Skip to content
AI.info

The Pulse

Seven AI-Model Operators in Hunan Summoned Over Security Lapses

Hunan’s cyberspace regulator summoned seven large-model operators after inspections found information-security violations, ordering rectification while five operators completed corrective work and two took models offline.

Seven AI-Model Operators in Hunan Summoned Over Security Lapses

AI.info Team ·

Hunan regulator summons seven AI-model operators

Seven large-model operators in China’s Hunan province were summoned by the Hunan provincial cyberspace administration after inspections found information-security problems in their generative-artificial-intelligence services, according to an announcement issued by the regulator and reported by MLex.

The operators were not identified by name. The announcement referred to them as seven large-model operating units and did not identify the models involved, the companies’ products or the specific technical failures found during the inspections.

The regulator said the operators’ services violated provisions of China’s Cybersecurity Law and the Interim Measures for the Management of Generative AI Services. The inspections concerned information-security compliance in the operators’ generative-AI services.

Regulator orders corrective work

The Hunan cyberspace administration summoned the people responsible for the seven operators and ordered them to correct the problems within a specified period. The requirements included investigating vulnerabilities in their information-security guardrails and implementing corrective measures.

The announcement did not provide separate findings for each operator. It did not say whether the violations involved content controls, model testing, data handling, security reviews or another aspect of the services’ information-security arrangements.

A Hunan provincial cyberspace administration official said:

相关运营单位要严格落实法律法规要求,切实履行主体责任,筑牢网络空间安全屏障。网信部门将坚持包容审慎监管原则,持续加大相关执法工作力度,推动生成式人工智能产业健康有序发展。

In English, the official said the operators should strictly comply with legal and regulatory requirements, fulfill their primary responsibilities and strengthen cybersecurity safeguards. The official also said cyberspace authorities would continue enforcement while applying a principle of tolerant and prudent regulation to support the orderly development of the generative-AI industry.

Five operators complete rectification

Five of the seven operators have completed rectification, the regulator said. The announcement did not identify those operators or list the corrective measures they adopted.

It also did not disclose the vulnerabilities found in the five operators’ information-security guardrails, explain how the fixes were tested or say whether the regulator had conducted follow-up inspections. The reported announcement therefore confirms completion of the corrective process without providing a technical account of the work.

Two models taken offline

The other two operators voluntarily took the affected large models offline, according to the regulator. Their names, the model names and the services associated with them were not disclosed.

The announcement did not state whether the two operators would be required to complete additional rectification before restoring the models. It likewise did not describe the security problems that led to the decision to remove the models from service.

Hunan enforcement action

The case records two outcomes among the seven operators. Five completed the corrective work required by the regulator, while two voluntarily took the affected models offline. All seven operators were identified by the regulator as having generative-AI information-security problems and as having violated the cited rules.

The action adds to the enforcement activity of local Chinese cyberspace authorities concerning generative-AI services. In this case, however, the public announcement provides limited detail beyond the number of operators involved, the legal provisions cited, the order to investigate security-guardrail vulnerabilities and the results reported after the operators were summoned.

It does not identify the companies, models or individual findings. It also does not provide information about the commercial impact of taking the two models offline or indicate when, if ever, those services might return.

Source

网信湖南

Explore

More articles