| Issuing framework | The proposal was released by the CAC for public consultation. | The final measures were jointly issued by the CAC, NDRC, MIIT, Ministry of Public Security and SAMR. | ~ Modified | Compliance ownership extends across a multi-authority governance framework. | Compare the publication announcements.Effective: 2026-07-15Previous sourceCurrent source |
| Lifecycle governance | The draft required provider safety-management systems and safeguards. | The final text expressly requires safety responsibilities across deployment, operation, upgrade and termination, together with monitoring, risk assessment and log retention. | i Clarified | Product governance should cover the complete service lifecycle rather than launch review alone. | Final Articles 9-10.Effective: 2026-07-15Current source |
| Minors | The draft addressed guardian consent, minors' data and protective settings. | The final rule expressly prohibits virtual-relative and virtual-partner services for minors and requires guardian consent before other services are provided to children under 14. | ~ Modified | Age assurance, mode switching and service restrictions need to be implemented together. | Final Article 14.Effective: 2026-07-15Current source |
| User data controls | The draft required a deletion option for historical interaction data. | The final text expressly provides both copying and deletion options and restricts third-party provision of interaction data absent a legal basis or clear consent. | ~ Modified | User-facing data controls should support export as well as deletion. | Final Article 16.Effective: 2026-07-15Current source |
| Legal status and penalties | The consultation draft contained no fixed commencement date. | The final rule took effect on 15 July 2026 and includes an operative enforcement and penalty provision. | + Added | The obligations now have a fixed implementation date and enforceable consequence framework. | Final Articles 30 and 32.Effective: 2026-07-15Current source |