Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ 086 · GENERATIVE-AI

Which of the Ten Duties Actually Bites: Cheng Xiao on Fault and Statutory Duty for Generative-AI Providers

In a Political Science and Law Tribune article, Tsinghua professor Cheng Xiao (程啸) resets how Chinese courts should reason from a generative-AI provider's statutory duties to civil fault. His thesis: tort liability here is fault-based under Civil Code Art. 1165(1); 'duty of care' is not a separate element but the objective reasonable-person standard in AI dress. Crucially, not every breach of a statutory duty is fault. Negative duties (do not infringe) collapse into the 'infringement of rights' element and prove nothing about fault; only breach of an affirmative statutory duty can ground fault — and only where the duty aims to protect individuals, the plaintiff is within its protected class, and the harmed interest is within its protected scope. Applying that filter to the ten affirmative duties in the Generative AI Interim Measures, Cheng sorts them into result-based and method-based obligations, sets out five factors for judging the method-based ones, and criticizes two court rulings that grounded fault on a labeling or risk-warning duty in copyright cases the duty was never meant to protect against.

Editor’s note. This is a DCC-framed structured summary of a law-journal article, not a translation. Cheng Xiao (程啸) is a professor at Tsinghua University School of Law; the piece ran in Political Science and Law Tribune (《政法论丛》) 2026 No. 4. It is doctrinal, but its payload is operational: it tells overseas counsel which of a generative-AI provider’s statutory obligations can actually convert into civil damages when an output harms someone — and which cannot, however sternly they are worded. Section and article numbers below are the author’s; the framing and the takeaways for practitioners are ours.

When a Chinese court has to decide whether a generative-AI provider owes damages for a harmful output — a defamatory hallucination, an image that infringes someone’s copyright, a face-swap that violates a right to one’s likeness — the contested question is almost always fault (过错). Cheng Xiao’s article is an attempt to discipline how courts get from the provider’s long list of regulatory duties to a finding of fault, and to stop them from treating “you broke a rule” as “you are at fault.”

Start from fault, not from a checklist

Chinese law has no special no-fault or presumption-of-fault regime for generative-AI harms, and no-fault liability must be expressly enacted. So the governing rule is the ordinary fault standard in Civil Code Art. 1165(1): a provider is liable only where it infringed a civil right or interest through fault.

Cheng’s first move is to deflate the fashionable “duty of care” (注意义务) framing. Duty of care is a common-law import (and the German Verkehrspflicht plays a different structural role); in Chinese tort law it is not a separate element of liability. It is simply the label for the objective, reasonable-person yardstick used to judge negligence — “what precautions a reasonable provider, in this position, with the technology then available, should have taken.” Reasoning through a provider’s “duty of care” therefore adds nothing new; it is the reasonable-person test wearing AI-era clothing. The practical consequence: a court cannot manufacture liability by inventing a free-floating “duty” the statutes never imposed.

Not every statutory duty can ground fault

Cheng’s central and most useful distinction is between two kinds of statutory duty a provider bears.

  • Negative duties (不作为义务) — do not infringe others’ personality rights, property, IP; do not endanger the public interest. These, he argues, do no work in the fault analysis. The obligation not to infringe a right is just the flip side of the right itself; whether the provider breached it is already captured by the “infringement of a civil right or interest” element of Art. 1165(1). Citing them proves the conduct was unlawful, not that it was at fault.
  • Affirmative duties (作为义务) — the positive things a provider must do. Only the breach of an affirmative statutory duty can support a finding of fault.

And even affirmative duties do not automatically count. Borrowing the logic of the German protective-statute (Schutzgesetz) doctrine and the American negligence-per-se test, Cheng sets a three-part protective-purpose filter. A breached affirmative duty grounds fault only where:

  1. the duty aims to protect individuals (not solely public order or national interest);
  2. the plaintiff falls within the class the duty protects; and
  3. the interest harmed falls within the scope the duty was meant to guard.

The ten affirmative duties — and how to read them

The most complete catalogue of a provider’s affirmative duties is the Generative AI Interim Measures. Cheng counts ten: (1) prevent discrimination (Art. 4(2)); (2) content accuracy and reliability (Art. 4(5)); (3) data quality (Art. 7(4)); (4) data labeling during training (Art. 8); (5) guide users and guard against minors’ dependence or addiction (Art. 10); (6) label generated content (Art. 12); (7) provide safe and stable service (Art. 13); (8) disposal, rectification, and reporting of illegal content and misuse (Art. 14); (9) maintain a complaint-and-report mechanism (Art. 15); and (10) security assessment and algorithm filing for services with public-opinion or social-mobilization capacity (Art. 17).

Because no statute makes breach of these duties conclusively or presumptively equal to fault, each must be run through the protective-purpose filter in the concrete case. All ten, Cheng accepts, protect individuals to some degree — but the plaintiff and the harmed interest still have to line up.

He then adds a second axis, drawn from the French distinction between obligations of means and of result:

  • Result-based obligations (结果性义务) — judged purely by outcome. Four of the ten qualify: content labeling, disposal/rectification/reporting, the complaint mechanism, and assessment/filing. Either the provider labeled the image, stood up the complaint channel, and filed the algorithm, or it did not.
  • Method-based obligations (方式性义务) — judged by whether due care was taken, not by whether a perfect outcome was reached. The other six: anti-discrimination, content accuracy/reliability, data quality, data labeling, user guidance/anti-addiction, and safe-and-stable service. The law asks only for “effective measures,” not a guarantee — no provider can promise zero discriminatory or inaccurate output.

For the method-based duties, Cheng offers five factors a court should weigh to decide whether the provider’s measures were adequate — a practical rubric for counsel assessing exposure:

  1. Service type — public-opinion/social-mobilization capacity; video/audio vs. text/image; sensitive domains (news, medical, financial, legal); open conversational models vs. closed task models. Higher-stakes services demand fuller measures (source verification, currency checks, provenance labels).
  2. Technical cost — a provider need not deploy measures the industry cannot yet deliver or can deliver only at prohibitive cost. Cheap, effective measures (a pop-up warning that output “may be inaccurate — verify with a professional”) should be universal; expensive ones (large human-review teams, full-chain traceability, cross-modal deepfake detection, mass retraining) are not required of everyone.
  3. Rank of the interest at stake — the higher the civil interest (life and health above reputation, privacy, likeness, or personal-information interests), the stronger the measures required.
  4. User type — heightened duties toward minors, the elderly, and people with disabilities (echoed in the minors’-mode requirements of the AI Anthropomorphic Interaction Measures).
  5. Paid vs. free — a provider profiting from the service can be held to a stricter standard than one offering it gratis.

Where courts have gone wrong

Cheng’s sharpest practitioner signal is his critique of two rulings that found fault on duties whose protective purpose did not reach the plaintiff’s harm — a copyright case in particular:

  • A risk-warning “duty” (prompting users not to infringe others’ copyright) is not actually imposed by any rule, and the duty not to infringe copyright binds every user regardless of any warning. A provider’s failure to warn has no causal link to the user’s later infringement — so it cannot be fault.
  • The content-labeling duty (Art. 12 of the Interim Measures; the Deep Synthesis Provisions) exists to stop the public from being misled by AI output that looks real — protecting users against inaccurate information, not protecting copyright holders against infringement. A copyright owner is outside that duty’s protected class, and copyright is outside its protected scope. Failing to label may draw an administrative penalty, but it is not tortious fault vis-à-vis the copyright owner. Cheng approvingly cites a Hangzhou Internet Court decision that read the labeling duty exactly this way — as a warning duty owed to users about the service’s limitations.

AI standards concretize the reasonable person — but don’t decide fault

Recommended national standards (GB/T) and industry standards for AI are, with narrow exceptions, not legally binding and cannot themselves create statutory duties. What they do — GB/T 45654-2025 on generative-AI service security, the GB/T 45288 large-model series, and others — is supply concrete technical methods that flesh out what a “reasonable provider” would do, and they update far faster than legislation. But because fault is always assessed case-by-case against the reasonable-person standard, a court may treat a standard as evidence, not a switch: compliance is not automatic no-fault, and non-compliance is not automatic fault.

The takeaway for overseas counsel

A Chinese regulator can penalize a generative-AI provider for breaching any of the Interim Measures’ obligations. Civil damages are a narrower gate. Before assuming a rule breach translates into tort exposure, ask Cheng’s questions: Is this an affirmative duty, or merely a restatement of “don’t infringe”? Does the duty aim to protect this plaintiff and this interest? Is it an obligation of result (did we do the discrete act?) or of means (did we take reasonable, cost-appropriate measures for this service, this interest, and this user)? Get those right and the provider’s real litigation surface is far smaller — and far more manageable — than the raw list of ten duties suggests.

Structured summary of an article by Cheng Xiao (程啸), Tsinghua University School of Law, in Political Science and Law Tribune (《政法论丛》) 2026 No. 4, reposted via WeChat. — Not legal advice.

— Not legal advice.


§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →