While the United States argues about whether to slow the frontier, China has moved on to a different question: what do you do with an agent once it is running. Reuters reported on September 14 that Beijing has begun drafting a mandatory national safety standard for AI agents - one expert called it possibly the world's first of its kind - grounded in a policy that treats the operational loss of control of an agent as a real and present risk.

The policy, issued in May by China's cyberspace regulator, economic planner, and industry ministry, requires developers to improve their ability to detect, intervene in, block, and recover from improper agent behavior. It also demands protections against data poisoning, algorithm manipulation, and system vulnerabilities - and it insists that users be informed about an agent's autonomous decisions while retaining final decision-making authority.

The framing is notable because it is procedural rather than apocalyptic. There is no call to pause development. There is a requirement to build agents that can be stopped. The distinction matters: where the American debate has been about whether to slow the pace, the Chinese approach has been about how to build a handle. A standard that demands detectability and recoverability is a standard about engineering control, not about moral restraint.

The Handle Problem

China's earlier AI safety framework, updated last September, had already sharpened a warning about a possible sudden leap in intelligence followed by resource acquisition, self-replication, and power-seeking behavior. The new principle added to that framework was 'trusted application, preventing loss of control.' The mandatory standard is the technical companion to that principle - a way of making the abstract warning concrete enough to audit.

The contrast with the American position is sharp. In the United States, the conversation has centered on coordination among labs and a plea for a safety waiver, a debate that has already produced an antitrust lawsuit. In China, the state is writing a rulebook for the agents themselves. Neither approach has been proven. But the Chinese one at least assumes that the agents will exist, and that the question is not whether to let them run but how to reach them when they do.

Read as a counterpoint to the brakes arc this paper has tracked since No. 73, the standard is the other half of the story. The labs want to slow down so safety research can catch up. Beijing wants to build agents that can be switched off regardless of how fast the research moves. One of those is a plea for time. The other is a plan for control - and it may be the more durable of the two.