AI Safety Governance Framework v1.0/v2.0
Issuer: TC260 (under CAC guidance)
Date: SEP 2024
Status: VOLUNTARY / SOFT LAW in China, as of 29 JUL 2026
First cross-scenario risk classification; lifecycle duties; agents & embodied AI in v2.0.
China's first cross-scenario AI risk classification system: a shift from 'one rule per scenario' toward systemic governance. v1.0 (9 Sep 2024): four risk categories (model/algorithm, data, system, application). v2.0 (15 Sep 2025): finer risk grading, lifecycle coverage from R&D to decommissioning, explicit duties for developers/providers/users, and new coverage of AI agents and embodied intelligence. Soft law, a Level-4 normative document, not binding, positioning China for a future unified AI law.
What it actually requires (3 provisions)
- v1.0: four risk categories: model/algorithm, data, system, application (Sep 2024)
- v2.0: finer risk grading, full-lifecycle duties, AI agents + embodied intelligence (Sep 2025)
- Soft law, not binding; positions for a future unified AI law
How its status moved
- V1.09 Sep 2024
- V2.015 Sep 2025
- CURRENTSoft law: de facto national risk vocabulary
Sources (1)
Framework 2.0: AI Safety Governance Framework
China's first cross-scenario AI risk classification; v2.0 adds lifecycle duties, agents and embodied AI.
The rest of the China stack
12 more instruments in this jurisdiction, each with its own status, provisions and sources.
- Algorithm Recommendation ProvisionsIN FORCEFirst binding algorithm rules; opt-out of feeds; anti-cocoon; created the CAC filing registry.
- Deep Synthesis ProvisionsIN FORCEReal-name, consent of impersonated persons, prominent labeling, algorithm filing.
- GenAI Interim Measures (CAC Order No. 15)IN FORCEPublic GenAI needs security assessment + filing before launch (Art. 17); socialist-core-values content duties.
- CAC filing registriesIN FORCE868 GenAI services + 530 apps (Apr 2026); ~5,672 deep-synthesis algorithms in 14 batches; >5,000 recommendation algorithms; public lists.
- AI Content Labeling Measures + GB 45438-2025IN FORCEDual explicit + implicit labels; platform verification; tampering prohibited.
- Facial Recognition Security MeasuresIN FORCECommercial FR: consent, DPIA, local storage, mandatory-scan bans, 100k-faces filing; state use via PIPL Art. 26 carve-out.
- Anthropomorphic AI Interaction Measures (Decree No. 21)IN FORCEWorld-first companion rulebook: disclosure each session, 2-hr break prompts, minor companion ban, ≤RMB 200k fines; Doubao/Qwen features shut at deadline.
- TC260 mandatory/voluntary standardsIN FORCEGB/T 45654-2025, GB/T 45652-2025 (eff. Nov 2025), GB/T 42888-2023; WG9 AI Security Working Group (2026); 400+ standards.
- Comprehensive national AI lawNOT ENACTED2025 legislative plans softened commitment; official draft reported Dec 2025 ⚠; AI provisions instead folded into amended Cybersecurity Law (eff. 1 Jan 2026).
- PBOC Credit Reporting MeasuresIN FORCECredit scoring = licensed business; explainable, traceable, filed models; mainland data storage.
- Shanghai AI Industry RegulationIN FORCEFirst provincial AI law; sandbox, graded management, ethics council; Art. 69 recruitment non-discrimination.
- Global AI Governance Initiative (2023) + Action Plan (Jul 2025)IN FORCE13-point roadmap; proposed Global AI Cooperation Organization, potential Shanghai HQ.
Where this sits in the wider picture
- The China regime dossier gives the doctrine this instrument belongs to, next to the other two jurisdictions.
- The Framework Explorer, filtered to CN lists every instrument in this jurisdiction in one filterable index.
- The governance simulator shows what these rules do to a real AI system, next to what the other two jurisdictions do to the same one.
- The timeline places this date beside what the other capitals were doing that month.
Knowing the instrument is step one. Complying with it is the job.
The programs teach the work that follows a rule like this one: classification calls, conformity assessment, filings, documentation, and the judgment to defend every decision.
VERIFIED 29 JUL 2026. Every fact on this page is drawn from the sources listed above and dated to the day it was checked. Study aid, not legal advice: the official texts are always authoritative.