For a decade of antitrust fights, the thing regulators tried to pry out of Google's grip was the browser, the search box, the default. On July 16, Brussels went after the assistant. In two binding specification decisions under the Digital Markets Act, the European Commission ordered Google to hand rival AI assistants the same deep hooks into Android that Gemini enjoys — wake-word activation, screen reading, the ability to act inside other apps — and to sell competitors, explicitly including AI chatbots, the anonymised search data underwriting its dominance since the early 2000s.
It is the first time a major regulator has treated the AI assistant layer as a distribution chokepoint requiring mandated access. The assistant, not the browser, is now the thing being unbundled.
What the Commission actually ordered
The Android decision (case DMA.100220, Article 6(7) DMA) names eleven features Google must open to third-party AI services, across four categories: invocation, context, actions on apps and the OS, and access to resources. In practice a rival assistant must be able to be summoned by a long-press of the home button or a developer-defined hotword equivalent to "Hey Google"; read on-device app data through the centralised channel Google's own services use via AppSearch; tap ambient sensor streams from microphone, camera and screen; drive multi-step tasks inside other apps through Android's Computer Control screen-automation stack, today reserved for Gemini; and call system-level on-device models including Gemini Nano on equal performance terms. Structured integration extends to eight Google apps — Gmail, Calendar, Drive, Docs, Maps, YouTube, Messages and Phone. Access must be free, ecosystem-wide, and not conditioned on holding a default role.
The access is not unconditional. Five of the eleven — screen automation, structured on-device integration, system integration, centralised on-device app data, and context-aware intelligence — sit behind an eligibility program Google must publish in draft by 1 February 2027 and finalise by 1 May 2027, with certification decisions due within four weeks and independent third parties assessing alongside Google. Users must explicitly consent per feature, per assistant.
The search-data decision (case DMA.100209, Article 6(11)) is the quieter half and arguably the more consequential. Google must share anonymised ranking, query, click and view data — queries, query metadata, URLs viewed, interactions with results, result positions — with eligible search engines and, for the first time, AI chatbots with search functionality. The Commission was blunt about why it intervened: Alphabet's original compliance offer was "removing between 90 and 100% of unique search queries from the dataset" and excluded AI chatbots entirely, so "there has been no meaningful uptake by potential beneficiaries."
The Commission's case, and Google's
"With today's measures, we want to support innovation and diversity in the European Union, enabling fair competition in the markets of AI assistant for Android devices and search engines," said Henna Virkkunen, the Commission's Executive Vice-President for Tech Sovereignty, Security and Democracy. The reasoning rests on scale: roughly 60% of European mobile users are on Android, and Google Search has held more than 90% share in Europe for decades.
Google's response came within hours, from Kent Walker, President of Global Affairs at Google and Alphabet. The decisions "risk undermining vital privacy and security guardrails for millions of Europeans," Walker wrote, arguing that "this Android ruling threatens device security by granting external apps sensitive and powerful device permissions" without the vetting phone makers perform, and warning that "Europeans' private searches would be exposed to unfamiliar companies, without adequate anonymisation of the data and without user knowledge or consent."
The Commission anticipated that. Anonymisation runs through three technical steps — stripping direct identifiers and timestamps, suppressing rare or unusually long queries, and generalising metadata to a k-anonymity threshold of at least 1,000 users per group, with 95% of users in groups of 29,000 or more — plus ringfencing, a ban on re-identification, and independent audits before access and annually thereafter.
Analysis: price, gate, and clock
The telling design choice is that Brussels did not mandate free access. Search data is priced on a FRAND formula pegged to Google's incremental costs plus a return capped at Alphabet's weighted average cost of capital, with an extra margin allowed only against very-large-scale beneficiaries, never SMEs. Eligibility requires a genuine EEA search business: two years of operation, or under two with more than EUR 50 million raised, plus 50,000 monthly EU users. Access runs five years maximum per beneficiary, at seven-day minimum latency.
Priced, gated, audited, time-limited — the Commission is conceding that raw access to a search corpus is not a public good. The pinch point is therefore administrative rather than legal. As Rob Bratby, managing partner at Bratby Law, put it, "the harder operational question is rarely the substantive standard... but the independent audit and eligibility-vetting process a gatekeeper controls and can use to slow access even where the rules are settled." Google runs both the Android certification gate and the search-data eligibility review.
The calendar is also slower than the headlines suggest. The Android measures land with Android 18 and by 1 August 2027 at the latest, not July, and concurrent hotword detection — letting a user run different assistants for different voice tasks — slips to Android 19 and 1 August 2028. On the search side, the 2026 milestones are procedural; Alphabet must finalise its pricing offer by January 2027, which is when access becomes real rather than theoretical.
What to watch
First, whether Alphabet appeals to the General Court: it has objected loudly on its blog but had confirmed no challenge as of publication. Second, the 1 February 2027 draft certification terms — the first concrete read on whether the eligibility program is a safety mechanism or a moat. Third, whether the logic travels. Apple is already in a parallel standoff with Brussels over Siri, and the Commission has now written the template for what "open your assistant" means in operational detail. If the eleven features survive appeal, they become the de facto specification for every gatekeeper assistant in Europe.
“Today's decisions risk undermining vital privacy and security guardrails for millions of Europeans.”— Kent Walker, President of Global Affairs, Google and Alphabet