What this is
From 2024 to 2026, China's AI Safety Governance Framework released three versions in three years. The regulatory target list swapped protagonists: 1.0 monitored models, data, systems, and outputs; 3.0 now reads "model, Agent, tools, memory, runtime." This shifts governance focus from "whether the answer is right" to "whether execution oversteps authority."
3.0 breaks intelligent agent security into four independent risk categories: identity-permission abuse, reasoning-planning deviation, call-execution overreach, and memory-storage contamination. They share one common trait—most risks are not at the input end. Stack as many layers as you want on pre-filtering, you cannot catch them all. One wrong tool call by an Agent could trigger a data leak, an unauthorized approval, even an irreversible business incident.
The framework also introduces a new concept: AI cognitive supply chain—training corpora, knowledge bases, web pages, search results, tool-returned data, long-term memory. If any link is contaminated, risk propagates along the entire retrieval, reasoning, and execution chain. GEO poisoning (mass-publishing tilted content to pollute AI's web retrieval results) has therefore been officially written into regulatory documents.
Industry view
Supporters argue that the direction of these three consecutive updates aligns closely with OWASP and the international Agent security community's taxonomy. Regulation moving from "content review" to "runtime guardrails" is, in their view, a technical response to the reality of Agent deployment. The introduction of the Fail Closed principle (when the system is abnormal, default to refusing execution rather than permitting it) is read by engineering teams as a critical shift in security defaults from "permissive" to "conservative."
Opposition exists. Many security practitioners we speak with worry the framework's scoping of "high-risk actions" remains too broad—delete, transfer, modify permissions—when filtered down to SMEs, lacking fine-grained judgment criteria. The result may be that only large enterprises build complete processes, while SME AI deployments remain exposed. Other technical teams point out that simply hanging an extra review model is far from sufficient: detection models will false positive and miss; permission boundaries and emergency braking must be enforced by systems, not models—models are suited only for semantic judgment; systems are responsible for braking.
Impact on regular people
For enterprise IT: Before an Agent accesses corporate email, knowledge bases, or APIs, teams must first answer three questions: "what can it call, can it hand off permissions to the next Agent, and who rolls back when it errs." Approval flow design must upgrade from "human reviews content" to "human reviews actions."
For individual workers: When using AI Agents to handle emails, organize materials, and run workflows, start paying attention to "what it has done with my identity." We expect work audit logs to be reviewed before chat records going forward.
For consumer markets: Once AI customer service and AI assistants are widely deployed in high-permission scenarios like banking, government, and healthcare, regulators will mandate secondary confirmation, circuit breakers, and default-deny mechanisms. Ordinary users will increasingly encounter the "popup confirmation before AI acts on your behalf" experience.