Cybersecurity 2026

CHINA Trends and Developments Contributed by: Kate Yin, Sherman Deng, Yanjun Zhuang and Patrick Guo, Fangda Partners

Information Services, both traditional AI and Gen AI algorithms must be filed with central CAC (“Algorithm Filing”). Separately, pursuant to the Interim Measures for the Administration of Generative Artificial Intelli - gence Services, providers of Gen AI services must also file with provincial CAC (“Gen AI Filing”). Accord - ingly, Gen AI products follow a “dual filing” require - ment. Traditional AI components are subject to Algo - rithm Filing, while the Gen AI component requires Gen AI Filing. In comparison, purely traditional AI products without generative functionality only require Algorithm Filing. Take the example for interpretation, if an AI product consists of three components: (i) Gen AI; (ii) search algorithm; and (iii) ranking algorithm, Algorithm Filing is required for items (ii) and (iii), while Gen AI Filing applies to item (i). Products that rely on foreign-based SaaS services or overseas infrastructure are generally considered regu - latory “vulnerability” as such services fall outside Chi - nese jurisdiction and often lack mandatory Chinese requirements, such as MLPS certification, “positive energy” content mechanisms, and controls to prevent prohibited or sensitive content. Consequently, CAC tends to apply a more cautious review standard in practice. The “dual filing” essentially mandates AI developers to disclose the core aspects of public-facing AI systems, including: (i) the developer’s risk management system; (ii) data protection; (iii) technical documentation; (iv) record keeping; (v) transparency and explainability; (vi) human oversight; (vii) assessments for robust - ness, accuracy and cybersecurity; and (viii) content moderation. Summary of new developments The 2026 regulatory landscape introduces high- stakes enforcement for AI. First, public-facing AI ser - vices that have not completed the required filing may be subject to enforcement sweeps by CAC, including taking these services down, particularly if the service has a large user base or generates illegal content. For example, the founder of the AI service Alien Chat is under criminal prosecution for pornographic content generated by AI.

Second, AI Companion services featuring human emulation reaching specific thresholds, such as one million registered users, are now required to undergo mandatory security assessments by CAC. App stores are also deputised to verify compliance before listing services. For businesses operating in China, 2026 marks a shift toward integrated governance and enforceable techni - cal standards, requiring immediate gap assessments and governance upgrades to navigate heightened supervisory scrutiny and operational requirements. Mitigation measures We would recommend foreign businesses operating in China establish and continuously improve a cyberse - curity compliance programme to keep pace with rapid legal and technological developments. As Sun Tsu famously said in the Art of War, “Don’t work on the assumptions that your opponents will not attack, but on the assumption that they will attack but you already have a contingency plan”. Given the inevitability of cybersecurity incidents and the ensu - ing government inspection, companies should adopt a security by default and security by design strategy, continuously enhancing their compliance programmes so that, when regulators knock on the door, affirmative defences are already in place. At its core, the programme can be summarised as “know it, do it, test it”. A company will need to know its data and assets through proactive inventory and discovery process, and align them with applicable legal requirements via data mapping and RoPA. Once mapping is complete, companies must build control points, for example, completing MLPS for key assets, dual filing for Gen AI, and setting up multi-factor authentication for admin account holders. After the control points are set up, companies also need to test these control points through assessments and audits to ensure they are effective, resilient and robust. All of these efforts, if preserved through excellent “record keeping” in the form of audit reports, management communication and training records, will serve as exculpatory evidence or credits of the company, helping to mitigate liability in the event of regulatory enforcement.

94 CHAMBERS.COM

Powered by