导语
当AI Agent逐渐深入操作系统、走向跨应用操作,商业生态、数据安全与产业治理随之面临结构性风险,治理规则需要同步跟进。针对这一趋势,弗若斯特沙利文在《2026年侵入式Agent产业治理白皮书》中系统分析了跨应用执行带来的生态影响,并提出以双重授权和全链路可审计为治理基础,逐步形成以API协同为主、GUI模拟为辅的跨应用协作机制。提升执行效率的同时,更应保障用户知情、平台可控、责任可追溯。智能体产业能否形成长期价值,取决于效率与信任能否保持平衡。
AI Agents are evolving from information interaction toward task execution, with cross-application operations emerging as an important direction of product development. However, as Agents gain deeper access to operating systems and applications, risks associated with insufficient authorization and unclear accountability are also increasing, requiring governance rules to evolve in parallel.
2026年上半年以来,Agent产业密集演进,在应用生态内、应用与应用、应用与终端、终端与终端均涌现多款基于接口或协议的交互方案。这表明,白皮书所揭示的产业损害逻辑——流量价值迁移、开发成本攀升、安全风险集中——正被越来越多的行业参与者所验证和认知。Agent权限边界的合规压力也在推动产业回归可治理、可追责的轨道上。
Against this backdrop, Frost & Sullivan’s White Paper on the Governance of Invasive Agents 2026 systematically examines the ecosystem implications of cross-application execution. It proposes a governance framework built on dual authorization and end-to-end auditability, with API-based collaboration as the primary approach and GUI simulation as a supplementary mechanism. The objective is to improve execution efficiency while ensuring that users remain informed, platforms retain control, and accountability remains traceable. The Agent industry’s ability to create long-term value will depend on maintaining a sustainable balance between efficiency and trust.
但与此同时,应用授权不充分、责任边界模糊、高危权限滥用等侵害产业的潜在问题依然存在。白皮书指出,随着全球AI竞争加速,治理能力和信任基础正成为企业进入国际市场的重要竞争条件。若以牺牲信任换取短期扩张,不仅会压缩中国AI企业的国际合作空间,也可能损害中国AI产业的长期国际信誉。Agent技术的演进方向,不应以侵入替代协同,而应在可信治理的框架内,实现从“能做什么”到“该做什么”的产业共识收敛。
As global competition in AI accelerates, governance capabilities and a strong foundation of trust are becoming increasingly important for companies seeking to enter international markets. Pursuing short-term expansion at the expense of trust could not only constrain international cooperation opportunities for Chinese AI companies, but also cause lasting damage to the global reputation of China’s AI industry.
根据沙利文《2026年侵入式Agent产业治理白皮书》,AI Agent加速进入系统层,跨应用执行正在重塑移动互联网入口与生态治理规则
Frost & Sullivan’s 2026 White Paper on the Governance of Invasive Agents: AI Agents Move Deeper into the System Layer, Reshaping Mobile Entry Points and Ecosystem Governance
随着多模态大模型从概念验证步入商业化落地,AI智能体(AI Agent)正逐渐深度介入设备底层操作,并展现出独立执行跨应用复杂任务的能力。在此背景下,部分绕过标准应用程序接口(API)、直接利用系统底层特权干预应用运行的“侵入式Agent”迅速蔓延,给现有的互联网信任机制与生态协同带来了空前挑战。
As multimodal large language models move from proof-of-concept to commercial deployment, AI Agents are increasingly becoming deeply involved in low-level device operations and are demonstrating the ability to independently execute complex tasks across applications. Against this backdrop, invasive Agents that bypass standard application programming interfaces (APIs) and directly use low-level system privileges to interfere with application operations are spreading rapidly, creating unprecedented challenges for existing internet trust mechanisms and ecosystem collaboration.
基于对全球及中国AI Agent市场的系统调研,弗若斯特沙利文(Frost & Sullivan,以下简称“沙利文”)于2026年3月正式发布《2026年侵入式Agent产业治理白皮书》。本报告聚焦侵入式Agent机制对产业流量分配、商业生态运作及底层数据安全造成的冲击,并对行业未来的规范化落地与治理路径进行了前瞻性研判。
In March 2026, based on systematic research into the global and Chinese AI Agent markets, Frost & Sullivan has officially released the White Paper on the Governance of Invasive Agents 2026. The white paper focuses on the impact of invasive Agent mechanisms on industrial traffic allocation, commercial ecosystem operations, and underlying data security, while providing forward-looking analysis of the industry’s future standardization and governance pathways.

01 侵入式Agent依托系统层权限突破应用边界,为产业治理带来新风险
Invasive agents breach application boundaries through system-level privileges, introducing a new layer of governance risk
侵入式Agent的关键特征,在于其不依靠标准接口或协议,借助系统签名级权限直接读取界面信息、识别页面内容,并模拟用户完成点击、输入、跳转等操作。借助这一路径,Agent可以在未获得应用方业务授权的情况下,跨越多个软件连续执行任务。相较于基于标准接口开展协同的路径,这种方式虽然降低了跨应用联动对生态合作的依赖,却也突破了原有应用边界与权限边界,将风险前置到系统层。
The defining feature of invasive agents is that they do not depend on standard interfaces or protocols exposed by third-party applications. Instead, they rely on high-level system privileges, including signature-level permissions, to directly read interface content, interpret on-screen information, and simulate user actions such as clicking, inputting text, and navigating between pages. Through this approach, agents are able to execute continuous tasks across multiple applications without obtaining business authorization from the applications involved. Compared with models built on standardized interface-based collaboration, this pathway reduces dependence on ecosystem cooperation for cross-application orchestration, but at the same time pushes risk upward into the system layer by breaking through established application and permission boundaries.
过去,用户需要先进入具体应用,再逐步完成信息获取与操作决策;如今,系统层Agent开始承接用户意图理解、任务拆解和动作调度,应用则更多退居为任务执行的承载界面。随着移动端原有以应用为中心的入口逻辑被改写,系统层Agent在提升任务执行便利性的同时,也开始对既有生态秩序、权限规则与治理边界形成新的冲击。
Historically, users entered individual applications and completed information discovery and decision-making step by step within each app environment. Today, system-level agents are increasingly taking over intent understanding, task decomposition, and action scheduling, while applications are being relegated to execution interfaces. As this shift rewrites the app-centric entry logic of the mobile internet, system-level agents are improving task convenience while simultaneously placing new pressure on existing ecosystem order, permission rules, and governance boundaries.
侵入式Agent的定义
Defining Features of Invasive AI Agents

02 侵入式Agent前置用户决策环节,第三方应用商业价值承压
By moving user decision-making upstream, invasive agents place pressure on the commercial value of third-party applications
当侵入式Agent逐步成为用户发起任务的主要入口,传统移动应用在生态中的角色也随之发生变化。原本由应用自身承接的搜索、浏览、比较、点击和下单等行为,被越来越多地前置到Agent侧完成,应用留给用户的直接交互时长和触达机会显著减少。
As invasive agents increasingly become the primary entry point for users to initiate tasks, the role of conventional mobile applications within the ecosystem is also changing. Activities that were previously carried out within apps, including search, browsing, comparison, clicking, and purchasing, are increasingly being completed on the agent side before users ever meaningfully interact with the application itself. As a result, applications face a sharp reduction in direct engagement time and user touchpoints.
这一变化将直接传导至应用开发者的商业模式。工具类应用首当其冲,交易类与社交类的生态价值也将被冲击。无论是依赖停留时长和曝光分发的信息流广告,依赖深度使用形成粘性的会员订阅,还是依赖交易链路闭环获得收益的佣金模式,都会受到不同程度影响。
This shift is likely to have direct consequences for application developers’ monetization models. Utility applications are expected to come under the greatest pressure first, but transactional and social/content platforms will also face material disruption. Whether monetization depends on information-flow advertising tied to user time spent and exposure allocation, subscription models built on deep engagement, or commission-based models supported by closed-loop transaction paths, each of these commercial mechanisms may be weakened to varying degrees.
白皮书测算显示,若未来侵入式Agent在用户侧渗透率达到25%,工具类应用商业价值预计下降39%,内容与社交类应用预计下降19.5%,交易类应用预计下降15.4%。这意味着,侵入式Agent带来的并非单点效率优化,而是应用生态商业价值的重新分配。
Frost & Sullivan estimates that if invasive agents reach a 25% user-side penetration rate in the future, the commercial value of utility applications could decline by 39%, while content and social applications could see a 19.5% decline and transactional applications a 15.4% decline. This suggests that the rise of invasive agents is not merely about marginal efficiency enhancement. It represents a broader redistribution of commercial value across the application ecosystem.
用户触达流量入口转移
Shift in User Traffic Entry Points

03 流量迁移未带来显著增量,反而导致产业内卷与高治理成本
Traffic migration does not generate meaningful incremental value, but instead intensifies internal competition and drives up coordination and governance costs across the industry
白皮书进一步指出,侵入式Agent带来的影响,并不主要体现为产业新增量,而更多体现为对现有流量分配关系的重新切分。当系统层Agent试图绕过既有合作机制直接承接用户需求时,平台方、应用开发者与Agent提供方之间的关系会由协同合作转向零和博弈。
The white paper further notes that the impact of invasive agents is not primarily reflected in the creation of substantial new market value. Rather, it is more accurately understood as a redivision of existing traffic allocation relationships. When system-level agents attempt to bypass established cooperation mechanisms and directly intermediate user demand, the relationship among platform operators, application developers, and agent providers may shift from coordinated collaboration to a zero-sum game.
侵入式Agent内卷式工具特征
Invasive AI Agents and Zero-Sum Competition

在这一过程中,应用开发者往往需要通过界面调整、反自动化识别、权限收紧和策略更新等方式进行防御,以应对未经许可的数据读取和界面操作。这使得软件迭代频率、兼容维护难度以及安全防护投入同步抬升。
In this process, application developers are often compelled to respond through interface adjustments, anti-automation detection, tighter permission controls, and ongoing strategy updates in order to defend against unauthorized data extraction and interface manipulation. This raises software iteration frequency, increases compatibility-maintenance complexity, and drives additional spending on security protection.
研究显示,在侵入式Agent渗透率达到25%的情况下,移动应用综合开发成本预计上升16%,包括合作协调、合规审查与安全防御在内的产业链综合治理成本预计上升34.4%。这一趋势说明,若缺乏清晰规则约束,侵入式发展路径很可能将产业资源更多消耗在对抗之中,而非创新本身。
Research indicates that at a 25% penetration rate for invasive agents, overall mobile-application development costs could increase by 16%, while total ecosystem governance costs, including coordination, compliance review, and security defense, could rise by 34.4%. The implication is clear. Without an explicit governance framework, an invasive development path is likely to consume more industry resources in defensive confrontation than in genuine innovation.
04 高权限集中叠加指令诱导,显著放大数据与资产安全风险
The concentration of high-level permissions, combined with instruction-based manipulation, significantly amplifies data and asset-security risks
为实现跨应用、跨场景的连续任务执行,侵入式Agent通常需要长期持有较高等级的系统权限,并在多个业务场景中维持账户登录与操作能力。这意味着,原本分散在不同应用中的数据边界和权限边界,开始向单一Agent集中。一旦出现权限滥用、模型误判或安全缺口,影响范围将不再局限于单个应用,而可能扩散至整个终端环境。
To enable continuous execution across applications and use cases, invasive agents typically require long-term access to elevated system permissions and the ability to maintain logged-in operational states across multiple business scenarios. This means that data boundaries and permission boundaries that were previously distributed across different applications begin to converge into a single agent. Once permission abuse, model misjudgment, or security vulnerabilities occur, the consequences are no longer confined to a single application, but may spread across the entire terminal environment.
与此同时,由于侵入式Agent具备读取屏幕内容并触发后续动作的能力,其还可能受到外部信息的诱导。攻击者可以通过网页、邮件、文档等载体嵌入特定指令,诱导Agent在用户未充分察觉的情况下执行删除、转发、修改、支付等敏感操作。原本局部、可控的识别偏差,在高权限执行环境下可能迅速演变为隐私泄露、账户风险甚至资产损失事件。由此可见,侵入式Agent带来的已不只是传统意义上的信息安全问题,更是权限集中背景下的系统性风险放大。
At the same time, since invasive agents can read screen content and trigger subsequent actions, they may also be inherently susceptible to indirect prompt injection. Attackers may embed specific prompts or instructions in webpages, emails, or documents, inducing the agent to perform sensitive actions such as deletion, forwarding, modification, or payment without the user’s full awareness. In a high-permission execution environment, what might otherwise have remained a localized and manageable recognition error can rapidly escalate into privacy leakage, account compromise, or even financial loss. In this sense, invasive agents do not merely create conventional information-security concerns. They materially increase systemic risk under conditions of concentrated authority.
零点击邮件指令触发网盘批量误删
Zero-Click Email Injection Triggers Bulk Cloud-Drive Deletion

05 以双重授权和全链路可审计为基础,构建可信治理框架
A trusted governance framework should be built on dual authorization and full-chain auditability
针对上述问题,白皮书提出,Agent产业的可持续发展不应建立在越过生态边界和削弱信任机制的基础上,而应推动形成以API协同为主、GUI模拟为辅的治理框架。其核心在于建立双重授权机制,即Agent开展跨应用操作,不仅需要获得用户对系统权限的明确授权,也需要获得被调用应用或服务方对具体业务动作的许可。
In response to these risks, the white paper argues that the sustainable development of the agent industry should not be built on bypassing ecosystem boundaries or weakening trust mechanisms. Instead, the industry should move toward a governance framework in which API-based collaboration remains the primary model and GUI simulation plays only a supplementary role. The core principle is the establishment of a dual-authorization mechanism. This means that for an agent to perform cross-application actions, it must not only obtain the user’s explicit authorization for system-level permissions, but also secure permission from the invoked application or service provider for the underlying business action itself.
在具体实施层面,可信治理框架应围绕四个方向展开。其一,清晰界定Agent的权限边界与可代办事项范围,防止能力外溢。其二,对涉及隐私、支付、资产和身份变更等高风险操作设置更严格的动作约束与确认机制。其三,建立覆盖授权、决策、执行与结果反馈的全过程留痕体系,确保关键操作可核验、可复盘。其四,在可审计基础上进一步明确责任归属,为后续争议处理、损失核定和制度约束提供依据。
At the implementation level, the report proposes that a trusted governance framework should advance along four directions. First, agent permission boundaries and the scope of delegable tasks should be clearly defined in order to prevent capability spillover. Second, stricter constraints and confirmation mechanisms should be imposed on high-risk actions involving privacy, payments, assets, and identity changes. Third, a full-process traceability system should be established across authorization, decision-making, execution, and result feedback so that critical actions can be verified and reconstructed. Fourth, on the basis of auditability, responsibility allocation should be clarified to support future dispute resolution, loss assessment, and institutional enforcement.
白皮书最终强调,Agent技术的演进方向不应是以侵入替代协同,而应是在可验证、可约束、可追责的框架内实现跨主体协作。只有在保障生态秩序、商业公平与用户安全的前提下,Agent才能真正释放其对社会效率提升的长期价值。
The white paper ultimately emphasizes that the future direction of agent development should not be one in which invasion replaces collaboration, but one in which cross-entity coordination takes place within a framework that is verifiable, enforceable, and accountable. Only by safeguarding ecosystem order, commercial fairness, and user security can agents fully deliver their long-term value in improving social and economic efficiency.
06 全球竞争不能以透支信任为代价,可信治理将成为中国AI走向国际市场的前提
Global AI competition cannot be pursued at the expense of trust; trusted governance will be a prerequisite for China’s AI industry to expand internationally
白皮书进一步指出,不能片面以创新视角理解侵入式Agent,而应考虑其对产业生态、公众隐私、安全环境、国际竞争的综合影响。Agent并不只是模型能力、产品形态和落地速度的竞争,更是治理能力、信任基础与规则适配能力的竞争。若侵入式Agent以突破权限底线、削弱授权机制、牺牲用户信任为代价,看似抢占了竞争先机,实则可能为整个产业与社会发展埋下更大风险。
The white paper further argues that invasive agents should not be viewed solely through the lens of innovation. Their broader implications for industrial ecosystems, public privacy, security conditions, and international competition must also be taken into account. Competition in AI agents is not only a matter of model capability, product form, and deployment speed. It is also a competition in governance capacity, trust infrastructure, and the ability to adapt to evolving rules. If invasive-agent providers seek short-term advantage by pushing beyond permission boundaries, weakening authorization mechanisms, and eroding user trust, such an approach may appear to secure an early lead, but in reality it may embed greater risks for the wider industry and society.
中美AI竞争格局的演进,不仅关乎技术能力和落地速度,也越来越取决于创新效率、安全约束与生态协同之间能否实现可持续平衡。对中国人工智能产业而言,具备安全、信任与规则兼容基础的Agent体系,将更有助于提升其面向全球市场的长期竞争力;若过度依赖以牺牲信任为代价的扩张路径,不仅可能削弱单一产品或企业的国际合作空间,也可能对中国AI整体的国际信誉带来负面影响,对融入全球主流的AI技术路线与治理体系同样构成负面障碍。
The evolution of China-US AI competition increasingly depends not only on technological capability and implementation speed, but also on whether innovation efficiency, security constraints, and ecosystem coordination can be balanced in a sustainable way. For China’s AI industry, an agent framework grounded in security, trust, and compatibility with emerging governance norms will be more conducive to strengthening long-term global competitiveness. By contrast, an expansion path built at the expense of trust may not only narrow the international cooperation space available to individual products or companies, but may also negatively affect the broader international credibility of China’s AI industry and create additional obstacles to its integration into mainstream global AI technology and governance systems.



