---
title: "China's generative-AI security baseline is now live — what GB/T 45654-2025 actually asks"
date: 2026-10-01
category: Policy & Governance
site: NeuroAI
canonical: https://neuroai.site/a/na-policy-genai-security-baseline-45654
language: en
---

# China's generative-AI security baseline is now live — what GB/T 45654-2025 actually asks

> A new national recommended standard, GB/T 45654-2025, sets the security homework behind China's generative-AI filing regime — covering training data, model safety and verifiable measures.

Most readers heard about China's AI "rules" as a vague cloud of paperwork. One concrete piece landed on 1 November 2025, and almost nobody outside compliance teams noticed it: a national standard that tells a generative-AI (生成式人工智能) service exactly what "safe enough to launch" means.

It is not a press-release slogan. It is a technical checklist.

## The standard, in plain terms

The document is **GB/T 45654-2025**, full title *Cybersecurity Technology — Basic Security Requirements for Generative AI Services* (《网络安全技术 生成式人工智能服务安全基本要求》).

Key facts, verified on the national standards platform (samr.gov.cn):

- **Issuer:** State Administration for Market Regulation (SAMR) and Standardization Administration (SAC).

- **Published:** 25 April 2025.

- **Effective:** 1 November 2025.

- **Status:** current (现行).

- **Type:** recommended (GB/T), not mandatory (GB).

It is the technical companion to the *Interim Measures for Generative AI Services* (《生成式人工智能服务管理暂行办法》), which took effect in August 2023, and to the **大模型备案 (model filing)** regime run by the Cyberspace Administration of China (CAC).

## What it actually covers

The standard is built around three load-bearing requirements:

- **Training-data security:** where the pre-training and optimization data comes from, how it is filtered, and how rights and legality are handled.

- **Model safety:** what the model must not do once deployed, and how those guards are tested.

- **Security measures:** the controls a provider must run continuously — not just at launch.

Crucially, it gives **verification methods** for each requirement. That is the part regulators and third-party evaluators use when they assess a filing. A provider can no longer hand over a vague policy paragraph; the standard points to how a claim gets checked.

## Why "recommended" still bites

Because the prefix is GB/T, the standard is technically voluntary. But in practice it is the reference manual for the filing system. If your service goes through 大模型备案, the evaluators use documents like this to decide whether you pass.

So the real hierarchy is:

- The *Interim Measures* set the legal obligation.

- The filing (备案) regime makes it operational.

- GB/T 45654-2025 tells everyone what "good" looks like.

A mandatory counterpart, **GB 45438-2025** (AI-generated content labeling), took effect on 1 September 2025 and forces visible and hidden watermarks on synthetic content. The security baseline and the labeling rule are two halves of the same policy push — one about how models behave, the other about how their output is marked.

## Who it touches

Any Chinese provider offering a public or enterprise large model (大模型) service: the model labs, the cloud platforms reselling inference, and the industry players fine-tuning domain models. It also shapes overseas model providers that serve China-facing products, because the filing logic follows the deployment, not the headquarters.

## A day in the compliance workflow

For a team building a public model, the standard turns vague promises into a checklist it can hand to an auditor. Training-data provenance stops being a sentence in a launch blog and becomes a documented chain — source, license, filter, and a record of how rights were handled. Model-safety testing is expected to be repeatable, not a one-off demo. And the security measures are framed as continuous controls, which means a post-launch incident is judged against whether the controls were actually running, not against whether the model happened to be safe on launch day.

## Why this matters beyond China

The interesting part for global readers is that "how do we certify a model is safe" is an unsolved problem everywhere. The EU's AI Act leans on conformity assessments; the US has no single federal standard yet. China's approach — a recommended technical baseline that the filing system quietly enforces — is a different bet on the same question. Even if you never file in China, the structure shows what a regulator-grade checklist looks like when someone actually writes it down. And because the text is public, a foreign team can read it directly instead of guessing from press summaries — a small but real transparency win that most regimes do not offer.

## Honest limitations

This article describes the standard's scope and dates from the official national-standards record; it does not reproduce the full technical text. Because GB/T 45654-2025 is recommended, real enforcement runs through the filing regime, and we cannot quantify how strictly or uniformly it is applied across provinces or sectors. The standard also focuses on general generative services and does not, by itself, cover specialized domains like medical or invasive BCI devices, which sit under separate medical-device rules.

## What readers can do now

- If you ship a model in China, read GB/T 45654-2025 alongside the *Interim Measures* before any launch — the filing will be measured against it.

- Treat training-data provenance as a first-class deliverable, not a footnote; the standard makes it testable.

- Separate the two rules in your compliance plan: labeling (mandatory, GB 45438-2025) vs. security baseline (recommended but filing-linked, GB/T 45654-2025).

---

Published by NeuroAI (https://neuroai.site/) — https://neuroai.site/a/na-policy-genai-security-baseline-45654
Free to quote with attribution and a link to the original.
