China artificial intelligence and data governance: AI law, generative AI, algorithm and cross-border data rulesMonitor the PRC artificial intelligence and data regime for the AI, data and digital governance industry, jurisdiction China.免费开启
What legal basis does the CAC cite for the Palo Alto Networks review?
The Cybersecurity Review Office invoked the National Security Law, the Cybersecurity Law and the Cybersecurity Review Measures. The review targets products sold in China by Palo Alto Networks on grounds of safeguarding critical information infrastructure and national security.
What can a cybersecurity review conclude under the Cybersecurity Review Measures?
The office may clear the product with conditions, order the buyer to adjust procurement, or determine that the product or supplier may not be purchased by critical information infrastructure operators. It can also request source code, data-handling and supply-chain information during the review.
How is this different from the January 2026 guidance on foreign cybersecurity vendors?
The January 2026 steer was informal and procurement-directed, covering US and Israeli vendors as a category. The August 6, 2026 announcement is the first named, statute-based review of Palo Alto Networks under the Cybersecurity Review Measures, with potential procurement-restriction outcomes.
Does the amended Cybersecurity Law change the consequences of failing a review?
Yes. The Cybersecurity Law amendment adopted on October 28, 2025 and in force since January 1, 2026 raised administrative penalty ceilings for non-compliant network operators and product suppliers and strengthened personal liability for responsible managers.