← Back to context

Comment by peterspath

7 days ago

It’s the DMA regulation that forces Apple to give the same access as they have to other AI chat apps.

Once it leaves the device Apple does not know what those other ai chat apps will do with the gathered data.

> Siri AI is private by design and deeply integrated across Apple’s platforms using on-device processing and Private Cloud Compute, which extends the privacy and security of iPhone into the cloud. However, under EU regulators’ extreme interpretation of the DMA, Apple would have to give any virtual assistant direct access to users’ private data — and the ability to directly control other installed applications — as soon as Siri AI is made available in the EU, without the essential protections necessary to keep users and their data safe.

https://www.apple.com/newsroom/2026/06/due-to-dma-siri-ai-de...

Apple loves to play dumb about this stuff. The EU imposes a pretty straightforward regulation regarding equality of access. Apple seems to come up with all sorts of "solutions" to this "problem", and each one never amounts to true equality of access. They could easily just allow users to decide "Do you want to give this app unfettered access to all your device data, including other apps' data?". Let users decide. 99% of Apple users in the EU will probably click "no". I'm sure they'll make the user warnings scary enough to ward off anybody who doesn't know what's going on.

There are 2 potential outcomes: either the sky really does fall, and there's a meaningful uptick in bad things happening to iPhone users, in which Apple can easily point the finger at the EC and say "they made us do this". Apple looks like the good guys who put up a good fight for their users, but ultimately their hands were tied, and they'll probably get the revisions to EU law they're so desperately fighting for.

The other possibility is that the sky does not fall, and Apple looks both silly and malicious at the same time for ever having suggested that it would, which was clearly in bad faith.

Clearly, Apple cannot afford scenario #2, so I think they will probably never give their users the actual freedom that the MDA requires them to. They will just exit Europe entirely before allowing that to happen.

  • > Do you want to give this app unfettered access to all your device data, including other apps' data?

    Which Facebook and instagram will present as “tee hee updated terms of service” in the first 15 seconds, and people will tick it, because they’re not interested in reading T&C’s, just want to message their friend about dinner, and aren’t suddenly expected be deceived like that.

    • Obviously there should be a system dialog to grant system permissions. I'm not aware of any kind of system with a capability-based permissions system (e.g. Android, MacOS, browsers, etc.) where apps are allowed to show their own dialog to request permissions. You always have to do something in the system settings to grant permissions.

      That's how it should be done. And that would be the responsible way to comply with the DMA.

    • Did they really circumvent this exact restriction which was imposed on them on OS level by Apple?

  • > There are 2 potential outcomes: either the sky really does fall, and there's a meaningful uptick in bad things happening to iPhone users, in which Apple can easily point the finger at the EC and say "they made us do this". Apple looks like the good guys who put up a good fight for their users, but ultimately their hands were tied, and they'll probably get the revisions to EU law they're so desperately fighting for. > > The other possibility is that the sky does not fall, and Apple looks both silly and malicious at the same time for ever having suggested that it would, which was clearly in bad faith.

    I think the most likely outcome is between these two extremes. My personal data ends up sold to shady companies who use it to target ever more invasive advertising at me in places I wouldn't expect/. Like a boiling frog, I won't really notice the difference and my life will gradually become a little shittier.

    • Then just click "no" if your phone ever asks you to grant permissions like this to a third party app, which should obviously be the default option. Or better yet, don't install the third party apps to begin with. For you, it will be as though nothing has changed.

      For the people who want a bit of freedom though, their lives will suddenly get a lot better.

  • > There are 2 potential outcomes: either the sky really does fall, and there's a meaningful uptick in bad things happening to iPhone users, in which Apple can easily point the finger at the EC and say "they made us do this". Apple looks like the good guys who put up a good fight for their users, but ultimately their hands were tied, and they'll probably get the revisions to EU law they're so desperately fighting for.

    I'd prefer they focus on safeguarding my data instead of playing a ridiculous game of brinksmanship with regulators to make a point.

    • I agree. Safeguarding data and user freedom are 100% compatible, no brinkmanship required.

  • > There are 2 potential outcomes: either the sky really does fall, and there's a meaningful uptick in bad things happening to iPhone users, in which Apple can easily point the finger at the EC and say "they made us do this". Apple looks like the good guys who put up a good fight for their users, but ultimately their hands were tied, and they'll probably get the revisions to EU law they're so desperately fighting for.

    I don't think that is what will happen. People, and the media, will blame Apple: it is them after all giving that data over because they hold it. No that doesn't make logical sense, but that has never mattered before why would it matter now.

    Once Apple loses that trust re. data privacy, its gone forever. I get why they're being particular about it.

    • People will absolutely not blame Apple if the exact thing they warned would happen, and said would be really bad, actually turns out to happen and be really bad.

      Apple has very well-funded PR. They will make sure that the EC is blamed.

      Then, they get to be the heroes once the law is changed to allow them to come to everyone's rescue by banishing all third-party app access forever. They would ultimately be the saviours.

      1 reply →

    • Yeah and we've already seen this with Facebook getting blamed for Cambridge Analytica.

> EU regulators’ extreme interpretation of the DMA

It's not extreme interpretation, it's the intent.

Just say it would break your vendor lock-in.

  • I don't want my apps that have AI implemented to be able to read my messages because Europe mandates feature parity. And that's just the tip of the iceberg. For Apple it means building all the APIs that probably already exist but this time to be requested by apps, which would be a huge attack surface, even Apple's own apps suffers from security breaches (like Message before the switch to closed container execution). AI breaks the separation of concerns, which can lead to disastrous consequences.

    EU has great intentions, and of course, feature parity should be offered so that competition can exist, but I don't find it crazy that it is more complicated on a product like that. As tech people things are very obvious to us but we need to remember that we are talking about a product used by everyone.

    • It’s not clear how it is significantly different from allowing apps access to your contacts, calendar, photos, and so on. And Apple doesn’t say that they merely need more time to properly implement it, the claim that they are unable to implement it without compromising privacy and security. And the latter I don’t really see, with the proper set of permissions presented in the way users are already used to.

      As an Apple user I feel more patronized than empowered here.

      3 replies →

    • The law does not require Apple to grant all permissions to all apps for all users. It just requires Apple to ask users if the user wants to grant elevated permissions to specific apps that they download. The user can always say "no", which should obviously be the default.

      The situation is that Apple won't even allow users to grant elevated permissions to any 3rd party app, even if the user wants to.

      2 replies →

    • > don't want my apps that have AI implemented to be able to read my messages because Europe mandates feature parit

      App permissions.

      Beside you don't have to install any third party app, I only have Google assistant installed on my Android.

      I heard the same kind of talk when the eu forced apple to switch to USB C...

      There is a real, strong, monopolistic issue with some American companies that their government refuse to deal with because it's so corrupt. It would be fine if it didn't impact us in Europe, but it does.

    • > I don't want my apps that have AI implemented to be able to read my messages because Europe mandates feature parity.

      The AI provider would still be YOUR choice. You could stick with Apple's if you don't trust the other ones.

so to translate:

- Apple has powerful capabilities in iOS to enable Siri AI.

- EU's DMA requires them to allow users to install third-party AI backends.

- Apple doesn't think parties other than themselves should be trusted with those iOS permissions.

I guess it'd be like if Apple allowed a first-party screen reader for iOS, so they refused to allow third-party screen readers.

  • As a screen reader user, Apple does have a first party screen reader, VoiceOver, and does indeed not let you run a third party one. In fact, it does not work well even on the more open MacOS. So essentially it's VoiceOver or nothing. Luckily, especially on iOS, VoiceOver mostly works well.

    • I'm glad it works decently on iOS, at least. my mom has little central vision, and she struggles on iOS just using high contrast plus scaling plus magnifier. I think she has just enough vision to not absolutely need VoiceOver but it still makes using her phone a frustrating and tiring experience.

      1 reply →

  • > Apple doesn't think parties other than themselves should be trusted with those iOS permissions.

    I think we have ample evidence that regardless of whether Apple in particular is to be trusted, tech companies by default are certainly not.

    Opening up access to users’ private data requires not just any given app to be trustworthy, but all of them.

    • In this case I think it is true that 3rd parties can not be trusted with this capability, but Apple brought this on themselves by creating a ton of other capabilities like AirDrop, Airpods integrations, and apple watch capabilities which would have been safe for 3rd parties to use but keeping them locked down so you'd get a better experience with Apple accessories.

> Once it leaves the device Apple does not know what those other ai chat apps will do with the gathered data.

It's the user's data. Not Apple's. And it should be the user's right to send it to whoever for whatever results, imo

  • I think there’s a case that Apple’s commitment to privacy here will increase participation by 3rd party developers.

    For example, if I’m maintaining a secure chat app, I think I’d be more likely to adopt the APIs to share the chat messages with the system AI due to Apple’s promises that the data will either be processed On Device, or in their Private Compute Cloud.

    If I instead believe that sharing the chat messages with the system AI would cause those messages to be sent to unknown-to-me other entities, I think I’d be less likely to participate in the new API.

    This user might be okay with their data going to this other provider, but what about the people they’re messaging? I have a responsibility and a commitment to _all_ of my users to protect their data.

    I might not be able to control what any specific user does with the data, but proactively writing the code that sends the chat messages to this other system is something that I have control over.

    • > This user might be okay with their data going to this other provider, but what about the people they’re messaging? I have a responsibility and a commitment to _all_ of my users to protect their data.

      That's nice of you but your users are going to just copy-paste data to and from ChatGPT anyway.

      1 reply →

    • That’s not your data, why do you think you have the right to prevent the user from doing what they want? Other users shared that chat data with each other, you have no right to that data, so as an app developer I’d say you should not care about the API.

  • And that's exactly how it works for apps you download from the App Store. Apple even makes app publishers declare data collection and privacy practices on the App Store before you install apps.

    It's clearly just Apple not wanting to further open up their platform to competition.

    • Not only that but it's an honour system they aren't checking any of the privacy policies or labels for accuracy, just last year a whole bunch of high-profile apps like Candy Crush Saga and Clash of Clans got caught claiming suitability for all ages while their privacy policies banned under 13s so they could advertise and collect data indiscriminately.

      1 reply →

  • Meta would probably start a massive ad campain to pay people money to install Meta iPhone AI.

    • They wouldn’t even need to do that. It’s pretty easy to come up with any number of pernicious approaches they’d use:

      - “instagram is better with MetaAi: yes/ask-me-later”.

      - updated ToS which bundles a “we’ll use our own ai, and do whatever we waaaaant”

      Lying, gaslighting and underhanded “growth hacking” tricks are their bread-and-butter, and you can be sure that whatever they’d have you install would blindly slurp up as much as they possibly can with zero regard for user privacy.

> Once it leaves the device Apple does not know what those other ai chat apps will do with the gathered data.

Yeah, that's the whole fucking point.

> It’s the DMA regulation that forces Apple to give the same access as they have to other AI chat apps.

But why can Tesla ship Grok to their cars in the EU without any problems? Why aren't they required to let me choose between Grok, OpenAI etc or even a custom endpoint?

  • > But why can Tesla ship Grok to their cars in the EU without any problems?

    Simply because they are too small in user count. EU DMA, DSA etc. only apply at certain thresholds. Twitter for example falls under the scope, but Tesla is a distinct entity from Twitter and even if they were merged together, they would still be distinct services in the eye of the law.

  • Tesla is not marked as a gatekeeper by the EU and thus the law does not apply.

Translation:

Since it's the user's device, not Apple's, EU correctly "interprets" this as the user has the right to do whatever they please, including installing third-party chat apps.

Apple are just bulshitters when it comes to actual users, and not their corporate definition of a user.

BTW, did you know that in Japan, and in Japan only, you can change the Siri shortcut button to start other voice assistants? https://mjtsai.com/blog/2025/11/18/ios-26-2-third-party-voic...

Or that they wouldn't let you set default maps app outside of the EU: https://mjtsai.com/blog/2025/03/14/dma-compliance-default-ma...

  • > Or that they wouldn't let you set default maps app outside of the EU

    They were mandated to create a scheme in isolation on a deadline, without having input either from navigation apps or from consumers, and without any requirement that web browsers or other operating systems would need to support the same scheme.

    As another comment pointed out - it doesn't work. Websites and apps still integrate with a navigation product directly, rather than use this scheme. And why wouldn't they? Even if it was launched worldwide on iOS, it still is just a defined subset of any particular navigation product functionality. It also is just yet another navigation option to integrate into your platform, since the feature still wouldn't be available on desktops/Android.

    Until everyone is sitting at the table wanting to work towards interoperability, the feature simply can't work. So why perpetuate a broken chooser into other markets?

    • > They were mandated to create a scheme in isolation on a deadline

      Self-imposed isolation and deadline.

      > without having input either from navigation apps or from consumers

      Because Apple never asked either navigation app developers or consumers since "Apple knows best" and spent several years fighting DMA instead of implementing these features.

      > Websites and apps still integrate with a navigation product directly, rather than use this scheme.

      Because there was no scheme to begin with, and when Apple finally relented and made it, it only made it available in the EU.

      > Until everyone is sitting at the table wanting to work towards interoperability, the feature simply can't work.

      Yes, Apple doesn't want to sit at the table to work towards interoperability.

      Apple Maps was made default on iOS in 2012. They literally only implemented the "scheme" last year, 13 years later.

      DMA entered force in 2022. Apple had known about it coming for at least two years before that.

      And even without DMA that would be a proper thing to do to begin with which they had to be forced to do by government action.

  • This is such a shallow take. There are obvious privacy and security tradeoffs here. The EU competition framework is good in many ways, but this is actually something I don’t think we have the regulatory frameworks in place to handle yet , or social norms and understanding about why giving any Tom dick and Harry root on all your data is a bad idea.

    It’s paternalistic, but I agree with Apple that free for all access to this kind of data is not a great idea. Ironically, before this could work we’d actually need much more EU style data regulation, and more consistently enforced.

    • There's nothing shallow about my take.

      Apple uses "privacy and security" as a cudgel to prevent anyone from breaking into the vendor lock in. To the point that EU actually had to explicitly tell Apple what to do [1], as Apple delayed features, made them extremely hard or convoluted for third-parties to use, and pulled every trick out of the malicious compliance manual.

      This whole virtual assistants thing will drag on for another several years.

      Edit: I mean they show their models accessing and changing a password on the user's bank site at the same time as accessing and changing passwords on another random site. Which is one prompt away from exfiltrating user data. So spare me the "Apple knows best about privacy and security so they should keep any access to their platforms locked down"

      [1] https://digital-markets-act.ec.europa.eu/developer-portal/in...

      3 replies →

Sounds like Apple PR bullshit.

Unless Apple proves otherwise I'm more inclined to believe they're either 1. Using this to try and shape the DMA in their own interest (definitely not their users' interest) or 2. Doing something with the data that would not be allowed in the EU (also not in their users' interest at all) or both.