What happened

On 16 July the European Commission issued two legally binding specification decisions against Google. One requires it to open anonymised Google Search data to third parties. The other requires Android to give competing AI assistants the system-level access that in practice only Gemini has had — including waking a rival assistant by voice and letting an AI agent act inside apps on the user’s behalf.

The list of who can receive that search data is wider than most people assume. It covers traditional search engines, but AI chatbots with a search function are on it too, and what Google has to hand over is the same data it uses to improve its own search product, priced by a set formula, through a transparent application process. The clock runs in two stages: search data sharing starts in January 2027, and the Android changes are expected to reach users by July 2027.

Two things are worth getting right. These decisions are not a fine, and they do not find that Google broke the law — they are specification decisions, which tell Google what compliance is supposed to look like, and they can still be overturned on judicial review. Google is openly against them: president of global affairs Kent Walker said they “risk undermining vital privacy and security guardrails for millions of Europeans,” though the company has not committed to an appeal.

Why it matters to you

Block one very natural assumption first: more entry points does not mean more visibility for you.

What Google hands over is behavioural data — anonymised queries, results and related metrics. That is a snapshot of who is getting clicked right now. It carries no understanding of who a brand is, what it does, or how it relates to everyone else in the category. So the first thing any recipient will do with it is carry Google’s existing order across. The terms you cannot break into on Google are the terms you will not break into on a new surface either; the only difference is that the same report card now gets copied several times.

Put the last month side by side and it reads clearly. The UK order gave publishers the right to opt out of AI Overviews; this one widens the field of entry points. Regulators can redistribute data and permissions. They cannot redistribute what an AI understands about you — that still gets built out of your own site, your entity information, and what third parties write about you. Between the two orders, not one line addresses whether you get cited.

The jurisdiction is worth stating plainly too: this applies to the European market, and brands outside it are not under the umbrella. But the AI services collecting that data mostly run globally, so a spillover is a reasonable inference, not a promise. Nobody can give you a date; anyone offering you a guaranteed timeline is selling something.

The countdown is real, though. January 2027 is more than a year out, and that window is the time you still have to change the shape that gets copied later. Once the data moves and more surfaces use it as their opening position, the impression you need to fix is no longer one search engine’s.

Should you act now

Don’t go looking for a way into that data pool — it is opened to qualifying service providers by application, you cannot get in, and you don’t need to. What the order means for you is narrower than that: it puts an expiry date on the assumption that keeping Google happy is the same as keeping your visibility.

The work is the same basic thing it was before: check which sources an AI actually draws on when it answers questions in your industry, and whether you are among them. That question is untouched by how the regulators rule, and it does not improve on its own as entry points multiply — more surfaces just means more places to watch, and each one is another place you have to re-check whether you have dropped out.

If you want to know how AI describes your brand right now, and whether it treats you as a source, we can take a look first.