What it is
The AI Safety Governance Framework is a non-binding technical standard issued by China’s National Cybersecurity Standardization Technical Committee (known by its working shorthand, TC260), under the guidance of the Cyberspace Administration of China (CAC). It is not a law. It carries no penalties of its own. Instead it functions as a reference document — a shared vocabulary and risk taxonomy that regulators, standards bodies, and companies can draw on when writing binding rules or internal compliance programs elsewhere in China’s AI governance stack, which includes the Data Security Law, the Personal Information Protection Law, and CAC’s generative-AI service rules.
The framework classifies AI risks (bias, misuse, loss of control, data leakage, and similar categories), assigns them into tiers, and pairs each tier with recommended technical and governance countermeasures — spanning the AI lifecycle from data collection and model training through deployment and monitoring. It was first released on 9 September 2024. TC260 has since revised it annually: version 2.0 arrived on 15 September 2025, and version 3.0 was unveiled on 14 September 2026, each launch timed to coincide with China’s National Cybersecurity Publicity Week. Development of the later versions drew on a wider set of contributors, including the China Internet Development Research Institute, the National Computer Network Emergency Response Technical Team, and the Chinese Cyberspace Security Association, alongside research institutes and industry firms.
Each revision has kept the same underlying logic — risk classification, technical response, comprehensive governance — while updating the risk categories and countermeasures to track how the technology itself has moved: version 2.0 shifted from stakeholder-specific guidance toward a full lifecycle view of AI systems; version 3.0, released one day before the observatory’s editorial referenced it, updates risk classifications again to address what CAC’s announcement called “emerging AI development trends and novel security governance challenges” — language read by outside observers as encompassing more autonomous, agentic AI systems.
Why it matters for AI governance and narratives
The framework sits at the center of a framing contest the observatory tracks closely: whether AI safety governance is a genuine technical undertaking or an instrument of strategic communication. Beijing’s own state media frames the annual reissue as evidence of a serious, iterating domestic safety program — proof that China is not merely reacting to Western AI-safety discourse but building parallel institutional infrastructure. External critics, and the framework’s own non-binding status, complicate that reading: because TC260 standards are voluntary reference documents rather than enforceable law, the actual behavioral bite of any given version is difficult to verify from the document alone, and Chinese authorities have simultaneously used AI-safety rhetoric abroad to characterize US export controls and containment measures as protectionism dressed in safety language. That is the tension the editorial gestured at — safety governance functioning as both a genuine domestic program and a rhetorical position in the US-China contest over who gets to define responsible AI. Tracking whether the framework’s technical content changes in ways that map onto real product or deployment behavior — versus changing mainly in emphasis and vocabulary — is the empirical test of which reading holds.
Key facts and dates
- 9 September 2024 — Version 1.0 released by TC260, providing initial stakeholder-specific safety guidelines across the AI lifecycle.
- 15 September 2025 — Version 2.0 released during National Cybersecurity Publicity Week, led by the National Internet Emergency Center; restructured guidance around a full lifecycle perspective with more granular technical recommendations, and introduced risk-stratification research.
- 14 September 2026 — Version 3.0 released at the opening of the 2026 National Cybersecurity Publicity Week, developed under CAC guidance with a broader set of research and industry contributors; updates risk classifications and governance measures again, framed around “people-first” and “risk awareness with safety and control” principles, and explicitly linked to China’s Global AI Governance Initiative.
- The framework is voluntary and non-binding; its influence operates through its role as a reference standard for other, enforceable Chinese AI and data regulations rather than through direct legal force.
Where to learn more
- CAC.gov.cn: 《人工智能安全治理框架》2.0版发布 — the official Cyberspace Administration of China announcement of version 2.0.
- Xinhua: 《人工智能安全治理框架3.0》发布 — the state-media announcement of version 3.0, including contributing organizations.
- OneTrust: China’s TC260 Releases AI Safety Governance Framework — independent legal/compliance analysis of the original framework’s structure and its relationship to China’s broader data and AI law regime.
- SESEC: TC260 Published AI Safety Governance Framework 2.0 — European standards-watch analysis of what changed between versions 1.0 and 2.0.