The second version of China’s Artificial Intelligence Safety Governance Framework landed on Monday at the main forum of the 2025 Cybersecurity Week in Kunming, Yunnan province. The document, published by China Daily, was jointly developed by the National Computer Network Emergency Response Technical Team/Coordination Center of China (CNCERT/CC) and a consortium of AI professional institutions, research institutes, and industry enterprises. It follows the 1.0 version released in 2024.

The 2.0 version is not a radical departure. It builds on the first edition by integrating developments in AI technology and application practices, tracking risk changes, refining risk classifications, and updating preventive measures, according to a news release from the Cyberspace Administration of China (CAC). An official from CNCERT/CC said the new version “aligns with global AI development trends, balancing technological innovation with governance practices and deepening consensus on AI safety, ethics and governance.”

That language matters. The framework promotes “a safe, trustworthy and controllable AI development ecosystem” and establishes “a collaborative governance model that spans borders, fields and industries.” The official also said the release supports advancing AI safety governance cooperation under multilateral mechanisms and promotes the “inclusive sharing of technological achievements worldwide.”

What is genuinely new here is not the content of the framework itself, which remains largely abstract at the level of public description. What is new is the timing and the audience. The 2.0 version arrives as the European Union’s AI Act enters enforcement phases, as the United States struggles to pass comprehensive federal AI legislation, and as the Global South — nations in Southeast Asia, Africa, and Latin America — looks for governance models that do not require alignment with either Washington or Brussels.

China is positioning its framework as a third way. The language of “controllable” AI development, of “multilateral mechanisms,” and of “inclusive sharing” of technological achievements is calibrated for nations that want AI governance without the human rights conditionality embedded in Western frameworks. The EU AI Act ties risk classification to fundamental rights impacts. The U.S. executive orders on AI safety tie governance to democratic values. China’s framework offers a more transactional bargain: adopt our governance model, get access to our AI ecosystem.

The CNCERT/CC is an interesting choice of lead developer. It is a technical incident-response organization, not a legislative body or a standards-setting institution like the National Institute of Standards and Technology (NIST) in the U.S. or the European Committee for Standardization (CEN). That choice signals that the framework is intended to be operational, not aspirational. The 1.0 version was released in 2024; the 2.0 version already incorporates “risk changes” observed in the intervening year. This is a governance document designed to be updated on a cadence that matches AI capability release cycles, not legislative cycles.

The framework’s emphasis on “refining risk classifications” is a direct response to the problem that has plagued every AI governance effort to date: risk taxonomies that are either too vague to be enforceable or too rigid to accommodate new capabilities. The EU AI Act’s four-tier risk classification (unacceptable, high, limited, minimal) has been criticized for its ambiguity around general-purpose AI models. The U.S. NIST AI Risk Management Framework is voluntary and lacks enforcement mechanisms. China’s approach appears to be iterative and technical, with the CNCERT/CC acting as a central clearinghouse for risk classification updates.

But the framework has a blind spot that should concern AI builders inside and outside China. The language of “trustworthy and controllable” development implies a governance model where the state retains ultimate authority over what counts as safe AI. For researchers working on open-weight models, on adversarial robustness, or on interpretability, the framework’s “collaborative governance model that spans borders, fields and industries” may translate into a requirement to coordinate with the CAC and CNCERT/CC before publishing findings or releasing models. That is a different governance philosophy from the West’s emphasis on independent safety evaluations and researcher-led disclosure.

The framework’s reception in the Global South will be the test. Nations like Indonesia, Brazil, Nigeria, and Vietnam are building AI strategies from scratch. They face a choice among regulatory models. The EU model requires institutional capacity for enforcement and a legal tradition of rights-based governance. The U.S. model is fragmented and voluntary. China’s model offers a single framework, a technical lead organization, and a promise of technological inclusion. For a government that wants to regulate AI without adopting Western political values, the CNCERT/CC framework is an attractive package.

The 2.0 version’s support for “advancing AI safety governance cooperation under multilateral mechanisms” is not just diplomatic language. China has been active in the United Nations, the International Telecommunication Union, and the World Internet Conference in pushing its vision of AI governance. The framework provides the technical scaffolding for that diplomatic push. If a dozen nations adopt the CNCERT/CC risk classification system as their national standard, the framework becomes a de facto international standard, regardless of what the EU or the U.S. does.

For AI builders, the implication is straightforward. The governance landscape is not converging. It is diverging into at least three regulatory blocs: the EU’s rights-based model, the U.S.’s market-led model, and China’s state-coordinated model. Each bloc has its own risk taxonomy, its own enforcement mechanisms, and its own expectations for model developers. A company shipping a foundation model globally will need to comply with all three, or choose which markets to serve.

The CNCERT/CC framework 2.0 is not a revolutionary document. It is an incremental update to a governance approach that China has been developing since 2023. But its release at Cybersecurity Week 2025, with explicit language about cross-border cooperation and multilateral mechanisms, signals that China intends to export its governance model as aggressively as it exports its AI hardware and applications. The framework’s real impact will be measured not by what it says, but by how many nations adopt it.