Of course, General AI is a pipe dream, told to Investors to fluff them into pumping ever more billions into the Artificial Intelligence industry. (Don’t ask me – I’ve been well and truly left behind because I didn’t embrace the metaverse. Or NFTs.)
Two days ago, Google announced Google Search: Introducing AI Mode in the UK, ahead of the EU and its pesky laws and regulations (it’s currently available in UK, USA and India).
As far as I can tell, the only reason for “AI” in search is to keep people on a Google domain, rather than send them to where the search engine actually found the information that its AI regurgitates. If you think it’s not fair for Google to hoover up other people’s content without sending visitors their way, and thereby starving them of search revenue, you wouldn’t be the only one.
“a site previously ranked first in a search result could lose about 79% of its traffic for that query if results were delivered below an AI overview. The study also found that links to YouTube – owned by Google’s parent company Alphabet – were more prominent compared with the normal search result system. The research has been submitted as part of a legal complaint to the UK’s competition watchdog about the impact of Google AI Overviews
Google’s core search engine service is misusing web content for Google’s AI Overviews in Google Search, which have caused, and continue to cause, significant harm to publishers, including news publishers in the form of traffic, readership and revenue loss” the Independent Publishers Alliance document said.
Referral traffic itself and how those traffic flows have evolved over time. I will say this, and I’m happy to follow up, but the picture is somewhat more nuanced from our perspective. We see that AI overviews lead to a greater diversity of sites appearing in search. We see that the quality of the traffic that is being sent to websites is of a higher quality. People tend to stay longer and we’re seeing more links in the web results so more opportunities for websites
So everything’s great and people who publish should stop their whining.
Perhaps you don’t care about plagiarism, or starvation of independent publishers and sites. If so, that’s your right (but you’re a monster). Google became huge back in the carboniferous era, because it was by far the best way to search the web. So how good is its shiny new AI search?
Amazingly brilliant! or so Google claims:
Picture this: asking Google Search whatever is on your mind — as messy or complicated as it may be — and instantly receiving an AI-powered response that really understands your question, gives you the information you’re looking for and helps you dig deeper into the topic.
But let’s not take Google’s word for it.
A small company called housefresh.com that tests domestic air purifiers did some deep research into how Google’s AI overviews try to sell you products that Google search knows are bad, or which don’t exist. In her excellent, deep blogpost Beware of the Google AI salesman and its cronies, Gisele Navarro writes
are AI Overviews leading you to the best results on the web? Or is this just a new prime spot for selling you products you will regret buying? And how does this change affect the websites that made Google’s AI possible in the first place?
To find out, we spent weeks conducting research into air purifiers we reviewed (including models that don’t exist) to determine whether Google Search results and AI Overviews are leading consumers to good advice.
It turns out this rabbit hole is deeper than we thought, with ramifications that span major Reddit communities and could be leading you to scams and defamatory hallucinations.
It’s a long, deep read. But I thoroughly recommend it.
Bonus: Bruce’s handy No-Ai search trick
Right now (in the UK, at least) the best way to avoid AI nonsense in your search is to include a swear word in your search terms. For example, searching “what’s the best beatles album” showed me an “AI overview”:
The UK competition regulator has recently undergone significant changes; its Chair was replaced by Doug Gurr, a former country manager of Amazon UK and president of Amazon China, and the chancellor has told regulators there is “too much bureaucracy”.
So the CMA is now all about ‘growth’ and reducing regulation (music to Big Tech’s ears, of course), and run by someone closely connected with Big Tech. Because the UK government has clamboured into bed with Google, while CMA is investigating both Google’s search business and mobile ecosystem, the meeting of its Growth and Investment Council would seem a way to get a sense of how the new regime is likely to function.
Unfortunately, the meeting notes are vague (no-one except the Chair is attributed with saying anything) and full of Corporate blah such as:
The Chair expressed a sense of energy and momentum coming out of the session, noting that the Council’s work is becoming increasingly concrete and impactful, moving beyond discussion into delivery.
I told Google Gemini to rewrite the minutes “in the style of a 1940s film noir”. The results are no more enlightening, but at least far more entertaining:
The Boardroom Jungle: Where the predators wear pinstripes and the only law is survival.
The dame they called London was wearing her usual drab dress of grey flannel and drizzle. It was the third of July, the kind of damp, promising-nothing morning that makes you want to crawl back into a bottle and pull the cork in after you. Down in a room that smelled of expensive coffee and quiet desperation, the bigwigs of the Competition and Markets Authority were gathering. They called it the Growth and Investment Council. I called it a den of sharks in tailored suits.
The man at the head of the table was Doug Gurr, the Chairman. He had a face built of old money and granite, and he settled into his seat like a man who owned it and the ten other souls around him. He gave the welcome, his voice smooth as aged whiskey, but with an edge that could cut glass.
Then there was the real muscle, the CEO, Sarah Cardell. She wore a suit so sharp it could have been a weapon, and her eyes missed nothing. She took the floor to give an “update.” It was less of an update, more of a declaration of territory. She laid out the CMA’s recent moves, the kind of talk that sounded like alphabet soup to a civilian but meant life or death for some poor sap’s business empire. She spoke of agility and impact, but what I heard was, we’re watching, so don’t try anything funny.
The main event was a number they called the “Growth Duty.” Sounded noble. It meant letting the big fish swim a little closer to the beach, so long as they promised to only eat the swimmers nobody would miss. A fellow with the nervous energy of a man holding a losing hand, talked about “balancing” things. I’ve seen that kind of balance before. It’s the look on a man’s face right before he jumps. The Council chewed it over, their words cloaked in jargon about “frameworks” and “outcomes.” It all boiled down to one question: who gets rich, and who gets rolled?
Then the talk turned to the real reason they were all there: the long green. Investment. The lifeblood. A slick character, all polished shoes and hungry ambition, talked about making the CMA’s “appetite” clear to the money men. Appetite. That was the word. These people were starving, and the whole British economy was on the menu. A heavy-set man with a watch worth more than my car, nodded slowly, his eyes calculating the odds. They wanted “clear signals,” the kind a cardsharp gives his partner before cleaning out the table.
Finally, Gurr called for “Any Other Business.” The silence was heavy. No one had anything else to say. They’d already carved up the world. What was left?
The meeting broke. The sharks slid out of their chairs and disappeared back into the London gloom, leaving behind only the lingering scent of power. I watched them go from the shadows. The game was over for today, but I knew the score was far from settled. Out on the street, the rain began to fall a little harder. It always does.
For some reason, I was thinking about the Roger Hargreaves kids’ book character, Mr Tickle, who is bright orange with tiny little hands that he can’t keep to himself, coming to Scotland.
Yesterday (23 July 2025), the UK’s monopoly regulator, the Competition and Markets Authority (CMA), announced that it was proposing to designate Apple and Google as having “Strategic Market Status” (SMS) as they hold an “effective duopoly” over the UK mobile ecosystem. It published proposed roadmaps of changes required to the way they operate to “promote competition in digital markets while protecting UK consumers and businesses from unfair or harmful practices”.
The CMA notes the importance of Smartphone Apps to the UK economy, which is
Europe’s largest app economy by revenue and app developer count. In total, the UK app economy generates an estimated 1.5% of the UK’s GDP and supports around 400,000 jobs here.
Because there is a duopoly, the CMA proposes “roadmaps” for the companies to make changes, in order to:
Ensure a fair and transparent app review process and app store rankings
Allow the ability for developers to ‘steer’ users out of app stores, for example to make purchases.
Ensure UK app developers have interoperable access to key Apple functionality
Address Apple restrictions on digital wallets, and enabling connected devices like smartwatches and gaming headsets to seamlessly connect with smartphones
Ensure consumers have a genuine choice over the services they use on their devices
Leverage blue-sky synergies with “A.I.” magical sparkledust (I’m not interested in this one – can you tell?)
Both investigations treated “mobile platform” as a combination of
Mobile Operating System – so i[Pad]OS or Android
Native App Distribution, both the pre-installation of first party apps on mobile devices; and the installation, distribution and operation of third-party native apps through the the vendors’ App/ Play Stores
Mobile Browser and Browser Engines
Each proposed decision notes the colossal revenue share agreement between Apple and Google, whereby Google pays Apple 36% of the advertising revenue it makes from Google Search being the default in Apple’s Safari web browser. This discourages competition between the two duopolists. From the Apple decision [PDF], paragraph 6.2:
We also find that revenue sharing agreements between Apple and Google limit their incentive to compete for users. Considered in the round, we find that these factors result in limited competition between Apple’s and Google’s Mobile Platforms. In line with this, when considering evidence on outcomes, we observe limited competition on price and quality between the two.
However, neither of the proposed roadmaps prioritise ending the revenue share agreement – probably because that’s between their HQs which are outside UK, and are anyway has been found to be illegal in court in Trumpistan.
Apple’s part in duopoly
The CMA notes the Apple Browser Ban. Paragraph 1.11.(f) of the proposed Apple decision says
Apple requires all browsers that wish to operate on iOS and iPadOS to use its browser engine WebKit, again limiting the features and functionality third-party browsers can offer. It is particularly important that this restriction does not hold back innovation in mobile browsing
and paragraph 1.25 notes that Apple has long self-preferenced its own Safari:
In mobile browsers, Apple’s Safari also faces limited competitive constraints within Apple’s Mobile Ecosystem. Although other mobile browsers are available – in March 2025, Safari had a web traffic share of supply of 86% on Apple’s Mobile Ecosystem in the UK. The ability of other mobile browsers to provide a competitive constraint is limited by several barriers to entry and expansion, in particular the requirement to use Apple’s WebKit browser engine, as well as Safari’s superior access to functionality, and choice architecture.
Our immediate focus in this area will be on considering improvements to the process by which app developers can request interoperable access to key functionality within Apple’s mobile operating systems (Category 1). Whilst the aim would not be to create a default interoperability requirement, it would aim to ensure that Apple’s decisions in respect of interoperability requests are fair, transparent and objective
(Quite why the CMA does not aim to create a default interoperability requirement is beyond my small brain to fathom. I’ll be raising it in my response to the consultation.)
Other top priorities (from Autumn 2025) relate to fairness in AppStore reviews, rankings, data collection, allowing developers to steer users out of the AppStore, as well as fair interoperability request processes.
Priority 2 (for consultation in 2026) are interoperability for digital wallets and connected devices, and (of most interest to me) choice architecture, browsers and PWAs. Paragraphs 1.17-1.18 say
We are therefore prioritising the requirement to use Apple’s WebKit browser engine on iOS and iPadOS (the WebKit restriction) and allowing alternative browser engines onto iOS and iPadOS, whilst ensuring that these alternatives able to function effectively.
Finally, we are intending to prioritise furthering our understanding of progressive web apps (PWAs) and their potential competitive impact, including through additional stakeholder engagement, with a view to considering if measures are needed to enable their development.
Quite why PWAs require “additional stakeholder engagement” is a mystery; in previous reports, the CMA have been quite supportive. Regular readers will know me as a sunny, optimistic chap, so let’s hope Apple will have a change of heart (eg, leadership) and properly allow alternative browser engines to access iOS, thus PWAs will Just Work™ and no furher action will be required.
Areas where CMA is “still considering prioritisation, subject to international developments”:
• Requiring Apple to allow alternative app stores in iOS and iPadOS.
• Requiring Apple to allow users to download apps directly from the app developer’s own website (‘sideloading’).
• Requiring Apple to allow alternative payment methods for in-app purchases beyond Apple’s own in-app payment system.
• Action to address the impact on competition arising from the revenue share agreement between Apple and Google.
Google
Google isn’t incentivised to compete against Apple. Android dominates the low-end of the market, Apple the high-end. Paragraphs 6.65 – 6.66 of the proposed Google Decision [PDF] note:
if an Android end-user using Google Search switches to an Apple mobile device, Google is likely to retain that user as a user of Google Search. Therefore, the financial consequence on Google of losing a user from its Mobile Ecosystem are diminished compared to a situation in which the revenue sharing provisions are not in place.
In addition to the reduced incentive to compete for users with Apple at the margin, we consider that Google has a wider incentive not to disrupt its relationship with Apple by competing with it head-on.
The Google decision notes the importance of being the default search engine in paragraphs 6.61 – 6.62:
Being the preset default general search engine is valuable because end-users rarely change the preset default.
The level of revenue share paid to Apple – and hence the revenue retained by Google – does not differ significantly depending on whether Apple’s Safari or Google’s Chrome browser is used.
Google cements its default search dominance on iOS by bunging Apple $20 Billion each year. For handset manufacturers other than Apple, there are very few OS options available to handset manufacturers (Google decision, 6.10):
Google faces extremely limited constraint from the threat of OEMs switching to license a different Mobile Platform. This results in Google having substantial market power in its negotiations with OEMs, allowing it to control the use of its Mobile Platform and the placement and promotion of its broader services.
On Android, Google cements its search default via contracts with handset manufacturers who wish to license Android. Annex C of the Google decision (Appendix C: Overview of Google’s agreements with OEMs and MNOs [PDF]) deals with the contractual landscape in UK, which is complex (and heavily redacted). Paragraph C.54 summarises it:
the agreements between Google and Android OEMs create substantial financial incentives for OEMs to promote Google’s apps and services on their mobile devices
As paragraph 4.56 of the proposed Google decision states,
The operating system is pre-installed software which powers Android mobile devices. As noted above, a large majority of apps in the UK are downloaded on Android from the Play Store. Google’s agreements with OEMs also contain provisions financially incentivising pre-installation and prominent placement of Chrome, which runs on Blink, and Chrome is pre-installed on the majority of Android devices in the UK
The proposed Google roadmap prioritises Play Store fairness (transparent ranking, reviews, not unfairly using data).
Its priority 2 list (for consultation or investigation from 2026) has Choice architecture, further work to explore the potential for Progressive Web Apps, and allowing developers to direct their potential customers off the Play Store.
On Choice Architecture, the proposed decision notes (para 1.13):
Our other key concern is in relation to the agreements Google has with mobile device manufacturers and, combined with Google’s control over the Android operating system, the significant influence that these have on the content and services users access on an Android mobile device. We are therefore planning to focus on choice architecture to try and ensure users make an active choice as to their content or service provider, and in turn enable third-party app developers to compete on more of a level playing field with Google’s own services.
Perhaps this helps explain why in the EU, Google is playing even more hardball than Apple about relinquishing the hotseat if a non-Chrome browser is set as default.
Interestingly, paragraph 1.11 of the Google roadmap notes Judge Gonzalez Rogers order for Apple to stop imposing its commissions on purchases made for iPhone apps through web links inside an app:
While the design of any potential steering intervention will need careful consideration, one form of this intervention implemented by Apple in the US appears to be delivering positive benefits. In a matter of weeks, it resulted in changes such as app developers rolling out new and improved products, and announced price decreases for affected users.
Assuming that the army of Apple lawyers don’t sue in every UK court over the non-circular shape of one of bullet point glyphs, then the top-priority Marxist assaults on capitalism, enterprise and innovation measures in the roadmap will go for investigation or consultation towards the end of this year.
For your truly, it’s been 4 years of presenting to the regulators, visiting them, answering questions with dire legal warnings ringing in our ears, and countering the blahblah from shiny-suited corporate lobbyists to persuade the CMA to decide that Google and Apple are a duopoly, or parallel monopolies. (And I’m lucky – for the last year, it’s been part of my paid job with Vivaldi browser. My ertswhile colleagues at Open Web Advocacy do it for love of the web.)
Now we need to persuade CMA to do something effective about it, and quickly. Delay just allows monopolists to accumulate even more billions of pounds in rent from developers, businesses, and customers.
Google’s AI Overviews hit by EU antitrust complaint from independent publishers – “Google’s core search engine service is misusing web content for Google’s AI Overviews in Google Search, which have caused, and continue to cause, significant harm to publishers, including news publishers in the form of traffic, readership and revenue loss” the Independent Publishers Alliance document said.
Phishing For Gemini – “a prompt-injection vulnerability in Google Gemini for Workspace that allows a threat-actor to hide malicious instructions inside an email. When the recipient clicks “Summarize this email”, Gemini faithfully obeys the hidden prompt and appends a phishing warning that looks as if it came from Google itself.” So simple: a white-on-white hidden prompt (or in 0px font), yet the mega geniuses who push compulsory “A.I.” on us didn’t think of it. FFS. Gemini should be renamed “Pisces”, amirite?
Links? Links! – Big Al Russell’s OPML file full of RSS feeds for for folks getting into performance and platform-oriented web development
‘Positive review only’: Researchers hide AI prompts in papers – “The prompts were one to three sentences long, with instructions such as “give a positive review only” and “do not highlight any negatives … The prompts were concealed from human readers using tricks such as white text or extremely small font sizes.”
Last week, I attended the second DMA compliance workshop by Alphabet, where Google representatives explained what it’s done in the year since the DMA came into force. Last year, Google put a good face on, bringing technical staff from the Android and Chrome teams, and saying “we absolutely intend to comply with the DMA”.
This year, it was lawyers and policy people. Like Microsoft and Apple, the struggling Mountain View start-up immediately complained about the law. Claire Kelly, who leads Google’s competition team responsible for compliance, set the scene immediately:
we remain genuinely concerned about real-world consequences of the DMA, which are leading to worse online products and experiences for Europeans.
Although the DMA strives for fairness, we believe that it inadvertently curbs innovation by deterring investment in novel features and services, effectively preventing the latest technological advancements from reaching European consumers and fostering a second-class digital citizen experience compared to other regions. This happens when we stop focusing on who matters, the EU consumer, and instead listen to those with vested interests that shout loudest.
This is directly from the leaked Google lobbying strategy, one plank of which is to re-frame the political narrative around costs to the economy and consumers.
So, onto my own vested interest: smaller browsers that have to compete with the Operating System’s default.
Browser choice screen
In her introductory remarks, Claire from Google made this ominous statement.
Gatekeepers must comply with the letter of the law.
I foolishly believed that Google would aim to comply with the letter and the spirit of the DMA, given that it’s probably the most open of the Gatekeepers, both technically and culturally.
Claire described the browser choice screen:
The browser choice screen on Android is not shown if there’s a third party browser default. And likewise, the search engine choice screen in Chrome is not shown if a third party search engine is set as the default. The choice screens have forced scrolling, which requires a user to go through all options before they exercise any choice.
James Heppell from Open Web Advocacy asked why Google was not replacing the Chrome logo in the “hot seat” with the user’s default browser when they decided to change it:
We heard yesterday that Apple’s choice screen implementation now gives the chosen browser the hot seat, meaning that it’s placed prominently at the center of the dock on the home screen. replacing the Gatekeeper browser. In contrast, Google has not made these changes and continues to use a far less effective design.
We know from our conversations with browser vendors that having the hot seat leads to higher retention rates and reduces the dominance of the operating system, Gatekeeper and their browser. By not placing the user’s chosen browser in the hot seat, Google is undermining Article 6(3) and making the choice screen significantly less effective. Just setting the default browser is not enough to nullify the advantage that Google gives their own browser via their control of Android’s default setup.
Given that Google already benefits from the hot seat on iOS, and we have heard Google mention this about the hot seat, our question is, can Google commit to implementing an equivalent hot seat placement for browsers on Android, and if so, when can we expect that to roll out?
Claire responded:
Again, our approach to this is informed by what the DMA says. And Article 6.3 is clearly about defaults. A Hot Seat is not a default. So a default is a service that will trigger as a result of a generic user action, as I mentioned earlier. And so if a user goes to do something, for example, clicks on a URL, it would be the browser that is used in order to then fulfill that specific user intents.
The placement of a particular app on a device has nothing to do with the default. And so that’s our view in respect of how the hot seat question fits with what we’re talking about when we talk about compliance with the DMA.
Kush Amlani, Director of Global Competition and Regulation for Mozilla, commented
coming back to the hot seat and to your response there, I wanted to say that if you select a browser via a choice screen and it downloads to page 13 of your apps I’m not sure that necessarily complies with 6.3 and would contest your interpretation.
Recital 49 of the DMA says that gatekeepers should allow end users to easily change default settings when those default settings favour their own software applications and services. And Article 6.3 also says that the gatekeeper should allow and technically enable end users to easily change default settings, including by prompting via a choice screen.
So from our point of view, we think both of those things do require you to place the selected browser in the hot seat. And obviously it’s already been done by other gatekeepers as well.
I agree with Kush, and not only because he’s bigger than me. But, perhaps unsurprisingly, Claire doesn’t, and had not changed her mind over the course of the conversation. Google would stick to the letter of the law, and even out-stickler Apple (in this matter, at least):
we think our position on this one is is pretty clear in respect of the hot seat, I mean, again, we can understand your perspective on things, but again, it has to come back to what’s said in the DMA.
Even your reference to the recital refers to default. Default means a very, very specific thing, and it hasn’t to do with placement on a device. And in any event, on Android, it’s extremely easy for users to move around where their apps are placed when they’re downloaded.
So again, we don’t think this gives rise to any questions of non-compliance with the DMA. our position is as I would have stated earlier.
This is an overly narrow interpretation, and it’s particularly striking that Google chose to emphasise that the default browser is the one used when a user clicks on a URL, given that this is something Google itself actively undermines on Android. The Android Google Search widget, for instance, doesn’t open links in the user’s chosen default browser but instead opens them in the Google Chrome in-app browser.
Many other popular apps also override the system default browser and silently open links in their own in-app browsers, a practice we’ve documented extensively. As a result, the very concept of a default browser is being steadily eroded on mobile. In this environment, securing a position in the hotseat has become a crucial source of traffic for the user’s selected browser and a key part of respecting the user’s choice.
Artificial Intelligence
The second session of the day was on “Artificial Intelligence”. My distaste for mad billionaires stealing intellectual property, and then burning the globe to turn that stolen IP into bullshit is unbounded. But one question interested me because it’s about Search consuming and regurgitating websites, instead of sending traffic (and thereby starving them of the revenue to keep publishing).
Angela Mills-Wade from the European Publishers Council asked:
So notwithstanding Oliver’s claim that AI overviews are an evolution of search, they stand out as representing a kind of separate product and they compete directly in real time with primary source journalism and this is increasingly diverting audience attention away from publishers’ own channels.
This is not a DMA point, but it is important for the context. They’re representing information without any of the editorial standards or legal liability or accountability that define journalism. It’s also impacting Google’s search referral.They’re dipping (the referrals), sometimes as much as 50% to 60% and rising in some countries, which means both advertising revenues and opportunities for publishers to convert visitors to paying subscribers fall off a cliff.
The Google search engine seems to be accelerating the role of extractive products like AI overviews, and of course in the United States we also see AI mode, and they rely on content created by others to generate answers in their own ecosystem for Google to monetize.
There is no specific mechanism for publishers to opt out of all AI training while retaining inclusion and ranking in traditional search. So Google is both gatekeeper and competitor, self-preferencing, I know we’re not talking about that, AI product in competition with and obscuring primary source journalism.
And this unfair extraction and use of publisher content is without real consent, control or compensation to produce these new separate services which undermine not only copyright law but also the FRAND principles under the DMA, self-preferencing as I’ve mentioned, but also the lack of transparency.
…How does Google justify that full narrative answers AI overviews at the top of their search page means referrals to original journalism are falling fast, which reduces the economic return for publishers to be present on the search.
How does Google justify the extraction of publishers’ content in breach of copyright law and FRAND? And why does Google purchase third-party data for its own content services, for example finance, while treating publisher content as free input?
Why can’t publishers opt out of all AI if they would like to without losing their appearance in traditional search?
And will Google be respecting the publisher’s rights reservations, which is publishers right to do so under article 4 of the copyright directive or develop some granular controls specifically for AI overviews?
Olli from Google replied:
is there disruption to the news industry? Is there a need for an evolution within the ecosystem when it comes to the ways in which traffic goes to various parties and players? Yes, that has been the case for some time. We believe in journalism, the value of journalism. It’s a big part of Google’s success for there to be high-quality content on the Internet, but the internet is evolving and changing.
As part of that, we have done our best. I think we have made good steps, taken a creative and open-minded and have invested heavily, in fact, in ensuring that partners that we work with are able to evolve with those evolutionary ecosystem changes as they’re occurring around us, whether it’s news funds, new forms of partnership agreements, a raft of different initiatives that globally we’ve been very invested in to ensure that news publishers can innovate and evolve in this highly disruptive, technologically advancing environment.
Referral traffic itself and how those traffic flows have evolved over time. I will say this, and I’m happy to follow up, but the picture is somewhat more nuanced from our perspective. We see that AI overviews lead to a greater diversity of sites appearing in search.
We see that the quality of the traffic that is being sent to websites is of a higher quality. People tend to stay longer and we’re seeing more links in the web results so more opportunities for websites so when we’re thinking about referral traffics that of course not a single site analysis or even a subset of sites analysis you look in the round to see how the ecosystem has benefited from some of these innovations and i would posit that the picture is a little bit more nuanced than than perhaps is being represented here.
I’m not sure that really assuaged anyone’s worries. In fact, there are reports that an organisation called Independent Publishers Alliance and others have filed complaints to EU and UK about AI Overviews.
Data portability
The afternoon was devoted to data portability and sharing Google search index data, which wasn’t so interesting for me personally (it was a hot day, and I was tired after my friend’s wedding). The fourth session was a look at a new data portability tool, and its synthesised voice narrator was so weird I turned it off.
Initial impressions
I was disappointed that Google has chosen to view the hotseat issue so narrowly (and to continue having Chrome open links in its pre-installed Search app, even when it’s not default). This highly legalistic approach was demonstrated by the lack of any technical people in the Google team this year.
Apart from the predictable handwringing that every Gatekeeper felt obliged to perform about how EU consumers won’t receive the latest AI bells and whistles at the same time as Americans do, because of beastly regulation, Google made a good point about the regulatory regime:
My third point concerns the risk of fragmentation arising from enforcement of the DMA at the member state level. We see an increasing risk of regulatory fragmentation from national enforcement actions and private litigation. As the DMA allows for national level involvement, it clearly also designates the European Commission as the sole enforcer, with the goal of harmonising rules across the European Union. That is explicitly stated in Recital 6. This harmonisation objective is now being called into question as a result of an ever-increasing number of actions at the national level.
This matters for two critical reasons. First, the DMA’s core objective under Article 114 of the Treaty of the Function of the European Union is to prevent internal market fragmentation from divergent national rules. If national DMA litigation goes unchecked by the Commission, the central objective will fail.
Second, a potential explosion of national enforcement cases would create significant new regulatory overhead, directly contradicting the EU’s simplification package initiative. More practically, if a third party can simply take an issue to a member state court, potentially circumventing the Commission’s harmonising role, this undermines the incentive that gatekeepers have to engage constructively with the European Commission.
Publishing clear guidelines for national authorities and courts on engaging with the Commission on DMA compliance matters would send a very strong signal for coordination.
It seems to me that many of these national enforcement cases are due to frustration about how little has changed in the last 16 months. Microsoft is still self-preferencing its Edge browser on Windows; Google had showed encouraging signs, but its “letter of the law” approach is worrying; and Apple still doesn’t really allow other browser engines to ship on iThings, it still chokes Progressive Web Apps, and is litigating everything that moves in Brussels.
“Regulatory dialogue” is, of course, vital. But over a year after the DMA came into force, we need enforcement action by the Commission, as well as conversation.
Unofficial transcripts
I made these transcripts using MacWhisper from the official video recording. I manually corrected the passages I quoted above, so those are more accurate than these raw transcripts. Apologies if the software or I mis-spelled a name!
This reading list is courtesy of Vivaldi browser, who pay me decent money to fight for a better web and don’t moan at me for reading all this stuff. We released Vivaldi 7.5 today, so try it, unless you enjoy having a browser that’s like a panopticon sloth.
Link of the Month: Digital sovereignty can’t be bargained away – “The European Commission has tools, public support and a mandate to act on Big Tech. Trading that away for short-term calm would be a costly mistake … Enforcing the EU’s laws, reclaiming a fair share of the value extracted by monopolies, breaking them up to unfreeze markets and using the proceeds to invest in our digital infrastructure could be exactly the kind of economic reset Europe needs” by Robin Berjon
PNG is back! – A new PNG spec was just released! Now with added HDR, Animation and EXIF support. As resurrected by W3C with reps from Adobe, Apple, BBC, Comcast / NBCUniversal, Google, MovieLabs. Work has already begun on the next two PNG spec updates. “After 20 years of stagnation, PNG is back with renewed vigor!”
Meta and Yandex are de-anonymizing Android users’ web browsing identifiers – “Tracking code that Meta and Russia-based Yandex embed into millions of websites is de-anonymizing visitors by abusing legitimate Internet protocols, causing Chrome and other browsers to surreptitiously send unique identifiers to native apps installed on a device”
Web Bucks – Brian Kardell looks at the current developments in web micropayments/ microtransactions
Microsoft Could Repeat its Teams Strategy, this time with Bing and Edge – “LinkedIn—a designated core platform under the DMA—is growing at just 8%. At this rate, Search and News could soon outpace LinkedIn in revenue, while remaining outside the scope of DMA enforcement … This helps explain Microsoft’s incentive to push cloud, search, browser, and advertising services as aggressively as possible before new regulatory oversight catches up. The stakes are high.”
After all the fun of attending the second Microsoft DMA Compliance Workshop in person, I attended the similar Apple event remotely, as I was Best Man at my oldest schoolfriend’s wedding in the afternoon. The quotations below are from a transcript I made from the official EC Stream recording.
Session 1: Interoperability
The first session was looking back at the first year of DMA, and Apple’s interoperability. Kyle Andeer, vice president of products and regulatory law at Apple, came out fighting immediately. He said Apple does not believe “that the lawmakers intended for the EC’s DMA teams to be the final arbiters of user safety and security”, and that the Commission clearly doesn’t know how to do its job:
The Commission still has an opportunity to create a workable requirement here, to create a proportional interpretation of the DMA, to focus on interoperability areas where clear contestability risks appear, and to pay closer attention to the technical implications of their requirements.
He gave several indications that Apple intends to litigate until the 29th century:
As we’ve made clear here, we have disagreements with the EC’s interpretation of Article 6(7) and have exercised our fundamental right to seek judicial review …
We think the ambiguity in the law is so significant, and we recognize that the commission has taken its positions, in some cases we think extreme positions, that we hope can be tested as quickly as possible by the European court …
It’s unfortunate, very unfortunate, that we’re going to have to wait years in some cases for the courts to weigh in…
And we’re going to be looking forward to getting some of that guidance from the courts.
Obviously, this isn’t at all “unfortunate” for Apple; while it wastes time and EU money on litigation, it will continue to rake in billions of dollars of rent from its AppStore tax – which is particularly important now Judge Gonzales Rogers has forbidden Apple’s off-app sales tax in the USA.
work out how to get closer to a particular risk but be prepared to manage it it it does go nuclear, … steer the ship as close as you can to that line because that’s where the competitive advantage occurs…
Apple had to pay a large fine, Tim [Cook]’s reaction was that’s the right choice, don’t let that scare you, I don’t want you to stop pushing the envelope.
After these warning shots, Kyle went on to tug on our heart strings:
But in order to comply with the EC’s interpretation of the DMA, all the changes we’ve put in place lead to very un-Apple bureaucratic processes we aren’t used to.
It’s true: Apple will have to design for interoperability, and (most egregiously) will have to pause to consider the legality and monopolistic potential of its products before launching them. Very un-Apple, indeed.
Personally, I started welling up when I realised that Apple’s reluctance to comply with the interpretation of the law by those entrusted to administer it is not only because that could hurt a struggling Cupertino technology company, but could harm other developers else, too:
No, our focus is not on just the billion-dollar companies, but also the millions of developers today and to come in the future.
Competition is what will ensure that Apple’s conduct and business decisions do not thwart the next Apple
What Apple calls the Commission’s “extreme interpretation of interoperability” is going to hurt EVERYONE, including developers, the economy, puppy dogs, fluffy kittens, and even EU consumers.
Throughout Apple’s history, it has entirely been in Apple’s interest to invest in giving developers the technologies they need, to create great apps for our users to enjoy, and we’re continuing to do so. Unfortunately, because the EC’s version of interoperability flips that successful model on its head, we’ve already had to make the decision to delay the release of products and features we announced this month for our EU customers. These features include enhancements to iPhone mirroring and new Maps features like visited places and preferred routes.
John Ozbay, of Open Web Advocacy, asked about the process by which developers and other supplicants can request interoperability with iOS:
the commission made it clear, if Apple wants to run a request-based system, it must meet basic standards. That includes short response timelines, a clear process with deadlines for Apple, proper explanations when a request is rejected, and a public searchable tracker showing the status of all requests accessible to any developer. Now, none of this is difficult, and Apple already runs public GitHub trackers for other projects. They could have done the same here or built something custom with the brilliant engineers they have. But instead, and this is the genuinely bizarre part, they chose to publish a PDF. Static document, updated once a week, hidden behind a hard-to-find link. No search, no comments, no filtering, or no interactivity. So our question is this. Does Apple believe that a static PDF meets the very clear requirements laid out by the Commission? Thank you.
Apple replied
Now, we are amazing at what we do. We can do amazing things. Achieving a fantastic solution against those deadlines while trying to comply with the obligations placed upon us causes some practical realities. We set out to comply. We did something that was the absolute best we could achieve in that short timeline. And, of course, we will be looking as we go along to enhance it as we do with everything we work on. It is also available to all developers. Just log in to App Store Connect to access it.
I managed to ask one question about the interoperability process:
On behalf of Vivaldi, I submitted an interop request for 3rd party browser engines to read iOS Parental Control settings on Nov 15, 2024 [INTEROP-246]. On Mar 7, 2025 I received Apple’s response: “We will introduce new API to the BrowserEngineKit framework to interoperate with Web Content restrictions … This is a mild engineering effort. We plan to complete development of this solution by March 2026, and ship it shortly thereafter”. Does Apple genuinely believe that 16 months for a mild engineering effort is fast enough? Vivaldi is 57 people, but we’re happy to loan you a C++ engineer if this will expedite implementation
(Well, that’s what I typed into Slido but, although that is still shorter than most of the in-person questions, Slido rejected it as too long. So I had to frantically edit all the context out, until it became “In November 24, I sent an interrupt request for all the browser engines to read iOS parental control settings. In March, Apple said, “this is a mild engineering effort. We plan to complete by March 2026.” The question is, is 16 months for a mild effort fast enough?”)
Kyle answered
we are working through a number of different requests. Some of those are very simple and we get solutions out very quickly. Others are more complex. When you’re talking about parental controls, you’re talking about tools that are used to protect children. Those are not tools that we are going to simply rush through and see what happens. There are going to be different standards here in terms of what we’re being asked to provide. If we think children are going to be at risk, whether it’s through manipulative or deceptive advertising techniques or other things on our platform that puts them at risk, we’re going to be very careful about developing those solutions.
Kyle’s more jovial sidekick, Gary Davis, senior director on Apple’s legal team in Europe, added
Maybe just one small point on the mild engineering efforts. That’s not a term that we would use, of course, in the normal course. That’s a term that was introduced by the specification decision. So we are required to indicate efforts as mild, medium, and significant. And so the actual engineering effort was mild. It still takes considerable time. As Kyle indicated, we have to do it in a way that takes full respect of the risks that arise in that space.
So, that was my answer: a mild engineering effort still takes a year, and if you think that’s too slow, WILL NO-ONE THINK OF THE CHILDREN???
In the next session, James Heppell from Open Web Advocacy returned to my point:
it sounds that you had six, seven months to implement or at least to know that you had to implement the interoperability system. And sure, maybe it’s hard to create a new system in that time, but we’re not saying you have to make something from scratch. There’s lots of existing systems like GitHub, like Bugzilla for WebKit, like all of these things you use internally that you could have used, which would have been much, much more helpful to developers than the PDF.
And in reference to the App Store thing, you say you’re very contactable, that we can come to you with these problems, but there’s not actually a button (unless the app has already been installed) in the App Store to report scams when people try and get in touch with you. It’s a bit of a joke in the website stuff, in the browser community, that sometimes there’s the black hole of the Apple interoperability thing, because we just don’t get back answers sometimes. It’s months. Bruce had the question about 16 months replies. It’s not really workable.
According to Apple, they didn’t have time to set up a Github/ Bugzilla system, and anyway, the system is working brilliantly:
I think one needs to take account of the time period, the discussion, the correct outcome, what the Commission had in mind, what we could agree to before one could work towards an acceptable outcome. But I believe the process is working really well now. I believe requests are coming in. We are responding within the allotted time. We have some very specific times that we need to respond by. All of those times have been met, Not one single one of those has been missed in the time period in which we’ve been asked to respond in.
At that point, it was lunchtime, and I had to go to a wedding. Luckily, OWA had sent three of their finest operatives (codenamed The Chauffeur, The Piano Man, and The Hepcat) and I caught up with the recording next day.
Session 2: App Store
The headline of this session was that Apple is dropping its Core Technology Fee. Or, more accurately, renaming it. There are a huge number of tweaks to the Apple Taxes, and to the customer experience. The most important part for me is a new “unified model” of payments to Apple
that all developers will be subject to starting next year. First, there will be a Core Technology Commission, or CTC, of 5% on sales of digital goods and services. The CTC reflects value Apple provides to developers regardless of whether they choose the App Store or alternatives for distribution. The CTC is not tied to whether a developer is distributing through the App Store or steering a customer to making a purchase outside of the store.
The CTC reflects Apple’s ongoing investments in platform tools, technologies, and services that enable developers to build and share innovative apps with users. To be clear, as of January, there will be no core technology fee. There will only be the CTC. Second, developers distributing apps on the App Store will pay an App Store Commission on sales of digital goods and services. So this captures things like subscriptions, digital content, and paid apps. Developers who choose alternative distribution do not pay this commission…
Under the new terms, there is also a store services fee, or SSF. That reflects the ongoing services and capabilities that Apple provides to developers, including app distribution and management, rediscovery and engagement, app insights, and more.
The Core Technology Commission really offends me, as it’s a tax on using the iOS operating system. Developers must already purchase an Apple Developer License every year, buy a Mac to run Xcode, and various iThings to test on, yet must also pay this tax.
Other device manufacturers know the value of a vibrant app ecosystem gives them. For example, a few days ago, a Danish judge found Google had abused Android to safeguard its dominant position in online advertising. One of the ways it did this was tying access to the Play Store to the pre-installation of the Google Search app and Google Chrome. It could do this because it knew most device manufacturers would be unwilling to ship phones that had no access to an full application store.
Developers are essential to a vibrant app store, and so vital to Apple’s success. I can see no moral justification for a Core Technology Commission/ Fee/ Tax. It’s just rent extraction.
Of course, Apple claims that its marvellous curation of the AppStore is what makes it so valuable to developers:
A big reason why small developers around the world have been able to reach massive audiences on the App Store is because users trust the App Store. In fact, it’s hard to remember what downloading software was like before the App Store. Back then it was the Wild West of the open web. You never really knew what you were downloading. At Apple, we set out to change all that and build a marketplace that users could trust.
That pesky “open web”, eh? No school shooter apps, sanctioned Russian bank apps or ripped-off games get past the in-depth App Store review process. Thanks for saving us, Auntie Apple!
John Ozbay from Open Web Advocacy made this point in his usual terse manner:
Kyle, you spoke at length about the App Store as if every app is carefully reviewed, safe, and secure. But that doesn’t simply match the reality. We use the App Store daily. And every single week we’re served ads, often directly from Apple, for apps that are live in the store right now and clearly designed to scam users out of money. These are called fleeceware apps. And they rely on deceptive subscription models and dark patterns to exploit users. And Apple’s review process is ineffective at solving this. So some facts are pretty striking.
Apple has just 500 reviewers looking at over 130,000 apps every week. And most of them only spend a few minutes per app, if you divide and do the math. So few have technical backgrounds, and mainly just click around the interface from what we’re understanding. And they work 10-hour shifts. And even Apple’s own executives, once worried it might resemble sweatshop conditions, according to what’s come out.
But the real eye-opener for me comes from internal emails revealed during the Epic versus Apple case. Senior Apple staff were openly frustrated, and some quotes, and some of my favorites are,
“Is no one reviewing these apps? This is insane!!!!”
“AppReview is bringing a plastic butter knife to a gun flight.”
“They’re more like greeters at a Hawaiian airport than drug-sniffing dogs.”
“Just like in October, AppReview fails to review properly.”
So my question is, If Apple’s own internal communications acknowledge that human app review is ineffective, and the App Store continues to host widespread fraud and abuse, how can Apple credibly use this system as a defence against third parties who might actually offer more effective safeguards?
Session 3: browser choice architecture
Apple’s choice screen started out as a terrible mess, but with feedback from other browser vendors and the EC, Apple re-designed it a much better way. I have my disagreements with how the Gatekeeper chooses which competitors it shows on the choice screen, which I’ve raised with the DMA team, but Mozilla, DuckDuckGo (and we at Vivaldi) have seen user numbers increase. I also question why a browser is limited to how often it can check if it’s default (4 times a year).
But Apple deserves congratulation on its choice to follow the spirit of the DMA by putting the newly-chosen default browser in Safari’s place on the “hotseat” (the bottom row of apps that always shown, regardless of which home screen is in view). As Roderick Gadellaa from Open Web Advocacy said,
we agree with Apple that the hot seat should be default on Android as well. So we will be raising this tomorrow.
Then, Roderick turned to the ridiculous terms Apple imposes on vendors who want to ship non-WebKit browsers:
The DMA has been enforced now for 15 months. Despite this, not a single browser vendor has been able to port their browser using its own engine to iOS. It’s not because they’re incapable or they don’t want to; it’s because Apple’s strange policies are making this nearly impossible. One of the key issues slowing progress is that Apple is not allowing browser vendors to update their existing browser app to use their own engine in the EU, and Apple’s WebKit engine elsewhere. This means that browser vendors have to ship a whole new app just for the EU and tell their existing EU customers to download their new app and start building the user base from scratch. Now, we would love for Apple to allow competing browsers to ship their own engines globally.
But if they insist on allowing this only in the EU, Apple can easily resolve this problem. Here’s how. They can allow browsers to ship two separate versions of their existing browser to the App Store, one version for the EU and one for the rest of the world. Something which is currently possible in other App Stores. This would allow existing European users to get the the European version of the app without having to download a separate app simply by receiving a software update. But it seems Apple doesn’t want that, and they make this very clear in their browser engine entitlement contract. Given that, Apple can easily resolve this problem simply by allowing browsers to ship a separate version of the app to the EU under the same bundle ID. Why is Apple still insisting that browser vendors lose all their existing EU customers in order to take advantage of the rights granted on the DMA?
This wasn’t answered. Gary handwaved:
both Google and Mozilla have everything they need to build their engines and ship them on iOS today. We heard some other issues mentioned. We are happy to engage in those issues. We are engaging on those issues, but everything is in place to ship here in the EU today. I think that’s an extremely important point to take away from this.
Kyle added
I think one other point I wanna make sure I address as I reflected upon the end, there was a question about why we don’t do this on a global basis. And I think we’ve always approached the DMA as to the European law that relates to Europe. And we are not going to export European law to the United States, and we’re not going to export European law to other jurisdictions. Each jurisdiction should have the freedom and decision making to make its own decisions. And so we’re going to abide by that.
Frederick from riedel.wtf asked about APIs currently avalable to WebKit-based browsers (similar to mine about Parental Controls earlier):
I would love to learn how Apple will make sure that existing APIs that are currently available in WebKit will be available when people decide to use custom browser engines as well.
As an example, we use the ScreenTime API, more specifically the managed settings part of it that really specifically allows us to block certain websites. Users can, for example, also decide to block porn sites. also a parental control setting, but also users decide to put it on their own phones.And yeah, I would love to know if and how Apple will allow developers like me to apply such restrictions in third-party browser engines as well.
Kyle answered vaguely
we’re in a period of transition where we built an operating system, a set of operating systems that was designed to be the most secure in the world, and that is what we have built. A critical aspect of that was our integration of WebKit into our operating systems. We’ve also introduced flexibility and APIs for third-party browser engines to take advantage of these new opportunities under the DMA. We’re also engaged in ongoing conversations with Mozilla and with the other company in terms of bringing them to iOS.
Apple has given all web browsers on iOS a 17 plus age rating, despite the fact that the websites they can load are not controlled using the age restriction setting, but using the web content restriction setting … So how can it be that the browser’s user interface itself is considered inappropriate for children, not the web content display?
Given that all browsers on iOS, including Safari, use the exact same web content restriction setting, what is it about other browsers that means that they’re not allowed to be installed or used when Safari is?
So thanks to this dark pattern, we discovered that most users under age of 18, an estimated up to 15% of all European users, cannot use any browser other than Safari, undermining their meaningful browser choice. So these users will grow up having only ever used Safari on iOS and perhaps not even knowing about the existence of other browsers…
So given that under the article 13.4 of the DMA, Apple must not use interface design or behavioral techniques to undermine its compliance. What specific steps will Apple take to ensure that third-party browsers and social media apps are treated equally in age-restricted environments?
Gary’s answer, again, was encouraging but so unspecific it could have been a watercolour by Turner when he was feeling especially timid:
obviously, APIs are available to WebKit or available to WebKit. I think it might be trying to make them available to others on the platform. And obviously, as we go forward– and this is in the 6(7) session– as browser engines become available, which are alternative browser engines, which I presume they will in a timeline to come, there will be 6(7) issues there as well in terms of what iOS features are available to Apple services.
And so that’s something we will have a look at in that context as they come in. And certainly, those are the kinds of conversations having, even I think the question we had from Rita, that has been a topic.
So you asked about the screen time APIs and how we look at those. They’re all actively under discussion. Some of those things we’ve received interoperability requests for. And I think that is a good process in which to understand what it is that developers need and respond to them in a timely manner. And I think we have been doing that.
We are very anxious for child protection and age assurance reasons to make sure that that is working in a good manner on the platform.
So, rather than just making things interoperable, it looks like Apple want people to request piecemeal access to each system API (explaining why, so perhaps giving product plans to a gatekeeper competitor). Thereafter, it will be logged in a static PDF in a secret filing cabinet and, if it is a “mild engineering effort”, you might be able to use it in 16 months’ time. Agile!
Talking of developer woe, James Heppell of OWA asked
Web developers globally must be able to test their sites in the new competing browsers on iOS regardless of where they’re located. We understand that Apple may not wish to allow these browsers to ship to consumers, that’s their choice, I suppose, but that is a completely separate issue to allowing developers to test it.
So my question is, what solution does Apple propose to ensure that web developers outside of the EU can install and test these browsers and maintain compatibility and interoperability for users in the EU?
Gary’s answer was Turner-esque again:
I think as we’ve been going along, we have learned a lot as to how to facilitate that kind of testing outside of the EU, even in relation to browser engines. I think that’s a subjective, active discussion. I think we’ve been discussing it with Mozilla and Google also. And the commission, I would expect to see some updates there. So you can just generally see we are trying to be more conscious of that.
John “porn advocate” Ozbay of OWA asked a question that we’d jammed together before the meeting:
Last year, after we made a lot of noise to get Apple to reinstate homescreen web apps in the EU,
Apple announced that homescreen web apps “continue to be built directly on WebKit and its security architecture”. However, under Article 5.7 of the DMA, Apple is not allowed to impose a browser engine on either users or third-party browsers.
Can Apple update us on the progress made for allowing third-party browser engines to install and manage homescreen web apps on iOS once third-party browser engines arrive on iOS?
Kyle was neither vague, nor encouraging; a sort of dayglo Francis Bacon to Gary’s Turner:
So I think on homescreen web apps, obviously these are available today here and around the world. We have nothing to announce in terms of what we will do if and when a third-party browser engine comes to iOS.
Certainly I can say from a high level perspective, our focus will continue to be, as I’ve said several times on ensuring that anything that’s operating on our platform is as secure and as private as possible, and it does not damage the operating system.
Browsers and home screen web apps are different than other things. They have other access to the operating system that we will have to manage and control. And so we have not settled out on any of those issues. As I’ve said again, we’ve engaged with Mozilla, we’ve engaged with Google. We’re figuring out the solution that works best for all parties.
John “Fruity Fetish” Ozbay continued,
Apple has previously told the Australian and the UK regulators that web apps are a viable competitor to native apps, and their own app store developer guidelines say that if a developer does not want to use the app store, there’s always the open internet.
As such, we believe that web apps should get equal treatment to native apps when it comes to installation. Users can install native apps with one click via the app store, which a website can link to, or even open without user interaction.
Users can also directly install native apps with one click within browsers using smart install banners on the top. Web apps inside of Safari and even third party browsers are unable to do either of these at the moment.
So to install a web app on iOS, user must go through a four-step process, navigating the Safari menu, finding the share icon, which I don’t know why it’s labeled share, scrolling down and clicking to the confusingly named at the home screen button instead of install.On other operating systems, most browsers clearly place this button labeled install app in the first page of the menu or in the address bar and crucially allow websites to prompt users to install web apps just like native apps.
So our question is, what will Apple do to ensure quality and installability between native apps and web apps?
And related to this question, has to do with iOS26… Last year, in a beta release, right before DMA deadline, Apple quietly tried to kill web apps on iOS until we, Open Web Advocacy, led an letter with over 5,000 signatures from organizations, companies, individuals, including European MEPs, to ring the alarm bells and tried to stop Apple.
So this year, right before this DMA workshop, with the iOS 26 beta, Apple has made it even more difficult to install web apps and added them to add them to home screen and hidden, the functionality, two more button presses and menus deep compared to the previous version.
So why is Apple trying to make it even harder than already is to install web apps and trying to add them to the home screen?
Gary again:
So I think we’ll have to get back to the iOS 26 issue. That’s not something I’m aware of.
And I think on the first issue, I do think there is a fundamental difference in terms of installability and what a user should know between an app that has gone through the thorough app review process, which has checked it across all the app store guidelines, run the code, examined how it worked, and then see what the experience is, check what privileges it wants to access, examined how it’s going to access them.
To me, those things are different. And I think they’re different from a threat vector for users. And so I do think they’re going to have to operate slightly differently to make sure that users are not unintentionally installing something from the web that they simply don’t understand.
And that concludes my highlights from the day. Session 4 was on data portability, which is vital, but outside my primary interests.
My initial thoughts
Apple made a few vague promises, but I expect those to be punted decades hence, as Apple gets its litigation leviathan prowling the depths of the Commission. Which is a shame, but leopards don’t change their spots.
There were a few occasions in the day when I suspected that the Apple representatives might be playing a game of saying spectacularly preposterous things, just to see if anyone noticed in the heat.
For example, Kyle claims that it is
difficult to strike the right balance between privacy and security concerns and interoperability, as the Commission is acting without detailed input from the experts in the field who can weigh in with their deep knowledge…
all the complex decisions on the trade-offs that must be weighed around interoperability are being made by those without the requisite ongoing technical knowledge in privacy and security.
Alas, Apple did not disclose which independent experts it consults with, when it weighs up the trade-off between interoperability and security. Perhaps the EU and Apple could share the expertise of that particular totally independent third party?
I was tempted to ask (but didn’t) whether Apple had considered asking some of the developers of MacOS to come and work for them. After all, I can install apps on my Mac without going through its AppStore – even those that contain non-WebKit engines! – yet simultaneously Apple claims MacOS is secure and private:
Designed to protect your privacy. Mac gives you the freedom to choose what you share and how you share it, so you can use apps more securely, protect your data, and keep yourself safer on the web…
Advanced security comes standard on Mac. By integrating Mac with Apple silicon and macOS, Apple builds security protections into Mac from the ground up. Every Mac comes with industry-leading encryption and robust virus protections.
Linux, Windows, and Android are similar. Such magical Operating Systems! If only Apple knew how to contact the developers of MacOS.
Another fun part was when James Heppell (OWA) pointed out that he was not paid by anyone and, like the other two folks there from Open Web Advocacy, had travelled to Brussels and booked a hotel on his own dime:
I’m just a student. I volunteer because I truly believe in the open web. I don’t get paid. I don’t receive any compensation. I paid for myself to be here because I want to be.
Kyle replied, with jaw-dropping condescension,
I am not in any way disparaging where you’re coming from. I understand you’re a well-meaning person who believes that he understands how to best design our operating system. I get that.
However, Kyle didn’t mention anything about the funding of ACT/ The App Association (“a global policy trade association for small and medium-sized technology companies”) who were always on hand to ask softball questions. Presumably he knows that ACT receives more than half its funding from Apple.
My favourite Pinocchio-nasal-expansion moment was Apple’s Kyle Andeer claiming “You won’t see Apple telling any developers what to do in their app”. They probably wouldn’t be getting half of the regulatory attention they’re enjoying now if the App Store rules hadn’t imposed rule 2.5.6: “Apps that browse the web must use the appropriate WebKit framework and WebKit JavaScript”, or imperiously decreed that they must use Apple’s payment service.
The experience of attending online is very different from being there in person. Asking questions over Slido in only 280 characters is very hard. I wished that the Slido questions were asked in order of the number of upvotes they received.
I didn’t especially like that the questions were bagged up into groups before the Gatekeepers answered; it made it easy to forget the details, or (gasp!) to evade them. Perhaps Gatekeepers should give shorter initial presentations, and questions answered one by one.
Lucia Bonova, Queen of the DMA, attempted to keep Apple to schedule, and moderated the day with good humour, continually mocking John Ozbay who frankly deserves it because he’s handsome, talented, fabulously wealthy yet an all-round good guy (the bastard).
I made these transcripts using MacWhisper from the official video recording. I manually corrected the passages I quoted above, so those are more accurate than these raw transcripts. Apologies if the software or I mis-spelled a name!
I’m jolly thrilled that my third album, On The Air, is now out. The theme of this album, I realised after writing all the songs, is the power of radio broadcasting – for good, or for ill. As ever, my friend Tony Sherrard (of The Very Things and Silverlake) contributed a lot of bass guitar, drum programming, good ideas, good ears, and knob-twiddling. Millsy also contributed live drums on the song Silka, Wearing Fancy Dress.