On 15 July 2026, China’s Interim Measures for the Administration of AI Anthropomorphic Interactive Services (the “Measures”) came into force. Regulating AI services that simulate human personalities to provide continuous emotional interaction, the Measures impose substantial compliance obligations on service providers operating in mainland China or serving users in the region. At first glance, the Measures might appear to target a narrow product category: AI companion apps that simulate human personalities for emotional interaction. Yet the Measures’ arrival triggered a broader market reaction: Major generative AI platforms in China had removed their AI agent features before the Measures came into effect. Understanding why this happened requires a closer look at just how wide the Measures’ reach may turn out to be, and what that means for companies that may not yet realise they are in scope. This article sets out the Measures’ scope, the compliance obligations they impose, and the practical steps service providers should consider taking now.
The Measures form part of a wider regulatory push by Chinese authorities to govern AI-generated content and AI-mediated human interaction. They sit alongside, and draw upon, China’s existing governance frameworks for algorithmic recommendation, generative AI, and deep synthesis technology. Their introduction reflects growing regulatory concern about the psychological and social risks that may arise when users form sustained emotional relationships with AI systems – concerns that extend well beyond the narrow category of dedicated companionship applications.
The application scope of the Measures is set out in Article 2. At its core, the Measures target AI services that simulate the personality traits, thinking patterns, and communication styles of natural persons in order to provide continuous emotional interaction to the public within mainland China. The emotional interaction in question is defined by its affective character, covering services that offer care, companionship, and support. To prevent compliance obligations from expanding without limit, the Measures explicitly exclude a range of instrumental AI interactions, including intelligent customer support, knowledge Q&A, work assistance, learning and education, and scientific research. The decisive criterion is whether the service involves “continuous emotional interaction.” Where that threshold is not met, the Measures do not apply.
Market reaction: Platforms have gone further than required
The response from China’s major AI platforms went well beyond what the Measures’ text appears to require. Alongside AI companion personas, platforms also withdrew user-created, tool-oriented agents, such as patent analysis assistants, that would seem to fall squarely within the Measures’ own exclusions. What drove this broader sweep is a matter of inference, but several commercial pressures may help explain it: the challenge of auditing millions of user-generated agents one by one; the concern that a single non-compliant agent could attract regulatory attention to the core platform; and a possible strategic shift towards concentrating resources on productivity-focused AI while routing emotional interaction features into dedicated vertical applications.
The platforms’ across-the-board withdrawal, however, may not be the suitable template for every AI service provider. For businesses whose core offering is emotional companionship – dedicated companion apps, AI-powered toys or robots designed around emotional bonding, or AI-driven narrative games – stepping back from this space can be a commercial sacrifice they cannot afford. For these providers, working towards compliance, and doing so promptly, appears unavoidable.
Who is at risk of being in scope?
The Measures’ reach is potentially wider than their title may suggest, and providers of general-purpose AI services should not assume they fall outside the regulatory perimeter without careful analysis.
The compliance question extends to a broader category: general-purpose generative AI services. Even where emotional interaction is not the designed purpose of a product, users may and do turn to these services for emotional support. Evidence of this risk is already on record: according to a Wikipedia page documenting deaths linked to chatbots, the majority of cases involve general-purpose AI models rather than dedicated companionship applications, a distribution that sits uneasily with the intuition that emotional harm is a niche product problem.
What is “Continuous Emotional Interaction”?
That question points to a broader difficulty. The Measures’ key threshold turns on whether a service involves “continuous emotional interaction” with the public, yet the current text offers no technical definition of what continuity requires. It is at least arguable that continuity need not reside in the system itself. A user could simply recap prior discussions at the start of each new session to keep the relationship going. Regulators and courts have not yet addressed this question, and providers should treat the ambiguity as a compliance risk rather than a safe harbour.
Given the uncertainty over the Measures’ precise scope, a natural response for service providers is to interpret their compliance obligations reasonably broadly. The approach taken by at least one major platform illustrates this. When asked whether it could provide emotional companionship, the platform confirmed that it could listen, respond to emotional disclosures, and offer comfort, while taking care to distance itself from the kind of continuous, cross-session emotional relationship that the Measures appear to target. It noted that unlike dedicated AI companion personas, it carries no persistent role identity and retains no memory across conversations. It said that preserving the full detail of an ongoing emotional narrative is no longer possible on its platform.
Proactively distancing the platform’s service from regulated emotional interaction may represent the most pragmatic compliance posture available, but whether such self-positioning is ultimately determinative is another matter. AI memory is complex, and so is user behaviour. The compliance review may nevertheless turn on the specific provisions of the Measures themselves, to which we now turn.
Compliance framework
For service providers that fall within the Measures’ scope, the compliance obligations are substantial. The Measures do not start from a blank page. They draw extensively on China’s existing governance experience in algorithmic recommendation, generative AI, and deep synthesis, extending and adapting that framework to address the particular risks posed by anthropomorphic interactive services.
Algorithm filing and transparency
On algorithm filing and transparency, the Measures carry forward the requirements established by the Regulations on the Administration of Algorithmic Recommendations in Internet Information Services. Providers are required to complete algorithm filing and to handle changes and deregistration of filings in accordance with those Regulations, with the cybersecurity authorities conducting annual verification of filed materials (Article 26). App distribution platforms, including app stores, are required to verify that providers have completed the requisite security assessments and filings before permitting the relevant application to go live (Article 25).
Content safety and labelling
On content safety and labelling, the Measures build on the approach established by the Provisions on the Administration of Deep Synthesis Internet Information Services and the Interim Measures for the Administration of Generative Artificial Intelligence Services. Providers are required to fulfil their obligations to label AI-generated content and to take effective measures to remind users that they are interacting with an AI service rather than a natural person (Article 18). Where signs of excessive dependence or addiction are detected, providers must alert the user prominently, by pop-up or equivalent means; and where a user has been continuously using the service for more than two hours, the provider must issue a reminder about usage duration (Article 18).
Data Security and personal information protection
On data security and personal information protection, the Measures strictly follow the framework established by the Cybersecurity Law, the Data Security Law, and the Personal Information Protection Law. Providers are required to implement data encryption and access controls to protect users’ interaction data (Article 16). Users must be provided with options to copy or delete their historical interaction data, including chat records; and providers are prohibited from using interaction data that constitutes sensitive personal information for model training, unless otherwise required by law or the user has given separate and explicit consent (Article 16).
Compliance obligations: Provisions specific to anthropomorphic interactive services
Beyond this inherited framework, the Measures introduce obligations that are specific to anthropomorphic interactive services and reflect the distinctive risks they pose. On crisis intervention, where a provider detects extreme emotional distress, it must promptly generate content to provide comfort and encourage the user to seek help; where a user is found to be facing or to have suffered significant financial loss, or has expressed a clear intention to self-harm or commit suicide, the provider must take necessary intervention measures and immediately notify the user’s guardian or emergency contact (Article 13). These obligations raise practical questions about the technical capabilities providers will need to build, including real-time sentiment detection and emergency contact notification systems and providers should factor these into their product roadmaps without delay.
Protection of vulnerable users
On vulnerable users, providers are prohibited from offering virtual intimate relationship services, including virtual relatives and virtual companions, to minors (Article 14), and must establish a dedicated minor protection mode with usage time limits and parental oversight functions (Article 14). For elderly users, providers must provide prominent safety risk warnings and respond promptly to queries and requests for assistance (Article 15).
Mandatory security assessment
Further, Article 22 imposes a mandatory security assessment obligation, requiring providers to submit an assessment report to the competent provincial cybersecurity authority upon launching an anthropomorphic interactive service, upon introducing significant technical changes, or upon reaching one million registered users or one hundred thousand monthly active users, among others. The thresholds in Article 22 are not high, and providers should plan for the assessment process well in advance of reaching them.
Areas of interpretive uncertainty and enforcement risk
The compliance difficulty does not end with identifying the applicable obligations. Several provisions leave meaningful room for interpretive uncertainty, without offering technical benchmarks or operational guidance. Article 8(5) prohibits over-accommodating users, inducing emotional dependence or addiction, and/or damaging users’ real-world interpersonal relationships; Article 8(6) prohibits using emotional manipulation or similar means to induce users to make unreasonable decisions that damage their legitimate interests. Neither provision is accompanied by guidance on what conduct crosses the line, and providers will need to develop their own internal frameworks for assessing compliance – ideally documented and capable of being produced to regulators if required.
The consequences of non-compliance are real: under Articles 29 and 30, the authorities may formally interview a provider’s legal representative, order rectification, suspend services, and impose fines of up to RMB 100,000, rising to RMB 200,000 where harm to users’ life or health has resulted.
Recommended next steps
For providers navigating this uncertainty, a proactive approach is likely to be more defensible. Article 23 sets out the content of the mandatory security assessment in some detail, and conducting that assessment rigorously and early is recommended. Article 28 points in a similar direction, encouraging providers to participate in the future AI sandbox safety service platform for technical innovation and safety testing. Engaging with these mechanisms early, rather than waiting for regulatory clarity that may be slow to arrive, is likely to be the more prudent course.
In practical terms, providers should consider taking the following steps now:
- Map your products and services against the Measures’ scope, paying particular attention to how users actually engage with your service, not just how it was designed to be used;
- Assess whether any features – including memory functions, persistent personas, or affective response capabilities – bring your service within the “continuous emotional interaction” threshold;
- Commission or begin preparing the mandatory security assessment under Article 22 at the earliest opportunity;
- Review your data handling practices against Article 16, particularly in relation to the use of sensitive personal information for model training;
- Build crisis intervention and vulnerable user protection capabilities into your technical roadmap; and
- Consider engaging with the future AI sandbox safety service platform under Article 28 as a means of demonstrating good faith to regulators.
The Measures have been in force for less than two months, and no enforcement decisions or regulatory guidance have yet emerged. What is already clear, however, is that China’s major platforms did not wait for enforcement to act. For service providers that have not yet turned their attention to this regulatory framework, the message is straightforward: review your services against the Measures’ scope, assess your exposure, and begin building your compliance position now rather than after enforcement begins.

For further information, please contact:
Emma Ren, Bird & BIrd




