The European Commission has opened a new front in its regulation of Big Tech, this time targeting the control Google and Apple hold over artificial intelligence assistants on their smartphones — and both companies are pushing back hard, citing privacy and security concerns that regulators are treating with considerable scepticism.
The commission is demanding that Google give rival AI agents broader access to Android by July 2027, as part of enforcement of the Digital Markets Act — the EU’s sweeping Big Tech regulation framework that came into force in 2023. The mandate would allow EU users to access third-party AI assistants via voice commands and use them to operate apps on their behalf, just as they currently can with Google’s Gemini. The commission also wants Google to share search data with rival search engines and AI chatbots, a requirement that takes effect in January.
Apple’s response has been even more drastic. In June, the company announced it would not launch its new Siri AI assistant in the EU at all, citing the DMA’s requirements as incompatible with its approach. Apple says the EU’s rules would force it to give any virtual assistant “direct access to users’ private data” — a standard it says it cannot accept. The company says it proposed alternative solutions that were rejected and continues to engage with regulators.
Together, Apple and Google control approximately five billion active iPhones and Android devices worldwide, according to market research firm Omdia. Around 427 million of those fall under EU jurisdiction.
What the EU Actually Wants
The commission’s position is that Google and Apple’s dominance over smartphone operating systems gives their own AI assistants a structural advantage that DMA-compliant competitors cannot overcome through competition alone. By requiring Google to open Android’s deepest permissions to external AI agents — access to device screens, microphones, messages, and app control — the EU is trying to create conditions where a product like OpenAI’s ChatGPT can compete with Gemini on equal technical footing.
ChatGPT is already installed on approximately 30% of EU smartphones, according to Omdia analyst Runar Bjorhovde. The EU’s rules could extend that foothold significantly. “The question is what the implications for Google or the consumer might be if the user can utilize ChatGPT to book an Uber, completely bypassing the need to engage with Android,” Bjorhovde said.
ALSO READ: European Court Dismisses Google’s Appeal, Confirming €4.1 Billion Fine for Android Antitrust Abuse
What Google and Apple Are Saying — and What Critics Think
Google’s global affairs president Kent Walker said the Android changes would give external apps “sensitive and powerful device permissions,” posing a major security risk. He added that the search data sharing requirement would “weaken citizen privacy, risk business trade secrets and endanger national security.” Google’s Android president separately said the commission “is on the wrong track” and that users already have the ability to change their default AI assistant through Android’s settings.
Apple cited parallel concerns, saying EU rules would compromise the privacy architecture it has built into its operating system.
Independent experts broadly agree that deeper third-party access to smartphone operating systems does carry genuine privacy and security risks. But some question whether those concerns are the primary motivation for resistance from companies that have historically not prioritised user privacy above commercial interests.
“I would say that we have to take these tech companies’ arguments with a grain of salt and look at whether they’ve cared about privacy up to the point where suddenly a decision was affecting them in ways they don’t like,” said Calli Schroeder, senior counsel at the Electronic Privacy and Information Center.
The Real Privacy Risks — and Why They Matter Regardless
The technical risks Schroeder and other experts describe are not hypothetical. Giving AI agents access to a user’s location, messages, device screen, and microphone creates a surface area for misuse or malfunction that is qualitatively different from previous generations of app permissions. “It could exercise the user’s delegated authority to do other things that maybe the user might not have wanted it to happen,” said Michael Stokes, senior vice president of emerging technologies at Veilant.
Without protections built directly into the operating system software, external AI agents could potentially siphon information from a user’s device without their knowledge. If Google’s position prevails, it would be device manufacturers like Samsung making decisions about which external AI agents are granted those permissions — a layer of accountability the commission has not specifically addressed.
The commission’s response has been that DMA-designated gatekeepers “can implement appropriate privacy, security and integrity safeguards” — a position that implicitly acknowledges the risk while placing responsibility for managing it back on the companies themselves.
AI systems also raise broader data awareness issues that regulation has not yet fully addressed. Many AI models are trained by scraping large volumes of internet data that may include personal information without users’ explicit knowledge. “We also want to make sure that users are aware of the risks they’re taking when they engage with AI systems,” Schroeder said. “And I think that awareness is where we really need to catch up a little bit more.”
The July 2027 deadline for Android access gives Google roughly a year to comply — or to challenge the mandate further through legal and regulatory channels. Apple’s decision to simply not launch Siri AI features in the EU represents a different kind of resistance, one that leaves EU consumers without a product rather than opening the platform. Neither approach resolves the underlying question of how to structure AI access on mobile devices in a way that is genuinely competitive without becoming genuinely dangerous.
Stay informed. Subscribe to the JournalTodays Newsletter for the latest technology news, AI regulation coverage, and business updates delivered straight to your inbox.




