Doubao AI Assistant Sparks Struggle for System Control with Major Chinese Apps

Doubao AI Assistant Sparks Struggle for System Control with Major Chinese Apps

A new AI mobile assistant launched by Doubao has triggered a conflict over system-level control, prompting defensive measures from China's dominant messaging and banking applications. The incident marks the first major confrontation involving "AI Agents" directly operating on smartphone interfaces, highlighting the friction between emerging artificial intelligence capabilities and established app ecosystems.

Users reported earlier this week that activating the Doubao AI assistant triggered security protocols in WeChat, the ubiquitous messaging platform owned by Tencent. The app flagged the AI's operation as an "abnormal login environment," forcing users offline and requiring them to switch devices to regain access. Simultaneously, mobile apps from major lenders, including Agricultural Bank of China and China Construction Bank, issued pop-up warnings demanding the AI assistant be disabled due to screen-sharing risks.

In a statement released late on December 3, the Doubao team denied allegations of hacking, clarifying that the assistant utilizes standard Android system-level permissions to function. The company announced it has temporarily disabled the capability to operate WeChat while affected accounts are being restored. Doubao characterized the software as a "technical preview" aimed at early adopters rather than a mass-market consumer product.

The standoff underscores a critical challenge for the AI industry in 2025: the battle for interface dominance. As AI agents seek to perform tasks across different applications, they face resistance from developers and security mechanisms designed to isolate apps and prevent unauthorized automated behaviors.

Security Protocols and Operational Clashes

The disruptions centered on the AI assistant’s ability to simulate user interactions. According to user feedback, the Doubao assistant was initially able to perform tasks such as platform price comparisons and information gathering. However, complications arose when the system interacted with sensitive applications. WeChat’s security systems identified the automated inputs as non-typical user behavior, triggering immediate account lockouts to prevent potential compromise.

Banking institutions reacted with similar caution. The mobile applications for state-owned banks detected the AI assistant's screen-reading capabilities—essential for the AI to "see" and navigate the interface—as a potential breach of privacy similar to unauthorized screen sharing, prompting immediate blocks on usage.

Doubao responded by detailing its technical framework, stating that its operations rely on Android’s "INJECT_EVENTS" permission. This system-level authority allows the software to cross app boundaries and simulate clicks to fulfill user commands. The company emphasized that this permission requires explicit user authorization and is disclosed in the permissions list. Doubao asserted that other industry AI assistants rely on similar accessibility permissions to provide hands-free services.

Privacy Defenses and Data Handling

Addressing privacy concerns, Doubao stated that while the assistant must read screen content to function, it generally does not store this data in the cloud. The company affirmed that screen data and operational records are not saved on servers and are excluded from model training datasets.

The company outlined its transparency protocols, noting that the assistant displays clear visual cues when executing long tasks, allowing users to interrupt the process at any time. For sensitive operations—such as payment verifications, password entry, or system-level authorization prompts—the AI is designed to pause, requiring the user to manually take over the screen. Doubao maintained that it does not perform sensitive authorizations on behalf of the user.

The Structural Conflict: Agents vs. App Silos

Technical experts suggest the friction is systemic rather than accidental. Zhang Yao, a former security specialist at major internet firms, explained that mobile operating systems utilize sandbox mechanisms to isolate applications, preventing direct data access between them. To bypass this, AI agents must simulate user clicks, which triggers anti-fraud and risk control systems in third-party apps.

"If the AI assistant does not log in via the server side, it touches the data access boundaries of different applications on the client side," Zhang said. He noted that developers are naturally sensitive to this intrusion. When users authorize an AI agent, they effectively surrender the choice of whether a specific app allows proxy operations, a surrender developers like Tencent strongly resist. Zhang predicted that resolving these conflicts would be difficult, as powerful developers will likely continue to block third-party agents from controlling their interfaces.

Market Implications and OEM Dominance

The incident highlights the fragmentation of the Android ecosystem compared to closed systems. Zhong Xiaolei, an analyst at Omdia, pointed out that while manufacturers are open to accessing different large models, the lack of standardized protocols creates a chaotic environment. Currently, the "simulated click" method is a generic solution that offers broad compatibility but hits efficiency bottlenecks and triggers security tripwires.

Industry observers believe the balance of power lies with smartphone manufacturers rather than third-party model developers. Zhang noted that while model developers have technical superiority in AI, phone manufacturers control the underlying operating system. Consequently, manufacturers like Xiaomi are likely to prioritize their native assistants rather than ceding system-level privileges to third-party software.

Zhong added that the future competition is "system against system." To achieve seamless AI integration without triggering security lockdowns, the industry requires standardized APIs and open protocols between models and applications—a challenging prospect given the current fragmentation of the Android market compared to rivals like iOS or HarmonyOS.

Subscribe to ChinaBiz Insider

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
[email protected]
Subscribe