---
title: "One Machine Room, Five Regulatory Identities: MaaS Compliance for China's AI Compute Centers"
author: "DCC Editorial"
published: 2026-08-25T10:00:00.000Z
url: https://datacompliancechina.com/posts/compute-center-maas-five-regulatory-identities/
description: "AnJie Broad partners Cai Hang and Yao Ting and associate Liu Zeqiang argue that the IDC-era compliance checklist no longer fits the AI compute center. Their thesis: one machine room now carries five regulatory identities at once — domestic IDC operator, cross-border AI service provider, service exporter under the Export Control Law, supplier of self-deployed model capability, and responsible entity for the agents it ships — each with its own logic, and each transmitting obligations to the others. The brief works through value-added telecom licensing (B11/B12), energy-conservation review and PUE caps, the continuing duties under the Regulation on Network Data Security Management (State Council Decree No. 790), the token-export exemptions in CAC Decree No. 16 and what they do not exempt, the territorial limits of the GenAI Interim Measures, the Export Control Law catch-all, the unsettled line between large-model filing (备案) and large-model registration (登记), open-weight license trigger clauses, and the criminal exposure that follows an agent's tool calls under Criminal Law Article 285."
tags: ["compute-centers", "intelligent-computing-center", "maas", "ai-agents", "cross-border", "export-control", "open-source-models", "algorithm-filing", "idc"]
laws_cited: ["network-data-security-regulations", "pipl", "cross-border-data-flows-provisions", "genai-services-interim-measures", "algorithmic-recommendation-provisions", "deep-synthesis-provisions", "ai-content-labeling-measures", "cybersecurity-review-measures", "anti-unfair-competition-law"]
domains: ["ai-governance", "cross-border", "data-security"]
account: "anjie-broad"
original_title: "视点 | 算力中心的MaaS服务合规进阶：境内建设、跨境输出与智能体交付的法律审视"
original_author: "蔡航 (Cai Hang), 姚婷 (Yao Ting), 刘泽强 (Liu Zeqiang)"
original_publication: "安杰世泽律师事务所 (AnJie Broad) WeChat Official Account"
original_url: "https://mp.weixin.qq.com/s/nrb7z0dPmhSi5uRnVW1UuQ"
source_language: "zh"
---

> **Source: Data Compliance China** — https://datacompliancechina.com/posts/compute-center-maas-five-regulatory-identities/ · China data law, translated and annotated for overseas counsel. Cite as: Data Compliance China, "One Machine Room, Five Regulatory Identities: MaaS Compliance for China's AI Compute Centers", https://datacompliancechina.com/posts/compute-center-maas-five-regulatory-identities/
> *Editor's Note — DCC.*
>
> On **August 25, 2026** the **AnJie Broad (安杰世泽)** WeChat channel published
> a client alert by partners **Cai Hang (蔡航)** and **Yao Ting (姚婷)** and
> associate **Liu Zeqiang (刘泽强)** on the compliance perimeter of the AI
> compute center. DCC translates it because its organizing argument is one we
> have not seen made this cleanly elsewhere: the **intelligent computing center
> (智算中心)** has stopped being a single regulated thing. The same facility is
> now, simultaneously, a domestic **Internet Data Center (IDC)** operator, a
> cross-border AI service provider, a service exporter in the export-control
> sense, a supplier of self-deployed model capability, and the responsible
> entity for the agents it ships to customers — five identities, five bodies of
> rules, transmitting obligations to one another.
>
> Two notes on scope. First, the authors' section on **energy-conservation
> review (节能审查)** and **PUE** caps, and their section on foreign-equity
> limits, are energy and telecom regulation rather than data protection; DCC
> has kept them in compressed form because they set up the layering argument,
> but readers should treat them as context. Second, the authors introduce their
> export-control discussion as spanning **both the Chinese and US regimes**, but
> the published piece develops only the Chinese side. DCC has not supplied the
> missing half — analysis of US export controls is outside what this
> publication covers, and readers can get it directly from English sources.
>
> One factual flag. The article states specific commercial thresholds in the
> **Kimi K3** license (a US$20 million/12-month MaaS revenue trigger, and a
> 100-million-MAU badge requirement). DCC reproduces those as the authors'
> characterization of a third-party license and has **not** independently
> verified them against the license text. Anyone relying on the point should
> read the license itself.
>
> For adjacent DCC coverage, see the briefs on the
> [TC260 agent-deployment practice guide](/posts/tc260-ai-agent-deployment-security-guidelines/),
> the [agent governance framework](/posts/ai-agent-rules-governance-framework/),
> the [Beijing Agent Measures on token-to-value](/posts/beijing-agent-measures-token-to-value/),
> and Shanghai's [first FTZ negative-list export filing](/posts/shanghai-data-export-negative-list-first-filing/).
>
> Per the channel's own disclaimer, the article represents the authors' views
> and is not a formal legal opinion of the firm.

As China builds out the **East Data and West Computing project (东数西算工程)**
and the **integrated national computing-power network (全国一体化算力网)**, the AI
compute center has evolved out of the cabinet-rental business that defined the
traditional **Internet Data Center (IDC)**. It is now a composite business
vehicle combining computing-power services, cross-border technology export, and
delivery of intelligent tooling.

That means the regulatory controls applicable to an IDC — telecom market
access, energy-conservation review, **Multi-Level Protection Scheme (MLPS)**
grading — are now only the base layer. On top of them sit a set of rules that
did not exist in the IDC era: cross-border data transfer administration, export
control, **algorithm filing (算法备案)**, and the emerging norms for AI agents.
Running an intelligent computing center off an IDC-era compliance checklist no
longer fits the situation.

This brief follows the authors through four questions:

- Building a compute center in China, which regulatory thresholds must now be
  cleared that did not previously exist?
- Exporting computing power, or token-billed large-model inference, to overseas
  customers — what dual domestic and foreign legal constraints apply?
- When the compute center serves model capability from its own deployment, how
  do filing obligations and open-source licensing actually work?
- What liability does the **Harness** toolchain and the various agents
  delivered alongside it transmit back to the operating entity?

## 1. Why demand shifted after the open-source model wave

The recent wave of highly capable Chinese open-source model releases did not
reduce total demand for computing power. It relocated it.

**Training compute is concentrating.** Open-source models achieve high
inference efficiency at relatively low training cost, so large numbers of small
and medium enterprises no longer need to build their own training clusters and
instead adopt off-the-shelf open-source models. Training demand therefore
concentrates among the handful of vendors with the capacity to keep iterating.

**Inference compute is growing explosively.** Open-source models sharply lower
the barrier to AI applications, and total **token (词元)** call volume is rising
exponentially. After deploying open-source models, some intelligent computing
centers have seen their allocation shift from a training-dominant pattern to
one where training, tuning, and inference carry comparable weight — or where
inference takes the larger share.

Policy is pushing the same way. The **Implementing Opinions on Deepening the
East Data and West Computing Project and Accelerating the Construction of the
Integrated National Computing-Power Network** (发改数据〔2023〕1779号), issued by
the **National Development and Reform Commission (NDRC)** with four other
departments, encourages computing-power services to move away from cabinet
rental and annual or monthly packages toward short-term, connect-and-use,
pay-as-you-go models. It supports computing-power vouchers (算力券), transport
vouchers (运力券), and exploration of data center REITs. **Compute-as-a-Service
(算力即服务)** is becoming the policy-favored supply form.

There is also a stock problem. Intelligent computing centers launched in
concentrated waves across provinces have left built computing power idle.
Open-source models happen to supply a low-cost, on-demand deployment path — and
so, in practice, a route to putting that idle capacity back to work.

The authors' conclusion from this section frames everything that follows:
because compute center projects will inevitably involve cross-border output,
the compliance architecture has to cover domestic operation, overseas service,
and agent delivery **from the outset** — not as three separate later problems.

## 2. Building domestically: three layers of constraint

### 2.1 Telecom licensing — serving third parties is the dividing line

Whether an intelligent computing center needs a **Value-Added Telecommunications
Business License (增值电信业务经营许可证)** turns first on whether it provides
computing power or bandwidth to anyone other than itself.

An enterprise serving only its own business, not renting out cabinets,
computing power, or bandwidth, in principle needs no value-added telecom
qualification. But once it provides server hosting, cabinet rental,
computing-power rental, or cloud (IaaS) resources, it falls within the
**Internet Data Center business (category B11)** or **Internet resource
collaboration services (category B12, i.e. cloud services)** under the
**Catalogue of Telecommunications Services (2015 edition)** — and a license is
required. Cross-province operation is applied for to the **Ministry of Industry
and Information Technology (MIIT)**; operation within a single province, to the
provincial Communications Administration.

Unlicensed operation persists in practice. Some intelligent computing centers
provide computing power externally under the banner of testing, piloting, or
internal sharing, planning to regularize the license later. The authors regard
this as very high risk: once characterized as unlicensed operation, the
**Telecommunications Regulations of the PRC** allow an order to rectify,
confiscation of illegal gains, fines, and even an order to suspend business for
rectification. Licensing should be designed in step with the business model,
not retrofitted mid-operation.

### 2.2 Energy-conservation review and PUE — the binding constraint at build stage

Data center projects generally sit under **filing (备案)** administration rather
than government approval (核准), handled by the local development-and-reform or
economy-and-IT department. But filing does not mean a low threshold. The real
screening happens on energy consumption and regional access.

Under the **Measures for the Energy-Conservation Review of Fixed-Asset
Investment Projects** (NDRC Order No. 2 of 2023), projects with annual
comprehensive energy consumption of 10,000 metric tons of standard coal or more are
reviewed by the provincial energy-conservation review authority, and
**construction may not begin without a review opinion**. Large intelligent
computing centers routinely consume tens of thousands of metric tons, so almost all
fall into provincial review.

**PUE (power usage effectiveness)** is the core review metric. National policy
requires new large and super-large data centers to come in below 1.3, and
national hub nodes below 1.25; Beijing, Shanghai, and Guangdong impose stricter
local standards, along with controls the authors render as "power determines
computing" (以电定算) and "computing determines output" (以算定产), plus
energy-consumption substitution quotas.

Local practice is turning green-power expectations into conditions. When the
Beijing Municipal Development and Reform Commission issues an
energy-conservation review opinion on a computing project, it commonly attaches
a PUE ceiling, self-built photovoltaic capacity, and participation in green
power trading. Individual projects have been required to reach a renewable
utilization ratio of no less than 60% by 2026 and 100% by 2030, with waste-heat
recovery. Energy-conservation review has become, in effect, an instrument for
local governments to steer where computing capacity gets built.

### 2.3 Data security — continuing obligations under classification and grading

The **[Regulation on Network Data Security Management](/laws/network-data-security-regulations/)**
(网络数据安全管理条例, State Council Decree No. 790, effective January 1, 2025)
raises the data-processing security obligations of data center operators
considerably. Under the Regulation:

- Network data is subject to **classified and hierarchical protection**;
  **important data (重要数据)** must be identified and declared in accordance
  with national rules.
- An important-data handler must designate a network data security officer and
  a security management body, and **the officer must be a member of
  management**.
- A **risk assessment** is required before providing, entrusting, or jointly
  processing important data, with an annual risk assessment report submitted to
  the competent authority at provincial level or above.
- Handling the personal information of **10 million people or more** is managed
  by reference to the important-data rules.

For an intelligent computing center, the consequence is that it is not merely a
lessor of computing power. It is simultaneously an **entrusted processor** of
data, and may itself constitute an important-data handler. MLPS Level 3 filing
and testing is only the compliance floor; the data classification-and-grading
system and the annual risk assessment mechanism are the daily obligations that
must be discharged continuously throughout operation.

If the center constitutes a **critical information infrastructure operator
(CIIO)**, or is involved in important-data processing together with an overseas
listing, it must also attend to cybersecurity review obligations under the
**[Cybersecurity Review Measures](/laws/cybersecurity-review-measures/)**.

### 2.4 Algorithm filing where large-model services are offered

Where an intelligent computing center also provides large-model services to the
domestic public, it must discharge algorithm filing and security assessment
obligations under the
**[Provisions on the Administration of Algorithmic Recommendation Services for Internet Information Services](/laws/algorithmic-recommendation-provisions/)**,
the **[Provisions on the Administration of Deep Synthesis of Internet Information Services](/laws/deep-synthesis-provisions/)**,
and the **[Interim Measures for the Management of Generative Artificial Intelligence Services](/laws/genai-services-interim-measures/)**
— what practitioners call **algorithm filing (算法备案)** and **large-model
filing (大模型备案)**. Services may not be offered externally until the entity
appears on the CAC's published list of filed information.

The authors flag an important limit. These filing obligations target the case
of **directly providing large-model capability** — self-developed, fine-tuned,
further-developed, or trained. An operator that merely calls a third-party
model that has already been filed, acting as a pure API relay, does not need
large-model filing. This distinction carries over into the agent discussion in
Part 5, and is developed in Part 4.

### 2.5 Foreign investment — an equity cap and a security review, running in parallel

Foreign participation in a domestic compute center is not off-limits, but it is
constrained. The **Special Administrative Measures for Foreign Investment
Access (Negative List) (2024 edition)** retains the requirement that foreign
equity in value-added telecom services not exceed 50% (excluding e-commerce,
domestic multi-party communication, store-and-forward, and call centers), and
that basic telecom services be Chinese-controlled. IDC is a value-added telecom
service, so outside pilot areas foreign access is uniformly subject to the 50%
cap, with approval under the **Provisions on the Administration of
Foreign-Invested Telecommunications Enterprises**.

That position has been partly opened up. MIIT's **Circular on Carrying Out the
Pilot Program for Expanding the Opening-Up of Value-Added Telecommunications
Services** (工信部通信函〔2024〕107号) runs pilots in the Beijing comprehensive
demonstration zone for expanded opening of the service sector, the Lin-gang
Special Area of the Shanghai Pilot Free Trade Zone and its socialist
modernization leading zone, the Hainan Free Trade Port, and the Shenzhen pilot
demonstration zone — permitting foreign wholly-owned or controlled enterprises
to operate IDC, CDN, and cloud services.

But the authors add a caution that is the real point of the section. Foreign
participation in computing operations that involve important data, critical
information infrastructure, or large-scale personal information may still
trigger national security review under the
[Cybersecurity Review Measures](/laws/cybersecurity-review-measures/) and the
[Regulation on Network Data Security Management](/laws/network-data-security-regulations/).
**The 50% numerical threshold and the substantive security-review threshold are
two parallel and mutually independent sets of rules, and must not be
conflated.**

## 3. Exporting compute and tokens: three regimes stacked

A domestically operated intelligent computing center providing token-billed
large-model API inference to overseas customers is not a hypothetical — it is a
live business scenario. It sits under three constraints at once: China's
cross-border data transfer regime, the territorial reach of Chinese AI
regulation, and export control. A gap at any one of the three creates
compliance risk.

### 3.1 Cross-border transfer — the exemption removes the filing, not the duty

The general position requires the operator to arrange, as applicable, the
**Data Export Security Assessment**, the **Standard Contract for Cross-Border
Transfer of Personal Information**, and **Personal Information Protection
Certification**.

For the token-export scenario specifically, the exemptions in the
**[Provisions on Promoting and Regulating Cross-border Data Flows](/laws/cross-border-data-flows-provisions/)**
(促进和规范数据跨境流动规定, CAC Decree No. 16) deserve attention:

- **Article 4** — personal information collected and generated **abroad**,
  transmitted into China for processing and then provided abroad, where no
  domestic personal information or important data is introduced during
  processing, is exempt from declaration. This is the most direct exemption
  channel for the model in which an overseas customer's data completes
  inference on domestic GPUs and returns overseas.
- **Article 5** — a non-CIIO providing abroad, cumulatively within the year,
  the non-sensitive personal information of fewer than 100,000 people is exempt
  from declaration.
- **Article 6** — pilot free trade zones may formulate data export negative
  lists, with data outside the list exempt from declaration. Shanghai and
  Hainan already have practice here.

The authors then make the point that matters most: **what these provisions
exempt is the declaration procedure, not the compliance obligation itself.**
Even where an exemption applies, the operator must still discharge
notice-and-consent, the **Personal Information Protection Impact Assessment
(PIPIA)** required by
[PIPL](/laws/pipl/) Articles 55–56, and security safeguard obligations.

Most critically, the Article 4 exemption is premised on **no domestic personal
information or important data being introduced**. Once an overseas customer's
call scenario involves images, voice, or medical information collected within
China being fed into the model through the API, that data flow leaves the
exemption and must be brought back under one of the three pathways.

### 3.2 Territorial jurisdiction — export-only services escape filing, conditionally

The scope of the
[GenAI Interim Measures](/laws/genai-services-interim-measures/) is limited to
providing services **to the domestic public**. Article 2, paragraph 3 states
that research, development, and application activities not provided to the
domestic public fall outside the Measures.

On that basis, a domestic entity providing API inference services only to
overseas customers, and not open to the domestic public, in principle does not
fall within mandatory GenAI filing and security assessment. Algorithm filing is
likewise territorial, judged by whether the service recipients are located in
China.

But the authors stress that this exemption carries a strict implicit
precondition: **the service must not, in fact, flow back to the domestic
public.** If overseas customers can access, register for, or download the
service from within China, or if the domestic entity knowingly supports resale
of the model capability back to the domestic public, the arrangement may be
characterized on a **look-through** basis as providing services domestically —
triggering filing and security assessment after all.

Geographic isolation in the overseas version, and contractual limits on scope
of application, are therefore **not optional features**. They are the necessary
conditions for maintaining the exemption.

### 3.3 Export control — the variable that can end the deal

Export control is the element most often underestimated in the token-export
scenario, and the one most likely to upend a transaction.

On the Chinese side, the **Export Control Law of the PRC** brings **services**
within the scope of controlled items, and characterizes the provision of
controlled items by entities within China to foreign organizations and
individuals as **export**. For items not on a control list, an exporter who
**knows or should know** that a risk of endangering national security exists
and exports anyway must apply for a license — this is the **catch-all provision
(兜底条款)**.

The **Catalogue of Technologies Prohibited or Restricted from Export in China**
does not currently list open large-model weights, compute-as-a-service, or AI
inference technology as separate entries. The authors are explicit that **this
does not constitute a safe harbor**: technologies or services that are not
catalogued but present national security risk can still be controlled on a
case-by-case basis through the catch-all provision and temporary control
mechanisms.

*[DCC note: the authors introduce this section as spanning both the Chinese and
US regimes, but the published piece develops only the Chinese side.]*

### 3.4 Two details that get missed: telecom qualification and settlement

**Circuits.** Where a cross-border computing service depends on IPLC, IPVPN, or
data center interconnect to give overseas customers low-latency access, that is
operational cross-border telecom activity. It must be routed through a provider
holding an international data communications services license — currently, in
the main, basic telecom operators with international communications gateway
qualifications — and through an international communications gateway.

**Foreign exchange and tax.** Token-export revenue is an export of services
under trade in services. It may be freely settled and sold under the current
account, but must be handled through a bank and is subject to authenticity
review. Where a cross-border digital service export is wholly consumed abroad,
the operator may seek VAT zero-rating or exemption treatment (财税〔2016〕36号).

## 4. Self-deployed models: two commonly misread basics

Before turning to the Harness and agents, the authors clear up two
misconceptions they encounter regularly among operators:

1. That so long as you do not call a third-party API and instead self-deploy an
   open-source model, you escape filing and registration obligations.
2. That because a model is open-source, you may of course provide it externally
   for free.

Neither is accurate.

### 4.1 Large-model filing (备案) versus large-model registration (登记)

**Serving overseas customers.** Article 2 of the GenAI Interim Measures limits
their scope to the use of generative AI technology to provide services to the
domestic public, and Article 2(3) excludes research, development, and
application not provided to the domestic public. The core test for the filing
obligation is therefore the **external-facing character of the service**. A
self-deployed open-source model serving only overseas customers does not, on a
strict reading of the text, trigger domestic filing.

**Serving domestic customers.** On **large-model filing**: where a
self-deployed model directly calls the capability of a third-party base model
that has already been filed, without fine-tuning, training, or further
development, and merely exposes the self-deployed model's API interface — with
no modification made to the base model — no large-model filing is required.

On **large-model registration**, the regulatory standard is not yet settled.
Drawing on the CAC's successive filed-information announcements and on
consultations with local CAC offices, the authors report that local positions
differ:

- **Some CAC offices** take the view that large-model registration applies to
  **AI applications**, and that a self-deployed model is essentially just a
  token-forwarding call platform whose core external offering is an API
  interface — not an AI application in the sense of an app, webpage, or client
  software. On that view, no registration is required.
- **Others** apply a "report everything that ought to be reported" (应报尽报)
  principle and recommend proactively submitting a registration filing.

Whether registration is required therefore has to be judged case by case,
against the operator's actual service model and the view of the local
cyberspace administration.

### 4.2 Open weights are not the same as free commercial use

Open source does not mean unrestricted free commercial use — a proposition that
applies with particular force to open-source models. The authors first separate
two concepts: **open weights (开放权重)** and **open-source code (开源代码)**.
The DeepSeek series (MIT license) has both code and weights open. The
ultra-large-parameter Kimi and Qwen models release weights for download but
under **custom licenses**, each with its own conditions on commercial use.

Their worked example is **Kimi K3**, which although open-source carries
revenue-sharing terms:

- **MaaS revenue threshold.** If the licensee (and its affiliates) operates a
  **Model-as-a-Service (MaaS)** business — that is, provides third parties with
  inference or fine-tuning access while exercising substantial control over
  inputs, parameters, or training data — and aggregate total revenue over 12
  consecutive months exceeds **US$20 million**, it must enter into a separate
  commercial agreement with **Moonshot AI (月之暗面)** and may not continue
  using the model for free.
- **Large-scale commercial threshold.** If the model is used in the licensee's
  commercial product or service and that product or service has more than
  **100 million monthly active users**, or monthly revenue exceeding **US$20
  million**, the "Kimi K3" mark must be prominently displayed in the product or
  service user interface.

The authors' point is that choosing which model to serve MaaS from is not
mainly a license-fee question. The risk sits in the **trigger clauses**: MAU
thresholds that convert a free license into a commercial one, labeling and
naming obligations for derivative models, restrictions on using model output to
train other models, and the behavioral restrictions transmitted by
OpenRAIL-type licenses.

On the MAU measure specifically, license terms usually count the monthly active
users of products or services provided by **you or your affiliates**. Whether a
compute center that aggregates call volume across many customers counts that
volume toward its own MAU **is open to interpretation**, and has to be assessed
carefully against the specific license text.

Finally, the consequences of breaching an open-source license are not confined
to contractual breach. A **copyright infringement** claim may be asserted, the
license may terminate with an obligation to cease use, and the business may be
forced offline. It is also a focal check item in financing due diligence.

## 5. Harness and agent delivery: how liability travels

When a compute center delivers a **Harness** — the authors' term, written in
Latin script, for an agent development framework, toolchain, or API relay — and
agents alongside it, the operator's compliance responsibility extends from the
machine-room layer up to the application layer. *[DCC note: the Beijing Agent
Measures render the same engineering layer as 驾驭层, the "harness layer".]*

### 5.1 There is no standalone "agent filing" — only a stack of existing duties

Chinese law does not currently treat the **AI agent (智能体)** as a standalone
regulatory object. An agent's compliance obligations are in fact the
superposition of several existing ones:

- **algorithm filing** — for planning, retrieval, scheduling, and
  decision-making algorithms;
- **deep synthesis filing** and the **"two-new" security assessment (双新评估)**
  — for dialogue and content generation;
- **large-model filing or registration** — depending on whether the base is
  self-developed or a third-party model is called;
- **industry qualifications** — for vertical scenarios such as finance and
  healthcare;
- **AI-generated content labeling obligations**.

What practitioners call "agent filing" is this combination, integrated. **There
is no standalone filing category.**

The most substantively important element is **Article 22(2) of the GenAI
Interim Measures**, under which service providers include organizations and
individuals that provide generative AI services **by means such as providing a
programmable interface**. On that basis, a Harness, API gateway, or model relay
platform may be directly characterized as a **service provider** even where it
does no more than forward a third party's model capability — and **cannot claim
exemption on grounds of technology neutrality**.

Which path applies depends on how upstream capability is obtained and how
downstream delivery is structured: calling official APIs points to the
large-model registration path; a self-developed base points to the large-model
filing path; and calling an **overseas, unfiled** model generally cannot enter
the registration channel reserved for direct calls to already-filed models.

### 5.2 The liability chain of tool calling — civil through criminal

An agent's ability to autonomously call tools (search, sending email, accessing
internal systems) is the core value of the Harness and also the most
concentrated source of legal risk.

**For upstream platforms and systems.** A user's authorization is not the same
as a continuing right of access. Disguising an AI's identity, bypassing
technical barriers, or continuing to access after a platform has expressly
refused may, under Chinese law, trigger **Article 285 of the Criminal Law** —
the crime of illegally obtaining data from a computer information system, or
the crime of illegally controlling a computer information system. The standard
established in **SPP Guiding Case No. 36**, that access exceeding authorization
constitutes intrusion, is directly relevant here. The same conduct may also
constitute online unfair competition under the
**[Anti-Unfair Competition Law](/laws/anti-unfair-competition-law/)**.

The authors draw the comparative point explicitly: where US law is relatively
tolerant of this kind of conduct, Chinese law regulates unauthorized and
excess-authorization access markedly more strictly, and criminal,
administrative, and civil liability may stack.

**For tool and interface providers.** Cracking interfaces, misappropriating API
keys, and bypassing billing mechanisms may constitute offenses under Article
285. Developing or selling dedicated cracking tools may constitute the offense
under Article 285(3) of providing programs or tools for intruding into or
illegally controlling computer information systems. Knowingly providing
technical assistance where a downstream party uses API relay to commit fraud or
other crimes may fall within **Article 287-2**, the crime of aiding information
network criminal activities.

**For agent product and service providers.** They bear input and output review
obligations, content-producer responsibility, and **personal information
handler** responsibility, together with disposal and reporting obligations once
unlawful content is discovered.

From this the authors derive a design prescription. A Harness product should
build in four baseline arrangements at the design level — **identity
transparency, authorization boundaries, human in the loop (人在环路), and
end-to-end audit** — impose mandatory human approval for high-value or
irreversible operations (large payments, contract signature, deletion of core
data), and retain complete log evidence so that responsibility can be
allocated afterward.

### 5.3 Office agents and vertical agents

**Office agents.** The core risk is not the technology but data security.
Autonomous agent operation inherently cuts against the three basic principles
of personal information processing — informed consent, purpose limitation, and
minimum necessary. Office data (contracts, customer lists, operating data) is
mostly **trade secrets** or **important data**, and an agent's automatic
retrieval, external transmission, or feeding of that data into a third-party
cloud model's training is a high-incidence leakage point.

The authors flag one point in particular: **data stored within China but
accessed or called by an overseas institution equally constitutes a
cross-border data transfer.** Calling an overseas model API may therefore
trigger the compliance obligations of the three pathways. They add that OpenAI,
Anthropic, and other mainstream overseas models have not listed mainland China
as a supported region, so relay-station arrangements require **look-through
verification** of the underlying model's source and legality.

**Vertical agents.** Compliance here turns mainly on sectoral market access. A
medical diagnostic-assistance agent may constitute a medical device product
requiring **NMPA registration**. A robo-advisory agent needs securities
investment advisory qualifications. A legal agent offering professional
judgment to the public faces exposure for unauthorized practice, and must
prominently mark, in both interface and agreement, that its output does not
constitute legal, financial, or medical advice — avoiding misleading
designations such as "advisor" or "expert".

Vertical agents also generally carry the baseline obligations: MLPS grading and
testing, ICP filing or a value-added telecom license, and public-security
network filing.

### 5.4 Labeling AI-generated content

Under the
**[Measures for the Labeling of AI-Generated and Composed Content](/laws/ai-content-labeling-measures/)**
(人工智能生成合成内容标识办法, 国信办通字〔2025〕2号, effective September 1,
2025), agent output must satisfy a dual obligation:

- a **visible label (显式标识)** — presented in text, sound, or graphics, and
  clearly perceivable by the user; and
- an **implicit label (隐式标识)** — added by technical means in file metadata,
  not readily perceivable.

No organization or individual may maliciously delete, alter, forge, or conceal
these labels, or provide tools or services enabling others to do so.

For a Harness or a relay chain, responsibility for **adding, transmitting,
retaining, and displaying** labels must be expressly allocated at both the
contractual and the technical-interface level. Output from an overseas model
will not necessarily carry labels that comply with Chinese rules, and **the
platform cannot rely on the upstream model service provider to do this for
it.**

## 6. Conclusion: one facility, five sets of regulatory logic

Returning to the question the authors opened with — the traditional IDC
compliance checklist is entirely inadequate for the intelligent computing
center, and the underlying reason is that the compute center's positioning is
no longer singular.

The same machine room may simultaneously be:

- a domestic **IDC operator**;
- a **cross-border AI service provider**;
- a **service exporter** in the export-control sense;
- a **supplier of self-deployed model capability**; and
- the **responsible entity for agent-related services**.

Multiple identities correspond to multiple sets of regulatory logic, which are
superimposed on and transmit into one another.

For investors and operating entities, the authors locate the key to building a
compliance system in four junctures:

1. **Before project initiation**, identify which obligation combination each
   positioning attracts — pure self-use, domestic external operation, or a
   scope that includes overseas services — substituting ex ante design for ex
   post remedy.
2. **In overseas scenarios**, strictly maintain geographic isolation and the
   boundary of not introducing domestic data, so that the convenience of the
   filing exemption and declaration exemption does not lapse through blurred
   boundaries.
3. **When self-deployed models provide capability externally**, handle
   large-model filing and registration and open-source license trigger clauses
   correctly, rather than treating model provenance or deployment method as
   grounds for avoiding obligations that apply.
4. **When delivering a Harness and agents**, hold yourself to the standard of a
   **service provider** rather than positioning yourself as a lessor of
   infrastructure.

Regulatory certainty, the authors conclude, is growing in step with the
industry's evolution. The operators able to arrange compliance logic
systematically across their multiple identities — as asset, as service, as
model supplier, and as data hub — are the ones positioned to last through this
cycle.

---

**Source:** 蔡航 (Cai Hang), 姚婷 (Yao Ting), 刘泽强 (Liu Zeqiang),
《视点 | 算力中心的MaaS服务合规进阶：境内建设、跨境输出与智能体交付的法律审视》,
安杰世泽律师事务所 (AnJie Broad) WeChat Official Account, August 25, 2026.
[Original](https://mp.weixin.qq.com/s/nrb7z0dPmhSi5uRnVW1UuQ)

— Not legal advice.
