AI law comparison · Data verified 2026-08-22
China AIGC Measures vs China Data Security Law
China AIGC Measures and China Data Security Law are two of the 169 AI and data regulations Aegis Firma tracks. They have different scopes, effective dates, and penalties — and many businesses fall under both. Here is the side-by-side, drawn directly from the regulatory registry.
Find which laws apply to my businessSide by side
Summary of publicly available regulatory text. Verify against current official sources before relying on this for compliance decisions. Not legal advice.
The key difference
China Data Security Law takes effect first, so it is usually the more urgent of the two. China AIGC Measures tracks 5 compliance requirements and China Data Security Law tracks 4. They are not interchangeable — meeting one does not discharge the other. The practical question is not which law is “stricter,” but which of them — or both — actually applies to your business.
China Interim Measures for Generative AI Services (AIGC)
China's Interim Measures for the Management of Generative Artificial Intelligence Services (issued by CAC and six agencies, effective August 15, 2023) applies to any organization providing generative AI services to the general public within China — including overseas companies with users in China. Requirements cover training data legitimacy, content accuracy, security assessments, algorithm registration (for services…
Full China AIGC Measures requirementsChina Data Security Law (DSL)
China's Data Security Law (DSL, effective September 1, 2021) establishes a data classification and tiered protection system based on data's importance to national security and economic development. DSL applies to all data processing activities within China and extraterritorially when data processing outside China "harms China's national security, public interests, or the lawful rights and interests of Chinese citizen…
Full China Data Security Law requirementsCommon questions
Could both China AIGC Measures and China Data Security Law apply to my business?
Yes. China AIGC Measures and China Data Security Law are separate regulations with separate scopes — a business can fall under both at once. China AIGC Measures covers Applies to organizations providing generative AI services to the "general public within China" — this includes both Chinese-registered entities and overseas com… China Data Security Law covers DSL applies to: (1) data processing activities within China; (2) data processing activities outside China that harm China's national security, public interests,… If your operations meet both scopes, you must comply with both. Aegis Firma's free scan checks all 169 tracked regulations against your business profile so you do not have to read each law to find out.
Which has the higher maximum penalty — China AIGC Measures or China Data Security Law?
China AIGC Measures: Service suspension; fines under Cybersecurity Law (up to ¥1,000,000) and PIPL (up to ¥50,000,000 or 5% revenue) China Data Security Law: ¥2,000,000–¥10,000,000 (general violations); ¥5,000,000–¥50,000,000 (important data violations); service suspension; individual liability Penalty structures differ by regulator and violation type — read each law's full page for the cure periods and per-violation detail.
When does each law take effect?
China AIGC Measures — effective 2023-08-15. China Data Security Law — effective 2021-09-01. Dates last verified against official sources on 2026-08-22 and 2026-08-22 respectively.
Related comparisons
Stop guessing which laws apply
Answer a short questionnaire about your business and Aegis Firma tells you exactly which of 169 regulations apply — and what each one requires you to do.
Start free compliance scan