Doubao phones have resumed sales. Most mobile phone manufacturers, including Huawei and Honor, are still invoking accessibility permissions.
On one hand, in the second - hand market, there's a phenomenon where mobile phones are hyped up to sky - high prices and are extremely difficult to obtain. On the other hand, major platforms like WeChat and Alipay are "encircling and blocking" it. On one hand, there are technological fantasies of AI taking over tasks. On the other hand, there are pointed questions about privacy leakage and compliance risks... Since its launch, the controversies surrounding the Doubao Phone have never stopped.
The reason for the strong reactions from all parties is that Doubao has accessed the underlying permissions of the mobile phone system. It's like an AI growing an "invisible hand". Without relying on apps and mobile phone manufacturers, it can simulate human clicks and swipes, and it has extremely high universality.
Reporters from "IT Times" will conduct a comparison from three aspects: mobile phone manufacturers, app developers, and foreign AI phones to explore the deep - seated logic behind the huge controversies caused by the Doubao Phone.
On December 16th, according to the official website of ZTE Mall, the waiting list application channel for F - codes of the Doubao Phone Assistant and its cooperative model nubia M153 has been restarted, and the product purchase qualification has been officially restored.
Different Modes, the Same Purpose
Half a year after the report "There's a Hand Across the Screen! Behind the AI Phone Automatically Ordering Coffee is the Stealthily Activated Accessibility Function", reporters from "IT Times" tested new models of major mobile phone manufacturers again and found that the intelligence level of AI assistants has been "significantly enhanced" and is no longer limited to ordering coffee.
Image source: Jimeng AI
"Help me choose a cheap pair of jeans on Taobao." When giving this command to Honor's new model Magic 8 and Huawei's new model Mate 80, the AI assistant can not only open Taobao and search for the "jeans" category but also automatically compare prices and filter out "cheap" products according to the instructions and display them in front of you. If more detailed size and color information is provided, the AI assistant can complete the task "in one go", and users only need to make the payment.
Behind the increasing intelligence of AI assistants is the invocation of "accessibility" permissions. In the "Privacy Policies" of various mobile phone AI assistants, reporters still found explanations from mobile phone manufacturers about invoking accessibility functions, simulating clicks, screen - reading, and auxiliary functions to assist AI decision - making.
For example, in the "Statement on Honor AI Basic Services and Privacy" of Honor's new model Magic 8, the "Context Awareness" clause clearly states: "To accurately obtain operation information and screen content on the application interface, we will dynamically use the system's accessibility function to obtain the above information." Compared with the previous generation Magic 7's statement "To accurately obtain application usage information, we will dynamically use the system's accessibility function to analyze application usage", the new model's clause emphasizes "obtaining operation information and screen content on the application interface".
Privacy policies of Magic 8 and Magic 7
Xiaomi and vivo list the simulated click function as a separate clause, stating that "this function aims to convert your voice commands into simulated operations just like using your fingers. We need to collect the following information: the positions of interface controls, text, and images, media and audio - visual data, contact information, etc. At the same time, the auxiliary function permission needs to be enabled to assist in obtaining the information you input and the content on the screen."
Privacy policies of Xiaomi and vivo
Qu Zilong, the founder of the security team Network Juggernaut, once explained to reporters from "IT Times" that to prevent apps from reading each other's data, an isolation system is generally set up, and only by accessing the corresponding API (Application Programming Interface) can data be invoked. The accessibility function belongs to the system - level API, which can read the interaction information between users and devices and can represent apps to interact with users. For example, when the mouse pointer hovers over a key area on the screen, users can get feedback without actually touching the screen. "It's like a 'universal card' that can open the 'access control' between apps."
However, in front of the Doubao Phone, the invocation of "accessibility permissions" has become "inferior". According to the analysis of technical experts, the Doubao Phone may have used the underlying system permission INJECT_EVENTS, which is a system - level dangerous permission in the Android system.
To put it simply, INJECT_EVENTS allows an app to "forge" user operation events (keystrokes, touches, trackball movements, etc.) to the system and send them to any window or app. In the Android permission design, generally only system apps pre - installed by mobile phone manufacturers or apps that have obtained the same signature key as the mobile phone system have this permission, and it is rarely open to the outside world to prevent malicious programs from batch - controlling devices.
Qu Zilong specifically explained that a mobile phone is like a sandbox, and apps cannot control other apps unless they obtain more underlying control capabilities. The main breakthrough of the Doubao AI Phone this time is the "background wake - up" ability.
This time, the Doubao Phone Assistant has chosen ZTE as its cooperation partner. ZTE is one of the few mobile phone manufacturers in the market that has not developed its own AI assistant yet. The Doubao Phone Assistant is equivalent to empowering smartphones without AI assistants.
With more underlying system permissions, the Doubao Phone Assistant can not only interact with system - built - in apps such as the camera, photo album, notepad, calendar, and itinerary but also get rid of the dependence on "accessibility tools". It can open multiple apps simultaneously, providing a smoother experience.
Big Players and Banks Say "No" Collectively, Game - related Apps are Less Affected
As a large - model enterprise, Zhipu has also taught AI to "use mobile phones". The capabilities of its released large - model AutoGLM are comparable to those of the Doubao Phone. However, a "smart" move is to open - source it and prioritize deploying cloud - based mobile phones, putting the "key" to controlling AI in the hands of the entire industry.
In contrast, the "app - free" operation mode of the Doubao Phone allows users to complete tasks without opening apps, directly shaking the position of super - apps as traffic entrances and the foundation for commercial monetization. Now, apps such as WeChat, Alipay, Taobao, and banks have restricted the use of the Doubao Phone by forcibly popping up warning windows or setting login restrictions on the grounds of security risk control.
According to Article 7.3 of the "Tencent WeChat Software License and Service Agreement", it is clearly stipulated that it is prohibited to log in to or use this software and services through third - party software, plug - ins, cheats, or systems that are not developed or authorized by Tencent, or to perform automated operations.
Tencent responded: "There is no special action. Maybe the Doubao Phone Assistant triggered WeChat's risk control mechanism, and its simulated click operations were recognized as 'automated scripts'." Alipay is similar to WeChat and has judged the actions of the Doubao Phone Assistant as "cheat scripts".
From a technical perspective, the risk control system does not directly "recognize" Doubao. Instead, it comprehensively judges that the current operation is not performed by a real person by analyzing the abnormal characteristics of the device and user behavior.
In the article "A Complete Guide to Anti - Crawling and Anti - Cheating Technologies in 2025: The Offensive and Defensive Battle from Device Fingerprinting to AI Risk Control", it is mentioned that device fingerprinting is the core means of identifying terminal devices. The risk control system will collect hundreds of parameters of the device's hardware, software, and network to generate a unique "device fingerprint" to detect whether the device is a simulator. Behavioral timing analysis will combine behavior data such as mouse trajectory, touch pressure, and scrolling speed to build a dynamic portrait to distinguish real - person operations from automated scripts. Since the Doubao Phone uses the INJECT_EVENTS, which is a high - risk system permission, it will be identified as a risk label.
From an ecological perspective, super - apps rely on the user traffic and scenario barriers accumulated over the years, and the entrance is a crucial commercial monetization position. Alibaba has just released the Quark AI glasses. Reporters from "IT Times" tested them and found that it is the "Qianwen Large Model" that realizes intelligent driving, and it has opened up Alibaba - affiliated ecological apps such as Taobao, Gaode, Alipay, and Fliggy to realize functions such as navigation, price comparison, and booking flights and hotels.
However, this AI collaborative model within the ecosystem is more like "internal empowerment" on the existing commercial map rather than a subversion of the existing traffic pattern. Doubao is trying to bypass the traffic entrances of super - apps directly as an "external intruder", which undoubtedly touches the core interests of big players.
So, what do small - app developers think of the Doubao Phone taking over apps?
"Game - related and tool - related apps are still taking a wait - and - see attitude, but social and content - related apps will oppose it more strongly." Zhang Chen (a pseudonym), a technical staff member engaged in mobile phone app development, told reporters that for apps with strong operability, all the Doubao Phone Assistant can do is the "opening" step. The original intention of users to use apps is to operate them by themselves, and users who are willing to use Doubao to open such apps need more precise instructions. This also means that these apps have relatively high user stickiness and relatively independent functions, and the intervention of AI assistants is difficult to replace the core user experience.
However, for small social and content - related apps, their revenues often depend on user stay time, content exposure, and ad clicks. The Doubao Phone's "one - step - to - the - goal" operation mode may allow users to quickly skip content recommendations and ad displays unconsciously and directly reach the final result, which is undoubtedly "hitting the vital point".
Compliance Concerns are Becoming More Prominent, Foreign Phones are Moving More Slowly
While the "Domestic Jarvis" is making waves, foreign AI phones seem to be carefully exploring the balance between privacy compliance and ecological compatibility.
In September, Apple's Apple Intelligence was launched on all overseas device platforms. Its core functions include real - time translation, parsing screen content and enabling image search, visual intelligence for text summarization, as well as Genmoji 2.0 that can generate exclusive dynamic emojis and "Workout Buddy" that provides personalized encouragement based on fitness data. However, these functions have not yet achieved cross - app automated operations like domestic AI assistants and still require users to manually authorize each step of the operation.
The Magic Cue function of Google's Pixel 10 series, although claiming to "anticipate user needs", actually only stays at the information - pushing level. For example, it can automatically retrieve flight numbers from Gmail during a call and recommend corresponding photos during a chat. The whole process does not require users to manually search, but it has never broken through the boundary of "passive suggestions" and has not involved real cross - app proxy operations. The AI functions of Samsung's Galaxy series still mainly focus on basic scenario reminders and ecological linkage. Even when cooperating with large models such as Baidu, it has not launched a "global AI agent" like domestic phones.
On the contrary, in China, users have a high acceptance of efficiency tools. In high - frequency scenarios such as comparing prices and placing orders for takeaways, automatically recording bills, extracting document summaries, and cross - device collaboration, there is a strong demand for AI proxy operations. IDC predicts that in 2026, the shipment volume of China's new - generation AI phones will reach 147 million units, a year - on - year increase of 31.6%, accounting for 53% of the overall market.
However, under this "rapid - advancing" development model, concerns about compliance and security are gradually emerging. The Doubao Phone may just be the beginning. As more mobile phone manufacturers focus on AI functions, how to ensure the safe use of user data and clarify the responsibility boundaries of AI decisions while improving the user experience will become an important issue that the entire industry must face.
This article is from the WeChat official account "IT Times" (ID: vittimes), author: Shen Yibin, editors: Hao Junhui and Sun Yan. It is published by 36Kr with authorization.