1. [para. 1][para. 2] AI is boosting efficiency and convenience across daily life, but it is also creating distinctive and unprecedented risks for personal-data protection. China’s internet regulator recently released draft rules for large-scale handlers of personal information, seeking public comment on measures including encryption, de-identification, access controls, and anonymization, while encouraging online-identity authentication, data-labeling, and certification.
2. [para. 3][para. 4] Personal-data protection is hardly new, yet AI’s high-frequency interaction with users has made it more complicated and harder to manage. Generative AI presents particular risks as users interact with chatbots and other tools, and the technical mechanisms behind those interactions can complicate the application of existing privacy rules. Protection frameworks must keep pace with rapidly evolving technology.
3. [para. 5][para. 6] The spread of generative AI is driving industrial and technological development while bringing fresh risks. According to the 57th Statistical Report on China’s Internet Development, the country had 602 million generative-AI users as of December 2025, up 141.7% from end-2024, with penetration of 42.8%, up 25.2 percentage points. Users aged 19 and younger accounted for 26.4% of the total, and minors and older people are especially vulnerable to leaks.
4. [para. 7][para. 8][para. 9] The deeper risks stem from generative AI’s nature: the scale, intensity, and reach of potential leaks can far exceed those of traditional point-to-point systems, and they are harder to detect. AI systems rely on large volumes of personal information at every stage, from data collection and labeling to model training. Outsourced and subcontracted data-labeling work creates multilayered chains where personal information can slip out of control.
5. [para. 10][para. 11] Technical vulnerabilities can also trigger leaks without malicious intent. In March 2023, a flaw in an open-source library exposed parts of other users’ ChatGPT chat histories and payment information. China’s CNCERT warned that information-leakage vulnerabilities are common in domestic large models. Specially crafted inputs can prompt models to reveal personally identifiable information, credentials, and sensitive internal material, including security rules.
6. [para. 12][para. 13][para. 14] The immediate priority is strengthening public awareness. Under interim rules issued by the Cyberspace Administration of China and other agencies, generative-AI providers must process training data lawfully and obtain individuals’ consent where personal information is involved. Users may not fully understand terms governing data retention and training, especially for minors or sensitive information, so platforms should obtain consent in clearer, more intelligible ways.
7. [para. 15][para. 16][para. 17] Technology companies need to place greater emphasis on technical governance. Differential privacy and homomorphic encryption can strengthen privacy protections built into generative-AI systems. In a Changsha court case, a student used “AI face-forgery video” technology to steal more than 50,000 yuan (about $7,412) from bank cards in under four months; Hangzhou heard a public-interest lawsuit involving an AI-generated face passing liveness detection. These cases show how misuse of personal information can fuel AI-enabled crime.
8. [para. 18][para. 19][para. 20][para. 21][para. 22] Protecting personal information also requires tougher enforcement and more detailed rules. Regulators have said model providers must safeguard user inputs and usage records, not collect unnecessary personal information, illegally retain identifiable data, or provide inputs and records to others. Interim rules require providers to respond to individuals’ requests to access, copy, correct, supplement, or delete their information. Effective governance must turn requirements into enforceable protections and ensure large handlers follow through on privacy commitments.
AI generated, for reference only