On August 24, 2026, the National Technical Committee 260 on Cybersecurity of SAC (TC260) released a key technical guidance document: Cybersecurity Standard Practice Guide — Security Guide for Individual Users of AI Services (TC260-PG-20267A).
While titled as a guide for individual users, this document is equally crucial for AI service developers, technology providers, and operators compliance-wise. It reflects China’s ongoing efforts to standardise AI security, data privacy, and ethical compliance.
Key highlights from the new guidelines include:
🔹 Regulatory Alignment & Filing Requirements: Individual users are advised to use Generative AI services that have officially completed the required Generative AI Service Filing and avoid unauthorized proxies or unknown third-party relay stations.
🔹 Data Minimization & Opt-Out Mechanisms: Users are urged to carefully inspect Privacy Policies to verify whether their input data is being used for model training and ensure mechanisms exist to withdraw consent.
🔹 Watermarking & Content Labeling: In alignment with mandatory rules (such as GB 45438-2025), users are instructed not to tamper with or remove AI-generated content watermarks/labels.
🔹 Risk Boundary & Professional Liability: AI outputs in sensitive sectors—such as legal, medical, financial, employment, and education—are explicitly defined as reference-only and must be independently verified.
🔹 Intellectual Property & Identity Protection: Clear behavioral standards prohibit using AI to impersonate others, generate illegal/harmful content, or replicate protected IP (such as artworks, code, text, or music).
💡 Key Takeaway for Businesses: If you operate or deploy AI services/agents targeted at users in China, ensure your compliance architecture aligns with these operational guidelines—particularly regarding user data opt-outs, clear privacy disclaimers, robust watermarking mechanisms, and mandatory AI service filings.
📄 Official Document Reference: TC260-PG-20267A (August 2026)


