11. Cybersecurity at Risk: How the EU’s Digital Markets Act Could Undermine Security across Mobile Operating Systems
- Author:
- Matthias Bauer and Dyuti Pandya
- Publication Date:
- 02-2025
- Content Type:
- Policy Brief
- Institution:
- European Centre for International Political Economy (ECIPE)
- Abstract:
- The EU’s fight against cybersecurity threats risks being undermined by the over-enforcement of the Digital Markets Act (DMA). Article 5(4) could force mobile operating system providers to allow unregulated external links, bypassing critical security controls and exposing millions of smartphone users to cyber threats. The DMA focuses on market structure, overlooking how differences in operating system design affect security vulnerabilities. A one-size-fits-all approach ignores platform-specific security needs, leaving European users exposed to cyber threats. This risks undermining the EU’s economic security agenda, including initiatives like the Cybersecurity Strategy, Cyber Resilience Act, and NIS2 Directive, which aim to strengthen digital defences. The unintended consequences of this regulatory approach are already evident in Apple’s recent decisions to withhold certain features – such as advanced AI functionalities and enhanced app security tools – from the EU market due to DMA-related concerns. As a result, EU consumers face reduced access to innovative technologies, diminished user experiences, and weaker security protections compared to users in other regions. Now, Android, a widely used open-source system, may also be compromised by DMA enforcement, potentially limiting its flexibility, security, and the broader ecosystem of app developers and device manufacturers that rely on its open architecture.
- Topic:
- European Union, Cybersecurity, Digital Economy, and Digital Markets Act (DMA)
- Political Geography:
- Europe