Healthcare AI 2025

CHINA Trends and Developments Contributed by: Gil Zhang, Diana Li, Muran Sun and Huihui Li, Fangda Partners

data assets. This creates legal risks for healthcare AI companies using competitors’ data without authori - sation during model training, which may be deemed improper appropriation of commercial resources and market disruption. This trend underscores the growing importance for healthcare AI companies of establish - ing clear compliance boundaries between technologi - cal innovation and fair competition. Regulatory Developments and Trends Existing regulatory landscape China currently lacks a unified legal framework specif - ically tailored to healthcare AI. In China, any AI-based medical software meeting the statutory definition of a “medical device” is regulated as such. The sectoral regulatory landscape is composed of existing regula - tory rules, such as the Regulation on the Supervision and Administration of Medical Devices (Revised in 2024) and the Administrative Measures on the Regis - tration and Record-filing of Medical Devices. Accord - ingly, AI medical software qualifying as a medical device will be categorised under the Guiding Princi - ples for the Classification and Definition of AI-based Medical Software Products as Class II/III medical devices, depending on their algorithm maturity level and specific functionalities. This sectoral regulatory framework is further supplemented by specialised technical guidelines, such as the Guiding Principles for Registration Review of AI-based Medical Devices and the Key Review Points for Deep Learning-Assist - ed Decision-Making Medical Device Software. Likewise, regulatory rules universally applicable to generative AI (GenAI) and algorithms, as well as cybersecurity and data protection, will apply for cor - responding issues, including the Interim Measures for the Administration of Generative Artificial Intelli - gence Services (the “Gen AI Measures”), the Provi - sions on the Administration of Algorithm-generated Recommendations for Internet Information Services (the “Algorithm Provisions”), the Cybersecurity Law, the Data Security Law and the Personal Information Protection Law. Aside from general data and privacy protection requirements, the following compliance action items are especially worthy of attention from companies operating healthcare AI.

• LLM and algorithm filing: Any GenAI service that interacts with the public and has the potential to influence public opinion or mobilise social action must undergo a formal security assessment and register with the provincial CAC under the Gen AI Measures (referred to as “LLM filing”). Addition - ally, these services must complete the algorithm filing procedures under the Algorithm Provisions (“algorithm filing”). For GenAI services based on third-party LLMs that have already been filed, via an application programming interface (API) or other technical means, a simplified registration process at the provincial CAC is required instead of the full LLM filing. • Training data and algorithm security: If a healthcare AI developer engages in pre-training or fine-tuning activities rather than directly invoking third-party LLM APIs, they must: (a) use data from legitimate sources; (b) avoid the use of personal information, or if necessary, ensure that appropriate consent or other lawful bases are satisfied; and (c) enhance the quality of training data by improv - ing its authenticity, accuracy, objectivity and diversity. • Content moderation: GenAI services are pro - hibited from producing any content that violates laws or regulations, such as material that incites subversion of state power, undermines the social - ist system or endangers national security. Provid - ers of GenAI services are primarily responsible for content safety. They must immediately cease generation and dissemination, remove any offend - ing content and retrain their models upon detecting any prohibited material. • Cybersecurity multilevel protection scheme (MLPS): Medical institutions and companies deploying and operating on-premises AI diagnostic systems must conduct pre-deployment security risk assessments and fulfil relevant MLPS obliga - tions. This includes system grading, filing with local public security organs and conducting regular security assessments. Under China’s updated MLPS 3.0 (2025), operators of healthcare systems are required to reassess the grading of their sys - tems based on new standards and complete data inventories for systems above level 2.

62

CHAMBERS.COM

Powered by