Skip to content

State of AI Safety in China (2026)

July 2026

We are pleased to release the State of AI Safety in China (2026) report. This annual report, first published in 2023, has become a go-to resource for policymakers, researchers, and industry leaders seeking a clear-eyed view of China’s evolving AI safety and governance landscape.

For the first time, this year’s report is accompanied by a companion website with interactive resources, including a China AI Safety Policy-Risk Matrix and a database of Chinese frontier AI safety research: https://aisafetychina.com/

Over the three years tracked by this series, it has become increasingly clear that China’s approach has expanded beyond controlling what AI says to governing what AI does — especially what it does to people and society.

The 2026 edition covers updates from July 2025 to June 2026. Key findings include:

  • After the open source agent OpenClaw proliferated in early 2026, regulators issued dedicated guidance on agentic AI security and standards bodies began drafting agent security standards. 
  • New binding rules on AI companion services impose obligations around suicide intervention, addiction prevention, and protection of minors and the elderly.
  • Frontier risks feature more prominently across governance layers: senior officials referenced “risks of technological loss of control,” and CBRN misuse appeared in a national standard for the first time.
  • China and the US announced an intergovernmental AI dialogue, ending a two-year freeze in official bilateral engagement on AI safety.
  • China backed two new UN mechanisms and proposed a World AI Cooperation Organization, positioning itself as an architect of multilateral AI governance;
  • Chinese frontier AI safety research output grew roughly 60%, with agent safety rising from 8% of new papers in early 2025 to 27% in Q1 2026.
  • Agentic AI safety emerged as a distinct strand of Chinese expert discourse, with prominent experts warning about erosion of human oversight and recursive self-improvement.
  • Industry’s collective safety efforts pivoted toward agents and — for the first time — frontier risks, with new voluntary commitments and safety benchmarks covering deception and loss of control.
  • Company-level safety transparency remains lackluster: only five of ten leading foundation-model developers reported safety evaluation results when releasing models this past year.  No company did so consistently.
Authors: Gabriel Wagner, Erik Lindblad, Kwan Yee Ng, and Brian Tse
Back To Top