Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ 100 · COMPUTE-CENTERS

One Machine Room, Five Regulatory Identities: MaaS Compliance for China's AI Compute Centers

AnJie Broad's Cai Hang, Yao Ting, and Liu Zeqiang argue the IDC-era checklist no longer fits the 智算中心. The stack they work through: value-added telecom licensing (B11/B12), State Council Decree No. 790's continuing duties, the CAC Decree No. 16 token-export exemptions and what they do not exempt, the territorial limit of the GenAI Interim Measures, the Export Control Law catch-all, the unsettled line between large-model filing (备案) and registration (登记), open-weight license triggers, and Criminal Law Article 285 exposure that arrives with an agent's tool calls.

AnJie Broad partners Cai Hang and Yao Ting and associate Liu Zeqiang argue that the IDC-era compliance checklist no longer fits the AI compute center. Their thesis: one machine room now carries five regulatory identities at once — domestic IDC operator, cross-border AI service provider, service exporter under the Export Control Law, supplier of self-deployed model capability, and responsible entity for the agents it ships — each with its own logic, and each transmitting obligations to the others. The brief works through value-added telecom licensing (B11/B12), energy-conservation review and PUE caps, the continuing duties under the Regulation on Network Data Security Management (State Council Decree No. 790), the token-export exemptions in CAC Decree No. 16 and what they do not exempt, the territorial limits of the GenAI Interim Measures, the Export Control Law catch-all, the unsettled line between large-model filing (备案) and large-model registration (登记), open-weight license trigger clauses, and the criminal exposure that follows an agent's tool calls under Criminal Law Article 285.

Editor’s Note — DCC.

On August 25, 2026 the AnJie Broad (安杰世泽) WeChat channel published a client alert by partners Cai Hang (蔡航) and Yao Ting (姚婷) and associate Liu Zeqiang (刘泽强) on the compliance perimeter of the AI compute center. DCC translates it because its organizing argument is one we have not seen made this cleanly elsewhere: the intelligent computing center (智算中心) has stopped being a single regulated thing. The same facility is now, simultaneously, a domestic Internet Data Center (IDC) operator, a cross-border AI service provider, a service exporter in the export-control sense, a supplier of self-deployed model capability, and the responsible entity for the agents it ships to customers — five identities, five bodies of rules, transmitting obligations to one another.

Two notes on scope. First, the authors’ section on energy-conservation review (节能审查) and PUE caps, and their section on foreign-equity limits, are energy and telecom regulation rather than data protection; DCC has kept them in compressed form because they set up the layering argument, but readers should treat them as context. Second, the authors introduce their export-control discussion as spanning both the Chinese and US regimes, but the published piece develops only the Chinese side. DCC has not supplied the missing half — analysis of US export controls is outside what this publication covers, and readers can get it directly from English sources.

One factual flag. The article states specific commercial thresholds in the Kimi K3 license (a US$20 million/12-month MaaS revenue trigger, and a 100-million-MAU badge requirement). DCC reproduces those as the authors’ characterization of a third-party license and has not independently verified them against the license text. Anyone relying on the point should read the license itself.

For adjacent DCC coverage, see the briefs on the TC260 agent-deployment practice guide, the agent governance framework, the Beijing Agent Measures on token-to-value, and Shanghai’s first FTZ negative-list export filing.

Per the channel’s own disclaimer, the article represents the authors’ views and is not a formal legal opinion of the firm.

As China builds out the East Data and West Computing project (东数西算工程) and the integrated national computing-power network (全国一体化算力网), the AI compute center has evolved out of the cabinet-rental business that defined the traditional Internet Data Center (IDC). It is now a composite business vehicle combining computing-power services, cross-border technology export, and delivery of intelligent tooling.

That means the regulatory controls applicable to an IDC — telecom market access, energy-conservation review, Multi-Level Protection Scheme (MLPS) grading — are now only the base layer. On top of them sit a set of rules that did not exist in the IDC era: cross-border data transfer administration, export control, algorithm filing (算法备案), and the emerging norms for AI agents. Running an intelligent computing center off an IDC-era compliance checklist no longer fits the situation.

This brief follows the authors through four questions:

  • Building a compute center in China, which regulatory thresholds must now be cleared that did not previously exist?
  • Exporting computing power, or token-billed large-model inference, to overseas customers — what dual domestic and foreign legal constraints apply?
  • When the compute center serves model capability from its own deployment, how do filing obligations and open-source licensing actually work?
  • What liability does the Harness toolchain and the various agents delivered alongside it transmit back to the operating entity?

1. Why demand shifted after the open-source model wave

The recent wave of highly capable Chinese open-source model releases did not reduce total demand for computing power. It relocated it.

Training compute is concentrating. Open-source models achieve high inference efficiency at relatively low training cost, so large numbers of small and medium enterprises no longer need to build their own training clusters and instead adopt off-the-shelf open-source models. Training demand therefore concentrates among the handful of vendors with the capacity to keep iterating.

Inference compute is growing explosively. Open-source models sharply lower the barrier to AI applications, and total token (词元) call volume is rising exponentially. After deploying open-source models, some intelligent computing centers have seen their allocation shift from a training-dominant pattern to one where training, tuning, and inference carry comparable weight — or where inference takes the larger share.

Policy is pushing the same way. The Implementing Opinions on Deepening the East Data and West Computing Project and Accelerating the Construction of the Integrated National Computing-Power Network (发改数据〔2023〕1779号), issued by the National Development and Reform Commission (NDRC) with four other departments, encourages computing-power services to move away from cabinet rental and annual or monthly packages toward short-term, connect-and-use, pay-as-you-go models. It supports computing-power vouchers (算力券), transport vouchers (运力券), and exploration of data center REITs. Compute-as-a-Service (算力即服务) is becoming the policy-favored supply form.

There is also a stock problem. Intelligent computing centers launched in concentrated waves across provinces have left built computing power idle. Open-source models happen to supply a low-cost, on-demand deployment path — and so, in practice, a route to putting that idle capacity back to work.

The authors’ conclusion from this section frames everything that follows: because compute center projects will inevitably involve cross-border output, the compliance architecture has to cover domestic operation, overseas service, and agent delivery from the outset — not as three separate later problems.

2. Building domestically: three layers of constraint

2.1 Telecom licensing — serving third parties is the dividing line

Whether an intelligent computing center needs a Value-Added Telecommunications Business License (增值电信业务经营许可证) turns first on whether it provides computing power or bandwidth to anyone other than itself.

An enterprise serving only its own business, not renting out cabinets, computing power, or bandwidth, in principle needs no value-added telecom qualification. But once it provides server hosting, cabinet rental, computing-power rental, or cloud (IaaS) resources, it falls within the Internet Data Center business (category B11) or Internet resource collaboration services (category B12, i.e. cloud services) under the Catalogue of Telecommunications Services (2015 edition) — and a license is required. Cross-province operation is applied for to the Ministry of Industry and Information Technology (MIIT); operation within a single province, to the provincial Communications Administration.

Unlicensed operation persists in practice. Some intelligent computing centers provide computing power externally under the banner of testing, piloting, or internal sharing, planning to regularize the license later. The authors regard this as very high risk: once characterized as unlicensed operation, the Telecommunications Regulations of the PRC allow an order to rectify, confiscation of illegal gains, fines, and even an order to suspend business for rectification. Licensing should be designed in step with the business model, not retrofitted mid-operation.

2.2 Energy-conservation review and PUE — the binding constraint at build stage

Data center projects generally sit under filing (备案) administration rather than government approval (核准), handled by the local development-and-reform or economy-and-IT department. But filing does not mean a low threshold. The real screening happens on energy consumption and regional access.

Under the Measures for the Energy-Conservation Review of Fixed-Asset Investment Projects (NDRC Order No. 2 of 2023), projects with annual comprehensive energy consumption of 10,000 metric tons of standard coal or more are reviewed by the provincial energy-conservation review authority, and construction may not begin without a review opinion. Large intelligent computing centers routinely consume tens of thousands of metric tons, so almost all fall into provincial review.

PUE (power usage effectiveness) is the core review metric. National policy requires new large and super-large data centers to come in below 1.3, and national hub nodes below 1.25; Beijing, Shanghai, and Guangdong impose stricter local standards, along with controls the authors render as “power determines computing” (以电定算) and “computing determines output” (以算定产), plus energy-consumption substitution quotas.

Local practice is turning green-power expectations into conditions. When the Beijing Municipal Development and Reform Commission issues an energy-conservation review opinion on a computing project, it commonly attaches a PUE ceiling, self-built photovoltaic capacity, and participation in green power trading. Individual projects have been required to reach a renewable utilization ratio of no less than 60% by 2026 and 100% by 2030, with waste-heat recovery. Energy-conservation review has become, in effect, an instrument for local governments to steer where computing capacity gets built.

2.3 Data security — continuing obligations under classification and grading

The Regulation on Network Data Security Management (网络数据安全管理条例, State Council Decree No. 790, effective January 1, 2025) raises the data-processing security obligations of data center operators considerably. Under the Regulation:

  • Network data is subject to classified and hierarchical protection; important data (重要数据) must be identified and declared in accordance with national rules.
  • An important-data handler must designate a network data security officer and a security management body, and the officer must be a member of management.
  • A risk assessment is required before providing, entrusting, or jointly processing important data, with an annual risk assessment report submitted to the competent authority at provincial level or above.
  • Handling the personal information of 10 million people or more is managed by reference to the important-data rules.

For an intelligent computing center, the consequence is that it is not merely a lessor of computing power. It is simultaneously an entrusted processor of data, and may itself constitute an important-data handler. MLPS Level 3 filing and testing is only the compliance floor; the data classification-and-grading system and the annual risk assessment mechanism are the daily obligations that must be discharged continuously throughout operation.

If the center constitutes a critical information infrastructure operator (CIIO), or is involved in important-data processing together with an overseas listing, it must also attend to cybersecurity review obligations under the Cybersecurity Review Measures.

2.4 Algorithm filing where large-model services are offered

Where an intelligent computing center also provides large-model services to the domestic public, it must discharge algorithm filing and security assessment obligations under the Provisions on the Administration of Algorithmic Recommendation Services for Internet Information Services, the Provisions on the Administration of Deep Synthesis of Internet Information Services, and the Interim Measures for the Management of Generative Artificial Intelligence Services — what practitioners call algorithm filing (算法备案) and large-model filing (大模型备案). Services may not be offered externally until the entity appears on the CAC’s published list of filed information.

The authors flag an important limit. These filing obligations target the case of directly providing large-model capability — self-developed, fine-tuned, further-developed, or trained. An operator that merely calls a third-party model that has already been filed, acting as a pure API relay, does not need large-model filing. This distinction carries over into the agent discussion in Part 5, and is developed in Part 4.

2.5 Foreign investment — an equity cap and a security review, running in parallel

Foreign participation in a domestic compute center is not off-limits, but it is constrained. The Special Administrative Measures for Foreign Investment Access (Negative List) (2024 edition) retains the requirement that foreign equity in value-added telecom services not exceed 50% (excluding e-commerce, domestic multi-party communication, store-and-forward, and call centers), and that basic telecom services be Chinese-controlled. IDC is a value-added telecom service, so outside pilot areas foreign access is uniformly subject to the 50% cap, with approval under the Provisions on the Administration of Foreign-Invested Telecommunications Enterprises.

That position has been partly opened up. MIIT’s Circular on Carrying Out the Pilot Program for Expanding the Opening-Up of Value-Added Telecommunications Services (工信部通信函〔2024〕107号) runs pilots in the Beijing comprehensive demonstration zone for expanded opening of the service sector, the Lin-gang Special Area of the Shanghai Pilot Free Trade Zone and its socialist modernization leading zone, the Hainan Free Trade Port, and the Shenzhen pilot demonstration zone — permitting foreign wholly-owned or controlled enterprises to operate IDC, CDN, and cloud services.

But the authors add a caution that is the real point of the section. Foreign participation in computing operations that involve important data, critical information infrastructure, or large-scale personal information may still trigger national security review under the Cybersecurity Review Measures and the Regulation on Network Data Security Management. The 50% numerical threshold and the substantive security-review threshold are two parallel and mutually independent sets of rules, and must not be conflated.

3. Exporting compute and tokens: three regimes stacked

A domestically operated intelligent computing center providing token-billed large-model API inference to overseas customers is not a hypothetical — it is a live business scenario. It sits under three constraints at once: China’s cross-border data transfer regime, the territorial reach of Chinese AI regulation, and export control. A gap at any one of the three creates compliance risk.

3.1 Cross-border transfer — the exemption removes the filing, not the duty

The general position requires the operator to arrange, as applicable, the Data Export Security Assessment, the Standard Contract for Cross-Border Transfer of Personal Information, and Personal Information Protection Certification.

For the token-export scenario specifically, the exemptions in the Provisions on Promoting and Regulating Cross-border Data Flows (促进和规范数据跨境流动规定, CAC Decree No. 16) deserve attention:

  • Article 4 — personal information collected and generated abroad, transmitted into China for processing and then provided abroad, where no domestic personal information or important data is introduced during processing, is exempt from declaration. This is the most direct exemption channel for the model in which an overseas customer’s data completes inference on domestic GPUs and returns overseas.
  • Article 5 — a non-CIIO providing abroad, cumulatively within the year, the non-sensitive personal information of fewer than 100,000 people is exempt from declaration.
  • Article 6 — pilot free trade zones may formulate data export negative lists, with data outside the list exempt from declaration. Shanghai and Hainan already have practice here.

The authors then make the point that matters most: what these provisions exempt is the declaration procedure, not the compliance obligation itself. Even where an exemption applies, the operator must still discharge notice-and-consent, the Personal Information Protection Impact Assessment (PIPIA) required by PIPL Articles 55–56, and security safeguard obligations.

Most critically, the Article 4 exemption is premised on no domestic personal information or important data being introduced. Once an overseas customer’s call scenario involves images, voice, or medical information collected within China being fed into the model through the API, that data flow leaves the exemption and must be brought back under one of the three pathways.

3.2 Territorial jurisdiction — export-only services escape filing, conditionally

The scope of the GenAI Interim Measures is limited to providing services to the domestic public. Article 2, paragraph 3 states that research, development, and application activities not provided to the domestic public fall outside the Measures.

On that basis, a domestic entity providing API inference services only to overseas customers, and not open to the domestic public, in principle does not fall within mandatory GenAI filing and security assessment. Algorithm filing is likewise territorial, judged by whether the service recipients are located in China.

But the authors stress that this exemption carries a strict implicit precondition: the service must not, in fact, flow back to the domestic public. If overseas customers can access, register for, or download the service from within China, or if the domestic entity knowingly supports resale of the model capability back to the domestic public, the arrangement may be characterized on a look-through basis as providing services domestically — triggering filing and security assessment after all.

Geographic isolation in the overseas version, and contractual limits on scope of application, are therefore not optional features. They are the necessary conditions for maintaining the exemption.

3.3 Export control — the variable that can end the deal

Export control is the element most often underestimated in the token-export scenario, and the one most likely to upend a transaction.

On the Chinese side, the Export Control Law of the PRC brings services within the scope of controlled items, and characterizes the provision of controlled items by entities within China to foreign organizations and individuals as export. For items not on a control list, an exporter who knows or should know that a risk of endangering national security exists and exports anyway must apply for a license — this is the catch-all provision (兜底条款).

The Catalogue of Technologies Prohibited or Restricted from Export in China does not currently list open large-model weights, compute-as-a-service, or AI inference technology as separate entries. The authors are explicit that this does not constitute a safe harbor: technologies or services that are not catalogued but present national security risk can still be controlled on a case-by-case basis through the catch-all provision and temporary control mechanisms.

[DCC note: the authors introduce this section as spanning both the Chinese and US regimes, but the published piece develops only the Chinese side.]

3.4 Two details that get missed: telecom qualification and settlement

Circuits. Where a cross-border computing service depends on IPLC, IPVPN, or data center interconnect to give overseas customers low-latency access, that is operational cross-border telecom activity. It must be routed through a provider holding an international data communications services license — currently, in the main, basic telecom operators with international communications gateway qualifications — and through an international communications gateway.

Foreign exchange and tax. Token-export revenue is an export of services under trade in services. It may be freely settled and sold under the current account, but must be handled through a bank and is subject to authenticity review. Where a cross-border digital service export is wholly consumed abroad, the operator may seek VAT zero-rating or exemption treatment (财税〔2016〕36号).

4. Self-deployed models: two commonly misread basics

Before turning to the Harness and agents, the authors clear up two misconceptions they encounter regularly among operators:

  1. That so long as you do not call a third-party API and instead self-deploy an open-source model, you escape filing and registration obligations.
  2. That because a model is open-source, you may of course provide it externally for free.

Neither is accurate.

4.1 Large-model filing (备案) versus large-model registration (登记)

Serving overseas customers. Article 2 of the GenAI Interim Measures limits their scope to the use of generative AI technology to provide services to the domestic public, and Article 2(3) excludes research, development, and application not provided to the domestic public. The core test for the filing obligation is therefore the external-facing character of the service. A self-deployed open-source model serving only overseas customers does not, on a strict reading of the text, trigger domestic filing.

Serving domestic customers. On large-model filing: where a self-deployed model directly calls the capability of a third-party base model that has already been filed, without fine-tuning, training, or further development, and merely exposes the self-deployed model’s API interface — with no modification made to the base model — no large-model filing is required.

On large-model registration, the regulatory standard is not yet settled. Drawing on the CAC’s successive filed-information announcements and on consultations with local CAC offices, the authors report that local positions differ:

  • Some CAC offices take the view that large-model registration applies to AI applications, and that a self-deployed model is essentially just a token-forwarding call platform whose core external offering is an API interface — not an AI application in the sense of an app, webpage, or client software. On that view, no registration is required.
  • Others apply a “report everything that ought to be reported” (应报尽报) principle and recommend proactively submitting a registration filing.

Whether registration is required therefore has to be judged case by case, against the operator’s actual service model and the view of the local cyberspace administration.

4.2 Open weights are not the same as free commercial use

Open source does not mean unrestricted free commercial use — a proposition that applies with particular force to open-source models. The authors first separate two concepts: open weights (开放权重) and open-source code (开源代码). The DeepSeek series (MIT license) has both code and weights open. The ultra-large-parameter Kimi and Qwen models release weights for download but under custom licenses, each with its own conditions on commercial use.

Their worked example is Kimi K3, which although open-source carries revenue-sharing terms:

  • MaaS revenue threshold. If the licensee (and its affiliates) operates a Model-as-a-Service (MaaS) business — that is, provides third parties with inference or fine-tuning access while exercising substantial control over inputs, parameters, or training data — and aggregate total revenue over 12 consecutive months exceeds US$20 million, it must enter into a separate commercial agreement with Moonshot AI (月之暗面) and may not continue using the model for free.
  • Large-scale commercial threshold. If the model is used in the licensee’s commercial product or service and that product or service has more than 100 million monthly active users, or monthly revenue exceeding US$20 million, the “Kimi K3” mark must be prominently displayed in the product or service user interface.

The authors’ point is that choosing which model to serve MaaS from is not mainly a license-fee question. The risk sits in the trigger clauses: MAU thresholds that convert a free license into a commercial one, labeling and naming obligations for derivative models, restrictions on using model output to train other models, and the behavioral restrictions transmitted by OpenRAIL-type licenses.

On the MAU measure specifically, license terms usually count the monthly active users of products or services provided by you or your affiliates. Whether a compute center that aggregates call volume across many customers counts that volume toward its own MAU is open to interpretation, and has to be assessed carefully against the specific license text.

Finally, the consequences of breaching an open-source license are not confined to contractual breach. A copyright infringement claim may be asserted, the license may terminate with an obligation to cease use, and the business may be forced offline. It is also a focal check item in financing due diligence.

5. Harness and agent delivery: how liability travels

When a compute center delivers a Harness — the authors’ term, written in Latin script, for an agent development framework, toolchain, or API relay — and agents alongside it, the operator’s compliance responsibility extends from the machine-room layer up to the application layer. [DCC note: the Beijing Agent Measures render the same engineering layer as 驾驭层, the “harness layer”.]

5.1 There is no standalone “agent filing” — only a stack of existing duties

Chinese law does not currently treat the AI agent (智能体) as a standalone regulatory object. An agent’s compliance obligations are in fact the superposition of several existing ones:

  • algorithm filing — for planning, retrieval, scheduling, and decision-making algorithms;
  • deep synthesis filing and the “two-new” security assessment (双新评估) — for dialogue and content generation;
  • large-model filing or registration — depending on whether the base is self-developed or a third-party model is called;
  • industry qualifications — for vertical scenarios such as finance and healthcare;
  • AI-generated content labeling obligations.

What practitioners call “agent filing” is this combination, integrated. There is no standalone filing category.

The most substantively important element is Article 22(2) of the GenAI Interim Measures, under which service providers include organizations and individuals that provide generative AI services by means such as providing a programmable interface. On that basis, a Harness, API gateway, or model relay platform may be directly characterized as a service provider even where it does no more than forward a third party’s model capability — and cannot claim exemption on grounds of technology neutrality.

Which path applies depends on how upstream capability is obtained and how downstream delivery is structured: calling official APIs points to the large-model registration path; a self-developed base points to the large-model filing path; and calling an overseas, unfiled model generally cannot enter the registration channel reserved for direct calls to already-filed models.

5.2 The liability chain of tool calling — civil through criminal

An agent’s ability to autonomously call tools (search, sending email, accessing internal systems) is the core value of the Harness and also the most concentrated source of legal risk.

For upstream platforms and systems. A user’s authorization is not the same as a continuing right of access. Disguising an AI’s identity, bypassing technical barriers, or continuing to access after a platform has expressly refused may, under Chinese law, trigger Article 285 of the Criminal Law — the crime of illegally obtaining data from a computer information system, or the crime of illegally controlling a computer information system. The standard established in SPP Guiding Case No. 36, that access exceeding authorization constitutes intrusion, is directly relevant here. The same conduct may also constitute online unfair competition under the Anti-Unfair Competition Law.

The authors draw the comparative point explicitly: where US law is relatively tolerant of this kind of conduct, Chinese law regulates unauthorized and excess-authorization access markedly more strictly, and criminal, administrative, and civil liability may stack.

For tool and interface providers. Cracking interfaces, misappropriating API keys, and bypassing billing mechanisms may constitute offenses under Article 285. Developing or selling dedicated cracking tools may constitute the offense under Article 285(3) of providing programs or tools for intruding into or illegally controlling computer information systems. Knowingly providing technical assistance where a downstream party uses API relay to commit fraud or other crimes may fall within Article 287-2, the crime of aiding information network criminal activities.

For agent product and service providers. They bear input and output review obligations, content-producer responsibility, and personal information handler responsibility, together with disposal and reporting obligations once unlawful content is discovered.

From this the authors derive a design prescription. A Harness product should build in four baseline arrangements at the design level — identity transparency, authorization boundaries, human in the loop (人在环路), and end-to-end audit — impose mandatory human approval for high-value or irreversible operations (large payments, contract signature, deletion of core data), and retain complete log evidence so that responsibility can be allocated afterward.

5.3 Office agents and vertical agents

Office agents. The core risk is not the technology but data security. Autonomous agent operation inherently cuts against the three basic principles of personal information processing — informed consent, purpose limitation, and minimum necessary. Office data (contracts, customer lists, operating data) is mostly trade secrets or important data, and an agent’s automatic retrieval, external transmission, or feeding of that data into a third-party cloud model’s training is a high-incidence leakage point.

The authors flag one point in particular: data stored within China but accessed or called by an overseas institution equally constitutes a cross-border data transfer. Calling an overseas model API may therefore trigger the compliance obligations of the three pathways. They add that OpenAI, Anthropic, and other mainstream overseas models have not listed mainland China as a supported region, so relay-station arrangements require look-through verification of the underlying model’s source and legality.

Vertical agents. Compliance here turns mainly on sectoral market access. A medical diagnostic-assistance agent may constitute a medical device product requiring NMPA registration. A robo-advisory agent needs securities investment advisory qualifications. A legal agent offering professional judgment to the public faces exposure for unauthorized practice, and must prominently mark, in both interface and agreement, that its output does not constitute legal, financial, or medical advice — avoiding misleading designations such as “advisor” or “expert”.

Vertical agents also generally carry the baseline obligations: MLPS grading and testing, ICP filing or a value-added telecom license, and public-security network filing.

5.4 Labeling AI-generated content

Under the Measures for the Labeling of AI-Generated and Composed Content (人工智能生成合成内容标识办法, 国信办通字〔2025〕2号, effective September 1, 2025), agent output must satisfy a dual obligation:

  • a visible label (显式标识) — presented in text, sound, or graphics, and clearly perceivable by the user; and
  • an implicit label (隐式标识) — added by technical means in file metadata, not readily perceivable.

No organization or individual may maliciously delete, alter, forge, or conceal these labels, or provide tools or services enabling others to do so.

For a Harness or a relay chain, responsibility for adding, transmitting, retaining, and displaying labels must be expressly allocated at both the contractual and the technical-interface level. Output from an overseas model will not necessarily carry labels that comply with Chinese rules, and the platform cannot rely on the upstream model service provider to do this for it.

6. Conclusion: one facility, five sets of regulatory logic

Returning to the question the authors opened with — the traditional IDC compliance checklist is entirely inadequate for the intelligent computing center, and the underlying reason is that the compute center’s positioning is no longer singular.

The same machine room may simultaneously be:

  • a domestic IDC operator;
  • a cross-border AI service provider;
  • a service exporter in the export-control sense;
  • a supplier of self-deployed model capability; and
  • the responsible entity for agent-related services.

Multiple identities correspond to multiple sets of regulatory logic, which are superimposed on and transmit into one another.

For investors and operating entities, the authors locate the key to building a compliance system in four junctures:

  1. Before project initiation, identify which obligation combination each positioning attracts — pure self-use, domestic external operation, or a scope that includes overseas services — substituting ex ante design for ex post remedy.
  2. In overseas scenarios, strictly maintain geographic isolation and the boundary of not introducing domestic data, so that the convenience of the filing exemption and declaration exemption does not lapse through blurred boundaries.
  3. When self-deployed models provide capability externally, handle large-model filing and registration and open-source license trigger clauses correctly, rather than treating model provenance or deployment method as grounds for avoiding obligations that apply.
  4. When delivering a Harness and agents, hold yourself to the standard of a service provider rather than positioning yourself as a lessor of infrastructure.

Regulatory certainty, the authors conclude, is growing in step with the industry’s evolution. The operators able to arrange compliance logic systematically across their multiple identities — as asset, as service, as model supplier, and as data hub — are the ones positioned to last through this cycle.


Source: 蔡航 (Cai Hang), 姚婷 (Yao Ting), 刘泽强 (Liu Zeqiang), 《视点 | 算力中心的MaaS服务合规进阶:境内建设、跨境输出与智能体交付的法律审视》, 安杰世泽律师事务所 (AnJie Broad) WeChat Official Account, August 25, 2026. Original

— Not legal advice.

— Not legal advice.


§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →