China Releases Draft Standard on AI Application Security Classification and Grading
China has released a draft national standard setting out methods for classifying and grading the security of AI applications. We explain what the draft contains, how it fits into China’s rapidly expanding AI governance framework, and what companies deploying AI in China should do to prepare.
On July 15, 2026, the Secretariat of the National Cybersecurity Standardization Technical Committee (TC260) released an exposure draft of the national standard Cybersecurity Technology – Classification and Grading Methods for Artificial Intelligence Application Security (hereinafter, the “draft” or “draft standard”) for public comment. Comments can be submitted until September 13, 2027, an unusually long consultation window of 14 months, suggesting the committee anticipates substantial industry input as AI technologies continue to evolve.
The draft arrives at a moment of rapid expansion for China’s AI sector. According to data from the China Academy of Information and Communications Technology (CAICT), the core AI industry surpassed RMB 1 trillion (approx. US$140 billion) in scale in 2025, with over 5,300 active AI companies operating across the foundation, model, and application layers, and could reach RMB 1.4 trillion (approx. US$196 billion) by the end of 2026. Meanwhile, more than 700 generative AI models had been registered with the Cyberspace Administration of China (CAC) by the end of 2025, with a further 48 services added in March 2026 alone, while total algorithm filings under China’s various algorithm registration regimes have exceeded 6,000.
As adoption accelerates under the State Council’s “AI+” Initiative, regulators are moving to put in place a systematic methodology for sorting this fast-growing universe of applications by risk.
What does the draft standard propose?
The draft proposes methods for the classification and grading of AI application security, and is applicable to developers and operators of AI applications when carrying out classification and grading activities.
Classification: Three dimensions of risk
Classification identifies risk types from three aspects:
- Application scenario attributes: The context and sector in which the AI application is deployed, such as finance, healthcare, education, or public services;
- Application task attributes: With task types including content generation, decision support, and autonomous control; and
- Application intelligence capabilities: The degree of capability and autonomy of the AI system.
Grading: Five security levels
Grading is then based on a comprehensive assessment of the probability of risk occurrence and the severity of impact. The draft establishes five security levels – low, general, relatively serious, major, and extraordinarily major, with the overall level determined according to the principle of applying the highest and strictest applicable standard.
Five risk domains
An appendix sets out detailed lists of risks across five domains: cyber systems, information, the physical world, cognition and derivative risks, and ethics.
This taxonomy indicates that regulators are thinking well beyond conventional cybersecurity to encompass physical safety, cognitive influence, and ethical harms, mirroring the expanded risk categories in TC260’s AI Safety Governance Framework 2.0, released in September 2025, which notably added frontier concerns such as loss of control to the committee’s risk mapping.
How the draft fits into China’s AI governance framework
The draft should not be read in isolation. Since 2021, China has built up a layered body of AI-related rules through what has been described as a “regulatory chain” running from algorithmic recommendation and deep synthesis rules through to generative AI and, most recently, anthropomorphic interaction.
Within TC260’s own work programme, the draft follows the January 2026 practice guide setting out general principles for AI application security and the May 2026 ethics-focused companion guide, as well as the committee’s July 2026 calls for participants to draft sector-specific AI application security documents for finance, healthcare, and broadcasting.
Seen against this backdrop, the classification and grading draft supplies the missing connective tissue: a common methodology for sorting AI applications by risk, onto which sector-specific requirements (and, potentially, future binding obligations) can be attached. Notably, after China removed a comprehensive AI law from its 2025 legislative agenda in favour of an incremental approach built on pilots, standards, and targeted rules, standards such as this one are doing much of the heavy lifting in defining how AI risk is actually assessed in practice.
From recommended standard to de facto obligation
National standards of this type are generally recommended (marked “GB/T”) rather than mandatory. In practice, however, they frequently serve as the technical benchmark against which regulators assess compliance with binding legislation, including the Cybersecurity Law, the Data Security Law, the Personal Information Protection Law (PIPL), and the Interim Measures for the Management of Generative AI Services.
The stakes of non-compliance with the underlying legislation are considerable. Violations of the PIPL involving the mishandling of personal information can attract fines of up to RMB 50 million (approx. US$7 million) or five percent of the previous year’s turnover, while the amended Cybersecurity Law has increased penalties across data handling, prohibited content, and cross-border data transfer violations.
A tiered grading system may also lay the groundwork for future risk-based obligations, such as heightened filing, assessment, or licensing requirements for applications graded at the more serious levels, an approach that echoes the risk-based logic of the EU’s AI Act, albeit within China’s distinct regulatory architecture and with a broader conception of harm that extends to cognitive and ethical risks.
The commercial calculus for companies
Companies that understand the grading logic early can design products, deployment scopes, and human-oversight mechanisms around a target tier, potentially avoiding more costly obligations later. Retrofitting a live application to reduce its grade will be far more expensive.
Documentation will also be critical. Dynamic reassessment means classification will become an ongoing governance process rather than a one-off exercise. Building grading records, risk assessments, and reassessment triggers into AI operations now will reduce future compliance costs and support regulatory inspections, procurement reviews, and incident response.
Meanwhile, compliance itself is becoming a market. China’s algorithm and generative AI filing regimes have already created demand for specialised intermediaries, third-party filing and assessment services reportedly quoted at between RMB 15,000 and RMB 80,000 (approx. US$2,000–11,000) per generative AI filing. A finalised grading standard could further expand opportunities in testing, certification, and assurance services.
Multinationals may be able to reuse parts of their EU AI Act compliance infrastructure, including risk registers, impact assessments, and monitoring systems. However, equivalence should not be assumed: China’s five-domain taxonomy, emphasis on cognitive and ethical harms, and content governance requirements differ significantly from the EU framework.
The standard is also likely to appear in procurement requirements. State-owned enterprises and regulated sectors may include conformity in tenders before it becomes legally mandatory, turning early alignment into a commercial advantage.
Key takeaways
Companies developing or deploying AI applications in China should review the draft text, map their systems against the proposed classification and grading framework, and assess how design and deployment choices affect their likely tier.
Embedding risk assessment and documentation processes into AI operations today, and engaging with the consultation before the September 13, 2027 deadline, will lower the cost of compliance once the standard, and any binding obligations built on top of it, take effect.
How Dezan Shira & Associates can help
Dezan Shira & Associates can help foreign investors and technology companies assess how China’s evolving AI rules may affect product design, data compliance, risk grading, and internal governance.
Our teams support regulatory mapping, cybersecurity reviews, risk-assessment frameworks, and alignment with regional or global compliance systems. Contact our local advisors to discuss how the proposed framework may affect your operations.
Our Business Advisory service helps companies navigate China’s complex business landscape from initial market entry to ongoing expansion. We advise on corporate structuring, company setup, due diligence, legal contracts, intellectual property, and M&A transactions. Clients benefit from both standalone projects and integrated support from our in-house tax, audit, HR, and technology teams.
About Us
China Briefing is one of five regional Asia Briefing publications. It is supported by Dezan Shira & Associates, a pan-Asia, multi-disciplinary professional services firm that assists foreign investors throughout Asia, including through offices in Beijing, Tianjin, Dalian, Qingdao, Shanghai, Hangzhou, Ningbo, Suzhou, Guangzhou, Haikou, Zhongshan, Shenzhen, and Hong Kong in China. Dezan Shira & Associates also maintains offices or has alliance partners assisting foreign investors in Vietnam, Indonesia, Singapore, India, Malaysia, Mongolia, Dubai (UAE), Japan, South Korea, Nepal, The Philippines, Sri Lanka, Thailand, Italy, Germany, Bangladesh, Australia, United States, and United Kingdom and Ireland.
For a complimentary subscription to China Briefing’s content products, please click here. For support with establishing a business in China or for assistance in analyzing and entering markets, please contact the firm at china@dezshira.com or visit our website at www.dezshira.com.
- Previous Article EU-China Relations After the 2024 European Elections: A Timeline
- Next Article






