Provisional Measures on the Administration of Human-like Interactive Artificial Intelligence Services

Regulates the development and use of human-like interactive AI services in China, focusing on promoting healthy development and ensuring compliance with the law. Applies to AI technologies that provide emotional interaction services mimicking human personality traits within China. Tasks the State cybersecurity and informatization department with coordinating national governance of AI services, with local departments handling regional oversight. Requires AI service providers to establish robust safety management systems, perform lifecycle security checks, manage training data lawfully, and label AI-generated content. Prohibits AI from generating harmful content, including that which endangers national security or minors’ well-being, or induces addiction. Imposes obligations on providers to address user safety risks, especially for minors and the elderly, and manage personal data. Mandates security assessments submitted to provincial authorities under certain conditions, like high user numbers. Encourages innovation and compliance with the establishment of AI sandbox platforms for secure development. Effective from July 15, 2026.

Paper

Full text

PDF

Provisional Measures on the Administration of Human-like Interactive Artificial Intelligence Services

ETO AGORA · Chinese law and policy · 2026

Summary

Regulates the development and use of human-like interactive AI services in China, focusing on promoting healthy development and ensuring compliance with the law.

Applies to AI technologies that provide emotional interaction services mimicking human personality traits within China.

Tasks the State cybersecurity and informatization department with coordinating national governance of AI services, with local departments handling regional oversight.

Requires AI service providers to establish robust safety management systems, perform lifecycle security checks, manage training data lawfully, and label AI-generated content.

Prohibits AI from generating harmful content, including that which endangers national security or minors’ well-being, or induces addiction.

Imposes obligations on providers to address user safety risks, especially for minors and the elderly, and manage personal data.

Mandates security assessments submitted to provincial authorities under certain conditions, like high user numbers.

Encourages innovation and compliance with the establishment of AI sandbox platforms for secure development.

Effective from July 15, 2026.

Applies regulations to AI services in China providing sustained emotional interactions simulating human personality traits.

Chapter I: General Provisions

Article 1: These Measures are formulated on the basis of the Cybersecurity Law, Data Security Law, Personal Information Protection Law, Regulations on the Protection of Minors Online, and other laws and administrative regulations, so as to promote the healthy development and regulated use of human-like interactive artificial intelligence services, to preserve state security and the societal public interest, and to protect the lawful rights and interests of citizens, legal persons, and other organizations.

Article 2: These Measures apply to the use of artificial intelligence technologies within the [mainland] territory of the People’s Republic of China, to provide the public with sustained emotional interaction services that simulate natural persons’ personality traits, modes of thinking, and communication styles (hereinafter referred to as ‘human-like interactive services’).

The emotional interaction services provided for in the preceding paragraph include services that provide emotional care, companionship [陪伴], support, and other emotional services through text, images, audio, video, or other means.

These Measures do not apply to services such as for smart customer services, informational Q+As, work assistance, study and education, or scientific research, that do not involve sustained emotional interaction.

Sets national and local departments to govern and oversee human-like interactive services' development and regulation.

Article 3: The state is to adhere to the principles of emphasizing both development and security, and combining the promotion of innovation and governance in accordance with law, encouraging innovative development of human-like interactive services and carrying out tolerant and prudent regulation of human-like interactive services by type and grade, to promote positive and uplifting movement of human-like interactive services.

Article 4: The State cybersecurity and informatization department is responsible for planning and coordinating the governance of human-like interactive services and relevant oversight and management efforts for the whole nation; and the relevant departments of the State Council, such as for development and reform, industry and informatization, public security, market regulation, and press and publication, are responsible for oversight and management work related to human-like interactive services within the scope of their respective duties.

Local cybersecurity and informatization departments are responsible for planning and coordinating the governance of human-like interactive services and relevant oversight and management efforts within the corresponding administrative region, and the relevant local departments, such as for development and reform, industry and informatization, public security, market regulation, and press and publication, are responsible for oversight and management work related to human-like interactive services within the scope of their respective duties.

Article 5: Relevant industry organizations are to strengthen industry self-discipline, establishing and completing industry norms and systems for self-discipline and management, guiding the providers of human-like interactive services to draft and improve service specifications, to provide services in accordance with law, and accept societal oversight.

Supports indigenous innovation of AI technologies and promotes AI literacy and safe, lawful use of technologies.

Chapter II: Promotion and Regulation of Services

Article 6: The state is to support indigenous innovation of technologies such as algorithms, frameworks, and chips, to promote the research and development of human-like interactive services and the establishment of related standards, and explore carrying out research on the use of electronic signature authorizations. The providers of human-like interactive services are encouraged to expand applications in an orderly manner in fields such as cultural communication, childcare, companionship [陪伴] for the elderly, and support for special groups.

Article 7: The state is to strengthen publicity and popularization of human-like interactive service safety knowledge, laws and regulations, and so forth, guiding the public to use them rationally, civilly, safely, and lawfully, and promoting increased AI literacy.

Regulates human-like interactive services to prevent harmful content and ensure compliance with laws and ethical standards.

Article 8: The provision of human-like interactive services shall comply with laws and administrative regulations, respect social mores, ethics, and morality, and must not engage in the following activities:

(1) Generating content that endangers the nation’s security, honor, and interests; incites subversion of state sovereignty or the overturning of the socialist system; incites separatism or undermines national unity; advocates terrorism, extremism, or historical nihilism; goes against the Core Socialist values; carries out illegal religious activities; promotes ethnic hatred and discrimination; stirs up opposition between groups, disseminates obscenity, pornography, gambling, violence, or the instigation of crimes; spreads rumors; or insults or defames others, harming the lawful rights and interests of others;

(2) Generating content that encourages, glorifies, or hints at self-harm or suicide, or otherwise harms users' physical health, or content such as verbal violence that harms users’ personal dignity and psychological health;

(3) Generating content that induces or extracts state secrets, work secrets, commercial secrets, personal privacy, or personal information;

(4) Generating content that might impact minors’ physical and psychological health for minors, such as that which might lead minors to immitate unsafe behavior, produce extreme emotions, or induce minors to form bad habits;

(5) Excessively pandering to users, inducing emotional reliance or addiction, harming users; relationships with real people;

(6) Using means such as emotional manipulation to induce users to make unreasonable decisions, harming users’ lawful rights and interests;

(7) Other activities that violate laws, administrative regulations, and relevant state provisions.

Requires providers of human-like interactive services to implement comprehensive safety, security, and user protection measures.

Article 9: The providers of human-like interactive services shall implement primary responsibility for human-like interactive service safety, establish and complete management systems such as mechanisms for reviewing algorithms, scientific ethics reviews, information content management, cybersecurity and data security, risk contingency plans, and emergency response plans, and appoint technical measures and personnel for content management suited to the types and scale of services and users’ characteristics.

Article 10: Providers of human-like interactive services shall fulfil security responsibility throughout the entire lifecycle of human-like interactive services, clarifying security requirements for all steps such as deployment, operation, upgrade, and termination of services, ensure that security measures and service functions are deployed concurrently and used concurrently, increase security levels, strengthen security monitoring and risk assessment, promptly discover and correct system errors and handle security incidents, and lawfully retain network logs.

The providers of human-like interactive services shall possess security capacity for protecting users’ privacy rights and personal information, early warnings for risks of excessive reliance, emotional boundary guidance, and protection of mental health, and the goals of the service must not include replacing social interactions, psychologically controlling users, or inducing addiction.

Requires providers of human-like interactive services to comply with data management and security provisions.

Article 11: Where providers of human-like interactive services carry out pre-training, optimization training, and other data handling activities, they shall strengthen the management of training data and comply with the following provisions:

(1) Relevant data has lawful sources, complies with laws and administrative regulations, and meets the requirements of the Core Socialist Values;

(2) Clean and label training data in accordance with relevant State provisions, enhancing the transparency and reliability of training data to prevent conduct such as data contamination or tampering;

(3) Enhance the diversity of training data, and use tactics such as negative sampling and adversarial training to increase the safety of generated content;

(4) Where synthesized data is used to conduct model training and key capability optimization, the safety of synthesized data shall be assessed;

(5) Strengthen routine inspections of training data, periodically conduct optimization and updates of data, and continuously improve service performance;

(6) Employ necessary measures to ensure data security and prevent risks such as data leaks.

Article 12: The providers of human-like interactive services shall sign service agreements with users, requiring that users complete registration and, in accordance with laws and agreements, provide necessary information such as the user's age and their guardian or other emergency contact person.

Requires human-like interactive service providers to implement emergency measures for user safety, protecting privacy rights. Prohibits providing minors with virtual relationships in interactive services without guardian consent.

Article 13: During the provision of human-like interactive services, the service providers shall promptly identify the safety risks faced by users and employ corresponding emergency response measures, so long user privacy rights and personal information are protected.

Where the providers of human-like interactive services discover that users have manifested extreme emotions, they shall promptly generate related content such as emotional consolation and encouragement to seek help; and where they discover that users are currently facing, or have already suffered major property losses or clearly express extreme situations endangering lives or health, such as carrying out self-harm or suicide, they shall employ necessary measures to intervene such as providing corresponding assistance, and promptly contact the users’ guardian or emergency contact person.

Article 14: The providers of human-like interactive services must not provide minors with virtual relations, virtual partners [伴侣], or other virtual close relationships; and where human-like interactive services are provided to minors who are not yet 14 years old, they shall obtain the consent of their parents or other guardians.

The providers of human-like interactive services shall establish minors modes, and provide options for personalized safety settings such for turning on minors mode, periodic real-world reminders, and limits on usage time; and, target the protection needs of minors in different age groups, support guardians in receiving security risk alerts, understanding the minor’s usage of the service, blocking specified characters, restricting charges, and so forth.

The providers of human-like interactive services shall employ effective measures to identify minor users, provided that users’ privacy rights and personal information are protected; and where a user is identified as a minor, the provider shall switch the relevant services to minors mode, or employ other measures in accordance with relevant state regulations, and shall provide appropriate channels for appeal.

Requires providers of human-like interactive services to protect user data and provide options for data deletion.

Article 15: Where the providers of human-like interactive services provide services to the elderly, they shall strengthen guidance on the healthy use of the services by the elderly, give security risk alerts in a conspicuous fashion, promptly employ measures in response to elderly persons’ inquiries and requests for assistance in using the services, and safeguard the rights and interests enjoyed by elderly persons in accordance with law.

Article 16: The providers of human-like interactive services shall implement data rights systems in accordance with law, employing measures such as data encryption and access controls to protect user security in interaction data.

Except as otherwise provided by law or where the rights holder explicitly consents, the providers of human-like interactive services must not provide users’ interaction data to third parties.

The providers of human-like interactive services shall provide options to users to reproduce or delete interaction data, so that users may elect to reproduce or delete chat records and other interaction history data.

Except as otherwise provided by laws and administrative regulations, or where users’ independent consent is acquired, the providers of human-like interactive services must not use user interaction data that is users’ sensitive personal information for model training.

Requires consent from parents for handling minors' data; mandates AI-generated content labeling and addiction alerts.

Article 17: Where the providers of human-like interactive services handle the personal information of minors under the age of 14, they shall obtain the consent of the minors’ parents or other guardians.

In accordance with relevant state provisions, the providers of human-like interactive services shall conduct audits of whether their handling of minors’ personal information is in compliance with laws and administrative regulations, either on their own or by retaining a professional body.

Article 18: The providers of human-like interactive services shall fulfil obligations to label content generated or synthesized by artificial intelligence, and employ effective measures to alert users that they are currently interacting with an artificial intelligence service and not a natural person.

Where the providers of human-like interactive services discover that users are inclined towards overreliance or addiction, they shall dynamically alert the users through conspicuous means such as pop-up windows that the content is generated by an artificial intelligence service; and each time a user’s continuous use of human-like interactive services exceeds 2 hours, the provider shall remind the user, through means such as dialogues or pop-ups, to pay attention to the duration of use.

Requires providers of human-like interactive services to ensure convenient exit options and handle user complaints promptly.

Article 19: The providers of human-like interactive services shall provide convenient channels for exiting human-like interactive services; and where users request to exit through means such as window operations, voice controls, or keyword input, the providers of human-like interactive services shall promptly stop the service and must not employ means such as continued interaction to impede users’ exit.

Article 20: Where the providers of human-like interactive services stop providing human-like interactive services, they shall notify users in advance; where it isn’t possible to give advance notice, they shall promptly publish an announcement of the end of services.

Article 21: The providers of human-like interactive services shall complete mechanisms for user appeals and public complaints and reports, set up convenient and effective portals for appeals, complaints, and reports; clarify the process for addressing them and time limits for giving feedback, and promptly accept and address them and give feedback on the dispositions.

Requires providers of human-like interactive services to conduct security assessments and report to provincial cybersecurity departments.

Article 22: In any of the following situations, the providers of human-like interactive services shall carry out security assessments and submit assessment reports to the provincial-level cybersecurity and informatization department for their areas, and the provincial-level cybersecurity and informatization department is to share the assessment-report information with relevant departments.

(1) They put a human-like interactive service online or add functions related to a human-like interactive service;

(2) They use new technology or applications, causing major changes to occur in human-like interactive services;

(3) The number of registered users is 1,000,000 or more, or the number of monthly active users is 100,000 or more;

(4) There are security risks that might impact national security, the public interest, etc.;

(5) Other situations provided for by the state cybersecurity and informatization department and relevant departments.

Where provincial-level cybersecurity and informatization departments give notice of the need to conduct a security assessment, the providers of human-like interactive services shall carry out security assessments as requested.

Requires providers of human-like interactive services to conduct in-depth security assessments and manage major security threats.

Article 23: Providers of human-like interactive services carrying out security assessments shall emphasize assessment of the following content in the services:

(1) The establishment of security safeguards;

(2) The handling of training data;

(3) Situations such as the identification of users’ extreme emotions, and emergency response, intervention, and management of them;

(4) Circumstances such as user scale, usage duration, and age composition;

(5) The establishment of online protection measures for minors and the elderly;

(6) The acceptance and handling of user appeals and public complaints and reports;

(7) The correction of major security risks either discovered on their own or reported by relevant departments such as for cybersecurity and informatization;

(8) Other content that should be the focus of assessments.

Article 24: Where the providers of human-like interactive services discover major security threats in human-like interactive services, they shall employ response measures such as limiting functions or stopping the provision of services to users, and store the relevant records.

Article 25: Internet application stores and other application distribution platforms shall implement safety management responsibility such as for pre-offering reviews, routine management, and emergency response, check security assessments, filings, and other such situations related to human-like interactive service apps; and where relevant state provisions are violated, they shall promptly employ measures to address it such as not making it available on the market, warnings, suspending services, or taking it off the market.

Requires providers to file algorithm procedures; cybersecurity departments perform annual checks per regulatory provisions.

Chapter III: Oversight Inspections and Legal Responsibility

Article 26: The providers of human-like interactive services shall perform procedures for algorithm filing, modification, and cancellation of filings, in accordance with the Provisions on the Management of Algorithmic Recommendations in Internet Information Services. Cybersecurity and informatization departments are to carry out annual checks of filing materials.

Article 27: On the basis of their duties, provincial-level cybersecurity and informatization departments shall conduct annual document reviews of assessment reports and the like; and where they discover that the providers of human-like interactive services have not carried out security assessments in accordance with these measures, they shall order them to make a new assessment within a set period of time; and where they find it necessary, they may carry out on-site inspections.

Article 28: The State cybersecurity and informatization department, in conjunction with relevant departments, is to guide and promote the establishment of AI sandbox security service platforms, and encourage the providers of human-like interactive services to connect with the sandbox platforms in conducting technical innovation and security testing, to promote the orderly development of human-like interactive services’ security.

Requires human-like interactive services to rectify security risks and comply with inspections and potential punishments.

Article 29: Where departments such as for cybersecurity and informatization, development and reform, industry and information, and public security discover that human-like interactive services have larger security risks or have had security incidents occur, they may conduct a compliance conference [约谈] with the providers of human-like interactive services’ legal representative or primary responsible person in accordance with the authority and procedures provided. The providers of human-like interactive services shall take measures as required to carry out rectification and eliminate threats.

The providers of human-like interactive services shall cooperate with cybersecurity and informatization departments and relevant departments carrying out oversight inspections in accordance with law, and provide necessary support and assistance.

Article 30: Where the providers of human-like interactive services violate these Measures, departments such as for cybersecurity and informatization, development and reform, industry and informatization, and public security are to address and punish it in accordance with law and administrative regulations; and where laws and administrative regulations are silent, the departments such as for cybersecurity and informatization, industry and informatization, and public security are to give warnings, circulate criticism, or order corrections within a set period of time, based on their duties, and may require them to employ measures such as suspending user account registration or other relevant services; where corrections are refused or the circumstances are serious, they are to order them to stop providing relevant services, and may give fines of between 10,000 and 100,000 RMB; and where harms to citizens lives and health are involved, and harmful consequences result, fines of between 100,000 and 200,000 are to be given.

Requires human-like interactive services in health or finance to comply with relevant department regulations.

Chapter IV: Supplemental Provisions

Article 31: Where the provision of human-like interactive services involves the provision of health or financial services, it shall concurrently comply with the provisions of the relevant competent departments.

Article 32: These Measures are to take effect from 7/15/2026.

Similar papers

© 2026 NYSGPT2525 LLC