadline August 28, 2026.
This is a general cyberviolence statute, not an AI statute. Article 2 defines cyberviolence as concentrated or sustained online conduct harming reputation, honour, privacy, likeness or personal information. AI sits inside that frame, as a means and as a tool of governance. Calling it an AI law would misdescribe it.
What makes it worth an entry here is rank. The drafting explanation makes that case in its own words: existing cyberviolence legislation is 比较分散, relatively scattered, with basic concepts and platform responsibility not clearly defined, and what is needed is 反网络暴力高位阶立法, higher-ranking anti-cyberviolence legislation. That rendering is mine, and it is the whole point of the exercise.
Which articles carry AI duties, and what do they say?
Three articles carry AI text on their face. Quotations come from the draft as published on cac.gov.cn; the English is my rendering.
Article 8 is the enabling side, encouraging use of AI to raise cyberviolence governance capability: 运用人工智能技术,提升网络暴力治理能力.
Article 13 is the operative platform provision, in three paragraphs. Paragraph 1 would require providers to build monitoring and identification mechanisms, including a feature library, a sample library of typical cases and early-warning models, using 人工智能、大数据等技术手段和人工审核相结合的方式, which I read as AI and big-data means combined with human review. The human review is in the text, not left to the operator. Paragraph 2 would bar a provider that has found a cyberviolence risk from using algorithmic recommendation to push the content. Paragraph 3 is the one people will quote:
网络服务提供者……应当加强对利用人工智能技术制作、复制、发布、传播网络暴力信息……的防范治理,按照国家有关规定落实人工智能生成合成内容标识等制度,增强网络暴力信息溯源能力Draft Anti-Cyberviolence Law, Article 13, paragraph 3
My rendering: providers shall strengthen prevention and governance of the use of AI to produce, reproduce, publish or disseminate cyberviolence information, shall implement systems such as labelling of AI-generated and synthesised content in accordance with relevant State provisions, and shall strengthen their capacity to trace the origin of that information. Where such a risk is found, they must take measures, carry out provenance tracing and report to the relevant departments.
Note what the clause does not do. It writes no new labelling standard. It points at the existing State labelling regime and gives the duty to follow it a statutory anchor.
Article 31 is the conduct ban, and it runs against everyone, not just platforms. Item (4) is 利用生成合成、个性化推送等人工智能技术, using AI technologies such as generation-and-synthesis or personalised push, to produce, reproduce, publish or disseminate cyberviolence information or carry out other cyberviolence activity.
What would the money look like if this text were enacted as written?
Conditional, because none of it is live. Article 48 covers breaches of Articles 13, 14, 19 and 34: order to correct, warning, confiscation of unlawful gains, and a fine of RMB 100,000 to RMB 1,000,000, rising to RMB 1,000,000 to RMB 2,000,000 where correction is refused or the circumstances are serious. Suspension of business and licence revocation are also available.
Article 49 handles platform failures under Articles 16, 17, 18, 20 and 21. Its second paragraph is the outer edge: where the violation causes 特别严重 effects or consequences, RMB 2,000,000 to RMB 10,000,000, plus RMB 200,000 to RMB 1,000,000 on directly responsible managers and other directly responsible personnel. Personal liability runs through the draft.
Article 50 is where the Article 31 AI ban lands. Where other law sets a penalty, that applies; where none does, RMB 100,000 to RMB 500,000, and RMB 500,000 to RMB 2,000,000 for refusal to correct or serious circumstances. Article 54 is the one civil litigators will read twice: a provider that knew or should have known a user was using its service for cyberviolence, and did not take necessary measures in time, would bear joint and several liability with that user.
Who would owe these duties, and how far does the draft reach offshore?
The addressee is the 网络服务提供者, the network service provider. Article 21 adds a heavier tier for providers with very large user numbers or significant influence over users: rapid response, periodic risk assessment, and an annual governance report published for public scrutiny. Article 33 reaches operators of high-influence public accounts. Article 34 reaches multi-channel distribution agencies that sign them, and Article 48 penalises it.
On extraterritoriality, read Article 3 as two sentences. Paragraph 1: this Law applies to cyberviolence activities carried out within the territory of the PRC. Paragraph 2: 境外的组织、个人针对中华人民共和国境内实施的网络暴力活动,依照本法有关规定处理和追究责任. My rendering: where organisations or individuals outside the territory carry out cyberviolence activities directed at targets inside the PRC, those activities are to be handled and liability pursued under the relevant provisions of this Law.
That is a conduct hook, keyed to offshore acts aimed inside China. It is not drafted as a general statement that the Law governs every foreign platform, and press framing of it that way goes further than the sentence does. It says nothing about enforcement mechanism, which is what a comment letter is for.
How does this compare with the China instruments already on this tracker?
The three China items below are separate instruments at separate ranks. Side by side, they show what a statute would change.
| Instrument | Rank | Status on July 29, 2026 | AI content and enforcement |
|---|---|---|---|
| Draft Anti-Cyberviolence Law (this item) | National law, if enacted by the NPC Standing Committee | Draft for comment to August 28, 2026; commencement clause blank | AI detection, labelling and tracing at Article 13(3); AI cyberviolence ban at Article 31(4); fines at Articles 48, 49, 50 |
| Rewritten Internet Information Services rules | Administrative rules, below statute | Draft, comment window closed August 2, 2026 | 94 articles including a new Smart Information Services section on AI |
| Network Data Security Risk Assessment Measures | Departmental measures, CAC, MIIT, MPS | Finalised, in force August 20, 2026 | Annual risk assessment duty on important-data processors |
| TC260 sector AI-security guides | Technical standards work, not law | Drafting calls opened July 7, 2026 | AI security guidance for finance, health, broadcasting |
The finalised measures bind you. The standards work shapes how an assessor reads your controls. This draft would do something neither does: put labelling and tracing in a statute, with statutory fines and personal liability.
What should a China-facing platform or vendor do before August 28?
With no China-facing user base and no Chinese distribution partner, this is a watching item. Otherwise:
- Read Articles 13 and 31 in Chinese, or have counsel who can. Article 13(3) is drafted as an addition to paragraphs 1 and 2, so it assumes you already have the monitoring machinery they describe.
- Work out whether Article 21 would catch you. Very large user numbers or significant influence over users is undefined, and an undefined threshold that triggers annual public reporting is worth raising in a comment.
- Map your labelling posture against the existing State AI content labelling regime, which Article 13(3) incorporates by reference rather than restating.
- Look at provenance. If your logging cannot establish where a synthetic asset entered your service, that is a long-lead build item.
- File a comment if the text creates a problem for you. Comment periods are the cheapest point of influence in any legal system.
One thing to resist: reading this as a reason to rip out human moderation in favour of a detection model. Article 13(1) as drafted requires AI and big-data means combined with human review.
What this piece does not say
It does not say the Law has been passed, predict that it will be, or give an adoption date, because the notice gives none. It attributes no document number, because the notice carries none. It names no predecessor instrument, because the notice names none, though other coverage supplies a 2024 departmental regulation. And it does not read Article 3 as a general assertion of jurisdiction over foreign platforms.
Frequently asked questions
Is the Anti-Cyberviolence Law in force in China?
No. The Cyberspace Administration of China released it on July 29, 2026 as a draft for public comment. Article 60, the commencement article, is blank: it states the Law takes effect from a year, month and day that have not been filled in. Comments close August 28, 2026, and nothing in the draft binds anyone today.
What AI duties does the draft place on platforms?
Article 13. Paragraph 1 would require providers to build cyberviolence monitoring and identification systems using AI and big data techniques combined with human review. Paragraph 2 would bar algorithmic recommendation of the content once a risk is found. Paragraph 3 would require providers to implement AI-generated and synthesised content labelling in line with relevant State provisions, strengthen their ability to trace the origin of cyberviolence information, and run provenance tracing and report to the authorities when an AI-driven risk is detected.
What fines does the draft attach to the AI provisions?
Article 48 covers breaches of Articles 13, 14, 19 and 34: order to correct, warning, confiscation of unlawful gains and a fine of RMB 100,000 to RMB 1,000,000, rising to RMB 1,000,000 to RMB 2,000,000 where correction is refused or the circumstances are serious. Article 50 covers the Article 31 conduct ban, which includes the AI prohibition, at RMB 100,000 to RMB 500,000, or RMB 500,000 to RMB 2,000,000 for refusal or serious circumstances, where no other law sets a penalty.
Does the draft reach organisations outside China?
Article 3 paragraph 1 states the Law applies to cyberviolence activities carried out within the territory of the PRC. Paragraph 2 states that cyberviolence carried out by organisations and individuals outside the territory and aimed at targets inside the PRC is to be handled and liability pursued under the relevant provisions of the Law. That is a conduct hook aimed at offshore cyberviolence, not a general statement that the Law applies to every foreign platform.
Last verified: July 29, 2026