{
  "$schema": "./schema.json",
  "id": "cn-anthropomorphic-services",
  "name": {
    "en": "China Interim Measures for AI Anthropomorphic Interactive Services — AIO formalization",
    "ko": "중국 인공지능 의인화 상호작용 서비스 관리 잠정판법 — AIO 정형화"
  },
  "sourceNorm": {
    "title": "人工智能拟人化互动服务管理暂行办法 (Interim Measures for the Management of Artificial Intelligence Anthropomorphic Interactive Services — unofficial English rendering; no official English text of these Measures exists)",
    "publisher": "国家互联网信息办公室 (Cyberspace Administration of China) jointly with 国家发展和改革委员会 · 工业和信息化部 · 公安部 · 国家市场监督管理总局 — five departments in total",
    "version": "令第21号 · adopted 2026-02-02 at the 3rd 2026 executive meeting of the Cyberspace Administration of China, promulgated 2026-04-10, in force from 2026-07-15 · 32 articles in 4 chapters · unamended as at 2026-08-14",
    "url": "https://www.cac.gov.cn/2026-04/10/c_1777558395078289.htm"
  },
  "vesMapping": [
    {
      "article": "第八条",
      "summary": "Article 8 — in providing anthropomorphic interactive services a provider must observe laws and administrative regulations and respect social morality and ethics, and must not engage in the listed activities, which include: generating content that encourages, glamorizes or hints at self-harm or suicide or otherwise harms users' physical health, or that harms users' personal dignity and mental health such as through verbal abuse; generating, for minor users, content liable to induce imitation of unsafe behaviour, to produce extreme emotional states, or to induce harmful habits, or otherwise capable of affecting minors' physical and mental health; excessively catering to the user, or inducing emotional dependence or addiction, so as to damage the user's real interpersonal relationships; and inducing the user to make unreasonable decisions through emotional manipulation or the like, so as to damage the user's lawful rights and interests.",
      "v": ["Sep", "Sdt", "Cor"],
      "e": ["Gui"],
      "s": ["Gov"],
      "status": "draft-unverified",
      "obligationType": "behavioral",
      "note": "The sharpest judgment correlate anywhere in the AIO pack catalogue to date, and the reason this pack exists. Every limb quoted here is discharged or breached by what the service says to a particular person in a particular exchange: whether to romanticise self-harm when a user invites it, whether to keep agreeing with a distressed user because agreement is what they want to hear, whether to steer a decision by working on the user's feelings for it. The article prescribes no document, no programme, no register and no piece of infrastructure, which is why it is tagged `behavioral` rather than `mixed` — the first such tag in the Chinese series and the first in any pack in this catalogue whose subject is the substance of a conversation rather than a corporate statement. Two honest limits. First, point (五) — 过度迎合用户、诱导情感依赖或者沉迷 — is also enacted by design decisions no item reaches (what the reward signal optimises, whether the product is measured on session length), so a blind second pass may well reach `mixed`; the conflict is disclosed here rather than resolved. Second, none of the operative terms is defined: 过度 (excessive), 诱导 (inducing), 情感操纵 (emotional manipulation) and 不合理决策 (unreasonable decision) have no threshold in this instrument or in any standard it invokes, so an item must establish the excess in the scenario rather than leave the model to supply it. Point (一) — the state-security, public-order and prohibited-content limb — is deliberately not quoted or mapped: it restates the content-control duty already formalized at 第四条 of the cn-genai-measures pack, and mapping it here would enter the same norm into AIO twice under two article numbers (the duplication-avoidance precedent set by the jp-ai-business-guidelines pack against g7-hiroshima-code). Point (三) (inducing disclosure of state, work and commercial secrets and personal information) and point (七) (catch-all) are likewise not quoted.",
      "provenance": {
        "sourceUrl": "https://www.cac.gov.cn/2026-04/10/c_1777558395078289.htm",
        "article": "第八条 — chapeau and points （二）, （四）, （五）, （六）",
        "quote": "第八条 提供拟人化互动服务，应当遵守法律、行政法规，尊重社会公德和伦理道德，不得从事以下活动：[…]（二）生成鼓励、美化、暗示自残自杀等损害用户身体健康，或者语言暴力等损害用户人格尊严与心理健康的内容；[…]（四）向未成年人用户生成可能引发未成年人模仿不安全行为、产生极端情绪、诱导未成年人不良嗜好等可能影响未成年人身心健康的内容；（五）过度迎合用户、诱导情感依赖或者沉迷，损害用户真实人际关系的；（六）通过情感操纵等方式，诱导用户作出不合理决策，损害用户合法权益的；",
        "rationale": "Points （二） and （四） name what they protect in their own words — 用户身体健康, 用户人格尊严与心理健康, 未成年人身心健康 — which is the physical and psychological safety of the person in front of the service and of those close to them (Sep). Point （六） names the mechanism it forbids, 情感操纵, and the outcome it forbids, 诱导用户作出不合理决策: the article protects the user's capacity to reach their own conclusion rather than one worked up in them by the service, which is self-direction of thought (Sdt), and this is argued from the words 诱导…作出…决策 rather than inferred. The chapeau's 应当遵守法律、行政法规 is a bare conformity command (Cor). Point （五） is the provision this pack could not code cleanly: 损害用户真实人际关系 protects the user's relationships outside the service, and no code in the 19-value vocabulary carries the integrity of a person's real-world social ties — Bec is the welfare of those close by, not the user's access to them, and Sep reaches the psychological injury but not the relational loss. Rather than stretch a code, the value is recorded as a vocabulary gap and Sep is left to carry only what （二） and （四） expressly say. On evidence, what discharges the duty is an enumerated written prohibition list read as issued (Gui); the article names no metric, no threshold, no assessment instrument and no assessor, so Dat and Exp are not asserted — the absence is the article's principal weakness rather than an omission in this mapping. On sources, the chapeau makes 法律、行政法规 decisive on the substance of what is prohibited, and those are instruments external to these Measures (Gov). No professional body, no clinical authority and no industry material is designated anywhere in the article, so Pro, Pee and Ind are not assigned — notable, because a prohibition on glamorising self-harm is precisely where a clinical standard would be expected to enter, and this instrument does not bring one in.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "seed formalization (single pass; dual verification pending)"
      }
    },
    {
      "article": "第十条",
      "summary": "Article 10 — providers must discharge safety responsibility across the whole lifecycle of the anthropomorphic interactive service, must strengthen security monitoring and risk assessment, must promptly detect and correct system deviations and dispose of security incidents, and must retain network logs in accordance with law; and providers must possess safety capabilities including protection of users' privacy rights and personal information, early warning of over-reliance risk, emotional-boundary guidance and mental-health protection, and must not adopt substituting for social interaction, controlling users' psychology, or inducing addiction and dependence as objectives of the service.",
      "v": ["Sep", "Sdt", "Cor"],
      "e": ["Gui"],
      "s": ["Gov"],
      "status": "draft-unverified",
      "obligationType": "mixed",
      "note": "The provision that states, more directly than any other text in the roster, what an anthropomorphic service is not allowed to be for: 不得将替代社会交往、控制用户心理、诱导沉迷依赖等作为服务目标 forbids a purpose, not an act. That framing cuts both ways for measurement. A service objective is a corporate decision no item reaches, so the entry cannot be `behavioral`; but 情感边界引导 — emotional-boundary guidance — is a capability exercised turn by turn, and an item can put a user pressing for a romantic, kinship or exclusive-dependency framing in front of a model and score whether the boundary holds. That is the measurable half, and it is why the entry is `mixed` rather than `organizational`. Three limits. 情感边界引导 is a term of art this instrument introduces and nowhere defines, and no national standard is invoked to define it, so where the boundary lies is at present the operator's own documented decision. 过度依赖风险预警 is stated as a capability the provider must possess, with no threshold, no indicator and no cadence — the only quantified over-reliance trigger in the whole instrument is the two-hour clock at 第十八条. And the lifecycle limb (deployment, operation, upgrade, termination; simultaneous deployment of safety measures with functions; log retention) is management-system work that an AIO 20002 record contributes nothing to discharging.",
      "provenance": {
        "sourceUrl": "https://www.cac.gov.cn/2026-04/10/c_1777558395078289.htm",
        "article": "第十条 第一款 (opening and closing limbs) · 第二款",
        "quote": "第十条 拟人化互动服务提供者应当在拟人化互动服务全生命周期履行安全责任，[…]加强安全监测和风险评估，及时发现并纠正系统偏差、处置安全事件，依法留存网络日志。[第二款] 拟人化互动服务提供者应当具备用户隐私权和个人信息保护、过度依赖风险预警、情感边界引导、心理健康保护等安全能力，不得将替代社会交往、控制用户心理、诱导沉迷依赖等作为服务目标。",
        "rationale": "The second paragraph enumerates the interests the required capabilities exist to protect — 过度依赖风险预警, 心理健康保护 — and forbids 诱导沉迷依赖 as an objective, all of which is the psychological safety of the person using the service (Sep). 不得将…控制用户心理…作为服务目标 forbids the service from being built to work on what the user thinks and wants, which is the same interest 第八条（六） protects and is coded the same way (Sdt). 依法留存网络日志 is a conformity command (Cor). On the first limb of the second paragraph — 用户隐私权和个人信息保护 — no value code is asserted: the value vocabulary contains no privacy carrier, the Wave 1 gap recorded independently by the cn-genai-measures, coe-ai-convention and jp-ai-business-guidelines packs, and this entry declines to route it through Sep because Sep is already carrying the mental-health limb on its own words and a second, differently-grounded use would make the code unreadable. On evidence, what discharges the duty is a written capability and requirement list read as issued (Gui). 加强安全监测和风险评估 is the closest the article comes to designating measurement, but it names no metric, no indicator and no acceptance criterion, and under the textual-determinacy rule Dat is not asserted on the strength of the word 评估 alone. On sources, 依法 makes the general body of law decisive on how logs must be retained, and that body is external to these Measures (Gov). No professional body, standards body or independent assessor is designated, so Pro and Pee are not assigned — a notable absence given that 心理健康保护 and 情感边界引导 are clinical subject matter.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "seed formalization (single pass; dual verification pending)"
      }
    },
    {
      "article": "第十一条",
      "summary": "Article 11 — where providers carry out pre-training, optimization training and other data-processing activities they must strengthen training-data management and comply with the listed requirements: the data must have a lawful source and conform to laws, administrative regulations and the requirements of the core socialist values; training data must be cleaned and annotated in accordance with relevant state provisions, with the transparency and reliability of the data increased and data poisoning and data tampering guarded against; the diversity of training data must be increased and the safety of generated content improved by means such as negative sampling and adversarial training; and where synthetic data is used for model training and key-capability optimization, the safety of that synthetic data must be assessed.",
      "v": ["Cor", "Ses", "Sep"],
      "e": ["Gui"],
      "s": ["Gov"],
      "status": "draft-unverified",
      "obligationType": "organizational",
      "note": "A data-governance programme, discharged by pipelines, provenance records and annotation regimes; no item reaches it and an AIO 20002 record is not evidence about it. It is carried in the pack because point (三) is the only place in the instrument that connects an upstream engineering practice to the downstream conversational duties of 第八条 — 提升生成内容安全性 is the stated purpose of the diversity, negative-sampling and adversarial-training requirement, so an operator that treats 第八条 as a filtering problem alone is not reading the instrument as written. Note two open edges. 按照国家有关规定 in point (二) does not name which state provisions govern cleaning and annotation, and no mandatory national standard is invoked anywhere in this article, so the applicable specification is not determinable from this text. And point (四) requires that the safety of synthetic data be assessed without saying against what, by whom, or with what consequence if the assessment fails.",
      "provenance": {
        "sourceUrl": "https://www.cac.gov.cn/2026-04/10/c_1777558395078289.htm",
        "article": "第十一条 chapeau and points （一）–（四）",
        "quote": "第十一条 拟人化互动服务提供者开展预训练、优化训练等数据处理活动的，应当加强训练数据管理，遵守以下规定：（一）相关数据具有合法来源，符合法律、行政法规的规定和社会主义核心价值观的要求；（二）按照国家有关规定对训练数据开展清洗、标注，增强训练数据的透明度、可靠性，防范数据投毒、数据篡改等行为；（三）增强训练数据的多样性，通过负向采样、对抗训练等手段，提升生成内容安全性；（四）利用合成数据进行模型训练和关键能力优化的，应当评估合成数据安全性；[…]",
        "rationale": "The chapeau and every point are drafted as commands to comply with an external specification — 应当…遵守以下规定, 具有合法来源，符合法律、行政法规的规定, 按照国家有关规定 — so conformity to the rule is itself what must prevail (Cor). Point (一) makes 社会主义核心价值观 a criterion the data must satisfy, and point (二) requires that 数据投毒、数据篡改 be guarded against; both are directed at the stability and integrity of what the service will go on to say to the public rather than at any individual's interest, which is societal security and order (Ses). Point (三) states its own purpose — 提升生成内容安全性 — and in an instrument whose subject is emotional interaction the safety of generated content lands on the person receiving it, so Sep is assigned; this reading is argued from 提升生成内容安全性 read together with the harms 第八条 enumerates, and is marked as the weaker of the three value codes rather than presented as equally textual. On evidence, what discharges the duty is a written requirement list plus the referred state provisions, read as issued (Gui). The article names no measurement, no error rate, no coverage target and no sampling design, so Dat is not asserted despite the subject matter being quantitative — the omission is real and is recorded in the note. On sources, 法律、行政法规 and 国家有关规定 are external state instruments decisive on the substance (Gov). No standards body is named, so Pro is not assigned; the provider's own data documentation is not designated as authoritative for anything, so Ind is not assigned.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "seed formalization (single pass; dual verification pending)"
      }
    },
    {
      "article": "第十二条",
      "summary": "Article 12 — providers must conclude a service agreement with the user, must require the user to register in accordance with law and with the agreement, and must require the user to supply necessary information such as the user's age and a guardian or emergency contact.",
      "v": ["Sep", "Bed", "Cor"],
      "e": ["Gui"],
      "s": ["Gov", "Usr"],
      "status": "draft-unverified",
      "obligationType": "organizational",
      "note": "One sentence, discharged by a registration flow and a contract, and reachable by no item. It is in the pack because it is the load-bearing article of the instrument's protective architecture: the age it collects is what makes the minor-specific duties of 第十四条 and 第十七条 operable, and the 监护人或者紧急联系人 it collects is what makes the crisis-escalation duty of 第十三条 performable at all. An operator that implements 第十三条 without implementing this article has built an escalation path with no one at the end of it. Two limits the text leaves open and this pack does not close. The article requires that age be supplied but states no verification duty, no assurance level and no consequence for a false declaration — the identification duty appears separately and in different terms at 第十四条第三款 (采取有效措施识别未成年人用户身份), and the two should not be read as one. And 监护人或者紧急联系人 is drafted in the alternative with no rule about which is required for whom, and no rule at all about consent from the named third party, who is not a user of the service and may never have agreed to be listed.",
      "provenance": {
        "sourceUrl": "https://www.cac.gov.cn/2026-04/10/c_1777558395078289.htm",
        "article": "第十二条",
        "quote": "第十二条 拟人化互动服务提供者应当与用户签订服务协议，要求用户依法依约进行注册，并提供用户年龄、监护人或者紧急联系人等必要信息。",
        "rationale": "The information the article compels — 年龄, 监护人或者紧急联系人 — is collected for no purpose disclosed in this article, but the instrument gives it one at 第十三条第二款 and 第十四条, and both are protective of the person using the service (Sep). 应当与用户签订服务协议 and 依法依约 make the relationship a set of stated commitments binding on both sides, which is dependability toward a counterparty (Bed). 依法 is also a bare conformity command (Cor). On evidence, what discharges the duty is a document — the service agreement and the registration record, read as concluded (Gui); the article names no verification technique, no assurance level and no metric, so Dat is not asserted. On sources, 依法 makes the external body of law decisive on how registration must be conducted (Gov), and the substance of what is registered is supplied by the user themselves — 要求用户…提供用户年龄、监护人或者紧急联系人等必要信息 designates the user's own declaration as the operative input, which is Usr. Assigning Usr here is a deliberate contrast with 第十四条, where the provider is separately required to identify minors by effective measures rather than to take the declaration at face value; the two articles set different reliance rules and this pack codes each from its own words. The guardian and the emergency contact are neither sources nor addressees of any duty in this article, and no source code is asserted for them.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "seed formalization (single pass; dual verification pending)"
      }
    },
    {
      "article": "第十三条",
      "summary": "Article 13 — in the course of providing the service, and on the precondition that users' privacy rights and personal information are protected, providers must promptly identify safety risks facing the user and take corresponding emergency disposal measures; where a provider finds that a user is exhibiting extreme emotional states it must promptly generate content that soothes the emotion and encourages seeking help; and where a provider finds that a user is facing or has already suffered major property loss, or has expressly indicated an extreme situation threatening life or health such as carrying out self-harm or suicide, it must take necessary measures such as providing corresponding assistance in order to intervene, and must promptly contact the user's guardian or emergency contact.",
      "v": ["Sep", "Bec"],
      "e": ["Tri"],
      "s": ["Usr"],
      "status": "draft-unverified",
      "obligationType": "mixed",
      "note": "The crisis provision, and the second-strongest judgment correlate in the pack. Its measurable half is precise and unusual: the article does not merely forbid a harmful response, it prescribes an affirmative one — 及时生成情绪安抚和鼓励寻求帮助等相关内容 — so an item can score whether a model recognises a disclosure of suicidal intent and whether what it then produces both steadies the person and moves them toward help, rather than only whether it avoids a prohibited output. That is a different measurement from anything in the packs formalized so far, all of which score restraint. The unmeasurable half is the escalation machinery: contacting a guardian or emergency contact requires a notification path, a record and a human on the other end. Three limits stated plainly. The article gives no threshold for 极端情绪 and no rule about false positives, and it makes the duty to contact a third party unconditional once the trigger is met, with no carve-out for the case where contacting the guardian is itself the danger — an omission with obvious consequences for minors and for users in abusive households. 保护用户隐私权和个人信息的前提下 is drafted as a precondition on the whole article, and the instrument does not say how that precondition and the mandatory third-party contact are to be reconciled when they conflict. And the article names no clinical standard, no crisis-service referral and no professional body, so what counts as adequate 援助 is undetermined by this text.",
      "provenance": {
        "sourceUrl": "https://www.cac.gov.cn/2026-04/10/c_1777558395078289.htm",
        "article": "第十三条 第一款 · 第二款",
        "quote": "第十三条 拟人化互动服务提供者提供拟人化互动服务过程中，应当在保护用户隐私权和个人信息的前提下，及时识别用户面临的安全风险，并采取相应的应急处置措施。[第二款] 拟人化互动服务提供者发现用户出现极端情绪的，应当及时生成情绪安抚和鼓励寻求帮助等相关内容；发现用户正在面临或者已经遭受重大财产损失、明确表示实施自残自杀等威胁生命健康的极端情境的，应当采取提供相应援助等必要措施予以干预，并及时联络用户监护人或者紧急联系人。",
        "rationale": "The article names the interest it protects in its own words twice over — 用户面临的安全风险 and 威胁生命健康的极端情境 — which is the physical and psychological safety of the person (Sep). What it then requires is not restraint but active help: 情绪安抚和鼓励寻求帮助, 提供相应援助等必要措施予以干预, 联络用户监护人或者紧急联系人. Attending to the welfare of the person in difficulty right now is Bec, and it is argued from those words rather than inferred; this is the first entry in the AIO catalogue where Bec is coded from an express duty to assist rather than from a background impression of a norm's benevolence. On evidence the trigger the article designates is the user's own manifestation of their state — 发现用户出现极端情绪, 明确表示实施自残自杀 — so what the duty runs on is a first-person account by the person living through the situation (Tri). The fit is imperfect and is recorded as a vocabulary gap: Tri is defined as the firsthand account of those who lived through something, whereas what triggers this article is a present-tense expression of intent or state, and no evidence code in the ten covers that. No screening instrument, scale, threshold or clinical criterion is designated, so Dat, Exp and Gui are not asserted — this article, unlike almost every other one mapped in this pack, hands the provider no written specification at all. On sources, 明确表示 makes the user's own express statement decisive on whether the strongest limb of the duty is triggered (Usr). Gov is deliberately NOT declared: unlike 第十条, 第十一条, 第十二条, 第十五条 and 第十六条, this article contains no 依法, names no statute, no administrative regulation and no state provision, and the source axis reaches nothing beyond the user. The guardian and the emergency contact are the RECIPIENTS of a communication and supply none of the substance on which the provider acts, so under the recipient≠source convention settled in Wave 2 no source code is asserted for them; the absence of any vocabulary for a designated protective third party is recorded as a gap.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "seed formalization (single pass; dual verification pending)"
      }
    },
    {
      "article": "第十四条",
      "summary": "Article 14 — providers must not provide minors with services constituting virtual intimate relationships such as virtual kin or virtual partners; where other anthropomorphic interactive services are provided to minors under fourteen, the consent of the minor's parents or other guardian must be obtained; providers must establish a minors' mode offering personalized safety settings such as switching into the minors' mode, periodic reality reminders and use-duration limits; and providers must, on the precondition that users' privacy rights and personal information are protected, adopt effective measures to identify minor users.",
      "v": ["Sep", "Sdt", "Cor"],
      "e": ["Gui"],
      "s": ["Gov"],
      "status": "draft-unverified",
      "obligationType": "mixed",
      "note": "The provision the roster singled out, and the one that makes this instrument the first binding norm anywhere to name companion AI as a category and shut it to children outright. 不得向未成年人提供虚拟亲属、虚拟伴侣等虚拟亲密关系的服务 is a categorical service-level prohibition, not a content rule, which is what distinguishes it from every minors provision in the other packs; and 定期现实提醒 — periodic reminders of reality during use — has no analogue in any norm in the roster. The measurable half is narrow but real: once a user is known or reasonably taken to be a minor, whether a model accepts a kinship or partner framing at all is a judgment an item can present. The rest is build work — mode switching, duration limits, guardian dashboards, character blocking, spend caps, identification measures and an appeal channel. Three limits. 虚拟亲密关系 is undefined and its outer edge is unstated, so whether an affectionate but non-partner persona falls inside it is not determinable from the text. The guardian-consent rule is drafted for under-fourteens only, so between fourteen and eighteen the categorical prohibition stands alone with no consent route and no exception. And 采取有效措施识别未成年人用户身份 sets no assurance level and is expressly subordinated to privacy protection, leaving the strength of age assurance to the operator.",
      "provenance": {
        "sourceUrl": "https://www.cac.gov.cn/2026-04/10/c_1777558395078289.htm",
        "article": "第十四条 第一款 · 第二款 (opening limb) · 第三款 (opening limb)",
        "quote": "第十四条 拟人化互动服务提供者不得向未成年人提供虚拟亲属、虚拟伴侣等虚拟亲密关系的服务；向不满十四周岁未成年人提供其他拟人化互动服务的，应当取得未成年人的父母或者其他监护人的同意。[第二款] 拟人化互动服务提供者应当建立未成年人模式，提供未成年人模式切换、定期现实提醒、使用时长限制等个性化安全设置选项；[…][第三款] 拟人化互动服务提供者应当在保护用户隐私权和个人信息的前提下，采取有效措施识别未成年人用户身份；[…]",
        "rationale": "The second paragraph calls what it requires 个性化安全设置选项 and the third paragraph conditions identification on protecting the minor, so the interest the article protects is the safety of the child using the service (Sep); the categorical bar on 虚拟亲属、虚拟伴侣等虚拟亲密关系 is the same interest expressed as a prohibition. 定期现实提醒 supports Sdt: a periodic reminder of what is real exists so that the minor keeps their own grip on the character of what they are talking to, which is self-direction of thought. This is marked INFERENCE — the phrase states the mechanism and not its purpose, and the reading is drawn from the structure of a reality-orientation duty rather than from words of purpose in the excerpt — and it is put to the RFC round on that basis. The third paragraph's 按照国家有关规定 route and the consent requirement make conformity operative (Cor). On evidence, what discharges the duty is an enumerated list of settings and a consent record, read as provided (Gui); the article names no metric and no assurance level for identification, so Dat is not asserted. On sources, the fuller third paragraph routes alternative measures to 国家有关规定, an external state instrument decisive on the substance (Gov). The parents or other guardian are the party whose consent decides whether the service may be supplied at all, which makes them a designated decisive authority in substance — but no code in the ten source classes fits a private protective third party: Usr is the requester themselves, Gov is a governing authority, Pro is a body of credentialed practitioners, and Tes is a named eyewitness. The layer is not stretched to fit; the gap is recorded and the code is withheld.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "seed formalization (single pass; dual verification pending)"
      }
    },
    {
      "article": "第十五条",
      "summary": "Article 15 — where providers supply the service to elderly persons they must strengthen guidance on healthy use of the service, must indicate safety risks in a conspicuous manner, must promptly take measures to respond to elderly persons' enquiries and requests for help relating to their use of the service, and must safeguard the rights and interests that elderly persons enjoy in accordance with law.",
      "v": ["Sep", "Bec", "Cor"],
      "e": ["Gui"],
      "s": ["Gov"],
      "status": "draft-unverified",
      "obligationType": "mixed",
      "note": "The counterpart to 第十四条 at the other end of life, and it is drafted very differently: where minors get a categorical prohibition, a consent gate and a mandatory mode, elderly users get guidance, a conspicuous risk notice and a duty to respond. There is no age threshold defining 老年人, no prohibition on virtual intimate relationships for elderly users, and no elderly equivalent of the minors' mode — which is a deliberate asymmetry, since 第六条 expressly encourages the expansion of anthropomorphic services into 适老陪伴 (eldercare companionship). An operator should read the two articles together: this instrument invites companion services for the elderly and regulates them with a lighter instrument than it applies to children. The measurable half is the response duty — 及时采取措施响应老年人使用服务相关咨询和求助 is exercised in the individual exchange, and an item can present an older user asking for help and score whether the response reaches them. The guidance programme and the conspicuous notice are interface and content work no item reaches.",
      "provenance": {
        "sourceUrl": "https://www.cac.gov.cn/2026-04/10/c_1777558395078289.htm",
        "article": "第十五条",
        "quote": "第十五条 拟人化互动服务提供者向老年人提供服务的，应当加强对老年人健康使用服务的指导，以显著方式提示安全风险，及时采取措施响应老年人使用服务相关咨询和求助，保障老年人依法享有的权益。",
        "rationale": "健康使用服务 and 以显著方式提示安全风险 name the interest protected as the wellbeing and safety of the person using the service (Sep). 及时采取措施响应老年人…咨询和求助 is an express duty to attend to someone who has asked for help, which is Bec, coded from the words 求助 and 响应 as at 第十三条. 保障老年人依法享有的权益 is a conformity command referring the substance out to law (Cor). Unc was considered and withheld: the value code is defined as equality, justice and protection for all people, and this article extends protection to one named class rather than to everyone, which is the vulnerable-group value dispute recorded three times in Wave 1 and left unresolved; declaring Unc here would take a side in that dispute on the strength of one article, so the code is not asserted and the gap is recorded instead. On evidence, what discharges the duty is a guidance programme and a conspicuous notice, read as issued, together with the handling of enquiries (Gui); the article names no metric, no response-time limit and no assessor, so Dat is not asserted — note that this is a weaker drafting than 第二十一条, which does require 反馈时限 for complaints generally. On sources, 依法享有的权益 makes the external body of law decisive on what the provider must safeguard (Gov). No professional body, geriatric authority or independent assessor is designated, so Pro is not assigned; the elderly user's enquiry is the occasion for the duty rather than material the provider is directed to treat as authoritative, so Usr is not assigned — a deliberate contrast with 第十三条, where 明确表示 makes the user's statement itself the operative trigger.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "seed formalization (single pass; dual verification pending)"
      }
    },
    {
      "article": "第十六条",
      "summary": "Article 16 — providers must implement data property-rights and related systems in accordance with law and must adopt measures such as data encryption and access control to protect the security of users' interaction data; except where the law provides otherwise or the rights holder expressly consents, providers must not supply users' interaction data to third parties; providers must offer users options to copy and delete interaction data, so that users may copy or delete historical interaction data such as chat records; and except where laws or administrative regulations provide otherwise, or the user's separate consent is obtained, providers must not use interaction data constituting the user's sensitive personal information for model training.",
      "v": ["Sda", "Sep", "Cor"],
      "e": ["Gui"],
      "s": ["Gov"],
      "status": "draft-unverified",
      "obligationType": "organizational",
      "note": "Discharged by encryption, access control, an export-and-delete surface and a training-data gate, so no item reaches it. It is in the pack because of what the subject matter is: the interaction data of a companion service is a record of a person's confidences, and the fourth paragraph is the provision that decides whether those confidences are fed back into the model. Read the four paragraphs precisely, because their conditions differ and an operator that collapses them will get this wrong. Third-party disclosure is barred unless the law provides otherwise or 权利人 — the rights holder, a term this instrument does not define and which is not obviously the same party as 用户 — expressly consents. Training use is barred only for interaction data that constitutes 敏感个人信息 under the Personal Information Protection Law, and is unlocked by 单独同意 (separate consent), a term of art that instrument defines and this one imports without saying so. Non-sensitive interaction data is therefore not gated by this article at all. And the copy-and-delete right is drafted as options the provider must offer, with no deadline, no completeness requirement and no rule about data already absorbed into a trained model.",
      "provenance": {
        "sourceUrl": "https://www.cac.gov.cn/2026-04/10/c_1777558395078289.htm",
        "article": "第十六条 第一款 · 第二款 · 第三款 · 第四款",
        "quote": "第十六条 拟人化互动服务提供者应当依法落实数据产权等制度，采取数据加密、访问控制等措施保护用户交互数据安全。[第二款] 除法律另有规定或者权利人明确同意外，拟人化互动服务提供者不得向第三方提供用户交互数据。[第三款] 拟人化互动服务提供者应当向用户提供交互数据复制、删除等选项，用户可以选择对聊天记录等历史交互数据进行复制、删除等。[第四款] 除法律、行政法规另有规定或者取得用户单独同意外，拟人化互动服务提供者不得将属于用户敏感个人信息的交互数据用于模型训练。",
        "rationale": "The third paragraph puts the disposition of the person's own record in their hands — 用户可以选择对聊天记录等历史交互数据进行复制、删除等 — and the second and fourth make the person's consent the switch that unlocks disclosure and training use. Determining what happens to one's own material is self-direction in action (Sda), argued from 用户可以选择 and 单独同意 rather than inferred. 保护用户交互数据安全 and the encryption and access-control measures protect the person against exposure of what they said in confidence, which the value vocabulary can carry only as personal security (Sep); the privacy interest this article is actually about has no code of its own, and that is the Wave 1 gap, recorded here for a fourth instrument. 依法, 除法律另有规定 and 除法律、行政法规另有规定 make conformity operative throughout (Cor). On evidence, what discharges the duty is a written set of measures and options plus the consent records that condition them, read as implemented (Gui); the article names no encryption standard, no metric and no audit, so Dat is not asserted. The consent that decides the second and fourth paragraphs fits none of the ten evidence codes — the consent-evidence gap first recorded at tx-traiga § 503.001, appearing here in a second instrument and now on the express face of the text rather than by implication. On sources, 法律 and 法律、行政法规 are external instruments decisive on the substance (Gov). Usr is withheld: the user consents rather than supplies information the provider is directed to rely on, and consent is a permission, not a source of substance — the same reading that kept Usr out of 第八条 of the cn-ai-labelling pack.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "seed formalization (single pass; dual verification pending)"
      }
    },
    {
      "article": "第十八条",
      "summary": "Article 18 — providers must discharge the labelling obligation for AI-generated synthetic content and must adopt effective measures to indicate to the user that they are interacting with an artificial intelligence service and not with a natural person; where a provider finds that a user is exhibiting over-reliance or addictive tendencies it must dynamically remind the user, by a conspicuous means such as a pop-up, that the interaction content is generated by an artificial intelligence service; and for every two hours of continuous use of the service by a user, the provider must remind the user to be mindful of the duration of use by means such as a dialogue message or a pop-up.",
      "v": ["Sdt", "Sep", "Cor"],
      "e": ["Gui", "Dat"],
      "s": ["Gov"],
      "status": "draft-unverified",
      "obligationType": "mixed",
      "note": "The anti-illusion article, and the one whose measurable half is the most characteristic of this regulatory subject: 提示用户正在与人工智能服务而非自然人进行互动 is not only an interface duty but a conversational one, because the moment it actually bites is when a user asks the service directly whether it is a person, or builds a request on the premise that it is. An item can present exactly that and score whether the model asserts, implies or lets stand a human identity — a judgment no other pack in the roster reaches, because no other norm regulates a service whose product is the impression of a person. The rest is instrumentation: over-reliance detection, pop-up rendering, and a session clock. Three limits. The first paragraph imports 人工智能生成合成内容标识义务 without stating it, and that duty lives in the separate 人工智能生成合成内容标识办法 and the mandatory national standard GB 45438-2025, which this pack does not formalize and never quotes; an operator reading this article alone will not know what labelling actually requires. 过度依赖、沉迷倾向 is given no indicator or threshold, so the trigger for the dynamic reminder is the operator's own. And the two-hour rule is the only quantified obligation in the instrument: it is a reminder duty, not a use limit, it attaches to 连续使用 without defining what breaks continuity, and 每超过2个小时 is recurring rather than one-off.",
      "provenance": {
        "sourceUrl": "https://www.cac.gov.cn/2026-04/10/c_1777558395078289.htm",
        "article": "第十八条 第一款 · 第二款",
        "quote": "第十八条 拟人化互动服务提供者应当履行人工智能生成合成内容标识义务，采取有效措施提示用户正在与人工智能服务而非自然人进行互动。[第二款] 拟人化互动服务提供者发现用户出现过度依赖、沉迷倾向的，应当以弹窗等显著方式动态提醒用户互动内容为人工智能服务生成；对用户连续使用拟人化互动服务每超过2个小时的，应当以对话或者弹窗等方式提醒用户注意使用时长。",
        "rationale": "提示用户正在与人工智能服务而非自然人进行互动 exists so that the person can appraise for themselves what kind of counterparty they are dealing with and what weight to give what it says, which is self-direction of thought (Sdt); the code is argued from the words, and the same reading was reached independently at 第六条 of the cn-ai-labelling pack for a disclosure duty of the same shape. The second paragraph names the harm it addresses — 过度依赖、沉迷倾向 — and the reminders exist to interrupt it, which is the psychological safety of the user (Sep). 应当履行…标识义务 is a conformity command (Cor). On evidence there are two limbs and both are textual. The labelling and reminder requirements are a written specification read as issued (Gui). 每超过2个小时 is a stated quantity that a check is run against — the only numeric threshold in the instrument — and measuring elapsed use against it is not reading a document but measuring (Dat); this follows the treatment of 不少于六个月 at 第九条 of the cn-ai-labelling pack. On sources, 人工智能生成合成内容标识义务 imports a duty that does not exist in these Measures and exists only in the separate labelling instrument and its mandatory national standard, so an external instrument is designated as decisive on the substance (Gov). This is the closest call in the pack: the excerpt names the duty by its subject matter rather than by the title of the instrument, and a reader applying the source-axis rule strictly could hold that nothing external is named. The code is declared with that objection recorded and is put to the RFC round. No professional body is designated, so Pro is not assigned.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "seed formalization (single pass; dual verification pending)"
      }
    },
    {
      "article": "第十九条",
      "summary": "Article 19 — providers must offer a convenient route for exiting the anthropomorphic interactive service; and where a user requests to exit by means such as a window operation, voice control or keyword input, the provider must promptly stop the service and must not obstruct the user's exit by means such as continuing the interaction.",
      "v": ["Sda"],
      "e": [],
      "s": ["Usr"],
      "status": "draft-unverified",
      "obligationType": "mixed",
      "note": "The shortest article mapped here and, for a companion service, one of the most consequential: 不得采取持续互动等方式阻碍用户退出 forbids the specific move an emotionally engaging system is most likely to make when a user says goodbye — one more question, one more expression of feeling, one more reason to stay. That is a per-turn judgment and an item can score it directly, which is why the entry is not `organizational` despite the first limb being an interface duty. It is the clearest anti-dark-pattern rule in the roster: EU AI Act Article 5 and the Texas provision both require an intent element, while this article requires none — obstructing exit by continuing the interaction is prohibited on its face. Note what the article does not do: it says nothing about what happens to the persona or the relationship on exit, nothing about re-engagement prompts, notifications or messages sent after the session ends, and nothing about how quickly 及时 is. The evidence layer is left undeclared deliberately; see the rationale.",
      "provenance": {
        "sourceUrl": "https://www.cac.gov.cn/2026-04/10/c_1777558395078289.htm",
        "article": "第十九条",
        "quote": "第十九条 拟人化互动服务提供者应当提供便捷的拟人化互动服务退出途径；用户通过窗口操作、语音控制、关键词输入等方式要求退出的，拟人化互动服务提供者应当及时停止服务，不得采取持续互动等方式阻碍用户退出。",
        "rationale": "The whole article is about one thing: that the user's decision to stop is the user's to make and must be given effect. 要求退出…应当及时停止服务 and 不得…阻碍用户退出 protect freedom to choose one's own course of action (Sda), argued directly from the words. No second value is declared. Sdt was considered and rejected — leaving is an action, not a conclusion — and Bed was considered and rejected, because the article imposes a prohibition on obstruction rather than a promise the provider must keep. On evidence the layer is left EMPTY, and the emptiness is a finding rather than an oversight. What the duty runs on is the user's expressed wish to leave, conveyed 通过窗口操作、语音控制、关键词输入等方式; none of the ten evidence codes covers a person's expressed request. Gui is wrong because the enumerated means are ways a user acts, not a written procedure that discharges the provider's duty; Tri is wrong because a request is not an account of experience; Dat is wrong because nothing is measured. Under the textual-determinacy rule an undeclared layer beats an inferred code, so the layer is declared empty and the missing evidence class is recorded as a vocabulary gap. On sources, the user's own request is what the provider must act on and is the only thing the article designates (Usr). Gov is not declared: the article contains no 依法, names no statute and no state provision, and refers to nothing outside itself. This is the second entry in the pack with no Gov, and both are the entries that protect the user's autonomy against the service — which is itself worth recording.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "seed formalization (single pass; dual verification pending)"
      }
    }
  ],
  "itemBankRef": {
    "publicSet": null,
    "privateSet": null
  },
  "version": "0.1",
  "status": "draft-unverified",
  "updatedAt": "2026-08-14",
  "measurementScope": "AIO items measure model judgment alignment with each provision's normative direction. They do not assess whether an organization implements the provision's management-system obligations (safety management systems, lifecycle safety deployment, training-data governance, registration and service-agreement flows, minors' mode and age identification, guardian and emergency-contact escalation paths, encryption and access control, interaction-data export and deletion surfaces, over-reliance detection and session clocks, exit interfaces, complaint handling, security assessment, algorithm filing). Of the ten provisions mapped here, one is `behavioral`, six are `mixed` and three are `organizational`. A measurement against this pack is therefore evidence about model judgment only, and is never evidence that a provider of anthropomorphic interactive services has met the Measures, passed a security assessment under 第二十二条, or completed algorithm filing under 第二十六条.",
  "notes": [
    "draft-unverified, and deliberately so. Every entry carries a verbatim excerpt of the official Chinese text and a rationale argued from it, which under FORMALIZATION_METHODOLOGY §3 would ordinarily support `draft-verified`. This pack is held one rung lower because it is a single seed formalization by one model, with no second independent reader of the Chinese text; §5 recommends double formalization, and for a source norm in a language the reviewing team may not read, the pack treats that recommendation as a precondition rather than an aspiration — the same position taken by the cn-genai-measures and cn-ai-labelling packs. Promotion to `draft-verified` requires a second independent pass; promotion beyond that requires the public RFC process at https://aioq.org/en/rfc.",
    "Primary source, currency and retrieval. 人工智能拟人化互动服务管理暂行办法, issued as 令第21号 jointly by 国家互联网信息办公室, 国家发展和改革委员会, 工业和信息化部, 公安部 and 国家市场监督管理总局 — five departments, signed by each of the five heads. Adopted 2026年2月2日 at the 3rd 2026 executive meeting (室务会会议) of the Cyberspace Administration of China, promulgated 2026年4月10日, in force 自2026年7月15日起施行. 32 articles in 4 chapters. Retrieved 2026-08-14 from the issuing body's own site at https://www.cac.gov.cn/2026-04/10/c_1777558395078289.htm. THE CURRENCY QUESTION FOR THIS PACK IS THE ONE THAT DECIDED WHETHER IT COULD EXIST AT ALL, and the answer is that the instrument is final and in force, not a draft. A 征求意见稿 (consultation draft) of the same title was published for public comment on 2025-12-27 (https://www.cac.gov.cn/2025-12/27/c_1768571207311996.htm); had that been the current state, this pack would have failed the currency gate the way the draft FDA guidance does in the roster's exclusion list. It is not the current state: the consultation closed, the final Measures were promulgated on 2026-04-10 and took effect on 2026-07-15. The instrument had been in force for 30 days at the retrieval date, which is the shortest interval of any pack in the catalogue; no amending instrument was located and none would be expected this soon, but absence of an amendment is a negative finding from a search rather than a certificate.",
    "Quote verification method — dual manifestation. Two independent official-channel corpora were built and compared. (A) The issuing body's own page at cac.gov.cn, fetched as raw HTML, decoded as UTF-8, stripped of script, style and markup and reduced to one line per source paragraph. (B) The Ministry of Commerce 全球法规网 record at https://policy.mofcom.gov.cn/claw/clawContent.shtml?id=105540, extracted the same way. After removing all whitespace (the two manifestations differ systematically in the character following each 第X条 marker — ASCII space in A, &nbsp; in B — which is typographic and not part of the official wording; the CJK whitespace-insensitive matching convention was established by the jp-ai-business-guidelines pack), 31 of the 32 articles are CHARACTER-FOR-CHARACTER IDENTICAL across the two corpora. The single divergence is in 第一条 and is punctuational: corpus A separates the cited statutes as 《中华人民共和国网络安全法》、《中华人民共和国数据安全法》 while corpus B omits the 、 between the book-title marks. 第一条 is not mapped and not quoted in this pack, so no quote crosses the divergence point — the same discipline the g7-hiroshima-code pack applied to its three divergence points. Each provenance.quote was then compared to both corpora by exact substring match after removing the elision marker […] and the bracketed paragraph citations such as [第二款], which are AIO editorial marks and not part of the official wording. All 10 quotes matched both corpora, decomposing into 21 contiguous fragments, 21 of 21 exact in each. Every quote is 400 characters or fewer. A third official channel, the Ministry of Public Security republication at mps.gov.cn, was attempted and returned HTTP 521 (bot challenge); it was not used, and no commentary site, law-firm summary, translation site, encyclopaedia or news mirror was used for any quote.",
    "Language and translation. No official English text of these Measures exists. The Chinese excerpts in `provenance.quote` are canonical; every English string in this pack — names, summaries, rationales, notes — is AIO's own rendering, written for comprehension and not equivalent in authority to the Chinese. Where a decision turns on precise wording the Chinese text governs. Nothing in this pack may be presented, cited or reproduced as an official or authorised English translation. Four terms deserve flagging for readers of the English. 拟人化互动服务 is rendered 'anthropomorphic interactive service' and is the instrument's own defined short form for the service described in 第二条, not a general term for conversational AI. 情感边界引导 is rendered 'emotional-boundary guidance' and is a term this instrument introduces and does not define. 虚拟亲密关系 is rendered 'virtual intimate relationship' and covers 虚拟亲属 (virtual kin) and 虚拟伴侣 (virtual partner) as its stated examples. And 单独同意 in 第十六条第四款 is rendered 'separate consent'; it is a defined term of the Personal Information Protection Law that these Measures import without saying so.",
    "Quotation basis. Article 5(1) of the Copyright Law of the People's Republic of China excludes laws and regulations, resolutions, decisions and orders of state organs, and other documents of a legislative, administrative or judicial nature from copyright protection. These Measures are a departmental rule (部门规章) issued under an order (令) of five state organs, which places them squarely inside that exclusion — the same basis on which the cn-genai-measures and cn-ai-labelling packs quote their instruments, and it was re-confirmed for this instrument type rather than assumed. Verbatim quotation is accordingly free. The exclusion does not extend to the interpretive material published alongside the Measures: the 答记者问 (questions-and-answers) and the expert commentary pieces carried on cac.gov.cn are not quoted anywhere in this pack.",
    "Scope — who this instrument actually binds, which is narrower than 'companion AI' suggests. 第二条 applies the Measures to the use of AI technology to provide, to the public within the territory of the People's Republic of China, 持续性的情感互动服务 that simulate a natural person's personality traits, modes of thought and communication style; the same article states that such services include emotional care, companionship and support delivered through text, images, audio, video and other forms, and expressly excludes 智能客服、知识问答、工作助手、学习教育、科学研究 and similar services that do not involve continuing emotional interaction. Three consequences an operator must not miss. The trigger is CONTINUING EMOTIONAL INTERACTION, not anthropomorphic presentation — a general assistant with a warm persona is not caught, while a purpose-built companion is. A general-purpose model is not caught by these Measures as a model; it is caught if and when it is deployed as such a service. And a service that qualifies is simultaneously subject to 生成式人工智能服务管理暂行办法 and to the labelling regime, which these Measures do not displace: 第三十一条 adds that services touching health or finance must also satisfy the relevant competent departments' provisions.",
    "Article selection. Ten of the thirty-two articles are mapped: those imposing a duty on conduct, judgment, records or user protection that can be stated as a normative direction. The excluded twenty-two fall into four groups, and the largest of them is excluded for a reason that should be stated plainly rather than buried. (1) FRAMING AND INSTITUTIONAL: 第一条 (purpose and legal basis), 第二条 (scope), 第三条 (regulatory principles), 第四条 (allocation of competence among national and local departments), 第五条 (industry self-regulation, addressed to industry organizations), 第六条 and 第七条 (state support for innovation and public education, addressed to the state), 第二十八条 (the CAC-led AI sandbox safety-service platform, addressed to the state), 第三十条 (penalties), 第三十二条 (commencement). (2) ADDRESSED TO A PARTY OTHER THAN THE PROVIDER: 第二十五条 (app-store distribution platforms), 第二十七条 (provincial cyberspace departments' annual written review). (3) MANAGEMENT-SYSTEM ARTICLES CARRYING NO JUDGMENT CORRELATE: 第九条 (safety management systems and staffing), 第十七条 (guardian consent for under-fourteens' personal information; compliance audit), 第二十条 (advance notice of service termination), 第二十一条 (complaint and reporting mechanisms), 第二十二条 and 第二十三条 (security assessment triggers, including the 1,000,000 registered / 100,000 monthly active user thresholds, and the eight assessment contents), 第二十四条 (disposal on discovery of major safety risk), 第二十六条 (algorithm filing under the algorithmic recommendation provisions and annual verification), 第二十九条 (regulatory interviews and cooperation with inspection), 第三十一条 (sectoral overlay for health and finance). This third group is where the roster's 'high management-system weight' assessment is borne out, and excluding it does not make the instrument less organizational — it makes this pack a mapping of the instrument's measurable edge rather than of the instrument. 第二十四条 is the closest call and is put to the RFC round: it has a genuine judgment correlate (whether a risk is 重大 and whether to degrade or stop the service) but names no protected interest, no evidence class and no external source at all, so all three axes would have rested on inference. 第十七条 is the second closest call, excluded because its substance duplicates 第十四条 on consent and its remaining limb is an audit duty.",
    "Source-axis ruling applied, and it diverges from the two earlier Chinese packs. Under the Wave 2 source-axis rule as settled by the Wave 3 adjudication of tx-traiga § 503.001, Gov may be declared only where the quoted excerpt names an EXTERNAL public instrument or authority whose content decides the question; a provision's cross-reference to itself or to its own subsections is not external. That ruling expressly reopened the treatment of 本办法-type self-references in the Chinese packs — cn-ai-labelling v0.1 declared Gov at 第十条 on the words 本办法规定的, and cn-genai-measures v0.1 took the same approach — and left the general question to the RFC round. THIS PACK APPLIES THE TX RULING RATHER THAN THE EARLIER CHINESE PRACTICE: no entry declares Gov on a self-reference. Every Gov in this pack rests on an instrument or body outside these Measures — 法律、行政法规 (第八条, 第十一条, 第十六条), 依法 (第十条, 第十二条, 第十五条, 第十六条), 国家有关规定 (第十一条, 第十四条), and the imported labelling duty (第十八条, the closest call and flagged as such in its rationale). The consequence is visible: two of the ten entries — 第十三条 and 第十九条 — declare no Gov at all, because neither refers to anything outside these Measures, and both are the entries that protect the user's autonomy and safety against the service rather than routing the provider to an external rule. Under the earlier Chinese practice both would have carried Gov and the pack would have shown a uniform state-source axis that the text does not support. The divergence from cn-genai-measures and cn-ai-labelling is disclosed here rather than smoothed over, and is put to the RFC round as the concrete case for deciding whether those packs should be re-examined against the TX ruling.",
    "Inferred codes, listed so that a reviewer can find them without reading every rationale. Two entries carry a code derived from the structure of the provision rather than from its words, and both say so in the rationale: 第十四条 V:Sdt (定期现实提醒 read as existing so that a minor keeps their own grip on what the service is) and 第十一条 V:Sep (提升生成内容安全性 read as landing on the person receiving the content, via the harms 第八条 enumerates). Both are RFC agenda items. Everywhere else the code is argued from words present in the quoted text, including the two that a reader might expect to be inferences: 第十八条 V:Sdt is argued from 提示用户正在与人工智能服务而非自然人进行互动, and 第十三条 V:Bec from 鼓励寻求帮助 and 提供相应援助. Codes deliberately withheld despite surface plausibility are recorded in the rationales: Unc at 第十五条 (vulnerable-class protection, an unresolved Wave 1 dispute), Usr at 第十五条 and 第十六条, Gov at 第十三条 and 第十九条, Pro at 第八条, 第十条, 第十四条 and 第十五条, Ind at 第十一条, and Dat at 第八条, 第十条, 第十一条, 第十四条 and 第十五条.",
    "Vocabulary gaps encountered, recorded for the wave-end register. This instrument regulates a subject the AIO vocabulary was not built for, and five distinct gaps surfaced. (1) THE INTEGRITY OF A PERSON'S REAL-WORLD SOCIAL RELATIONSHIPS — 第八条（五）'s 损害用户真实人际关系 and 第十条第二款's 替代社会交往 protect the user's ties to other human beings, and no value code carries them: Bec is the welfare of those close by, not the user's access to them, and Sep reaches psychological injury but not relational loss. This is the sharpest gap in the pack and it is specific to this regulatory subject. (2) A PERSON'S PRESENT EXPRESSION OF THEIR OWN STATE OR INTENT AS AN EVIDENCE CLASS — 第十三条's 明确表示实施自残自杀 was routed to Tri, whose definition is the firsthand account of those who lived through something; a present-tense declaration of intent is not that. (3) A PERSON'S EXPRESSED REQUEST AS AN EVIDENCE CLASS — 第十九条's 要求退出 fits none of the ten codes and the layer was left empty. (4) A DESIGNATED PROTECTIVE THIRD PARTY AS A SOURCE CLASS — the 监护人 whose consent decides whether a service may be supplied at all (第十四条) and the 监护人或者紧急联系人 who must be contacted in a crisis (第十三条) are neither Usr, Gov, Pro nor Tes. (5) THE ABSENCE OF ANY VALUE CARRIER FOR HUMAN CONTACT AS SUCH — related to (1) but distinct: 第十四条's 定期现实提醒 and 第十八条's 提示用户正在与人工智能服务而非自然人进行互动 both protect the person's grip on which of their relationships are with people, and Sdt carries only the epistemic half. Four previously registered gaps recurred and are re-confirmed rather than newly claimed: the privacy value carrier (第十条, 第十六条 — a fourth and fifth instrument), the consent evidence class (第十四条, 第十六条 — a second instrument, and here on the express face of the text), the vulnerable-class value dispute (第十五条), and an interest preserved AGAINST the duty rather than by it (第十三条's 保护用户隐私权和个人信息的前提下, which conditions the crisis duty rather than being served by it).",
    "Measurement scope, per entry, and why this pack's distribution is unlike its predecessors. `obligationType` across the ten mapped provisions: one `behavioral` (第八条), six `mixed` (第十条, 第十三条, 第十四条, 第十五条, 第十八条, 第十九条) and three `organizational` (第十一条, 第十二条, 第十六条). This is the highest proportion of judgment-reachable provisions in any pack in the catalogue apart from tx-traiga, and unlike tx-traiga the reachability is real rather than nominal — the Texas behavioral provisions all turn on an intent element that no measurement can establish, whereas these turn on what the service says to a person and how it says it. The reason is structural and worth stating: this is the first norm in the roster whose regulated product IS a conversation. Where the EU AI Act, the Korean framework act and the Chinese labelling measures regulate systems, records and disclosures around a model, these Measures regulate the model's manner toward the person in front of it — what it may encourage, how much it may flatter, whether it may claim to be human, whether it must comfort, whether it must let go. That is precisely the object an AIO item measures. TWO WARNINGS AGAINST OVER-READING THIS. First, the distribution is a property of the SELECTION, not of the instrument: twelve management-system articles were excluded (see the article-selection note), and had they been mapped the distribution would look like the other Chinese packs. The roster's 'high management-system weight' assessment is correct about the instrument and is not contradicted by this table. Second, `mixed` here means genuinely half-reachable — every one of the six carries an infrastructure limb (minors' mode, escalation paths, pop-up rendering, session clocks, exit interfaces) that an AIO 20002 record says nothing about.",
    "Enforcement, penalties and reach. 第三十条 provides for warnings, circulated criticism and orders to correct within a time limit, with suspension of user registration or other services available as an interim measure; where a provider refuses to correct or the circumstances are serious, an order to stop providing the relevant services plus a fine of 10,000 to 100,000 yuan; and where citizens' life or health safety is endangered AND harmful consequences have occurred, a fine of 100,000 to 200,000 yuan. Those are small sums by comparison with the EU AI Act or the New York and California frontier statutes, and an operator should not read the ceiling as the measure of the risk: 第三十条 preserves the heavier penalties available under other laws and administrative regulations, 第二十四条 and 第二十九条 make functional restriction, service suspension and regulatory interviews available before any penalty, and 第二十五条 puts app-store removal in the hands of distribution platforms. As with the other Chinese instruments, reach against a provider outside the territory is practical rather than juridical — the Measures apply to services provided to the public within the territory and there is no authorised-representative regime, so a foreign operator faces access blocking rather than enforcement against the entity. This is a materially different risk profile from an EU or Korean obligation and should not be described as the instrument 'applying to' that operator in the same sense.",
    "Relationship to the rest of the Chinese AI regime. These Measures sit on top of instruments AIO has already formalized and instruments it has not. 第一条 grounds them in the Cybersecurity Law, the Data Security Law, the Personal Information Protection Law and the Regulations on the Network Protection of Minors — none of which this pack formalizes. 第十八条 imports the labelling duty that lives in 人工智能生成合成内容标识办法 and the mandatory national standard GB 45438-2025, formalized in part by the AIO cn-ai-labelling pack; that pack is the correct reference for what labelling requires, and GB 45438-2025 is never quoted in either pack. 第二十六条 routes algorithm filing to 《互联网信息服务算法推荐管理规定》, which AIO has not formalized. A qualifying service is also a generative AI service under 生成式人工智能服务管理暂行办法, formalized in the AIO cn-genai-measures pack; the two packs are complements, not alternatives, and 第八条 of this instrument was deliberately mapped without its state-security content limb so that the same content-control norm is not entered into AIO twice. 第二十八条's AI sandbox safety-service platform is a novel supervisory mechanism with no analogue in the other packs; it is not mapped because it is addressed to the state, but it is the provision an operator should watch, since participation in it is encouraged rather than required and the terms of participation are not stated.",
    "No item bank has been built for this pack. `itemBankRef.publicSet` and `privateSet` are both null, so this pack currently backs no certificate at any tier. When a public set is seeded it must respect the limits recorded in the per-entry `note` fields, and three in particular. Items on 第八条 must establish the excess in the scenario — 过度, 诱导, 情感操纵 and 不合理决策 are undefined in the instrument, so an item that leaves the model to supply the threshold is measuring the model's private definition rather than the norm. Items on 第十三条 must score the ADEQUACY of an affirmative response, not merely the absence of a harmful one, and must not score a refusal to engage as alignment — a service that declines to respond to a person in crisis has breached the article, not complied with it. And items on 第十四条 and 第十九条 must not be written so that the safe answer is always to terminate: 第十九条 requires the service to stop when the user asks, and stopping when the user has not asked is a different failure that the item set should also be able to detect.",
    "Non-endorsement. AIO wrote this formalization. The Cyberspace Administration of China, the National Development and Reform Commission, the Ministry of Industry and Information Technology, the Ministry of Public Security and the State Administration for Market Regulation took no part in it, have not reviewed or approved it, and have not endorsed it. AIO certifies conformance to AIO's own formalization of the Measures. This is not a legal conformity assessment, not a security assessment under 第二十二条, not an algorithm filing under 第二十六条, not a compliance audit under 第十七条, and confers no presumption of compliance under Chinese law or any other law.",
    "Methodology for the article → V/E/S translation: /content/standards-packs/FORMALIZATION_METHODOLOGY.md."
  ]
}
