China’s AI Regulations: What Foreign Tech Companies Must Know

China’s artificial intelligence regulatory framework has matured rapidly since 2022, and by mid-2026 it represents one of the most comprehensive AI governance regimes in the world. For foreign technology companies operating in or selling into China, understanding this framework is no longer optional. Compliance failures can mean pulled licenses, blocked products, or forced data disclosures. Getting it right, however, opens access to one of the most dynamic AI markets on the planet.

The Three-Layer Regulatory Framework

China’s AI rules are not a single statute. They are built in layers, each targeting a specific type of AI application.

Layer 1: Algorithm Recommendation Rules (2022)

The Cyberspace Administration of China (CAC) issued the Provisions on the Management of Algorithmic Recommendations, which took effect in March 2022. These rules apply to any platform using algorithmic systems to push content, products, or services to Chinese users. Foreign apps distributed through Chinese app stores or accessed by Chinese users via web are covered.

Key obligations include: disclosing to users that algorithmic recommendations are in use, providing opt-out mechanisms for personalized recommendations, and prohibiting the use of algorithms to trap users in filter bubbles that harm their interests. Platforms serving Chinese minors face additional restrictions on push frequency and content type.

Layer 2: Deep Synthesis (Deepfake) Rules (2023)

The CAC’s Provisions on the Administration of Deep Synthesis Internet Information Services govern AI-generated audio, video, and image content. Effective January 2023, these rules require providers of deepfake or AI-generated media tools to label synthetic content clearly, verify user identities before allowing content generation, and maintain logs of generated content for at least six months. Any foreign company offering generative AI tools that produce realistic media and whose service reaches Chinese users is within scope.

Layer 3: Generative AI Rules (2023, updated 2024)

The Interim Measures for the Management of Generative Artificial Intelligence Services, issued jointly by the CAC and six other ministries in July 2023, apply to providers of generative AI services (text, image, audio, video, code) to the public within China. Core requirements include: conducting security assessments before launch, submitting algorithms to the CAC’s national filing registry, ensuring training data complies with Chinese law, and implementing content filtering. Foreign providers accessing the Chinese market through partnerships or subsidiaries must ensure their local partners are fully compliant.

Regulator Map: Who Enforces What

Multiple Chinese government bodies share AI jurisdiction. Foreign companies need to know which agency regulates their specific technology:

  • Cyberspace Administration of China (CAC): The primary AI regulator. Handles algorithm filings, generative AI security assessments, and deep synthesis rules.
  • Ministry of Industry and Information Technology (MIIT): Oversees AI in industrial settings, IoT, and smart manufacturing. Foreign industrial tech, robotics, and autonomous system providers should monitor MIIT guidance closely.
  • National Data Administration (NDA): Established in 2023, the NDA oversees data governance and the use of data as a factor of production. AI systems relying on large-scale Chinese data sets must account for NDA oversight alongside CAC rules.
  • State Administration for Market Regulation (SAMR): Enforces anti-monopoly rules in AI markets, including restrictions on dominant platforms using AI to foreclose competition.

This multi-agency structure means compliance is cross-departmental. A single AI product may require filings or approvals from multiple regulators simultaneously. As covered in our guide to China’s Cybersecurity Law, identifying which body holds primary jurisdiction is the essential first step before any compliance program is built.

The Algorithm Filing System

One of the most operationally significant requirements is the algorithm filing (算法备案) system, administered by the CAC. Any company providing algorithm recommendation, deep synthesis, or generative AI services to the Chinese public must file their algorithm with the CAC’s national registry.

The filing requires disclosing the algorithm’s purpose, application scenario, training data sources, content filtering mechanisms, and security assessment results. As of early 2026, the CAC registry contains over 2,000 filed algorithms from domestic providers. Foreign companies with Chinese subsidiaries or joint ventures must ensure their local entity has completed this filing or face service suspension orders.

The security assessment, a prerequisite for filing, must be conducted by a CAC-approved evaluation institution. Foreign companies without existing relationships with such firms should budget three to six months for this process.

Data and AI: The Intersection That Matters Most

China’s AI rules layer on top of the broader data governance framework, particularly the Personal Information Protection Law (PIPL) (2021) and the Data Security Law (DSL) (2021). AI systems that process personal information of Chinese citizens are subject to PIPL’s consent and data minimization requirements. AI systems training on or transmitting “important data” face additional review requirements under the DSL.

For foreign tech companies, this intersection creates a specific compliance scenario: an AI model trained on Chinese user data and operated from servers outside China may trigger cross-border data transfer restrictions. The CAC requires either a government-conducted security assessment or a standard contractual clause (SCC) filing, depending on data volume and type. This connects directly to our detailed analysis of China’s data localization laws, which foreign AI companies should review alongside this AI-specific guidance.

US Export Controls: The Other Side of the Compliance Equation

US tech companies must navigate not just Chinese AI rules but also US export control constraints that affect what AI technology can lawfully be transferred to China.

The US Bureau of Industry and Security (BIS) has placed controls on advanced semiconductor chips — restricting exports of NVIDIA A100/H100-class chips and subsequent generations to China — that power AI training infrastructure. US companies providing cloud-based AI services to Chinese clients must assess whether those services involve controlled technology. Additionally, US companies partnering with Chinese AI firms should conduct Entity List screening; the BIS Entity List includes several major Chinese AI-related companies with which US firms face strict licensing requirements.

This dual compliance environment defines the operating reality for US tech firms in Chinese AI. The most successful foreign entrants map both regulatory landscapes before committing to a market entry structure.

Practical Compliance Roadmap

Step 1: Classify Your AI Product

Determine which regulatory layer applies. Algorithm recommendation, deep synthesis, and generative AI each trigger different filing and assessment obligations. Many enterprise AI tools fall under algorithm recommendation rules even if they are not consumer-facing.

Step 2: Assess Data Flows

Map where your AI system collects, processes, and stores data generated by Chinese users. If data crosses the border for model inference or logging, identify whether a CAC security assessment or SCC filing is required.

Step 3: Engage Local Compliance Counsel

Chinese AI compliance requires local legal counsel familiar with CAC procedure and relationships with approved security assessment institutions. Budget for a local compliance retainer from the outset.

Step 4: Structure Market Entry to Manage Risk

Many foreign tech companies enter China’s AI market through a domestic partner or a WFOE that bears the primary compliance obligation, while the foreign parent provides technology under a licensing arrangement. Our guide on China’s blockchain and fintech regulations covers analogous structuring considerations for regulated technology businesses.

The Opportunity Inside the Compliance Burden

China’s AI market is projected to exceed $60 billion by 2028, with industrial AI, healthcare AI, and smart logistics offering strong footholds for foreign technology. Completing the algorithm filing process and maintaining CAC-compliant data practices creates a market access credential that many domestic competitors lack — foreign companies with regulatory standing are better positioned to win enterprise contracts with Chinese SOEs and regulated industries.

As explored in our analysis of China’s tech sector opportunities and risks for Western partners, the foreign companies thriving in China’s regulated tech environment are those that treat compliance as a competitive moat rather than a cost center. The regulatory environment is demanding. But for well-prepared foreign tech companies, it is also navigable.