Unauthorized automated operations on financial apps are not allowed without the authorization of financial institutions.
Recently (August 27), the Beijing Financial Technology Industry Alliance released the "Security Requirements for Intelligent Agent Technology in Financial Applications" group standard, which is the first group standard focusing on the security of intelligent agent applications in the financial sector. The standard clearly states: third-party intelligent agents on mobile devices must not use system permissions to automatically read and operate the GUI interface of financial application software without the authorization of financial institutions; when obtaining data through microphone, screen capture, recording, or screen sharing permissions, they must comply with the security policies of the called party. Industry experts summarize the above requirements as "dual authorization": intelligent agents must obtain both user and institutional authorization to operate financial apps.

This standard was led by the Beijing National Financial Technology Certification Center, jointly developed by financial institutions such as China Post Savings Bank, Industrial and Commercial Bank of China, China UnionPay, Bank of China, Communications Bank, and Huaxia Bank, as well as technology companies like Huawei, Ant Group, Volcano Engine, and Tencent Cloud. It applies to financial institutions and technology companies conducting development and security construction of intelligent agent technologies in financial scenarios. The standard covers five aspects: initialization and input, model reasoning and decision-making, identity authentication and operation, data security and privacy protection, and risk control and compliance, making it the first group standard in China focusing on the security of intelligent agent applications in the financial field.
In December 2025, after the release of a smartphone model equipped with an AI assistant, users reported abnormal logins and payment issues on multiple bank apps; on the same month's 6th, the assistant removed its functionality for operating financial apps. At that time, there were no specific rules in the industry.
As intelligent agents accelerate their deployment in financial scenarios, the risks posed by their high-level permissions have attracted attention. A financial technology professional explained that some intelligent agents achieve this by reading screens, simulating clicks, and using OCR to recognize interface text, rather than using official APIs provided by the app developers. This method has wide coverage but also bypasses the management of permission scope, risk control, and liability division by the app developers. In licensed financial business scenarios such as payments and wealth management, such operations directly affect user accounts and fund safety.
In May 2026, the Cyberspace Administration of China, the National Development and Reform Commission, and the Ministry of Industry and Information Technology jointly issued the "Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents," proposing to manage the permissions and behaviors of intelligent agents. In July of the same year, the "Artificial Intelligence Intelligent Agent Interconnection" (GB/Z185.1~185.7—2026) series of national standard technical guidance documents were released, and the State Administration for Market Regulation simultaneously issued the mandatory national standard plan for "Basic Requirements for Intelligent Agent Application Security." On July 15, the Cyberspace Administration of China announced a new batch of terminal-side generative AI service filing lists, totaling seven items.
On the terminal side, many manufacturers have adjusted their technical routes, with the common point being that operations require the consent of the app developer. According to reports, the new generation of Doubao phones has changed its collaboration approach with super apps like Alibaba and Tencent, no longer reading the screen or simulating clicks after user authorization. Only when the app itself provides MCP services and allows control can it be accessed. At the same time, Jieyue Star STEPX Neo also adopted the GUI-MCP protocol, allowing the app developer to decide on the open scope. In June 2026, WeChat and Honor and other phone manufacturers launched A2A (Intelligent Agent to Intelligent Agent) assistant capabilities, enabling users to initiate WeChat calls or send messages via voice assistants — this capability is opened by WeChat through active API access and connected with the manufacturer's intelligent agent, forming a second level of authorization beyond user authorization. Internationally, Google and Samsung also adopted a system-opened-permission and app-cooperated approach on the Galaxy S26 series.


Standard Link:
Full Text Link: Beijing Financial Technology Industry Alliance - Group Standard





