China drafts a GB standard for grading AI security | TLY

AI Regulation Tracker  /  China, draft standard

China moves AI security grading from practice guide to draft national standard

TC260 opened public consultation on 15 July 2026 on a draft GB standard setting a method for security classification and grading of AI applications. It is a draft for comment. It binds nobody today.

What did TC260 actually publish?

A notice, a draft standard and a drafting explanation. The notice is short and it says what it says:

经标准编制单位的辛勤努力,现已形成国家标准《网络安全技术 人工智能应用安全分类分级方法》征求意见稿。为确保标准质量,网安标委秘书处面向社会广泛征求意见。恳切希望您对该标准提出宝贵意见。并将意见于2027年09月13日前反馈给网安标委秘书处。TC260 Secretariat, consultation notice, 15 July 2026

In English: "Through the diligent work of the standard-drafting units, a draft-for-comment of the national standard 'Cybersecurity Technology: Method for Security Classification and Grading of Artificial Intelligence Applications' has now been produced. To ensure the quality of the standard, the TC260 Secretariat is soliciting comments broadly from society. We sincerely hope you will offer your valuable comments on this standard, and provide them to the TC260 Secretariat before 13 September 2027."

The notice carries the Secretariat's signature block dated 2026年07月15日 and links the 征求意见稿 and the 编制说明, the draft and the drafting explanation, as attached PDFs. It gives the title, the dates and the attachments. It does not summarise the grade tiers, and neither does this article. The printed deadline of 13 September 2027 sits more than fourteen months after the open date, which is long for a TC260 consultation. It is quoted here as published.

Why does moving from practice guide to GB standard matter?

TC260 issues two quite different kinds of document. One is the 实践指南, the practice guide, a technical reference the committee can put out quickly without going through the national standard process. The other is the GB national standard, which runs through drafting units, public consultation, review and formal issuance. Recent AI security material from TC260 has largely appeared as practice guides (实践指南), which sit below the national standard system.

Practice guides are useful and they are read. They are not national standards. In Chinese regulatory practice the GB tier carries more weight than practice guides, and binding rules can incorporate GB standards by reference. Moving a grading method into the GB track is a change in the document's future leverage.

The elevation is the story, not the tiers, which the notice does not describe.

Would the finished standard be mandatory or recommended?

Unknown from the consultation notice, and that distinction is not cosmetic. China's GB system contains mandatory standards (强制性国家标准) and recommended standards (推荐性国家标准). A mandatory GB standard is compulsory in its own right. A recommended one is voluntary on its face and acquires force when a regulation, a contract or a conformity assessment scheme points at it.

The designation genuinely changes the analysis, and the notice does not state which one is intended. Anyone telling you now that this will be compulsory is guessing.

Where does this sit against other AI risk classification schemes?

Every AI regime has to answer the same question: who decides how risky a deployment is, and what follows from that decision. They answer it differently.

AI risk classification schemes compared
SchemeLegal statusWho applies the gradingDoes the grade drive obligations directly?
China, TC260 draft AI application security classification and grading methodDraft national standard, in consultation. No GB number assigned. Mandatory or recommended designation not stated.Not stated in the consultation noticeNot today. A GB standard drives obligations when a binding rule or scheme incorporates it by reference
EU AI Act risk tiersBinding regulationProvider self-classification against the Act's own categories, supervised by national authoritiesYes. The tier determines the obligations that attach
NIST AI Risk Management FrameworkVoluntary US framework, no legal force of its ownThe organisation, internallyNo. It structures risk work. Force comes from contract, procurement or sector supervision that references it
Colorado AI Act (SB 24-205)State statuteDeveloper and deployer, applying the statutory definition of a high-risk system used in consequential decisionsYes, for systems that fall inside the definition

The Chinese draft is closest to NIST in mechanics, a method rather than a command, and may end up closest to the EU in consequence, because Chinese rules often cite GB standards. That combination is why it is worth tracking early.

What should a US company deploying AI in China do about a draft?

Three things, none of them urgent this quarter.

Read the draft rather than the coverage. The notice links the 征求意见稿 and the 编制说明 directly. The drafting explanation usually reveals more about intended scope than the standard text does, including which documents the drafters see themselves as building on.

Work out, internally, where your own deployments would land under a grading method you did not write. If the grading turns on data sensitivity, deployment context and consequence of failure, which is the general shape of Chinese security grading work, a US firm running customer-facing AI on Chinese user data should not assume it lands at the bottom of the scale. That is a planning assumption, not a claim about this draft's contents.

Comment if the grading would land badly for a deployment you actually run. Consultation is the only window where the method is still movable, and this window is a long one. A comment costs a memo.

What not to do is rebuild a control framework around a draft. Know where you would sit, keep the evidence you would need, and wait for the final text and its designation.

What this draft does not do

It imposes no obligation on any company, creates no filing, licensing or registration duty, and sets no penalties. On the face of the notice it does not repeal the existing TC260 practice guides, so a company already working to those guides has no reason to stop. It carries no GB number, and none should be quoted for it. And it does not tell you yet whether the finished standard will be compulsory.

Frequently asked questions

Is China's draft AI security grading standard binding?

No. As of 28 July 2026 it is a draft for comment, published by the TC260 Secretariat on 15 July 2026. It creates no obligation on any company. Even after finalisation, its binding force will depend on whether it is issued as a mandatory (强制性) or recommended (推荐性) GB standard, and the consultation notice does not state which designation is intended.

What is the standard called and does it have a GB number?

The Chinese title is 《网络安全技术 人工智能应用安全分类分级方法》, rendered in English as 'Cybersecurity Technology: Method for Security Classification and Grading of Artificial Intelligence Applications'. No GB number is assigned in the consultation notice. Draft GB standards are commonly circulated for comment before a number is allocated, so the absence of a number is not unusual and a number should not be inferred.

When do comments close?

The notice asks that comments be provided to the TC260 Secretariat before 13 September 2027. That date is printed on the notice page itself. It is an unusually long window for a TC260 consultation, and it is reported here exactly as published rather than adjusted.

How does this relate to the TC260 AI practice guides?

TC260 has issued AI security material as practice guides (实践指南), technical documents that sit below the national standard system. This draft would put a security classification and grading method into the GB national standard track instead, the tier that binding Chinese rules can reference.

Last verified: July 28, 2026