China now regulates AI agents as their own legal category, separate from the generative-AI models they run on — a framing no other major jurisdiction has adopted as of late August 2026. The Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents took effect 15 July 2026, and organizations with China operations that deploy autonomous agents are already inside its scope, whether or not they have mapped their compliance posture to it yet.

What was issued, by whom, and when

The Implementation Opinions were released 8 May 2026 and became enforceable 15 July 2026 — a lead time of just over two months (Machinebrief). They were issued jointly by three bodies: the Cyberspace Administration of China (CAC), the National Development and Reform Commission (NDRC), and the Ministry of Industry and Information Technology (MIIT) (AI Governance Institute). The document is widely described as the first national policy to treat AI agents — defined by autonomous perception, memory, decision-making, interaction, and execution — as a distinct regulated category, rather than folding agent behavior into existing generative-model rules (AI Governance Institute).

That distinction matters practically. A generative-AI regulation asks what a model outputs. An agent-specific regulation asks what an agent does — which actions it takes, with what degree of independence from a human, and with what consequence if it acts wrongly. China's framework is built around the second question, and it belongs on the same regulatory-tracking list as the AI governance guide covers for EU and US frameworks.

The three-tier decision-authority model

China's Implementation Opinions establish a three-tier decision-authority model that governs how much independent action an agent may take before a human is required in the loop, with compliance intensity scaled to that tier (Machinebrief):

  1. Human-only decisions — actions an agent may recommend or prepare but not execute without explicit human sign-off.
  2. User-authorized decisions — actions an agent may execute within a scope a user has pre-approved, without a per-action confirmation.
  3. Fully autonomous decisions — actions an agent may take and execute entirely on its own initiative, within its deployed scope.

Obligations scale with the tier: light registration applies to lower-risk agents, while Level 3 (fully autonomous) deployments face pre-deployment review plus quarterly audits (Machinebrief). The compliance burden is a direct function of how much independent authority the agent has been given, not of which industry or application category it sits in.

Autonomy tiers vs. the EU AI Act's risk categories

The clearest way to place China's approach is against the framework most compliance teams already know. The EU AI Act sorts systems into risk categories by use case — a hiring tool, a credit-scoring system, and a biometric identification system each land in a different tier because of what they are used for, regardless of how autonomously they operate. China's model sorts by how much independent decision authority the agent holds, regardless of use case.

Dimension EU AI Act China's Implementation Opinions
Sorting axis Use-case risk category (e.g., employment, credit, biometrics) Decision-authority tier (human-only, user-authorized, fully autonomous)
Applies to AI systems generally, including non-agentic models AI agents specifically, as a distinct regulated category
Obligation trigger Which category the deployment falls into How much autonomous action the agent is granted
High-obligation example High-risk use-case deployments (documentation, human oversight, conformity assessment) Level 3 fully autonomous agents (pre-deployment review, quarterly audits)

Two systems performing the identical task — say, an agent that books appointments — can land in different compliance tiers under China's framework depending on whether it merely recommends a booking (human-only), executes within a pre-approved window (user-authorized), or books and rebooks entirely on its own judgment (fully autonomous). Under the EU AI Act, the same task is more likely to be assessed by what category of decision it affects, largely independent of that autonomy distinction. Neither model is a superset of the other; a multinational compliant with one is not automatically compliant with the other, and a compliance program built around only one axis will have a genuine blind spot in the jurisdiction it didn't design for.

Sector rules: healthcare, transportation, media, public safety

Agents deployed in four sectors — healthcare, transportation, media, and public safety — face mandatory filing, compliance testing, and product-recall provisions under the Implementation Opinions (Machinebrief). This sector list overlaps meaningfully with where organizations are already deploying agentic systems at scale: clinical documentation and triage support, autonomous or driver-assist transportation systems, AI-generated or AI-curated media, and public-safety monitoring or response tools. How this recall provision maps onto the EU AI Act's own corrective-action and withdrawal obligations is a comparison worth doing carefully, sector by sector, rather than assuming the two regimes are structurally interchangeable.

Why an agent-specific framework changes the compliance question

Most AI regulation written before 2026 was built around the generative model as the unit of analysis: what a model was trained on, what it outputs, and what disclosures accompany that output. China's Implementation Opinions instead treat the agent — a system that perceives, remembers, decides, interacts, and executes — as the unit of analysis. That shift has a direct compliance consequence: two organizations running the identical underlying model can face entirely different obligations depending on how much independent decision authority they've configured the agent built on top of it to hold.

This also means compliance work done for model-level regulation does not automatically satisfy agent-level regulation. An organization that has completed a thorough model evaluation and disclosure process under a generative-AI framework has answered "is this model safe and disclosed correctly" — not "how much independent authority has this deployment been given, and does that authority match its registered tier." Those are different questions, and China's framework is built to ask the second one specifically.

What a multinational with China operations should be doing now

For organizations already running or planning to deploy autonomous agents that touch China operations, the practical starting point is a decision-authority audit, not a risk-category audit:

  1. Inventory every agent deployment operating in or reachable from China by the decision authority it currently holds — human-only, user-authorized, or fully autonomous — not by industry vertical alone.
  2. Cross-check each fully autonomous deployment against the four flagged sectors (healthcare, transportation, media, public safety) for mandatory filing exposure.
  3. Map the pre-deployment review and quarterly-audit cadence required for Level 3 deployments against existing internal governance and compliance-reporting cycles, since a quarterly cadence is more frequent than most existing internal AI review cycles.
  4. Do not assume EU AI Act compliance work transfers. The sorting axis is different enough — autonomy tier versus use-case risk — that a deployment compliant under one framework needs a separate assessment under the other; see how to classify a system under the EU AI Act for the contrasting model.
  5. Track implementing guidance as it publishes, since sector-specific filing detail is still being clarified.

What remains unclear as of late August 2026

The Implementation Opinions establish the three-tier structure and the four flagged sectors, but the specific filing formats, testing protocols, and recall procedures for each sector are still being clarified through implementing and sector-specific guidance as of late August 2026. Organizations building compliance programs against this framework now should treat the sector-filing detail above as directional rather than final, and revisit it as clarifying guidance publishes. This sits alongside the site's existing coverage of US state AI laws and the NIST AI RMF as a third, structurally distinct model compliance teams now need to track — this one built around what an agent is authorized to decide, not which category of system it belongs to. It also complements the site's broader AI agent compliance checklist for teams tracking multiple concurrent regimes.

Compliance programs that already map cleanly to the EU AI Act's use-case tiers should not assume that mapping transfers. China's Implementation Opinions ask a different question, and answering it requires a decision-authority inventory most organizations have not yet built — one that starts with autonomy level, not industry vertical, as its first sorting axis.