惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

IT之家
IT之家
N
Netflix TechBlog - Medium
Microsoft Security Blog
Microsoft Security Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Stack Overflow Blog
Stack Overflow Blog
量子位
Cyberwarzone
Cyberwarzone
Hugging Face - Blog
Hugging Face - Blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
D
Darknet – Hacking Tools, Hacker News & Cyber Security
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Simon Willison's Weblog
Simon Willison's Weblog
Know Your Adversary
Know Your Adversary
T
The Exploit Database - CXSecurity.com
Security Latest
Security Latest
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Scott Helme
Scott Helme
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
D
Docker
大猫的无限游戏
大猫的无限游戏
宝玉的分享
宝玉的分享
人人都是产品经理
人人都是产品经理
M
MIT News - Artificial intelligence
Hacker News: Ask HN
Hacker News: Ask HN
SecWiki News
SecWiki News
F
Full Disclosure
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
H
Heimdal Security Blog
Google DeepMind News
Google DeepMind News
Recorded Future
Recorded Future
Cloudbric
Cloudbric
W
WeLiveSecurity
S
Schneier on Security
Project Zero
Project Zero
T
Threat Research - Cisco Blogs
罗磊的独立博客
Schneier on Security
Schneier on Security
G
Google Developers Blog
Cisco Talos Blog
Cisco Talos Blog
L
Lohrmann on Cybersecurity
A
Arctic Wolf
P
Privacy & Cybersecurity Law Blog
小众软件
小众软件
有赞技术团队
有赞技术团队
云风的 BLOG
云风的 BLOG
NISL@THU
NISL@THU
S
Security Affairs
Application and Cybersecurity Blog
Application and Cybersecurity Blog
www.infosecurity-magazine.com
www.infosecurity-magazine.com
博客园_首页

Featured Blogs - Forrester

Inclusive Design Is Automotive’s Overlooked Growth Opportunity B2B Social Media Influencers Have More Influence Than Ever Comcast Split Puts NBCUniversal In Play What Technology Leaders Should Not Miss At Technology & Innovation Forum Central Why Your AI Strategy Needs A DEXM Solution: Lessons From Nexthink Masters Of Experience The Dawn Of The Accidental Developer The Next Era Of B2B Events: 8 Data-Backed Shifts Defining 2026 The Next Era Of B2B Events: Eight Data-Backed Shifts Defining 2026 Identiverse 2026 Recap: Identity Security for Agentic AI Dominates Announcing The Forrester Wave™ On Extended Detection And Response Platforms: Platformization, AI, And…AI Announcing The Forrester Wave™ On Extended Detection And Response Platforms: Platformization, AI, And … AI Use EO 14409 As A Canary For Enterprise PQC Migration And Procurement Use The New Executive Order As A Canary For Enterprise PQC Migration And Procurement EO 14409 Makes PQC Migration A Multi-Year Operational Program For Federal Security Leaders New Executive Order Makes PQC Migration A Multiyear Operational Program For Federal Security Leaders AI Is Moving Fast, But Trust Is Struggling To Keep Up: Why Security And Risk Leaders Can’t Miss Forrester’s AI Forum Answer Engines Will Select Your Content. Your Digital Experience Has To Do More. Meta Gambles With Its Trust In Prediction Markets Don’t Just Hear About The IT Singularity — Work Through It At Our Austin Tech Forum Don’t Just Hear About The IT Singularity — Work Through It At Our NYC Tech Forum The Cost Of AI Productivity Is Less Creativity Dollars And Sense At FinOps X 2026: Is AI Value Management Bigger Than FinOps? Quantum Security Is No Longer Optional: A Practical Blueprint For Successful Implementation The AI Orchestration Layer In Banking Is The New Battleground The Canary in the CDP Mine: Databricks CustomerLake Is The Litmus Test For Agentic Marketing The Canary in the CDP Mine: Databricks CustomerLake Is The Litmus Test For Agentic Marketing AI Forces A Redesign Of How Marketing And Agencies Work The IT Singularity Is Here: Announcing Forrester’s 2026 Technology Events Nuvei Makes Its B2B Cross-border Payment Move: The Payoneer Acquisition Google Dethrones OpenAI As Agencies’ Preferred AI Partner When Algorithms And LLMs Become Sellers, Your Commerce Strategy Must Change Google Goes All-In: An AI-Operated System, Not AI-Assisted Products Cisco’s Platform Push: Big Vision, Real Questions Retail's Incremental Total Experience Shift: Select Brands See Significant Improvement It's Time To Elevate Journeys Into Decision Systems AI Agents Need Real-Time Context: Data Streaming Is How You Are Going To Get It Tackle Enterprise AI’s Hardest Question At Forrester’s AI Forums Building The Human Foundation For AI At CX Forum East What Separates Scalable AI-Driven Innovation From Promising Experiments Hyland CommunityLive 2026: A Call To Action for Enterprise Content Management Leaders Call For Entries: Forrester’s B2B Forum EMEA 2026 Awards AI Agents Are Your New Customer. But Can You Target and Grow Their Trust in Your Brand? Survey Insights: How Business Applications Are Purchased Governance: New Strategy, Old Hands On The Wheel … US Health Insurers Show Experience Improvements Announcing The 2026 Forrester Wave™ On Accounts Payable Invoice Automation Announcing The Forrester Wave™: Accounts Payable Invoice Automation Software, Q2 2026 US Banks’ Total Experience Is Improving, But Most Still Have Work To Do UK Social Media Ban Forces Platform Accountability Total Recall: A Cautionary Fable Of Anthropic And The US Government Consumers Aren’t Ready To Delegate Payments To AI Agents Fox Makes $22B Roku Acquisition Bet Secure The Future Of Internet Traffic As Agents Take Over Coupa’s Inspire 2026 Unveils A Strategy And Acquisition Spree To Build The Autonomous Spend Management “Network” A Fake PLG Strategy Is Exposed Through Your Digital Commerce Experiences Conway’s Law: Your Operating Model Matters More Than The AI Model Turn Application Portfolio Rationalization Into A Continuous Optimization Capability Healthcare And Life Sciences: Turning AI Momentum Into Lasting Value How To Build A Loyalty Team That Scales With Your Program Align B2B Marketing Teams To Thrive In A Buyer-Centric World OpenAI’s Proposed IPO Opens A Trifecta Of Opportunities For It, But Don’t Lock In Just Yet Retention-As-A-Service Is An Intriguing Idea — Here’s What It Actually Means Customer Success And Customer Experience: The Difference Is More Than Semantic How Fable 5 And Mythos 5 Change AI Security, Data Retention, And Vendor Risk Announcing Forrester’s Top Cybersecurity Threats For 2026 Your AI Bill Is A Context Problem Build The Human Foundations Before You Scale AI The State Of Agentic AI In 2026: Companies Are Chasing, Few Are Catching Move Over WAF. The Web Application Protection Platform Takes Over Microsoft Build 2026: Pushing The Frontier With A More Opinionated AI Playbook Anthropic’s Proposed IPO Will Change The Economics Of Enterprise AI AI Is Forging A New RevOps Identity AI Is Forging A New RevOps Identity Build Meaning Before Machines: Why Semantics, Ontologies, And Knowledge Graphs Matter For Agentic AI Red Hat Summit 2026: Can Red Hat Win Its Claim As The Hybrid AI Control Plane? Ad Creative Is A Technology Problem And Opportunity The State Of Portfolio And Product Marketing In 2026 Miro’s Big Bet: Can A Whiteboard Company Become The AI Decisioning Layer For The Enterprise? Agents Are In The Aisle: The 2026 NRF APAC Innovators To Watch Italy’s B2B Marketing Challenge Is Not Strategy — It’s Focus And Alignment If Buyers Change How They Search, Marketing Must Change How It Shows Up European B2B Marketing Has A Data Problem, Not A Vision Problem The AppGen And Low-Code Platforms Landscape, Q2 2026, Is Out! What Anthropic’s Two Recent Announcements Mean For Manufacturers Agentic AI In Insurance: Stop Chasing Autonomous Agents. Start Engineering Trust. The Consolidation Wars: M&A Is Rewriting Finance Automation Seven Ways To Turn CX Forum East Analyst Time Into Real Momentum Seven Ways To Turn CX Forum West Analyst Time Into Real Momentum Leading With Intention: What Women Leaders Told Us About AI And The Future Of Work Redesign B2B2C Digital Strategy For The AI Era Marketplace Platforms Aren’t One Market Anymore: Announcing Forrester’s Two Landscapes For 2026 The State Of Agentic Commerce In Mid-2026 If Your Employees Aren’t Ready For AI, Neither Is Your Business Announcing The Forrester Wave™: Governance, Risk, And Compliance Platforms, Q2 2026 Financial Well-Being Is Under Pressure — A Strategic Priority For Banks TeamViewer Connect: A Pragmatic Look At How IT Can Level Up DEX Freshworks Signals A More Practical Future For AI Service Management Zendesk Relate 2026 Showed Why Agentic Customer Service Starts With Knowledge
The EU’s Digital Markets Act Meets The Mobile OS, Round 2
Paddy Harrington · 2026-06-25 · via Featured Blogs - Forrester

Currently, there is some contention between the leading mobile OS providers, Apple and Google, and the EU Commission with regards to the Digital Markets Act (DMA) and it’s put me in a bit of a dilemma. Consumers should be able to do what they want with devices they purchase. But is there an obligation for OS developers, no matter the underlying platform (desktop, mobile, IoT, or OT), to protect the user from themselves? Let me explain.

A quick perusal of the DMA shows that it’s about ensuring fairness and competition when it comes to what they call “gatekeepers”; large digital platforms, like Amazon, Apple, Alphabet (Google), Meta, or Microsoft that provide core services like search and app stores. For Apple and Google, “gatekeepers” for mobile devices means these providers aren’t just offering an OS, but a plethora of services that have direct ties into the OS; app store, virtual assistant, search capabilities, browsers, and email to name a few. When it comes to mobile apps, Google has been transparent about fairness and interoperability as Android allows using other apps stores, side-loading of apps, and switching the default of any Google provided app to a third-party. Apple has, until rather recently, been more closed and have made many structural changes to allow third-parties access to the same functions. These changes only directly impact EU-resident of Apple (and now Japan) and that comes across as a slight to non-EU customers and developers as they should open the platforms for all customers globally, but that’s a different issue. Where things get heated is when we turn to AI and the DMA’s Article 6(7).

Yes, six seven. The meme has become something real.

There is nothing specific in the DMA with regards to artificial intelligence, only to virtual assistants and that the same level of access the native virtual assistants have should apply to any 3rd party assistant that the phone’s owner wants to use. However, because the current assistants shipped by Apple and Google are using AI, some of the arguments have become how the AI brought in through the third-party virtual assistants can access the same things that Apple and Google’s assistants’ access. This is where things can quickly go off the rails and brings us to that crossroads.

Malware on smartphones is a serious problem, and we’re not just talking about apps that are sideloaded or downloaded from 3rd party stores; both Apple and Google have had malware/spyware/trojans within apps hosted on their maintained app stores. These apps steal data, hijack identities, or possibly allow an attacker to compromise other apps and damage the user. Because of mobile OSs are designed, it’s rare when mobile malware can access the OS core and fully compromise the device. But by forcing open this door into the area where mobile virtual assistants play – interacting with the user for their input, retrieving and submitting information into any app that’s requested by the user, the changing settings within the OS, accessing the sensors, and, in the case of Google, access to the searches that the user has done through their account – the EU commissioners are playing with fire. Virtual assistants directly interact with your applications, have read/write access to system configurations, stay resident on the system, in the context of Google, have access to all other components, including search history, from your Google account, etc, and if that assistant is malicious, not only would local device data be compromised, your account data, data from other apps on the device, or even data from websites your accessed through that assistant could be compromised. But we also have to consider AI agents as virtual assistants.

AI agents act on your behalf, but they are not you. They have their own identity and when interacting with various layers on an endpoint or enterprise, they will take all necessary actions to complete their tasks and there have been occurrences where an agent took malicious actions, even when prompted not to. In the case of a smartphone, an AI-based virtual assistant could easily – either prompted by an attacker or simply by hallucination – prompt a user to take an inappropriate action and expose themselves, or their business, to compromise.

The drive for fairness by the EU commissioners and those who want control of the devices they own, and the data associated with them is fair. So long as they acknowledge that if they do something silly with those devices, like downloading a random AI-powered virtual assistant and installing it on their smartphone, they should be responsible for the consequences of their actions. But is your average user, consumer or corporate, computer and cybersecurity savvy enough to know how to avoid unsavory apps and agents. What about business leaders? And defaulting to “our endpoint security solution will pick up any malicious actions” is invalid because data from our 2026 Forrester Security Survey says only about 40% of environments are using mobile antivirus and 35% are using mobile threat defense – the equivalent of EDR for mobile. So, unless more security leaders begin deploying mobile threat defense (MTD) solutions, they’re not going to have much insight into what if their users are using their mobile devices safely. And if they’re not deploying MTD on the BYO devices that are connecting to company resources, they end up with a compromised mobile device containing a rogue virtual assistant that could pilfer data or spread malware within your organization.

Forrester clients interested in this topic should connect with me to discuss via an inquiry or guidance session.