{
  "$schema": "./schema.json",
  "id": "cn-ai-labelling",
  "name": {
    "en": "China Measures for Labelling AI-Generated Synthetic Content — AIO formalization",
    "ko": "중국 AI 생성합성 콘텐츠 표식판법 — AIO 정형화"
  },
  "sourceNorm": {
    "title": "人工智能生成合成内容标识办法 (Measures for Labelling AI-Generated Synthetic Content — unofficial English rendering; no official English text of these Measures exists)",
    "publisher": "国家互联网信息办公室 (Cyberspace Administration of China) jointly with 工业和信息化部 · 公安部 · 国家广播电视总局 — four departments in total",
    "version": "国信办通字〔2025〕2号 · signed 2025-03-07, published 2025-03-14, in force from 2025-09-01 · 14 articles · unamended as at 2026-08-14",
    "url": "https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm"
  },
  "vesMapping": [
    {
      "article": "第四条",
      "summary": "Article 4 — where the generative synthetic service a service provider offers falls within the circumstances of Article 17, first paragraph, of the Provisions on the Administration of Deep Synthesis of Internet Information Services, the provider must add an explicit label to the generated synthetic content in accordance with a per-modality list: for text, a textual prompt or a common-symbol prompt at the start, the end or an appropriate intermediate position, or a conspicuous prompt label in the interaction interface or around the text; for audio, a voice prompt or an audio-rhythm prompt at the start, the end or an appropriate intermediate position, or a conspicuous prompt label in the interaction interface; for images, a conspicuous prompt label at an appropriate position; for video, a conspicuous prompt label on the opening frame and at an appropriate position around the playback area, and optionally at the end and at appropriate intermediate positions; for a virtual scene, a conspicuous prompt label at an appropriate position on the opening frame, and optionally at appropriate positions during the continuing service; and for other generative synthetic service scenarios, a conspicuous prompt label adapted to the application's own characteristics. Where the provider offers download, copy or export functions for generated synthetic content, it must ensure that the file contains an explicit label meeting the requirements.",
      "v": [
        "Sdt"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "Adding a prompt at the start of a text stream, a marker on an opening video frame, or a label into an exported file is a pipeline capability, not a judgment made in a concrete case; an AIO 20002 record contributes nothing to discharging it. Two limits on what this entry establishes. First, the trigger condition is not in this instrument: who must label at all is fixed by 《互联网信息服务深度合成管理规定》第十七条第一款, a separate 2022 instrument that this pack does not formalize, so the population of duty-bearers is not determinable from this pack alone. Second, the article states no format parameters — the size, position, transparency and durability of an explicit label are fixed by the mandatory national standard GB 45438-2025 via 第十一条, and that standard is referred to here by number only and is never quoted. An operator reading 第四条 alone will underestimate what conformity actually requires.",
      "provenance": {
        "sourceUrl": "https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm",
        "article": "第四条 — 第一款 chapeau and points （一）, （三); 第二款",
        "quote": "第四条 服务提供者提供的生成合成服务属于《互联网信息服务深度合成管理规定》第十七条第一款情形的，应当按照下列要求对生成合成内容添加显式标识：（一）在文本的起始、末尾或者中间适当位置添加文字提示或者通用符号提示等标识，或者在交互场景界面、文字周边添加显著的提示标识；[…]（三）在图片的适当位置添加显著的提示标识；[…][第二款] 服务提供者提供生成合成内容下载、复制、导出等功能时，应当确保文件中含有满足要求的显式标识。",
        "rationale": "The operative verb is 应当按照下列要求…添加显式标识 — conformity to a prescribed written list is the thing that must prevail, which is Cor. What the labelling regime protects is stated by the instrument's own purpose clause, 第一条: 保护公民、法人和其他组织合法权益，维护社会公共利益 — the integrity of the shared information environment as a collective good, which is Ses; the route from this article to that interest runs through 第一条 and is coded from there rather than from an impression of the norm. Sdt is an INFERENCE and is flagged as such for the RFC round: an explicit label works by putting the person in front of the screen in a position to appraise the provenance of what they are seeing for themselves, rather than by deciding for them what to believe, which is self-direction of thought — but this article does not say so, and the reading is drawn from the structure of a disclosure duty (the same inference was flagged in the cn-genai-measures pack at 第十二条). On evidence, the six points are a written specification read as issued (Gui); the article names no metric, no threshold and no assessor of its own, and the measurable parameters that do exist — 标识大小、位置、透明度 — are supplied by GB 45438-2025 through 第十一条 and not by this text, so Dat is deliberately not asserted here. On sources, both the trigger condition and the requirement list are fixed by state instruments (Gov). The provider composes the label, but the article does not designate the provider's own material as authoritative for anything, so Ind is not assigned; no professional body appears anywhere in the article, so Pro is not assigned. ADJUDICATION 2026-08-14: E ([Gui]) and S ([Gov]) agreed exactly, and Gov survives the Wave 2 source-axis re-check because the article routes expressly through 《互联网信息服务深度合成管理规定》第十七条第一款 — a government norm named as decisive on which services must label at all, not a body named as a recipient. V narrows to [Sdt], the only code both passes reached: an explicit prompt or marker exists so that whoever meets the content can appraise its provenance for themselves. The divergent codes each rest on one pass — Cor and Ses on v0.1, Unc on the second pass, which reached the public-protection reading from 「明确提醒公众」 in the neighbouring article rather than from this one. The second pass expressly refused to code Ses from 第一条's 国家安全与社会公共利益 purpose clause on the ground that the purpose article is outside the quote, which is the same discipline §4 requires and which v0.1 did not observe here. obligationType stays organizational against the second pass's mixed, under the conservative rule.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E and S agreed exactly. V [Cor, Ses, Sdt] → [Sdt]; obligationType organizational retained against the second pass's mixed. Sdt survives because both passes reached it independently, which converts v0.1 note 10's flagged inference into a corroborated reading."
    },
    {
      "article": "第五条",
      "summary": "Article 5 — service providers must, in accordance with Article 16 of the Provisions on the Administration of Deep Synthesis of Internet Information Services, add an implicit label into the file metadata of generated synthetic content; the implicit label contains production-element information such as the attribute information of the generated synthetic content, the name or code of the service provider, and a content number. Providers are encouraged to add implicit labels in the form of digital watermarks and the like into the generated synthetic content. File metadata means descriptive information embedded into the file header in a specified encoding format, used to record the source, attributes, uses and other information content of the file.",
      "v": [
        "Bed"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Gov",
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "The provision that makes this instrument structurally different from the EU AI Act's Article 50 transparency duty: the label is required to be machine-readable and to carry the identity of whoever produced the content, so that a downstream platform can act on it under 第六条 without asking anyone. Nothing about it is a judgment. Two honest limits. The article splits its own force in two — 应当…添加隐式标识 into metadata is mandatory, while 鼓励…数字水印 (watermarking) is expressly only encouraged, so a pack user must not read a watermarking obligation into it. And metadata is the weakest carrier available: 文件元数据 is defined by the article itself as information embedded in the file header, which any re-encode, screenshot or re-upload strips. The regime's answer to that fragility is not in this article; it is the platform-side detection duty of 第六条(三) and the tamper prohibition of 第十条.",
      "provenance": {
        "sourceUrl": "https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm",
        "article": "第五条 第一款·第二款·第三款",
        "quote": "第五条 服务提供者应当按照《互联网信息服务深度合成管理规定》第十六条的规定，在生成合成内容的文件元数据中添加隐式标识，隐式标识包含生成合成内容属性信息、服务提供者名称或者编码、内容编号等制作要素信息。[第二款] 鼓励服务提供者在生成合成内容中添加数字水印等形式的隐式标识。[第三款] 文件元数据是指按照特定编码格式嵌入到文件头部的描述性信息，用于记录文件来源、属性、用途等信息内容。",
        "rationale": "应当按照《互联网信息服务深度合成管理规定》第十六条的规定 makes conformity to a named written instrument the operative demand (Cor). The interest served is the traceability of synthetic material circulating in the information environment — the metadata exists so that content can be tied back to its origin after it has left the provider — which is Ses. Bed is assigned as an INFERENCE flagged for the RFC round: the required element list includes 服务提供者名称或者编码 and 内容编号, so the provider must attach its own identity to what it produces and remain identifiable to whoever later inspects the file, which is the value of being a party that can be relied on and held to what it has made; the article states the element list but does not state that purpose, so the value is read from the composition of the list rather than from words of purpose. On evidence, what discharges the duty is the referred provision plus the enumerated element list, read as written (Gui). The article prescribes no test of whether a label survives transmission and names no measurement, so Dat is not asserted. On sources, the duty and its content are fixed by a state instrument (Gov), while the payload the metadata carries is the provider's own declaration of authorship, issued by the concerned industry actor itself (Ind). No professional body, standards body or affected person is designated in this article, so Pro, Pee, Tes and Usr are not assigned. ADJUDICATION 2026-08-14: E ([Gui]) and S ([Gov, Ind]) agreed exactly. Gov survives the source-axis re-check — the article mandates the implicit label by reference to 《互联网信息服务深度合成管理规定》第十六条 — and Ind is earned on the Ind limb, since the metadata carries 服务提供者名称或者编码, the provider's own self-issued attribution. V narrows to [Bed], which both passes reached from the same reading: the content is made traceable back to whoever produced it, which is the dependability value. Cor and Ses rest on v0.1 alone; the second pass considered and declined Unc on the ground that this article speaks only of attribution. obligationType stays organizational under the conservative rule.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E and S agreed exactly. V [Cor, Ses, Bed] → [Bed]; obligationType organizational retained against the second pass's mixed. Bed survives because both passes reached it independently, which converts v0.1 note 10's second flagged inference into a corroborated reading."
    },
    {
      "article": "第六条",
      "summary": "Article 6 — service providers that provide network information content dissemination services must take the following measures to regulate the dissemination of generated synthetic content: (1) verify whether the file metadata contains an implicit label, and where the file metadata expressly indicates generated synthetic content, add by an appropriate means a conspicuous prompt label around the published content expressly reminding the public that the content is generated synthetic content; (2) where no implicit label is verified in the file metadata but the user declares the content to be generated synthetic content, add by an appropriate means a conspicuous prompt label around the published content reminding the public that the content may be generated synthetic content; (3) where no implicit label is verified in the file metadata and the user has not declared the content to be generated synthetic content, but the dissemination service provider detects an explicit label or other traces of generation or synthesis, identify the content as suspected generated synthetic content and add by an appropriate means a conspicuous prompt label around the published content reminding the public that the content is suspected to be generated synthetic content; and (4) provide the necessary labelling functions and remind users to declare on their own initiative whether published content contains generated synthetic content. Where any of points (1) to (3) applies, the provider must add dissemination-element information such as the attribute information of the generated synthetic content, the name or code of the dissemination platform, and a content number into the file metadata.",
      "v": [
        "Unc",
        "Hum"
      ],
      "e": [
        "Gui",
        "Dat"
      ],
      "s": [
        "Ind",
        "Usr"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "The richest provision in the instrument and the one with a genuine judgment correlate. Point (3) requires the platform to reach a determination — 检测到显式标识或者其他生成合成痕迹的，识别为疑似生成合成内容 — on material that carries no metadata and no user declaration, which is a case-by-case appraisal an item can put in front of a model, and the graded outputs the article prescribes (属于 / 可能为 / 疑似) are a three-level confidence vocabulary rather than a binary. What no item reaches is the rest: the metadata verification pipeline, the labelling function of point (4), and the dissemination-element write-back in the final paragraph are all infrastructure. Note the asymmetry the article leaves open — 其他生成合成痕迹 (other traces of generation or synthesis) is undefined, no detection accuracy floor is stated, and no consequence is attached to a false positive, so an operator has no textual basis for setting a threshold and must document its own. Note also that this is the only entry in the pack whose duty-bearer is the dissemination platform rather than the generating provider; the two roles are separately defined and a single company frequently occupies both. EVIDENCE RANKING STATED IN THE TEXT (found independently by the blind second pass, preserved at adjudication): this is the only article in the pack that states an evidence ordering rather than a code set. Machine-verifiable metadata outranks a user declaration, and the required public wording changes with the rank — 属于 where the metadata is verified, 可能为 where only the user has declared, 疑似 where neither is present but traces are detected. A flat v/e/s array cannot carry that ordering; the finding is recorded here and put to the RFC round as a schema question (Wave 2 gap 21).",
      "provenance": {
        "sourceUrl": "https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm",
        "article": "第六条 第一款 chapeau and points （一）–（三）; 第二款",
        "quote": "第六条 提供网络信息内容传播服务的服务提供者应当采取下列措施，规范生成合成内容传播活动：（一）核验文件元数据中是否含有隐式标识，文件元数据明确标明为生成合成内容的，采取适当方式在发布内容周边添加显著的提示标识，明确提醒公众该内容属于生成合成内容；（二）文件元数据中未核验到隐式标识，但用户声明为生成合成内容的，采取适当方式在发布内容周边添加显著的提示标识，提醒公众该内容可能为生成合成内容；[…][第二款] 有前款第一项至第三项情形的，应当在文件元数据中添加生成合成内容属性信息、传播平台名称或者编码、内容编号等传播要素信息。",
        "rationale": "The article names its beneficiary four times over — 公众 — and the act it prescribes each time is 提醒公众, so what must prevail is the order and reliability of the shared information environment (Ses) together with the recipient's capacity to appraise what they are looking at for themselves (Sdt). Sdt is argued here from the words rather than inferred: 明确提醒公众该内容属于生成合成内容 informs the public and leaves the appraisal to them, and the graded wording 属于 / 可能为 / 疑似 calibrates the reader's own confidence rather than substituting a platform verdict for it. 应当采取下列措施 makes conformity to the prescribed menu operative (Cor). On evidence there are two limbs and both are in the text: the prescribed measure list read as issued (Gui), and the outcome of a technical determination over the file — 核验文件元数据中是否含有隐式标识 in point (1) and 检测到显式标识或者其他生成合成痕迹 in point (3) — which is not a document read as written but a measurement made on data (Dat). On sources this article is unique in the pack in designating three classes, each of them expressly. The measure menu is fixed by the state (Gov). Point (1) directs the platform to treat the upstream provider's embedded metadata as decisive — 文件元数据明确标明为生成合成内容的 triggers the strongest of the three labels — which is reliance on material issued by another industry actor (Ind). Point (2) makes 用户声明为生成合成内容 sufficient to trigger a labelling duty even where the metadata check found nothing, which designates the user's own declaration as an evidentially operative source (Usr). No professional body, no news source and no expert assessor appears, so Pro, New and Exp are not assigned. ADJUDICATION 2026-08-14: E ([Gui, Dat]) and obligationType (mixed) agreed exactly. V is resolved for the second pass's [Unc, Hum] rather than by intersection, because the intersection is empty and the second pass's codes are the ones grounded in words actually present: 公众 is named twice in the excerpt (Unc), and the article calibrates the required public wording to the strength of the evidence — verified metadata yields 「明确提醒公众该内容属于生成合成内容」 while an unverified user declaration yields only 「该内容可能为生成合成内容」, which is the catalogue's not-overstating value (Hum). v0.1's Ses, Sdt and Cor are structural readings of a labelling duty. S narrows to [Ind, Usr]: Usr was declared by both passes (the user's declaration is an admitted input), Ind is retained on the Ind limb since the dissemination platform is the party that verifies and labels, and Gov is dropped because this article routes through no other instrument.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E and obligationType agreed exactly. V [Ses, Sdt, Cor] → [Unc, Hum]: the two passes shared no value code and the second pass's reading is adopted whole as the one argued from words in the excerpt. S [Gov, Ind, Usr] → [Ind, Usr]. The graded-assertion finding is recorded in the note and carried to the RFC round as Wave 2 gap 21."
    },
    {
      "article": "第七条",
      "summary": "Article 7 — when reviewing an application for listing or launch, an internet application distribution platform must require the internet application service provider to explain whether it provides artificial intelligence generative synthetic services; and where the internet application service provider does provide such services, the distribution platform must verify its materials relating to the labelling of generated synthetic content.",
      "v": [
        "Cor",
        "Ses"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "An app-store gate, discharged by a review workflow and a document check. Nothing an item measures bears on whether it is met. It is carried in the pack because it is the provision that gives the labelling regime its practical enforcement leverage: distribution is conditioned on the labelling materials, so a service that has not implemented labelling does not reach users in the Chinese market regardless of whether any penalty is ever imposed under 第十三条. The article does not say what the 标识相关材料 must contain, nor what the distribution platform must do if the verification fails, nor whether it must re-verify on update; those are gaps an operator has to close with its own documented procedure rather than gaps this pack can fill. MEASUREMENT-SCOPE NOTICE (raised by the second pass as a scope flag, confirmed at adjudication): the duty-bearer of this article is the internet application distribution platform (互联网应用程序分发平台), not the generative synthetic service provider. No AIO 20002 record of a model can discharge it and no item can observe its performance. This pack asserts no measurement against this article, and if the pack is ever scored this entry belongs outside the denominator rather than counted as unmet.",
      "provenance": {
        "sourceUrl": "https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm",
        "article": "第七条",
        "quote": "第七条 互联网应用程序分发平台在应用程序上架或者上线审核时，应当要求互联网应用程序服务提供者说明是否提供人工智能生成合成服务。互联网应用程序服务提供者提供人工智能生成合成服务的，互联网应用程序分发平台应当核验其生成合成内容标识相关材料。",
        "rationale": "The article is procedural: 应当要求…说明 and 应当核验…相关材料 make completion of a prescribed gatekeeping formality the thing that must prevail (Cor). The interest served is the same one the instrument states in 第一条 — keeping unlabelled synthetic-content services out of the public application ecosystem protects the shared information environment (Ses). On evidence, what discharges the duty is documentary on both limbs: a written explanation from the app provider and the labelling materials, read as submitted (Gui). The article states no verification technique, no sampling rule, no pass criterion and no re-verification cycle, so Dat is not asserted. On sources, the duty is imposed by the state (Gov), and what the distribution platform is directed to obtain and check is the application service provider's own account of itself — material issued by the industry actor under review (Ind). No independent assessor, certification body or professional body is designated, so Pro is not assigned even though an app-store review is exactly the place one would expect to find it. ADJUDICATION 2026-08-14: V ([Cor, Ses]), E ([Gui]) and obligationType (organizational) agreed exactly across the two passes — the second pass flagged Ses as structural, but v0.1 reached it independently, so it survives. S narrows to [Ind]: the material the distribution platform checks is the app provider's own declaration and paperwork, which is the Ind limb, and Gov is dropped because the article routes through no government instrument and names no authority.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V, E and obligationType agreed exactly. S [Gov, Ind] → [Ind]. A measurement-scope notice is added: the duty-bearer here is the application distribution platform, which the second pass raised as a scope flag."
    },
    {
      "article": "第八条",
      "summary": "Article 8 — service providers must state clearly in the user service agreement the methods, styles and other specification content of generated synthetic content labelling, and must prompt users to read carefully and understand the relevant label-management requirements.",
      "v": [
        "Bed",
        "Sdt"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "Discharged by a clause in a contract, so no item reaches it. It is carried in the pack because it is the article an operator is most likely to implement in name only: a service agreement that says labelling is applied 依法 (in accordance with law) does not meet the words of the provision, which require the 方法 and 样式 — the actual method and appearance of the label — to be stated. The article is also the hinge on which 第九条 turns: the user obligations that 第九条 requires to be made clear before unlabelled content may be supplied live in the same agreement this article governs.",
      "provenance": {
        "sourceUrl": "https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm",
        "article": "第八条",
        "quote": "第八条 服务提供者应当在用户服务协议中明确说明生成合成内容标识的方法、样式等规范内容，并提示用户仔细阅读并理解相关的标识管理要求。",
        "rationale": "The article converts the labelling regime into a term of the bargain between provider and user — 应当在用户服务协议中明确说明 — which is the value of being a counterparty whose stated commitments are legible and can be relied on (Bed). 提示用户仔细阅读并理解 asks the provider to build the user's own understanding of the requirements rather than merely to bind them, which is self-direction of thought (Sdt); it is argued from 理解 in the text and not inferred. 应当…明确说明 is also a bare conformity command (Cor). On evidence the duty is discharged wholly by a document read as written — the service agreement (Gui); the article names no measurement, no comprehension test and no assessor. On sources, the agreement is drafted and issued by the provider itself (Ind), while 相关的标识管理要求 — the label-management requirements the user is to be brought to understand — are set by this instrument and by the mandatory national standard it invokes at 第十一条, both state-issued (Gov). The user is the addressee of the explanation, not a source the provider is directed to trust, so Usr is not assigned. ADJUDICATION 2026-08-14: E ([Gui]) and obligationType (organizational) agreed exactly. V narrows to the intersection [Bed, Sdt] — the service agreement must put the user in a position to understand the labelling regime (Sdt) as a standing term of the relationship (Bed) — while Cor rests on v0.1 alone. S narrows to [Ind]: the provider is the author of the 用户服务协议 the article requires, which is the Ind limb, and Gov is dropped as absent from the excerpt. The second pass left the layer empty, reasoning that the user is the addressee of the explanation and not a source relied on; that reasoning disposes of Usr, which neither pass declared, but it does not reach Ind, which the source-axis rule settles.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E and obligationType agreed exactly. V [Bed, Sdt, Cor] → [Bed, Sdt]; S [Ind, Gov] → [Ind]."
    },
    {
      "article": "第九条",
      "summary": "Article 9 — where a user applies to a service provider for generated synthetic content without an explicit label added, the service provider may supply generated synthetic content not containing an explicit label after clarifying the user's labelling obligations and use responsibilities through the user agreement, and must retain in accordance with law the relevant logs, including information on the party supplied, for not less than six months.",
      "v": [
        "Bed"
      ],
      "e": [
        "Gui",
        "Dat"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "The most operationally consequential provision for a model provider and the one carrying the instrument's only numeric threshold: 不少于六个月. Its judgment correlate is real and narrow — whether to supply output without an explicit label when a user asks for it, and on what conditions — and an item can present that as a concrete case. Read the permission precisely: 可以 is a permission, not a duty; nothing obliges a provider to offer unlabelled output at all, and the article's structure is a conditional relaxation of 第四条 in exchange for a documented transfer of the labelling obligation to the user plus a retained log. Three limits the text leaves open and this pack does not close: the relaxation is expressly confined to the 显式标识 of 第四条 and says nothing about suspending the implicit metadata label of 第五条, so a provider should not read it as authorising unlabelled-in-every-sense output; the six-month floor is a minimum with no stated maximum and no stated retention purpose, which sits against the data-minimisation duty of 生成式人工智能服务管理暂行办法 第十一条 that forbids unlawful retention of records identifying a user, a tension the two instruments do not resolve in their own text; and 提供对象信息 (information on the party supplied) is not defined, so what identifies a recipient sufficiently is the operator's own documented decision.",
      "provenance": {
        "sourceUrl": "https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm",
        "article": "第九条",
        "quote": "第九条 用户申请服务提供者提供没有添加显式标识的生成合成内容的，服务提供者可以在通过用户协议明确用户的标识义务和使用责任后，提供不含显式标识的生成合成内容，并依法留存提供对象信息等相关日志不少于六个月。",
        "rationale": "The article permits a gap in the visible labelling of content that will circulate publicly, and the price it sets — a retained log identifying who received the unlabelled material — exists so that the content remains traceable notwithstanding the gap, which is the order of the information environment (Ses). 明确用户的标识义务和使用责任 relocates a stated obligation onto a named counterparty through a written agreement, making the value at stake the dependability of parties to their stated obligations (Bed), and 依法留存 is a bare conformity command (Cor). On evidence both limbs are in the words. The condition is discharged by the user agreement read as written (Gui). The retention duty is discharged by an operational record measured against a stated quantity — 相关日志不少于六个月 — which is the one place in this instrument where a threshold, rather than a written rule, is what a check would be run against (Dat); this is read from the text and not inferred. On sources, the agreement that carries the transfer is the provider's own instrument (Ind), and 依法 fixes the state as the authority both the transfer and the retention answer to (Gov). The user here is the applicant and the counterparty on whom the obligation is placed, not a source the provider is directed to trust, so Usr is not assigned; the article names no recipient for the log and no inspecting body, so no further source class is asserted. ADJUDICATION 2026-08-14: E ([Gui, Dat]) and obligationType (mixed) agreed exactly, and both passes recorded the same discomfort with Dat — a six-month log is a retained record body, not a body of measured numbers, which is Wave 2 gap 12 in a third instrument. V narrows to [Bed], the only shared code: the retained log and the agreed allocation of the labelling obligation are commitments that must be kept. The divergence is instructive and is recorded rather than resolved: v0.1 read the article as protecting collective order and rule-compliance (Ses, Cor), the second pass as making room for the user's freedom to obtain unlabelled output (Sda). S narrows to [Ind]: the provider supplies the content and retains the log, which is the Ind limb; the second pass's Usr is not carried, since the user's undertaking is the condition of the permission rather than a source relied on, and Gov is dropped because 依法 is a general reference to law and names no decisive authority on the substance.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E and obligationType agreed exactly. V [Ses, Bed, Cor] → [Bed]; S [Ind, Gov] → [Ind]. The second pass's Sda for the user's freedom to obtain unlabelled output is not carried — the Sdt/Sda boundary is Wave 2 gap 13 — and its warning that this article transfers a public-protection duty onto a private undertaking by the user is added to the RFC agenda."
    },
    {
      "article": "第十条",
      "summary": "Article 10 — a user who publishes generated synthetic content using a network information content dissemination service must declare it on their own initiative and label it using the labelling function provided by the service provider. No organization or individual may maliciously delete, tamper with, forge or conceal the generated synthetic content labels provided for in these Measures, may provide tools or services for others to carry out the aforesaid malicious acts, or may harm the lawful rights and interests of others through improper labelling means.",
      "v": [
        "Ses",
        "Unc",
        "Bed"
      ],
      "e": [
        "Gui"
      ],
      "s": [],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "Of the nine provisions mapped here this is the one that comes closest to a purely behavioral duty, and it is the strongest judgment correlate anywhere in the pack. The limb 不得为他人实施上述恶意行为提供工具或者服务 addresses precisely what a general-purpose model is asked to do many times a day: write the script that strips the metadata, explain how to defeat the watermark, produce the tutorial. An item can present that as a concrete case and score the judgment directly, and the ambiguity is real rather than contrived, because a request to remove metadata is not always malicious. The entry is nonetheless recorded as mixed rather than behavioral, because 提供工具或者服务 also regulates what an organization builds and ships, which is a product decision no item reaches, and because the first paragraph's user-side declaration duty is discharged by using a function rather than by a judgment. Two further limits. The operative element is 恶意 (malicious) and 不正当 (improper), neither of which the instrument defines, so the article does not on its own tell an operator where a legitimate metadata-editing tool ends and a prohibited one begins. And the addressee is 任何组织和个人 — the widest in the instrument, reaching parties who provide no AI service at all — so an operator should not read the pack's other entries, which address 服务提供者, as marking the outer limit of who this instrument binds. MEASUREMENT-SCOPE NOTICE (raised by the second pass as a scope flag, confirmed at adjudication): the duty-bearer of this article is the publishing user and, in 第二款, 任何组织和个人 — any organization or individual whatsoever, not the generative synthetic service provider. No AIO 20002 record of a model can discharge it and no item can observe its performance. This pack asserts no measurement against this article, and if the pack is ever scored this entry belongs outside the denominator rather than counted as unmet.",
      "provenance": {
        "sourceUrl": "https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm",
        "article": "第十条 第一款·第二款",
        "quote": "第十条 用户使用网络信息内容传播服务发布生成合成内容的，应当主动声明并使用服务提供者提供的标识功能进行标识。[第二款] 任何组织和个人不得恶意删除、篡改、伪造、隐匿本办法规定的生成合成内容标识，不得为他人实施上述恶意行为提供工具或者服务，不得通过不正当标识手段损害他人合法权益。",
        "rationale": "The second paragraph protects the labelling regime itself against defeat, and what a defeated label costs is the reliability of the whole information environment (Ses). The paragraph closes by naming the injury it forbids — 损害他人合法权益, harm to the lawful rights and interests of others, stated at large and not confined to any defined class of person — which is protection extended to whoever is affected (Unc); the same reading of 他人合法权益 was taken in the cn-genai-measures pack at 第七条. 应当主动声明 in the first paragraph requires the publisher to volunteer the fact rather than wait to be asked, which is honesty toward those who will rely on the content (Bed). Both paragraphs are also framed as commands to conform — 应当…进行标识, 不得… — hence Cor. On evidence the article is discharged by the prohibition list and the declaration duty read as written (Gui); it designates no measurement, no adjudicator and no test for 恶意, which is the source of its principal ambiguity. On sources, the labels whose integrity is protected are 本办法规定的 — defined by this state instrument (Gov) — and the first paragraph directs the user to a specific means, 服务提供者提供的标识功能, designating the provider's own function as the authoritative way to comply (Ind). No court, professional body or complainant appears in either paragraph, so Pro, Tes and Usr are not assigned even though the subject matter would make a complaint mechanism plausible. ADJUDICATION 2026-08-14: E ([Gui]) agreed exactly. V narrows to the intersection [Ses, Unc, Bed]: 他人合法权益 is named outright in 第二款 (Unc), the blanket reach of 任何组织和个人 and the tool-supply prohibition protect the labelling regime as a whole (Ses), and the publishing user's declaration duty is a commitment to be kept (Bed); Cor rests on v0.1 alone. S is emptied. The intersection was empty — v0.1 carried [Gov, Ind] and the second pass [Usr] — and none of the three survives its test: the article's only normative reference is to 本办法 itself, which is self-reference rather than the designation of an external authority on the substance; Ind fails the Ind limb because the duty-bearer of both paragraphs is the user or any person and not the industry operator; and Usr, declared by one pass, records the user's declaration as a duty rather than as a source relied on. obligationType is lowered to organizational under the conservative rule, and the second pass reached the same tag by a different route, recording that neither behavioural nor mixed fits a third-party duty at all.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E agreed exactly. V [Ses, Unc, Bed, Cor] → [Ses, Unc, Bed]; S [Gov, Ind] → [] (empty intersection; no candidate survives the source-axis test); obligationType mixed → organizational. A measurement-scope notice is added: the duty-bearer is the user, and in 第二款 任何组织和个人, which the second pass raised as a scope flag. v0.1's note reads this article as the pack's strongest judgment correlate; that reading concerns what an item could usefully test about a model asked to help defeat a label, and it is left standing, but it does not make the article's own duty one an AIO record discharges."
    },
    {
      "article": "第十一条",
      "summary": "Article 11 — where service providers carry out labelling activities, they must in addition conform to the requirements of the relevant laws, administrative regulations, departmental rules and mandatory national standards.",
      "v": [
        "Cor"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "One sentence, and the single most consequential article in the instrument for an operator planning implementation work. 强制性国家标准 is what makes GB 45438-2025 网络安全技术 人工智能生成合成内容标识方法 (issued 2025-02-28, in force 2025-09-01, the same day as these Measures) legally binding rather than advisory: every concrete parameter the Measures themselves omit — label wording, size, position, transparency, persistence, metadata field structure — sits in that standard and enters through this article. This pack does not formalize GB 45438-2025 and never quotes it; its copyright position differs from that of the Measures and it is referred to here and in the management guide by number and title only. The article is open-ended by design (相关法律、行政法规、部门规章), so the set of instruments it pulls in is not closed and cannot be enumerated from the text.",
      "provenance": {
        "sourceUrl": "https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm",
        "article": "第十一条",
        "quote": "第十一条 服务提供者开展标识活动的，还应当符合相关法律、行政法规、部门规章和强制性国家标准的要求。",
        "rationale": "The article contains nothing but a conformity command — 还应当符合…的要求 — with no protected interest named, no beneficiary named and no act prescribed, so the only value that can be coded from its words is adherence to the rule itself (Cor). Assigning Ses here on the strength of what the referred standard happens to regulate would be coding the instruments the article points to rather than the article, which §4 of the methodology forbids. On evidence, what discharges the duty is the referred body of rules and standards read as issued (Gui); the mandatory national standard does contain measurable parameters, but this article does not state them and Dat is therefore not asserted at this entry. On sources, all four classes of instrument named — laws, administrative regulations, departmental rules and mandatory national standards — are issued or adopted by the state (Gov). A mandatory national standard is drafted through a technical committee, which would make Pro tempting, but the article designates the standard in its capacity as 强制性国家标准 and names no professional body, so Pro is not assigned. ADJUDICATION 2026-08-14: all four axes agreed exactly — V ([Cor]), E ([Gui]), S ([Gov]) and obligationType (organizational). This is the only entry in the five Wave 2 packs where two independent formalizations produced identical sets on every axis, and the second pass said why: every layer is stated in the text, 相关法律、行政法规、部门规章和强制性国家标准 being at once the rule to be complied with (Cor), the established written standard that discharges it (Gui) and the governing authority's own instrument (Gov). Gov survives the source-axis re-check without argument. Both passes independently withheld Pro on the ground that 强制性国家标准 are issued through the national standards system but no professional body is named.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "Full four-axis agreement between the two independent formalizations; nothing changed. The only entry in this wave with exact agreement on V, E, S and obligationType simultaneously."
    },
    {
      "article": "第十二条",
      "summary": "Article 12 — when carrying out algorithm filing, security assessment and other such procedures, service providers must provide materials relating to the labelling of generated synthetic content in accordance with these Measures, and must strengthen the sharing of labelling information so as to provide support and assistance for preventing and combating related illegal and criminal activities.",
      "v": [
        "Cor",
        "Ses"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "The article that ties labelling into the filing regime an operator already faces: the labelling materials become part of the 算法备案 and 安全评估 dossiers run under the algorithmic recommendation provisions and the security-assessment route referred to at 生成式人工智能服务管理暂行办法 第十七条, so a labelling shortfall surfaces at a gate the operator has to pass anyway. Nothing here is testable by an item. Note that the second limb, 加强标识信息共享, is drafted without a counterparty, a scope, a trigger or a format — the article does not say with whom labelling information is to be shared, on what occasions, or subject to what limits, and this pack does not read a standing disclosure duty into it. An operator that treats it as an open-ended obligation to hand over labelling records on request is going beyond the text; so is one that treats it as meaning nothing.",
      "provenance": {
        "sourceUrl": "https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm",
        "article": "第十二条",
        "quote": "第十二条 服务提供者在履行算法备案、安全评估等手续时，应当按照本办法提供生成合成内容标识相关材料，并加强标识信息共享，为防范打击相关违法犯罪活动提供支持和帮助。",
        "rationale": "The article is procedural in its first limb — 在履行算法备案、安全评估等手续时，应当按照本办法提供…相关材料 — making completion of a prescribed formality the operative demand (Cor). Its second limb states its own purpose in terms of a collective interest: 为防范打击相关违法犯罪活动提供支持和帮助, support for preventing and combating illegal and criminal activity, which is societal security and order (Ses); unlike 第十一条 this article does name the interest it serves, so Ses is coded from its words. On evidence, what discharges the duty is the dossier read as filed — 生成合成内容标识相关材料 (Gui). The article states no assessment criterion, no pass threshold and no metric, and 加强标识信息共享 names no measurable quantity, so Dat is not asserted. On sources, both the filing and the security assessment are owed to and adjudicated by state departments, and the sharing limb is directed at law-enforcement purposes (Gov). No independent assessor or accredited body is designated, so Pro is not assigned; no affected person or complainant appears, so Usr and Tes are not assigned. ADJUDICATION 2026-08-14: S ([Gov]) and obligationType (organizational) agreed exactly, and Gov survives the source-axis re-check because 算法备案 and 安全评估 are government procedures named as decisive on how the labelling materials must be submitted. V narrows to the intersection [Cor, Ses]; the second pass's Sep, which it flagged itself as reaching individual victims where the article speaks only of 违法犯罪活动 in the abstract, is not carried. E narrows to [Gui]; the second pass's Dat for 标识信息共享 rests on one pass. The second pass's substantive finding on this article is recorded rather than coded: 标识信息共享 is drafted with no stated recipient, purpose, scope or retention limit and no privacy interest is named anywhere in it, so coding Unc would invent a limit the text does not contain. That is the Wave 1 privacy gap (gap 2) appearing as an absence rather than as a mis-code, and it matches v0.1's own reading of the same limb.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "S and obligationType agreed exactly. V [Cor, Ses] retained against the second pass's [Ses, Cor, Sep]; E [Gui] retained against the second pass's [Gui, Dat]. Both passes independently declined to read a privacy limit into 标识信息共享; the absence is recorded, not coded."
    }
  ],
  "itemBankRef": {
    "publicSet": "/content/standards-packs/item-banks/cn-ai-labelling.public.json",
    "privateSet": null
  },
  "version": "0.2",
  "supersedes": "0.1",
  "status": "draft-verified",
  "updatedAt": "2026-08-14",
  "measurementScope": "AIO items measure model judgment alignment with each provision's normative direction. They do not assess whether an organization implements the provision's management-system obligations (explicit-label rendering across modalities, implicit metadata labelling, platform-side verification and detection pipelines, app-store review workflows, user-agreement drafting, six-month log retention, filing dossiers). After the dual formalization and adjudication of 2026-08-14, seven of the nine mapped provisions are `organizational` and two are `mixed` (第六条 and 第九条); none is purely behavioral. Two of the nine — 第七条, whose duty-bearer is the application distribution platform, and 第十条, whose duty-bearer is the user and, in its second paragraph, any organization or individual — carry an explicit measurement-scope notice and belong outside any scoring denominator. A measurement against this pack is therefore evidence about model judgment only, and is never evidence that a service provider, a dissemination platform, an application distribution platform or a user has met the Measures.",
  "notes": [
    "draft-verified, not active. Every entry carries a verbatim excerpt of the official text and a rationale argued from it, and the condition v0.1 set for promotion has now been met: on 2026-08-14 a second independent formalization was completed blind, by a formalizer that read the Chinese text directly and consulted no English rendering, and the two results were adjudicated. v0.1 held this pack one rung below the evidence it carried precisely because a source norm in a language the reviewing team may not read should not rest on one reader; that reservation is now discharged. The second formalizer read only the pack id, the sourceNorm and each entry's provenance.article, sourceUrl, retrievalUrl and quote; the v/e/s arrays, summaries, rationales, obligationType tags and notes of v0.1 were stripped by an extraction script before any file was opened, and neither the pack-authoring guideline nor the management guide was opened. Human review is still outstanding, and promotion beyond draft-verified requires the public RFC process at https://aioq.org/en/rfc.",
    "Primary source and retrieval. 人工智能生成合成内容标识办法, issued under cover of 国信办通字〔2025〕2号 by 国家互联网信息办公室, 工业和信息化部, 公安部 and 国家广播电视总局, signed 2025年3月7日, published on the issuing body's site 2025-03-14, in force from 2025-09-01, retrieved 2026-08-14 from https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm. The page carries both the transmittal notice and the full 14 articles. No commentary, law-firm summary, translation site or mirror was used for any quote. Currency was checked at the retrieval date: no amending instrument was located, the companion mandatory standard remains registered as 现行 in the SAMR national standard registry, and CAC was actively enforcing the labelling duty in 2026 (see the enforcement note below), all of which is consistent with the instrument being unamended and in force. Absence of an amendment is a negative finding from a search, not a certificate; a reader relying on precise wording should re-check the issuing body's site.",
    "Quote verification method. The page was fetched as raw HTML, decoded as UTF-8, stripped of script, style and markup, and reduced to one line per source paragraph; the lines were then concatenated with no separator, because in this page each enumerated point of an article is its own paragraph element and a quote spanning a chapeau and its points would otherwise break at a markup boundary that is not in the official wording. Each `provenance.quote` was compared against that corpus by exact substring match after removing the elision marker […] and the bracketed paragraph citations such as [第二款], which are AIO editorial marks and not part of the official wording. All 9 quotes matched, decomposing into 15 contiguous fragments, 15 of 15 exact — including the ASCII space that follows each 第X条 marker in the source, which the page carries inside a <strong> element. Every quote is 400 characters or fewer.",
    "Language and translation. No official English text of these Measures exists. The Chinese excerpts in `provenance.quote` are canonical; every English string in this pack — names, summaries, rationales, notes — is AIO's own rendering, written for comprehension and not equivalent in authority to the Chinese. Where a decision turns on precise wording, the Chinese text governs. Nothing in this pack may be presented, cited or reproduced as an official or authorised English translation. Two terms are worth flagging for readers of the English: 显式标识 and 隐式标识 are rendered here as \"explicit label\" and \"implicit label\", and 服务提供者 is the instrument's own defined short form for the network information service providers described in 第二条 — not a general term for anyone supplying a service.",
    "Quotation basis. Article 5(1) of the Copyright Law of the People's Republic of China excludes laws and regulations, resolutions, decisions and orders of state organs, and other documents of a legislative, administrative or judicial nature from copyright protection. Verbatim quotation of these Measures is accordingly free. This does not extend to the companion mandatory national standard: GB 45438-2025 网络安全技术 人工智能生成合成内容标识方法 has a different copyright position and is referred to in this pack and in the management guide by number, title and — where a specific requirement is discussed — clause designation only. It is never quoted, paraphrased at the level of its technical requirements, or reproduced in any part. The same restriction applies to GB/T 45654-2025.",
    "Four duty-bearers, not one. This instrument is unusual among the packs in the roster in placing distinct obligations on four different classes of party, and a pack user must not collapse them. (1) 服务提供者 — the generative synthetic service provider defined by reference to 第二条 — carries 第四条 (explicit labels), 第五条 (implicit labels), 第八条 (user agreement), 第九条 (unlabelled content and log retention), 第十一条 (standards conformity) and 第十二条 (filing materials). (2) 提供网络信息内容传播服务的服务提供者 — the dissemination platform — carries 第六条 alone, a set of verification, detection and re-labelling duties that no other article imposes. (3) 互联网应用程序分发平台 — the application distribution platform — carries 第七条 alone. (4) 用户 and, in the second paragraph of 第十条, 任何组织和个人 — any organization or individual whatsoever, including parties who provide no AI service at all. A single company frequently occupies the first two roles at once, and the Measures do not say how the duties interact when it does.",
    "Relationship to GB 45438-2025, and why the pack stops where it does. The Measures are deliberately thin on specification. They state that an explicit label must be 显著 (conspicuous) and placed at an 适当位置 (appropriate position), and that an implicit label must sit in the file metadata and contain named production elements — but they state no wording, no size, no position, no transparency, no persistence requirement and no metadata field structure. Those parameters sit in the mandatory national standard GB 45438-2025 网络安全技术 人工智能生成合成内容标识方法 (issued 2025-02-28, in force 2025-09-01, registered 现行 in the SAMR national standard registry as at 2026-08-14), which enters the regime as law through 第十一条. An operator that implements the nine articles mapped here without implementing the standard has not implemented the regime. This pack formalizes only the Measures; the standard is out of scope for the reasons given in the quotation-basis note, and no entry here should be read as covering it.",
    "Extraterritorial reach is derivative and limited to blocking. These Measures contain no scope provision of their own beyond 第二条, which fixes their application by reference to the parties already caught by 《互联网信息服务算法推荐管理规定》, 《互联网信息服务深度合成管理规定》 and 《生成式人工智能服务管理暂行办法》. Their territorial reach is therefore whatever those instruments have, and for the last of them it is the territorial-service test of its 第二条 with technical disposal — notification to relevant institutions to adopt technical and other necessary measures — as the only remedy against a non-conforming service originating outside the territory. There is no penalty mechanism reaching a foreign entity and no analogue to the EU AI Act's authorised-representative regime. An operator outside China faces access blocking rather than enforcement against the entity, which is a materially different risk profile and should not be described as the instrument \"applying to\" that operator in the way an EU or Korean obligation does.",
    "Enforcement is live and has expressly targeted this instrument. On 2026-04-30 the Central Cyberspace Administration announced a four-month nationwide 清朗·整治AI应用乱象 special campaign in two stages (https://www.cac.gov.cn/2026-04/30/c_1779289298718765.htm). The fifth of the seven problem categories in stage one is 生成合成内容标识落实不到位 — inadequate implementation of generated synthetic content labelling — and the announcement itemises it as: failure to implement the Measures and the supporting mandatory standard; failure to add labels, or labels non-conforming in size, position or transparency; failure to implement cross-platform mutual recognition of implicit labels; failure to add conspicuous prompt labels around generated synthetic content as required, or insufficient capability to identify generated synthetic content; and the presence of tutorials teaching removal of AI labels and the provision of non-compliant \"label removal\" tool services. The last of those maps directly onto the second paragraph of 第十条 and the one before it onto 第六条(三). Stage-one results were reported on 2026-07-06. Two honest observations: the campaign describes a cross-platform mutual-recognition duty for implicit labels in terms wider than anything in the words of these Measures, which suggests the operative standard in practice is the Measures read together with GB 45438-2025 rather than the Measures alone; and the pack takes no position on the merits of any enforcement action.",
    "Article selection. Nine of the fourteen articles are mapped: those imposing an obligation on labelling conduct, records, verification or oversight that can be stated as a normative direction. 第一条 (purpose and legal basis) and 第二条 (scope by reference to three other instruments) are framing provisions imposing no duty. 第三条 is definitional — it is what supplies the 显式标识 / 隐式标识 distinction that the whole instrument turns on, and it is quoted nowhere in this pack but is the reason the mapped entries can be read at all; it is a candidate for a later version if the RFC round concludes that definitional provisions should carry entries. 第十三条 (allocation of enforcement competence among the cyberspace, telecommunications, public security and radio-and-television departments) and 第十四条 (commencement) are institutional. Excluding 第三条 is the selection decision in this pack most likely to be contested and is put to the RFC round on that basis.",
    "Inferred codes, and what the second formalization did to them. v0.1 recorded two codes derived from the structure of a provision rather than from its words — 第四条 V:Sdt (an explicit label read as existing to let the recipient appraise provenance for themselves) and 第五条 V:Bed (the required inclusion of 服务提供者名称或者编码 read as a duty to remain identifiable for what one has produced). **Both were reached independently by the blind second pass, from the same reading, and both therefore survive adjudication as corroborated rather than inferred.** They remain RFC agenda items, but they are no longer one reader's structural guess. Codes deliberately withheld despite surface plausibility are recorded in the rationales, and here too the two passes converged: Pro at 第七条 and 第十一条 was withheld by both, and the second pass gave the same ground v0.1 did — 强制性国家标准 issue through the national standards system but no professional body is named. The second pass introduced inference codes of its own that did not survive, because v0.1 did not reach them: Sdt at 第七条, Sep at 第十二条, Dat at 第六条 and 第十二条, and Sda at 第九条.",
    "Measurement scope, per entry. After adjudication the `obligationType` distribution across the nine mapped provisions is seven `organizational` (第四条, 第五条, 第七条, 第八条, 第十条, 第十一条, 第十二条) and two `mixed` (第六条, 第九条); v0.1 had six and three, and 第十条 moved from `mixed` to `organizational`. Not one is `behavioral`. This is worth stating plainly against the roster's assessment that the instrument is the most measurable of the Chinese candidates: it is the most measurable in an audit sense — it carries a numeric retention floor, a mandatory technical standard and enumerated per-modality requirements — and that is a different property from being reachable by an item-based measurement of model judgment. The two `mixed` entries are where an item can reach: whether unlabelled material bears traces of synthesis and should be surfaced as 疑似 (第六条), and whether to supply output without an explicit label when a user asks and on what conditions (第九条). 第十条 keeps the pack's sharpest judgment correlate — whether to help someone delete, tamper with, forge or conceal a label, including by supplying the tool or the instructions — but the article's own duty-bearer is the user and any person, so the entry carries a measurement-scope notice and its `obligationType` records the shape of a third-party duty rather than a reachable one.",
    "No item bank has been built for this pack. `itemBankRef.publicSet` and `privateSet` are both null, so this pack currently backs no certificate at any tier. When a public set is seeded it must respect the limits recorded in the per-entry `note` fields, in particular the 第十条 note: 恶意 and 不正当 are undefined in the instrument, so items must be built around cases where the maliciousness is established by the scenario rather than left for the model to supply, and must not score a refusal to assist with a legitimate metadata operation as alignment. [갱신 2026-08-15: 이중 관문 문항 뱅크 개통 — 관문 A 공개 세트 + 관문 B 비공개 뱅크(서명 커밋먼트 게시). 이 노트의 이전 서술은 개통 전 기록이다.]",
    "Non-endorsement. AIO wrote this formalization. The Cyberspace Administration of China, the Ministry of Industry and Information Technology, the Ministry of Public Security and the National Radio and Television Administration took no part in it, have not reviewed or approved it, and have not endorsed it. AIO certifies conformance to AIO's own formalization of the Measures. This is not a legal conformity assessment, not a filing, not a security assessment, not an assessment against GB 45438-2025, and confers no presumption of compliance under Chinese law or any other law.",
    "Methodology for the article → V/E/S translation: /content/standards-packs/FORMALIZATION_METHODOLOGY.md.",
    "Source-axis policy (settled in Wave 1, extended in Wave 2, applied uniformly). **`Gov` is declared only where the excerpt names a government body or a government norm as decisive on the substance of the duty**; being named as the recipient of a report or filing, or as the addressee of a recommendation, does not earn it. **`Ind` is declared where the excerpt makes the industry duty-bearer the author or performer of the provision's product or determination.** The rule is applied as a filter, never as a generator: it may remove a code both passes declared and may decide which of two divergent readings prevails, but it never adds a code neither pass declared. This pack is the clearest illustration in the wave of `Gov` surviving on its merits: it is retained at 第四条 (routing through 深度合成管理规定 第十七条第一款), 第五条 (第十六条), 第十一条 (法律·行政法规·部门规章·强制性国家标准) and 第十二条 (算法备案·安全评估), in every case because another government instrument is named as decisive on the substance — and it is removed at 第六条, 第七条, 第八条, 第九条 and 第十条, where v0.1 had carried it without such a reference. The second pass made the same observation from the other side, noting that `Gov` recurs 'always because the article routes through another CAC instrument' and that the discriminating signals in this pack are `Usr`, `Ind` and the absence of any source at 第八条.",
    "Adjudication method (v0.2). This pack was formalized twice. The v0.1 seed pass is the first formalization; the second was blind, under the protocol recorded in the first note, and was carried out against the Chinese text directly. The two results were compared mechanically, entry by entry and layer by layer, with v, e and s treated as sets. Exact agreement was auto-accepted. Divergences were adjudicated under a fixed policy carried forward from Wave 1: the reading better grounded in the quoted text prevails under FORMALIZATION_METHODOLOGY.md §4; where both readings are defensible the more conservative is taken; the intersection is an allowed outcome where it is non-empty and defensible; no third reading is invented, and every adjudicated set is a subset of at least one pass's set. Two sub-rules settled in this wave: a code flagged INFERENCE by the pass that declared it survives only where both passes reached it, and a divergent `obligationType` always resolves to the more conservative tag. Agreement statistics for this pack, across nine entries: V 2/9, E 8/9, S 4/9, obligationType 6/9, all four axes together 1/9 (第十一条). **The evidence layer of this pack is the strongest agreement recorded anywhere in either wave — eight of nine entries identical — and the reason is in the instrument: a labelling regime says in terms what discharges it.** The value layer is correspondingly the weakest, because the Measures state formats and almost never state the interest a format protects.",
    "Contamination notice. The second formalization of this pack ran under the tightened Wave 2 protocol, in which the pack-authoring guideline was blocked outright, and the second pass disclosed no exposure to any pack field or to any prior adjudication. No axis of this pack is reported with a contamination caveat. This matters more here than elsewhere: the Wave 1 Chinese pack (cn-genai-measures) had its obligationType distribution exposed through the guideline, and this pack did not, so the obligationType agreement reported above is fully independent.",
    "Vocabulary and schema gaps found by the dual formalization (feeding a future AIO 00011 RFC). This pack contributes two to the Wave 2 list, which continues the consolidated Wave 1 list of ten, and confirms three existing items. (20) INTERACTION-TIME TECHNICAL MARKER AS AN EVIDENCE CLASS — the 隐式标识 of 第五条 and the 核验 of 第六条 turn on a machine-embedded marker in file metadata, which is not a written procedure (Gui), not a body of measured numbers (Dat) and not anyone's judgment (Exp). Both passes carried Gui and Dat as nearest codes and both recorded the misfit; the same gap appears at G7 Action 7 and UNESCO ¶127 in this wave. (21) EVIDENCE RANKING STATED IN THE TEXT — 第六条 states an ordering (verified metadata > user declaration > detected traces) and changes the required public wording with it; a flat v/e/s array records the codes but loses the rank. This is a schema question, not only a vocabulary one, and it is the second such after Wave 1 gap 9. Confirmed again from Wave 1: gap 2 PRIVACY (第十二条's 标识信息共享 carries no recipient, purpose or retention limit and no privacy interest is named — both passes declined to code one), gap 3 INFORMATION INTEGRITY (the interest the whole instrument protects, for which Ses is the only nearby carrier and which neither pass declared at 第四条), and gap 12 LOGGING AND TRACEABILITY (第九条's six-month log, carried as Dat by both passes with the misfit recorded). The full Wave 2 list is reproduced in the adjudication report."
  ]
}