EU Opens Android to Rival AI Agents: 2026 DMA Order
July 21, 2026

On July 16, 2026, the European Commission adopted two binding specification decisions telling Google exactly which parts of Android it must open to competing AI services.1 The document that came out of it reads less like a regulatory ruling and more like a capability spec for phone-based agents.
In one line: The EU has ordered Google to give third-party AI agents free access to 11 Android features — including wake-word activation, screen automation, background execution, and the on-device Gemini Nano models — which today are either reserved for Gemini outright or open to rivals only on worse terms, with most of it due in Android 18 by August 1, 2027.2
TL;DR
- What happened: The Commission adopted two sets of binding specification measures on July 16, 2026 — one on AI interoperability with Android under Article 6(7) DMA, one on Google Search data sharing under Article 6(11).123
- The core of it: Third-party AI services get access to 11 Android features, grouped into four buckets: invocation, context, actions on apps and the OS, and access to resources.2
- The headline capabilities: always-on hotword detection ("Hey [your assistant]"), screen automation that drives apps in a background virtual window, background execution, and guaranteed equal access to Android's built-in on-device models including Gemini Nano.2
- Deadline: Android 18, and no later than August 1, 2027. Concurrent hotword detection — multiple assistants listening for different wake words — lands later, in Android 19, by August 1, 2028.2
- Not a free-for-all: Five of the 11 features are gated behind an eligibility program Google must publish in draft by February 1, 2027 and finalize by May 1, 2027.2
- Google's position: President of Global Affairs Kent Walker said the decisions "risk undermining vital privacy and security guardrails for millions of Europeans."4
What You'll Learn
- What the Commission actually decided on July 16 — and the important thing it did not decide
- All 11 Android features, and what each one unlocks for an agent
- Which five features are gated, and the certification timeline for them
- The real search-data timeline, which most coverage has reported incorrectly
- What this changes if you're building an AI agent that targets phones
- What Google is objecting to, in its own words
What the Commission actually decided
A specification decision under Article 8(2) of the DMA is not a fine and not a finding that a company broke the law. It is the Commission spelling out, in technical detail, what compliance with an existing obligation has to look like.5
That distinction matters here. Google was already obligated under Article 6(7) DMA to provide "free and effective interoperability" with Android features. What it did not have was a definition of which features counted.2
The Commission opened these proceedings on January 27, 2026, ran a public consultation on the proposed measures, and adopted the final decision on July 16 — ahead of the statutory six-month deadline of July 27, 2026.25
The stakes attached to it are real. Under Article 30(1)(b) of the DMA, failing to comply with measures specified in an Article 8(2) decision exposes a gatekeeper to fines of up to 10% of total worldwide turnover. A separate provision, Article 30(2), raises the ceiling to 20% for a repeat infringement of an underlying Article 5, 6, or 7 obligation on the same core platform service within eight years.6
The Commission's stated reasoning is about distribution. Around 60% of European mobile users are on Android devices, and the Commission's view is that Gemini's deep OS access on that installed base is a structural advantage no rival can match by writing a better model.2
The 11 features, and what each one unlocks
The Commission organized the 11 features into four categories: invocation (how a user summons an agent), context (what the agent can see), actions (what it can do), and resources (what compute it can use).2
| # | Feature | Category | What it unlocks |
|---|---|---|---|
| 1 | Long-press home button / navigation handle | Invocation | Launch a third-party agent from the central home button, with context — the access point behind Circle to Search |
| 2 | Always-on hotword detection | Invocation | Wake-word activation with screen off, in standby, or in battery saver |
| 3 | Centralised access to on-device app data | Context | Query app data in one place rather than app-by-app, the way Google does via AppSearch |
| 4 | Context-aware intelligence | Context | Proactive suggestions without being prompted — the capability behind Magic Cue |
| 5 | Ambient data | Context | Real-time streams from microphone, camera, screen, and speakers |
| 6 | Structured on-device integration | Actions | Perform in-app tasks ("send a message", "schedule a meeting") via App Functions |
| 7 | Screen automation | Actions | Drive multi-step tasks in a separate virtual window via Computer Control |
| 8 | System integration | Actions | Change brightness, control media, toggle do-not-disturb or Bluetooth |
| 9 | System-level on-device models | Resources | Call preinstalled on-device models, including Gemini Nano |
| 10 | On-device model implementation | Resources | Install and run your own on-device models under Google's hardware and background conditions |
| 11 | Background execution | Resources | Run timely actions while the user is elsewhere or the screen is off |
Table: The 11 Google Android features covered by the Commission's July 16, 2026 specification decision. Source: European Commission, DMA.100220 Q&A.
Three of these are the ones that change what an agent can architecturally be on a phone.
Screen automation (#7) is the one that most resembles what desktop computer-use agents already do. The Commission's description is specific: the agent imitates user behaviour in a separate virtual window, so it can finish a task in the background while the user does something else.2
Android implements this via Computer Control, currently reserved for Google's own services.2 It's the same interaction model as the browser agents from Anthropic, OpenAI, and Google, moved down to the OS layer.
Background execution (#11) is what makes an agent something other than a chat window — without it, an agent can only act while you're looking at it. The Commission notes this is "particularly useful for AI-related apps," which are often designed to work while the user is in another app entirely.2
Third-party apps aren't locked out of background execution today. What changes is that they must get the same access as Google's own apps, under "transparent, objective, precise and non-discriminatory rules."2
System-level on-device models (#9) is the sleeper, and it's a parity fix rather than a door being unlocked. The on-device models that ship with Android — Gemini Nano among them — are already accessible to third parties; what the decision adds is a guarantee of equal access, explicitly including performance.2
That matters more than it sounds. An agent developer gets local inference for summarizing text, proofreading, and speech recognition without shipping their own model weights — and now with a commitment that it won't run slower than it does for Google.
Structured on-device integration (#6) also comes with a concrete list attached: Google must expose Gmail, Calendar, Drive, Docs, Maps, YouTube, Messages, and Phone through OS-level integration channels.2
The five gated features
Access is not automatic for everything. The Commission allows Google to impose "objective and non-discriminatory eligibility conditions" on five features it considers sensitive:2
- Screen automation
- Structured on-device integration
- System integration
- Centralised access to apps' data stored on the device
- Context-aware intelligence
Certification is performed by Google together with independent third parties, and the Commission was explicit that no commercial requirements may be attached — this is a security and privacy gate, not a licensing one.2
The certification calendar runs ahead of the feature deadline. Google must publish draft terms for consultation by February 1, 2027, publish final terms by May 1, 2027, and begin accepting applications on that same date. Each application must be assessed within four weeks.2
A set of general obligations applies across all 11 features, gated or not: interoperability must be free of charge, must work across the whole Android ecosystem including other manufacturers' devices, must not require extra user friction, and — notably — cannot be conditioned on the AI provider holding a default role on the device.2
Google also has to hand over complete documentation, let developers test the interoperability solutions including via beta, and provide technical assistance. Any new functionality added to a covered feature must reach third parties at the same time it reaches Google's own services.2
The search-data timeline most coverage got wrong
The second decision, under Article 6(11) DMA, covers Google Search data sharing — and it's where reporting has drifted from the source.
Multiple outlets have written that Google must begin sharing search data with rivals in January 2027. The Commission's own timeline says something different: by January 2027 — six months after adoption — Alphabet must finalise the pricing offer and communicate it to the Commission and to third-party search engines.3
The actual milestones are earlier and more granular:3
| Deadline | What Alphabet must do |
|---|---|
| End August 2026 | Submit eligibility application form; publish a webpage explaining how to apply |
| September 2026 | Provide template licence agreements and test data samples; submit cost estimates |
| November 2026 | Finalise the anonymised search dataset; submit latency and personal-data-detector information |
| January 2027 | Finalise the pricing offer and communicate it |
Table: Google Search data-sharing implementation milestones. Source: European Commission, DMA.100209 Q&A.
The reason this decision exists at all is blunt in the Commission's telling: Alphabet's initial compliance proposal was removing between 90% and 100% of unique search queries from the shared dataset, and excluded AI chatbots with search functions from eligibility entirely.3 The Commission says this produced "no meaningful uptake by potential beneficiaries."3
The fix explicitly brings AI chatbots offering search functionality into scope as eligible recipients.3 To qualify, a service needs at least 50,000 monthly average users in the EU over the past year, plus either two consecutive years of operation in the EU or founding within the last two years and more than €50 million in capital investment.3
Anonymisation is handled with k-anonymity at a floor of 1,000 users sharing the same location, device type, and query language — with the Commission noting 95% of users will sit in groups of at least 29,000.3 Data is shared with a minimum seven-day latency, for up to five years per beneficiary.3
Usage is fenced: recipients may improve query understanding, ranking and retrieval, and indexing — but may not train general-purpose AI models on it, use it for consumer profiling or advertising, or systematically replicate Google's results.3
What this changes if you build agents
The practical shift is that the mobile agent surface stops being a Google-only product decision and becomes a documented, testable interface with a compliance deadline behind it.
Plan for a certification track, not just an SDK. If your agent needs screen automation or app-data access — and most useful agents will — you're in the gated five. Draft terms land February 2027, applications open May 2027. That's a procurement and security-review workstream, not an afternoon of integration.
The permission surface is genuinely large. Ambient microphone and camera streams, on-device app data, screen contents, and the ability to act in apps while the screen is off is a substantial blast radius. This is precisely the territory covered by the zero-trust framing security teams are now applying to agents — and the Commission's answer is user consent plus the eligibility gate, not architectural restriction.
Geography is a real constraint. These measures are EU obligations. Nothing here compels Google to ship the same access in the US or elsewhere, and the decision covers Android only.
Apple's iOS carries its own Article 6(7) interoperability obligations, but the Commission specified those in two separate decisions adopted on March 19, 2025 — covering connected physical devices and the process for requesting interoperability.7 Neither is an AI-services equivalent of what Google just received.
Watch the tooling layer converge. An agent that can call OS-level app functions on Android and MCP servers over the network is dealing with two different tool-invocation surfaces. The MCP spec finalizing on July 28 governs the second; this decision governs the first.
What Google is objecting to
Kent Walker, President of Global Affairs at Google & Alphabet, published Google's response the same day.4
"Today's decisions risk undermining vital privacy and security guardrails for millions of Europeans. We have repeatedly offered solutions to safeguard users while satisfying the DMA's goals, but these rulings discount extensive evidence of user harm."4
His specific objection on Android is about who does the vetting. Walker's argument is that AI assistants already access Android capabilities safely today "with phone makers playing a key role in vetting them," and that the ruling "threatens device security by granting external apps sensitive and powerful device permissions without these safeguards."4
On search data, Walker wrote that "Europeans' private searches would be exposed to unfamiliar companies, without adequate anonymisation of the data and without user knowledge or consent."4
Google has not, as of July 21, 2026, announced an appeal of either decision. Specification decisions are challengeable before the EU General Court in the same way as other Commission decisions, and obligations remain live during any challenge.5
The Commission says it will monitor implementation over the coming two years, with Google required to report regularly on design, development, and release progress.2
Bottom Line
The interesting thing about this decision isn't the competition politics. It's that a competition regulator has ended up publishing what is arguably the clearest public breakdown yet of what an AI agent actually needs from a phone.
Invocation, context, actions, resources — that four-part split is a reasonable architecture diagram for a mobile agent, and it now has legal force and a date attached. Whether Gemini's rivals can build something worth summoning is a separate question, and not one the Commission set out to answer for them.
The deadline that actually matters for builders is not August 2027. It's February 2027, when the terms for the five gated features go out for consultation — because that's the document that will determine who gets to ship a real agent on Android and who ships a chat window.
Footnotes
-
European Commission, "Commission provides guidance to Google for AI interoperability on Android and sharing of Google Search data under the Digital Markets Act" (16 July 2026). https://digital-markets-act.ec.europa.eu/commission-provides-guidance-google-ai-interoperability-android-and-sharing-google-search-data-under-2026-07-16_en ↩ ↩2 ↩3
-
European Commission, "Alphabet specification proceedings — Interoperability for AI services," Questions and Answers, case DMA.100220 (16 July 2026). https://digital-markets-act.ec.europa.eu/developer-portal/interoperability/alphabet-specification-proceedings-interoperability-ai-services_en ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25
-
European Commission, "Alphabet specification proceedings — Sharing of Google Search data," Questions and Answers, case DMA.100209 (16 July 2026). https://digital-markets-act.ec.europa.eu/developer-portal/data-access/alphabet-specification-proceedings-sharing-google-search-data_en ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11
-
Kent Walker, President of Global Affairs, Google & Alphabet, "The DMA should not undercut security & privacy for Europeans," The Keyword (16 July 2026). https://blog.google/company-news/inside-google/around-the-globe/google-europe/the-dma-should-not-undercut-security-privacy-for-europeans/ ↩ ↩2 ↩3 ↩4 ↩5
-
Regulation (EU) 2022/1925 (Digital Markets Act), Article 8 — Compliance with obligations for gatekeepers. Article 8(2) provides that the implementing act specifying compliance measures "shall be adopted within 6 months from the opening of proceedings pursuant to Article 20." https://www.eu-digital-markets-act.com/Digital_Markets_Act_Article_8.html — On appealability and the practical effect of a challenge, see also Bratby Law, "DMA Specification Decisions Explained." https://bratby.law/dma-specification-decisions-google/ ↩ ↩2 ↩3 ↩4
-
Regulation (EU) 2022/1925 (Digital Markets Act), Article 30 — Fines. https://www.eu-digital-markets-act.com/Digital_Markets_Act_Article_30.html ↩ ↩2
-
European Commission, "Commission provides guidance under Digital Markets Act to facilitate development of innovative products on Apple's platforms" (19 March 2025) — specification decisions DMA.100203 (nine iOS connectivity features for connected devices) and DMA.100204 (interoperability request process). https://digital-markets-act.ec.europa.eu/commission-provides-guidance-under-digital-markets-act-facilitate-development-innovative-products-2025-03-19_en ↩