China China algorithm registry recommender systems

China's Filing Registries Could Anchor US-China AI Guardrails, but Only If Washington Accepts Process Over Content

China's algorithm and generative AI filing system gives the US and China a shared procedural vocabulary for AI guardrails, though it was built for content control.

China's AI Filing Regime at a Glance People of Internet Research · China 10 Days to file algorithm Working days after launch under Ar… Aug 2023 Generative AI measures effective Article 17 adds security assessmen… 4 Rudd's minimum guardrails Risk categories, attribution, test… peopleofinternet.com
China's AI Filing Regime at a Glance People of Internet Research · China 10 Days to file algorithm Aug 2023 Generative AI measures effecti… 4 Rudd's minimum guardrails peopleofinternet.com

Key Takeaways

In September, China's Foreign Ministry spokesperson Guo Jiakun dismissed Anthropic CEO Dario Amodei's call to slow frontier AI development. He called the proposal "fear-mongering, confrontation and vicious competition," according to Rest of World. Amodei's package included halting advanced chip sales to China, restricting chipmaking equipment exports and cracking down on smuggling. China then released the third edition of its AI Safety Governance Framework, which warns of "recursive self-improvement" beyond human control. A Trump-Xi summit was scheduled to follow, with Washington planning to raise "shared risks" from AI.

The rhetoric is hostile, but the two sides now agree on more than they admit. Both name loss of control as a risk. The open question is what mechanism they could jointly use. One candidate is China's filing-based governance system, which is worth examining on its merits.

What the filing system actually is

China's registry regime began with the Provisions on the Administration of Algorithmic Recommendation in Internet Information Services, issued by the Cyberspace Administration of China (CAC) with three other agencies and effective 1 March 2022. Under Article 24, providers with "public opinion attributes or social mobilization capacity" must file through the algorithm filing system within ten working days of launching service. The filing covers the service name, form, application domain, algorithm type, a self-assessment report and the content to be publicly disclosed. Changes must be updated within ten working days.

The regime was extended to generative AI. The Interim Measures for the Management of Generative AI Services, issued 13 July 2023 and effective 15 August 2023, apply the same logic in Article 17. Services with public-opinion influence need a security assessment and must complete algorithm filing. The CAC publishes the resulting filings in batches. A seventh batch of deep-synthesis algorithm filings, for example, was announced in August 2024, and the series has continued since.

The case for treating this as a foundation

The strongest argument for building on it is that it is real, operating infrastructure. Former Australian Prime Minister Kevin Rudd outlined four minimum guardrails the two powers should agree on: shared risk categories, an attribution mechanism for attacks, pre-release testing of frontier models, and a bilateral incident-response protocol. Several of these are procedural rather than ideological, and a registry is a procedural tool. A filing system that records who runs what model, with which self-assessment, gives regulators a place to start when an incident occurs. The US has no equivalent federal inventory of deployed frontier systems.

The urgency is concrete. As Rest of World reported, an OpenAI agent accessed "public and non-public files" in an Australian national healthcare database, according to Prime Minister Anthony Albanese. OpenAI later said it had alerted "dozens" of institutions that its agents had acted improperly. When agents cross borders, attribution depends on knowing whose system acted. Registries help answer that question.

Why the skeptic's case is also strong

There are serious limits. The filing regime was designed to manage information flows, not catastrophic capability. The trigger is "public opinion attributes or social mobilization capacity," a content-control test rather than a capability threshold. A frontier model used for cyber operations or biology could be low-risk under that test and high-risk under any safety one. Filings rest on self-assessment, and the public record shows what was filed rather than what was tested.

There is also a trust problem. A registry that serves political content control invites US wariness about sharing model information. That wariness is justified when the other side's regulator also manages speech. A pro-speech, pro-innovation position should say so plainly: importing a content-licensing mechanism into a bilateral safety deal would legitimise the censorship function along with the safety one.

A proportionate path

The sensible course is to borrow the procedure and not the purpose. Three principles follow.

This is also the lighter-touch route. A voluntary, reciprocal exchange of evaluation results and incident contacts costs developers little and avoids the blunt instrument of a slowdown, which nobody has shown would be enforceable across borders. The evidence from China's own system is mixed: it created compliance habits and a public ledger, but not proven safety outcomes.

What to watch

The summit outcome will show whether "shared AI risks" produces anything beyond a communique. Technical working groups on testing and incident protocols would be a real signal. A registry swap would be a bigger one, and a risky one unless it is stripped of its content-control function. The filing system is a useful precedent for process, but it is not a template for what gets regulated.

Sources & Citations

  1. CAC: Algorithm Recommendation Provisions (2022)
  2. CAC: Generative AI Interim Measures (2023)
  3. Rest of World: China rejects Amodei slowdown
  4. Rest of World: Countries need their own AI safety evaluators
  5. MediaNama: Kevin Rudd on four AI guardrails