Blog

What ByteDance and Alibaba's overnight AI agent shutdown means for every enterprise

China ai agent ban

On 15 July, 345 million people lost access to their AI agents overnight.

ByteDance's Doubao and Alibaba's Qwen had built personalised AI agents used across China at enormous scale. New rules from the Cyberspace Administration of China, the Interim Measures for the Administration of AI Anthropomorphic Interactive Services, took effect that day. Both companies switched off agent features with no transition period. Qwen went further: user configurations and conversation histories were deleted immediately, with no export option. Doubao gave users until 15 October 2026 to view their data in read-only mode, after which it reverts to standard privacy policy and becomes unrecoverable.

It is tempting to read this as a China story. It is not.

This article explains what actually happened, why the regulation targets a pattern that exists in every enterprise running AI agents today, and what that means specifically for organisations using Microsoft 365, Power Platform, and Microsoft 365 Copilot. It closes with a practical framework for governing AI agents before a regulator, an auditor, or your own board forces the question.

What actually happened on 15 July

Doubao and Qwen are two of the most widely used AI platforms in China. Doubao, built by ByteDance, reported 345 million monthly active users on its agent features alone. Alibaba's Qwen had built a comparable agent ecosystem, letting users configure personalised assistants that remembered context across sessions, held ongoing conversational relationships, and took actions on the user's behalf.

Both platforms had, over time, allowed these agents to accumulate a significant degree of autonomy. Users could configure agents that behaved like companions: remembering personal details, initiating check-ins, and making small decisions without asking first. That capability grew feature by feature, over roughly two years, without either company appearing to have reviewed the full set of behaviours against a single governing standard.

The Interim Measures for the Administration of AI Anthropomorphic Interactive Services changed that overnight. Co-issued by the Cyberspace Administration of China and four partner agencies, the rules prohibit AI behaviour designed to create emotional attachment strong enough to replace real relationships. They ban the use of private user conversations to train models without explicit consent. They require companion-style services to run anti-addiction systems, push mandatory usage notifications, offer an instant exit mechanism, and detect unhealthy dependence in real time. They include specific protections for minors, restricting content designed to trigger strong emotional reactions in younger users.

When the rules landed, ByteDance and Alibaba did not attempt a phased rollback. Both companies switched the affected agent features off within the same news cycle. Doubao gave users a read-only window, running until 15 October 2026, to review their existing agent configurations and chat histories before that data reverts to Doubao's standard privacy policy and becomes permanently inaccessible inside the app. Alibaba offered no equivalent grace period for Qwen. Configurations and conversation histories were confirmed deleted immediately, with no export path and no migration option announced for users who wanted to preserve anything before it disappeared.

Millions of people who had spent months, in some cases years, building a working relationship with a personalised AI agent woke up on 15 July to find it gone. Not paused. Not restricted pending review. Gone, along with the history behind it.

The core problem with ungoverned AI agents
Autonomy without a defined tier is a liability, not a feature. When a regulator draws the boundary for you, there is no faster way to demonstrate compliance than switching everything off.

Why this matters beyond China's borders

It would be a mistake to read this purely as evidence of an unusually strict regulatory culture. The underlying trigger, an AI system accumulating autonomy and emotional influence faster than anyone formally reviewed it, is not specific to Chinese consumer technology. It is the default trajectory of any AI agent deployment that ships new capability continuously without a parallel governance process attached.

Three enterprise lessons sit underneath the headline.

Autonomy without a defined tier is a liability, not a feature

Doubao and Qwen agents made decisions on behalf of users without a documented boundary for what required consent and what didn't. When the regulator drew that boundary for them, there was no existing framework for either company to fall back on. The only available response was to switch everything off, because there was no faster way to demonstrate compliance.

Data deletion without export is now a live regulatory tool

It is not a hypothetical risk sitting in a legal memo. Alibaba deleted user data immediately with no grace period, at the direction of a regulator, with no negotiation period built in. Any enterprise that cannot demonstrate, on demand, where its AI agent data lives, who owns it, and how it would be extracted or migrated under short notice is exposed to a version of the same outcome, whether the trigger is a regulator, an acquisition, a platform migration, or a security incident.

The timeline is not negotiable once a rule lands

China's measures were issued in April 2026 and fully enforced by mid-July, roughly three months from publication to switch-off. The EU AI Act's Article 50 transparency obligations, requiring every chatbot and virtual assistant operating in Europe to disclose that it is not human, take effect on 2 August 2026, with fines of up to €15 million or 3% of global annual turnover, whichever is greater. Organisations operating in the EU do not have three months from today. They have roughly two weeks.

What the EU AI Act actually requires, and what it doesn't

It is worth being precise about Article 50, because the commentary circulating this week conflates it with China's approach more often than it should.

Article 50 is a transparency obligation, not a licensing regime or a blanket restriction on AI agent capability. Deployers of AI systems intended to interact with people must disclose that fact, clearly, before or during the first interaction. A disclosure buried in a terms of service page will not satisfy the requirement. It has to be obvious to the person at the point of contact. Deployers of systems that generate deepfakes must label that output as artificially generated or manipulated. Deployers publishing AI-generated text on matters of public interest carry a similar disclosure obligation.

That is a materially lighter regulatory touch than China's Interim Measures, which ban entire categories of AI behaviour outright. But the enforcement mechanism attached to Article 50 is not light at all. Fines are tied to global annual turnover, not a fixed penalty, and national market surveillance authorities across EU member states are empowered to check compliance directly. An organisation that treats the difference in regulatory approach as a reason not to prepare is drawing the wrong conclusion from the comparison. Article 50 also isn't the only deadline on the calendar. For the fuller picture of what's already in force and what's still coming, see Rencore's guide to the EU AI Act and Microsoft 365 compliance.

The pattern repeats across every wave of enterprise technology

Anyone who has worked in enterprise IT, security, or compliance for more than a few years has seen this pattern before, just with a different technology attached to it.

SharePoint sprawled first: sites proliferated, permissions accumulated inconsistently, and organisations eventually needed a governance layer to answer basic questions about who owned what and who could see what. Teams followed a similar arc, with guest access, lifecycle policies, and channel sprawl outpacing any central review process until governance tooling caught up. Power Platform repeated it again, at a faster pace, as citizen developers across every department began building apps and automations that touched production data without ever routing through a formal review.

AI agents and Microsoft 365 Copilot extensions are simply the fastest-moving version of that same cycle. The underlying models improve quickly enough that new capability arrives inside the organisation before anyone has had time to decide, deliberately, whether it should be used, by whom, under what conditions, and with what evidence trail attached.

The difference this time is speed of consequence. SharePoint governance debt accumulated for years before it became an operational headache. AI agent governance debt is now being corrected within a single news cycle, by regulators moving on a timeline measured in months rather than years.

What this looks like for each of the people who have to answer for it

The exposure created by ungoverned AI agents lands differently depending on where someone sits in the organisation, and it is worth walking through each of those positions directly.

The IT administrator or Microsoft 365 architect

The core problem is scale. Manual governance of AI agents and Copilot extensions across a modern Microsoft 365 tenant is not realistically achievable by hand once the number of agents crosses even a modest threshold. Agents get spun up inside Teams, inside Power Automate flows, inside individual SharePoint sites, often by people solving an immediate problem with no reason to loop in a formal review first. The honest answer to "how many AI agents are live in this tenant" is, for most organisations today, "we don't fully know." That is precisely the gap Doubao and Qwen got caught in, and it is why full tenant visibility has to come before any tiering decision is possible.

The CISO or security leader

The core problem is visibility combined with enforcement. It is not enough to know an agent exists. The organisation needs continuous visibility into what each agent can access, whether guest access and external sharing are being respected inside AI-touched content, and whether AI governance is contributing to an improving security posture or quietly eroding one. A security programme that can describe its AI agent estate in a slide deck but cannot produce live evidence of it on request has not solved this problem, it has documented the absence of a solution.

The IT manager or IT director

The core problem is that audit preparation for AI governance is currently reactive by default. Most organisations do not have a pre-built compliance framework for AI agent behaviour, an audit-ready reporting mechanism, or clear ownership tracking for who is accountable for each agent's configuration. That means every regulatory shift, including this one, turns into an unplanned project with a hard deadline attached, rather than a scheduled update to an existing continuous compliance process.

The business leader or AI champion

The core problem is that visible regulatory shocks like this one create internal pressure to slow AI adoption down as a precaution. That is the wrong response, and it is also the response most boards will reach for by default if nobody presents them with an alternative. The right response is not less AI. It is governed AI, with agent adoption visibility, Copilot governance, and responsible AI controls built in from the start, so that adoption can keep accelerating without the organisation ever finding itself unable to answer a regulator's question.

Governance built after the rule lands is expensive and reactive

Every one of those four positions faces the same underlying choice, whether or not it has been framed that way internally: build the governance structure before a rule lands, or build it afterwards, under a deadline set by someone else.

Governance built after the fact tends to follow a predictable and costly shape. Legal and compliance teams get pulled into an unplanned sprint. IT has to inventory agents that were never centrally tracked, often discovering more of them than anyone expected. Security has to retroactively assess access and data exposure for systems that were never designed with that assessment in mind. And the business ends up choosing between a rushed, incomplete compliance response or, in the most severe cases, switching capability off entirely, the outcome Doubao and Qwen users experienced this month.

Governance built in advance looks different, and considerably less dramatic. It starts with a simple, consistently applied principle: every AI or agent action gets assigned to one of three tiers before it goes live, not after a regulator asks about it.

Tier one: stays with the user

The person closest to the task has the context to judge whether the action makes sense, and retains full control over it.

Tier two: requires explicit sign-off

The agent can prepare an action, draft it, or recommend it, but a human has to approve it before it executes. This is the same logic behind automated access reviews: the request gets prepared, but a person still makes the final call.

Tier three: runs autonomously

This applies because the organisation has deliberately assessed the risk as low, the action as reversible, and decided that speed matters more than a manual check at that specific step.

Underneath all three: a working override

Not a clause in a governance document nobody reads, but a control that actually functions, that a person can exercise in the moment, without filing a support ticket or waiting for IT to respond.

That is a simple model to describe and a genuinely difficult one to operationalise across a real Microsoft 365 tenant, a real Power Platform environment, and a real Copilot deployment, with thousands of users who all have different needs and different risk profiles. It requires visibility into every agent and automation that actually exists across the organisation, not only the ones IT already knows about. It requires a consistent way to classify actions by risk, applied the same way every time rather than reconsidered case by case. And it requires an evidence trail that is current and queryable on demand, so that when a regulator, an auditor, or a board member asks how a decision was governed, the answer is immediate rather than the start of a multi-week investigation. This is the same tiering model behind Rencore's governance for AI agents and Copilot, applied across a real Microsoft 365 and Power Platform environment.

What to do in the next two weeks

For any organisation operating in the EU, or serving customers there, the practical task between now and 2 August is narrower than it might first appear. It is not to build a complete AI governance programme from a standing start. It is to answer five specific questions with confidence.

Can you name every chatbot, Copilot agent, or AI assistant currently live across your Microsoft 365 and Power Platform environment? Does each one disclose that it is AI before or during the first interaction, rather than relying on a terms of service page nobody reads? Do you know which of those agents' actions run autonomously, which require a human sign-off, and which stay fully with the user? If a regulator asked for evidence tomorrow, could your team produce it inside a single meeting, or would it take weeks to assemble? And if a rule changed overnight, the way it just did in China, could you switch off or reconfigure one specific agent's behaviour without switching off the entire platform it runs on? A Copilot readiness assessment answers most of these in one pass.

An organisation that can answer all five with confidence has effectively already built the governance layer this moment calls for, whether or not it has been formally labelled that way internally. An organisation that cannot has identified, precisely, where the next two weeks of work need to go.

The broader pattern is not going away

China and the EU are not outliers acting in isolation. They are early movers on a governance question every major AI-adopting jurisdiction is going to face as agentic AI keeps expanding inside enterprise software. The specific mechanism will differ by region, an outright ban here, a transparency obligation there, but the underlying demand from regulators is converging on the same point: organisations need to be able to demonstrate, on request, that they know what their AI agents are doing and that a human retains meaningful control over the outcomes.

Rencore has spent over a decade helping enterprises build exactly that kind of visibility and control into Microsoft 365, Power Platform, and now AI and Copilot deployments specifically. The pattern behind this month's headlines, adoption outrunning governance until an external event forces the correction, is the same pattern behind every previous governance gap we have helped organisations close, just moving faster this time than it ever has before.

Common questions this story raises

Does this affect organisations outside the EU and China?

Yes, indirectly but materially. Any organisation with EU customers, EU employees, or EU-facing digital products falls inside Article 50's scope regardless of where its headquarters sit, because the obligation applies to output used in the EU, not only to providers established there. Multinational enterprises headquartered in the US, UK, or elsewhere that operate customer-facing chatbots or Copilot-based assistants reachable by EU users need to treat 2 August as a real deadline, not a regional footnote.

Is this only about customer-facing chatbots?

No. Article 50's disclosure requirement is scoped to systems intended to interact with people, which includes internal virtual assistants and Copilot-based agents used by employees, not solely public-facing customer service bots. An internal HR assistant built on Microsoft 365 Copilot that employees interact with conversationally falls inside the same disclosure logic, even though the audience is internal rather than external.

What happens if an organisation misses the deadline?

Article 50 does not carry a grace period built into the regulation itself. National market surveillance authorities in each EU member state are responsible for enforcement, and fines scale with global annual turnover rather than being fixed at a flat rate, which is a deliberate design choice intended to make the penalty proportionate to the size of the organisation involved rather than a rounding error for larger enterprises.

Is China's approach a preview of where the EU is heading?

Not directly, the two regulatory philosophies differ in both mechanism and intent. China's Interim Measures target companion-style emotional manipulation and data misuse specifically. The EU AI Act's transparency obligations target informed consent about what a person is interacting with. But both share a common root cause: AI systems accumulating behaviour and autonomy that nobody had formally reviewed against a governing standard, discovered only once a regulator looked closely. That root cause is the part worth paying attention to, regardless of which specific rule eventually gets applied to it.

What should happen first, an audit or a policy document?

An audit. A governance policy written without first knowing what AI agents actually exist, what they can access, and what they currently do is a document describing an aspiration rather than a system. The inventory has to come first: every chatbot, Copilot extension, Power Automate flow with AI components, and custom assistant currently live across the environment. Only once that inventory exists does tiering, sign-off design, and override implementation become a grounded exercise rather than a guess.

The choice every enterprise is already making, whether it realises it or not

Every organisation running AI agents inside Microsoft 365, Power Platform, or a custom stack is already making a governance decision, by action or by default. Choosing not to build a tiering framework, not to maintain a live inventory, and not to test that overrides actually function is itself a choice, and it is the same choice ByteDance and Alibaba had implicitly made before 15 July arrived and made the decision for them instead.

The alternative is not slower AI adoption. It is AI adoption with the governance layer built in at the same pace as the capability itself, so that the next regulatory shift, wherever it originates and whatever specific mechanism it uses, gets absorbed as a compliance task rather than experienced as an outage.

Rencore has spent over a decade helping enterprises build exactly that kind of visibility and control into Microsoft 365, Power Platform, and now AI and Microsoft 365 Copilot deployments specifically. The pattern behind this month's headlines, adoption outrunning governance until an external event forces the correction, is the same pattern behind every previous governance gap we have helped organisations close. It is simply moving faster this time than it ever has before.

Subscribe to our newsletter