Among the cases the Cyberspace Administration of China published on September 2 as examples of what it had scrubbed from the Chinese internet were AI remixes of Romance of the Three Kingdoms and Journey to the West — classical epics rewritten by generative models into sensationalized clickbait. The regulator has a term for it: "digital swill." It sits in the same bulletin as deepfaked videos of public figures, fabricated disaster footage aimed at elderly users, and AI agents whose generated dialogue sexualized minors.
The CAC said authorities have removed more than 5.61 million pieces of unlawful or rule-violating content, acted against more than 49,000 accounts, and dealt with more than 2,400 websites and apps. That is the reported yield of the second phase of a four-month "Qinglang" special action against chaos in AI applications, launched April 30 — a campaign whose first phase pulled more than 14,000 non-compliant AI products offline, per Chinese state media in July.
These figures come from the regulator and were distributed through Xinhua. They cannot be independently verified, and the CAC publishes no breakdown separating fraud and impersonation takedowns from politically sensitive removals. What is verifiable is the shape of the machinery, because Beijing has documented it in unusual detail.
What the campaign actually covers
The four categories named in the CAC's announcement are AI-fabricated disinformation, violent or vulgar synthetic material, AI-enabled impersonation, and content infringing on minors' rights. A fifth strand is AI-powered astroturfing — hosting software that automates accounts and comments, which the regulator frames as a machine-scale evolution of China's commercial "water armies."
The pressure runs across three layers of the stack rather than only at the post. Distribution platforms — Douyin, Kuaishou, Weibo, Tencent, Baidu, Bilibili, Xiaohongshu, Zhihu, Douban and Taobao — expanded face, voiceprint and violation-sample libraries feeding automated detection, issuing 46 governance notices between them. Model providers including Doubao, Yuanbao, Qwen and Ernie Bot tightened review of training corpora and output filtering. App stores run by Huawei, Xiaomi, Oppo and Vivo raised developer vetting and rechecked listed apps.
The legal footing is what makes 2026 different from the equivalent 2025 sweep. The Measures for the Labeling of AI-Generated and Synthesized Content — issued in March 2025 by the CAC with the industry, public security and broadcasting ministries — took effect September 1, 2025 alongside a mandatory national standard on labeling methods, layered on the 2021 algorithmic recommendation rules and the 2023 deep synthesis and generative AI measures.
How labeling enforcement works in practice
The regime pairs explicit labels — visible to users — with implicit metadata identifiers embedded in the file. Yu Yonghe, who heads the CAC's Network Management Technology Bureau, described the architecture in a February signed article as a "1+1+N" structure: one normative document, one mandatory standard, multiple implementation guides.
The engineering choices are pointedly unambitious, and that appears deliberate. Rather than requiring robust digital watermarking, which demands capability smaller platforms lack, the system accepts metadata-based implicit labels — and those retain information only on the most recent dissemination platform, not the full chain, to hold down costs. Detection is not mandatory for distribution platforms; the rules lean on user self-declaration. Text gets a corner "AI" mark modeled on trademark badges; short audio gets a Morse-code rhythm cue for "A" and "I."
Four months in, Yu reported that Doubao, DeepSeek, Qwen and Ernie had cumulatively labeled more than 150 billion generated items, and that dissemination platforms had attached prominent prompts to more than 220 million. Again: regulator-sourced numbers.
The gaps are documented in Chinese state media too. Xinhua reported in February on an open grey market in "AI mark removal," from tools costing 9.9 yuan (about $1.40) to bespoke services in the thousands, with evasion evolving from cropping into metadata cleansing and format conversion. "Content that is required to carry an AI label on one platform may evade scrutiny on another after a simple change in format," said Shen Yulin, deputy director of the Gansu provincial computing center.
Aggressive promotion, aggressive policing
The reflex reading is that this campaign is a brake on Chinese AI. It is not. Beijing is running maximum promotion and maximum policing at once, and the CAC's own bulletins state the parallel goal of fostering "healthy and orderly" AI development. The same state that removed 5.61 million items is backing compute buildout and open-weight releases from Alibaba, DeepSeek and ByteDance. Enforcement is positioned as what makes rapid diffusion politically survivable.
The implication for Western policy debates is technical rather than ideological. Provenance labeling at national scale has been treated in the US and Europe as an aspiration with unresolved feasibility. C2PA's Content Credentials ecosystem passed 6,000 members and affiliates by January 2026 and reached consumer hardware with the Pixel 10, but adoption is uneven and the credential chain still breaks whenever a platform strips metadata on upload. China took the opposite path: a mandatory floor with modest technical demands, enforced by a regulator that can delist apps. The 150 billion figure, even discounted heavily, suggests the binding constraint on provenance in the West was never purely engineering.
That is exactly where borrowing gets dangerous. The mechanism — mandatory dual labeling, platform verification duties, app-store gatekeeping — is separable in principle from the censorship apparatus it rides on. In practice, the Qinglang brand has been the vehicle for annual removals of speech challenging official narratives since 2016, and no external audit distinguishes the scam takedowns from the rest. Writing for the Carnegie Endowment in March, Hong Kong democratic activist and former legislator Nathan Law argued that "robust digital authoritarianism is now enabled by powerful AI systems," while noting a limit: heavy repression starves censorship models of training data, so human reviewers remain essential and expensive.
What to watch
The four-month window closed at the end of August, so the September 2 bulletin reads as a wrap-up — watch whether the CAC converts it into a standing regime or opens a third phase. Watch for named penalties against platforms for labeling failures specifically, which would show the Measures enforced as law rather than as campaign atmosphere. Watch the promised guidelines for AI agents and digital humans, categories the current standard handles poorly. And watch which governments start citing the 150 billion number in their own provenance debates.
“Content that is required to carry an AI label on one platform may evade scrutiny on another after a simple change in format.”— Shen Yulin, Deputy director, Gansu provincial computing center