TC260 Issues Draft Cybersecurity Practice Guide on Intelligent Agent System Development Security for Public Comment
关于对《网络安全标准实践指南——智能体系统开发安全指南(征求意见稿)》公开征求意见的通知
What happened
On 2026-09-18, 全国网络安全标准化技术委员会 (TC260 (Cybersecurity Standards)) published the notice 《关于对《网络安全标准实践指南——智能体系统开发安全指南(征求意见稿)》公开征求意见的通知》, releasing a draft practice guide on cybersecurity standards for public comment. source The draft 《网络安全标准实践指南——智能体系统开发安全指南(征求意见稿)》 proposes security development guidelines covering the preparation, design, implementation, testing, and release phases of software intelligent agent systems. source It is intended to help developers identify risks—such as prompt injection, data leakage, and supply chain risks—and implement corresponding security controls. source
Who is affected
Developers and operators of software intelligent agent systems are directly affected, as the draft guide 《网络安全标准实践指南——智能体系统开发安全指南(征求意见稿)》 addresses security across their development lifecycle. source Central-level cybersecurity standard-setting participants and AI technology stakeholders in China should also monitor this draft. source
What to do
Review the draft 《网络安全标准实践指南——智能体系统开发安全指南(征求意见稿)》 to assess how its security guidelines apply to your intelligent agent systems. source
Audit your development lifecycle against the draft guide’s security controls for the preparation, design, implementation, testing, and release phases, paying special attention to risks such as prompt injection, data leakage, and supply chain security. source
Monitor www.tc260.org.cn/ for the finalized text of the practice guide and further updates from 全国网络安全标准化技术委员会 (TC260 (Cybersecurity Standards)). source
Key dates
2026-09-18: Publication of the draft notice and 《网络安全标准实践指南——智能体系统开发安全指南(征求意见稿)》 by 全国网络安全标准化技术委员会 (TC260 (Cybersecurity Standards)). source