What happened
China’s national cybersecurity standards-setting body released the third version of its AI security governance framework on Monday, September 15, 2026, during the opening of the country’s annual Cybersecurity Week. The update refines the approach to categorizing AI risks and responding through technical and broader governance measures. While retaining the core risk-based approach of previous versions, the new framework emphasizes people-centered and responsible AI development, stronger risk awareness, and controllable security. The release specifically underscores Beijing’s effort to build consensus on AI safety and strengthen capacity to prevent and address emerging risks, including those posed by AI agents and embodied intelligence. MLex reports that the official statement and the framework document itself are available in Chinese.
On Monday, September 15, 2026, China’s national cybersecurity standards-setting body unveiled the third version of its AI security governance framework. This release coincided with the opening of the country’s annual Cybersecurity Week, highlighting the government's prioritization of AI safety within its broader cybersecurity strategy.
According to MLex, the new framework refines the method for categorizing AI risks and outlines responses through both technical and broader governance measures. It retains the core risk-based approach established in earlier versions but introduces updated emphases on people-centered development and responsible AI practices.
A key distinction in version 3.0 is the explicit focus on 'controllable security' and stronger risk awareness. The framework specifically identifies emerging risks posed by AI agents and embodied intelligence, indicating that regulators are preparing for more autonomous and physically interactive AI systems.
MLex notes that the official statement and the full framework document are currently available in Chinese. The release underscores Beijing’s ongoing effort to build domestic consensus on AI safety and enhance its capacity to prevent and address new types of AI-related risks.
Why it matters
This update signals a maturing regulatory posture in China, shifting from general principles to more specific risk categorization and governance mechanisms. By explicitly addressing AI agents and embodied intelligence, the framework anticipates the next wave of AI deployment, providing a structured path for compliance and safety. For global stakeholders, this clarifies the direction of Chinese AI policy, which may influence international standards and cross-border data or model interactions. The emphasis on 'controllable security' suggests a focus on operational oversight rather than just theoretical safety, potentially impacting how AI systems are deployed in critical infrastructure and consumer applications within China.
The update provides a more granular regulatory structure for AI safety in China, moving beyond high-level principles to specific risk categorization and governance measures. This is significant for companies operating in or with China, as it defines the compliance landscape for AI development and deployment.
By explicitly mentioning AI agents and embodied intelligence, the framework acknowledges the evolving nature of AI technology. This forward-looking approach suggests that Chinese regulators are attempting to stay ahead of technological shifts, which could influence global AI safety standards and best practices.
The emphasis on 'controllable security' implies a focus on operational oversight and risk mitigation in real-world applications. This may lead to stricter requirements for monitoring, auditing, and intervention capabilities in AI systems, particularly those deployed in critical sectors.
As China continues to develop its AI ecosystem, this framework serves as a signal to both domestic and international stakeholders about the country's commitment to balancing innovation with safety. It may also impact cross-border AI collaborations and data flows, as compliance with Chinese standards becomes a key factor for market access.
What to watch next
Monitor for English translations of the framework document to understand specific technical requirements. Watch for guidance from Chinese regulators on how existing AI products must adapt to the new risk categories. Observe whether other nations or international bodies reference this framework in their own policy discussions. Track industry responses from major Chinese AI developers regarding compliance timelines and technical adjustments.
The availability of an official English translation of the framework document will be crucial for international stakeholders to understand the specific technical and governance requirements. Until then, interpretations may vary, creating uncertainty for global companies.
Regulatory guidance on how existing AI products and services must adapt to the new risk categories will be important. Companies may need to conduct internal audits and make technical adjustments to ensure compliance with the updated framework.
Industry responses from major Chinese AI developers and tech companies will provide insight into the practical implications of the framework. Look for statements on compliance timelines, technical challenges, and potential impacts on product development and deployment.
International reactions and potential alignment or divergence with other national AI safety frameworks will be significant. This could influence global AI governance discussions and the development of international standards for AI safety and security.