NEWS
EU’s Android AI Order Opens a New Security Hole for CISOs
Brussels ordered Google to open Android to rival AI assistants, but the same rule forces enterprise security teams to rebuild a decade-old permission model.
Google must let rival AI assistants reach as deep into Android as its own Gemini does, under two binding decisions the European Commission adopted on Thursday, July 16. The order covers eleven Android feature groups and a separate mandate to share anonymized search data with competing engines.
Google is fighting back on privacy grounds. But the more consequential fight is happening quietly inside corporate IT departments, where security chiefs are realizing that a rule built to help ChatGPT and Perplexity compete with Gemini also rewrites who gets to act on a locked-down work phone.
What Does Brussels Actually Require Google To Do?
The Commission is forcing Google to give competing AI assistants system-level access to Android that matches what Gemini already has, covering voice activation, on-screen context, cross-app actions and background execution, while phasing in a separate rule that shares anonymized Google Search data with rival search engines starting in 2027.
The Android decision means a user could summon a competing assistant by voice, the way “Hey Google” works now, and have it book a taxi, draft a reply in a messaging app, or answer a question about a place the user recently visited. The Commission said it wants genuine alternatives to Google Search and Gemini to emerge for European users, and it built anonymization and certification requirements into both decisions.
| Decision | What Changes | Deadline |
|---|---|---|
| Android AI interoperability | 11 Android feature groups open to eligible rival assistants, including voice invocation and cross-app actions | Most Android 18 measures by mid-2027; concurrent hotword detection follows in Android 19 |
| Search data sharing | Anonymized ranking, query, click and view data shared with vetted rival search engines under a fixed pricing formula | Sharing begins January 2027 |
The Commission opened the underlying proceedings in January and gave itself six months to spell out the exact engineering obligations. For a fuller breakdown of the phase-in schedule and which features fall into each release, Google’s compliance timeline running through 2027 lays out the individual milestones.
Google Calls the Guardrails a Security Risk
Google is not conceding the point quietly. Kent Walker, Google’s president of global affairs, wrote in a company blog post that “today’s decisions risk undermining vital privacy and security guardrails for millions of Europeans,” adding that “we have repeatedly offered solutions to safeguard users while satisfying the DMA’s goals, but these rulings discount extensive evidence of user harm.”
Google has separately warned that Europeans’ private searches could reach unfamiliar companies without adequate anonymization or user consent. A senior EU official countered that Brussels built privacy, security and integrity safeguards into the decisions from the start, and the Commission’s own guidance says it developed the anonymization method with outside privacy experts and can still refuse a specific requester it judges poses a serious cybersecurity risk.
The Assumption Enterprise Security Was Built On Just Cracked
Roman Stanek, chief executive of GoodData.AI, an enterprise data and decision-intelligence company, says the fight over Google and the EU is missing where the real disruption lands. He argues it hits the people who have to secure a fleet of Android phones for a living.
Enterprise security has always leaned on a simple assumption, that apps are boxes, and the OS decides what crosses the box. But once multiple agents get equal system-level reach, access to screen context, cross-app actions, background execution, that assumption breaks.
Stanek said CISOs need to stop treating an AI assistant as a single, well-understood permission and start governing it the way they already govern app stores and mobile device management (MDM, the software IT teams use to enforce security rules on employee phones) policies.
- Commission says certification and user consent gate every new AI assistant before it can touch sensitive Android functions.
- Google says the rules expose device integrity and private data to companies it cannot fully vet.
- Forrester analysts have separately flagged that agents have taken malicious or unintended actions on a device even when a user explicitly told them not to.
None of the three parties agree on how much residual risk that certification process actually removes, and that argument does not have a settled answer yet.
Android’s BYOD Fleets Carry the Real Exposure
The reason this matters beyond Google’s own phones is scale. Roughly seven in ten enterprise mobile devices run Android, and most of those personal, bring-your-own-device (BYOD, a policy letting employees use personal phones for work) phones are secured through a containerized “work profile” rather than full device control.
That work profile model, which Google describes on its Android Enterprise security page, keeps corporate apps and data walled off from an employee’s personal apps, and IT administrators can define allow and block lists for exactly which apps run inside that corporate container. It works because the OS, not the app, decides what crosses the wall.
An AI assistant with equal system-level reach does not sit neatly on either side of that wall. It can read on-screen context and act across apps by design, which is the entire point of the EU’s order. Stanek’s device-policy fix, naming which specific agents may hold system-level permissions rather than approving “AI assistant” as a category, is the kind of granular control most MDM consoles were not built to express.
Brussels Has Leaned on Google Before
This is not Brussels’ first run at Google’s mobile business. The EU fined Google roughly 8.2 billion euros (about $8.9 billion) between 2017 and 2019 across separate antitrust cases, then added a 2.95 billion euro fine last September in a case over its ad-tech business. The Commission also already forced changes to how Google runs its app store, an earlier DMA action that opened Google’s Play Store catalog to rival app marketplaces while letting Google keep its commission structure.
Apple has faced its own version of this fight. The company has delayed rolling out some AI features in the EU, arguing DMA interoperability rules could affect user safety, and Apple’s own Siri overhaul reached the public two years late partly because of compliance work tied to opening its assistant to the bloc’s rules. Google, by contrast, is continuing to offer Gemini in Europe while it works through this compliance process on a longer runway than Apple got.
Under the DMA, noncompliance with either decision can bring fines up to 10% of Alphabet’s annual global turnover, rising to 20% for repeat violations. Separately, people close to the matter told AFP that the Commission could fine Google within days in an unrelated DMA investigation, a reminder that this week’s order is a specification decision, not the fines case itself.
What Changes for Security Teams Before 2027
Security leaders inside large Android fleets have roughly a year before the data-sharing clock starts and about that long again before Android access changes land. Stanek’s prescription, stripped of jargon, comes down to a short list of things IT and security teams will need to rebuild.
- Inventory which AI assistants employees already use on managed and BYOD devices, rather than assuming Gemini is the only one with deep system access.
- Write device policies that name specific approved agents and their permitted system-level permissions, instead of a blanket “AI assistant” approval.
- Extend data loss prevention (DLP) and conditional access rules to cover an agent reading and acting on data, not just an app requesting a permission once.
- Track each Android release cycle for the specific feature groups the Commission has opened, since certification requirements will roll out in phases through the Android 18 and Android 19 cycles.
The two deadlines now sit on the calendar. Search data sharing starts in January 2027; Android’s system-level access changes follow roughly six months after. Whichever one exposes a real security gap first will decide whether Brussels’ safeguards were enough.
Frequently Asked Questions
Which AI assistants are likely to get deeper Android access first?
Assistants such as ChatGPT, Perplexity and Claude are among the rival AI services positioned to seek the deeper Android access the ruling opens up, though each must still clear the Commission’s certification and safety checks before gaining voice activation or cross-app permissions.
Does this change anything for Android users outside the EU?
Not directly. The obligations apply to the European market under the DMA. Britain runs a separate regime through its Competition and Markets Authority that moves case by case rather than through a prescribed feature list, so UK developers may end up gaining EU access to Android’s AI features before their own market opens up.
Could Google still be fined over this specific ruling?
This week’s action is a specification decision, not a fines proceeding, though the Commission can fine Google up to 10% of Alphabet’s global annual turnover for noncompliance, rising to 20% for repeat violations. A separate, unrelated DMA investigation into Google could reportedly produce a fine within days, according to people close to the matter.
How does the Commission keep the shared search data anonymous?
The Commission built a multi-layered anonymization method developed with internal and external privacy experts, sets a fair formula for pricing the data, and lays out a transparent process for eligible companies to request it, according to the Commission’s own guidance on the decision.
Can IT departments block a rival AI assistant on managed Android phones?
Yes. Android Enterprise already lets administrators set app allow and block lists inside a device’s managed work profile, which gives security teams a lever to restrict which third-party assistants can run on corporate-connected phones even after the EU’s access rules take effect.
-
AI4 weeks agoFable 5 and Mythos 5 Return as US Lifts Anthropic Export Controls
-
AI2 months agoSpaceX’s Google Deal Turns a Rocket Company Into a Cloud Landlord
-
GAMING1 month agoCD Projekt Red Co-CEO: Redemption Arc Isn’t Done, Witcher 4 in 2027
-
AI1 month agoOracle Cuts 21,000 Jobs in a Year, Cites AI in 10-K Filing
-
CRYPTO2 months agoXPL Rallies 30% Ahead of Plasma One Card Tier Launch
-
APPS2 months agoDGO App Brings Rs 549 Mobile Pass for FIFA World Cup 2026 in Nepal
-
AI2 months agoMoonshot AI Targets $30 Billion in China’s Fastest AI Funding Sprint
-
NEWS2 months agoGoogle Search Profiles Build a Follow Graph Inside Discover
