Part of the AI Regulation News hub.
China opens drafting of sector AI-security guides for finance, health and broadcasting
Updated 21 August 2026 with a TC260 item published 10 July 2026, describing a kick-off meeting held 8 July 2026. The original report was published on 11 July 2026; the text below includes corrections added on 19 September 2026.
What this reported: On 7 July 2026, the secretariat of China's National Cybersecurity Standardization Technical Committee issued notices soliciting drafting participants for AI-application-security guiding technical documents covering three regulated sectors: finance, healthcare, and broadcasting and television.
Added in the 21 August update: A separate TC260 item, published 10 July 2026 and describing a joint kick-off meeting held 8 July 2026, lists six sector documents in drafting: the same three plus education, emergency management and government affairs.
Bindingness: The record we opened does not establish that any of these six documents is in force. They are guiding technical documents at the drafting stage, and The July record describes a drafting programme for guiding technical documents and does not establish a binding effect.
Who this affects: US and multinational firms running or deploying AI in Chinese banks, insurers, hospitals and broadcast or media operations, plus their PRC subsidiaries, cloud and AI vendors, and compliance teams.
Primary sources: TC260 drafting-participant notice, finance, 7 July 2026 · TC260 item on the 8 July 2026 kick-off meeting, published 10 July 2026
- Editorial Note
- Informational analysis for working professionals, not legal advice. Confirm how any rule applies to your situation with qualified counsel.
- Instrument
- Guiding technical documents on AI application security, by sector, at the drafting stage
- Authority
- Secretariat of the National Cybersecurity Standardization Technical Committee (TC260)
- Jurisdiction
- China
- Bindingness
- The TC260 record we opened does not establish a binding effect for these documents: the July notices solicit drafting participants and do not address binding effect, and none of these had been issued on the record we opened.
- What the 7 July notices covered
- Three sectors: finance, healthcare, broadcasting and television
- What the 10 July TC260 item lists
- Six sector documents in drafting: health, broadcasting and television, education, emergency management, finance, government affairs
- Stated programme
- TC260 described the kick-off as implementing a plan to accelerate one hundred national AI standards. We have not read that plan.
- Status
- Drafting. Issuance, adoption or finalisation of the six guiding technical documents is not established by the record we opened.
- Last verified
- 21 August 2026
- Primary source
- https://www.tc260.org.cn/tc260/xwdt1/202607/cbe8e217d6504aad8cfbfa7600f1b310.shtml
What TC260 actually did on July 7?
On July 7, 2026, the secretariat of China's National Cybersecurity Standardization Technical Committee, known as TC260, posted three notices on tc260.org.cn. Each one solicits participating units to help draft a guidance technical document. The three titles differ by a single sector name: 《网络安全技术 人工智能应用安全 金融》 for finance, 《网络安全技术 人工智能应用安全 卫生健康》 for healthcare, and 《网络安全技术 人工智能应用安全 广播电视》 for broadcasting and television (all July 7, 2026).
The notices are administrative, not substantive. They do not publish rules. The notice titles solicit drafting participants. We did not verify application conditions, submission contacts, deadlines or the routing of applicants, because the notices' attachments were not opened. That is the important part. No sector document text appears in the extracted notice text we reviewed. The notice titles solicit drafting participants for the sector guiding technical documents.
Added 21 August 2026: a TC260 item listing six sector documents
Our 11 July report, based on the 7 July participant-recruitment notices, named three sectors: finance, healthcare and broadcasting. A separate TC260 item, published 10 July 2026 and describing a joint kick-off meeting held 8 July 2026, lists six sector documents in active drafting, the same three plus education, emergency management and government affairs.
We have not established whether the three additional sectors were constituted through a different notice track, added after 7 July, or simply omitted from the recruitment-notice reporting chain. Both figures are reported as TC260 stated them, on their respective dates.
The agencies in the room are the useful part for anyone tracking who owns what. TC260's item records attendance and remarks from the information technology and automation standards division of the State Administration for Market Regulation, which handles standards, and from the review and assessment division of the cybersecurity coordination bureau of the Central Cyberspace Affairs Commission Office, which handles security review. Representatives of the Ministry of Emergency Management, the financial regulator, the National Radio and Television Administration and the Ministry of Education also attended, alongside the deputy leader of the AI security standards working group, WG9, and about thirty participants including representatives of all six drafting groups. The meeting was chaired by the director of the cybersecurity research centre at the China Electronics Standardization Institute.
Two named individuals are worth recording only so they can be recognised in future TC260 documents: 张震, deputy leader of WG9, and 姚相振 of the China Electronics Standardization Institute, who chaired. Attendance by an agency does not by itself establish that it owns or will approve a given sector's document, and TC260's item does not say so.
TC260 described the kick-off meeting as implementing the 《加快推动人工智能百项国家标准建设专项行动计划》, a stated plan to accelerate one hundred national AI standards. We have not located or reviewed the plan itself and cannot characterise its scope, timeline, or the six sector documents' place within it.
Why does the move one general guideline to three vertical baselines matter?
TC260 has been assembling the horizontal layer of China's AI-security work. The original report stated that it circulated the general principles for AI application security, the 人工智能应用安全指引总则 practice guide, as a draft for comment in January 2026, with the ethics-focused 人工智能应用伦理安全指引 following in May 2026; those dates are carried from the original report and were not re-verified against dated primaries for this correction. Those documents speak to AI generally, across sectors.
The July 7 notices mark the next phase. Instead of one guideline that a bank, a hospital, and a broadcaster all read the same way, TC260 is now writing separate technical documents for each. That matters because the security questions are not the same. An AI model that scores loan applications, one that flags a tumor on a scan, and one that generates broadcast content carry different data sensitivities, different failure modes, and different regulators watching over them. Sector documents let TC260 write governance, data-handling, access-control, and testing expectations that fit each vertical rather than the average of all three.
What the July record establishes about legal effect
US general counsel often read the word "guidance" and relax. That reflex is worth examining here, but we are not going to tell you these documents will bind you, because nothing in the record we read supports that. The TC260 record we opened does not establish a binding effect for these documents. What the TC260 records establish is that six sector documents are in drafting and that drafting groups exist. They do not establish how any regulator, procurement body or enforcement authority will treat the finished texts.
So the honest way to describe the July 7 notices is this: recruitment to draft sector guiding technical documents, whose publication is not established by the record we opened, from a committee whose July record does not establish a binding effect for these documents. Worth watching closely because of where they are aimed, not because anything about their future legal effect has been established.
What this means for a US firm operating AI in China?
Three groups should pay attention now. First, financial institutions and their vendors, including US banks, insurers, asset managers, and the AI and cloud suppliers behind them, whose Chinese operations use AI for credit, fraud, trading, or claims. Second, healthcare and life-sciences firms running clinical, diagnostic, or administrative AI in Chinese hospitals. Third, media and broadcast operators using AI to generate or moderate content that reaches Chinese audiences.
On the 10 July item, education, emergency management and government affairs are also in drafting, which widens the set of organisations with a reason to watch this programme beyond the three sectors named in the July notices.
For each, the July 7 notices answer a question that GCs and CISOs have been asking: is China going to write AI-security rules that are specific to my sector, or leave me under one broad guideline. The answer is now visible. Vertical documents are coming, and the drafting has started.
The drafting window is the influence window?
There is a practical reason to act during a solicitation rather than after publication. The route these notices document for an outside organization to shape one of these documents is participation in drafting. Once TC260 finalizes text, a foreign firm reacts to it. During the participation window, a firm can apply to contribute through the route the notices describe and, if admitted, flag requirements that would be costly or unworkable for how it actually runs AI.
That does not guarantee a seat. Drafting groups are curated, and foreign participation in Chinese standards work carries its own sensitivities that legal and government-affairs teams should weigh. But a firm that ignores the window gives up the one route these notices document.
Update, 18 September 2026 (corrections added 19 September 2026). On 15 September 2026 the TC260 secretariat issued four final Cybersecurity Standard Practice Guides (网络安全标准实践指南): the general AI Application Security Guidelines (人工智能应用安全指引 总则, TC260-PG-20268A, v1.0-202609), which this article noted was circulated in draft in January 2026, and sector guides for education, health, and broadcasting and online audiovisual. Section 7.1 of the general guide, covering the early planning stage, asks the organisations carrying out an AI application to grade it into one of five safety-risk tiers on a stricter-applies principle (就高从严) before choosing security measures. These are practice guides in the TC260-PG series, not standards and not the sector guiding technical documents whose drafting is reported above, and we found no governing primary source indicating that the September notice establishes a new binding legal obligation. The 15 September notice does not connect the four guides to the July drafting programme, no finance guide was released, and on the record we read none of the six guiding technical documents has been issued.
What we did not verify
We did not read any of the six sector documents. Their issuance is not established by the record we opened, and nothing here describes the content of any of them.
We did not establish why the 7 July notices named three sectors while the 10 July item lists six. We set out both figures as TC260 stated them and reach no conclusion.
We did not read the 《加快推动人工智能百项国家标准建设专项行动计划》. We report only that TC260's item names it as the plan the kick-off implements, and we make no claim about its scope, timeline or content.
TC260's item as published reports attendance and the existence of drafting groups. We do not report any deliberative outcome, agreed timeline or consensus, because the item does not state one.
We did not verify whether attendance by a ministry or regulator carries any formal role in approving a sector document. Nothing here should be read as an allocation of jurisdiction.
The Chinese term rendered here as AI application security is 人工智能应用安全. It is a cybersecurity-standards concept and should not be read as equivalent to the broader policy idea of AI safety used in other jurisdictions.
A US firm deploying AI inside Chinese banking, insurance, hospitals or media should treat these documents as a signal of sector-specific AI-security expectations and decide whether to seek a seat at the drafting table. As of the 21 August update, the sector set on TC260's own record is wider than the three named in the July notices, so firms in education, emergency management and government-facing work have reason to watch it too.
Source File
https://www.tc260.org.cn/tc260/xwdt1/202607/cbe8e217d6504aad8cfbfa7600f1b310.shtml
Open the three TC260 drafting-participant notices of 7 July 2026 and confirm the sector names in each title. Then open the TC260 item published 10 July 2026 describing the 8 July kick-off meeting and confirm the six document titles it lists, the attending bodies, and the sentence naming the plan to accelerate one hundred national AI standards. Note that the notices and the meeting item are separate records published three days apart.
6项人工智能应用安全国家标准化指导性技术文件启动会在京召开 · 全国网络安全标准化技术委员会, item published 10 July 2026 on a kick-off meeting held 8 July 2026
FAQ
Are these TC260 documents in force now?
The record we opened does not establish that any is. The July 2026 solicitation notices (dated July 6, 7, and 15) only open the drafting stage and solicit participating units, and none of the sector guiding technical documents has been published in the record we opened. The record we opened establishes no effective date for any of them.
How many sector documents are there, three or six?
Both figures come from TC260. Its 7 July 2026 notices covered three sectors: finance, healthcare and broadcasting. A separate TC260 item published 10 July 2026, describing a kick-off meeting held 8 July, lists six documents in drafting, adding education, emergency management and government affairs. We have not established why the two records differ and report each as stated.
If they are only "guidance," can I ignore them?
We would not, but we also will not tell you they bind you. The record we read does not establish a binding effect for these documents. The records we read establish that six sector documents are in drafting; they say nothing about how regulators or procurement bodies will treat the finished texts. Track them as a signal of where sector-specific expectations are being built, not as duties.
Which of my AI systems are affected?
Firms running AI inside Chinese finance, healthcare or broadcasting operations, for example credit and fraud models, clinical and diagnostic tools, and content-generation or moderation systems, are the ones to watch the drafting; which particular systems the finished documents will cover has not been verified because no text exists on the record we opened. On the 10 July item, education, emergency management and government affairs are also in drafting.
Can a US company join the drafting?
The notice titles solicit drafting participants; the application conditions, submission contacts, deadlines and the eligibility of any particular US company or PRC entity were not verified, because the notices' attachments were not opened. Foreign participation in Chinese standards work has sensitivities, so involve legal and government-affairs teams before applying.
Related briefings
Sponsored Training
Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.