· artificial intelligence · 5 min read
AI and cloud briefing: the EU forces Google open, plus three cyber security alerts
A factual briefing for 28 July 2026: the EU orders Google to open Android and search data to AI rivals, and we round up three cyber security alerts businesses should act on: a record Microsoft Patch Tuesday, an actively exploited WordPress flaw, and a ransomware breach at Coca-Cola's Fairlife dairy unit.

Here is our latest round-up of what matters in AI and cloud for UK businesses. It is short and factual, with links to credible sources so you can read further.
Lead story: the EU forces Google to open Android and Search to AI rivals
The European Commission has adopted two binding decisions under the Digital Markets Act, announced on 16 July, requiring Google to give competing AI assistants and search engines the same access to Android and Google Search that it currently reserves for its own products. Google must open 11 Android capabilities across five categories, covering invocation, context, actions, system services and on-device machine-learning resources, so that a rival AI assistant can be triggered by voice in the same way as “Hey Google”. Google must also start sharing anonymised search data with competing search engines and AI chatbots from January 2027, with full Android AI assistant access due by August 2027.

These are specification decisions, not fines: they convert obligations Google already carried into concrete engineering requirements, following roughly two years of talks that failed to produce a workable remedy. Google has objected. Kent Walker, its president of global affairs, said in a 16 July statement that the decisions risk weakening “vital privacy and security guardrails” for European users, and the company is expected to appeal. That appeal will not buy Google time, though: a July 2026 court ruling in the related Apple gatekeeper cases established that designated gatekeepers must comply with DMA obligations while any appeal is heard, rather than being able to pause compliance in the meantime.
Why this matters: this is one of the most significant regulatory interventions yet into how a dominant AI ecosystem is built, not just how it is marketed. If it holds, rival AI assistants could become far more capable on Android devices almost overnight by industry standards, and smaller search and AI providers could gain access to data that today only Google has. For any UK business that has standardised on Android or Google Search, the competitive landscape around AI assistants may look different within 18 months.
What to do this week:
- If your business builds on or integrates with Android or Google Search, watch for API and access changes rolling out from January 2027.
- Consider whether easier switching between AI assistants changes which one your business should standardise on, or whether it is worth waiting to see how rivals respond.
- Treat this as one of several signals that regulators are now willing to intervene directly in how AI products are built. Expect more decisions like this to follow.
Cyber security round-up: three alerts worth your attention this week
1. Microsoft ships its biggest Patch Tuesday on record
Microsoft’s July 2026 Patch Tuesday fixed 622 vulnerabilities, roughly triple June’s total and the largest single release on record. Three were zero-days: two, in SharePoint Server and Active Directory Federation Services, were already being exploited before a fix existed, and a third, a BitLocker bypass, was publicly known ahead of the patch. The update also closes a critical elevation-of-privilege flaw in the Windows Hyper-V virtual switch, rated 9.9 out of 10 for severity. In total, 62 of the 622 fixes are rated Critical.

What to do: confirm your SharePoint Server and AD FS systems are patched, since these were under active attack, and check the Hyper-V virtual switch fix has been applied if you run it.
2. An actively exploited WordPress flaw needs no credentials at all
CISA added CVE-2026-63030, nicknamed “wp2shell”, to its Known Exploited Vulnerabilities catalogue on 21 July. The flaw chains a route-confusion bug in WordPress Core’s REST API batch endpoint with a SQL injection weakness, letting an unauthenticated attacker run arbitrary code on a default WordPress installation, no plugins and no credentials needed. It affects WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2.

What to do: if you or your web agency run WordPress, check your version now and update immediately if you are on an affected release. This is one of the more dangerous kinds of flaw, since it needs no login at all.
3. Ransomware halts Coca-Cola’s Fairlife dairy plants
Coca-Cola disclosed on 16 July that a ransomware attack had disrupted its Fairlife dairy subsidiary, forcing a temporary halt to production at four US facilities while Canadian operations continued as normal. The Anubis ransomware group claimed responsibility and said it had stolen around 1 terabyte of corporate data. After Coca-Cola did not meet its deadline, Anubis published the stolen files on its leak site. Coca-Cola has confirmed the data theft and says most Fairlife production has since resumed, with no reported impact on product safety.

What to do: if you rely on suppliers whose production or logistics systems connect to their IT networks, ask how those systems are segmented, and review your own backup plan for operational systems, not just office data.
The takeaway
Four stories, one thread: regulators, attackers and vendors are all reshaping the rules businesses operate under, often within the same week. Staying current on AI regulation, patching promptly, and testing your incident response plan all matter more as these changes stack up. If you would like help reviewing your AI strategy or your security posture, get in touch.
AI Agent based research and content, AI can do mistake, please help us to improve.