Europe’s AI Market: Security as the New Barrier to Entry
COMMENTARY: On July 16, the European Commission issued two binding decisions outlining requirements for Google to comply with the Digital Markets Act (DMA).
European Commission’s Decisions
The first mandate opens 11 Android features to competing AI assistants, enabling users to activate alternatives like ChatGPT or Claude via voice commands and operate them at the system level, similar to how Gemini functions today. The second directive compels Google to share anonymized data from Google Search, including rankings, queries, clicks, and views, with rival search engines and AI chatbot providers under fair, reasonable, and non-discriminatory terms. Data sharing will commence in January 2027, with Android modifications rolling out to users by July 2027.
Clarifications
No financial penalties are imposed, and the EU AI Act remains unrelated to these measures. The decisions conclude a six-month negotiation where the commission specified how a designated gatekeeper like Alphabet must fulfill existing obligations under competition laws.
Shift in AI Regulation Focus
This marks the clearest example to date of AI competition policy, a regulatory area that has yet to be widely addressed. Current AI regulation has focused on model behavior, such as bias, hallucination, copyright issues, and misuse. The European Union has now shifted attention to a different question: who controls access to AI users?
Market Dominance and System-Level Access
As assistants evolve into primary interfaces for search, applications, and services, market dominance will depend as much on distribution as on model quality. The commission’s rationale hinges on an imbalance. Installing a rival assistant on an Android device results in an application, whereas integrating a proprietary assistant like Gemini grants system-level access, enabling voice interaction, screen reading, and cross-app functionality.
Search Data Mandate
Google’s ability to refine search results using behavioral data at a scale unmatched by competitors necessitates a defined, anonymized data slice for rivals, creating a viable path for alternatives to Google Search and Gemini.
Google’s Concerns
Google contends these measures weaken privacy and security safeguards for European users, expose private searches to unfamiliar entities, and grant external software excessive device permissions. These concerns are significant. Expanding access to privileged parties increases the attack surface of the world’s most widely used mobile platform.
Safeguards and Security Measures
The commission has established specific safeguards rather than broad assurances. Search data will undergo multi-layered anonymization, including removal of direct identifiers and suppression of rare queries that could identify individuals. Recipients face contractual restrictions on data usage and storage, along with audit requirements. Google may charge for access at cost plus a reasonable margin.
Security as a Market Access Condition
The final provision is critical. The commission can deny a company access to Europe’s dominant mobile ecosystem—and the search data fueling AI products—on security grounds. Security has transitioned from a post-commercial control to a prerequisite for market participation.
Broader Regulatory Framework
This decision also addresses a common misunderstanding about European AI regulation, which is often perceived as limited to the AI Act. In reality, AI governance in Europe involves multiple frameworks: the AI Act for trustworthy AI, the DMA for competition, GDPR for personal data, the Digital Services Act for platform accountability, the Cyber Resilience Act for product security, and NIS2 for operational cyber risk.
Implications for Organizations
Organizations must manage AI assistants as they would any supplier with deep system access: identify which assistants are active on devices handling corporate data, determine acceptable vendors based on security records and data handling practices, define permissions, monitor updates, and establish removal protocols in case of compromise.
Steve Durbin, chief executive, Information Security Forum SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Each contribution aims to provide a unique perspective on critical cybersecurity issues. Content is maintained to the highest standards of quality, objectivity, and non-commercial integrity.
