From Departmental Rule to National Law
On July 29, 2026, the Cyberspace Administration of China (CAC) released a draft Anti-Cyberbullying Law for public comment, open through August 28 (CAC notice). The move is less a bolt from the blue than an escalation: the CAC already issued Regulations on the Governance of Online Violence Information in December 2023, which took effect in August 2024. Those were departmental rules — sub-statutory, issued solely by the CAC. The new draft is a law (法), meaning it would go through the National People's Congress Standing Committee and carry the weight of national legislation, with penalties several multiples higher than its predecessor.
The draft runs seven chapters and 60 articles (CAC notice). It requires platforms to build "cyberbullying feature libraries" and early-warning models using AI, big data and human review; to detect and trace AI-generated abuse such as deepfakes; to verify users' real identities before allowing posting or messaging; and to assist victims with evidence preservation. Violations carry tiered fines from ¥50,000 up to ¥2–10 million for cases with severe impact, plus service suspension, app shutdown, and licence revocation, with individual liability of up to ¥100,000 for responsible staff (CAC notice). Crucially, the law claims extraterritorial jurisdiction: "organizations and individuals outside PRC territory targeting those within PRC borders" face the same accountability (CAC notice; Caixin Global).
The Case For It
The strongest argument for this law is that it responds to a documented, serious harm rather than a manufactured one. Chinese platforms have seen high-profile pile-ons — Caixin's own reporting has traced how a K-pop fandom dispute metastasized into a national cyberbullying controversy — and coordinated harassment campaigns leading to real psychological damage are well-documented globally, from South Korea's 2020 "Sulli Law" push after a celebrity suicide to the EU's own harassment provisions under the Digital Services Act. AI has made this worse: deepfake harassment and synthetic abuse are qualitatively harder for a human moderator to catch than a text insult, and a regulator asking platforms to build detection systems for AI-generated abuse is not, on its face, an unreasonable response to an AI-native problem. The law also creates victim-side tools — evidence preservation, streamlined appeals, police assistance for private suits — that are the kind of due-process infrastructure that critics of platform inaction usually demand. On Weibo, the draft's hashtags drew over 7.8 million views, with many users arguing platforms should share responsibility for amplification (Global Times). That public appetite is real and shouldn't be dismissed as engineered consensus.
Where the Design Goes Further Than Harm Reduction
The trouble is the gap between the stated target — harassment — and the compliance architecture platforms must build to satisfy it. "Cyberbullying" is defined as concentrated or sustained online activity infringing reputation, honor, privacy, portrait rights or personal information (CAC notice) — a definition broad enough to cover a sustained journalistic investigation into a company executive, or coordinated public criticism of a local official's conduct, as easily as it covers targeted harassment of a private citizen. China's harassment and "rumor" statutes have a documented history of being applied to reporters and activists, not just trolls, and a mandate to build AI models that flag "concentrated or sustained" negative attention about a person is dual-use by design: the same classifier that catches a pile-on catches a viral accountability campaign.
The real-name mandate compounds this. China has required real-identity registration for social accounts since 2017, so this isn't new in principle — but pairing it with mandatory pre-emptive AI scanning and an extraterritorial jurisdiction clause changes the risk calculus for anyone abroad who criticizes entities inside China, since anonymity and distance were previously the two main insulators. Zhihu and other platforms are already tightening anonymous-account policies in anticipation (TheNextWeb), which is precisely the compliance-chilling-speech dynamic that vague, broadly worded content laws reliably produce, regardless of jurisdiction.
What to Watch
The honest, proportionate version of this law would narrow the definition to targeted, individualized harassment with intent and repetition requirements, wall off newsgathering and public-interest criticism explicitly, and drop or narrow the extraterritorial clause to cases with a genuine nexus to China rather than any "targeting." None of that is present in the July 29 draft. The 30-day comment window closing August 28 is the only real leverage point before this becomes binding law with NPC backing — worth tracking closely, because the fine schedule and enforcement discretion built into the final text will determine whether this becomes a genuine victim-protection statute or a broadened tool for policing online criticism under a harassment label.