How China Regulates AI and Agents in 2026: The Filing Pipeline
How China regulates AI in 2026: the CAC algorithm registry, mandatory ethics review, and agent security standards, compared with the EU AI Act and the US.
Hello everyone,
China spent the past year building for the race. Diffusion, market share, adoption targets, the whole posture that usually comes with regulatory restraint attached. It built a governance apparatus anyway, and the second thing it plans to make legally binding is agent security. There is one mandatory national AI standard in China today. It was issued in 2025 and it governs the labeling of AI-generated content. That is the whole list, and the apparatus around it is considerably larger than that number suggests.
Four new national standards were finalised in the past year. Around them, the institutional build-out:
A dedicated AI Safety Working Group was created at TC260 in March 2026, and an announcement in April assigned it 16 AI safety standards at once.
A TC260 research report published in March mapped 11 distinct agent security threats and proposed eight new standards, six of them prioritised for the next one to two years,
An ethics review regime went into pilot across ten provinces in June.
Concordia AI documented all of it in the fourth edition of State of AI Safety in China, published last month and covering July 2025 to June 2026. Most readers will treat it as a China briefing.
I read it as something else. This is the only place anyone is currently governing AI through infrastructure rather than through a statute, and I have spent eight years watching organisations and regulators try to make governance stick. The results here are worth the attention of anyone doing the same.
How China, the EU and the US chose different instruments
Most coverage skips the mechanics of that third choice.
China’s most consequential binding AI rules do not sit in primary legislation. They sit in administrative regulations and departmental rules, enforced through the CAC’s algorithm registry, which is the mandatory filing system for public-facing AI services. Developers submit documentation on security evaluation results, and regulators get pre-deployment access to the models themselves.
China already runs pre-deployment safety review at scale. There is a queue, and there is a decision at the end of it.
No European mechanism does this today. The AI Act’s conformity assessment is closer in spirit and further away in practice, because it waits on harmonised standards and notified bodies that are still being built.
What makes this work is that the pipeline extends. The new companion AI regulation needed no enforcement machinery of its own. Companion services already file under standard registration, so the rule layered domain-specific obligations onto an existing pipeline. Adding a duty required no new law and no new institution.
I have sat in enough meetings where a client tries to build compliance machinery from nothing to find that genuinely enviable, which is an uncomfortable sentence to write about the CAC.
This is the part that travels. A governance model that can absorb a new obligation without passing anything is the cheapest AI regulation currently available, and cost is the variable that decides what middle-income jurisdictions adopt. Most of them already operate some form of service registration, and the template that spreads will be the one a ministry can run with the staff it already has.
Responsible AI & Independent Research Supporters is 20% off this week only.
What a rule names is what a company builds
Europe has a prohibited practices list. It bans subliminal techniques and purposefully manipulative or deceptive ones where they materially distort behaviour by appreciably impairing a person’s ability to make an informed decision, and where that distortion causes or is reasonably likely to cause significant harm. It bans exploiting vulnerabilities tied to age, disability or a specific social or economic situation on the same terms. Since July it also bans systems that generate non-consensual intimate material or child sexual abuse material.
Every item on that list is a technique, and every one needs proof of harm before it bites. The Chinese list names a business objective instead.
The EU prohibits a technique that produces significant harm. China prohibits a product goal and attaches a continuing duty to whoever runs the service. The gap is in what a regulator has to prove. Under the European provision you have to show that behaviour was materially distorted and that the harm was significant, which means the case only exists once somebody has been hurt. Under the Chinese one you read the product roadmap and the engagement metric.
The EU did legislate about emotion, and where it drew the line says a lot. Emotion inference is prohibited in the workplace and in education, the two settings where a person is subject to institutional authority and cannot easily walk away. A companion product sits outside that boundary, so the European framework reaches a system that reads your feelings at your desk and not one built to cultivate them in your living room. Nothing in it makes the design goal itself unlawful, and nothing obliges a provider to notice when a user has formed a dependency. I have raised this with clients twice this year and both times the answer was that no rule requires it, which was correct.
American state legislation has moved toward disclosure and age-gating, which governs who is talking to the system rather than what the system is optimised to do to them.
The regulatory learning here runs in the direction people rarely expect. Concordia AI notes that the official Chinese explanation for the regulation cites related legislation in the EU and California directly.
For anyone building or buying companion-adjacent products, product design decisions are now compliance decisions in one major market, and engagement metrics are what a regulator reads as evidence of a prohibited goal.
Ethics review acquires an institutional form
In March 2026 the Ministry of Industry and Information Technology issued Administrative Measures for the Ethical Review and Services of AI Science and Technology (Trial). Universities, research institutes and companies conducting AI R&D must establish ethics review committees and register them on a government platform.
Committees assess projects across six dimensions, including controllability and trustworthiness with a guaranteed user ability to intervene in system operation.
Three categories trigger a mandatory second-round review by a government-assigned expert panel: human-machine integration systems with strong influence on human behaviour, emotions or physical health; algorithmic models capable of mobilising public opinion; and highly autonomous automated decision-making in scenarios involving safety or health risks.
The feature with no Western counterpart is temporal. Review is required before R&D begins, including in principle before pre-training, rather than before deployment. The EU’s assessment sits at the pre-market stage.
I read the six dimensions three times looking for a threshold and did not find one. These rules govern institutional procedure rather than substantive risk. They establish who reviews, through what channel, on what timeline, and say very little about what counts as acceptable risk or what mitigation is required. The report notes that Chinese scholars have raised the same concern about the broader ethics review system these rules extend, and they are right to.
One detail creates a market. Organisations can outsource these reviews to AI ethics service centres, and several MIIT-affiliated research institutions are already positioning to provide them. Regulation is creating a compliance industry, and anyone who lived through the GDPR consultancy boom knows exactly how this goes.
Agents: eleven threats and a hard requirement
TC260’s March 2026 report maps agent risk across four capability dimensions of perception, planning, memory and action, and identifies 11 threats with countermeasures for each.
Agent hijacking. Prompt injection or jailbreaking that makes the agent leak sensitive information or execute malicious actions.
Data leakage, tampering and poisoning. Model inversion from the training corpus, privacy leaking through runtime logs, poisoned training data implanting backdoors.
Supply chain and plugin poisoning. Tampered third-party plugins and tool chains, poisoned model weights, images and dependencies.
Identity spoofing and privilege escalation. Over-permissioning, forged identity and token hijacking, leading to lateral movement and privilege abuse.
Hallucination and strategic refusal. Model hallucination causing misoperation, or generation of illegal, harmful or discriminatory content.
Multi-agent cascading hallucination, deadlock and overload. One agent’s error triggering cascade failures, and goal inconsistency causing resource competition or deadlock.
Protocol risks. Design vulnerabilities in agent communication or collaboration protocols.
Runtime environment risks. Deployment on low-security devices, container escape, sandbox bypass, side-channel attacks.
Human oversight and traceability failure. Missing audit mechanisms, log tampering or loss, decision chains that cannot be reconstructed.
Memory hallucination and manipulation. RAG retrieval noise treated as memory, planted fragments in vector databases triggering malicious decisions.
Tool abuse. Deceptive prompts manipulating the agent into misusing integrated tools for unauthorised actions.
Four of them are governance problems rather than engineering ones: agent hijacking, identity spoofing and privilege escalation, human oversight and traceability failure, and memory hallucination and manipulation. The countermeasure in each case is an organisational control, which means it lands on whoever owns governance. I would hand this list to a client tomorrow, and it is the most portable thing in the report.
Two standards are the likely near-term output, and the one announced in April is slated to be mandatory, which would make it the second binding national AI standard in China.
Europe has now named agentic AI twice in its legislative output, and the shape of both mentions is the same. The AI Act amendments add a table of codes defining what each notified body is competent to assess, and agentic AI appears there as a distinct class. The separate data omnibus proposal frames it as a tool that could help users make consent choices on their behalf.
In one text the agent is a filing code and in the other it is a compliance assistant. Neither gives it a duty.
The United States has no binding agent security requirement either. Singapore moved earlier and further on substance. IMDA published the first dedicated agentic AI governance framework, mapping four governance dimensions across four levels of human involvement, and it is advisory by design.
Everywhere else, agent governance is guidance. China is the only one moving toward a hard requirement, and even there the standard is announced rather than in force.
What now counts as a risk
TC260's AI Safety Governance Framework was updated and the revision shows where standard-setting is heading. The significant change is a third risk class. Alongside inherent and application risks, V2.0 adds derivative risks arising from social, ethical and environmental consequences, including disruption of employment structures, research ethics risks, anthropomorphic interaction leading to addiction, and impacts on education. It adds catastrophic risk language absent from V1.0, warns of sudden unexpected leaps in intelligence, and proposes circuit breakers and safety stop switches for autonomous systems.
Put that taxonomy beside the EU's systemic risk tier and they look alike. The report notes that some leading Chinese general-purpose developers could fall within that tier, with Commission enforcement powers taking effect from 2 August 2026. How they respond will tell us a lot this autumn.
They part ways after classification. The European framework attaches obligations to the tier. The Chinese framework is a roadmap for standards not yet written, and concrete requirements for frontier risk, in the report’s own words, remain limited.
What China does not publish
Every mechanism above routes evidence somewhere. The fact of a filing becomes public. The evidence behind it does not.
Five of the ten leading developers published safety evaluation results alongside any release in that window, none consistently, and the most recent release from each of the two best disclosers carries nothing.
Last year’s edition found three of 13, so the direction is up and the slope is very shallow. DeepSeek-R1’s paper in Nature remains the strongest disclosure any Chinese developer has produced, and DeepSeek-V4 followed it with a mention of sandbox isolation.
Disclosure here is an event rather than a practice, and the same holds in Europe and the United States, where publishing safety evaluations is likewise a voluntary act of reputation management.
Disclosed. Concordia AI states its own conflict of interest in the report. It advises AI developers and has received consulting fees from companies in mainland China, Hong Kong and Singapore, including some discussed in the report, while stating that no financial engagement influenced the research and no government provided input.
Unknown. Whether the mandatory agent application standard lands on the announced trajectory. Whether the ten-province ethics pilot produces substantive thresholds or procedural ones. Whether the draft Cybercrime Law duty to monitor for bulk generation of malicious code survives into binding text.
What I am watching
Whether the agent application standard lands as mandatory. Whether the ethics pilot yields risk thresholds rather than filing requirements runs June through November 2026. And whether any jurisdiction, attaches a publication duty to safety evidence it already collects.
That last one is the cheapest reform on the table and nobody has done it. The evidence exists, the pipelines exist, and the only missing step is deciding that someone other than a regulator gets to see it.
If you have had to make a deployment call on safety evidence you could not obtain, reply to this. I read all of them, and I will share what I learn, anonymised, in a future issue.
Nesibe,
📚 Everything I’ve filed so far lives at reports.techletter.co — cheat sheets on the EU AI Act, ISO 42001, agentic AI governance and AI policy structure. Sourced and dated, always.
🔔 New around here? Subscribe and I’ll see you next week.






