AI Governance Institute
All governance templates →How do we comply with China's AI regulations?

Implementation Kit

China AI Compliance Checklist and Algorithm Filing Tracker

The compliance set for offering AI services in China: an applicability matrix across the CAC instruments, a security assessment checklist, a content labeling specification, and an algorithm filing tracker.

Who this is for: The compliance owner for AI products available to users in mainland China.

Download the kit (Markdown) ↓4 artifacts. Every table also copies as CSV.

1. China AI regulatory applicability matrix

Spreadsheet

Which CAC instrument applies to which product or feature.

Template

Product / featureGenerative AI MeasuresDeep Synthesis ProvisionsAlgorithm Recommendation ProvisionsData / PIPLSecurity assessment required?
<feature>Y / NY / NY / NY / NY / N

Worked example

Product / featureGenerative AI MeasuresDeep SynthesisAlgorithm RecommendationData / PIPLSecurity assessment?
Text assistant (public)YNNYY (public-facing generative service)
Image generationYYNYY
Product recommendation feedNNYYfiling, not full assessment
Internal analytics (no public output)NNNYN

Acceptance criteria

  • Every China-available feature is assessed against each instrument.
  • The trigger for a security assessment versus a filing is recorded per feature.
  • PIPL and data-export obligations are tracked alongside the AI-specific instruments.

2. CAC security assessment checklist

Spreadsheet

The areas a self-assessment (and any filed assessment) must cover for a public generative service.

Template

AreaRequirementStatusEvidence
Training datalawful sources; IP respected; no unlawful content; personal data handled per PIPL
Data annotationannotation rules; staff training; quality checks
Content safetyfiltering for prohibited content categories; refusal behaviour
Output testingpre-release testing against a content-safety test set; documented pass rate
Model transparencydisclosure of service provider; complaint channel
Real-name and minorsuser identity verification; minors protection measures
Incident handlingtakedown, model tuning, and reporting process for unlawful content

Worked example

AreaStatusEvidence
Training dataCompleteprovenance records; content filter on ingestion
Data annotationCompleteannotation SOP; annotator training log
Content safetyCompletemulti-category filter; refusal tests
Output testingComplete2,000-prompt safety set; pass rate documented
Model transparencyCompleteprovider disclosure + complaint form in-product
Real-name / minorsIn progressidentity check via partner; minors mode pending
Incident handlingCompletetakedown + retrain + report runbook

Acceptance criteria

  • Every area has a status and attached evidence.
  • Output testing has a documented test set and a pass rate, not a claim.
  • A content-incident handling process exists and has been exercised.

3. Content labeling implementation specification

Spreadsheet

What must be labeled as AI-generated, how, and in which formats, per the labeling rules.

Template

Content typeExplicit label (visible/audible)Implicit label (metadata)Placement / formatImplemented?
Generated text
Generated images
Generated audio
Generated video

Worked example

Content typeExplicit labelImplicit labelPlacement / formatImplemented?
Generated text"AI-generated" notice near the outputprovider + generated flag in response metadataprepended line; not removable in the UIYes
Generated imagescorner watermark + captionC2PA-style metadata; provider IDbottom-left, min 5% widthYes
Generated audiospoken disclosure at startmetadata tagfirst 2 secondsPartial
Generated videoon-screen label first + persistent corner markmetadata tagfirst 3 seconds + corner throughoutPartial

Acceptance criteria

  • Both explicit (visible/audible) and implicit (metadata) labels are specified per content type.
  • Label placement and format meet the size and duration expectations in the rules.
  • Partial items have an owner and a date.

4. Algorithm filing tracker

Spreadsheet

Filing status, registration numbers, and renewal dates for each algorithm subject to filing.

Template

Algorithm / serviceFiling typeSubmittedRegistration numberApprovedRenewal / update dueOwner
<name>initial / changeYYYY-MM-DDYYYY-MM-DDYYYY-MM-DD<name>

Worked example

Algorithm / serviceFiling typeSubmittedRegistration numberApprovedRenewal / update dueOwner
Text assistant (generative)initial2026-05-10(redacted)2026-07-02on material changeChina Compliance
Recommendation feedinitial2026-04-01(redacted)2026-05-20annual review 2027-05China Compliance

Acceptance criteria

  • Every algorithm subject to filing has an entry with its current status.
  • Material changes to a filed algorithm trigger a change filing, tracked here.
  • Renewal and review dates are on the China compliance calendar.

Governance controls this kit produces evidence for

Completing the artifacts above gives you a head start on the evidence requirements for these controls.

CMP-001
CMP-001

The applicability matrix is multi-jurisdiction mapping for the China instruments.

CMP-006
CMP-006

The labeling specification is the AI content watermarking and labeling compliance record.

DGC-001
DGC-001

The training-data area of the CAC checklist maps to training data provenance.

SAF-004
SAF-004

Output safety testing against a content-safety set is AI reliability testing evidence.

CMP-002
CMP-002

The compliance calendar for CAC guidance updates is part of standards and regulatory monitoring.

This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.

Decide what to implement next

Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.

Start the AI governance assessment →