China: 1,112 registered AI services and a new security framework 3.0
By 31 August, China's regulator had registered 1,112 generative AI services and 731 applications. Four days before it published those figures, the authority announced the third version of its AI security framework.

China's oversight of generative artificial intelligence rests on registration, not prohibition. On 14 September, the Cyberspace Administration of China (CAC) published an updated list of services that have completed the registration procedure. The latest batch of filings includes seven generative AI services that run locally on phones. Another 133 applications or features were registered through the authority's local branches.
Scale: 1,112 services and 731 applications
According to the notice, by 31 August 2026 a total of 1,112 generative AI services had been registered, along with 731 applications or features that use them. The regulator draws a line between two levels: the model that provides access through an API, and the end product that calls that model. The second distinction matters, because applications are what reach the user.
Registration comes with a duty to disclose. Chinese rules require a working application to state, in a visible place or in the product description, which registered service it uses, together with the model name and the registration or filing number. Services that shape opinion or mobilise users must go through the procedure via the authority's local branch.
Framework 3.0: continuity, not revolution
On 14 September, at the opening of the national cybersecurity week, the National Technical Committee for Network Security Standardisation published the third version of the "Framework for the Secure Management of Artificial Intelligence". The document was drawn up under CAC supervision, with the Chinese Academy of Cyberspace Studies, research institutions and companies taking part. Earlier versions appeared in 2024 and 2025.
The framework keeps the same logic: risk classification, technical response, comprehensive management. The new version updates the risk taxonomy and refines the measures. It is best read as part of China's offer in technology diplomacy, since the document refers directly to the Global Initiative for AI Governance.
A separate signal comes from academia. During a debate on 24 September, Liu Yuanchun, rector of Shanghai University of Finance and Economics, argued that AI is a "superclass technology" and that the control point over it must move much earlier, before the effects become irreversible. He recalled an open letter of 13 July signed by nearly 200 researchers and entrepreneurs, among them 16 Nobel laureates, and research by economist Daren Acemoglu on AI's impact on the labour market and inequality. China's debate about regulation is therefore not only a matter of content control. Increasingly, it concerns the distribution of profits and jobs.
The CAC notice goes beyond statistics. Administrators of applications with generative AI features must display the model name and the service's registration number in a visible place, so that users know which system they are working on and whether the provider has completed the formalities. This is the opposite of the European Union's approach: Brussels presses mainly for content labelling, while Beijing first tidies up the catalogue of providers and models.
Framework 3.0 did not appear in a vacuum. Version 1.0 was announced in 2024, 2.0 a year later, and the third instalment adds a three-layer logic to the earlier assumptions: risk classification, technical response, and management split among the regulator, industry and academia. The document was prepared under CAC direction within the national cybersecurity standardisation committee, as a contribution to the Global Initiative for AI Governance launched by China.
Sources
3All figures and quotations in this text come from the sources listed below.
Content prepared by the editorial team with AI assistance.
Comments
0- No comments yet — be the first.