China China algorithm registry recommender systems

China's Third AI Safety Framework Rests on a Filing Registry That Records Algorithms but Cannot Show Whether They Are Safe

TC260's September 2026 framework targets self-improving AI, but its enforcement backbone is still the 2022 algorithm registry and deep-synthesis filings.

China's Algorithm Filing Regime People of Internet Research · China 18 Deep-synthesis batches published Eighteenth batch published July 17… 10 Days to file after launch Working days, per Article 24 of th… Mar 2022 Recommender rules in force since Issued December 31, 2021 by four a… peopleofinternet.com
China's Algorithm Filing Regime People of Internet Research · China 18 Deep-synthesis batches published 10 Days to file after launch Mar 2022 Recommender rules in force since peopleofinternet.com

Key Takeaways

On September 14, 2026, China's national cybersecurity standards body, TC260, released the third edition of its AI Safety Governance Framework. According to Rest of World, it addresses AI systems that could "autonomously learn, optimize itself, and undergo 'recursive self-improvement'" faster than humans can control. The timing is pointed. Earlier in September, Anthropic CEO Dario Amodei called for the industry to slow development of its most powerful models. On September 11, Foreign Ministry spokesperson Guo Jiakun called the proposal "fear-mongering, confrontation and vicious competition."

Beijing is not ignoring frontier risk, then. It is rejecting a slowdown that would be negotiated with Washington. The more useful question is what machinery China would use to act on the framework, and what that machinery can and cannot do.

The case for China's approach

The strongest argument for the registry model is legibility. A regulator that does not know which algorithms are in service cannot govern any of them. China's Algorithmic Recommendation Provisions were issued on December 31, 2021 by the Cyberspace Administration of China (CAC), the Ministry of Industry and Information Technology, the Ministry of Public Security and the State Administration for Market Regulation. They took effect on March 1, 2022. The official text on cac.gov.cn requires providers with "public opinion properties or social mobilization capabilities" to file within ten working days of launching. The filing includes the provider's name, service form, application domain, algorithm type and a self-assessment report.

Some of the substantive duties are consumer protections that a liberal democracy would recognise. The Stanford DigiChina translation shows Article 17 obliging platforms to offer users "a convenient option to switch off algorithmic recommendation services." Article 21 bars algorithmic price discrimination based on consumer characteristics or habits. Few other jurisdictions require recommender opt-outs by default.

The registry keeps growing, and it now covers generative AI

The filing model was extended to generative media. The Deep Synthesis Provisions were released by the CAC, MIIT and the Ministry of Public Security on November 25, 2022 and took effect on January 10, 2023 (see the CAC's publication). Under them the CAC began publishing lists of filed deep-synthesis algorithms. The first appeared on June 20, 2023, according to the Digital Policy Alert tracker. Batches have continued since: the seventeenth on May 6, 2026, and the eighteenth on July 17, 2026.

That is a steady cadence, roughly one batch every two to three months. It shows that the filing regime is operational, not decorative. It also shows what the regime measures: which services exist and who runs them.

What a registry cannot tell you

The risk the new framework names is recursive self-improvement, and a filing captures none of it. Look at the fields the recommender rules require: name, form, domain, algorithm type, and a self-assessment. Every one of them describes a system at a moment in time, and the self-assessment is written by the provider. A model that changes its own behaviour after deployment can move well beyond what was on file. Nothing in the registry model, as published, tests whether the filed description still matches the running system.

The second problem is scope. The recommender filing duty attaches to services with public opinion or social mobilisation capacity. That trigger comes from content-control logic. It was built to find services that can shape what people see and coordinate what they do. It was not built to find systems whose capabilities could outrun oversight. Applying a speech-governance tool to a capability-governance problem produces a mismatch. A frontier lab's internal research model may never be offered to the public and would never trigger a filing.

A third cost falls on ordinary developers. Ex-ante filing gives regulators a chokepoint at launch. For a startup, that means paperwork and delay before a product reaches users. For a state, it means a standing list of everyone to call when something goes wrong. Both things can be true, and only the first one is a cost to innovation.

The proportionate alternative

The better design principle is to regulate the risk, not the registration. Post-deployment monitoring, incident reporting and independent evaluation address self-modifying systems directly. They do so without making every launch wait for a clearance. Registration lists are cheap to run and easy to publish. They should not be mistaken for assurance.

There is also a lesson for the Western debate that provoked this response. Rest of World reports that Chinese officials and engineers read Amodei's proposal as an attempt to preserve the U.S. lead. Whatever one thinks of that reading, a slowdown that depends on one government's cooperation is fragile. A credible international conversation would begin with what can be verified. That includes whether filed descriptions match deployed behaviour, and whether incidents get reported. Neither Washington nor Beijing has built that verification yet.

What to watch

Three things will show whether the third edition has teeth. The first is whether TC260's language on autonomous learning turns into a mandatory standard or stays voluntary guidance. The second is whether CAC filing forms gain fields on model updating and self-modification. The third is whether the nineteenth deep-synthesis batch says anything about how post-filing changes are audited. Until then, China has the most extensive algorithm registry in the world and a framework that names a risk the registry was not built to see.

For readers outside China, the practical point is narrow. The registry is evidence of administrative capacity, and administrative capacity is not the same as safety. Policymakers elsewhere copying the filing template should ask what it lets a regulator verify after launch, not how many entries it holds.

Sources & Citations

  1. CAC: Algorithmic Recommendation Provisions (official text)
  2. CAC: Deep Synthesis Provisions (official text)
  3. Rest of World: Dario Amodei wants to slow AI. China isn't taking orders
  4. Stanford DigiChina: Algorithmic Recommendation Provisions translation
  5. Digital Policy Alert: Seventeenth deep synthesis filing batch