The more your phone “understands” you, the more transparent your privacy becomes?
Release Date:
2025-04-13
Simply issue the command “Help me order a coffee” to your phone, and it will use information such as the time, your location, and your behavioral patterns to identify your preferred brand and flavor. It will then automatically launch your go-to food-delivery app, complete the order, fill in the delivery address, process the payment, and handle everything else—without any manual input from you. This kind of convenient everyday scenario is now a reality.
Recently, many smartphone manufacturers have launched in-house or third-party large‑model‑powered mobile agents, such as Super Xiao Ai, BlueHeart AI, and Bixby. Backed by advanced large models and artificial intelligence (AI) technologies, these assistants can serve as users’ personal aides, autonomously handling tasks like ordering coffee or sending WeChat red envelopes to multiple contacts.
“While enjoying the convenience brought by mobile AI agents, we must also remain keenly aware that this convenience comes at the cost of surrendering our personal privacy data,” Liu Huiyong, Director of the Information Security Department at the School of Computer Science of Beijing Information Science and Technology University and an associate professor in the field of cyberspace security, told reporters. As AI begins to “take over” smartphones, the age-old trade-off—“exchanging privacy for convenience”—has resurfaced in new technological use cases. Safeguarding user privacy is a challenge that cannot be sidestepped if mobile AI agents are to develop in a healthy and sustainable manner.
Accessibility features harbor hidden risks.
By reviewing the announcements from multiple smartphone AI‑assistant launch events, reporters found that these assistants are largely built around AI technology, integrating speech recognition, natural language processing, and multimodal perception. They offer features such as information retrieval, AI‑driven writing, sketch‑to‑image conversion, and video‑locked‑screen functionality, bridging the gap between basic Q&A and proactive services—turning smartphones into users’ personal assistants. Meanwhile, a small number of manufacturers have further enhanced the naturalness and fluidity of human–machine interaction by embedding large, on-device, localized models.
“The use of mobile AI agents is predicated on the extensive collection and utilization of data. To enable functions such as AI‑powered screen reading and simulated taps, users are often required to activate accessibility features,” said Li Ruiyuan, an associate professor at the School of Computer Science at Chongqing University, in an interview with a reporter.
He explained that accessibility features are a dedicated set of tools built into the Android system for people with disabilities, encompassing screen readers, screen magnification, auto‑tap, enhanced audio, and customizable subtitles—designed to enable users with disabilities to use smartphones just as easily as anyone else. For a mobile AI agent to “take over” a phone, the user must first grant it access to the Accessibility Services; then, leveraging an AI‑powered screen reader, it can access all apps on the device and, much like a human, perceive, interpret, and analyze onscreen elements—including bank card details, special password keyboards, and chat histories. Ultimately, it simulates human finger movements to perform tasks such as online shopping, money transfers, and app downloads.
Liu Huiyong further explained that once users enable accessibility features, it’s akin to installing a universal access card on their phone. When using voice assistants, smart recommendations, and other functions, the phone’s AI can unrestrictedly collect sensitive data such as location, app usage patterns, and WeChat messages. Moreover, some smartphone AIs even automatically activate accessibility permissions without the user’s knowledge, silently gathering personal information.
“Contacts, text message histories, call logs, and other data stored on a smartphone are all considered sensitive information. Operating systems typically implement access‑control mechanisms to protect such data, requiring apps to obtain explicit user consent before accessing it,” said Liu Huiyong. “However, when users rely on smartphone assistants to perform tasks like sending WeChat messages via voice or one‑tap red‑envelope transfers, the situation is different. These operations necessitate cross‑app bundled authorization, during which the operating system grants access to SMS or WeChat permissions to ensure the relevant functions operate smoothly.”
Multiple stakeholders are working together to safeguard personal data security.
“The convenience of technology and the risks to privacy are inherently at odds. Meanwhile, industry standards and legal regulations often lag behind technological adoption,” observes Liu Huiyong. He notes that today, the data collected and utilized by mobile AI agents flows among multiple stakeholders—such as device manufacturers, AI developers, and cloud service providers—making it difficult to determine who holds ownership, usage rights, or control over that data. When a data breach occurs, the lengthy accountability chain further complicates effective attribution and tracing.
Liu Huiyong cited examples: some low‑security mobile agents may exploit accessibility features to automatically send red envelopes in WeChat groups and lure users into clicking, thereby transferring funds to criminals’ accounts and causing financial losses. Alternatively, they might sell the personal data they have collected to third‑party companies, leading to algorithmic discrimination. “Due to the lack of technical standards and protective mechanisms, even when users suffer losses, it is often difficult for them to recover their funds through effective channels,” Liu Huiyong said.
In response, Liu Huiyong recommends that mobile phone manufacturers and operating system platforms continuously refine relevant technologies, streamline user data‑handling processes, and develop more intelligent internal defense systems to prevent the emergence of covert data‑abuse issues as smart‑agent technologies evolve.
In addition, Li Ruiyuan suggests that smartphone manufacturers should strive to offer on-device AI–enabled smart‑app services. While cloud‑based AI can deliver more convenient functionality, it requires users’ data to be frequently uploaded to the cloud, posing significant privacy risks. By contrast, on-device AI enables computations and processing to take place directly on the device—such as a smartphone—minimizing data transmission and offering a “more private” technological solution.
Ren Longlong, a lecturer at the School of Civil and Commercial Law of Southwest University of Political Science and Law, stated that the practical application of technology cannot be separated from the constraints of laws and regulations. At present, the Civil Code of the People’s Republic of China, along with the Cybersecurity Law of the People’s Republic of China, the Data Security Law of the People’s Republic of China, and the Personal Information Protection Law of the People’s Republic of China, as well as regulations such as the Regulations on the Security Management of Network Data, which took effect on January 1, 2025, all set forth provisions governing the use of emerging technologies—including data, personal information, and generative AI. Nevertheless, as an emerging technological application, mobile intelligent agents still face certain legal ambiguities.
Ren Longlong recommends that the relevant authorities should proactively introduce appropriate policies and strengthen regulatory oversight. By establishing a more refined legal framework, they should further subdivide data categories and clearly delineate rights such as ownership of data resources, the right to process and use data, and the right to commercialize data products, thereby preventing privacy breaches arising from malicious authorization.
“Until the relevant technologies and regulations are fully in place, users should strengthen their awareness of security risks,” said Ren Longlong. When using mobile AI assistants, consumers should exercise caution when enabling accessibility features, disable the password‑free payment authorization for these assistants, regularly review their phone’s privacy reports, and promptly identify and address any unusual behavior by the AI assistant. (Reporter: Wang Shanshan)
[Editor-in-charge: Zhu Jiaqi]
Source: Science and Technology Daily
Tags:
More information
Contact Us
Address:
No. 1, No. 1, New District Road No. 1, Gaocheng District, Shijiazhuang City, Hebei Province
WeChat/WhatsApp:
Phone:
Email: