What if Google could decide who has access to your banking app? Or to your future digital wallet? On 22 April, at Google Cloud Next in Las Vegas, Google announced Google Cloud Fraud Defense, billed as ‘the next evolution of reCaptcha’. The wording is marketing-speak, but the substance is structural.
Behind the announcement of a web security service lies an architectural shift whose implications for European digital sovereignty have, to date, not been the subject of any known regulatory process, any major parliamentary debate, or any coordinated institutional response in Europe.
This silence is telling. It reveals something about the true nature of European digital sovereignty — not as a non-existent political project, but as rhetoric that remains largely disconnected from the practical mechanisms through which control over digital infrastructure is played out, quietly, in the product management decisions of a handful of American companies.
The mechanism
Fraud Defense works as follows: when a website detects suspicious traffic, it no longer necessarily presents the user with the traditional image puzzle. Instead, it displays a QR code. The user scans it with their smartphone. The smartphone then sends a cryptographic certificate to Google’s servers via Google Play Services, confirming that the device is certified, unmodified and approved. Access is granted – or denied.
What appears to be an anti-fraud mechanism is also an infrastructure for authentication and validation. Every successfully completed challenge sends a signal to Google: a certified device has accessed a particular service at a specific time. The device’s authentication therefore not only determines access – it also creates the potential for correlation based on a stable hardware identity.
The documentation detailing this dependency on Play Services had been online since October 2025 – seven months before the issue came to public attention, and even before the official announcement at Cloud Next. Existing reCAPTCHA customers, used by millions of websites worldwide, were migrated to this new system without any major public communication regarding the architectural implications of the change.
2023: when Google asked the question
To understand what happened in 2026, we need to go back to 2023. In June of that year, a Google engineer named Yoav Weiss submitted a proposal entitled ‘Web Environment Integrity’ to web standards bodies. The principle was straightforward: before serving a page, a server could require a cryptographic certificate proving that the browser was running on a certified device.
The Mozilla Foundation issued a formal statement within a few days: the proposal “works against the interests of users” and “creates a closed internet controlled by OS and device manufacturers”. The Electronic Frontier Foundation described it as “Google’s plan to put the web under DRM”. Developer organisations around the world rejected the proposal. Google withdrew the proposal three weeks after it was published.
This withdrawal was seen as a victory for the digital civil society. That was probably a misinterpretation. It wasn’t necessarily a defeat for Google. It may have been a test of approach.
The lesson learned from 2023 seems clear: the open web standardisation process can block a proposal. It cannot necessarily block a commercial product that has already been rolled out. In 2026, Google did not submit a proposal. Instead, it launched a product, integrated its existing customers, and quietly documented the hardware requirements several months before the issue became public knowledge.
Justification: genuine and exploited
Google does not present Fraud Defense as a monitoring mechanism. The company presents it as a response to a real and documented threat: the ‘agent-driven web’, that is, the emergence of autonomous AI agents capable of carrying out complex transactions on the web without human intervention. The argument is not hypothetical. Google cites its own security data: the time taken between an initial malicious access and a secondary actor is said to have fallen from 8 hours to 22 seconds in three years. Today’s bots no longer simply click boxes – they reason, plan and execute.
The security justification is therefore valid. However, it also masks structural implications that are rarely mentioned in the group’s official communications: the reliance on Google Play Services for QR codes, the de facto exclusion of certain alternative Android environments, and the difficulty for browsers that refuse to integrate certain proprietary mechanisms to participate in this chain of trust.
This is particularly true of Firefox on Android, which by design refuses to integrate Play Integrity, and of GrapheneOS, a hardened Android system recommended by the Electronic Frontier Foundation and used in sensitive environments by journalists, lawyers and security researchers.
It cannot be said that the threat posed by malicious AI agents does not exist. However, it is clear that the chosen solution produces structural side effects similar to those that standardisation bodies had rejected three years earlier.
eIDAS 2: how Europe has set itself a trap
This is where the issue becomes more complex – and more uncomfortable for advocates of European digital sovereignty. For the problem is not merely that Google acts in accordance with its own commercial logic. The problem is that Europe, at the same time, is indirectly funding and legitimising some of the very mechanisms against which it claims to want to protect itself.
The eIDAS Regulation 2 (2024/1183), adopted by the European Parliament in February 2024 and which came into force in May 2024, is the most ambitious project ever launched by the European Union in the field of sovereign digital identity. It requires each Member State to provide its citizens with a digital identity wallet – the Eudi Wallet – by the end of 2026. The code must be open source. Data is stored locally on the device. The design is privacy-by-design. The wallet must function in an interoperable manner across all 27 Member States.
On paper, the project follows a radically different approach to that of Fraud Defense. In practice, however, the two systems converge on the same critical point: the terminal’s hardware authentication.
To ensure the security of these wallets – including fraud prevention, detection of compromised devices and resistance to emulators – eIDAS 2 requires mechanisms for biometric verification and device integrity. However, the only hardware attestation infrastructures currently deployed on a large scale on consumer smartphones are Google’s Play Integrity API and Apple’s App Attest.
The result: several European public authorities, faced with very tight implementation deadlines, are already relying on these technological building blocks for services relating to digital identity, payments and age verification. This is not complicity. It is a structural dependency resulting from the combination of high regulatory ambitions and fragmented industrial capabilities. The technical specifications for eIDAS 2 were still incomplete in early 2026. Faced with the December 2026 deadline, national development teams took the path of least resistance. Apple and Google were already there. The sovereign alternative, however, was not yet in place.
A thread posted by the GrapheneOS team on X sums up the contradiction: “Instead of preventing Apple and Google from engaging in blatantly anti-competitive behaviour, governments are directly involved in stifling competition through their own services.”
The European players are there; it’s just that nobody is linking them together
The question is not whether Europe has the players capable of building a sovereign alternative for hardware-based authentication. It does. The question is why no one has yet established the link between these players and the specific requirements of eIDAS 2.
Infineon Technologies manufactures security chips used in European biometric passports, national electronic ID cards and several eIDAS-related projects. Its expertise in secure elements and TPMs makes it a natural candidate for a sovereign chain of trust. However, the group operates primarily in the government and industrial infrastructure sectors, not in the consumer smartphone market.
NXP Semiconductors plays a key role in NFC payments, transport and European electronic ID documents. Its technology is already used in critical components of the continent’s trust chain.
STMicroelectronics is the creator of OP-TEE, an open-source secure execution environment that has become a global benchmark in Trusted Execution Environments.
Thales supplies Common Criteria-certified HSMs used in critical government and banking infrastructures.
These stakeholders possess the necessary technical expertise. What they do not yet have, collectively, is a coordinated industrial roadmap that would enable them to provide a sovereign alternative to smartphone-based authentication across all 27 Member States within the timeframe set by eIDAS 2.
Above all, no European institution appears to have publicly orchestrated this convergence.
What institutional silence reveals
The European Commission is pursuing DMA proceedings against Google on several fronts: search engines, Android and programmatic advertising. These proceedings are high-profile, well-documented and, at times, dramatic.
Google Fraud Defense does not fall into any of these categories. It is neither a search engine nor an app store. It is a B2B service that can be enabled with just a few lines of code, and which can gradually transform access to certain web services into access that is conditional upon private certification.
There is a legal argument for regarding the Play Integrity API as a form of intermediary service within the meaning of the DMA, insofar as it makes access between users and third-party services conditional upon certification controlled by Google. To date, this argument has not yet been tested in court.
The DSA (Digital Services Act) could provide a second angle of analysis through its transparency requirements and issues of non-discriminatory access. Here too, there are currently no known proceedings that explicitly address this area.
Above all, this silence highlights a structural weakness in European digital sovereignty policy: its ability to regulate visible markets remains more advanced than its ability to anticipate the infrastructural mechanisms through which technological dependencies are cemented.
The moment that counts
What unfolded between 2023 and 2026 goes far beyond a mere story of cybersecurity. It is a chapter in the history of technological governance. In 2023, the democratic process of web standardisation worked: a proposal was submitted, debated and then rejected by a coalition of technical and civil society stakeholders. In 2026, this same mechanism was circumvented not by force, but by commercial logic. The proposal became a product. There was virtually no public debate. Customers were integrated into a new architecture without any political confrontation equivalent to that of 2023.
Historically, the open internet was based on a simple principle: no private company could unilaterally determine the technical conditions for access to the shared infrastructure. This principle remains intact in law. In practice, however, it is gradually becoming subject to conditions. And this condition has emerged without any real structured European political debate on its implications.
European digital sovereignty is not a myth. It is a genuine endeavour, backed by strong industrial players, an ambitious regulatory framework and tangible political will. But as long as the sovereignty policy focuses primarily on the visible layers of the market whilst dependence continues to grow in the lower layers of the infrastructure – hardware, attestation, certification – the term remains hollow precisely where it becomes strategic.



