# EU Forces Google to Share Android's AI Gateway with Rivals—A Landmark Interoperability Mandate


The European Commission has issued one of its most consequential digital regulation orders yet: Google must grant competing AI assistants the same unfettered access to Android's hardware sensors and system functions that its own Gemini assistant enjoys. The decision, announced Thursday under the Digital Markets Act, requires Google to ship these capabilities in Android 18 by August 1, 2027, fundamentally reshaping how AI assistants interact with mobile devices across Europe's 60% Android market.


The mandate also forces Google to share anonymized search query data and ranking information with competing search engines and AI chatbots—a second binding specification that exposes the depths of Google's control over European digital infrastructure and the Commission's willingness to dismantle it.


## The Ruling: 11 Features, Two Tiers of Access


The Commission's decision covers 11 core Android operating system features, divided into two categories based on how strictly Google can control access.


### Restricted Features (Certification Required)

Five features remain behind a certification gate, requiring Google to establish a Qualified AI Assistant Programme where third-party Trusted Certification Authorities (TCAs) can verify that competing assistants meet baseline security and privacy standards:


  • Centralized on-device data access (AppSearch) – today's repository of apps that have opted into data sharing
  • Context-aware intelligence – the proactive suggestion machinery (Magic Cue)
  • Structured on-device integration – App Actions and App Functions
  • Screen automation – Computer Control, which allows assistants to automate taps and typing to drive other apps
  • System integration – settings, media, screenshots, notifications, power controls

  • The third restriction cuts directly at Google's app ecosystem: certified assistants gain the ability to retrieve and draft Gmail, create and manage Calendar events, pull Drive and Docs content, trigger Maps navigation, control YouTube playback, access SMS/MMS/RCS in Messages, and place phone calls—all the high-value integrations that make Gemini sticky.


    ### Unrestricted Features (No Gatekeeping Allowed)

    The remaining six features face zero certification requirements, and Google is explicitly barred from restricting which apps can access them:


  • Ambient data – continuous microphone input, system audio, camera feed, screen contents, location, and sensor data (accelerometer, etc.)
  • Always-on hotword detection – wake words that survive locked screens and battery saver mode
  • Long-press invocation – direct hardware button triggers
  • System-level on-device models – local AI inference without cloud connectivity
  • Third-party model implementation – the ability to run competing LLMs locally
  • Background execution – persistent operation without user awareness

  • This second tier is the regulatory sledgehammer. Any app—including user-installed third-party assistants—can now request continuous access to your microphone, camera, and screen contents under the same minimal consent prompts that Google's own services currently use. The Commission explicitly notes that Google today reaches these sensors with "reduced consent processes and privacy indicators" for its own services, while third parties faced higher friction. That friction is now gone.


    ## Background: The Digital Markets Act Comes Alive


    This decision marks the first major enforcement action under the Digital Markets Act, the EU's 2022 legislation designating certain tech companies as "gatekeepers" whose platforms are so critical to digital commerce that they must be forcibly opened to rivals.


    Google was formally designated a gatekeeper in September 2023. The Commission opened proceedings against Google on January 27, 2026, and has now, six months later, issued binding specifications—regulatory blueprints for what Google must build. Critically, these are not fines. They are instructions. The Commission retains separate power to open non-compliance cases and impose penalties if Google drags its feet or attempts circumvention.


    The timing is significant: AI assistants have rapidly become the primary interface between users and digital services. By locking these capabilities behind Gemini-exclusive access, Google was replicating its search dominance in a new layer. The EU saw the risk and moved preemptively.


    ## What Google Must Actually Build


    Google is required to:


    1. Establish a Qualified AI Assistant Programme – define reasonable, non-discriminatory terms; approve Trusted Certification Authorities; accept their certifications without adding extra conditions; and commit never to revoke certifications arbitrarily.


    2. Ship in Android 18 by August 1, 2027 – a hard deadline that allows little room for delay or watering down.


    3. Handle six unrestricted features with zero friction – ambient data, hotword detection, and background execution must be available to any app that requests them, subject only to runtime consent.


    4. Process isolation and encryption are still permitted – Google can require that third-party assistants run in isolated sandboxes and encrypt their data, but it cannot use these as pretexts to deny access entirely.


    5. Share search data – provide anonymized search queries, clicks, and ranking data to rival search engines and AI chatbots at a "cost-based fee."


    There is one escape hatch: Google can file a "reasoned request" with the Commission arguing that a feature should be moved to the restricted list if there is "good cause." The Commission may agree. But the burden of proof is now on Google, not the EU.


    ## Implications for Developers, Users, and Privacy


    For AI Startups and Competitors: This is a watershed moment. OpenAI, Anthropic, Mistral, and dozens of smaller AI labs now have a legal right to build AI assistants that are first-class citizens on Android—with the same sensor access, system hooks, and app integration capabilities as Gemini. The certification requirement for five restricted features is designed to be a security checkpoint, not a moat.


    For Android OEMs: Device manufacturers like Samsung and Xiaomi gain leverage. They are no longer forced to promote Google's assistant exclusively and can now bundle or default competing assistants with full capability parity.


    For Privacy and Security: The unrestricted features—particularly continuous microphone and camera access—raise significant concerns. The Commission's note that Google currently uses "reduced consent processes" for its own services is a tacit acknowledgment that expanding this to third-party apps represents a privacy regression. The counter-argument is that users will benefit from real choice and can select assistants with privacy-first designs. The devil will be in the implementation details: Android 18's consent UI, how easy it is to revoke access, and whether multiple always-on assistants can meaningfully coexist without degrading battery life and security.


    For Google's Business Model: Gemini's integration depth was a competitive moat. Forcing parity erodes that advantage. However, Google retains control over the restricted features' certification process and can still prioritize Gemini in its own UI and defaults.


    ## Recommendations for Organizations


  • Cloud AI and SaaS providers should begin planning for Android 18 compatibility, particularly if they offer voice or visual AI services.
  • Device manufacturers should review their assistant strategies; OEM differentiation may now lie in UI/UX integration rather than exclusive backend access.
  • Privacy teams should monitor Google's Android 18 beta and the consent implementation details closely, as continuous sensor access from multiple third-party apps introduces novel risks.
  • Security researchers should prepare adversarial analysis of the Qualified AI Assistant Programme—how easy is it to subvert certification, and what does "reasonable and non-discriminatory" actually mean in practice?

  • ---


    ## HackWire Analysis


    This decision exposes a paradox at the heart of digital regulation. The EU is correct that Google's exclusive control over Android's AI gateway represents a dangerous concentration of power—Gemini's privileged access to your microphone, camera, and app automation is a form of gatekeeping that stifles competition. Forcing parity is the logical remedy.


    But the Commission's remedy also reveals the limits of interoperability mandates when applied to security-sensitive hardware. Ambient data—continuous microphone and camera feeds—is not like email inboxes or search indexes. It is raw sensor input from a device physically present in your home and pocket. The more assistants that listen simultaneously, the larger the attack surface. A poorly secured third-party assistant with always-on microphone access is not a minor privacy inconvenience; it is a potential surveillance vulnerability.


    The Commission's solution—rely on runtime consent and let certification authorities sort out security—works only if consent prompts are genuinely meaningful and certification is not a rubber stamp. History suggests both assumptions are optimistic. Users habitually grant permissions without reading them; certifiers under commercial pressure can be captured; and security vulnerabilities surface in production, not at approval time.


    The deeper pattern: Europe is using regulatory force to undo winner-take-all dynamics in AI, much as it did with search, messaging, and app distribution. This is ideologically coherent—the EU sees gatekeeping as inherently bad and interoperability as inherently good. But in AI specifically, where assistants require deep system integration and real-time sensor access to be useful, the interoperability-first approach creates novel risks. A better route might have been to require *choice*—let users pick their default assistant and grant it full parity—rather than mandating that all assistants can listen all the time.


    That said, the decision is here, it is binding, and it will reshape the Android ecosystem. The risk for Google is not fines (none are imposed here) but implementation difficulty: building a certification framework, opening sensor APIs, and managing security audits for dozens of third-party assistants is a grinding operational burden. The risk for users is fragmentation: Android 18 may ship with better AI choice but worse privacy defaults.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Policy](https://www.hackwire.news/category/policy) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)