Google filed two actions at the EU General Court in Luxembourg on 29 September 2026, challenging the European Commission's July decisions under the Digital Markets Act (DMA). Filing does not pause the orders. The January 2027 and August 2027 deadlines remain in force unless the court intervenes, according to TNW's report, which drew on Reuters.
What the Commission ordered
On 16 July 2026 the Commission issued two binding specification measures. They are not fines. They spell out, step by step, how Google must comply with obligations it already has under the DMA.
The first measure covers Android. Rival AI assistants must get access equivalent to Gemini's for 11 phone features by August 2027. These include voice activation and the ability to act inside apps. The Commission's own examples are booking a taxi on a user's behalf and asking an assistant about a place the user recently visited.
The second measure covers search. From January 2027, Google must share anonymised data on what people search for and click on with eligible rival search engines, including AI chatbots that offer search. The Commission describes this as data "that only Google Search can collect at scale." According to LexisNexis's summary of the decisions, the sharing operates under a multi-layered anonymisation framework developed with the European Data Protection Board.
The strongest case for the Commission
The case for these orders is serious. Search quality depends heavily on query and click data. A rival cannot learn which results satisfy users without a comparable feedback loop, and only the incumbent has one at scale. On Android, a default position and privileged system access are exactly the kind of gatekeeper advantage the DMA was written to address. If a rival assistant cannot be summoned by voice or cannot act inside apps, it competes at a permanent handicap that better engineering cannot fix. Ex-ante rules exist because a conventional antitrust case takes years, and by then the market may have tipped. The Commission also frames the measures as pro-innovation. Executive Vice-President Henna Virkkunen said they will "support innovation and diversity in the European Union."
Google's objection
Google's argument rests on two claims. Oliver Bethell, its senior director of competition, said the search rules would force Google to share search histories that are not fully anonymised. "Mandating we share these personal queries without adequate safeguards would cause irreversible harm to user privacy," he said. Google also argues that opening 11 Android features to third parties could weaken Android's security.
These are not frivolous points. Search queries are among the most revealing data people generate, and long-tail queries can identify individuals even after names are removed. Deep system-level access for third-party assistants also widens the attack surface of a device that holds banking, health and messaging data.
Where the evidence points
The Commission answers that its privacy safeguards were designed with expert consultation and that Google may refuse data access to companies that pose security or privacy threats. DuckDuckGo, a privacy-focused rival, has backed the regulator, arguing that the anonymisation rules are sound. That matters, because a privacy-first search company has little incentive to endorse a weak design.
This is the right frame for the case. Whether the anonymisation holds up is an empirical, technical question, and the court should test it on evidence. Privacy and security are legitimate constraints, but they are also the most convenient argument any incumbent can make against any access remedy. The claim should be judged on the measures' actual design, including the refusal right and the EDPB's involvement, and not treated as decisive because it sounds protective.
A proportionate path
From a pro-innovation view, the orders have real merits and real risks.
- Merit: they are targeted at specific features and a specific data set, not a broad structural remedy. They also keep Google's right to refuse access to unsafe recipients.
- Merit: staged deadlines, January 2027 for data and August 2027 for Android, give engineers time to build and test safeguards.
- Risk: anonymisation is a moving target. Re-identification techniques improve, so the framework needs periodic review, and the Commission should commit to one.
- Risk: eligibility rules for recipients decide whether this helps real competitors or lets thinly resourced entrants harvest data. Clear, published vetting criteria protect both users and Google.
- Risk: system-level access needs a defined security baseline. A rival assistant that is easy to compromise damages the whole Android ecosystem, including the rivals themselves.
The litigation is a proper use of the rule of law. A gatekeeper is entitled to ask the General Court whether a measure is proportionate, and the Commission is right to defend it. The strongest outcome would be for both to engage on evidence: independent testing of the anonymisation, publication of the security baseline, and a review clause. If the safeguards are as robust as the Commission says, they should survive scrutiny. If they are not, users are better served by finding out before January than after.
Until the court rules, the deadlines run. Google must build compliance while it litigates, and rivals must prepare to receive data responsibly. That is a workable tension, provided regulators treat privacy as a design requirement and not as an obstacle.