2026.09.01 周汀 李汭卿
I. Executive Summary
On July 29, 2026, the Cyberspace Administration of China (CAC) released the draft Anti-Cyberbullying Law of the People’s Republic of China (the Draft). Although principally directed at curbing online abuse, the Draft also imposes AI-content monitoring, algorithmic-recommendations and government-cooperation obligations on network service providers that extend beyond its stated subject matter. It is the latest in a rapid succession of Chinese AI and data governance measures and follows the Interim Measures for the Administration of Anthropomorphic AI Interaction Services (the Measures), the Regulation on the Administration of Network Data Security (the Regulation), and the AI Safety Governance Framework 2.0 (the Framework 2.0).
These rules reflect an increasingly dense compliance framework governing AI-generated content, platform accountability and data sovereignty. MNCs operating platforms, AI products or data-intensive operations in China will need to address these requirements as a single, integrated system rather than as a series of isolated rules. The recent blocking of the Meta–Manus transaction further illustrates the broader policy environment: Chinese authorities regard China-connected AI technology, data and talent as strategic assets relevant to national technology security and may intervene through both content and data regulation and investment-review mechanisms.
II. The Draft: Key Provisions Affecting Multinational AI Platforms in China
The Draft consists of seven chapters and 60 articles. While several provisions are aimed at platform governance generally, four are of particular significance for MNCs from a data-compliance and U.S-China competition standpoint.
Article 3 gives the law extraterritorial effect. It applies to cyberbullying conducted within China and provides that organizations and individuals outside China that engage in cyberbullying targeting persons in China may be held liable under the law. This approach is consistent with the long-arm provisions in China’s Personal Information Protection Law (PIPL) and Data Security Law (DSL), and with a broader trend—also reflected in the Network Data Security Regulation discussed below—of Chinese regulators asserting authority over conduct affecting persons or interests in China, even where the actor has no physical presence in the country. For global social-media, gaming and content platforms that serve Chinese users without maintaining an onshore entity, Article 3 materially weakens any assumption that an offshore operating model alone limits exposure to Chinese enforcement.
Article 13 incorporates AI governance directly into platform obligations. It requires network service providers to develop cyberbullying feature databases, case libraries and early-warning models using AI, big data and human review. Separately, it requires providers to strengthen safeguards against the use of AI technology to generate, reproduce, publish or disseminate cyberbullying content. Providers must also implement AI-generated-content labeling systems ‘in accordance with the relevant state regulations’ to improve traceability. This provision connects the Draft to China’s existing AI-generated-content labeling regime and to the training-data obligations discussed in Section IV below. Therefore, platform systems developed for broader trust-and-safety, content-moderation or product purposes will need to be assessed against cyberbullying-specific monitoring and traceability requirements.
Article 21 imposes enhanced duties on platforms with ‘extremely large number of users or have a significant influence on users’. These providers must establish rapid-response mechanisms for cyberbullying, conduct periodic risk assessments, publish annual cyberbullying-governance reports and submit to public oversight. The approach is comparable to the ‘very large online platform’ tier under the EU Digital Services Act and is likely to capture the major global social-media, e-commerce and streaming platforms operating in China. It adds an annual public-reporting requirement and a standing risk-assessment function that are distinct from, but may overlap with, the large-platform reporting duties under the Network Data Security Regulation.
Article 25 establishes a mandatory cooperation obligation. It authorizes the CAC, together with the public security, culture, tourism, radio and television authorities, to supervise and inspect platforms’ compliance with their cyberbullying-governance obligations. Network service providers must ‘promptly provide necessary support and cooperation’ when authorities conduct inspections or collect evidence. Read together with Article 54—which imposes joint and several liability where a provider knew or should have known that a user was using its services to conduct cyberbullying and failed to act—these provisions create a substantial incentive for platforms to provide Chinese authorities with access to user data and internal records. That obligation may create tension with the data-export controls under the Network Data Security Regulation and, for U.S.-headquartered companies, with the applicable U.S. export-control, sanctions or blocking-statute restrictions on disclosures to Chinese authorities.
III. The Measures: A Tailored Regulatory Regime for Companion AI
The Measures, effective July 15, 2026, apply to AI-driven services that simulate a natural person’s personality, thought patterns or communication style in order to provide sustained emotional interaction. This includes companion chatbots, emotional-support applications and comparable products. The Measures expressly exclude customer-service, question-and-answer, work-assistant and educational tools that do not provide sustained emotional interaction.
With respect to data, providers may not share user interaction data with third parties without user consent. They must also enable users to copy or delete their chat history and, absent separate consent, they may not use interaction data constituting sensitive personal information for model training. Providers must label AI-generated content and provide usage-duration reminders after two consecutive hours of use. Large providers—those with at least 1 million registered users or 100,000 monthly active users—must complete a security assessment and file it with the provincial-level CAC before launch and following material changes.
For MNCs, the Measures add a companion-AI-specific layer to the general obligations discussed below. Any global company offering a persona-based AI assistant, companion application or emotionally engaged chatbot to Chinese users—whether through gaming, social-media or consumer-engagement products—may face a filing requirement comparable in practical effect to a licensing obligation; restrictions on using user interaction data for global model training; and tailored safeguards for minors. These requirements differ from the approaches reflected in the EU AI Act’s rules on manipulative AI practices and in the U.S. state-level and Federal Trade Commission scrutiny of companion-AI products. Therefore, they require jurisdiction-specific product design and cannot be addressed simply through a company’s global compliance baseline.
IV. The Regulation: An Underlying Data Architecture
The Regulation, effective since January 1, 2025, functions as the general data-security rulebook against which the AI-specific rules above operate. Like the Draft, it reaches beyond China’s borders: it applies to the processing of PRC individuals’ personal information processed outside China where that processing meets the extraterritoriality criteria in Article 3(2) of the PIPL, and it authorizes the pursuit of legal liability against extraterritorial data processing that harms China’s national security, public interests or the rights of Chinese citizens or organizations.
Three sets of rules are particularly relevant to MNCs. First, ‘important data’ requires data processors to identify and report important data in accordance with the catalogues issued by the competent authorities and industry regulators. It also requires annual risk-assessment reports to the provincial-level or higher regulators addressing processing purposes, security measures, security incidents and cross-border data transfers.
Second, cross-border data-transfers require a government security assessment, certification, execution of a standard contract or reliance on an applicable exemption before personal information may be transferred overseas. Important data collected or generated through Chinese operations is subject to a separate security-assessment requirement before it may be exported.
Third, large network platforms—defined as those with at least 50 million registered users or 10 million monthly active users—are subject to additional obligations, including the publication of an annual personal information protection social-responsibility report and enhanced cross-border data-security measures. Article 19 separately requires providers of generative AI services to strengthen their security management of training data; an obligation reflected in more detailed form in Article 11 of the Measures referenced above.
V. The Framework 2.0: Policy Considerations Behind the Rules
Framework 2.0, released on September 15, 2025, refines the risk taxonomy established in Framework 1.0. It retains the categories of intrinsic AI safety risks and application safety risks and adds a third category— ‘application-derived risks’—to address broader societal effects, including employment displacement and algorithmic bias. It also identifies ‘trustworthy application and the prevention of the loss of control’ as a guiding principle. Although Framework 2.0 does not impose legally enforceable obligations, its focus on controllability, traceability and human oversight for frontier and agentic AI systems offers a useful indication of the regulatory direction.
VI. Conclusion: What This Regulatory Build-Out Means for Multinationals
Taken together, these four instruments reflect the sustained and accelerating effort by Chinese regulators to establish a comprehensive, interlocking AI and data-governance framework in a relatively short period. The direction is clear: expanded extraterritorial reach; AI-specific obligations concerning content and training data layered onto general data-security requirements; and increased reporting and risk-assessment obligations for large platforms.
This regulatory development reflects the priority Chinese authorities place on AI safety, trustworthiness and data sovereignty as matters of national security. The regulatory intervention in the Meta–Manus transaction, notwithstanding the target’s offshore restructuring, illustrates the broader policy posture: AI technology, data and talent with substantial Chinese connections may be treated as strategic assets within China’s regulatory reach, regardless of the corporate form. For multinationals, the practical implications are threefold.
Regarding compliance, the overlapping monitoring, labeling, reporting and assessment requirements call for a coordinated compliance program spanning platform governance, AI training-data management, important-data identification and cataloguing, and cross-border transfer mechanisms.
Regarding cross-border data transfers, the extraterritorial provisions and mandatory government-cooperation requirements in both the Draft and the Regulation increase the prospect of conflict between Chinese data-localization or disclosure requirements and export-control, sanctions or data-transfer restrictions in an MNC’s home jurisdiction.
Regarding U.S.–China competition, these regulations operate alongside China’s foreign investment security-review and technology-export-control regimes as a means of maintaining regulatory reach over strategically significant AI capabilities, data and talent. Therefore, MNCs considering AI- or data-driven operations, transactions or partnerships in China should assess their compliance and geopolitical risk as a single, integrated issue.
Disclaimer
Articles published on JunHe's official website represent only the opinions of the authors and should not in any way be considered as formal legal opinions or advice given by JunHe or its lawyers. If any part of these articles is reproduced or quoted, please indicate the source.Any picture or image contained in these articles MUST not be reproduced or used unless otherwise consented by us in writing. You are welcome to contact us for any further discussion or exchange of views on the relevant topic.