AIBRIEF

EU Orders Google to Open Android AI Features and Search Data to Rivals Under the DMA

E
EffectStory 編輯部Editorial Team
Published · Updated
According to The Verge and iThome, the European Commission issued two legally binding decisions under the DMA on July 16, ordering Google to open Android AI-assistant features and search data to competitors by January and July 2027, or face fines of up to 10% of global turnover. Google says the mandates risk user privacy and security.

What kind of decision did the EU issue under the DMA?

The European Commission handed down two decisions on Thursday, July 16, 2026, under the Digital Markets Act (DMA), targeting Google's Android operating system and Google Search. According to The Verge, the two decisions "could weaken Google's control over two of the tech industry's most important platforms and have far-reaching consequences for the company."

iThome reports the same two measures as "legally binding implementing regulations" (實施規範) requiring Google to open up AI interoperability features on Android and share anonymized search data with qualifying third-party search services, aimed at promoting fair competition in the AI-assistant and search markets.

Importantly, iThome notes these regulations are primarily a clarification of how Google must fulfill its existing DMA obligations — they do not constitute a finding that Google has already violated the DMA, and therefore do not carry fines at this stage.

How must Google open Android to rival AI assistants?

Per The Verge, the Android decision "sets out how Google must give rival AI assistants the same kind of system features and data access as it gives Gemini." As a result, Android users could eventually choose ChatGPT, Claude, Perplexity, or other assistants as deeply integrated system assistants instead of Gemini, with comparable access to device capabilities.

iThome adds operational detail: Google must let third-party AI assistants access Android features on equal footing with Gemini. Users will be able to invoke a preferred AI assistant through a voice command similar to "Hey Google," and have that assistant perform cross-app tasks such as booking a taxi, suggesting replies to chat messages, or answering questions about recently visited locations. EU users are expected to benefit from these changes starting in July 2027.

What must Google open up in search data?

The second decision focuses on Google Search and the data it generates. The Verge reports it "sets out how competing search engines and AI services can gain access to information historically kept by Google," and notably, the EU said this includes AI chatbots, which effectively function as search engines in some cases.

iThome specifies that Google must, starting in January 2027, share anonymized search data with qualifying third-party search service providers; AI chatbots with search functionality may also apply for access. In principle, Google must provide the same category of data it uses to optimize Google Search itself.

What privacy and security concerns has Google raised?

Google has pushed back against both measures. The Verge quotes the company arguing the requirements "pose an unacceptable risk to user privacy and security, as well as compromise its products." Google global affairs president Kent Walker said: "Today's decisions risk undermining vital privacy and security guardrails for millions of Europeans. We have repeatedly offered solutions to safeguard users while satisfying the DMA's goals, but these rulings discount extensive evidence of user harm."

iThome reports Walker separately warned that giving third-party AI assistants greater Android permissions could weaken existing device security mechanisms, since phone makers currently play an important role in vetting such AI services; external apps gaining sensitive system permissions without equivalent safeguards would raise security risk. On the search-data side, Google is concerned that users' private search content could flow to third parties with insufficient anonymization and without the user's knowledge or consent, potentially endangering personal privacy, trade secrets, or even national security.

How does the EU say it will prevent misuse of the opened data?

The Verge reports the EU said there will be limits on how search data can be used, and that Google will be able to vet which services get deeper access to Android "to ensure safety and security aren't compromised."

European Commission executive vice president for tech sovereignty, security, and democracy Henna Virkkunen framed the goal in policy terms: "With today's measures, we want to support innovation and diversity in the European Union, enabling fair competition in the markets of AI assistant for Android devices and search engines."

What are the deadlines and penalties for non-compliance?

ItemDetailSource
Decisions issued2, on July 16, 2026 (Thursday)The Verge
Search data sharing beginsJanuary 2027The Verge / iThome
Android changes implementedJuly 2027The Verge / iThome
Maximum fine for non-complianceUp to 10% of annual worldwide turnoverThe Verge

The Verge reports Google "has until January 2027 to begin sharing search data and July 2027 to implement changes to Android." If Google does not comply, the European Commission could impose fines of up to 10 percent of its annual worldwide turnover — potentially, per The Verge, "tens of billions of dollars."

What precedent has the DMA set for the tech industry?

Google is not the only company to resist DMA-driven interoperability mandates. The Verge notes that Apple declined to release Siri AI in Europe, "explicitly blaming the DMA and arguing its interoperability requirements compromise user safety."

What this means

The two deadlines sit six months apart — search data sharing must start in January 2027, Android changes by July 2027 — giving Google a staged compliance window rather than an immediate mandate (The Verge). Yet the EU's own framing, that this is a clarification of obligations rather than a violation finding with no fines attached at this stage (iThome), sits in tension with Google's repeated warnings, voiced by Kent Walker, that the same measures "risk undermining vital privacy and security guardrails for millions of Europeans" (The Verge) and could weaken device security or leak private search content (iThome). The EU's countermeasures — limits on data use and letting Google vet which services get deeper Android access (The Verge) — are presented as addressing exactly the risks Google cites, though whether they satisfy Google's objections remains contested by the company. Apple's earlier decision to withhold Siri AI from Europe over the same DMA interoperability requirements (The Verge) shows this friction between the EU's competition mandate and vendors' security claims predates Google's case.

📊 Evidence

FAQ

Is this EU decision itself a fine or penalty against Google?

No. According to iThome, the implementing regulations clarify how Google must fulfill its DMA obligations; they are not a finding that Google has violated the DMA, so no fines are involved at this stage.

When will EU Android users actually see the new AI assistant options?

According to iThome, EU users are expected to benefit from the Android changes starting in July 2027, when Google must complete implementation.

📎 Sources

  1. theverge.com
  2. ithome.com.tw
E
EffectStory 編輯部Editorial Team

Related

BRIEF

TSMC Adds $100B to Arizona Buildout as AI Chip Demand Signals Multi-Year Cycle

According to reports by CNA, CTEE and UDN, TSMC (台積電) will add $100 billion to its Arizona investment, lifting the total to $265 billion, while raising 2026 capex to $60–64 billion. CFO Wendell Huang (黃仁昭) called AI chip demand a multi-year structural trend, though a TSMC executive flagged local construction-worker shortages as a challenge.

EffectStory 編輯部 ·
BRIEF

Hugging Face Confirms Autonomous AI Agent Breached Production Systems, Stole Credentials and Moved Laterally Across Clusters

According to TechNews, Hugging Face confirmed its production environment was breached by an AI agent-led attack that stole internal datasets and credentials via two abused code-execution paths, leaving over 17,000 event log entries. iThome reports the agent escalated to cluster-level access and moved laterally into multiple internal clusters within a single weekend. Hugging Face says it found no evidence of tampering with models, datasets, or its software supply chain.

EffectStory 編輯部 ·