news

China's AI Agent Regulations: What They Mean in 2026

July 27, 2026

China's AI Agent Regulations: What They Mean in 2026

China now treats an autonomous AI agent as its own regulated category, separate from the chatbot it runs on. In May 2026 the Cyberspace Administration of China and two other ministries issued the Implementation Opinions on Intelligent Agents — widely described as the world's first national policy framework built specifically for AI agents.12

TL;DR

On May 8, 2026, China's Cyberspace Administration (CAC), National Development and Reform Commission (NDRC), and Ministry of Industry and Information Technology (MIIT) jointly released the Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents.12 It defines an AI agent as an "intelligent system capable of autonomous perception, memory, decision-making, interaction, and execution," pulls agents out of China's older generative-AI rules, and requires developers to disclose which decisions an agent may take on its own, which need user authorization, and which the user keeps entirely.1 Agents in sensitive sectors — healthcare, transportation, media, public safety — face filing, mandatory testing, and product recalls.13

A separate, binding rule — the Interim Measures for AI Anthropomorphic Interaction Services — took effect July 15, 2026 and targets companion bots, not work agents. That is the rule that forced ByteDance's Doubao and Alibaba's Qwen to pull companion features.45 Most headlines conflate the two. This post keeps them apart.

What You'll Learn

  • Why China's 2026 rules are actually two documents, and which one does what
  • What the Implementation Opinions say: the agent definition, the four pillars, and the three tiers of decision authority
  • How filing, testing, and recalls work for agents in sensitive sectors
  • Why Doubao and Qwen shut down features on July 15 — and why that was the other rule
  • How China's "deploy first, govern along the way" posture differs from the West
  • A short checklist of what builders should do now

Two documents that keep getting confused

The single biggest error in coverage of "China's AI agent rules" is treating one story as two, or two stories as one. There are two distinct instruments, issued weeks apart by overlapping groups of regulators, aimed at two different kinds of agent.6

The first is the Implementation Opinions on Intelligent Agents, released May 8, 2026. In Chinese administrative practice, "Opinions" (意见) sits below binding "Measures" (办法) or "Regulations" (条例) in the legal hierarchy — a guiding policy instrument that sets direction and tasks regulators with building standards and filing regimes.7 Analysts at NYU Shanghai's research group frame the document as the country's "first dedicated policy framework treating AI agents as a distinct class,"1 and researcher Thorsten Jelinek argues it is "a standards move, not a regulatory one" — a definitional and infrastructural step more than an enforcement statute with fixed penalties.8 Some legal trackers, though, describe the framework as taking effect on July 15, 2026 with enforceable provisions, so its exact force is read differently across sources.9

The second is the Interim Measures for AI Anthropomorphic Interaction Services, issued in April 2026 and effective July 15, 2026. "Measures" (办法) are binding administrative rules with real teeth, and this one governs emotional-companion AI, not task-completing work agents.46 The two share regulators and a general philosophy, but they are not the same rule — and the widely reported July 15 shutdowns belong to the second document, not the first.

What the Implementation Opinions actually say

The Implementation Opinions matter first because of a definition. China now describes an AI agent as an "intelligent system capable of autonomous perception, memory, decision-making, interaction, and execution."1 That phrasing deliberately lifts agents out of the 2023 generative-AI rules, which mostly addressed content safety and algorithm registration, and recognizes that a system which plans and acts with tools poses different risks than one that only generates text.1

The document is organized around four pillars.1 Foundations calls for stronger base models, complete agent tool chains covering development, testing, deployment, and maintenance, and a national standards system for interfaces, data exchange, safety assurance, and trustworthiness certification. Safety and security covers behavior-containment technology, algorithmic governance, supply-chain protection, and risk frameworks for data poisoning, privacy breaches, and system failures. Application-driven adoption names 19 priority scenarios spanning scientific research, smart manufacturing, transportation, agriculture, financial risk control, healthcare, education, government services, judicial assistance, and public safety. Innovation ecosystem promotes open-source frameworks, compatibility with domestic chips and operating systems, and active participation in international standards-setting for agent protocols.1

Read together, the pillars describe a state that wants agents deployed widely and quickly — but with registration, testing, and audit trails wired in from the start rather than bolted on later.

The three tiers of decision authority

The most concrete builder-facing provision concerns who is allowed to decide what. The Implementation Opinions require developers to "clarify the reasonable boundaries and required authority for various decision-making methods," and distinguish three tiers of decision authority: decisions limited to the user, decisions requiring user authorization, and autonomous decisions made by the agent itself.1

The crucial line is that users retain "the right to know and the final decision-making power" over an agent's autonomous decisions, and that an agent's actions must not exceed the scope the user authorized.1 In practice that is a disclosure-and-consent obligation: an agent product has to make explicit, per action, whether it is acting inside a pre-authorized boundary or crossing into territory that needs a human's sign-off. It maps closely to the "human-in-the-loop" approval gates that agent frameworks in the West already ship as an engineering feature, but China is now framing them as a governance requirement rather than a nice-to-have.

Some trackers recast these tiers as risk levels — "routine," "significant," and "high-stakes," mapped to autonomous, recommend-only, and escalate-to-human handling.9 That is a reasonable gloss, but the primary text is framed around authorization, not a fixed risk score: the same action can sit in different tiers depending on what the user has pre-approved.

Filing, testing, and recalls for sensitive-sector agents

Where the Implementation Opinions get closest to hard enforcement is in sensitive sectors. Agents deployed in healthcare, transportation, media, and public safety are expected to face filing requirements, mandatory testing, and — the provision that drew the most attention abroad — product recalls, with oversight shared between cyberspace regulators and each sector's own authority.13

A recall regime is a notable choice. It treats a misbehaving autonomous agent like a defective physical product: something that must be identifiable, testable, and removable from the market when it goes wrong.3 For lower-risk consumer scenarios, the framework leans instead on platform governance, third-party evaluation, and industry self-regulation, backed by a credit-evaluation system that can penalize repeat violators.1 The document also singles out two harm vectors it wants contained: anthropomorphism-driven dependence among minors and older users, and misuse of agents for automated attacks, privacy violations, and fraud.1

For a US contrast, there is no single federal agency that plays the role China is assigning to the CAC here; oversight of autonomous agents remains fragmented across existing regulators.3 That gap is a large part of why the Chinese framework drew international attention.

Why Doubao and Qwen went dark on July 15

Here is where the two documents finally touch. On July 15, 2026 — the effective date of the Interim Measures for AI Anthropomorphic Interaction Services — ByteDance's Doubao and Alibaba's Qwen pulled their personified companion features.4 The Measures ban minors from virtual intimate relationships, require providers to disclose that users are talking to an AI, mandate anti-dependency safeguards and a minor mode with usage-time limits, and restrict training on users' private conversations.6 Rather than re-engineer around those constraints, both companies switched the companion experiences off.4

The transitions differed. Doubao — which reached around 345 million monthly active users in early 2026, per QuestMobile data10 — gave people read-only access to their companion data for a window after the cutoff, while Qwen users were reported to have no export path, with agent configurations and conversation histories deleted.5 Coverage repeatedly labels these "AI agent features," which is where the conflation starts: the shutdowns were driven by the companion Measures, not by the functional-agent Implementation Opinions. The work-agent framework did not order anyone to shut anything down in July; it set a direction for how work agents should be built and registered going forward.

"Deploy first, govern along the way"

The Implementation Opinions read differently from much of the Western agentic-AI debate. Where US and UK discussions have leaned on catastrophic loss-of-control scenarios, the CAC document focuses on integrating agents into existing institutions and argues that ordinary constraints — compute quotas, credit ceilings, access permissions, and system shutdowns — already bound how far an agent's autonomy can run.1 Analysts have summarized the posture as "deploy first, govern along the way."1

There is a strategic layer too. By tying the policy to domestic chips, operating systems, and open-source frameworks, and by signaling intent to shape international standards for agent protocols, China is positioning itself to influence the global rules for autonomous systems rather than inherit them.1 That mirrors, from the opposite direction, the standards-and-interoperability fights already unfolding elsewhere — from agent payment standards to EU-driven agent interoperability rules.

It is worth holding the counterpoint in view. Read as policy guidance, the Implementation Opinions' real force depends on the sector-specific filing and testing regimes regulators build next; read as an operative framework — as several legal trackers do — its provisions already reach sensitive-sector deployments. Skeptics call the document aspirational until the follow-on rules land; supporters call it the scaffolding that makes them inevitable. Both can be true at once.

What builders should do now

If you ship agents into China — or expect similar frameworks to spread — a few moves are low-regret regardless of how the binding rules settle. Treat decision authority as an explicit, per-action property of your agent, not an implicit outcome of a prompt: log which tier every action falls into and keep a human-final-decision path for anything above your authorized boundary. If you operate in a sensitive sector, assume filing, testing, and a removal-or-recall obligation, and build the audit trail that makes an agent's actions reconstructable after the fact. And keep your product's "does the work" agents cleanly separated from any "keeps you company" features, because those two now sit under different rules with very different tolerances. Much of this overlaps with the zero-trust containment patterns already emerging for autonomous agents in production.

Bottom Line

China's AI agent regulations in 2026 are less a single "AI agent law" than a two-part signal: a policy framework that defines work agents and tells builders to make decision authority explicit, and a binding companion-AI rule that already reshaped consumer products overnight. The details will harden as sector regulators write the filing and testing rules the framework calls for. Build now as if decision boundaries, human-final-decision paths, and recall-grade audit trails are required — because in at least one major market, the direction is already set.

Footnotes

  1. NYU Shanghai RITS, "China Issues First National Policy Framework Dedicated to AI Agents," May 11, 2026 (citing the CAC original document, Xinhua, and People's Daily). https://rits.shanghai.nyu.edu/ai/china-issues-first-national-policy-framework-dedicated-to-ai-agents/ 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21

  2. Cyberspace Administration of China, "智能体规范应用与创新发展实施意见" (Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents), May 8, 2026. https://www.cac.gov.cn/2026-05/08/c_1779979789523320.htm 2

  3. Robert Szczerba, "China Plans AI Agent Recalls. America Can't Even Agree Who Regulates Them," Forbes, July 14, 2026. https://www.forbes.com/sites/robertszczerba/2026/07/14/china-plans-ai-agent-recalls-america-cant-even-agree-who-regulates-them/ 2 3 4

  4. TechNode, "ByteDance's Doubao and Alibaba's Qwen to shut down AI agent features on July 15," July 6, 2026. https://technode.com/2026/07/06/bytedances-doubao-and-alibabas-qwen-to-shut-down-ai-agent-features-on-july-15/ 2 3 4 5 6 7

  5. TechTimes, "China AI Companion Law Takes Effect: Doubao and Qwen Shut Down, Millions Lose Chat Data," July 15, 2026. https://www.techtimes.com/articles/320525/20260715/china-ai-companion-law-takes-effect-doubao-qwen-shut-down-millions-lose-chat-data.htm 2 3

  6. Hunton Andrews Kurth, "China's First Regulatory Framework for Virtual Companions Soon to Take Effect," 2026. https://www.hunton.com/privacy-and-cybersecurity-law-blog/chinas-first-regulatory-framework-for-virtual-companions-soon-to-take-effect 2 3 4

  7. Sarah Zhao (Rimon Law), "China's new AI rules: Ethics, AI agents and anthropomorphic AI," IAPP, July 8, 2026. https://iapp.org/news/a/china-s-new-ai-rules-ethics-ai-agents-and-anthropomorphic-ai

  8. Thorsten Jelinek, "China Just Defined the Intelligent Agent. It's a Standards Move, Not a Regulatory One," Substack, May 2026. https://thorstenjelinek.substack.com/p/china-just-defined-the-intelligent 2

  9. Pebblous, "China's AI Agent Rules: Three Tiers of Decision Authority," 2026. https://blog.pebblous.ai/blog/china-ai-agent-decision-tiers/en/ 2 3

  10. BigGo Finance, "Doubao Paid Subscription Sparks Controversy: Computing Power Crunch and Monetization Push for 345 Million MAU" (reporting QuestMobile Q1 2026 data), 2026. https://finance.biggo.com/news/Fks8Cp4BDXrLZJaAbcpF

Frequently Asked Questions

China issued two related instruments. The Implementation Opinions on Intelligent Agents (May 8, 2026) is a national policy framework for work agents that sets an agent definition, four development pillars, three tiers of decision authority, and filing/testing/recall expectations for sensitive sectors.1 The Interim Measures for AI Anthropomorphic Interaction Services (effective July 15, 2026) is a binding rule for emotional-companion AI.46