China's Cyberspace Administration, National Development and Reform Commission, and Ministry of Industry and Information Technology have jointly issued Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents — the first national policy framework written specifically for AI agents rather than generative AI in general. Multiple policy trackers report the measures reaching compliance effect on July 15, 2026, the same week as China's separate rules on anthropomorphic companion AI.
The framework defines an agent as a system capable of autonomous perception, memory, decision-making, interaction and execution — a deliberately narrower category than a chatbot, built around the fact that an agent can take real-world action rather than only produce text. Its central mechanism is a three-tier authorization structure. Some decisions remain user-exclusive, requiring direct human control regardless of the agent's confidence. Others are authorized decisions, delegated to the agent through explicit user permission — a standing grant, not a one-time click. The remainder are autonomous decisions the agent may take within its defined scope, though the framework states users 'retain the right to know and the ultimate decision-making authority' even over actions they never individually approved.
Three tiers of agent authorization, and what each covers
- User-exclusive · tier 1
- Decisions requiring direct human control
Includes: Every decision in this category, regardless of the agent's confidence
Excludes: Any standing delegation — this tier cannot be pre-authorized away - Authorized · tier 2
- Decisions delegated through explicit user permission
Includes: A standing grant the user set up in advance
Excludes: A one-time click — the framework specifies an ongoing grant, not a per-instance approval - Autonomous · tier 3
- Decisions the agent may take within its defined scope
Includes: Actions inside the agent's pre-set boundaries
Excludes: The user's "right to know and the ultimate decision-making authority," which the framework states persists even here
Filing, testing, recall — for the sectors where mistakes matter most
Agents operating in 'sensitive sectors and key industries' face heavier obligations: formal filing with regulators, compliance testing, and product-recall provisions if an agent is later found unsafe. The sectors named explicitly are healthcare, transportation, media, and public security — the categories where an autonomous action, taken wrong, is hardest to undo. An organization deploying an agent in one of those sectors without a documented decision-authorization policy is, per the framework, already out of compliance.
Users retain the right to know and the ultimate decision-making authority — even over the decisions the agent is permitted to make on its own.
A different category from the companion-AI rules
It would be easy to fold this into China's separate companion-AI rules, since both reach compliance effect in the same week. They are not the same instrument. The companion-AI rules regulate emotionally engaged interaction — AI designed to be treated as someone. This framework regulates the opposite category: AI built to work for you, sorted by how much authority it holds when it does. Read together, China has now drawn two distinct regulatory lines through consumer-facing AI in a single week — one for AI that bonds, one for AI that acts — where most jurisdictions have drawn none.
What is not established
The dating is messier than the compliance-deadline headlines suggest. One source traces the document's issuance to May 8, 2026, with no separate effective date specified in the text itself; multiple trackers instead report July 15 as when compliance obligations bite. The precise issuance-to-effect timeline could not be independently confirmed against China's official gazette, and no source located names a specific penalty schedule or enforcement body empowered to act on a violation yet. The examples given for each authorization tier — financial transactions, government approvals, medical decisions, judicial functions — are illustrative, not an exhaustive list; how a regulator classifies a genuinely ambiguous agent action in practice is untested.
- China's Implementation Opinions on Intelligent Agents sort every agent action into three authorization tiers.
- Tiers: decisions a user makes alone, decisions needing user authorization, and decisions an agent takes autonomously.
- Agents in healthcare, transport, media and public safety face mandatory filing, testing and recall provisions.
- It is the first national policy framework written specifically for agents, separate from generative-AI rules.
- Caveat: issuance and effective dates are reported inconsistently across trackers; the framework carries no disclosed penalty schedule yet.
