• 中国科学学与科技政策研究会
  • 中国科学院科技战略咨询研究院
  • 清华大学科学技术与社会研究中心
ISSN 1003-2053 CN 11-1805/G3

科学学研究 ›› 2026, Vol. 44 ›› Issue (9): 1811-1819.

• 热点议题 • 上一篇    下一篇

外资 AI Agent 军民两用技术安全审查判定标准研究

王文轩1,罗先觉2   

  1. 1. 中国科学院大学公共管理学院
    2. 中国科学院大学
  • 收稿日期:2026-05-21 修回日期:2026-06-25 出版日期:2026-09-15 发布日期:2026-09-15
  • 通讯作者: 罗先觉

A Study on the Judgment Criteria for Civilian-Military Dual-Use Security Review of Foreign Investment in AI Agent Technology

  • Received:2026-05-21 Revised:2026-06-25 Online:2026-09-15 Published:2026-09-15

摘要: AI Agent 技术依靠自主决策、多步骤任务执行以及环境感知能力,正在改变全球科技竞争的格局。它把大语言模型嵌入到支架软件中,在无人持续监控的情况下可以规划执行任务链,并操控外部系统,因此具有天然的军民两用性。双重性边界取决于部署方式而不是产品类别,使传统依靠产品类别的审查方法越来越失效。在美国战略竞争加剧、欧盟经济安全战略转向的背景下,美国以CFIUS审查、OISP对外投资限制、2025年国家安全备忘录将AI列为强制审查领域,欧盟以修订后的FDI审查条例并探索对外投资审查,均将AI列为强制审查领域,而中国《外商投资安全审查办法》虽然有涵盖但是缺少AI Agent的具体判定标准。本文用技术安全悖论来搭建框架,认为AI Agent的商业价值就在于它的自主性、适应性以及泛化能力,而正是这三种能力才成为它最大的军事转化风险,进而对比美欧中关于判定标准和实践的差别,并用Shield AI、OpenAI、SpaceX和xAI合并等实例来揭示目前审查对于技术识别准确度、标准协调性以及动态适应性的三大结构性缺陷。在此基础上提出以功能能力为锚点的分级审查模型,把AI Agent的能力分解成自主性、连接性、适应性、协同性、积累性五个方面,并设定四级阈值,任一维度达到第三级就触发深度审查,两个达到第三级或者任一达到第四级就触发限制性措施。进而从制度、操作、动态三个层面提出完善中国审查框架的建议,使审查焦点从技术是什么转向技术能做什么,为完善外资安全审查中AI Agent军民两用判定标准提供理论依据和制度参考。

Abstract: AI Agent technology is different from traditional large language models in that it can make autonomous decisions, perform multi-step tasks, and sense the environment; thus, it is now changing the world of technology. The AI Agent will use the large language model in the scaffolding software to plan and carry out a series of tasks independently without continuous human intervention, and it can do more than just answer questions. The purpose of this architecture is dual-use, and it can be employed for civil and military applications; thus, the same framework of autonomous planning and tool invocation that has optimised commercial workflows can also be used in the military for command and control, intelligence analysis, autonomous weapons systems, etc. Therefore, the dual-use boundary is determined not by the category of goods but by how they are used and connected in the system; thus, the old way of classifying or declaring the end-use of goods is no longer effective. With the intensification of strategic competition between China and the United States and the changes in the economic security strategy of the European Union, many countries have begun to add artificial intelligence to the mandatory foreign investment security review. The Committee on Foreign Investment in the United States has expanded the scope of application for inbound investment under the Foreign Investment Risk Review Modernization Act, introduced the Outbound Investment Security Program to curb outbound investment in countries of concern, and by 2025, the National Security Presidential Memorandum will increase control over sensitive technologies such as artificial intelligence. The new Foreign Direct Investment Screening Regulation in the EU lists artificial intelligence, quantum technology and semiconductors as important areas to be monitored for all member states, and the EU has started to study the screening of outbound investments. China's Measures for the Security Review of Foreign Investment have covered significant amounts of information and key technologies in the field of information technology and core industries, but specific judgment criteria for the new form of technology, AI agents, have not been established. Building on the foundation of technological security paradox, this paper thinks that the commercial value of AI Agent technology is directly related to its autonomy, adaptability and generalisation ability; at the same time, these are also the reasons for concern. Based on the criteria and practice in the United States, the European Union and China, as well as through cases such as Shield AI, OpenAI and the merger of SpaceX and xAI, this paper introduces the three structural defects of the current review system. The first is the accuracy of technical identification; static classification cannot consider that the capability changes according to the application environment. The second is the coordination of norms, as the security of a country is increasingly used to achieve technological containment in the background of geopolitical competition. The third is dynamic adaptability; that is to say, with the exponential growth in agents' capabilities, the revision of review norms has been slow. A new hierarchical review model based on functions, rather than product labels, will be put forward in this paper. The five parts of the AI Agent model are Autonomy, Connectivity, Adaptability, Collaboration and Accumulation, and one of them has been assigned to each of the four risk levels. If any aspect reaches the third level, a deep audit will be conducted; if two or more aspects reach the third level or any single aspect reaches the fourth level, then strict measures will be taken. Some proposals for the construction and operation of the Chinese review system were also made in this paper, such as adding a particular review guide for AI agent technology, establishing a joint expert assessment team to conduct practical capability tests, and introducing a regular update mechanism for threshold parameters. By changing the focus of the review from what a technology is to what it can do, the model aims to provide a theoretical basis and an institutional reference for China to improve the judgment criteria for the civilian and military dual-use attributes of AI Agent technology in foreign investment security review.

中图分类号: