Google's most senior security officials are sounding the alarm over European Union plans that would force the company to share search data and open up Android — warning that the proposals, as written, could expose billions of people's search queries to hackers and trigger a surge in fraud within weeks of implementation. The warnings come ahead of a July 27 deadline when European Commission officials are expected to announce final decisions in two landmark Digital Markets Act cases covering Google Search and Android interoperability.
At the center of the Search dispute: the EU's plan to give rival search engines access to 'any query input' people type into Google — essentially their raw search terms — along with click data and ranking signals. Google's privacy engineers claim they proved internally that proposed anonymization techniques can be defeated in under two hours, identifying specific users from supposedly anonymous data. Heather Adkins, Google's VP of security engineering and a founding member of its security team, argues that once data leaves Google's control, the company has no ability to secure it. She warns that small European startups receiving the data would be prime hacking targets and says large language models make de-anonymization even easier for bad actors.
For Android, the EU wants Google to allow third-party AI services to use wake words and interact with installed apps and user data — effectively giving outside AI agents deep access to phones and tablets. Eugene Liderman, director of Google's Android security team, warns that expanding access to microphone, camera, and on-screen permissions would undermine core mobile security practices. He predicts fraud could rise significantly in the EU within weeks of implementation. Apple has taken the unusual step of backing Google's position on the operating system access concerns.
Not everyone is buying Google's case. DuckDuckGo's chief policy officer Kamyl Bazbaz argues the legal standard only requires reducing reidentification risk to an insignificant level — not eliminating it entirely — and that the Commission's framework already does that. Alissa Cooper of the Knight-Georgetown Institute describes the Commission's technical and contractual regime as 'very robust' and says independent experts could validate the data's anonymization properties. Privacy search engine Brave acknowledges the current proposals may not produce truly anonymous data, but argues the answer is additional regulatory constraints on Google, not abandoning data sharing altogether.
The stakes are enormous: Google controls roughly 90% of the global search market, making it the only search engine subject to DMA search-sharing rules. The dataset at issue — years of raw query data that no competitor has ever had access to — could fundamentally reshape competition in AI and search. With a July deadline looming, the battle lines pit Google's security warnings against competitors and academics who argue those warnings are self-interested and technically overstated.
Gist is a free AI reader for your browser, iPhone, and Android. Get concise summaries and key takeaways from any article or podcast.
Get Gist — Free