An Eighteenth Round, Quietly Institutionalized
On July 17, 2026, the Cyberspace Administration of China (CAC) published the 18th batch of its deep-synthesis service algorithm filing list, the latest in a now-routine cadence of registry updates that began under the Provisions on the Administration of Algorithm Recommendation for Internet Information Services (effective March 1, 2022) and the Provisions on the Administration of Deep Synthesis of Internet Information Services (jointly issued by the CAC, MIIT, and the Ministry of Public Security in November 2022, effective January 10, 2023). The prior batch, the 17th, went up just ten weeks earlier, on May 6, 2026 — evidence that what began as an experimental disclosure mechanism is now a fixed bureaucratic rhythm, publishing every six to ten weeks without exception.
The regime applies to any deep-synthesis or recommendation-algorithm provider whose service carries "public opinion attributes or social mobilization capacity" — CAC's own language for platforms that can shape what large numbers of people see, believe, or do. Covered companies must file with the national registration system at beian.cac.gov.cn, disclosing the technical basis of their algorithm, the categories and sources of training data, whether personal information is involved, and an internally authored "algorithm security self-assessment."
The Scale Is No Longer Small
This is not a boutique compliance exercise. Registry data analyzed by Gradient Flow found that as of April 2025 the system already held 3,739 registered generative algorithmic tools from roughly 2,353 distinct companies, with new filings arriving at a pace of 250 to 300 per month. Eighteen published batches later, the filing regime has become the closest thing in the world to a real-time, compulsory census of which companies are running consequential recommendation and generative systems — and what they say those systems do.
The Fair Case for It
Before criticizing the mechanism, it's worth stating the strongest version of the case for it. No comparable jurisdiction requires this level of routine, mandatory disclosure of recommender and generative-AI systems before and during deployment. The EU AI Act's transparency obligations apply mainly to "high-risk" categories and lean on post-market conformity assessment; the US has no federal filing requirement for recommendation algorithms at all. China's regime forces every covered company — from Baidu down to small livestreaming apps — to document training data provenance, flag personal-information use, and submit a security self-assessment, on a fixed public schedule, before the algorithm reaches a mass audience. If the goal is to know who is running what before it shapes public discourse, this is a more systematic instrument than what Brussels or Washington has built.
Where the Case Breaks Down
The trouble is what "transparency" turns out to mean in practice. The Carnegie Endowment's analysis of the registry's public filings found that the disclosures visible to outsiders are frequently vacuous — Weibo's own filed description of its algorithm was, in Carnegie's assessment, "so high level as to be almost completely devoid of meaningful detail." The richer information — training data specifics, the actual self-assessment — is retained by regulators and never made public. That is disclosure to the state, not to the public whose feeds the algorithm shapes. Calling this a transparency regime for citizens overstates what it delivers; it is a transparency regime for the CAC.
More consequential still is what the registry actually functions as. ChinaTalk's analysis of the filing system lays out a live scholarly disagreement — Angela Zhang reads the regime as "merely" registration, while Matt Sheehan argues it operates "more like a licensing regime than a simple registration process" — and comes down on the licensing side of that line. Generative-AI large-model filings in particular require iterative rounds of fine-tuning and direct testing before a product can go live, and CAC maintains ongoing communication with providers after launch, not a one-time check-the-box filing. A company cannot simply notify the state that its algorithm exists; it must clear a gate the state controls, with no published appeals process beyond an objections mailbox for third parties.
The Design Flaw Is Fixable, and Instructive
That distinction matters for how other jurisdictions should think about recommender-system transparency, an idea gaining traction in the EU's Digital Services Act debates and in US state-level algorithm-disclosure bills. A disclosure mandate — file your training data sources, your risk assessment, on a public schedule — is a genuinely portable, pro-transparency idea. Converting that filing into a discretionary, opaque pre-clearance gate is not; it hands regulators the power to quietly block a product's market entry with no public reasoning and no independent review, a power that predictably favors incumbents who can absorb the compliance and negotiation overhead and disadvantages smaller entrants and foreign competitors who cannot. Eighteen batches in, China has proven the census can be built and sustained. What it has not proven — and what other regulators should not copy — is that the gate behind that census needs to be invisible to the public it claims to protect.