TC260 mandatory/voluntary standards
Issuer: National Cybersecurity Standardization Technical Committee
Date: ONGOING
Status: IN FORCE in China, as of 29 JUL 2026
GB/T 45654-2025, GB/T 45652-2025 (eff. Nov 2025), GB/T 42888-2023; WG9 AI Security Working Group (2026); 400+ standards.
The 'law + standard' dual drive. Key outputs: TC260-003 (Basic Security Requirements for GenAI Services, Feb 2024, the technical checklist for GenAI filings); GB 45438-2025 (labeling, mandatory); GB/T 45654-2025 and GB/T 45652-2025 (GenAI security + training-data security, eff. 1 Nov 2025); GB/T 42888-2023 (ML algorithm security assessment). TC260's AI Security Working Group (WG9) opened membership Mar 2026; 400+ cybersecurity standards published overall.
What it actually requires (4 provisions)
- TC260-003: the technical checklist behind GenAI filings (Feb 2024)
- GB 45438-2025: mandatory labeling standard (eff. 1 Sep 2025)
- GB/T 45654-2025 / 45652-2025: GenAI + training-data security (eff. 1 Nov 2025)
- WG9 AI Security Working Group (2026); 400+ standards published
How its status moved
- BASELINEGB/T 42888-2023: ML security assessment
- EXPANDEDGB 45438-2025 + GB/T 45654/45652 (2025)
- CURRENTWG9 active; mandatory standards for agents proposed
Sources (1)
TC260: TC260 AI standards program
'Law + standard' dual drive: GB 45438-2025 (mandatory labeling), GB/T 45654/45652-2025, 400+ cybersecurity standards.
The rest of the China stack
12 more instruments in this jurisdiction, each with its own status, provisions and sources.
- Algorithm Recommendation ProvisionsIN FORCEFirst binding algorithm rules; opt-out of feeds; anti-cocoon; created the CAC filing registry.
- Deep Synthesis ProvisionsIN FORCEReal-name, consent of impersonated persons, prominent labeling, algorithm filing.
- GenAI Interim Measures (CAC Order No. 15)IN FORCEPublic GenAI needs security assessment + filing before launch (Art. 17); socialist-core-values content duties.
- CAC filing registriesIN FORCE868 GenAI services + 530 apps (Apr 2026); ~5,672 deep-synthesis algorithms in 14 batches; >5,000 recommendation algorithms; public lists.
- AI Content Labeling Measures + GB 45438-2025IN FORCEDual explicit + implicit labels; platform verification; tampering prohibited.
- Facial Recognition Security MeasuresIN FORCECommercial FR: consent, DPIA, local storage, mandatory-scan bans, 100k-faces filing; state use via PIPL Art. 26 carve-out.
- Anthropomorphic AI Interaction Measures (Decree No. 21)IN FORCEWorld-first companion rulebook: disclosure each session, 2-hr break prompts, minor companion ban, ≤RMB 200k fines; Doubao/Qwen features shut at deadline.
- AI Safety Governance Framework v1.0/v2.0VOLUNTARY / SOFT LAWFirst cross-scenario risk classification; lifecycle duties; agents & embodied AI in v2.0.
- Comprehensive national AI lawNOT ENACTED2025 legislative plans softened commitment; official draft reported Dec 2025 ⚠; AI provisions instead folded into amended Cybersecurity Law (eff. 1 Jan 2026).
- PBOC Credit Reporting MeasuresIN FORCECredit scoring = licensed business; explainable, traceable, filed models; mainland data storage.
- Shanghai AI Industry RegulationIN FORCEFirst provincial AI law; sandbox, graded management, ethics council; Art. 69 recruitment non-discrimination.
- Global AI Governance Initiative (2023) + Action Plan (Jul 2025)IN FORCE13-point roadmap; proposed Global AI Cooperation Organization, potential Shanghai HQ.
Where this sits in the wider picture
- The China regime dossier gives the doctrine this instrument belongs to, next to the other two jurisdictions.
- The Framework Explorer, filtered to CN lists every instrument in this jurisdiction in one filterable index.
- The governance simulator shows what these rules do to a real AI system, next to what the other two jurisdictions do to the same one.
- The timeline places this date beside what the other capitals were doing that month.
Knowing the instrument is step one. Complying with it is the job.
The programs teach the work that follows a rule like this one: classification calls, conformity assessment, filings, documentation, and the judgment to defend every decision.
VERIFIED 29 JUL 2026. Every fact on this page is drawn from the sources listed above and dated to the day it was checked. Study aid, not legal advice: the official texts are always authoritative.