China’s Cyberspace Administration released a draft anti-cyberbullying law last week, sixty articles designed to prevent, deter, and penalize online harassment. It is open for public comment until August 28. On its face, this is unremarkable — most democracies are still trying to pass something comparable, and the harm cyberbullying causes to real people is well-documented and serious. But the specific architecture of this draft is worth reading carefully, because it reveals something that governance debates elsewhere tend to blur: the same technical infrastructure that protects individuals from harassment can, without any structural modification, protect states from criticism. The ambiguity is not incidental. It is the point.
The draft defines cyberbullying to include not only insults, threats, and the disclosure of personal information, but also “divisive content” and “hate speech” — categories whose legal edges, in the Chinese context, have historically been drawn to include political dissent, labor organizing, and ethnic minority expression. It also prohibits third parties from providing “technical support” to those engaged in cyberbullying, which means internet infrastructure providers, payment processors, and data hosts become enforcement instruments. Platforms are required to implement monitoring, early warning, and tiered incident classification systems. The tiering is based on “type of offense, number of participants, scope of impact, and severity of harm.” Scale and coordination are treated as aggravating factors. A viral campaign against a private individual and a viral protest movement are, in this framework, structurally identical.
“The draft defines cyberbullying as concentrated or sustained online acts that infringe on lawful rights, including reputation, honor, privacy, portrait rights, and personal information. Such acts include the mass distribution of insults, rumors, hate speech, divisive content, threats, and discriminatory remarks.”
This is where AI enters the picture, and why this is not simply a story about Chinese internet law. The monitoring, early warning, and classification systems the draft mandates are not feasible at scale without automated content analysis. Any serious enforcement regime across a platform the size of WeChat or Weibo requires machine learning systems making real-time decisions about what constitutes harassment, what constitutes coordinated behavior, and what crosses the threshold for intervention. Those systems have to be trained on something — and what they are trained on reflects choices about where to draw lines. Who draws the lines, under what legal authority, with what appeal mechanisms, is not a technical question. It is a governance question that the technical layer answers in advance.
Why It Matters
The Council of Europe, in its ongoing work on AI governance, frames the central risk plainly: AI “comes with serious potential risks to the enjoyment of human rights, the functioning of democracy, and the observance of the rule of law.” That framing is usually applied to authoritarian contexts as a cautionary tale for liberal democracies. But the more instructive reading is that the same risks exist on a spectrum, and liberal democracies are not exempt from the structural temptation. Anti-harassment law, content moderation policy, and national security law all require institutions to make decisions about what speech is harmful. When those decisions are automated, they become faster, cheaper, more consistent, and far harder to challenge. The appealability problem is not unique to China.
What changes when AI systems enforce speech law is not just scale — it is the redistribution of discretion. A human moderator making a judgment call is a locus of accountability, however imperfect. An automated system classifying “divisive content” at a billion decisions a day is a policy instrument that has been converted into infrastructure. You can critique a policy. You can lobby against a law. It is considerably harder to contest a weight in a neural network, especially when the model architecture is proprietary, the training data is undisclosed, and the appeal process routes back through the same platform that made the original determination.
The Partnership on AI — whose membership, according to Reuters, includes the ACLU, the Ford Foundation, and academic institutions — exists in part to surface these tensions in Western AI governance contexts. The gap between that body’s deliberative process and the enforcement architecture being built into the Chinese draft is real and meaningful. But the underlying structural question is shared: when automated systems make consequential decisions about speech and association, who set the parameters, and do the people subject to those decisions have any meaningful power to contest them?
Author’s Position
Cyberbullying causes genuine harm. Legislation addressing it is not inherently suspect. But a law that requires AI-enabled surveillance infrastructure, defines harm expansively to include coordination and divisive content, and deputizes payment processors and data hosts as enforcement partners is not primarily a protection for harassed individuals. It is a control architecture with harassment protection as the publicly legible use case.
The pattern is familiar from trade policy: gains are distributed broadly and abstractly, costs are concentrated and specific. The teenager being harassed is real. So is the labor organizer whose campaign gets classified as coordinated harassment. The law protects the first and immobilizes the second with identical machinery. The people who absorb that cost are the same people who have the least bargaining power to contest the terms — no seat at the drafting table, a thirty-day comment window, and an appeal process that runs through the state agency that wrote the law.
That is not a governance framework. It is a capture. And the AI systems that make it scalable are not a detail of implementation. They are the mechanism by which a policy choice becomes a structural condition.
References
- Artificial Intelligence – A cross-cutting priority
- China proposes draft anti-cyberbullying law for public consultation
Perspectives
The consensus treating this as a bullying law is doing exactly what the law needs it to do. China didn’t build an AI-enabled, infrastructure-deputizing, harm-definition-expanding surveillance architecture because some kids were mean online — that’s the alibi, not the answer. The people the law will most reliably protect are the ones who already have the least to fear from the state; the people it will most reliably silence are the ones using collective online speech to become visible at all. Everyone is nodding along at the individual protection framing because nobody wants to say the quiet part: the most effective censorship systems always arrive wearing someone else’s emergency.
The question is never whether the law protects anyone — it’s who controls the infrastructure the law runs on, and what toll they collect for that protection. China’s anti-cyberbullying framework deputizes platform operators as enforcement nodes, which means the rails for speech are now also the rails for surveillance, and the price of using them is your behavioral data fed into a classification system you have no access to and no appeal against. The expansive definitions of “harm” are not a bug in the drafting — they are the architecture; vague enough to catch genuine abuse, flexible enough to catch political inconvenience, and the distinction between the two will be made by the same apparatus that benefits from suppressing the latter. Every person the law actually protects from a harasser is also a person who has just agreed, without knowing it, to let the infrastructure provider decide what counts as harassment next time — and next time might be a labor organizer, a grieving parent asking inconvenient questions, or anyone whose dissent looks enough like “harm” to a system that was never designed to tell the difference.
The alignment problem China’s draft anti-cyberbullying law fails to solve is the fundamental one: you cannot build a harm-detection system that distinguishes “targeted harassment” from “coordinated dissent” without first deciding who gets to make that classification, and every architectural choice in this law answers that question in favor of the state. The definitional expansion — harm as psychological distress, harm as reputational damage, harm as content that “incites public sentiment” — is not ambiguity born of drafting difficulty; it is a specification, and the system is behaving as specified. Infrastructure providers, deputized as compliance nodes and liable for content they fail to suppress, have no incentive to err toward speech and every incentive to err toward removal. The protection offered to individuals is real in the narrow case and structurally irrelevant at scale: the same monitoring apparatus that catches a genuine harasser catches a labor organizer, a petition circulator, a person documenting official misconduct, and the system has no mechanism — no independent review body, no contestation process, no external audit — that would allow it to treat those cases differently.
The spec says “anti-bullying.” The architecture says “content graph with enforcement hooks baked into every infrastructure layer.” When you deputize ISPs and platform operators as compliance nodes, give them broad liability exposure for user-generated harm, and define harm expansively enough to include content that “damages social order,” you haven’t built a protection system with surveillance as a side effect — you’ve built a surveillance system with protection as a justification layer. The individuals this law will fail hardest are exactly the ones who could document that failure: the activists, the labor organizers, the people whose “bullying” complaints get quietly reclassified as the thing being complained about — and they’ll fail silently, because the same infrastructure that was supposed to surface their harm is the infrastructure logging their attempt to report it.





