---
title: "China binds AI agents with a mandatory safety standard"
date: 2026-09-24
category: Policy & Governance
site: NeuroAI
canonical: https://neuroai.site/a/na-policy-ai-standard
language: en
---

# China binds AI agents with a mandatory safety standard

> China has launched a mandatory national safety standard for AI agents—the first of its kind by Beijing's account. We break down what the rule covers, who must comply, and what "mandatory" really means before it takes force.

Your assistant booked a flight, moved money, and drafted an email to your boss—without pausing for permission. That autonomy is the whole appeal of an AI agent (智能体). It is also the nightmare scenario for anyone left holding the bag when it goes wrong. China has decided the moment to draw that line is now.

## What actually got approved

On 27 June 2026, China's national standards body entered a new project into the official pipeline: **《智能体应用安全基本要求》**, or **"General Security Requirements for Artificial Intelligence Agent Application."**

The details, pulled from the national standards platform (std.samr.gov.cn), are unusually specific for an early-stage rule:

- **Project number:** 20263116-Q-252

- **Status:** mandatory (强制性)—not a voluntary guideline

- **Development cycle:** 18 months

- **Proposed by:** the Cyberspace Administration of China (中央网络安全和信息化委员会办公室, the country's top internet regulator)

- **Handled by:** TC260, the national technical committee on cybersecurity standards

- **Drafted by:** China Mobile, the China Electronics Standardization Institute (CESI), and CNCERT, the national computer-emergency response team

The fact that it is **mandatory** is the headline. Most Chinese AI standards to date have been recommended (GB/T) documents that vendors could ignore. A mandatory standard, once in force, can become the legal floor for product design, testing, and market access.

## What the rule will demand

The draft scope is broad. It targets agent (智能体) applications deployed on **phones, tablets, computers, wearables, or cloud platforms**—specifically those that can call system or local tools to get things done. That deliberately captures the assistants that no longer just answer, but act.

The technical requirements read like a safety checklist for a junior employee who now holds the company credit card:

- **Identity tagging** so an agent is distinguishable from a human

- **Controlled system-permission calls** and **tool use**

- **Rules on data collection and use**

- **Human intervention for high-risk operations**

- **Input/output safety protection**

- **Log retention and dynamic monitoring**

- **Abnormal-operation blocking and emergency shutdown**

In plain terms: if the agent can move money, send mail, or run code, someone has to be able to see it, stop it, and audit it afterward. The "emergency shutdown" line is the clearest signal that regulators are imagining agents that can do real-world damage, not just write poems.

## A second standard, quieter but foundational

The agent rule is not the only 2026 AI standard worth watching. On 30 April 2026, China published **GB/T 47507-2026 《人工智能 可信赖 通则》**—"Artificial intelligence—Trustworthiness—General rules." It took effect on 1 August 2026.

Unlike the agent rule, this one is **recommended (GB/T)**, not mandatory. But it is billed as the country's first general, foundational standard for trustworthy AI, covering the core elements that make an AI system dependable across its full life cycle—design, development, deployment, testing, and monitoring. Think of it as the vocabulary and the baseline that sector-specific rules like the agent standard will sit on top of.

Together, the two show a deliberate sequence: set the trustworthy-AI baseline first, then attach mandatory teeth to the riskiest emerging use case.

## Why agents, why now

The trigger is functional, not philosophical. AI agents (智能体) have shifted from generating text to executing tasks—opening browsers, calling APIs, operating other software, and making multi-step decisions. That leap is exactly what creates the new failure modes the standard names: data leakage, runaway permissions, tool misuse, and actions that drift from a user's intent.

Chinese regulators have framed the mandatory status around protecting "personal health, life and property safety, national security, and basic economic and social management needs"—the legal grounds under which China designates a standard as compulsory.

## The "world's first" claim, and its weight

State media have described the agent standard as the **world's first mandatory national standard focused specifically on AI agent safety.** That is a meaningful claim if true, because it would put Beijing ahead of Brussels and Washington in turning agent risk into binding, code-level requirements rather than principles or voluntary codes.

We could not independently confirm that no other jurisdiction has a comparable mandatory instrument; the comparison rests on Chinese official statements. What is verifiable is the domestic fact: this is the first such mandatory standard in China, and it is moving through the formal standards pipeline with a named 18-month clock.

## Honest limitations

This article is built on the national standards platform record (std.samr.gov.cn) for project 20263116-Q-252 and the published GB/T 47507-2026 entry, cross-checked against People's Daily and Beijing municipal-science reporting. Key points to keep straight:

- The agent standard is **not yet in force.** It is a project under development with an 18-month cycle; the technical text has not been finalized or enacted. Every "will demand" above describes the draft scope, not a binding rule on the books today.

- Figures such as the 18-month cycle, the project number, and the drafting bodies are taken from the official standards record. We did not access a full draft text, so the exact threshold values for each requirement are not yet public.

- The "world's first" framing is a Chinese official-media characterization; we have not independently benchmarked it against other countries' standards.

- GB/T 47507-2026 is a **recommended** standard. Treating it as law would be wrong; it is a baseline that mandatory sector rules will build on.

- The standard targets agents that call tools or system functions. Narrow, non-tool-calling chat features fall outside its stated scope.

## What readers can do now

- **If you ship AI agents (智能体) into China,** start mapping your permission, logging, and emergency-stop architecture against the ten named requirements now—the 18-month clock means conformance work should begin long before enforcement.

- **If you follow AI governance,** watch TC260's public-comment periods for this project; the draft text, not the announcement, will define what "mandatory" practically costs vendors.

- **If you build cross-border products,** assume China's agent-safety floor will diverge from the EU AI Act and U.S. executive-order approach—design for the strictest applicable regime rather than the lowest common denominator.

---

Published by NeuroAI (https://neuroai.site/) — https://neuroai.site/a/na-policy-ai-standard
Free to quote with attribution and a link to the original.
