# China AI Compliance Checklist and Algorithm Filing Tracker

The compliance set for offering AI services in China: an applicability matrix across the CAC instruments, a security assessment checklist, a content labeling specification, and an algorithm filing tracker.

**Who this is for:** The compliance owner for AI products available to users in mainland China.

Source playbook: https://aigovernance.com/playbook/china-ai-regulation-compliance

---

## China AI regulatory applicability matrix

_Which CAC instrument applies to which product or feature._

### Template

| Product / feature | Generative AI Measures | Deep Synthesis Provisions | Algorithm Recommendation Provisions | Data / PIPL | Security assessment required? |
|---|---|---|---|---|---|
| <feature> | Y / N | Y / N | Y / N | Y / N | Y / N |

### Worked example

| Product / feature | Generative AI Measures | Deep Synthesis | Algorithm Recommendation | Data / PIPL | Security assessment? |
|---|---|---|---|---|---|
| Text assistant (public) | Y | N | N | Y | Y (public-facing generative service) |
| Image generation | Y | Y | N | Y | Y |
| Product recommendation feed | N | N | Y | Y | filing, not full assessment |
| Internal analytics (no public output) | N | N | N | Y | N |

### Acceptance criteria

- Every China-available feature is assessed against each instrument.
- The trigger for a security assessment versus a filing is recorded per feature.
- PIPL and data-export obligations are tracked alongside the AI-specific instruments.

---

## CAC security assessment checklist

_The areas a self-assessment (and any filed assessment) must cover for a public generative service._

### Template

| Area | Requirement | Status | Evidence |
|---|---|---|---|
| Training data | lawful sources; IP respected; no unlawful content; personal data handled per PIPL | | |
| Data annotation | annotation rules; staff training; quality checks | | |
| Content safety | filtering for prohibited content categories; refusal behaviour | | |
| Output testing | pre-release testing against a content-safety test set; documented pass rate | | |
| Model transparency | disclosure of service provider; complaint channel | | |
| Real-name and minors | user identity verification; minors protection measures | | |
| Incident handling | takedown, model tuning, and reporting process for unlawful content | | |

### Worked example

| Area | Status | Evidence |
|---|---|---|
| Training data | Complete | provenance records; content filter on ingestion |
| Data annotation | Complete | annotation SOP; annotator training log |
| Content safety | Complete | multi-category filter; refusal tests |
| Output testing | Complete | 2,000-prompt safety set; pass rate documented |
| Model transparency | Complete | provider disclosure + complaint form in-product |
| Real-name / minors | In progress | identity check via partner; minors mode pending |
| Incident handling | Complete | takedown + retrain + report runbook |

### Acceptance criteria

- Every area has a status and attached evidence.
- Output testing has a documented test set and a pass rate, not a claim.
- A content-incident handling process exists and has been exercised.

---

## Content labeling implementation specification

_What must be labeled as AI-generated, how, and in which formats, per the labeling rules._

### Template

| Content type | Explicit label (visible/audible) | Implicit label (metadata) | Placement / format | Implemented? |
|---|---|---|---|---|
| Generated text | | | | |
| Generated images | | | | |
| Generated audio | | | | |
| Generated video | | | | |

### Worked example

| Content type | Explicit label | Implicit label | Placement / format | Implemented? |
|---|---|---|---|---|
| Generated text | "AI-generated" notice near the output | provider + generated flag in response metadata | prepended line; not removable in the UI | Yes |
| Generated images | corner watermark + caption | C2PA-style metadata; provider ID | bottom-left, min 5% width | Yes |
| Generated audio | spoken disclosure at start | metadata tag | first 2 seconds | Partial |
| Generated video | on-screen label first + persistent corner mark | metadata tag | first 3 seconds + corner throughout | Partial |

### Acceptance criteria

- Both explicit (visible/audible) and implicit (metadata) labels are specified per content type.
- Label placement and format meet the size and duration expectations in the rules.
- Partial items have an owner and a date.

---

## Algorithm filing tracker

_Filing status, registration numbers, and renewal dates for each algorithm subject to filing._

### Template

| Algorithm / service | Filing type | Submitted | Registration number | Approved | Renewal / update due | Owner |
|---|---|---|---|---|---|---|
| <name> | initial / change | YYYY-MM-DD | | YYYY-MM-DD | YYYY-MM-DD | <name> |

### Worked example

| Algorithm / service | Filing type | Submitted | Registration number | Approved | Renewal / update due | Owner |
|---|---|---|---|---|---|---|
| Text assistant (generative) | initial | 2026-05-10 | (redacted) | 2026-07-02 | on material change | China Compliance |
| Recommendation feed | initial | 2026-04-01 | (redacted) | 2026-05-20 | annual review 2027-05 | China Compliance |

### Acceptance criteria

- Every algorithm subject to filing has an entry with its current status.
- Material changes to a filed algorithm trigger a change filing, tracked here.
- Renewal and review dates are on the China compliance calendar.

---

## Governance controls this kit produces evidence for

- **CMP-001**: The applicability matrix is multi-jurisdiction mapping for the China instruments.
- **CMP-006**: The labeling specification is the AI content watermarking and labeling compliance record.
- **DGC-001**: The training-data area of the CAC checklist maps to training data provenance.
- **SAF-004**: Output safety testing against a content-safety set is AI reliability testing evidence.
- **CMP-002**: The compliance calendar for CAC guidance updates is part of standards and regulatory monitoring.
