context: The CPC started shoring up its domestic data regime with the 2017 Cybersecurity Law, detailing data localisation and preservation requirements. To accommodate the rapid development of AI and tighten regulations, the NPC (National People’s Congress) Standing Committee proposed revision to the bill in 2025. The amendment decision was passed on 28 October 2025. The following are comments by an NPC special committee spokesperson on revision rationale.
This revision responds to new circumstances and issues that emerged in regulatory practice, adopting a piecemeal approach to consolidate legal liability, notes Wang Xiang 王翔 NPC (National People’s Congress) Standing Committee Legislative Affairs Commission spokesperson.
Following the first round of review and feedback from various sectors, the draft amendment is to be further refined in three main areas
- roll out Xi Jinping 习近平directives on building a cyber power: added clause
- cybersecurity work shall uphold the leadership of the CPC
- uphold a holistic approach to state security: balance development and security
- address the need for AI governance and development
- AI: strategic tech
- driving a new wave of scientific and industrial transformation
- profoundly changing human life and production
- integrating AI into economic and social development could inject new momentum into Chinese-style modernisation
- parallel risks unseen in the past
- adhere to Xi's directives
- take firm control of AI and development
- steer AI use towards a beneficial, safe and fair direction
- adds framework provision on AI safety and development
- support basic research in AI theory and key tech, such as algorithms
- promote AI infrastructure build-up
- improve ethical norms for AI
- boost risk monitoring and assessment
- innovate and enhance AI security regulation
- AI: strategic tech
- improve legal liability provisions
- refine penalties for failing to perform cybersecurity obligations: in line with
- enactment of the Data Security Law and the Personal Information Protection Law
- rollout experience of Cybersecurity Law
- further consolidating provisions against certain offences
- personal data protection: boosting coordination with the Civil Code and Personal Information Protection Law
- refine penalties for failing to perform cybersecurity obligations: in line with