E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants
13:44 · July 17, 2026 · Hacker News AI Section

The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has: the camera, the microphone, whatever is on screen, a wake word that fires with the display off, and the ability to drive other apps in the background by imitating taps and typing. Google has to ship it in the next major release, Android 18, and by 1 August 2027 at
Summary
The European Commission has adopted two binding specification decisions under the Digital Markets Act that directly affect Google’s Android and Search services. The first requires Google to open eleven operating-system features to rival AI assistants so they can reach the same device capabilities already available to Gemini. These include continuous access to microphone and camera streams, on-screen content, location and sensor data, always-on hotword detection on supported hardware, and background execution that can drive other applications through simulated input. Six of the features are available to any user-installed app once the user grants consent; the remaining five are designated restricted and require prior certification through a new Qualified AI Assistant Programme administered by independent trusted certification authorities.
Google must finalise the programme’s terms by February 2027 and open it for applications by May 2027, with the full set of capabilities required to ship in Android 18 no later than August 2027. Certification criteria are limited to demonstrable security practices, prompt-injection hardening, and reconfirmation of user intent for sensitive actions; the same standards apply to Gemini itself. Google may still impose process isolation and encryption, and it retains the ability to request that a feature be moved to the restricted list if it can show concrete risk, but it cannot unilaterally decide which developers may request access.
A second decision obliges Google to supply anonymised Search query, click and ranking data to qualifying rival search engines and AI services that perform search. The anonymisation pipeline removes direct identifiers, suppresses records containing rare or sensitive terms, and generalises metadata until each record belongs to a group of at least one thousand users. Recipients must meet minimum usage thresholds, pass independent audits, and accept contractual restrictions that prohibit re-identification or onward disclosure. Data is delivered at least seven days old and may be retained for up to five years.
The final measures incorporate several changes from the April draft, most notably the introduction of the certification regime and tighter eligibility rules for data recipients. Google has criticised both decisions, arguing that they weaken device security and expose trade secrets, yet the Commission has retained the power to open separate non-compliance proceedings if the obligations are not met.
Why it matters
Directly addresses EU-mandated changes to AI assistant permissions, privacy controls, and security certification that apply in the Netherlands, enabling Dutch security teams to prepare compliance and risk mitigation for Android AI deployments.










