AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

Not sure where to start? Answer 3 questions and get a tailored compliance action plan.

What applies to me? →
Must ComplyRegulationChinaHigh riskLimited riskMinimal risk

Interim Measures for Artificial Intelligence Anthropomorphic Interactive Services

Issued by

Cyberspace Administration of China, National Development and Reform Commission, Ministry of Industry and Information Technology, Ministry of Public Security, State Administration for Market Regulation

liveEffective 2026-07-15CN-AIAISVerified August 2026

China's Interim Measures for Artificial Intelligence Anthropomorphic Interactive Services establish a binding administrative framework governing AI systems that simulate human-like interaction, including conversational agents and agentic AI products. The rules apply to providers and deployers of such services operating within Chinese jurisdiction. They require defined user authorization boundaries, tiered risk approvals, and registration obligations before services can be offered to the public.

Applies To

Large enterpriseSMBAI developerAI deployer

Overview

The Interim Measures, jointly issued by five Chinese regulatory bodies, took effect on July 15, 2026, and represent China's first dedicated binding framework targeting AI services that exhibit anthropomorphic characteristics such as persona adoption, conversational continuity, or autonomous task execution. The rules apply to any organization providing or deploying anthropomorphic AI interactive services to users in China, regardless of where the operator is incorporated. Core provisions include mandatory scope restrictions on what actions AI agents may take on behalf of users, explicit user authorization requirements before AI systems perform consequential tasks, and a risk-tiered filing and approval system calibrated to the potential social and economic impact of the service. Enforcement authority is distributed across the five co-issuing agencies, with the Cyberspace Administration of China holding primary oversight responsibility for internet-facing services. Non-compliant services may be subject to suspension orders, administrative fines, or removal from Chinese app stores and distribution platforms.

Key Requirements

  • Providers must define and technically enforce explicit user authorization boundaries before any AI system performs tasks on a user's behalf.
  • All anthropomorphic AI interactive services must complete a risk-tiered filing with the Cyberspace Administration of China prior to public launch, with higher-risk services subject to pre-approval review.
  • Services classified as higher risk must implement real-time behavioral logging sufficient to reconstruct agent actions for regulatory audit.
  • Providers must disclose to users that they are interacting with an AI system and may not design interfaces that deliberately obscure this fact.
  • Operators must establish accessible user complaint and redress mechanisms and respond to regulatory inquiries within prescribed timeframes.
  • Foreign enterprises offering services to Chinese users must designate a local compliance representative or entity accountable to Chinese regulators.

What Your Organization Must Do

  • Audit all AI interactive products and features deployed in China or directed at Chinese users and classify each by the risk tier criteria defined in the Measures.
  • Map existing user consent flows and agent permission architectures to the authorization boundary requirements, and remediate gaps before operating under the new framework.
  • Complete pre-launch filings for any anthropomorphic AI service not yet registered, prioritizing products that execute tasks or make decisions on user behalf.
  • Appoint or contract a China-resident compliance representative if your organization lacks a registered local entity, and document this designation in writing.
  • Update data retention and logging infrastructure to capture agent action records at the granularity required for regulatory audit requests.
  • Review vendor and partner contracts to confirm that third-party AI components integrated into your services meet the Measures' disclosure and authorization requirements.

Playbook Guidance

Step-by-step implementation guidance for compliance teams.

Frequently Asked Questions

Does CN-AIAIS apply to foreign companies offering anthropomorphic AI services to Chinese users without a local entity?
Yes. The Measures apply to any organization providing anthropomorphic AI interactive services to users in China, regardless of where the operator is incorporated. Foreign enterprises without a registered local entity must designate a China-resident compliance representative accountable to Chinese regulators before offering such services.
What is the filing deadline for anthropomorphic AI services already operating in China before the July 2026 effective date?
The Measures took effect on July 15, 2026, and require pre-launch filing with the Cyberspace Administration of China before services are offered to the public. Organizations operating existing services should treat the effective date as the trigger for immediate compliance review, though the draft text does not specify a separate grandfathering grace period.
What penalties can regulators impose on providers that fail to comply with CN-AIAIS?
Non-compliant services may face suspension orders, administrative fines, or removal from Chinese app stores and distribution platforms. Enforcement authority is shared across five co-issuing agencies, with the Cyberspace Administration of China holding primary oversight for internet-facing services.
How does the risk-tiered filing system under CN-AIAIS work, and which services require pre-approval rather than simple registration?
All anthropomorphic AI interactive services must complete a risk-tiered filing before public launch, with the tier determined by the service's potential social and economic impact. Higher-risk services, such as those executing consequential tasks autonomously on behalf of users, are subject to a pre-approval review rather than simple notification filing.
What logging and record-keeping obligations apply to higher-risk anthropomorphic AI services under the Measures?
Services classified as higher risk must implement real-time behavioral logging granular enough to allow regulators to fully reconstruct agent actions during an audit. Providers should update their data retention and logging infrastructure now to meet this standard, as it exceeds typical application-level activity logging.
How does CN-AIAIS compare to the EU AI Act in its treatment of AI systems that simulate human interaction?
Both frameworks require disclosure that users are interacting with an AI, but CN-AIAIS goes further by mandating technically enforced user authorization boundaries before any agent acts on a user's behalf. The EU AI Act addresses transparency obligations broadly, while CN-AIAIS specifically targets agentic and conversational AI with a dedicated filing and approval structure.