- Type
- AI regulatory framework
- Lead regulator
- Cyberspace Administration of China (CAC)
- Key measures
- Algorithm recommendations (2022), deep synthesis (2023), generative AI services (2023), content labelling (2025)
- Labelling rules
- Effective 1 September 2025
- Under development
- Comprehensive AI law (scholar draft, 2024)
- Related
- EU AI Act, AI Regulation in Malaysia, DeepSeek
- Type
- AI regulatory framework
- Lead regulator
- Cyberspace Administration of China (CAC)
- Key measures
- Algorithm recommendations (2022), deep synthesis (2023), generative AI services (2023), content labelling (2025)
- Labelling rules
- Effective 1 September 2025
- Under development
- Comprehensive AI law (scholar draft, 2024)
- Related
- EU AI Act, AI Regulation in Malaysia, DeepSeek
AI regulation in China consists of a layered set of laws, administrative measures and technical standards that govern the development and use of artificial intelligence in the People's Republic of China. Rather than a single omnibus statute, the framework has developed iteratively since 2022, with rules targeting specific technologies and risks — algorithmic recommendation, deep synthesis media, generative AI services and, most recently, the labelling of AI-generated content — administered principally by the Cyberspace Administration of China (CAC) together with industry ministries.[1][4]
History
China's approach builds on its broader digital rulebook — the Cybersecurity Law of 2017, the Data Security Law of 2021 and the Personal Information Protection Law of 2021 — which established security assessments, data governance and privacy obligations that later AI rules extend.[4]
The first AI-specific instrument was the Provisions on the Administration of Algorithmic Recommendations in Internet Information Services, which took effect in March 2022 and required providers of recommendation algorithms to file with regulators and offer users control over algorithmic feeds. The Provisions on the Administration of Deep Synthesis in Internet Information Services followed in January 2023, targeting synthetic media such as deepfakes and requiring labels on AI-generated or edited content.[4]
In July 2023 China issued the Interim Measures for the Management of Generative Artificial Intelligence Services, the first administrative regulation dedicated to generative AI, which took effect on 15 August 2023. The measures require providers of services available to the public to conduct security assessments, file algorithms with the CAC, label training data, moderate outputs and respect intellectual property and personal data rules, under what the regulation describes as categorical and hierarchical supervision.[4]
A second phase focused on transparency of generated content. On 14 March 2025 the CAC, the Ministry of Industry and Information Technology, the Ministry of Public Security and the National Radio and Television Administration jointly issued the Measures for the Labelling of AI-Generated Synthetic Content, which took effect on 1 September 2025, supported by a mandatory national standard, GB 45438-2025.[1][2][3] Scholars had also drafted a comprehensive Artificial Intelligence Law circulated in 2024 as a proposal, and policy timelines anticipate an initial framework of AI laws and regulations by 2025 and a more complete system by 2030.[5][6]
Key Concepts and Technology
The 2025 labelling measures operate through two mechanisms. Explicit labels are visible marks — text, audio or graphic notices — affixed to AI-generated content or shown in interfaces, such as a prompt at the beginning or end of generated text, a notice on images, or identifying marks on videos and virtual scenes. Implicit labels are machine-readable metadata embedded in files, including the provider's name, content identifier and, where feasible, digital watermarks, so that provenance can be detected further down the distribution chain.[1][7]
The rules also allocate duties across the content pipeline. Service providers must add both kinds of labels and preserve them when users download or export content; distribution platforms must check for implicit labels and, where content is identified as, claimed to be, or suspected of being AI-generated, add conspicuous notices for users. Maliciously removing, altering or concealing labels is prohibited, and app stores must verify whether generative AI applications comply before listing them.[1][3][7]
These obligations sit alongside China's algorithm filing and security assessment regime: providers of public-facing generative AI services must register their algorithms, undergo security assessments and align with national standards on training data and content safety. Mandatory standards released in April 2025 added technical requirements for generative AI security and governance, complementing the labelling standard.[4]
Applications and Impact
The framework's practical effect is most visible in how AI-generated content circulates on Chinese platforms. Chatbots, image and video generators and social platforms must label synthetic outputs, and enforcement campaigns — including the CAC's 2025 Qinglang actions — have targeted unlabelled AI content and misuse of AI tools in disinformation. Compliance incorporates major domestic model providers such as DeepSeek, Alibaba's Qwen services and ByteDance's Doubao, as well as the platforms on which their outputs spread.[3][4]
Commentators describe China's iterative style as distinct from the European Union's omnibus AI Act: China regulates by technology layer and application, adjusting rules quickly as new risks emerge, in what analysts characterise as a pragmatic, security-oriented approach that pairs industrial promotion with content control. The labelling rules are also significant internationally, because Chinese platforms and model exports carry their compliance requirements — including metadata conventions — into other markets.[4][6]
>See Also
Malaysia has taken a lighter-touch path than China. It has no dedicated AI statute, relying instead on the National AI Office, the AI Governance Framework and sectoral regulators, while studying further regulation under its national AI roadmap. The contrast is relevant to Malaysian policymakers and businesses that trade with, or build on, Chinese AI technology.[10]
Chinese artificial intelligence investment is deeply embedded in Malaysia's digital economy. ByteDance, the parent of TikTok and Doubao, has committed billions in data centre investment in Johor through its partner Bridge Data Centres, with state figures putting the related investment above RM29.5 billion by 2026, and Alibaba Cloud operates a public cloud region in Johor serving its Qwen-family AI services. Malaysian companies that publish AI-generated content on Chinese platforms must meet the labelling requirements described above, and Malaysian regulators and researchers treat China's labelling standards as a reference point in ASEAN discussions on synthetic media governance.[8][9][10]
For Malaysian businesses operating in China, the practical compliance checklist is now relatively concrete: use providers that file algorithms and assessments with the CAC, preserve labels and metadata when content is exported, declare AI-generated material when uploading it, and reconcile these duties with domestic obligations under the Personal Data Protection Act 2010 and the communications and multimedia framework.[1][3]
References
- ↑China Law Translate. (2025). Measures for Labeling of AI-Generated Synthetic Content. https://www.chinalawtranslate.com/en/ai-labeling/
- ↑Cyberspace Administration of China. (2025). Notice on issuance of the Measures for the Identification of AI-Generated Synthetic Content. https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm
- ↑Inside Privacy (Covington). (2025). China Releases New Labeling Requirements for AI-Generated Content. https://www.insideprivacy.com/international/china/china-releases-new-labeling-requirements-for-ai-generated-content/
- ↑White & Case. (2026). AI Watch: Global regulatory tracker - China. https://www.whitecase.com/insight-our-thinking/ai-watch-global-regulatory-tracker-china
- ↑Center for Security and Emerging Technology (CSET). (2024). Artificial Intelligence Law of the People's Republic of China (Draft for Suggestions from Scholars). https://cset.georgetown.edu/publication/china-ai-law-draft/
- ↑Cambridge Forum on AI Law and Governance. (2025). Navigating China's regulatory approach to generative artificial intelligence and large language models. https://www.cambridge.org/core/journals/cambridge-forum-on-ai-law-and-governance/article/navigating-chinas-regulatory-approach-to-generative-artificial-intelligence-and-large-language-models/969B2055997BF42DE693B7A1A1B4E8BA
- ↑Regulations.AI. (2025). AI Content Identification - China. https://regulations.ai/regulations/RAI-CN-NA-MIASCXX-2025
- ↑New Straits Times. (2026). Johor remains focused on ByteDance AI investment, now exceeding RM29.5bil. https://www.nst.com.my/business/corporate/2026/01/1350672/johor-remains-focused-bytedance-ai-investment-now-exceeding
- ↑Malaysian Investment Development Authority (MIDA). (2024). Bridge Data Centres and ByteDance celebrate grand opening of the first phase hyperscale data centre (MY06) in Johor. https://www.mida.gov.my/media-release/bridge-data-centres-and-bytedance-celebrate-grand-opening-of-the-first-phase-hyperscale-data-centre-my06-in-johor-malaysia/
- ↑Ministry of Digital, Malaysia. (2025). AI Malaysia - Pemacu Utama Menuju Negara AI 2030. https://www.digital.gov.my/en-GB/siaran/AI-Malaysia-Pemacu-Utama-Menuju-Negara-AI-2030