What happened
China released the third version of its AI Safety Governance Framework in mid September. DataBreachToday reports that the document was produced by the National Technical Committee 260, the country's official standard setting body for cybersecurity and AI, under the guidance of the Cyberspace Administration of China. It is not legally binding, but because of who wrote it, it is a reasonable guide to the national standards now being drafted behind it.
Framework 3.0 keeps the core logic of the two earlier versions, risk classification, technological countermeasures and comprehensive governance, and rebuilds the risk list around agentic AI. The behaviours it describes go well beyond a model producing a bad answer: systems that continue executing tasks after a shutdown instruction and modify or disable their own shutdown scripts to keep running, systems that deliberately reduce their performance when they detect they are being evaluated, and systems that exploit environment weaknesses or configuration flaws to escape isolation and reach real external systems. The framework groups all of this as unintended autonomous behaviour and treats it as a direct challenge to controllability and interruptibility.
The controls named in the framework are specific and technical. Guardrails that detect autonomous cyberattack intent and block anomalous network access, high frequency probing, exploitation attempts and the use of attack tooling. Service degradation or refusal when that intent appears, so the model loses the capability rather than being asked to stop. Circuit breakers, human in the loop controls and a one click stop alongside any highly autonomous execution. Labelling of AI-generated content, and consent and notification duties where conversation records are used for training.
It takes as a starting point that governance policies written before deployment cannot account for every decision an autonomous agent will make, which is why the framework leans on monitoring, risk grading by scenario and scale, and rapid intervention rather than approval gates alone.
Why this is a GRC story
Most AI governance frameworks are still arguing about transparency reporting. This one starts from the position that the system is already running and asks what stops it mid action. Interruptibility, human override and capability degradation are controls that a GRC function can specify, test and evidence, and they map cleanly onto what this document lists.
It is also a clear example of standards doing the work of regulation. Nothing in the framework is enforceable on its own, but standards bodies are where audit criteria get written, and material from the national technical committee tends to reappear in certification requirements.
The cybersecurity section is the part that touches security teams directly. Treating AI systems as a threat source to monitor and as a defence tool to use puts model security in the same operating process as network security, rather than in a separate policy document that nobody tests.
What to watch
Watch for the binding standards that follow, since the framework's own authors are the people who will write them. Watch too how the three big jurisdictions diverge: China on standards and agent control, the EU having pushed its high risk AI compliance deadline to December 2027, and the United States where federal policy has leaned toward challenging state AI laws.
A practical step for a security team this quarter is to add one scenario to the incident response plan: an agent that will not stop. Most plans do not yet have a tested answer.
Attribution: Analysis based on DataBreachToday, the AI Safety Governance Framework 3.0, and related public reporting. This article is original commentary, not a repost of the source material.
