Two days ago, on July 15, 2026, China’s Cyberspace Administration (CAC), together with the National Development and Reform Commission (NDRC) and the Ministry of Industry and Information Technology (MIIT), brought into force a document that no other country has produced: a dedicated national policy framework for AI agents.
The regulation is titled “Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents.” It does not borrow language from existing AI model regulations or repurpose general software rules. It treats agentic AI as a distinct category of digital infrastructure, with its own governance logic, its own compliance obligations, and its own definition of what an AI agent actually is.
For business leaders building or deploying AI agents, this is worth paying close attention to. China often drafts the first version of a regulatory framework that the rest of the world adapts over the following years. The EU AI Act is the obvious precedent: it began as one jurisdiction’s rulebook and became the default compliance template for global companies operating in European markets. The Implementation Opinions could follow the same trajectory for agentic AI.
What the Regulation Actually Says
The CAC’s definition of an intelligent agent is precise: an autonomous system capable of perception, memory, decision-making, interaction, and execution. That is a broader definition than most enterprises currently work with. A customer service chatbot that routes tickets falls inside this definition. So does a data pipeline agent that triggers actions based on business rules. The regulation is not just about advanced autonomous systems. It covers any AI component that perceives, decides, and executes without a human approving each step.
The centerpiece of the framework is a three-tier decision authorization model.
Tier One: User-owned decisions. Some actions remain fully in the user’s hands regardless of what the agent recommends. The regulation does not specify an exhaustive list, but the principle is that certain categories of consequential decisions should require explicit human initiation, not just a default approval flow.
Tier Two: Agent actions requiring user authorization. For a defined scope of tasks, the agent can propose or prepare, but must receive active user sign-off before executing. This is the middle tier: the agent takes on complexity and reduces human effort, but the human retains clear checkpoint authority at the moment of action.
Tier Three: Autonomous agent decisions. A bounded set of actions can be taken by the agent alone, within limits the user has already set. These are the repetitive, well-understood, low-consequence tasks where requiring human approval on every step creates more friction than value.
The document is explicit that users retain “final decision-making power” in all cases and that agents “cannot act beyond the scope authorized by the user.” That framing matters. Agentic AI in the enterprise context is not being treated as an autonomous actor with independent authority. It is being treated as a delegated system operating within boundaries its principals set.
Sector-Specific Compliance
The framework is not flat. It applies different levels of obligation based on industry risk.
In high-risk sectors, specifically healthcare, transportation, media, and public safety, operators must complete mandatory filing, pass compliance testing, and have product recall procedures in place before deploying agent systems. These are the areas where an agent making a wrong autonomous call carries the most direct harm potential.
In lower-risk fields, including general office productivity and entertainment, the framework relies on operator self-assessment and industry self-regulation. There is no mandatory filing. Compliance is expected but not gate-checked by a regulator before deployment.
In total, the regulation identifies nineteen priority sectors where its provisions apply. That list covers most of what enterprise AI is actually being deployed to do in 2026: finance, logistics, legal services, manufacturing, customer service, and human resources all feature.
What This Framework Signals About the Direction of AI Governance
The most consequential aspect of this regulation is not any single provision. It is that agentic AI is now a distinct regulatory category in the world’s second-largest economy.
Until now, AI agents have mostly been governed indirectly: through existing software liability rules, data protection laws, or the general provisions of regulations like the EU AI Act and China’s earlier generative AI rules. The Implementation Opinions change that. They treat an AI agent, a system that autonomously perceives, decides, and executes, as a fundamentally different kind of digital actor than a model or a software tool.
That framing will spread. The EU AI Act’s next implementation phase, currently scheduled for August 2, 2026, is already grappling with how to handle agentic systems under its risk categorization framework. US state-level proposals in Illinois and Colorado are moving in the same direction. The three-tier decision authorization model is clear, logical, and easy for other regulators to adapt.
What This Means for Business
If you are building AI agent products, start mapping your architecture against the three-tier framework now, even if you do not operate in China. Structurally designing agents with explicit authorization tiers makes them easier to govern, easier to explain to enterprise customers, and easier to adapt as similar rules emerge in other markets. The companies that wait for their home jurisdiction to mandate this will be retrofitting.
If you are procuring AI agent platforms, ask vendors how they handle decision authorization. The companies that can clearly articulate what their agents do autonomously, what requires user approval, and what stays with the human are the companies that have thought seriously about governance. That is a meaningful quality signal beyond features and benchmarks.
If you operate in any of the nineteen covered sectors, the July 15 enforcement date is live. Healthcare, finance, logistics, transportation, media, legal, manufacturing, HR: if your AI agents are in any of these categories and you have operations in China or are building products for Chinese markets, filing and testing obligations are active.
If you are thinking about AI strategy more broadly, file this regulation in the same folder as the EU AI Act and US state AI laws. The compliance landscape for agentic AI is fragmenting fast, and each jurisdiction is writing its own rules independently. A tiered governance architecture designed for one market will likely satisfy most of the others. The principles are converging even as the specific requirements diverge.
The businesses that come out of this regulatory moment in the best position will be the ones that build agent governance into their architecture now, not the ones that treat compliance as something to bolt on when regulators force the issue.
Enterprise DNA’s Omni services are designed around exactly this kind of structured, accountable deployment: AI agents that operate within defined boundaries, with clear human oversight built into the design. If you want to understand how to deploy AI agents that will hold up under this regulatory environment, talk to our team.
Free Resource
Going deeper with Claude?
Get the free 32-page implementation guide for ANZ teams.
Your guide is ready
Check your downloads folder. If it did not open automatically, use the button below.
Download the GuideWant this working inside your business?
See what's possible