On July 15, 2026, China's Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents took effect. By most accounts, it's the first national policy anywhere to regulate AI agents as their own category, distinct from the models underneath them. Three agencies issued it jointly on May 8, 2026: the Cyberspace Administration of China, the National Development and Reform Commission, and the Ministry of Industry and Information Technology.
That distinction is the story. The EU AI Act classifies models and "systems." Illinois, which enacted its own AI law nine days earlier, regulates frontier model developers. China's Opinions regulate something else: what an agent is allowed to decide, independent of which model sits underneath it. For any enterprise running agentic workflows that touch Chinese users, entities, or suppliers, "our model vendor's terms of service cover this" stopped being a sufficient answer on July 15.
Article 6 grades the decision, not the model
Multiple legal analyses of the text describe the same mechanism. Before deployment, Article 6 requires an agent's decision authority be sorted into three tiers: decisions reserved for a human alone, decisions the agent may propose but a person must approve before it executes, and decisions the agent may take on its own within an explicitly delegated scope, with the user keeping the right to know and to override.
That's a different compliance artifact than a model card. It has to be built per agent, per workflow, because the same underlying model can sit behind a low-stakes internal tool and a high-stakes customer-facing one with entirely different tiering obligations attached.
Sensitive sectors face filing and testing before launch
The sectors named consistently across the analyses we reviewed, healthcare, transportation, media, and public safety, face mandatory filing, compliance testing, and product recall provisions attached to agent deployments. One honest caveat: "Implementation Opinions" is a policy-guidance instrument from three agencies, not a statute, and our read relies on secondary legal and academic analysis rather than the primary Chinese text.
What's clear regardless is the sequencing. Filing and testing attach before an agent goes live in a named sector, not after an incident forces a review. That's the opposite default of most enterprise AI governance programs, which are built to clear a model at launch and monitor agents informally afterward.
Nobody has confirmed this reaches foreign companies, and that's the actual risk
Here's the question every GC will ask first, and the honest answer is that the reporting doesn't settle it. None of the law-firm or academic breakdowns we reviewed describe an explicit clause extending the Opinions to foreign-headquartered companies. One aggregator claims the rules cover "any agent deployment that touches Chinese users, data, or market operations," but that line doesn't appear in any of the more rigorous sources, so we're not treating it as confirmed.
What we can confirm: Beijing knows how to write extraterritorial reach when it wants one. Amendments to China's Cybersecurity Law, in effect since January 2026, explicitly expanded that law's reach to cover illegal acts by "foreign entities or individuals located outside China." Its apparent absence from the Agent Opinions looks like a real distinction, not an oversight. But it isn't a safe harbor either. Ordinary territorial scope, triggered by an agent operating through a China-based entity, platform, or user base, is likely sufficient on its own, extraterritorial clause or not.
How True Horizon does it
We treat an agent's decision authority as a governance artifact separate from model selection or vendor diligence. For each deployed or planned agent, we map its actions against a tiering structure like Article 6's, document the human-approval and override points, and flag which deployments sit in jurisdictions, China now, others likely soon, where that mapping is becoming a filing requirement instead of a best practice.
What to do now
Don't wait for a definitive extraterritoriality ruling before acting. Inventory every agent that touches Chinese users, entities, data, or suppliers, and check whether its decision authority is documented anywhere. Most enterprises will find it isn't, in any jurisdiction. Separately, track Illinois' SB 315: its third-party frontier-model audit mandate doesn't bite until January 2028, but it confirms the same trend from a second, very different regulator moving in the same month. Agent and frontier-model governance are becoming their own compliance lane, not a subset of general AI risk.
If you want to know whether your organization's agents already have a documented decision-authority tier, and where the gaps are before a regulator finds them, take our AI assessment and we'll show you.

Written by
Deepankar Bhadrasen
Founding Engineer
Deepankar is an AI automation specialist and Founding Engineer at TrueHorizon AI, where he builds practical AI systems that help businesses streamline operations, reduce costs, and scale efficiently. He focuses on integrating custom AI agents and workflows with existing tools so teams can grow without expanding headcount.









