China's first batch of AI Agent identity codes landed in Beijing on July 21. Over 200 enterprises signed up on day one. The era of unmanaged, untraceable agents is over.
On July 21, at the Zhongguancun Forum Exhibition Center, something quietly historic happened: the first official AI Agent identity codes were issued under China's new national standard GB/Z 185 — Artificial Intelligence Agent Technology Specification. More than 200 organizations, including Alibaba 1688, Meituan, Didi, Xiaomi, China Southern Power Grid, and all three major telecom operators, joined the pilot on day one.
If you're building or deploying AI agents in production — especially in data-intensive domains like business intelligence — this is not a regulatory footnote. It's a structural shift in how agents are trusted, composed, and governed.
The Problem: Agents Without Identity Are a Liability
Before GB/Z 185, most enterprise agent deployments operated on an implicit assumption: the agent behind the API is whoever claims to be. There was no standardized way to verify an agent's identity, describe its capabilities, or audit its behavior after the fact.
This created three compounding risks:
- Identity spoofing: Any process could impersonate a legitimate agent, inject malicious instructions, or exfiltrate data — with no forensic trail.
- Capability ambiguity: Teams had no machine-readable way to declare what an agent could or couldn't do, leading to over-permissioned agents running unchecked.
- Audit black holes: When something went wrong — a hallucinated report, an unauthorized data access, a cascading multi-agent failure — there was no standardized way to reconstruct what happened.
For regulated industries and data-driven enterprises, these aren't theoretical concerns. They're blockers to production deployment.
GB/Z 185: A 7-Part Lifecycle for Agent Governance
The GB/Z 185 standard addresses this with a comprehensive 7-part lifecycle framework covering the full agent journey:
Architecture and Reference Model — Defines the structural components every compliant agent must implement, from reasoning engines to tool invocation interfaces.
Identity Management — Establishes the identity code system itself: a unique, verifiable identifier for each agent, bound to its organizational owner and operational scope.
Trusted Access Management — Specifies authentication and authorization protocols for agent-to-agent and agent-to-service interactions, replacing implicit trust with cryptographic verification.
Capability Description — Introduces a standardized schema for agents to declare their abilities, constraints, and operational boundaries in machine-readable form.
Discovery and Matching — Enables agents to find and evaluate each other's capabilities programmatically, essential for multi-agent collaboration at scale.
Interconnection Protocols — Defines communication standards for agent-to-agent dialogue, including message formats, negotiation flows, and error handling.
Tool Invocation — Standardizes how agents call external tools and APIs, with built-in authorization checks and invocation logging.
Accompanying the standard, the AIP Protocol V2.1 (Agent Interconnection Protocol) operationalizes these principles with six functional modules: trusted access, identity authentication, capability discovery, interconnection, settlement, and behavior audit.
What Agent Identity Means for Business Intelligence
Business intelligence is one of the domains most immediately affected by agent governance. As BI platforms evolve from dashboards into conversational, agent-driven interfaces, the stakes around identity and trust escalate rapidly.
Here's how the three core pillars of GB/Z 185 map onto real BI challenges:
Pillar 1: Identity Trust → Secure Natural Language Access
When a user asks an AI analyst "What drove revenue down last quarter?", the system needs to know which agent is processing that query, what data it's authorized to access, and whether its response can be trusted. Without agent-level identity, every conversational query is essentially a blind delegation — you know who asked the question, but not who answered it.
Pillar 2: Composable Capabilities → Multi-Agent Collaboration
Modern BI workflows increasingly involve multiple specialized agents: one for data retrieval, one for statistical analysis, one for visualization, one for narrative generation. GB/Z 185's capability description and discovery standards let these agents find and collaborate with each other securely — without over-exposing internal data or operational scope.
Pillar 3: Auditable Behavior → Regulatory Compliance
For financial reporting, healthcare analytics, or any domain with compliance requirements, you need to prove not just what the answer was, but how the agent arrived at it. The behavior audit module in AIP Protocol V2.1 creates a standardized forensic trail for every agent interaction.
Quick BI's Approach: Governance Built In, Not Bolted On
Lingyang's Quick BI — the only Chinese BI vendor recognized in Gartner's Magic Quadrant for Analytics and Business Intelligence Platforms for seven consecutive years — offers a practical case study in how agent identity principles translate into product architecture.
Its conversational AI feature, Smart Q (智能小Q), implements three governance layers that align directly with GB/Z 185 requirements:
Identity Authentication: Every Smart Q session is bound to a verified user identity and an authenticated agent instance. Queries don't float in an anonymous void — they're traceable to a specific agent with defined permissions.
Data Permission Control: Smart Q inherits Quick BI's granular permission model — including row-level and column-level data permissions — ensuring the agent can only access what the user is authorized to see. No agent can see beyond its assigned data scope.
Operation Logging: All interactions are logged with full context: the query, the agent instance, the data accessed, and the response generated. This creates the audit trail that GB/Z 185's behavior audit module requires.
Beyond individual agent governance, Quick BI's Skill-based architecture enables multi-agent collaboration where each agent declares its capabilities and constraints upfront. This maps directly to GB/Z 185's capability description standard — agents don't discover each other's powers through trial and error, but through structured, machine-readable declarations.
The Governance Tradeoff: Control vs. Agility
Implementing full agent identity governance isn't free. Teams face real tradeoffs:
Strict governance (every agent identified, every interaction logged, every capability declared) maximizes security and compliance but adds overhead to development and deployment. New agents require identity registration, capability schema definition, and access policy configuration before they can participate.
Lightweight governance (minimal identity checks, permissive capability access) accelerates experimentation but creates the exact blind spots that GB/Z 185 was designed to close.
The practical middle ground, and what the standard's phased pilot approach suggests, is:
- Production agents: Full identity registration, strict permission inheritance, comprehensive logging.
- Development and testing: Relaxed identity requirements with synthetic identity codes, but capability declarations still enforced.
- Experimental agents: Sandbox isolation with no access to production data, identity codes scoped to the sandbox boundary.
This tiered approach lets organizations adopt agent governance progressively — without blocking innovation in the lab while locking down production.
What to Do Next
If your organization deploys AI agents in any capacity — and especially if those agents touch business data — the GB/Z 185 pilot is a signal worth acting on now, even before the standard becomes mandatory.
Start with a simple diagnostic: Can you name every agent in your production environment, describe what data it can access, and reconstruct its last 50 interactions? If the answer to any of those is no, you have an agent governance gap — and the industry just moved to close it.
The 200+ enterprises that joined the pilot on day one didn't wait for regulation to become mandatory. They recognized that in a world of increasingly autonomous agents, identity isn't bureaucracy — it's the foundation of trust.
Quick BI is Lingyang's intelligent business analytics platform, recognized in Gartner's Magic Quadrant for Analytics and Business Intelligence Platforms for seven consecutive years — the only Chinese BI vendor to achieve this distinction. Smart Q (智能小Q) is its conversational AI analytics feature.





Top comments (0)