Most AI regulation written so far treats agentic systems as an extension of whatever chatbot or model rules already existed, one more application layer sitting on top of a large language model. China's Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents, jointly issued by the Cyberspace Administration, the NDRC and the Ministry of Industry and Information Technology and enforceable since 15 July, does the opposite. It treats an AI agent - defined as a system capable of autonomous perception, memory, decision-making, interaction and execution - as its own category of digital infrastructure, with its own governance obligations distinct from the model underneath it. NYU Shanghai's Center for Responsible AI notes this is the first time any jurisdiction has systematically regulated agentic AI as infrastructure in its own right, rather than folding it into general AI or platform rules.
Three tiers, decided before deployment, not after something goes wrong
The operative mechanism, per Article 6 of the Opinions, requires every agent's decision authority to be sorted into three categories before it's allowed to operate: decisions only a human may make, decisions that need explicit user approval first, and decisions the agent may carry out entirely on its own. Pebblous's analysis of the framework is blunt about what makes this different from the voluntary "human-in-the-loop" language most Western frameworks use: it isn't a best-practice recommendation an organisation can interpret loosely, it's a pre-deployment classification exercise with the regulator's expectations baked into where the lines fall. The Opinions are explicit that "users retain the right to know and the final right to decide" over anything an agent does autonomously, which puts the burden of proof on the deploying organisation to show its tiering was done honestly, not on a regulator to catch it after the fact.
Sensitive sectors get a second, heavier layer on top of tiering. Agents deployed in finance, healthcare, judicial systems, public safety, transport and energy face mandatory filing, security testing and evaluation, product certification, and - the detail that should concentrate minds fastest - product recall provisions if an agent's behaviour falls outside its declared tier once it's live. Lower-risk consumer applications get to lean more on platform self-governance, which is a meaningfully lighter touch, but the line between "consumer application" and "sensitive sector" is exactly the kind of boundary that regulators tend to interpret more broadly than the companies sitting on the other side of it expected.
Why "we don't operate in China" isn't the exemption it sounds like
The scope question is the one enterprise legal and compliance teams outside China are most likely to get wrong. Coverage of the enforcement date is consistent on this point: the rules reach any AI agent that touches Chinese users, Chinese data, or Chinese market operations, regardless of where the company deploying it is headquartered. A multinational running a single agentic workflow that processes data from a China-based subsidiary, or offers an agent-enabled feature to customers who happen to be in China, is in scope even if the organisation has no meaningful presence there and never intended to be a China-facing AI business. That's a familiar shape for anyone who has already built compliance programmes around GDPR's extraterritorial reach, but it's a newer and less anticipated wrinkle for teams whose AI governance work has so far assumed jurisdiction follows headquarters.
It also lands three months after China's separate rules on anthropomorphic, companion-style AI took effect on the same 15 July date, which we covered when they were announced. Read together, the two frameworks describe a regulator working through agentic AI's different failure modes in sequence: companion-style anthropomorphic interaction first, now decision-making authority and autonomous execution. Enterprises that treated the companion rules as a narrow carve-out limited to consumer chatbots should revisit that assumption, because the agent tiering rules are the second half of the same regulatory programme, and they apply to workplace and enterprise agents that the companion rules explicitly exempted.
What this means if you're not a China-facing business at all
Even organisations with genuinely zero China exposure have a reason to pay attention here, and it isn't a compliance one. The three-tier model China has now made mandatory - human-only, approval-required, autonomous - is close to the same architecture the Five Eyes' joint agentic AI guidance recommends on a voluntary basis, which we wrote about earlier this month. When a major regulator and a coalition of national cybersecurity agencies converge independently on the same three-way split for agent decision authority, that's a reasonably strong signal about where the rest of the regulatory landscape is heading, whether the mechanism arrives as a binding filing requirement or as guidance your customers and insurers start asking about anyway. Building that tiering discipline into your agentic AI architecture now, before any regulator with jurisdiction over you requires it, is cheaper than retrofitting it under a compliance deadline.
- Map every agentic AI deployment against Chinese user, data or market touchpoints, including through subsidiaries and partner integrations, not just direct China operations.
- Adopt a three-tier decision classification - human-only, approval-required, autonomous - for your own agentic systems regardless of whether Chinese jurisdiction currently applies, given its convergence with the Five Eyes guidance.
- Treat any agent operating in finance, healthcare, transport, energy or public safety as requiring the heavier compliance path by default, and build filing and testing evidence into the deployment process rather than assembling it after a regulator asks.
- Revisit any assumption that China's AI companion rules were a narrow, consumer-only carve-out - the agent tiering rules explicitly cover the workplace and enterprise agents the companion rules exempted.
Regulators rarely converge on the same architecture by accident, and two independent frameworks landing on a three-way split for agent decision authority within a few months of each other is worth treating as a design specification, not a regional compliance footnote. If you'd like help mapping your agentic AI estate against tiered decision authority before a regulator, customer or insurer asks you to, email sales@halfteck.com.