惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Attack and Defense Labs
Attack and Defense Labs
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园_首页
博客园 - 司徒正美
月光博客
月光博客
Apple Machine Learning Research
Apple Machine Learning Research
T
Tailwind CSS Blog
Jina AI
Jina AI
GbyAI
GbyAI
Y
Y Combinator Blog
罗磊的独立博客
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
P
Proofpoint News Feed
Last Week in AI
Last Week in AI
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
量子位
雷峰网
雷峰网
博客园 - 【当耐特】
H
Hackread – Cybersecurity News, Data Breaches, AI and More
The GitHub Blog
The GitHub Blog
S
Secure Thoughts
博客园 - 三生石上(FineUI控件)
Cyberwarzone
Cyberwarzone
NISL@THU
NISL@THU
J
Java Code Geeks
C
Cisco Blogs
人人都是产品经理
人人都是产品经理
Webroot Blog
Webroot Blog
腾讯CDC
博客园 - 叶小钗
C
Cyber Attacks, Cyber Crime and Cyber Security
T
Troy Hunt's Blog
AI
AI
L
LangChain Blog
Know Your Adversary
Know Your Adversary
T
Tenable Blog
M
MIT News - Artificial intelligence
P
Privacy & Cybersecurity Law Blog
L
LINUX DO - 最新话题
Hugging Face - Blog
Hugging Face - Blog
F
Full Disclosure
P
Proofpoint News Feed
AWS News Blog
AWS News Blog
有赞技术团队
有赞技术团队
A
Arctic Wolf
Security Archives - TechRepublic
Security Archives - TechRepublic
S
Schneier on Security
Recent Commits to openclaw:main
Recent Commits to openclaw:main
W
WeLiveSecurity
The Cloudflare Blog

Privacy & Cybersecurity Law Blog

New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale and Licensing Restrictions CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026 Illinois Governor Signs Frontier AI Model Law New Hampshire Amends the NHDPA to Prohibit the Sale of Children’s Personal Data Canada’s Proposed Social Media Ban for Children and Chatbot Regulation: Bill C-34’s Impact on Platforms European Commission Unveils Cybersecurity and AI Action Plan European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays EDPB Opens Public Consultation on New Personal Data Breach Notification Template European Commission Advances New Proposal to Expand Cloud Capacity and AI Infrastructure U.S. Supreme Court FTC Ruling Prompts Fresh Scrutiny of EU-U.S. Data Privacy Framework China Issues New Measures for Network Data Security Risk Assessment China Issues Regulations on Internet Content Multi-Channel Network Distribution Services UK Data Protection Complaints Obligations Take Effect Vermont Enacts Significant Amendments to Data Broker Legislation Vermont Becomes 23rd State with Comprehensive Consumer Privacy Law Louisiana Enacts Comprehensive Consumer Privacy Law Connecticut Signs Comprehensive AI Bill into Law China CAC Issues Guidance on Conducting Audits Technology Companies Should Prepare for FTC Enforcement of Take It Down Act HHS Reorganizes Office for Civil Rights Oregon Prohibition on Public Body Disclosures to Data Brokers for Federal Immigration Purposes Now In Effect Connecticut Privacy Law Updates: Data Broker Rules, Geolocation Sale Ban, Surveillance Pricing Restrictions, and Genetic Data Regulations NYDFS Warns of Cybersecurity Risks from Frontier AI Models UK and Australia Announce Memorandum of Understanding on AI Security FTC Announces Settlements With Three Marketing Firms Over Allegations of Deceptive Statements About Active Listening AI-Powered Services Cybersecurity Authorities Issue Joint Guidance on the Adoption of Agentic AI Systems Colorado AI Act Amended and Effective Date Delayed European Commission Releases Draft Guidelines on High-Risk AI Under the EU AI Act Texas AG Announces Lawsuit Against Netflix for Alleged Misrepresentations Regarding User Data UK ICO Recommends Targeted Changes to PECR Rules for Online Advertising California AG Announces Record $12.75M Settlement with GM over CCPA Data Minimization and Purpose Limitation Violations Illinois Department of Human Rights Issues Regulations Governing the Use of AI in Employment Decisions Delta Dental Agrees to $2.25 Million Settlement with NYDFS Over MOVEit Data Breach Response Maryland Enacts First-of-its-Kind Ban on Surveillance Pricing for Grocery Sales UK ICO Publishes Guidance on Storage and Access Technologies CIPL Report Discusses Significant Alignment between GDPR and Global CBPR CalPrivacy Announces the Agenda for its April 30–May 1 Board Meeting CalPrivacy Requests Preliminary Comments on Notices & Disclosures, Employee Data COPPA Rule Amendment Compliance Deadline Approaches House Republicans Introduce Comprehensive Federal Privacy Bill: “SECURE Data Act” Kentucky Classifies Smart TV Data as Sensitive Alabama Becomes 21st State With Comprehensive Consumer Privacy Law CalPrivacy Director Expects CCPA Compliance Audits in 2026 Virginia Bans Sale of Geolocation Data HHS’ Office for Civil Rights Settles HIPAA Investigation of Health Care Software Company New Jersey Enacts New Restrictions on Health Care Facilities’ Use of Patient Data Washington State Enacts Law Regulating AI Companion Chatbots with Private Right of Action Guardrails for Legal AI: What California’s SB 574 Would Require of Attorneys and Arbitrators
China’s First Regulatory Framework for Virtual Companions Soon to Take Effect
2026-06-29 · via Privacy & Cybersecurity Law Blog

On July 15, 2026, the Interim Measures for the Administration of AI-Based Anthropomorphic Interactive Services (available in Chinese only) (the “Measures”) will take effect. This comprehensive regulation governs the growing industry of artificial intelligence (“AI”) virtual companions and emotional support bots.

The Measures apply to the provision of “AI-based anthropomorphic interactive services” within the territory of Mainland China. These are defined as services that simulate the personality traits, thinking patterns and communication styles of natural persons to provide continuous emotional interaction,​ such as emotional care, companionship and support via text, images, audio or video.  The Measures do not apply​ to intelligent customer service, knowledge Q&A, work assistants, education and learning, or scientific research services that do not involve continuous emotional interaction. Below is a summary of certain of the key provisions of the Measures.

Obligations of Providers

Providers of “AI-based anthropomorphic interactive services” are required to comply with several obligations under the Measures. For example, providers are required to:

  • ensure the AI systems do not generate content that endangers national security, promotes extremism or obscenity, induces self-harm or suicide, or induces disclosure of state secrets or personal information, or push harmful content to minors or use emotional manipulation to induce dependency or harmful decision-making;
  • establish and implement internal policies and procedures for algorithm review, ethics review, content management, cybersecurity and data security, risk contingency plans and emergency response;
  • fulfill security responsibilities throughout the AI system lifecycle with security measures deployed in parallel with AI system functions;
  • ensure training data is lawfully sourced and aligns with core values, undergoes cleaning and labeling, and is protected against data poisoning and tampering;
  • ensure user interaction data is encrypted and access controlled. Unless required by law or with explicit user consent, providers must not share user interaction data with third parties;
  • ensure the AI systems can identify user safety risks in real time while protecting user privacy. The Measures set out requirements for how the AI system should respond to user safety risks;
  • fulfill their obligations on AI-generated content labeling and clearly inform users that they are interacting with an AI system and not a natural person. If a user shows signs of over-dependency or addiction, they must be provided with prominent dynamic reminders (e.g., pop-ups) that the content is AI-generated; and
  • restrict access to the service to children under 14 without explicit consent from a parent or guardian, and implement a "Minor Mode" for children featuring usage limits, reality reminders, guardian alerts, blocking of specific characters, and restrictions on top-ups and spending.

Safety Assessment and Filing

A provider is required to perform and submit a safety assessment​ and report on the AI system and algorithm to the provincial-level cyberspace administration in certain instances, including when launching a new AI-based anthropomorphic interactive service or adding AI-based anthropomorphic interactive functions to an existing service, or when registered users reach 1 million​ or when monthly active users reach 100,000. The assessment must cover, amongst other things, security safeguards, identification or intervention in extreme situations, user scale, usage and age structure, and measures for protecting minors and the elderly.