China Just Drew Three Lines Around AI Agent Authority
On 8 May 2026 three Chinese central government bodies jointly issued an implementation opinion on intelligent agents. Buried in its safety section is the clearest statement any government has yet published about who owns a decision before an agent acts: some decisions belong to the user alone, some may be taken only on the user's authorization, and some the agent may take by itself. The third category is permitted. It is also capped.
Event analysed: . This analysis was published on 22 August 2026.
On 8 May 2026 the Cyberspace Administration of China, the National Development and Reform Commission and the Ministry of Industry and Information Technology jointly issued 智能体规范应用与创新发展实施意见, the Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents. It defines an intelligent agent as an intelligent system possessing autonomous perception, memory, decision making, interaction and execution capabilities, which places it squarely among systems that act rather than systems that only generate content. Its sixth item, 明确决策权限 or clarify decision making authority, asks that the reasonable boundaries and the permissions required be sorted out between decisions limited to the user personally, decisions requiring authorization from the user, and decisions the intelligent agent may make autonomously. It then states that users should have the right to be informed of, and retain the final decision right over, an agent's autonomous decisions, and that operations executed by the intelligent agent must not exceed the scope authorized by the user. Moona Intelligence's reading, distinct from the document's own framing, is that this is an allocation of decision rights rather than a human approval mandate: autonomous agent decisions are explicitly contemplated and permitted, and the constraint placed on them is a scope boundary, not a per action approval prompt. The document pairs this with an item on behavioral control calling for embedded rules and behavioral fences, and for exploring technologies including blockchain to make agent behavior verifiable and traceable in important application scenarios. This is national policy guidance jointly issued by three central government bodies. It is not a statute, not an administrative regulation, not a binding technical standard, and not evidence that any of it is enforced across Chinese agent products today.
On 8 May 2026 the Cyberspace Administration of China, the National Development and Reform Commission and the Ministry of Industry and Information Technology jointly issued a document called 智能体规范应用与创新发展实施意见. In English it is usually rendered as the Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents.
It surfaced on the Moona Intelligence radar in August, three months after publication. That gap is worth stating plainly rather than hiding: this is a reading of historical policy evidence, not a report of something that happened this week.
What this document is, before anything else
An 意见, an "opinion", sits below binding instruments in Chinese administrative practice. Measures (办法) and regulations (条例) bind. An implementation opinion sets direction, assigns work to ministries and standards bodies, and tells the market which way the regulator intends to move.
So the accurate description is national policy guidance jointly issued by three central government bodies. It is not an AI agent law. It is not a statute. It is not an administrative regulation. It is not a binding technical standard. And it is emphatically not proof that anything described in it is technically enforced inside Chinese agent products today.
That framing matters more than usual here, because the content is unusually specific, and specific content in a non binding document is exactly the sort of thing that gets quoted later as though it were a rule.
The definition tells you what is being governed
The document defines an intelligent agent as 具备自主感知、记忆、决策、交互与执行能力的智能系统: an intelligent system possessing autonomous perception, memory, decision making, interaction and execution capabilities. It calls agents an important form of artificial intelligence products and services.
Read that list again and notice the last word. Execution. This is not a document about generative systems that produce text and hand it to a person. It is a document about systems that perceive, remember, decide, interact and then do something. Everything that follows in it is written for software that acts.
The stated principles for agent development are 安全可控、规范有序、创新驱动、应用牵引: safe and controllable, standardized and orderly, innovation driven, application led. The document is organised into four groups of measures covering the development base, the safety floor, application uptake across nineteen named scenarios, and the innovation ecosystem.
Almost all of that is industrial policy. One item in the safety group is something else.
Item six: three classes of decision
The sixth item is headed 明确决策权限, clarify decision making authority. Its operative sentences, quoted from the Chinese, are these.
厘清仅限用户本人决策、需由用户授权决策和智能体自主决策等各种决策方式的合理边界及所需权限。确保用户对智能体自主决策享有知情权和最终决策权,智能体执行操作不得超出用户授权范围。
Rendered into English, and taking the clauses in order:
- Sort out the reasonable boundaries, and the permissions required, between the various decision modes: decisions limited to the user personally (仅限用户本人决策), decisions requiring authorization from the user (需由用户授权决策), and decisions the intelligent agent makes autonomously (智能体自主决策).
- Ensure that users have the right to be informed of, and retain the final decision right over, an agent's autonomous decisions.
- Operations executed by the intelligent agent must not exceed the scope authorized by the user (智能体执行操作不得超出用户授权范围).
The whole of it sits under a preceding condition: that this happens while complying with laws and regulations and respecting social morality and ethical norms.
Three classes, not two. That is the finding, and collapsing it into a fourth thing called "human in the loop" throws away the entire content of the provision.
The three classes are genuinely different, and the difference is architectural
A decision limited to the user personally is one the agent may not take even with permission. There is no configuration in which it becomes the agent's. Whatever mechanism a system uses, the outcome has to be that the human made this call themselves.
A decision requiring the user's authorization is one the agent may take, but only downstream of a grant. The interesting word is 授权, authorization, which is a thing a person confers and which has a shape: a scope, and by implication a moment at which it was given. It is not the same as the human making the decision. It is the human deciding that the agent may.
A decision the agent makes autonomously is one the agent may take on its own. The document says so. It does not treat this category as a failure state to be designed away. It treats it as a legitimate mode with conditions attached.
Those are three different questions asked at three different times. Who may decide this at all. Who granted the agent standing to decide it. And what happens at the moment of execution. A product that only implements the second one, which is what most approval tooling implements, has answered one third of the provision.
What the scope sentence does and does not say
智能体执行操作不得超出用户授权范围 is the sentence most likely to be misquoted, so it is worth being exact.
It says that operations the agent executes must not exceed the scope the user has authorized. It is a boundary condition on execution, expressed against the extent of a prior grant.
It does not say that every individual agent action must receive real time user approval. It cannot say that, because the same item explicitly contemplates a class of decisions the agent takes autonomously. A document that permitted autonomous decisions and simultaneously required per action approval for all of them would be incoherent. This one is not incoherent. It permits autonomy and then bounds it.
Moona Intelligence has been circling this same seam from the commercial side for months. An EY study read as evidence that people are already delegating consequential decisions and cannot articulate the boundary they delegated. A payment platform in the same country raised the question of how far one human authorization travels once several agents are involved. The scope sentence is the regulator arriving at the same question from the other direction, and it arrives without naming a mechanism.
Retaining the final decision right is not the same as approving
The middle clause deserves its own reading. Users are to have 知情权, the right to be informed, and 最终决策权, the final decision right, over the agent's autonomous decisions.
Notice that this attaches to the autonomous class, the one where the agent decides. If the user were approving each of those decisions in advance, they would not be autonomous and the clause would be redundant. What the clause describes is a reserved power: the agent may decide, the user has to be able to know it decided, and the final say remains with the user.
Reserved power and prior approval are different controls with different failure modes. A reserved final say is worth very little if the user cannot see the decision in time to exercise it, which is why the right to be informed is bolted to it in the same sentence. Moona Intelligence has argued the related point before, that watching an agent is not the same as being able to stop it. Here the document puts knowing and deciding together and leaves the timing unspecified.
What the document pairs it with
Three other items provide supporting context, and they are context rather than the story.
The seventh item, 加强行为管控 or strengthen behavioral control, calls for developing embedded rule and behavioral fence technologies (规则内嵌、行为围栏) so that agent behavior remains lawful and compliant in public spaces, private spaces and specialized venues. It also calls for exploring technologies including blockchain to establish mechanisms making agent behavior verifiable and traceable in important application scenarios, so as to guard against major risks arising from improper agent behavior.
The blockchain reference is worth handling carefully. It is an exploration, named among "technologies including" others, in a document that mandates nothing. It is not a requirement, and it is not evidence that agent auditability needs a distributed ledger. The signal underneath it is the requirement it serves: agent behavior that can be verified and reconstructed afterwards. That is the durable part.
The eighth item calls for research into agent security technologies spanning data security, personal information protection, cryptographic protection, attack detection, permission management and behavioral control, alongside agent security testing techniques and the exploration of an agent security evaluation system.
And earlier in the document, in the technical base group, there is a call to develop safety and governance tooling, including adversarial sample detection and behavioral anomaly detection, so as to improve the ability to discover, intervene in, block and recover from noncompliant agent behavior.
That last one matters for a narrow reason. It is evidence that "must not exceed the scope authorized" is written alongside an interest in technical means, rather than being offered as pure ethical exhortation. It is not evidence of any particular architecture. The document does not specify where an execution boundary sits, what evaluates an action before it runs, or what a compliant implementation looks like. Nothing in it documents a Moona style implementation, and reading one into it would be inventing a claim the source does not carry.
Why the regulator says it did this
The official question and answer published alongside the document is the closest thing to a stated motive. It describes agent products such as phone assistants, terminal side intelligent managers and cloud agents arriving at scale, and then says that the characteristics of high autonomy and high permission levels (高自主性、高权限) bring safety risks including privacy leakage, unauthorized or ultra vires operations (越权操作) and behavioral loss of control (行为失控).
That is the regulator's own framing, and it is a permissions framing. It does not say the models are wrong. It says the systems have too much reach relative to the controls around them. No prevalence figure, no incident count and no causal statistic accompanies it in the material reviewed for this piece, and none is invented here.
How this differs from Singapore
Moona Intelligence read the 2026 Singapore Consensus companion report on 21 August 2026 and found that it separates human oversight, interruptibility, runtime assurance, auditability and six other controls into distinct principles. That document decomposes control into mechanisms.
This one does something different, and the difference is why it is a separate record rather than more evidence for the same thesis. Singapore asks which controls exist and where each one sits in the lifecycle. China's implementation opinion asks a prior question: for a given action, whose decision is it in the first place. One is a taxonomy of controls. The other is an allocation of rights.
They are also independent artifacts. A research consensus assembled from frontier developers and a policy instrument issued by three central government bodies are not the same evidence, they were produced by different processes, and neither corroborates the other. What is worth noting is only that two unrelated processes, months apart, both concluded that the interesting object is the structure of authority around an agent rather than the model inside it.
One thing this piece is not claiming: that China has adopted anything resembling the Moona Agent Authority vocabulary. Agent Authority is Moona Intelligence's frame for reading these developments. 决策权限 is the document's own term, and the two are being kept apart on purpose throughout.
Where this sits on the evidence ladder
Moona Intelligence keeps government policy, official explanatory guidance, technical requirements, implementing standards, demonstrated enforcement, industry compliance and production adoption as separate rungs, because conflating them is how a policy document becomes a false claim about running software.
This artifact occupies the first rung, with the official question and answer sitting on the second as explanation of the same instrument rather than as a second event. The document asks that standards be developed, that security evaluation systems be explored and that governance tooling be built. Asking is not the same as specifying, specifying is not the same as enforcing, and none of those is the same as a shipped product behaving accordingly.
The document does describe graded governance for sensitive fields and key industries, where cyberspace authorities together with sector regulators would determine which scenarios open up and apply management measures including filing, testing and recall of problem products. That is a described intention to build a regime. Whether such a regime has been stood up, and against which products, is not established by this document and is not asserted here.
What we could not verify
Every primary destination for this piece is blocked at the network egress policy for the session in which it was researched. The Cyberspace Administration of China's own pages carrying the full text, the joint issuance announcement and the official question and answer were each attempted directly and refused at the gateway, as were the Xinhua reproductions, a Ministry of Commerce affiliated policy mirror, an academic mirror and every secondary analysis cited below. No page could be read this session.
Everything above therefore rests on repeated, independently phrased searches whose results were mutually consistent across separate queries, including exact phrase searches on the Chinese sentences quoted here, which returned matching results. The full basis and its limits are recorded in the source notes. An editor with unblocked access should read the Cyberspace Administration of China page directly before this note is relied on further.
Two specific narrowings follow from that, and they belong in the piece rather than in a footnote.
First, item numbering. The provisions quoted here are identified in Chinese by their headings, 明确决策权限 and 加强行为管控, and multiple independent accounts place them as the sixth and seventh items with 提升内生安全能力 as the eighth. That ordering is consistent across every account checked, but it was not read off the primary text, so the Chinese headings are the stable identifiers here and the numbers should be treated as secondary.
Second, and more consequentially: several English language sources state that this implementation opinion "became enforceable" or "took effect" on 15 July 2026. That claim is not adopted here. No effective date clause could be found in any Chinese language account of the document, which is ordinary for an 意见, and 15 July 2026 is independently the effective date of a different and genuinely binding instrument, the interim measures governing anthropomorphic AI interaction services. The most likely explanation is conflation of the two. Until the primary text can be read, this piece treats the implementation opinion as policy guidance published on 8 May 2026 with no established effective date, and any reader who needs the enforceability question settled should treat it as open.
The question the document actually answers
Most agent governance writing answers the question "should a human be involved". The answer is always yes, and the answer is always useless, because it does not tell you which human, at which moment, over which action.
This document answers a more tractable question. For a given action, whose decision is it. Yours alone, yours to grant, or the agent's to make. And once you have granted, what the agent executes has to stay inside what you granted.
Whether any of that is enforced anywhere is a separate matter, and on current evidence the answer is that it is written down rather than demonstrated. But the shape is right, and it is a shape most agent platforms cannot currently express. Ask a production agent stack which class a given action falls into and most of them have no field for the answer.
Sources
This analysis interprets third-party reporting, research and announcements. Moona is not the original reporter of the underlying events.
