Google's head of Android platform security says Google has started to include the requirements for security patching into its OEM agreements
Mishaal Rahman / XDA Developers :
Context & Ripple Effects
This lands a month after researchers testing 1,200 Android phones from 2017 found OEMs frequently shipping devices without the patches they claimed to install — ZTE and TCL each skipping four or more. Google's answer is contractual: its head of Android platform security says patching requirements are now being written into the agreements that govern access to the ecosystem itself.
It is the first step in an escalation that later coverage makes explicit — by October 2018 a leaked contract required at least two years of updates for phones with 100K+ activations (per The Verge), and in 2020 Google followed with the Android Partner Vulnerability Initiative to audit OEM devices directly.
First-order effects
- OEMs signing new or renewed Android agreements now face patching obligations as a condition of the license, converting what was voluntary practice into enforceable terms for every device maker shipping Google services.
Second-order effects
- Vendors with weak update track records — the ones the Wired testing caught omitting patches — must either fund real monthly security engineering or risk their access to Google's apps and services, raising the cost floor for low-margin Android hardware.
Third-order effects
- If the pattern holds through the leaked two-year minimum and the APVI audits, Android's open-licensing model drifts toward Apple-style centralized control of device security lifecycles, with Google dictating update policy across hardware it does not build.
The trend: Android security is shifting from Google's own Nexus OTA program toward contractual enforcement over third-party OEMs, culminating years later in risk-based prioritized monthly updates.