The National Cybersecurity Standardization Technical Committee released the 'AI Safety Governance Framework 3.0' at the opening of the 2026 National Cybersecurity Awareness Week, upgrading the country's approach to managing emerging AI risks.
Building on version 2.0, the new framework adds risk assessment for intelligent agents and embodied artificial intelligence — the fast-moving classes of systems that can act autonomously and physically interact with the world. It refines safety-governance requirements for large-model applications.
The framework lays out a three-in-one governance path of risk classification, technical response and comprehensive governance, and sets out principles of classified grading and agile governance. Its rapid iteration — keeping pace with the speed of AI technology — reflects regulators' intent to move from high-level principles toward operable, enforceable细则.
Cybersecurity experts note that as agents begin executing multi-step tasks and embodied robots leave the lab, the attack surface widens from data and model to physical action and critical infrastructure. Version 3.0 is meant to give developers and deployers a common reference for identifying and mitigating those risks.
The release coincides with a wave of AI governance activity in China, including the AI for Health Global Initiative annual meeting in Hangzhou and a China-ASEAN AI ministers' roundtable in Nanning — signaling that Beijing is pairing model development with a maturing safety and governance architecture.




