web analytics
AI Governance

China AI Regulation

The Intelligent Agent Framework, the Companion-AI Rules, and the Stack Underneath

The one-paragraph answer

China AI regulation produced two separate instruments in 2026 that the field keeps merging into one. The first is the Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents, jointly issued by the Cyberspace Administration of China (CAC), the National Development and Reform Commission (NDRC), and the Ministry of Industry and Information Technology (MIIT) on May 8, 2026. It is the first national framework anywhere to treat an AI agent as its own governance category rather than as an application built on a generative model, it defines an agent as a system capable of autonomous perception, memory, decision-making, interaction, and execution, and it sets a three-tier decision-authorization model: actions reserved for humans, actions permitted only with user authorization, and actions the agent may take on its own. The second is the Interim Measures for the Administration of AI Anthropomorphic Interactive Services, issued April 10, 2026 and effective July 15, 2026, which is a companion-AI rule, not an agent rule, and which forced ByteDance’s Doubao and Alibaba’s Qwen to shut down their personalized companion features on that date. The correction this page exists to make: the widely repeated claim that “China’s agent rulebook took effect July 15, 2026” fuses the two. The agent Opinions are a May 8 policy framework that directs regulators to build standards that do not all exist yet, they are not a finished, enforceable recall statute; the thing that actually took effect July 15 is the companion rule, and it deliberately spares work agents.

The pain China AI regulation is causing multinationals

A multinational deploys an AI agent that books logistics, approves refunds, and files paperwork across its China operations. In July 2026 its compliance team reads a wave of newsletters announcing that China’s “AI agent rulebook” became enforceable on July 15, with mandatory filing and product-recall duties. The team scrambles to file. Then its China counsel points out that the July 15 instrument is the companion-AI rule, which does not touch a refund-approval agent at all, and that the actual agent framework is a May 8 policy document whose filing and testing mechanics are still being written into national standards. The company has spent two weeks preparing for the wrong deadline. This is the concrete cost of the conflation, and it is happening across enterprise compliance teams right now.

The deeper problem is that both instruments are real, both matter, and the obligations are genuinely different. An agent that does work is governed by the May 8 framework and the standards flowing from it. An agent that provides sustained emotional companionship is governed by the July 15 companion rule. A company that cannot tell which of its deployments is which cannot answer either regime.

The intelligent agent framework, in plain language

The Implementation Opinions are the first time any government has pulled “intelligent agents” out of the generative-AI bucket and named them a distinct class of system requiring their own governance. That definitional move is the substantive event. China’s 2023 generative AI rules governed systems that produce text, images, and code; the May 8 Opinions govern systems that act, defined as autonomous perception, memory, decision-making, interaction, and execution.

The framework is risk-tiered by deployment scenario. Agents in sensitive sectors and key industries, healthcare, finance, transportation, judicial services, public security, and media, face the heaviest requirements: filing with regulators, mandatory compliance testing, third-party certification, auditing, product recall mechanisms, and oversight by both the cyberspace regulator and the relevant sector authority. Lower-risk scenarios such as office productivity and entertainment lean on self-assessment, information reporting, platform governance, and industry self-regulation, backed by a credit-evaluation system that can penalize violators. The framework identifies nineteen application scenarios and sits inside the “AI Plus” industrial strategy, which targets 70 percent agent adoption across smart terminals and public services by 2027, rising to 90 percent by 2030.

The word that should stop any operator is recall. Putting recall into the official governance vocabulary for autonomous software implies the whole apparatus a recall requires: you cannot recall what you cannot identify, freeze, trace, or version. A forthcoming mandatory national standard, the General Security Requirements for Artificial Intelligence Agent Application, is expected to specify identity authentication, permission and tool invocation controls, manual intervention for high-risk operations, log retention, dynamic monitoring, anomaly blocking, and emergency shutdown. That standard, not the May 8 Opinions, is where the enforceable engineering duties will actually live.

The three-tier decision authorization model

The framework’s most portable idea, and the one worth adopting regardless of whether you operate in China, is its classification of agent decisions into three categories:

  1. Reserved for humans. Decisions an agent may never make autonomously. The human holds them by design.
  2. Permitted with user authorization. Decisions an agent may make only after an explicit, scoped grant from the user, and never beyond the authorized scope.
  3. Autonomous. Decisions the agent may take on its own, within its defined boundaries.

The Opinions state that users “have the right to know and the final decision-making power regarding the autonomous decisions made by the intelligent agent, and that the intelligent agent’s actions do not exceed the scope authorized by the user.” That is functionally close to the European idea of meaningful human control, but framed around deployment rather than precaution. The practical demand it makes is one most organizations cannot currently meet: write down, per agent, which decisions fall in which tier. Ask an executive what a given agent is allowed to decide without a human in the loop, and the answer is usually a blank stare. The three-tier model turns that blank into a required artifact.

The companion-AI rule that actually took effect July 15

The instrument that became legally effective on July 15, 2026 is the Interim Measures for the Administration of AI Anthropomorphic Interactive Services, co-issued April 10, 2026 by the CAC and four partner agencies (NDRC, MIIT, the Ministry of Public Security, and the State Administration for Market Regulation), after a three-month grace period. It governs services that simulate human personality, thinking patterns, and communication styles to provide sustained emotional interaction. On its effective date, ByteDance’s Doubao and Alibaba’s Qwen pulled their personalized AI companion features, affecting hundreds of millions of users; Doubao gave users until October 15, 2026 to export their data.

Read quickly, it looked like Beijing had switched off AI agents. It had not. The Measures draw a precise line between the agent that keeps you company and the agent that does your work. Customer-service bots, knowledge Q&A systems, workplace productivity assistants, and educational tools remain explicitly permitted, provided they avoid sustained emotional engagement. The rule adds mechanisms for extreme-scenario life intervention, emotional-boundary control, and dynamic anti-addiction, and it is the newest link in a chain that runs algorithm recommendation, deep synthesis, generative AI, anthropomorphic interaction.

The correction: two instruments, constantly merged

Here is the error stated plainly, because it is now in wide circulation. Multiple governance trackers and newsletters report that “China’s Implementation Opinions on intelligent agents became enforceable on July 15, 2026, the world’s first dedicated regulatory category for AI agents,” and in the same breath attribute the Doubao and Qwen shutdowns to that instrument. Three things are wrong or conflated in that sentence:

  • The date. The agent Opinions were issued May 8, 2026, per China’s own government announcement and Xinhua. July 15 is the effective date of a different rule.
  • The instrument behind the shutdowns. Doubao and Qwen pulled companion features because of the Anthropomorphic Interactive Services Measures, not the agent Opinions. The agent framework does not order any companion shutdown.
  • The enforceability. The agent Opinions are an implementation framework, not a finished statute. They direct regulators to develop the standards, filing mechanics, and recall procedures, many of which do not yet exist. Calling them an enforceable “rulebook” overstates their current legal bite.

None of this makes the agent framework unimportant. It makes it important for the right reason: it is the first binding-track legal definition of an AI agent and the clearest three-tier authorization model in any jurisdiction, and a draft national AI Law now moving through the National People’s Congress is expected to codify these principles into hard statute with broader sector coverage. Definitions are leverage, and this one came out of Beijing.

The regulatory stack underneath

The two 2026 instruments sit on a decade of sequential Chinese AI and algorithm rules, and the sequence is the point. China has regulated in a deliberate chain: the Algorithm Recommendation Provisions (2022), the Deep Synthesis Provisions (2023), the Interim Measures for Generative AI Services (2023), the Anthropomorphic Interactive Services Measures (2026), and now the Intelligent Agent Opinions (2026). Each new rule assumes the prior ones and extends them to the next capability. Underneath all of it sits the Personal Information Protection Law (PIPL), China’s GDPR-analog, which governs any agent that processes personal information regardless of which capability-specific rule applies. TC260’s Ethics-Safety Guidelines for AI Applications 1.0 (effective July 1, 2026) add nine ethics principles across the whole stack. An operator that treats any single instrument in isolation will miss the way the chain compounds.

What the research says about China AI regulation and agentic governance

Existing governance frameworks such as the NIST AI RMF and the EU AI Act articulate essential principles of fairness, accountability, and transparency, but they remain largely static and principle-based, whereas agentic systems are dynamic, tool-using, and adaptive, requiring continuous oversight rather than one-time certification.

China’s three-tier authorization model is one of the first regulatory attempts to encode that continuous-oversight requirement into law rather than principle, by fixing per-decision autonomy limits before deployment rather than certifying a system once.

Agent autonomy can be measured directly from the code that governs an agent, which allows autonomy levels to be classified and bounded as a governance control rather than inferred after the fact from behavior.

How to respond to China AI regulation: a 5-step path

  1. Separate your companion agents from your work agents. The two 2026 instruments govern different things. Any deployment that provides sustained emotional interaction is inside the July 15 Anthropomorphic Services rule; work agents are not. Classify every deployment on that line first, because the obligations diverge from there.
  2. Build a per-agent decision-rights register using the three tiers. For every agent, document which decisions are reserved for humans, which require user authorization, and which are autonomous. This is the artifact the May 8 framework demands and the one most organizations cannot currently produce, in China or anywhere else.
  3. Map sensitive-sector deployments to the filing and recall track. If an agent operates in healthcare, finance, transportation, judicial services, public security, or media in China, assume filing, testing, certification, audit, and recall duties are coming through the forthcoming national standard, and build identifiability, traceability, version control, and an emergency shutdown now.
  4. Align your internal agent taxonomy to the Chinese definition. “Autonomous perception, memory, decision-making, interaction, and execution” is a usable working definition. Adopting it lets one inventory answer the EU AI Act’s human-oversight duties, the Chinese authorization tiers, and your own board’s risk questions at once.
  5. Track the draft national AI Law. The principles in the May 8 Opinions are expected to harden into statute through the National People’s Congress. What is a policy framework today becomes binding law later, and the sector coverage is expected to widen. Watch the NPC calendar, not just the CAC.

Frequently asked questions about China AI regulation

Did China’s AI agent rules take effect on July 15, 2026?

No. The agent framework (the Implementation Opinions on Intelligent Agents) was issued May 8, 2026 as a policy framework. The instrument that took effect July 15, 2026 is the separate Anthropomorphic Interactive Services rule, which governs companion AI and drove the Doubao and Qwen shutdowns. The two are frequently and incorrectly merged.

Are the agent Opinions actually enforceable now?

Only partially. They are an implementation framework that directs regulators to build the filing, testing, and recall standards. The enforceable engineering duties are expected to arrive through a forthcoming mandatory national standard, the General Security Requirements for Artificial Intelligence Agent Application, and eventually through the draft national AI Law.

Do these rules reach a company outside China?

They reach AI agents deployed into Chinese operations and markets. A company headquartered elsewhere but running agents that touch Chinese users, sectors, or infrastructure is in scope. The three-tier authorization model and the sensitive-sector filing duties attach to the deployment, not the company’s home jurisdiction.

Where does China AI regulation fit in SRJ’s work?

The decision-rights register the Chinese framework demands is exactly the artifact the AI Business Enablement Audit and the AI Risk & Governance Review produce: a per-agent map of what each system may decide alone, what needs authorization, and what stays human. See Volume III: The AI Risk & Governance Review.

Primary sources on China AI regulation

Ready to see where you stand?

The AI Business Enablement Audit™ measures your organization against every framework in this library, including China AI Regulation, and delivers a defensible governance dossier. Start or finish your audit below.

Start or finish your AI Audit →
Schedule a Free AI Consultation