Google warns EU Android AI interoperability rules could weaken security #AI


The proposed interoperability measures may weaken Android safeguards, according to Google’s warning on EU Android AI agent rules.

Google has warned that binding EU interoperability measures for Android AI services could expose European users to scams, data theft and malicious software by giving third-party assistants deeper access to smartphones.

The European Commission adopted the measures on 16 July under the Digital Markets Act. They require Google to give competing AI services access to 11 Android features on terms comparable to those available to its own services, including Gemini.

Covered capabilities include voice activation, screen and sensor context, interaction with other applications, background execution and automated device controls. The Commission argues that competing assistants need such access to perform tasks across applications and offer services comparable to Gemini.

AI services such as ChatGPT, Claude and Perplexity already operate on Android within isolated application sandboxes. According to Google, more deeply integrated assistants are generally provided by device manufacturers or vetted partners, allowing security risks to be assessed before they receive sensitive permissions.

Google argues that the EU measures could require access to continuous inputs from microphones, cameras, screens and other device sensors without sufficiently robust qualification procedures. It also objects to provisions that allow users to override certain protections when enabling high-risk functions, such as screen automation.

The company warned that malicious applications or hidden prompt-injection instructions could manipulate autonomous agents into accessing private information or performing unintended actions. Unlike conventional applications, AI agents may interpret information, plan several steps and operate across multiple services.

Google also criticised a certification system involving independent assessors, arguing that operating-system providers and device manufacturers should retain the ability to approve, suspend or revoke access because they possess broader threat intelligence and system telemetry.

The European Commission maintains that users must explicitly consent before an AI service accesses covered features. It also allows Google to establish objective and non-discriminatory eligibility requirements for several sensitive functions. It says the GDPR, Cyber Resilience Act and other EU security rules will continue to apply.

Most measures must be implemented through Android 18 by 1 August 2027. Concurrent voice activation for multiple AI services must be implemented on Android 19 by August 2028, and Google will report regularly to the Commission during implementation.

Google is urging the Commission to involve cybersecurity laboratories, standards organisations and mobile-security specialists as the technical systems are developed. It says greater competition should not transfer responsibility for complex security decisions from platform operators to individual users.

Why does it matter?

The measures could determine whether competing AI assistants receive the same smartphone access as Gemini while preserving protections for private data and device controls. Their implementation will test whether the DMA can open a dominant platform without creating new attack routes for untrusted autonomous agents.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW