China is developing rules and testing frameworks intended to reduce the risk that advanced artificial-intelligence systems could act beyond meaningful human control. The work covers scenarios including self-replication, autonomous acquisition of resources and power-seeking behaviour, bringing Beijing’s regulators into a global debate over how to supervise increasingly capable AI agents.
The Cyberspace Administration of China included potential loss-of-control situations in safety frameworks issued in 2024 and 2025. More recent rules for AI agents require mechanisms that allow operators to monitor behaviour and intervene when systems act improperly. President Xi Jinping and other senior officials have also emphasized that humans must retain authority over important decisions.
China’s approach combines state regulation with technical assessment. Authorities support external evaluations and third-party safety testing, particularly where AI may interact with critical infrastructure or sensitive data. The system does not mirror the internal watchdog arrangements proposed by some Western companies, and implementation can vary between mandatory regulation, standards and policy guidance.
Beijing also promotes open-weight AI models, which allow researchers and cybersecurity teams to inspect software more directly. Greater access can improve auditing and help identify weaknesses, but it can also make powerful models easier to modify or misuse. Chinese policy documents acknowledge that tension rather than treating openness as risk-free.
The issue has become part of strategic competition with the United States. American officials and technology executives have called for controls on advanced chips and model capabilities, while Chinese representatives argue that attempts to exclude China from AI development would undermine global governance. Both governments nevertheless recognize that uncontrolled systems could create risks that cross national borders.
Specific claims about a model escaping human control remain hypothetical risk scenarios, not reports that such an event has occurred. The purpose of the frameworks is preventive: regulators are trying to define testing, monitoring and shutdown requirements before agents gain greater autonomy.
Enforcement will require measurable tests. Regulators need definitions for unauthorized replication, deceptive behaviour and unacceptable access to computing or financial resources. Developers must also record actions in a form that auditors can inspect and provide reliable ways to suspend an agent. These controls can conflict with performance goals if companies are rewarded for greater autonomy. China’s framework is important because its domestic AI market is large enough that technical requirements imposed there may influence model design and safety practices outside the country.
Cross-border cooperation would still be required for incidents involving models, cloud infrastructure or users in several jurisdictions. China has supported discussion of international AI governance, while insisting that its companies should not be denied access to advanced technology. Safety talks therefore remain connected to the unresolved dispute over export controls.
China’s safeguards will be judged by enforcement, disclosure and the independence of evaluations. The confirmed development is the integration of loss-of-control risks into formal Chinese AI policy, showing that the country’s drive for technological leadership is being accompanied by a regulatory effort to preserve human intervention and accountability.




