On 2 September 2026, the Cyberspace Administration of China (CAC) reported progress in the second phase of its targeted AI enforcement campaign, with actions spanning content generation, account operations and app distribution; enterprises should examine how review responsibilities and accountability connect across these stages. On 2 September 2026, the Department of Science and Technology of the Ministry of Industry and Information Technology (MIIT) invited comments on drafts submitted for approval of recommended national standards, including “Intelligent manufacturing—Guidelines for the implementation of intelligent decision making”, providing a reference for defining requirements and preparing acceptance criteria for industrial intelligent decision-making projects, without creating new mandatory obligations. On 4 September 2026, the CAC published an implementation plan jointly issued by seven departments, setting a policy direction for assessing resource consumption across the generative AI lifecycle and encouraging proactive disclosure, with implications for model energy-efficiency records and supplier transparency. On 1 September 2026, Hong Kong’s Office of the Privacy Commissioner for Personal Data (PCPD) reported on a briefing session for its school AI sandbox, which provides privacy and technical guidance for educational applications while leaving participating schools responsible for compliance. On 1 September 2026, Singapore’s Accounting and Corporate Regulatory Authority (ACRA) updated its explanation of AI-assisted screening of financial statement disclosures, outlining a process of automated identification, human validation and advisory letters, with potential material disclosure non-compliance subject to escalation to formal regulatory review.
On 2 September 2026, the Cyberspace Administration of China (CAC) reported progress in the second phase of the “Qinglang” campaign to address misconduct in AI applications, publishing illustrative cases involving false information, impersonation, infringement of minors’ rights and non-compliant AI applications.
The announcement is an enforcement progress update and introduces no new regulatory provisions. Local cyberspace authorities organise inspections and remediation, platforms take action on content and accounts, and app stores conduct admission reviews, spot checks and retesting, establishing a governance chain spanning generative services, distribution platforms and app distribution. Specific measures described in the update include reviewing training data, restricting non-compliant outputs, implementing content labelling, and addressing coordinated online manipulation that uses AI-managed accounts to simulate human users. Official figures report the cumulative removal of more than 5.61 million items of unlawful or non-compliant information, action against more than 49,000 accounts, and measures involving more than 2,400 non-compliant websites, apps and other services. These are cumulative results and should not be interpreted as new penalties imposed during the reporting week; actions against accounts should not automatically be equated with administrative penalties.
For enterprises operating digital human marketing, content generation or public-facing AI agents, deployment reviews should start with the actual publishing workflow. For example, digital humans used to sell products may raise both likeness authorisation issues and the risk of false product claims; enterprises can link authorisation documents, product fact-checks and publication approvals to a single content record. Agent testing should cover cover images, descriptions and multi-turn conversations, rather than checking only individual responses. When integrating third-party models, enterprises should clarify the respective responsibilities of the supplier and the enterprise for output blocking, propagation of content labels and complaint investigations, and repeat testing after model updates. Approvals and audit trails should be traceable to specific content and accountable individuals, with records such as the model version, review outcome and publishing account; the scope and duration of retention should reflect the actual business context and applicable rules. These recommendations respond to the update’s cases involving false advertising by digital humans, non-compliant agent content and platform remediation. They concern the design of deployment controls and are not new, uniform technical requirements introduced by the announcement.
The campaign follows the two-phase approach previously announced: the launch notice of 30 April 2026 focused the first phase on filing requirements, training-data security and review capabilities, while the second phase targets content generation and dissemination and account abuse. The 2 September update provides practical examples of action taken during the second phase. Subsequent monitoring can assess whether enterprise remediation covers the original enforcement priorities, without speculating about new penalty regimes. In parallel, on 31 August 2026, the European Commission designated ChatGPT as a Very Large Online Search Engine under the Digital Services Act (DSA), which is already in force, and explained that the service must comply with additional systemic risk assessment and mitigation obligations within the transition period following notification of the designation. Both initiatives address illegal content and the protection of minors, but use different regulatory instruments and assign responsibility to different entities: China’s campaign examines content, accounts and applications, while the EU designation targets the operator of a specific large service. Enterprises operating across jurisdictions may reuse content detection and investigation tools, but still need to determine separately which entities are in scope, which response procedures apply and what evidence is required in each market.
On 2 September 2026, the Department of Science and Technology of the Ministry of Industry and Information Technology (MIIT) published a notice inviting public comments on drafts submitted for approval of nine recommended national standards, including “Intelligent manufacturing—Guidelines for the implementation of intelligent decision making”, addressing the implementation of intelligent decision-making technologies in industrial enterprises.
The development marks entry into the public comment stage for drafts submitted for approval, following completion of drafting. The comment period runs from 3 to 9 September 2026; it does not establish that the standards have been formally issued or taken effect. The project description on the National Public Service Platform for Standards Information states that the guidelines address the identification of business use cases, requirements analysis and key implementation considerations. They cover intelligent stocking and replenishment, production planning and scheduling, dispatching, transport route planning, production and sales coordination, pricing and marketing, with a focus on the technical requirements of different use cases. The full text of the draft submitted for approval could not be accessed for this review. These descriptions therefore rely on the official project summary and should not be treated as clause-by-clause confirmation of the draft.
Manufacturers and industrial software suppliers can use this development to prepare project requirements and acceptance criteria. For a production scheduling system, for example, an enterprise can first define delivery deadlines, capacity, material and equipment constraints, check whether the input data supports those constraints, and then verify that the algorithm’s proposed schedules are executable. Replenishment and dispatching applications can incorporate inventory anomalies, sudden changes in demand and equipment failures into pre-deployment testing. If large models or AI agents are subsequently integrated, enterprises should specify whether they may make recommendations, modify plans or issue instructions directly, and establish approvals, execution records and human takeover mechanisms for actions affecting production. Procurement teams can also ask suppliers to document the boundaries of applicable use cases, test results and exception-handling procedures. These are governance recommendations derived from the application scenarios and must not be presented as new mandatory obligations introduced by this notice. The available official material is also insufficient to establish that the guidelines specifically target generative AI or prescribe a uniform log-retention period.
In terms of the standard-setting process, the official project page records an earlier public notice period from 13 February to 15 March 2025. This week’s development advances to comments on the completed draft submitted for approval, shifting the focus from project initiation to implementation content. Industrial application guidelines and statutory compliance requirements serve different purposes: the Standardization Law of the People’s Republic of China provides that the state encourages the adoption of recommended standards. Official explanations from the Standardization Administration of China also note that such standards can create corresponding obligations when incorporated into contracts as a basis for delivery, publicly declared by an enterprise as standards it follows, or referenced in relevant legal provisions. The next developments to monitor are the final published text and whether enterprises incorporate it into procurement contracts and acceptance criteria. For current projects, enterprises should first map their requirements, then determine the scope of adoption and delivery commitments once the final text is published.
On 4 September 2026, the Cyberspace Administration of China published the “Implementation Plan for Promoting Coordinated Digital and Green Transformation and Development (2026–2030)”, jointly issued with the National Development and Reform Commission, the Ministry of Industry and Information Technology, the Ministry of Ecology and Environment, the Ministry of Housing and Urban-Rural Development, the Ministry of Agriculture and Rural Affairs, and the Ministry of Commerce. The plan proposes establishing a framework for assessing resource consumption across the full generative AI lifecycle and guiding service providers to proactively disclose resource utilisation by large models.
The Implementation Plan is an issued policy document, while its resource assessment and disclosure provisions remain directions for framework development and policy guidance. It places improvements in model training and inference efficiency alongside resource consumption assessment within the same workstream. On the technical side, it proposes optimising model architectures, using model compression techniques and exploring lightweight deployment. Assessment is intended to cover the full generative AI lifecycle. Disclosure is explicitly directed at generative AI service providers through guidance encouraging proactive disclosure. The document does not yet specify resource accounting boundaries, measurement methods, disclosure frequency or verification procedures, nor does it establish penalties for this disclosure provision.
Enterprises that train or deploy their own models can begin recording resource use by model version, training job and inference service, linking compute utilisation and runtime to available energy-consumption data and identifying measured values, estimates and allocation methods. This enables comparisons between compressed and original models to assess both task quality and resource consumption, avoiding judgments about efficiency based solely on parameter counts. Enterprises using external model APIs can ask suppliers which stages their resource data covers, whether it can be broken down by model and deployment region, and whether the basis for estimates is available. API charges and call volumes cannot directly substitute for energy measurement. These are recommendations for deployment readiness in response to the proposed assessment direction, rather than uniform mandatory reporting requirements. Procurement and architecture teams can first establish what data they can obtain, then decide whether resource-efficiency metrics can be incorporated into model selection and service acceptance criteria.
The “Implementation Guidelines for Coordinated Digital and Green Transformation and Development”, issued in 2024, already addressed data centre energy-efficiency monitoring, energy savings at the application level and algorithm optimisation. The new plan explicitly identifies the full generative AI lifecycle as the subject of assessment, extending resource management to model services. The next issue to monitor is how assessment methods and disclosure parameters are implemented. The EU addresses the same topic through a different framework: Article 53 and Annex XI of the Artificial Intelligence Act (AI Act), which is already in force, include known or estimated model energy consumption in the applicable technical documentation for general-purpose AI models, to be made available to competent authorities on request. They also provide an exemption from documentation obligations for qualifying open-source models that do not pose systemic risk. China’s direction on proactive disclosure and the EU’s regulatory documentation obligations therefore differ in terms of the entities covered, the recipients of information and their legal effect. Providers operating across jurisdictions need to assess each set of applicable requirements separately; a public environmental report cannot automatically serve as common evidence of compliance in both markets.
On 1 September 2026, Hong Kong’s Office of the Privacy Commissioner for Personal Data (PCPD) issued a media statement on the briefing session for the “Safeguarding Personal Data AI Sandbox”, jointly organised with the Digital Policy Office (DPO) and held on 28 August 2026. The session explained participation procedures, evaluation criteria and privacy safeguards for educational AI applications to primary and secondary schools.
The Sandbox is a voluntary official pilot programme providing regulatory and technical guidance to schools adopting AI. Its first phase is intended to select 15 publicly funded primary and secondary schools for a six-month participation period, with applications closing on 30 October 2026. Its scope is the practical use of ready-made AI solutions, including personalised learning, chatbots and administrative automation; it does not cover testing solutions still under development. The PCPD provides personal data protection guidance, while the DPO and supporting organisations offer relevant governance and technical advice. The framework makes clear that selection does not constitute regulatory endorsement: schools remain subject to the Personal Data (Privacy) Ordinance and other applicable laws. Participants must submit a report on implementation progress, outcomes and privacy challenges at the end of the programme.
When procuring personalised learning or assignment-feedback tools, schools can translate Sandbox guidance into checks on specific data flows: where student names, assignments, grades and conversation records are sent; whether suppliers use them for model training; who can access them; and how they are deleted when the service ends. Education technology suppliers can prepare descriptions of data processing, access configurations, retention periods and evidence of deletion verification to help schools compare solutions. Where model outputs affect student assessment or learning groups, teacher review and correction channels should be established, with operational records retained only as necessary to avoid excessive storage of student data for traceability purposes. These measures reflect the risk assessment, human oversight and system management recommendations in the PCPD’s existing Model Framework; the new development is a channel for obtaining tailored guidance. Sandbox participation cannot replace schools’ procurement reviews or contractual allocation of supplier responsibilities. Project teams can also organise test findings, remediation measures and residual risks as evidence for their end-of-programme reports.
The initiative builds on the PCPD’s “Artificial Intelligence: Model Personal Data Protection Framework”, published in 2024, and was formally launched on 6 July 2026. The 1 September announcement concerns recruitment and application guidance; it should not be described as evidence that selected schools have already completed deployment. In England, the Department for Education’s (DfE) guidance, “Generative AI: product safety standards”, addresses education technology developers and suppliers, setting out expectations for content filtering, access management, privacy protection and product risk assessment. It also makes suppliers selling directly to schools responsible for verifying upstream capabilities. These represent different forms of support: Hong Kong’s initiative emphasises collaborative guidance as schools adopt specific solutions, while England’s guidance focuses on demonstrable supplier product capabilities. Subsequent monitoring can track Hong Kong’s selection results and how programme experience is used to identify common challenges, providing a reference for education technology companies preparing procurement evidence for different markets.
On 1 September 2026, Singapore’s Accounting and Corporate Regulatory Authority (ACRA) updated its official explanation of the “AI-assisted Disclosure Advisory Initiative”, describing arrangements for using the CLAIR tool to screen the financial statements of Singapore-incorporated listed companies for potential disclosure gaps.
The initiative follows a workflow of AI identification of potential issues, validation by regulatory officers, and advice to boards of directors. It currently covers two Singapore Financial Reporting Standards (International): Impairment of Assets (SFRS(I) 1-36) and Fair Value Measurement (SFRS(I) 13). ACRA selects financial statements on a risk basis and may issue a Disclosure Advisory Letter (DAL) after validation. A DAL requires no response and carries no regulatory consequences in itself; where human validation identifies potential material disclosure non-compliance, the matter may be escalated to the formal Financial Reporting Surveillance Programme. Companies and auditors should assess the observations in light of materiality, specific facts and circumstances, and professional judgment. The page states only its update date and does not specify when the tool first went live.
Finance teams using generative AI to draft notes to financial statements or check disclosure completeness can adapt their internal review workflows accordingly. Each model-generated flag should be linked to the relevant standard, location in the notes and supporting evidence, with a person capable of exercising accounting judgment deciding whether a revision is needed. For example, if the model flags inadequate impairment disclosures, the reviewer can revisit valuation working papers, key assumptions and their applicability, avoiding unsupported additions made solely to clear a flag. Teams should retain the input financial statement version, model outputs, human review decisions and final approval records, and limit any “no issues identified” conclusion to the tool’s actual review scope. When procuring such tools, enterprises can ask suppliers to explain standards coverage, source traceability and false-positive handling. These are enterprise deployment recommendations derived from the regulatory workflow, not new statutory logging requirements. Their purpose is to ensure that automated findings can be verified and disclosure judgments have a clear accountable owner.
ACRA has previously reviewed financial statements through its Financial Reporting Surveillance Programme (FRSP) and emphasised in an official speech in January 2025 that directors must not over-rely on auditors. The arrangements now described add an AI-assisted advisory channel alongside existing supervision, while retaining a route for escalation to formal review. The Australian Securities and Investments Commission’s (ASIC) report, “ASIC’s oversight of financial reporting and audit 2023–24” (REP 799), also records work to assess AI tools for improving the selection of entities for review. The two sources show technology being applied at different points: the Australian report concerns selection for review, while Singapore’s explanation extends to validation of potential disclosure issues and the handling of advisory letters. Future monitoring can track ACRA’s proposed expansion of standards coverage and publication of anonymised common findings to identify where enterprises may need to extend their internal review rules. The available material is insufficient to quantify screening accuracy or conclude that enforcement intensity has increased.
Cite as · AI Governance Weekly · 10 September 2026
If you want both columns delivered together, four times a year, in one quiet email — leave an address. Otherwise just bookmark this page.