HomeArticle

AIs have started sending WeChat messages to each other. Who will step in to supervise them?

爱范儿2026-09-07 10:16
The uncharted territory requires new rules.

WeChat is starting to let AI chat for you.

It is reported that WeChat is conducting internal testing of the "Xiaowei AI Social" feature: in the future, if you want to know your friends' updates, you can call WeChat's built-in AI Agent "Xiaowei" to contact the other party's Xiaowei and get a direct response from it.

You don't have to ask in person, and the other person doesn't have to answer in person. The ultimate convenience of civilization is probably that we can both be absent from the entire conversation.

The "human vibe" of social interactions is hanging by a thread, but Xiaowei is not an isolated product experiment. Starting from AI customer service, there have long been Agents standing between us and the services we use; conversely, we have also begun to use Agents to reply to inquiries on Xianyu and fend off harassing calls.

Both ends of communication will sooner or later be dominated by AI. The world is inevitably rushing into a new era —

An era where the vast majority of affairs are completed through conversations between Agents.

A2A, A Major Trend That Is Unfolding Right Now

The trend of letting Agents take over affairs is most vividly reflected in the office scenario.

Not long ago, WeCom officially announced a feature upgrade: AI Agents such as Workbuddy and DeepSeek Harness can read and call various documents, spreadsheets and schedules through WeCom's interfaces.

The most direct significance of WeCom integrating Agents is not that "AI can help us do more things", but a change in product mindset: software has begun to proactively consider how it can be understood and used by Agents.

In other words, Agent readability is becoming a new basic design principle of the Internet, following human readability.

Once more and more services are willing to open their capabilities in a way that Agents can understand, the next step will naturally be: Agents can not only call software, but also call other Agents, and better connect to services with the help of the capabilities of "specialized" Agents.

At this point, we enter the Agent to Agent (A2A) stage.

At this stage, what we need is no longer just interfaces, but to develop a dedicated "communication language" for Agents.

Figure | X@@liam_fallen

In the final analysis, from the perspective of information exchange, natural languages and interactive interfaces designed for humans are rather inefficient protocols. The only reason they are still in use today is to accommodate the limited expression capabilities of humans and the digital infrastructure that is too difficult to rebuild from scratch.

Considering that A2A is a brand new scenario without historical baggage, and both parties in the communication know that the other is an Agent, it is obviously much more convenient to directly adopt communication specifications specially designed for A2A interactions than to imitate human operations.

The A2A protocol launched by Google is exactly such a set of communication specifications.

It uses structured language to define the message structures for different Agents to discover each other, conduct dialogues, delegate tasks and return results. Later, the A2A protocol was handed over to the Linux Foundation for management, and has been supported by more than 150 organizations.

If the A2A protocol is widely popularized, the way we work will most likely become:

Users describe their intentions in natural language. After the Agent understands the goal, it connects to various service Agents through structured protocols, and then "translates" the results back to natural language for users to review.

This is very similar to today's Vibe Coding. The real working language of Agents is command lines and APIs, but all these specific steps are packaged into a "black box" and hidden under the user interface. All you need to do is issue commands and check the results.

The Next-Generation Internet Interfaces No Longer Serve Humans

Behind the trend is demand. To put it bluntly, who wouldn't want Agents to handle those Shit Jobs?

The vast majority of work that Agents can help complete are affairs with clear rules, high repeatability, and whose value mainly comes from execution rather than creation.

Tasks that sound like a headache, such as filling out forms, comparing prices, booking tickets, reimbursements, after-sales services and replying to emails, were previously done by people only because we had no other choice; once AI can take over, the vast majority of people will unhesitatingly pass these messes to AI.

Figure | X@Tibor Blaho

However, the current model where AI assistants operate interfaces on our behalf to complete these tasks may only be a transitional stage.

In the A2A era, the user interface itself is no longer a necessity — all users need to do is describe their intentions. Steps including understanding intentions, finding services and completing tasks can all be handed over to Agents.

In fact, before this attempt to bring Xiaowei into friend relationships, WeChat has already tested the waters for this transformation through several rounds of gray-scale tests.

In June this year, Xiaowei began to gain the ability to operate some native WeChat features. You don't need to open the Didi mini-program or flip through menus on food delivery platforms. Just tell it "Help me call a car to Baiyun Airport" or "Order a Cantonese food takeaway with the highest rating nearby", and it can call the corresponding mini-program in the background to complete searches, price comparisons, order placement, and even make payments directly through the exclusive "AI Special Card".

The logic of Xiaowei exactly foreshadows the core transformation in the A2A era: mobile phones will evolve from "terminals for humans to operate Apps" to "terminals for humans to authorize Agents to access the Internet".

Figure | Stuff

Once Agents become the default intermediary between users and services, the business model will change accordingly.

We all know that the foundation of the advertising industry is to compete for human attention, but Agents don't care about the banners and advertising storylines designed for humans. They have their own metrics of concern, for example, they may pay more attention to rebates, ratings and discounts when booking flights and hotels.

If all parties act in good faith, this may be a better model in terms of user interests. Merchants will directly compete on prices for Agents, skipping middlemen such as advertisers and KOLs, and turn the budget originally used for advertising into discounts for users, which seems to be a win-win situation for everyone.

But there is no reason for us to believe in the premise that "all parties act in good faith".

Not long ago, *Time* magazine began testing Markdown ads on its website that are specifically designed for AI Agents to read. This is not something to worry too much about by itself — as a well-known media, the "Agent-oriented" ads placed by *Time* will indeed go through review first and come with ad labels.

But who can guarantee that all platforms that advertise to AI in the future will have the same level of integrity?

Is implanting exaggerated and misleading information in Agent-oriented ads considered normal advertising, or a kind of injection attack? If it is an attack, how can society manage such attack behaviors? But even if we set that aside, what is the difference between advertisements targeted at humans, especially those that repeatedly bombard users to implant brand impressions, and injection attacks?

At a time when machine traffic has surpassed human traffic, everyone knows that the "attention economy" business model cannot sustain; but almost no one can predict what the upcoming world will look like.

If Information Pollution Enters an Automatic Loop

The "credibility" issue, the dark cloud hanging over the A2A building, seems more gloomy than we imagined.

Earlier this year, Moltbook, a forum that only allows AI Agents to post and interact, became a hit for a while.

Just one week after its launch, more than 1.5 million Agent accounts debated philosophy, invented religions, discussed cryptocurrencies on the forum, and even tried to create a dedicated language that humans cannot understand.

Moltbook seems to be a fun experiment, but security researchers soon found that these Agents frequently produce information that sounds authoritative but is completely wrong in their conversations with each other.

Analysis by content moderation agency Originality.ai shows that the number of harmful factual errors on Moltbook is three times that of similar topics on Reddit, and most of these errors are "made up" by Agents in a confident and professional tone.

What is more dangerous is that when other Agents read these contents, they will take the wrong information as reliable input, further spread and reinforce it.

Similarly, a commentary article in Harvard Medical School assumed an emergency department scenario: if Agent A, which is responsible for reading X-ray films, makes a wrong judgment, for example, mistaking a severe fracture for a simple one, then Agent B and C, which are responsible for subsequent ward arrangement and emergency resource coordination, will take Agent A's judgment as a fact, make wrong arrangements, and even apply this judgment to other patients with similar symptoms.

The whole thing is a bit like us writing AI hallucinations into articles, then other AIs crawl the articles and take the wrong information as fact...

After going through a cycle, a "false fact" is created in this way.

If false information only circulates idly inside a closed Agent network, its impact may still be limited — but what if Agents start using this information to guide actions, or even actively deceive humans?

In a case reported by Reuters, a computer science student found that someone tried to inject malicious code into an open source project on GitHub, so he raised an issue to remind the maintainer.

Soon, two accounts posted seemingly well-documented replies, refuting his judgment that "the project is under attack".

The problem is that these two comment accounts are sockpuppet accounts created by the out-of-control Anthropic Mythos 5 Agent in a security test. It registered these small accounts just to use language to deceive humans who might discover its attack behavior.

Information pollution is certainly not exclusive to A2A networks, but the high connectivity and recursive loops of A2A networks will make risks expand at a speed far exceeding the past. As Agents are widely deployed in production environments, the "error spiral" may drag us into it at any time.

For this reason, what Agents can trust, what they cannot trust, and when human inspection and approval are mandatory, have become the "top priority" for