---
title_en: "Basic Security Requirements for Generative Artificial Intelligence Services (TC260-003)"
title_zh: "生成式人工智能服务安全基本要求（TC260-003）"
abbreviation: "TC260-003 GenAI Basic Requirements"
hierarchy: "standard"
issuing_body: "National Information Security Standardization Technical Committee (TC260)"
adopted_date: 2024-02-29
effective_date: 2024-02-29
status: "effective"
related_laws: ["gbt-45654-genai-basic-security-requirements", "genai-services-interim-measures", "gbt-45652-genai-training-data-security", "gbt-45674-genai-data-annotation-security", "algorithmic-recommendation-provisions", "deep-synthesis-provisions", "ai-content-labeling-measures", "pipl"]
domains: ["ai-governance"]
url: https://datacompliancechina.com/laws/tc260-genai-basic-security-requirements/
summary: "Released by TC260 on February 29, 2024 as document TC260-003, this technical document was for eighteen months the operative checklist for China's generative-AI security assessment and filing regime, and it remains the text most existing filing reports were written against. It states that it 'supports' the 2023 Interim Measures and that providers performing filing formalities must self-assess under its Chapter 9 and submit the report. Its five substantive chapters — corpus security (source, content, annotation), model security, security measures, keyword and test-bank requirements, and assessment — introduced the thresholds later carried into GB/T 45654-2025: the 5% unlawful-content ceiling per source, multiple sources per language and modality with domestic pairing for foreign data, licence, collection-record and contract requirements, consent and separate consent for personal information in corpora, a named IP officer and complaints channel, annotator training and role separation, a 96%/98% corpus pass rate, a 90% generated-content pass rate, 95%/5% refusal ratios, a 10,000-keyword library and 2,000-question test bank, the four-click opt-out for training on user inputs, and monitoring staff proportionate to scale. It also contains provisions the national standard dropped or softened: a hard rule that third-party foundation models must themselves be filed, an explicit warning about models capable of deceiving humans, self-replication or self-modification and about misuse for malware or biological and chemical weapons, a supply-chain assessment of chips, software and computing power with a preference for hardware-based trusted boot, and a concrete suspension trigger of three consecutive or five daily unlawful inputs. Assessment reports must be signed by the legal representative, the security lead and the legal-compliance lead. GB/T 45654 now carries the same requirements as a national standard; the practice guide remains the reference for filings made before November 2025."
---

> **Source: Data Compliance China** — https://datacompliancechina.com/laws/tc260-genai-basic-security-requirements/ · English rendering and annotations by DCC; the Chinese original governs. Cite as: Data Compliance China, "Basic Security Requirements for Generative Artificial Intelligence Services (TC260-003)", https://datacompliancechina.com/laws/tc260-genai-basic-security-requirements/
> *DCC summary, not a translation.* TC260-003 is copyrighted by the TC260
> Secretariat. The structured summary below is DCC's own paraphrase
> grounded in the published text; specific clauses should be checked
> against the document. Providers assessing new services after November 1,
> 2025 should work from [GB/T 45654-2025](/laws/gbt-45654-genai-basic-security-requirements/).

**Published by:** National Information Security Standardization Technical Committee (全国网络安全标准化技术委员会, SAC/TC260).  
**Document No.:** TC260-003. **Released February 29, 2024.** Drafters led by CESI and CNCERT with the Zhongguancun Laboratory, Zhejiang University, the Shanghai AI Laboratory and Baidu, Baichuan, Alibaba Cloud, MiniMax, SenseTime, iFlytek, Zhipu and other developers.

## Scope

The document specifies basic security requirements for generative-AI services — corpus security, model security and security measures — and gives security-assessment requirements. It applies to service providers conducting security assessments and raising their security level and serves as a reference for competent authorities. "Generative-AI service" is defined as a service using generative-AI technology to provide generated text, images, audio, video or other content to the public *within the territory of the PRC*; "training corpus" (训练语料) covers all direct training inputs across pre-training and fine-tuning; "sampling pass rate" is the proportion of samples free of the 31 risks in Annex A; "foundation model" is a deep neural network trained on large data for general purposes and adaptable to downstream tasks; and "unlawful and harmful information" refers to the 11 categories of unlawful and 9 of harmful information under the Provisions on the Ecological Governance of Online Information Content, focused on the 29 risks in A.1–A.4.

Clause 4 sets the frame: the document supports the [Interim Measures for Generative AI Services](/laws/genai-services-interim-measures/); providers going through filing formalities assess themselves under Chapter 9 and submit the report; providers must separately meet cybersecurity, data-security and personal-information rules; and providers should watch long-term risks — AI capable of deceiving humans, self-replicating or self-modifying — and misuse for writing malware or making biological or chemical weapons.

## Key contents

### Corpus security (clause 5)

**Sources (5.1).** Assess a source before collection and reject it if more than 5% of content is unlawful or harmful; verify after collection and do not train on it if the threshold is exceeded. Use multiple sources per language and per type, and pair foreign corpora with domestic ones. Ensure traceability: open-source licences or authorizations; collection records for self-collected corpora and no collection of what others have barred (robots.txt, technical restrictions, refused consent), with linked or generated content treated as self-collected; enforceable contracts and supplier undertakings for commercial corpora, with review; and user authorization records for user inputs. Information blocked under Chinese cybersecurity law and policy may not be used as corpus.

**Content (5.2).** Filter all corpora for unlawful and harmful information by keywords, classifiers and manual sampling. Appoint an IP officer for corpora and generated content and adopt an IP management policy; identify major infringement risks before training and do not train on infringing corpora, with particular attention to copyright in literary, artistic and scientific works; run an IP complaints channel; warn users in the service agreement of IP risks and allocate responsibility for identifying IP problems; update the policy in line with national policy and complaints; and preferably publish summaries of IP-relevant corpus content and allow third parties to query corpus use through the complaints channel. Obtain consent for personal information and separate consent for sensitive personal information before use, unless another legal basis applies.

**Annotation (5.3).** Train annotators on task rules, tools, quality verification and data-security management; examine them and grant, periodically renew, and where necessary suspend qualifications; separate annotation and review roles so that one person does not hold both on a task; allow sufficient time per task. Rules must cover objective, format, method and quality indicators, be written separately for functional and security annotation across annotation and review, guide functional annotators to true, accurate, objective and diverse corpora, and give security annotators rules for all 31 Annex A risks. Manually sample every functional batch (re-annotate if inaccurate, discard if unlawful content is found) and have at least one reviewer approve every security annotation; preferably store security annotation data in isolation.

### Model security (clause 6)

A service built on a third-party foundation model must use a model that has been filed with the competent authority. Treat generated-content security as a principal training metric; detect user inputs for security in every dialogue and guide the model toward positive content; maintain routine monitoring and fix problems through instruction fine-tuning or reinforcement learning. Improve accuracy (consistency with scientific consensus and mainstream understanding) and reliability (useful, well-structured output) by technical means.

### Security measures (clause 7)

Justify necessity, suitability and safety of each application field; add proportionate safeguards for CII, automatic control, medical information, psychological counselling and financial information services; for minors, allow guardian-set anti-addiction limits, no paid services beyond civil capacity, and beneficial content, and keep minors out of services not meant for them. Publish scope (users, settings, uses, preferably the base model) prominently and disclose limitations, model and algorithm summaries, and personal-information collection and use in the homepage or service agreement, or in API documentation. Where user inputs are used for training, provide an opt-out within four clicks and disclose the status and the opt-out prominently. Label images and video per national rules and standards. Assess the supply-chain security — continuity and stability — of chips, software, tools and computing power used for training and inference, and preferably use chips supporting hardware-based secure and trusted boot. Provide complaint channels with handling rules and time limits. Detect user inputs with keywords and classifiers and suspend service for users who enter unlawful content three times in a row or five times in a day; refuse clearly extreme or inducing questions but answer all others; staff monitors proportionate to scale who track policy and analyze complaints. Adopt a security policy for model updates and re-assess after important updates. For stability, isolate training from inference, monitor inputs for DDoS, XSS and injection attacks, audit frameworks and code regularly, and keep backups and recovery strategies.

### Keyword libraries, test banks and classifiers (clause 8)

A keyword library of at least 10,000 entries covering the 17 risks in A.1–A.2 (at least 200 per A.1 risk, 100 per A.2 risk), updated at least weekly; a generated-content test bank of at least 2,000 questions covering all 31 risks (at least 50 per A.1–A.2 risk, 20 per other risk), with operating procedures and criteria, updated at least monthly; should-refuse and should-answer test banks of at least 500 questions each (the latter covering China's system, beliefs, image, culture, customs, ethnicity, geography, history and heroes, and gender, age, occupation and health, at least 20 per topic, with domain-specific models allowed to omit irrelevant topics), updated at least monthly; and classifiers covering all 31 risks.

### Security assessment (clause 9)

Assessment may be self-conducted or entrusted to a third party and must cover every clause of Chapters 5–8 with an individual result of conforming, non-conforming or not applicable — conforming results need supporting evidence; non-conforming results need reasons, with explanations for equivalent alternative measures or for measures adopted but not yet sufficient and a plan; not-applicable results need justification. Results and evidence go into the filing report (or its annex where the format does not allow). The overall conclusion is fully conforming, partly conforming or fully non-conforming, with recommended ("should preferably") clauses not affecting the conclusion. Self-assessment reports must be signed by three persons: the legal representative, the overall security lead (principal manager or cybersecurity lead) and the legality-assessment lead (principal manager or legal lead). Corpus security is tested by manual sampling of at least 4,000 items at a 96% pass rate and technical sampling of at least 10% at 98%; generated-content security by manual, keyword and classifier sampling of at least 1,000 test questions each at 90%; and refusal by 300 questions from each bank at not less than 95% refusal and not more than 5% over-refusal.

### Annex A (normative)

The 31 risks in five groups: A.1 content contrary to the core socialist values (eight items), A.2 discriminatory content (nine), A.3 commercial violations (five), A.4 infringement of others' lawful rights (seven), and A.5 inability to meet the safety needs of specific service types (inaccuracy; unreliability).

## How it fits the regime

TC260-003 was the bridge between the [Interim Measures](/laws/genai-services-interim-measures/) of August 2023 and the national standards of 2025. Its thresholds were adopted wholesale by [GB/T 45654-2025](/laws/gbt-45654-genai-basic-security-requirements/), whose bibliography cites it, while its corpus and annotation chapters were expanded into [GB/T 45652](/laws/gbt-45652-genai-training-data-security/) and [GB/T 45674](/laws/gbt-45674-genai-data-annotation-security/). What did not carry over is instructive: the national standard dropped the foundation-model filing rule (now handled through the filing process itself), the three-strikes/five-a-day suspension trigger (replaced by a provider-set rule), the supply-chain and trusted-boot clauses, and the three-signature requirement. Because the practice guide is not formally repealed and most filed services were assessed under it, it remains the reference point for understanding existing filing reports and for regulators comparing pre- and post-2025 assessments; new work should be done to the national standard.
