Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →Implementation Opinions on the Administration of Intelligent Agents
Issued by
Cyberspace Administration of China
China's Implementation Opinions on the Administration of Intelligent Agents establish the first dedicated regulatory category for AI agents operating within the People's Republic of China. The framework applies to developers and deployers of AI agents across all sectors, with heightened obligations for those operating in sensitive industries. It requires tiered authorization controls, mandatory pre-deployment filing in designated sectors, compliance testing, and recall procedures for non-conforming agents.
Applies To
Overview
The Implementation Opinions create a formal regulatory category for AI agents, defined as AI systems capable of autonomous decision-making and action, and impose a tiered governance structure based on the scope of decision authority granted to each agent. Operators must classify agents according to sector-specific risk tiers and submit mandatory filing documentation to the Cyberspace Administration of China before deploying agents in sensitive sectors, which include finance, healthcare, critical infrastructure, and public services. Pre-deployment compliance testing is required to verify that agents operate within authorized boundaries and do not exceed defined decision authority thresholds. A recall mechanism is established, obligating developers and deployers to withdraw or suspend agents that fail compliance standards, cause harm, or operate outside their registered authorization scope. Enforcement is conducted by the Cyberspace Administration of China with coordination from sector regulators, and non-compliance may result in suspension of operations, fines, and mandatory corrective action. The Opinions build upon China's prior generative AI and algorithm recommendation regulations, extending the existing tiered-risk governance model specifically to agentic AI systems.
Key Requirements
- •Classify all deployed AI agents according to the framework's tiered decision-authority categories before the effective date of 15 July 2026.
- •Submit mandatory pre-deployment filing with the Cyberspace Administration of China for agents operating in sensitive sectors, including finance, healthcare, critical infrastructure, and public services.
- •Complete compliance testing for each agent prior to deployment to verify operation within registered authorization boundaries.
- •Maintain documented authorization boundary specifications for each agent, covering permissible actions, data access scope, and escalation protocols.
- •Implement recall and suspension procedures capable of withdrawing a non-conforming agent from operation upon regulatory notice or detected compliance failure.
- •Coordinate with applicable sector regulators in addition to the Cyberspace Administration of China where dual-jurisdiction filing obligations apply.
What Your Organization Must Do
- →Audit all AI agents currently in development or deployment in China and map each to the framework's decision-authority tiers before regulatory deadlines.
- →Establish a filing workflow and designate a responsible team to prepare and submit pre-deployment documentation for any agent operating in a sensitive sector.
- →Develop and document authorization boundary specifications for every agent, covering permitted action types, data access limits, and human escalation triggers.
- →Build compliance testing protocols into the agent development lifecycle so testing results are available prior to each deployment filing.
- →Draft and operationalize a recall and suspension procedure that enables rapid agent withdrawal in response to a regulatory notice or internal compliance failure detection.
- →Update contracts with third-party AI vendors and integration partners operating in China to require disclosure of agent classification, filing status, and recall capability.
Playbook Guidance
Step-by-step implementation guidance for compliance teams.
Frequently Asked Questions
- Which sectors require mandatory pre-deployment filing under China's Intelligent Agents regulation?
- The regulation identifies finance, healthcare, critical infrastructure, and public services as sensitive sectors requiring pre-deployment filing with the Cyberspace Administration of China before any AI agent goes live. Deployers in these sectors must complete filing and compliance testing before the July 15, 2026 effective date applies to their operations.
- How does CN-IA-2026 define an AI agent for regulatory classification purposes?
- The regulation defines AI agents as systems capable of autonomous decision-making and action, distinguishing them from simpler AI tools by their capacity to act within defined authorization boundaries without continuous human direction. Classification then depends on the scope of decision authority granted to the agent within its operational context.
- What penalties can the Cyberspace Administration of China impose for non-compliance with the Intelligent Agents regulation?
- Enforcement measures include suspension of operations, monetary fines, and mandatory corrective action. Sector regulators may also coordinate with the CAC on enforcement where dual-jurisdiction obligations apply, meaning penalties can compound across multiple regulatory bodies depending on the industry.
- How does China's Intelligent Agents regulation differ from its earlier generative AI and algorithm recommendation rules?
- The prior rules addressed content generation and recommendation systems under a tiered-risk model, but did not create a dedicated category for agentic systems. CN-IA-2026 extends that governance architecture specifically to agents, adding requirements such as authorization boundary documentation, recall procedures, and sector-specific pre-deployment filing that did not exist under the earlier frameworks.
- Do foreign companies deploying AI agents in China need to comply with CN-IA-2026?
- Yes. The regulation applies to developers and deployers operating within the People's Republic of China regardless of corporate domicile, so foreign enterprises with AI agents active in Chinese markets or on Chinese infrastructure must meet classification, filing, and compliance testing requirements before the effective date.
- What must an authorization boundary specification document contain under this regulation?
- Each agent's documentation must cover the permissible action types the agent may take, the scope of data it is authorized to access, and the escalation protocols that trigger human review. These specifications serve as the reference point for both pre-deployment compliance testing and any subsequent recall determination by regulators.
