Dividing AI Agents' "Permitted Actions" into Three Stages: The Details of China's World-First Dedicated Regulations
On July 15th, China's AI agent regulations officially came into effect. This is the world's first framework to treat AI agents (systems that autonomously perform cognitive, memory, judgment, dialogue, and execution) as a separate, independent regulatory category from generative AI. China is the first country to seriously address the challenge of "how to legally define the autonomy of agents," a problem no other country had yet tackled. From an engineer's perspective, let's examine the details of this system.
The Framework of "Implementation Opinions" Jointly Created by Three Ministries
First, let's look at the background of the system. The "Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents" were jointly formulated by three ministries: the National Internet Information Office (CAC), the National Development and Reform Commission (NDRC), and the Ministry of Industry and Information Technology (MIIT). Initially announced on May 8th, it came into effect on July 15th.
Up until now, China's AI regulations have primarily focused on generative AI (models that generate content), emphasizing model registration, content review, and data compliance. This new framework goes a step further, clearly establishing the idea of treating "autonomous AI" as a separate category with qualitatively different risks from generative AI.
The Core: A Three-Tier Classification of Decision-Making Authority
The most technically interesting aspect is the mechanism defined in Article 6 of this regulation. Before deploying an agent, it is mandatory to classify its decision-making authority into the following three stages:
1. Areas where only humans can make decisions
2. Areas requiring user approval
3. Areas where agents may process autonomously
For sensitive areas such as healthcare, transportation, media, and public safety, even stricter obligations are imposed, including registration, compliance testing, and product recall clauses. A policy target of 70% intelligent agent penetration in smart devices by 2027 has also been set.
The Difficulty of "Proof" That Trouble Engineers
This is the point I want to emphasize most this time. The fact that "decisions are categorized into three stages" can be declared in a single policy document. However, the real difficulty lies in proving afterward that the agent actually acted only within the declared stages.
When an auditor later asks, "Which stage did this decision actually fall into?", "Did the user really approve it?", and "What was the agent's basis for their decision?", the answer doesn't exist in the code or the policy document. In practice, this means that audit trails and data lineage must be incorporated from the system design stage. The point that companies trying to retroactively address existing systems risk being burdened with the virtually impossible task of "creating a non-existent past" is spot on.
This is also interesting from a software architecture perspective. It's not enough to simply design "what this agent can do"; you need to incorporate a system from the outset that logs "why that decision was made" and "who approved it" in a verifiable format. This may become an unavoidable design requirement for all companies that will commercially deploy AI agents in the future.
This regulation: Experts are actually divided on its "binding force"
Another point I want to frankly mention is that experts do not agree on the legal weight of this regulation. Several law firms and compliance media outlets explain that this framework will "commence and be enforceable" from July 15th.
On the other hand, a research group at NYU Shanghai and researcher Thorsten Jelinek offer a different view. In Chinese administrative practice, the position of "Opinions" documents is subordinate to binding "Measures" and "Regulations," and they are considered guideline documents that indicate direction and require regulatory authorities to develop future standards and notification systems. Jelinek describes this as "more of a standard-setting step than a regulatory step."
In other words, the meaning of this matter changes considerably depending on whether it is viewed as "already legally binding and in effect" or "a stage where guidelines that will serve as a foundation for future regulatory development have been provided." For Chinese companies operating overseas, this difference in interpretation directly impacts the priority of practical compliance responses.
Another related regulation implemented around the same time
Separately, the "Provisional Measures for the Management of AI Anthropomorphic Interactive Services," targeting conversational services with anthropomorphic AI (agents with emotional interactions, like AI companions), also came into effect on July 15th. This regulation prohibits minors from using virtual companion services, mandates detection and intervention for emotional dependence, and requires disclosure of AI use at the start of a session. The structure of treating AI systems with different uses—work agents and companion AIs—under separate regulations is an interesting design in terms of regulatory sophistication.
What Engineers Should Note
The reason this news is being treated as a technical article is that it has more significance than simply being "another new regulation." It's important to note that this is the world's first instance of imposing extremely implementation-level requirements—"tiered authority" and "post-implementation verifiability"—on AI agents, a new form of software not previously anticipated by law.
There's a strong possibility that this "three-tiered authority" concept will be referenced when the US and Europe create AI agent regulations in the future. For companies deploying agents for the Chinese market, as well as for all engineers designing AI agents globally in the future, the idea of "integrating access control and audit trails from the very beginning of the design process, rather than adding them later," seems to be a perspective that should be kept in mind.