China · CAC labelling Measures

China's AI labelling rules: two labels, and four parties who must apply them

In force since 1 September 2025, and enforced. One label a person can see, one written into the file. They bind different parties, on different triggers, and only one of them is unconditional.

In force
1 Sep 2025Measures and mandatory standard took effect together.
Instruments
TwoThe Measures (management duties) and GB 45438-2025 (the technical method).
Duty holders
FourGeneration provider, dissemination platform, app store, publishing user.
Fines in the Measures
NoneArticle 13 refers enforcement out to existing law. Sanctions are administrative.

01The clock

Unusually, the rule and the engineering specification arrived together and commenced together, with roughly six months of transition. That is why Chinese implementations are further along than most Western ones: the technical answer was published at the same time as the duty.

  1. GB 45438-2025 is issued

    The mandatory national standard — Cybersecurity technology — Labeling method for content generated by artificial intelligence — issued by SAMR and SAC. Note "GB", not "GB/T": mandatory, not recommended.

  2. The Measures are published

    Issued jointly by the Cyberspace Administration of China with MIIT, the Ministry of Public Security and the NRTA. Fourteen articles.

  3. Both instruments commence

    The management duties and the technical method take effect on the same day.

  4. First nationwide enforcement sweep

    CAC concentrates enforcement against mobile apps over labelling failures — on both the provider side and the platform side. What they cited is below.

02Are you covered?

This is the most-missed point in English coverage, and it is the first thing to get right. The Measures do not define their own class of regulated entity. Article 2 borrows the scope of three upstream instruments, and you are caught only if you already fall inside one of them.

  1. Are you within the Algorithm Recommendation Provisions?
  2. Are you within the Deep Synthesis Provisions?
  3. Are you within the Interim Measures for Generative AI Services?

Any one yes, and the labelling duties attach. None, and the Measures do not reach you — the scope is derivative, not free-standing. Whether the regime reaches a provider located outside China is not settled in public guidance; the practitioner reading is that availability to users in China matters more than where the company sits, but any page that gives you a clean answer on that is overclaiming.

03Two labels, not one

The regime splits every obligation along one axis: can a person perceive it? Getting this distinction wrong is the most common implementation failure, because the two labels have different legal triggers.

The explicit label — conditional

Article 4 · perceptible to the user

Text, sound or graphics presented in the content or the interface, which the user can plainly perceive. Placement is prescribed per modality: at the start, end or an appropriate middle position for text and audio; a prominent mark on images; the start frame and the playback surround for video, with end and middle positions permitted but not required.

Measures, Art. 4 · geometry specified by GB 45438-2025

The trigger is narrower than most summaries suggest: this duty bites where the service falls within Article 17(1) of the Deep Synthesis Provisions — broadly, services that could cause public confusion about what is real, such as voice cloning, face generation or swapping, realistic scene generation, or dialogue simulating a real person. Not every AI output needs a visible label.

A separate sentence of Article 4 is the one that has actually drawn enforcement: where you offer download, copy or export, the exported file must still carry the explicit label. A badge that lives only in your web player does not satisfy it.

The implicit label — unconditional

Article 5 · written into the file

Metadata embedded in the content file carrying the generation attribute, the service provider's name or code, and a content number. GB 45438-2025 fixes the encoding: a JSON object under an AIGC key, written into the format's native metadata — EXIF or XMP for images, XMP for audio and video, the document information dictionary for PDF, the docProps entries for Office formats.

Measures, Art. 5 · schema at GB 45438-2025 Annex E

This duty flows from a different upstream article than the explicit label and carries no equivalent condition. If the Measures reach you, the metadata label applies.

And the correction worth making loudly: digital watermarking is encouraged, not required. Article 5 mandates the metadata label and separately encourages watermarks. A great deal of English commentary reports watermarking as mandatory. It is not — which matters, because the mandatory layer is also the fragile one. A screenshot, a re-encode or a CMS that normalises metadata on ingest destroys the compliant label while leaving the content intact.

04The chain

This is the structural difference from every Western regime. The EU regulates the producer. China regulates the distribution chain — four parties, each with its own duty, and the file carries provenance from one to the next.

WhoMust doWhere
Generation service provider Apply the explicit label where the trigger is met; always write the metadata label; preserve the label through download, copy and export; state the labelling method in the user agreement; supply labelling materials at algorithm filing and security assessment. Arts. 4, 5, 8, 11, 12
Dissemination platform Verify the metadata on what users publish, classify it, display the matching notice, and write its own provenance fields back into the file. Provide a declaration function. Art. 6
App distribution platform At listing or go-live review, require the developer to state whether AI generation services are offered, and if so verify the labelling materials. Art. 7
Publishing user Proactively declare generated content and use the platform's labelling function. Art. 10

Article 10 also prohibits anyone — not just regulated providers — from maliciously deleting, tampering with, forging or concealing a label, or supplying tools or services for others to do so. It further prohibits harming someone's lawful interests through improper labelling, which catches false labelling too: tagging a genuine human recording as AI-generated in order to discredit it is within the prohibition.

05The platform's three questions

Article 6 gives a dissemination platform a decision procedure, and the wording of the notice it must display changes with the answer. The distinction between the three tiers is not cosmetic — it is the difference between telling the public something is, may be, or is suspected to be synthetic.

What the platform findsHow it must describe the content
Metadata present and marks the file as generatedIt is generated or synthesised content
No metadata, but the user declared itIt may be generated or synthesised content
No metadata, no declaration, but an explicit label or other traces are detectedIt is suspected generated or synthesised content

In all three cases the platform must then write dissemination elements into the file metadata — the generation attribute, its own platform name or code, and a content number. This is the step platforms skip. They ship the badge and omit the write-back, and it was cited as a violation in CAC's first enforcement sweep.

Note what the platform is exposed to here. Tier one is a verification duty — an affirmative check of files. Tier three is a detection duty triggered by traces. Neither the Measures nor the standard set an accuracy threshold, so a platform is answerable for outcomes against no defined benchmark. What it can do is show what it saw and what it decided, at the time it decided.

06The six-month log

Article 9 is the only retention duty in the Measures, and it is routinely reported far more broadly than it reads. It is not a general log-retention rule for AI content.

Where a user asks for generated content without an explicit label, the provider may supply it — but only after the user agreement has fixed that user's own labelling obligation and use responsibility — and must then retain logs including information identifying who received it, for not less than six months.

Measures, Art. 9

Four conditions, all narrow: it binds the generation provider only, not the platform; only in the unlabelled-supply case; only after the agreement is in place; and the metadata label still applies — Article 9 waives the visible label, not the embedded one.

What it actually creates is an evidentiary duty rather than a labelling one. Six months later, the provider has to be able to show who received unlabelled output and on what agreed terms. That is a duty on the record, not only on the act — and a record that can be edited in the intervening six months does not discharge it.

07Duty → receipt

This is where Planisphere enters, and not before. One event type per act in the chain. The field names are the fields the API accepts, and they follow the regime's own structure — including the propagation write-back and the Article 9 case.

ActEvent typeWhat is committed
Declaring what is in scope system_declared role output_classes marking_techniques counter_binding effective_from · commits scope_sha256
Explicit label applied (Art. 4) explicit_label_applied label_form label_placement modality · commits content_sha256
Metadata label written (Art. 5) implicit_label_embedded provider_code content_id metadata_standard · commits content_sha256
Platform notice and write-back (Art. 6) propagation_label_added platform_code upstream_content_id notice_form · commits content_sha256
User declaration received (Arts. 6, 10) user_declaration_received declarant_ref declared_at channel · commits content_sha256
Unlabelled supply and its log (Art. 9) unlabelled_supply_agreed agreed_at retention_until · commits agreement_sha256 recipient_id_sha256

Two properties matter more than the field list. Content never leaves your systems — commitments are hashes, so a record can bind to a file, an agreement or a recipient identifier without any of them being transmitted. And records are sealed on write: hash-chained into a per-tenant series, signed, and periodically anchored, so an edit to an earlier record breaks the chain in a way a third party can detect without trusting either of us. For a six-month retention duty, that difference is the whole point.

08The integration

One HTTPS call per act, from wherever the act happens. Nothing sits in your generation or publishing path, so nothing here can fail closed and take your pipeline down.

# A dissemination platform classified a file and wrote its provenance fields back. curl -X POST https://api.planisphere.ooo/v1/record \ -H "Authorization: Bearer $PLANISPHERE_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "pack": "cn-ai-labelling", "event_type": "propagation_label_added", "occurred_at": "2026-08-01T09:14:52Z", "system_id": "feed-ingest", "system_seq": 8814021, "source_payload": { "content_sha256": "7b31…" // the file. Never sent. }, "metadata": { "platform_code": "PLT-00417", "upstream_content_id": "PRD-9f22a1", "notice_form": "is_generated" // tier one: metadata present } }'

The Article 9 case is the same call with unlabelled_supply_agreed, committing the agreement hash and a hashed recipient identifier, with retention_until carrying the six-month horizon. The recipient is committed as a hash, so the log identifies who received the content without your putting an identity into our systems.

The full API reference covers authentication, idempotency, batching and rate limits; pricing is per record with a monthly free allowance.

09How it is actually enforced

Article 13 sets no penalty. The Measures are a normative document and cannot create one; they refer enforcement out to the competent departments under existing law, with sanctions borrowed from the upstream instruments and the Cybersecurity Law. In practice, published enforcement has been administrative rather than financial — regulatory interviews, orders to rectify within a deadline, formal warnings, delisting, and account-level sanctions.

What has actually happened is more instructive than the theory:

  • 25 November 2025 — a nationwide sweep of mobile apps. On the provider side, CAC cited missing explicit labels, labels not carried through on export, and missing metadata. On the platform side: failure to verify metadata, failure to display the notice, failure to write dissemination metadata, and no declaration function for users. The number of apps was not disclosed.
  • 12 February 2026 — a campaign reporting 13,421 accounts sanctioned and more than 543,000 items removed. Categories included unlabelled AI content, face-swap impersonation of public figures, and — squarely under Article 10 — selling de-labelling tutorials, software and services.
  • 28 April 2026 — CAC publicly named three services for failing to implement labelling effectively, citing the Cybersecurity Law, the Interim Measures for Generative AI Services and these Measures together, and directed local offices to apply interviews, rectification orders and warnings.

The pattern to plan against: enforcement is specific and it names the failure. Two of the three most-cited failures — export stripping and the missing write-back — are questions about what your systems did to a particular file on a particular day.

10What Planisphere does not do

Stated plainly, because a vendor who is vague here will be vague in front of a regulator. Planisphere is an evidence layer. It sits beside your systems, never inside the act.

  • It does not apply explicit labels, write the AIGC metadata block, or watermark anything. Your pipeline does that.
  • It does not verify metadata on your behalf, classify content into the three tiers, or detect synthetic media.
  • It does not host or distribute content, and does not observe what your users published.
  • It is not an algorithm filing, not a security assessment, and not a determination that a label satisfies GB 45438-2025.
  • It does not certify compliance or make a legal determination. No vendor can. A record is evidence a third party can check; it is not a finding that you complied.
  • It does seal the acts you performed, at the moment you performed them, in a form that a hostile reader can verify and you cannot quietly revise — which is what a six-month retention duty and a per-file verification duty both actually require.

11Questions

Does our C2PA implementation satisfy GB 45438-2025?
No. The standard specifies a flat JSON object under an AIGC key in the file's native metadata, with named fields for the producer and the propagator. C2PA is a cryptographically signed manifest with assertions and a hard binding to the asset. They can coexist in the same file — and in a multi-jurisdiction pipeline they generally must — but neither satisfies the other.
We only sell an API to businesses. Are we out?
Unresolved. The Measures contain no B2B or API exemption, and scope is inherited from the upstream instruments — one of which carves out services not provided to the domestic public. An API confined to a closed enterprise pipeline is arguably outside; one whose output reaches public-facing Chinese content is not. This is a question for counsel, not a page.
Our metadata keeps getting stripped by re-encoding. Is that a violation?
Article 10's prohibition is on malicious removal, so incidental loss in a transcode is not on its face a breach of it. But it can still put you in breach of your own Article 5 or Article 6 duty, and preserving the block through edit, transcode, export and delivery is an engineering programme rather than a configuration change. Recording what you wrote, when, is the part that survives the re-encode.
How does this compare with the EU?
China prescribes the method and regulates the whole distribution chain; the EU states an outcome and binds providers and deployers only. Nothing in Article 50 obliges a platform or an app store to inspect files and re-mark them. The EU page covers that regime.
What happens to our content and metadata?
Content is never transmitted — only hash commitments. Declared metadata values are retained only when the pack marks the key as retainable and your organisation has enabled retention; otherwise only key names and a canonical hash are kept. Person-identifying keys are never retainable, which is why a recipient identifier is committed as a hash.

12Sources

Every article number, date and duty on this page traces to one of these. Where the Chinese text is summarised in English, the summary is ours and the citation points at the original.

Start the evidence trail

The console opens on the China pack with every act in the chain listed, each showing the exact call that seals it. Sealing one record takes about a minute, and the first thousand each month are free. If you would rather read first, the integration guide covers authentication, batching and the retention controls.