The rapid emergence of AI-powered smartphones capable of automating a wide array of tasks is transforming the consumer technology landscape in China, but it is also igniting a fierce debate over user privacy and control. Major manufacturers including Huawei, Honor, OPPO, vivo, and ZTE are actively integrating AI Agent capabilities into their latest flagship models, promising a new era of digital convenience.
A prominent example is the "Doubao Phone" (努比亚NaviX Ultra), developed by ByteDance, which received its network access license and was scheduled for sale in September 2026. This device is specifically designed to automate tasks such as price comparison and ordering food, showcasing the potential for AI to interact deeply with a user's digital life. However, this level of automation comes at a cost, as these AI agents often demand high system permissions, notably "accessibility services" (无障碍权限). This extensive access allows them to read screen information, simulate clicks, and switch between applications, effectively granting AI the ability to interact with chat records, bank accounts, and payment pages.
Concerns regarding privacy and data security are widely reported by various outlets across China. Experts and officials, including National Political Consultative Conference member Jiang Haoran, have openly questioned how to effectively regulate these AI phones if they misuse their extensive system permissions. These worries are not theoretical; in early March 2026, the Ministry of Industry and Information Technology's cybersecurity threat and vulnerability information sharing platform issued a security alert. The alert highlighted high security risks in some instances of OpenClaw, an open-source AI tool with strong automation capabilities, which could lead to information leakage or malicious use.
Experts use the term "Intrusive AI" (侵入式AI) to describe AI agents that leverage accessibility permissions to bypass traditional application boundaries. This capability, they warn, could lead to large-scale data collection and significant user privacy exposure. The problem is exacerbated by black and grey market actors who have already exploited accessibility permissions for illicit activities, such as automatic verification code collection and automated ticket or shopping processes. Traditional "sandbox" mechanisms, designed to isolate application data and enhance security, can be circumvented by AI agents operating with elevated system permissions. Some of these AI agents are even capable of operating autonomously, without requiring code, fundamentally shifting the paradigm from "manual operation" to "automated operation."
Despite its commercial launch, the "Doubao Phone" (努比亚NaviX Ultra) has faced practical limitations. Many mainstream applications have restricted its access, leading to situations where users are disconnected from popular games like "Honor of Kings." In response, Doubao Phone introduced a Screen Automation Execution Protocol (SAEP), which allows third-party applications to declare whether they accept GUI intelligent agent operations. This protocol includes a 30-day public comment period, and if apps explicitly refuse, the AI phone's automation capabilities will be limited within those applications.
Adding to the complexity, some users have alleged that certain applications, particularly those required by universities, demand excessively high permissions. These apps are reportedly capable of scanning other applications like Taobao, JD, and Pinduoduo, and even manipulating the phone to open additional permissions. It has also been alleged that some mobile AI agents automatically enable accessibility permissions without the user's knowledge, silently collecting user privacy data. Furthermore, it is technically possible, some reports suggest, for AI agents to bypass payment password input, potentially leading to unauthorized fund transfers. Netizens reportedly dubbed the "Doubao Phone" a "pure ByteDance dedicated machine" if mainstream apps refuse its GUI operations. Despite these concerns, some reports suggest the "Doubao Phone" sold out quickly, creating a price surge in the second-hand market, with its second generation reportedly achieving "one-second sales exceeding 100 million yuan" on its first day.
The Chinese government is actively promoting the adoption of AI-enabled products. In June 2026, China's Ministry of Commerce and seven other government bodies released 17 measures to promote "AI plus consumption," aiming to stimulate the economy by encouraging consumers to upgrade. Beijing is guiding product design and consumer expectations, hoping AI will drive spending and economic growth. IDC predicts that in 2026, China's new generation AI smartphone shipments will reach 147 million units, a 31.6% year-on-year increase, accounting for 53% of the total market.
However, the regulatory framework lags behind technological advancements. Former China Mobile Chairman Wang Jianzhou stated that existing user agreements, privacy protection measures, and authorization systems are designed for human operation, not for AI agents. He emphasized the urgent need for new standards and protocols encompassing system-level (how operating system capabilities are exposed to agents), application-level (how apps open entry points to agents), and data-level (what user information agents can access) aspects.
Many questions remain unanswered. How to effectively govern AI phones if they abuse system permissions is an open question raised by officials. The long-term impact of relying on AI for tasks might lead to users becoming lazier in thinking and developing a sense of losing control over their devices. Whether users truly understand how their information and permissions are used by AI phones and the associated risks remains a core challenge. The ownership, usage rights, and control of data collected and used by AI phone intelligent agents, which flows between manufacturers, developers, and cloud service providers, are difficult to define. If data leakage occurs, the chain of accountability is long and difficult to trace effectively. Future AI agent operations could become more covert and efficient, and cross-platform unauthorized operations could cause greater harm and wider impact. Establishing clear boundaries for AI agents as they become human proxies in the digital world is considered more critical than functional innovation itself. The development of AI phones is not just a technological race but also a compliance race, as Chinese tech companies' overseas development will depend on passing strict privacy and compliance reviews in various countries.
New standards and protocols for AI phone ecosystems will require collaborative efforts from manufacturers, chip developers, operating system providers, large model providers, app service providers, and telecom operators. The question of whether users truly need an AI phone that automates tasks and improves efficiency is still being considered by major manufacturers. The current underlying commercial interest distribution mechanism for AI phones is still unclear, with a need to shift from "traffic distribution" or "token distribution" to a mechanism based on "results achieved by intent." Apple is reportedly developing an AI home security camera, expected in 2027, that will only provide text descriptions of events instead of video recordings, aiming to address privacy concerns, though its acceptance by users who might need video evidence is yet to be seen. It is currently unclear if all processing for Apple's rumored AI home security camera will be done on the device.
As AI-powered smartphones become more pervasive, the challenge lies in balancing the undeniable convenience they offer with robust protections for user privacy and control, ensuring that technological advancement does not come at the expense of individual autonomy and security. This complex interplay of innovation, regulation, and consumer trust will define the future of smart devices.
