Veeam Completes Acquisition of Securiti AI to Create the Industry’s First Trusted Data Platform for Accelerating Safe AI at Scale

View

How Will China’s Generative AI Regulations Shape the Future?

Contributors

Anas Baig

Product Marketing Manager at Securiti

Muhammad Faisal Sattar

Director of Product Legal & Global Data Compliance

FIP, CIPT, CIPM, CIPP/Asia

Published October 16, 2023

Listen to the content

Generative AI remains a highly dynamic phenomenon. OpenAI's CEO, Sam Altman, has been fairly transparent about his views on AI and how little his team understands the technology they're dealing with.

However, he has been absolute on one surprising aspect related to AI: regulation. In his now high-profile testimony before the US Senate, Altman called for strict and thorough regulation of the technology, a belief he repeated in South Korea as part of his AI regulation world tour.

Few countries have been as proactive as China in regulating Generative AI.

Now more than ever, these regulations, discussed in greater detail below, have begun to have a noticeable impact on China's leadership in AI development. This impact will become increasingly seismic in the coming months and years.

Understanding how these regulations are poised to affect China's future will aid tremendously in gaining vital foresight into the future of technology and its place within the world in general.

China's AI Regulations: A Brief Overview

In April, the Cyberspace Administration of China released a draft, "Measures for Generative Artificial Intelligence Services." The interim measures were meant to manage the use of AI services like OpenAI's ChatGPT.

More importantly, the measures aimed to lay the groundwork for future regulation of generative AI products and services in addition to how they would operate in China in tandem with several pre-existing regulations.

The Chinese Regulatory Approach

China has gained plaudits for a highly proactive approach to AI regulations. While the country does not yet have dedicated central legislation related to the use of AI, there has been no shortage of official guides, outlines, roadmaps, and initiatives launched to ensure the AI sector continues to thrive while being managed responsibly.

Official releases such as Made in China 2025, the Next Generation Artificial Intelligence Development Plan of 2017, Action Outline for Promoting the Development of Big Data (2015), Deep Synthesis Provisions, and Administrative Provisions on Recommendation Algorithms in Internet-based Information Services ensure that the development, use, and deployment of any AI-related tech within China's is governed within the confines of properly defined ethics and considerations.

The aforementioned guides are used in tandem with China's three data-related regulations, including the Cybersecurity Law (CSL), Data Security Law (DSL), and Personal Information Protection Law (PIPL).

Moreover, separate provincial regulations for specific regions, such as the Shanghai and Shenzhen Regulations, deal with AI-related matters on a more specific and municipal level.

As a result, not only can China boast of a highly structured and methodical regulatory infrastructure in place to curate the use and development of AI technology within its borders, but it can also make targeted amendments within these regulations dependent on the needs to ensure regulations do not impede innovation at any juncture.

Impact on Local Tech Companies

Owing to the sheer size of the Chinese economy, any regulatory decision in Beijing has a ripple effect on the rest of the world economy and the business world in general. However, its most immediate effect is almost always on the local tech companies.

This was the case when the initial draft measures were released in April. Considered by some as overly strict, it followed a pattern of CAC ensuring the presence of thorough and comprehensive mechanisms that would allow the central government a deeper insight into how various organizations were developing different AI products and services.

Other requirements included standards to ensure the training data and the output generated were of adequate accuracy and strict emphasis on using legitimate data sources.

However, the latest draft measures (AI Measures) offer critical leeway to organizations developing AI services, with only organizations offering their services directly to the public being subject to these requirements.

Economic Growth & Productivity

Similar to the rest of the world, Chinese tech companies have been busy burning the midnight oil in undertaking several ventures that could give them the lead in the global AI market.

Traditional giants such as Baidu and the Alibaba Group have seen record investments over the last couple of months, with dozens of AI models and algorithms being developed in the wake of ChatGPT's monumental success since the start of 2023.

However, despite the presence of both investment and products at various stages of development, most tech companies in China have held back from introducing their products to the wider public.

The recent announcement of the finalized version of the draft measures introduced in April has been cited as the primary reason. Most organizations developing AI products and services have adopted a wait-and-see approach before releasing their products to ensure they stay within legal requirements.

Additionally, tech companies within the B2B sector have focused on expanding the industrial applications of their products, with JD becoming the latest name to join the list with its ChatRhino model.

Balancing Innovation & Regulation

In this particular regard, China faces the same fundamental issue as the rest of the world: how best to balance innovation and regulation.

As elaborated earlier, the AI Measures provide some much-needed "breathing room" for tech companies within the AI sector, as these measures will only apply to content created or generated for the public.

Crucially, the AI Measures exempt research institutions and services developed exclusively for overseas users. This allows Chinese tech companies with greater incentives to collaborate with international partners and expand their services globally without fear of backlash at home.

China's regulatory reputation has been intensely debated over the years. Many point to the strict censorship of the Internet, social media, and the overall flow of information as detrimental to technological innovation.

However, regulators in the country have adopted a more nuanced approach to AI regulation, with the AI Measures emphasizing the need to balance "development and security."

To this end and to protect data subjects, the AI Measures bind generative AI service providers to comply with network information security and personal data protection obligations. The measures also direct to ensure the safety of vulnerable groups, i.e., minors, by preventing overreliance or addiction to generative AI.

The requirement of generative AI products to undergo a security assessment before their availability for use shows the extra due diligence put in place for the safety of the users. Additionally, seven national agencies will oversee the implementation of the AI Measures, including the National Development and Reform Commission and the Ministry of Education, signaling the degree of importance China has placed on effectively handling AI regulations.

The AI Measures also address the potential risk of generative AI using existing work of original creators, directing service providers to respect and not infringe upon the intellectual property rights granted by the law. Organizations are also required to take effective measures to improve the transparency, accuracy, and reliability of the content generated using AI.

What The Future Holds

In many ways, China's regulatory actions related to Generative AI starkly contrast its previous record. The regulatory bodies clearly see the potential AI represents for China as well as China's own strengths within the field.

No country can match China regarding AI-related academic papers, patents, investments, and funding raised. More importantly, China's overall AI investments are expected to cross the $26 billion mark within three years, with the country forecasted to account for almost 10% of global AI investments.

Needless to say, China has a strong case to be the world leader in the AI industry. The establishment of the Shanghai and Shenzhen Innovation Zones, in addition to exclusive regulations for these regions, indicates the resources China is willing to dedicate towards its ambitions of global AI leadership with complete self-sufficiency.

How Securiti Can Help

Generative AI presents a unique opportunity for businesses globally. At the same time, owing to the collective lack of understanding related to its potential, it can cause severe data compliance issues for organizations.

Organizations in China will find themselves facing a similar conundrum. As proactiveness within AI adoption has enabled China to press its claim as the global leader in AI, a similar approach toward regulatory compliance will be necessary.

Securiti, a leader in providing enterprise data privacy, security, compliance, and governance solutions, has various dedicated modules and products to help organizations meet any regulatory obligations they may be subject to, specifically ones where organizations may be required to undertake special measures related to user data in the context of generative AI.

A global leader in providing enterprise data privacy, security, compliance, and governance solutions, Securiti Data Command Center enables organizations to optimize their oversight and compliance with China's extensive AI and data regulatory regulations.

As a result, organizations can identify and respond to any irregularities within their compliance protocols proactively while minimizing any chance of regulatory violations or neglect.

Request a demo today and learn more about how Securiti can help your organization achieve regulatory compliance with AI regulations in China today.

Analyze this article with AI

Prompts open in third-party AI tools.
Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox



More Stories that May Interest You
Videos
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...
AWS Startup Showcase Cybersecurity Governance With Generative AI View More
AWS Startup Showcase Cybersecurity Governance With Generative AI
Balancing Innovation and Governance with Generative AI Generative AI has the potential to disrupt all aspects of business, with powerful new capabilities. However, with...

Spotlight Talks

Spotlight 50:52
From Data to Deployment: Safeguarding Enterprise AI with Security and Governance
Watch Now View
Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Spotlight 12:!3
You Can’t Build Pipelines, Warehouses, or AI Platforms Without Business Knowledge
Watch Now View
Spotlight 47:42
Cybersecurity – Where Leaders are Buying, Building, and Partnering
Rehan Jalil
Watch Now View
Spotlight 27:29
Building Safe AI with Databricks and Gencore
Rehan Jalil
Watch Now View
Spotlight 46:02
Building Safe Enterprise AI: A Practical Roadmap
Watch Now View
Latest
View More
DataAI Security: Why Healthcare Organizations Choose Securiti
Discover why healthcare organizations trust Securiti for Data & AI Security. Learn key blockers, five proven advantages, and what safe data innovation makes possible.
View More
The Anthropic Exploit: Welcome to the Era of AI Agent Attacks
Explore the first AI agent attack, why it changes everything, and how DataAI Security pillars like Intelligence, CommandGraph, and Firewalls protect sensitive data.
View More
Aligning Your AI Systems With GDPR: What You Need to Know
Securiti’s latest blog walks you through all the important information and guidance you need to ensure your AI systems are compliant with GDPR requirements.
Network Security: Definition, Challenges, & Best Practices View More
Network Security: Definition, Challenges, & Best Practices
Discover what network security is, how it works, types, benefits, and best practices. Learn why network security is core to having a strong data...
Australia’s Guidance for AI Adoption View More
Australia’s Guidance for AI Adoption
Access the whitepaper to learn about what businesses need to know about Australia’s Guidance for AI Adoption. Discover how Securiti helps ensure compliance.
Montana Privacy Amendment on Notices: What to Change by Oct 1 View More
Montana Privacy Amendment on Notices: What to Change by Oct 1
Download the whitepaper to learn about the Montana Privacy Amendment on Notices and what to change by Oct 1. Learn how Securiti helps.
View More
Solution Brief: Microsoft Purview + Securiti
Extend Microsoft Purview with Securiti to discover, classify, and reduce data & AI risk across hybrid environments with continuous monitoring and automated remediation. Learn...
Top 7 Data & AI Security Trends 2026 View More
Top 7 Data & AI Security Trends 2026
Discover the top 7 Data & AI security trends for 2026. Learn how to secure AI agents, govern data, manage risk, and scale AI...
View More
Navigating HITRUST: A Guide to Certification
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...
The DSPM Architect’s Handbook View More
The DSPM Architect’s Handbook: Building an Enterprise-Ready Data+AI Security Program
Get certified in DSPM. Learn to architect a DSPM solution, operationalize data and AI security, apply enterprise best practices, and enable secure AI adoption...
What's
New