On July 29, 2026, China’s National Technical Committee 260 on Cybersecurity (SAC/TC260) opened a Call for Comment on the TC260 Practice Guide - TC260-PG-2026NA Security Requirements for Agent Interaction and TC260-PG-2026NA Practice Guide for AI Browser Security. The comment period closed on August 12, 2026. These two documents draw on China’s existing national standards and rules to establish domestic frameworks for agent interconnection protocols, security risk management, and lifecycle security controls.
TC260-PG-2026NA Security Requirements for Agent Interaction is grounded in the China’s Cybersecurity Law and Data Security Law. It establishes general security requirements for agent-to-agent interactions, as well as specific security requirements for interactions between agents and tools.
The Practice Guide is built around four pillars: identity and identification, access control, communication security, and risk management and control. It is intended to provide security practice guidance for service providers and tool providers of intelligent agents. It may also serve as a reference for third-party evaluation organizations and other entities.
TC260-PG-2026NA Practice Guide for AI Browser Security is based on the Interim Measures for the Administration of Generative Artificial Intelligence Services and GB/T 45654-2025 Cybersecurity technology - Basic security requirements for generative artificial intelligence service. It focuses on the security risks arising from AI browsers’ capabilities in automated web interaction, cross-site data extraction, and user behavior proxying. The Practice Guide proposes a multi-dimensional protection framework covering human verification of high-risk operations, supply chain security, and enhanced communication and content security. It is intended for AI browser providers to implement security controls throughout the full lifecycle of design, development, testing, deployment, operation, and evaluation.
Both documents make clear that agentic AI security cannot be reduced to model-level safeguards alone. Whether governing agent-to-agent and agent-to-tool interactions, or AI browsers operating across websites on behalf of users, both guidelines point toward lifecycle governance of the interaction layer—spanning identity verification, access control, cross-system communication, and behavioral boundaries. For foreign stakeholders, these Practice Guides offer early insight into domestic benchmark requirements for AI agents and AI-enabled browsers, allowing time to review technical alignment and make necessary adjustments to stay competitive and compliant.
If you need more information, please contact info@bestao-consulting.com
Top Read Articles
Switch articles-
2026.08.28China Proposes Seven Mandatory Standards for Data and Cybersecurity Case Handling – AUG, 2026
-
2026.08.28China Eases Personal Information Protection Duties for Small-Scale Handlers – JUL, 2026
-
2026.08.25Five-Year Plan for China’s Power System Support Emerging Sectors – AUG, 2026
-
2026.08.24National ICV Standard Revised into Mandatory Requirements in China – AUG, 2026
-
2026.08.21Regulation of China on Integrated Circuits Design Protection Revised – AUG, 2026