China releases AI Safety Governance Framework 3.0 covering agents and embodied AI
China’s National Technical Committee 260 on Cybersecurity released AI Safety Governance Framework 3.0 at the opening of 2026 National Cybersecurity Week. The Cyberspace Administration of China published the same notice. The 136-page bilingual PDF keeps the risk-classification, technical-responses, and comprehensive-governance structure from versions 1.0 and 2.0 and expands coverage of AI agents, embodied intelligence, and computing infrastructure — including risks of autonomous cyberattacks.
While U.S. labs argue about pacing, Beijing’s standards body shipped an updated national AI safety framework that explicitly catalogs agent autonomy, robot and embodied failure modes, and AI-driven cyber offense. Readers get the primary document, not a rumor about what China “might” do.
China’s National Technical Committee 260 on Cybersecurity, or TC260 — the country’s national cybersecurity standards committee — released 《人工智能安全治理框架3.0》 / AI Safety Governance Framework 3.0 at the opening of 2026 National Cybersecurity Week on 14 Sep 2026. The Cyberspace Administration of China, or CAC — the internet regulator — republished the same notice that evening at 19:40, crediting 全国网安标委, the national cybersecurity standards body. That TC260 publish page, the CAC notice, and the official 136-page PDF are the filing event. This is a standards-body framework — guidance and a risk map — not a new statute this desk can name. This desk did not sit in Jinan.
CAC says Frameworks 1.0 and 2.0 came out in 2024 and 2025. Version 3.0, the notice says, was compiled under CAC guidance with the China Academy of Cyberspace, the CAC data and technology support center, plus labs and industry. File that as CAC’s account of who wrote it. This desk is not listing every contributing lab.
The official PDF cover names “National Technical Committee 260 on Cybersecurity of SAC” and is dated September 2026. SAC is China’s Standardization Administration. The document is bilingual Chinese and English, 136 pages. File the cover names, the date on the cover, and the page count as the PDF’s. This desk did not retypeset the book.
The structure stays “风险分类、技术应对、综合治理” — risk classification, technical responses, and comprehensive governance — the same three-part spine as 1.0 and 2.0, with updated risk classes and adjusted measures, per CAC and the PDF table of contents. File that as the official outline. This is not a claim that every old control was rewritten.
PDF risk chapters, as the document’s §2 lays them out, include endogenous risks — problems inside the system, in models, algorithms, data, compute facilities, and runtime — application risks, including agent safety and embodied intelligence, and derivative risks, including the spread of cyberattack capability and autonomous cyberattack threats. An AI agent here is software that can plan and act, not only chat back an answer. Embodied AI is AI that acts in the physical world — robots, vehicles, machines that move. File those classes as the PDF’s. This desk is not inventing a new incident.
Agent risks the PDF calls out include identity and privilege abuse, planning failures, tool and plugin call risks, and memory-store risks. Embodied risks include sensing, physical action, human-robot interaction, and multi-robot coordination (PDF §2.2). File those named failure modes as the framework’s catalog. This desk did not crash a robot to check them.
Annex 2 is an “Agentic AI risk management framework,” per the PDF table of contents / Appendix 2. File the annex name as printed. It is a risk-management annex, not a license this desk can show.
Principles on the record include “可信应用、防范失控” — trusted use, and prevent loss of control — with explicit attention to agent behavior slipping out of control (PDF §1.5). File those as the document’s words. Loss of control here is a risk the framework names, not a claim a system already escaped.
CGTN’s same-day wrap, as event context only: Cybersecurity Week runs 14–20 Sep 2026 in Jinan, in eastern China’s Shandong Province. The theme ties cybersecurity to the “intelligent era.” Organizers also released 2026 test results for AI-enabled cybersecurity apps and a list of consumer cameras that finished cybersecurity labeling. File those as CGTN’s event notes — not as the framework body.
MLex’s 15 Sep Insight note, a specialist secondary, frames the update as expanding coverage of compute infrastructure, AI agents, and embodied intelligence amid concern about evasion of controls and lower barriers to cyberattacks. File that as MLex’s read. It is not a second official primary.
PRIMARY here: TC260’s 14 Sep 2026 publish page with the PDF attachment — Tier A official record — plus CAC’s same-day notice and the official 136-page bilingual PDF hosted by CAC. CGTN is same-day state-media corroboration of the week and the release. MLex is a 15 Sep specialist secondary. The 3.0 release, the 1.0/2.0 years, the three-part structure, the agent / embodied / compute risk catalog, Annex 2, and the trusted-use / prevent-loss-of-control line are official-document-attributed. NOT claimed: a new statute, fines, a mandatory compliance deadline, that this “bans” frontier models, that U.S. labs endorsed it, that it is the same document as Amodei’s “pace the frontier” essay, that this desk audited every page as a legal instrument, or investment advice. Distinct from the already-filed china-gt-amodei-cold-war, chen-yixin-ai-strategic-rivalry, trump-rejects-ai-guardrails-amodei, and altman-pacing-not-stopping.
RELATED
- China state media calls Amodei’s AI slowdown essay a ‘Cold War playbook,’ Reuters reports
- China spy chief warns AI is a ‘new arena for strategic rivalry,’ SCMP and Bloomberg report
- Trump says the only AI guardrails needed are a ‘High IQ’ president, names Anthropic’s Amodei
- Altman: ‘pacing’ AI does not mean stopping — and labs shouldn’t wait for Congress
Sources
- TC260 — 《人工智能安全治理框架3.0》 publish page
tc260.org.cn
- CAC — 《人工智能安全治理框架3.0》发布
cac.gov.cn
- Official PDF — AI Safety Governance Framework 3.0 (136 pp, bilingual)
cac.gov.cn
- CGTN — China unveils AI security governance framework 3.0
news.cgtn.com
- MLex — China updates AI safety framework to address agent, embodied AI risks
mlex.com
