The Implementation Guidelines for the Responsible Use and Innovative Development of AI Agents An Overview and International Comparison

I. Legal Nature of the Document: Not a Law, but a Strong Signal of Regulatory Intent

In formal terms, the document resembles a policy-oriented and guidance document rather than a law that directly creates legal liability. In other words, a violation of an individual principle contained in the document will not necessarily, by itself, result in an administrative penalty.

From the perspective of regulatory practice, however, documents of this kind generally serve three purposes:

First, they provide a policy basis for subsequent legislation, departmental rules, national standards, and industry standards. Second, they serve as a reference for regulatory authorities in determining whether an enterprise has fulfilled its obligations regarding safety and security management. Third, they provide a foundation for designing mechanisms such as pilot programs in key industries, filing requirements, testing, assessments, certification, and product recalls.

The document expressly refers to mechanisms including filing, testing, the recall of problematic products, third-party evaluations, mutual recognition of certifications, credit assessments, and mandatory standards. This indicates that it is not merely a broad policy initiative; rather, it is laying the groundwork for the future transformation of “soft law” into “hard law.”

II. Regulatory Focus: From “Model Compliance” to “Conduct Compliance”

Historically, AI compliance in China has primarily focused on several issues: whether training data was obtained and used lawfully, whether generated content was unlawful, whether algorithmic recommendations were transparent, whether deep-synthesis content was properly labeled, and whether personal information was processed lawfully. AI agents introduce a new set of questions: Will an agent make decisions on behalf of a person? Will it operate an account, send messages, place orders, make payments, control or schedule equipment, or access business systems on the user’s behalf? The central legal logic of this document is therefore that the subject of AI-agent regulation is not limited to “output content”; it also includes the agent’s “executive conduct.”

The document requires the clarification of decision-making authority. It calls for clear boundaries among decisions that may only be made by the user personally, decisions that require user authorization, and decisions that an AI agent may make autonomously. It also requires that users retain the right to be informed about autonomous decisions made by AI agents, as well as the right to make the final decision. Any action performed by an AI agent must remain within the scope of the user’s authorization. These requirements align with the rules on automated decision-making under the Personal Information Protection Law of the People’s Republic of China. Where a decision made through automated decision-making has a significant impact on an individual’s rights and interests, the individual has the right to request an explanation and the right to refuse a decision made solely through automated means.

III. The Real Compliance Challenge: An Agent’s “Permissions” Are More Dangerous Than Its “Answers”

When an ordinary chatbot gives an incorrect answer, the principal risk is misinformation. When an AI agent is connected to email, calendars, payment systems, office automation systems, customer relationship management systems, enterprise resource planning systems, medical systems, financial systems, or government service systems, the risk escalates into the possibility of real-world harm.

Enterprises therefore cannot limit compliance measures to content moderation. They must also conduct permission reviews, operational reviews, log audits, outcome reviews, and human verification.

IV. Relationship with Existing AI Regulations: Cumulative Rather Than Substitutive

This document does not exist in isolation. When an AI-agent product is deployed in China, it will generally be subject to multiple regulatory frameworks simultaneously.

Where an AI agent provides text, image, audio, video, or other content-generation services to the public within China, the Interim Measures for the Management of Generative Artificial Intelligence Services may apply. These Measures expressly apply to services that use generative AI technologies to provide generated content to the public within China. They emphasize the equal importance of development and security, law-based governance, inclusive and prudent regulation, and classified and tiered supervision.

Where an AI agent performs functions such as ranking, recommendation, personalized push notifications, scheduling decisions, or content distribution, the Provisions on the Administration of Algorithmic Recommendations in Internet Information Services may also apply. The regulatory objectives of these Provisions include regulating algorithmic recommendation activities, safeguarding national security and the public interest, protecting the lawful rights and interests of citizens and legal persons, and requiring algorithmic recommendation services to operate in accordance with the law.

Where an AI agent generates or synthesizes text, images, audio, video, virtual scenes, or other content, the requirements concerning the labeling of AI-generated and synthetic content must also be considered. The Measures for Labeling AI-Generated and Synthetic Content provide that such labeling includes both explicit and implicit labels. Service providers that conduct activities involving the labeling of generated or synthetic content under the prescribed circumstances are subject to these Measures.

Compliance for AI agents is therefore not a matter of determining whether a single document applies. It requires a combined assessment of multiple factors:

Is the service offered to the public? Does it generate content? Does it involve algorithmic recommendations? Does it involve deep synthesis? Does it process personal information? Does it use automated decision-making? Is it connected to a high-risk industry? Does it involve cross-border data transfers? Does it possess public-opinion attributes or the capacity for social mobilization?

V. Five Institutional Signals That Deserve Particular Attention

1. Classified and Tiered Governance Will Become the Main Regulatory Approach

The document proposes classified and tiered governance of AI agents according to their application scenarios and potential impact. For sensitive fields and key industries, cybersecurity and information authorities may work with the relevant sectoral regulators to determine the scenarios in which AI-agent applications may be permitted and may implement measures such as filing, testing, and the recall of problematic products. In low-risk areas, governance is more likely to rely on compliance self-assessments, information reporting, platform management, and industry self-regulation.

This means that future regulation of AI agents is unlikely to adopt a one-size-fits-all approach. Office assistants, entertainment and companionship agents, shopping assistants, medical-support agents, financial risk-control agents, judicial-support agents, and public-security agents will be subject to significantly different levels of regulatory scrutiny.

2. “Ultimate Human Control” Will Become a Mandatory Requirement

The document requires that users have the right to be informed about autonomous decisions made by AI agents and retain the right to make the final decision. In practical terms, this requires AI-agent systems to preserve mechanisms for human intervention. In sectors such as healthcare, finance, justice, government services, education, employment, insurance, and credit, it will be difficult for enterprises to avoid liability merely by claiming that “the system made the decision automatically.”

In practice, high-risk AI agents should, at a minimum, incorporate the following safeguards: explicit user authorization, secondary confirmation for significant actions, human review, revocable authorization, emergency or abnormal-operation termination mechanisms, operational logs, and complaint or appeal channels.

3. AI-Agent Conduct Must Be “Verifiable and Traceable”

The document proposes exploring the use of blockchain and other technologies to establish mechanisms under which the conduct of AI agents in important application scenarios can be verified and traced. This is highly significant for enterprises. Log retention is no longer merely a technical issue; it is also a matter of establishing a defense against liability and demonstrating regulatory compliance.

4. Supply-Chain Security Will Be Subject to Greater Scrutiny

The document emphasizes security management in areas including model integration, API calls, and the use of extension tools. This means that an enterprise cannot simply argue that it bears no responsibility because the underlying model was supplied by a third party. Where an enterprise combines third-party models, plug-ins, robotic process automation tools, knowledge bases, payment interfaces, and office systems into an AI-agent service, the enterprise, as the deployer or operator, must still assume the corresponding management responsibilities.

Contracts should clearly address the scope of data use, whether data may be used for training, responsibility for outputs, vulnerability-response obligations, log-retention requirements, audit rights, ownership of intellectual property, the relationship between personal information processors and entrusted processors, cross-border data arrangements, and incident-notification obligations.

5. Industry Applications Will Initially Be Opened and Subsequently Tightened

The document identifies potential applications in healthcare, financial services, judicial services, government services, public security, tendering and bidding, education, and other fields. This indicates that the policy does not prohibit AI agents from entering high-risk industries. Instead, it encourages “controlled pilot programs.” However, the more important or sensitive the industry, the more likely it is that subsequent mandatory standards, filing requirements, assessments, certifications, and regulatory inspections will be introduced.

VI. The Legal Pitfalls Enterprises Are Most Likely to Encounter

The first is excessive authorization. For example, a user may merely ask an AI agent to “check my emails,” while the system is granted, by default, full permission to read, forward, and delete emails, download attachments, access contacts, and send external messages. This creates significant personal information protection and data-security risks.

The second is automated decision-making without human review. Where matters involve lending, recruitment, insurance, educational assessment, medical advice, discriminatory pricing, or similar issues, decisions made entirely by AI agents may raise concerns regarding the fairness and transparency of automated decision-making, as well as the individual’s right to an explanation.

The third is the failure to label generated content. In the future, explicit and implicit labeling of AI-generated or synthetic text, images, audio, video, virtual scenes, and other content will become an important area of compliance.

The fourth is using AI agents to circumvent sector-specific licensing requirements. Examples include providing medical diagnoses without the necessary medical qualifications, giving investment advice without the required financial licenses, or guaranteeing the outcome of legal proceedings without the qualifications required to provide legal services. Such conduct may be regarded as operating beyond the permitted business scope, false advertising, or misleading consumers.

The fifth is the use of excessively broad disclaimers. A user agreement stating simply that “AI-generated results are for reference only and the platform assumes no responsibility” does not automatically exempt the platform from its statutory obligations regarding product design, data processing, security safeguards, content governance, and permission controls.

VII. Impact on Different Market Participants

For foundation-model providers, the primary areas of concern are model security, content governance, labeling and watermarking, interface security, filing and assessment requirements, and management of the developer ecosystem.

For AI-agent development platforms, the main priorities are plug-in review, tiered permission management, application-store governance, developer access requirements, the removal of malicious AI agents, and supply-chain audits.

For enterprises deploying AI agents in specific industries, the primary concerns are the legality of the business scenario, human review, industry qualifications, data compliance, log retention, and customer disclosure.

For terminal-device manufacturers, the key issues are local data processing, voice and image collection, the security of device controls, the protection of minors, private or secure spaces, and safeguards against accidental activation.

For government, judicial, medical, and financial institutions, AI agents are more appropriately used as supporting tools and should not directly replace the legally responsible person or institution in making final decisions.

The regulatory logic conveyed by the Implementation Opinions on the Regulated Application and Innovative Development of AI Agents may be summarized as follows: China’s approach to AI agents is not prohibition, but rather “encouraging application, implementing classified regulation, controlling permissions, recording conduct, ensuring traceability of risks, and applying stricter rules in key industries.”

For enterprises, whether an AI-agent product may be launched in compliance with the law depends not only on the strength of the underlying model, but also on six questions:

1. Does the user clearly understand what the AI agent can and cannot do?

2. Does the AI agent act only within the scope of the user’s authorization?

3. Is there a mechanism for final human confirmation where significant rights and interests are involved?

4. Are data, personal information, and sensitive information processed in accordance with the law?

5. Is AI-generated and synthetic content labeled as required by law?

6. Where an error, unauthorized action, infringement, or security incident occurs, can the chain of responsibility be traced?

VIII. International Comparison

From an international perspective, the major economies have adopted different regulatory approaches to AI and AI agents. A common trend, however, is that the focus of regulation is shifting beyond the question of whether the model itself is safe toward questions concerning how an AI system is deployed, whether it can make decisions on behalf of individuals, whether human oversight is maintained, and whether responsibility can be traced. This closely corresponds to the emphasis placed by the Implementation Opinions on the Regulated Application and Innovative Development of AI Agents on permission boundaries, behavioral controls, classified and tiered governance, and traceability mechanisms.

The European Union follows an approach centered on binding legislation. The EU Artificial Intelligence Act is based on risk classification and imposes stricter compliance obligations on high-risk AI systems, with particular emphasis on transparency, human oversight, risk management, and the protection of fundamental rights. In areas such as healthcare, finance, education, employment, and justice, it is not sufficient for an AI system to be merely “technically usable.” The provider or deployer must also demonstrate that its risks are controllable and that responsibility is clearly allocated.

The United States follows an approach that gives greater priority to innovation and standards-based frameworks. Unlike the European Union, the United States has not established a single, unified AI statute. Instead, it relies more heavily on risk-management frameworks issued by institutions such as the National Institute of Standards and Technology, together with sector-specific rules, government procurement requirements, corporate governance mechanisms, and ex post liability. The US model therefore places greater emphasis on whether an enterprise has established mechanisms for testing and evaluation, supply-chain management, data governance, security response, and internal accountability.

The United Kingdom follows a principles-based regulatory approach. It places greater emphasis on existing regulators interpreting and applying AI-governance principles within their respective industries, including safety and robustness, transparency and explainability, fairness, accountability, and access to redress. Rather than immediately adopting a single law governing all AI applications, the United Kingdom places greater importance on proportionate regulation tailored to different application scenarios.

Singapore, Japan, and the G7 Hiroshima AI Process reflect a greater reliance on soft-law governance and international coordination. These mechanisms generally promote the establishment of trustworthy AI systems through guidelines, testing tools, codes of conduct, and risk-management frameworks. Although they may not directly impose mandatory penalties, they influence the compliance standards applied to multinational enterprises, products entering overseas markets, and international cooperation.

The Implementation Opinions on the Regulated Application and Innovative Development of AI Agents reflect a combined regulatory approach. On the one hand, the document encourages the deployment of AI agents in important fields such as healthcare, finance, education, government services, justice, public security, and tendering and bidding. On the other hand, it emphasizes classified and tiered governance, controlled permissions, behavioral records, risk traceability, and stricter supervision in key industries. China is therefore not simply prohibiting the application of AI agents. Rather, it is promoting “controlled pilot programs” and “regulated development.”

The Implementation Opinions on the Regulated Application and Innovative Development of AI Agents may be understood within the broader global trend of AI governance. In the future, the key question in AI-agent compliance will not merely be whether the underlying model is powerful, but whether the enterprise can demonstrate that the AI agent operates in real-world business activities with proper authorization, clearly defined boundaries, effective oversight, adequate logs, mechanisms for accountability, and procedures for correcting errors.

Note: The author is Shanli Zhang. He is a doctoral candidate at the School of Law, Shandong University, and an editorial assistant at Data Economy Review. WeChat: 18811157736. Comments and corrections are welcome.

Leave a Reply

Your email address will not be published. Required fields are marked *