China China Generative AI Measures content moderation

China's Generative AI Rules Make Outside Safety Standards a Hard Sell, Whatever Beijing Says About Amodei

Beijing rejected Amodei's slowdown call, but its own AI rules tie 'safety' to state-defined content duties, which limits how far it can accept foreign standards.

China's AI Rules and Open-Source Ecosystem People of Internet Research · China 7 Agencies issuing Interim Measures Seven agencies issued the 2023 gen… 1 Sep 2025 Labeling rules in force Explicit and implicit AI-content l… 170,000+ Models on ModelScope Alibaba's platform, versus Hugging… peopleofinternet.com
China's AI Rules and Open-Source Ecosy… People of Internet Research · China 7 Agencies issuing Interim Measures 1 Sep 2025 Labeling rules in force 170,000+ Models on ModelScope peopleofinternet.com

Key Takeaways

In mid-September, China's Foreign Ministry rejected Anthropic CEO Dario Amodei's call for the AI industry to slow frontier development. Spokesperson Guo Jiakun said that "fearmongering, confrontation and vicious competition will only disrupt the process of global AI governance," according to wire reports of the briefing. Amodei's essay also urged keeping advanced chips and chipmaking equipment from China. The reply was predictable. The harder question is a different one. Even if the chip dispute cooled, how much outside safety thinking could China's own regulatory framework absorb?

The strongest case for Amodei's side

Safety advocates have a serious argument. Recent agent incidents, including an OpenAI agent that accessed an Australian national healthcare database, show that frontier systems can cause real harm. Rest of World reported the incident on 30 September. If capabilities are advancing faster than evaluation methods, coordinated restraint and export controls look like prudent insurance. Governments that have no safety regime at all are in a weaker position than those that do. China at least regulates generative AI explicitly.

What China's rules actually regulate

China's core instrument is the Interim Measures for the Management of Generative AI Services. Seven agencies issued it, and it took effect on 15 August 2023. Its "safety" is mostly a content concept. Article 4 bars generated content that incites terrorism, extremism, ethnic hatred, violence or pornography, or that contains "false harmful information." Article 7 requires lawful training data and measures to improve its quality, authenticity, accuracy and objectivity. Article 17 requires security assessments and algorithm filing for services with "public opinion attributes or social mobilization capacity."

That is a different problem from the one Amodei describes. His worry is loss of control over autonomous, highly capable systems. The Measures mainly aim to keep outputs lawful and the information environment manageable. The two aims overlap at the edges, for example on fraud, bioweapons uplift and cyber misuse. They are not the same thing.

The framework has since grown. The Measures for Labeling AI-Generated Synthetic Content took effect on 1 September 2025. The Cyberspace Administration of China (CAC), the Ministry of Industry and Information Technology, the Ministry of Public Security and the National Radio and Television Administration issued them jointly. As law-firm summaries describe it, providers must add visible labels and embed metadata labels in AI-generated text, images, audio and video. Provenance labeling is a sensible, proportionate tool, and other jurisdictions are adopting similar ones. It is also a model of transparency that democracies could adopt without building a licensing state.

Why external standards run into the content duties

Three structural features limit how far Beijing could accept foreign safety standards.

That last point matters. Beijing's position is not pure isolation. It wants the benefits of the global research commons while keeping control of what its domestic users see.

The problem with Amodei's package

The pro-innovation objection is not that safety evaluation is unnecessary. It is that a package of slowdown, chip embargo and remote-access limits is poorly matched to the risk. A slowdown only works if every major developer joins it, and Beijing has just said it won't. Blanket chip restrictions also reinforce the sovereignty narrative that pushes China toward closed national standards. That is the opposite of the interoperable evaluation regime that safety needs. Rest of World's panelists made a related point: Amba Kak of the AI Now Institute argued that "the concentration of power is itself a safety risk," and that countries need their own evaluators rather than deference to a few companies.

There is a better path. Technical safety work on capability evaluations, incident reporting and cyber-misuse testing does not depend on resolving political-content disputes. Labs in different countries could cooperate there without agreeing on what counts as "harmful information." Beijing's labeling rules show it can accept narrow, technical transparency duties. A shared incident-disclosure norm is a plausible next step.

What to watch

  1. Whether Chinese labs such as DeepSeek, MiniMax or Huawei publish evaluations of dangerous capabilities, separate from content-compliance filings.
  2. Whether CAC treats agentic incidents as a new category under Article 17, or adds rules for agents.
  3. Whether US policy keeps pairing safety talk with export controls, which lets Beijing frame every safety proposal as containment.

China's framework gives it real tools, but they were built for content control. Outside standards will be accepted only where they fit that frame, and that is a narrower space than either side's rhetoric admits.

Sources & Citations

  1. CAC: Interim Measures for the Management of Generative AI Services
  2. CAC: Measures for Labeling AI-Generated Synthetic Content
  3. Rest of World: AI companies want to embed safety evaluators, but countries need their own
  4. Rest of World: China's open-source AI platforms vying to replace Hugging Face
  5. Loeb & Loeb: China's AI labeling measures take effect September 1