A Routine Filing, A Durable System
On July 17, 2026, the Cyberspace Administration of China (CAC) published its eighteenth batch of domestic deep-synthesis service algorithm filings, the latest entry in a registry that has now been running, batch by batch, since June 2023. The announcement is procedurally unremarkable — a list of companies and algorithms newly entered into the Internet Information Service Algorithm Filing System, issued under the 2022 Provisions on the Administration of Deep Synthesis in Internet-Based Information Services. But the routineness is the point. Three years and eighteen batches in, China has built the most institutionalized algorithm-disclosure regime in the world, and it is quietly becoming the reference model other regulators cite when they debate whether to build one of their own.
What the Registry Actually Does
Under the Deep Synthesis Provisions and the earlier 2021 Algorithm Recommendation Provisions, any deep-synthesis or recommendation algorithm with "public opinion properties or social mobilization capacity" must file with CAC before public deployment, alongside a security self-assessment covering training data, intended use, and risk controls. The seventeenth batch, published May 6, 2026, cites the same statutory hook — Article 19 — that the eighteenth batch does, and both remind unfiled providers to come into compliance or face removal. The cadence has held steady at roughly every six to ten weeks since 2023, per the batch-by-batch tracking compiled by Digital Policy Alert, and it now runs parallel to a separate generative-AI service registry: CAC's own count shows 988 generative AI services had completed registration as of June 30, 2026, up from 796 at the end of February — evidence that the filing requirement has not throttled the market, whatever else it has done.
The Case For It
The strongest argument for a mandatory algorithm registry is not abstract. Deep-synthesis tools generate convincing fake video, audio, and text at a scale no platform's trust-and-safety team can review line by line, and a national filing requirement gives a regulator a standing map of who is deploying what, before a deepfake-driven fraud or disinformation wave forces a scramble to figure out which company built the tool. It also creates a paper trail — security self-assessments, dataset provenance, update-and-cancellation obligations — that most jurisdictions still ask platforms for only after something has already gone wrong. The EU's AI Act imposes its own registration duties on general-purpose and high-risk AI systems for similar reasons. A pre-market checkpoint is a defensible instrument for a technology whose harms are hard to attribute after the fact, and eighteen consecutive batches suggest CAC has actually operationalized that checkpoint rather than let it lapse into a one-time compliance exercise.
Where It Breaks Down
The problem is what the registry discloses to whom. Once an algorithm clears filing, CAC releases only an abbreviated public record — company name, a short algorithm description, a registration number — while the underlying security assessment, training-data sourcing, and technical logic stay inside the regulator. That is a meaningful transparency gap: the public, independent researchers, and foreign competitors get a directory entry, not an audit. Combined with the rule that generative AI services cannot be built on unregistered foundation models — which as a practical matter locks out unvetted foreign open-source releases — the registry functions less as a public accountability mechanism than as a state visibility and market-access control layer. That is a coherent design choice for a government whose stated priority, per its own repeated emphasis on "public opinion properties," is content control on a heavily censored internet, not consumer protection in the sense Western regulators usually mean it.
The registry gives Beijing a real-time inventory of every deep-synthesis and recommendation algorithm operating at scale in China — and gives everyone else a list of names.
Why It Matters Beyond China
Other jurisdictions weighing algorithm-registration mandates — the EU's GPAI registration under the AI Act, UK proposals for algorithmic transparency in recommender systems — should take the throughput lesson (988 registered services in eighteen months is not a market in collapse) without importing the opacity. A registry that discloses enough to the public to let outside researchers actually evaluate risk, not just confirm a filing exists, would do more for accountability than China's version does, at comparable compliance cost to industry. Proportionate regulation means matching disclosure to the harm you're trying to catch: mandatory filing for high-risk deep-synthesis tools is defensible; keeping the substance of every filing behind a state-only wall is a choice about who gets to audit power, not a technical necessity. Regulators reaching for China's registry as a template should copy the cadence and the pre-market checkpoint, and leave the opacity behind.