The European Commission opened specification proceedings to define how Google must meet Digital Markets Act (DMA) interoperability requirements for Android and data-access requirements for Google Search. The Android proceeding concerns whether third-party AI-service providers must receive access to the same hardware and software features used by Google's own services, including Gemini, under Article 6(7). A separate Article 6(11) proceeding examines fair, reasonable, and non-discriminatory access to anonymised Search ranking, query, click, and view data for rival search engines, including whether AI chatbot providers qualify. The Commission said the proceedings themselves did not establish non-compliance but could inform later enforcement, including fines or periodic penalty payments.
Google said the Commission's final Android AI interoperability measures would require deeper access for user-downloaded AI agents to sensitive capabilities such as ambient microphones, cameras, on-screen content, and screen automation. The company warned that fraud, social engineering, polymorphic malware, and indirect prompt injection could abuse such access to compromise user data, accounts, and devices. Google also opposed a Trusted Certification Authorities model that could allow third parties to certify restricted-feature access without Google or device manufacturers retaining final approval, suspension, and revocation authority, and called for cybersecurity-expert consultation and strong platform enforcement controls during implementation.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
The European Telecommunications Standards Institute released its Securing Artificial Intelligence baseline cybersecurity requirements for AI models and systems.
Google was required to fully comply with applicable DMA obligations for its designated core platform services.
The European Commission designated multiple Google services as core platform services under the Digital Markets Act, including Google Search, Android, Chrome, Play, Maps, YouTube, Shopping, and online advertising services.
The European Commission issued final DMA interoperability measures requiring Android to provide user-downloaded AI agents with deeper access to device capabilities, including provisions for qualification of some high-risk features and a Trusted Certification Authorities program.
The Commission opened two DMA specification proceedings to clarify Google's compliance obligations for Android interoperability under Article 6(7) and Google Search data access under Article 6(11). The proceedings do not themselves determine that Google is non-compliant.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.