Complete AI Training

AI news ·

Key Compliance Considerations for Selecting AI Computing Centres in China

Choosing AI computing centres requires checking operational licences, security history, and IP rights. Clear contracts with data protocols and contingency plans ensure compliance and risk management.

Share

Compliance Factors for AI Computing Centres

Computing power is a critical pillar of AI development, alongside data and algorithms. As AI applications proliferate—especially with open-source large models like DeepSeek—the demand for powerful computing resources has surged worldwide. Given the high costs of building and maintaining local infrastructure, many companies now turn to intelligent computing centres for support.

These centres are cloud platforms focused on AI applications and big data processing, equipped with high-performance hardware such as GPUs (graphics processing units) and FPGAs (field-programmable gate arrays). In December 2023, China launched the “East Data, West Computing” initiative, promoting computing power as a key productivity driver and encouraging cross-regional intelligent computing centre development.

Against this backdrop, companies face a new compliance challenge: how to select an appropriate intelligent computing centre that meets legal and regulatory standards.

Credential Requirements

Enterprises must verify the supplier’s operational licences to ensure supply chain stability and legal compliance.

  • Operational licences. In China, providers need licences under the Telecommunications Regulations to offer computing power services. Common permits include internet data centre operations (B11), electronic data interchange (B21), and internet content providers (B25). A B11 permit is essential for IaaS/PaaS models, while PaaS/SaaS offerings require an additional B25 permit.
  • Technical qualifications. Centres providing specialised services must hold specific certifications. For example, the Ministry of Natural Resources’ 2024 Notice requires entities handling geospatial data from intelligent connected vehicles to have certified surveying and mapping qualifications. This prohibits centres without upgraded certifications from processing raw geospatial information legally.
  • Preferential policies. Free trade zones offer advantages such as streamlined licensing and data export channels. The Beijing Free Trade Zone, for instance, publishes a negative list for outbound data, aiding cross-border transmission planning. Hainan Free Trade Port and Shanghai Lingang provide dedicated channels and special measures for international data centre operations and data filing.

Compliance Obligations

  • Tiered protection scheme. Article 21 of China’s Cybersecurity Law mandates all domestic network systems to implement tiered protection. Intelligent computing centres should help enterprise clients secure their applications accordingly.
  • Mandatory standards. When products or services fall under the Catalogue of Critical Network Equipment and Cybersecurity-specific Products, enterprises must comply with the General Security Requirements for Critical Network Equipment.
  • Security maintenance. Article 22 requires continuous security maintenance from intelligent computing centres throughout the agreed service period. Businesses should prioritise security upkeep to prevent performance issues amid rapid industry growth.
  • Cybersecurity scrutiny. Operators of critical information infrastructure must undergo cybersecurity scrutiny when procuring network products that affect national security. Intelligent computing centres could be classified under this category. If core suppliers are overseas and fail scrutiny, service interruptions may occur. Hence, contracts must clearly define contingency plans and liability to avoid misuse of force majeure clauses.

Rights and Liabilities

  • Intellectual property clauses. Users typically retain IP rights to AI-generated content. However, intelligent computing centres may include contract clauses claiming joint ownership or specific rights if their proprietary algorithms substantially contribute to the output.
  • Intellectual property infringement liability. Centres might be considered network service providers under law. According to article 1197 of the Civil Code, if a centre controls infringing behaviour or fails to act upon awareness, it could be held jointly liable. For example, in China’s first AI-generated voice personality rights case, the Beijing Internet Court ruled a cloud platform not liable due to lack of subjective fault. AI computing centres should expect increased IP and personality rights litigation, so enterprises must review liability clauses carefully.

Key Takeaways

Enterprises must conduct thorough legal compliance assessments before selecting an AI computing centre. This includes checking operational licences and reviewing the centre’s security history for data incidents or regulatory breaches.

Contracts should clearly outline data handling and storage protocols, with additional agreements as necessary. Special attention to intellectual property and trade secret protections helps prevent ownership disputes.

Moreover, agreements should include contingency plans for cases like hardware suppliers failing cybersecurity scrutiny. Defining response measures and liability terms for data breaches and security incidents is critical to managing risks effectively.

For legal professionals involved in AI deployment, understanding these compliance factors is essential to safeguard company interests and ensure regulatory adherence.

Share