The Cyberspace Administration of China (CAC) has released a progress report on the second phase of its “Qinglang” special campaign targeting the misuse of AI applications. In this phase, regulators removed more than 5.61 million pieces of illegal or non-compliant content, punished more than 49,000 accounts, and took action against more than 2,400 non-compliant websites and apps. Platforms issued a combined 46 governance notices during the period, and cyberspace authorities in Beijing, Shanghai, Zhejiang, Guangdong and other regions carried out the actual enforcement.
The problems targeted in phase two are entirely different from phase one: using AI to produce and spread false information, disseminate violent or vulgar content, impersonate or counterfeit others, infringe on the rights of minors, run astroturfing and paid-comment operations, and non-compliant content generated by AI products themselves.
From Shutting Down Products to Purging Accounts
The special campaign was rolled out in late April this year, running for four months across two phases and focusing on 14 categories of prominent problems. Placing the results of the two phases side by side makes the shift in focus immediately clear.
Phase one’s report showed action taken against more than 14,000 non-compliant AI products, over 1,300 non-compliant AI products pulled from distribution, and 9 non-compliant open-source datasets taken down — all aimed at the technical source: whether large models were registered as required, whether platforms’ security review and filtering capabilities were adequate, whether training data had been poisoned, and whether labeling requirements for AI-generated synthetic content had been implemented. The targets were the products themselves.
In phase two, the number of products acted against dropped to 2,400, while the number of accounts punished jumped from 26,000 to nearly 49,000 — almost double. The volume of removed content stayed roughly flat across the two phases (more than 6 million versus 5.61 million pieces), but the same volume of content now traces back to nearly twice as many accounts. A rough calculation shows that in phase one, each punished account was linked to about 230 pieces of violating content on average; in phase two that figure fell to around 115. Output per account is shrinking while the number of accounts involved is growing — a textbook pattern of what happens once a tool becomes widespread: as the barrier to AI generation drops, so does the cost of mass-producing accounts to churn out content, forcing enforcement to operate at an ever finer grain.
What Platforms Turned In
On the content-platform side, Douyin, Kuaishou, Weibo, Tencent, Baidu, Bilibili, Xiaohongshu, Zhihu, Douban and Taobao concentrated their efforts on detection capability: refining multimodal recognition models, dynamically expanding face, voiceprint and violation-sample databases, and rolling out real-time facial governance systems. The fact that faces and voiceprints were singled out points to the thorniest problem of this phase — impersonation and counterfeiting, commonly known as face-swapping and voice-cloning.
On the AI-product side, Doubao, Yuanbao, Qwen and Ernie Bot were named and required to tighten review of raw training data, strictly limit non-compliant output, and reinforce implementation of labeling requirements for AI-generated synthetic content. Regulators are now assessing both the generation side and the distribution side together: a model not generating violating content is the first checkpoint, a platform being able to detect it is the second, and both need to leave an auditable record.
Even the very top of the distribution chain wasn’t spared. App stores run by several major smartphone makers were required to set strict developer-onboarding standards and listing requirements, spot-check and retest apps already on the shelf, and block non-compliant apps at the point of entry. Developer registration, app listing, content generation, content distribution and account operation — this round covered enforcement criteria for all five links in the chain.
Where the Center of Gravity for Compliance Has Shifted
For teams building AI applications in China, the practical difference between the two phases comes down to a change in what compliance spending goes toward.
Phase one was about clearing the entry gate: model registration, data provenance and content labeling — a one-time investment that, once done, holds up for a while. Phase two tests the operations gate: once a product is live, who is using it, what it’s generating, and whether it’s being exploited for mass account farming all become the platform’s responsibility. The 46 governance notices and the more than 49,000 punished accounts show that this gate isn’t cleared with a single filing — it requires a review system and enforcement pipeline that keep running continuously.
The content-labeling requirement deserves particular attention. In phase one it was a yes/no compliance box; by phase two it had become the starting point of an accountability trail: for a reported piece of false information, complete labeling lets regulators trace it back to the generation source, while missing labeling leaves the platform to account for the entire chain itself. Real spending is shifting toward review systems and traceability capability, no longer just the registration paperwork.
Sources: Cyberspace Administration of China announcement, Xinhua, CocoLoop, China News Service; the content-removal, account-punishment and product-action figures for both phases were checked line by line against official announcement wording, and the per-account average was calculated from public figures.