On 7 September 2026 China's Supreme People's Court issued Fa Fa [2026] No. 10, an Opinion in five parts and 24 articles telling judges how to decide civil disputes involving artificial intelligence. Article 4 is the one that matters outside China: using AI to generate a recognisable digital replica of a real person without consent infringes their personality rights, and using someone's voice as training material to imitate their timbre infringes their rights in that voice.
Read the test carefully and it is not the test the detection industry sells against. The court asks whether a natural person is recognisable in the output. A deepfake detector asks whether the output was generated. Those are different questions, answered by different systems, and they disagree in the cases that matter most.
- It is an Opinion, not a judicial interpretation. Fa Fa [2026] No. 10 guides how Chinese courts adjudicate; it is not itself the binding authority a judgment rests on. Reports calling it a ban are overstating it.
- No commencement date is stated in the court's announcement or in any wire coverage of it. Plan around the document, not around an assumed in-force date.
- Article 4 turns on recognisability, not on whether content was generated. That is a face recognition and speaker verification question, not a synthesis detection question.
- The voice limb reaches the training set. Using a person's voice as training material without consent, to imitate their timbre and intonation, is itself an infringement.
- Article 7 liability starts at notice, so the audit trail of what you did after being told is the defence. Article 12 lets a court order a developer asserting non-infringement to disclose training data sources and process records.
- Provenance labels mostly do not survive the trip. Metadata is lost to re-encoding and visible marks are removed by the adversary; intrinsic artefacts are what reach the case file.
China's Supreme People's Court published a document on 7 September 2026 that no other senior court has attempted: it tells judges how to decide when a cloned face or voice is a civil wrong, and hangs the answer on whether an ordinary person would recognise the human being in the output. Not on whether the media was generated. On whether it identifies someone.
That sounds like a lawyer's quibble. It is the whole engineering problem. A deepfake detector answers a question about provenance; the Opinion asks a question about identity. Any organisation expecting its detection stack to answer the court's question is holding the wrong instrument.
What the Supreme People's Court issued
The document is the Opinion of the Supreme People’s Court on Lawfully Adjudicating Cases Involving Artificial Intelligence Disputes, carried on the court's own site as Fa Fa [2026] No. 10, in five parts and 24 articles. Sina Finance sets out the structure: articles 1 and 2 give guiding principles, 3 to 11 cover AI-related infringement, 12 to 16 intellectual property, and the rest evidence, criminal conduct and case management.
Xinhua reported the substance the same day. Article 4 makes it an infringement of personality rights to use AI to process a natural person's name or likeness without consent so as to generate an identifiable virtual digital figure and then use or publish it. It does the same for voice: using a person's voice as training material without consent, to imitate their timbre, intonation and pronunciation style and produce a recognisable synthetic voice, infringes their rights in that voice. Manipulating such a figure or voice to make untrue statements that lower someone's standing is a separate reputation claim, and the protection extends to the digital likeness of the dead on behalf of near relatives.
Article 7 puts generative AI service providers on the hook. Once a rights holder notifies them, a provider that fails to take timely necessary measures, including stopping generation of the infringing content, bears the resulting loss. Users who deliberately steer a model into producing harmful output are liable in their own right. Article 8 allows a personality-rights injunction where waiting would cause irreparable harm, article 10 reaches algorithmic price discrimination, and article 5 covers doxxing.
Tao Kaiyuan, a vice president of the court, framed the document as an attempt to balance development against security, telling AFP that room had been left deliberately for refinement as experience accumulates. Zhou Jiahai, who heads the court's research office, put the rationale more bluntly in remarks carried by The Star: "We cannot expect every consumer to become an expert at spotting deception. The law must step in promptly to protect consumers' legitimate rights and interests."
An Opinion, not an interpretation
Almost every English-language report calls this document rules, guidelines or a framework. Those words do a lot of quiet work, because in the Chinese system the instrument class matters and the class here is an 意见, an Opinion. Sina Finance makes the distinction explicitly: this is adjudication guidance rather than a 司法解释, a judicial interpretation, the instrument that carries binding interpretive force and that courts apply as law.
The practical consequence is that the Opinion shapes how cases are decided without itself being the authority a judgment rests on. Judges are being told what the senior court thinks the existing Civil Code and consumer statutes already require. That makes it strong evidence of where Chinese litigation is heading and a weak basis for the claim, now circulating widely, that China has "banned" unconsented voice cloning.
A second gap in the record is worth stating plainly. No commencement date appears in the court's own announcement, nor in the Xinhua, AFP, China News Service or Sina coverage, and the announcement does not carry the standard formula 自发布之日起施行, effective from the date of publication.
That blank matters more than it usually would, because articles like this one are increasingly read by machines before they are read by lawyers. Dahl, Magesh, Suzgun and Ho, writing in the Journal of Legal Analysis, measured hallucination rates between 58% and 88% when large language models were asked specific, verifiable questions about federal court cases, and found the models frequently failed to correct a false legal premise supplied by the user. A summary that omits instrument class and commencement date is not neutral. It is an invitation to fill the blanks in.
Table 1: Every legal authority this article relies on, with its instrument class, its dates and who it binds. The blank cell is the point: no commencement date is given in the court's announcement or in the wire coverage.
Article 4 turns on one word
可识别. Identifiable, or recognisable. It appears in both halves of Article 4 and it is the hinge the personality-rights section swings on. The court is not asking whether a model produced the image; it is asking whether the natural person can be picked out of it.
The two limbs are not symmetrical. For likeness, the wrong is generating an identifiable virtual figure and then using or publishing it. For voice, the text reaches back into the training set: using the person's voice as training material, without consent, to imitate their vocal characteristics. The voice limb attaches liability at a stage the likeness limb does not, a detail almost every summary has dropped.
Chinese courts have already been pushing that line outward. In March 2026 the Beijing Internet Court held that an unauthorised AI face swap remains unlawful even where the image has since been modified, as Rest of World reported. That is a refusal to let editing launder identity, and it shows which way the interpretive pressure runs.
Recognition is not detection
Here is where the legal test and the technical stack come apart. A deepfake detector answers one question: does this signal carry the traces a generator leaves behind? Our explainer on the traces generators miss sets out what that residue consists of. Article 4 needs something else: is the person in this clip the specific human being bringing the claim? That is a face recognition or speaker verification question, measured against a reference, with its own false-match and false-non-match rates.
Both are answerable, by different systems that fail in different ways. Proving a clip was generated says nothing about whose face it wears; matching a face says nothing about whether the footage was real.
Fa Fa [2026] No. 10 · Article 4
Two different questions, two different systems
Article 4 hangs liability on whether a natural person is recognisable in the output. A detector asks whether the output was generated. The two tests disagree in half the cases, and one disagreement is where the harm keeps running.
The court's question (Art. 4): is this natural person recognisable?
A cloned face that reads as the person
The paradigm case the Opinion describes: name, likeness or voice processed without consent into an identifiable digital figure. Portrait, name, voice and reputation rights all available.
A blended identity that still sells
Attributes borrowed from a real person but blended below recognition, with the identity claim carried by the caption, the logo and the setting instead of the face. The persuasion survives; the statutory hook does not attach to a natural person.
Real footage, used without consent
Existing portrait and reputation rights already govern this, with or without the Opinion. Nothing in the media itself is generated, so a synthesis detector has nothing to report.
Nobody in particular
Stock or anonymous imagery. No identifiable person and no synthesis, so neither the personality-rights test nor the detection test has anything to act on.
The seam is narrower than it looks. In March 2026 the Beijing Internet Court held that an unauthorised AI face swap remains unlawful even where the image has been modified, which pushes the recognisability line back towards the attacker. How far back is the open question, and it is a question about perception, not about provenance.
Cell logic derived from Article 4 as published by the Supreme People's Court, 7 September 2026. Beijing ruling per Rest of World. Quadrants describe legal reach and detector behaviour, not accuracy.
The cell that should worry a compliance team is the one where the media is synthetic and the person is not quite recognisable. The persuasive work of a scam advertisement does not all sit in the face. It sits in the caption naming the person, the logo behind them, the studio set, the voice register. Blend a likeness far enough to lose the identification and the advertisement still sells, while the statutory hook loses its grip on any particular person. The architecture we described in the deepfake advertising supply chain is what makes that substitution cheap.
None of which is an argument against the Opinion. It is an argument that the Opinion creates demand for a capability most organisations do not currently buy, and that the capability is identity measurement rather than synthesis detection. The same distinction runs through liveness detection versus deepfake detection: adjacent controls, different questions, not interchangeable.
Article 7 runs at the speed of notice
Provider liability under Article 7 begins when a rights holder gives notice. Before notice, nothing. After it, the clock starts and the standard is whether measures were timely. This is the familiar notice-and-takedown bargain with its familiar failure mode: the defence runs at the speed a human can find, recognise and report a clip, while the offence runs at the speed a model can generate one.
For an individual, that asymmetry is brutal. The person whose face has been cloned has to see the clip to report it, and the clips that damage them most circulate where they will never look. Article 8's injunction helps once litigation is under way and does nothing about the interval between publication and discovery, which is where the money moves. We argued the same point from the other direction in prevention versus reaction.
Meeting Article 7 well is therefore a throughput problem before it is a detection problem: a notice queue that does not silt up, a decision record per item, and a way to catch the near-identical re-uploads that follow every removal.
The takedown arithmetic so far
The scale China already operates at shows what Article 7 is being layered onto. On 2 September 2026, days before the Opinion appeared, the Cyberspace Administration of China reported removing more than 5.61 million pieces of unlawful or rule-violating content and actioning roughly 49,000 accounts across more than 2,400 sites and apps, in a campaign against AI slop, fabricated news and impersonation, per the South China Morning Post. Penalised examples included accounts using AI face and voice swapping to impersonate public figures.
Platforms report their own numbers. ByteDance has removed more than 85,000 videos of unauthorised AI face and voice reproduction since the start of 2026, and the Guangzhou Internet Court has heard roughly 700 AI face-theft cases in three years, both per Rest of World.
Table 2: The enforcement volumes the Opinion lands on top of. Each is a count of removals or cases acted on, not a count of content generated.
Millions of removals, hundreds of cases. That gap is not a sign the courts are failing. It is a sign the takedown pipeline does nearly all the work and litigation is the exception. Article 7 formalises the pipeline without shrinking the volume flowing into it.
Where the provenance evidence dies
China has spent three years building the provenance apparatus that ought to make these cases easy. The Deep Synthesis Provisions, in force since 10 January 2023, brought synthetic media under a dedicated regime. The Measures for Labelling of AI-Generated Synthetic Content, in force since 1 September 2025 with the mandatory standard GB 45438-2025 attached, require two marks: an explicit label a viewer can see, and an implicit label in the file's metadata. Articles 17 and 18 then direct courts to examine the authenticity and integrity of electronic data across its generation, collection, storage and transmission.
Coherent on paper, fragile in transit. The fragility is not a Chinese problem. It is a property of how files move.
Articles 17–18 · Authenticity of electronic data
The evidence the rules create, and where it dies
China's labelling regime puts provenance in two places: a visible mark, and an implicit mark in the file's metadata. Articles 17 and 18 then ask courts to weigh the integrity of electronic data across its whole journey. Follow one clip along the route it actually travels, and only one evidence type is still there when the case is filed.
Fails to the adversary. It survives every technical step in the chain and is removed in seconds by the one party with a motive to remove it.
Fails to the pipeline. No hostile act is required. Re-encoding on upload rewrites the container and the signed manifest goes with it.
Degrades, but arrives. Compression and re-capture weaken the signal and never delete it, because it is a property of the pixels rather than an attachment to them.
This is why the standards bodies added soft bindings. The C2PA specification states plainly that Content Credentials can be removed and that provenance alone cannot tell you whether content is true. A watermark or perceptual fingerprint answers row two. Nothing in either regime answers row one.
Label types per the Measures for Labelling of AI-Generated Synthetic Content, in force 1 September 2025, with standard GB 45438-2025. Evidence duties per Articles 17–18 of Fa Fa [2026] No. 10. Manifest fragility per the C2PA explainer. Row states describe mechanism, not measured survival rates.
The C2PA specification is candid about this in its own explainer. Content Credentials can be removed, which is why the standard added durable credentials backed by invisible watermarks and perceptual fingerprints. Provenance alone, it says, cannot tell you whether content is true, accurate or factual, and no assumption should be drawn from whether an asset carries a manifest at all. Absence of a label is not evidence of synthesis, and presence of one is not evidence of honesty.
What survives the trip is the signal in the pixels and the samples: the intrinsic traces of the generator that made the file. Compression degrades them and re-recording degrades them further, but neither deletes them, because they are a property of the content rather than an attachment to it. For a court applying Articles 17 and 18 that is the difference between evidence that can be argued about and evidence that is gone, which is also why explainable detection output matters more in a legal setting than a confidence score does.
Training data became discoverable
Article 12 should most concern anyone building models rather than moderating them. A developer raising a non-infringement defence can be ordered to produce its training data sources, its training process records and its model operating mode. The defence is available but not free: asserting it opens the training pipeline to the court.
Read that alongside the voice limb of Article 4, which attaches liability to the use of a person's voice as training material in the first place, and the two interlock. A claimant alleges their voice was in the corpus. The developer denies it. The denial triggers disclosure over exactly the records that would settle the question.
These records have to exist before the claim arrives. Provenance logging assembled after a complaint carries little weight and invites an adverse inference, and our note on how much data it takes to clone a face or a voice explains why that is uncomfortable: a single scraped interview can be the whole corpus for one identity.
How this lines up against the EU
European readers now have two live regimes to hold at once. The EU AI Act's Article 50 transparency obligations became applicable on 2 August 2026, per the European Commission, requiring generated content to be marked in machine-readable form and deepfakes to be disclosed. We covered the mechanics in Article 50 and eIDAS 2.
The two are not variants of one idea. Article 50 regulates the act of generation and asks whether the output was marked; Article 4 regulates the depiction of a person and asks whether that person is recognisable. A clip can comply fully with one and infringe the other.
Table 3: The two regimes ask different questions of the same clip. Sources: Fa Fa [2026] No. 10 as published by the Supreme People's Court; the European Commission's summary of the AI Act's transparency obligations.
For a multinational, a single labelling programme does not cover both. Marking output satisfies Brussels and does nothing for a Chinese personality-rights claim, where the question is who is in the frame. Our survey of what is changing in deepfake regulation this year sets out how quickly this patchwork is thickening.
What to do before a notice arrives
Four capabilities follow from the text, and none is a purchase order for a detector on its own.
Keep a decision record for every notice, not only the ones you action: timeliness under Article 7 is judged on what you did after you were told, so the audit trail is the defence. Know whether you can measure identity as well as synthesis, before a claim asks you to. Hash and log media at ingest, because Articles 17 and 18 make the integrity of the file's journey a live issue and the copy reaching you is already several generations from the original. And if you train models, keep provenance records from the first epoch.
Table 4: Four moments the Opinion creates, and the capability each assumes you already have. Derived from the article text as published by the Supreme People's Court.
The teams that will find this easiest already treat detection output as evidence rather than as a score, the posture we argued for in where detection fits in an identity verification stack.
What the Opinion does not settle
Three questions stay open. How recognisable is recognisable? The text supplies a standard and no threshold, normal for a personality-rights provision and unhelpful for anyone building a control. The Beijing Internet Court's March position suggests modification is no defence; where the line sits for a blended identity is unanswered.
What weight does an Opinion carry against a judicial interpretation? Courts will apply it as guidance. How it fares against a contrary reading of the Civil Code is a question for the first appellate judgment.
And when does it commence? The public record does not say. Treat that blank as a blank rather than assuming publication and commencement are the same date.
Frequently Asked Questions
Has China made deepfakes illegal?
No. The Opinion tells courts how to handle civil disputes over AI-generated content. Creating a recognisable digital replica of a real person without consent infringes their personality rights and gives them a civil claim. That is not a criminal prohibition, and the Opinion is adjudication guidance rather than a judicial interpretation with binding force.
Does the Opinion apply outside China?
It governs how Chinese courts decide cases before them, so its practical reach covers any platform or model provider available in China that receives a notice from a Chinese rights holder. The final part also addresses international judicial cooperation.
What counts as a recognisable digital replica?
The Article 4 test is whether the output identifies the natural person. Not whether it was AI-generated, and not a similarity percentage. The Beijing Internet Court held in March 2026 that modifying an AI face swap does not cure the infringement, so cosmetic editing is unlikely to help a defendant.
Is voice cloning treated the same as face swapping?
Not quite. The voice limb reaches the training stage, treating the unconsented use of someone's voice as training material to imitate their timbre as an infringement of their voice rights. The likeness limb attaches at generation and publication. The voice provision is the broader of the two.
Will provenance labels prove a case?
Rarely on their own. Visible labels are removable by anyone motivated to remove them, and metadata is commonly lost when a file is re-encoded on upload. The C2PA specification says provenance cannot establish whether content is true and that no inference should be drawn from a missing manifest. Intrinsic artefact analysis is what survives the distribution chain.
Methodology
Primary sourcing for the Opinion is the Supreme People's Court's own announcement at court.gov.cn, including the document number, structure and article text. Wire reporting from Xinhua, AFP and China News Service was read directly to corroborate it, and Sina Finance supplied the part-by-part structure and the instrument classification. Enforcement figures come from the South China Morning Post and Rest of World, not from the court. Standards and comparative material come from the primary bodies: the C2PA specification, and the European Commission for the AI Act timeline. Where the public record is silent, notably on commencement, this article says so instead of inferring.
Sources
- Supreme People’s Court: Opinion on AI Dispute Cases, Fa Fa [2026] No. 10
- Xinhua: China’s top court sets rules for AI deepfakes
- AFP via TechXplore: Top court posts guidelines on deepfakes
- The Star: Fake AI-generated content now liable
- China News Service: 最高法发文明确AI换脸拟声等案件裁判规则
- Sina Finance: 最高法发布我国首部涉人工智能司法裁判规则文件
- South China Morning Post: China cracks down on AI deepfakes
- Rest of World: A new marketplace to rent human faces
- C2PA: Content Credentials Explainer, specification 2.4
- Loeb & Loeb: China’s AI labelling measures
- China Briefing: Deep Synthesis Provisions, in force January 2023
- European Commission: Regulatory framework for AI
- Dahl et al.: Large Legal Fictions, Journal of Legal Analysis 16(1)














