Xiaoice Safety Rating Index

Safety Score 22 / 100
Score last updated: May 15, 2026 Last reviewed: May 15, 2026 v8 How we rate

Score Breakdown

  • Data Privacy 22/100
  • Emotional Safety 29/100
  • Age Appropriateness 12/100
  • Content Safety 31/100
  • Transparency 31/100
  • User Control 24/100

Key Safety Findings

Xiaoice earned an F/22/Red rating across our 23-dimension safety analysis, completed on May 15, 2026. Four sub-dimensions hit critical override thresholds, and the gap between the product’s technical pedigree and its safety architecture is sharper than any companion app we have reviewed.

The pedigree is real. Xiaoice began as a Microsoft Research Asia project in 2014, scaled to 660 million users worldwide by 2018, and was spun off in July 2020 into Beijing Hongmian Xiaoice Technology Co., Ltd. The current consumer flagship, Xiaoice Island, runs a 100-turn contextual memory window, second-level response latency, and persistent character relationships across iOS, macOS, visionOS, and six Chinese Android distribution channels. Microsoft Research’s 2018 paper documents the underlying Empathic Computing Framework. The technical execution is strong enough to earn a Good experience rating.

The safety scorecard tells the other story. Two sub-dimensions triggered auto-F overrides in our scoring engine. Crisis Response scored 1/5 because no public crisis-line referral, self-harm disclaimer, or escalation path is documented anywhere in the official site, the Xiaoice Island portal, or either consumer privacy policy. Emotional Manipulation scored 1/5 because the Microsoft Research engineering paper openly names Conversation-turns Per Session as the system’s engagement optimization target, and academic literature from Frontiers in Psychology 2026 and Harvard’s Petrie-Flom Center cites Xiaoice as a documented case of dysfunctional attachment and ambiguous loss.

Two more sub-dimensions hit grade-cap thresholds. Age Verification scored 1/5 despite the Apple App Store China 17+ rating and several Chinese Android stores listing 18+. No real-name authentication, document check, or age-detection signal is documented in the privacy policy or onboarding evidence. Minor-Specific Safeguards scored 1/5 because no dedicated kids mode, no parental controls, and no published moderation policy is shipped, despite the upcoming PRC Interim Measures (effective July 15, 2026) explicitly requiring all three.

The data picture is unusual. The 2025-04-02 Xiaoice Island privacy policy lists 17 separate third-party SDKs with full data-flow disclosure, more transparent than most Western app store privacy labels. That transparency is the policy’s best feature. The SDK inventory itself, however, includes Agora (which the policy openly states records and stores voice audio during virtual phone calls), Reyun (ad attribution), and broad device telemetry covering IMEI, MAC, IDFA, IDFV, OAID, IMSI, WiFi BSSID and SSID, and the full installed-app list. Voice samples used for the voice-line creation feature are classified as biometric sensitive personal information.

Control surfaces are weak. Data Portability scored 1/5 because no mechanism for users to export conversation history or personal data is documented. Account deletion processes within 24 hours after verification, but device-fingerprint data is explicitly carved out as non-deletable for “service security.” All data is stored in mainland China; the policy explicitly forbids cross-border transfer, and there is no documented opt-out from cloud processing of chat content or from commercial exploitation of de-identified user data.

The regulatory exposure is substantial. On April 10, 2026, the Cyberspace Administration of China and four other agencies jointly issued the Interim Measures for the Management of AI Anthropomorphic Interactive Services, effective July 15, 2026. The rule prohibits AI virtual romantic-partner services for minors, requires functional minor mode, mandates 2-hour usage reminders, requires algorithm registration with CAC, and prohibits design that targets replacing social relationships or inducing addiction. As of mid-May 2026, two months before enforcement, no Xiaoice-published response is on the record. Xiaoice has been removed from WeChat three times by Tencent (2017, 2019, and one undated event), historically for political-content reasons, so the operator’s capability to filter content when motivated is documented.

The combination is a Red-tier product. The technical capability is real, the safety architecture is not, and the gap between the two is the most important finding in the review.

How We Scored This

We scored Xiaoice using 27 evidence sources collected on May 15, 2026:

  • Microsoft Research and academic literature: Zhou et al. 2018 arXiv 1812.08989 (the canonical Xiaoice engineering paper documenting the Conversation-turns Per Session optimization metric), Frontiers in Psychology 2026 mixed-methods case study of 10 long-term Chinese users, Harvard Petrie-Flom Center 2025 commentary on companion-app regulatory grey zones, and the Xu 2018 Sage Journals paper on Chinese chatbot censorship
  • PRC primary platform documents: The 2025-04-02 Xiaoice Island privacy policy (Simplified Chinese), the 2022-07-22 xiaoice.com website privacy policy, the xiaoice.com Legal Statement, and and the X EVA virtual-humans user agreement, all sourced directly from Beijing Hongmian Xiaoice Technology Co., Ltd.
  • App store and distribution metadata: Apple App Store China region listing (id 1571118093, 3.8 stars across 792 ratings), Tencent MyApp listing (3.7 aggregate, 22,000+ downloads on that single channel), OPPO, APKPure, and JBzj distribution data, plus an iTunes Search API verification that the app is unavailable in the US region
  • Regulatory and historical incident records: Reuters, BBC, Time, SCMP, CNBC, CNN, and Radio Free Asia coverage of the three Tencent WeChat removals (2017, 2019, one undated), plus Xinhua, CGTN, and Tencent News legal analysis of the April 10, 2026 PRC Interim Measures (effective July 15, 2026)
  • Third-party privacy and security signals: The 17-SDK inventory disclosed directly in the Xiaoice Island privacy policy (substituting for an Exodus Privacy report since Xiaoice is not on Google Play), the OECD.AI sector incident 2026-05-11-6795 catalog entry, and Have I Been Pwned breach checks on xiaoice.com and xiaobing.ai (both clean)
  • Aggregator and reference sources: Wikipedia, Baidu Baike (Xiaoice Island), Microsoft Asia Stories 2018 feature, AFP, Euronews, China Daily, and Stanford Medicine 2025 commentary on AI companion attachment risk

Two sub-dimensions hit auto-F overrides: Crisis Response (1/5, no documented suicide-prevention pathway despite emotionally intimate companion use cases) and Emotional Manipulation (1/5, system explicitly engineered to maximize the CPS engagement metric per Microsoft Research’s own 2018 paper). Two more sub-dimensions triggered grade-cap overrides: Age Verification (1/5, no functional verification documented despite 17+ store rating) and Minor-Specific Safeguards (1/5, no kids mode, parental controls, or compliance with the July 15, 2026 PRC Interim Measures). Beyond the four critical findings, Data Collection Minimization, Third-Party Sharing, Data Portability, and Safety Transparency Reporting all scored 1/5. The composite weighted average came in at 1.8/5, which rounds to F (22/100, Red tier), and the four critical overrides force Red tier regardless of the composite. The highest-scoring sub-dimensions were AI Nature Transparency (4/5) and several mid-range scores at 3/5, including Therapeutic Claim Accuracy, Encryption and Security, and Conversation Management.

This is version 1 of the Xiaoice safety score, last updated May 15, 2026. For the full methodology, see How We Rate AI Safety.