2026-09-10

Enterprises use the AI compliance self-inspection checklist - based on the latest provisions of the "Opinions of the Supreme People's Court on the Adjudication of Dispute Cases Involving Artificial Intelligence"

Author:Ran Jieyue, Zhang Fang

Preface

Currently, artificial intelligence technology is penetrating every aspect of business operations at an unprecedented speed. From the automatic generation of customer service scripts to the intelligent writing of marketing copy, from the AI-generated production of product images to the intelligent analysis of business data, AI has become a daily productivity tool for various market entities.

China has not yet introduced a specific artificial intelligence legislation. Currently, a preliminary framework has been formed based on the "Cybersecurity Law", "Data Security Law", "Personal Information Protection Law", "Interim Measures for the Management of Generative Artificial Intelligence Services", "Regulations on the Deep Synthesis Management of Internet Information Services", "Measures for Identifying Artificial Intelligence Generated and Synthesized Content", and the judicial interpretation issued by the Supreme People's Court on September 7, 2023, "Opinions on the Legal Handling of Disputes Involving Artificial Intelligence", jointly forming an artificial intelligence legal system. In specific scenarios of using artificial intelligence, the current legal framework still has a large amount of interpretative space and disputes regarding application.

Based on the practical experience of providing specialized legal services for a leading e-commerce company on artificial intelligence compliance recently, this article focuses on the five core legal risks for enterprises as users of generative artificial intelligence services in their daily operations, and summarizes the key controversial points in legal application, providing an analysis path for enterprises' compliance self-examination.

01 Copyright infringement risk

Infringement issues of training data

Article 7 of the "Interim Measures for the Management of Generative Artificial Intelligence Services" stipulates that generative artificial intelligence service providers should use "data and basic models with legal sources; involving intellectual property rights, shall not infringe upon the intellectual property rights of others". This article clearly stipulates that AI service providers shall not infringe upon the legitimate rights of others when training models. Whether enterprises, as users of AI services, need to bear the obligation of reviewing the compliance of AI model training data, that is, if they continue to use AI models knowing or should know that the training data of the AI models has an infringement suspicion, constitutes joint infringement? This issue has no clear regulations in the current legal framework.

Most enterprises as users of AI services are more directly at risk that their employees upload works with copyright (such as well-known IP characters, photography works, design drafts) to AI tools as reference materials or training data. Judicial practice has also clearly established cases. The Beijing Tongzhou District People's Court in (2025) Jing 0112 558 No. 1 case1 held that the defendant's use of AI "image generation" technology to generate images based on others' artistic works and the process without originality constituted the crime of infringing copyright.

The originality and rights attribution of AI-generated content

The copyrightability of AI-generated content has significant differences of opinion. The "Opinions on the Legal Handling of Disputes Involving Artificial Intelligence" (hereinafter referred to as "the Opinions") has not made a clear stipulation on this issue. From the case studies in judicial practice, the Beijing Internet Court (2023) Jing 0491 Civil No. 11279 "AI Image Generation" case3 and the Jiangsu Province Changshu City People's Court (2024) Su 0581 Civil No. 6697 "Bingxin" case4 held that when the user invests sufficient creative labor through writing prompts, adjusting parameters, and subsequent modifications, the AI-generated content can constitute a work, and the user can enjoy copyright.

Although there is still controversy over the copyrightability of AI-generated content, according to existing judicial cases, if enterprises hope to enjoy copyright over the content generated by employees using AI, they need to prove that the employees have invested sufficient intellectual labor in the use of AI. In subsequent cases, the Beijing Intellectual Property Court also established the evidentiary standard of "original generation record" - when a user claims the copyright of AI-generated content, they must submit original evidence such as creative ideas, input instructions, and operation logs. It is recommended that enterprises establish a systematic system for recording the AI creation process during their daily use of AI.

Substantial similarity infringement

Article 12 of the "Opinions" stipulates: "If an AI user knows or should know that an existing work exists, uses AI to generate a work that is substantially similar to the existing work without reasonable defense reasons, and the rights holder of the existing work requests that the user bear the infringement liability, the court shall support it." If an enterprise employee uses prompts to guide AI to generate content, and the prompts deliberately imitate or replicate the original creative expression of the existing work, resulting in the generated content being "substantially similar" to the existing work, it may constitute copyright infringement.

From the perspective of the elements constituting the infringement liability, if the AI user knows an existing work and guides AI to generate content that is substantially similar to it through carefully designed prompts, their behavior is essentially a copy. However, if the user has no subjective intent, and the AI model outputs content similar to the existing work "autonomously" due to the influence of training data, there is some controversy in determining the fault. In the "Doudou Pan" case of the Jinshan District People's Court of Shanghai, it was determined that using AI to train a model for commercial use and disseminating it infringes upon the reproduction right and information network dissemination right of the original work.

02 Risk of infringement of personality rights

Extension of protection of portrait rights and voice rights

According to Article 1019 of the Civil Code, it is prohibited to produce, use, or disclose the portrait of another person without consent. Article 4 of the "Opinions" stipulates that when using AI to process the name or portrait of a specific natural person or deceased person, it must not violate laws and regulations, and must not violate public order and good morals, and clarifies the determination and assumption of infringement liability based on specific scenarios.

If the AI-generated image used by an enterprise is recognizable as a real person (especially a celebrity, influencer, or well-known model), even if it is obtained through "AI face swap" or "generation", it may still constitute infringement of the portrait rights of others. In the typical case 6 of the Beijing Internet Court in 2025, it was clearly stated: AI face swap, AI mockery of the portrait of others, and unauthorized creation of an AI image of a natural person, etc., are all determined as infringements. When an enterprise uses AI virtual models, it should ensure that the model image is completely original and does not resemble any real person.

The current law does not clearly define the standard of "recognizability", and the author believes that if the general public can identify a specific natural person based on the AI-generated image, it has the characteristic of "recognizability".

The logic of protecting voice rights is similar. When the AI-synthesized voice can enable the public to identify a specific natural person in terms of tone, intonation, and pronunciation style, it falls within the scope of protection of voice rights. In scenarios such as using AI dubbing or digital person live streaming, even if it uses "synthesized voice", if it imitates the voice characteristics of a specific natural person, it may still face infringement risks.

AI "hallucination" risk of reputation rights and corporate goodwill

Infringement of reputation rights by AI-generated false content that involves competitors or specific entities may constitute infringement of reputation rights as stipulated in Article 1024 of the Civil Code. It is worth discussing whether the degree of fault caused by AI "hallucination" information is equivalent to that of deliberately fabricating false information.

Article 3 of the "Opinions" stipulates: "If the law does not clearly stipulate the application of no-fault liability or fault presumption liability, the liability of the actor for infringement shall be determined in accordance with the principle of fault liability stipulated in Article 1165 of the Civil Code." When enterprises use AI tools to generate content, they should review the authenticity of the AI-generated output. If they have fulfilled their reasonable review obligations but still fail to detect errors in the AI-generated content, according to the current interpretation, they can claim to mitigate or exempt liability.

Looking at the cases in judicial practice, in the first AI "hallucination" infringement case in China, the Hangzhou Internet Court applied general fault liability rather than product liability to the AI service provider. The reasoning behind the judgment was that the inaccuracy of the AI-generated content did not possess the high-risk nature targeted by product liability, and the service provider lacked sufficient foresight and control over the generated content.

03 Data Security and Personal Information Protection

The Difficult situation of Business Secrets "Leakage"

When enterprise employees directly input commercial secret information such as customer lists, sales data, selection strategies, financial data, and core technical parameters into public AI tools, it is currently the most common and dangerous high-risk behavior. Once data is input into public AI models, its control and security may become out of control, easily causing data leakage.

After the data is input into the public AI model, although it is not directly made public, the AI service provider may use this data for model training, resulting in the information being indirectly "remembered" in the model parameters, with the possibility of being reverse-extracted. Even though this risk is difficult to quantify in practice, from a compliance and prudent perspective, inputting commercial secrets into an external public AI tool that is not under the control of the enterprise may constitute a violation of the confidentiality obligation and result in the loss of legal protection of business secrets.

It is worth discussing whether enterprises can input information into public AI tools after "data de-sensitization" or "de-identification" processing. The technical feasibility of this solution depends on the thoroughness of de-sensitization and the reconstruction ability of the AI model. However, in any case, enterprises should establish an "AI tool usage data classification system" to clearly define which information can be input into public AI, which information must undergo de-sensitization processing, and which information must not be input into any external AI tools.

The purpose limitation principle of personal information protection

When enterprises directly input customer names, phone numbers, addresses, order information, etc., of personal information into third-party AI platforms for summarization, analysis, or content generation, it may violate the consent principle and purpose limitation principle of the Personal Information Protection Law. Even if enterprises legally collected customer data (such as purchase records, browsing behaviors), if they use it to optimize AI models (such as training personalized recommendation algorithms) without the consent of the customers, it is beyond the original purpose of use and violates the "purpose limitation principle" of the Personal Information Protection Law.

Compliance governance for training data and data annotation

For enterprises with self-developed or fine-tuned AI model requirements, the three key issues of compliance governance are whether the data is legal, how to mark the content, and the liability for infringement. The training process of the model relies on a large amount of high-quality training data, and the data must ensure legal collection and annotation. Data annotation is a key link in the training process of generative artificial intelligence models, referring to the manual or semi-automatic classification, identification, and interpretation of the original data to give it semantically understandable information.

According to the provisions of GB/T 45674-2025 "Cybersecurity Technology - Safety Specifications for Generative Artificial Intelligence Data Annotation", when enterprises conduct data annotation for AI model training, they must meet the following requirements: The annotators must undergo security training and pass the assessment; The annotation results must be verified, and the proportion of security annotations in the data annotation should be no less than 3%.

04 Unfair Competition Risks

AI-generated false comments and fraud

According to the relevant provisions of the "Anti-Unfair Competition Law", the "E-commerce Law", and the "Regulations on Supervision and Management of Online Transactions", behaviors such as fabricating transactions, fabricating user reviews, and fabricating click-through rates/attention levels/interaction data are typical acts of unfair competition. Article 20 of the "Opinions" stipulates: "If using artificial intelligence to implement infringement and counterfeiting, false promotion, quantity manipulation, etc., which infringe upon others' rights or constitute unfair competition, one shall bear corresponding responsibilities in accordance with the law."

The judgment reasoning of the Hangzhou Intermediate People's Court in the case of "AI Writing" (Case No. 3998 of 2025) also clearly states that AI service providers, by using the content of specific platforms as a selling point to attract users to generate content highly similar to the platform's content, are essentially using AI technology to implement "free-riding" behavior, disrupting the market competition order, and constituting unfair competition.

If it constitutes fraud against consumers, the user shall also bear compensation liability to consumers, and may also be required to stop infringement and compensate losses to competitors; in addition to civil liability, the user may also face administrative liability, such as the Beijing Chaoyang District Market Supervision Bureau's investigation of Beijing Aolongde Information Technology Co., Ltd. for using the internet to implement confusion cases 9, the Shanghai Xuhui District Market Supervision Bureau's investigation of Shanghai Entropy Cloud Network Technology Co., Ltd. for using the internet to implement confusion cases 10, and the Shanghai Market Supervision Bureau's investigation of Shanghai Qiaoneng Network Information Technology Co., Ltd. for assisting in false promotion cases 11, all of which were fined; in serious cases, it may constitute a criminal offense.

AI crawling competitors' business information

Through AI technology to directly crawl competitors' price strategies, product selection data, user reviews, etc. of business information, it may involve infringing on trade secrets or constituting unfair competition. The crawled information is publicly available (such as displayed product prices), which may constitute anti-unfair competition; however, if the crawled information is information that needs to bypass technical protection measures to obtain (such as backend data, encrypted interfaces), etc., it may also face criminal liability risks.

05 Obligation of Identifying Generated Content

The scope of application of the obligation to identify

It should be clearly stated that not all content generated using AI tools requires identification. The core applicable scenario of the obligation to identify is "publicly released" generated and synthesized content. If the enterprise uses AI tools for data analysis, document organization, plan discussion, etc., and does not involve external release, it generally does not trigger the obligation to identify. There is also some controversy regarding public release, such as whether the content using AI to generate in enterprise internal training materials belongs to "external release", and whether the AI-generated reports shared among partners need to be identified. In my personal opinion, such scenarios still belong to internal use and are not within the scope of the obligation to identify.

Dual compliance of explicit and implicit identification

The obligation to identify includes explicit identification and implicit identification. Explicit identification requires adding an identifiable mark in the content or interaction interface; implicit identification requires embedding the attributes information of generated and synthesized content in the file metadata. For enterprises as AI service users, they should fulfill the obligation to display identification, and add "AI-generated/containing AI-generated content" in the AI-generated product images, promotional videos, etc.

The compliance of implicit identification is more complex. Whether enterprises need to review the content generated by AI tools that has already embedded implicit identification, and if the AI service provider fails to fulfill the obligation of implicit identification, whether the user needs to bear joint liability? This issue has no clear provisions in the current legal framework. According to Article 10, Paragraph 2 of the "Regulations on Identifying Generated Content by AI", "No malicious deletion, tampering, forgery, or concealment of the identification of generated and synthesized content stipulated in these regulations shall be carried out." This regulation suggests that the user at least has the negative obligation of not destroying the existing identification.

The Intersection of Identification Obligations and Consumer Rights Protection

The legislative purpose of the identification obligation for AI-generated content is not only to meet regulatory requirements, but also to safeguard consumers' right to know and their right to choose. If enterprises fail to identify AI-generated product images or promotional videos, causing consumers to have misunderstandings about the authenticity of the products, it may simultaneously trigger violations of relevant provisions of the "Consumer Rights Protection Law".

Conclusion

Under the current legal framework, there are significant interpretative spaces, application disputes, and issues of balancing interests in the compliance legal aspects related to AI usage. Moreover, the legislative development is quite rapid. Valuable compliance reviews do not merely involve mechanically comparing against compliance checklists; rather, they involve establishing a compliance mindset, that is, conducting a holistic review from the input to the output throughout the entire business process. Of course, the establishment of such a mindset cannot be achieved without the support of institutional frameworks, such as AI usage compliance management manuals, data classification systems, creation process traceability systems, content review processes, employee training mechanisms, and so on. The establishment of these systems itself represents the transformation of enterprises from a passive response to an active management approach.

Footnotes:

1. Beijing Tongzhou District People's Court (Case No. 558 of 2025, Criminal Case File, Case Number: 2025-09-1-160-001);

2. Zhou Jiahai, Si Yanli, Qin Yuanming, Jia Yuhui, Zhang Yin: "Understanding and Application of the Opinions of the Supreme People's Court on the Legal Handling of Dispute Cases Involving Artificial Intelligence";

3. Beijing Internet Court (Civil Judgment No. 11279 of 2023);

4. Jiangsu Province Changshu People's Court (Civil Judgment No. 6697 of 2024);

5. WeChat Official Account of the Shanghai Higher People's Court https://mp.weixin.qq.com/s/Plae0snaOEsqqmodLU9j4g;

6. WeChat Official Account of the Beijing Internet Court https://mp.weixin.qq.com/s/E-9ECMK1t8znrXGAMR1Arg;

7. Hangzhou Internet Court (Civil Judgment No. 18143 of 2025, First Instance, Hangzhou People's Court, Zhejiang Province);

8. Hangzhou Intermediate People's Court (Civil Judgment No. 3998 of 2025, Second Instance, Hangzhou Intermediate People's Court, Zhejiang Province);

9. Beijing Market Supervision and Administration Bureau https://scjgj.beijing.gov.cn/ztzl/gpjzyqjc/sjap/202603/t20260325_4565637.html;

10. National Market Supervision Administration https://www.samr.gov.cn:3030/xw/zj/art/2026/art_0bea53d4e3904015a340b4e83241a8ec.html;

11. National Market Supervision Administration https://www.samr.gov.cn:3030/xw/zj/art/2026/art_0bea53d4e3904015a340b4e83241a8ec.html.

Share