Promulgated by: Cyberspace Administration of China and Ministry of Public Security. Released November 15, 2018. Effective November 30, 2018.
Translation note — DCC. 舆论属性 is rendered “public opinion attributes” and 社会动员能力 “social mobilization capacity”, tracking the official usage carried into the Generative AI Interim Measures. The assessment under these Provisions is a self-assessment filed with the authorities (自行开展安全评估), not a government approval — a distinction that matters when advising on sequencing, because the filing must precede launch.
Article 1. These Provisions are formulated in accordance with the Cybersecurity Law of the People’s Republic of China, the Measures for the Administration of Internet Information Services, and the Measures for the Administration of the Security Protection of the International Networking of Computer Information Networks, in order to strengthen the security management of internet information services with public opinion attributes or social mobilization capacity and of related new technologies and new applications, to regulate internet information service activities, and to safeguard national security, social order and the public interest.
Article 2. Internet information services with public opinion attributes or social mobilization capacity, as referred to in these Provisions, include the following circumstances:
(1) operating information services such as forums, blogs, microblogs, chat rooms, communication groups, public accounts, short video, live streaming, information sharing, and mini-programs, or attaching corresponding functions;
(2) operating other internet information services that provide a channel for the expression of public opinion or that have the capacity to mobilize members of the public to engage in specific activities.
Article 3. An internet information service provider shall, where any of the following circumstances applies, carry out a security assessment on its own in accordance with these Provisions, and shall be responsible for the assessment result:
(1) an information service with public opinion attributes or social mobilization capacity is launched, or relevant functions are added to an information service;
(2) the use of new technologies or new applications causes material changes to the functional attributes, technical implementation method, or basic resource allocation of the information service, resulting in a material change in its public opinion attributes or social mobilization capacity;
(3) the scale of users increases significantly, resulting in a material change in the public opinion attributes or social mobilization capacity of the information service;
(4) unlawful or harmful information is disseminated and spread, indicating that the existing security measures are inadequate to effectively prevent and control cybersecurity risks;
(5) other circumstances in which a cyberspace administration department or public security organ at or above the municipal level gives written notice that a security assessment is required.
Article 4. An internet information service provider may carry out the security assessment itself, or may entrust a third-party security assessment institution to carry it out.
Article 5. In carrying out a security assessment, an internet information service provider shall comprehensively assess the legality of the information service and of the new technologies and new applications, the effectiveness of its implementation of the security measures prescribed by laws, administrative regulations, departmental rules and standards, and the effectiveness of its prevention and control of security risks, and shall assess the following matters as key items:
(1) the determination of a person responsible for security management and of information review personnel commensurate with the services provided, or the establishment of a security management body;
(2) measures for verifying users’ true identities and for retaining registration information;
(3) measures for retaining log information such as users’ accounts, operation times, operation types, network source addresses and destination addresses, network source ports, and client hardware characteristics, as well as records of information published by users;
(4) measures for preventing and disposing of unlawful and harmful information, and for preserving relevant records, in user account and communication group names, nicknames, profiles, remarks and identifiers, and in service functions such as information publication, forwarding, commenting and communication groups;
(5) technical measures for personal information protection and for preventing the dissemination and spread of unlawful and harmful information and the risk of loss of control over social mobilization functions;
(6) the establishment of complaint and reporting systems, the publication of complaint and reporting channels and other information, and the timely acceptance and handling of relevant complaints and reports;
(7) the establishment of a working mechanism to provide technical and data support and assistance for cyberspace administration departments to perform their supervision and administration duties over internet information services in accordance with the law;
(8) the establishment of a working mechanism to provide technical and data support and assistance for public security organs and state security organs to safeguard national security and to investigate and handle unlawful and criminal acts in accordance with the law.
Article 6. Where an internet information service provider discovers a security hazard in the course of a security assessment, it shall rectify it promptly, until the relevant security hazard is eliminated.
Where, having undergone the security assessment, the service conforms to laws, administrative regulations, departmental rules and standards, a security assessment report shall be prepared. The security assessment report shall include the following:
(1) basic particulars of the internet information service, including its functions, service scope, software and hardware facilities and deployment locations, and the status of the acquisition of relevant licences and certificates;
(2) the implementation of security management systems and technical measures, and the effectiveness of risk prevention and control;
(3) the conclusion of the security assessment;
(4) other relevant matters that should be explained.
Article 7. An internet information service provider shall submit the security assessment report, through the National Internet Security Management Service Platform, to the cyberspace administration department and the public security organ at or above the municipal level in the place where it is located.
Where circumstance (1) or (2) of Article 3 of these Provisions applies, the internet information service provider shall submit the security assessment report before the information service or the new technology or new application goes online or the function is added; where circumstance (3), (4) or (5) of Article 3 of these Provisions applies, it shall submit the security assessment report within 30 working days from the date on which the relevant circumstance arises.
Article 8. Cyberspace administration departments and public security organs at or above the municipal level shall conduct a documentary review of security assessment reports in accordance with their respective duties.
Where it is found that the content or items of a security assessment report are missing, or that the security assessment method is manifestly improper, they shall order the internet information service provider to conduct the assessment again within a specified period.
Where it is found that the content of a security assessment report is unclear, they may order the internet information service provider to provide a supplementary explanation.
Article 9. Where, on the basis of the documentary review of a security assessment report, the cyberspace administration department and the public security organ consider it necessary, they shall conduct an on-site inspection of the internet information service provider in accordance with their respective duties.
On-site inspections by cyberspace administration departments and public security organs shall in principle be carried out jointly, and shall not interfere with the normal business activities of the internet information service provider.
Article 10. For an internet information service that presents relatively large security risks and may affect national security, social order or the public interest, the cyberspace administration department and the public security organ at or above the provincial level shall organize experts to conduct a review, and may, where necessary, carry out an on-site inspection together with the relevant local departments.
Article 11. On-site inspections by cyberspace administration departments and public security organs shall be conducted in accordance with the provisions of the relevant laws, administrative regulations and departmental rules.
Article 12. Cyberspace administration departments and public security organs shall establish monitoring and management systems, strengthen cybersecurity risk management, and urge internet information service providers to perform their cybersecurity obligations in accordance with the law.
Where it is found that a provider of an internet information service with public opinion attributes or social mobilization capacity has not carried out a security assessment in accordance with these Provisions, the cyberspace administration department and the public security organ shall notify it to carry out a security assessment in accordance with these Provisions.
Article 13. Where a cyberspace administration department or public security organ finds that a provider of an internet information service with public opinion attributes or social mobilization capacity refuses to carry out a security assessment in accordance with these Provisions, it shall, through the National Internet Security Management Service Platform, alert the public that the internet information service presents security risks, and shall supervise and inspect the internet information service in accordance with its respective duties; where unlawful acts are found to exist, it shall handle them in accordance with the law.
Article 14. Cyberspace administration departments shall coordinate the security assessment work for internet information services with public opinion attributes or social mobilization capacity, and public security organs shall periodically report their security assessment work to the cyberspace administration departments.
Article 15. Cyberspace administration departments, public security organs and their staff shall strictly keep confidential any state secrets, trade secrets and personal information of which they become aware in the performance of their duties, and shall not divulge, sell or unlawfully provide the same to others.
Article 16. The security assessment of new technologies and new applications of internet news information services shall be carried out in accordance with the Provisions on the Administration of Security Assessment of New Technologies and New Applications of Internet News Information Services.
Article 17. These Provisions take effect on November 30, 2018.
Why this 2018 rule matters now
For most of its life this instrument was read as a content-governance formality — the filing you made before launching a forum or a public account. Two later rules turned it into the enforcement hook for AI:
- Article 17 of the Generative AI Interim Measures requires a provider of GenAI services with public opinion attributes or social mobilization capacity to carry out a security assessment “in accordance with the relevant provisions of the State” — these Provisions.
- Article 20 of the Deep Synthesis Provisions imposes the same duty on deep synthesis providers launching new products, applications or functions with those attributes.
Neither AI rule contains its own assessment procedure. The procedure, the triggers, the report contents, and the filing channel all live here. In the CAC’s September 2026 enforcement batch, two of the ten cases were charged in part under these Provisions — one of them resulting in an order to take a mini-program offline. See the DCC brief on that batch.
Source: www.gov.cn · www.cac.gov.cn