China's AI Safety Governance Framework (Versions 1.0–3.0)

A voluntary, standards-body framework issued by China's national cybersecurity standardization committee that sets risk-classification and technical guidance for AI development — now in its third annual iteration as of September 2026.

Created 2026-09-15 Last reviewed 2026-09-15

What it is

The AI Safety Governance Framework is a non-binding technical standard issued by China’s National Cybersecurity Standardization Technical Committee (known by its working shorthand, TC260), under the guidance of the Cyberspace Administration of China (CAC). It is not a law. It carries no penalties of its own. Instead it functions as a reference document — a shared vocabulary and risk taxonomy that regulators, standards bodies, and companies can draw on when writing binding rules or internal compliance programs elsewhere in China’s AI governance stack, which includes the Data Security Law, the Personal Information Protection Law, and CAC’s generative-AI service rules.

The framework classifies AI risks (bias, misuse, loss of control, data leakage, and similar categories), assigns them into tiers, and pairs each tier with recommended technical and governance countermeasures — spanning the AI lifecycle from data collection and model training through deployment and monitoring. It was first released on 9 September 2024. TC260 has since revised it annually: version 2.0 arrived on 15 September 2025, and version 3.0 was unveiled on 14 September 2026, each launch timed to coincide with China’s National Cybersecurity Publicity Week. Development of the later versions drew on a wider set of contributors, including the China Internet Development Research Institute, the National Computer Network Emergency Response Technical Team, and the Chinese Cyberspace Security Association, alongside research institutes and industry firms.

Each revision has kept the same underlying logic — risk classification, technical response, comprehensive governance — while updating the risk categories and countermeasures to track how the technology itself has moved: version 2.0 shifted from stakeholder-specific guidance toward a full lifecycle view of AI systems; version 3.0, released one day before the observatory’s editorial referenced it, updates risk classifications again to address what CAC’s announcement called “emerging AI development trends and novel security governance challenges” — language read by outside observers as encompassing more autonomous, agentic AI systems.

Why it matters for AI governance and narratives

The framework sits at the center of a framing contest the observatory tracks closely: whether AI safety governance is a genuine technical undertaking or an instrument of strategic communication. Beijing’s own state media frames the annual reissue as evidence of a serious, iterating domestic safety program — proof that China is not merely reacting to Western AI-safety discourse but building parallel institutional infrastructure. External critics, and the framework’s own non-binding status, complicate that reading: because TC260 standards are voluntary reference documents rather than enforceable law, the actual behavioral bite of any given version is difficult to verify from the document alone, and Chinese authorities have simultaneously used AI-safety rhetoric abroad to characterize US export controls and containment measures as protectionism dressed in safety language. That is the tension the editorial gestured at — safety governance functioning as both a genuine domestic program and a rhetorical position in the US-China contest over who gets to define responsible AI. Tracking whether the framework’s technical content changes in ways that map onto real product or deployment behavior — versus changing mainly in emphasis and vocabulary — is the empirical test of which reading holds.

Key facts and dates

Where to learn more

Sources

Official Cyberspace Administration of China (CAC) announcement of version 2.0; primary government source
State news agency report on the version 3.0 release, dated one day before the editorial's reference to it; primary contemporaneous source
Independent compliance/legal analysis explaining TC260's role and the framework's structure and scope
European standards-monitoring body's analysis of the 1.0-to-2.0 revision, useful for tracking the iteration pattern
Referenced in: Editorial No. 321