The European Commission is preparing to announce new regulations targeting Google next month, and the company isn’t happy about it. But Google’s argument isn’t the usual “don’t regulate us” — it’s that the proposed changes could create serious security and privacy risks for users.
Heather Adkins, Google’s VP of security engineering, laid out the concerns in an interview with Wired. The EU has two main proposals: first, force Google to let users integrate alternative AI models on Android with the same system-level access as Gemini. Second, require Google to share anonymized search data with competitors.
Adkins warned that the first change could lead to a surge in fraud on Android devices in the EU. “If implemented as described today, I think within a short period of time on Android, we’d see a significant increase in fraud in the EU,” she said. The timeline she suggested? Weeks, not months.
The EU’s intent is healthy enough — rein in Big Tech dominance and give competitors a fair shot. But Google’s point has merit: opening up system-level access to third-party AI models on billions of devices introduces a massive new attack surface. Not every AI company has Google’s security infrastructure.
On the data-sharing front, the risks are more nuanced. Anonymized search data sounds harmless, but re-identification is a well-documented problem. The more copies of that data floating around, the harder it gets to keep it truly anonymous.
It’s a rare case where a company’s competitive interests and genuine security concerns actually align. Whether that means the regulations are wrong or just poorly designed is the real debate.
