JC JC Mobile App Studio
JC

On-device AI , Friday July 17, 2026

On-device AI was supposed to mean fewer apps listening. The EU's new Android order complicates that.

This week's Digital Markets Act order forces Google to open system-level on-device models, the mic, and the camera to rival AI assistants. What that actually does to the privacy pitch. Verified July 17, 2026.

A smartphone screen glowing softly in a dim room, held in one hand, a gentle AI orb icon inside a chat bubble.
Local processing was never the same thing as fewer parties involved.

The whole pitch of on-device AI has been simple: your data doesn't have to leave your phone to get smart features. No round trip to a server, no third party's cloud holding a copy of what you asked it. It's a real, meaningful privacy improvement over cloud AI, and it's the reason this studio builds that way. But "processing stays local" and "fewer parties have access to your phone" are two different promises, and this week is a good example of why.

The Commission's order requires Google to grant rival AI assistants unrestricted access to six Android features, including the microphone, the camera, screen contents, always-on hotword detection, and system-level on-device models themselves, with no certification barrier. That last one is the interesting part for this topic specifically: it's not just "an app can ask the mic for input," it's a rival assistant getting equivalent access to the on-device intelligence layer that used to be Google's alone. (The Hacker News)

Once a second, third, or fourth assistant is granted device-level mic and camera access as a matter of regulatory mandate, the number of parties with that access grows even though each one is still technically "processing on-device." The privacy math isn't just about where the computation happens, it's about how many companies now have standing permission to that computation in the first place. Concurrent hotword detection, more than one assistant listening for its wake word at once, is explicitly part of this order and doesn't even land until 2028. (The Hacker News)

Google's own argument against the order cited a real, demonstrated vulnerability class, notification-based prompt injection attacks against Gemini, as evidence that more assistants with more access means more attack surface. The Commission's response was a set of safeguards: user consent requirements, encryption standards, and independent audits of data recipients. Whether those hold up under real-world abuse is something we'll only know once this actually ships in Android 18, not before.

The honest version of on-device AI's privacy pitch was never "nobody but you ever has access," it was "your data doesn't have to travel to get the feature." That's still true, and it's still worth choosing. But this week is a useful reminder that the number of parties standing at the door matters as much as where the room is. It's part of why this studio's apps keep the AI and the data inside one app on one phone, with no third assistant granted a standing invitation.

General information on a developing regulatory story, not a security guarantee. See also what it takes for a phone to run on-device AI at all. You can see what this studio builds at jcmobileappstudio.com/apps.

JC

Written by Josuam Collazo

A lifelong tech enthusiast in his mid-thirties who builds privacy-first iOS apps in his spare time and writes plain-language pieces on tech, money, on-device AI, and your rights at work, drawn from his own experience at work and in life. More about Josuam

More from the blog

Plain-language writing on tech, workers' rights, investing, and on-device AI.

Read the blog

Comments

Be kind and stay on topic. Comments are reviewed before they appear.

Contact

Get in touch.

Beta access, app ideas, bug reports, or partnership questions, the inbox is open.

Support available in English and Espanol.