AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

← News
Enforcement2026-07-22

EU Binding DMA Measures Force Google to Open Android AI Access and Share Search Data by July 2027, Reshaping Enterprise AI Procurement Risk

What happened

The European Commission has issued final binding specification measures under the Digital Markets Act requiring Google to open Android's system-level access to competing AI platforms on equivalent terms to those currently granted to Gemini, and to make search data available to rival search providers for a reasonable fee. Full details are reported in the Ars Technica account of the Commission's decision. The measures set two distinct compliance deadlines: search data sharing obligations take effect by January 2027, while Android AI interoperability must be in place by July 2027. Critically, the Commission has ruled that AI chatbots are to be treated as search services for data-sharing purposes, meaning the data-sharing and anonymization obligations extend to AI assistant products, not only to traditional search engines. A multilayered anonymization approach is mandated for all shared data, imposing specific technical and process requirements on any party accessing or receiving that data.

Why it matters

  • ·Enterprise procurement teams that have standardized on Gemini as the default AI assistant on managed Android device fleets must now assess an expanded field of competing AI assistants that will have equivalent system-level access - each representing a new third-party AI vendor that requires risk assessment, contract review, and shadow AI controls under frameworks such as the EU AI Act.
  • ·The Commission's classification of AI chatbots as search services for data-sharing purposes creates a precedent that regulators in other jurisdictions may follow, meaning that AI assistant products handling search-adjacent queries could face data access, sharing, and anonymization obligations beyond what current privacy and AI governance programs anticipate.
  • ·Enterprises building AI products that consume Google search data, or that operate AI assistants in EU markets, face direct operational obligations: they must evaluate whether their data intake processes, anonymization controls, and vendor agreements are compatible with the multilayered anonymization standard and the January 2027 data-sharing deadline.

Governance controls affected

What to do now

  • Audit all managed Android device policies to identify where Gemini is currently deployed as a default AI assistant, and map the governance implications of new competing AI assistants gaining equivalent system-level access after July 2027.
  • Update third-party AI vendor due diligence templates to include questions about DMA compliance status, multilayered anonymization capabilities, and data-sharing obligations for any AI assistant or search-adjacent AI product operating in the EU.
  • Review vendor contracts for AI products that ingest Google search data or operate as AI assistants in EU markets, and identify whether data processing agreements reflect the Commission's anonymization requirements ahead of the January 2027 deadline.
  • Assess shadow AI risk exposure by inventorying which AI assistants employees may begin adopting on Android as interoperability opens the platform, and extend acceptable use policy enforcement to cover newly accessible assistants.
  • Brief legal and compliance leadership on the Commission's classification of AI chatbots as search services, and evaluate whether that classification affects regulatory obligations for any AI assistant products the organization deploys or procures.

What to watch next

Compliance teams should monitor whether the Commission issues further technical specifications on the multilayered anonymization standard ahead of the January 2027 data-sharing deadline, as the technical detail of that standard will directly affect data governance program updates. Google's formal response and any appeal proceedings could shift the implementation timeline, so tracking enforcement milestones through the first half of 2027 is warranted. Teams should also watch for other jurisdictions - particularly the UK and US - citing the Commission's chatbot-as-search-service classification as a basis for extending data-sharing or interoperability obligations to AI assistant products under their own regulatory frameworks, which would materially expand the multi-jurisdiction compliance mapping work required under [CMP-001].

Stay ahead of stories like this

Get every EU AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Corporate Policy2026-08-12

Twitch's Default Opt-In for AI Training Exposes Consent Design Risks

Twitch has introduced a privacy toggle allowing streamers to opt out of having their content used to train Amazon's generative AI models, but the setting defaults to opted-in and covers only future data collection. The opt-out does not apply to content already collected, and a streamer's chat activity on another channel remains subject to that channel owner's preference. The move illustrates how platform-level training data consent is being operationalized at scale, and why the design choices matter for enterprise governance teams.

Enforcement2026-08-10

181,874 Meetings Exposed After tl;dv Ignored Six-Month Disclosure

A security researcher found that tl;dv, an AI meeting recording platform used by more than two million people, left its entire Firestore meetings database readable by any authenticated user due to a missing tenant isolation control. The exposure covered 181,874 meeting records across 84,312 users, including government agencies in 23 countries, universities, and corporations. The vulnerability was disclosed in January 2026 but remained unpatched as of July 2026, despite the company's published claims of SOC2, GDPR, and EU AI Act compliance.

Corporate Policy2026-08-14

OpenAI's Computer History Feature Brings Keylogging and Prompt Injection Into Enterprise Scope

OpenAI has introduced an opt-in feature called Computer History for ChatGPT Pro, Business, and Enterprise users on macOS that records keystrokes, clicks, and app context to build AI memories over time. Interaction data is stored unencrypted locally for up to 48 hours before being transmitted to OpenAI servers for summarization, with resulting memory files potentially retained for longer periods. The feature is unavailable in the EEA, Switzerland, and the UK, and requires admin approval before Business and Enterprise users can enable it.