Eight weeks ago, the European Commission concluded its review of the Digital Markets Act (DMA) – its landmark regulation of technology platforms. The Commission said that the regulation is fit for purpose and that its own performance under the Act merits high marks.
These are bold statements considering that innovation and new services are changing the nature of competition for designated gatekeepers – indeed for entire platform markets. The growth of AI assistants and the emergence of agentic AI are a profound development for technology markets. And so far, the DMA regulators do not seem to have a coherent concept for how they should think about these developments. And in the review, they failed to respond to a question that has bedeviled the DMA since its start: fit for what purpose, exactly?
The question is becoming far more piercing because the DMA is already intervening in AI markets – even if that may not be the intention. A recurring difficulty in technology governance is that regulatory frameworks assume relatively stable market structures and identifiable points of control. The DMA was born out of the European Commission’s frustration that traditional competition policy was too slow to discipline the platform economy: rules had to be set in advance (rather than reacting after harm occurs). As a theory, the DMA rested on some solid observations about the speed of market change and the desirability to have future-proof regulation. As a practice, however, the DMA has so far been a tool to address mostly old issues – some characteristics of the platform market in the 2010s.
In fact, it is not to stretch the argument to say that DMA regulators have, for the most part, been chasing their own ghosts of that era and aspired to control the market development in search, operating systems (OS), interoperability, and self-preferencing. A lot has happened under the DMA. However, the actual outcomes of all these DMA actions remain wanting – something the DMA review also admitted. Changing competition in markets with strong consumer experiences and preferences for simplicity, security, and trust has proven to be a tall order.
But even if these DMA actions are trying to “fix” old issues, they are now impacting the market for AI assistants and the emerging market for agentic AI. There is a discussion about how the DMA should incorporate AI assistants and chatbots, and what role market regulation should play. It is an important one. However, it neglects the fact that DMA actions are already impacting on the markets for AI assistants and agentic AI – and that DMA regulators, seemingly unintentionally, already aspire for more.
Take two very timely issues. First: some weeks ago, Apple announced that it cannot market Siri AI in the EU when it launches iOS27 and iPadOS 27 because of the DMA. More precisely, the way DMA regulators have implemented interoperability demands means that an OS with Siri AI would have to accept equal deep access for other AI assistants, even if they raise concerns over privacy and security.
And, secondly, the European Commission is just a few weeks away from announcing its decisions in the two specification proceedings with Google under the DMA. The provisional measures that were announced in April are very far reaching – so far reaching that even Google’s competitors felt necessary to respond to the Commission’s consultation! Both proceedings are going deep into the architectural design of Google search and Android OS, and they demand changes that are highly impactful for the market for AI assistants.
Like with Apple, these decisions can ultimately restrict what services that Google can offer in the EU. Alarmingly, Europe may soon be confronted with a scenario under which neither Apple nor Google can service the market with core AI functionality in the same way they do elsewhere.
These two examples reveal a lot about the DMA and why the Commission needs to develop a much better concept for how competition regulation should impact AI. The DMA access-interoperability demands put on the two companies do not intend to guide or control the market for AI assistants and agentic AI. This outcome is rather a consequence of the European Commission’s DMA implementation and the pursuit by regulators of a DMA that is excessively programmatic and not adaptive to actual market developments.
This approach also raises questions about the direct application of the DMA on AI assistants and agentic AI. In fact, it raises questions about whether the DMA is really fit for purpose – and, if so, for what purpose? In this Insight, we will dive deeper into the relationship between the DMA and the emerging AI market.
Converging Enforcement: The Limits of Ex Ante Antitrust in AI
Let’s start by landscaping Europe’s broad competition policy on matters of AI conduct. Alongside DMA enforcement against the platforms now integrating AI into core services, the Commission is scrutinising AI integration under traditional competition law (Article 102 TFEU), focusing on how control over key interfaces and inputs may affect downstream competition.
Although Google and Meta are designated gatekeepers and the services at issue are designated core platform services, both are subject to new investigations that were opened as antitrust rather than DMA cases. In the case of Google, the concerns centre on the use of third-party content in AI-driven search outputs such as AI Overviews and AI Mode: whether generative AI in search disintermediates content providers and shifts value towards the platform on terms publishers cannot meaningfully negotiate.
In the case of Meta, the focus is on whether restrictions on third-party AI assistants interacting with WhatsApp users could foreclose access to a key communication interface. That investigation has already produced results: opened in December 2025, the case led in June 2026 to interim measures ordering Meta to restore third-party AI assistants’ access to WhatsApp — a reminder that the ex post toolkit, including interim relief, can act quickly in fast-developing AI markets.
The case raises a further enforcement question that remains unresolved. Following the interim measures, Meta shifted from outright exclusion to a pay-for-access model, charging third-party AI assistants for access to WhatsApp. The Commission challenged that too, issuing a Supplementary Statement of Objections on the basis that pricing with the same exclusionary effect as a ban is equally impermissible. Yet the legal basis for an absolute prohibition on charging is not fully settled: the Court of Justice’s ruling in the Android Auto case held that a dominant firm may require a fair and proportionate contribution from third parties to cover actual development costs incurred in enabling interoperability. Whether a fee constitutes legitimate cost recovery or de facto exclusion is a conduct-specific question – but one that will matter greatly as agentic AI platforms scale and access conditions become commercially significant.
AI-related conduct, in other words, is already being assessed through established, effects-based frameworks. In practice, the standard competition regime and the DMA are converging on a common set of concerns: access, visibility, and the potential for ecosystem leverage. The result is regulatory overlap, with structurally distinct instruments, alongside AI-specific regulation, deployed simultaneously against risks that remain only partially understood.
Still, DMA regulators say they keep the AI designation question open for future cycles. The pressure to fold emerging AI markets, including agentic AI, into the gatekeeper framework will return as well.
Add to this the parallel DMA development restricting what a gatekeeper in OS and search are free to do. In the specification proceedings with Google (and, before that, Apple), the deeper difficulty is that they carry second-order effects for the very markets a DMA extension would claim to protect. The Commission has taken no competition action aimed directly at AI assistants and agents, and the AI Act pursues objectives other than competition enforcement. But DMA enforcement is already shaping agentic AI indirectly. Obviously, SiriAI is not launched in Europe for Apple Operating Systems covered by the DMA. The two Google specification proceedings now seem likely to constrain Google’s choices over design, integration, and distribution whether by forcing open architectural layers in ways that strengthen rival agents, or by restricting the OEM arrangements through which Google would deploy its own.
The concern is therefore not simply that enforcement may affect the timing or presentation of particular AI products. It is that DMA obligations can alter the deployment calculus of firms building AI products and agentic systems. The Apple example shows this directly: the issue is not merely that Siri AI may arrive later in the EU, but that Apple may not introduce the functionality at all while the scope of interoperability obligations remains unresolved. That is the structural deterrence problem. Mandatory openness obligations and regulatory uncertainty shape not only how a gatekeeper may compete, but whether it will bring the relevant AI functionality to the market in the first place.
The paradox is that the DMA’s first effects on agent markets may be to reshape competition before it has even formed, in ways that risk reducing rather than increasing competitive dynamism. That paradox points to the structural mismatch: the gatekeeper model presupposes exactly the kind of settled market architecture that AI services does not yet have.
This mismatch becomes clearer once competition in the AI market is understood as developing at two levels at once. At one level, there is intra-ecosystem leveraging: existing platforms may use control over OS, search, browsers, app stores, messaging services, or default settings to favour their own AI assistants or restrict rivals’ access to users. Those are concrete theories of harm, and they are precisely the kind of conduct that can be assessed through effects-based competition law.
More importantly, at the second level there is emerging inter-AI ecosystem competition: AI assistants and agents may themselves become new gateways, platforms, and distribution environments capable of constraining today’s incumbents. That layer is much less settled and, if anything, competition is increasing. It remains unclear which AI ecosystems will emerge, whether users will multi-home across them, whether they will discipline existing gatekeepers, or whether they will instead consolidate into a new set of bottlenecks. That is why the distinction strengthens the case against premature use of the DMA and other ex ante regulations in the emerging AI market.
The existence of intra-ecosystem risks does not mean that the AI market is a stable gatekeeper market. It obviously is not and the development of different open models are directly alleviating bottleneck risks in the stack. Given the capital expenditures necessary to build the infrastructure layer in the stack, it is clear that there will be fewer actors upstream than downstream. But specific leveraging conduct could and should be addressed where it arises, through case-by-case assessment.
By contrast, extending the DMA’s ex ante logic to AI assistants or agents would risk fixing regulatory categories around a market whose competitive constraints, routes to users, and ecosystem boundaries are still in flux. The consequence could even be that premature DMA actions encourage the very development that the Act is there to prevent. For instance, Google has developed an open model – Google Gemma – that intends to deal with bottleneck problems. If the provisional measures in the specification proceedings remain intact, the consequence may be that the company will have to make changes to its business model in Europe that reduced also the role of Gemma in the region.
Programmatic application of the DMA will further impact the AI market. The Act clearly closes around a set of categories – CPS, designated gatekeepers, prohibited conduct – and then accumulates obligations, enforcement practices, and institutional expectations. By routing AI deployments through existing CPS, it applies a classification designed for one generation of intermediation to systems whose architecture, function, and market position are fundamentally different. Agentic AI will sharpen the fit problem further. In multi-step agentic workflows, a model decomposes objectives and generates subtasks autonomously. Enforcing an obligation tied to discrete “tasks” or “services” requires knowing what the task was and where it began – conditions that become indeterminate when the model itself defines the subtasks. The DMA’s categorical logic assumes stable, identifiable services. Agentic AI is precisely the technology that dissolves that assumption.
Moreover, designating a current-generation AI assistant as a “virtual assistant” within the meaning of Article 2(12) DMA already stretches the concept beyond its design premises. Agentic AI widens that gap further. Article 2(12) contemplates a system that intermediates between a user and a service: routing a request, surfacing a result. An agentic system does not route: it decomposes objectives, selects tools, generates subtasks, and executes actions across multiple services without the user specifying each step. The category assumes a passive conduit; agentic AI is an autonomous actor. A classification built around the intermediation metaphor does not merely fit poorly today, it becomes more structurally obsolete with each successive generation of AI capability.
The taxonomy problem is therefore not merely semantic. Once AI assistants or agents will be forced into inherited DMA categories, the obligations attached to those categories will begin to shape product architecture, integration choices, and routes to market even more. That is precisely how a classification error ends up becoming a market-development problem.
Creating a new AI-specific CPS category also would not escape the taxonomy trap – it would replicate it at a higher level of abstraction. Any designation drawn today would need to define what counts as an AI assistant or agent, which capabilities trigger obligations, and at what threshold of scale or reach. Each of those definitional choices would face the same problem: the technology is still forming, deployment models are diverging, and the competitive dynamics are unresolved. A new category designed around today’s AI would be obsolete by the time it was enforced, for the same structural reason that the existing categories already are – the framework would be classifying a moving target and then holding it still.
Given these systems are still in the early stages of development, and no one knows what technologies, business models, and modes of deployment will attract users. Agentic AI is likely to evolve through fluid and layered forms of intermediation: an agent may sit between a user, a model, a set of tools, and the services it acts upon, with each layer supplied by different firms. This makes the regulatory challenge concrete – not just that the market is immature, but that regulators will face difficulty identifying a single responsible actor, a stable market boundary, or a clear point at which obligations should attach. And it is not yet clear where, or whether, a bottleneck will emerge at the agent interface, the model layer, cloud infrastructure, or connector governance – let alone whether any such bottleneck would be durable rather than transient. Nor is it clear that agentic AI will produce the kind of stable, identifiable gatekeeper position that designation presupposes.
Current agentic systems further illustrate this difficulty. They span chat-based agents with tool-use capabilities (ChatGPT Agent, Claude Code), browser and computer-use agents (Perplexity Comet, ByteDance TARS), and enterprise workflow agents integrated into business-process automation (Microsoft Copilot Studio, ServiceNow). Autonomy across these categories varies enormously and is shaped by human approval requirements, override mechanisms, and monitoring tools – which is precisely why agentic AI sits uneasily within an ex ante model designed around predefined categories of firms and prohibited conduct. The same design choice may function simultaneously as a safety feature, an accountability mechanism, and a restriction on access: its legal significance depends on context, not on category. Premature ex ante intervention may therefore do more than constrain anticompetitive conduct – it may shape the technical and commercial architecture through which agentic AI develops.
Market Structure: Downstream Fragmentation and Upstream Concentration
Importantly, agentic AI should not be treated as creating dependency for the first time. Digital markets have long been structured around intermediary layers that shape access to users, rank alternatives, authenticate transactions, and extract value from complementors. The more limited novelty is that agentic AI may combine these functions in a dynamic, task-oriented orchestration layer. Rather than merely displaying options, an agent may select and execute actions on the user’s behalf. This may reduce dependence on particular downstream services by lowering search, switching, and multihoming costs, but it may also shift dependence toward the agentic interface, model layer, cloud infrastructure, or connector governance. The resulting competitive effects are therefore ambiguous. The relevant question is not whether dependencies exist, but whether particular dependencies are durable, non-replicable, and capable of being used to foreclose rivals or distort user choice.
Emerging interoperability standards such as MCP can illustrate this distinction and why it matters. MCP may make downstream services more substitutable by standardising how agents connect to external tools, data sources, and workflows. A service exposed through a common protocol can, in principle, be accessed by multiple agents rather than being tied to a single vertically integrated environment. Two implications follow and both turn on how interoperability arises rather than on the mere fact that it does. First, the ecosystem is generating its interoperability layer endogenously. MCP spread because it lowers integration costs, it evolves with the technology it connects, and no firm is compelled to adopt it. That weakens the claim that agentic markets are inevitably closing — openness is emerging without a gatekeeper obligation in sight.
Second, the layering insight cuts in the opposite direction as well. Openness at the agent layer depends on conditions in the layers beneath it. Protocol-level interoperability can reduce integration costs between agents and tools, but it cannot by itself offset concentration in foundation models, compute infrastructure, cloud distribution, or proprietary data. If those upstream layers become bottlenecks, the appropriate competition concern lies there. The answer is not to impose broad interoperability duties downstream simply because the agent layer is becoming commercially important.
This matters because mandatory openness is a poor default instrument for agentic AI markets. Interoperability mandates work best where the regulator can identify a relatively stable access point: a defined interface, a bounded service, and a clear moment at which compliance can be assessed. Agentic systems make that task more difficult. They decompose objectives across models, tools, and external applications. The relevant access layer is therefore not a single chokepoint but a moving set of interfaces whose competitive significance depends on context.
These dynamics therefore expose a structural tension. At the application layer, the market is fragmented and dynamic – numerous agentic systems compete, and no “gatekeeper agent” has yet emerged. But fragmentation at the application layer does not mean contestability throughout the stack. All agents depend on upstream providers for frontier models, compute, and cloud infrastructure. In other words, downstream competition concerns and upstream concentration can coexist.
Two structural features complicate this standard foreclosure story, however. First, agentic systems can route tasks between different models depending on cost, latency, and performance – introducing a form of real-time substitution that earlier platform markets, with their locked-in defaults, did not permit. Whether that substitution is real in practice depends on whether API terms, fine-tuning dependencies, and cloud integration make routing genuinely feasible rather than merely theoretical.
Second, the firms best positioned to foreclose upstream often have commercial incentives not to – and they build on already established commercial and regulatory practices. Take again the examples of Apple and Google. Their AI assistants are already dependent on a host of different stack operators. The issues about interoperability on their platforms are already principally settled: they are open, with varying conditions. What DMA regulators are now pursuing in specification proceedings is a goal of architectural openness that has little value for downstream agent interaction and competition.
Moreover, Google’s investment in Anthropic, Amazon’s partnerships with both Anthropic and OpenAI, and Apple’s arrangement with Google for Gemini create frenemy relationships in which foreclosing a downstream AI rival may simultaneously mean foreclosing a cloud or compute customer. These incentive structures do not eliminate foreclosure risk, but they mean that upstream concentration does not automatically translate into exclusionary conduct.
This matters because the DMA’s foreclosure model assumes both the ability and the incentive to exclude. The frenemy structures described above complicate the incentive side: firms with cross-investment or infrastructure exposure to potential rivals may still have strategic reasons to protect their ecosystems, but exclusion may also impose commercial costs by reducing the value of the very firms, models, or services in which they are invested. AI assistants also complicate the ability side. What looks like withholding access may in some cases reflect unresolved architectural questions about how rival assistants can safely interact with system-level functions and user data.
Regulatory Response: Contingent Risks and Governance-Based Accountability
Nonetheless, the argument against premature ex ante classification should not be mistaken for the view that agentic AI is competitively harmless. Agentic systems eventually may create risks, including algorithmic collusion, prompt injection, and lock-in. The point is that these risks are very much contingent on market structure, system design, deployment context, information flows, and firm conduct. They are therefore better understood as reasons for careful competition analysis, market monitoring, and governance-based accountability than as grounds for treating agentic AI as inherently suspect or for automatically extending the DMA.
A first risk concerns algorithmic coordination. The UK Competition and Markets Authority (CMA) has warned that algorithmic pricing can increase the risk of coordinated market outcomes even without explicit communication between businesses, particularly where algorithms learn from and react to each other in concentrated markets. In its work on agentic AI, the CMA has further noted that these risks may intensify where AI agents are delegated commercial decisions. Where multiple businesses deploy autonomous agents to optimise pricing or commercial strategy, interaction between those systems may dampen competitive pressure. Repeated-pricing experiments illustrate the concern: Q-learning pricing algorithms can learn to charge supra-competitive prices without communicating, sustaining elevated prices through punishment strategies after deviations.
This creates a difficult enforcement problem, but not a wholly new legal vacuum. Purely parallel conduct, or tacit coordination, is not generally unlawful in itself. The challenge is identifying when algorithmic interaction crosses the line into unlawful coordination, signalling, information exchange, or hub-and-spoke collusion. Agentic AI may make that line harder to draw because agents can monitor rivals, react rapidly to market changes, and adapt strategies over time. But the legal question remains conduct-specific: whether the firm used, designed, instructed, or knowingly relied on the system in a way that reduced strategic uncertainty or facilitated coordination.
Design matters for the same reason. Experimental evidence shows that collusive behaviour in algorithmic systems is highly sensitive to architecture and deployment conditions – some design choices may even make collusion more potent by limiting overfitting rather than preventing it. For competition analysis, the question is therefore not whether agentic AI can ever facilitate coordination, but whether a particular system is designed or deployed in a way that makes coordination likely, attributable to an undertaking, and capable of producing market effects.
This supports a differentiated and evidence-based regulatory response. Where risks arise from communication between agents, shared optimisation tools, repeated interaction, information symmetry, stable counterparties, or algorithmic monoculture, competition authorities should examine whether those conditions actually exist in the relevant market and whether they produce attributable and market-relevant coordination. The better reading of this literature is that agentic collusion is contingent rather than inherent. The relevant studies identify technical and market conditions that may amplify or attenuate collusion risk, but they do not establish a general basis for treating agentic AI systems as intrinsically cartelising or for imposing broad ex ante design mandates independent of market context.
A second and distinct risk is prompt injection: hidden instructions inserted in websites, documents, or tool outputs can manipulate an agent’s behaviour in ways that distort commercial decisions – steering purchasing agents toward particular suppliers, or creating coordination channels that resemble hub-and-spoke collusion. Unlike algorithmic coordination, this is not primarily a competition structure problem but a security and governance one. Addressing it requires technical safeguards – input sanitisation, provenance tracking, and output verification – rather than structural competition intervention. For competition regulation, prompt injection becomes relevant only when it manipulates market-facing agents or distorts commercial decisions in ways attributable to insecure system design or intentional conduct. The appropriate regulatory focus is on governance and accountability, not on treating agentic AI as inherently problematic.
The third risk, vendor lock-in, is real but contingent on design choices that are already being contested in the market. Memory-portability protocols, sovereign-memory architectures, and cross-platform asset-exchange standards are emerging at the research, production, and standards levels – including the Linux Foundation’s OpenSharing project – indicating that interoperability in agentic markets is being institutionalised without regulatory compulsion. Where lock-in does arise, the relevant legal question is whether it reflects demonstrable market power and exclusionary design, or merely the transient friction of an immature market. That is a conduct-specific question answerable through existing tools: Article 102 TFEU, merger control, interoperability remedies, and data portability obligations.
The current state of these initiatives thus carries a structural lesson of its own. The memory-portability protocols, sovereign-memory architectures, and asset-exchange standards described above are competing and, as yet, mutually non-interoperable: even the layer of the agentic stack designed to prevent lock-in has not consolidated. A market in which not even the interoperability standards have produced a winner is a market in which no layer of the stack has produced a gatekeeper. It is hard to find clearer evidence that designation-style regulation would be premature.
Together, these risks – call for governance-based accountability rather than ex ante structural regulation. That does not, however, create a safe harbour for firms that deploy anticompetitive agents. Existing competition law already contains tools for addressing these harms, and firms cannot hide behind algorithmic autonomy to implement unlawful coordination or exclusionary strategies. The Commission’s revised Horizontal Guidelines make clear that firms cannot avoid liability simply because pricing practices are implemented by algorithms. If pricing conduct would be unlawful offline, it is likely to remain unlawful online; an algorithm remains under the firm’s control, and the firm may be liable even where its actions were informed by algorithmic systems.
The relevant distinction is therefore not between firms that satisfy an ex ante design checklist and firms that do not. It is between speculative risks associated with an emerging technology and concrete uses of that technology that can be assessed under ordinary competition-law principles. Governance measures may help reconstruct how an agentic system acted, what risks were foreseeable, and whether less restrictive alternatives were available. But they should not be converted into general design mandates for agentic AI.
Conclusion: Enforcement before Regulation
Two distinct issues henceforth frame the assessment of AI under the DMA. The first concerns spillovers. As shown above, DMA enforcement in adjacent platform markets is already shaping AI indirectly, through specification proceedings and remedies that alter the architecture on which AI assistants and agents are built and distributed. That influence counsels close attention to the second-order effects of current enforcement. Before it takes these actions, the Commission should develop a much better understanding of how they impact on the markets for AI assistants and agentic AI.
A programmatic application of the DMA risks causing a different “foreclosure risk” – that European consumers, developers, and smaller companies are saddled with older technology that is less useful and increasingly distant from the global innovation frontier. It is already happening with SiriAI – and it follows other non-AI functionality that European customers and developers cannot use. The risk now is that other companies will have to make the same decisions: that interoperability demands effectively mandating equal access into their architecture will leave them with few other choices than to stop marketing services in Europe. The acceleration in agentic AI is reinforcing risks to cybersecurity and data privacy at the same time as DMA demands stronger access to the architecture.
The second issue concerns AI agents. Any case for intervention would need to be based on durable features of AI markets such as business models or bottlenecks that could block competitors or restrict user choice rather than replicating DMA enforcement in other tech sectors. Applying DMA-style regulation before a gatekeeper emerges could influence market dynamics, for example by affecting which companies gain early advantages, how standards develop, or how users and investors adopt different solutions. Until clear evidence of dominance or anti-competitive bottlenecks appears, enforcement can rely on monitoring and targeted remedies rather than broad ex ante regulation.
The abstract case for moving sooner – that the DMA should be geared to more directly address AI-driven intermediation and that regulatory adjustments are needed to cover assistive and agentic AI – deserves to be taken seriously. Yet that position presupposes settled market structures, identifiable gatekeepers, and stable theories of harm that do not yet exist in this market. Acting on that assumption risks converting a monitoring problem into a regulatory one before the evidence justifies the move, and before current enforcement in adjacent markets has produced results that could inform the scope of any future intervention.
The introductory question – fit for what purpose, exactly? – has a concrete answer. The DMA’s current implementation is producing effects that were never its purpose: deterring AI deployment, bifurcating the EU market from the rest of the world, and shaping the architecture of agentic AI through regulatory side-effects rather than deliberate design. Apple’s decision not to ship Siri AI in the EU and the likely emergence of a feature-stripped Google product for the European market are not the outcomes of a coherent competition policy. They are the cost of applying yesterday’s regulatory logic to tomorrow’s technology. The right response is not to extend that logic further into AI markets, but to let current enforcement run its course, monitor what actually emerges, and build the evidentiary record that any credible future intervention would require.
One response to “Before the Gatekeeper: AI and the Limits of Ex Ante Competition Regulation”