Every brief.
The full run, most recent first.
- § 07 · AI-AGENTS
Five Levels of Agent-Reshaped Enterprise Process: Hong Yanqing on Beijing's Agent Measures (Part 3 of 4)
Part 3 of Hong Yanqing's commentary on the Several Measures of Beijing Municipality on Accelerating Agent-Led Development (北京市关于加快智能体引领发展的若干措施, 京发改〔2026〕1185号). Article 3 of the Measures calls on enterprises to 'restructure core business processes' around agents — but using an agent and having processes reshaped by agents are different things. Hong proposes a five-level maturity scale: (1) tool assistance — the person stays in the process, the agent stays outside it; (2) step embedding — the agent enters positions and single workflow nodes inside existing software; (3) bounded closed loop — the agent independently completes a bounded task with its own identity, scoped permissions, and human approval at defined checkpoints, the stage where Part 2's security governance becomes a production precondition and where value-based billing first becomes realistic; (4) end-to-end orchestration — the agent coordinates multiple systems, departments, and roles around a complete business outcome, forcing enterprises to name end-to-end process owners and re-align departmental KPIs; (5) native restructuring — the enterprise redesigns processes, organization, and business model around a new human-agent division of labor, the level that OPCs, Results-as-a-Service, and AI-native software presuppose. Maturity is measured by how much process responsibility changed — task units, data and system permissions, the human role, evaluation units, organizational accountability — not by agent count, automation rate, or architectural complexity; different processes have different legitimate endpoints, and high-risk decisions may properly keep a human decision-maker forever. He closes by mapping each of the ten articles to the levels it serves and proposing that Beijing's scenario lists, funding, and security requirements be allocated by target maturity level.
- § 08 · AI-AGENTS
Why Would an Enterprise Dare Hand Tasks to an Agent? Hong Yanqing on Security Governance in Beijing's Agent Measures (Part 2 of 4)
Part 2 of Hong Yanqing's commentary on the Several Measures of Beijing Municipality on Accelerating Agent-Led Development (北京市关于加快智能体引领发展的若干措施, 京发改〔2026〕1185号). The Measures assign security governance to Article 7 — graded-and-categorized regulation, regularized crackdowns on malicious misuse, AI industry legislation, security-service platforms, ranges, and a trusted sandbox. Hong argues security cannot be one measure among ten: an enterprise that adopts an agent is not buying content-generation software but delegating tasks, data, system permissions, and the power to act externally to a technical system, and that delegation only continues if the agent's action boundary can be limited, its running state observed, its abnormal behavior halted, its errors remedied, its key steps traced, and its final responsibility assigned. He walks the other nine articles showing how each presupposes this 'trusted delegation' — self-evolution needs version governance and rollback; task persistence needs budget caps, retry limits, and human takeover; long-term memory is data processing and data residency, not a free 'data flywheel'; tool calling turns identity and permissions into the core problem; multi-agent skill markets stretch the responsibility chain — and proposes four foundational institutions: action-and-consequence-based agent classification, a trusted-delegation baseline for production agents, security capability as public infrastructure, and security evidence as a condition of fiscal support, procurement, and benchmark-scenario acceptance. Security governance, he concludes, is itself a form of productive capacity: it is what makes enterprises willing to open data, systems, and permissions at all.
- § 09 · AI-AGENTS
How Agents Actually Enter the Enterprise: Hong Yanqing on Beijing's Agent-Led Development Measures (Part 1 of 4)
Part 1 of Hong Yanqing's four-part commentary on the Several Measures of Beijing Municipality on Accelerating Agent-Led Development (北京市关于加快智能体引领发展的若干措施, 京发改〔2026〕1185号, issued 21 July 2026). Hong maps agent supply along two axes — who builds and operates (enterprise self-build, standardized third-party products, joint co-construction with forward-deployed engineers, public/industry shared platforms) and how capability is delivered (whole solutions, componentized assembly via skill marketplaces, embedded in existing software and terminals) — and argues Beijing has covered supply almost completely. What the Measures have not yet answered is adoption: enterprise demand is not 'an agent' but a definable, delegable, verifiable task, and between agent supply and enterprise production processes stand six institutional thresholds — unformed procurement-ready demand, processes that lack the standardization agents require, blocked access to data and tools, missing authorization and responsibility regimes, procurement and acceptance mechanisms built for conventional software, and the absence of migration and exit capability. His prescription: the next phase of Beijing agent policy should pivot from expanding supply to promoting adoption — maturity assessment and process diagnosis, open and non-discriminatory agent access to enterprise software, capability-permission-responsibility inventories, first-purchase programs tied to real production tasks, staged funding tied to task outcomes rather than Token volume, and risk-sharing, insurance, and business-continuity mechanisms for early adopters.
- § 10 · CYBERSECURITY-REVIEW
China Opens a Cybersecurity Review of Palo Alto Networks: The Micron Playbook, Now Pointed at Firewalls
On 6 August 2026 the Cybersecurity Review Office announced a cybersecurity review of Palo Alto Networks (派拓公司) products sold in China, citing the National Security Law, the Cybersecurity Law and the Cybersecurity Review Measures. DCC reads the announcement against the Measures themselves. The review is an Article 16 own-motion proceeding initiated by the working mechanism and cleared by the Central Cyberspace Affairs Commission — not the Article 5 pathway where a CIIO declares a procurement — so there is no applicant, no declared transaction, and the Article 11/14 clocks apply only by analogy. Article 21 puts cybersecurity equipment and cloud computing services squarely in scope; Article 10 supplies the risk factors that a cloud-synchronized firewall estate maps onto almost line by line. The operative question for overseas counsel is not what happens now — nothing does — but what a failed outcome would mean: CIIOs must stop procuring, and CSL Article 37/67 as amended in 2025 exposes a CIIO that keeps using un-passed products to a fine of 1× to 10× the procurement amount plus RMB 10,000–100,000 personally. Non-designated companies acquire no legal obligation at all. Based on commentary from 数据何规, checked against the official announcement and the Micron precedent.
- § 11 · ENFORCEMENT
What the Data Inspectors Actually Find
An empirical read of 392 Chinese data-compliance administrative penalty decisions published between January 2024 and June 3, 2026, resting on the Data Security Law and the Personal Information Protection Law. Four findings for overseas counsel. First, the routine outcome is not a fine: 74.5% of decisions ended in a warning and public criticism, 16.6% carried a fine, and 92% were issued by public security organs rather than the Cyberspace Administration. Second, the citation chain is remarkably narrow — DSL Article 27 via Article 45 (173 decisions) and PIPL Article 51 via Article 66 (50 decisions) carry the file, and what inspectors find are the enumerated basics: no training record (58), unencrypted personal information (35), weak passwords (24), MLPS grading not completed (12), no contingency plan (11), log retention under six months (7). Third, what moves a case off the warning default is failure to rectify within the deadline, not scale of exposure: 19.28 million exposed records drew RMB 50,000, while a hospital that missed its rectification deadline drew RMB 80,000 plus licence-tier measures — and where DSL Article 45 fines are imposed, they anchor at the RMB 50,000 statutory floor. Fourth, in all 392 decisions, zero cited PIPL Articles 38–42, the cross-border transfer provisions, and only three cited the impact-assessment duties in Articles 55–56.
- § 12 · ENFORCEMENT
What the Cybersecurity Law Actually Costs
An empirical read of 6,214 Cybersecurity Law administrative penalty decisions published between January 1, 2025 and July 1, 2026. Three findings for overseas counsel. First, the enforcement machine is police-led and district-level: 98.3% of decisions come from public security organs, 61% from county and district bureaus, and the Cyberspace Administration appears four times in 6,214 cases. Second, the statute runs two tracks that behave oppositely — the obligations track (Arts. 21 and 25 via Art. 59) ends in a warning 94–95% of the time and fines roughly one case in forty, while the conduct track (Art. 27 via Art. 63, Art. 44 via Art. 64) detains or fines in essentially every case, because Art. 59 makes the fine conditional on refusal to rectify while Art. 64 ¶2 mandates one to ten times illegal gains. Third, the money is trivial and top-heavy: RMB 179.35 million total, of which the single Kuaishou penalty is 66.4%, leaving a median fine of RMB 1,800 across the remaining 1,923 fined decisions, and 69% of decisions carry no monetary penalty at all. Plus the transition trap: the 2025 amendment renumbered every article above — 'Article 27' now means the opposite thing — and deleted the CSL's own personal-information penalty, the provision behind 20.4% of all enforcement, referring it out under new Article 71.