China's National Technical Committee 260 on Cybersecurity (TC260), under the guidance of the Cyberspace Administration of China (CAC), released the Artificial Intelligence Safety Governance Framework 3.0 on September 14, 2026, at the opening of the 2026 National Cybersecurity Awareness Week. The document is the third edition of the national AI risk classification reference, succeeding Framework 1.0 (2024) and Framework 2.0 (2025), and it is the first to add a dedicated agentic AI risk management framework and a set of trustworthy AI principles.
The framework retains the core logic of "risk classification, technical countermeasures, comprehensive governance" but updates the risk taxonomy to track the shift of AI from answering questions to executing tasks. TC260 organized the revision through the China Cyberspace Research Institute, the CAC Data and Technology Support Center, research bodies and industry companies. The full text is published as a PDF on the CAC releases page.
What is new in Framework 3.0 compared with the 2025 edition?
The headline change is the recognition of agentic AI as a distinct risk class. The 2025 edition treated agents only obliquely; version 3.0 adds a standalone application risk category for agents (section 2.2.1) covering identity and permission abuse, reasoning and planning failures, tool call execution, and memory storage. It is backed by a full Agentic AI Risk Management Framework in Appendix 2 and Fundamental Principles for Trustworthy AI in Appendix 3.
The taxonomy also adds embodied AI risks (section 2.2.2), cybersecurity impact risks (2.2.3) including autonomous cyberattack behavior, and named threat columns on GEO poisoning of model recommendations and agent social platforms. The inherent risk section (2.1) is expanded on data poisoning of agent memory modules and synthetic data defects. The governance section keeps the regulatory sandbox mechanism and adds emphasis on preventing loss of control over autonomous behavior.
| Edition | Year | Key addition |
|---|---|---|
| Framework 1.0 | 2024 | Baseline risk classification and technical measures |
| Framework 2.0 | 2025 | Refined risk classes and governance measures |
| Framework 3.0 | 2026 | Agentic AI risk framework, trustworthy AI principles, embodied AI and cyberattack classes |
Who must act on the updated risk taxonomy?
Providers and deployers of AI services in the China market are the exposed audience, including Baidu, Alibaba, Tencent and ByteDance, and foreign providers selling into China. The framework is the technical reference that feeds the binding instruments already in force: the Interim Measures for the Management of Generative AI Services (effective August 15, 2023), the Algorithm Recommendation Provisions and the Deep Synthesis Provisions. Under those measures, public facing generative AI services must complete an algorithm filing with the CAC and a security assessment before launch.
The updated taxonomy gives those enforcement touchpoints a concrete vocabulary. A team filing an algorithm registration or preparing a security assessment will now be expected to map its system against the v3.0 risk classes, and the agentic AI framework in Appendix 2 sets the expected controls for tools, memory, identity and planning. Products that delegate actions to agents, call external tools, or maintain long term memory fall squarely in the new section 2.2.1.
Is the framework binding law, and what are the compliance stakes?
No. Framework 3.0 is a TC260 technical guidance document, not a statute and not a mandatory GB standard. It carries no compliance deadline. The binding rules remain the CAC interim measures listed above, and the comprehensive Artificial Intelligence Law remains in the State Council's legislative work plan, with enactment not expected before 2027.
The stakes are indirect but material. The CAC uses the TC260 framework as the risk classification anchor for security assessments and for how it exercises registration and filing friction under the Generative AI Measures. A product whose risk profile the framework now classes as high, an autonomous agent with tool access for example, should expect more probing scrutiny in the assessment than one scoped to text generation. Continuous, per jurisdiction real time monitoring surfaces this kind of reference update the moment it publishes.
What should compliance teams do now?
Four concrete steps follow from the revision. First, map your internal AI risk register to the v3.0 taxonomy, especially the new agentic and embodied classes. Second, review any agentic product against Appendix 2, covering identity, tool, memory and planning controls. Third, refresh algorithm filings and security assessment inputs to cite the v3.0 risk classes where relevant. Fourth, track the CAC releases page for the implementing notices that translate the framework into filing expectations. There is no statutory deadline, so the right moment to align is before your next filing.
Confirm whether your offering meets the threshold for the new agentic AI controls, brief the model, agent and security teams on the Appendix 2 expectations, and make sure your next algorithm filing reflects the updated taxonomy. The framework is guidance, but it is the guidance the supervisor uses.
Subscribe to the free newsletter
Verify which v3.0 risk classes apply to your services, confirm your algorithm filings and security assessments cite the updated taxonomy, and brief the teams building agents or embodied AI on Appendix 2. Obsidian tracks this CAC page and the TC260 register so revisions and implementing notices do not arrive unannounced.


