China's TC260 has released AI Safety Governance Framework 3.0, a non-binding third edition that adds a regulatory sandbox chapter exploring a limited liability exemption and an annex on managing AI agent risk

China TC260 Framework 3.0 Adds AI Sandbox Chapter. The Leveraged Years regulation briefing card.

The sandbox chapter is the headline and section 4.3.3 is the sentence counsel will be asked about. It explores an exemption from liability, it does not create one, and it names four kinds of conduct the sandbox cannot shield.

The short version

Bottom line: Non-binding. Framework 3.0 is a governance framework prepared by a standards committee under CAC guidance, not a regulation or a mandatory standard. It states no effective date, no filing deadline and no penalty. Its sandbox liability exemption is something the text says should be explored, not something any firm can claim today.

Who this affects: In-house counsel and compliance leads at model developers and deployers serving the PRC market, security architects and product owners building AI agents, regulatory affairs teams at critical information infrastructure operators that run AI systems, and policy analysts tracking how PRC sandbox rules may later be written.

Issue date: The PDF cover reads 2026年9月, September 2026, with no day. The CAC notice, headed 2026年09月14日 19:40 and sourced to TC260, reports the release on 14 September 2026 at the opening ceremony of the 2026 National Cybersecurity Publicity Week. We give both dates because the document itself carries only the month.

What changed: Set against the September 2025 edition 2.0, our reading of both PDFs finds two structural additions: a regulatory sandbox chapter (section 4.3, four items) and an agent risk management framework (Annex 2). Five-tier risk grading, critical information infrastructure filing language, open-source prohibited-use wording and the four-role safety guidelines are carried over from 2.0 and revised, not introduced.

Analysis: Section 4.3.3 reads as a direction to whoever will write sandbox rules, and the document names no body, procedure or date for granting an exemption. Annex 2 is the part a working team can use now: it lists agent controls in the imperative, from unique agent identities to default refusal when a human approver does not respond, and it says on its own terms that it is offered for reference.

Primary sources: AI Safety Governance Framework 3.0, bilingual PDF on cac.gov.cn · CAC notice of the release, 14 September 2026

Instrument (EN)
AI Safety Governance Framework 3.0 (人工智能安全治理框架3.0), third edition of a governance framework; the preface says it was prepared on the basis of Framework 1.0 (2024) and Framework 2.0 (2025)
Authority
National Technical Committee 260 on Cybersecurity of SAC (TC260), under the guidance of the Cyberspace Administration of China, according to the preface and the CAC notice
Jurisdiction
People's Republic of China
Status
Released 14 September 2026 per the CAC notice. Cover dated September 2026. Not a draft and not a consultation; also not an enacted rule
Bindingness
Non-binding. A governance framework and set of safety guidelines from a standards committee. It creates no obligation, no exemption and no penalty by itself
Issue date / next deadline
Released 14 September 2026 (CAC notice); cover reads September 2026. The document states no entry into force date, no compliance deadline and no consultation closing date. The only duration in the text is a guideline in 5.3.6 that application run logs be kept for not less than six months, which is an operational recommendation, not a deadline
Document
Bilingual PDF hosted on cac.gov.cn. Chinese text on printed pages 1 to 48, the framework's own English rendering from printed page 49. No instrument number; 3.0 is the edition
Primary source
https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf

One release date, one cover month, and no effective date

The CAC notice is dated 14 September 2026 at 19:40 and is sourced to TC260. Its first paragraph reports that on 14 September, at the opening ceremony of the 2026 National Cybersecurity Publicity Week, the committee released Framework 3.0, and it links the PDF directly. The PDF cover itself says only 2026年9月, September 2026. We treat 14 September as the release date on the strength of the notice and the cover month as the document's own date.

Nothing in the framework takes effect. It is a governance framework and a set of safety guidelines prepared, in the preface's words, by TC260 under the guidance of the Cyberspace Administration of China, working with professional bodies, research institutes and companies. The preface says it was drawn up on the basis of Framework 1.0 (2024) and Framework 2.0 (2025) and that it continues the same core logic of risk classification, technical response and comprehensive governance. We searched the Chinese text for a repeal or replacement clause and found none. 3.0 is a new edition building on the earlier two, and that is as far as the document goes.

So the stage flag for every operative sentence below is the same: these are things the framework says should be done, explored or established. None of them is an obligation that this document imposes on anyone.

What is new against Framework 2.0, and what is carried over

We compared the Chinese tables of contents and the relevant sections of the 2.0 PDF released in September 2025 with the 3.0 text. Two things are structurally new. Section 4.3, titled constructing a flexible, dynamic and controllable sandbox regulatory environment, has no counterpart chapter in 2.0, although 2.0 did mention sandbox simulation as a testing technique at its item 6.1.11. Annex 2, the agent risk management framework, is also new as an annex. Both editions have three annexes: 2.0 carries risk grading, trustworthy AI principles and a terminology annex, while 3.0 carries risk grading, agent risk management and trustworthy AI principles, so the agent annex replaces the terminology annex in the line-up.

The rest of the headline material is inherited. The five-tier risk grading, low, general, relatively major, major and especially major, sits in Annex 1 of both editions. The trustworthy AI principles that were Annex 2 in 2.0 are Annex 3 in 3.0, revised and renumbered. The call in 3.0 section 4.4.1 for AI systems used in critical information infrastructure to be registered and filed, and for them to have protection capabilities matched to their security needs, appears in 2.0 at section 5.5. The call in 3.0 section 4.4.4 for open-source model providers and communities to make clear the prohibited conduct for downloading and using open-source models appears in 2.0 at section 5.4. The four sets of safety guidelines by role, research and development, construction and deployment, operation and management, and access and use, were sections 6.1 to 6.4 in 2.0 and are sections 5.1 to 5.4 in 3.0.

This matters because the sweep material that reached us presented several of those inherited items as new. They are not. A reader who already mapped Framework 2.0 in 2025 has two things to read closely in 3.0, the sandbox chapter and Annex 2, and a set of revisions to check elsewhere.

Section 4.3.3 in the framework's own words

The Chinese text of 4.3.3, printed pages 22 to 23, reads: 4.3.3 探索规范责任豁免制度。对沙箱测试中无主观过错且风险处于可控范围内的行为,探索责任豁免机制。对危害国家安全、侵犯人身权益、造成重大损害或者故意实施的违法行为,不因进入沙箱而免除依法应当承担的责任。

Our translation: 4.3.3 Explore a standardised liability exemption system. For conduct in sandbox testing that involves no subjective fault and whose risk remains within a controllable range, explore a liability exemption mechanism. For unlawful acts that endanger national security, infringe personal rights and interests, cause major damage, or are committed intentionally, the liability that is to be borne according to law is not excused by entry into the sandbox.

The framework's own English rendering, on printed page 90 of the same PDF, puts it this way: "A mechanism for liability exemption should be explored for conduct during sandbox testing where there is no subjective fault and the associated risks remain controllable. For illegal acts that endanger national security, infringe upon personal rights and interests, cause major harm, or are committed intentionally, liability that should be borne according to law shall not be exempted due to entering the sandbox." We cite it as the framework's English text, not as an independent source.

Three features of the sentence carry the weight. The verb is 探索, explore, used twice; the framework does not establish, grant or promise an exemption. The eligibility test has two limbs that both have to be met, no subjective fault and risk within a controllable range, and the text does not define either. The exclusions are four: harm to national security, infringement of personal rights and interests, major damage, and intentional unlawful conduct. Whatever a future sandbox rule does with the first two limbs, the document already says those four categories stay outside it. Calling this a safe harbour or a no-fault immunity would go past the words on the page.

The rest of the sandbox chapter: rules, admission, data

Section 4.3.1 calls for sandbox regulatory rules that combine industry classification with risk grading. It lists what those rules should settle: who the sandbox applies to, the scope of testing, the allocation of rights and responsibilities, and exit conditions. It says entry standards and testing requirements should be drawn up separately for sectors such as finance, education, broadcasting and television, and health, and that monitoring and intervention should vary with a project's risk grade. The framework supplies none of those rules itself.

Section 4.3.2 describes dynamic testing and flexible admission. Testing periods, scope and application scenarios should be adjusted as the technology iterates and testing progresses, with real-time monitoring, staged evaluation and rule adjustment running through the whole test. The main admission criteria named are technological innovativeness, controllability of risk and social value, with an appropriate tilt toward start-ups, small and medium-sized enterprises and public service projects. No testing duration is given.

Section 4.3.4 asks for a sandbox test data sharing platform that integrates government data and public industry data to give admitted firms compliant test data, and for rules on certifying test results and recognising them across departments so that sandbox results feed into later procedures without repeat testing. Again, these are things the text says should be built. The document does not say any of them exist.

Annex 2 reads like a control checklist for agent builders

Annex 2 opens by saying agents have carried AI from answering questions to executing tasks, that their high autonomy and high privileges bring risks of privacy leakage, unauthorised operations and loss of behavioural control, and that the annex proposes prevention measures for developers, providers and users of agent applications to reference. Part one walks the agent lifecycle from design and development through installation, instruction input, reasoning and planning, invocation and execution, memory, output and decommissioning, plus a residual group, and names the failure modes at each stage: prompt injection hidden in documents, emails, web pages, logs or messages; context overflow; goal hijacking; tool poisoning, tool privilege creep and tool selection bias; memory pollution and memory theft; and leftover permissions and credentials after shutdown.

Part two is where the operational content sits, in seven groups, and everything in it is reference material the annex offers to developers, providers and users; nothing in it is enforceable through this document. On identity and permissions it says each agent should carry a unique identifier, that instances of an agent application should not share one, that an agent should receive only the minimum permissions needed for the current task, and that credentials should be revoked immediately when a task ends or the agent is retired. On human approval it says a list of high-risk operations should be drawn up and handed to the user to take over before execution, that deleting files, sending data and changing system configuration should get a second confirmation or human approval with rollback available, and that when the approval system fails, the user does not respond or no approval rule exists, the default is to refuse the operation.

The same reference-only status applies to the remaining groups. On tools and supply chain it says an agent should check a tool's version, description file, parameter definitions and metadata before calling it and should not call publicly known malicious tools, and that skills from reliable, security-tested sources should be used by preference, with risk precautions taken before any untested skill is used. On runtime it says credentials and keys should in principle not be written to memory, that code execution and tool calls should run in sandboxes or containers, and that step counts, call frequency, execution time and resource use should be bounded. On monitoring it asks for full logging of file operations, command execution, network connections, skill calls and payment transactions, data collected or generated within China to be stored within China, a standing red-team programme, and a security impact assessment with regression testing whenever the model, agent framework, tools, permissions or security policy change materially. On retirement it asks for a full shutdown including revocation of third-party authorisations and cancellation of subscriptions and auto-renewals, a backup of records still needed, and a clean-down of files, knowledge bases, plug-ins, skill configurations and account credentials. Each of these is a recommendation in a non-binding annex, not a requirement.

Two related items in the main guidelines belong with this. Section 5.1.12 asks developers to set reasonable boundaries on agent behaviour and to attach a human approval mechanism to operations that could cause serious harm. Section 5.3.6 asks operators to keep application run logs, covering system and user behaviour, for not less than six months and to audit them regularly. The annex closes by saying agent cognition and action are still iterating quickly and that the risk framework will keep being upgraded. None of this is enforceable through this document, and Annex 2 says twice that it is offered for reference.

What we did not verify

What we opened: the bilingual Framework 3.0 PDF served from cac.gov.cn, read in the Chinese text for the cover, the table of contents, the preface, sections 4.1 to 4.5, sections 5.1.12, 5.3.6 and 5.3.19, Annex 1, all of Annex 2 and the opening of Annex 3, and read in the framework's own English text for section 4.3; the CAC notice of 14 September 2026; and, for the comparison, the Chinese table of contents and sections 5.4, 5.5, 6.1.11 and Annex 1 of the Framework 2.0 PDF released in September 2025.

What we did not open: Framework 1.0; any TC260 or CAC statement about how or whether sandbox rules under section 4.3 will be drafted; the separately consulted draft national standard on AI application security classification and grading, which Annex 1 does not issue or finalise; the Global AI Governance Initiative and the Global AI Governance Action Plan the framework cites; and any PRC law under which the liability preserved by 4.3.3 would actually be borne.

What we refuse to claim: we do not say Framework 3.0 supersedes or repeals 2.0, because we found no such clause. We do not say a sandbox exemption, safe harbour or immunity is available, because 4.3.3 says explore and names no procedure or body. We do not say the five risk tiers, the critical information infrastructure filing language, the open-source prohibited-use language or the trustworthy AI principles are new, because they are in 2.0. We do not say the framework is binding, that it took effect on 14 September, that it sets a filing deadline or penalty, or that firms outside China acquire duties from it. We do not say who will run a sandbox, how long a test would last or how an exemption would be adjudicated, because the document does not. Where the word must or shall appears above, it is inside the framework's own English rendering.

Informational analysis for working professionals, not legal advice. Confirm how any rule applies to your situation with qualified counsel.

Key compliance takeaway

Read 4.3.3 as a signal, not a shield. If your PRC-facing product would want sandbox treatment, the two things to track are whether a regulator writes admission and exit rules under 4.3.1 and whether any exemption mechanism under 4.3.3 gets a procedure and a decision-maker; this framework itself provides no application procedure and no claimable exemption. If you build agents, take Annex 2 part two as a review checklist today, treating it as what it says it is, reference-only recommendations in a non-binding framework rather than requirements: unique agent identity, least privilege with immediate credential revocation, a written high-risk operation list with human takeover, default refusal when the approver is silent, credentials and keys in principle not written to memory, and full logs kept at least six months per 5.3.6.

Source File

https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf

Open the PDF and confirm four things: the cover says 2026年9月 with no day; the preface says the framework was prepared on the basis of Framework 1.0 (2024) and 2.0 (2025) and does not repeal them; section 4.3.3 on printed pages 22 to 23 uses 探索 (explore) twice and lists four excluded categories; and Annex 2 says it is provided for reference by developers, providers and users of agents. Then open the CAC notice and confirm it reports the release on 14 September 2026.

4.3.3 探索规范责任豁免制度。对沙箱测试中无主观过错且风险处于可控范围内的行为,探索责任豁免机制。对危害国家安全、侵犯人身权益、造成重大损害或者故意实施的违法行为,不因进入沙箱而免除依法应当承担的责任。 · AI Safety Governance Framework 3.0 (人工智能安全治理框架3.0), section 4.3.3, printed Chinese pages 22 to 23, released 14 September 2026

FAQ

Is AI Safety Governance Framework 3.0 legally binding?

No. It is a governance framework and a set of safety guidelines prepared by TC260, a standards committee, under CAC guidance. It states no effective date, no compliance deadline and no penalty. The sandbox chapter says rules should be established; it does not establish them. The document does not say how, or whether, any of its content will be carried into binding law.

Can a company in an AI sandbox now claim a liability exemption in China?

Not on the strength of this document. Section 4.3.3 says a liability exemption mechanism should be explored for sandbox conduct that involves no subjective fault and whose risk stays within a controllable range. It names no body to grant an exemption and no procedure. It also says that unlawful acts that endanger national security, infringe personal rights and interests, cause major damage or are intentional are not excused by entry into the sandbox.

Does Framework 3.0 replace Framework 2.0?

The preface says 3.0 was prepared on the basis of Framework 1.0 (2024) and Framework 2.0 (2025) and continues the same core logic. We found no repeal or replacement clause in the Chinese text. It is a new edition building on the earlier two. What is structurally new is the sandbox chapter (4.3) and the agent risk annex (Annex 2); the five-tier grading, filing language, open-source wording and role-based guidelines are carried over and revised.

What does Annex 2 say about human approval for AI agents?

Part two, item 3, says a list of high-risk operations should be drawn up and that the agent should hand such operations to the user to take over before executing them, with user authorisation needed before medium and low risk operations. Deleting files, sending data and changing system configuration should get a second confirmation or human approval, with rollback available. If the approval system fails, the user does not respond or no approval rule applies, the default is to refuse the operation. Approval records should be kept in a tamper-resistant, verifiable form. These are reference recommendations in a non-binding annex, not requirements imposed on anyone.

Sponsored Training

Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.

."}}]}