China China Personal Information Protection Law PIPL

China's AI Companion Rules Pair Real PIPL Data Rights With a Birth-Rate Mandate

Beijing's July 15 rules give AI companion users copy/delete rights and consent protections, bundled with content licensing aimed at boosting births.

China's AI Companion Rules, By the Numbers People of Internet Research · China 5 Agencies co-issuing rules CAC, NDRC, MIIT, Ministry of Publi… Under 14 Guardian consent age threshold Providers must obtain guardian con… 2 hours Continuous-use alert trigger Providers must prompt users after … Oct 15, 2026 Doubao data deletion deadline ByteDance gives users a read-only … peopleofinternet.com
China's AI Companion Rules, By the Num… People of Internet Research · China 5 Agencies co-issuing rules Under 14 Guardian consent age threshold 2 hours Continuous-use alert trigger Oct 15, 2026 Doubao data deletion deadline peopleofinternet.com

Key Takeaways

China's Cyberspace Administration and four other ministries — the National Development and Reform Commission, the Ministry of Industry and Information Technology, the Ministry of Public Security, and the State Administration for Market Regulation — jointly issued the Interim Measures for the Administration of AI Anthropomorphic Interactive Services on April 10, 2026. After a three-month compliance window, the rules took effect July 15, applying to AI products that simulate a stable personality and sustain an ongoing emotional relationship with users — companion chatbots, virtual romantic partners, roleplay agents — while explicitly exempting general-purpose assistants, customer-service bots, and study tools.

The Privacy Core Is Genuinely PIPL-Grounded

Strip away the politics and the data-protection layer of these rules looks like a fairly ordinary extension of the 2021 Personal Information Protection Law into a new product category. Per the CAC's own explainer, providers may not share a user's interaction data with third parties "except when legally required or with explicit consent" (除法律另有规定或者权利人明确同意外,不得向第三方提供用户交互数据), and users must be given the ability to copy or delete their own chat histories, plus a convenient way to exit the service entirely. For anyone processing a minor's personal information — defined here as under 14 — providers must first obtain guardian consent.

Those are not radical asks. They track the same portability-and-deletion logic found in the EU's GDPR and the age-gating logic behind the US's COPPA and similar under-16 provisions in the UK's Age Appropriate Design Code. A market defined by apps engineered to maximize daily engagement with an artificial companion — where the entire business model runs on emotional stickiness — is a reasonable candidate for consent and portability rules with real teeth. That's the steelman for regulators here, and it's a fair one: engagement-optimized companion AI has a structural incentive problem that ordinary consumer software doesn't, and light-touch disclosure alone hasn't addressed it anywhere it's been tried.

Where the Measures Go Further Than Data Protection

The rules don't stop at data rights. They ban virtual romantic or familial relationships with any user under 18 outright — not just requiring consent, but forbidding the product category for minors entirely. They mandate a pop-up disclosure reminding users the content is AI-generated, and require providers to alert users after two continuous hours of use. Providers must also contact a user's emergency contact or guardian if the system detects signs of a mental health crisis. And every covered service needs a government security and content review before launch, repeated whenever it adds anthropomorphic features, changes its underlying technology significantly, or crosses roughly one million registered users.

That last piece is where this stops looking like PIPL enforcement and starts looking like a licensing regime. "Significant technology change" is not a defined threshold — it's whatever the reviewing agency decides it is, which hands regulators open-ended leverage over which companion products get to exist, not just how they handle data. South China Morning Post reported that ByteDance's Doubao and Alibaba's Qwen preemptively disabled their custom, humanlike agent features ahead of the deadline: Qwen cut its personalized agent functions on July 10 and shut down broader agent services on July 15, while Doubao is giving users a read-only window on their saved companions until October 15, after which the data becomes unrecoverable. Those are two of China's best-resourced AI labs, with compliance teams built for exactly this kind of regulatory turn. A smaller companion-app startup facing the same pre-launch review and the same discretionary re-review trigger doesn't have that cushion — the practical effect is a market that consolidates around incumbents able to absorb the compliance overhead, which is the opposite of what proportionate regulation should produce.

The Motive Problem

What separates this from a conventional data-protection rollout is the declared rationale. As MediaNama reported, the Wall Street Journal's framing — echoed across Chinese state commentary — ties the rules directly to the country's record-low birth rate: officials worry that always-agreeable AI partners are keeping people out of the human relationship and marriage market. That is a legitimate demographic anxiety for Beijing to have, but it is not a data-protection rationale, and folding it into a privacy statute blurs a line that should stay bright. A consent-and-deletion regime protects users regardless of what they choose to do with a companion app. A regime that also bans a category of relationship for being too appealing, reviewed pre-launch by the same state apparatus that vets political content, is optimizing for a policy outcome — more marriages, more births — that has nothing to do with whether a user's chat history is safe from a data broker.

The portability and consent provisions here are worth keeping and worth other jurisdictions studying. The pre-launch content licensing bundled in alongside them, justified by a state fertility target rather than user harm, is a different animal — and it's the one that should worry anyone watching whether "AI safety" regulation becomes a vehicle for behavioral engineering rather than user protection.

Sources & Citations

  1. CAC — Interim Measures announcement
  2. CAC — Official Q&A on the Measures
  3. South China Morning Post
  4. MediaNama