Google has built a "security cage" inside Android that controls which AI agents can act on your phone — and Google alone decides who gets in.

The system, called EXECUTE_APP_FUNCTIONS, lives in Android's AppFunctionsManager framework and is reserved for what Google calls "approved agents," according to Android Police. Right now, that approval flows almost entirely to Google's own Gemini assistant. The same company that censors search results, deplatforms dissidents, and tracks your every move is now building the leash for artificial intelligence on the device you carry in your pocket.

The infrastructure is real but empty. Android Police reports that the EXECUTE_APP_FUNCTIONS permission exists in the operating system but no third-party agents are using it yet. Gemini's access is limited to "a small, in-house group of testers that Google handpicked," with no timeline for broader availability. Developers who want in must apply to an early program with no guarantee of selection — and no guarantee the rules won't change.

Here's how it works: instead of an AI agent simulating finger taps on your screen, developers build shortcuts to specific app actions. Ask an AI to book a ride, and instead of opening the app and hunting for buttons, it triggers the action directly — like a hyperlink for a task. Android tracks these shortcuts through the AppFunctions system.

Android Police framed this as Google making the "right call" by building the cage before the tenant arrives, noting Android's habit of shipping features first and locking them down after something goes wrong. But that framing buries the real question: who decides which agents get approved, and on what grounds?

The stakes are not hypothetical. At the Fortune Leaders Forum in Macau, Black Lake Technologies founder Yuxiang Zhou described how AI agents now make many of his company's decisions. "A lot of my decisions are now made by agents, large language models, and my executives," Zhou said. When corporations hand decision-making to AI, the question of who controls the AI's permissions becomes a question of who controls the decisions.

Google's security cage isn't just about protecting users from rogue AI. It's about controlling which AI gets to operate on the most widely used mobile operating system on Earth. The permission system means Google decides which agents are "approved" — and which are locked out.

The cage is built. The keys are in Google's hand. The only question left is who they let in — and who they keep out.