AI Governance Institute
← News
Enforcement2026-07-22

EU Binding DMA Measures Force Google to Open Android AI Access and Share Search Data by July 2027, Reshaping Enterprise AI Procurement Risk

What happened

The European Commission has issued final binding specification measures under the Digital Markets Act requiring Google to open Android's system-level access to competing AI platforms on equivalent terms to those currently granted to Gemini, and to make search data available to rival search providers for a reasonable fee. Full details are reported in the Ars Technica account of the Commission's decision. The measures set two distinct compliance deadlines: search data sharing obligations take effect by January 2027, while Android AI interoperability must be in place by July 2027. Critically, the Commission has ruled that AI chatbots are to be treated as search services for data-sharing purposes, meaning the data-sharing and anonymization obligations extend to AI assistant products, not only to traditional search engines. A multilayered anonymization approach is mandated for all shared data, imposing specific technical and process requirements on any party accessing or receiving that data.

Why it matters

  • ·Enterprise procurement teams that have standardized on Gemini as the default AI assistant on managed Android device fleets must now assess an expanded field of competing AI assistants that will have equivalent system-level access - each representing a new third-party AI vendor that requires risk assessment, contract review, and shadow AI controls under frameworks such as the EU AI Act.
  • ·The Commission's classification of AI chatbots as search services for data-sharing purposes creates a precedent that regulators in other jurisdictions may follow, meaning that AI assistant products handling search-adjacent queries could face data access, sharing, and anonymization obligations beyond what current privacy and AI governance programs anticipate.
  • ·Enterprises building AI products that consume Google search data, or that operate AI assistants in EU markets, face direct operational obligations: they must evaluate whether their data intake processes, anonymization controls, and vendor agreements are compatible with the multilayered anonymization standard and the January 2027 data-sharing deadline.

Governance controls affected

What to do now

  • Audit all managed Android device policies to identify where Gemini is currently deployed as a default AI assistant, and map the governance implications of new competing AI assistants gaining equivalent system-level access after July 2027.
  • Update third-party AI vendor due diligence templates to include questions about DMA compliance status, multilayered anonymization capabilities, and data-sharing obligations for any AI assistant or search-adjacent AI product operating in the EU.
  • Review vendor contracts for AI products that ingest Google search data or operate as AI assistants in EU markets, and identify whether data processing agreements reflect the Commission's anonymization requirements ahead of the January 2027 deadline.
  • Assess shadow AI risk exposure by inventorying which AI assistants employees may begin adopting on Android as interoperability opens the platform, and extend acceptable use policy enforcement to cover newly accessible assistants.
  • Brief legal and compliance leadership on the Commission's classification of AI chatbots as search services, and evaluate whether that classification affects regulatory obligations for any AI assistant products the organization deploys or procures.

What to watch next

Compliance teams should monitor whether the Commission issues further technical specifications on the multilayered anonymization standard ahead of the January 2027 data-sharing deadline, as the technical detail of that standard will directly affect data governance program updates. Google's formal response and any appeal proceedings could shift the implementation timeline, so tracking enforcement milestones through the first half of 2027 is warranted. Teams should also watch for other jurisdictions - particularly the UK and US - citing the Commission's chatbot-as-search-service classification as a basis for extending data-sharing or interoperability obligations to AI assistant products under their own regulatory frameworks, which would materially expand the multi-jurisdiction compliance mapping work required under [CMP-001].

Stay ahead of stories like this

Get every EU AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Corporate Policy2026-08-29

OpenAI's Zero Data Retention Option Shifts Audit Log Burden to Enterprise

OpenAI has introduced a zero data retention option for eligible API customers using frontier models, under which prompts and model responses are not stored after processing. The offering resolves a data minimization concern but transfers responsibility for audit-trail capture entirely to the enterprise customer. Regulated organizations must now ensure their own logging infrastructure compensates for the absence of vendor-side retention.

Enforcement2026-08-27

Grok CSAM Lawsuit Sets a Training Data Provenance Liability Benchmark

A federal lawsuit filed by a child sex abuse material survivor alleges that xAI trained its Grok models on CSAM identified via hash lists maintained by NCMEC and the Canadian Centre for Child Protection. The complaint also alleges that xAI's terms of service create a training pipeline that recycles public posts and model outputs without explicit exclusion categories for illegal content. Enterprise compliance teams now have a concrete litigation template against which to audit their own training data provenance and vendor due diligence controls.

Corporate Policy2026-08-31

Redacted Anthropic Risk Report on Claude Mythos Preview Leaves Compliance Teams Without a Safety Case

Anthropic published a formal risk report in August 2026 referencing Claude Mythos Preview, a model available through its limited-access Glasswing program. The report signals a safety-review posture but is substantially redacted, leaving enterprise buyers without the full evaluation findings needed to assess suitability for regulated deployment. Compliance teams should not treat report existence as a substitute for complete model documentation.