Your AI Platform Lock-In Expires in 12 Months

Two binding DMA decisions force Google to open 11 Android AI features to rivals and share search data with AI chatbots by January 2027. The EU just classified AI assistants as infrastructure — and every enterprise CIO building on platform-specific AI integration has 12 months before that exclusivity ends.

By Rajesh Beri·July 20, 2026·14 min read
Share:
THE DAILY BRIEF
DMAEU AI RegulationGoogle AndroidAI Assistant InteroperabilityEnterprise Platform StrategyAI Vendor Lock-InGeminiDigital Markets ActAI GovernanceEnterprise Compliance
Your AI Platform Lock-In Expires in 12 Months

Two binding DMA decisions force Google to open 11 Android AI features to rivals and share search data with AI chatbots by January 2027. The EU just classified AI assistants as infrastructure — and every enterprise CIO building on platform-specific AI integration has 12 months before that exclusivity ends.

By Rajesh Beri·July 20, 2026·14 min read

By Rajesh Beri | July 20, 2026


On July 16, 2026, the European Commission did something no regulator has done before. It classified AI assistants as infrastructure — and issued binding orders to prove it means it.

Two specification decisions under the Digital Markets Act force Google to open 11 specific Android features to rival AI assistants — voice invocation, screen context, cross-app task execution, on-device models — and to share anonymized search ranking, query, click, and view data with competing search engines and AI chatbots on fair, reasonable, and non-discriminatory (FRAND) terms. Search data sharing starts January 2027. Android feature parity arrives with Android 18, by August 1, 2027 at the latest. Concurrent wake-word detection follows in Android 19, by August 1, 2028.

If you run enterprise AI on mobile devices, deploy AI assistants across your workforce, or sell AI products into European markets, these deadlines are now your deadlines. Every platform decision you make in the next 12 months has a regulatory dimension it didn't have two weeks ago.

This is not an antitrust curiosity. It is the first time a major regulatory body has drawn a line between "AI assistant as application" and "AI assistant as operating system layer" — and ruled that the operating system layer must be open. The implications for enterprise AI platform strategy are immediate and structural.

What the Decisions Actually Require

The detail in these decisions matters more than the headlines suggest. Bratby Law's analysis of the specification decisions provides the most granular breakdown of what Google must build.

Android AI Interoperability (Article 6(7) DMA — Case DMA.100220):

The Commission identified 11 specific features across four categories that currently give Gemini structural advantages over every other AI assistant on Android:

  1. Invocation surfaces. Gemini can be activated by wake word ("Hey Google"), long-press home button, and navigation handle. Rivals get none of these system-level triggers. Under the new order, any qualifying AI assistant can register its own wake word and claim the same entry points.

  2. Screen context and situational awareness. Gemini can read what's on the user's screen and use that context to answer questions. Third-party assistants are sandboxed. The order mandates equal access.

  3. Cross-app task execution. Gemini can send emails, order food, book taxis, and orchestrate tasks across applications through privileged API access. Rivals are confined to their own sandbox. The order requires equal API access for qualifying providers.

  4. Hardware and system model resources. Gemini gets scheduling priority and preferential access to on-device neural processing. The order mandates equal resource allocation.

Six of the 11 features are open to any qualifying third party. Five — including centralized on-device data access and agentic screen automation — are restricted to providers certified under a new Qualified AI Assistant Programme, for which Google must publish draft certification terms by February 1, 2027 and final terms by May 1, 2027.

Search Data Sharing (Article 6(11) DMA — Case DMA.100209):

This is the decision that should keep platform strategists up at night. Google must share anonymized ranking, query, click, and view data — the same data it uses internally to optimize Search — with eligible rivals on FRAND pricing terms, fixed for five years. The eligibility criteria explicitly include AI chatbots that provide search-engine functionality, subject to a genuine-economic-activity test: two years of trading (or under two years with over €50 million in capital) plus at least 50,000 monthly EU users.

The pricing structure is incremental cost-based, WACC-capped. SMEs always qualify for strict incremental-cost pricing. Very-large-scale beneficiaries — at gatekeeper-equivalent scale — can be charged up to Google Search's own operating margin.

The anonymization standard combines technical suppression of identifiers with contractual controls: a 13-month cap on data retention by recipients, a ban on re-identification attempts, and mandatory independent ISAE 3000 assurance before access and annually thereafter.

In plain English: OpenAI, Anthropic, Perplexity, and any qualified AI chatbot can now buy the same search intelligence that Google uses to train Gemini. Starting January 2027.

Apple Is Fighting the Same Battle — and Losing

Google is not the only platform under fire. Apple has been clashing with the Commission over parallel DMA requirements to open Siri AI to third-party competitors. Apple's response has been remarkably confrontational — the company argues that EU regulators rejected its proposals for introducing Siri AI while supporting third-party virtual assistants, and that the Commission's interpretation of the DMA would force Apple to allow third-party assistants access to private user data in ways that fundamentally compromise device security.

The Commission disagrees. Its position: when a company controls the operating system on billions of devices, and uses that control to give its own AI assistant capabilities that competitors cannot access, that is a gatekeeper behavior the DMA was designed to address.

For enterprise CIOs, the takeaway is identical regardless of which platform you deploy: the assumption that your AI assistant vendor controls the device layer is now a regulatory liability in the EU, and the precedent will spread.

Why Enterprise CIOs Should Care About a Consumer Ruling

The instinct will be to dismiss this as a consumer story. Android phones. Wake words. Booking taxis. That instinct is wrong.

Consider how enterprise AI actually reaches your workforce in 2026. Field service technicians use AI assistants on Android devices to pull up work orders. Sales teams use voice-activated AI to update CRM records between meetings. Healthcare workers use AI agents to query patient records hands-free. Logistics operators use on-device AI for real-time routing. Every one of these use cases runs on the same platform integration layer that the EU just forced open.

VentureBeat reported last week that 35% of enterprises identify vendor lock-in as the risk they fear most when AI control resides with a model provider. Gartner says agentic AI puts $234 billion in enterprise SaaS spending at risk, precisely because operational learning risks remaining with providers rather than customers.

The DMA just accelerated both risks. If you built your enterprise mobile AI strategy around Gemini's exclusive Android integration, you have 12 months before that exclusivity ends in the EU — and regulatory contagion means similar rules are coming elsewhere. The UK's CMA has designated Google with strategic market status for both general search and Android, though it has not yet imposed equivalent interoperability requirements. When, not if, it does, the DMA's specification decisions will be the template.

The Security Argument Is Real — But Not the Way Google Frames It

Google's President of Global Affairs Kent Walker responded to the decisions on July 16 with two specific objections.

On Android: giving any qualifying third-party service real-time screen capture and cross-app execution capabilities without the existing manufacturer safeguard review creates "a meaningful attack surface." He pointed to a warning from ENISA, the EU's own cybersecurity agency, that "security fundamentals matter more than ever in the age of AI."

On search data: broader access would expose private user searches to "unfamiliar companies, without adequate anonymization of the data and without user knowledge or consent." The R Street Institute noted that the recipient list is not limited to European entities, meaning behavioral data from EU users — including data from American diplomats, military personnel, and government contractors traveling in Europe — could flow to companies outside EU data-protection jurisdiction.

These concerns are legitimate. The R Street Institute's July 15 analysis makes a specific structural argument: the DMA's Article 6(7) interoperability mandate is on a collision course with the EU's own Cyber Resilience Act, which requires companies to minimize attack surfaces, deliver secure-by-default products, and bear lifecycle liability for product security. The two obligations run in opposite directions. The Commission has not stated which takes precedence when they conflict.

For enterprise security teams, this creates a genuinely new threat model. As we covered with 1Password's AI identity crisis, non-human identities operating with persistent access already outnumber human ones in most enterprise environments. The DMA's forced interoperability now means enterprise security teams must evaluate not just the AI assistants they chose, but the AI assistants that might be running on the same devices with equivalent system-level permissions — because any qualifying assistant can claim those permissions.

The Competitive Landscape Just Changed

Yale economist Fiona Scott Morton, in a Bruegel working paper published July 1, offered the clearest assessment of what these decisions mean competitively. The specification, she argued, correctly identifies the four access points — invocation surfaces, contextual data, on-device actions, and system-level model resources — that determine whether a rival AI assistant can function as a genuine device-level service or merely another downloaded app.

If enforced as adopted, Scott Morton wrote, the decisions would "prevent the monopolization of AI services in Europe and eliminate the need for a long and ineffective antitrust case" to produce the same result.

The practical effect: OpenAI's ChatGPT, Anthropic's Claude, and Perplexity will gain the same Android integration capabilities that currently make Gemini the only real AI assistant on Android. Combined with access to Google's search data on FRAND terms, the structural moat that Google spent a decade building around Search and two years embedding into Android disappears in 12 months.

For enterprises evaluating AI assistant platforms, this is the most significant shift in competitive dynamics since OpenAI's ChatGPT Enterprise launch in 2023.

Framework #1: AI Platform Lock-In Risk Scorecard

Score your enterprise's exposure across five dimensions. Each dimension is rated 1 (low risk) to 5 (critical risk). A total score above 15 demands immediate action.

Dimension Score 1 (Low) Score 3 (Medium) Score 5 (Critical)
Data Portability All AI training data, prompts, and outputs exportable in standard formats Partial export; some proprietary formatting or vendor-specific embeddings Data locked in vendor-specific formats; no export API; retraining required to switch
API & Integration Dependency Standard APIs (REST/GraphQL); MCP-compatible; vendor-agnostic orchestration Mix of standard and proprietary APIs; some vendor-specific SDKs Deep OS-level integration (wake words, screen context, cross-app execution) tied to single vendor
Identity & Access Architecture AI assistant identities managed through enterprise IAM (Entra ID, Okta) Hybrid: some assistants in enterprise IAM, others use vendor-managed identity AI assistants use vendor-controlled identity; no enterprise visibility into permissions or audit logs
Regulatory Exposure No EU operations; no EU customer data; no EU-manufactured devices in fleet Some EU operations; partial GDPR exposure; mixed device fleet Significant EU workforce or customers; Android/iOS fleet deployed under DMA-designated platforms
Exit Cost Switching AI vendor requires <30 days; no workflow disruption 3-6 month migration; some workflow retraining; moderate cost 12+ month migration; custom integrations break; retraining workforce; >$500K switching cost

Scoring Guide:

  • 5-10: Low lock-in risk. Maintain monitoring posture.
  • 11-15: Moderate risk. Begin multi-vendor evaluation and data portability audit within 90 days.
  • 16-20: High risk. Initiate vendor diversification program. Review DMA compliance exposure.
  • 21-25: Critical risk. Your platform strategy is a single point of failure. Execute contingency plan before January 2027 data-sharing deadline.

How to use this: Score your current primary AI assistant platform. Then score each alternative you're evaluating. The gap between your current score and the best alternative is your migration incentive. If your current platform scores 18+ and an alternative scores 10, you have a model-agnostic architecture problem that regulation is about to make urgent.

Framework #2: DMA AI Compliance & Enterprise Action Timeline

This is not just for companies subject to the DMA. If you deploy AI on mobile devices, sell AI products into EU markets, or source AI infrastructure from DMA-designated gatekeepers, every date on this timeline affects your operations.

Date DMA Milestone Enterprise Action Required
July 16, 2026 Specification decisions adopted; enforceable immediately Audit current AI assistant deployments for single-vendor dependency on Android/iOS platform integration
January 2027 Google begins sharing anonymized search data with qualified AI chatbots Evaluate whether your enterprise search/RAG infrastructure can benefit from FRAND data access; assess competitive implications if rivals gain access
February 1, 2027 Google publishes draft Qualified AI Assistant Programme certification terms Review certification requirements; determine if your enterprise AI tools or partners qualify; begin security assessment of newly qualifying assistants
May 1, 2027 Final certification terms published; applications accepted Decide which AI assistants to certify/approve for enterprise fleet; update MDM policies; begin security testing
August 1, 2027 Android 18 ships with 10 of 11 interoperability features live Update enterprise device management to govern multi-assistant environments; revise acceptable-use policies; deploy monitoring for AI assistant privilege escalation
August 1, 2028 Android 19 adds concurrent wake-word detection (11th feature) Full multi-assistant parity live; finalize enterprise AI assistant governance framework

Critical enterprise actions before January 2027:

  1. Audit AI assistant dependencies. Map every AI assistant integration that relies on platform-specific capabilities (wake words, screen context, cross-app execution). Identify which capabilities become commoditized under the DMA.

  2. Assess regulatory contagion. The UK's CMA has designated Google for strategic market status but has not yet imposed interoperability requirements. Assume it will. Plan for equivalent rules in your top 5 markets by 2028.

  3. Evaluate FRAND data access. If you build enterprise AI products, determine whether your organization qualifies for Google search data under the genuine-economic-activity test (2 years trading, or <2 years with >€50M capital, plus 50K monthly EU users). The data sharing starts in six months.

  4. Update your threat model. With AI agents already 2.5x riskier than humans in production, forced interoperability means enterprise security teams must plan for AI assistants they didn't deploy gaining system-level permissions on their devices. Update your agentic control gap assessment accordingly.

  5. Build a multi-vendor AI assistant strategy. The era of "our enterprise runs on one AI assistant" is ending — not because of product quality, but because regulators are mandating choice. Model-agnostic architecture is no longer a best practice; it's becoming a compliance requirement.

The Bigger Pattern: AI Assistants Are Being Regulated Like Utilities

Step back and look at what happened in July 2026. The EU ordered AI assistant interoperability on Android. Apple is fighting the same battle on iOS. China's WAICO bloc of 29 nations is building its own AI governance framework. The U.S. Senate's AI AGENT Act proposes user-linked accountability and FTC registration for AI agents. AI governance gaps are widening faster than deployment, with only 12% of enterprises using a centralized platform to govern their AI agents despite 96% already running them in production.

The convergence is unmistakable. AI assistants are being reclassified from "applications you choose" to "infrastructure you must share." The regulatory logic is the same one that opened telecom networks, mandated browser choice screens, and forced payment interoperability: when a layer becomes essential enough that one company's control of it distorts competition, that layer gets pried open.

For enterprise AI leaders, the strategic question is no longer "which AI assistant do we pick?" It's "how do we architect for a world where the AI assistant layer is open, governed, and multi-vendor by default?"

The companies that built their AI strategies around exclusive platform integration have 12 months to adapt. The ones that built for interoperability from the start — with model-agnostic architectures, portable data pipelines, and vendor-neutral identity frameworks — just had their strategy validated by the European Commission.

The DMA didn't create the multi-vendor AI future. It made it mandatory.


Continue Reading

THE DAILY BRIEF

Enterprise AI insights for technology and business leaders, twice weekly.

beri.net

Subscribe at beri.net/subscribe for twice-weekly AI insights delivered to your inbox.

LinkedIn: linkedin.com/in/rberi  |  X: x.com/rajeshberi

© 2026 Rajesh Beri. All rights reserved.

Your AI Platform Lock-In Expires in 12 Months

Photo by Sora Shimazaki on Pexels

By Rajesh Beri | July 20, 2026


On July 16, 2026, the European Commission did something no regulator has done before. It classified AI assistants as infrastructure — and issued binding orders to prove it means it.

Two specification decisions under the Digital Markets Act force Google to open 11 specific Android features to rival AI assistants — voice invocation, screen context, cross-app task execution, on-device models — and to share anonymized search ranking, query, click, and view data with competing search engines and AI chatbots on fair, reasonable, and non-discriminatory (FRAND) terms. Search data sharing starts January 2027. Android feature parity arrives with Android 18, by August 1, 2027 at the latest. Concurrent wake-word detection follows in Android 19, by August 1, 2028.

If you run enterprise AI on mobile devices, deploy AI assistants across your workforce, or sell AI products into European markets, these deadlines are now your deadlines. Every platform decision you make in the next 12 months has a regulatory dimension it didn't have two weeks ago.

This is not an antitrust curiosity. It is the first time a major regulatory body has drawn a line between "AI assistant as application" and "AI assistant as operating system layer" — and ruled that the operating system layer must be open. The implications for enterprise AI platform strategy are immediate and structural.

What the Decisions Actually Require

The detail in these decisions matters more than the headlines suggest. Bratby Law's analysis of the specification decisions provides the most granular breakdown of what Google must build.

Android AI Interoperability (Article 6(7) DMA — Case DMA.100220):

The Commission identified 11 specific features across four categories that currently give Gemini structural advantages over every other AI assistant on Android:

  1. Invocation surfaces. Gemini can be activated by wake word ("Hey Google"), long-press home button, and navigation handle. Rivals get none of these system-level triggers. Under the new order, any qualifying AI assistant can register its own wake word and claim the same entry points.

  2. Screen context and situational awareness. Gemini can read what's on the user's screen and use that context to answer questions. Third-party assistants are sandboxed. The order mandates equal access.

  3. Cross-app task execution. Gemini can send emails, order food, book taxis, and orchestrate tasks across applications through privileged API access. Rivals are confined to their own sandbox. The order requires equal API access for qualifying providers.

  4. Hardware and system model resources. Gemini gets scheduling priority and preferential access to on-device neural processing. The order mandates equal resource allocation.

Six of the 11 features are open to any qualifying third party. Five — including centralized on-device data access and agentic screen automation — are restricted to providers certified under a new Qualified AI Assistant Programme, for which Google must publish draft certification terms by February 1, 2027 and final terms by May 1, 2027.

Search Data Sharing (Article 6(11) DMA — Case DMA.100209):

This is the decision that should keep platform strategists up at night. Google must share anonymized ranking, query, click, and view data — the same data it uses internally to optimize Search — with eligible rivals on FRAND pricing terms, fixed for five years. The eligibility criteria explicitly include AI chatbots that provide search-engine functionality, subject to a genuine-economic-activity test: two years of trading (or under two years with over €50 million in capital) plus at least 50,000 monthly EU users.

The pricing structure is incremental cost-based, WACC-capped. SMEs always qualify for strict incremental-cost pricing. Very-large-scale beneficiaries — at gatekeeper-equivalent scale — can be charged up to Google Search's own operating margin.

The anonymization standard combines technical suppression of identifiers with contractual controls: a 13-month cap on data retention by recipients, a ban on re-identification attempts, and mandatory independent ISAE 3000 assurance before access and annually thereafter.

In plain English: OpenAI, Anthropic, Perplexity, and any qualified AI chatbot can now buy the same search intelligence that Google uses to train Gemini. Starting January 2027.

Apple Is Fighting the Same Battle — and Losing

Google is not the only platform under fire. Apple has been clashing with the Commission over parallel DMA requirements to open Siri AI to third-party competitors. Apple's response has been remarkably confrontational — the company argues that EU regulators rejected its proposals for introducing Siri AI while supporting third-party virtual assistants, and that the Commission's interpretation of the DMA would force Apple to allow third-party assistants access to private user data in ways that fundamentally compromise device security.

The Commission disagrees. Its position: when a company controls the operating system on billions of devices, and uses that control to give its own AI assistant capabilities that competitors cannot access, that is a gatekeeper behavior the DMA was designed to address.

For enterprise CIOs, the takeaway is identical regardless of which platform you deploy: the assumption that your AI assistant vendor controls the device layer is now a regulatory liability in the EU, and the precedent will spread.

Why Enterprise CIOs Should Care About a Consumer Ruling

The instinct will be to dismiss this as a consumer story. Android phones. Wake words. Booking taxis. That instinct is wrong.

Consider how enterprise AI actually reaches your workforce in 2026. Field service technicians use AI assistants on Android devices to pull up work orders. Sales teams use voice-activated AI to update CRM records between meetings. Healthcare workers use AI agents to query patient records hands-free. Logistics operators use on-device AI for real-time routing. Every one of these use cases runs on the same platform integration layer that the EU just forced open.

VentureBeat reported last week that 35% of enterprises identify vendor lock-in as the risk they fear most when AI control resides with a model provider. Gartner says agentic AI puts $234 billion in enterprise SaaS spending at risk, precisely because operational learning risks remaining with providers rather than customers.

The DMA just accelerated both risks. If you built your enterprise mobile AI strategy around Gemini's exclusive Android integration, you have 12 months before that exclusivity ends in the EU — and regulatory contagion means similar rules are coming elsewhere. The UK's CMA has designated Google with strategic market status for both general search and Android, though it has not yet imposed equivalent interoperability requirements. When, not if, it does, the DMA's specification decisions will be the template.

The Security Argument Is Real — But Not the Way Google Frames It

Google's President of Global Affairs Kent Walker responded to the decisions on July 16 with two specific objections.

On Android: giving any qualifying third-party service real-time screen capture and cross-app execution capabilities without the existing manufacturer safeguard review creates "a meaningful attack surface." He pointed to a warning from ENISA, the EU's own cybersecurity agency, that "security fundamentals matter more than ever in the age of AI."

On search data: broader access would expose private user searches to "unfamiliar companies, without adequate anonymization of the data and without user knowledge or consent." The R Street Institute noted that the recipient list is not limited to European entities, meaning behavioral data from EU users — including data from American diplomats, military personnel, and government contractors traveling in Europe — could flow to companies outside EU data-protection jurisdiction.

These concerns are legitimate. The R Street Institute's July 15 analysis makes a specific structural argument: the DMA's Article 6(7) interoperability mandate is on a collision course with the EU's own Cyber Resilience Act, which requires companies to minimize attack surfaces, deliver secure-by-default products, and bear lifecycle liability for product security. The two obligations run in opposite directions. The Commission has not stated which takes precedence when they conflict.

For enterprise security teams, this creates a genuinely new threat model. As we covered with 1Password's AI identity crisis, non-human identities operating with persistent access already outnumber human ones in most enterprise environments. The DMA's forced interoperability now means enterprise security teams must evaluate not just the AI assistants they chose, but the AI assistants that might be running on the same devices with equivalent system-level permissions — because any qualifying assistant can claim those permissions.

The Competitive Landscape Just Changed

Yale economist Fiona Scott Morton, in a Bruegel working paper published July 1, offered the clearest assessment of what these decisions mean competitively. The specification, she argued, correctly identifies the four access points — invocation surfaces, contextual data, on-device actions, and system-level model resources — that determine whether a rival AI assistant can function as a genuine device-level service or merely another downloaded app.

If enforced as adopted, Scott Morton wrote, the decisions would "prevent the monopolization of AI services in Europe and eliminate the need for a long and ineffective antitrust case" to produce the same result.

The practical effect: OpenAI's ChatGPT, Anthropic's Claude, and Perplexity will gain the same Android integration capabilities that currently make Gemini the only real AI assistant on Android. Combined with access to Google's search data on FRAND terms, the structural moat that Google spent a decade building around Search and two years embedding into Android disappears in 12 months.

For enterprises evaluating AI assistant platforms, this is the most significant shift in competitive dynamics since OpenAI's ChatGPT Enterprise launch in 2023.

Framework #1: AI Platform Lock-In Risk Scorecard

Score your enterprise's exposure across five dimensions. Each dimension is rated 1 (low risk) to 5 (critical risk). A total score above 15 demands immediate action.

Dimension Score 1 (Low) Score 3 (Medium) Score 5 (Critical)
Data Portability All AI training data, prompts, and outputs exportable in standard formats Partial export; some proprietary formatting or vendor-specific embeddings Data locked in vendor-specific formats; no export API; retraining required to switch
API & Integration Dependency Standard APIs (REST/GraphQL); MCP-compatible; vendor-agnostic orchestration Mix of standard and proprietary APIs; some vendor-specific SDKs Deep OS-level integration (wake words, screen context, cross-app execution) tied to single vendor
Identity & Access Architecture AI assistant identities managed through enterprise IAM (Entra ID, Okta) Hybrid: some assistants in enterprise IAM, others use vendor-managed identity AI assistants use vendor-controlled identity; no enterprise visibility into permissions or audit logs
Regulatory Exposure No EU operations; no EU customer data; no EU-manufactured devices in fleet Some EU operations; partial GDPR exposure; mixed device fleet Significant EU workforce or customers; Android/iOS fleet deployed under DMA-designated platforms
Exit Cost Switching AI vendor requires <30 days; no workflow disruption 3-6 month migration; some workflow retraining; moderate cost 12+ month migration; custom integrations break; retraining workforce; >$500K switching cost

Scoring Guide:

  • 5-10: Low lock-in risk. Maintain monitoring posture.
  • 11-15: Moderate risk. Begin multi-vendor evaluation and data portability audit within 90 days.
  • 16-20: High risk. Initiate vendor diversification program. Review DMA compliance exposure.
  • 21-25: Critical risk. Your platform strategy is a single point of failure. Execute contingency plan before January 2027 data-sharing deadline.

How to use this: Score your current primary AI assistant platform. Then score each alternative you're evaluating. The gap between your current score and the best alternative is your migration incentive. If your current platform scores 18+ and an alternative scores 10, you have a model-agnostic architecture problem that regulation is about to make urgent.

Framework #2: DMA AI Compliance & Enterprise Action Timeline

This is not just for companies subject to the DMA. If you deploy AI on mobile devices, sell AI products into EU markets, or source AI infrastructure from DMA-designated gatekeepers, every date on this timeline affects your operations.

Date DMA Milestone Enterprise Action Required
July 16, 2026 Specification decisions adopted; enforceable immediately Audit current AI assistant deployments for single-vendor dependency on Android/iOS platform integration
January 2027 Google begins sharing anonymized search data with qualified AI chatbots Evaluate whether your enterprise search/RAG infrastructure can benefit from FRAND data access; assess competitive implications if rivals gain access
February 1, 2027 Google publishes draft Qualified AI Assistant Programme certification terms Review certification requirements; determine if your enterprise AI tools or partners qualify; begin security assessment of newly qualifying assistants
May 1, 2027 Final certification terms published; applications accepted Decide which AI assistants to certify/approve for enterprise fleet; update MDM policies; begin security testing
August 1, 2027 Android 18 ships with 10 of 11 interoperability features live Update enterprise device management to govern multi-assistant environments; revise acceptable-use policies; deploy monitoring for AI assistant privilege escalation
August 1, 2028 Android 19 adds concurrent wake-word detection (11th feature) Full multi-assistant parity live; finalize enterprise AI assistant governance framework

Critical enterprise actions before January 2027:

  1. Audit AI assistant dependencies. Map every AI assistant integration that relies on platform-specific capabilities (wake words, screen context, cross-app execution). Identify which capabilities become commoditized under the DMA.

  2. Assess regulatory contagion. The UK's CMA has designated Google for strategic market status but has not yet imposed interoperability requirements. Assume it will. Plan for equivalent rules in your top 5 markets by 2028.

  3. Evaluate FRAND data access. If you build enterprise AI products, determine whether your organization qualifies for Google search data under the genuine-economic-activity test (2 years trading, or <2 years with >€50M capital, plus 50K monthly EU users). The data sharing starts in six months.

  4. Update your threat model. With AI agents already 2.5x riskier than humans in production, forced interoperability means enterprise security teams must plan for AI assistants they didn't deploy gaining system-level permissions on their devices. Update your agentic control gap assessment accordingly.

  5. Build a multi-vendor AI assistant strategy. The era of "our enterprise runs on one AI assistant" is ending — not because of product quality, but because regulators are mandating choice. Model-agnostic architecture is no longer a best practice; it's becoming a compliance requirement.

The Bigger Pattern: AI Assistants Are Being Regulated Like Utilities

Step back and look at what happened in July 2026. The EU ordered AI assistant interoperability on Android. Apple is fighting the same battle on iOS. China's WAICO bloc of 29 nations is building its own AI governance framework. The U.S. Senate's AI AGENT Act proposes user-linked accountability and FTC registration for AI agents. AI governance gaps are widening faster than deployment, with only 12% of enterprises using a centralized platform to govern their AI agents despite 96% already running them in production.

The convergence is unmistakable. AI assistants are being reclassified from "applications you choose" to "infrastructure you must share." The regulatory logic is the same one that opened telecom networks, mandated browser choice screens, and forced payment interoperability: when a layer becomes essential enough that one company's control of it distorts competition, that layer gets pried open.

For enterprise AI leaders, the strategic question is no longer "which AI assistant do we pick?" It's "how do we architect for a world where the AI assistant layer is open, governed, and multi-vendor by default?"

The companies that built their AI strategies around exclusive platform integration have 12 months to adapt. The ones that built for interoperability from the start — with model-agnostic architectures, portable data pipelines, and vendor-neutral identity frameworks — just had their strategy validated by the European Commission.

The DMA didn't create the multi-vendor AI future. It made it mandatory.


Continue Reading

Share:
THE DAILY BRIEF
DMAEU AI RegulationGoogle AndroidAI Assistant InteroperabilityEnterprise Platform StrategyAI Vendor Lock-InGeminiDigital Markets ActAI GovernanceEnterprise Compliance
Your AI Platform Lock-In Expires in 12 Months

Two binding DMA decisions force Google to open 11 Android AI features to rivals and share search data with AI chatbots by January 2027. The EU just classified AI assistants as infrastructure — and every enterprise CIO building on platform-specific AI integration has 12 months before that exclusivity ends.

By Rajesh Beri·July 20, 2026·14 min read

By Rajesh Beri | July 20, 2026


On July 16, 2026, the European Commission did something no regulator has done before. It classified AI assistants as infrastructure — and issued binding orders to prove it means it.

Two specification decisions under the Digital Markets Act force Google to open 11 specific Android features to rival AI assistants — voice invocation, screen context, cross-app task execution, on-device models — and to share anonymized search ranking, query, click, and view data with competing search engines and AI chatbots on fair, reasonable, and non-discriminatory (FRAND) terms. Search data sharing starts January 2027. Android feature parity arrives with Android 18, by August 1, 2027 at the latest. Concurrent wake-word detection follows in Android 19, by August 1, 2028.

If you run enterprise AI on mobile devices, deploy AI assistants across your workforce, or sell AI products into European markets, these deadlines are now your deadlines. Every platform decision you make in the next 12 months has a regulatory dimension it didn't have two weeks ago.

This is not an antitrust curiosity. It is the first time a major regulatory body has drawn a line between "AI assistant as application" and "AI assistant as operating system layer" — and ruled that the operating system layer must be open. The implications for enterprise AI platform strategy are immediate and structural.

What the Decisions Actually Require

The detail in these decisions matters more than the headlines suggest. Bratby Law's analysis of the specification decisions provides the most granular breakdown of what Google must build.

Android AI Interoperability (Article 6(7) DMA — Case DMA.100220):

The Commission identified 11 specific features across four categories that currently give Gemini structural advantages over every other AI assistant on Android:

  1. Invocation surfaces. Gemini can be activated by wake word ("Hey Google"), long-press home button, and navigation handle. Rivals get none of these system-level triggers. Under the new order, any qualifying AI assistant can register its own wake word and claim the same entry points.

  2. Screen context and situational awareness. Gemini can read what's on the user's screen and use that context to answer questions. Third-party assistants are sandboxed. The order mandates equal access.

  3. Cross-app task execution. Gemini can send emails, order food, book taxis, and orchestrate tasks across applications through privileged API access. Rivals are confined to their own sandbox. The order requires equal API access for qualifying providers.

  4. Hardware and system model resources. Gemini gets scheduling priority and preferential access to on-device neural processing. The order mandates equal resource allocation.

Six of the 11 features are open to any qualifying third party. Five — including centralized on-device data access and agentic screen automation — are restricted to providers certified under a new Qualified AI Assistant Programme, for which Google must publish draft certification terms by February 1, 2027 and final terms by May 1, 2027.

Search Data Sharing (Article 6(11) DMA — Case DMA.100209):

This is the decision that should keep platform strategists up at night. Google must share anonymized ranking, query, click, and view data — the same data it uses internally to optimize Search — with eligible rivals on FRAND pricing terms, fixed for five years. The eligibility criteria explicitly include AI chatbots that provide search-engine functionality, subject to a genuine-economic-activity test: two years of trading (or under two years with over €50 million in capital) plus at least 50,000 monthly EU users.

The pricing structure is incremental cost-based, WACC-capped. SMEs always qualify for strict incremental-cost pricing. Very-large-scale beneficiaries — at gatekeeper-equivalent scale — can be charged up to Google Search's own operating margin.

The anonymization standard combines technical suppression of identifiers with contractual controls: a 13-month cap on data retention by recipients, a ban on re-identification attempts, and mandatory independent ISAE 3000 assurance before access and annually thereafter.

In plain English: OpenAI, Anthropic, Perplexity, and any qualified AI chatbot can now buy the same search intelligence that Google uses to train Gemini. Starting January 2027.

Apple Is Fighting the Same Battle — and Losing

Google is not the only platform under fire. Apple has been clashing with the Commission over parallel DMA requirements to open Siri AI to third-party competitors. Apple's response has been remarkably confrontational — the company argues that EU regulators rejected its proposals for introducing Siri AI while supporting third-party virtual assistants, and that the Commission's interpretation of the DMA would force Apple to allow third-party assistants access to private user data in ways that fundamentally compromise device security.

The Commission disagrees. Its position: when a company controls the operating system on billions of devices, and uses that control to give its own AI assistant capabilities that competitors cannot access, that is a gatekeeper behavior the DMA was designed to address.

For enterprise CIOs, the takeaway is identical regardless of which platform you deploy: the assumption that your AI assistant vendor controls the device layer is now a regulatory liability in the EU, and the precedent will spread.

Why Enterprise CIOs Should Care About a Consumer Ruling

The instinct will be to dismiss this as a consumer story. Android phones. Wake words. Booking taxis. That instinct is wrong.

Consider how enterprise AI actually reaches your workforce in 2026. Field service technicians use AI assistants on Android devices to pull up work orders. Sales teams use voice-activated AI to update CRM records between meetings. Healthcare workers use AI agents to query patient records hands-free. Logistics operators use on-device AI for real-time routing. Every one of these use cases runs on the same platform integration layer that the EU just forced open.

VentureBeat reported last week that 35% of enterprises identify vendor lock-in as the risk they fear most when AI control resides with a model provider. Gartner says agentic AI puts $234 billion in enterprise SaaS spending at risk, precisely because operational learning risks remaining with providers rather than customers.

The DMA just accelerated both risks. If you built your enterprise mobile AI strategy around Gemini's exclusive Android integration, you have 12 months before that exclusivity ends in the EU — and regulatory contagion means similar rules are coming elsewhere. The UK's CMA has designated Google with strategic market status for both general search and Android, though it has not yet imposed equivalent interoperability requirements. When, not if, it does, the DMA's specification decisions will be the template.

The Security Argument Is Real — But Not the Way Google Frames It

Google's President of Global Affairs Kent Walker responded to the decisions on July 16 with two specific objections.

On Android: giving any qualifying third-party service real-time screen capture and cross-app execution capabilities without the existing manufacturer safeguard review creates "a meaningful attack surface." He pointed to a warning from ENISA, the EU's own cybersecurity agency, that "security fundamentals matter more than ever in the age of AI."

On search data: broader access would expose private user searches to "unfamiliar companies, without adequate anonymization of the data and without user knowledge or consent." The R Street Institute noted that the recipient list is not limited to European entities, meaning behavioral data from EU users — including data from American diplomats, military personnel, and government contractors traveling in Europe — could flow to companies outside EU data-protection jurisdiction.

These concerns are legitimate. The R Street Institute's July 15 analysis makes a specific structural argument: the DMA's Article 6(7) interoperability mandate is on a collision course with the EU's own Cyber Resilience Act, which requires companies to minimize attack surfaces, deliver secure-by-default products, and bear lifecycle liability for product security. The two obligations run in opposite directions. The Commission has not stated which takes precedence when they conflict.

For enterprise security teams, this creates a genuinely new threat model. As we covered with 1Password's AI identity crisis, non-human identities operating with persistent access already outnumber human ones in most enterprise environments. The DMA's forced interoperability now means enterprise security teams must evaluate not just the AI assistants they chose, but the AI assistants that might be running on the same devices with equivalent system-level permissions — because any qualifying assistant can claim those permissions.

The Competitive Landscape Just Changed

Yale economist Fiona Scott Morton, in a Bruegel working paper published July 1, offered the clearest assessment of what these decisions mean competitively. The specification, she argued, correctly identifies the four access points — invocation surfaces, contextual data, on-device actions, and system-level model resources — that determine whether a rival AI assistant can function as a genuine device-level service or merely another downloaded app.

If enforced as adopted, Scott Morton wrote, the decisions would "prevent the monopolization of AI services in Europe and eliminate the need for a long and ineffective antitrust case" to produce the same result.

The practical effect: OpenAI's ChatGPT, Anthropic's Claude, and Perplexity will gain the same Android integration capabilities that currently make Gemini the only real AI assistant on Android. Combined with access to Google's search data on FRAND terms, the structural moat that Google spent a decade building around Search and two years embedding into Android disappears in 12 months.

For enterprises evaluating AI assistant platforms, this is the most significant shift in competitive dynamics since OpenAI's ChatGPT Enterprise launch in 2023.

Framework #1: AI Platform Lock-In Risk Scorecard

Score your enterprise's exposure across five dimensions. Each dimension is rated 1 (low risk) to 5 (critical risk). A total score above 15 demands immediate action.

Dimension Score 1 (Low) Score 3 (Medium) Score 5 (Critical)
Data Portability All AI training data, prompts, and outputs exportable in standard formats Partial export; some proprietary formatting or vendor-specific embeddings Data locked in vendor-specific formats; no export API; retraining required to switch
API & Integration Dependency Standard APIs (REST/GraphQL); MCP-compatible; vendor-agnostic orchestration Mix of standard and proprietary APIs; some vendor-specific SDKs Deep OS-level integration (wake words, screen context, cross-app execution) tied to single vendor
Identity & Access Architecture AI assistant identities managed through enterprise IAM (Entra ID, Okta) Hybrid: some assistants in enterprise IAM, others use vendor-managed identity AI assistants use vendor-controlled identity; no enterprise visibility into permissions or audit logs
Regulatory Exposure No EU operations; no EU customer data; no EU-manufactured devices in fleet Some EU operations; partial GDPR exposure; mixed device fleet Significant EU workforce or customers; Android/iOS fleet deployed under DMA-designated platforms
Exit Cost Switching AI vendor requires <30 days; no workflow disruption 3-6 month migration; some workflow retraining; moderate cost 12+ month migration; custom integrations break; retraining workforce; >$500K switching cost

Scoring Guide:

  • 5-10: Low lock-in risk. Maintain monitoring posture.
  • 11-15: Moderate risk. Begin multi-vendor evaluation and data portability audit within 90 days.
  • 16-20: High risk. Initiate vendor diversification program. Review DMA compliance exposure.
  • 21-25: Critical risk. Your platform strategy is a single point of failure. Execute contingency plan before January 2027 data-sharing deadline.

How to use this: Score your current primary AI assistant platform. Then score each alternative you're evaluating. The gap between your current score and the best alternative is your migration incentive. If your current platform scores 18+ and an alternative scores 10, you have a model-agnostic architecture problem that regulation is about to make urgent.

Framework #2: DMA AI Compliance & Enterprise Action Timeline

This is not just for companies subject to the DMA. If you deploy AI on mobile devices, sell AI products into EU markets, or source AI infrastructure from DMA-designated gatekeepers, every date on this timeline affects your operations.

Date DMA Milestone Enterprise Action Required
July 16, 2026 Specification decisions adopted; enforceable immediately Audit current AI assistant deployments for single-vendor dependency on Android/iOS platform integration
January 2027 Google begins sharing anonymized search data with qualified AI chatbots Evaluate whether your enterprise search/RAG infrastructure can benefit from FRAND data access; assess competitive implications if rivals gain access
February 1, 2027 Google publishes draft Qualified AI Assistant Programme certification terms Review certification requirements; determine if your enterprise AI tools or partners qualify; begin security assessment of newly qualifying assistants
May 1, 2027 Final certification terms published; applications accepted Decide which AI assistants to certify/approve for enterprise fleet; update MDM policies; begin security testing
August 1, 2027 Android 18 ships with 10 of 11 interoperability features live Update enterprise device management to govern multi-assistant environments; revise acceptable-use policies; deploy monitoring for AI assistant privilege escalation
August 1, 2028 Android 19 adds concurrent wake-word detection (11th feature) Full multi-assistant parity live; finalize enterprise AI assistant governance framework

Critical enterprise actions before January 2027:

  1. Audit AI assistant dependencies. Map every AI assistant integration that relies on platform-specific capabilities (wake words, screen context, cross-app execution). Identify which capabilities become commoditized under the DMA.

  2. Assess regulatory contagion. The UK's CMA has designated Google for strategic market status but has not yet imposed interoperability requirements. Assume it will. Plan for equivalent rules in your top 5 markets by 2028.

  3. Evaluate FRAND data access. If you build enterprise AI products, determine whether your organization qualifies for Google search data under the genuine-economic-activity test (2 years trading, or <2 years with >€50M capital, plus 50K monthly EU users). The data sharing starts in six months.

  4. Update your threat model. With AI agents already 2.5x riskier than humans in production, forced interoperability means enterprise security teams must plan for AI assistants they didn't deploy gaining system-level permissions on their devices. Update your agentic control gap assessment accordingly.

  5. Build a multi-vendor AI assistant strategy. The era of "our enterprise runs on one AI assistant" is ending — not because of product quality, but because regulators are mandating choice. Model-agnostic architecture is no longer a best practice; it's becoming a compliance requirement.

The Bigger Pattern: AI Assistants Are Being Regulated Like Utilities

Step back and look at what happened in July 2026. The EU ordered AI assistant interoperability on Android. Apple is fighting the same battle on iOS. China's WAICO bloc of 29 nations is building its own AI governance framework. The U.S. Senate's AI AGENT Act proposes user-linked accountability and FTC registration for AI agents. AI governance gaps are widening faster than deployment, with only 12% of enterprises using a centralized platform to govern their AI agents despite 96% already running them in production.

The convergence is unmistakable. AI assistants are being reclassified from "applications you choose" to "infrastructure you must share." The regulatory logic is the same one that opened telecom networks, mandated browser choice screens, and forced payment interoperability: when a layer becomes essential enough that one company's control of it distorts competition, that layer gets pried open.

For enterprise AI leaders, the strategic question is no longer "which AI assistant do we pick?" It's "how do we architect for a world where the AI assistant layer is open, governed, and multi-vendor by default?"

The companies that built their AI strategies around exclusive platform integration have 12 months to adapt. The ones that built for interoperability from the start — with model-agnostic architectures, portable data pipelines, and vendor-neutral identity frameworks — just had their strategy validated by the European Commission.

The DMA didn't create the multi-vendor AI future. It made it mandatory.


Continue Reading

THE DAILY BRIEF

Enterprise AI insights for technology and business leaders, twice weekly.

beri.net

Subscribe at beri.net/subscribe for twice-weekly AI insights delivered to your inbox.

LinkedIn: linkedin.com/in/rberi  |  X: x.com/rajeshberi

© 2026 Rajesh Beri. All rights reserved.

Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe

Latest Articles

View All →