MacroA-sharesKey event

China Releases AI Safety Governance Framework 3.0 to Strengthen Agent Risk Controls

Published: Updated: By 24TopNews Editorial Desk

China's National Technical Committee 260 on Cybersecurity released the AI Safety Governance Framework 3.0 on September 14, 2026, updating risk classifications, technical responses, and governance measures for artificial intelligence. The framework addresses risks across the full lifecycle of AI agents, including model outputs, applications, data, identity, and execution permissions, as large models increasingly connect to enterprise knowledge bases, databases, business systems, and APIs.

Large AI models are gradually moving from information-processing tools into enterprise production, research and development, office work, and business decision-making. Several international large-model companies have disclosed information about their models in cybersecurity testing and actual malicious use. OpenAI disclosed related security incidents, and Anthropic published a threat intelligence report covering AI abuse. As AI agents develop, related security issues involve the model output layer, applications, data, identity, and execution permissions, including which tools a model can invoke, which data it can access, which systems it can connect to, how much execution authority it receives, and whether deviations from preset objectives during actual execution can be detected and blocked in time.

After enterprises connect large models to internal knowledge bases, databases, business systems, and various APIs, the links between AI and traditional IT infrastructure deepen. Once connected to an enterprise knowledge base, a large model can invoke internal information; once connected to business systems, it can execute related tasks; and as it develops into an AI agent, it can autonomously plan steps, invoke tools, and execute continuously according to task objectives. Security issues at the model level involve prompt injection, jailbreaking, model theft, training data poisoning, and malicious input. At the application level, connecting large models with plug-ins, APIs, knowledge bases, and business systems introduces new interface and permission risks. At the execution level, as AI agents gain stronger operational capabilities, the security chain involves identity authentication, permission control, behavior auditing, and anomaly interception.

The outline of the 15th Five-Year Plan explicitly calls for comprehensively implementing the AI Plus initiative, improving the safety regulatory framework for new technologies and new business forms, refining relevant laws, regulations, policies, application standards, and ethical guidelines in the AI field, improving systems for algorithm filing, transparency management, and security assessment, and promoting the establishment of a full-lifecycle risk management system for AI, forming a risk prevention and control system covering security monitoring, risk early warning, and emergency response.

On September 14, 2026, the National Technical Committee 260 on Cybersecurity released the AI Safety Governance Framework 3.0. Focusing on new trends brought by AI development and new challenges in safety governance, it updates risk classifications, technical responses, and comprehensive governance measures, further improving the AI safety governance system.

24TOPNEWS IMPACT INTELLIGENCE

Why this event matters

The event has a measured impact on 6 industrys. The strongest current signal is positive for Artificial Intelligence, with intensity 82/100 and 78% confidence over a medium term horizon.

Technology · 10.4

Artificial Intelligence

Direction
positive
Intensity
82
Confidence
78%
Horizon
Medium term
Effective impact +50
Technology · 10.7

Enterprise Software

Direction
positive
Intensity
72
Confidence
65%
Horizon
Medium term
Effective impact +37
Technology · 10.6

General Software & IT Services

Direction
positive
Intensity
68
Confidence
62%
Horizon
Medium term
Effective impact +33
Technology · 10.3

Cloud Services & Data Centres

Direction
positive
Intensity
65
Confidence
62%
Horizon
Medium term
Effective impact +31
Technology · 10.8

Professional Services

Direction
positive
Intensity
60
Confidence
58%
Horizon
Short term
Effective impact +27
Electronic Equipment · 9.3

Network Equipment

Direction
positive
Intensity
55
Confidence
55%
Horizon
Medium term
Effective impact +24

Impact figures are analytical estimates that combine direction, intensity, confidence and event importance. They are not investment advice.