EU Mandates Google Open Android Features: Access for Rival AI Assistants by 2027

5

EU Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants

The European Commission on July 16 ordered Google to grant rival AI assistants the same access to Android's microphone, camera, screen and wake-word detection that its own Gemini assistant already enjoys — with a hard deadline of August 1, 2027.

The ruling marks one of the most sweeping interventions yet under the Digital Markets Act (DMA), arriving at a moment when AI assistants are rapidly becoming the dominant interface between users and their devices. With Android powering roughly 60% of European mobile users, the decision carries enormous commercial weight for every company competing in the AI assistant space.


What the EU Is Actually Requiring

The Commission adopted two binding specification decisions on July 16, six months after opening proceedings on January 27. Neither decision is a fine. Specification proceedings define what a gatekeeper must build; separate non-compliance proceedings — which can include fines — remain available to the Commission if Google fails to deliver.

The Android Decision: Two Tiers of Access

The first decision targets Android directly. It covers 11 operating system features split into two tiers.

Six features carry no certification requirement and must be opened to all third-party apps, including user-installed ones:

  • Ambient data — continuous microphone input, system audio, camera feed, screen contents, location and sensor data such as the accelerometer
  • Always-on hotword detection — running on the low-power DSP so it survives a locked screen and battery saver mode
  • Long-press invocation
  • System-level on-device models
  • Third-party model implementation
  • Background execution

The remaining five features — including screen automation, structured on-device integration with Google's own apps, and context-aware intelligence — fall under a new Qualified AI Assistant Programme that Google must create. Third-party Trusted Certification Authorities (TCAs) will certify assistants into the programme free of charge. Google accepts those certifications without adding conditions and cannot revoke them. It can revoke a TCA's approved status, but only on reasonable and non-discriminatory terms cleared with the Commission two months in advance.

The certification bar is deliberately capped. Google may only test whether an assistant reconfirms user intent before sensitive or irreversible actions, meets baseline mobile security standards and is hardened against agentic risks. Anything beyond those criteria requires Commission approval first — and the same standards apply to Gemini.

The Search Data Decision

The second decision requires Google to share anonymised Search query, click and ranking data with rival search engines and AI chatbots that perform search functions, for a cost-based fee. The anonymisation process runs three passes: stripping direct identifiers, suppressing records containing rare or sensitive terms and generalising metadata until every user sits within a group of at least 1,000 people sharing location, device type and query language. The data arrives at least seven days stale and access expires after five years per recipient.

This is a significant structural concession. Search data is the foundation on which AI assistants train their relevance models, and restricting access to it has long been cited as one of the core barriers to meaningful competition. For businesses tracking how AI is reshaping customer-facing services, the downstream implications of more capable rival assistants entering the European market are worth monitoring closely.


Google's Objection and the Security Debate

Kent Walker, Google's president of global affairs, said the Android decision "threatens device security by granting external apps sensitive and powerful device permissions." He argued that phone manufacturers currently vet assistants and that the ruling strips that safeguard away. On the Search decision, Walker contended that the anonymisation standard is insufficient and that the data handover raises trade-secret and national-security concerns.

Walker cited ENISA, the EU's cybersecurity agency, which wrote this month that "security fundamentals matter more than ever in the age of AI." However, that ENISA paper focuses on frontier AI models collapsing the window between vulnerability discovery and exploitation. It does not address Android interoperability or app permissions.

The Security Concern Is Not Theoretical

The security concern is not entirely without foundation. Gemini itself offers a cautionary data point. The decision hands third-party assistants access to notifications, SMS and screen contents — the same channel that cybersecurity firm SafeBreach used in a demonstrated indirect prompt injection attack against Gemini's Android Utilities agent. No malicious app on the device was required. Google mitigated that attack server-side in November 2025 before SafeBreach published its findings. Resistance to input attacks is now one of the criteria a candidate assistant must satisfy to earn certification.

This tension between openness and security sits at the heart of the broader debate around AI deployment in commercial environments. Organisations weighing this balance will find it useful to understand the risks and challenges of artificial intelligence in business before committing to any assistant integration strategy.

What Google Did Not Receive

What Walker did not receive was discretion. The final measures require that any integrity condition Google imposes must be:

  • Strictly necessary
  • Backed by objective evidence Google must retain
  • Verifiable by an independent party
  • Applied identically to Google's own services

Google must give the Commission four weeks' notice before applying any new condition. The effect is to transform Google from arbiter of access into a regulated infrastructure provider — a shift with long-term implications for how the Android ecosystem is governed.


Key Dates, Developer Impact and What Comes Next

The Implementation Timeline

The timeline runs tight. Google must open the six uncertified features and ship draft programme terms for the certified tier by February 1, 2027. Final terms and open applications follow on May 1, 2027. The full Android decision takes effect August 1, 2027, aligned with Android 18. Concurrent hotword detection — allowing multiple assistants to listen simultaneously — slips to Android 19 and August 1, 2028.

On Search data, Google must publish an eligibility form and beneficiary webpage by the end of August 2026, deliver a finished dataset by November 2026 and publish pricing by January 2027.

What This Means for Developers

For developers building Android apps, the practical implication is immediate: by August 2027, a certified assistant can open an app on a virtual display, read its screen and execute actions within it while the user multitasks elsewhere. Developers should evaluate how their apps handle sensitive views before Android 18 enters beta.

This is particularly relevant given the ongoing debate around Android versus competing mobile platforms — a ruling of this scope reinforces Android's regulatory exposure in Europe while simultaneously opening it as a more competitive development environment for third-party AI builders.

The Fight Moves to February 2027

The contest now shifts to February 2027, when Google must publish its draft certification programme terms. Having spent the spring arguing that uncertified assistants should not hold these permissions — and winning a certification regime that did not exist in the April draft — Google must now write those rules in public, knowing they will be read back and applied to Gemini.

For businesses operating in Europe, the ruling signals that AI assistant interoperability is now a regulatory baseline, not a competitive courtesy — and that compliance timelines are measured in months, not years.

For a broader understanding of how the DMA is reshaping digital markets across the EU, the European Commission's Digital Markets Act overview provides authoritative detail on the enforcement framework underpinning decisions like this one.

You might also like