China's AI labelling rules: two labels, and four parties who must apply them
In force since 1 September 2025, and enforced. One label a person can see, one written
into the file. They bind different parties, on different triggers, and only one of them is
unconditional.
NoneArticle 13 refers enforcement out to existing law. Sanctions are administrative.
01The clock
Unusually, the rule and the engineering specification arrived together and commenced together,
with roughly six months of transition. That is why Chinese implementations are further along than
most Western ones: the technical answer was published at the same time as the duty.
GB 45438-2025 is issued
The mandatory national standard — Cybersecurity technology — Labeling method for content
generated by artificial intelligence — issued by SAMR and SAC. Note "GB", not "GB/T":
mandatory, not recommended.
The Measures are published
Issued jointly by the Cyberspace Administration of China with MIIT, the Ministry of Public
Security and the NRTA. Fourteen articles.
Both instruments commence
The management duties and the technical method take effect on the same day.
First nationwide enforcement sweep
CAC concentrates enforcement against mobile apps over labelling failures — on both the
provider side and the platform side. What they cited is below.
02Are you covered?
This is the most-missed point in English coverage, and it is the first thing to get right. The
Measures do not define their own class of regulated entity. Article 2 borrows the
scope of three upstream instruments, and you are caught only if you already fall inside one of them.
Are you within the Algorithm Recommendation Provisions?
Are you within the Deep Synthesis Provisions?
Are you within the Interim Measures for Generative AI Services?
Any one yes, and the labelling duties attach. None, and the Measures do not
reach you — the scope is derivative, not free-standing. Whether the regime reaches a provider
located outside China is not settled in public guidance; the practitioner reading
is that availability to users in China matters more than where the company sits, but any page that
gives you a clean answer on that is overclaiming.
03Two labels, not one
The regime splits every obligation along one axis: can a person perceive it? Getting this
distinction wrong is the most common implementation failure, because the two labels have different
legal triggers.
The explicit label — conditional
Article 4 · perceptible to the user
Text, sound or graphics presented in the content or the interface, which the user can plainly
perceive. Placement is prescribed per modality: at the start, end or an appropriate middle
position for text and audio; a prominent mark on images; the start frame and the
playback surround for video, with end and middle positions permitted but not required.
Measures, Art. 4 · geometry specified by GB 45438-2025
The trigger is narrower than most summaries suggest: this duty bites where the service falls
within Article 17(1) of the Deep Synthesis Provisions — broadly, services that could cause public
confusion about what is real, such as voice cloning, face generation or swapping, realistic scene
generation, or dialogue simulating a real person. Not every AI output needs a visible
label.
A separate sentence of Article 4 is the one that has actually drawn enforcement: where you offer
download, copy or export, the exported file must still carry the explicit label. A badge that lives
only in your web player does not satisfy it.
The implicit label — unconditional
Article 5 · written into the file
Metadata embedded in the content file carrying the generation attribute, the service
provider's name or code, and a content number. GB 45438-2025 fixes the encoding: a JSON object
under an AIGC key, written into the format's native metadata — EXIF or XMP for
images, XMP for audio and video, the document information dictionary for PDF, the
docProps entries for Office formats.
Measures, Art. 5 · schema at GB 45438-2025 Annex E
This duty flows from a different upstream article than the explicit label and carries
no equivalent condition. If the Measures reach you, the metadata label applies.
And the correction worth making loudly: digital watermarking is encouraged, not
required. Article 5 mandates the metadata label and separately encourages watermarks. A
great deal of English commentary reports watermarking as mandatory. It is not — which matters,
because the mandatory layer is also the fragile one. A screenshot, a re-encode or a CMS that
normalises metadata on ingest destroys the compliant label while leaving the content intact.
04The chain
This is the structural difference from every Western regime. The EU regulates the producer.
China regulates the distribution chain — four parties, each with its own duty, and
the file carries provenance from one to the next.
Who
Must do
Where
Generation service provider
Apply the explicit label where the trigger is met; always write the metadata label;
preserve the label through download, copy and export; state the labelling method in the user
agreement; supply labelling materials at algorithm filing and security assessment.
Arts. 4, 5, 8, 11, 12
Dissemination platform
Verify the metadata on what users publish, classify it, display the matching notice, and
write its own provenance fields back into the file. Provide a declaration
function.
Art. 6
App distribution platform
At listing or go-live review, require the developer to state whether AI generation
services are offered, and if so verify the labelling materials.
Art. 7
Publishing user
Proactively declare generated content and use the platform's labelling function.
Art. 10
Article 10 also prohibits anyone — not just regulated providers — from maliciously deleting,
tampering with, forging or concealing a label, or supplying tools or services for others to
do so. It further prohibits harming someone's lawful interests through improper labelling,
which catches false labelling too: tagging a genuine human recording as AI-generated in order to
discredit it is within the prohibition.
05The platform's three questions
Article 6 gives a dissemination platform a decision procedure, and the wording of the notice it
must display changes with the answer. The distinction between the three tiers is not cosmetic — it
is the difference between telling the public something is, may be, or is
suspected to be synthetic.
What the platform finds
How it must describe the content
Metadata present and marks the file as generated
It is generated or synthesised content
No metadata, but the user declared it
It may be generated or synthesised content
No metadata, no declaration, but an explicit label or other traces are detected
It is suspected generated or synthesised content
In all three cases the platform must then write dissemination elements into the file metadata —
the generation attribute, its own platform name or code, and a content number. This is the step
platforms skip. They ship the badge and omit the write-back, and it was cited as a violation in
CAC's first enforcement sweep.
Note what the platform is exposed to here. Tier one is a verification duty — an
affirmative check of files. Tier three is a detection duty triggered by traces. Neither the
Measures nor the standard set an accuracy threshold, so a platform is answerable for outcomes
against no defined benchmark. What it can do is show what it saw and what it decided, at the time it
decided.
06The six-month log
Article 9 is the only retention duty in the Measures, and it is routinely reported far more
broadly than it reads. It is not a general log-retention rule for AI content.
Where a user asks for generated content without an explicit label, the provider
may supply it — but only after the user agreement has fixed that user's own labelling obligation
and use responsibility — and must then retain logs including information identifying who received
it, for not less than six months.
Measures, Art. 9
Four conditions, all narrow: it binds the generation provider only, not the platform; only in the
unlabelled-supply case; only after the agreement is in place; and the metadata label still applies —
Article 9 waives the visible label, not the embedded one.
What it actually creates is an evidentiary duty rather than a labelling one. Six months later,
the provider has to be able to show who received unlabelled output and on what agreed terms. That is
a duty on the record, not only on the act — and a record that can be edited in the
intervening six months does not discharge it.
07Duty → receipt
This is where Planisphere enters, and not before. One event type per act in the chain. The field
names are the fields the API accepts, and they follow the regime's own structure — including the
propagation write-back and the Article 9 case.
Two properties matter more than the field list. Content never leaves your systems
— commitments are hashes, so a record can bind to a file, an agreement or a recipient identifier
without any of them being transmitted. And records are sealed on write: hash-chained
into a per-tenant series, signed, and periodically anchored, so an edit to an earlier record breaks
the chain in a way a third party can detect without trusting either of us. For a six-month retention
duty, that difference is the whole point.
08The integration
One HTTPS call per act, from wherever the act happens. Nothing sits in your generation or
publishing path, so nothing here can fail closed and take your pipeline down.
# A dissemination platform classified a file and wrote its provenance fields back.
curl -X POST https://api.planisphere.ooo/v1/record \
-H "Authorization: Bearer $PLANISPHERE_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"pack": "cn-ai-labelling",
"event_type": "propagation_label_added",
"occurred_at": "2026-08-01T09:14:52Z",
"system_id": "feed-ingest",
"system_seq": 8814021,
"source_payload": {
"content_sha256": "7b31…"// the file. Never sent.
},
"metadata": {
"platform_code": "PLT-00417",
"upstream_content_id": "PRD-9f22a1",
"notice_form": "is_generated"// tier one: metadata present
}
}'
The Article 9 case is the same call with unlabelled_supply_agreed,
committing the agreement hash and a hashed recipient identifier, with
retention_until carrying the six-month horizon. The recipient is
committed as a hash, so the log identifies who received the content without your putting an identity
into our systems.
The full API reference covers authentication, idempotency, batching
and rate limits; pricing is per record with a monthly free allowance.
09How it is actually enforced
Article 13 sets no penalty. The Measures are a normative document and cannot create one; they
refer enforcement out to the competent departments under existing law, with sanctions borrowed from
the upstream instruments and the Cybersecurity Law. In practice, published enforcement has been
administrative rather than financial — regulatory interviews, orders to rectify within a deadline,
formal warnings, delisting, and account-level sanctions.
What has actually happened is more instructive than the theory:
25 November 2025 — a nationwide sweep of mobile apps. On the provider side,
CAC cited missing explicit labels, labels not carried through on export, and missing
metadata. On the platform side: failure to verify metadata, failure to display the notice,
failure to write dissemination metadata, and no declaration function for users.
The number of apps was not disclosed.
12 February 2026 — a campaign reporting 13,421 accounts sanctioned and more
than 543,000 items removed. Categories included unlabelled AI content, face-swap impersonation of
public figures, and — squarely under Article 10 — selling de-labelling tutorials, software
and services.
28 April 2026 — CAC publicly named three services for failing to implement
labelling effectively, citing the Cybersecurity Law, the Interim Measures for Generative AI
Services and these Measures together, and directed local offices to apply interviews,
rectification orders and warnings.
The pattern to plan against: enforcement is specific and it names the failure. Two of the
three most-cited failures — export stripping and the missing write-back — are questions about what
your systems did to a particular file on a particular day.
10What Planisphere does not do
Stated plainly, because a vendor who is vague here will be vague in front of a regulator.
Planisphere is an evidence layer. It sits beside your systems, never inside the act.
It does not apply explicit labels, write the AIGC metadata block,
or watermark anything. Your pipeline does that.
It does not verify metadata on your behalf, classify content into the three
tiers, or detect synthetic media.
It does not host or distribute content, and does not observe what your users
published.
It is not an algorithm filing, not a security assessment, and not a
determination that a label satisfies GB 45438-2025.
It does not certify compliance or make a legal determination. No vendor can. A
record is evidence a third party can check; it is not a finding that you complied.
It does seal the acts you performed, at the moment you performed
them, in a form that a hostile reader can verify and you cannot quietly revise — which is what a
six-month retention duty and a per-file verification duty both actually require.
11Questions
Does our C2PA implementation satisfy GB 45438-2025?
No. The standard specifies a flat JSON object under an AIGC key
in the file's native metadata, with named fields for the producer and the propagator. C2PA is a
cryptographically signed manifest with assertions and a hard binding to the asset. They can coexist
in the same file — and in a multi-jurisdiction pipeline they generally must — but neither satisfies
the other.
We only sell an API to businesses. Are we out?
Unresolved. The Measures contain no B2B or API exemption, and scope is inherited from the
upstream instruments — one of which carves out services not provided to the domestic public. An API
confined to a closed enterprise pipeline is arguably outside; one whose output reaches public-facing
Chinese content is not. This is a question for counsel, not a page.
Our metadata keeps getting stripped by re-encoding. Is that a violation?
Article 10's prohibition is on malicious removal, so incidental loss in a transcode is
not on its face a breach of it. But it can still put you in breach of your own Article 5 or Article
6 duty, and preserving the block through edit, transcode, export and delivery is an engineering
programme rather than a configuration change. Recording what you wrote, when, is the part that
survives the re-encode.
How does this compare with the EU?
China prescribes the method and regulates the whole distribution chain; the EU states an
outcome and binds providers and deployers only. Nothing in Article 50 obliges a platform or an app
store to inspect files and re-mark them.
The EU page covers that regime.
What happens to our content and metadata?
Content is never transmitted — only hash commitments. Declared metadata values are retained
only when the pack marks the key as retainable and your organisation has enabled
retention; otherwise only key names and a canonical hash are kept. Person-identifying keys are
never retainable, which is why a recipient identifier is committed as a hash.
12Sources
Every article number, date and duty on this page traces to one of these. Where the Chinese text is
summarised in English, the summary is ours and the citation points at the original.
PrimaryCAC — the Measures, full text and issuing noticeAll fourteen articles: the derivative scope in Art. 2, the two labels in Arts. 4 and 5, the platform ladder in Art. 6, the six-month log in Art. 9, the prohibitions in Art. 10, and the referral of enforcement in Art. 13.
PrimaryCAC — the November 2025 enforcement sweepThe itemised provider-side and platform-side failures, including export stripping and the missing dissemination write-back.
The console opens on the China pack with every act in the chain listed, each showing the exact
call that seals it. Sealing one record takes about a minute, and the first thousand each month are
free. If you would rather read first, the integration guide covers authentication, batching and the
retention controls.