Explore the companion resources
China AI Safety Policy-Risk Matrix
China's web of AI safety policies, regulations, and technical standards is dense and growing fast. This interactive overview shows which policies address which risk.
Explore the matrix → Technical researchChinese Technical AI Safety Paper Database
An interactive explorer for Concordia AI's database of frontier AI safety papers and research groups in China.
Open the database →Executive Summary
As AI capabilities advance and agentic systems move from demonstrations into wide deployment, understanding how China approaches AI safety and governance remains essential to any serious effort at international coordination. Since 2023, Concordia AI's annual reports on the State of AI Safety in China have tracked how China addresses risks from general-purpose AI.
This year's report provides updates from July 2025 to June 2026 across five domains: domestic governance, international governance, technical safety research, expert views on AI safety and governance, and industry governance.
Over the three years this report series has tracked, it has become increasingly clear that China's approach to AI safety and governance extends far beyond content control. Much of China's early AI regulation in 2023 focused on what AI says. Throughout 2024 and 2025, the rise of multimodal models moved the regulatory focus toward images, videos, and audio, prompting strict rules around labeling AI-generated content. With the rise of autonomous agents and AI companion products over the past year, the concern has expanded to what AI does and what it does to people and society, from mental-health impacts to labor-market disruptions.
Domestic Governance
- The 15th Five-Year Plan (2026–2030) cements “AI Plus” — the drive to diffuse AI across sectors to spur economic growth — as China's overarching AI policy, while continuing to prioritize safety and risk management. Enshrined in March 2026, the plan carries forward President Xi Jinping's April 2025 language on the importance of early risk warning and emergency response. It also highlights new concerns around AI's impact on employment, with calls for monitoring AI's labor-market impact, strengthening reskilling programs and employment support, and leveraging AI's ability to create jobs.
- The arrival of autonomous agents reoriented Chinese governance from controlling what AI says to controlling what it does. After the open source agent OpenClaw proliferated in early 2026, multiple cybersecurity authorities issued warnings, and in May 2026 the Cyberspace Administration of China (CAC) and two other agencies issued dedicated guidance on agentic AI, devoting a full chapter to safety and proposing risk-based governance. Several major AI standard-setting bodies are now drafting agent-related security standards. This marks a shift in China's framework from content control toward action control.
- Binding rules and standards increasingly target specific AI risks that go beyond political content control. New Interim Measures on Anthropomorphic AI Interaction Services, effective July 2026, impose obligations on AI companion services around suicide intervention, addiction prevention, and protection of minors and the elderly. New AI ethics review rules require institutions to establish registered ethics committees, with a ten-province pilot running June–November 2026. Meanwhile, a series of standards operationalizes requirements for labeling and watermarking AI-generated content disseminated online. Together these rules show China increasingly confronting AI governance problems shared with other jurisdictions, rather than just content-control issues that historically dominated its AI regulations.
- Frontier risks are being discussed more across China's governance layers, even as concrete requirements remain limited. State media coverage of a speech by President Xi Jinping referenced “risks of technological loss of control,” and a major standard-setting body has flagged the need for “circuit breakers” and “safety stop switches.” Most concretely, the draft Cybercrime Law would require AI service providers to monitor for bulk generation of malicious code and report related incidents to authorities. Meanwhile, chemical, biological, radiological, and nuclear (CBRN) misuse appeared in a national standard for the first time.
International Governance
- China is positioning itself as an architect of multilateral AI governance. China supported two new United Nations (UN) mechanisms: the Independent International Scientific Panel on AI, to which two Chinese experts were appointed, and the Global Dialogue on AI Governance, which will convene for the first time in July 2026. China also proposed a World AI Cooperation Organization (WAICO), though the timeline, leadership, and membership remained unconfirmed as of June 2026. China's UN-centered approach contrasts sharply with the US’ growing skepticism toward multilateral AI governance.
- China and the United States announced the launch of an intergovernmental AI dialogue, ending a two-year freeze in official bilateral engagement on AI safety. The agreement followed President Trump's May 2026 visit to Beijing. Official bilateral channels with other countries featured relatively little discussion of AI safety. However, non-official dialogues between groups in China and the West produced increasingly substantive AI safety outputs, including on biosecurity risks, misuse by non-state actors, and updated bilingual glossaries.
Technical AI Safety Research
- Chinese frontier AI safety research output grew substantially, and agent safety is now the single most active area. Total monthly output rose roughly 60%, from around 36 papers/month in June 2025 to 57 in April 2026. Agent safety was the topic of around 27% of new papers in Q1 2026 — up from 8% in early 2025 — spanning operational failures, alignment challenges, and a smaller but growing body of work on loss-of-control risks such as self-replication and multi-agent collusion.
- Some research directions became more prominent, while other areas' output was similar to the previous year. AI-generated content detection and watermarking remained a consistently high-output area (~11–13% of papers each quarter). Mechanistic interpretability — the ability to explain internal workings of AI systems — grew from a niche topic to roughly 15% of output by Q1 2026. CBRN risks are a standard component of major Chinese safety frameworks, but dedicated research on the topic remains rare.
- Research output remains concentrated in universities and state-backed labs. Of 28 “key research groups” with a particularly strong focus on AI safety, the large majority sit at universities (20), especially at top schools like Tsinghua University, Peking University, and Fudan University. While only three groups are at state-backed labs, their research output is disproportionately high, with Shanghai AI Lab standing out, co-authoring around one in ten papers. Of the remaining key research groups, three are at private companies, one is a state-owned enterprise, and one is a university-industry joint group. Within industry, over half of all safety output comes from just six big-tech firms — Alibaba, Ant Group, Huawei, Tencent, China Telecom, and ByteDance.
Expert Views
- Agentic AI safety emerged as a distinct strand of Chinese expert discourse. Prominent Chinese experts warned that human oversight could be eroded as agents gain autonomy. Experts also discussed potential risks associated with recursive self-improvement as well as giving agents physical instantiation (e.g. robotics).
- Chinese experts deepened their analyses of AI risks in cybersecurity, biosecurity, and open source AI. Cybersecurity debates were made more salient by the release of US frontier models that were reported to autonomously discover and exploit zero-day vulnerabilities. The reactions tended to emphasize using AI to improve defensive cybersecurity capabilities, rather than creating new regulation for AI itself. On biosecurity, experts assessed risks from biological design tools and autonomous laboratories. Chinese experts remained broadly favorable toward open source AI, though several proposed building capacity for tighter oversight, including risk-assessment centers.
Industry Governance
- Industry's collective safety efforts pivoted toward agents and, for the first time, toward frontier risks. The AI Industry Alliance of China (AIIA) instigated voluntary safety commitments on agentic consumer products in February 2026, followed by commitments on cloud-based agents in April 2026. This builds on a robust set of AI agent security publications from Chinese AI and cloud companies. AIIA’s voluntary testing program with a government-affiliated think tank is increasingly focusing on frontier risks. In November 2025, the program released cybersecurity misuse evaluations of 15 open source coding models. It then launched the AI Safety Benchmark 2.0, adding new categories for model deception, loss of control, dangerous-domain misuse, and agentic risks.
- Company-level public transparency on safety remains thin and inconsistent, lagging well behind Western peers. Only five of ten leading foundation-model developers reported safety evaluation results alongside any release this past year, and none did so consistently; DeepSeek-R1's peer-reviewed Nature paper and Moonshot AI's Kimi K2 model card were the most detailed disclosures yet, but flagship follow-ups like DeepSeek-V4 and Kimi K2.5 were released with no safety evaluation results at all.
Our newsletter is the best way to stay up to date on China's AI safety and governance.
From the archives
Download our previous State of AI Safety in China reports.