Skip to main content
ChinaIN FORCE

TC260 mandatory/voluntary standards

Issuer: National Cybersecurity Standardization Technical Committee

Date: ONGOING

Status: IN FORCE in China, as of 29 JUL 2026

GB/T 45654-2025, GB/T 45652-2025 (eff. Nov 2025), GB/T 42888-2023; WG9 AI Security Working Group (2026); 400+ standards.

The 'law + standard' dual drive. Key outputs: TC260-003 (Basic Security Requirements for GenAI Services, Feb 2024, the technical checklist for GenAI filings); GB 45438-2025 (labeling, mandatory); GB/T 45654-2025 and GB/T 45652-2025 (GenAI security + training-data security, eff. 1 Nov 2025); GB/T 42888-2023 (ML algorithm security assessment). TC260's AI Security Working Group (WG9) opened membership Mar 2026; 400+ cybersecurity standards published overall.

What it actually requires (4 provisions)

  • TC260-003: the technical checklist behind GenAI filings (Feb 2024)
  • GB 45438-2025: mandatory labeling standard (eff. 1 Sep 2025)
  • GB/T 45654-2025 / 45652-2025: GenAI + training-data security (eff. 1 Nov 2025)
  • WG9 AI Security Working Group (2026); 400+ standards published

How its status moved

  1. BASELINEGB/T 42888-2023: ML security assessment
  2. EXPANDEDGB 45438-2025 + GB/T 45654/45652 (2025)
  3. CURRENTWG9 active; mandatory standards for agents proposed

Sources (1)

The rest of the China stack

12 more instruments in this jurisdiction, each with its own status, provisions and sources.

Where this sits in the wider picture

Knowing the instrument is step one. Complying with it is the job.

The programs teach the work that follows a rule like this one: classification calls, conformity assessment, filings, documentation, and the judgment to defend every decision.

VERIFIED 29 JUL 2026. Every fact on this page is drawn from the sources listed above and dated to the day it was checked. Study aid, not legal advice: the official texts are always authoritative.