Administrative Measures for the Security Assessment of Generative AI Services (2023) and Algorithmic Recommendation Management Provisions (2022)
Evidence request list. 48 controls, 48 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Algorithm Recommendation
Providers must not record illegal or undesirable keywords into user interest profiles or use them as criteria for recommending content to users.
- User-tagging rules excluding illegal/harmful keywords
- Recommending content based on illegal-content interest tags
Providers must strengthen the ecological management of recommendation feeds, establish manual intervention and user self-selection mechanisms, and actively present information consistent with mainstream value orientation in key sections such as front pages, hot-search and selected topics.
- Manual-intervention and user self-selection mechanisms
- No human oversight of recommendation feeds
Providers are encouraged to optimise transparency and explainability of search, ranking, selection, push and display rules, and to avoid adverse effects on users and to prevent or reduce controversy and disputes.
- Documentation of ranking/filtering rules and transparency measures
- Opaque ranking rules causing user harm
Providers must not use algorithms to falsely register accounts, manipulate accounts, fabricate transactions/likes, manipulate rankings, or control trending topics, comments and other activities that interfere with online information presentation.
- Controls preventing fake-account and ranking manipulation
- Algorithmic manipulation of rankings or trending content
Providers must not use algorithms to unreasonably restrict other internet information service providers, or to impede or sabotage the lawful operation of their services, monopolise or engage in unfair competition.
- Policy against anti-competitive algorithmic practices
- Algorithms used to block or degrade competitors
Providers must inform users in a conspicuous manner that they provide algorithmic recommendation services and publicise the basic principles, purpose/intent and main operating mechanisms in an appropriate way.
- Conspicuous disclosure that recommendation is used
- Published description of recommendation logic
- Users not told that content is algorithmically recommended
Providers must offer users options not targeted at their personal characteristics or a convenient way to switch off algorithmic recommendation, and must let users select or delete user tags used for recommendation; where a user objects, the provider must stop the service.
- Opt-out / non-personalised toggle
- Tag selection and deletion function
- No opt-out from personalised recommendation
- No ability to delete recommendation tags
Providers serving minors must fulfil minor-protection duties, facilitate minors' healthy use through suitable service modes, and must not push information that may induce minors to imitate unsafe behaviour, commit acts contrary to social morality, or develop harmful habits or addiction.
- Minor mode / age-appropriate recommendation controls
- Recommending addictive or harmful content to minors
Providers serving the elderly must protect their lawful interests, account for their travel, medical, consumption and other needs, provide intelligent and accessible adaptations per state rules, and support fraud detection and prevention.
- Accessibility adaptations for elderly users
- Anti-fraud features
- No accessibility or fraud safeguards for elderly users
Providers offering work-scheduling services to workers must protect their lawful interests in remuneration, rest and working hours, and establish and refine platform-order distribution, remuneration composition/payment, working hours, rewards/penalties and other algorithms.
- Fair work-scheduling and pay algorithms
- Worker-impact assessment
- Exploitative gig-work scheduling algorithms
Providers selling goods or services to consumers must protect consumers' fair-trading rights and must not use algorithms to commit unreasonable differential treatment on price or trading conditions based on consumer preferences or trading habits.
- Pricing-fairness controls preventing algorithmic discrimination
- Algorithmic price discrimination ('big-data price gouging')
Providers must establish convenient complaint and public-reporting entry points, disclose the handling process and timeframes, and promptly accept, handle and give feedback on complaints.
- Published complaint/report channel and timelines
- No accessible complaint mechanism for recommendation services
Providers with public-opinion attributes or social-mobilisation capacity must, within ten working days of providing service, file via the internet information service algorithm filing system the provider name, service form, application field, algorithm type, algorithm self-assessment report, content to be publicised and other information; changes within ten working days and termination within twenty working days.
- Algorithm filing record (name, type, self-assessment report)
- Change/termination filings
- Opinion-influential algorithm not filed within ten working days
Providers that have completed filing must indicate their filing number in a conspicuous position on their website, application or other service interface and provide a link to the publicised information.
- Filing number displayed on the service interface
- Filing number not displayed after registration
Providers with public-opinion attributes or social-mobilisation capacity must carry out a security assessment in accordance with relevant national provisions.
- Completed algorithm security assessment
- No security assessment for opinion-influential algorithms
Providers must cooperate with cyberspace and other authorities' supervision and inspection, give explanations, retain relevant logs (records) for the period prescribed by law, and provide necessary technical/data support and assistance.
- Retained algorithm logs/records
- Inspection cooperation evidence
- Inadequate log retention or failure to cooperate with inspection
Algorithmic recommendation service providers must establish and improve management systems and technical measures for algorithm-mechanism review, science-and-technology ethics review, user registration, information release review, data security and personal information protection, anti-telecom-fraud, security assessment and monitoring, and security incident response.
- Documented algorithm security management system covering the listed domains
- Missing one or more mandated management systems (ethics review, incident response, etc.)
Providers must regularly review, evaluate and verify algorithm mechanisms, models, data and application outcomes, and must not set up algorithm models that induce users to become addicted or spend excessively, or that violate laws or ethics.
- Periodic algorithm review/evaluation records
- No periodic algorithm review
- Addiction-inducing algorithm design
Providers must strengthen information-content management, establish feature libraries to identify illegal and undesirable information, label or stop transmission, and report illegal information to authorities; undesirable information must be handled per relevant rules.
- Illegal/undesirable-content feature library and handling records
- No detection/handling of illegal or harmful recommended content
Cross-Cutting
The CAC AI regime is grounded in the Cybersecurity Law, Data Security Law and Personal Information Protection Law. Network operators providing these services must fulfil Multi-Level Protection Scheme (MLPS / dengbao) obligations: graded protection, security measures, log retention and incident handling. Referenced here as a cross-cutting obligation; full text not held in this corpus.
- MLPS grading certificate
- Baseline security controls and log retention
- No MLPS grading or baseline cybersecurity controls
Where the recommendation/generation services process personal information through automated decision-making, the Personal Information Protection Law requires transparency and fairness of the decision, prohibits unreasonable differential treatment in trading conditions, and grants individuals the right to an explanation and to refuse decisions made solely by automated means. Referenced here as a cross-cutting obligation of the CAC AI regime; full text not held in this corpus.
- Automated-decision transparency notice
- Opt-out / human-review mechanism
- No transparency or opt-out for automated decisions
Deep Synthesis
Providers must strengthen management of deep synthesis content, take technical or manual measures to review user inputs and synthesis results, establish and improve feature libraries to identify illegal and undesirable information, and keep records and report to authorities when such information is found.
- Input/output moderation controls
- Illegal-content feature library and reporting records
- No moderation of deep synthesis inputs or outputs
Providers and technical supporters must strengthen training-data management and ensure data security; where training data contains personal information they must comply with personal-information protection rules, and where it involves editing biometric information such as faces or voices they must notify and obtain the separate consent of the individuals concerned.
- Training-data security controls
- Separate consent records for biometric editing
- Editing faces/voices without separate consent
Providers and technical supporters offering functions such as biometric editing of faces/voices or generation/significant alteration of content that may involve national security, national image, public interest or social order must conduct a security assessment themselves or commission a professional body.
- Security assessment of high-risk editing/generation functions
- High-risk biometric editing deployed without security assessment
Providers must add technical markings (e.g. implicit identifiers) to information content generated or edited using deep synthesis that do not affect users' use, and must retain logs in accordance with law.
- Implicit/technical watermarking of synthetic content
- Log retention
- Synthetic content without technical markers
For deep synthesis services that may cause public confusion or mistaken identity (e.g. intelligent dialogue, synthetic human voice, face generation/replacement/manipulation, immersive simulated scenes), providers must add conspicuous labels in reasonable positions to alert the public to the synthesis.
- Conspicuous synthetic-content labels on high-deception services
- Unlabelled deepfakes or voice clones
No organisation or individual may use technical means to delete, alter or conceal the deep synthesis markings required by the Provisions.
- Controls preventing removal of synthesis markings
- Removal or concealment of synthesis identifiers
Deep synthesis service providers with public-opinion attributes or social-mobilisation capacity must complete filing and change/cancellation procedures under the Algorithmic Recommendation Management Provisions, and display their filing number conspicuously.
- Deep synthesis algorithm filing record and displayed number
- No filing for opinion-influential deep synthesis services
When developing and launching new products, applications or functions with public-opinion attributes or social-mobilisation capacity, providers must conduct a security assessment in accordance with relevant national provisions.
- Pre-launch security assessment for mobilisation-capable functions
- Launching opinion-influential features without security assessment
No organisation or individual may use deep synthesis services to produce, copy, publish or transmit information prohibited by law, or to engage in activities such as endangering national security/interests, damaging the national image, infringing others' lawful rights, or fabricating and disseminating false information.
- Acceptable-use policy aligned to the Art. 6 prohibitions
- Deep synthesis used to fabricate news or harm others
Deep synthesis service providers must establish and improve management systems for user registration, algorithm-mechanism review, science-and-technology ethics review, information release review, data security, personal information protection, anti-telecom-fraud, and emergency response, with effective technical safeguards.
- Documented deep-synthesis management systems including ethics review
- Missing mandated management systems for deep synthesis
Deep synthesis service providers must authenticate the real identity of users based on mobile phone number, identity document number, unified social credit code or national network-identity authentication public service, and must not provide information-publishing services to users who have not completed real-identity authentication.
- Real-name authentication implementation
- Block on publishing for unverified users
- Allowing unverified users to publish synthetic content
Ethics
Both the Deep Synthesis Provisions (Art. 7) and the Algorithmic Recommendation Provisions (Art. 7) require providers to establish a science-and-technology ethics review system as part of their algorithm management. Ethically sensitive AI activities must undergo ethics review before deployment.
- Science-and-technology ethics review committee/process
- Ethics review records for AI features
- No ethics review process for AI/algorithmic features
Generative AI Measures
Providers must clarify and disclose the applicable users, occasions and purposes of the service, guide users to lawful use, and take effective measures to prevent minors from over-reliance on or addiction to generative AI services.
- Disclosed usage scope and guidance
- Anti-addiction measures for minors
- No safeguards against minor over-reliance
Providers must fulfil personal-information protection duties for user input information and usage records; must not collect unnecessary personal information, unlawfully retain input/records that can identify users, or unlawfully provide them to others; and must handle data-subject access, copy, correction, supplement and deletion requests in accordance with law.
- Retention and minimisation policy for prompts and logs
- Data-subject request handling procedure
- Indefinite retention of identifiable prompts
- No mechanism for access/deletion requests
Providers must label generated images, videos and other content in accordance with the Provisions on the Management of Deep Synthesis of Internet Information Services.
- Synthetic-content labelling implementation evidence
- Unlabelled AI-generated media
Providers must provide safe, stable and continuous service throughout the service period, safeguarding users' normal use.
- Service-availability and continuity controls
- Incident/outage handling records
- No continuity safeguards for the service
On discovering illegal content, providers must promptly stop generation and transmission, take disposal measures such as model optimisation training, and report to the competent authorities. On discovering a user using the service to engage in illegal activity, providers must warn, restrict functions, suspend or terminate service, keep records and report to authorities.
- Illegal-content takedown procedure
- User-violation handling and reporting records
- No takedown or authority-reporting process for illegal content
Providers must establish a sound complaint and reporting mechanism, set up easy-to-use entry points, disclose the process and timeframes, and promptly handle complaints and provide feedback.
- Published complaint channel and timelines
- Complaint-handling logs
- No accessible complaint mechanism
Relevant competent authorities (cyberspace, development/reform, education, science/technology, industry/IT, public security, radio/TV, press/publication) supervise generative AI services according to their duties and are to formulate corresponding categorised and graded regulatory rules or guidelines.
- Awareness of applicable sector classification/grading
- Not applicable as a control objective; defines the supervisory regime
Providers of generative AI services with public-opinion attributes or social-mobilisation capacity must carry out a security assessment in accordance with national provisions and complete algorithm filing (and changes/cancellation) under the Algorithmic Recommendation Management Provisions.
- Completed security assessment report
- Algorithm filing record and number
- No security assessment or filing for opinion-influential services
Providers must cooperate with competent-authority supervision and inspection, explain as required the sources, scale and types of training data, annotation rules and algorithm mechanisms, and provide necessary technical and other support; authorities must keep state secrets, trade secrets and personal information confidential.
- Documentation of training data sources/scale/types, annotation rules, algorithm mechanisms ready for inspection
- Inability to explain data sources or algorithm mechanisms on request
Applies to the provision of generative AI services to the public within China to generate text, images, audio or video. Internal research and development not provided to the public is excluded.
- Scoping determination of whether the service is public-facing generative AI under the Measures
- Treating a public-facing service as exempt internal R&D
Violations are dealt with under the Cybersecurity Law, Data Security Law, Personal Information Protection Law, Law on Scientific and Technological Progress and other laws; where no specific provision exists, authorities may warn, order correction and suspend service; serious cases may incur criminal liability.
- Awareness of enforcement exposure across the cited laws
- Not applicable as a control objective; defines penalties
Service provision and use must uphold core socialist values and must not generate content that incites subversion of state power, endangers national security/interests or damages the national image; must not contain ethnic/belief/gender/age/occupation/health discrimination, infringe IP or commercial ethics, harm others' rights (likeness, reputation, honour, privacy, personal information); and must take measures to improve transparency, accuracy and reliability of generated content.
- Content moderation policy mapped to the Art. 4 prohibitions
- Bias and discrimination testing records
- No content filter for prohibited categories
- Unmitigated discriminatory outputs
Providers must use training data from lawful sources, not infringe intellectual property, obtain consent where personal information is used (or meet another lawful basis), and take measures to improve the quality, truthfulness, accuracy, objectivity and diversity of training data, complying with data-protection and other laws.
- Data provenance / licensing records
- Consent or lawful-basis records for personal data in training sets
- Data quality assessment
- Unlicensed or scraped training data
- No lawful basis for personal data used in training
Where data annotation is carried out during development, providers must establish clear, specific and operable annotation rules that meet the Measures' requirements, conduct quality assessment and sampling verification of annotation accuracy, and train annotation staff on the rules.
- Documented annotation rules
- Annotation quality-assessment and sampling records
- Annotator training records
- Undocumented or inconsistent annotation
- No annotation quality control
The provider bears responsibility as the producer of online information content and as the personal-information processor for information-security obligations, and must sign a service agreement with registered users clarifying both parties' rights and obligations.
- User service agreement
- Records evidencing producer-liability controls
- No service agreement defining responsibilities
- Provider disclaiming responsibility for outputs
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.