ENG
Report

Assessing the State of AI-Powered Mobile Security

0
October 29, 2025

Introduction

Artificial Intelligence (AI) is playing an increasingly important role in mobile security for smartphones. Not only are attackers getting more sophisticated with the use of AI, but platform providers, like Google and others, continue to integrate Machine Learning (ML) and advanced LLMs in their security stack to address real-time vulnerabilities and changing threat scenarios.

The shift towards AI for security, whether on-device or in the cloud, introduces new considerations regarding the efficacy of AI systems that benefit from access to vastly larger datasets. While on-device processing enhances privacy by keeping user data localized, cloud-based capabilities are critical to ensure systems can continue to learn and stay on top of changes in the threat environment. The combination of both aspects of AI implementations creates a framework capable of meaningfully impacting the user experience in a positive manner.  

A recent Counterpoint consumer study across six key countries indicates that safety and security are key considerations for current smartphone owners. Users across nationalities (Brazil, Germany, India, Thailand, UK and US) and demographics indicate that they are concerned AI could be misused for fraud or scams, above other potential impacts it might have on their mobile experience and lives. However, improvements in the prevention of phishing and social engineering attacks, deep fake/image verification, data protection enhancements, and improvements in biometrics (such as fingerprints and facial recognition) are all viewed in a positive light and indicate that users recognize the value these new technologies can offer and the positive impact they can have.


For smartphone OEMs in the Android ecosystem, these results are validation of their existing and continued efforts to utilize increasingly powerful AI tools to combat rising threats and connect with user base concerns in the right way. It also positions them well to address security as a future purchase parameter. In the same study, respondents indicated that increased confidence in AI-powered security will impact the next device choice to a significant level - highlighting the overall importance users place on mobile security.


Google, as an OS provider, has been pushing the utilization of proactive security measures in the Android platform for some time. The company is now increasingly supplementing Machine Learning-based features with LLM-based AI capabilities to further strengthen the platform and introduce new features that previously have not been possible to implement.


While features like real-time call screening or phone call spam detection provide increased security via the Android platform, they are not universally available yet due to the open and diverse nature of the Android platform. The openness of the platform allows OEMs to utilize the features they consider fit and develop their own solutions in addition to existing Android features to differentiate their products from the competition. Apple, on the other hand, can control the end-to-end development of hardware and software-based security features uniformly. Until WWDC25, the company had not been as publicly active in integrating advanced AI features in its security stack, but announcements at the event, including automatic spam filtering in Messages, indicate that Apple is moving in a similar direction to Google.

This report focuses on examining OEM efforts in proactively addressing real-time security threats using AI across phone calls, messaging, browsing, app installation and physical theft.


TLDR: Key Findings

 Smartphones host many aspects of a user's digital life, from communication and entertainment to banking and health-related apps. At the same time, sophisticated threats are on the rise, putting more personal data at risk.

AI is increasingly becoming pivotal in transforming mobile security from a static set of features trying to combat threats when they reach the user to a proactive solution intelligently recognizing and predicting threats to actively mitigate attacks as they happen.

Google has been openly pushing AI as a key enabler to further enhance the effectiveness of Android security for its user base. Key features for Android include:

●       Google Play Protect: Utilizes AI to continuously scan apps for malware, both in the Play Store and on the device.

●       Scam and Phishing Detection: Real-time, on-device detection of scams in calls, messages, emails and web browsing on Chrome.

●       Theft Detection Lock: Uses AI to detect if a phone has been stolen and automatically locks the screen to protect user data.

The overall improvements in mobile compute power have not only made on-device AI a reality but are critical to drive security application enhancements forward. This allows for the analysis of sensitive data directly on the user's device, which enhances trust and allows advanced features to run without the need for a connection to the cloud – enabling a completely new set of AI security features.

The nature of the Android ecosystem allows OEMs freedom and flexibility to develop their own solutions on top of the features provided by the platform, while at the same time giving them access to the full suite of Google developed security features via Google Mobile Services.

Consolidating the security user experience across Android will be a critical area of focus for Google and its OEM partners going forward. Inconsistent security feature deployment can hide the biggest benefits of Android's security innovations, especially those powered by AI.

Apple is taking more public steps to enhance iOS security with AI, as highlighted by announcements at its latest developer conference. Developing features that allow for interaction with the user during an event (spam message filtering) lets iOS users engage with technology meant to protect them in a more personal way and highlights the capabilities of AI-powered solutions.

Going forward, it will become increasingly pivotal for solutions to remain agile. Platforms must be able to train their models on new input data to ensure the models remain relevant and capable of identifying new threats as they appear.

For users, awareness of security threats and the technologies developed to fight them must remain a constant focus as they use devices for more services and expose more data to potential attacks. Users should demand high-powered, AI-driven security from the brands they use for their mobile lives and actively contribute to creating solutions that can protect users on a global scale.

AI-powered Security Comparison Table: Android vs iOS

Below is a round-up of the main AI-enabled security features on default Android and the equivalent default iOS implementation. Google’s focus on proactive measures, enabled with AI, helps Android stay on even footing with potential attacks – if not ahead of them. Assessing Apple's AI security implementations relies on publicly available information, primary research and hands-on testing.



AI Security Overview

 Threats in mobile are not new. The emergence of AI has enabled both bad actors and the security community. While it is now easier than before to develop new attacks and pathways to fraud activity, mobile platform providers are now equally better equipped to respond and have access to technologies to proactively intercept new security challenges.

Historically, many sophisticated AI features relied on cloud processing due to the intensive computational resources required and the benefits of training models on massive, diverse datasets. However, significant advancements in mobile processor capabilities (Apple's Neural Engine, Qualcomm's AI Engine in Snapdragon SoCs, Google’s Tensor Processing Unit) and AI model optimization techniques (such as quantization and pruning) have made enhanced on-device AI increasingly viable, further strengthening the overall robustness of security features.

Google is now driving the utilization of AI as a key security enabler, especially for tasks involving sensitive user data, such as analyzing personal communications or browsing habits for security threats. This trend generally enhances user trust and combines on-device compute and cloud-based adaptability.

Android is more overt in its current public-facing efforts about leveraging on-device behavioral analysis for distinct security functionalities. In contrast, Apple's approach with Apple Intelligence seems to be building a more generalized, privacy-preserving understanding of user context and behavior. While this deep contextual awareness undoubtedly has security benefits and could be foundational for future security applications, it is not always framed as a direct “anomaly detection” tool for specific threats in the same way as some of Android's features are specifically targeted at mitigating current and future threats. Android has invested more into specific (and discussed publicly) AI-driven behavioral security tools – critical to user education as tools and features become available to bridge user hesitancy towards new, difficult-to-explain and potentially invasive capabilities.

Despite the significant advancements AI brings to mobile security, it is not a finished solution, and current implementations have areas for improvement – false positives and negatives impacting user confidence, evolving threats requiring constant updates to AI models, contextual understanding of voice prompts and interactions, resource consumption on the device and in the cloud, data bias, user trust and transparency in showing the reasoning behind decisions made by AI, and overall effectiveness. While these are required improvements for an AI system, they are especially critical for security features.

Malware Detection

Google Play Protect is a built-in malware protection platform for Android devices with Google Mobile Services. It continuously scans apps on the device and apps being installed from the Google Play Store, using AI to detect and prevent harmful apps from being installed.

Google Play Protect (GPP)

The scanning of apps occurs both before an app is listed on the Play Store and continuously on the user's device for installed apps. The continuous cycle of scanning all apps on the device, including those side-loaded or downloaded from third-party app stores, is an important added level of protection and indicates that changes, even with already installed apps, can be addressed.

Malicious well-designed apps are hard to distinguish from normal apps for most mainstream users. Having built in- malware protection to deactivate, or remove the app, creates a path to visibility for the end user who might be looking for the app, or is wondering why it disappeared.

The integration of AI in the Google Play app review process strengthens the constant checks. Because Android is an open platform, Google needs to have a systematic approach to dealing with applications reaching user devices outside of the Play Store. When Android detects an app that's never been scanned before, it alerts the user with a large on-screen pop-up message and offers to run an initial check. This check sends information to the Play Protect cloud for a real-time evaluation of the app in question. Only after the check can the app be installed. Usually, this real-time check happens incredibly fast and does not pose a serious hindrance to users to the point of becoming frustrated with the process.

On-device AI capabilities can detect potential malware by analyzing app behaviors and alert the user. This safety layer of security is an outstanding tool to prevent misuse of app permissions and enables user education that app permissions can also lead to security breaches. This real-time capability ensures that apps behave in the way they are expected to.

The feature also highlights the fluid nature of app permissions, security threats and user expectations. An application might not be inherently fraudulent, but certain practices used by the developer can still put users at risk or structure the app’s behavior in ways unclear to the end user. This is an important level of defense for users once an app has passed safety scanning in the Google Play Store and on-device checks.

Google’s utilization of bold and overlaying notifications from GPP makes it hard for users to ignore warnings. Overlaying warnings creates an action item for the user to engage with and read before dismissing. In normal usage, users are unlikely to constantly download new applications once they have their preferred set of apps on their device, thus making it less likely that notification fatigue will set in, driven by constant requests for app validations.

Scam and Phishing Detection

Google has taken a very public and advanced path to deploy native, AI-driven anti-phishing capabilities in its first-party browser and communications applications: Chrome, Gmail, Phone by Google and Google Messages.

Phone by Google

The Phone by Google app, default on Pixel devices and available for other Android phones, includes several features to combat fraudulent calls:

Caller ID and Spam Protection: This feature, active by default in Phone by Google, attempts to identify businesses and display warnings for suspected spam numbers before the user answers the call. The visually striking red color on the call screen is an easy indicator and is more pronounced than on other Android devices.

Filter Spam Calls: Users can enable a setting to automatically prevent suspected spam calls from ringing, sending them directly to voicemail.

Call Screen (Pixel devices): This is an interactive screening tool where Google Assistant answers calls from unknown numbers on the user's behalf. The Assistant asks the caller for their name and reason for calling, and a real-time transcript of the interaction is displayed on the user's screen. The user can then decide to answer the call, hang up, report it as spam, or ask for more information. It is one of the best tools for users to bridge the gap between rejecting all unknown numbers and providing flexibility for users who might need to answer calls from unknown numbers, like from schools, clinics or other businesses.

There is a version of this feature for devices that ship with “Phone by Google” as the default phone app. The key difference here is that the non-Pixel implementation requires user awareness (that the correct app is installed as the dialer application on the phone) and then user input to use suggested replies to engage with a potentially fraudulent call.

Scam Detection (Pixel 9 and newer): This feature uses on-device AI models (Gemini Nano) to analyze the audio of incoming calls from non-contacts in real time. It looks for patterns and keywords indicating common scam tactics, such as requests for payment via gift cards or pressure to provide personal information. If a potential scam is detected, the user receives audio and haptic alerts, along with an on-screen warning.

To protect privacy, call audio is processed on the device and deleted after completion; no audio or transcriptions are recorded or sent to Google – a key privacy feature critical to help alleviate user concerns of phone calls being tracked, recorded and used for AI training without consent. Switching the feature from “off by default” (as it is now) to “on by default” and requiring users to opt out could be a future enhancement, which would raise visibility of the feature and utilization.

It will be critical to continuously enhance this feature, as increasingly sophisticated call attacks, using AI to create fake voices and mimic real people, are on the rise.

Android, particularly on Pixel devices, has more deeply integrated native, real-time AI-driven call content analysis through features like Call Screen and on-device AI Scam Detection. To improve the performance of each feature, Google needs to work with its OEM partners to implement them on non-Pixel devices.

Google Messages

Google Messages, the default RCS and SMS/MMS app on many Android devices, includes native spam protection that warns users about suspected spam and phishing attempts.

A significant AI-powered enhancement, launched in March 2025, is Scam Detection. This feature uses on-device capabilities to analyze SMS, MMS and RCS messages from non-contacts in real time. It is designed to detect suspicious patterns, including conversational scams that may start as seemingly normal conversations but evolve to soliciting personal information for fraud. If a suspicious pattern is detected, the user receives a warning with options to dismiss the alert or report and block the sender. This feature is on by default and happens on-device. A critical next step will be the expansion of language support beyond the current list of English, Spanish, Portuguese and German, especially considering the advancements made in real-time text translation.

The challenge for AI in messaging scam detection lies in the evolving nature of conversational scams and the need to balance detection with user privacy. Conversational scams are designed to bypass simple keyword filters by starting with benign interactions and gradually manipulating victims. On-device AI, as implemented in Google Messages, must analyze message content, sender behavior and conversational patterns locally. While this preserves privacy by not sending message content to the cloud, it also means the AI model's learning is primarily based on the data it was initially trained with and any on-device updates, potentially limiting its exposure to new scam trends. A cloud-based solution would be able to notice changing trends but requires off-device processing. The system’s effectiveness against entirely novel scam scripts is an ongoing concern. Google will need to find a way to generate training data from on-device models, without relying on users to agree to send reports to the cloud.

Another area of improvement, which Google is beginning to address, is enabling similar security features as found in Messages on third-party messaging apps, like WhatsApp. In many markets, SMS/RCS messaging is not the primary method of messaging. A platform approach from Android will go a long way to create a safety layer at scale, without users having to wait for individual developers to implement their own frameworks.

Gmail

Gmail incorporates AI and machine learning to protect users from spam and phishing emails. By analyzing patterns across billions of messages, Gmail can identify characteristics of malicious emails.

The app provides warnings before users download potentially risky attachments or if suspicious login activity related to their Google Account is detected. The visual similarity between the user experience online and on the handset helps create a sense of familiarity with the safety capabilities in Gmail, creating trust, as long as the correct messages are flagged as suspicious.

A byproduct of Google’s success in combating threats to user inboxes is the transferability of the knowledge gained from analyzing billions of messages with malicious and fraudulent content. The company is able to combine analysis of these messages with the information gathered through Chrome Safe Browsing and create a learning loop, benefiting both services.

Via Gmail, Google has been able to establish a significant level of user trust in the brand. This is critical to help users get on board with some of these advanced features. A long history, tangible for many users via their own inboxes, should help Google overcome concerns about AI being used in ways that are not truly beneficial to the individual user, especially considering apprehension shown in the Counterpoint survey towards losing control over private data to train models.

Browsing – Chrome Safe Browsing

The inclusion of on-device AI for phishing and scam detection is a key advancement. Traditional anti-phishing methods often relied on checking URLs against blacklists of known malicious sites. However, new phishing sites can emerge quickly and bypass static catalogs. On-device LLMs can analyze the content, structure and behavior of a webpage in real time for suspicious patterns, even if the URL is previously unseen. Performing this analysis on-device enhances user privacy by avoiding the need to send all browsing data to cloud servers for scrutiny, thereby offering a potent combination of AI's pattern-recognition strengths in a privacy-centric use case.

With the Enhanced Protection mode, Chrome provides a higher level of security by proactively sending URLs and small samples of content and system information to the Google Safe Browsing backend, which includes a visual inspection of websites to detect fake sites via the TensorFlow lite model, for real-time analysis, helping detect known and new threats.

Google has a history of alerting browser users to potentially harmful websites with clear visuals. The inclusion of AI will further refine the system, leading to fewer false alerts for users who are trying to access a legitimate website – another key consumer concern.

One-Time Passcode (OTP) protection

An often-overlooked potential risk to mobile users is OTPs, which are meant to increase security between apps and sensitive data found in them. However, if users are tricked into granting notification access to bad-actor apps, OTPs can be intercepted. OTP notifications are automatically redacted when notifications are shared with apps and can also be blocked from view when screen sharing is ongoing.

Providing added levels of security for an under-the-radar feature is critical because users are likely not thinking about a notification meant to protect them as being the target of an attack.

Theft Detection Lock

Theft Detection Lock uses AI in conjunction with device motion sensors (like the accelerometer), Wi-Fi and Bluetooth signals to detect if a phone is suddenly stolen from the user and the thief escapes. If such an event is detected, the device's screen automatically locks to protect its content. AI helps interpret physical actions as indicators of theft and goes beyond geo-fencing to identify safe zones or whether a user is at home or away. It also allows the phone to react to the threat without having to wait for the user to lock the device remotely (effectively confirming the theft) through a different device. This could take too long and put data at risk. Google combines AI-powered theft protection with features like Offline Device Lock, Enhanced Remote Lock and Factory Reset Protection Enhancements to create a well-rounded solution, bridging AI, connectivity and on-device features.

This is another level of security whose benefit greatly outpaces its potential perceived nuisance. In most cases, a user will not be faced with additional requests for verification very often during the normal usage of the device, but it is a critical benefit if things have gone wrong.

Android OEM Implementation Comparison

A critical part of the effectiveness of AI-powered security features being deployed via the platform has to do with the implementation of those features by OEM partners. The duality of Google as the platform provider and OEM creates tension between which features are exclusive to Pixel, which aren’t and which should be platform features right away.



OEM Implementation – Google Pixel 10 Pro XL

Google's Pixel line has consistently emphasized tight integration between hardware, software and AI capabilities. The Pixel 10 Pro XL continues this strategy, positioning on-device AI as a key to its security features. 

AI-driven Security Features

Google's on-device LLM, Gemini Nano, is optimized to run on the Tensor G5. This model underpins several key AI-driven security features. Its ability to understand and process natural language and contextual information locally allows for features like on-device scam detection in phone calls and text messages. Google Chrome’s enhanced Safe Browsing capabilities rely on machine learning to analyze website content directly on the device for phishing and malware indicators.

The Pixel 10 Pro XL's security strategy showcases a deep commitment to leveraging custom-designed hardware in conjunction with sophisticated on-device AI models like Gemini Nano. This integrated approach allows Google to deliver highly effective, privacy-centric security features, particularly in combating communication-based threats such as scams and phishing. Google is proactive in addressing real-time threats, engaging users, and providing physical security options as well.

Across implementations, it is the numerous touchpoints provided by Google’s security implementation that sets the range apart from the competition. Real-time interactions push users to be alert. While features are visible and easily accessible to the user and not hidden in menu lists, which a user must discover on their own. Making the security setup, or tutorial, a part of the device set-up is a critical step to fostering awareness and increasing utilization.


OEM Implementation – Samsung Galaxy S25 Ultra

Samsung's Galaxy S series benefits from the Knox umbrella of security features developed by the company, alongside partners.

AI-driven Security Features

A key privacy feature for Galaxy AI is the option for users to choose to process data only on-device. When enabled, this setting restricts Galaxy AI features from sending data to the cloud for processing, giving users a significant level of control over their experience.

The Galaxy S25 Ultra features AI Call Screening capabilities to detect and filter spam calls, giving users the ability to interact with incoming calls before answering. Using text prompts, users can have the phone read out additional prompts to further inquire about the reason for a call.

Samsung's AI security strategy for the Galaxy S25 Ultra is a hardware-anchored approach using the Knox brand. It provides a baseline of security, particularly appealing for enterprise users who value data segregation and management tools like Secure Folder and Knox Matrix.

However, many features are hidden in menus, which users must discover without much surface-level guidance. While “AI search” in the settings app allows for a free-flow approach to search for an item, security features like call screening are hidden deep in the interface. Any friction in discoverability is a significant hurdle to mass adoption and utilization of these AI features. Hence, they need to be as easily accessible as possible so that mainstream users can be made aware of their availability and usefulness.

It also appears that more potentially problematic calls and texts make it through the Samsung screening process, creating a higher likelihood of an attack reaching a user. While Samsung has built brand awareness with Knox, the on-device interface relies on the user to be proactive. The overall system needs to be more proactive in addressing threats and surfacing mitigation solutions.

OEM Implementation – Motorola razr Plus (2025)

The Motorola razr Plus (2025) approaches AI-enabled security by combining core Android features with Motorola's own software enhancements and a significant partnership for advanced threat detection.  

AI-driven Security Features

The primary AI-driven security capability on the razr Plus is the Moto Threat Defense by Zimperium. The z9 engine uses an on-device machine learning engine to analyze device behavior, network activity (Man-in-the-Middle), and app integrity to detect and mitigate threats, including zero-day exploits, rooting and jail breaking attempts, without relying on cloud-based signature updates for many detection types. A significant advantage is its ability to function even when the device is offline.  

However, Motorola's software update policy, which has historically been shorter (e.g. three years of OS upgrades and four years of security updates for Razr devices) than that of competitors like Google and Samsung, creates the potential for more threats to reach users later in the device’s lifecycle. In the rapidly evolving landscape of AI threats and defenses, a longer update commitment is generally preferable to ensure continued protection and access to the latest AI security innovations.

While Motorola, via Lenovo, can rely on a history of enterprise-grade security developments and brand recognition, it is unclear whether the ThinkShield brand has had an impact on the target user audience for Motorola’s foldables or most other device ranges in the current portfolio. Motorola’s strategy highlights a key concern: OEMs must be able to be judged to operate ethically and effectively with AI. A strategy relying on multiple external partners will make it harder for Motorola to tell a straightforward story about its value proposition.

OEM Implementation – OnePlus 13

OnePlus increased its focus on securing data with the OnePlus 13, via OnePlus AI features supported by a hybrid processing architecture. 

AI-driven Security Features

OnePlus is making a significant push with its OnePlus AI ecosystem on the OnePlus 13 – prioritizing on-device processing within a TEE for sensitive data while utilizing an encrypted Private Computing Cloud for more intensive tasks. The security of new features like AI Plus Mind and various AI assistants is central to this strategy.

OnePlus also integrates established Android security measures, such as Google Play Protect Live Threat Detection and enhanced theft protection features. The effectiveness and transparency of its Private Computing Cloud, particularly in how it compares to or differs from other secure cloud processing solutions, will be critical for the company to highlight going forward.

The naming similarity between OnePlus' Private Computing Cloud and Google's Private Compute Core should be clearer. Creating a similar security brand to Google’s existing brand is likely going to impact user trust and hinder OnePlus’ ability to develop a standalone suite of features. 

Apple iOS26 & iPhone 17 series

With iOS26 and its iPhone 17 series, Apple announced a few new features that will mirror what is already available on Android devices, particularly the Pixel.

Building on Live Voicemail, the Phone app now includes Call Screening. This feature enables a preemptive step in the call process which aims to block calls from unknown, potentially risky, numbers. Call Screening allows a caller to provide additional details about the call, visible to the recipient of the call. Only the transcription and summarization of the voice note is currently handled by Apple Intelligence - on-device. However, a lot of the process to determine which call should be let through to the user happens without the user's knowledge or participation. Apple received negative feedback on the way Apple Intelligence initially handled notification summaries, and it will take time for the company to prove to users that it can handle real-time calls without dismissing legitimate calls too soon and too often.

Apple Messages can now also filter messages into a dedicated folder if they are from unknown numbers. This is a feature that has existed on Android for some time, particularly within the Google Messages app. Segmenting these types of messages is a key step in highlighting them as ‘different’ for the end user – potentially preventing fraudulent messages from reaching a user without necessary caution.  

Locked and Hidden Apps allow users to lock any app, requiring Face ID, Touch ID, or a passcode to open it. Information from within a locked app, such as messages or calendar events, will not appear in search, notifications, or other places across the system. For even greater security, users can choose to hide an app entirely, moving it to a locked, hidden apps folder.  

This functionality is a direct competitor to features like Samsung's Secure Folder, OnePlus’ Mind Space or Pixel’s Private Space. While Secure Folder and Private Space create an entirely separate, encrypted container for apps and files, Apple's approach appears to be a simpler, app-by-app locking mechanism integrated directly into the OS, which may be more intuitive for average users. Samsung’s KEEP announcement also provides a path to block apps from accessing sensitive information across app silos.

However, the advent of Agentic AI is putting pressure on certain apps’ ability to view and interact with content and data from other apps more frequently. Here, proactive notifications and detailed overviews and explanations will be critical for Android users to remain confident that their data is protected. Google’s proactive approach to scanning existing apps is a critical benefit here.

In summary, Apple's iOS26 announcements focused on the company’s strengths – leveraging tight hardware-software integration to push as much AI processing as possible onto the device, and where cloud processing is necessary, building verifiably private architecture to handle it. New features like Locked Apps and more granular permissions give users more direct control, while the adoption of encrypted RCS closes a major gap in cross-platform communication security. This positions Apple not as the most feature-rich AI player but as one sticking to its strategy of conservative feature expansion, even as the industry races ahead with many new paths to combat threats proactively.

Outlook

The integration of AI is no longer a developing trend but is rather a critical factor in reshaping mobile security, enabling a shift from mostly reactive measures to proactive and even predictive defense strategies. The industry-wide push towards on-device AI processing is pivotal in reconciling the demand for intelligent security features with ironclad user privacy requirements. In the recent Counterpoint study, respondents indicated that they feel more protected by their phone with the inclusion of AI. Android users felt slightly more positive (67%) than iOS users (62%) about the impact AI made on this part of the mobile user experience. While user trust is difficult to win, a positive impact has already been established. However, this trust is easily lost.

The evolution of mobile security will face several challenges. AI models must continually adapt to keep pace with rapidly evolving threats, including the rise of sophisticated deepfakes, advanced social engineering tactics, and new malware. Managing the accuracy of these AI systems to minimize false positives (which can frustrate users and erode trust) and false negatives (leading to security breaches) must remain at the heart of any development. Addressing these potential pitfalls head on will go a long way to alleviate concerns respondents in the survey showed regarding false or misleading content being generated (62% voiced some level of concern), unauthorized actions being taken on behalf of the user (58% reported some level of concern) and private data sharing (57% indicated some level of concern). Therefore, ensuring the ethical use of AI in security, avoiding biases, and maintaining transparency in AI-driven decisions will also be crucial. Furthermore, the AI models themselves can become targets, necessitating robust measures to secure their integrity.

Anticipated developments in mobile security are likely to include more sophisticated behavioral biometrics for continuous authentication, AI-driven vulnerability discovery within the operating systems themselves, and potentially more autonomous AI-powered incident response capabilities directly on user devices. The fusion of AI with hardware security features, such as Trusted Execution Environments or Secure Enclaves, may lead to the development of ‘AI-secured Enclaves’ which could be capable of running complex, privacy-preserving security models in an even more isolated and compromise-resistant manner, allowing for highly sensitive analyses without data leaving the secure parts of the processing platform. This would further strengthen the privacy-preserving AI narrative while potentially enabling more powerful on-device AI security.

As AI becomes more deeply embedded in mobile operating system security, the ‘explainability’ of AI-driven security decisions will become increasingly important for user trust. Unexplained AI decisions resulting in users being locked out of their devices or legitimate activities being flagged as fraudulent, without justification, are likely to face significant pushbacks from end-users.

Advancements will need to incorporate this explainability into mobile security AI to provide greater transparency for actions taken by generative AI systems. This will be key to maintaining user confidence as AI assumes more autonomous roles in an Agentic AI-enabled future mobile experience. The connection between OS-native AI security capabilities and specialized third-party AI security solutions will also continue to evolve, particularly as platform APIs become more powerful and versatile, offering users a dynamic and intelligent wall against sophisticated threats.

While iOS and Android offer enhanced security frameworks, each is taking a different approach to threat mitigation. iOS emphasizes hardware-software synergy and a curated environment to deliver consistent security, with privacy being the focus. Android, which is built on an open-source foundation, provides robust security and privacy layers and is growing aggressive in deploying AI-driven proactive threat detection mechanisms to protect its diverse user base – while enabling partners to benefit, re-use and build on top of the platform-provided features.


With its latest security features, Google is directly addressing concerns highlighted by users across major markets. The company is not only developing highly sophisticated features with the integration of AI but is also using these features as a differentiator between its platform and the competition, recognizing that end-users are clearly aware and in favor of AI being used as a key tool in proactively addressing and preventing mobile threats across the smartphone user experience.


Category

Industry

Smartphone

Service

Standard

Report Type

Report

Time Period

Other

Receive our insightful weekly newsletter and stay ahead of the competition.

Author

Gerrit Schneemann

twitter_icon
linkedin_icon

Gerrit has 17 years of experience in the telecoms and consumer electronics industry. With a long history of covering the global smartphone market, he provides clients with strategic insights and advice impacting short and long-term business needs and decisions. Before joining Counterpoint Research, he spent over a decade at iSuppli, IHS/Markit and finally Omdia, before a short stint at GfK Boutique.