Brussels Tells Google to Share Android's Sensors With Rival AI — Whether It Likes It or Not
The European Commission has handed down two binding decisions under the Digital Markets Act that are going to make Google's product team very uncomfortable. The first forces Google to open up Android's hardware and system features to competing AI assistants at the same level Gemini currently enjoys. The second compels Google to share anonymised Search data with rival search engines and AI products. Neither comes with an immediate fine, but both carry teeth.
Android 18 is the target vehicle, and 1 August 2027 is the hard deadline.
The Commission opened proceedings in January. That it's reached binding specification decisions six months later is not a slow pace, by Brussels standards.
What exactly has to open up
The Android decision covers eleven OS features. Five of them Google can keep behind a certification gate. The other six it cannot restrict at all.
The gated five include things like AppSearch (centralised on-device data), the proactive suggestion machinery, App Actions and App Functions, screen automation, and broader system integration covering settings, notifications, screenshots, and media. Google can require assistants to pass a certification process before touching these.
The open six are where it gets interesting. Ambient data access, always-on hotword detection, long-press invocation, on-device models, third-party model implementation, and background execution all open to any third-party app, no gatekeeping permitted. Paragraph 119 of the decision explicitly bars Google from restricting the type or use case of apps that call these features.
Ambient data, to be specific, means microphone, camera, system audio, screen contents, location, and sensor feeds like the accelerometer, available continuously in the background under the same consent prompts Google uses for its own services. That last clause is doing a lot of work. Right now third-party apps get full runtime consent dialogs per use; Google's own stuff gets lighter treatment. The Commission is closing that gap.
Hotword detection runs on the low-power DSP, which means it works on a locked screen, survives battery saver mode, and keeps recording until the user says they're done. Multiple assistants listening simultaneously, however, slips to Android 19 and a 2028 deadline.
The certification regime Google now has to build
For the five restricted features, Google must establish a Qualified AI Assistant Programme. It has to accept certifications from third-party Trusted Certification Authorities, free of charge, without bolting on extra conditions, and without revoking them. Google writes the programme terms and decides who can become a TCA, but those terms must be reasonable, non-discriminatory, and cleared with the Commission before changes.
So Google cannot revoke a TCA's certification of an assistant directly. It can, however, revoke the TCA itself. That's the lever that remains.
The certification bar is capped. Google can test whether an assistant reconfirms user intent before sensitive or irreversible actions, whether it minimises data leakage, whether it clears basic mobile security standards, and whether it's hardened against agentic manipulation. Anything beyond that requires Commission approval first. The same bar applies to Gemini.
Suspension is narrow. Google needs consistent evidence of serious and immediate harm, must hand it to the Commission and certification authorities, and must answer appeals within a month. There's also a user bypass: under paragraph 135, users can opt out of the certification requirement per service, per device, without the option being buried in developer settings.
Draft programme terms are due February 2027. Applications open May 2027.
What this means if you build Android apps
From August 2027, a certified AI assistant (or one the user has manually approved) can open your app on a virtual display, read its UI, and interact with it autonomously while the user is doing something else. That's not hypothetical. The feature list explicitly includes the ability to block sensitive views from the controlling assistant, and if you want that protection, you need to wire it into your app before the Android 18 beta lands.
Two further protections are permitted but not required: Google may build tools to let developers block automation on parts of their apps, or keep context away from proactive-suggestion components. It does not have to. Whether those controls exist at all is Google's call.
The Search data deal
The second decision requires Google to share anonymised Search query, click, and ranking data with rival search engines and AI products that do search, for a cost-based fee.
Anonymisation runs three passes. First, strip direct identifiers: usernames, IPs, precise timestamps, input format. Second, suppress records containing rare terms like full names, passwords, addresses, or account numbers, or unusually long queries. Third, generalise metadata until every user falls into a group of at least 1,000 people sharing location, device type, and query language, with 95% sitting in groups of 29,000 or more.
Contractual conditions cover the rest: ringfenced processing, no linking to external datasets, no re-identification attempts, independent audits before and annually after access.
To qualify, recipients need 50,000 monthly average EU users over the past year, cannot be under sanction, and cannot be controlled by a country the EU considers a serious cybersecurity or data protection risk. Data arrives at least seven days stale and stops flowing after five years per recipient. Google also retains the right to assess individual recipients for cyber and data protection risks before handing anything over.
Timeline: eligibility form and beneficiary webpage by end of August, completed dataset by November, pricing by January 2027.
Google's objections, and what they're actually worth
Kent Walker, Google's president of global affairs, argues the Android decision creates security risks by granting external apps powerful device permissions, and that it strips out the vetting that phone manufacturers currently provide. On Search, his position is that the anonymisation is insufficient, users haven't been asked, and that trade secrets and national security could be compromised. He cited ENISA, the EU's cybersecurity agency.
That ENISA paper, for the record, is about frontier AI models accelerating the gap between vulnerability discovery and exploitation. It doesn't mention Android, interoperability, or app permissions. Walker used it anyway.
The security concern is not entirely fabricated, though. Gemini is the test case. The same digital-context access the Commission is mandating for third-party assistants (notifications, SMS, screen contents) is the attack surface SafeBreach used to compromise Gemini's Android Utilities agent via indirect prompt injection, no malicious app needed. Google patched it server-side in November 2025, before SafeBreach published the research. Input manipulation is now one of the things candidate assistants have to demonstrate hardening against. Google writes that test.
What changed between April and now
The safeguards Walker is pointing to as missing are the ones that weren't in the April draft. The Commission's original proposal had no restricted features, no certification programme, and no certification authorities. Draft paragraph 134 actually barred Google from restricting who could benefit at all, and only permitted a verification process run by neutral third parties via the Play Store.
The final version lets Google certify applicants itself. The integrity clauses were tightened in other ways but loosened in others. The Search draft had no user threshold, no country-risk exclusion, and a metadata floor of 50 rather than 1,000. The deadlines moved: most Android features were due January 2027 in the draft, now August 2027. Concurrent hotwords slipped by over a year.
Google spent the spring arguing against unrestricted third-party access, and won a certification regime that didn't exist in April. That's a genuine concession from the Commission.
What Google didn't win is discretion. Any integrity measure must be strictly necessary, backed by objective evidence Google must retain, verifiable by parties other than Google, and applied identically to Gemini. It cannot hold third parties to a higher standard than it holds itself. It owes the Commission four weeks' notice before applying any new measure, unless the change is purely technical, non-user-facing, identical for all parties, and harmless to third parties. All four conditions, simultaneously, or give notice.
The next real deadline is 1 February 2027, when draft programme terms go public. Google spent months arguing for a certification gate, and got one. Now it has to write down exactly what the bar is, in public, knowing that whatever it puts in the document gets read straight back against how Gemini is treated.