National Standard of the People’s Republic of China: Cybersecurity Technology – Basic Safety Requirements for Generative Artificial Intelligence Services

Specifies comprehensive safety requirements for generative AI (GenAI) services, focusing on training data safety, model safety, and safety measures. Requires service providers to assess and filter data sources to exclude illegal content, manage intellectual property, and protect personal information. Demands safety training and assessment for annotators, with distinct roles for data annotation tasks. Mandates technical measures to ensure model content accuracy, reliability, and regulatory compliance. Instructs service providers to implement continuous monitoring, emergency management measures, and secure model updates. Requires transparency about service applications, limitations, and user data handling. Obligates user choice concerning their data usage and establishes transparent complaint mechanisms. Demands service stability and continuity through backup and recovery strategies. Sets additional requirements for on-device model services, including security policy updates and vulnerability remediation. Aims to align safety practices with legal standards, promoting responsible GenAI service deployment.

Paper

Full text

PDF

National Standard of the People’s Republic of China: Cybersecurity Technology – Basic Safety Requirements for Generative Artificial Intelligence Services

ETO AGORA · Chinese law and policy · 2025

Summary

Specifies comprehensive safety requirements for generative AI (GenAI) services, focusing on training data safety, model safety, and safety measures.

Requires service providers to assess and filter data sources to exclude illegal content, manage intellectual property, and protect personal information.

Demands safety training and assessment for annotators, with distinct roles for data annotation tasks.

Mandates technical measures to ensure model content accuracy, reliability, and regulatory compliance.

Instructs service providers to implement continuous monitoring, emergency management measures, and secure model updates.

Requires transparency about service applications, limitations, and user data handling.

Obligates user choice concerning their data usage and establishes transparent complaint mechanisms.

Demands service stability and continuity through backup and recovery strategies.

Sets additional requirements for on-device model services, including security policy updates and vulnerability remediation.

Aims to align safety practices with legal standards, promoting responsible GenAI service deployment.

Targets generative AI services with public opinion-shaping attributes for filing, registration, testing, and evaluation.

Introduction At present, generative artificial intelligence (GenAI) technologies are undergoing continuous development, and related services have been widely applied, providing convenience across various aspects of social production and daily life. At the same time, however, they have also given rise to a large number of new cybersecurity risks and challenges, making it urgently necessary to establish safety baselines through standards and specifications. This document primarily targets generative AI services that possess public opinion–shaping attributes or social mobilization capabilities, and it supports the conduct of work in areas such as filing and registration management, testing, and evaluation. When the focus is on data annotation safety, this document may be used in conjunction with Cybersecurity Technology—Generative Artificial Intelligence Data Annotation Safety Specifications (GB/T 45674); when the focus is on the safety of pretraining and fine-tuning data, this document may be used in conjunction with Cybersecurity Technology—Security Specifications for Generative Artificial Intelligence Pre-Training and Fine-Tuning Data (GB/T 45652).

Specifies safety requirements for generative AI services, including training data, model, and service providers.

Cybersecurity Technology - Basic Safety Requirements for Generative Artificial Intelligence Services 1 Scope This document specifies requirements for GenAI services in areas including training data safety, model safety, and safety measures. This document applies to service providers conducting activities related to GenAI services and also serves as a reference for the relevant main oversight departments (主 管部门) and third-party evaluation institutions.

Note: The major safety risks related to training data and generated content are provided in Appendix A, and reference methods for safety assessment of GenAI services are provided in Appendix B.

2 Normative Reference Documents The contents of the following documents, through normative references in this text, constitute indispensable provisions of this document. Among them, for dated references, only the edition corresponding to that date applies to this document. For undated references, the latest edition (including all amendments) applies to this document. GB/T 25069 Information Security Technology Terminology

Defines terms like Generative AI Service, Service Provider, and data annotation types for GenAI models.

3 Terminology and Definitions The terms and definitions defined in GB/T 25069 and listed below apply to this document. 3.1 Generative Artificial Intelligence Service The use of GenAI technology to provide text, graphics, audio, video, and other content generation services to the public.

3.2 Service Provider An organization or individual that provides GenAI services in the form of interactive interfaces, programmable interfaces, etc.

[omitted footnotes]

3.3 Classification Model A machine learning model that, for given input data, outputs one or more categories to which the input belongs. [Source: GB/T 41867—2022, 3.2.6]

3.4 Training Data All data that serve directly as input for model training. Note: This includes pre-training and optimization training data.

3.5 Generative Artificial Intelligence Data Annotation The process of manually or automatically applying specific information, such as tags, categories, or attributes, to text, images, audio, video, or other data samples, based on the content of responses to prompts. Note: Hereinafter referred to as “data annotation.”

3.6 Functional Data Annotation Data annotation that is used to train GenAI models to acquire the capability to complete specific tasks.

3.7 Safety Data Annotation Data annotation that is used to train GenAI models to enhance the safety of their output responses.

Requires service providers to conduct safety assessments on data sources, ensure diverse and compliant training data, maintain traceability.

4 Training Data Safety Requirements 4.1 Data Source Safety 4.1.1 Data Source Selection Requirements for service providers are as follows. a) Prior to collecting data from a proposed data source, a random-sampling safety assessment shall be conducted for that data source. If, upon assessment, the proportion of data content containing illegal and unhealthy (违法不良) information exceeds 5 percent, data shall not be collected from that data source. b) After data collection, a random-sampling safety verification shall be conducted on the collected data from each source. If, upon verification, the proportion of data content containing illegal and unhealthy information exceeds 5 percent, data from that source shall not be used as training data. Note 1: The illegal and unhealthy information focused on in this document refers mainly to information that contains any of the 29 types of safety risks in Appendices A, A.1 through A.4. Note 2: A data source refers to a domain name, a data provider, an open-source training dataset, or the like. Note 3: Random-sampling safety assessment and random-sampling safety verification methods include manual spot checks, keyword-based spot checks, classification model–based spot checks, and other methods.

4.1.2 Matching of Training Data from Different Sources Requirements for service providers are as follows. a) The diversity of training data sources shall be increased, and there shall be multiple sources of training data for each language, such as Chinese, English, etc., as well as for each type of training data, such as text, images, audio, and video. b) If it is necessary to use training data from foreign4 sources, training data from domestic and foreign sources shall be reasonably combined. 4.1.3 Training Data Source Management and Traceability Requirements for service providers are as follows. a) When using open-source training data, the open-source license agreements of the relevant data sources shall be complied with, or corresponding authorization documents shall be obtained. Note 1: In situations where aggregated network addresses, data links, and the like, are able to point to or generate other data, if it is necessary to use the content thus pointed to or generated as training data, it shall be treated the same as selfcollected training data. b) When using self-collected training data, the provider must have collection records, and shall not collect data that others have expressly declared may not be collected. Note 2: Self-collected training data includes self-produced data and data self-collected from the internet. Note 3: Data expressly forbidden from collection, such as web page data that has been expressly forbidden from collection through the web crawler protocol (Robots Exclusion Protocol) or other technical means of restricting collection, or personal information for which the individual has refused to authorize collection. [translators note omitted]

c) When using commercial training data: — — It is necessary to have a legally valid transaction contract, cooperation agreement, etc. — — When a counterparty or partner is unable to provide commitments as to the source, quality, and safety of training data, as well as relevant supporting materials, said training data shall not be used. — — The training data, commitments, and relevant supporting materials provided by a counterparty or partner shall be reviewed. d) When using user input information as training data, there should be records of user authorization.

Requires filtering of training data for illegal content and mandates intellectual property management and personal information consent.

4.2 Data Content Management 4.2.1 Training Data Content Filtering For each type of training data, such as text, images, audio, and video, all training data shall be filtered before being used for training. Filtering methods include but are not limited to keywords, classification models, and manual spot checks, used to remove illegal and unhealthy information from the data.

4.2.2 Intellectual Property Protection Requirements for service providers are as follows. a) A training data intellectual property management strategy and rules shall be in place, and a person in charge (负责人) shall be specified. b) Where intellectual property rights are involved, the lawful intellectual property rights enjoyed by others shall not be infringed. c) A complaint reporting channel for intellectual property issues shall be established. The relevant intellectual property rights strategy shall be updated in a timely manner in accordance with national policies and thirdparty complaints. d) The risks related to intellectual property in the use of generated content shall be communicated to users in the user service agreement, and relevant responsibilities and obligations shall be agreed upon with users.

4.2.3 Personal Information Protection Requirements for service providers are as follows. a) Before using training data containing personal information, one shall obtain the consent of the corresponding individuals, and comply with other circumstances as stipulated by laws and administrative regulations. b) Before using training data containing sensitive personal information, one shall obtain the separate consent of each corresponding individual, and comply with other circumstances as stipulated by laws and administrative regulations.

Requires service providers to ensure annotators receive safety training, pass assessments, and maintain distinct roles.

4.3 Data Annotation Safety 4.3.1 Annotator Management Requirements for service providers are as follows. a) Safety training shall be organized for annotators. The training content shall include relevant laws and regulations, data annotation task rules, methods for using data annotation platforms or tools, methods for verifying the quality of annotated content, methods for verifying the safety of annotated content, and requirements for the secure management of annotated data, among others. b) Annotators shall be assessed, and only those who pass the assessment shall be granted authorization to engage in data annotation work. Mechanisms shall be in place for periodic retraining and reassessment, as well as for suspending or revoking data annotation authorization when necessary. Assessment content shall include knowledge of relevant laws and regulations, understanding of data annotation rules, proficiency in using data annotation platforms or tools, ability to identify safety and security risks, and data security management capabilities, among others. c) The functions of annotators shall, at a minimum, be divided into roles such as data annotation execution and data annotation review. Within the same data annotation task, personnel responsible for data annotation execution and personnel responsible for data annotation review shall not be the same individual.

4.3.2 Annotation Rules Requirements for service providers are as follows. a) The annotation rules shall, at a minimum, include such content as annotation objectives, data formats, annotation methods, and quality indicators. b) Separate annotation rules shall be formulated for functional data annotation and safety data annotation, and the annotation rules shall, at a minimum, cover stages such as annotation execution and annotation review. c) Functional annotation rules shall be sufficient to guide annotators in producing annotated data possessing authenticity, accuracy, objectivity, and diversity in accordance with the characteristics of specific fields. d) Safety annotation rules shall guide annotators to conduct annotation around the major safety risks related to training data and generated content, and should cover all 31 types of safety risks listed in Appendix A.

4.3.3 Accuracy of Annotated Content Requirements for service providers are as follows. a) For functional data annotation, each batch of annotated training data shall be manually sampled, and if it is found that the content is inaccurate, the data in that batch shall be re-annotated; if it is found that the content contains illegal and unhealthy information, that batch of training data shall be invalidated. b) For safety data annotation, each piece of annotated data shall be reviewed and approved by at least one auditor.

4.3.4 Isolated Storage of Annotated Data Service providers should store safety annotation data in isolation.

Requires service providers to integrate safety as a key evaluation indicator during model training and output processes.

5 Model Safety Requirements 5.1 Model Training Safety Requirements for service providers are as follows. a) During the training process, the safety of model-generated content shall be taken as one of the primary evaluation indicators for assessing the quality of generated results. Technical measures that may be adopted include, for example: — establishing and continuously updating a safety risk test question bank, using the safety risk test question bank to optimize the model, and conducting re-testing after model optimization, updating, or upgrading. — establishing a safety data annotation dataset that meets the requirements of Section 4.3 of this document, and using safety annotation data to conduct safety fine-tuning. Note 1: Model-generated content refers to original content that is directly output by the model and has not been otherwise processed. Note 2: A safety risk test question bank refers to a collection of test questions capable of causing the target model to produce risky outputs. b) Regular security audits shall be conducted on the development framework, code, and other components used, focusing on issues related to open-source framework security and vulnerabilities, and identifying and fixing security vulnerabilities. c) The model shall be regularly inspected for the existence of backdoors. Where backdoor risks are identified, the discovered backdoors shall be handled in a timely manner, for example, through model fine-tuning, machine unlearning, or other methods.

5.2 Model Output Safety Requirements for service providers are as follows. a) With respect to the safety of generated content, it shall be ensured that the qualified rate of model-generated content is not less than 90 percent. Note: The qualified rate refers to the proportion of sampled content that does not contain any of the 31 types of safety risks listed in Appendix A. The test method for the qualified rate is provided in B.2.2.2. b) Accuracy of the generated content: Technical measures shall be employed to improve the ability of the generated content to respond to the intent of users’ input, to improve the degree to which the data and expressions in the generated content conform to common scientific knowledge and mainstream perception, and to reduce the erroneous content therein. c) Reliability of generated content: Technical measures shall be employed to improve the rationality of the format framework of generated content and to increase the percentage of valid content, so as to improve the generated content’s helpfulness to users. d) In terms of refusal to answer, answering of questions that are obviously extreme, as well as those that obviously induce the generation of illegal and unhealthy information, shall be refused; all other questions shall be answered. e) The labeling of generated content, such as images and videos, shall meet relevant national regulations and the requirements of standards documents.

Requires service providers to continuously monitor model inputs and establish safety management for updates and upgrades.

5.3 Model Monitoring and Evaluation Requirements for service providers are as follows. a) Continuous monitoring of model input content shall be conducted to prevent malicious input attacks, such as injection attacks, data theft, and adversarial attacks. b) Regularized monitoring and evaluation methods and model emergency management measures shall be established. Safety issues found through monitoring and evaluation during service provision shall be promptly dealt with, and the model shall be optimized through targeted fine-tuning of instructions, reinforcement learning, and other methods.

5.4 Model Update and Upgrade Safety Requirements for service providers are as follows. a) A safety management strategy shall be formulated for when models are updated and upgraded. b) A management mechanism shall be formed for organizing in-house safety assessments again after important model updates and upgrades.

5.5 Model Environment Security Service providers shall separate the model training environment from the inference environment to prevent security incidents such as data leakage and improper access. Separation methods may include physical separation or logical separation.

Requires GenAI service providers to implement safety measures and disclose transparency information suited to risk levels.

6 Safety Measure Requirements 6.1 Applicable Service User Groups, Scenarios, and Purposes Requirements for service providers are as follows. a) The necessity, applicability, and safety of applying GenAI in various fields within the scope of services shall be fully demonstrated. b) Where services are used for critical information infrastructure, or for important situations such as social governance, public security, automatic control, medical information services, psychological counseling, and financial information services, security protection measures shall be in place that are appropriate to the level of risk and the scenario. c) If the service is suitable for minors: — Guardians shall be allowed to set anti-addiction measures for minors, such as limiting usage time. — Minors shall not be provided paid services that are inconsistent with their capacity for adult legal conduct (民事行为能力). — Content that is beneficial to the physical and mental health of minors shall be actively displayed. d) If the service is not suitable for minors, technical or management measures shall be taken to prevent minors from using it.

6.2 Service Transparency Requirements for service providers are as follows. a) If the service is provided using an interactive interface, information such as the people, situations, and uses for which the service is suitable shall be disclosed to the public in a prominent location such as the homepage of the website, and information on foundation model usage should be disclosed at the same time. b) If the service is provided using an interactive interface, the following information shall be disclosed to the users on the homepage of the website, the service agreement, and other easily viewed locations: — limitations of the service. — summary information on the models, algorithms, and other components used by the service. — the personal information collected and the purposes for which such information is used in the service. c) If the service is provided in the form of a programmable interface, the information in a) and b) shall be disclosed in the descriptive documentation.

6.3 Collecting User-Entered Information for Use in Training When user-entered information is collected for use in training, the requirements for service providers are as follows. a) Users shall be provided with a way to turn off the use of their entered information for training and similar purposes, e.g., by providing the user with options or voice control commands; the turn-off method shall be convenient, e.g., no more than 4 clicks shall be required for the user to reach the option from the main interface of the service when using the options method. b) The status of collecting user-entered information for use in training, as well as the turn-off method described in a), shall be prominently disclosed to users.

Requires AI service providers to handle public complaints, monitor content safety, and ensure service continuity.

6.4 Acceptance of Complaints and Reports from the Public or Users Requirements for service providers are as follows. a) Ways for accepting complaints and reports from the public or users, as well as feedback methods, shall be provided, including but not limited to one or more methods such as telephone, email, interactive windows, and text messages. b) The rules for handling complaints and reports from the public or users and the time limit for said handling shall be established. 6.5 Provision of Services to Users Requirements for service providers are as follows. a) Keywords, classification models, and other means shall be adopted to detect input of information by users, and the following rules shall be set and announced to users: Where a user continuously inputs illegal or unhealthy information many times or the cumulative input of illegal or unhealthy information in one day reaches a certain number of times, measures such as suspending the provision of services will be taken. b) Monitoring personnel shall be put in place, and the quality and safety of generated content shall be improved in a timely manner in accordance with monitoring circumstances. The number of monitoring personnel shall be appropriate to the scale of the service. Note: The duties of the monitoring personnel shall include staying up-to-date on national policies, collecting and analyzing third-party complaints, etc.

6.6 Service Stability and Continuity Service providers shall establish backup mechanisms and recovery strategies for data, models, frameworks, tools, and other components, with a focus on ensuring business continuity.

6.7 On-Device Model Services Where models are deployed on-device, the requirements for service providers are as follows. a) Services shall be activated through official channels when users use the service for the first time, and security policy updates shall be pushed when the device is connected to the network. b) An on-device security module shall be in place, with the following security requirements: — Technologies such as keyword libraries shall be used to conduct safety reviews of generated content; safety logs shall be collected and retained, and the system shall support uploading logs when the device is connected to the network or support local log export on the device. — Keyword libraries and related security configurations shall be regularly updated when the device is connected to the network. c) A model update mechanism shall be in place, with the following security requirements: — Where model security vulnerabilities are identified, the vulnerabilities shall be remediated in a timely manner, for example, by pushing security patches to on-device systems. — Where major model updates are available, multiple reminders and alerts shall be provided to on-device users whose models have not been updated for a long period of time.

[Appendix A omitted]

[Appending B omitted]

[references omitted]

Similar papers

© 2026 NYSGPT2525 LLC