EU Orders Google and Apple to Open AI Assistants to Rival Platforms

The European Commission is forcing Apple and Google to grant rival AI assistants deep device access, including microphone, camera and screen permissions, reigniting a genuine security debate over how much autonomous access AI agents should have to consumer devices.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region4 min read
wo smartphones resting on a modern office desk, each displaying a different abstract AI assistant interface with glowing icons, under soft natural lighting.

wo smartphones resting on a modern office desk, each displaying a different abstract AI assistant interface with glowing icons, under soft natural lighting.

Google and Apple have a significant advantage in the AI race: their control over billions of smartphones worldwide. The European Commission is now moving to limit how much that advantage translates into control over AI assistants specifically.

What the EU is actually demanding

Apple and Google combine for roughly 5 billion active Android phones and iPhones globally, according to market research firm Omdia, with about 427 million of those devices falling under EU jurisdiction. As AI assistants increasingly move from answering questions to completing tasks on a user's behalf, the European Commission wants rival virtual assistants to have access comparable to Google's Gemini and Apple's Siri.

Under the Digital Markets Act, Google must begin sharing search data with rivals by January 2027 and provide broader AI assistant access to Android by July 2027, granting third party AI agents access that includes device microphone, camera, and screen functions.

Both companies are pushing back, citing security

Google's response has been unusually direct. Kent Walker, president of global affairs at Google and Alphabet, said the Android changes would pose a major security risk by giving external apps sensitive and powerful device permissions, and warned that sharing search data would weaken citizen privacy, risk business trade secrets, and endanger national security.

Sameer Samat, Google's Android president, said on social media that the European Commission is on the wrong track, and pointed out that Android users already have the option to switch their default AI assistant through device settings. Apple has taken a more drastic route: the company announced in June that it will not launch its new Siri AI assistant on iPhones and iPads in the EU at all, citing the Digital Markets Act as the reason.

A genuine security question, not just a competitive one

Experts broadly agree that opening deep device access to external AI agents carries real security and privacy implications, independent of whichever company is making that argument. Without carefully built protections, apps granted deeper access to Android or iOS could quietly extract information from a user's phone.

The stakes rise further with AI agents specifically, since a malfunctioning or compromised assistant with access to messages, location, camera, and microphone represents a meaningfully different risk profile than a traditional app with narrower permissions. This is precisely the governance gap security vendors have been racing to close over the past year, with a new generation of AI native security platforms competing to become the defining governance layer for autonomous agents operating inside enterprise and consumer environments alike, treating unmanaged agent permissions as a genuinely new category of attack surface rather than a variation on existing mobile app risk.

At the same time, some observers question whether privacy concerns are Google's primary motivation for resisting the EU's rules, given the company's own commercial interest in keeping its assistant as the default gateway on Android devices.

Why this matters beyond Europe

This dispute sits at the centre of a question that extends well past EU borders: how much autonomous access should AI agents have to the devices and data they operate on, and who gets to decide. It is the platform governance version of a technical problem enterprise security teams have been tracking closely at the application layer this year, autonomous AI agents gaining broader system access faster than the security architecture around them matures, a dynamic already prompting enterprise platforms to build real time governance and instant action reversal specifically for autonomous agents rather than relying on traditional access control models designed for human users.

Regulators, enterprises, and platform operators across the GCC building or procuring AI assistant technology are watching a live case study in how that tension gets resolved at scale, and whichever balance the EU ultimately settles on between platform openness and device security will likely shape how other regulatory bodies, including those across the Gulf, approach similar AI assistant governance questions as agentic AI becomes standard on consumer devices globally.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

AI agent security governanceplatform regulation and device accessautonomous agent risk management