Posted in

China’s amended Cybersecurity Law in force from 1 January 2026: AI clauses, tenfold penalties and wider extraterritorial reach

  • The Decision amending the Cybersecurity Law was adopted on 28 October 2025 and takes effect on 1 January 2026, with 14 amendments and a reissued text.
    修改《网络安全法》的决定于2025年10月28日通过、2026年1月1日起施行,共14项修改并重新公布。
  • A new Article 20 builds the first basic-law “development plus oversight” framework for artificial intelligence in China.
    新增第20条,在中国基础性法律层面首次为人工智能构建”发展保障+安全监管”双重框架。
  • Maximum fines jump from the million-yuan range to RMB 10 million, and dual liability on units and responsible individuals is now the norm.
    罚款上限由百万级跃升至1000万元级,单位与直接责任人的双罚制成常态。
  • Critical information infrastructure operators face procurement-linked penalties of one to ten times the purchase amount.
    关键信息基础设施运营者面临”采购金额1—10倍”的罚则。
  • Extraterritorial application is widened: overseas actors harming China’s cybersecurity may be pursued and sanctioned, including asset freezes.
    域外适用扩大,境外危害中国网络安全的机构、组织、个人可被追究法律责任并面临包括冻结财产在内的制裁。
  • Personal information handling is explicitly tied to the Civil Code and PIPL, tightening the legal basis for processing.
    个人信息处理被明确要求遵守《民法典》《个人信息保护法》,做实法律衔接。
  • Foreign-invested enterprises should re-screen CII status, verify product certifications, and re-align cross-border data and remote-access arrangements.
    外商投资企业应重新梳理关键信息基础设施认定、核验产品认证,并对齐跨境数据与远程访问安排。

China’s amended Cybersecurity Law in force from 1 January 2026: AI clauses, tenfold penalties and wider extraterritorial reach | 2026年1月1日施行的新修改《网络安全法》:人工智能专条、阶梯式重罚与域外适用扩围

Overview: Why This Matters to Foreign-Invested Enterprises

The *Decision of the Standing Committee of the National People’s Congress on Amending the Cybersecurity Law* was adopted at the 18th session of the 14th NPC Standing Committee on 28 October 2025, promulgated by Presidential Order No. 61, and takes effect on 1 January 2026, with 14 amendments and a reissued text.

The Cybersecurity Law, the Data Security Law and the Personal Information Protection Law form the backbone of China’s network and data security legal system. The amendment raises the fine ceiling by an order of magnitude, introduces the first basic-law AI framework, tightens the Civil Code/PIPL link, and expands extraterritorial reach.

The Legislative Facts

The amending Decision was passed at the 18th meeting of the Standing Committee of the 14th NPC on 28 October 2025, promulgated by Presidential Order No. 61, and takes effect on 1 January 2026; the original law had been in force since 1 June 2017, and the amendment renumbers the articles and reissues the full text. Per the Constitution and Law Committee report of 27 October 2025, the Standing Committee deliberated on 25 October, the Committee studied the articles clause by clause that evening, and — after consulting relevant departments — fixed the effective date as 1 January 2026, adopting the suggestions to add AI-promotion content and to widen extraterritorial application.

A New Guiding Principle and the AI Article

The first amendment inserts a new Article 3: “Cybersecurity work adheres to the leadership of the Communist Party of China, implements the holistic view of national security, coordinates development and security, and advances the building of a cyber power.”

The headline addition is new Article 20 — the AI clause. It provides that the state supports foundational AI theoretical research and R&D of key technologies such as algorithms, promotes training-data and computing-power infrastructure, improves AI ethics norms, strengthens risk monitoring, assessment and security supervision, and promotes sound AI application and development; it also supports innovative cybersecurity management and the use of new technologies such as AI to raise protection levels.

Personal Information Linkage

The former Article 40 becomes new Article 42 and adds a second paragraph: a network operator processing personal information must comply with this Law and with laws and administrative regulations such as the Civil Code and the Personal Information Protection Law.

Stepped Penalties: The Order-of-Magnitude Jump

The former Article 59 becomes new Article 61 with a graded, stepped schedule; the maximum fine rises to RMB 10 million.

SeverityWhoUnit fine (RMB)Individual fine (RMB)
General duty failure (Art. 23/27), persistsNetwork operator50k–500k10k–100k
CII duty failure (Art. 35/36/38/40), persistsCII operator100k–1m10k–100k
Serious: large leak / CII partial lossEither500k–2m50k–200k
Especially serious: CII main-function lossEither2m–10m200k–1m

The design is graduated: a first-tier failure draws a warning and a modest fine; only persistence or actual harm escalates. The upper tiers — large-scale data leakage or a CII losing partial function, and a CII losing its main function — carry the RMB 10 million ceiling and individual liability up to RMB 1 million.

Product Certification and the Closing of Applications

New Article 63 targets the supply side: selling or providing network key equipment or dedicated cybersecurity products that have not passed security certification or detection, or that are unqualified, draws an order to stop sales or provision, a warning and confiscation of unlawful gains; where gains are below RMB 100,000 an additional RMB 20,000–100,000 fine applies, and where gains exceed RMB 100,000 an additional one-to-five-times fine applies; in serious cases, business may be suspended, rectified, or licences revoked.

The former Article 61 becomes new Article 64, and disposal measures add “closing the application” alongside “closing the website”.

Critical Information Infrastructure: Procurement and Offshore Storage

The former Article 65 becomes new Article 67: a CII operator using products or services not security-reviewed, or that failed review, in violation of Article 37, is ordered to rectify, stop use, eliminate effects on national security, and fined one to ten times the procurement amount, with responsible individuals fined RMB 10,000–100,000.

New Article 65 (former Article 62) covers unauthorised cybersecurity certification, detection, risk assessment, or publicly releasing vulnerabilities, viruses, attack or intrusion information: a warning and up to RMB 100,000; persistent or serious cases draw RMB 100,000–1,000,000 plus possible suspension, closure or licence revocation, with individuals fined up to RMB 100,000.

New Article 69 (merging former Articles 68 and 69(1)) covers failure to stop transmission of unlawful information, take elimination measures, keep records or report: a warning and up to RMB 500,000; persistent or serious cases draw RMB 500,000–2,000,000 plus possible suspension, closure or revocation, with individuals fined RMB 50,000–200,000; especially serious impact raises the fine to RMB 2,000,000–10,000,000 and individuals to RMB 200,000–1,000,000; electronic-information and app-download providers failing Article 50(2) duties are punished under the same paragraphs.

New Article 71 (merging former Articles 64, 66 and 70) routes three categories to other laws: (1) publishing or transmitting information prohibited under Article 13(2) and other laws; (2) infringing personal-information rights under Articles 24(3) and 43–45; and (3) a CII operator storing personal information and important data offshore, or providing such data offshore, in violation of Article 39; stealing or illegally obtaining, selling or providing personal information not yet constituting a crime is punished by public security authorities.

Proportionate Penalties and Extraterritorial Reach

New Article 73 introduces a general leniency clause: where a violation also meets circumstances for lighter, mitigated or exempt punishment under the Administrative Penalty Law, those provisions apply.

The final amendment changes the former Article 75 to new Article 77 and widens extraterritorial application. Overseas institutions, organisations or individuals endangering China’s cybersecurity are now “pursued for legal liability according to law”; where serious consequences are caused, the public security department and relevant State Council departments “may decide to take freezing of assets or other necessary sanctions.” Adding “pursued for legal liability” and broadening the trigger materially expands the law’s reach beyond China’s borders.

How Officials Framed the Revision

The CAC Network Rule-of-Law Bureau described the amended law as enriching guiding principles, adding AI security and development content, aligning personal-information protection with the Civil Code and PIPL, improving the liability system, and widening extraterritorial application. He Bo, director of the CAICT Internet Law Research Center, noted the stepped penalties categorise general, persistent/serious and especially serious cases, applying punishment and education so enforcement “has both strength and warmth,” and called the 1 January 2026 effective date a marker that “China’s cybersecurity rule-of-law has entered a new stage”; the NPC Standing Committee Economic Law Office stated the amendment implements the thought on building a cyber power and that the three laws together constitute China’s network and data security legal system.

What Foreign-Invested Enterprises Should Do Next

  1. Re-screen CII status. Determine whether your China entity, or parts of it, are or may be designated critical information infrastructure, since the heaviest tiers and the procurement multiple attach to that status.
  2. Verify product certifications. Audit network key equipment and dedicated cybersecurity products against the certification/detection catalogues; obtain and retain proof before purchase and deployment.
  3. Re-align the legal basis for personal-information processing. Update privacy notices, processing records and contracts to cite Article 42(2) and the Civil Code/PIPL linkage.
  4. Build an approval path for outward vulnerability and security-information release. Article 65 rules require internal sign-off before any external disclosure.
  5. Review group-level cross-border data and remote access. The Article 71 offshore route and widened Article 77 reach bear directly on group clouds, cross-border systems and remote operations by overseas parent or affiliate staff.
  6. Re-rate the compliance budget and individual exposure. With dual liability normalised and a RMB 10 million ceiling, assign board-level ownership and director-officer risk awareness.

Related Reading

Two companion articles on this site cover adjacent ground without overlap: the Multi-Level Protection Scheme (MLPS) and foreign-invested enterprises, and the Regulations on Network Data Security Management; the cross-references are pointers.


2026年1月1日施行的新修改《网络安全法》:人工智能专条、阶梯式重罚与域外适用扩围

概览:本次修法对外商投资企业的含义

《全国人民代表大会常务委员会关于修改〈中华人民共和国网络安全法〉的决定》于2025年10月28日第十四届全国人大常委会第十八次会议通过,经国家主席令第六十一号公布,自2026年1月1日起施行,共14项修改并重新公布全文。

《网络安全法》与《数据安全法》《个人信息保护法》共同构成我国网络与数据安全法律体系的支柱;本次修法将罚款上限提高一个数量级,首次在基础性法律层面为人工智能设立框架,做实与《民法典》《个人信息保护法》的衔接,并扩大域外适用。

立法事实

修改决定于2025年10月28日第十四届全国人大常委会第十八次会议通过,由中华人民共和国主席令第六十一号公布,自2026年1月1日起施行。原法自2017年6月1日施行;本次修改相应调整条文顺序并重新公布全文。根据2025年10月27日宪法和法律委员会的报告,常委会于10月25日分组审议,宪法和法律委员会当晚逐条研究,并与有关部门研究后将施行时间确定为2026年1月1日;委员会采纳了”增加促进人工智能应用、运用人工智能提升网络安全保护水平”的意见,也采纳了”扩大域外适用情形”的建议。

新增指导原则与人工智能专条

第一项修改新增第3条:”网络安全工作坚持中国共产党的领导,贯彻总体国家安全观,统筹发展和安全,推进网络强国建设。”

实质性新增是第20条(人工智能专条)。其规定,国家支持人工智能基础理论研究和算法等关键技术研发,推进训练数据资源、算力等基础设施建设,完善人工智能伦理规范,加强风险监测评估和安全监管,促进人工智能应用和健康发展;同时规定,国家支持创新网络安全管理方式,运用人工智能等新技术,提升网络安全保护水平。这是中国基础性法律层面首次为人工智能构建”发展保障+安全监管”双重框架。

个人信息保护的衔接

修改将原第40条改为第42条并增加一款:网络运营者处理个人信息,应当遵守本法和《民法典》《个人信息保护法》等法律、行政法规的规定。这做实了与《民法典》《个人信息保护法》的衔接。

阶梯式罚则:量级的跃升

原第59条改为第61条,引入分级、阶梯式处罚安排,罚款上限由百万级跃升至1000万元级。

情节层级适用主体单位罚款(元)责任人罚款(元)
一般性义务未履行且拒不改正(第23、27条)网络运营者5万–50万1万–10万
关基义务未履行且拒不改正(第35、36、38、40条)关基运营者10万–100万1万–10万
严重后果:大量数据泄露、关基丧失局部功能二者均适用50万–200万5万–20万
特别严重后果:关基丧失主要功能二者均适用200万–1000万20万–100万

设计刻意呈阶梯状:第一层级仅招致警告与较低罚款;唯有拒不改正或实际造成危害才逐级抬升。但顶层——大规模数据泄露或关基丧失局部功能,以及关基丧失主要功能的特别严重情形——触及1000万元上限,责任人个人责任可达100万元。

产品认证检测与应用关停

新增第63条指向供给端:销售或提供未经安全认证、安全检测,或者不合格、不符合要求的网络关键设备和网络安全专用产品,将被责令停止销售或提供、警告并没收违法所得;无违法所得或不足10万元的,并处2万–10万元;违法所得10万元以上的,并处违法所得1–5倍;情节严重的,可责令暂停业务、停业整顿、吊销许可证或营业执照。

原第61条改为第64条,处置措施在”关闭网站”之外新增”关闭网站或者应用程序”。

关键信息基础设施:采购与境外存储

原第65条改为第67条:关基运营者违反第37条,使用未经安全审查或安全审查未通过的网络产品或者服务的,被责令限期改正、停止使用、消除对国家安全的影响,并处采购金额1–10倍罚款,责任人处1万–10万元。

新增第65条(原第62条)规制未经许可开展网络安全认证、检测、风险评估,或向社会发布系统漏洞、计算机病毒、网络攻击、网络侵入等网络安全信息:责令改正、警告,可处1万–10万元;拒不改正或情节严重的,处10万–100万元,并可责令暂停业务、停业整顿、关闭网站或应用程序、吊销许可证或营业执照,责任人处1万–10万元。

新增第69条(合并原第68条与第69条第1项)规制未停止传输违法信息、未采取消除处置措施、未保存记录或未报告:责令改正、警告、通报,可处5万–50万元;拒不改正或情节严重的,处50万–200万元,并可责令暂停业务、停业整顿、关闭网站或应用程序、吊销许可证或营业执照,责任人处5万–20万元;造成特别严重影响、特别严重后果的,处200万–1000万元,责任人处20万–100万元。电子信息发送服务提供者、应用软件下载服务提供者不履行第50条第2款安全管理义务的,依照前两款处罚。

新增第71条(合并原第64、66、70条)将三类行为交由其他法律、行政法规处理处罚:(一)发布或传输第13条第2款和其他法律禁止发布或传输的信息;(二)违反第24条第3款、第43至45条规定侵害个人信息权益;(三)违反第39条规定,关基运营者在境外存储个人信息和重要数据,或向境外提供个人信息和重要数据。窃取或非法获取、非法出售或非法提供个人信息尚不构成犯罪的,由公安机关依法处罚。

过罚相当与域外适用扩围

新增第73条引入一般从轻条款:违反本法规定但具有《行政处罚法》规定的从轻、减轻或不予处罚情形的,依照其规定。

最后一项修改将原第75条改为第77条,扩大域外适用。其现规定:境外的机构、组织、个人从事危害中华人民共和国网络安全活动的,”依法追究法律责任”;造成严重后果的,国务院公安部门和有关部门并可以决定对该机构、组织、个人采取冻结财产或者其他必要的制裁措施。原条文仅规定冻结财产等制裁,新增”依法追究法律责任”且触发情形扩大,使该法的域外辐射显著拓宽。

官方对本次修法的定调

中央网信办网络法治局指出,修改后的网络安全法”充实网络安全工作指导原则,增加促进人工智能安全与发展的内容,在个人信息保护方面做好与《民法典》和《个人信息保护法》的衔接,进一步完善网络安全法律责任制度,扩大域外适用情形”。中国信通院互联网法律研究中心主任何波在网信办官网刊文表示,新法设置阶梯式处罚,按一般性违法、拒不改正或情节严重、造成特别严重影响/后果分类施策,宽严相济,使执法”既有力度又有温度”;并称2026年1月1日施行”标志着我国网络安全法治建设进入新阶段”。全国人大常委会法工委经济法室表示,修改重点之一是贯彻网络强国重要思想、充实指导原则;网络安全法与数据安全法、个人信息保护法共同构成我国网络安全和数据安全法律体系。

外商投资企业下一步应做什么

  1. 重新梳理关基认定。 厘清中国实体或其部分是否被认定或可能被认定为关键信息基础设施,因为最重罚则层级与采购倍数均附着于该身份。
  2. 核验产品认证。 对照认证/检测目录审计网络关键设备与网络安全专用产品,在采购与部署前取得并留存证明。
  3. 对齐个人信息处理的法律依据。 更新隐私政策、处理记录与合同,引据第42条第2款及《民法典》《个人信息保护法》衔接。
  4. 建立漏洞与网络安全信息对外发布的审批路径。 第65条风险评估与信息发布规则要求任何对外披露前完成内部签批。
  5. 复核集团层面的跨境数据与远程访问。 第71条境外存储/提供路径与拓宽的第77条域外适用,直接关涉集团云、跨境系统与境外母公司或关联方人员的远程运维。
  6. 重估合规预算与个人风险。 双罚制常态化、上限1000万元,须配置董事会层级的责任归属与高管风险意识。

延伸阅读

本站另有两篇相邻主题文章,互不重叠:网络安全等级保护(MLPS)与外资企业、《网络数据安全管理条例》。新修改的《网络安全法》作为基础性法律居于二者之上;此处仅作交叉引用,不作重写。

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *