DCC summary, not a translation. TC260-003 is copyrighted by the TC260 Secretariat. The structured summary below is DCC’s own paraphrase grounded in the published text; specific clauses should be checked against the document. Providers assessing new services after November 1, 2025 should work from GB/T 45654-2025.
Published by: National Information Security Standardization Technical Committee (全国网络安全标准化技术委员会, SAC/TC260).
Document No.: TC260-003. Released February 29, 2024. Drafters led by CESI and CNCERT with the Zhongguancun Laboratory, Zhejiang University, the Shanghai AI Laboratory and Baidu, Baichuan, Alibaba Cloud, MiniMax, SenseTime, iFlytek, Zhipu and other developers.
Scope
The document specifies basic security requirements for generative-AI services — corpus security, model security and security measures — and gives security-assessment requirements. It applies to service providers conducting security assessments and raising their security level and serves as a reference for competent authorities. “Generative-AI service” is defined as a service using generative-AI technology to provide generated text, images, audio, video or other content to the public within the territory of the PRC; “training corpus” (训练语料) covers all direct training inputs across pre-training and fine-tuning; “sampling pass rate” is the proportion of samples free of the 31 risks in Annex A; “foundation model” is a deep neural network trained on large data for general purposes and adaptable to downstream tasks; and “unlawful and harmful information” refers to the 11 categories of unlawful and 9 of harmful information under the Provisions on the Ecological Governance of Online Information Content, focused on the 29 risks in A.1–A.4.
Clause 4 sets the frame: the document supports the Interim Measures for Generative AI Services; providers going through filing formalities assess themselves under Chapter 9 and submit the report; providers must separately meet cybersecurity, data-security and personal-information rules; and providers should watch long-term risks — AI capable of deceiving humans, self-replicating or self-modifying — and misuse for writing malware or making biological or chemical weapons.
Key contents
Corpus security (clause 5)
Sources (5.1). Assess a source before collection and reject it if more than 5% of content is unlawful or harmful; verify after collection and do not train on it if the threshold is exceeded. Use multiple sources per language and per type, and pair foreign corpora with domestic ones. Ensure traceability: open-source licences or authorizations; collection records for self-collected corpora and no collection of what others have barred (robots.txt, technical restrictions, refused consent), with linked or generated content treated as self-collected; enforceable contracts and supplier undertakings for commercial corpora, with review; and user authorization records for user inputs. Information blocked under Chinese cybersecurity law and policy may not be used as corpus.
Content (5.2). Filter all corpora for unlawful and harmful information by keywords, classifiers and manual sampling. Appoint an IP officer for corpora and generated content and adopt an IP management policy; identify major infringement risks before training and do not train on infringing corpora, with particular attention to copyright in literary, artistic and scientific works; run an IP complaints channel; warn users in the service agreement of IP risks and allocate responsibility for identifying IP problems; update the policy in line with national policy and complaints; and preferably publish summaries of IP-relevant corpus content and allow third parties to query corpus use through the complaints channel. Obtain consent for personal information and separate consent for sensitive personal information before use, unless another legal basis applies.
Annotation (5.3). Train annotators on task rules, tools, quality verification and data-security management; examine them and grant, periodically renew, and where necessary suspend qualifications; separate annotation and review roles so that one person does not hold both on a task; allow sufficient time per task. Rules must cover objective, format, method and quality indicators, be written separately for functional and security annotation across annotation and review, guide functional annotators to true, accurate, objective and diverse corpora, and give security annotators rules for all 31 Annex A risks. Manually sample every functional batch (re-annotate if inaccurate, discard if unlawful content is found) and have at least one reviewer approve every security annotation; preferably store security annotation data in isolation.
Model security (clause 6)
A service built on a third-party foundation model must use a model that has been filed with the competent authority. Treat generated-content security as a principal training metric; detect user inputs for security in every dialogue and guide the model toward positive content; maintain routine monitoring and fix problems through instruction fine-tuning or reinforcement learning. Improve accuracy (consistency with scientific consensus and mainstream understanding) and reliability (useful, well-structured output) by technical means.
Security measures (clause 7)
Justify necessity, suitability and safety of each application field; add proportionate safeguards for CII, automatic control, medical information, psychological counselling and financial information services; for minors, allow guardian-set anti-addiction limits, no paid services beyond civil capacity, and beneficial content, and keep minors out of services not meant for them. Publish scope (users, settings, uses, preferably the base model) prominently and disclose limitations, model and algorithm summaries, and personal-information collection and use in the homepage or service agreement, or in API documentation. Where user inputs are used for training, provide an opt-out within four clicks and disclose the status and the opt-out prominently. Label images and video per national rules and standards. Assess the supply-chain security — continuity and stability — of chips, software, tools and computing power used for training and inference, and preferably use chips supporting hardware-based secure and trusted boot. Provide complaint channels with handling rules and time limits. Detect user inputs with keywords and classifiers and suspend service for users who enter unlawful content three times in a row or five times in a day; refuse clearly extreme or inducing questions but answer all others; staff monitors proportionate to scale who track policy and analyze complaints. Adopt a security policy for model updates and re-assess after important updates. For stability, isolate training from inference, monitor inputs for DDoS, XSS and injection attacks, audit frameworks and code regularly, and keep backups and recovery strategies.
Keyword libraries, test banks and classifiers (clause 8)
A keyword library of at least 10,000 entries covering the 17 risks in A.1–A.2 (at least 200 per A.1 risk, 100 per A.2 risk), updated at least weekly; a generated-content test bank of at least 2,000 questions covering all 31 risks (at least 50 per A.1–A.2 risk, 20 per other risk), with operating procedures and criteria, updated at least monthly; should-refuse and should-answer test banks of at least 500 questions each (the latter covering China’s system, beliefs, image, culture, customs, ethnicity, geography, history and heroes, and gender, age, occupation and health, at least 20 per topic, with domain-specific models allowed to omit irrelevant topics), updated at least monthly; and classifiers covering all 31 risks.
Security assessment (clause 9)
Assessment may be self-conducted or entrusted to a third party and must cover every clause of Chapters 5–8 with an individual result of conforming, non-conforming or not applicable — conforming results need supporting evidence; non-conforming results need reasons, with explanations for equivalent alternative measures or for measures adopted but not yet sufficient and a plan; not-applicable results need justification. Results and evidence go into the filing report (or its annex where the format does not allow). The overall conclusion is fully conforming, partly conforming or fully non-conforming, with recommended (“should preferably”) clauses not affecting the conclusion. Self-assessment reports must be signed by three persons: the legal representative, the overall security lead (principal manager or cybersecurity lead) and the legality-assessment lead (principal manager or legal lead). Corpus security is tested by manual sampling of at least 4,000 items at a 96% pass rate and technical sampling of at least 10% at 98%; generated-content security by manual, keyword and classifier sampling of at least 1,000 test questions each at 90%; and refusal by 300 questions from each bank at not less than 95% refusal and not more than 5% over-refusal.
Annex A (normative)
The 31 risks in five groups: A.1 content contrary to the core socialist values (eight items), A.2 discriminatory content (nine), A.3 commercial violations (five), A.4 infringement of others’ lawful rights (seven), and A.5 inability to meet the safety needs of specific service types (inaccuracy; unreliability).
How it fits the regime
TC260-003 was the bridge between the Interim Measures of August 2023 and the national standards of 2025. Its thresholds were adopted wholesale by GB/T 45654-2025, whose bibliography cites it, while its corpus and annotation chapters were expanded into GB/T 45652 and GB/T 45674. What did not carry over is instructive: the national standard dropped the foundation-model filing rule (now handled through the filing process itself), the three-strikes/five-a-day suspension trigger (replaced by a provider-set rule), the supply-chain and trusted-boot clauses, and the three-signature requirement. Because the practice guide is not formally repealed and most filed services were assessed under it, it remains the reference point for understanding existing filing reports and for regulators comparing pre- and post-2025 assessments; new work should be done to the national standard.