AI Regulation

China's Generative AI Regulation Update: What Changed in

What Does the Global AI Regulatory Landscape Look Like Now?

China's generative AI regime has evolved from a single framework into a layered system of measures, filings, and labelling duties. The foundation remains the Interim Measures for the Management of Generative AI Services, which took effect on 15 August 2023 and require providers of public-facing generative AI services to obtain security assessments, complete algorithm and generative-AI filings with the Cyberspace Administration of China (CAC), and ensure content and data compliance. By early 2025, the CAC had processed filings for well over 200 generative AI services, and the regime's reach has steadily widened from chatbots to multimodal and enterprise deployments.

Two developments frame the June 2025 picture. First, the CAC published the Measures for Labelling AI-Generated Synthetic Content in March 2025, effective 1 September 2025, imposing explicit labelling obligations on AI-generated text, images, audio, and video—with particular strictness for services that could be used to spread disinformation. Second, the CAC circulated a revised draft of the generative AI measures for public comment in June 2025, signalling that the 2023 Interim Measures are being upgraded into a more comprehensive regulation. Stanford's AI Index 2025 reported that China produced 36% of the world's notable foundation models in 2024, behind only the United States at 40%—which explains why regulators view generative AI as a strategic sector needing both promotion and control.

For multinational enterprises, the environment is demanding but navigable. China's approach combines registration obligations, content requirements, and data-localisation expectations with sector-specific rules for finance, healthcare, and critical infrastructure. The June 2025 update window is therefore not a niche compliance event; it is the moment when the operating assumptions of the past two years are being revisited.

What Changed in China's Generative AI Rules as of June 2025?

Three changes define the mid-2025 state of play. First, labelling becomes mandatory from 1 September 2025: providers and, in some configurations, deployers of AI-generated synthetic content must make the synthetic origin explicit through visible and metadata labels, with stronger requirements for services capable of generating realistic or deceptive content. Second, the draft revision of the generative AI measures, circulated for comment in June 2025, is expected to extend obligations beyond public-facing providers, sharpen requirements on training data, and align the framework with newer developments such as deepfakes, agents, and multimodal systems. Third, enforcement has broadened in practice: regulators are scrutinising not only major platforms but also the enterprise and vertical applications that the 2023 measures left comparatively light-touch.

The practical effect is that "comply with the 2023 Interim Measures" is no longer a sufficient posture. Organisations that offer generative AI services in China should be planning against the labelling rules now in force as of September 2025 and the expanded obligations likely to arrive with the revised measures. The filing system itself remains central: algorithms used in China must be filed under the Algorithm Recommendation and Deep Synthesis filing regimes, and generative AI services must complete the CAC filing before going live.

It is also worth noting what has not changed. The core content requirements—training data obtained and used lawfully, measures to prevent illegal content, protections for personal information, and mechanisms for user complaints—remain in force, and the June 2025 revisions are expected to deepen rather than relax them. The direction of travel is consistent: more explicit obligations, more operational detail, and a regime that increasingly resembles a full product-compliance framework rather than a set of platform rules.

What Are the Compliance Requirements for Enterprise AI?

  • Algorithm and Service Filings: Complete algorithm recommendation, deep synthesis, and generative AI service filings with the CAC before public deployment.
  • Synthetic Content Labelling: Implement visible and metadata labelling for AI-generated content in line with the measures effective 1 September 2025.
  • Security Assessment: Undergo the security assessment required for public-facing generative AI services, including content-safety testing.
  • Training Data and IP Compliance: Ensure training data is obtained and used lawfully, respecting intellectual property and personal information rules.
  • Cross-Border and Data Governance: Address data localisation and cross-border transfer requirements for personal information used in model training and service delivery.

These obligations form a connected chain. A service cannot launch without its filings; filings require a completed security assessment; the assessment examines content safety and training-data practices; and training-data practices implicate both intellectual property and personal information regimes. Enterprises that sequence these requirements as a single project—rather than treating each as a separate workstream—move through the CAC process faster and with fewer surprises.

How Do You Build a Sustainable Compliance Programme?

Sustainable compliance in China rests on organisational commitment, technical infrastructure, and regulatory intelligence. Assign a named owner in-country, supported by legal counsel familiar with CAC practice, and build a working group that includes engineering, data, and product teams—content-safety requirements are implemented in code, not just in policy documents. Invest in technical infrastructure that automates monitoring and documentation: content-filtering systems, labelling pipelines, and audit logs that can be produced for regulators on demand.

Regulatory intelligence is essential because China's AI rulemaking moves faster than most compliance programs can follow. Between the labelling measures, the June 2025 draft revision, and sector-specific rules in finance and healthcare, requirements change on a quarterly basis. Organisations that maintain a standing regulatory watch—reviewing new drafts, mapping them to existing controls, and updating the gap analysis—will absorb the revised measures as an incremental change; organisations that check China compliance once a year will find themselves rebuilding programs repeatedly.

What Does an Enterprise AI Compliance System Actually Contain?

Beehive Strategy recommends building the compliance system across three dimensions: organisational structure, institutional processes, and technical tools. Establish clear responsibility assignments, including an AI compliance lead reporting to the Chief Risk Officer or General Counsel, with sufficient independence and authority to challenge product decisions. Create cross-departmental working groups spanning legal, technology, data, and business teams, because China AI compliance involves trade-offs across content safety, data governance, and product experience that need a decision forum.

Processes should cover the full AI lifecycle. At project evaluation, run a preliminary compliance risk assessment that identifies which filings, assessments, and labelling obligations apply. During development, maintain comprehensive records of training data sources, model design decisions, and performance test results, and build content-safety testing into the release pipeline. At deployment, complete filings before launch and operate continuous compliance monitoring. During changes and decommissioning, handle data properly and retire models in a compliant manner, including updating filings when functionality changes materially.

For multinational enterprises, the practical priority is integration: China compliance should not be a separate track from global AI governance but a structured overlay on it. Because China's filing and labelling duties are the most operationally concrete in Asia-Pacific, building to them first—while keeping the documentation format compatible with Korea, Singapore, and EU requirements—lets enterprises satisfy the region's strictest market while reusing the artefacts everywhere else. Beehive Strategy maintains specialists familiar with Chinese data regulations and has helped multinational enterprises establish compliance frameworks across data localisation, cross-border transfer assessment, and personal information protection—sequencing the China work so it strengthens rather than duplicates the global program.

What Does the Generative AI Filing Process Actually Involve?

Filings are the single most common source of launch delay, because teams treat them as paperwork rather than as an engineering prerequisite. In practice a generative AI filing is a documentation exercise that depends on artefacts only the product team can produce.

The package normally covers service description and intended use cases, the model's provenance and version, training data sources and lawful basis, content-safety mechanisms including keyword and model-level filtering, user complaint handling, and the identity of the responsible entity and in-country contact. Each item has an owner: legal owns the descriptions, engineering owns the filter documentation, data governance owns the training-data record, and product owns the use-case list. When those four are not coordinated, the filing stalls on the same question every time — what exactly does this service do, and for whom.

Three practices shorten the cycle. Build the documentation as a living artefact from the start rather than assembling it at the end, since the questions are predictable. Keep a version history, because a refiled change is far cheaper than an unanswered regulator query about drift between versions. And run an internal pre-assessment against the same checklist the assessment body will use; teams that do this typically find two or three gaps that would otherwise surface as formal deficiencies.

How Do Data and Cross-Border Rules Affect Generative AI Compliance?

Generative AI sits at the intersection of three data regimes, and the obligations are cumulative rather than alternative. Personal information protection rules govern how training and prompt data are collected, stored and used. Data security rules classify datasets and impose handling requirements by classification. Cross-border transfer rules determine whether data collected in China can leave it, and under which mechanism.

For a multinational, the practical question is usually not whether data can leave the country but which of the available pathways applies: a security assessment, standard contractual terms, or certification, each with its own thresholds. The decision has architectural consequences. Training a global model on China-sourced data is a different project from training an in-country model on localised data, and the choice should be made deliberately rather than inherited from an existing pipeline.

Two operating patterns work. Either keep China data in-country with a separate model instance and a controlled interface to global systems, or design a single global pipeline with data minimisation applied before any transfer — aggregated or de-identified inputs where the use case allows. What does not work is assuming that because data already flows for another purpose, the same path is available for model training. Generative AI workloads attract materially more scrutiny than ordinary business reporting, and the transfer mechanism has to be documented for this purpose specifically.

What Does Ongoing Compliance Look Like After Launch?

Launch is the beginning of the obligation, not the end of the project. Three activities carry most of the ongoing load, and all three fail in the same way — they are owned by nobody after the launch team disbands.

  • Change-triggered reassessment. Define in advance which changes require a fresh review: a new model version, a new language, a new use case, a change of training data source, or a change to the filtering stack. Without a written trigger list, changes ship unreviewed by default.
  • Content-safety monitoring with evidence. Log filter hits, false positives, escalations and resolution times. Regulators ask for evidence that controls operate in practice, not just that they exist in design documents, and the log is the evidence.
  • Regulatory intelligence with a decision path. Track measures, drafts and standards as they are published, and route each through a named owner who decides whether it changes the roadmap. Collecting updates is easy; converting them into decisions is where most programmes fall behind.

The measurable test of a working programme is whether the organisation can answer, within a day, four questions: which AI services are live, what filings each holds, who owns content safety for each, and what the last regulatory change required of us. Teams that can answer those questions quickly tend to stay ahead of the regime; teams that cannot usually discover the gap during an inquiry.

One further discipline is worth building from the first release: a single register that maps every live AI feature to its filings, its owner, its training-data sources and its content-safety controls. The register takes a day to create and turns every subsequent regulatory question into a lookup rather than an investigation.

What Practical Steps Should Multinationals Take Next?

  • Map every generative AI service offered in China and its filing status under the algorithm, deep synthesis, and generative AI regimes.
  • Stand up labelling infrastructure now, ahead of the 1 September 2025 effective date, covering text, image, audio, and video outputs.
  • Review training-data sourcing for lawfulness, including intellectual property and personal information compliance, with documented lineage.
  • Track the June 2025 draft revision of the generative AI measures and update your gap analysis when the final text is published.
  • Engage counsel familiar with CAC practice for the security assessment and filing sequence, and keep records of every submission.

The window between draft and final regulation is short and valuable. Enterprises that use it to prepare labelling, filing, and documentation infrastructure will experience the revised measures as an update; those that wait will compress a multi-month compliance project into a launch bottleneck. In a market moving as quickly as China's, the difference between those two outcomes is usually decided months before the regulation lands.

Frequently Asked Questions

A public-facing generative AI service generally needs its algorithm recommendation filing, a deep synthesis filing where synthetic media is generated, and the generative AI service filing, all completed before the service goes live, plus a security assessment covering content safety. The practical difficulty is rarely the form itself: it is producing the supporting documentation on model provenance, training data sources, filtering mechanisms and complaint handling. Treat the filing as an engineering deliverable with named owners for each artefact, and build the documentation alongside the product rather than after it.

Providers must make the synthetic origin of AI-generated content explicit in two places: a visible label that users can see, and metadata embedded in the file so that the origin survives redistribution. Services capable of producing realistic or potentially deceptive content face stricter expectations, including labelling at the point of generation rather than at the point of publication. In engineering terms this means the label has to be written by the generation pipeline, not added downstream by a publishing tool, and it has to persist through export, compression and re-upload.

Decide the architecture deliberately rather than inheriting it. Either keep China-sourced data in-country with a separate model instance and a controlled interface to global systems, or apply data minimisation before transfer so that only aggregated or de-identified inputs leave. Whichever path is chosen, document the specific transfer mechanism for this purpose — the fact that data already flows for reporting or CRM does not establish a pathway for model training, which attracts materially closer scrutiny. Also record the lawful basis for training data separately from the lawful basis for service delivery.

Two cadences matter. A formal review at least twice a year, covering live services, filings held, owners, and open regulatory changes. And an event-triggered review whenever a model version, language, use case, training data source or filtering component changes. The trigger list should be written down before launch, because without it changes ship unreviewed by default. The programme is working if the organisation can answer within a day which AI services are live, what filings each holds, who owns content safety, and what the last regulatory change required.
Book a personalised demo

Ready to transform your data strategy?

See how Beehive Strategy's conversational analytics platform unlocks real-time insights across your operations, from upstream data to downstream decisions.

Book a Demo Explore the Solution
3x
Typical first-year ROI
78%
Faster query resolution
92%
Adoption in 6 months
50+
Data connectors