Healthcare AI 2026

Last Updated August 05, 2026

China

Law and Practice

Authors



Fangda Partners was founded in 1993 and is a leading full-service law firm with approximately 800 lawyers across offices in Beijing, Guangzhou, Hong Kong, Nanjing, Shanghai, Shenzhen and Singapore. The firm adopts a one-firm approach, providing integrated legal services across all practice areas and locations. Recognised as the firm of choice for complex and high-stakes legal matters, Fangda advises major domestic and international companies on both transactions and disputes. Fangda’s team includes lawyers qualified in the PRC, Hong Kong, the United States, the United Kingdom, Australia and Singapore, offering strong cross-border capabilities with a distinct China focus. Fangda has extensive experience in the AI and life sciences sectors, such as personalised medicine, digital health and biotechnology, including genomics and cancer diagnostics. The firm has assisted several leading pharmaceutical companies in deploying AI tools to support offline marketing and streamline business operations.

In China, AI is widely used across the healthcare and life science sectors. In clinical settings, AI powers diagnostic imaging, virtual consultations and surgery planning tools, and provides clinical decision support for general practitioners. In the pharmaceutical sector, AI is primarily used for drug discovery, including target identification, virtual screening and clinical trial design. Meanwhile, AI-enabled wearable devices support remote patient monitoring and chronic disease management.

In recent years, Chinese authorities have taken active steps to guide and accelerate the development of healthcare AI. In November 2024, the Reference Guide for AI Application Scenarios in the Healthcare Industry (the “AI Application Scenarios Reference Guide”) identified 84 use cases across four categories: medical service management, public health and primary care, health industry innovation (such as robotics and drug development), and medical education and research. Further, in early 2025, the Notice on Carrying out the 2025 Innovation Task of AI-based Medical Devices (the “2025 Innovation Task Notice”) was issued, promoting breakthroughs in intelligent diagnostic and therapeutic tools. In March 2025, the Opinions on Comprehensively Deepening the Reform of Drug and Medical Device Regulation to Promote the High-Quality Development of the Pharmaceutical Industry strengthened the regulation of next-generation medical technologies, including AI and medical robotics, by improving national technical standards and regulatory systems.

Healthcare AI adoption in China is driven by both systemic needs and innovation opportunities. On the one hand, medical institutions face growing pressure from limited medical resources, uneven care quality between urban and rural areas in China, and a rising demand for faster and more accurate diagnoses. On the other hand, pharmaceutical companies are under pressure to accelerate drug discovery, reduce R&D costs and improve trial design. These challenges have created strong incentives across the healthcare system to adopt AI solutions that can improve outcomes, enhance efficiency and support clinical decision-making.

AI technologies bring several significant benefits to healthcare delivery. First, they can improve diagnostic accuracy and efficiency, particularly in radiology and pathology, by supporting faster and more reliable image interpretation. Second, AI improves access to care by supporting primary care healthcare professionals (HCPs) in under-resourced areas through triage, symptom assessment and risk prediction tools. Third, AI enables more personalised treatment by integrating genomics, pathology and patient-specific health data to support tailored clinical decisions, especially in oncology. Fourth, AI contributes to public health by strengthening early warning and monitoring systems. During the COVID-19 pandemic, AI tools were used for outbreak modelling, contact tracing and real-time policy support. Fifth, AI helps standardise care pathways across medical institutions, promoting more equitable treatment regardless of geography. Finally, AI accelerates pharmaceutical innovation by optimising target identification, virtual compound screening and trial design. These tools are increasingly being integrated into R&D workflows, shortening timelines and boosting productivity.

Despite these advantages, AI also brings challenges around safety, liability, regulatory oversight and integration into professional workflows.

China’s healthcare AI market is rapidly evolving under strong policy support and industrial demand. The AI Application Scenarios Reference Guide and the 2025 Innovation Task Notice emphasise scenario-based adoption and regulatory readiness. Local governments have issued tailored plans to accelerate integration, such as the Shanghai and Suzhou.

Pharmaceutical companies and technology developers are the primary drivers of innovation, and big technology firms and AI startups play a key role as enablers in these ecosystems.

Notable collaborations reflect how tech and medical institutions are jointly reshaping healthcare delivery through AI. Hospitals such as Zhongshan Hospital, Jiangsu Provincial People’s Hospital, the Second Affiliated Hospital of Zhejiang University and China-Japan Friendship Hospital have partnered with Huawei, iFlytek, Tencent, Alibaba Health and Baidu to deploy AI solutions across imaging, triage, follow-up, patient engagement and clinical decision support.

Current law and regulations lack a statutory definition for “healthcare AI systems”. However, the AI Application Scenarios Reference Guide provides concrete definitions for specific AI healthcare application scenarios. AI-based medical software packages meeting the statutory definition of medical devices are regulated as medical devices. The AI Application Scenarios Reference Guide categories healthcare AI applications into four domains with specific use cases.

  • AI + Medical Service Management – including medical services, pharmaceutical services, health insurance services, traditional Chinese medicine administration and hospital management.
  • AI + Primary Public Health Services – including health management services, public health services and elderly and childcare services.
  • AI + Health Industry Development – including medical robotics, drug research and development and traditional Chinese medicine industry.
  • AI + Medical Education & Research – including medical education and medical research.

AI medical software packages qualifying as medical devices are categorised under the Guiding Principles for the Classification and Definition of AI-based Medical Software Products as follows.

  • Low-maturity algorithms – any AI medical software performing assisted decision-making functions is classified as a Class III medical device, and any such software without assisted decision-making capabilities is classified as a Class II medical device.
  • High-maturity algorithms – according to the Classified Catalogue of Medical Devices, the following product types exist, with the management categories (Class II and Class III) also determined based on this catalogue:
    1. treatment planning software;
    2. medical image analysis software;
    3. clinical data mining software;
    4. diagnostic decision support systems;
    5. in vitro diagnostic (IVD) algorithms; and
    6. rehabilitation progress tracking tools.

China lacks unified healthcare AI legislation.

Alongside existing medical device regulations, such as the Regulation on the Supervision and Administration of Medical Devices (revised in 2024; the “Medical Devices Supervision Regulation”) and the Administrative Measures on the Registration and Record-filing of Medical Devices (“Registration and Filing of Medical Devices Measures”), sector-specific rules target technologies like generative AI (GenAI) and deep synthesis algorithms – such as the Interim Measures for the Administration of Generative Artificial Intelligence Services (the “Gen AI Measures”), the Provisions on the Administration of Deep Synthesis of Internet-Based Information Services (the “Deep Synthesis Rules”), the Provisions on the Administration of Algorithm-generated Recommendations for Internet Information Services (the “Recommendation Rules”), the Cybersecurity Law (CSL), the Data Security Law (DSL) and the Personal Information Protection Law (PIPL). Specialised technical guidelines also form part of the regulatory framework, such as the Guiding Principles for Registration Review of AI-based Medical Devices (the “Guiding Principles for AMD Registration Review”). Moreover, investments in the healthcare AI sector remain subject to general foreign direct investment restrictions.

The regulatory framework comprises three distinct categories: AI medical devices, algorithm-based products, and medical service and medical technology.

Regarding AI medical devices, pursuant to the Guiding Principles for AMD Registration Review, the regulatory process covers several stages, starting with design and development and followed by pre-submission, submission and review and finally certification.

After determining the registration category, AI-based medical software is registered as standalone software. In special circumstances, streamlined pathways may apply, specifically covering two scenarios:

  • combined registration, which is applicable when software functionally depends on other medical software to operate, allowing it to be registered as an integrated component of that host software; and
  • priority review, for products meeting the criteria under the Registration and Filing of Medical Devices Measures (eg, innovative device, priority or emergency registration procedures) that may access the accelerated review process.

The foundational regulatory obligations include three main aspects:

  • general medical device requirements, covering registration/filing and post-market obligations (quality management, adverse event reporting and recalls);
  • AI-specific registration, encompassing the registration requirements of the Guiding Principles for AMD Registration Review and the cybersecurity requirements of the Guiding Principles for Cybersecurity Registration Review of Medical Devices (the “Guiding Principles for Cybersecurity Registration”); and
  • production standards, where for standalone software, the Appendix to Guidelines for Quality Management of Medical Device Production – SaMD (“SaMD Quality Management”) imposes specific controls (eg, separation of development/testing roles, record requirements, quality control).

Regarding AI algorithm requirements, according to the Deep Learning-Assisted Decision-Making SaMD Review, algorithm design shall consider the quality control requirements for the following activities: algorithm selection, algorithm training, cybersecurity protections and algorithm performance evaluation.

As for continuous learning, according to the Guiding Principles for AMD Registration Review, the registration applicant shall verify and validate the safety and effectiveness of self-learning updates under its quality management system, apply for change registration where required and deploy such updates only upon obtaining the National Medical Products Administration's (NMPA) approval.

Currently, healthcare AI is still subject to general data protection legal requirements, including the PIPL, CSL, DSL and Network Data Security Management Regulations, etc.

Where patient data or wearable device users’ personal data is to be used for AI model training and operation, the following data processing activities should be carefully considered.

  • Collection and use: Developers and operators of AI-based medical devices must strictly adhere to the principles of lawfulness, legitimacy, necessity and data minimisation. Medical institutions should inform patients of the nature, function, and potential risks of AI assistance with a clear explanation of the intended purpose and obtain necessary consent prior to treatment.
  • Storage: Patients’ medical record data constitutes sensitive information and thus must be securely stored using technical and managerial measures.
  • Sharing and cross-border data transfer (CBDT): Please see 6.3 Data Sharing and Access for details.
  • Anonymisation: Please see 6.4 De-Identification and Anonymisation for details.
  • Cybersecurity multi-level protection scheme (MLPS): Enterprises or medical institutions deploying and operating on-premises AI diagnostic systems must conduct pre-deployment security risk assessments and meet relevant MLPS obligations based on their data processing activities.

Applicable standards are scattered across national, industry and group standards. While national standards mainly cover general cybersecurity and data protection, technical guidance pertinent to healthcare AI is largely found in industry and group-level standards.

GenAI systems that interact directly with patients shall obey the following requirements stipulated by national standards.

  • Basic security requirements – if healthcare AI systems directly interact with patients, it is required that AI developers should pay close attention to user notification, content moderation and safety requirements for both large language model (LLM) training and outputs, and overarching primary security measures.
  • Pre-training and training data – the relevant national standard sets requirements for the pre-training and optimisation of training data used in GenAI, as well as the processing activities involved.
  • AI-generated content (AIGC) labelling – labelling includes both explicit and implicit forms. Explicit labelling uses visible cues to alert the public and prevent confusion, while implicit labelling relies on metadata-based tagging. Detailed requirements are set out in the Measures for Labelling AI-Generated or Composed Content and the national standard GB/T 45438-2025.

In addition to GenAI services, healthcare AI systems are also subject to the following technical requirements and standards.

  • Full-cycle personal health data processing – various standards specify principles and security requirements for personal information-related activities such as collection, storage, use, sharing, transfer, public disclosure and deletion.
  • Telemedicine platforms, information access and data exchange – many national standards focus on the architecture of telemedicine platform data access and exchange, including technical requirements for front-end gateway data exchange.
  • Specific scenario-based applications – industry and group standards have already been developed for various AI applications in different medical treatment scenarios, such as lung image analysis tools and coronary computed tomography (CT) imaging software.

National standards are normally developed by standardisation institutions and sectoral administrations, such as the National Information Security Standardization Technical Committee (TC260) and the NMPA, while group standards are often led by the China Communications Standards Association, with supervision and direction by regulatory agencies like the Cyberspace Administration of China (CAC), the Ministry of Industry and Information Technology (MIIT) and the NMPA.

Regulators can be categorised by sectoral administration and supervision mandates as:

  • medical sector regulators, where the NMPA governs medical device registration, technical reviews and post-market surveillance for healthcare AI products, and the National Health Commission supervises medical institutions and their usage of AI products and/or services;
  • technology regulators, where CAC and MIIT govern cybersecurity, AI-related matters and data compliance; and
  • ancillary regulators, where the State Administration for Market Regulation monitors advertising compliance, while the National Development and Reform Commission and Ministry of Commerce supervise foreign investment.

Inter-agency co-ordination occurs through specialised law enforcement campaigns. CAC and MIIT, as technology regulators, lead these efforts, but in practice will defer to sector-specific authorities such as the NMPA for healthcare oversight.

Pre-market requirements for healthcare AI developers in China mainly apply to AI-based medical devices, which are regulated under the Medical Devices Supervision Regulation, Registration and Filing of Medical Devices Measure, and relevant technical guidelines.

Pursuant to the Guiding Principles for AMD Registration Review and the Guiding Principles for SaMD Registration Review, developers must:

  • conduct clinical evaluations – unless explicitly exempt – through clinical trials or literature-based analysis;
  • prepare technical documentation, including algorithm descriptions, software life cycle records, data governance protocols, and quality control for training and testing datasets; and
  • perform risk assessments that demonstrate traceability, reliability and safety throughout the product life cycle, along with defined usage limitations.

Regulators also require disclosure of algorithm structure, training data and performance metrics. To enhance transparency and interpretability, visual tools such as heatmaps are often encouraged. Furthermore, developers must mitigate bias through representative data collection and fairness assessments. For transparency, explainability and bias mitigation, please see 5.2 Transparency and Explainability and 5.3 Bias and Fairness.

Post-market surveillance requirements vary by application types. For hospital-deployed medical AI, according to the Administrative Measures for Adverse Drug Reaction Reporting and Monitoring , there is currently no overarching legal framework specifically addressing AI-related risks. AI-based medical devices are subject to the Medical Devices Supervision Regulation, which mandates that registrants and filing holders conduct adverse event monitoring, re-evaluate marketed devices and implement recall mechanisms where necessary.

Concerning algorithm updates, as outlined in 2.4 Software as a Medical Device (SaMD), developers must:

  • verify and validate the safety and effectiveness of any self-learning or updated models; and
  • apply for change registration when such updates materially affect the product’s intended use or safety profile.

For adaptive or continuous learning algorithms, the Guiding Principles for AMD Registration Review require that such features remain disabled or used solely for research purposes unless separately approved. These models, which update based on real-world data, introduce uncertainty in safety and effectiveness. Developers must validate any changes resulting from self-learning and apply for registration modification before such updates can be deployed in clinical settings.

A centralised adverse event reporting system exists for medical devices for monitoring and reporting adverse events; however, no dedicated monitoring mechanism is in place for AI applications outside the scope of medical device regulation.

Regarding enforcement, administrative penalties have been imposed on the use of unregistered AI-based medical software and on health data breaches. However, no publicly reported cases of regulatory intervention, warnings or product recalls specific to healthcare AI have been identified.

Penalties vary by violation type. Under the Medical Devices Supervision Regulation, use of unregistered Class II/III AI medical devices may trigger confiscation, fines or business suspension. Under the DSL, data protection failures may lead to fines of up to CNY2 million, suspension of operations or licence revocation. Although no significant or systematic enforcement against healthcare AI has been seen, in June 2023, a Beijing software company developing human gene exome data analysis systems was fined for failing to implement sufficient data security measures.

China has not yet established a dedicated legal framework specifically addressing liability allocation between AI-related stakeholders. Liabilities are allocated under the traditional tort law, contract law and administrative regulations regarding generic products, medical devices, patients and healthcare providers.

The Civil Code – Generic or Special Product Liability Provisions

If a healthcare AI system causes personal injury or property damage due to defects, the liability depends on the system type.

  • If the healthcare AI system qualifies as a “generic product” (which is highly likely as PRC law defines “products” mainly by their sales purpose, without requiring physical/tangible form), the patients may claim product liability against the system’s producer/manufacturer (developer) and seller. A seller who compensates patients has the right to seek recourse from producers/manufacturers (developers). A medical institution, as the direct user of the AI system, is generally not liable under product liability unless it caused the defect.
  • If the healthcare AI system is further classified as a “medical device”, then the patient can claim medical damage liability not only against the producer/manufacturer (developer) and the seller, but also directly against the medical institution in the first instance. The institution can then seek recourse from the producer/manufacturer (developer).

Steps to determine whether the AI system is defective in judicial practice typically include the following.

  • Verifying that the AI system’s design complies with mandatory or recommended standards; violation of standards indicates defects.
  • If no standards are violated, examining the algorithmic logic to see if obvious improvements could have prevented the harm. If so, a defect might be recognised (currently, AI diagnosis is not yet a “black box”, meaning that the underlying algorithmic logic can always be examined). Additionally, the producer (developer) failing to provide necessary warnings to the user or patient may constitute a warning defect.

Product Quality Law and Consumer Rights Protection Law

If healthcare AI systems are defined as “products”, their safety, suitability and instructions must comply with relevant standards. Developers and sellers bear civil and administrative liability for non-compliance.

Regulations on the Supervision and Administration of Medical Devices (2024 Revision)

If healthcare AI systems qualify as medical devices, manufacturers are responsible for their quality, safety and effectiveness. Regulatory authorities may order recalls or impose penalties for design defects or software update failures.

Medical institutions and HCPs remain subject to traditional medical malpractice standards. Given that most AI systems in clinical practice function as decision-support tools rather than fully autonomous systems, ultimate responsibility typically rests with the human user. Improper reliance on AI-generated recommendations or inadequate supervision of the system’s application can expose medical treatment providers to legal claims.

In such cases, traditional rules on patient harm and malpractice apply, so the patient must prove four elements: wrongful act, damage, causation and fault, where proving fault of medical personnel is the most challenging.

China has not yet prescribed a unified risk management framework specific to healthcare AI, but medical institutions and developers are subject to some fragmented regulatory and technical requirements.

Medical Institutions

Medical institutions deploying AI systems are generally expected to establish internal oversight mechanisms, including risk identification, adverse event tracking and algorithm performance monitoring. AI is typically treated as an assistive tool, and liability remains with licensed HCPs, reinforcing the need for robust human-in-the-loop safeguards.

Developers

AI-based medical devices shall comply with existing medical device regulations. Local guidance, such as that from the Beijing Medical Products Administration, requires risk documentation covering the full life cycle – risk identification, control measures, residual risk evaluation and traceability – particularly for AI-specific risks like false negatives or model drift.

Risk Assessment and Insurance

There is no mandatory AI-specific insurance, but some policy proposals encourage tailored coverage. In practice, a few insurers and medical institutions have piloted AI-related liability coverage or internal reserve mechanisms to manage emerging risks.

In generic/medical device product liability cases, under general tort law and product liability law the burden of proof lies mainly with the patient rather than the producer/manufacturer (developer), seller or medical institute. There is no reversal of the burden of proof. Consequently, it remains relatively difficult for the patient to hold AI developers or users liable.

In current judicial practice, courts will rely on experts to review AI system algorithms and determine whether there is obvious room for improvement that could have prevented the harm (ie, design defects). To date, no cases have involved “black-box” AI systems that are completely opaque and cannot be reviewed, and no relevant precedents exist.

In medical institute malpractice cases, there are also no specific liability limitations or “safe harbour” provisions available to healthcare users who used AI tools in treatment or diagnosis. The medical institute still needs to independently review and verify the AI system’s conclusion according to the medical standards prevailing at the time.

The ethical framework for healthcare AI consists of various mandatory requirements, recommended guidelines and industrial standards. This ethical framework emphasises the ethical review process to ensure compliance and AI’s human-centred nature.

A key milestone is the Measures for Scientific and Technological Ethics Review (Trial) in 2023. Companies conducting life science, healthcare and AI research in sensitive ethics-related fields must establish an internal ethics review committee to assess legal and ethical compliance. For activities with higher ethical risks, such as highly autonomous AI systems used in safety-related or health-related scenarios, additional expert ethics review is required.

Various recommended guidelines have also been developed as sectoral best practice for developers and health institutions. For example, the Code of Ethics for the New Generation Artificial Intelligence provides ethical codes from R&D, supply, use and management perspectives. Similar ethical principles are also seen in the Industrial Expert Consensus of Deployment of DeepSeek by Medical Institutions.

In practice, ethical considerations are embedded in regulatory processes such as product registration, clinical trials and post-market adverse event monitoring. For AI medical devices, ethics committee approval is required for clinical trials and, where data collection is involved, should be included in the algorithm research report submitted for registration.

For healthcare AI systems that qualify as medical devices, the instructions of the product shall comply with the requirements of transparency and explainability, and shall include basic algorithm information. If an AI system’s security level is severe, additional algorithm research summaries, use restrictions and necessary precaution information shall also be provided, as required in the Guiding Principles for AMD Registration Review.

HCPs are only explicitly required to disclose to patients when healthcare AI is being used in their care in limited situations. For example, before using AI-assisted diagnostic technology for invasive examinations or performing surgery assisted by an AI surgical system, the purpose of the examination/surgery, risks, precautions, potential complications and preventive measures should be communicated by the HCP to the patient and their family members in advance. An informed consent form should also be signed.

For other healthcare AI systems that may process HCPs’ and patients’ personal information, general transparency requirements under the PIPL will apply, and the purpose and means of data processing shall also be made available to the HCPs and patients concerned.

The Gen AI Measures (where applicable) require GenAI service providers to take effective measures to prevent bias during algorithm design, the selection of training data, model generation, optimisation and service provision.

For AI medical devices, the Guiding Principles for AMD Registration Review provide that, to ensure data quality and control data bias during the training of AI systems, the collection of sample data must consider the compliance, sufficiency and diversity of data sources. In the registration materials for AI medical devices, it is also required that the NMPA be provided with algorithm risk management information.

For healthcare-related GenAI services, the Gen AI Measures require service providers to carry out a security assessment, under which training data and outputs that contain discriminative, unreliable or imprecise content that does not meet the security requirements in healthcare information services must be strictly managed and controlled during sampling tests. Content monitoring and a user complaint mechanism shall also be adopted during service provision.

Healthcare AI adheres to a human-centred principle, and automatically generating prescriptions, falsely using an HCP’s name or replacing an HCP in providing diagnosis and treatment services is explicitly prohibited. The final diagnosis and treatment must be determined by a qualified HCP.

Healthcare AI systems can only serve as a tool for users (HCPs or patients) to collect medical referential information, or to assist users (HCPs or patients) with auxiliary decision-making. In addition, highly autonomous AI systems that involve safety or health risks are subject to ethical review and expert re-examination.

For healthcare AI systems that qualify as medical devices, the Guiding Principles for AMD Registration Review provide key compliance requirements for the training data.

  • Data quality – data training process must consider compliance and quality control requirements during data collection, collation, annotation, and construction. Key requirements include:
    1. data collection devices and personnel management;
    2. data desensitisation; and
    3. process management, the establishment of data collection, cleansing and annotation.
  • Fair representation – the training dataset should ensure that the sample distribution is balanced, scientific and rational. Data should be collected as extensively as possible based on the intended use and application scenarios of the product.
  • Documentation – the source of training data and quality control processes shall be traceable, well-documented and structurally managed.

For other generic healthcare-related Gen AI services, the Gen AI Measures will regulate the data training process as follows:

  • Data quality – establish data screening and data quality assessment mechanisms, including managing illegal and harmful content (less than 5%), abandoning data sources with third-party infringement risks, identifying and removing misleading, fake or false content in vertical fields like healthcare, etc, and assessing data quality through annotation.
  • Data representation – ensure diverse sources of data of the same format, use both overseas and local training data, etc.
  • Data documentation – sources of training data shall be traceable and documented, including through the provision of relevant authorisation documents and data collection (from the internet) records that comply with the limitations of robot protocols and technical restrictions.

For bias-mitigation measures, please refer to 5.3 Bias and Fairness.

If healthcare data used for training contains personal information, the PIPL and Measures for the Ethical Review of Life Science and Medical Research Involving Humans requires that data processing activities, including secondary use of healthcare data for AI training and development, shall be disclosed in the privacy policy/informed consent form to patients, and consent shall be obtained.

Although consent for secondary use may be difficult to obtain, current laws do not expressly exempt secondary use of healthcare data from consent requirements or recognise it as compatible use. However, the recommended national standard GB/T 39375-2020 Health and Medical Data Security Guidelines provides a mechanism to request secondary use of healthcare data from medical institutions, albeit that this is limited to non-identifiable data and non-profit purposes.

Current legislation governing data sharing and access remains centred around:

  • the PIPL, if personal information is involved in the training; and
  • the laws governing medical institutions’ responsibility for managing medical records, such as the Regulations for Medical Institutions on Medical Records Management, and the requirement for institutional approval for external data sharing under the Administrative Measures for the Cybersecurity of Medical and Healthcare Institutions.

As required by the PIPL, medical institutions collaborating with enterprises on healthcare AI development must strictly comply with the notification and separate consent requirements before sharing patients’ data. A data sharing agreement must be established to define the scope, purpose and means of data sharing and responsibilities.

Cross-border transfer of personal information and important data for healthcare AI development shall also comply with the CBDT mechanisms required by CAC. If training data involves human genetic resources, the Regulations on the Administration of Human Genetic Resources also require that mandatory filing and data backup be completed before such data can be lawfully transferred outside of China.

The de-identification and anonymisation of health data are primarily governed by the PIPL and the recommended national standard GB/T 37964-2019 Guidelines for De-identifying Personal Information.

As raw health and medical data still constitute personal information, many AI system developers are considering the feasibility of de-identifying and anonymising such data for training purposes, to be exempted from the compliance requirements under the PIPL. While there are no legal standards for health and medical data anonymisation as of yet, AI system developers are adopting multiple de-identification measures, aiming to minimise the risk of re-identification to an acceptable level.

Under the Chinese Patent Law, an invention must be a novel technical solution that solves technical problems using natural laws and leads to technical effects. Purely abstract algorithms or mental methods are not patentable. To form a complete “problem–means–effect” chain, the healthcare AI patent application must clearly show how the technical systems solve specific technical issues. In practice, the Guidelines for Patent Applications for AI-related Inventions, published by the National Intellectual Property Administration (CNIPA), further clarify that, due to the “black-box” nature of AI, the patent specifications must include experimental data and parameter relationships to meet the implementation requirements.

Further, Article 25.1.3 of the Patent Law prohibits patents for diagnosis and treatment methods for illnesses. This limitation poses a significant barrier to healthcare AI patent applications that directly involve medical diagnoses. In practice, AI algorithms that directly diagnose diseases from patient data are typically considered “diagnostic methods” and are excluded from patent protection. To navigate this restriction, companies often reframe their inventions to avoid the word “diagnosis” and emphasise systems and devices rather than diagnostic methods.

A notable case is Tencent’s MiYing AI for glaucoma diagnosis, which passed the regulatory requirements for medical devices and was approved as an innovative medical instrument. This case demonstrates that AI applications integrated with medical equipment and following specific technical and regulatory guidelines can be successfully patented.

Copyright Protection

In China, Article 3(8) of the Copyright Law expressly lists computer software among the categories of copyrightable works. This statutory protection is further elaborated in Article 2 expressly protected under the Copyright Law and Article 3 of the Regulations on the Protection of Computer Software, which specify that software, including computer programmes, source code and accompanying documentation, qualify for copyright protection once the originality requirement has been met. Copyright protection is automatically granted upon creation without the compulsory need for registration, although voluntary registration is commonly used for evidentiary purposes in practice.

For healthcare AI, the underlying algorithmic logic and model structure of training models generally do not meet the threshold for authorship under copyright law and thus lack direct copyright protection. As noted in 7.1 Patent Protection, patent protection for AI algorithms integrated into concrete technical solutions remains uncertain. Accordingly, healthcare AI companies tend to rely more on trade secret protection to safeguard core models, parameters and data preprocessing workflows.

Trade Secret Protection

Pursuant to Article 9(4) of the Anti-Unfair Competition Law, technical information may qualify as a trade secret if it is not publicly known, commercially valuable and subject to reasonable confidentiality measures. Healthcare AI companies often protect model weights, training datasets, algorithm design frameworks and operational processes as trade secrets through NDAs, information compartmentalisation, encrypted storage and access controls. Companies also implement internal policies on employee IP ownership and post-employment non-compete obligations to mitigate the risk of misappropriation or disputes over employee inventions.

Regulatory Disclosure and Confidentiality Mechanisms

For medical device registration, healthcare AI developers shall submit detailed technical documentation to regulatory authorities. Reviewers and external experts are prohibited from disclosing trade secrets obtained during the regulatory process without the applicant’s consent. To mitigate the risk of repeated disclosure, a “master file” system has been introduced, enabling companies to file core algorithmic materials separately and authorise their being referenced across multiple product applications.

Meanwhile, the Guiding Principles for AMD Registration Review mandate transparency by requiring companies to disclose key information (eg, algorithm performance, data provenance and training processes) to ensure product safety. For clinical decision support tools, product manuals shall include performance evaluations and a summary of training data. For black-box models, additional disclosures regarding usage limitations and risk warnings are required. In practice, companies typically meet these transparency requirements through summary disclosures and performance reports while safeguarding detailed algorithms as internal confidential information.

Health AI outputs are often deemed part of medical services and are generally not recognised as independently tradable IP.

  • Diagnostic recommendations, treatment recommendations and other outputs generated by healthcare AI systems are generally regarded as analytical outcomes rather than original expressions and thus are typically not independently protectable by copyright or patent.
  • Healthcare AI outputs are merely the result of using a (potentially patented) tool; the outputs themselves are not novel “technical solutions”, thus failing to meet the patentability criteria.
  • For copyright protection, current law lacks specific provisions regarding AI outputs. As elaborated in 7.2 Copyright and Trade Secrets, Chinese courts have recognised that when the AI outputs created by natural persons reflect original expression, such outputs may obtain copyright protection. In practice, however, healthcare AI outputs normally lack human authorship and sufficient originality of form, and generally do not qualify as “works” under the Copyright Law.

Given the premise that the outputs themselves generally do not involve IP rights, contractual practice is unlikely to specifically allocate such rights. Instead, contracts would primarily treat the outputs as data and assign rights and obligations from the perspective of data usage.

Due to the absence of specific legal provisions, contractual agreements between AI technology providers and healthcare institutions play a decisive role in allocating IP rights and responsibilities. Typically, AI providers retain IP in core technologies, such as algorithms, software and models, while healthcare institutions receive licences to use and deploy the AI outputs as end users. These contracts often address IP as follows:

  • copyrights of AI software and algorithms belong to the provider, and healthcare institutions may not infringe on providers’ technical secrets through means such as reverse engineering and redistribution;
  • healthcare institutions typically assume legal responsibility for the final diagnosis and decision-making, regardless of AI participation; and
  • healthcare institutions may be required to maintain medical liability insurance to cover potential AI-related errors or adverse outcomes.

A variety of commercialisation models are employed in the healthcare AI sector, including technology licensing and collaboration, software-as-a-service (SaaS) subscriptions and direct sales of regulated medical devices.

  • Healthcare AI companies often licence their technologies to major pharmaceutical or medical device firms to facilitate AI adoption in areas such as drug discovery, imaging and diagnostics. Additionally, companies frequently engage in joint innovation projects with hospitals or pharmaceutical companies to facilitate clinical integration of AI applications.
  • AI diagnostic services are also offered via cloud platforms, with hospitals subscribing annually or on a per-use basis. This model enables rapid updates and lowers maintenance costs, but raises issues around cybersecurity, network reliability and reimbursement eligibility.
  • Healthcare AI companies may also obtain Class II or Class III medical device approvals to directly commercialise their AI-assisted diagnostic or therapeutic products to healthcare institutions.

Regulatory and Reimbursement Challenges

Under the current Classified Catalogue of Medical Devices, AI diagnostic software offering only clinical support is regulated as Class II, while software generating autonomous diagnostic outputs requires Class III approval, including additional clinical trials. The longer approval timeline for Class III products often leads companies to frame their tools as assistive. Even after regulatory approval, inclusion in hospital billing systems and insurance coverage remains essential for commercial-scale use, yet no AI healthcare product is currently reimbursed under China’s public healthcare system. Consequently, commercialisation still requires active engagement with healthcare authorities to explore viable reimbursement models.

Academic-Industry Collaboration

To accelerate clinical adoption, many AI companies collaborate with hospitals and universities by forming joint labs or R&D alliances. These partnerships integrate clinical expertise and large-scale medical data, enabling the co-development of AI tools tailored to real-world settings. Recent examples include collaborations between SenseTime and West China Hospital, iFLYTEK and Anhui Provincial Hospital, and Baidu’s AI hospital consortium with Shenzhen South Hospital and other partners. These partnerships support the development of real-world AI applications in imaging, triage and diagnostics, creating models for wider industry adoption.

In China, AI-based clinical decision support systems (CDSS) are regulated under a “general regulation + technical guidance” approach. At the general level, they are subject to the Medical Devices Supervision Regulation and the Registration and Filing of Medical Devices Measures, and are typically classified as Class III medical devices when they involve diagnostic or therapeutic decision-making. Relevant technical guidance also addresses ethical review, clinical governance, safety and hospital system integration.

In practice, developers are expected to disclose training data sources and validate model performance. For example, the Guiding Principles for AMD Registration Review emphasise that AI-based medical devices shall undergo performance verification, including in relation to sensitivity, specificity and consistency with clinical standards. Hospitals are also expected to conduct ethical reviews, ensure system traceability and monitor diagnostic performance.

AI-based diagnostic tools are regulated under the “general regulation + technical guidance” approach. They are typically classified as Class II or III medical devices based on their risk profile. To address domain-specific challenges, regulators and industry bodies have issued supplemental technical guidelines. For example, the Center for Drug Evaluation (CDE) of the NMPA released the Review Guidelines for AI-based Pulmonary Nodule Detection Software via CT Imaging, and the Artificial Intelligence Medical Device Innovation and Cooperation Platform issued the Key Review Points for Deep Learning-Assisted Decision-Making Medical Device Software.

Under these frameworks, developers are generally required to provide clinical validation data, define algorithm performance metrics, and demonstrate proper data governance and human oversight mechanisms.

AI systems used in treatment planning are also regulated under the “general regulation + technical guidance” approach and are typically classified as Class III medical devices if they directly influence therapeutic decisions. Additionally, the Regulatory Rules for Internet-based Diagnosis and Treatment (Trial) explicitly prohibit AI from replacing licensed HCPs in delivering care or issuing prescriptions. In practice, such systems are treated as assistive tools that support but do not substitute for clinical judgment.

Currently, there are no dedicated technical guidance documents for treatment-planning AI. Nonetheless, oversight principles follow existing frameworks for clinical decision support: licensed HCPs shall validate AI outputs, and medical institutions remain responsible for ethical oversight, system traceability and patient safety.

AI applications and devices used for remote patient monitoring and telemedicine are subject to specific regulatory requirements, including but not limited to government filing/registration for medical devices, filing/registration for AIGC products and requirements related to human oversight.

For home or non-clinical use, such settings may encompass mobile medical devices and general wearables for consumers. In addition to privacy, data quality and security requirements, clear instructions and user training materials are essential to ensure proper use of AI systems as required by the Provisions on the Administration of Instructions and Labels of Medical Devices. If used in decentralised clinical trials, the Technical Guidelines for the Implementation of Patient-Centered Clinical Trials (Trial) mandate proper de-identification and protection of patient data, and careful evaluation of digital health technologies (DHTs) based on disease characteristics and patient attributes. Real-time alerts for potential adverse events are also required.

Broader telemedicine laws, like the Regulatory Rules for Internet-based Diagnosis and Treatment (Trial), explicitly restrict the use of AI in clinical decision-making and require AI use to be human-centred. These AI-related considerations are closely linked with broader management requirements for medical records.

AI applications in drug discovery and development are subject to general pharmaceutical laws, such as the Drug Administration Law, the Measures for the Administration of Drug Registration and the Measures for the Administration of Drug Standards. Although there are no AI-specific regulations in this area, validation must align with existing technical standards.

Notably, the CDE issued the Guiding Principles for Model-Informed Drug Development, which require that the data used to establish models be derived from credible sources such as clinical trials, non-clinical studies or bibliographic references. When real-world data is used, developers must also comply with the Guiding Principles for Real-World Data regarding data quality, governance and applicability.

Several general legislative and regulatory initiatives in China are underway that may shape the development and use of healthcare AI.

  • The Medical Device Management Law (public consultation draft) – this draft proposes a unified national framework for medical device data management, promoting data interoperability and resource sharing. It also allows the use of qualified foreign clinical trial data in registration under certain circumstances.
  • The Artificial Intelligence Law (draft, included in the State Council’s 2024 legislative plan) – while China’s proposed AI law draft was removed from the 2025 legislative agenda, the issues of liability and risk management in medical AI remain long-term concerns. It is advisable to keep in view and monitor the development.
  • Model Artificial Intelligence Law 2.0 (expert draft) – the draft, crafted by legal experts, has not officially entered the legislative agenda but may potentially serve as a reference.

At the national level, MIIT and the NMPA have launched a task-based programme targeting AI medical devices. Selected participants receive regulatory and technical support to accelerate AI product development and deployment. In parallel, the National Data Administration and other regulatory bodies have introduced policy to support enterprise data utilisation, with an emphasis on piloting regulatory sandboxes to create a flexible, innovation-friendly environment.

Many local governments have also published their own policies. In Beijing, the AI Data Training Base incorporates a regulatory sandbox that facilitates compliant access to large-scale, high-quality datasets for AI model training. Shanghai and Shenzhen are piloting similar approaches.

Beijing’s Data Foundation System Pilot Zone and AI Data Training Base together provide trusted infrastructure for developing innovative AI data mechanisms. Beijing’s AI + Healthcare Action Plan (2025–27) further proposes a comprehensive support framework to boost healthcare AI development. By 2027, these measures aim to establish an innovative, globally influential healthcare ecosystem covering the entire value chain from R&D to application.

China actively engages in international efforts to harmonise healthcare AI regulation, participating in bodies like the International Medical Device Regulators Forum (IMDRF), World Health Organization (WHO) and International Organization for Standardization (ISO). China contributes to global rulemaking on AI safety, transparency and data governance, and shares agile regulatory approaches through platforms like the Belt and Road Digital Cooperation Network. WHO and IMDRF guidelines have influenced China’s focus on life cycle management, clinical validation and algorithm transparency. ISO standards also inform national and industry-level AI quality and data governance frameworks.

Key challenges include assigning liability for automated AI decision-making, clarifying the fair use of de-identified or copyrighted training data, and ensuring algorithm transparency and fairness. Data quality gaps and poor generalisability further complicate oversight.

Regulators are responding by drafting laws and regulations and exploring dynamic supervision for continuously learning systems, requiring regular performance reports and stricter data governance.

Concerning autonomous AI, future laws may define its legal status and clarify responsibilities among developers, users and institutions. Integration with robotics or virtual reality (VR) also gives rise to cross-sector co-ordination needs.

Healthcare AI developers need to implement “compliance by design” from the outset, embedding regulatory considerations into every stage, forming a comprehensive AI model life cycle document.

As general practice in AI governance, the following measures could be taken into consideration:

  • establishment of multidisciplinary AI ethics committees within organisations, comprising HCPs, legal experts and IT experts;
  • documentation of the entire AI life cycle, with clear version control and audit trails;
  • Monitoring systems tracking technical performance, data usage and clinical outcomes; and
  • compliance that addresses cross-border data flow, cybersecurity and algorithm validation per China’s evolving legal landscape.

As outlined in 9.2 Regulatory Sandboxes and Innovation Programs, regulatory sandboxes can facilitate a more effective balance between fostering innovation and ensuring compliance.

Healthcare AI contracts typically address the following key areas.

  • IP – core algorithms are usually retained by technology providers, and customised models or outputs may be co-owned.
  • Regulatory compliance – providers must ensure their products meet applicable medical device and AI-specific regulations.
  • Data and privacy – contracts define data sources, anonymisation standards and compliance with the PIPL and DSL.
  • Liability allocation – AI is used as a clinical support tool, and liability for medical decisions remains with HCPs.
  • Indemnity and warranties – liability caps and exclusions are common, and warranties may cover performance, updates and technical support.

Healthcare AI developers should prioritise insurance covering algorithm performance and data processing risks. Key coverage includes errors and omissions insurance for system malfunctions, incorrect outputs or performance failure. If their AI product is classified as a medical device, developers should also secure product liability insurance. Healthcare users should evaluate whether their existing medical malpractice insurance or professional liability coverage extends to the use of AI-assisted tools. In addition, organisations adopting healthcare AI must consider cyber liability coverage to protect cybersecurity and patient data security.

Currently, there is no mandatory requirement nor dominant market practice for healthcare AI insurance in China. To address the market gaps, the People’s Insurance Company (Group) of China (PICC) has introduced “Affirmative AI Cover”, providing exclusive protection against infringement risks from content generated by LLMs, including copyright, portrait and reputational infringements.

The risk assessment varies significantly between traditional insurers and those offering affirmative AI coverage:

  • traditional insurers tend to assess AI-related risks in healthcare by relying on established actuarial models and regulatory benchmarks, their focus is on how AI affects clinical workflows and liability exposure rather than the AI’s technical design; and
  • insurers providing Affirmative AI Cover take a more technical and adaptive approach, they conduct risk assessments and measurements based on AI application scenarios in the healthcare industry, upstream and downstream business chains, actual model performance and training data sources to adjust the coverage scope and premium.

In China, medical institutions are required to follow the best practices in the Management Specifications for Artificial Intelligence-Assisted Diagnosis Technology (Trial) and Management Specifications for Artificial Intelligence-Assisted Treatment Technology (Trial) for implementing healthcare AI systems that qualify as medical devices.

Organisation and Governance Structure

Healthcare organisations should involve ethics committees in the AI system deployment process, reviewing clinical applicability, patient safety and data usage compliance. Clinical departments and IT teams should co-ordinate implementation, ensuring that systems align with medical workflows and institutional values.

Training Requirements

HCPs shall meet the requirements outlined in the Management Specification for Artificial Intelligence-Assisted Diagnosis Technology (Trial) and Management Specifications for Artificial Intelligence-Assisted Treatment Technology (Trial), including at least six months of structured training at a certified provincial base, 20+ hours of theoretical study and supervised involvement in over 20 AI-assisted diagnosis cases. Post-training assessment should be conducted to ensure clinical competence in AI system use.

Change Management

Effective integration of AI in healthcare requires adapting clinical workflows and ensuring HCP buy-in. AI vendors could support this through:

  • workflow mapping to align AI with clinical practice;
  • pilot testing to gather feedback and refine usability; and
  • ongoing monitoring to ensure safety, compliance and performance.

Deploying healthcare AI across jurisdictions presents complex legal and regulatory challenges. Key issues include the diverse requirements for data privacy and protection, medical device governance and AI regulatory frameworks, etc.

To navigate the different regulatory requirements, it is advisable to:

  • Implement data localisation and modular deployment by verifying CBDT limits for each major jurisdiction, storing sensitive data on local servers and designing modular AI architectures that process data locally.
  • Create a global compliance framework with local nuances by developing a unified internal standard for AI ethics, quality and compliance while mapping and adapting to local legal differences, eg, benchmarking General Data Protection Regulation (GDPR) for data privacy and protection issues, and then including jurisdiction-specific compliance add-ons.
  • Use tech-enhanced compliance measures by leveraging technologies like differential privacy and federated learning to protect data while enabling cross-border AI scalability and minimising reliance on centralised datasets.
  • Design flexible contracts and liability frameworks by drafting jurisdiction-specific agreements with local partners to clearly define responsibilities, data control, algorithm update protocols and audit rights.
Fangda Partners

24/F, HKRI Centre Two
HKRI Taikoo Hui
288 Shi Men Yi Road
Shanghai 200041
China

+86 21 2208 1166

+86 21 5298 5599

email@fangdalaw.com www.fangdalaw.com
Author Business Card

Trends and Developments


Authors



Fangda Partners was founded in 1993 and is a leading full-service law firm with approximately 800 lawyers across offices in Beijing, Guangzhou, Hong Kong, Nanjing, Shanghai, Shenzhen and Singapore. The firm adopts a one-firm approach, providing integrated legal services across all practice areas and locations. Recognised as the firm of choice for complex and high-stakes legal matters, Fangda advises major domestic and international companies on both transactions and disputes. Fangda’s team includes lawyers qualified in the PRC, Hong Kong, the United States, the United Kingdom, Australia and Singapore, offering strong cross-border capabilities with a distinct China focus. Fangda has extensive experience in AI and life sciences sectors, such as personalised medicine, digital health and biotechnology, including genomics and cancer diagnostics. The firm has assisted several leading pharmaceutical companies in deploying AI tools to support offline marketing and streamline business operations.

Overall Industry and Market Trends

National policies to help develop the Chinese AI sector

China aims to become the world’s major AI innovation centre by 2030. A development plan issued by the State Council outlines the goal of realising an AI core industry exceeding CNY1 trillion (~USD 140.9 billion) in value, with related industries surpassing CNY10 trillion (~USD 1.4 trillion). Since 2016, China has achieved remarkable progress in the field of AI through strategic planning and initiatives. The government has introduced a series of comprehensive blueprints and public policies designed to support AI companies across multiple dimensions, including talent cultivation, start-up incubation, computing power and infrastructure procurement, investment schemes and incentives, taxation, product marketisation and other related aspects. Key policies include the “Internet+ AI” Three-Year Implementation Plan (2016), the New Generation Artificial Intelligence Development Plan (2017), National AI Open Innovation Platforms (2019), the AI Standardization Strategy (2020), AI Pilot Zones (2022) and the “AI+” Initiative (2024).

China’s adoption of AI across sectors is also growing rapidly, with the country’s AI ecosystem thriving under a wave of supportive policies. For instance, major shopping platforms, e-commerce sites and short-video apps are all deploying AI algorithms for content feeds, payments and user services. The government has also been pushing for “smart retail” upgrades, with retailers adopting AI for inventory management, cashier-free shopping and even the generative design of products. In addition, major Chinese tech companies have launched numerous large language models (LLMs). As of June 2026, approximately 900 LLMs have been filed with the Cyberspace Administration of China (CAC). These models cover a wide range of applications, including fintech, medical and healthcare, education, intelligent manufacturing, content creation and enterprise services. The emergence of OpenClaw and Claude Cowork has been accelerating the use of AI and agent in China across different sectors in 2026.

The medical sector: from departmental tools to institutional AI integration

AI is transforming Chinese hospitals from relying on isolated, department-specific tools to operating hospital-wide intelligent ecosystems. The emergence of “agent hospital” models–driven by LLMs–marks a strategic shift toward end-to-end clinical workflow management. In 2025, medical Copilots and Clinical Decision Support Systems (CDSS) decisively transitioned from pilot projects to standard infrastructure. These advanced agents now process real-world patient histories to provide differential diagnoses and medication alerts. Crucially, their deployment is strictly governed by the early-2026 generative AI clinical ethics consensus, which mandates stringent “hallucination rate” thresholds to ensure interpretability and safety in high-risk decisions.

Driven by technological maturity and breakthrough policies, hospital-level AI implementation is scaling rapidly across three key dimensions:

  • Massive clinical deployment – companies are moving beyond single-hospital pilots to a nationwide scale. For instance, Neusoft Medical’s NeuBrainCARE software for brain ischemia triage had been extensively deployed in over 200 hospitals by early 2026.
  • Accelerated regulatory approval – in May 2026, Deshi Bio achieved a global first, securing the first NMPA Class III medical device certificate for an LLM-based chromosome karyotype diagnosis software. Concurrently, Lianying Intelligence obtained a Class III certificate for its nuclear medicine AI and entered the NMPA’s special “green channel” for its complex multi-modal chest CT AI.
  • National commercial integration – in a historic shift in April 2026, the National Healthcare Security Administration officially included 12 AI-assisted diagnostic services in the national medical insurance catalogue. Transitioning from self-funded hospital IT expenses to reimbursable medical services has catalysed explosive institutional procurement.

Taken together, these developments show how AI is helping to optimise China’s limited healthcare resources and to support the development of a sustainable, well-regulated and commercially viable AI healthcare ecosystem.

Local policies: regional governments as regulators and enablers

Across China, local governments are accelerating the development of AI healthcare ecosystems through co-ordinated policies, clinical guidelines and payment innovations. Regional strategies increasingly emphasise ethical governance, standard-setting, and fast-track pathways for AI products.

Beijing: pioneering regulatory pathways and clinical governance

Beijing has shifted from simply providing funding to comprehensive regulatory and governance frameworks. Beijing introduced groundbreaking support for AI healthcare by:

  • establishing NMPA pre-communication channels and “key product service lists” for deep AI integration, particularly for predictive models and organoid trial designs;
  • enforcing strict in-hospital AI governance, mandating that “data remains within the hospital” while ensuring algorithm traceability and security; and
  • issuing the Medical Institution AI Application and Governance Expert Consensus (2026 Edition), providing guidelines on algorithm transparency, liability and data privacy.

Shanghai: scaling AI drug discovery and fast-tracking clinical trials

Shanghai has strategically merged its AI and biopharma industries under the “AI for Science” (AI4S) initiative. Recent municipal policies provide dedicated “computing power vouchers” to subsidise AI-driven drug discovery (AIDD) enterprises in hubs like Zhangjiang Science City. On the regulatory front, Shanghai’s November 2025 reforms established targeted registration guidance for AI medical devices and pioneered the mutual recognition of ethics reviews across multi-centre trials in the Yangtze River Delta, drastically cutting administrative delays.

Guangzhou, Jiangsu and other regional initiatives

Guangzhou’s March 2026 directives linked innovative AI medical devices to medical insurance payments, ensuring commercial viability. Meanwhile, the Jiangsu Free Trade Zone piloted the direct procurement of AI medical imaging services and supported enterprises in establishing national industry standards. Elsewhere, Hainan leverages its free trade port policy for AI-enabled clinical trials using real-world data, while Chengdu and Suzhou continue investing in AI biomedical parks with integrated regulatory support.

These local ecosystems are driving the transformation of AI healthcare from concept to scale, with regions acting as both regulators and incubators.

Foreign investment: from hardware vendors to full-chain AI innovators

Foreign medical technology companies are leveraging China’s evolving regulatory landscape to achieve a strategic transformation, shifting from traditional hardware vendors to full-chain innovators in the AI and medical data ecosystem. Despite global cross-border investment pressures, foreign direct investment  in China’s high-tech sector grew by 20.3% in the first four months of 2026, driven heavily by multinational “AI+” strategies.

A pivotal driver of this shift has been China’s gradual liberalisation of value-added telecom services (VATS), particularly the operation of internet data centres (IDCs).

In early 2025, Siemens Healthineers obtained pilot approval for VATS from the Ministry of Industry and Information Technology (MIIT), becoming the first foreign medical technology company in China to secure such qualification. This landmark approval grants the company full operational rights to establish and manage an IDC under a wholly foreign-owned structure. Through this, Siemens launched its Virtual Medical Imaging Center (VMIC), a platform that enables real-time collaboration between top-tier radiologists and primary-level hospitals nationwide, promoting equitable access to diagnostic expertise.

Beyond telecom and data infrastructure, multinationals are upgrading their Chinese operations into “three-in-one” strategic hubs: global R&D, high-end manufacturing and commercial application. For example, GE HealthCare partnered with Alibaba’s DAMO Academy to embed localised AI imaging algorithms into its high-end equipment, while AstraZeneca announced investments exceeding CNY100 billion by 2030 to build an AI drug R&D centre with Tsinghua University. Similarly, Roche has successfully deployed its “i-WiKi” AI medical laboratory agent across multiple top-tier hospitals to drastically improve report auditing efficiency.

Notably, the CAC’s filing regime has become accessible to the China subsidiaries of foreign enterprises. In late 2025, examples included Mercedes-Benz’s “Mercedes-Benz Virtual Assistant”, which was filed in Beijing, as well as Tesla’s “xBot Customer Service” and Volvo’s “Xiaowo Intelligent Assistant”, both of which were filed in Shanghai. These developments signal a more open and accommodating regulatory posture toward the localised deployment of LLM-based products by foreign companies in the China market.

As foreign companies gain deeper access to China’s AI healthcare infrastructure and its globally unique scale of clinical application scenarios, the domestic market is poised for greater international collaboration. Moving beyond a traditional manufacturing base, China is now an indispensable global hub for cross-border data processing, real-world evidence generation and AI model localisation.

Capital markets and investment landscape: from concept to commercialisation

Following the success of DeepSeek and the “AI Six Little Dragons”, investor interest has rapidly shifted toward sector-specific AI applications. Notably, China’s AI healthcare sector has decisively transitioned from concept-driven valuation to a clinically validated, investment-ready ecosystem. Driven by breakthrough clinical results, the investment landscape between late 2025 and mid-2026 has been characterised by historic exits and strategic industry consolidation. Key trends include the following:

  • HKEX IPO momentum – the Hong Kong Stock Exchange has emerged as the primary exit channel for top-tier Chinese AI pharmaceutical firms. Landmark IPOs include Insilico Medicine (raising HKD 2.277 billion in December 2025) and drug delivery pioneer METiS (raising over HKD 2.1 billion in May 2026), both attracting rare cornerstone backing from giants like Eli Lilly and BlackRock.
  • M&A consolidation – the market is shifting from pure financial backing to strategic industrial integration. Global and domestic device manufacturers are actively acquiring Chinese AI software firms, highlighted by Intuitive Surgical’s USD 200 million full acquisition of domestic developer Renhe Medical in June 2026 and Kangzhong Medical’s controlling stake in Maide Intelligent.
  • Late-stage mega-rounds – mature domestic start-ups are securing massive private funding for Phase III trials and global expansion. Notable raises include Beijing-based Deep Intelligent’s cumulative USD150 million and Anew Labs (a spin-off from Chinese tech giant ByteDance) securing a USD200 million debut round at a unicorn valuation in June 2026.
  • Blockbuster BDs and MNC partnerships – global pharmaceutical giants increasingly rely on Chinese AI platforms for drug discovery, evidenced by staggering out-licensing deals like Sanofi’s potential USD2.56 billion strategic pact with domestic leader HuaShen’s subsidiary Earendil Labs in early 2026.

Investors remain focused on regulatory compliance, particularly regarding algorithmic hallucination controls and data governance. This evolving capital environment underscores China’s broader shift towards a “validation-first” model, demanding demonstrable medical value and commercial returns rather than visionary concepts.

Intellectual Property Protection in Healthcare AI

Market trends

AI is bringing about a profound change in the global healthcare landscape. Innovations such as surgical robots, remote diagnosis, smart diagnostics and wearable devices are accelerating both in development and deployment. Meanwhile, China has emerged as the global leader in healthcare AI IP rights in recent years, especially in patents. According to the 2026 AI Index Report published by Stanford HAI, in both 2023 and 2024, Chinese entities accounted for more than 74.2% of global healthcare AI patents, up from 60% in the previous year, and remained ahead of all other countries.

The development of China’s healthcare AI field is driven by the co-operation between enterprises and academic institutions. As mentioned in the IP Press’s 2025 Healthcare Industry Patent Analysis White Paper, Ping An Health remains the global leading patent applicant, with 5,704 healthcare AI patents and maintains a leading position across AI, blockchain and big data technologies. Tencent comes next, with 1,901 patents nationwide concentrated in natural language processing, knowledge graphs, and large model applications, ranking among the global top five in healthcare AI patents. Academic institutions are also essential contributors, particularly in driving innovation in foundational algorithms, such as Zhejiang University standing as the sole academic institution among the global top ten healthcare patent applicants, with its patented technologies in medical image segmentation and multimodal fusion being actively transferred and commercialized by multiple enterprises.

Unfolding critical issues

Healthcare AI innovations in China are eligible for patent protection if they meet the technical criteria set forth by the Patent Law, and applicants should provide detailed descriptions of technical features, highlights of concrete technical effects and substantial data support to meet such criteria. In November 2025, the China National Intellectual Property Administration (CNIPA) further refined its Patent Examination Guidelines for AI-related inventions, introducing dedicated provisions on AI and big data, and providing more detailed rules on algorithmic features, model training, sufficiency of disclosure and inventor attribution. However, challenges persist, particularly with respect to satisfying the increasingly stringent requirements on technical disclosure, inventive step, and patent eligibility for AI-related inventions, as well as conflicts between the transparency of AI models and confidentiality requirements. Meanwhile, the underlying algorithmic logic and structure of training models generally do not meet the threshold for authorship under copyright law and thus lack direct copyright protection. As a result, healthcare AI companies tend to rely more on trade secret protection to safeguard core models, parameters and data preprocessing workflows.

Concerning copyright protection and allocation of liability related to AI-generated content, a series of landmark Chinese court decisions in 2025 and 2026 reflect the rapid evolution, albeit still fact-specific, judicial approach to AIGC governance. Recent decisions have expanded the focus of judicial review beyond the copyrightability of AI-generated works to encompass the protectability of AI prompts and the scope of duties owed by AI service providers and users, and the availability of protection under unfair competition regimes.

  • Regarding whether AI prompts qualify for copyright protection, the Shanghai Huangpu District Court held that prompts are merely functional instructions reflecting abstract creative ideas rather than protectable expression, and therefore do not constitute copyrightable works.
  • As for AI-generated voices, the Chongqing Yuzhong District Court recognized that although the voice timbre of a virtual character does not qualify as a copyrightable work, it may nevertheless be protected under the Anti-Unfair Competition Law where it functions as a distinctive identifier with market recognition
  • With respect to platform liability for infringing AI-generated content, the Shanghai Jinshan District Court departed from the approach adopted in the earlier Guangzhou Internet Court decision. Rather than finding the platform liable for copyright infringement, the court concluded that no contributory infringement had been established, emphasising that the AI platform had exercised the reasonable duty of care and had taken appropriate measures in response to infringing content.
  • Recent AI hallucination cases have further delineated the respective responsibilities of AI service providers and users. The Hangzhou Internet Court held the AI service provider not liable, finding that it had fulfilled its duty of care through appropriate content safeguards, prominent disclosures regarding the limitations of AI-generated outputs, and reasonable technical measures to improve output reliability. Separately, the Hangzhou Binjiang Court emphasized that users of AI-generated content bear independent obligations to reasonably verify factual content before publication and to provide clear AI-generated content labelling before dissemination.

Separately, according to a January 2026 report, Chinese law enforcement authorities investigated and solved the nation’s first criminal case involving trade secret infringement in the field of TCM-related AI. The case concerned Shenzhen WenZhi TCM Health Technology Co., Ltd. (“WenZhi”), which had invested over CNY30 million in developing its AI-assisted diagnostic system “TCM Brain.” The former head of its R&D team allegedly misappropriated WenZhi’s source codes and core technical information, launched a substantially similar low-priced product within three months, resulting in losses of approximately CNY2.72 million. Following a criminal investigation initiated by the Shenzhen Public Security Organs in April 2025, the suspect was placed under compulsory criminal measures in December 2025. The case is regarded as a significant enforcement example highlighting intensified protection of healthcare AI technologies as trade secrets in China.

Regulatory Developments and Trends

Existing regulatory landscape

China currently lacks a unified legal framework specifically tailored to healthcare AI. Any AI-based medical software meeting the statutory definition of a “medical device” is regulated as such. The sectoral regulatory landscape is composed of existing regulatory rules, such as the Measures for the Administration of Data Security and Personal Information Protection by Medical and Healthcare Institutions (Trial), Regulation on the Supervision and Administration of Medical Devices (Revised in 2024) and the Administrative Measures on the Registration and Record-filing of Medical Devices. Accordingly, AI medical software qualifying as a medical device will be categorised under the Guiding Principles for the Classification and Definition of AI-based Medical Software Products as Class II/III medical devices, depending on their algorithm maturity level and specific functionalities. This sectoral regulatory framework is further supplemented by specialised technical guidelines, such as the Guiding Principles for Registration Review of AI-based Medical Devices and the Key Review Points for Deep Learning-Assisted Decision-Making Medical Device Software.

Likewise, regulatory rules universally applicable to generative AI (GenAI) and algorithms, as well as cybersecurity and data protection, will apply for corresponding issues, including the Interim Measures for the Administration of Generative Artificial Intelligence Services (the “Gen AI Measures”), the Provisions on the Administration of Algorithm-generated Recommendations for Internet Information Services (the “Algorithm Provisions”), the Cybersecurity Law, the Data Security Law and the Personal Information Protection Law. Aside from general data and privacy protection requirements, the following compliance action items are especially worthy of attention from companies operating healthcare AI.

  • LLM and algorithm filing – any GenAI service that interacts with the public and has the potential to influence public opinion or mobilise social action must undergo a formal security assessment and register with the provincial CAC under the Gen AI Measures (referred to as “LLM filing”). Additionally, these services must complete the algorithm filing procedures under the Algorithm Provisions (“algorithm filing”). For GenAI services based on third-party LLMs that have already been filed, via an application programming interface (API) or other technical means, a simplified registration process at the provincial CAC is required instead of the full LLM filing.
  • Training data and algorithm security – if a healthcare AI developer engages in pre-training or fine-tuning activities rather than directly invoking third-party LLM APIs, they must:
    1. use data from legitimate sources;
    2. avoid the use of personal information, or if necessary, ensure that appropriate consent or other lawful bases are satisfied; and
    3. enhance the quality of training data by improving its authenticity, accuracy, objectivity and diversity.
  • Content moderation – GenAI services are prohibited from producing any content that violates laws or regulations, such as material that incites subversion of state power, undermines the socialist system or endangers national security. Providers of GenAI services are primarily responsible for content safety. They must immediately cease generation and dissemination, remove any offending content and retrain their models upon detecting of any prohibited material.
  • Cybersecurity multilevel protection scheme (MLPS) – medical institutions and companies deploying and operating on-premises AI diagnostic systems must conduct pre-deployment security risk assessments and fulfil relevant MLPS obligations. This includes system grading, filing with local public security organs and conducting regular security assessments. Under China’s updated MLPS 3.0 (2025), operators of healthcare systems are required to reassess the grading of their systems based on new standards and complete data inventories for systems above level 2. Medical institutions must implement at least Level 3 requirements when storing or processing important data.

Echoing the regulatory legislation, there is no specific regulatory authority in China responsible for the supervision of healthcare AI. Several regulatory authorities implement regulatory responsibilities within the scope of their duties, as follows.

  • Medical-sector regulators, where the National Medical Products Administration (NMPA) oversees medical device registration, technical reviews and post-market surveillance for healthcare AI products, while the National Health Commission regulates medical institutions and their use of AI products and/or services. Specifically, if a healthcare AI device involves the collection, use and transfer of human genetic resource data, the National Health Commission will intervene.
  • Technology regulators, where CAC and MIIT are responsible for cybersecurity, AI-related regulations and data compliance.
  • Ancillary regulators, where the State Administration for Market Regulation monitors advertising compliance, while the National Development and Reform Commission and the Ministry of Commerce oversee foreign investment.

Upcoming legislation and enforcement trends

Several critical legislative and regulatory initiatives moving forward in China are likely to define how healthcare AI is developed and deployed.

  • The Medical Device Management Law (consultation draft) – the draft creates a single national system for managing medical-device data, pushing for interoperability and shared resources. By opening the door to high-quality, standardised datasets, and allowing qualified foreign clinical trial data to be used for registration in defined cases, it is expected to expedite healthcare AI innovation.
  • The Artificial Intelligence Law (draft listed in the State Council’s 2024 legislative plan) – although the comprehensive AI bill has been dropped from the 2025 agenda, questions of liability and risk management for medical AI remain on the table. Stakeholders should therefore keep tracking any future version of the AI Law; as more scenario-specific rules emerge, the overall compliance load will not lighten.
  • The Model Artificial Intelligence Law 2.0 (expert draft) – drafted by academics, this non-binding text has yet to reach the formal legislative pipeline but may still inform later policy. Its key elements include strong backing for open-source AI through community building, explicit liability rules and new IP provisions that tackle the use of training data and personal information while clarifying protection for AI-generated output.

MIIT and the NMPA run a fast-track programme that gives selected firms early regulatory and technical guidance to shorten the path to market for AI medical devices, while the National Data Administration promotes “regulatory sandboxes” so companies can lawfully tap clinical data. Locally, Beijing has launched the country’s first “AI data training base and pilot zone”, integrating curated datasets and compliance tools into a one-stop sandbox for LLM developers. Similar pilots are under way in Shanghai and Shenzhen. Beijing’s 2025–27 AI+ Healthcare Action Plan adds expedited reviews, priority approvals and extra funding, aiming to create a globally influential, end-to-end innovation ecosystem by 2027.

Administrative penalties have been levied for the use of unregistered AI-based medical software and for health data breaches, while there have been no publicly reported cases of regulatory intervention, warnings or product recalls specifically targeting healthcare AI. Nevertheless, CAC has increased its enforcement of AI regulations since 2025. For example, in April 2026, CAC launched a four-month action plan titled “Clear and Bright Crackdown on Rectifying Disorder in AI Applications”, which is being implemented in two phases. This law enforcement campaign suggests that broad-sweeping and proactive enforcement actions and penalties are anticipated in the coming months, where:

  • the first phase targets seven key issues, including failure to complete LLM filing or registration, insufficient safety review and filtering capabilities, poor management of training materials, AI data poisoning, inadequate implementation of AI-generated content labelling requirements, misuse of AI technologies for unlawful activities, and weak safety management of open-source models; and
  • the second phase focuses on seven major issues, including AI-generated “digital garbage”, false or misleading information, impersonation of others, violent or vulgar content, infringement of minors’ rights, AI-driven online manipulation activities, and illegal or non-compliant AI products and applications.
Fangda Partners

24/F, HKRI Centre Two
HKRI Taikoo Hui
288 Shi Men Yi Road
Shanghai 200041
China

+86 21 2208 1166

+86 21 5298 5599

email@fangdalaw.com www.fangdalaw.com
Author Business Card

Law and Practice

Authors



Fangda Partners was founded in 1993 and is a leading full-service law firm with approximately 800 lawyers across offices in Beijing, Guangzhou, Hong Kong, Nanjing, Shanghai, Shenzhen and Singapore. The firm adopts a one-firm approach, providing integrated legal services across all practice areas and locations. Recognised as the firm of choice for complex and high-stakes legal matters, Fangda advises major domestic and international companies on both transactions and disputes. Fangda’s team includes lawyers qualified in the PRC, Hong Kong, the United States, the United Kingdom, Australia and Singapore, offering strong cross-border capabilities with a distinct China focus. Fangda has extensive experience in the AI and life sciences sectors, such as personalised medicine, digital health and biotechnology, including genomics and cancer diagnostics. The firm has assisted several leading pharmaceutical companies in deploying AI tools to support offline marketing and streamline business operations.

Trends and Developments

Authors



Fangda Partners was founded in 1993 and is a leading full-service law firm with approximately 800 lawyers across offices in Beijing, Guangzhou, Hong Kong, Nanjing, Shanghai, Shenzhen and Singapore. The firm adopts a one-firm approach, providing integrated legal services across all practice areas and locations. Recognised as the firm of choice for complex and high-stakes legal matters, Fangda advises major domestic and international companies on both transactions and disputes. Fangda’s team includes lawyers qualified in the PRC, Hong Kong, the United States, the United Kingdom, Australia and Singapore, offering strong cross-border capabilities with a distinct China focus. Fangda has extensive experience in AI and life sciences sectors, such as personalised medicine, digital health and biotechnology, including genomics and cancer diagnostics. The firm has assisted several leading pharmaceutical companies in deploying AI tools to support offline marketing and streamline business operations.

Compare law and practice by selecting locations and topic(s)

{{searchBoxHeader}}

Select Topic(s)

loading ...
{{topic.title}}

Please select at least one chapter and one topic to use the compare functionality.