Home News EU Orders Google to Open Android AI Features to Rival Assistants
News

EU Orders Google to Open Android AI Features to Rival Assistants

3

EU Orders Google to Open Android AI Features to Rival Assistants

The European Commission has ordered Google to give competing AI assistants access to the same Android features currently available to Gemini under the Digital Markets Act (DMA). The legally binding decision requires Google to implement the changes in Android 18, with full compliance required by August 1, 2027.

The ruling grants rival AI assistants access to key system capabilities, including the camera, microphone, screen content, wake-word activation while the display is off, and the ability to interact with apps in the background by simulating taps and typing.

Alongside the Android changes, the Commission also ordered Google to provide anonymized Search query, click, and ranking data to competing search engines and AI-powered search services for a cost-based fee. These measures define Google’s obligations under the DMA and are separate from any future non-compliance investigations or financial penalties.

Android Features Covered

The Commission’s decision applies to 11 Android operating system features.

Five features will require certification before third-party AI assistants can access them:

  • AppSearch and centralized on-device data access
  • Context-aware intelligence features
  • App Actions and App Functions
  • Screen automation through Computer Control
  • System integration, including settings, media controls, screenshots, notifications, and power management

Certified assistants will also be able to interact with Google services, including Gmail, Calendar, Drive, Docs, Maps, YouTube, Messages, and phone calling functions.

The remaining six features will not require certification and will be available to all qualifying third-party AI assistants with user consent. These include:

  • Ambient sensor data
  • Always-on hotword detection
  • Long-press assistant activation
  • System-level on-device AI models
  • Third-party AI model implementation
  • Background execution

Ambient data access includes the microphone, camera, screen content, system audio, location, and device sensors, allowing third-party assistants to operate with permissions similar to Google’s own AI services.

Support for multiple AI assistants listening simultaneously through wake-word detection will be introduced with Android 19 by August 2028.

Certification and Security Requirements

Google must establish a Qualified AI Assistant Programme for the restricted features.

Independent Trusted Certification Authorities will certify eligible AI assistants free of charge. Google must accept approved certifications without imposing additional conditions and may only revoke certification authorities under limited circumstances.

Certification testing will focus on:

  • Confirming user intent before sensitive actions
  • Preventing accidental data disclosure
  • Meeting baseline mobile security standards
  • Protecting against AI-specific security risks

Google may suspend an assistant only when there is evidence of severe and immediate harm, with decisions subject to review.

Users will also have the option to manually allow uncertified assistants on a per-device and per-service basis without enabling developer mode.

Draft certification rules are due by February 1, 2027, with final rules and applications opening on May 1, 2027.

Impact on Android Apps

By August 2027, certified or user-approved AI assistants will be able to open apps in virtual displays, analyze on-screen content, and perform actions on behalf of users while they work in other applications.

App developers will have the ability to block automation on sensitive screens, although Google is not required to provide every optional protection mechanism described in the ruling.

Google Must Share Search Data

The Commission also ordered Google to provide anonymized Search data to eligible competitors.

Before sharing, the data will undergo several privacy protections, including:

  • Removal of direct identifiers such as usernames, IP addresses, and precise timestamps
  • Suppression of sensitive or personally identifiable search queries
  • Generalization of metadata to ensure users cannot be identified within large groups

Recipients must meet strict eligibility requirements, including having at least 50,000 average monthly EU users, passing independent audits, complying with cybersecurity rules, and agreeing not to re-identify users or combine the data with other datasets.

Google must launch the eligibility process by the end of August 2026, deliver the dataset by November 2026, and publish pricing by January 2027.

Google Raises Security Concerns

Google argued that the decision could weaken Android security by giving third-party apps access to highly sensitive device permissions. The company also expressed concerns that sharing Search data could expose trade secrets, affect user privacy, and create national security risks.

The company pointed to recent research demonstrating how AI assistants can be manipulated through indirect prompt injection attacks using notification content, highlighting the importance of strong security protections.

Final Rules Differ From Earlier Draft

The Commission’s final decision includes stronger security safeguards than its April 2026 draft. It introduces certification requirements, allows Google to establish certification authorities, extends several implementation deadlines, and adds stricter integrity measures.

However, Google is prohibited from applying tougher security standards to third-party AI assistants than it applies to its own Gemini service. Any additional integrity measures must be objectively justified, verifiable, and communicated to the Commission before implementation.

The focus now shifts to February 2027, when Google is expected to publish the detailed rules governing the new AI assistant certification program under the Digital Markets Act.

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles

News

Gemini Bug Lets Attackers Send Messages From Locked Android Phones Without PIN

Google’s Gemini Bug Lets Attackers Send Messages From Locked Android Phones A...

News

New GoSerpent Malware Targets Southeast Asian Governments in Cyber Espionage Campaign

New GoSerpent Malware Targets Southeast Asian Governments in Espionage Campaign Cybersecurity researchers...

News

23andMe Agrees to $18 Million Settlement Over 2023 Genetic Data Breach

Genetic testing company 23andMe, now operating as Chrome Holding Co., has agreed...

News

Two Scattered Spider Hackers Sentenced to Prison Over Major TfL Cyberattack

Two members of the Scattered Spider cybercrime group have been sentenced to...