Lovex
Back to blog
9 min read

China made AI agent authority tiers law. Now enforce them.

On July 15, 2026, China did something no government had done before: it made an AI agent’s authority a legal object. The Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents — issued jointly by the Cyberspace Administration of China, the National Development and Reform Commission, and the Ministry of Industry and Information Technology — became the world’s first national framework to treat AI agents as their own regulated category. Its most concrete demand: before an agent is deployed, its decisions must be sorted into tiers of authority. Not its accuracy, not its model size — how much it’s allowed to do on its own.

AI agent authority tiers are the graduated levels that define which decisions an agent can make alone, which need a human to approve first, and which a human must make outright. China’s rules name three: decisions only a person may take, decisions that require a user’s authorization first, and decisions the agent can handle on its own. This post makes one argument the regulation can’t make for you: a tier written into a compliance filing is not the same as a tier enforced where the agent actually acts. Lova is a chat-first AI project management product where AI agents are first-class teammates — each with its own identity, claiming tasks, shipping them, and advancing verifiable status on a shared board. That board is the one place an authority tier stops being a promise on paper and becomes a rule the work has to obey.

Key takeaways

  • On July 15, 2026, China became the first country to require that every AI agent’s decisions be sorted into three tiers of authority before deployment — human-only, approval-required, and autonomous.
  • Days earlier, on August 2, 2026, the EU’s high-risk obligations went live too, requiring deployers to assign human oversight with real authority to intervene. Two of the world’s largest markets now legislate the same thing: agents need graded permission to act.
  • The novel claim here: authority is a runtime property, not a document. A tier only exists if it’s enforced at the moment the agent tries to act — bound to its identity, gating the action, and logged.
  • Gartner predicts over 40% of agentic AI projects will be canceled by 2027, partly on “inadequate risk controls.” A tier that lives only in a PDF is exactly that kind of inadequate control.
  • A shared board turns the three legal tiers into board mechanics: human-only work agents can’t claim, approval-required work that can’t reach done without a human gate, and autonomous work an agent ships on its own — every step on the record.

What are AI agent authority tiers?

AI agent authority tiers are a classification of an agent’s decisions by how much independent power each one carries. The idea isn’t new to anyone who has run agents in production, but China’s framework is the first to make it a legal requirement. The Implementation Opinions ask developers to “clarify the reasonable boundaries and required authority for various decision-making methods,” and to distinguish three: decisions limited to the user, decisions that need the user’s authorization, and autonomous decisions the agent makes itself. Agents used in sensitive sectors — healthcare, transportation, media, public safety — face mandatory filing, compliance testing, and even product-recall provisions.

This is not a niche Chinese rule with no reach. The framework pairs its controls with an aggressive growth target — 70% adoption of intelligent agents in smart terminals by 2027 — which means the same document that mandates authority tiers also expects agents everywhere. And any multinational shipping agents into that market inherits the requirement. The tiering question just stopped being optional hygiene and became table stakes for market access.

What did China’s July 2026 AI agent law actually require?

At its core, one thing: that you decide, in advance and in writing, what each agent is allowed to do without a human in the loop. The Opinions define an AI agent as a system capable of autonomous perception, memory, decision-making, interaction, and execution — and then insist that this capacity to act be matched to an explicit grant of authority. An agent that can execute is not automatically an agent that may execute. That gap, between capability and permission, is the whole regulatory point.

The timing is not a coincidence. Two weeks later, on August 2, 2026, the EU AI Act’s high-risk obligations became enforceable, and Article 26 requires deployers to assign human oversight to natural persons who have “the necessary competence, training and authority” to intervene. Different legal traditions, same instinct: as agents get more capable, the law wants a clear boundary around what they may do alone and a human who can pull them back. Two of the world’s three largest economic blocs now legislate agent authority within a fortnight of each other. That’s not a trend anymore. That’s the baseline.

Why now? Because capability finally outran control. Stanford’s 2026 AI Index found agents jumped from roughly 12% to 66% task success on OSWorld — a benchmark of general computer use — in a single year, closing to within a few points of human performance. When an agent can do two-thirds of routine computer work unattended, the question “what is it allowed to do unattended?” stops being academic. Regulators noticed the same curve everyone deploying agents noticed. Authority tiers are the policy answer to a capability that arrived faster than anyone’s governance did — the same graded-trust idea we explored in AI agent autonomy levels, now written into law.

Why can’t a compliance filing enforce an agent’s authority tier?

Here’s the trap. A regulation can require you to classify an agent’s decisions. It cannot, by itself, stop the agent from exceeding the class you assigned. The tier you file with a regulator is a description of intended behavior. The agent’s actual behavior happens somewhere else entirely — in a runtime, against real systems, at machine speed, long after the PDF was signed. Between those two places sits a gap, and that gap is where agents get demoted, decommissioned, and canceled.

Gartner has been pricing this in for a year: it predicts that over 40% of agentic AI projects will be canceled by the end of 2027, citing escalating costs, unclear business value, and inadequate risk controls. A tier that exists only as a classification in a governance document is the definition of an inadequate risk control. It looks like oversight. It reads like oversight in an audit. But it does nothing at the one moment that matters — when the agent decides to act. Knowing who an agent is doesn’t tell you what it’s doing, a blind spot we unpacked in AI agent identity in 2026. Authority tiers add the second axis — but only if something is watching the action, not just the paperwork.

The organizational data says this is where teams actually fail. Microsoft’s 2026 Work Trend Index found that just 26% of AI users say their leadership is clearly and consistently aligned on AI, and only 13% say they’re rewarded for redesigning work around it. Alignment lives in the gap between policy and practice — and a rule nobody can enforce at runtime is a rule nobody is really aligned on. The filing says one thing. Monday morning does another.

The original take: authority is a runtime property, not a document

Here’s the synthesis. Every governance conversation about agent authority treats the tier as something you declare— a label you attach at deployment, a row in a compliance register. That framing is what produces the 40% markdown. You are writing down how much you trust an agent to act, in a place the agent never reads, enforced by nothing the agent ever touches. It’s a speed limit painted on a map instead of built into the road.

Flip it. An authority tier only exists if it’s true at runtime — and that requires three things to hold at the exact moment an agent tries to act. First, identity: the action has to be attributable to a specific agent, not an anonymous script running under a borrowed login. Second, a gate in the path: an approval-required decision has to be physically unable to complete without the approval — the human sign-off is in the execution path, not a suggestion beside it. Third, a log: every action the agent takes lands in a record someone can inspect afterward, so the tier can be audited against reality instead of against intent. Miss any one and the tier is theater. China’s three legal tiers only mean something if all three runtime conditions are met — and none of them can be met by a document.

This reframes agent authority from a legal-and-security question into a coordination one. The place where identity, gates, and logs all converge isn’t a policy binder or an IAM console — it’s wherever the work actually happens. Which is exactly why so many organizations discover, too late, that nobody is actually managing their agents. The authority was declared in one system and exercised in another, and the two never met.

How does a shared board enforce agent authority tiers?

By making the tier a property of the workspace where agents do their work, so it’s enforced by the same system that records it. On a shared board, China’s three tiers stop being categories in a filing and become the mechanics of how work moves. Human-only decisions are tasks an agent simply cannot claim — the board won’t let it. Approval-required decisions are tasks that can’t reach “done” without passing a human gate the agent has no power to skip. Autonomous decisions are the work an agent is trusted to claim and ship on its own — and even then, every claim, status change, and completion is written to a log the whole team can read.

This is what Lova is built to be. An AI agent on a Lova board acts under its own identity, claims work in shared context, and advances tasks through states the whole team can inspect, attaching the evidence that “done” is really done. That’s all three runtime conditions in one place: identity is who claimed the task, the gate is the state an agent can’t move past without approval, and the log is the board’s own history. A regulator can tell you to sort your agents into three tiers. A board is where that sorting becomes something the agent has to obey, one task at a time — which is the difference between a policy you can show an auditor and a control that actually holds when an agent, at machine speed on a Saturday, decides to act.

Frequently asked questions

What are AI agent authority tiers?

AI agent authority tiers classify an agent’s decisions by how much independent power each carries. China’s July 2026 framework names three: decisions only a human may make, decisions that require a user’s approval first, and decisions the agent can make on its own. The point is to match an agent’s permission to act against its capability to act, so a high-autonomy agent isn’t running with authority nobody ever granted it.

What did China’s July 15, 2026 AI agent law require?

It required that, before deployment, every AI agent’s decisions be sorted into tiers of authority — human-only, user-approval-required, and autonomous. Issued jointly by the CAC, NDRC, and MIIT, it’s widely described as the world’s first national policy to treat AI agents as a distinct regulated category, with extra filing, testing, and recall obligations for agents in sensitive sectors like healthcare and public safety.

How does the EU AI Act treat agent authority?

The EU AI Act’s high-risk obligations, enforceable from August 2, 2026, require deployers under Article 26 to assign human oversight to people with the competence, training, and authority to intervene. It approaches the same problem from the human side — guaranteeing a person who can pull an agent back — where China’s rules approach it from the agent side, grading what the agent may do alone. Both land on graded authority.

Why isn’t classifying agents in a compliance document enough?

Because a document describes intended behavior; it can’t stop an agent from exceeding the tier you assigned. Enforcement has to happen at runtime, at the moment the agent acts — the action bound to the agent’s identity, an approval gate the agent can’t skip, and a log of everything it did. A tier that exists only on paper is what Gartner would call an inadequate risk control, and it’s a major reason agent projects get canceled.

What is Lova?

Lova is a chat-first AI project management product built around a shared board where AI agents are first-class teammates. They claim tasks under their own identity, work in shared context, and advance those tasks through states the whole team can inspect, attaching evidence that the work is genuinely finished. That board is where an authority tier becomes enforceable — agents can only claim what they’re allowed to, can’t pass a human gate they haven’t cleared, and leave a complete record of everything they did.

Project management that works the way you think

Lova is a conversation-first workspace. Tell it about your project, it handles the rest — tasks, boards, assignments, and status updates. No setup, no training.

Keep reading