MICKAI®ArticlesChina now regulates AI agents. Wh…
Article · 22 July 2026

China now regulates AI agents. What should UK boards take from it?

China's new agent rules point to a shape UK boards should adopt now: a mandate, an identity and a reviewable record for every agent.

Author
Micky Irons
Published
22 July 2026
Follow Micky Irons
LinkedInX
sovereign aiai agentsai governancechina ai regulationboard oversight

China's Implementation Opinions on intelligent agents became enforceable on 15 July 2026 and are widely reported as the first dedicated regulatory category built specifically for AI agents rather than for AI models in general. The detail is still emerging and should be treated as reported, not verified, but the direction is clear enough for UK boards to act on now: regulators are converging on the idea that an autonomous agent needs an explicit mandate, a checkable identity, and a reviewable record of what it actually did.

The question matters because UK boards are approving agentic AI deployments faster than any single regulator can legislate for them, and waiting for a UK statute before governing agents properly is a board risk in its own right, not a compliance shortcut.

What does China's agent framework reportedly require?

Reporting describes a tiered decision-authorisation framework in which agents operating in higher-risk sectors face filing requirements and are expected to operate within defined bounds of authority rather than open-ended discretion. The exact thresholds, penalties and article numbers are not independently verified here and should not be treated as settled; what is consistent across reporting is the underlying architecture, not the fine print.

Why does the shape matter more than the statute?

Because the shape is portable and the statute is not. A UK board does not need to read Chinese law to see the same three questions arriving in every serious agent-governance conversation: what is this agent allowed to decide alone, whose identity does it act under, and where is the evidence of what it did. Those questions already sit inside UK law in adjacent forms, from data protection accountability to senior management accountability in regulated sectors, without needing a bespoke UK agent statute to force the point.

What does an explicit agent mandate look like in practice?

A written boundary, not a vibe. A defensible mandate states, per agent, what decisions it may take without a human in the loop, what it must escalate, what data it may reach, and what happens when it is uncertain. Boards that skip this step are not avoiding governance, they are deferring it to the moment something goes wrong, which is the most expensive time to write it.

Why does an agent need its own identity?

Because shared credentials erase accountability. An agent acting under a shared service account or a borrowed human login cannot be distinguished, after the fact, from the person who set it up or the next person who touched the same login. A named, hardware-attested identity per agent means every action can be traced to the specific agent and the mandate it was operating under, which is the precondition for the next question being answerable at all.

What counts as a reviewable record rather than a chat log?

A reviewable record captures what the agent was asked, what it decided, what data it touched, and when, in a form that cannot be quietly edited after the event. Boards should test this directly: pick one agent, ask for the record of its last material action, and see how long it takes to produce and whether anyone has to trust the answer rather than verify it.

Does UK law already reach agentic AI without a dedicated statute?

Largely yes, through existing regimes. Data protection accountability under UK GDPR already requires organisations to explain automated processing that affects people. Senior managers in regulated sectors already carry personal accountability for controls in their area, agent or no agent. Contract law already asks whether an agent had authority to commit the company to what it did. None of that is new law; it is existing law meeting a new class of actor, which is exactly why boards should not wait for Parliament before applying it.

What should a UK board change this quarter?

Three moves that require no new legislation: require a written mandate for every agent already in production, not just the ones under review; assign each agent a distinct, attributable identity rather than a shared credential; and demand a sample audit of one agent's record at the next board meeting, pulled live rather than presented as a slide. Boards that can answer what an agent did last week in minutes are already ahead of most regulatory floors being drafted anywhere.

An agent without a mandate, an identity and a record is not autonomous, it is unaccountable.

How bounded mandates, hardware-attested identity and a sealed record fit together as one architecture is set out at /sovereign-ai, and the film at /film shows the interface in operation.

Frequently asked questions

Is China's agent law directly relevant to a UK company with no China operations?

Not as a compliance obligation, since it has no direct UK legal effect. It is relevant as an early signal of where agent governance is heading globally: authorisation tiers, filings for high-risk use and traceable records are appearing in multiple jurisdictions independently, suggesting the pattern will keep recurring rather than being a one-off.

What is the single most useful test a UK board can run on its own agents today?

Ask for the mandate, the identity and the record for one agent already in production, in that order. If any of the three is missing or takes more than a few minutes to produce, that gap is the governance priority, regardless of what any future statute eventually requires.

Does UK GDPR already cover decisions made by an AI agent?

Where an agent processes personal data or makes decisions with legal or similarly significant effects on a person, UK GDPR accountability and transparency obligations apply, and the Data (Use and Access) Act 2025 is reworking parts of the automated-decision regime in stages. The full detail sits outside this article, but the principle does not wait for an agent-specific statute.

Should a board wait for a UK AI agent law before acting?

No. The mandate, identity and record pattern is defensible under existing law and good governance practice regardless of what any future statute adds, and boards that build it now avoid a scramble later. Waiting converts a design decision into a remediation project.

Can bounded mandates slow an agent down too much to be useful?

A well-written mandate defines what the agent may decide alone, which speeds up the common case rather than slowing it, because the agent no longer has to guess where its authority ends. The friction most teams fear comes from vague mandates argued over case by case, not from clear ones written in advance.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/china-now-regulates-ai-agents-what-should-uk-boards-take-from-it. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles