Detailed explanation of large model filing: Which companies need to file? How to prepare efficiently?
Updated on:July-02nd-2025
Recommendation
An authoritative guide to big model filing to help companies operate in compliance with regulations
. Core content:
1. Definition and necessity of big model filing
2. Detailed explanation of enterprise filing conditions and procedures
3. Materials required for filing and recommendations on the filing cycle
Yang Fangxian
Founder of 53AI/Most Valuable Expert of Tencent Cloud (TVP)
Recently, I have come into contact with many clients from central state-owned enterprises, and they have many doubts about the registration of large models.I have sorted out the problems that I have encountered frequently recently and put them into a written form.Question 1: What is large model filing?Large model filing refers to the filing and approval process that large model products must go through with regulatory authorities such as the Cyberspace Administration of China (CAC) before they are opened to the public and used commercially.Question 2: Under what circumstances is it necessary to register a large model?According to the requirements of Article 17 and Article 22 of the "Interim Measures for the Administration of Generative Artificial Intelligence Services" , companies that provide generative artificial intelligence services with public opinion attributes or social mobilization capabilities are required to register algorithms and large models.It is recommended that the following types of enterprises make large model filings:- The model is self-developed, or has been fine-tuned or modified based on an open source model and has a lot of training data.
- Large-scale enterprise or large-scale model serving application.
- Enterprises whose main business is generative artificial intelligence and need to use it for commercial promotion.
- The local area has corresponding subsidy policies for those who have passed the registration.
- Enterprises notified or recommended by local Internet Information Offices, Industry and Information Technology Bureaus and other relevant departments.
The following enterprises do not need to file large models:Enterprises that are not engaged in generative artificial intelligence large model-related businesses.
Generative AI services that do not have public opinion attributes or social mobilization capabilities (e.g., those that are purely for self-use or only serve a small number of B-side users).
The situation of purely calling the third-party large model API interface (algorithm filing and registration filing are required).
Question 3: What is the general process for large model registration?- Enterprises take the initiative to apply to the local Cyberspace Administration of China (provincial level)
- After approval, the Cyberspace Administration will provide feedback on the materials that need to be submitted and select a tutor.
- The enterprise completes the self-assessment and prepares the materials required for filing (this is the key point)
- Submit the materials to the local Cyberspace Administration for evaluation (this may involve rejection and modification )
- After the material evaluation is passed, the local Cyberspace Administration will conduct a security assessment, that is, a large model interface security assessment
- After the security assessment is passed, the materials will be submitted to the Central Cyberspace Affairs Commission for review
- The Central Cyberspace Affairs Commission has reviewed and approved the large model interface security assessment
- After passing, it will be announced on the Internet Information Service Algorithm Filing System website.
Question 4: How long in advance do you usually need to start preparing for large model filing?Because the filing process involves multiple links and departments, and the situations of different companies are different, the filing period is not fixed. However, according to our practical experience, it usually takes 3-6 months from the beginning of preparation to the final announcement .Question 5: What materials are needed for large model registration?In actual work, different cases have different requirements for quantitative indicators of specific indicators. The red part in the figure is only a recommended value.Question 6: I am using an open source model, do I need to register it?Whether you need to file a record does not depend on whether you use an open source model or a closed source model, but whether you meet the conditions in question 2. In order to avoid unnecessary regulatory risks, it is recommended that companies should prepare as much as possible.Question 7: The large model service I provide is only for internal use within the company. Do I need to register it?If the enterprise is large in size, or if the enterprise officially releases large model services to the outside world, it is recommended that it still needs to be registered.Question 8: I directly call a third-party big model to provide external services, and the third-party big model has been registered. Do I still need to register it?According to the "Interim Measures for the Management of Generative Artificial Intelligence Services" and relevant regulations, for generative artificial intelligence applications or functions that directly call the registered large model capabilities through API interfaces or other means, a registration management method is adopted to allow them to go online to provide services.Question 9: How to write a large model safety assessment report?Answer: The "Large Model Security Assessment Report" mainly includes corpus security assessment, model security assessment, and security measures assessment.The corpus security assessment focuses on information such as the corpus size, corpus source, corpus annotation rules, training servers, etc. It is recommended that the algorithm department take the lead in writing it.The data security part mainly refers to the "Security Specifications for Pre-training and Optimization Training Data of Generative Artificial Intelligence for Cybersecurity Technology" (Draft for Comments) , and the annotation security part mainly refers to the "Security Specifications for Data Annotation of Generative Artificial Intelligence for Cybersecurity Technology" (Draft for Comments) .The model security assessment focuses on the security assessment of generated content, discrimination, transparency, etc. It is recommended that the algorithm and security departments work together to write the generated content security assessment. The generated content security assessment is mainly written with reference to the " Basic Security Requirements for Generative Artificial Intelligence Services" .The security measures assessment includes risk prevention measures during the model application process , personal information protection measures, privacy data protection measures, content identification and traceability measures , etc. It is recommended that the security and legal departments take the lead in writing it.The identification part is mainly written with reference to the "Cybersecurity Standard Practice Guide - Generative Artificial Intelligence Service Content Identification Method" and the "Cybersecurity Technology Artificial Intelligence Generated Synthetic Content Identification Method" .Question 10: If the existing APP is connected to the intelligent question-and-answer function based on the big model API, is it necessary to modify the privacy policy and user agreement?A: No, only native AI applications (Wenxinyiyan, Doubao, kimichat, etc.) need to be prepared separately. You can refer to these common large-model AI applications for specific writing based on actual business.