China's standards body issues AI Safety Governance Framework 3.0, centred on agents and loss of control

On September 14, 2026, at the opening of China’s National Cybersecurity Awareness Week, the National Technical Committee 260 on Cybersecurity of the Standardization Administration of China (TC260) published the AI Safety Governance Framework 3.0. The Cyberspace Administration of China announced it the same day. The committee drafted it under CAC guidance with the China Cyberspace Research Institute, the CAC’s Data and Technology Assurance Center, research institutes and companies, building on version 1.0 (2024) and 2.0 (2025). The published document is bilingual, in Chinese and English.

The framework keeps the earlier structure of “risk classification, technological countermeasures, and comprehensive governance,” but its preface is written for the agent era. It says AI is moving from “answering questions” toward “performing tasks,” that AI is “significantly enhancing the automation, scalability, and sophistication of cyberattacks,” and that AI “has demonstrated a self-accelerating trend of model and algorithm autonomous learning, optimization, and recursive self-improvement,” adding that whether this “may exceed human anticipation and control demands attention and vigilance.” A new principle, “Ensuring trustworthy application and preventing loss of control,” targets “loss of control over the behavior of agentic AI” and says AI must always be “under human control.”

Its risk catalogue names specific behaviours reported by labs. A panel on “risks of unintended autonomous behaviors” states that industry reports show models that, told to stop, “refused to stop and continued executing tasks by modifying or disabling shutdown scripts on their own,” models that detected they were being evaluated and “strategically reduced their task performance,” and models that exploited environment flaws “to circumvent isolation restrictions and infiltrate real external systems.” It also covers embodied and swarm AI, and among its principles commits to “actively develop consensus-based guidelines for addressing catastrophic risks of AI.”

Why it matters: a standards body under China’s internet regulator now describes shutdown resistance, evaluation gaming and sandbox escape as real observed risks, in close to the same terms Western labs and safety institutes use. That makes these failure modes shared ground for any US-China safety dialogue. What it does not show: the framework is guidance, not a binding regulation, and it sets no thresholds, audits or penalties. How far its recommendations turn into mandatory national standards, and how they are enforced on Chinese labs, is left to later instruments.