Brussels orders Google to share Android and Search with AI rivals, and Google's first move is to call it a privacy problem
On 16 July 2026 the European Commission ordered Google to give rival AI assistants and search engines direct access to Android hooks, with Google arguing the package puts user security at risk.

On 16 July 2026 the European Commission told Google to give rival AI assistants and search engines direct access to a defined set of Android functions. Brussels is now formally treating AI assistants as a class of services that must interoperate with the mobile operating system, not as guests that may be invited or refused at the gatekeeper's discretion.
The order is the next chapter in the long-running application of the bloc's Digital Markets Act to Alphabet's stack. It does not invent a fresh theory of harm. It accepts that incumbents with hundreds of millions of installed devices can deny a new generation of assistants the system-level plumbing they need to compete on equal terms, and tells the incumbent to stop.
Google's response landed within hours. The company argued that the package, as written, endangers user privacy and security. That framing will define the contest over the next months, and it deserves a careful read.
What the order actually covers
The Commission's decision forces Google to let rival AI assistants reach the camera, microphone, screen contents, locked-screen hotwords, and background app control on Android. It also forces Google to share additional search-related data with competing search providers.
In a research note posted on 16 July, Ars Technica confirmed that the order covers both search data and Android AI access, and flagged Google's privacy and security objections as the company's first line of defence. Coverage from The Verge on the same day, headlined "Google ordered to open Android and Search to rivals in Europe," matched the scope: rivals gain access to "key parts of Android and Google Search." The Hacker News, summarising the decision on 17 July, listed the same five Android surfaces and described the directive as a further DMA-style intervention against the platform incumbent.
In plain terms: an EU-resident user who has bought a phone running Android will in due course be able to replace the default assistant with a third-party one that can listen for its wake word on the lock screen, see what is on the display, open the camera and microphone under the user's control, and run in the background to handle tasks. The intervention is not theoretical. Phone manufacturers and carriers will have to configure those handoffs so they actually work for users, not just exist in a compliance manual.
Google's first line: privacy and security
Google's published position is that the package it has been given will compromise user privacy and security. The argument has two parts.
The first part is technical and worth taking seriously. If a rival assistant can listen for a hotword on the lock screen, can see screen contents, and can drive the camera and microphone in the background, the surface area for malicious or careless implementation expands. On Android today, sensitive inputs are mediated by permission systems and by Google's own pre-installed components. Rival assistants have so far lived behind those gates.
The second part is commercial. A "security risk" framing, if accepted by the Commission, slows implementation, narrows the scope of what must be opened, and conditions interoperability on technical audits that only a handful of approved vendors can pass quickly. That is a familiar playbook in platform regulation. The interesting question is how much room the DMA's text leaves for it.
The Verge's separate 16 July analysis ("Google is better at playing this game") argued that the order itself was unsurprising given the trajectory of EU enforcement, and that the harder question is execution. That is the right register. Brussels has won the doctrinal argument. The contest now moves into months of technical haggling over what counts as a "secure" handoff between an unfamiliar assistant and the deepest layers of the OS.
Why AI assistants, specifically
Until this year, the DMA fight with Google was framed mostly around the Chrome browser, the Play Store billing system, and self-preferencing in general search results. AI assistants enter the frame because they are doing what search did in the previous decade: becoming the front door through which users ask questions, transact, and choose what to read, watch, or buy.
For a Brussels regulator whose central concern is contestability of the gateway, that shift changes the calculation. If the assistant layer becomes the new chokepoint, then leaving it entirely under the incumbent's control recreates the very bottleneck the DMA was written to break. The order extends the same remedy that the Commission has already applied to browsers and app stores: any service classified as a core platform service can be required to interoperate with rivals on defined terms.
The user-visible effect, if implementation lands cleanly, is that an EU-resident iOS-style competition layer now exists on Android for AI in roughly the same way it already exists for browsers. The user chooses the default, the default behaves like a peer to the incumbent, and the operating system stops quietly favouring whichever assistant Alphabet prefers this quarter.
What stays contested
Three things remain genuinely unresolved on the public record available to this publication.
First, the timetable. The Commission has announced the substance; the exact implementation deadlines, the audit framework for "secure" handoffs, and the remedies if Google claims compliance is non-trivial, all sit in the negotiating space between the order and the eventual final text.
Second, the global template effect. Europe's regulatory reach ends at its borders, but Android is a global operating system. The Verge's analysis raised the prospect that Google might implement a Europe-only carve-out, with rival assistants enabled in EU member states and politely refused everywhere else, mirroring what the company has done with consent flows for ad targeting. That would satisfy the letter of the order while preserving the default in the rest of the world.
Third, the counter-narrative worth holding in mind. There is a defensible reading of the decision that says the Commission is overreaching: that AI assistants are still a young and fragile market, that the security concerns Google has raised are not pretextual, and that forcing the OS open before the threat model is fully understood could expose users to harm. The opposite reading is that incumbents always invoke security when asked to share, that the threat model for assistants is no worse than the threat model for browsers, and that Brussels has correctly identified that the next decade of gatekeeping will be done by assistants rather than search bars. Both readings rest on real evidence. The defining question is whether the technical implementation framework the Commission now writes keeps the door open to Google in good faith or hands it a veto dressed up as compliance.
This publication framed the order as the next logical step in the bloc's DMA-driven contestability project, with Google's privacy objection as the framing the company will lean on hardest in implementation. The Verge's 16 July analyses carried the strongest English-language read of the decision's scope.
Wire provenance
This editorial synthesis draws on the following public wire/social posts:
- https://t.me/thehackernews/1737
- https://t.me/theverge_news/