The European Commission issued two binding decisions under the Digital Markets Act requiring Google to expand interoperability on Android and provide certain Google Search data to qualifying rivals. Under the Android ruling, third-party AI assistants must be allowed access to capabilities that Google Gemini already uses, including microphone, camera, screen interaction, ambient sensor data, hotword activation, background execution, and app-driving automation, with most changes tied to Android 18 and a broader compliance deadline of 1 August 2027. For a smaller set of more sensitive functions, Google may require certification through a Qualified AI Assistant Programme, but the Commission limited Google’s discretion and required equal treatment with Gemini.
A second ruling compels Google to share anonymized search query, click, and ranking data with eligible rival search engines and AI chatbots that perform search, with rollout beginning in 2027 under contractual, audit, and independent review safeguards. Google said the measures could weaken privacy and security protections, expose sensitive search histories and trade secrets, and create broader national security risks, while the Commission said the final terms include tighter safeguards than earlier drafts. Google is expected to appeal the decisions.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
Google publicly opposed the Commission's rulings, arguing they could weaken privacy and security protections for European users and expose sensitive search histories, trade secrets, and other security-sensitive information. The company is expected to appeal the decisions.
The European Commission adopted two legally binding specification decisions under the Digital Markets Act requiring Google to expand Android interoperability for rival AI assistants and to share certain anonymised Google Search data with qualifying rivals. The measures include access to capabilities Gemini already uses on Android, while adding certification and safeguard provisions for more sensitive features.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcetechrepublic.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.