Technology & AIAnalysis

China Moves to Build Continuous Trust Frameworks for Autonomous AI Agents

As AI assistants gain spending power, Chinese institutions push continuous verification and identity standards to govern autonomous commercial actions.

Share
An elderly man receives a cup from a robotic arm in a modern office setting.
Photo by Pavel Danilyuk on Pexels

The Brief

As autonomous AI agents evolve from conversational tools to transaction-executing intermediaries, Chinese policymakers and tech enterprises are overhauling authentication frameworks to address rising security risks. Traditional one-time real-name verification is proving inadequate for multi-agent workflows, prompting initiatives such as Ant Group's APASS infrastructure and state-backed standardization guidelines. According to research from the China Academy of Information and Communications Technology, agent-embedded applications are forecast to jump from under 5 percent in 2025 to 40 percent in 2026, accelerating the push toward dynamic, three-layered identity governance and continuous intent monitoring.

Why it matters

The transition of AI from passive software to autonomous entities capable of spending money and invoking enterprise systems fundamentally breaks traditional human-account authentication. Without dynamic intent verification, the risk of unauthorized transactions and algorithmic fraud threatens commercial deployment just as autonomous agents prepare to mediate an estimated $15 trillion in global B2B procurement by 2028.

China context

Beijing is positioning agent governance at the intersection of industrial policy and cybersecurity. Following the release of national implementation opinions on agent standardization, state-affiliated bodies like CAICT and platform giants such as Ant Group are attempting to establish de facto domestic standards through ecosystems like IIFAA, aiming to secure commercial workflows before agent-based transactions scale widely across domestic e-commerce and enterprise software.

Editor's View

EDITOR'S VIEW — Analysis and inference, not factual reporting. The shift from verifying who created an account to monitoring what an autonomous instance intends to do at runtime marks a crucial evolution in digital governance. Rather than treating model safety purely as content moderation or alignment, Chinese industry players and technical regulators are treating autonomous agents as legal and financial delegates. By establishing a three-tiered identity model that distinguishes the software, the runtime instance, and the legal principal, these frameworks seek to resolve commercial liability before autonomous agents become ubiquitous in supply chains.

What to watch

  • Whether IIFAA and CAICT establish formal cross-platform standards for the minimum viable identity attributes required for autonomous agent operations.
  • The pace of APASS and continuous risk-control adoption across third-party enterprise resource planning and payment platforms beyond Ant Group's direct orbit.
  • Judicial clarifications and regulatory enforcement guidelines regarding financial liability when autonomous commercial agents exceed user instructions.

Key Takeaways

  • 1AI agent adoption in software applications is projected to grow from under 5 percent in 2025 to 40 percent in 2026, according to CAICT.
  • 2Industry forecasts predict AI agents will mediate 90 percent of B2B procurement by 2028, representing over $15 trillion in transaction volume.
  • 3Attacks targeting AI agents average 29 minutes, with the fastest recorded breach taking just 27 seconds, outpacing traditional enterprise security response windows.
  • 4A joint industry framework proposes a three-tier identity model distinguishing product identity, runtime identity, and the responsible legal principal to support continuous verification.
  • 5Ant Group deployed APASS, a 'Know Your Agent' trust infrastructure that has connected over one million agents across 442 service providers.
As artificial intelligence agents evolve from passive chatbots into autonomous software capable of executing financial transactions, traditional web authentication models are failing to keep pace. The emerging problem was highlighted by Chen Shupeng, head of AI payment security at Ant Group, who pointed to the risk of an agent tasked with compiling a slide presentation legitimately purchasing templates and research papers, but then proceeding to make an unauthorized 2,000-yuan purchase of consumer electronics. Because the agent plans, decides, and executes tasks across platforms, single-point real-name verification cannot ensure that ongoing actions align with user intent. Data from the China Academy of Information and Communications Technology (CAICT) indicates a rapid deployment curve paired with severe operational risks. Fu Shan, deputy director of the Information Security Department at CAICT's Telecommunication Terminal Labs, noted that while fewer than 5 percent of applications embedded AI agents in 2025, that proportion is projected to reach 40 percent in 2026. Concurrently, attacks against agents are accelerating, with breaches occurring in as little as 27 seconds and averaging 29 minutes, compared to traditional corporate security response times that are measured in hours. CAICT cited industry forecasts projecting that by 2028, 90 percent of business-to-business procurement will be mediated by AI agents, driving more than $15 trillion in transaction volume. In response, Chinese regulatory guidance and industry initiatives are shifting focus from whether underlying foundational models are safe to defining who the agent is and who bears legal responsibility for its execution. Under national implementation guidelines on the standardized application and development of intelligent agents issued earlier this year, authorities called for research into agent identification, trusted interconnection, and compliant payment systems. A joint industry report titled the Trusted Agent Identity Framework recommended replacing static credentialing with continuous trust management. The framework partitions agent identity into three distinct layers: product identity, runtime instance identity, and the responsible legal principal, evaluating trustworthiness dynamically against behavioral and contextual signals. Commercial infrastructure is beginning to reflect this methodology. Ant Group recently launched APASS, a trust system based on a "Know Your Agent" approach covering identity registration, continuous verification, intent security, and transaction recording. Chen reported that APASS has connected more than one million agents, with 110,000 activated across 442 service providers, while over 50 institutions have joined an agent ecosystem initiative under the Internet Finance Authentication Alliance (IIFAA). Nonetheless, industry analysts emphasize that common credential interoperability and standardized enforcement across fragmented platforms remain in nascent stages.