金融领域首个智能体安全标准发布
TL;DR - China’s first group standard focused on AI-agent security in finance requires third-party mobile agents to obtain authorization from both users and financial institutions before operating financial apps. It matters because it limits high-privilege GUI automation that could bypass institutional controls and endanger accounts or funds.
- The standard covers input handling, model reasoning and decisions, identity verification and operations, data privacy, and risk management and compliance.
- Unauthorized agents may not use system permissions to read or manipulate financial-app interfaces; microphone, screenshot, recording, and screen-sharing access must follow the app provider’s security policies.
- The “dual authorization” model favors institution-approved interfaces such as MCP, GUI-MCP, or agent-to-agent integrations over screen reading, OCR, and simulated clicks.
- Banks, payment networks, technology companies, and a national fintech certification center jointly developed the standard for financial institutions and agent developers.