EU forces Google to share Search data with rival AI assistants

July 17 roundup: first EU DMA AI ruling, Kimi K3 at Sonnet pricing, Germany puts AI Overviews under media law, Oracle near junk, 1Password for Claude.

Top Stories

EU Commission forces Google to share anonymised Search data with rival AI assistants

The European Commission issued two binding decisions on July 16, 2026 under the Digital Markets Act, the first time any regulator has put AI assistants and Search-data sharing on the same binding clock. Google must let Android users pick a rival assistant as default and activate it by voice at parity with Gemini, and the assistant must be able to act inside third-party apps (booking taxis, suggesting chat replies).

The second decision is the structural privacy story: Google must share the same anonymised Search data it uses to train its own models with rival search engines and AI chatbots, in groups of 1,000+ users, with rare or sensitive records suppressed. Only vetted firms with stated plans to improve Search may receive the data; independent audits apply; Google retains a security veto over what it shares. Compliance deadlines are July 2027 for the AI assistant rules and January 2027 for the Search-data sharing. Non-compliance fines reach up to 10% of global turnover.

Commission tech chief Henna Virkkunen said the Commission hopes “to see emerging alternatives to Google Search and Google’s AI services, such as Gemini.” Google’s Kent Walker warned the orders risk “undermining vital privacy and security guardrails for millions of Europeans.” The data-sharing clause dictates what anonymised Search data flows out of Google and into the training pipelines of every rival AI assistant in the EU.

Kimi K3 (Moonshot AI) lands at Claude Sonnet 5 pricing, 2.8T parameters, open weights July 27

Moonshot AI released Kimi K3 on July 16: a mixture-of-experts model with 896 experts (16 active per token), 2.8T parameters, 1M-token context, native image and video processing, and a new Kimi Delta Attention mechanism that The Decoder reports delivers up to 6.3x faster decoding on million-token inputs. On the Artificial Analysis Intelligence Index, K3 scores 57, just behind Claude Fable 5 (60) and GPT-5.6 Sol (59), and ahead of Claude Opus 4.8 (56).

API pricing is $0.30 per million cache-hit input / $3.00 cache-miss / $15.00 output, identical to Claude Sonnet 5 and roughly half of GPT-5.6 Sol ($5/$30) and Fable 5 ($10/$50). Simon Willison called it “the most expensive model released by a Chinese AI lab to date,” noting the jump from K2.6’s $0.95/$4. Per-task cost on the Intelligence Index is about $0.94, comparable to GPT-5.6 Sol ($1.04) and roughly half of Opus 4.8 ($1.80), but ~24x more than DeepSeek V4 Pro ($0.04).

Two caveats: hallucination rate climbed from 39% (K2.6) to 51% on K3, and the open-weights drop is expected by July 27. Live now on kimi.com, the iOS/Android/HarmonyOS apps, Kimi Code, and OpenRouter as moonshotai/kimi-k3. The “super-cheap Chinese AI” era is over for Moonshot at the frontier.

Germany puts Google AI Overviews and Perplexity under media law in first-of-its-kind ruling

Germany’s Commission for Licensing and Supervision (ZAK, chaired by Dr. Thorsten Schmiege) issued the first rulings classifying AI search engines and chatbots as content providers under Section 109 of the State Media Treaty. Targets: Google (AI Overviews) and Perplexity.

The specific accusations: AI Overviews get prime placement above traditional links, violating non-discrimination rules; Perplexity lacks a designated representative in Germany and transparency disclosures. The legal basis is the Digital Services Act’s liability shield does not apply because AI-generated responses are the providers’ own content, not redistributed third-party material. The ruling complements an earlier Munich court decision that already held Google liable for false claims in AI Overviews. Companies have one month to appeal; rulings are immediately enforceable. Google’s response was a “Preferred Sources” feature it can frame as user choice.

S&P cuts Oracle to one notch above junk as $117B AI data-centre debt stacks up

S&P cut Oracle to BBB- on July 9, 2026; shares fell nearly 6% the next day. Oracle has $117B in outstanding debt (the second-largest non-financial issuer in the Bloomberg US Corporate Bond Index after Amazon). Free cash flow was nearly -$24B in the fiscal year ended May 31; S&P projects the deficit widening to -$42B. Capex was more than $55B on data centres last fiscal year; Oracle plans to raise another $40B this year ($20B in stock sales).

Roughly half of $638B in remaining performance obligations is tied to OpenAI. Ten-year bonds now yield about 6.5%, above the BBB index average and approaching BB (junk) range. Cloud revenue grew 93% last quarter. Industry context: hyperscalers plan up to $725B in AI spending this year, and Big Tech AI debt has hit $350B. The Oracle downgrade is a canary on what happens when AI capex outruns cash flow.

Google delays next Gemini Pro because coding misses internal goals

A late-June data refresh meant to improve coding produced “disappointing” results, pushing the upgrade past Google’s May developer conference, per 10 current and former Google employees cited by Bloomberg. OpenAI and Meta have shipped models that beat Google on code generation. Alphabet shares fell more than 3% on the news.

Internal context: Google Cloud, DeepMind, and Android are each building competing AI coding tools; Chief AI Architect Koray Kavukcuoglu is consolidating them; Sebastian Borgeaud leads a new DeepMind team. Google claims 75% of its code is now AI-generated under the internal “Antigravity” platform. A Google spokesperson said the company is “shipping quickly across a wide range of models” and is testing the upgraded Pro and a new Flash model.

1Password launches a Claude integration where the AI never sees the password

1Password’s “1Password for Claude” browser extension uses a zero-exposure architecture: the user receives a prompt explaining which credential is requested and why, then approves via biometrics before the secret is injected into the page. Claude never sees the vault item, password, or one-time code; access ends when the task completes. After autofill the extension checks whether secrets were exposed on the page and clears filled values if submission fails.

Agentic Mode in the 1Password browser extension automatically locks the vault when a compatible AI agent takes control, and works with agents other than Claude. CTO Nancy Wang framed the design as letting “a user give an agent permission to use a credential without letting the agent see it.” Mac-only at launch; payment cards and identity support are planned. This is a direct privacy upgrade over the credential-leak prompt injection patterns we have covered in AI browsers.

Double neural bypass BCI restores movement and touch in a paralysed man

Feinstein Institutes’ system combines a brain-computer interface, AI decoder, and electrical stimulation of the spinal cord and brain, published in Nature Medicine. Participant Keith Thomas, paralysed from the chest down since a 2020 diving accident, regained the ability to feed himself and drink from a cup with his own hand. Over 35 weeks his right arm grew 86% stronger and his left 62% stronger. After about 25 weeks of “cortical mirroring” he regained feeling in a wrist that had been numb since the injury.

Gains persisted more than two years after stimulation stopped. Five microelectrode arrays were implanted in a 15-hour surgery; the AI decoder held 84.6% accuracy over five months without retraining. Larger trials are planned, including stroke. One of the few BCI stories with multi-year durability data.

Google Vids adds personal AI avatars and Gemini Omni, biometric data on the table

Google Vids now lets users star in their own AI videos, powered by Gemini Omni for prompt-driven video generation. Personal avatars are created by uploading a selfie and a short voice recording, are tied to the user’s Google account, and carry an invisible SynthID watermark. Avatars are limited to users 18+ in certain regions and are available to Google AI Pro and Ultra subscribers and Workspace business customers (TechCrunch).

The privacy beat is the avatar: capturing and storing your likeness and voice inside Workspace is a new biometric data-handling surface, on top of the existing personal-data questions every generative video tool raises.

Quick Hits

  • OpenAI Codex Micro controller ($230): Co-developed with keyboard maker Work Louder, the controller pairs a joystick (code review, debug, refactor workflows) with a rotary dial that sets reasoning level. RGB-lit top keys show agent status: thinking, working, waiting, done. Bluetooth or USB-C, Mac and Windows. Currently out of stock.

  • Roblox Build launches July 28 in New Zealand: A new mobile tab turns text prompts into playable games without code, generating mechanics, environment, characters, sound, and visual style. Age-verified users 9+ can play; 16+ can publish globally. Public alpha first in NZ; TechCrunch notes Roblox will rank games by player retention to avoid AI-generated low-quality content.

  • NotebookLM becomes Gemini Notebook, adds cloud computers: Now at ~30M users and 600K organisations. Each notebook ships with its own cloud computer that writes and runs code, initially for AI Ultra and Workspace customers. Google says the new system wins 65% of internal comparisons vs its predecessor (78.2% on advanced web research). The Decoder.

  • Google Search AI Mode opens to Instacart, Canva, YouTube Music: This week in the US, with more partners to follow. Use cases include adding ingredients to an Instacart cart from a grocery list and pulling Canva templates from Search. Google blog.

  • Sakana Fugu adds Nvidia Nemotron to test “collective intelligence”: Fugu is an orchestrator that picks and combines multiple LLMs per task. Nvidia’s open Nemotron 3 family slots in as specialists for coding, tool calling, and instruction following. No new benchmark numbers were disclosed.

  • Gemma 4 gets a stealth update under the same version name: Fixes tool-calling bugs and truncated responses, speeds up prompt processing 25-70% on Nvidia Hopper GPUs via Flash Attention 4. The “Gemma 4” label did not change, which broke agents pinning to a specific version.

  • xAI open-sources “Grok Build” after silent-upload data breach: Musk pledged to delete all uploaded user data; xAI released the 844,530-line Rust codebase under Apache 2.0 on GitHub. Data storage has been off by default since July 12.

  • EFF and Article 19 file DSA trusted-flagger comments: They support the goal but warn against over-removal of lawful speech. Recommendations: caution with cross-border legality, no trusted-flagger status for law enforcement, shield civil society from retaliation, and treat platform design (recommender systems) as part of systemic-risk evaluation. EFF.

  • NVIDIA Nemotron 3 Embed tops RTEB: The 8B-BF16 model ranks #1 overall on the RTEB retrieval benchmark at 78.5%, with the 1B-BF16 variant scoring 72.4%. Use cases span multilingual, code, agentic, and long-context retrieval. Hugging Face blog.

  • DoorDash ships “dd-cli”: A command-line tool for ordering food, explicitly designed for developers and AI agents. Limited beta for US/Canadian macOS developers via waitlist. TechCrunch.

Worth Watching

The EU’s DMA deadlines are now the timeline that matters. January 2027 is when Google must start sharing anonymised Search data with vetted rivals; July 2027 is when rival AI assistants must get Gemini parity on Android. That gap is when Google will test the “vetted firm” gate, the 1,000-user grouping, and its security veto, and when every rival assistant in Europe will either get real Search-data or be told why not. Worth tracking which rivals the Commission names as vetted.

The Germany ZAK ruling has a one-month appeal window. If Google or Perplexity pushes back, expect the first major test of whether AI-generated answers count as “providers’ own content” outside the DSA liability shield. A Munich court already held Google liable for false claims in AI Overviews; the ZAK ruling puts media-law teeth behind the same idea.

Kimi K3’s open-weights drop on July 27 sets the next comparison point in the open-weight LLM race, with DeepSeek V4 Pro still the price benchmark at roughly $0.04 per Intelligence Index task. The “super-cheap Chinese AI” framing will be tested on day one: if K3 weights run on consumer GPUs in acceptable quantisations, the open-weights story holds; if they need data-centre hardware, the story is just about API pricing.