China's national cybersecurity standardization committee, TC260, released AI Safety Governance Framework 3.0 on September 14. Prepared under the guidance of the Cyberspace Administration of China, it addresses the shift from models that answer questions to agents that act. This entry was added retrospectively on September 29.
The agent appendix recommends limited permissions and human checkpoints. Critical steps, including file deletion and data transfers, should require additional confirmation. If the necessary approval is absent, the action should not proceed. Approval records should remain traceable.
In a CCTV interview reproduced by the CAC, Wen Yuheng explains that the framework offers guidance rather than a compulsory law. His account of risks moving from digital environments into the physical world remains an expert assessment.
This risk signal records an official publication, not a new agent incident. It does not establish that providers have implemented the recommended controls or that those controls work. September 14 remains the publication date; later editorial discovery does not make it a new measure.