China has broadened its trade secret protection framework to explicitly include data and algorithms, strengthening enforcement mechanisms as it seeks to prevent technology leaks during escalating US-China competition.
China's regulatory authorities expanded the definition of trade secrets to encompass data sets and artificial intelligence algorithms, closing gaps in existing intellectual property protections.
The move addresses vulnerabilities in current law, which primarily focused on traditional trade secrets like formulas and manufacturing processes. Data and AI systems—increasingly central to Chinese tech development—now receive explicit legal coverage.
Key Changes
The updated rules establish that proprietary data and algorithms qualify as trade secrets when they provide competitive advantage and are subject to reasonable protection measures. Companies must demonstrate they've taken steps to maintain confidentiality, including access controls and employee agreements.
Enforcement penalties include damages up to 5 million yuan (approximately $700,000) for violations, with provisions for injunctions and seizures of infringing materials.
Strategic Context
The expansion reflects Beijing's concerns about technology transfer and espionage as US restrictions tighten on Chinese tech access. Recent sanctions targeting semiconductor companies and AI capabilities have intensified pressure on Chinese firms to secure proprietary developments domestically.
Data and algorithms represent critical assets for Chinese companies in cloud computing, autonomous vehicles, and large language models. Enhanced legal protections aim to prevent employee departures, corporate espionage, and unauthorized data access that could benefit competitors.
Implementation
The rules apply to both state-owned and private enterprises. Foreign companies operating in China must also comply with the expanded definitions when handling data and algorithms.
Courts will assess trade secret status on a case-by-case basis, considering factors like information uniqueness, competitive value, and protection efforts. The framework creates both opportunities for enforcement and potential complications for multinational firms navigating dual IP regimes.
China's move signals continued emphasis on securing technological independence amid geopolitical tensions and reflects broader global trends toward stricter data governance.
A new remote access trojan called Dolphin X leverages AI to profile and score infected users, enabling cybercriminals to prioritize high-value victims for exploitation.
A race condition vulnerability in the Linux kernel's XFS filesystem allows local attackers to overwrite protected files and gain root privileges. The flaw, tracked as CVE-2026-64600, has remained unpatched for nine years.
Intensified enforcement against online scam operations in Cambodia is displacing criminal networks to Sri Lanka, where authorities have arrested over 1,000 people in 2026.
Offensive cybersecurity researchers report that safety guardrails from OpenAI and Anthropic are restricting their ability to find vulnerabilities and develop security tools. The limitations are creating friction for legitimate security work.