← Back to blog
AiAbout 6 min read

China Wrote the First Mandatory Safety Standard for AI Agents

Published Oct 7, 2026
China Wrote the First Mandatory Safety Standard for AI Agents

Most AI rules start as guidance. Vendors read them, decide how much to follow, and ship. China just went a different way. On June 27 the Standardization Administration put a mandatory national standard on the books called Basic Security Requirements for Agent Applications, filed as plan number 20263116-Q-252. The drafting is led by China Mobile, the standard is administered by the Cyberspace Administration of China, and the technical work sits with the National Network Security Standardization Technical Committee, known as TC260.

The word that matters is mandatory. Voluntary standards and industry group standards have existed for a while, and companies treated them as a range of options. A mandatory national standard carries legal force. Once it takes effect, a public-facing agent product that does not meet it cannot pass testing, certification and market access review. Safety moves from a feature you advertise to a gate you pass.

What counts as an agent under the standard

The scope is wider than the word "agent" suggests. It covers applications deployed on phones, tablets, computers, wearables or the cloud that can call system or local tools to complete what the user asked for. Design, distribution, deployment and live operation all fall inside it. If the software takes an action rather than writing an answer, it is in scope.

That framing reflects how the risk has changed. Older AI rules focused on content: a model says something it should not, leaks private data or spreads false claims. Those failures can be contained after the fact with filtering, review queues and refusal mechanisms. An agent that holds network access and permissions and can drive external systems fails differently. Intent can drift. Permissions can slip. A tool call can misfire. A bad paragraph is a mild outcome. Worse is a payment cleared, a message sent to the wrong recipient, or a scheduling system taken down.

Chinese coverage of the drafting puts the risk inventory at 13 categories and 97 items, mapped across perception, decision and execution. The stated goal is to make a working agent authorizable, constrainable and accountable, which is a way of saying every action should trace back to a permission and an owner.

From guidance to a market gate

The practical consequence is that compliance becomes a cost of doing business for anyone shipping agents to the public. China Mobile is not an accidental choice as lead drafter. Telecoms operators sit on the identity, billing and messaging rails that consumer and enterprise agents want to use, and the industry has spent two years repositioning itself from pipes to services. A standard written by an operator is written by a party that has to run the plumbing.

The reported timeline is deliberate rather than rushed. The plan was filed in March, opened to public comment from April 1 to May 1, formally issued in late June, and discussed inside TC260's AI security working group in July. The drafting window is 18 months, which puts the finish line in the second half of 2027 at the earliest. Nothing is enforceable today.

That gap is where the interesting choices get made. A standard built on 97 enumerated risks risks driving vendors toward checklists. A standard built on outcomes gives buyers something to audit. The text that emerges over the next year will decide which of those two it becomes, and vendors in the market now have a reason to argue for the version they can already pass.

The rest of the stack arrived first

The agent standard did not appear alone. China published an AI security governance framework in September 2026 that widened its scope from individual technical steps to the whole chain of data, algorithms, models, applications and supply. An earlier safety guide for agent deployment landed in July. A generative AI service security grading standard took effect on October 8. Read together, the sequence moves from principles to grading to a mandatory floor, with each layer narrower and more enforceable than the last.

The agent identity question was already in motion too. China has been drafting rules for how agents carry identity and prove who they work for, which is a precondition for the permission model the safety standard assumes. You cannot constrain an agent's authority if nobody can tell whose authority it is acting under.

How this compares to the American approach

The United States has not written an equivalent technical floor. What it has is a proposal: a bipartisan AI Agent Accountability Act that would attach criminal liability to executives at companies deploying agents with cyber-operation capability, and require developers to take reasonable precautions against known out-of-scope abilities. That is a liability model, aimed at who pays after something goes wrong. The European Union, meanwhile, handles agents mostly through the AI Act's risk tiers and transparency duties rather than a dedicated agent standard.

The contrast is worth stating plainly, because it shapes what vendors build. Europe pushes disclosure. The United States debates blame. China is defining what a compliant agent is allowed to do before it reaches a user. For a company selling agents across all three markets, the Chinese floor is the one that will show up as an engineering requirement rather than a legal risk note.

What a compliant agent looks like in practice

The standard's risk list points at a set of engineering habits that vendors can start building now. Scoped permissions instead of broad ones, so an agent doing expense reports cannot reach the payroll system. An action log that records what the agent did, under whose authority and with which tool, since the 97-item inventory is only auditable if the actions are recorded in the first place. Explicit confirmation before anything irreversible, which is the same pattern Naver put in its browser assistant this month when it required approval before writing a calendar event.

There is a tension in that list. Logging every agent action produces a rich record of user behavior, and the same data that makes an agent accountable also makes it a surveillance surface. A standard written by a telecoms operator will have a view on retention, because operators carry legal obligations about communications data that most software vendors do not. How the text handles logging, and who can query it, is one of the parts worth watching in the drafting window.

What to watch

Two things will decide whether the standard matters outside China. The first is its conformance testing. A mandatory standard is only as strong as the labs that certify against it, and the 97-item risk list suggests a lot of surface area for interpretation. The second is whether the technical content is published in a form other jurisdictions can borrow. China has already exported its approach to content labeling, where the EU, the United States, Singapore and the UK are all moving in the same direction with different mechanisms. If the agent security requirements are concrete enough, the same thing could happen again, and a global vendor would face one more set of rules it did not help write.

For now, the honest read is that this is the first serious attempt to turn agent safety from a promise into a permit. The 18-month drafting window is a countdown. Anyone building agents for public use has until then to decide whether to shape the standard or just comply with whatever lands.

Related articles