Artificial intelligence is increasingly used to document, classify, monitor, reconstruct, and communicate cultural heritage. In China, these uses are governed not by a single heritage-AI statute but by overlapping rules on cultural relics, intangible cultural heritage, data security, personal information, copyright, generative AI services, and synthetic-content labeling. This article combines doctrinal analysis with a functional review of the heritage-AI lifecycle to identify where those layers apply and where they leave operational gaps. It makes three bounded contributions. First, it develops a four-tier framework with explicit rules for non-compensatory risk floors, stage-specific reassessment, escalation, and decision authority. Second, it defines the Cultural Data Passport as a heritage-specific adaptation and operational linkage of existing dataset, model, and provenance documentation, rather than as an entirely new data-governance mechanism. Third, it connects validation, public disclosure, responsibility, and correction in an auditable record chain. A worked normative scenario involving AI-assisted reconstruction of a Dunhuang mural traces those controls from data acquisition through public release and correction. The scenario tests the framework's internal operability but does not establish its empirical feasibility or institutional superiority. The framework distinguishes binding Chinese law from policy and non-binding UNESCO or WIPO guidance, while treating generated heritage images as reviewable reconstruction hypotheses rather than historical proof.