We are pleased to release the State of AI Safety in China (2026) report. This annual report, first published in 2023, has become a go-to resource for policymakers, researchers, and industry leaders seeking a clear-eyed view of China’s evolving AI safety and governance landscape.
For the first time, this year’s report is accompanied by a companion website with interactive resources, including a China AI Safety Policy-Risk Matrix and a database of Chinese frontier AI safety research: https://aisafetychina.com/
Over the three years tracked by this series, it has become increasingly clear that China’s approach has expanded beyond controlling what AI says to governing what AI does — especially what it does to people and society.
The 2026 edition covers updates from July 2025 to June 2026. Key findings include:
- After the open source agent OpenClaw proliferated in early 2026, regulators issued dedicated guidance on agentic AI security and standards bodies began drafting agent security standards.
- New binding rules on AI companion services impose obligations around suicide intervention, addiction prevention, and protection of minors and the elderly.
- Frontier risks feature more prominently across governance layers: senior officials referenced “risks of technological loss of control,” and CBRN misuse appeared in a national standard for the first time.
- China and the US announced an intergovernmental AI dialogue, ending a two-year freeze in official bilateral engagement on AI safety.
- China backed two new UN mechanisms and proposed a World AI Cooperation Organization, positioning itself as an architect of multilateral AI governance;
- Chinese frontier AI safety research output grew roughly 60%, with agent safety rising from 8% of new papers in early 2025 to 27% in Q1 2026.
- Agentic AI safety emerged as a distinct strand of Chinese expert discourse, with prominent experts warning about erosion of human oversight and recursive self-improvement.
- Industry’s collective safety efforts pivoted toward agents and — for the first time — frontier risks, with new voluntary commitments and safety benchmarks covering deception and loss of control.
- Company-level safety transparency remains lackluster: only five of ten leading foundation-model developers reported safety evaluation results when releasing models this past year. No company did so consistently.

