Skip to main content

AI Agents Barred from Financial Apps Without Dual Approval

No More Sneaking Around: AI Agents Need Double Permission to Touch Your Bank App

Imagine handing your phone to a helpful assistant, only to watch it fumble through your banking app. That's exactly the kind of scenario Beijing wants to prevent. On August 27, the Beijing Financial Technology Industry Alliance released a group standard titled "Security Requirements for Intelligent Agent Technology in Financial Applications" — the first of its kind in China.

At its core, the rule is simple: third-party AI agents on mobile devices cannot use system permissions to automatically read or operate a financial app's interface without the financial institution's blessing. If they pull data via microphone, screen capture, or screen sharing, they must follow the called party's security policies. Experts call this "dual authorization" — both the user and the institution must say yes.

Who's Behind It?

The standard was led by the Beijing National Financial Technology Certification Center and co-developed by heavyweights like China Post Savings Bank, ICBC, China UnionPay, Bank of China, and Huaxia Bank, alongside tech players Huawei, Ant Group, Volcano Engine, and Tencent Cloud. It covers five key areas: initialization and input, model reasoning and decision-making, identity authentication and operation, data security and privacy protection, and risk control and compliance.

Why Now? A Messy Wake-Up Call

Rewind to December 2025. A smartphone model with a built-in AI assistant hit the market, and users soon reported strange logins and payment glitches on multiple bank apps. By December 6, the assistant had quietly dropped its ability to operate financial apps. At the time, no specific rules existed.

The problem? Many agents rely on screen reading, simulated clicks, and OCR to recognize text — bypassing the official APIs that app developers provide. This approach works broadly but sidesteps permission controls, risk management, and liability. In licensed financial scenarios like payments and wealth management, that's a direct threat to user accounts and funds.

Regulatory Momentum Builds

May 2026 saw the Cyberspace Administration of China, the National Development and Reform Commission, and the Ministry of Industry and Information Technology jointly issue opinions on managing agent permissions and behaviors. By July, a series of national standard technical guidance documents on AI agent interconnection were released, and the State Administration for Market Regulation announced a mandatory national standard plan for "Basic Requirements for Intelligent Agent Application Security." On July 15, the Cyberspace Administration published a new batch of terminal-side generative AI service filings — seven in total.

Industry Shifts: From Bypass to Cooperation

On the terminal side, manufacturers are changing tack. The new generation of Doubao phones now requires the app developer's consent — no more screen reading or simulated clicks after user authorization. Only when an app offers MCP services and allows control can it be accessed. Similarly, Jieyue Star STEPX Neo adopted the GUI-MCP protocol, letting developers decide what to open up.

In June 2026, WeChat partnered with Honor and other phone makers on A2A (Agent-to-Agent) assistant capabilities. Users can initiate WeChat calls or send messages via voice assistants — but only because WeChat actively opens its API to connect with the manufacturer's agent. That's a second layer of authorization beyond the user's own.

Internationally, Google and Samsung took a similar route on the Galaxy S26 series: system-opened permissions paired with app cooperation.

Image

Image

Image

Key Points

  • Dual authorization required: AI agents need both user and financial institution approval to operate financial apps.
  • First of its kind: The standard is China's first group standard focused on AI agent security in finance.
  • Broad backing: Developed by major banks, payment networks, and tech companies.
  • Trigger event: December 2025 incidents with a phone assistant accessing bank apps without proper controls.
  • Industry pivot: Manufacturers are moving from screen-reading workarounds to API-based cooperation.

Standard Link: Full Text Link: Beijing Financial Technology Industry Alliance - Group Standard