China's AI labelling measures are already in force. Before an agent publishes a generated clip, someone needs to know which labels, metadata and declarations belong with it.
What changed, and when
The four authorities issued the Measures for Labelling Artificial Intelligence-Generated and Synthetic Content on 7 March 2025; CAC published the notice on 14 March. Article 14 made them effective on 1 September 2025. The official Q&A calls the Measures a normative document: these are binding administrative measures implementing underlying law, not a newly enacted statute or voluntary checklist. [1][2]
The official national-standard register lists GB 45438-2025 as compulsory and current, published 28 February 2025 and implemented 1 September 2025. We checked its register status, not clause-by-clause technical conformity. [5]
On 28 April 2026, CAC reported enforcement involving the Jianying (剪映) and Maoxiang (猫箱) apps and Jimeng AI (即梦AI) website over problems including failure to implement AI labelling requirements. The collectively reported actions included regulatory interviews, orders to correct, warnings and strict action against persons responsible. The notice does not assign each action to every platform or announce a fine amount. Article 13 refers violations to the applicable underlying laws and rules; it does not create a fixed fine tariff. [1][4]
Your role changes the duties
Article 2 ties scope to internet information service providers within the referenced algorithmic-recommendation, deep-synthesis and generative-AI regimes. Do not assume every AI-tool user worldwide has the same obligations. A CN field in software is not a jurisdictional determination. [1]
- Generation: Article 4 incorporates the deep-synthesis Article 17(1) trigger. For covered video, conspicuous explicit labels belong on the opening frame and in appropriate positions around playback; end/middle labels are additional options, not a universal continuous burned-in watermark. Download, copy and export files must carry qualifying explicit labels, subject to Article 9. [1][2]
- Metadata: Article 5 requires implicit file-metadata labels under the referenced Article 16, including generation attributes, provider name/code and content number. Digital watermarking is encouraged separately. Optional watermarks do not make required metadata optional. [1]
- Distribution: Article 6 requires dissemination services to check metadata, provide declaration tools and apply appropriate notices. Confirmed metadata, a user declaration without detected metadata, and suspected generated content have different certainty levels. Relevant distribution metadata is also required in the specified cases. Missing metadata is not proof that content is human-made. [1]
- Users: Article 10 requires publishing users to proactively declare generated/synthetic content and use the provider's labelling function. It also prohibits malicious removal, alteration, forgery or concealment of labels and assistance with those malicious acts. Accidental metadata loss is not automatically a finding of malicious removal. [1]
The exception is not a public-release permission slip
Under Article 9, a user may request generated content without explicit labels. The provider must first clarify the user's labelling obligations and use responsibilities through the user agreement and lawfully retain relevant logs, including recipient information, for at least six months. This does not waive implicit metadata duties. The official Q&A preserves declaration and explicit-labelling duties when that content is later published publicly. Separate rules for news publishing, film/TV and other specialist sectors still apply. [1][2]
Hypothetical: an AI video reaches the publish step
Assume the service is in scope and the applicable explicit-label trigger is met. An agent is about to publish a generated clip. The team checks required visible labels, metadata and the publishing platform's declaration path first. Any Article 9 handoff needs its own conditions checked; it is not permission to distribute an unlabelled public clip. This is an illustrative workflow risk, not a reported incident or a finding of legal breach. A review step is a workflow control, not a safe harbour mandated by these Measures. [1][2]
Separate actual isolated HaltState test
We executed the real policy engine from an immutable source archive against an authored synthetic policy. A content.publish request carried region=CN, labelling_review_required=true, proposed_outcome=publish and requester_role=content_operator. The engine returned APPROVAL_REQUIRED. These are authored fixture values, not legal classifiers or results of inspecting media.
Review remained pending. No content was published, no connected publishing service was blocked and no human approval was completed. The evidence records the policy version and a verified content digest. It is unsigned, hash-only evidence generated with in-memory policy/Redis fixtures, network/subprocess audit guards and an isolated credential-free environment. This test did not validate visible labels, metadata, watermarks, the national standard or production enforcement.
What HaltState does not solve
This test does not determine Chinese-law applicability, implement the technical standard, replace specialist review or certify compliance. Original Chinese sources control; our English translations received independent machine review, not Chinese counsel or native-speaker approval. Sources and status checked 10 September 2026. This article is technical commentary, not legal advice.
Before your agent publishes, identify the required checks and the reviewer. Then keep a record that says what actually happened.
Official sources
[1] measures [2] official-qa [3] announcement [4] enforcement [5] standard
Inspect the isolated test record and limitations.
Actual isolated test record
Authored in-memory policy evaluation. Unsigned hash-only evidence, not certification.
- Action
content.publish- Authored policy
cn_labelling_review_demo_v1 - Decision
APPROVAL_REQUIRED - Policy version
09cc81b326c0a92dfee699fa27c3fcf6 7135ba6c960b9755 cdbc4ce7c5cb45a9 - Frozen source
1929e1606d8687b9dfaede9b1e78af43 9a07fdc7 - Content digest
2c8592cbfb18a3676a8c42cb7e8561a5 cd5c3e10ee4cf9e7 faa8d507988b28cd
No video was published. No connected publication was blocked. No person completed an approval. No production connectors, persistent storage or signing were exercised.