China's AI agent rules: three tiers of decision authority
China's agent regulation took effect July 15, forcing every AI agent's decisions into three tiers before deployment. Copy the classification, skip the paperwork.
China now has the first national rulebook written specifically for AI agents, and its central requirement is one you should steal. Before an agent is deployed, its decisions have to be sorted into three tiers: what only a human may decide, what the agent may do after asking, and what it may do on its own. You will almost certainly never file anything with a Chinese regulator. You should still write that document for every agent you run, because nobody else is going to make you and the failure mode is expensive.
What actually happened
The Cyberspace Administration of China, the National Development and Reform Commission, and the Ministry of Industry and Information Technology jointly issued the Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents on May 8, 2026. Per Rimon Law's China AI brief, it took effect July 15, 2026.
The framework's first move is definitional. As NYU Shanghai's Research Institute summarizes, it defines an agent as an "intelligent system capable of autonomous perception, memory, decision-making, interaction, and execution" — pulling agents out of the generative-AI bucket China's 2023 rules put them in, on the theory that autonomy creates a different risk class than text generation does.
From there it's differentiated by sector. Agents in healthcare, transportation, media, and public safety face filing requirements, compliance testing, product recall provisions, and dual oversight from both cyberspace and sector regulators. Lower-risk consumer applications lean on platform governance, third-party evaluation, and industry self-regulation. And running underneath all of it: users keep the right to know what the agent decided autonomously, and the final say over it.
Why agent decision tiers matter for your business
Here's what usually happens instead. You give an agent an API key and a prompt that says "handle refunds under $50," and the tier boundary lives in a sentence in a system prompt that one model update can reinterpret. There's no list of what it may never do, no record of what it decided alone, and no place a human sits in the loop except by accident.
The three-tier exercise fixes that for the cost of an afternoon. Take any agent you're about to deploy and write three columns.
Human only. Issuing refunds above a threshold. Deleting records. Sending anything to your whole customer list. Signing, quoting, or committing money. These get no agent access at all — not a guardrail in a prompt, an absent credential.
Agent proposes, human approves. Drafted replies, scheduled changes, inventory adjustments. The control here is a real approval step in the workflow, not a confirmation the agent can be argued out of.
Agent decides alone. Classification, routing, enrichment, summarizing, tagging. Cheap to be wrong about, trivial to reverse.
Then add the part China's framework treats as a right and you should treat as engineering: a log of every tier-three decision the agent made, readable by a human who wasn't in the loop. If you can't produce that log, you don't have three tiers — you have one, and it's the wrong one.
The regulatory read is simpler still. Illinois already mandates third-party AI audits, the EU AI Act's transparency obligations are live, and China has now named agents a distinct regulated class. The shape of the rules is converging on "prove which decisions your agent makes alone." Do that work as architecture now and it's a design decision. Do it in 2027 and it's a compliance project.
Key takeaways
- China's CAC, NDRC, and MIIT issued agent-specific rules on May 8, 2026; they took effect July 15
- Agents are defined as systems with autonomous perception, memory, decision-making, interaction, and execution — a separate class from generative AI
- The core requirement: sort every decision into human-only, requires-user-approval, or agent-autonomous before deployment
- Healthcare, transportation, media, and public safety agents face filing, testing, and recall provisions; consumer apps get lighter platform-level governance
- Run the three-column exercise on your own agents and log every autonomous decision — the enforcement trend across the EU, Illinois, and China points the same direction
We build agents with the boundaries written down first. Which decisions are off-limits, which need a human click, which run unattended — plus the audit trail that proves it. See what we've shipped or bring us an agent you're nervous about.
Sources: NYU Shanghai RITS, Rimon Law China AI Brief.
- #ai-agents
- #ai-governance
- #agent-autonomy
- #regulation
- #automation-strategy
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Samsung: memory shortage runs to 2028. You're last in line.
Samsung says the memory shortage deepens in 2027 and lasts through 2028, with up to 70% of capacity locked into multiyear contracts. Plan hardware around allocation, not price.
Read itOkta buys Permiso: your IdP is the AI agent control plane
Okta is acquiring Permiso Security for about $200M to watch AI agents and machine identities. The lesson isn't buy a tool — it's use the identity provider you already pay for.
Read it