China's Agent Industry: From Model Race to Governance Race

By MAREF Research

Agent governance investment analysis policy解读 MAREF AI safety

China's AI Agent industry is undergoing a fundamental narrative shift: from "model capability race" to "governance capability race."

2026 is the foundation year for China's Agent regulatory framework. On May 8, three ministries jointly issued the "Implementation Opinions on Regulated Application and Innovative Development of Intelligent Agents"; on August 31, Document 414 launched the "AI Application Service Provider Cultivation Special Action." The two-layer policy overlay means "No Governance, No Agent" is becoming an industry iron rule.


Three Key Numbers

R₀ = 6.33
Error传播 Basic Reproduction Number
Far exceeds safety threshold of 1.0
4.7 seconds
Cascade Collapse Median Time
Human admins can't react in time
17x
Local Deviation Amplification
3% deviation → 52% system deviation

I. Longgang "LongAiQi": Pressure Test Sample

On September 4, 2026, Shenzhen's Longgang District launched the "LongAiQi" AI Agent, with core content including:

  • Trillion Token Subsidy: Up to 1 billion Tokens per enterprise, 3-month validity
  • ¥30 Billion Order Push: Procurement lists pushed to all attending entrepreneurs via "LongAiQi"
  • TEAS Foundation: Longgang Data Group's first public release of Trusted Enterprise Agent Service infrastructure

However, five-dimensional cross-validation revealed 7 fatal-level deficiencies out of 10 compliance requirements. This is not an isolated case, but a microcosm of China's entire Agent industry transitioning from "technology hotspot" to "policy governance cycle."

The Real Value of 1 Billion Tokens

Model 1B Token Value % of Compute Voucher Cap
DeepSeek V4-Flash ¥1,070 0.005%
DeepSeek R1 ¥6,325 0.03%
GPT-4o ¥48,562 0.24%

Conclusion: Token subsidies are not "compute普惠" but "user acquisition" — using minimal cost to bind enterprises to the platform, generate data, and create dependency.


II. Mathematical Nature of Cascade Risk

R₀ = 6.33: Errors Explode Exponentially

In Multi-Agent systems, error propagation follows the SIR epidemic model. The basic reproduction number R₀ = β/γ determines whether errors will outbreak in the system:

  • β (Transmission Efficiency) = Connection Density × Communication Frequency × Information Credibility
  • γ (Detection Capability) = Verification Mechanism × Knowledge Level × Reasoning Ability
Scenario R₀ Status
Industrial Era (Manual Service) 0.11 Safe
Traditional Software (Automated Systems) 0.43 Safe
Multi-Agent Collaboration (1000 Enterprises) 2.67 Outbreak
Multi-Agent + Data Sharing (LongAiQi) 6.33 Severe Outbreak

Case Validation

  • Wind Farm Cluster Cascade Collapse: 800+ turbines, one threshold error → 720+ units tripped in 3 minutes, ¥800M+ loss
  • 2010 Flash Crash: Autonomous trading algorithm interactions, $1 trillion market cap evaporated in 5 minutes
  • Retry Storm: 2-second jitter → 47-minute full outage

III. Governance Capability Ecosystem Gap

9 Frameworks Governance Capability Comparison

Dimension MAREF LangGraph Closed Platforms (Avg)
Formal Verification TLA+ 5 invariants None None
State Machine Governance 10-state Gray Code Graph state machine Vendor-specific
Circuit Breaker CircuitBreaker+HALT Conditional routing Yes
Zero-Trust Identity per-agent Ed25519 Tool binding Cloud IAM
National Crypto Compliance SM2/SM3/SM4-GCM None None

Conclusion: All mainstream Agent frameworks' governance capabilities currently fail to meet national regulatory requirements — they only differ in how much they fail by.


IV. Investment Framework

Value Chain Distribution

Upstream: Infrastructure (40-50% value capture)
├── Zhipu AI/DeepSeek (Model services)
├── Huawei Cloud/Alibaba Cloud/Tencent Cloud (Compute centers)
└── Longgang Data Group (Data assets)

Midstream: Security Governance (60-80% margin, new high-value segment) ⭐
├── MAREF (Open-source governance framework)
├── Garak (Red team testing)
├── Prediction Guard (Runtime governance)
└── Compliance audit services (CMA/CNAS qualifications)

Downstream: Application Scenarios (10-15% value capture)
├── Government (LongAiQi)
├── Finance/Healthcare/Manufacturing
└── Consumer/Education

Investment Ratings

Segment Rating Core Logic
Security Governance Strong Buy Policy-mandated demand + high margin (60-80%) + supply scarcity
Compliance Audit Strong Buy 2,000 provider mandatory evaluation + qualification barrier
Compute Infrastructure Buy Compute vouchers + Token subsidies + domestic substitution
Model Services Buy Zhipu AI/DeepSeek benefits, price war compresses margin
Token Economy Avoid 1B Tokens only worth ¥0.1-4.9K, subsidies unsustainable

V. Action Recommendations

For Enterprises: Three Questions Before Accepting Government Agents

  1. Does this Agent have audit logs? Is every operation signature-traced and accountable?
  2. Does this Agent have circuit breakers? Can abnormal behavior be automatically blocked in seconds?
  3. Who signs responsibility when something goes wrong? Is it a "model for reference only" disclaimer, or a named authorized person's legal liability?

If you can't answer all three, don't accept it.

For Investors: Remember This Formula

Governance Capability = Future Admission Threshold

For Technologists: Capability Transformation

The most scarce positions in the next three years won't be "model tuning engineers," but:

  • FDE Frontline Deployment Engineers (explicitly cultivated by Document 414)
  • Security Governance Architects (design behavior fences, circuit breakers, permission boundaries)
  • Compliance Auditors (CMA/CNAS qualifications, third-party evaluation)
  • Agent Red Team Test Engineers (Garak-class tools, 120+ vulnerability categories)

Salary increases for these positions are expected to exceed 50%.


Key Catalyst Timeline

Time Event Impact
2026 Q4 AI application service provider national standards released Strong catalyst: non-compliant products eliminated
2026 Q4-2027 Q1 First intelligent agent registration platform online Strong catalyst: digital ID system lands
2027 H1 2,000 provider resource pool acceptance Medium catalyst: head concentration, tail elimination
Any Time Major Agent security incident Black swan: regulation may fully tighten

Disclaimer: This report is based on public information and investment research models, and does not constitute investment advice. The AI Agent industry is in a period of rapid change, with significant uncertainties in policy implementation, technology maturity, and market landscape.

Related frameworks: MAREF | GitHub | GBA Report