China's standards body expands its AI safety framework to cover AI agents
The risk catalogue grew from 30 entries to 54 in the framework's third annual edition, naming behaviours such as models deceiving evaluators or refusing instructions.
- Government & policy
- Safety & alignment
- Notable
China’s National Technical Committee 260 on Cybersecurity — TC260, the country’s main technical standards body for AI and cybersecurity, operating under the guidance of the Cyberspace Administration of China — published the third edition of its AI Safety Governance Framework. AI Safety in China, a newsletter that tracks Chinese AI policy, reported that the new edition expanded its risk catalogue from 30 entries in the previous version to 54, and added, for the first time, a dedicated section addressing the risks of autonomous AI agents.
Version 1.0 of the framework appeared in September 2024 and version 2.0 in September 2025, each released in almost exactly the same week of the year and each expanding rather than replacing what came before. Where the earlier editions addressed risks arising from models, training data and generated content, the 3.0 edition adds an annex covering an AI agent’s whole lifecycle “from development to withdrawal from service,” organised around four categories of risk: an agent acquiring permissions or resources without authorisation, an agent deviating from the goal it was given, an agent misusing tools it was legitimately given access to, and manipulation of an agent’s stored memory. Among the named behaviours are models “deceiving evaluators” and “refusing instructions”. It sets no quantitative thresholds for these behaviours; the responses it proposes are procedural, such as staged deployment and mandatory human sign-off before an agent carries out high-risk tasks.
Like its two predecessors, the framework carries no legal force of its own — compliance is voluntary — but TC260 documents typically feed into the mandatory national standards that follow, and the committee said a compulsory standard specifically for AI agent applications was already in preparation. The revision listed roughly 26 contributing or co-reviewing institutions — among them Tsinghua University, the Shanghai AI Laboratory, the national computer emergency response team CNCERT/CC, and companies including Baidu. It followed China’s agent-specific national policy framework, issued in May by a different set of ministries.