DCC summary, not a translation. GB/T 45674-2025 is a copyrighted national standard. The structured summary below is DCC’s own paraphrase grounded in the published text; specific clauses should be checked against the standard.
Published by: State Administration for Market Regulation and Standardization Administration of China; proposed and administered by the National Information Security Standardization Technical Committee (SAC/TC260).
Published April 25, 2025. Implemented November 1, 2025. Recommended national standard.
Scope
GB/T 45674-2025 specifies the security requirements for the platforms or tools, rules, personnel and verification of data annotation for generative-AI training, and describes the evaluation methods. It applies to data-annotation organizers (数据标注组织方) carrying out training-data annotation, and provides a reference for data requesters (数据需求方) inspecting or accepting annotation work and for third-party security assessment. It normatively references GB/T 42755-2023 (data annotation procedures for machine learning) and GB/T 45654-2025. The introduction identifies the risks the standard targets — data theft and leakage, data poisoning, and the generation of risky content through defective rules, poorly managed staff or unclear verification standards.
Key definitions: a prompt (提示信息) is the input guiding the model to a task; a response (响应信息) is the human-cognition-conforming answer formed to the prompt and used to train the model’s response capability; functional annotation trains task capability and security annotation trains safer outputs; fine-tuning annotation and preference annotation (scoring or ranking positive and negative responses to the same prompt, with negatives used through reinforcement learning to reduce similar outputs) are the two paradigms; and annotators comprise executors, reviewers, arbitrators (who decide disputed or inconsistent results) and supervisors.
Key contents
Platform and tool security (clause 5)
Organizers shall assess annotation platforms periodically, remediate vulnerabilities and record findings and handling; conduct annotation only on secure platforms; ensure the platform logs user operations and system activity in enough detail to investigate incidents and trace processing history; for centralized annotation, provide a physically zoned and access-controlled environment that keeps unauthorized persons out, and for distributed annotation, secure each annotator’s device and network channel; preferably store security-annotation data in isolation; and ensure that any generative-AI-based automated annotation tool used for assistance complies with the laws and regulations on generative-AI services.
Annotation rule security (clause 6)
Rules shall at minimum cover annotation objectives, data format, method and quality indicators (Annex A gives examples); be drawn up separately for functional and security annotation and cover both execution and review; specify task types for text, image, audio, video and time-series content consistent with clause 5.1.1 of GB/T 42755-2023 (Annex B catalogues task types); for functional annotation, guide annotators to produce true, accurate, objective and diverse data with positive and negative examples, and include methods and examples for recognizing risky content so that risky prompts are identified and no risky responses are annotated; for security annotation, guide annotation around the main risks to data and generated content, with rules and examples for writing responses to risky prompts that give safe, positively guiding answers; include methods and examples for identifying inappropriate or erroneous annotation so that content can be updated or corrected; include quality and security verification methods; and include emergency-response and notification mechanisms for security incidents during annotation.
Personnel requirements (clause 7)
Training (7.1). Training must cover rule security requirements, platform use and security, quality and security verification methods, annotation-data security management, typical risk scenarios and case-identification methods, and security and law-abiding awareness. An examination follows, with qualification granted only to those who pass, records retained, and examination content covering legal knowledge, rule comprehension, tool proficiency, risk judgment and data-security management. Re-training and re-examination take place periodically or on major rule changes, with suspension or revocation for those who fail.
Task allocation (7.2). Determine the number and duties of annotators from the scale and needs of the task and adjust dynamically; divide roles into executors, reviewers, arbitrators and supervisors and allocate by role competence; record allocation.
Management (7.3). Executors annotate to the rules and submit for review; reviewers control quality and security; arbitrators make final decisions on inconsistent or disputed annotations, keeping records, and pass or discard/return the data; supervisors sample the work of each role, detect and handle data-security and transmission risks, and keep records; the same person may not be executor and reviewer on one task; and access to platforms, tools and data is revoked for departing annotators and for those disqualified for security reasons.
Verification requirements (clause 8)
Basic (8.1). Security-annotation data should be comprehensive and representative, covering at least the main risk scenarios in GB/T 45654 Annex A with preferably no fewer than 200 items per risk, and the proportion of security annotation in a dataset should be at least 3%. Results are verified manually (random sampling by annotators who did not work on the batch) or by hybrid means (algorithmic or automated checks followed by manual random-sample verification). Verification covers accurate understanding (clarity, intent, key and implicit conditions), prompt–response consistency, and quality (grammar, diction, style, diversity, clarity). Problems are corrected or re-annotated and tracked; re-annotation must correct every logged problem, record original and correcting annotator, content and times, and pass re-review before archiving; and verification records must document verifier, time, result, problems and measures.
Functional annotation (8.2). Functional data must contain no risky content (by reference to GB/T 45654 Annex A); prompts must be logical, valid, reasonable and diverse; data must be reasonable, true, accurate, objective and diverse; responses must be accurate (facts, geography, history, science), useful, current, logical and readable. Prompt-quality defects to check include non-conformity with rules and incompleteness or unclear intent; response-quality defects include non-conformity, lack of relevance to the prompt, forced answers to unanswerable questions, idiosyncratic or personalized style (unless required), typos and broken sentences, and verbose or illogical expression. Every batch is manually sampled; inaccurate content is re-annotated and a batch containing unlawful content is discarded.
Security annotation (8.3). Responses in fine-tuning annotation and positive responses in preference annotation must contain no risky content and must respond safely and reasonably to the risk in the prompt; every item is reviewed by at least one reviewer; and where the items failing security verification exceed 5% of the security-annotation total, the batch is discarded.
Evaluation methods (clause 9)
For each of the four areas the standard lists the documents, logs, records and platform checks an assessor uses (assessment and patch records; simulated operations to test logging; access-control inspection; rule documents checked against ten criteria; training, examination, allocation, arbitration and supervision records; verification records checked for coverage, proportion, method, content, correction, re-annotation detail and completeness) and the expected results, with a pass/fail judgment per test item.
Annexes
Annex A gives worked examples: a functional fine-tuning pair (a travel-guide prompt about Beijing with a helpful response), security fine-tuning pairs (a request for pirated software answered with a lawful-channel refusal citing the Copyright Law; a perpetual-motion question answered with the laws of thermodynamics), and preference pairs contrasting positive responses with negative ones — an unhelpful redirect to Nanjing, a piracy download list (an A.3 IP infringement), and a step-by-step perpetual-motion plan (an A.5 accuracy failure). Annex B catalogues annotation task types for text (type, topic, sentiment, entities, semantic roles, keywords, style, syntax, translation, matching, normalization, coherence), images (classification, position, count, attributes, scene, segmentation, keypoints, orientation, lighting, relations, actions, emotion, description, uncertainty, timestamps), audio, video, three-dimensional data and time series.
How it fits the regime
The standard fills in clause 4.3 of GB/T 45654, which requires annotator training, separate functional and security rules, batch sampling and single-reviewer sign-off, and it operates on the data that GB/T 45652 governs upstream. Its distinctive contribution is to treat annotation as a security control rather than a quality step: the 3% security-annotation floor and the 200-items-per-risk target are what give a model the refusal behavior that the 95% refusal threshold in GB/T 45654 Annex B then tests. For overseas developers and their labeling vendors, the personnel chapter — examination-based qualification, four-role separation, executor–reviewer separation and access revocation — is the part most likely to require changes to existing annotation workflows, and the rule that AI-assisted labeling tools must themselves comply with the Generative AI Interim Measures closes the loop on synthetic-label pipelines.