Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ LAW · BEIJING AGENT MEASURES

Several Measures of Beijing Municipality on Accelerating Agent-Led Development.

北京市关于加快智能体引领发展的若干措施

DCC catalogue entry — summary, not full text.

What this document is

The Several Measures of Beijing Municipality on Accelerating Agent-Led Development (北京市关于加快智能体引领发展的若干措施, 京发改〔2026〕1185号) is a ten-measure municipal industrial policy for AI agents (智能体), jointly issued — with the municipal government’s approval — by the Beijing Municipal Commission of Development and Reform, the Office of the Municipal Cybersecurity and Informatization Commission, the Municipal Science and Technology Commission (Administrative Commission of Zhongguancun Science Park), and the Municipal Bureau of Economy and Information Technology. It is dated 21 July 2026, was published 23 July 2026, and took effect on issuance.

It implements, at municipal level, the policy line opened by the national AI Agent Implementation Opinions (CAC/NDRC/MIIT, May 2026), and is by a clear margin the most technically literate local document in the genre: it legislates vocabulary — harness-layer engineering (驾驭层工程), task persistence, long-term memory, forward-deployed engineers (前沿部署工程师), “Token factories” (词元工厂), one-person companies (OPC, 一人公司) — that most policy texts have not yet absorbed.

The ten measures

  1. Base-model capability — online learning, continual learning and self-evolution; ultra-long-horizon task, reasoning and planning algorithms; world models, swarm intelligence, long context, tool calling, multi-agent collaboration, memory.
  2. Common agent-stack technology — harness-layer engineering (context engineering, task persistence, multi-agent collaboration, long-horizon execution stability); an agent development platform, skill marketplace, software store, and a secure, controllable technology stack.
  3. Agent-native applications and benchmark scenarios — native AI software, AI-for-science assistants, “AI scientists” and autonomous laboratories, an AI operating system, sector scenarios across science, healthcare, education, government affairs, manufacturing, and culture, delivered in part through on-site co-creation by forward-deployed engineers.
  4. Agent–terminal integration — embedding agent capability in phones, glasses, earphones, wearables, robots, and intelligent vehicles, with qualifying products added to the digital-products new-purchase subsidy program.
  5. New entrepreneurship models — one-person companies (OPC) and AI-augmented solo entrepreneurship, with public-service platforms for computing, incubation, finance, IP, and policy.
  6. The Token (词元) economy — Token-as-a-Service, Agent-as-a-Service, Results-as-a-Service; moving from billing by Token consumption toward value-based billing; Token service-quality assessment and billing norms.
  7. Security governance — graded-and-categorized regulation of agents (智能体分级分类监管), regularized crackdowns on malicious misuse, accelerating AI industry legislation, security-service platforms, security ranges (靶场), a trusted sandbox (可信沙箱), and “using models to govern models” (以模治模).
  8. Key inputs — a multi-tier computing-power supply system, low-cost standardized public computing, “Token factories,” and a data flywheel pooling sectoral knowledge and agent execution data.
  9. Open source and overseas expansion — open-source communities, interconnection protocols, development frameworks, terminal operating systems and reference hardware; country-by-country support for agent products expanding overseas.
  10. Implementation safeguards — coordinated fiscal funds, government investment funds, and rolling key projects supported at up to RMB 100 million each.

Why it matters for the data field

Most of the document is industrial promotion, not binding compliance rule-making — DCC catalogues it for three reasons.

Article 7 is a security-governance agenda in waiting. Graded-and- categorized agent regulation, a trusted sandbox, security ranges, and an express commitment to accelerate AI industry legislation signal where Beijing’s — and plausibly national — agent-specific rulemaking goes next. Read alongside the national Implementation Opinions’ Part Three (decision-authority boundaries, agent identity, tiered governance) and TC260’s agent-deployment practice guide, the direction is consistent: delegation, not generation, is becoming the unit of Chinese agent governance.

Article 8 puts agent execution data on the policy map. The “data flywheel” invites pooling of agent execution traces — which can contain personal instructions, business information, credentials, customer materials, and third-party information, with derived objects (long-term memory, embeddings, caches) retaining the originals’ sensitivity. How that squares with PIPL, DSL, and trade-secret protection is exactly the terrain DCC’s translated commentary works through.

The vocabulary will travel. OPC, Results-as-a-Service, harness-layer engineering, and Token-economy language introduced here are already appearing in commentary and will surface in procurement documents, benchmark-project acceptance criteria, and — eventually — binding rules.

DCC coverage

Hong Yanqing (洪延青) published a four-part commentary on the document within weeks of issuance, translated in full by DCC:

§ RELATED LAWS

See also.

§ COMMENTARY

Briefs on this law.

4 briefs reference this law.

  • § 01 · AI-AGENTS

    Tokens Meter Input, Not Value: Hong Yanqing on Beijing's Agent Measures (Part 4 of 4)

    Part 4, closing Hong Yanqing's commentary on the Several Measures of Beijing Municipality on Accelerating Agent-Led Development (北京市关于加快智能体引领发展的若干措施, 京发改〔2026〕1185号). The Measures' Article 6 proposes a Token (词元) economy — Token-as-a-Service, Agent-as-a-Service, Results-as-a-Service, and a shift from billing by Token consumption to value-based billing; Article 8 funds 'Token factories' and Token vouchers. Hong draws the line the policy still needs: Tokens measure the consumption of intelligent means of production, not the value of intelligent products. Tokenization differs across models; a task's full cost includes tool calls, memory storage, human review, and failed retries; and Token volume has no fixed ratio to task value — so treating Token throughput as industrial performance rewards long contexts, loops, and retries. His alternative is a five-layer evidence chain (resource input → system capability → valid task results → process results → enterprise and social value), a cost-per-valid-completed-task formula that counts review, retries, and expected risk losses, and an attribution discipline of pre-launch baselines and phased pilots. Outcome billing must be corrected for quality and risk — narrow metrics make customer-service agents rush calls and procurement agents chase price cuts, and vendors can cream-skim easy tasks while humans absorb the hard residue — so projects with unstable task boundaries should blend base, resource, and performance fees rather than jump to pure Results-as-a-Service. Different policy objects need different-layer metrics, mapped onto Part 3's five maturity levels, and fiscal support should pass staged evidence gates: prototypes may fail, pilots must beat baselines in real business, demonstrations must replicate at acceptable cost, and commercial-stage projects must survive subsidy taper — with prompt exit for projects that stop producing new evidence.

    ai-agents · beijing · token-economy
  • § 02 · AI-AGENTS

    Five Levels of Agent-Reshaped Enterprise Process: Hong Yanqing on Beijing's Agent Measures (Part 3 of 4)

    Part 3 of Hong Yanqing's commentary on the Several Measures of Beijing Municipality on Accelerating Agent-Led Development (北京市关于加快智能体引领发展的若干措施, 京发改〔2026〕1185号). Article 3 of the Measures calls on enterprises to 'restructure core business processes' around agents — but using an agent and having processes reshaped by agents are different things. Hong proposes a five-level maturity scale: (1) tool assistance — the person stays in the process, the agent stays outside it; (2) step embedding — the agent enters positions and single workflow nodes inside existing software; (3) bounded closed loop — the agent independently completes a bounded task with its own identity, scoped permissions, and human approval at defined checkpoints, the stage where Part 2's security governance becomes a production precondition and where value-based billing first becomes realistic; (4) end-to-end orchestration — the agent coordinates multiple systems, departments, and roles around a complete business outcome, forcing enterprises to name end-to-end process owners and re-align departmental KPIs; (5) native restructuring — the enterprise redesigns processes, organization, and business model around a new human-agent division of labor, the level that OPCs, Results-as-a-Service, and AI-native software presuppose. Maturity is measured by how much process responsibility changed — task units, data and system permissions, the human role, evaluation units, organizational accountability — not by agent count, automation rate, or architectural complexity; different processes have different legitimate endpoints, and high-risk decisions may properly keep a human decision-maker forever. He closes by mapping each of the ten articles to the levels it serves and proposing that Beijing's scenario lists, funding, and security requirements be allocated by target maturity level.

    ai-agents · beijing · maturity-framework
  • § 03 · AI-AGENTS

    Why Would an Enterprise Dare Hand Tasks to an Agent? Hong Yanqing on Security Governance in Beijing's Agent Measures (Part 2 of 4)

    Part 2 of Hong Yanqing's commentary on the Several Measures of Beijing Municipality on Accelerating Agent-Led Development (北京市关于加快智能体引领发展的若干措施, 京发改〔2026〕1185号). The Measures assign security governance to Article 7 — graded-and-categorized regulation, regularized crackdowns on malicious misuse, AI industry legislation, security-service platforms, ranges, and a trusted sandbox. Hong argues security cannot be one measure among ten: an enterprise that adopts an agent is not buying content-generation software but delegating tasks, data, system permissions, and the power to act externally to a technical system, and that delegation only continues if the agent's action boundary can be limited, its running state observed, its abnormal behavior halted, its errors remedied, its key steps traced, and its final responsibility assigned. He walks the other nine articles showing how each presupposes this 'trusted delegation' — self-evolution needs version governance and rollback; task persistence needs budget caps, retry limits, and human takeover; long-term memory is data processing and data residency, not a free 'data flywheel'; tool calling turns identity and permissions into the core problem; multi-agent skill markets stretch the responsibility chain — and proposes four foundational institutions: action-and-consequence-based agent classification, a trusted-delegation baseline for production agents, security capability as public infrastructure, and security evidence as a condition of fiscal support, procurement, and benchmark-scenario acceptance. Security governance, he concludes, is itself a form of productive capacity: it is what makes enterprises willing to open data, systems, and permissions at all.

    ai-agents · beijing · agent-security
  • § 04 · AI-AGENTS

    How Agents Actually Enter the Enterprise: Hong Yanqing on Beijing's Agent-Led Development Measures (Part 1 of 4)

    Part 1 of Hong Yanqing's three-part commentary on the Several Measures of Beijing Municipality on Accelerating Agent-Led Development (北京市关于加快智能体引领发展的若干措施, 京发改〔2026〕1185号, issued 21 July 2026). Hong maps agent supply along two axes — who builds and operates (enterprise self-build, standardized third-party products, joint co-construction with forward-deployed engineers, public/industry shared platforms) and how capability is delivered (whole solutions, componentized assembly via skill marketplaces, embedded in existing software and terminals) — and argues Beijing has covered supply almost completely. What the Measures have not yet answered is adoption: enterprise demand is not 'an agent' but a definable, delegable, verifiable task, and between agent supply and enterprise production processes stand six institutional thresholds — unformed procurement-ready demand, processes that lack the standardization agents require, blocked access to data and tools, missing authorization and responsibility regimes, procurement and acceptance mechanisms built for conventional software, and the absence of migration and exit capability. His prescription: the next phase of Beijing agent policy should pivot from expanding supply to promoting adoption — maturity assessment and process diagnosis, open and non-discriminatory agent access to enterprise software, capability-permission-responsibility inventories, first-purchase programs tied to real production tasks, staged funding tied to task outcomes rather than Token volume, and risk-sharing, insurance, and business-continuity mechanisms for early adopters.

    ai-agents · beijing · local-policy
§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →