Guozhen AIGlobal AI field notes and model intelligence

Realtime AI News

Google built a security cage for AI agents on Android, and it is still empty

Android Police reports that Google has built a real permission system for autonomous AI agents on Android, centred on a system permission called EXECUTE_APP_FUNCTIONS and the AppFunctionsManager framework, but it is gated almost entirely to first-party software such as Gemini. Because few developers have built the shortcuts it depends on, and Gemini's access is limited to a handpicked tester group, the cage currently controls almost nothing.

Published
Google 为 Android 的 AI Agent 建好了安全笼子,但里面还是空的
Image source: developer.android.com

Android Police's Ali Salman Zia set out to find a setting. After hearing that Google was bringing controls for AI agents to Android, he went looking through his own phone and found no toggle, no permission list, nothing he could actually tap. The answer, he writes in a September 13 report, was buried in developer documents, SDK release notes and a permission registry most Android users will never see.

What he found is that Google has built a real, functioning security cage for autonomous AI agents on Android, and that it is empty. Android contains a system permission called EXECUTE_APP_FUNCTIONS, reserved for approved agents; any app or assistant needs it before it can discover or run another app's functions. It is not on a menu and not in Developer options. It lives in Android's AppFunctionsManager framework and is gated almost entirely to first-party Google software such as Gemini.

The machinery behind it is AppFunctions. Instead of making an agent imitate finger taps around a screen, developers can expose a shortcut to a specific action inside their app, and Android keeps track of it. Ask Gemini to book a ride, and rather than opening the app and hunting for buttons, it triggers that action. Google compares this to letting outside tools connect to a service instead of using it like a person.

The appeal is tangible: no tapping, no breaking when an app moves a button in an update, and the agent records shortcuts rather than whole operation sequences, which is more robust. But it only works after a developer has built the shortcut, and right now almost nobody has.

That leaves an empty cage. Gemini's access to the system is limited to a small, handpicked in-house group of testers. The programme has no timeline for seeing daylight and could change without warning; getting real access today means applying to an early programme and waiting, with no guarantee of selection. For most developers, that is not yet worth the effort.

Building the cage before the tenant arrives is the right call, the report argues. Android has a habit of shipping features first and locking them down after something goes wrong, as location, background data and notifications all once did. Doing that with AI would be worse, because an unfettered agent could read messages or move money before anyone notices. Setting the rules before developers have ample reasons to push back matters most before real money and real users are involved. There is clearly appetite: third-party developers have already built Android agents the old way, tapping through screens via ADB, the fragile approach AppFunctions is meant to replace.

For now the permission set is carefully curated and controls almost nothing on a typical phone. The cage is built, tested and locked, and nobody has moved in. The moment to watch is not the permission's name in a registry but when Google opens the door to third-party developers; until then, agents on Android keep relying on the fragile old approach.

Why it matters

Android's permission design shows Google treating agent risk as a system-level problem rather than a patch applied later. But an empty cage also means today's third-party agents still run on fragile ADB tapping, and a real agent ecosystem on Android will not take shape until Google opens the framework to outside developers.

GoogleAndroidAgent
Back to realtime news

Nearby Updates

All

09/14, 01:53

Anthropic researcher's public exit sets off caution talks across AI labs as workers urge a slowdown

A New York Times report describes how the public resignation of Anthropic researcher Jacob Coxon, citing concerns about the technology, set off internal conversations across OpenAI, Meta and Google, with some AI workers urging executives to pause development until safeguards exist. It also notes that Anthropic and OpenAI are both preparing IPOs and worry that coordinating a slowdown could raise antitrust issues.

09/14, 00:51

AGENTPR unveils AI tool aimed at simplifying media and public reactions

AGENTPR has unveiled an AI tool aimed at simplifying how organizations handle media coverage and public reactions, according to a report by The Guardian Nigeria News. The report gives no pricing, availability or technical detail, so the launch currently stands as a product signal rather than a disclosed capability.

09/14, 00:30

Obama urges Democrats to have a clear plan for AI safeguards

Former President Barack Obama said Democrats must make artificial intelligence a central agenda and adopt a very clear plan for the technology's economic and safety risks. Speaking at a Democratic fundraising event, he urged the party to build a framework for a public conversation on AI, arguing the technology can be dangerous if it is not managed.

09/13, 18:59

Zhipu Raises About $5 Billion to Fund Next-Gen GLM, Self-Training and Compute

Zhipu AI (02513.HK) said on September 13 that it completed roughly $5 billion in financing, split between about $2 billion in share placement and about $3 billion in zero-interest convertible bonds. Proceeds will go to its next-generation GLM foundation models, a fully self-training system and related compute infrastructure.