Connect with us

NEWS

China’s Supreme People’s Court Gives AI Apps Safe Harbor

China’s Supreme People’s Court told judges AI apps need not scan every prompt, while unauthorized face and voice clones can be stopped by injunction.

Published

on

China’s Supreme People’s Court told judges on September 7, 2026 that generative AI apps need not scan every prompt for illegal output. The 24-article opinion still treats unauthorized face and voice clones as civil wrongs, and it lets victims seek fast personal-rights injunctions.

The document, Fa Fa [2026] No. 10, is the first AI dispute playbook from the country’s highest court. China still has no dedicated AI statute, so the court told lower tribunals to work from the Civil Code, the Cybersecurity Law, the Copyright Law, the Personal Information Protection Law and related statutes. Vice President Tao Kaiyuan said the filing was meant to keep development and safety in the same frame.

Providers Do Not Have to Read Every Prompt

The line that will govern product teams sits in the tort chapter, not in the deepfake headlines. Court officials said generative AI services organize huge volumes of data and cannot be asked to predict, review and intercept every output, because results depend on training data, model settings and the user’s prompt. When a model’s own errors, or a user’s malicious prompt, produce content that harms reputation or privacy, the provider’s civil duty starts after a valid notice.

That is the Civil Code’s Article 1195 notice-and-act rule for AI providers, applied to chatbots. A notice must include preliminary evidence of the infringement and the rightsholder’s real identity. If the provider then fails to stop generating the infringing output, or to block the relevant prompt, it can share civil liability for the extra harm. Users who feed infringing prompts on purpose remain liable themselves.

The same briefing closed two other doors that plaintiffs might have used to treat every AI company like a defective-product maker. Unless a statute already imposes no-fault or presumed-fault liability, AI civil cases use ordinary fault liability, so that early-stage industry is not loaded with duties it cannot meet. “AI products” are limited to goods with a physical carrier, such as robots and self-driving cars; pure software services are outside product-liability law.

Consent Rules for Faces, Voices and the Dead

Si Yanli, deputy director of the court’s research office, told the Beijing briefing that ordinary people can now be targets of face swaps, and that a voice can be stolen for a few yuan. Article 4 of the opinion converts that cheap trick into a named civil wrong.

THE PERSONALITY-RIGHTS BANS

  • Face and name: Making and publishing an identifiable virtual image from a person’s name or likeness without consent infringes name and portrait rights.
  • Voice: Using someone’s voice as training material to copy timbre, tone and speaking style, and then generating a recognizable synthetic voice, infringes voice rights.
  • Reputation: Driving a cloned face or voice to act badly or to spread false statements that lower social standing is a reputation injury.
  • The dead: Building or using a deceased person’s virtual image so that name, portrait or reputation is harmed lets close relatives sue under Civil Code Article 994.
  • Doxxing: Article 5 treats AI tools that track public posts to pull or leak private facts, or that peep and eavesdrop on private spaces, as privacy violations.

The court also pointed to “one-click undressing” software used to sexualize real people. Victims who can show that delay would cause harm that is hard to undo may apply under Article 8 for a personal-rights injunction. Judges may order the user to stop, and they may order the network or AI provider to cut off the service, without going past what the harm requires.

The traditional approach of seeking redress through litigation after the fact is not conducive to providing timely and effective protection for victims’ legitimate rights, making the proper application of personal-rights injunctions particularly important.

Supreme People’s Court, Opinions on legally trying cases involving artificial intelligence disputes

Serious misuse of deepfakes for fraud, defamation, personal-information crimes or obscene material can still move from civil court into a criminal file. The injunction is the speed tool; prison remains on the table for the worst cases.

Training on Public Personal Data Is Usually Lawful

Article 6 is the quieter clause, and it is the one model builders will actually code against. The court said large, high-quality training sets are the base of the technology. For model training, handling personal information that the person already made public, or that is otherwise lawfully public, within a reasonable scope, and where the person has not clearly refused, is generally not an infringement of personal-information rights.

Consent is still required when the handling has a major effect on the person’s rights. “Reasonable scope” is a facts test: whether the use is necessary and proportionate to the model’s function, how sensitive the data is, the setting in which it was posted, and what use the person could fairly expect. That is an opt-out design for public posts, not an opt-in wall around every selfie on the open web.

Anyone training a Chinese model will read that as permission to keep scraping lawfully public profiles, with a duty to honor a clear refusal and to get consent for sensitive uses. The personality-rights chapter still blocks turning those same public faces into a commercial clone without permission. The data can feed the model; the output still cannot wear a real person’s identity as a costume.

Two Copyright Fights the Court Refused to Decide

Articles 12 to 16 cover intellectual property, and they do real work on procedure while leaving the two industry fights untouched. If AI output is accused of copying a work, no one can walk away by saying a machine wrote it. Liability is supposed to track who had control and who owed a duty of care, looking at the service type, who fed the training data, who steered the prompt, what filters were used, and who got paid.

Rightsholders who sue a developer or provider must first show that the accused output came from that system and is substantially similar to their work. Because models are opaque, a developer who then claims there was no infringement must produce the training-data sources, training records and operating mode, and may have to back that with scientific explanation. A user who knew or should have known of a prior work, generated a substantially similar piece, and has no fair-use defense, infringes.

Li Jian, chief of the court’s No. 3 Civil Division, said those proof rules still do not answer the questions companies keep asking. During drafting, views diverged sharply on whether AI output can itself be copyrighted, and on whether training a large model on other people’s works without permission is infringement. The opinion therefore makes no ruling on either point, and the court said it will wait for more cases before it tries again.

China should avoid the constraints of both models and seek a balance between AI development and security.

Wang Liming, vice-president of the China Law Society and professor at Renmin University

Wang, writing as the opinion landed, said the European Union had leaned toward security and heavy rules while the United States had leaned toward development and lighter ones. The copyright blank is that balance in practice: identity theft is a named tort, and training-data copyright remains a case-by-case fight.

Fake Celebrity Livestreams Can Trigger Punitive Damages

Zhou Jiahai, director of the research office, said the law cannot expect every shopper to spot a fake. For the same goods or services, a business that uses algorithms to set unreasonable differences in price or terms, and causes harm, can be held to infringe. Using AI to impersonate a celebrity in livestream sales, where that impersonation is fraud, supports a consumer claim for punitive damages.

Self-driving and driver-assist crashes sit in the same consumer chapter. If a defect in the vehicle and the driver’s own fault combine to cause the same harm, the injured person may sue the driver and the maker or seller together under Civil Code Article 1172. Makers and sellers who overstate the automation level, intelligence, performance or use of a car, and harm consumers, can be sued under the Civil Code and the consumer-protection statute. A system handoff in the last second is not, on this text, a complete shield.

WHO CAN BE SUED, AND FOR WHAT

Harm Main target What the opinion allows
Face or voice clone without consent The user, then the provider after notice Damages plus an Article 8 injunction
AI hallucination that injures reputation Provider after a valid notice Civil liability for harm that continues
Algorithmic price discrimination The business running the algorithm Infringement damages
Fake celebrity livestream sales The seller using the impersonation Punitive damages if the conduct is fraud
Driver-assist crash with a vehicle defect Driver and maker or seller together Shared civil compensation

Unfair-competition claims also attach when operators use AI images, video or virtual people to fake traffic and praise, or to run face-swapped “science” clips as false advertising. The court said those tactics mislead buyers and disturb the market.

How These Civil Rules Differ From Europe’s Labels

Europe’s parallel clock is already running. Article 50 of the EU AI Act’s transparency rules that apply from 2 August 2026 require providers to put a machine-readable mark on synthetic text, image, video and audio, and require deployers to disclose deepfakes in a way people can actually see or hear. Companies face fines of up to €15 million, or up to 3% of worldwide annual turnover. Systems already on the market before that date have until December 2026 to finish the marking duty.

Beijing’s new civil opinion does not add that labeling duty. China already imposed administrative labels years earlier. Providers of public generative AI services must, under Article 12 of the interim measures on generative AI services, mark generated images and video in line with the deep synthesis rules that took effect in 2023. Those 2023 rules also told services that edit faces or voices to obtain the person’s consent. The September opinion is doing different work: it tells judges who pays after the harm, and when a court can order a stop.

THE ROAD TO THE SEPTEMBER OPINION

  1. January 10, 2023: Deep synthesis rules take effect, covering face and voice generation and requiring labels and consent for biometric edits.
  2. August 15, 2023: Interim measures on public generative AI services take effect, including lawful training-data sources and the labeling cross-reference.
  3. August 2, 2026: EU Article 50 transparency duties apply to providers and deployers of in-scope systems.
  4. September 7, 2026: The Supreme People’s Court issues the 24-article civil opinion, Fa Fa [2026] No. 10.

The sequence is the policy. China labeled deepfakes as an internet-information problem in 2023. In 2026 it told civil judges to use injunctions and a safe harbor, and to leave the hardest copyright calls for later. Europe, in the same season, made the label itself the legal duty.

AI-Written Filings Now Need a Courtroom Warning

The opinion also turns inward, because fake case citations have already reached Chinese dockets. Si Yanli said the courts have found multiple AI-generated false cases, and that parties and lawyers filed them without a full check. Reports of that pattern clustered in January 2026, and the court’s case database already holds examples.

DUTIES INSIDE THE COURTHOUSE

  • Disclose: If a filing or case-search report was made with AI help, the party must say so when it is submitted.
  • Verify: The filer must check the law, judicial interpretations and cases for truth and accuracy before the document reaches the judge, and bears responsibility for those contents.
  • Fake suits: Using AI, including by stripping labels, feeding selected prompts or interfering with outputs, to invent facts for a false lawsuit can mean a dismissed claim, fines, detention and, if a crime is made out, criminal charges.
  • Forged evidence: Using AI to forge evidence that obstructs a hearing is handled under Civil Procedure Law Article 114, again with fines, detention or criminal charges.

The three principles printed at the front of the opinion are people first, support for innovation, and a hard safety line. The deepfake injunctions serve the first. The harbor, the fault rule, the public-data carve-out and the copyright silence serve the second. Lower courts now have to apply all four at once, in live cases, without a statute that answers the training-data copyright question.

Frequently Asked Questions

Does the Supreme People’s Court Opinion Create a New AI Law in China?

No. Fa Fa [2026] No. 10 is a judicial opinion that tells judges how to use statutes already on the books, including the Civil Code, the Cybersecurity Law, the Data Security Law, the Copyright Law, the Anti-Unfair Competition Law, the Consumer Rights Protection Law, the Personal Information Protection Law and the Civil Procedure Law. Issues that still lack consensus, the court said, were left blank until more experience exists.

Can Chinese AI Companies Train on Photos People Posted in Public?

Generally yes, if the photos are personal information the person made public or that is otherwise lawfully public, the use stays in a reasonable scope, and the person has not clearly refused. Judges weighing that scope are told to look at whether the use is necessary for the model’s function, how sensitive the information is, the setting in which it was posted, and the use a person could fairly expect; a major effect on the person’s rights still requires consent under the statute.

Do AI Chatbots Have to Stop Illegal Deepfakes Before a User Complains?

Not as a civil pre-screening duty. Officials said providers cannot be required to predict and intercept every output, but after a notice that includes preliminary infringement evidence and the rightsholder’s real identity, they must take necessary steps such as stopping generation of the infringing content and blocking the relevant prompt, or they can be held liable for the extra harm.

Did the Court Say AI-Generated Works Can Get Copyright?

It did not. Drafters could not agree on whether AI output can be copyrighted, or on whether training a model on other people’s works without permission is itself infringement, so both questions are omitted. What the court did fix is the proof order: a developer who claims there was no infringement must produce training-data sources, training records and the model’s operating mode.

How Do These Civil Rules Relate to China’s 2023 Deepfake Labeling Rules?

They sit beside them rather than replacing them. The 2023 deep synthesis provisions and Article 12 of the generative AI interim measures already required labels on generated images and video, and consent for face and voice edits, as administrative duties on public internet services; the September opinion adds civil injunctions, the notice-and-act harbor, and fault-based damages without creating a new labeling cause of action.

Disclaimer: This article is news reporting and analysis of a judicial opinion, and it is for information only. It is not legal advice, is not a forecast of how any Chinese court will decide a live dispute, and should not be used as a substitute for counsel on deepfakes, training data, platform liability or consumer claims. Readers who need to act on these rules should consult a qualified lawyer admitted in the relevant jurisdiction before filing a notice, seeking an injunction or changing a product. Figures, article numbers and case-handling instructions reflect the Supreme People’s Court materials as published on September 7, 2026, and later amendments or guiding cases may change how judges apply them.

Harry runs CREATE MORE FLOW, an independent site, as its editor and lead writer, drawing on a decade of journalism that began in reporting and ended up in editing. His process is the same for every piece. A tip or a document comes in, he finds the primary source behind it, whether that is a regulatory filing, a transcript, a dataset he can open or a product he can test himself, and only then does the writing start. Before anything is published, each number is checked against where it came from, quotes are compared with the recording or transcript, and dates are confirmed. That routine serves a global readership across technology, business and news, science and sports, entertainment and lifestyle, travel, auto and gaming. When a mistake gets through, he corrects the article and leaves a dated note explaining the change, under a corrections policy that is published on the site. He reads his own inbox, and readers can reach him at support@createmoreflow.com with tips, documents or complaints.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending