Smartphones Might Be About to Change Forever

09/18 2026 369

Can AI Smartphones Free Our Hands?

Image Source | Internet (Please contact us for deletion if infringement occurs) Partially AI-generated

On September 16, 2026, the Nubia NaviX Ultra officially went on sale, surpassing 100 million yuan in sales within a second and accumulating over 370,000 pre-orders. In today's smartphone market, this figure represents a modest yet notable stimulus.

However, the real focus isn't just on sales figures. This device, officially positioned as the 'world's first AI agent smartphone,' has done something no previous smartphone has seriously attempted: it tries to transform the smartphone from 'a tool you operate' into 'an agent acting on your behalf.'

This statement might sound like marketing jargon. But when you see it press the orange AI button on the right side of the device, say 'Order me a coffee,' and watch as the phone opens a food delivery app, compares prices, selects a store, navigates to the payment page, and then turns the screen toward you—you realize something is indeed changing.

An Experiment in 'Hands-On' Interaction

To understand the significance of the NaviX Ultra, we must first revisit the controversy it sparked.

In December 2025, ByteDance and ZTE jointly launched the Nubia M153 engineering prototype, priced at 3,499 yuan. The first 30,000 units sold out instantly, and prices on the secondary market surged to 8,000 yuan.

Its capabilities were impressive at the time: you could say 'Help me compare prices and place an order,' and the AI would autonomously switch between WeChat, Meituan, and Taobao, reading the screen, recognizing buttons, and simulating clicks to complete the task on your behalf.

However, within a week of its launch, the phone became virtually unusable. WeChat accounts experienced login abnormalities, Taobao triggered human-machine verification prompts, and apps from banks like Agricultural Bank of China and China Construction Bank suspended services due to 'risky environments.'

Within days, national-level apps like WeChat, Alipay, Meituan, and Pinduoduo blacklisted the Doubao Assistant.

The reason is not hard to understand. The M153 relied on Android's INJECT_EVENTS permission, a low-level privilege that allows apps to inject simulated click events into the system.

For WeChat and Alipay, this was equivalent to someone using a master key to navigate your phone. While the operator claimed, 'I'm acting on behalf of the owner,' the risk control system couldn't verify this assertion.

As one lawyer bluntly put it: 'Such high-level system permissions could indeed be exploited by black-market operations, risking the leakage of personal privacy information.'

The deeper conflict lies in business logic. Zhou Hongyi, founder of 360, pointed out that AI assistants completing tasks like ordering food or shopping undermine the platform's traffic monetization model, which relies on 'users opening the app—browsing pages—clicking ads.'

Users no longer need to endure splash ads or scroll through recommended feeds, posing a structural threat to platforms' daily active users and engagement metrics.

Nine months later, the NaviX Ultra returned with a more cautious approach. Instead of bypassing app interfaces, it introduced a framework called SAEP (Screen Automation Operation Declaration Protocol), allowing third-party apps to voluntarily declare whether they accept AI assistant automation within their apps, with a 30-day public review period.

The brilliance of this design lies in returning control to app developers. Acceptance means the app is willing to collaborate with AI agents; rejection means the AI stays away.

For apps that neither accept nor reject after the public review period, Doubao will make its own judgment based on risk levels. In essence, this is a 'courtesy first, force later' draft for industry consultation.

How does it perform in practice? A journalist's hands-on test provided vivid details: when ordering food, Taobao Flash Sales and JD.com did not support AI operations, so Doubao suggested placing the order through Douyin's services; for ride-hailing, collaboration with Cao Cao Mobility worked relatively smoothly; however, WeChat message replies were directly blocked, with the explanation: 'WeChat is a risk-restricted app. Automatic message sending is prohibited due to account suspension risks.'

You can use it, but only within the boundaries set by others. This is the current reality of AI agent smartphones.

Can You Trust Your Butler with the Keys?

If the NaviX Ultra represents a technological direction, the debates surrounding it reflect a more fundamental question: how much decision-making power are users willing to cede to large models?

This is not an abstract proposition. Imagine these scenarios: AI compares prices across three food delivery platforms and selects the cheapest option, but you didn't actually want the cheapest one; AI replies to a work message with appropriate tone but not your usual style, and the recipient notices something is off; AI cancels a subscription service without your knowledge because it judged you 'didn't need it.'

These scenarios are not far-fetched. Previously, security researchers attempted to have an agent organize an email inbox, only for the program to misjudge tasks and delete large volumes of emails.

Even AI professionals struggle to fully predict an agent's behavioral paths.

The current industry solution is 'human confirmation for critical steps.' The NaviX Ultra mandates secondary user confirmation for high-risk scenarios like payments and identity verification, retaining ultimate decision-making power for humans.

While this is a necessary safety measure, it exposes an awkward reality: if AI requires your confirmation for every slightly important task, how different is it from 'opening the app for you to operate manually'?

From a legal perspective, the controversy centers on 'single authorization' versus 'dual authorization.' Experts from the China Information Industry Association's Data Intelligence Committee argue that agents are essentially extensions of user will and lack independent legal personality, so users' disposition rights over their accounts and data suffice as operational justification.

However, if every app demands platform-level secondary authorization, the negotiation costs for millions of apps would be prohibitively high, potentially granting platforms 'veto power' and ultimately undermining consumer choice.

Of course, platforms' concerns are not unfounded. In sensitive scenarios like financial payments and bulk data access, platforms have legal obligations to ensure security.

The issue is that the line between 'ensuring security' and 'maintaining monopoly' is often blurrier than we think.

Zooming out, the emergence of AI agent smartphones is not a sudden concept. It is a natural extension of three decades of smartphone evolution.

From the 1990s to 2007, feature phones dominated. Their core value was 'connection,' primarily addressing the basic need for anytime and anywhere (anytime, anywhere) communication. Users were entirely passive, with simple buttons and limited functions.

The 2007 iPhone launch ushered in the smartphone era. Touchscreens, high-performance processors, and rich app ecosystems transformed phones from communication tools into 'super terminals.'

However, the essential change was that smartphones gave users infinite choices while also burdening them with operational responsibilities. You had to actively tap, switch apps, and search for functions among dozens of icons.

Over the past decade, we've grown accustomed to this model. The more powerful the phone and the richer the apps, the more time we spend 'operating' it.

Ordering food requires opening an app, selecting a restaurant, choosing dishes, entering an address, and selecting a payment method—at least six or seven steps. Booking a flight involves comparing prices, selecting times, entering passenger information, and choosing seats, potentially taking tens of minutes.

AI agent smartphones aim to change precisely this. Their core logic is not 'giving you more functions' but 'completing operations for you.'

At the launch event, Nubia President Ni Fei put it bluntly: 'The first half of AI smartphones was about adding AI features to phones; the second half will be about using AI agents to move from 'voice commands' to 'hands-on action.''

This distinction matters. Over the past two years, nearly all mainstream smartphones have incorporated AI features like object removal, AI summarization, and voice-to-text transcription. But these essentially overlay AI tools onto traditional operating systems.

You still need to open apps and tap buttons; the results are just better.

Agent smartphones, however, aim to eliminate the need to open any apps. You simply state your desire, and the phone finds the path and executes it autonomously.

If this direction succeeds, the phone's role will fundamentally change—from 'a container for apps' to 'an executor of intentions.'

How Far Are We from Universal AI Smartphones?

IDC predicts that 147 million AI smartphones will ship in China in 2026, marking the first time penetration exceeds 53%. This means one in every two new phones sold will carry an 'AI' label.

Counterpoint data shows that generative AI smartphones will account for 45% of global shipments in 2026, potentially reaching 52% in 2027.

However, 'high AI smartphone penetration' and 'universal AI smartphones' are not the same.

A UBS survey revealed that only 24% of users would upgrade their phones earlier due to AI features, down 5 percentage points from six months prior.

Another survey covering the Indian market presented an interesting contradiction: 68% of consumers prioritize AI features when purchasing phones, 71% use generative AI features multiple times weekly, but 82% cite 'trust' as a key factor in their purchasing decisions.

Consumers 'care about AI' but 'won't pay for AI'—this nuanced divide reveals a reality: AI features have not yet become must-haves.

Cleaner photo editing, faster summarization, and more conversational voice assistants are nice improvements, but not enough to justify spending 5,000-6,000 yuan on a new phone.

What truly drives upgrades is the kind of experience 'you can't go back from.'

Could agent smartphones provide that 'can't-go-back' experience? That depends on three variables.

First is the breadth of ecosystem adaptation. Currently, the NaviX Ultra's auto-operation capabilities remain limited. ByteDance-owned apps offer the most complete experience, while third-party app integration depends on SAEP protocol adoption.

If a year from now, you find that only Douyin and Feishu can be auto-operated, 'acting on your behalf' will remain just a catchy slogan.

One investor's assessment rings true: 'Agent smartphones are still in early exploration. Ecosystem adaptation is the biggest variable, with scene-specific functionalities evolving dynamically based on app openness.'

Second is the establishment of trust mechanisms. Users need assurance that AI won't act behind their backs. The NaviX Ultra's fingerprint-activated AI button is an interesting design—confirming user identity before executing tasks—but the greater trust challenge lies in transparency: how can users know which operations the AI performed, which data it accessed, and where that data went?

Most AI phones currently address this by displaying 'task details' during execution, listing operational steps and allowing users to stop tasks anytime. This transparency is a necessary starting point but falls short of building genuine trust.

Third is app developers' willingness—the hardest yet most critical variable. The 'act on your behalf' model inherently disrupts platforms' core interests.

When users complete tasks through AI interfaces, they bypass app homepages, recommendation feeds, and splash ads—all foundational to platforms' business models.

Doubao's current approach negotiates access via MCP (Model Context Protocol) and A2A (Agent-to-Agent Protocol), operating only when apps voluntarily provide interfaces and permissions.

This is far gentler than the first generation's 'forceful entry,' but it also means AI capabilities are strictly limited to what app developers are willing to cede.

Omdia analysts emphasize: 'The current agent model, centered on simulating user operations, is highly versatile but easily triggers app-side risk controls while failing to truly solve efficiency bottlenecks. Open protocols or standardized APIs between apps and models are needed to resolve this.'""In other words, the true AI smartphone era won't arrive because a single manufacturer creates a stunning product.

It requires the entire mobile internet ecosystem to renegotiate rules—who defines AI's operational boundaries, who bears security responsibilities, and who benefits from efficiency gains.

Back to NaviX Ultra. It may not be the phone that 'defines the future'; perhaps it's just a transitional product, like BlackBerry in 2005 or Nokia's N-series in 2006, standing at the doorstep of a new era but not yet the era itself.

But it proves at least one thing: the relationship between phones and people is evolving from 'you operate it' to 'it understands you.' The direction of this change is certain; only the speed remains uncertain.

The last paradigm shift in interaction occurred in 2007 when Jobs replaced physical keyboards with multi-touch, and since then, we've spent fifteen years learning to slide our fingers across glass to accomplish everything.

The next shift may not take as long because this time, what's changing isn't finger movements but 'who makes the decisions.'

When AI can compare prices for you, plan your itinerary, and reply to messages, what you save is time, but what you surrender is decision-making power.

Whether this trade-off is worthwhile will vary from person to person.

The only certainty is this: phones may truly be about to change.

Solemnly declare: the copyright of this article belongs to the original author. The reprinted article is only for the purpose of spreading more information. If the author's information is marked incorrectly, please contact us immediately to modify or delete it. Thank you.