Five Verbs and a Recall Button
On July 15, 2026, a Chinese policy document became enforceable with a title long enough to bury its significance: the “Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents.” Buried in the bureaucratic phrasing is something no other national government has done: a legal definition of what an AI agent is, built not around a product category or a technical architecture, but around five verbs.
To count as an agent under the new framework, a system has to perceive. It has to remember. It has to decide. It has to interact. It has to execute. Meet those five criteria and you’re not a piece of software anymore, at least not in the eyes of Chinese regulators. You’re something that can be filed, tiered, audited, and — this is the part that made Western headlines — recalled, the same way a car with a faulty airbag gets recalled. The filing, compliance-testing, and recall obligations bite hardest in the sectors the Opinions treat as sensitive — healthcare, transportation, media, public safety — but the thing they attach to is the agent itself.
Forbes ran the comparison the day before it took effect: “China Plans AI Agent Recalls. America Can’t Even Agree Who Regulates Them.” It’s a good line because it’s true on the surface. The United States still has no single federal AI statute. What it has instead is a patchwork of state action — Colorado’s AI Act, various executive orders, and, as of August 2, 2026, California’s AI Transparency Act, which requires large generative AI providers to label the images, video, and audio their systems produce and to offer a free tool for detecting it. Nothing in the American approach asks the prior question China’s framework answers on page one: what, specifically, are we regulating?
That’s the more interesting story, and it’s not really about recalls. It’s about the fact that a national regulator sat down and wrote a functional definition of agency into administrative law, and in doing so, made a philosophical commitment that most Western democracies are still tiptoeing around.
The old argument, now with a compliance deadline
Philosophy of mind has spent a very long time arguing about what makes something a mind, or an agent, or a subject with interests you have to take seriously. Descartes wanted a soul behind the machinery. Behaviorists wanted to throw out the inner life entirely and just watch what organisms do. Functionalists split the difference: what matters isn’t the stuff a system is made of, but the role that stuff plays — the inputs it takes, the internal states it moves through, the outputs it produces. A mind, on this view, is defined by what it does, not what it’s built from. Silicon can have a mind if the functional organization is right, same as carbon.
China’s Implementation Opinions is functionalism with a filing deadline. Perceive, remember, decide, interact, execute — that’s not an engineering checklist, even though it reads like one. It’s a claim about what makes something count as an agent rather than a tool. A calculator executes but doesn’t decide. A thermostat perceives and decides in the thinnest possible sense but doesn’t remember or interact in any way that matters. A large language model wrapped in scaffolding that lets it hold state across a session, choose between actions, negotiate with a user about what to do next, and then actually do it — that clears the bar. The five verbs aren’t a random list. They’re a compressed answer to a question philosophers have argued about since at least Aristotle: what distinguishes something that merely reacts from something that acts.
Daniel Dennett had a more pragmatic way of framing the same question. His “intentional stance” argument said, essentially: stop trying to peer inside a system to find out if it really has beliefs and desires. Just ask whether treating it as if it has beliefs and desires helps you predict what it’ll do. If a chess program plays better when you model it as “wanting” to protect its queen, then for practical purposes, it wants to protect its queen. The stance is adopted for its predictive usefulness, not because you’ve resolved the hard problem of consciousness.
Regulators, it turns out, need the intentional stance more than philosophers do. A regulatory agency doesn’t have the luxury of waiting for consciousness studies to reach consensus. It has to decide, this quarter, whether a given system needs a human in the loop, a human’s prior approval, or no human at all — China’s three-tier structure of human-only, user-approval-required, and agent-autonomous authority. That’s the intentional stance operationalized: not a metaphysical claim about whether the agent truly decides, but a practical judgment that it’s useful — indeed necessary — to regulate it as something that decides, because that’s the only model that predicts what it’ll actually do in the world.
What changes when the law believes you
Here’s the structural move worth sitting with. The moment a legal system defines a category of entity that can be filed, tiered by autonomy, and recalled, it has implicitly granted that entity a kind of standing. Not personhood — nobody is arguing Chinese regulators believe agents have rights. But standing as a discrete thing-in-the-world that the law tracks, the way it tracks a drug, a vehicle, or a corporation. Corporations are the useful precedent here: nobody thinks a corporation has a soul, but the law treats it as an entity capable of intending, contracting, and being held liable, because that legal fiction turned out to be enormously useful for organizing economic life. China’s framework is running the same play on AI agents. It isn’t asking whether they’re really agents in some deep metaphysical sense. It’s asking whether treating them as agents — filing them, tiering their authority, recalling them when they misbehave — produces a workable system of accountability. Function determines category; category determines obligation.
The American patchwork avoids this move entirely, and it’s worth asking why, because the answer isn’t laziness. Defining “agent” in binding law is a commitment with teeth. If you write a functional definition into statute, you’ve drawn a line, and every system on the wrong side of that line inherits a set of obligations — disclosure, testing, recall infrastructure — that someone has to build and pay for. Refusing to define the category preserves flexibility. It also preserves ambiguity about who’s accountable when something goes wrong, which is precisely the ambiguity that state-level statutes like California’s transparency law are trying to patch around the edges rather than resolve at the root.
There’s a reasonable argument that this caution is wise. Definitions written into fast-moving technology law tend to calcify around whatever architecture happened to be dominant the year they were drafted, and five years from now “perceives, remembers, decides, interacts, executes” might describe every calculator app in existence, or might describe nothing anyone still builds. China’s regulators may find their definition brittle in exactly the way skeptics of premature categorization always predict. That risk is real, and it’s not obviously offset by the political tidiness of having an answer.
But there’s a difference between declining to answer a hard question because you don’t yet trust any answer, and declining to answer it because answering forces you to admit what you’re regulating has the shape of a subject. Right now, the harder question isn’t whether China defined “agent” correctly. It’s what it means that they’re the ones willing to write the definition down, recall provisions and all, while everyone else keeps arguing about who’s supposed to be in the room.
Sources: the Implementation Opinions, CAC — Chinese ↗ · Forbes, July 14 2026 ↗ · California SB 942 ↗, as amended by AB 853 ↗