There's an easy way to put them into compliance violation:
Get a large brigade of android users to request access to source on each security update.