The CAC AI regime is grounded in the Cybersecurity Law, Data Security Law and Personal Information Protection Law. Network operators providing these services must fulfil Multi-Level Protection Scheme (MLPS / dengbao) obligations: graded protection, security measures, log retention and incident handling. Referenced here as a cross-cutting obligation; full text not reproduced here.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.