A New Layer on an Old Stack
On July 29, 2026, the Cyberspace Administration of China (CAC) published a draft Anti-Cyberbullying Law of the People's Republic of China for public comment, with the consultation window closing August 28, 2026 (CAC notice). If enacted, it would be the first national statute — not just an administrative rule — dedicated to cyberbullying, and it arrives with a distinctly 2026 feature: platforms must specifically detect, trace, and report content where AI tools were used "to create, copy, distribute, or disseminate cyberbullying information," per the CAC's own notice.
Non-compliant platforms face fines reported at up to 10 million yuan (~$1.4 million), alongside service suspension, app removal, and business-license revocation; responsible individual officers can be fined personally (CAC notice; Caixin Global). The law also reaches overseas actors who target people or entities inside China, and it permits public prosecution — not just private lawsuits — for severe cases of online defamation, a deliberate shift documented by Caixin from a 2023 judicial guideline that struggled to get victims into court on their own.
The Problem Is Real
Before litigating the draft's flaws, it's worth taking its premise seriously. In the CAC's own expert commentary accompanying the release, the drafters describe cyberbullying as a phenomenon that "not only violates individuals' or organizations' lawful rights but disrupts online order," and point specifically to coordinated, profit-driven harassment campaigns and the "extremely high cost" victims bear trying to identify anonymous attackers and collect evidence (CAC interpretation). That is not a strawman. Doxing pile-ons, AI-generated fake nude images, and synthetic-voice harassment are documented harms everywhere, and victims genuinely struggle against the asymmetry of anonymous, automated abuse versus a single target with no subpoena power. A law that gives victims faster evidence-collection tools and pushes platforms to build real detection infrastructure, rather than simply waiting for reports, addresses a gap that most jurisdictions — including the US and EU — have also struggled to close.
The AI-specific provisions, too, are a logical next step rather than a new posture. China's AI-Generated Content Labelling Measures took effect September 1, 2025, requiring explicit and implicit (metadata/watermark) labels on AI-made text, image, audio, and video content across major platforms like WeChat and Douyin (SCMP). The draft cyberbullying law essentially asks platforms to repurpose that traceability infrastructure for a narrower, harm-specific purpose: flagging when the AI-origin label attaches to abusive content.
Where Proportionality Breaks Down
The trouble is that the draft does not confine itself to that narrow purpose. Multiple outlets reporting on the text — not China's state press alone — describe a real-identity verification requirement attached to posting and messaging, alongside a broad definition of "cyberviolence" that folds AI misuse in alongside ordinary trolling (TheNextWeb). That combination — mandatory identity verification plus an elastic harm category plus detection obligations — is precisely the architecture that makes a harassment law reusable as a dissent-tracing law. China's existing content rules already require generative AI output to align with "core socialist values"; stacking a traceability mandate for "AI-generated abuse" on top of an identity-verification regime does not obviously stay confined to abuse once a platform has built the pipeline.
This is the recurring failure mode in platform regulation generally, and China is simply the starkest version of it: a policy built to catch a narrow, genuinely harmful behavior (coordinated harassment) is implemented through infrastructure — universal real-name linkage, AI-content tracing, mandatory reporting to authorities — that generalizes far beyond that behavior. A platform told to trace AI-generated harassment back to an account, and separately told to verify that account's real identity, has built a tool that works just as well against an anonymous critic of a local official as against a coordinated troll farm. The CAC's own materials frame the law around victim protection and evidence costs — a legitimate frame — but enforcement ultimately reports up to the same regulator that already polices political speech online.
What to Watch
The 30-day comment window closed August 28; a finalized text has not yet been published. Three things will determine whether this lands as proportionate harm-reduction or speech infrastructure: whether the final law narrows "cyberviolence" to conduct-based harassment patterns rather than content categories; whether real-name data collected for abuse-tracing is firewalled from unrelated content-policing referrals; and whether the shift to public prosecution for "severe" defamation cases comes with a judicially reviewable threshold, rather than prosecutorial discretion alone. Platforms operating in China have no real choice but to comply with whatever emerges — but foreign platforms, investors, and policymakers watching China's generative-AI governance stack should read this draft as the latest data point in a pattern, not an isolated child-safety measure.