On September 14, 2026, the Cyberspace Administration of China (CAC) published its latest batch of generative AI filings. Cumulative filings reached 1,112 generative AI services and 731 registered applications or features as of August 31. In July and August alone, 124 services completed national filing and 133 applications completed local registration. Seven of the new entries run generative AI directly on smartphones (remio summary of the CAC notice).
The numbers are best read as the output of a regulatory architecture, not just a market indicator. That architecture deserves a fair hearing before it is criticised.
The case for the registry
The strongest argument for filing is accountability. A registry gives regulators a named counterparty for every deployed model. It forces providers to disclose which foundation model sits under a product. It creates a paper trail when something goes wrong. The CAC notice requires companies to display model names and filing identifiers prominently in launched products, which is a real transparency feature. Many jurisdictions debating AI accountability have nothing comparable.
China's framework also has a stated innovation clause. Article 3 of the Interim Measures for the Management of Generative AI Services, effective August 15, 2023, commits to balancing development and security. It calls for "inclusive and prudent" supervision that is tiered by category and risk. Under that logic, filing is a gate that most services are expected to pass.
How the two-track system works
The data shows a division of labour. Direct model providers complete national filing with the CAC. Downstream developers who build on an already-filed model register their applications through local cyberspace authorities. Registrations are growing faster than filings. Year-end 2025 stood at 748 filed services and 435 registered applications. By August 31, 2026 those figures were 1,112 and 731, about 49% and 68% higher respectively (per the remio summary above). The previous batch, covering May–June, added 120 services and 68 applications (Digital Policy Alert). The July–August batch nearly doubled the application count, from 68 to 133.
This layering matters. A small developer wrapping a filed model does not need national approval, which lowers the cost of building on top of the base layer. In that respect the system is more permissive than a flat licensing regime.
The second gate: algorithm filing
The generative AI filing is not the only gate. Article 17 of the Interim Measures says services with "public opinion attributes or social mobilization capability" must conduct a security assessment. They must also complete algorithm filing, change and cancellation procedures under the recommender-algorithm rules. Those rules are the Provisions on the Management of Algorithmic Recommendations in Internet Information Services, in force since March 1, 2022.
Article 24 of the Provisions requires covered providers to file within ten working days of launch. They submit their name, service form, application domain, algorithm type and a self-assessment report. Article 17 gives users a non-personalised option or a convenient way to switch recommendations off, and providers must stop immediately when a user opts out. These user-facing rights are the most defensible part of the regime. A non-personalised feed is a good idea, and several other jurisdictions have since copied it (Stanford DigiChina translation).
Where the proportionality problem lies
The trouble is the trigger. "Public opinion attributes or social mobilization capability" is not defined by risk to users. It is defined by a service's capacity to shape what people think and how they organise. Any chatbot, summariser or feed that reaches a wide audience can plausibly meet it. The test is a statement about speech, not a measure of harm such as fraud or safety defects, so it sits outside the proportionate, evidence-based model we favour.
Three consequences follow. First, a filing-before-launch model puts the regulator between a developer and its users. The developer must wait for approval and has little recourse if it is slow. Second, the opinion-based trigger gives officials wide discretion over which services count, and the public data does not show how many do. We could not find a published breakdown of how many filed services also hold an algorithm filing. Third, the registry's growth rewards scale. Large firms can run compliance teams, while a solo developer cannot easily absorb a multi-step process.
The counterargument is that 1,112 approvals show the gate is not a barrier. That reading is too generous. Approval counts say nothing about the services that were never submitted, were delayed or were quietly abandoned, and the CAC does not publish rejection or withdrawal figures. A registry with a visible approval stream and an invisible refusal stream cannot be evaluated on throughput alone.
What better would look like
Other jurisdictions should neither copy this model nor dismiss its transparency features. Disclosure of the underlying model, user-facing opt-outs from personalised feeds and a clear accountable entity are worth borrowing. A trigger based on content influence is not. Regulation tied to demonstrable harms such as fraud, safety failures and data misuse is narrower and easier to audit. It also leaves speech decisions to users and courts, not licensing officials.
China's own data supports the point about scale. The regime is processing hundreds of filings every two months, and the compliance load will keep growing. Publishing refusal and withdrawal figures alongside approvals would be a cheap test of whether the system is proportionate in practice. Until then, the headline count shows how many services are inside the system and little about how well it works.