Doubao Mobile Assistant consumer version goes on sale in September; AI voice assistants involve privacy and data compliance, lawyer explains three major risks.
ByteDance's Doubao mobile assistant consumer version has officially been released, and the first new phone equipped with this AI assistant is scheduled to go on sale on September 16. This means generative AI is penetrating from the app layer to the underlying mobile operating system, and voice assistants will gain system-level access to contacts, call logs, text messages, location, photo albums, and even payment processes. For ordinary users, this is not just a choice about switching phones, but also a major transfer of control over personal information. As a lawyer who has long handled data compliance and personal information infringement cases, I believe this release involves at least three levels of legal issues: whether informed consent for granting permissions is valid, where the compliance boundaries of data processing lie, and how users can defend their rights once a leak or abuse occurs.
1. Is the "consent" of a system-level AI assistant truly valid?
Articles 13 and 14 of the Personal Information Protection Law explicitly provide that processing personal information shall obtain the individual's consent, and such consent shall be given by the individual voluntarily and explicitly on the basis of full knowledge. Article 17 further requires that processors shall, in a conspicuous manner and in clear and easily understandable language, truthfully, accurately, and completely inform individuals of matters such as the purpose, method, type, and retention period of the processing.
The problem is that mobile AI assistants often adopt a "bundled authorization" model—when users activate them, they are presented with a lengthy privacy agreement and must click "agree" to use the service. Whether this kind of consent satisfies the requirements of "fully informed" and "explicit" is disputed in judicial practice. In 2023, the Beijing Internet Court ruled in several app personal information cases that bundling multiple unnecessary permissions and threatening users with "no authorization, no access" constitutes disguised forced consent, and the relevant clauses can be deemed invalid.
More critically, to achieve "intelligence," AI voice assistants typically need to upload voice data to the cloud for processing. This goes beyond the scope of "local recognition" and constitutes providing personal information to a third party (the cloud service provider). Under Article 23 of the Personal Information Protection Law, when providing information to a third party, the recipient's name, contact information, processing purpose, and methods must be separately disclosed, and separate consent must be obtained. If a manufacturer covers all scenarios with a single general agreement, there are compliance deficiencies.
2. When calls and contacts are read by AI, which red lines are crossed?
The most controversial features of AI phone assistants are automatically answering calls, summarizing call content, and replying to text messages on behalf of the user. This directly touches on the provisions regarding the right to privacy under Articles 1032 and 1033 of the Civil Code: unless otherwise provided by law or with the explicit consent of the rights holder, no organization may photograph, peep at, eavesdrop on, or publicly disclose another person's private activities, or process another person's private information. The content of a call is typical private information, and if an AI records, transcribes, and analyzes it without the consent of both parties to the call, it may simultaneously infringe on the privacy rights of the other party to the call.
It is worth noting that consent must be "bilateral." A user's authorization for AI to process a call does not mean the other party on the call also agrees to be "overheard" and transcribed by AI. In scenarios such as marriage and family matters, business negotiations, and labor disputes, where one party uses an AI assistant to record and preserve evidence, and the other party later claims privacy infringement, courts will comprehensively consider factors such as the purpose of the recording, the necessity of the means, and whether the legitimate rights and interests of others have been harmed. With reference to the Supreme People's Court's provisions on evidence in civil litigation, evidence obtained by seriously infringing upon the lawful rights and interests of others should be excluded.
Contact lists, in turn, involve the issue of sensitive personal information under Article 28 of the Personal Information Protection Law. A contact list contains the names and phone numbers of a large number of third parties, and the user has no right to give consent on behalf of others. If a manufacturer uploads the contact list for model training, it not only violates the separate consent requirement under Article 29, but may also constitute an infringement of third parties' personal information rights and interests.
3. Cross-Border Data and Model Training: Risks Users Cannot See
The core competitiveness of AI assistants comes from large models, and the training and inference of large models often involve cross-border data transmission. According to Articles 38 and 39 of the Personal Information Protection Law, providing personal information to overseas recipients requires passing a security assessment, certification, or entering into standard contracts, and obtaining the individual's separate consent. The 2024 Regulations on Promoting and Regulating Cross-Border Data Flows issued by the Cyberspace Administration of China further refined the exemptions, but sensitive data such as call records and biometric information are not automatically exempt.
Another hidden risk is "data used for model improvement." Many user agreements contain a clause like this: We may use your usage data to optimize our services. This seemingly mild statement, under the framework of the Personal Information Protection Law, signifies a change in processing purpose, and according to Article 14, such a change requires obtaining consent anew. If a vendor directly feeds users' voice recordings and chat logs into model training without providing a convenient channel to withdraw consent, users can demand deletion under Articles 44 and 47.
From a corporate compliance perspective, AI terminal manufacturers should establish a data classification and grading system, implement encrypted storage and minimized access for sensitive personal information, and regularly conduct personal information protection impact assessments (PIA).
4. After a leak or misuse occurs, how can users defend their rights?
Once a data breach occurs, users are not left with no choice but to wait passively. Article 69 of the Personal Information Protection Law stipulates that where the processing of personal information infringes on personal information rights and interests and causes harm, if the processor cannot prove that it is not at fault, it shall bear tort liability such as damages. This is the principle of presumptive fault liability, and the burden of proof lies with the company. Users only need to prove that there is a connection between the fact of harm and the processing conduct.
On the path to rights protection, users can first request access to and copies of their personal information under Article 45, and request deletion under Article 47; file complaints with the cyberspace administration and market regulation authorities; and if negotiations fail, file a personal information protection dispute lawsuit in court. Since 2021, the Guangzhou, Hangzhou, and Beijing Internet Courts have heard multiple cases involving personal information in AI products, with some rulings ordering manufacturers to delete data and pay compensation for emotional distress.
For ordinary consumers, my practical advice is: before activating an AI assistant, check its permissions item by item and turn off unnecessary access to contacts, call logs, and text messages; regularly check in your settings which apps have accessed the microphone and location; and if you discover unusual charges or information leaks, immediately take screenshots to preserve evidence and notify the manufacturer in writing.
AI phones are the trend, but technological convenience must not come at the cost of giving up legal rights. The Data Compliance and Personal Information Protection team at Guangdong Zhiming Law Firm has long handled cases involving personal information infringement, data breach claims, and corporate compliance reviews, and can provide full-process legal support for consumer rights protection and corporate product compliance.