Hello, this is Ryuta Hamamoto from TIMEWELL.
What Europe, the US, and Japan debate in AI regulation is how far to regulate. The EU AI Act uses four risk tiers. The US is a federal-absent state patchwork. Japan runs soft-law guidelines. The UK adjusts existing regulators. Each is choosing a position on the same axis: balance between regulation and freedom.
China is different. Chinese AI regulation is not about whether to regulate. It is about how to control. With the Interim Measures for Generative AI Services (August 2023) and the Measures for Identification of AI-Generated Synthetic Content (September 2025) as a two-stage structure, China has built a vertically integrated regulatory net from content generation through distribution platforms to user identification, operated centrally by CAC (Cyberspace Administration of China).
That net has extraterritorial application. Japanese companies providing AI services to mainland China users cannot avoid it. This article maps the structure of Chinese AI regulation and the full compliance vs exit binary it forces on Japanese firms.
TL;DR
- Interim Measures for Generative AI Services (effective August 15, 2023): CAC-led, extraterritorial reach
- Measures for Identification of AI-Generated Synthetic Content (effective September 1, 2025): dual labeling—explicit labels + implicit watermarks
- LLM filing: foundation-model developers must pre-register and disclose extensively
- 2026 Qinglang campaign: CAC + public security crackdown on AI fraud and deepfakes
- Japanese choice is close to binary: full compliance or full block of mainland China users
Overall structure: vertical control as design philosophy
To understand Chinese AI regulation, start from a different design origin than the West. The EU AI Act starts from protection of individual fundamental rights. Chinese regulation starts from national security and social order.
That is not only political system difference. It shows up in technical architecture. Western AI rules are largely a two-party story of operator duties and individual rights. Chinese rules are a four-layer structure: state, platform, operator, individual. Platforms and operators are positioned as transmission layers that carry state direction to individuals. That is the essence of Chinese AI regulation.
China has stacked rules over time to implement that structure1:
| Year | Rule | Core |
|---|---|---|
| March 2022 | Algorithm Recommendation Provisions | Government registration of recommendation algorithms |
| January 2023 | Deep Synthesis Provisions | Labeling duties for deepfakes |
| August 2023 | Interim Measures for Generative AI Services | Comprehensive generative AI service regulation |
| September 2025 | AI-Generated Synthetic Content Identification Measures | Full dual-labeling mandate |
| 2025–2026 | LLM filing | CAC pre-registration of foundation models |
| 2026 (in progress) | Anthropomorphic AI interim measures | Human-like AI (elderly dialogue, child-facing AI) |
Stacking incremental rules contrasts with Western one-comprehensive-statute approaches. CAC's ability to issue add-on rules quickly as technology shifts is the model's strength, and the source of unpredictability for foreign firms.
AI Security training, taken seriously
A 2-day intensive course fully aligned with OWASP, NIST, ISO/IEC 42001, and METI. Take it as executives, practitioners, or both.
Interim Measures for Generative AI Services: extraterritorial reality
Effective August 15, 2023, the Interim Measures for Generative AI Services are the foundation of China's generative AI regulation2. Joint promulgation by CAC and six other central agencies (MIIT, Ministry of Public Security, NRTA, and others) signals AI as a cross-ministry priority.
Core duties include:
- Truthfulness: generated content must be true and accurate
- Socialist core values: political neutrality and social order
- National security: prevent leakage of state secrets, military information, strategic materials data
- Personal information protection: alignment with China's PIPL
- Minor protection: age-based content filtering
- Content labeling: clear indication of AI generation
Especially important is the extraterritorial design. The text covers services to the public "within the territory of the People's Republic of China," which can reach overseas providers3.
CAC indicators of "targeting" (provision aimed at mainland China) include:
| Indicator | Conduct treated as in-scope |
|---|---|
| Payments | Accepting RMB |
| Account registration | Accepting Chinese mobile numbers |
| Marketing | Mainland-directed ads and social campaigns |
| Language | Chinese UI, Chinese customer support |
| Infrastructure | Mainland data centers, CDN use |
Avoiding all of these is how many Japanese companies stay effectively out of scope. Hitting any one raises the chance of falling inside Chinese regulatory reach.
The practical choice I work through with customers is binary: a detour strategy to stay out of scope, or a front strategy of full compliance and entry. There is no real middle. Market size versus regulatory burden must be an explicit management decision.
For Western contrast, see EU AI Act and Digital Omnibus and US federal AI policy 2026.
Dual labeling: what took effect September 1, 2025
The Measures for Identification of AI-Generated Synthetic Content are China's most technically deep AI rules4. CAC published the final text and mandatory national standard GB 45438-2025 on March 14, 2025; effective September 1, 2025.
Core: two-layer labeling.
Layer 1: Explicit (visible) labels
- Immediately recognizable to humans as AI-generated
- Text: phrases such as "AI-generated" or "content generated by artificial intelligence"
- Image/video: watermarks, identification marks
- Audio: opening voice announcement
Layer 2: Implicit labels (metadata)
- Machine-readable identifiers
- Embedded file metadata
- Cryptographic digital watermarks
- C2PA-like provenance technology direction
Scope covers text, image, audio, video, and virtual-space content. All platforms in China must implement both layers. Platforms also have verification duties. If unlabeled AI content is found, response within 24 hours is expected.
Technical difficulty is high, especially implicit labels. Watermark interoperability and detection-tool standardization remain open globally. China is using GB 45438-2025 to set a national standard first and appear to aim for a de facto global standard.
I read this as China's strategic use of regulation as an international-standardization tool. EU AI Act transparency (Article 50) points similar directions, but China goes further into technical specification detail.
LLM filing: pre-registration of foundation models
LLM filing is a China-specific regime and, for foreign firms, the heaviest practical barrier5. Operators deploying foundation models in China must pre-register with CAC and disclose:
- Full training-data picture: dataset composition, scale, sources, acquisition path
- Model capability evaluation: parameters, training compute, benchmark performance
- Safety evaluation results: security tests, red-team tests, bias evaluation
- Terms of use: end-user contracts, data-use policies
- Content moderation posture: filtering tech, human moderator staffing
This is orders of magnitude heavier disclosure than Western AI rules. EU AI Act GPAI developers have transparency duties, but not CAC-style government pre-review via registration.
For Japanese AI startups bringing foundation models into China, LLM filing is the first gate. Once filed, training data through operations become known to the Chinese government. How you price technology-leak risk relative to Chinese competitors is the strategic core.
Japanese AI executives I speak with often treat accepting LLM filing as equivalent to surrendering technology leadership. On the other hand, ByteDance (TikTok) and Tencent (WeChat) show global success built on the China market. Management must choose: give up the China market, or yield part of technology advantage.
2026 Qinglang campaign: enforcement on the ground
Alongside rule stacking, China is intensifying enforcement. The 2026 Qinglang (Clear and Bright) campaign is CAC-led crackdown with public security and others6.
Primary targets:
- AI fraud: AI voice/video scams
- Deepfakes: synthetic videos of politicians and celebrities
- Disinformation: AI-generated fake news and rumors
- Illegal apps: unregistered generative AI services, pirated apps
Legal bases combine mandatory labeling standard GB 45438-2025, LLM filing, 2023 Deep Synthesis Measures, new anthropomorphic AI interim measures. Multiple rules stacked. One violation can trigger several regimes, expanding cumulative penalties and reach.
Penalty range includes:
- Administrative penalties (fines, warnings)
- Service suspension (temporary or permanent)
- Time-limited corrective orders
- Criminal referral to public security for serious cases
Service suspension is commercially fatal. A service live in China becoming unreachable overnight is among the largest risks for foreign firms.
The binary China market choice—designed in WARP SECURITY
I opened by saying Japanese response is close to binary: full compliance front entry, or detour strategy to stay out of scope. More concretely:
Full compliance / front entry
- LLM filing: disclose training data through operations to CAC
- Dual labeling on all products and content
- Mainland data centers or delivery via a Chinese entity
- Ongoing CAC security assessments
This path accesses China's market scale (1.4 billion people; digital economy on the order of $8 trillion) in exchange for partial technology advantage transfer and ongoing unpredictability. Chinese rules add and revise on multi-month cycles; foreign firms must keep chasing.
Detour strategy to stay out of scope
- Do not accept RMB payments
- Do not accept Chinese mobile numbers for registration
- Do not market to mainland China
- Treat Chinese UI carefully (language alone is less likely to equal targeting; combined with China-directed ads, risk rises)
- Effectively block mainland access (IP restrictions, etc.)
This path forgoes China market entry in exchange for regulatory risk near zero. Many Japanese firms, especially B2B SaaS and consumer cloud, already operate this way in practice.
TIMEWELL's WARP SECURITY provides a framework for making this binary choice at management level. The core session builds a China market-entry decision matrix (opportunity × regulatory burden × technology-leak risk) with executives.
We especially stress not leaving a fuzzy middle state. Light China marketing without full entry is most dangerous when enforcement tightens (for example, Qinglang). Explicitly choosing entry or exit is how you control regulatory risk.
Even if you exit, not spending EU AI Act and US state AI resources on China is a major strategic benefit. It frees capacity for high-risk AI under the EU AI Act (Annex III from December 2, 2027; Annex I from August 2, 2028) and for Texas TRAIGA × New York RAISE Act.
Contrast with the European timeline (as of August 2026)
Europe, the counterpart to China's vertical control model, is working through its own phased timeline. The general date of application for the EU AI Act (European Commission) is August 2, 2026. What starts on that date is Chapter IV transparency obligations (Art. 50), Chapter III Section 5 (harmonised standards, conformity assessment, CE marking, registration), and the European Commission's power to fine general-purpose AI (GPAI) providers (Art. 101), among others. The substantive high-risk AI obligations do not start on that date.
This is the point most often misread, so it is worth stating precisely. Under the amending act Regulation (EU) 2026/1744 (the Digital Omnibus: adopted July 8, 2026; published in OJ L 2026/1744 on July 24, 2026; in force July 27, 2026), Chapter III Sections 1, 2 and 3 apply to Annex III high-risk AI (Art. 6(2)) from December 2, 2027, and to Annex I high-risk AI (Art. 6(1), embedded in products) from August 2, 2028. Deployer obligations (Art. 26) and the fundamental rights impact assessment (Art. 27) start at those same points. Separately, the Art. 5 prohibited practices and the Art. 4 AI literacy duty have applied since February 2, 2025, and the GPAI chapter (Chapter V) and the penalties chapter (Chapter XII) since August 2, 2025.
On penalties: up to €15 million or 3% of worldwide turnover (whichever is higher) for GPAI-related and other breaches, and up to €35 million or 7% of worldwide turnover (whichever is higher) for breaches of the Art. 5 prohibitions. Judged on scale of penalties alone, this is a monetary deterrence axis different from China's service-suspension toolkit. The emerging picture: China influences via technical specifications (dual labeling); the EU via enforcement powers and fines. Japanese companies face resource allocation on two fronts. Domestic Japanese developments are summarized in Personal Information Protection Act 2026 amendment.
Summary
- Interim Measures for Generative AI Services (August 2023) are the foundation, with extraterritorial reach
- AI-Generated Synthetic Content Identification Measures (September 2025) mandate explicit + implicit dual labeling
- LLM filing forces broad foundation-model disclosure. The heaviest barrier for foreign firms
- 2026 Qinglang campaign stacks multiple rules for tougher enforcement
- Japanese choice is binary: full compliance vs detour strategy to stay out of scope
Chinese AI regulation is a separate paradigm, state-led vertical control, not just a point on the Western soft/hard-law axis. Learning only EU AI Act and US state rules will not price China market risk. Conversely, understanding Chinese rules and deciding not to enter China can be a valid strategic management choice.
Technical-level rules such as dual labeling and LLM filing may also be referenced in global standardization debates. Even Japanese firms that never enter China should watch Chinese proposals in ISO and ITU. The scenario "we skip the China market, but Chinese rules become international standards" is realistic enough to plan for.
Further reading: EU AI Act and Digital Omnibus, Texas TRAIGA × New York RAISE Act, Japan AI Promotion Act and Business Guidelines v1.2.
References
- China: dual-track AIGC labelling and latest AI regulatory development - Linklaters
- China Releases New Labeling Requirements for AI-Generated Content - Inside Privacy
- Telecoms, Media & Internet Laws and Regulations Report 2026 China's Key Developments in AI Governance - ICLG
- China enforces new AI content identification rules - CADE
Footnotes
-
AI Watch: Global regulatory tracker - China - White & Case ↩
-
China: Generative AI Measures Finalized - Library of Congress ↩
-
China's Interim Measures for the Management of Generative AI Services - Future of Privacy Forum ↩
-
Measures for Labeling of AI-Generated Synthetic Content - China Law Translate ↩
-
Deep Synthesis Not Deepfake: How AI Compliance Works in China - China Law Vision ↩
-
China launches months-long campaign against AI misuse - The Next Web ↩






