The recent decision by the European Commission in the Google Android case – defining interoperability obligations for the operating system under the Digital Markets Act (DMA) – is not just another Brussels acronym. It signals that Europe has decided to change gear: no longer chasing Big Tech with mega‑fines after years of investigations, but moving first, with clear rules and tighter timelines.
From endless proceedings to anticipatory regulation
For more than a decade, the major antitrust cases – from Google Shopping to Android, and the investigations into Apple and Meta – have all shared the same flaw: they arrived late. In the Android case, for instance, the Commission found an abuse and imposed a record fine of €4.34 billion in 2018 for practices that had already become entrenched by 2011 – a seven‑year gap between the spread of the unlawful conduct and the sanction. And only in 2026 did the Court of Justice finally close the judicial chapter, confirming a fine of €4.1 billion: in total, almost 15 years between the start of the practices and the end of the story in court. In the meantime, the European mobile market had already been structured around the integration of Android, Google Search and Chrome that the Commission ultimately deemed anti‑competitive.
The DMA is born of this frustration. If you take seven or ten years to declare a business practice unlawful, in terms of market dynamics you have already lost. What is needed are ex ante rules, with proceedings that are completed in twelve months rather than in a decade.
With the DMA, the EU changes the basic template. It no longer starts from a suspicion of abuse and then builds, case by case, a vast file. It starts from a clearly defined list of online platforms – the gatekeepers – and from a standard package of obligations that apply automatically to app stores, operating systems, search engines, social networks, messaging services and, increasingly, cloud services.
A code of conduct for digital giants
The logic of these interventions is ex ante: the aim is to prevent market effects of potential abuses, whereas previously the EU would impose fines only once competition had already been compromised. The underlying idea is that companies controlling essential digital infrastructure must not be allowed to use that position to close one or more markets that depend on that infrastructure.
In practice, this means:
- no shortcuts to favour a gatekeeper’s own services in search results (the Google Shopping scenario);
- no rules preventing developers from offering subscriptions and payments outside app stores (the Apple anti‑steering case);
- no operating systems that work smoothly only with their “home” devices and make life difficult for competing hardware (the Apple interoperability proceedings);
- no unlimited data harvesting as a precondition for using a “free” service (the Meta “pay or consent” model).
It is, in substance, a code of conduct for Big Tech, applicable to digital firms that exceed specified thresholds of turnover, users and intermediation power.
Shorter timelines, fewer excuses
The difference is not just philosophical; it is also about timing. The first non‑compliance decisions against Apple and Meta stem from proceedings opened on 25 March 2024 and concluded in April 2025 – just over one year. The Commission found breaches of the DMA, imposed a total of €700 million in fines and, crucially, ordered concrete changes to the App Store rules and Meta’s “pay or consent” model. The system has therefore changed: there is no longer time for endless “guidance” or self‑regulatory processes. If, twelve months after the compliance deadline, a Big Tech player is still non‑compliant, a non‑compliance decision follows – with fines, certainly, but not only fines, as we shall see.
In other words, Europe’s timing on monitoring and enforcement has been radically redesigned.
There is more. The DMA also reverses the classic evidentiary dynamic. It is no longer the Commission that must demonstrate, each time and from scratch, that a given practice has exclusionary effects. It is now the gatekeeper that must show, within the prescribed deadlines, how it is aligning itself with the obligations. In case of doubt, the regulator may intervene with specification decisions addressing, inter alia, APIs, interoperability and data‑sharing duties.
Targeting conduct, not just balance sheets
Another qualitative leap lies in the use of specification decisions. The Commission no longer confines itself to declarations of principle: it operationalises obligations by stepping directly into the technical design of services. These decisions define which APIs must be opened, which system functions must become interoperable, which data flows must be shared and subject to which anonymisation and security safeguards.
In Apple’s case, the Commission did not simply request “more interoperability” in the abstract. It identified nine connectivity functions between iPhones and third‑party devices – ranging from notifications to automatic audio switching, from Wi‑Fi peer‑to‑peer to media casting – and set out a release schedule, version by version of the operating system. On the Google side, the trajectory has been similar: on one hand, opening the AI layer of Android to assistants competing with Gemini; on the other, requiring Google to share, under fair, reasonable and non‑discriminatory conditions, part of the data that currently fuel Google Search alone.
Unsurprisingly, the major platforms have challenged this approach, invoking security and privacy risks. Apple warns of the dangers of “opening up” deep device functions to third‑party software beyond its control; Google argues that mandatory AI interoperability and search‑data access may create new attack surfaces and weaken user protection. These are concerns that must be taken seriously, because the DMA operates precisely on the boundary between market openness and data protection.
Yet the political core of Europe’s choice is clear: listen to the objections, reinforce technical safeguards, but do not renounce the principle that a dominant provider alone cannot decide who gets to interface with its operating system and its data. It is no longer only about fines to be booked; it is about a structural rebalancing of the relationships between platforms, developers and users, in which technical architecture becomes a field of regulation rather than merely an internal engineering concern.
A European regulatory experiment still underway
In essence, the DMA is a major regulatory experiment: importing into the digital and Internet sphere a model of oversight that looks more like network‑sector regulation than traditional competition law enforcement. With all the associated risks: boundaries still to be clarified, frictions with other legal regimes, and inevitable litigation.
But the political signal is unequivocal. Europe does not want to merely narrate abuses after the fact. It wants to write the rules of the game in advance, before new chokepoints – from artificial intelligence to cloud computing – harden into impenetrable ecosystems. If it manages to do so without stifling innovation, the DMA will become a reference model for those, elsewhere in the world, trying to hold together competition, fundamental rights and the power of digital platforms.
Categories: DMA, Electronic Commerce, Online platforms
