Dr. Freddie Seba

AI Governance Keynote Speaker  ·  Author  ·  Scholar Operator

EdD · USF  ·  MBA · Yale  ·  MA · Stanford  · Teaching · UIC  ·  20+ years · Silicon Valley Founder & Global Executive · Digital Health · Fintech · Higher Ed.

| Ungoverned | China AI Safety Governance Framework 2.0

—-

You mapped your EU exposure. Have you mapped your China exposure?

TC260 — National Information Security Standardization Technical Committee, People’s Republic of China

By Dr. Freddie Seba © 2026 Freddie Seba. All rights reserved.

What China’s national AI governance framework covers — and what it leaves to your institution

Applying the AI Minimum Viable Governance (AI-MVG) framework and the Seba 12 Ps of Responsible AI

Governance as Leadership

The organizations that govern AI intentionally will lead. The ones that don’t will follow the consequences.

This series is not about compliance. It is about leadership. Every framework examined here surfaces the same question: not whether your institution is following the rules — but whether your leaders are governing the most consequential technological transformation of our time. Ungoverned: Applied Frameworks Under the Lens exists for leaders who understand the difference.

Previously: Anthropic, OpenAI, Google Gemini, NIST-CAISI, EU AI Act. This week: China AI Safety Governance Framework 2.0. Coming next: Singapore, South Korea, Canada.

Constructive analysis — three questions, every installment, without exception.

A note on framing before we begin. This edition applies exactly the same three-question analysis used in every other installment. China’s AI Safety Governance Framework 2.0 is examined on its own terms — its design, its scope, and what it leaves outside its frame. The governance gap identified here is not a geopolitical observation. It is an institutional governance question that applies to any organization that has not mapped its exposure to AI tools developed, trained, or governed within China’s regulatory jurisdiction.

Why this series — and why these frameworks

This series does not examine every AI governance framework that exists. It examines the frameworks that together reveal the full shape of the governance challenge — and the full scope of what institutional leadership must build in response.

The selection logic is deliberate. It begins with the AI labs — Anthropic, OpenAI, Google — because that is where most institutions first encountered the governance gap: in the terms of service of tools already embedded in their workflows. It moves to U.S. federal bodies — NIST-CAISI — because understanding the voluntary, underfunded, and pending-authorization nature of federal AI standards is essential context for every institution that assumed federal governance was someone else’s responsibility.

It then moves outward — to the EU AI Act, China, Singapore, South Korea, and beyond — because AI governance is not a Western conversation, and leaders who govern only within the frameworks they already know will be ungoverned by the ones they do not. It will explore Canada — not because Canada has a framework, but because it does not, and the governance vacuum left by failed legislation is itself a governance lesson every institution needs to examine. It will explore the Gulf states — UAE, Saudi Arabia, Qatar — because some of the world’s most aggressive AI investment is happening in jurisdictions whose governance frameworks Western institutions have barely begun to examine.

The frameworks explored in this series are not the only ones that matter. They are the ones that, examined together, reveal the pattern. The framework governs the platform, the standard, the model, or the market. Only the institution governs the consequences. That pattern is what this series is for.

This is a living series. Frameworks are added as the global AI governance landscape evolves — and it is evolving faster than any publication schedule can fully anticipate.

Series roadmap — a living intellectual agenda

This roadmap reflects the series as currently envisioned. New frameworks will be added as countries, standards bodies, and sector organizations publish governance guidance. The sequence may evolve. The three questions never will.

Tier 1 — AI Labs

The governance gap begins here — in the terms of service, privacy policies, and platform decisions of the tools already embedded in institutional workflows.

  1. Anthropic — United States
  2. OpenAI — United States
  3. Google Gemini — United States

Tier 2 — Government & Standards Bodies

Federal and national frameworks that shape institutional expectations — and the gaps those frameworks deliberately or structurally leave ungoverned.

4. U.S. NIST-CAISI — United States

Tier 3 — Binding Regulatory Frameworks

The binding laws and regulations that define legal compliance floors — and the institutional governance required to meet them.

5. EU AI Act — Europe

6. China AI Safety Governance Framework 2.0 — China

Tier 4 — International Standards & Multilateral Bodies

The frameworks that aspire to global consensus — and the institutional gaps that consensus cannot close.

Tier 5 — Sector & Vertical Frameworks

Where global frameworks meet institutional reality — in education, financial services, and emerging economies.

Tier 6 — Series Synthesis

What the frameworks — examined together — leave ungoverned. And what leadership must build in the space they leave behind: What the Frameworks Don’t Say

New frameworks added as the global AI governance landscape evolves.

A note on U.S. restrictions

As of the date of this publication, no blanket U.S. prohibition exists on civilian or commercial use of Chinese AI models including DeepSeek, Baidu Ernie, Zhipu GLM, or Kimi. Using these tools is currently legal for most U.S. institutions in commercial and research contexts. Sector-specific restrictions apply to U.S. government devices and networks. More than 20 U.S. states have banned DeepSeek on government-issued devices. Institutions in regulated industries, those holding federal contracts, or those operating in defense-adjacent supply chains should consult legal counsel regarding applicable restrictions. The governance gap this edition examines exists regardless of legal status — because the absence of a prohibition is not the same as the presence of governance.

Question One — What was the framework designed to govern?

China’s AI Safety Governance Framework 2.0 was officially published on September 15, 2025, by TC260 — the National Information Security Standardization Technical Committee — during the 2025 National Cybersecurity Awareness Week. It represents a systematic upgrade from the original Framework 1.0 published exactly one year earlier. The distinction between versions is important and worth understanding precisely.

Version 1.0 functioned primarily as a governance declaration. Version 2.0 is an operational manual — detailing how to govern AI, at what stages, and how to respond when problems arise. This evolution from principles to mechanisms, from frameworks to implementation, reflects the maturation of China’s AI governance approach and its growing ambition to shape global governance norms. Aicerts News

The framework is organized around four pillars. Governance principles establish four foundational values: people-centered development, AI for good, secure and controllable AI, and agile governance. Risk taxonomy introduces a five-level risk grading system based on application scenario, intelligence level, and scale of impact — classifying artificial intelligence security risks into three major categories: Technical Endogenous Security Risks such as algorithmic bias and model defects, Technical Application Security Risks such as cyber attacks and content security, and Application Derivative Security Risks such as ethical impact and social impact. Technical countermeasures provide specific measures for identified risk categories. Governance measures cover regulatory mechanisms, industry self-regulation, public participation, and international cooperation.

China’s governance ecosystem does not operate through a single framework. Between 2021 and 2025, China enacted more sector-specific AI regulations than any other country — covering algorithms, deepfakes, generative AI services, and data security. Framework 2.0 sits at the center of this ecosystem, providing the conceptual architecture that connects these regulations into a coherent governance system. May 2026 produced two marquee releases. TC260 issued the Ethics-Safety Guidelines for Artificial Intelligence Applications 1.0. CAC, NDRC, and MIIT unveiled agentic AI implementation rules. And in July 2026, China issued Interim Measures for Anthropomorphic AI Interaction Services, beginning to regulate AI agents as a distinct governance category rather than simply treating them as an extension of generative AI. Carnegie Endowment for International Peace

Framework 2.0 also carries explicit international ambitions. It calls for advancing global AI governance rules through the UN, APEC, G20, BRICS, and other multilateral platforms. In July 2025, Chinese Premier Li Qiang unveiled China’s Global AI Governance Action Plan alongside a proposed World AI Cooperation Organization — a thirteen-point roadmap for international AI development and governance. China will host the APEC summit in 2026 in Shenzhen — another platform through which its AI governance model is being actively advanced.

It governs AI development, deployment, and risk management within China’s regulatory ecosystem. Systematically. Rapidly. With binding technical standards following closely behind voluntary guidance — and with growing reach into multilateral governance structures.

Question Two — The Governance Gap: what falls outside the frame, and where leadership begins?

Institutional exposure mapping. And this is where leadership begins — not in understanding China’s framework, but in understanding your institution’s relationship to it.

China’s Framework 2.0 governs AI within China’s regulatory jurisdiction. It is a serious, technically sophisticated, and rapidly evolving governance architecture. What it cannot do — and was not designed to do — is tell your institution whether Chinese-developed AI tools, Chinese-trained models, or Chinese-governed data flows in your technology stack require institutional governance attention. That mapping belongs to the institution.

This is not a geopolitical statement. It is a governance observation that applies equally to any cross-jurisdictional AI dependency. The question is not whether China’s framework is credible — it demonstrably is. The question is whether your institution has mapped its exposure to AI tools that fall within that framework’s jurisdiction, and whether you have governance structures in place to respond when those tools are updated, deprecated, or subject to regulatory changes within China.

The absence of a U.S. blanket prohibition does not resolve the governance question. An institution that has not mapped its Chinese AI tool exposure is not compliant by default — it is ungoverned by choice. Consider what no framework can answer for your organization. Has your institution inventoried AI tools with Chinese development, training, or governance origins? If a Chinese-developed AI tool is subject to a regulatory update within China’s jurisdiction — and China’s regulatory iteration is among the fastest in the world — who in your organization is notified? Who evaluates the governance implications? Who determines whether continued use is appropriate given your institution’s own regulatory obligations including the EU AI Act’s provisions on third-country providers, HIPAA’s requirements for health data governance, or your own board-level AI risk frameworks? Who owns that risk?

China’s framework governs within its jurisdiction. Leadership governance governs within yours.

Question Three — What does governance as leadership look like before deployment?

This is where AI Minimum Viable Governance (AI-MVG) begins. Not after a supply chain audit reveals ungoverned dependencies — before deployment, when the institution still has the leverage to map, evaluate, and govern with intention. This is not a compliance checklist. It is a leadership architecture.

Vendor dependency mapping — inventory every AI tool in your institution’s technology stack, including tools developed, trained, or governed under frameworks outside your own regulatory jurisdiction

Decision ownership — name who is accountable for governance decisions related to cross-jurisdictional AI dependencies

Policy monitoring — establish a process to track China’s rapidly evolving regulatory standards in real time, not annually

Change management triggers — define what level of regulatory change within a vendor’s home jurisdiction requires institutional review

Contingency planning — document what happens if a tool your institution relies on is subject to regulatory action, export control, or governance changes in its country of origin

Legal counsel review — institutions in regulated industries, federal contractors, and defense-adjacent organizations should assess applicable restrictions before deployment

Executive accountability — assign a named leader responsible for cross-jurisdictional AI governance outcomes, not just domestic compliance

This week’s 12 Ps lens: Partnerships

Partnerships — the eighth P — means your institution has mapped every third-party AI relationship, including tools developed, trained, or governed under frameworks outside your own regulatory jurisdiction. Here is what the Partnerships lens surfaces across all 12 Ps when examined through China’s Framework 2.0:

Purpose — China’s framework establishes people-centered AI development as a foundational principle. Your institution must evaluate whether its own AI purpose statements align with the governance expectations of every jurisdiction in which its AI tools were developed or trained.

People — Framework 2.0 assigns governance responsibilities across government, industry, and the public. Your institution must name who is accountable for cross-jurisdictional AI governance internally.

Processes — China’s agile governance model anticipates rapid regulatory iteration. Your institution must have processes for responding to regulatory changes in vendor jurisdictions, not just your own.

Policy — China’s framework feeds directly into binding technical standards through the Law + Standard dual-drive model. Your institution must monitor those standards as they evolve.

Privacy — China’s data governance framework intersects with Framework 2.0. If your institution handles data flowing through Chinese-governed systems, your privacy governance must account for both jurisdictions.

Performance — China’s five-level risk grading system assesses AI based on scenario, intelligence level, and scale. Your institution should understand how tools in your stack are classified under this system.

Procurement — Your vendor contracts may not account for regulatory changes in the vendor’s home jurisdiction. Cross-jurisdictional governance obligations belong in procurement frameworks before deployment.

Partnerships — This is the governance gap. Your institution must map every AI partnership — including indirect ones through tools and platforms — against the regulatory jurisdictions those partnerships operate within.

Predictability — China has enacted more sector-specific AI regulations than any other country since 2021, and July 2026 brought new agentic AI rules. Anticipating continued rapid regulatory iteration is an institutional governance requirement, not an optional consideration.

Protection — Framework 2.0 includes technical countermeasures for identified risk categories. Your institution must evaluate whether those countermeasures align with or conflict with your own protection obligations.

Proof — China’s Law + Standard dual-drive model is translating framework principles into measurable, verifiable technical indicators. Your institution may be asked to demonstrate alignment with those indicators in procurement or partnership contexts.

Precedent — Framework 2.0 does not assign accountability for outcomes within your institution. Who owns the decision when a Chinese-governed AI tool produces an unexpected outcome in your operational workflows? Answering that question before deployment is what governance as leadership looks like.

China’s Framework 2.0 governs AI within its jurisdiction. Institutional leadership governance governs the consequences of AI deployment within yours. The absence of a U.S. prohibition is not a governance answer — it is a governance gap. One defines the standards of a sophisticated and rapidly evolving national governance system. The other maps your institution’s exposure to that system and builds the governance structures to respond. That is the foundation of AI Minimum Viable Governance — and it applies regardless of where the framework originates.

For executive briefings, board workshops, and keynote presentations → freddieseba.com

About the Author

Dr. Freddie Seba helps boards, trustees, and executive leadership teams build practical AI governance before AI failures make governance unavoidable. Scholar-operator, Silicon Valley founder, and global executive — EdD, USF · MBA, Yale · MA, Stanford.

This analysis is part of Ungoverned: Applied Frameworks Under the Lens, a recurring miniseries applying the AI Minimum Viable Governance (AI-MVG) framework and the Seba 12 Ps of Responsible AI to organizations shaping AI governance globally — including AI labs, governments, standards bodies, and international actors across the United States, Europe, Asia-Pacific, the Gulf, Latin America, and beyond. Drafted with AI-assisted tools. Final editorial judgment and responsibility remain with the author. This analysis is for informational and educational purposes only. It does not constitute legal, regulatory, or compliance advice. Institutions should consult qualified legal counsel regarding their specific obligations under applicable frameworks.

© 2026 Freddie Seba. All rights reserved.

References

TC260, National Information Security Standardization Technical Committee. (2025, September 15). AI Safety Governance Framework 2.0. Cyberspace Administration of China. https://www.cac.gov.cn/2025-09/15/c_1759653448369123.htm

Carnegie Endowment for International Peace. (2025, October). How China views AI risks and what to do about them. https://carnegieendowment.org/research/2025/10/how-china-views-ai-risks-and-what-to-do-about-them

AI CERTs. (2026, May). China AI safety guidelines reshape national AI governance. https://www.aicerts.ai/news/china-ai-safety-guidelines-reshape-national-ai-governance/

Global AI Governance & Compliance Center. (2026, June). China AI governance framework: What global businesses need to know in 2026. https://gaicc.org/blog/china-ai-governance-framework/

Lexology. (2025, November). An agile approach: Understanding China’s AI governance framework. https://www.lexology.com/library/detail.aspx?g=ef8efea8-05b1-4bf2-8fd5-08ac531bfd7d

Lexology. (2025, December). China’s AI governance framework: The evolution, trends, and outlook. https://www.lexology.com/library/detail.aspx?g=66e53682-84ad-48d7-85f0-9789ccc1412b

Rimon Law. (2026, July). China AI regulatory developments: July 2026 analysis. https://www.rimonlaw.com/china-ai-law-brief/

Permanent Mission of the People’s Republic of China to the UN. (2025, July 26). Global AI Governance Action Plan. https://un.china-mission.gov.cn/eng/zgyw/202507/t20250729_11679232.htm

International AI Safety Report 2026. (2026). Broader governance initiatives offer voluntary guidance. https://arxiv.org/pdf/2602.21012

#AIGovernance #ChinaAI #AIMVG #AILeadership #Ungoverned #BoardGovernance #AIPolicy #CIO #GlobalAIGovernance #SupplyChain #AIRisk #TechGovernance