The European Commission’s New Proposed Regulations Want to Re-Engineer Your Smartphone

Aei.org
1 juin 2026, 09:25

Texte de la source originale

The smartphone is a meticulously engineered security architecture, and the European Commission’s Draft Measures (DMs) under the Digital Markets Act (DMA) now threaten its integrity. Apple’s public response to the Commission’s Alphabet proceeding warns that these measures constitute a “large-scale security and privacy experiment” conducted on European users, challenging hardware and software engineering paradigms that have taken years to develop. The Commission is attempting to replace decades of specialized engineering judgment with a regulatory framework developed in just three months of analysis. Most significantly, the DMs would effectively dismantle the application sandbox—the foundational mobile security design that isolates apps from one another so that a breach in one cannot compromise the entire device. The Commission’s measures would require that apps be permitted to execute ‘cross-app actions’ and mimic user interactions without the user’s direct permission. By forcing the operating system to allow one app to control another, the Commission is enabling what security researchers call ‘indirect prompt injection,’ in which a malicious actor manipulates an AI agent via hidden instructions to perform unauthorized actions. In the expanding era of agentic AI, this risk is especially acute: Unlike conventional software, AI agents can dynamically alter their behavior in ways developers did not anticipate. Real-world incidents illustrate the stakes. The ‘Reprompt’ vulnerability in Microsoft Copilot showed how a single malicious email could hijack an AI agent to steal personal data. In separate incidents, an AI agent autonomously deleted a director’s entire email inbox and wiped a company’s production database in nine seconds. Mandatory cross-app access would expose every device to risks of this magnitude. The Draft Measures also exacerbate the “listening problem” by introducing ‘concurrent wake word invocation,’ which would require operating systems to support multiple competing third-party voice models running simultaneously. Critically, the DMs would allow third-party apps, not the OS, to determine when audio recording stops. The European Data Protection Board has already warned that expanding third-party access to the voice channel ‘materially compounds’ the risk of unauthorized device access. The DMs would codify that risk. Another issue is the User Interface “Ghost in the Machine” security concern regarding overlay attacks and phishing, stemming from the Commission mandates that require the OS to support “overlay functionalities” that allow one app to render content directly over another. Criminals have already exploited these techniques to bypass encryption in apps such as WhatsApp and Telegram, harvesting users’ banking credentials across Europe. Making overlay access a platform-wide requirement does not foster innovation; it mandates a well-documented attack surface. Beyond software vulnerabilities, there is the matter of physical device performance. Opening deep system integrations to unvetted third parties on a nominally ‘non-discriminatory’ basis creates real hardware risk: when multiple, uncoordinated AI models compete for a device’s neural processing resources without OS-level coordination, the result is degraded performance, instability, and accelerated hardware wear. The Commission’s framework treats the ‘Allow’ button as a sufficient safety backstop, but informed consent is not a security strategy. Empirical evidence shows that 90 percent of users grant excessive app permissions, even when an app incorrectly labels data access as ‘required.’ Relying on user consent to replace system-level protections shifts the security burden from engineers to distracted individuals. That is not empowerment; it is an abdication of responsibility. The DMs also create a direct conflict with the Commission’s regulatory framework. Both the EU AI Act and the Cyber Resilience Act legally require platform providers to reduce attack surfaces and mitigate systemic security risks. The DMs require the opposite, mandating that platforms expand access and weaken the protections those laws were designed to enforce. The Commission cannot simultaneously require platforms to comply with cybersecurity law and dismantle the mechanisms that enable compliance. A viable alternative exists: the ‘Trusted OS Agent’ model. Rather than granting third-party apps direct access to microphones, screens, or core system functions, the OS would serve as a secure intermediary, translating requests into system actions within a protected trust boundary. This approach preserves the security principle of ‘least privilege’ while enabling the AI-driven innovation the Commission says it wants to promote. The Commission’s current path poses a foundational question for tech policy: should the operating system remain a steward of users’ private lives, or will mandated ‘openness’ erode the defenses that make our most personal devices trustworthy? As agentic AI ecosystems mature, that question becomes more consequential, not less. Brussels should be reinforcing these security foundations, not legislating their removal. The post The European Commission’s New Proposed Regulations Want to Re-Engineer Your Smartphone appeared first on American Enterprise Institute - AEI .