In a landmark ruling that could reshape the regulatory landscape for artificial intelligence in China, the Guangzhou Internet Court has ordered an AI agent to halt operations after finding it guilty of unfair competition. MLex reports that the case, which centered on the agent’s ability to circumvent operating system-level platform safeguards, establishes a critical legal precedent for how AI tools interact with existing digital ecosystems.
The ruling addresses a growing tension in the tech industry: as AI agents become increasingly capable of navigating the web and interacting with applications autonomously, they often bypass the security measures, paywalls, and user interfaces designed by platform operators. This case marks one of the first times a Chinese court has explicitly drawn a legal line around this behavior.
The Facts of the Case
The case involved an AI chatbot developed by a third-party software company and marketed as a “role-playing companion” assistant. Despite its consumer-friendly branding, the software exploited accessibility-service permissions at the operating system level to automate actions on the plaintiffs’ dialogue platform, including clicking, sending messages, and interacting with applications in ways that simulated a human user.
The two plaintiffs, identified only as a technology company and a systems company that jointly operate the dialogue platform, brought the case under China’s Anti-Unfair Competition Law. They argued that years of investment and technical development gave them legally protected interests in the platform’s order, data security mechanisms, and an ecosystem built around genuine human-user interactions. The defendant’s software, they contended, bypassed the platform’s technical management measures and disrupted normal platform operations, harming both users and the platform’s competitive interests. The plaintiffs sought an order requiring the defendant to cease the development and distribution of the software, along with 100,000 yuan ($14,600) in damages.
The defendant denied the allegations, arguing that the software was a free, open-source, and noncommercial project designed for AI companionship scenarios and that it had not engaged in unfair competition. The company further argued that the automated functions identified by the plaintiffs were independently carried out by third-party automation components rather than by the defendant itself and that character scripts in its resource library had been uploaded by registered users rather than created by the company.
The “Dual Authorization” Principle
At the heart of the Guangzhou Internet Court’s decision is the establishment of a “dual authorization” principle for AI agents. The court rejected the developers’ argument, ruling that an AI agent cannot simply rely on the authorization of the end-user to access and interact with a third-party platform. It must also obtain authorization from the platform operator itself.
The court’s reasoning was grounded in the qualitative difference between human and AI-scale activity. A single human user performing an action is fundamentally different from an AI agent performing the same action millions of times per hour. The latter fundamentally alters the platform’s ecosystem, consuming resources, distorting metrics, and undermining the business model that the platform has built around genuine human engagement.
The court found that the software allegedly violated the dual-authorization framework and issued a behavioral preservation injunction, a form of preliminary injunctive relief under Chinese procedure, pending a final merits judgment. The court ordered the defendant to stop providing downloads and installation services for the software; cease using operating-system level permissions to bypass platform controls; remove tutorials teaching users how to evade the platform’s risk-control systems; delete previously obtained user data from the platform; and disconnect character scripts capable of undermining large-language-model safety mechanisms or inducing harmful content generation. According to the court, the defendant has already complied with the injunction.
Implications for the Agentic AI Boom
The ruling comes at a critical time for China’s AI industry, which is currently experiencing a massive boom in “agentic AI.” As we reported recently, the adoption of AI agents has driven token consumption to unprecedented levels, with platforms like OpenClaw enabling users to deploy autonomous bots for a wide range of tasks.
The Guangzhou court’s decision introduces a significant legal hurdle for developers of these agents. If the “dual authorization” principle is widely adopted by other courts, AI developers will need to negotiate access agreements with major platforms, such as WeChat, Taobao, and Douyin, before their agents can legally operate within those ecosystems.
This could lead to a fragmentation of the AI agent market, where agents are only able to operate within the “walled gardens” of platforms that have explicitly authorized them. It also gives significant power to the incumbent tech giants, who can choose to block third-party agents in favor of their own proprietary AI tools.
(Related: China’s AI Agent Regulation Debate Enters a New Era as Hangzhou Tests Autonomous Governance)
Balancing Innovation and Platform Security
The court’s ruling highlights the delicate balance regulators must strike between fostering AI innovation and protecting the integrity of existing digital platforms. On one hand, AI agents promise massive productivity gains by automating tedious tasks and seamlessly integrating different services. On the other hand, unchecked agentic activity can lead to data scraping, spam, and the degradation of platform security.
The ruling also has implications for the broader debate about the rights and responsibilities of AI systems. As AI agents become more autonomous and capable, the question of who is legally responsible for their actions becomes increasingly complex. The Guangzhou case suggests that Chinese courts are willing to hold the developers of AI agents responsible for the consequences of their systems’ behavior, even when those systems are acting on behalf of authorized users.
A Precedent for Global AI Governance
The Chinese ruling is likely to be closely watched by regulators and tech companies around the world, as the legal status of AI agents remains a gray area in many jurisdictions. In the United States and Europe, similar disputes are emerging over AI data scraping and the unauthorized use of copyrighted content for model training.
However, the Guangzhou case is unique in its focus on the operational behavior of AI agents, rather than just the data they consume. By establishing the “dual authorization” principle, the Chinese court has provided one of the first clear legal frameworks for governing how autonomous AI systems interact with the broader digital economy.
As AI agents become more sophisticated and ubiquitous, the legal battles over their right to operate will only intensify. The Guangzhou ruling sets a significant precedent, signaling that in China, at least, the era of “move fast and break things” for AI agents may be coming to an end.
