Mei Keyue
Online available: 2026-09-24
As large language models shift from content generation to task execution, a new product form has emerged in mobile terminals and personal computing environments: the system-level AI agent. Unlike plug-in assistants embedded in a single application, system-level agents operate at the operating-system layer. They can read screen content, identify interface states, invoke tools, and perform cross-application actions through simulated clicking, typing, and task chaining. This transition moves human-computer interaction from an application-centered mode to a task-centered mode. It also restructures the way data are accessed, circulated, and acted upon. Against this background, data security risks are no longer confined to one-off collection or isolated leakage. They become chain-based, cumulative, and processual, extending across data acquisition, data circulation, and task execution. The study is motivated by both industrial practice and regulatory signals. Products such as Doubao Mobile Assistant have demonstrated cross-application execution in searching, comparison shopping, ordering, and message coordination. OpenClaw has further shown how persistent memory, browser automation, file management, and script execution can be incorporated into open ecosystems. At the same time, regulators in China, including the MIIT threat and vulnerability information sharing platform (NVDB), CNCERT, and industry associations in the financial sector, have issued risk warnings concerning excessive privileges, weak default security configurations, prompt injection, malicious plugins, abnormal account control, and execution errors. These developments indicate that the problem has moved beyond a technical experiment and become a concrete governance issue. The research design is anchored in a lifecycle-based analytical framework. Drawing on the categories of the Data Security Law, the study reconstructs system-level AI agent data processing into three linked layers: acquisition, circulation, and execution. On this basis, the article combines doctrinal analysis with governance-oriented institutional analysis. It examines how system-level permissions, end-cloud collaboration, tool invocation, and continuous task execution reshape the boundaries of data collection and the structure of responsibility. It also reviews existing scholarship from three strands—technical security studies, personal-information and data-compliance research, and platform-governance studies—to show that current discussions remain fragmented and do not fully capture the integrated risk structure of system-level AI agents. The study reaches three main findings. First, system-level AI agents create a full-chain risk structure. At the acquisition layer, full-domain sensing and cross-application access turn local exposure into overall exposure and make over-collection and inadvertent collection more likely. At the circulation layer, end-cloud collaboration, plugin calls, and context retention generate hidden circulation risks, including re-identification after "desensitized" upload, contextual leakage, and ecological spillover across platforms. At the execution layer, automated agency amplifies the risks of unauthorized actions, cumulative deviations in multi-step task chains, and black-box loss of user correction capacity. Second, existing governance mechanisms are misaligned at three levels. Technically, the system is often operable but insufficiently visible, controllable, and verifiable. Normatively, responsibility attribution, the minimum-necessity principle, and informed consent rules are difficult to apply in multi-actor, cross-application, and continuous-execution environments. Economically, high compliance costs, strong incentives for data expansion, and the externalization of losses weaken firms' incentives to invest in sustained safety governance. Third, an effective response requires a three-tier governance framework rather than isolated fixes. The main contribution of this study lies in proposing a governance structure based on the sequence of rule-based boundary setting, technical embedding of constraints, and implementation support. On the rule side, the study argues for clarifying the boundaries of high-risk data, high-risk permissions, and high-risk tasks through the adjustment of the minimum-necessity principle, the optimization of informed consent, and the reconstruction of responsibility attribution. On the technical side, it proposes embedding those boundaries into system operation through visibility, controllability, and verifiability mechanisms, including layered tracking, dynamic markings, graded authorization, anomaly interruption, deletion proofs, and auditable records. On the implementation side, it recommends graded market access, pre-launch assessment, responsibility internalization, and risk-sharing mechanisms so that governance is not left to voluntary optimization. In this way, this study moves beyond traditional app-based or static compliance models and provides a more targeted framework for balancing operational efficiency with data security in the age of system-level AI agents.