2026年9月10日

AI Abusing Phone Permissions: From Ordering Your Coffee to Secretly Controlling Your Money

As business consultant Liu Run remarked, “Humans have become so lazy that they don’t even want to or...

As business consultant Liu Run remarked, “Humans have become so lazy that they don’t even want to order their own takeout.” In 2025, AI phone assistants have flooded the market, offering unparalleled convenience—but quietly opening a Pandora’s box for privacy and security.

AI permissions have become the next battlefield for tech giants. Mainstream smartphone manufacturers are rolling out AI agents, and large model platforms offer “operation-capable” AI phone assistants. With just a command, these assistants can read screens, simulate clicks, compare prices, place orders across apps, and even summarize content—delivering unprecedented convenience.

However, tests show that when a user says, “Order me a coffee,” the AI assistant may automatically open a food delivery app, search, and display nearby options—without explicit authorization or asking for preferences. Users, in pursuit of efficiency, may unknowingly surrender control over app choices.

More alarmingly, AI assistants can bypass sandbox protections in apps like WeChat and Taobao, accessing chat histories, verification codes, and bank details—raising serious privacy and payment security risks. Lawyer Tian Junwei notes that AI amplifies traditional vulnerabilities, blurring the boundary of user and platform responsibility.

Two core risks of AI permission abuse:

  1. Payment security risks: AI can read verification codes in milliseconds and complete transactions. Grey-market tools exploit accessibility permissions for automated ordering and code theft.
  2. Privacy leakage: AI may access private conversations, shopping records, and financial assets. Ambiguous user authorization complicates accountability.

In practice, AI can “invisibly control” users. While users interact with their devices, they cannot easily see how AI makes decisions, unlike the visible reasoning when chatting with large models.

Expert recommendations:

  • Informed authorization: Users must clearly understand the actions they authorize, rather than passively agreeing through complex terms.
  • Technical safeguards: Assign AI independent identities and dedicated data channels, with traceable operations.
  • Operational security: Avoid enabling password-free payments, set limits, and exercise caution with automated AI payments.

In the AI era, governance must balance convenience with the protection of personal privacy and financial security.

接著讀