GB/T 45654-2025: Basic security requirements for generative AI services (voluntary; implemented 2025-11-01)
Training-corpus source and content screening, model-safety requirements and the evaluation methods that underpin the security assessment
AIGE-OBL-CN-GBT45654. Drawn from chapter 08.
Text alternative
- Clause: GB/T 45654, GB/T 45654-2025.
- Duty holder: Not stated.
- Applies from: 2025-11-01, Voluntary.
- Artefact: Corpus-screening record.
- Layers: Layer 03, Layer 05.
- Evidence record: Evidence record v1.
- Record schema: Evidence record.
- The same topic in 21 other frameworks; the crosswalk section below links each clause.
- Id
AIGE-OBL-CN-GBT45654- Instrument
- GB/T 45654-2025 Basic security requirements for generative AI services standard
- Clause
- GB/T 45654-2025
- Applies from
- Voluntary · Recommended (voluntary) national standard; implemented 2025-11-01
The artefact that evidences it
Corpus-screening record; eval question banks; security-assessment report.
Patterns that build it
No pattern in the catalogue names this clause on its "Maps to" line yet; the artefact above is the engineering answer.
The same topic in other frameworks
From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.
Data governance
- EU AI Act Art. 10 Data and data governance (core)
- ISO 42001 A.7 Data for AI systems (core)
- TC260 Framework 3.0 TC260 2.1.3 Data safety risks (core)
- China GenAI Measures GenAI Art. 7 Training-data lawful sourcing (core)
- China GenAI Measures GenAI Art. 8 Data-annotation standards (core)
- China GenAI Measures GenAI Art. 11 Protection of user input and records (core)
- China Deep Synthesis DeepSyn Art. 14 Training-data management (core)
- EU AI Act Art. 10(2)(f)–(g) Examination for possible biases; measures to detect, prevent and mitigate them (core)
- GDPR Art. 5(1)(c) Data minimisation (core)
- GDPR Art. 25 Data protection by design and by default (core)
- ISO 42001 A.7.3 Acquisition of data (core) (clause not verified)
- CSA AICM DSP-20 Data Provenance and Transparency (core)
- UK ATRS ATRS 2.4.3 Development data specification (core)
- Singapore GenAI GenAI 2 Data (core)
- GAO AI Accountability 2.1 Sources: document sources and origins of data used to develop the models (core)
- GAO AI Accountability 2.2 Reliability: assess reliability of data used to develop the models (core)
- EU AI Act Art. 4a Special-category data for bias detection
- ISO 42001 A.4 Resources for AI systems
- NIST AI RMF MAP 2 MAP 2: Categorization of the AI system is performed
- NIST AI RMF MEASURE 2.10 MEASURE 2.10: Privacy risk of the AI system is examined and documented
- NIST AI RMF MEASURE 2.11 MEASURE 2.11: Fairness and bias are evaluated and results are documented
- TC260 Framework 3.0 TC260 5.1 Model R&D safety guidelines
- EU AI Act Art. 53 Obligations for providers of general-purpose AI models
- EU AI Act Art. 53(1)(c) Copyright policy, including rights reservations
- EU AI Act Art. 5(1)(e) Prohibited: untargeted scraping of facial images
- GPAI Code Copyright 1.1–1.5 Commitment 1: Copyright policy (Measures 1.1 to 1.5)
- GDPR Art. 9 Processing of special categories of personal data
- CSA AICM DSP-21 Data Poisoning Prevention & Detection
- OWASP LLM LLM05:2026 Data and Model Poisoning
- GAO AI Accountability 2.4 Variable selection: assess data variables used in the AI component models
- GAO AI Accountability 2.5 Enhancement: assess the use of synthetic, imputed, and/or augmented data
Documentation and transparency
- EU AI Act Art. 11 Technical documentation (core)
- EU AI Act Art. 13 Transparency and provision of information to deployers (core)
- EU AI Act Art. 53 Obligations for providers of general-purpose AI models (core)
- ISO 42001 7.5 Documented information (core)
- ISO 42001 A.6 AI system life cycle (core)
- ISO 42001 A.8 Information for interested parties (core)
- China AI Labelling Label Art. 4 Explicit labels for generated content (core)
- China AI Labelling Label Art. 5 Implicit (metadata) labels (core)
- China GenAI Measures GenAI Art. 12 Labelling of generated content (core)
- China Deep Synthesis DeepSyn Art. 16 Implicit technical labels (core)
- China Deep Synthesis DeepSyn Art. 17 Conspicuous labels for confusable content (core)
- GPAI Code Transparency 1.1 Drawing up and keeping up-to-date model documentation (core)
- GDPR Arts. 13–14 Information to be provided to the data subject (core)
- CSA AICM MDS-03 Model Documentation (core)
- Korea AI Act Art. 31 Transparency: prior notice, output labelling, realistic synthetic content (core)
- UK ATRS ATRS Tier 1 Summary information (core)
- Singapore GenAI GenAI 3 Trusted Development and Deployment (core)
- CoE Convention CoE Art. 14(2) Documentation sufficient to contest decisions; complaint to authorities (core)
- OECD AI Principles OECD 1.3 Transparency and explainability (core)
- G7 Code G7 Action 3 Publicly report capabilities, limitations and domains of use (core)
- GAO AI Accountability 1.9 Transparency: enable external stakeholders to access information on the design, operation, and limitations of the AI system (core)
- GAO AI Accountability 3.5 Documentation: document the methods for assessment, performance metrics, and outcomes of the AI system (core)
- EU AI Act Art. 50 Transparency obligations for providers and deployers of certain AI systems
- NIST AI RMF MAP 1 MAP 1: Context is established and understood
- NIST AI RMF MEASURE 2.8 MEASURE 2.8: Risks associated with transparency and accountability are examined and documented
- China GenAI Measures GenAI Art. 19 Disclosure to regulators
- China Algo. Rec. AlgoRec Art. 16 Notice that recommendation is used
- EU AI Act Art. 86 Right to explanation of individual decision-making
- EU AI Act Art. 18 Documentation keeping
- EU AI Act Art. 43 Conformity assessment
- EU AI Act Art. 53(1)(d) Public summary of the content used for training
- EU AI Act Art. 50(2), 50(4) Machine-readable marking of synthetic content; disclosure of deep fakes
- GPAI Code Transparency 1.2 Providing relevant information
- GDPR Art. 30 Records of processing activities
- NIST AI RMF MAP 1.6 MAP 1.6: System requirements are elicited from and understood by relevant AI actors. Design decisions take socio-technical implications into account to address AI risks
- NIST AI RMF MEASURE 2.9 MEASURE 2.9: The AI model is explained, validated, and documented, and AI system output is interpreted within its context as identified in the MAP function to inform responsible use and governance
- CSA AICM MDS-04 Model Documentation Requirements
- Korea AI Act Art. 34(1)(2) Explanation plan: result, main criteria, training-data overview
- UK ATRS ATRS 2.2 Description and rationale
- CoE Convention CoE Art. 15(2) Notification of interaction with an AI system
- GAO AI Accountability 1.7 Specifications: establish and document technical specifications
Robustness, security and evaluations
- EU AI Act Art. 15 Accuracy, robustness and cybersecurity (core)
- EU AI Act Art. 55 Obligations for providers of general-purpose AI models with systemic risk (core)
- ISO 42001 A.6 AI system life cycle (core)
- NIST AI RMF MEASURE 2 MEASURE 2: AI systems are evaluated for trustworthy characteristics (core)
- TC260 Framework 3.0 TC260 3 Technological countermeasures (core)
- TC260 Framework 3.0 TC260 App. 2 II.6 Sandbox validation and red teaming (core)
- China Deep Synthesis DeepSyn Art. 15 Technology management and algorithm verification (core)
- China Deep Synthesis DeepSyn Art. 20 Security assessment of new products (core)
- GPAI Code Safety 3.2 Measure 3.2: Model evaluations (core)
- NIST AI RMF MEASURE 2.7 MEASURE 2.7: AI system security and resilience as identified in the MAP function are evaluated and documented (core)
- CSA AICM MDS-06 Adversarial Attack Analysis (core)
- CSA AICM MDS-07 Robustness against Adversarial Attack / Model Hardening (core)
- Singapore GenAI GenAI 5 Testing and Assurance (core)
- Singapore GenAI GenAI 6 Security (core)
- Singapore Agentic Agentic 2.3.2 Before deploying, test agents (core)
- CoE Convention CoE Art. 16(2)(g) Testing before first use and when significantly modified (core)
- OECD AI Principles OECD 1.4 Robustness, security and safety (core)
- G7 Code G7 Action 1 Identify, evaluate and mitigate risks across the lifecycle, including testing (core)
- GAO AI Accountability 3.7 Assessment: assess performance against defined metrics to ensure the AI system functions as intended and is sufficiently robust (core)
- EU AI Act Art. 60 Testing of high-risk AI systems in real-world conditions outside AI regulatory sandboxes
- ISO 42001 9.1 Monitoring, measurement, analysis and evaluation
- TC260 Framework 3.0 TC260 5.3.14 Resilience
- China GenAI Measures GenAI Art. 17 Security assessment
- EU AI Act Art. 15(3) Declared accuracy levels and metrics
- EU AI Act Art. 9 Risk management system
- EU AI Act Art. 42(3) Presumption of conformity for cybersecurity (Cyber Resilience Act)
- GPAI Code Safety C6 Commitment 6: Security mitigations
- GDPR Art. 32 Security of processing
- NIST AI RMF MEASURE 2.1 MEASURE 2.1: Test sets, metrics, and details about the tools used during TEVV are documented
- NIST AI RMF MEASURE 1 MEASURE 1: Appropriate methods and metrics are identified and applied
- CSA AICM AIS-05 Application Security Testing
- OWASP LLM LLM01:2026 Prompt Injection
- OWASP Agentic ASI05 Unexpected Code Execution (RCE)
- Korea AI Act Art. 32(1) Safety duties for AI above the compute threshold
- GAO AI Accountability 3.2 Metrics: define performance metrics that are precise, consistent, and reproducible
Source
Chapter 08, section China, checked against its sources on the review date above.
Machine-readable
- This obligation:
/api/v1/obligations/aige-obl-cn-gbt45654.json - The register:
/api/v1/obligations.json· CSV - Schema and stability promise: open data and API
Cite this obligation
García Aibar, J. (2026). GB/T 45654-2025: Basic security requirements for generative AI services (voluntary; implemented 2025-11-01) (AIGE-OBL-CN-GBT45654). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-cn-gbt45654. CC BY 4.0
BibTeX
@misc{aige2026obligation,
author = {Jorge García Aibar},
title = {{GB/T 45654-2025: Basic security requirements for generative AI services (voluntary; implemented 2025-11-01) (AIGE-OBL-CN-GBT45654)}},
howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
year = {2026},
version = {0.5.0},
doi = {10.5281/zenodo.22956197},
url = {https://aigovernanceengineer.com/obligations/aige-obl-cn-gbt45654},
note = {Version 0.5.0}
}