China Unveils First Financial Sector Standard for Intelligent Agent Security
Automated interactions with financial applications are strictly prohibited unless explicitly authorized by the respective financial institutions.
On August 27, the Beijing Financial Technology Industry Alliance published the "Security Requirements for Intelligent Agent Technology in Financial Applications," marking the first industry standard dedicated to securing AI agents within financial services. The guidelines mandate that third-party agents on mobile devices cannot automatically read or manipulate the graphical user interface (GUI) of financial apps without explicit institutional consent. Furthermore, when accessing data via microphone, screen capture, or sharing permissions, agents must adhere to the security protocols established by the host application. Industry experts describe this framework as "dual authorization," requiring both user consent and institutional approval for any financial app operations.

Developed under the leadership of the Beijing National Financial Technology Certification Center, this standard involves collaboration from major financial entities—including China Post Savings Bank, Industrial and Commercial Bank of China, China UnionPay, Bank of China, Communications Bank, and Huaxia Bank—alongside tech giants such as Huawei, Ant Group, Volcano Engine, and Tencent Cloud. It provides a comprehensive security framework for financial institutions and technology firms developing AI agents, covering initialization, model reasoning, identity verification, data privacy, and compliance. This initiative stands as China’s inaugural group standard addressing the security of intelligent agents in financial contexts.
Following the December 2025 launch of a smartphone featuring an AI assistant, users reported unauthorized logins and payment anomalies across various banking apps. By the 6th of that month, the assistant’s financial operation features were disabled, highlighting a regulatory vacuum at the time.
As AI agents become more prevalent in financial services, concerns over their extensive permissions have intensified. A fintech expert noted that many agents bypass official APIs, instead using screen reading, simulated clicks, and OCR to interpret interface text. While this approach offers broad compatibility, it circumvents the developer’s permission controls, risk management systems, and liability frameworks. In regulated areas like payments and wealth management, such unauthorized operations pose direct risks to user accounts and fund security.
In May 2026, the Cyberspace Administration of China, the National Development and Reform Commission, and the Ministry of Industry and Information Technology jointly issued "Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents," emphasizing the need to regulate agent permissions and behaviors. By July, the "Artificial Intelligence Intelligent Agent Interconnection" (GB/Z185.1~185.7—2026) national technical guidance documents were released, alongside a mandatory national standard plan for "Basic Requirements for Intelligent Agent Application Security" from the State Administration for Market Regulation. On July 15, the Cyberspace Administration also announced the filing of seven new terminal-side generative AI services.
Device manufacturers have increasingly adjusted their technical strategies to prioritize developer consent. For instance, the latest Doubao phone has shifted its partnership model with super apps like Alibaba and Tencent, eliminating screen reading and click simulation even after user authorization. Access is now granted only when the app provides MCP services and explicitly permits control. Similarly, Jieyue Star STEPX Neo utilizes the GUI-MCP protocol, allowing developers to define the scope of accessibility. In June 2026, WeChat and Honor introduced A2A (Agent-to-Agent) capabilities, enabling voice assistants to initiate calls or send messages via WeChat through active API integration. This creates a secondary authorization layer beyond user consent. Globally, Google and Samsung have adopted similar system-opened permission models with app cooperation on the Galaxy S26 series.


Standard Link:
Full Text Link: Beijing Financial Technology Industry Alliance - Group Standard
Related article
LetinAR Raises $18.5 Million as Optical Modules Power Next-Gen Smart Glasses
Picture yourself cruising on a motorcycle at 160 km/h when a navigation arrow materializes directly on the road, guiding your turn. With no phone in sight and no need to glance at your dashboard, essential data blends seamlessly into your field of vi
Accenture partners with Anthropic to launch first embedded AI evaluator
Dario Amodei’s initiative to embed independent safety evaluators within AI laboratories is materializing: Anthropic has announced that employees from technology consulting firm Accenture will operate on-site to audit its models and personnel.Accordin
NSF to invest $90M in three new tech centers, including robotics
Science and Technology Centers build lasting partnerships across universities, industry, and government to accelerate the adoption of new ideas and technologies for scientific discovery. | Sources: NSF, left to right: Indiana University, Bloomington;
Related Special Topic Recommendations
Comments (0)
0/500
Automated interactions with financial applications are strictly prohibited unless explicitly authorized by the respective financial institutions.
On August 27, the Beijing Financial Technology Industry Alliance published the "Security Requirements for Intelligent Agent Technology in Financial Applications," marking the first industry standard dedicated to securing AI agents within financial services. The guidelines mandate that third-party agents on mobile devices cannot automatically read or manipulate the graphical user interface (GUI) of financial apps without explicit institutional consent. Furthermore, when accessing data via microphone, screen capture, or sharing permissions, agents must adhere to the security protocols established by the host application. Industry experts describe this framework as "dual authorization," requiring both user consent and institutional approval for any financial app operations.

Developed under the leadership of the Beijing National Financial Technology Certification Center, this standard involves collaboration from major financial entities—including China Post Savings Bank, Industrial and Commercial Bank of China, China UnionPay, Bank of China, Communications Bank, and Huaxia Bank—alongside tech giants such as Huawei, Ant Group, Volcano Engine, and Tencent Cloud. It provides a comprehensive security framework for financial institutions and technology firms developing AI agents, covering initialization, model reasoning, identity verification, data privacy, and compliance. This initiative stands as China’s inaugural group standard addressing the security of intelligent agents in financial contexts.
Following the December 2025 launch of a smartphone featuring an AI assistant, users reported unauthorized logins and payment anomalies across various banking apps. By the 6th of that month, the assistant’s financial operation features were disabled, highlighting a regulatory vacuum at the time.
As AI agents become more prevalent in financial services, concerns over their extensive permissions have intensified. A fintech expert noted that many agents bypass official APIs, instead using screen reading, simulated clicks, and OCR to interpret interface text. While this approach offers broad compatibility, it circumvents the developer’s permission controls, risk management systems, and liability frameworks. In regulated areas like payments and wealth management, such unauthorized operations pose direct risks to user accounts and fund security.
In May 2026, the Cyberspace Administration of China, the National Development and Reform Commission, and the Ministry of Industry and Information Technology jointly issued "Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents," emphasizing the need to regulate agent permissions and behaviors. By July, the "Artificial Intelligence Intelligent Agent Interconnection" (GB/Z185.1~185.7—2026) national technical guidance documents were released, alongside a mandatory national standard plan for "Basic Requirements for Intelligent Agent Application Security" from the State Administration for Market Regulation. On July 15, the Cyberspace Administration also announced the filing of seven new terminal-side generative AI services.
Device manufacturers have increasingly adjusted their technical strategies to prioritize developer consent. For instance, the latest Doubao phone has shifted its partnership model with super apps like Alibaba and Tencent, eliminating screen reading and click simulation even after user authorization. Access is now granted only when the app provides MCP services and explicitly permits control. Similarly, Jieyue Star STEPX Neo utilizes the GUI-MCP protocol, allowing developers to define the scope of accessibility. In June 2026, WeChat and Honor introduced A2A (Agent-to-Agent) capabilities, enabling voice assistants to initiate calls or send messages via WeChat through active API integration. This creates a secondary authorization layer beyond user consent. Globally, Google and Samsung have adopted similar system-opened permission models with app cooperation on the Galaxy S26 series.


Standard Link:
Full Text Link: Beijing Financial Technology Industry Alliance - Group Standard
LetinAR Raises $18.5 Million as Optical Modules Power Next-Gen Smart Glasses
Picture yourself cruising on a motorcycle at 160 km/h when a navigation arrow materializes directly on the road, guiding your turn. With no phone in sight and no need to glance at your dashboard, essential data blends seamlessly into your field of vi
Accenture partners with Anthropic to launch first embedded AI evaluator
Dario Amodei’s initiative to embed independent safety evaluators within AI laboratories is materializing: Anthropic has announced that employees from technology consulting firm Accenture will operate on-site to audit its models and personnel.Accordin





Home






