Supporters of Marcus Endicott’s Patreon can access weekly or monthly consultations on this topic.
The metaverse has never had a settled definition. Neal Stephenson coined the word in his 1992 novel Snow Crash, imagining a three-dimensional successor to the internet, and in the decades since it has been redefined by technologists, standards bodies, and governments according to their own emphases — Matthew Ball stressing persistence and the continuity of identity across interconnected worlds, the European Commission describing immersive environments built on extended reality, academic bodies conceding openly that no universal definition exists. What survives every reformulation is a set of foundational questions the concept forces open: how identity is established when a person appears as a digital representation of themselves, how governance is exercised in a space that spans jurisdictions, and how privacy is protected where the boundary between physical and digital life grows porous. It is around these questions, and not around the more lurid narratives that have attached to them, that the real regulatory contest is taking shape.
One of those lurid narratives concerns China, and it is worth dismantling before the substantive story can be told. The claim, widely circulated since 2023, is that China has proposed extending its social credit system into virtual worlds — that the surveillance apparatus imagined abroad as a single national score for every citizen is about to follow users into the metaverse. Almost every element of that claim is a misreading. China's social credit system, whose planning framework was set out in a State Council outline in June 2014, has never operated as a unified behavioral score. The 2014 document does not mention scoring at all. The system works instead through blacklists and redlists — binary mechanisms triggered by specific legal facts. Its most consequential instrument is the Supreme People's Court's judgment defaulter list, which bars people who defy court rulings from buying air or high-speed rail tickets, staying in luxury hotels, or serving as company directors; this is a court-enforcement tool rather than a behavioral index, and by 2018 it had blocked would-be air travelers more than seventeen million times. The data the system aggregates is overwhelmingly public credit information about businesses, gathered by agencies in the course of regulatory work. The Sesame Credit program often cited abroad as proof of citizen scoring is a private commercial loyalty scheme, and the People's Bank of China declined to grant its operator a personal credit license. By 2019 central authorities had clarified that scores could not be used to penalize citizens, local pilots were scaled back to voluntary rewards programs, and a guideline in March 2025 reaffirmed lawful data use and privacy protection. The system remains, in substance, a corporate compliance framework.
The metaverse-extension story rests on an equally slender foundation. In July 2023 China Mobile, a state telecommunications firm, submitted a proposal for a metaverse digital identity system to a focus group of the International Telecommunication Union meeting in Shanghai. The proposal envisioned linking real-world and virtual identities based on characteristics such as occupation, and it did contemplate identifying disruptive behavior — but it never mentioned social credit. The comparison was supplied by Western commentators and amplified in the press; the focus group is a non-binding consultative body, and nothing was adopted as a standard. China's actual government metaverse policy, a five-department three-year action plan issued in September 2023, is an industrial-development document whose governance provisions read in the ordinary language of content review, ethics, and data security. The behaviors the China Mobile paper anticipated are in any case already covered by China's existing internet governance: real-name registration has been mandatory since 2015, the Cybersecurity Law of 2017 and its successors require content moderation and permit enforcement against illegal online conduct, and in July 2025 the country launched a national online identity authentication system issuing alphanumeric verification codes across internet services. Applying these mechanisms to virtual environments requires no invocation of social credit at all.
Clearing away the mirage reveals a more consequential fact: China has built the most developed regulatory architecture for the technologies underpinning virtual beings of any jurisdiction, not through metaverse-specific law but through a deliberately layered stack. The Administrative Provisions on Deep Synthesis took effect in January 2023, covering face generation and replacement, gesture manipulation, voice synthesis, and three-dimensional reconstruction. The Interim Measures for Generative AI Services, China's first binding rules for the technology, followed in August 2023, imposing content obligations aligned with core socialist values, training-data requirements, and security assessments for services capable of shaping public opinion. In March 2025 the Measures for Labeling of AI-Generated Synthetic Content established a dual-track regime — human-visible markers plus embedded metadata — for all synthetic text, images, audio, video, and virtual scenes, backed by a mandatory national standard that took effect that September.
Most directly relevant is the draft Administrative Measures for Digital Virtual Human Information Services, released by the Cyberspace Administration of China for public comment in April 2026. It defines a digital virtual human as a non-physical digital image, built with computer graphics or artificial intelligence and driven by people or by computation, that simulates human appearance, voice, behavior, and personality. Its provisions are strikingly specific. They prohibit creating virtual humans bearing the identifiable traits of real persons without consent, ban virtual intimate relationships — virtual family members and romantic partners alike — for users under eighteen, forbid using AI avatars to bypass identity authentication, mandate disclosure labeling, require human oversight in government and judicial services, and impose fines of up to two hundred thousand yuan for violations threatening public health or safety. A companion draft on human-like interactive AI services, released weeks earlier, targets systems that simulate personality and emotional interaction and prohibits encouraging suicide, self-harm, verbal violence, and emotional manipulation. Together these are the most targeted attempt by any government to regulate the specific social dynamics of virtual beings. Beneath them sits a foundational suite — the Cybersecurity Law of 2017, the Data Security Law of 2021, and the Personal Information Protection Law of 2021, which classifies biometrics as sensitive data requiring separate consent and carries fines of up to fifty million yuan or five percent of annual revenue — with a comprehensive national AI law expected eventually to consolidate the whole.
The identity questions the metaverse raises are not only regulatory but technical, and here the privacy calculus resists simple framing. Realistic avatar systems, of which Apple's Persona feature is the most advanced consumer example, offer users a measure of pseudonymity by shielding real identity and biometric data during interaction. The same realism, however, has sharpened the threat of identity theft: security agencies warn that deepfake avatars can impersonate at scale and can be aged downward to target children, and industry surveys through 2024 found identity fraud rising steeply, with audio and video deepfake attacks reported by nearly half of organizations. Cryptographic responses exist — decentralized identifiers standardized by the World Wide Web Consortium, and zero-knowledge proofs that verify a claim without exposing the underlying data — but adoption remains thin, most major platforms still rely on centralized identity management, and observers caution that these tools do not by themselves stop verifiers from over-collecting personal information. The relationship between avatars and privacy is a trade-off, not a solution.
Set against this, no jurisdiction has enacted comprehensive metaverse legislation. The European Union's AI Act, in force since 2024 and phasing in through 2027, takes a risk-based approach — banning manipulative techniques and emotion inference in workplaces and schools, and requiring that synthetic media be labeled and that people be told when they are interacting with AI — but its Virtual Worlds Initiative of 2023 proposed no new law. The United States has no federal metaverse statute; action is fragmented across a handful of narrowly targeted federal bills and a surge of state legislation on companion chatbots, digital replicas, publicity rights, and AI transparency. The international conversation, in the World Economic Forum, the European Commission's citizens' panels, and the intellectual-property and infrastructure discussions of the G7 and G20, centers on privacy, interoperability, child safety, and intellectual property — not on social credit, which no government has proposed exporting into virtual worlds. The real challenge is not the transplantation of an authoritarian model but the construction of frameworks adequate to genuinely novel problems of identity, privacy, and safety, a task every jurisdiction has only begun. The story worth telling about China, then, is not the myth of a score following citizens into the metaverse. It is that while the myth circulated, China quietly assembled the most concrete rules anyone has yet written for the virtual person.