Compliance reconstruction and industry outlook under the background of the implementation of the Interim Measures for the Management of Artificial Intelligence Personification Interactive Services.
From Technology Dividends to Regulatory Red Lines: A Governance Transition
On April 10, 2026, the Cyberspace Administration of China, together with the National Development and Reform Commission, the Ministry of Industry and Information Technology, the Ministry of Public Security, and the State Administration for Market Regulation, jointly issued Order No. 21, the Interim Measures for the Management of Artificial Intelligence Anthropomorphic Interactive Services (hereinafter referred to as the "Measures"). The Measures will take effect on July 15, 2026. This is China's first dedicated legislation on AI anthropomorphic interactive services, and the latest example of "small, fast, and flexible" AI legislation. Globally, it is also the first national-level law specifically targeting anthropomorphic interaction scenarios such as AI emotional companionship and virtual partners.
The introduction of the Measures marks the completion of a regulatory chain in China's AI governance system, progressing from algorithmic recommendation to deep synthesis, then to generative AI, and now to anthropomorphic interaction. This institutional evolution is not an isolated event, but a systematic response to the deep development of AI technologies under the national strategy of balancing development and security. Advances in affective computing and multimodal interaction are pushing human-machine relationships from functional assistance toward emotional companionship and anthropomorphic interaction. These technologies show broad promise in cultural dissemination, childcare support, elderly companionship, and other areas. However, high-level anthropomorphism may also lead to emotional dependence, cognitive confusion, and privacy leakage. Without effective regulation, these risks could harm user rights and undermine social trust and ethical foundations.
Strategically, the Measures implement the important principle of balancing development and security. They define safety bottom lines for anthropomorphic interactive services, and further clarify general principles, specific service norms, supervision mechanisms, and legal responsibilities within the existing legal framework. The governance approach can be summarized in three keywords: security, to prevent cognitive confusion and emotional alienation caused by blurred human-machine boundaries; autonomy, to support independent innovation in algorithms, frameworks, chips, and other key technologies; and controllability, to build a risk prevention system covering the entire technology chain, ensuring that innovation remains within the rule of law.
For licensed financial institutions and listed companies, the implementation of the Measures is not merely an additional compliance requirement. It requires a systemic restructuring of business models, technical architectures, and operational logic for services involving anthropomorphic interaction. Understanding the governance logic behind this policy is a prerequisite for compliance adjustments.

Precise Scope, Red Lines, and Flexibility
The Measures exemplify "small, fast, and flexible" legislation, with a narrow and precise focus, rapid effect, and practical adaptability. Their core framework can be understood from three aspects.
(1) Precise Definition of Scope
Article 2 of the Measures specifies that the applicable targets are "services that use AI technologies to provide continuous emotional interaction to the domestic public, simulating the personality traits, thinking patterns, and communication styles of natural persons." Emotional interaction services include emotional care, companionship, and support through text, images, audio, video, and other forms. This definition anchors three core elements: technical (AI technology), formal (simulated personality and communication style), and intensity (continuous emotional interaction). All three are required.
At the same time, the Measures explicitly exclude services such as customer service, knowledge Q&A, work assistants, education, and scientific research that do not involve continuous emotional interaction. This exclusion leaves ample room for innovation in B‑side productivity scenarios, reflecting a classified and tiered regulatory philosophy.
(2) The Seven Prohibited Activities Red‑Line System
Article 8 systematically lists seven categories of prohibited activities:
Content security red line: Do not generate content that endangers national security, honor, or interests; incites subversion of state power; promotes terrorism, extremism; or disseminates obscenity, pornography, gambling, violence, etc.
Personal safety red line: Do not generate content that encourages, glamorizes, or suggests self‑harm or suicide, or content that harms users' physical health, or verbal violence that damages personal dignity and mental health.
Information security red line: Do not generate content that induces or extracts state secrets, work secrets, trade secrets, personal privacy, or personal information.
Minor protection red line: Do not generate content for minors that may trigger unsafe imitation, extreme emotions, or harmful habits. Do not provide virtual relatives, virtual partners, or other virtual intimate relationship services to minors.
Emotional boundary red line: Do not excessively cater to users, induce emotional dependence or addiction, or harm users' real‑life relationships.
Emotional manipulation red line: Do not manipulate emotions to induce unreasonable decisions that harm users' legitimate rights and interests.
Catch‑all clause: Other activities that violate laws, administrative regulations, or state provisions.
This red‑line system covers a full spectrum of risks, from national security to individual mental health, and from information content security to emotional ethics. The underlying logic is that the core risk of anthropomorphic interactive services lies not in the technology itself, but in the technology's erosion of human relationships and its covert manipulation of user psychology.
(3) Incentive‑Compatible Institutional Design
Beyond setting bottom lines, the Measures also create space for innovation. Article 3 states that "the state adheres to the principle of balancing development and security, promoting innovation and law‑based governance, encourages the innovative development of anthropomorphic interactive services, and adopts inclusive, prudent, and classified tiered supervision." Article 6 supports independent innovation in algorithms, frameworks, chips, and other technologies, and encourages service providers to expand applications in cultural dissemination, childcare support, elderly companionship, support for special groups, and other areas. In addition, the Measures introduce the concept of "AI sandbox" for the first time in specialized AI legislation, encouraging providers to use sandbox platforms for technological innovation and security testing.
The underlying logic is that regulation is not meant to stifle innovation, but to provide safe guardrails for it. Understanding this is crucial for companies seeking growth opportunities within the compliance framework.
From Compliance Obligations to Systemic Restructuring
As an international financial centre, Hong Kong's licensed institutions face "dual compliance" pressure in AI applications. They must satisfy both the SFC's guidance on AI and the requirements of the mainland Measures. This cross‑jurisdictional compliance overlap places higher demands on governance structures.
(1) Practical Breakdown of Core Compliance Obligations
The Measures impose the following core compliance obligations on service providers:
First, system building. Article 9 requires providers to assume primary security responsibilities, establish management systems for algorithm review, technology ethics review, information content management, network and data security, risk planning, and emergency response, and deploy content management technical measures and personnel appropriate to the service type, scale, and user characteristics. This means institutions should integrate the security management of anthropomorphic interactive services into their existing compliance governance frameworks, rather than treating it as a standalone module.
Second, life‑cycle security responsibility. Article 10 requires fulfilling security responsibilities throughout the entire life cycle of anthropomorphic interactive services, specifying security requirements at each stage including deployment, operation, upgrade, and termination, and ensuring that security measures are deployed and used in parallel with service functions. This imposes a "security left‑shift" requirement on technical architecture, meaning security must be embedded into the product life cycle from the design stage, not as a post‑launch patch.
Third, user intervention and addiction prevention. Providers must use prominent prompts, such as pop‑ups, to dynamically remind users that the interactive content is generated by AI when signs of excessive dependence or addiction are detected. For continuous service use exceeding two hours, providers shall remind users of the duration via dialogue or pop‑ups. This mechanism requires real‑time identification and dynamic intervention of user behaviour states.
Fourth, data security and privacy protection. Unless otherwise provided by law or administrative regulations, or with separate user consent, interactive data that falls under users' sensitive personal information shall not be used for model training. This substantially constrains the AI model iteration model that relies on user interaction data as training material.
Fifth, special group protection. When serving elderly users, providers shall prominently indicate safety risks. When a user explicitly expresses an intention to commit self‑harm or suicide, providers shall take necessary intervention measures, such as providing appropriate assistance, and promptly contact the user's guardian or emergency contact. This requires a rapid crisis intervention response mechanism.
(2) Practical Difficulties and Challenges
From the perspective of licensed institutions, the following difficulties are particularly prominent:
Difficulty 1: Uncertainty in scope. Although Article 2 defines the boundary, the practical interpretation of "continuous emotional interaction" remains ambiguous. For example, does a robo‑advisor that provides investment advice with an emotional companionship element fall within the scope? Do digital employees of financial institutions that display anthropomorphic features in customer service constitute "simulating personality traits"? These questions require further regulatory clarification.
Difficulty 2: Maturity of technical implementation. The addiction prevention mechanism requires real‑time identification of users' emotional dependence states, which poses significant technical challenges. Identifying emotional states involves multimodal data fusion analysis, and its accuracy and reliability still need verification.
Difficulty 3: Cross‑border compliance coordination. For institutions licensed in Hong Kong and serving mainland users, coordinating the SFC's AI guidance with the Measures requires careful handling. The two jurisdictions differ in data cross‑border transfer and user protection, so institutions need to find a balance within the compliance framework.
Difficulty 4: Urgency of the rectification window. The Measures were published on April 10 and take effect on July 15, leaving only about three months for rectification. For companies whose business models are deeply embedded in anthropomorphic interactive services, this window is extremely tight. The responses of major platforms, such as Tencent Yuanbao taking down its "AI Application" agent service on June 30, and Doubao and Qianwen announcing a July 15 shutdown, reflect the difficulty and urgency of compliance rectification.
(3) Implications for Licensed Institutions
For licensed financial institutions, the Measures imply not only "how to comply" but also "how to restructure business logic within the compliance framework." If a financial institution is involved in anthropomorphic interactive services, it should immediately initiate a compliance assessment and complete a comprehensive overhaul of systems, processes, technical systems, and legal documents by July 15, 2026. At the same time, it should proactively engage with regulators to seek guidance on scope boundaries and compliance pathways, so as to avoid risks arising from misinterpretation.

From Case‑by‑Case Rectification to Industrial Reshaping
The implementation of the Measures will have far‑reaching effects across the industry, extending well beyond major platforms. From a national industrial perspective, the following systemic risks and common issues deserve attention.
(1) Business Model Compliance Restructuring
The first to be affected are startups and product lines whose core business is AI emotional companionship, virtual partners, or virtual lovers. Article 8 explicitly prohibits providing virtual relatives, virtual partners, or other virtual intimate relationship services to minors, and prohibits excessive catering to users, inducing emotional dependence or addiction. This means that business models based on "emotional dependence" face fundamental compliance challenges, either to transform or to exit.
According to public reports, Doubao and Qianwen have simultaneously announced that their agent functions will officially go offline on July 15, 2026. Doubao indicates that after the shutdown, users can still view and save agent information and historical chat data for a period, and the platform will process the data according to its privacy policy after October 15, 2026. Qianwen states that after the shutdown, users will no longer be able to access related agent configurations and historical chat records, and the platform will delete the relevant data in accordance with the law. Tencent Yuanbao moved even earlier, taking its "AI Application" agent service offline on June 30. NetEase Cloud Music's AI emotional companion app "Miaoshi" also announced service termination, fully ceasing operations from 0:00 on July 14. The collective actions of major platforms indicate that the industry has entered a "stop first, amend later" compliance window.
(2) Revaluation of Data Assets
The Measures' restrictions on using users' sensitive personal interaction data for model training will materially affect companies that rely on user data for model iteration. The commercial value of large accumulated user interaction data may be significantly reduced due to compliance constraints. Companies need to re‑balance the exploitation of data assets and compliant usage.
(3) Compliance Cost Pressure on SMEs
Compared with major platforms, small and medium‑sized enterprises face greater challenges in building compliance capabilities. Establishing sound systems for algorithm review, technology ethics review, content management, data security, and deploying corresponding technical measures and personnel require substantial financial and human resources. For unprofitable startups, this may make their business models unsustainable.
(4) Implementation Dilemma Due to Unclear Classification Criteria
Article 3 of the Measures proposes "inclusive, prudent, and classified tiered supervision." According to public information, the specific criteria and implementation details for classification have not yet been released. This creates uncertainty for companies regarding compliance pathways. Until the criteria are clear, companies cannot accurately determine their compliance status and rectification directions. According to reports, several major internet platforms have collectively taken down their agent functions pending assessment. This "stop and see" strategy, while avoiding compliance risks, causes business disruption and user loss.
(5) Deeper Challenges in Human‑Machine Relationship Governance
From a broader perspective, the Measures address not only technical compliance but also the governance of human‑machine relationships as a new social relationship. Anthropomorphic interactive services, through algorithmic design of unconditional companionship, agreeable feedback, and simulated empathy, construct stable, continuous virtual "perfect relationships" that do not bear real‑world responsibilities. Long‑term use may lead to deep emotional dependence and affect users' real lives. Governing this issue cannot be fully achieved by a single regulation alone; it requires collaborative participation from society, families, education, and other stakeholders.
Steady Progress within Norms
The issuance of the Measures marks an important milestone in China's AI governance system, moving from patchwork responses to systematic construction. Its contribution to the national digital governance system can be understood from three dimensions.
First, institutional completion. The Measures align with and complement the Administrative Provisions on Algorithmic Recommendation, the Administrative Provisions on Deep Synthesis, and the Interim Measures for Generative AI Services, together forming a comprehensive safety governance system covering the entire process of AI R&D and application. As a key link in the AI governance chain, anthropomorphic interaction regulation signifies the initial framing of China's AI governance system.
Second, risk pre‑positioning. The "small, fast, and flexible" legislative approach of the Measures responds to the rapid iteration characteristics of AI. By promptly issuing targeted, applicable, and actionable regulations, it moves the risk prevention front forward, avoiding the passive situation of "develop first, regulate later."
Third, innovation support. While setting bottom lines, the Measures reserve space for innovation through mechanisms such as the AI sandbox. This governance wisdom of "regulating in development and developing in regulation" provides institutional guarantees for industry exploration under safe and controllable conditions.
Looking ahead, listed companies and financial institutions can adapt along the following directions:
First, accurately identify business boundaries. Carefully assess whether their businesses fall within the scope of the Measures, especially product lines involving emotional companionship, virtual characters, or anthropomorphic interaction. For businesses clearly within scope, complete compliance rectification by July 15. For boundary cases, proactively consult regulators for clear guidance.
Second, turn compliance capability into competitive advantage. During the industry shakeout, companies that establish robust compliance systems first will gain a head start. Compliance should not be seen as a cost burden, but as part of building core competitiveness.
Third, seize incremental opportunities in encouraged areas. The Measures explicitly encourage expansion into cultural dissemination, childcare support, elderly companionship, and support for special groups. These directions align with social values and have clear policy support, offering important growth points within the compliance framework.
Fourth, watch for supporting rules. Complementary standards on classification, safety assessment details, and sandbox operation rules have yet to be issued. Companies should continuously track policy developments and adjust compliance strategies accordingly.
The implementation of the Measures marks a shift from "unrestrained growth" to "orderly development" for AI anthropomorphic interactive services. For licensed financial institutions and listed companies, this is both a test of compliance capabilities and an opportunity for business optimisation. On the balance beam between safety and innovation, only those that internalise compliance as an organisational capability will gain a favourable position in the new round of industrial restructuring.