China Rolls Out AI Security Framework 3.0 as Its Cybersecurity Campaign Targets Everyday AI Risks
China's national cybersecurity standardization committee released the third version of its AI Security Governance Framework in as many years, at the opening of a awareness week that is trying to teach ordinary users — including a stage-play protagonist who granted an AI replica of his late wife access to his accounts, face and home — to distrust what the technology offers them.

China's answer to AI risk arrived on Monday as version 3.0. At the opening ceremony of this year's National Cybersecurity Awareness Week in Jinan, the country's cybersecurity standardization committee published the AI Security Governance Framework 3.0, the third annual edition of a rulebook first issued in 2024 under the guidance of the Cyberspace Administration, China's internet regulator. The framework carries the committee's standard ideological framing — "people-centered," committed to technology that is "upward and good" — and, per the release, is designed for "new trends in AI development and new governance challenges": the fast-moving world of AI agents, generated media and machine-authored scams that ordinary Chinese users met this year.
The ceremony in Jinan was stocked with the other hardware of China's governance-by-campaign style. Organizers released results of tests on AI-empowered cybersecurity products and unveiled a filing and labeling scheme for consumer internet-connected cameras — an acknowledgment that the device watching a living room is now an AI risk surface. The week itself is a ten-ministry production, co-hosted by bodies from the Central Propaganda Department to the People's Bank of China, and runs through September 20 with events across the country.

What makes the campaign interesting is whom it is aimed at. In Shanghai, the week opened with a stage play — a first for the event — whose protagonist, a retired man styled as an "AI whiz," grants an AI replica of his late wife access to his account details, his face and voice prints and his entire smart home, with predictably unhappy results. The theme slogan of the week, "cybersecurity for the people, cybersecurity relying on the people" (网络安全为人民,网络安全靠人民), captures the strategy: the state writes the frameworks, but the campaign treats every smartphone user as the front line. In Guangdong, the provincial opening featured humanoid robots on stage and a parallel message that AI safety is now a consumer issue, not a specialist one.

The urgency is not abstract. Chinese regulators and platforms have spent the summer policing AI-generated content, from the AI porn short-drama black chain exposed last month to an apology letter so obviously AI-written that China's own anti-fraud center flagged it. The framework's annual rewrite — 1.0 in 2024, 2.0 in 2025, 3.0 now, each in step with the Global AI Governance Initiative Beijing promotes abroad — is itself a signal: China has stopped treating AI governance as a one-time rulebook and started treating it as a living document, revised yearly to chase the technology's latest failure modes. Whether a voluntary framework and a stage play can keep up is the open question the week's slogan quietly concedes.