From the journal

Can EU Regulators Force Big Platforms to Open Up to AI Rivals?

Large digital platforms control operating-system features, search data, APIs, and user channels that rival AI services may need. The question is whether European Union enforcement can compel AI-facing interoperability, data, or distribution access. It also asks where that power ends. This analysis assumes Commission action under Regulation (EU) 2022/1925 or Article 102 TFEU. It treats access as a targeted remedy tied to a statutory breach or competitive harm. It does not assume disclosure of model weights, source code, or full training corpora.

Illia ProkopievCo-Founder and CEO12 min read

EU regulators are starting to require major platforms to give competing AI services access to key features, data, and customer channels. These remedies can improve competition, but they must address a specific legal breach and do not create a general right to model weights, source code, or training data.

Summary

  • The Commission’s June 2026 Meta order already required restored, free WhatsApp access for rival general-purpose AI assistants.
  • Regulation (EU) 2022/1925 can compel defined interoperability, portability, business-user data access, and search-data access. Articles 6(7), 6(9)–(11), and 8 supply the principal routes.
  • The Alphabet proceedings show direct AI application. Draft measures cover search data for eligible AI chatbots and Android access to invocation, app data, actions, resources, and on-device models.
  • The Alphabet measures remain preliminary on 15 July 2026. The Commission states that final decisions are due by 27 July 2026.
  • Article 102 TFEU and Articles 7–9 of Regulation (EC) No 1/2003 support three remedy routes. They permit final orders, interim measures, and binding commitments. Each measure must address the identified abuse and remain proportionate.
  • Current law grants no general competitor right to model weights, source code, or an entire training corpus. Broader access would require a closer statutory hook, proven abuse, commitments, or new legislation.
  • Privacy and security shape remedy design. They support consent controls, anonymisation, access limits, audit trails, secure APIs, and confidentiality terms, not automatic immunity.

Interim measures

On 8 June 2026, the Commission announced interim measures against Meta in Case AT.41034. The order required Meta to restore free WhatsApp access for rival general-purpose AI assistants. Meta had to maintain access while the merits investigation continued. European Commission, Case AT.41034, Exclusion of AI competitors from WhatsApp, interim measures announced 8 June 2026.

The Commission acted under Article 8(1) of Regulation (EC) No 1/2003. That provision permits interim measures in urgent cases. The Commission must find a prima facie competition infringement and serious, irreparable harm to competition. Regulation (EC) No 1/2003, art. 8(1).

The Commission stated that Meta appeared dominant in an EEA-wide market for consumer communications applications. It also stated that Meta’s policy excluded rival general-purpose AI assistants from WhatsApp while Meta AI remained available. The order required restored access within five working days. The substantive Article 102 investigation remains open.

This order proves the narrow proposition. The Commission may restore an AI provider’s access to a platform channel before a final infringement decision. It does not prove a final Article 102 violation. It also does not establish a general duty to host every AI service.

The DMA can compel defined AI-facing access

The Digital Markets Act creates direct duties for designated gatekeepers and designated core platform services. It does not require proof of dominance or abuse for each covered obligation. Regulation (EU) 2022/1925, arts. 3, 5–7.

Article 6(7) requires free and effective interoperability with designated operating-system or virtual-assistant features. The access extends to features available to the gatekeeper’s own services or hardware. A gatekeeper may protect system integrity and security through strictly necessary and proportionate measures. Regulation (EU) 2022/1925, art. 6(7).

Articles 6(9) and 6(10) address data portability and business-user data access. Article 6(9) covers data supplied by end users or generated through their activity. It requires continuous and real-time access tools where relevant. Article 6(10) covers data generated through business and end-user use of the core platform service. Personal-data access remains tied to user choice and applicable consent. Regulation (EU) 2022/1925, arts. 6(9)–(10).

Article 6(11) targets online search data. A designated search gatekeeper must offer competing online search engines access to ranking, query, click, and view data. The terms must be fair, reasonable, and non-discriminatory. Personal data must be anonymised. Regulation (EU) 2022/1925, art. 6(11).

Article 8 lets the Commission specify measures needed for effective compliance with Articles 6 and 7. The Commission may make those measures binding after notice and consultation. A specification decision operationalises an existing duty. It cannot create an unrelated entitlement outside the cited obligation. Regulation (EU) 2022/1925, art. 8.

The pending Alphabet proceedings show how these provisions may reach AI services. In Case DMA.100209, the Commission proposed search-data measures for eligible online search engines. The stated beneficiary group includes AI chatbots with search functionality. The proposed access covers anonymised ranking, query, click, and view data on fair, reasonable, and non-discriminatory terms. European Commission, Case DMA.100209, preliminary measures of 16 April 2026.

In Case DMA.100220, the Commission proposed Android interoperability measures for third-party AI services. The draft addresses custom wake words, system invocation, contextual data, app actions, processing resources, and display surfaces. It also addresses access to system-level on-device models and deployment of third-party on-device models. The draft calls for free, documented APIs, equal feature access, technical assistance, and reporting. European Commission, Case DMA.100220, preliminary measures of 27 April 2026.

These proposals are legally important, but not final. The Commission may revise them after Alphabet’s response and third-party comments. The Commission states that both final decisions are due by 27 July 2026. No final Alphabet specification decision existed on the stated date.

The DMA’s reach remains service-specific. Alphabet is covered because Google Search and Android are designated core platform services. The Commission’s current designation list contains no standalone general-purpose AI service. Embedded AI may still fall within duties governing a designated search engine, operating system, browser, social network, or communications service.

Article 18 offers a stronger DMA remedy after systematic non-compliance. Following the required market investigation, the Commission may impose proportionate and necessary behavioural or structural remedies. That route demands the statutory predicate and procedure. It is not an ordinary shortcut to new data rights. Regulation (EU) 2022/1925, art. 18.

Article 102 can support access beyond the DMA

Article 102 TFEU reaches abusive conduct by a dominant undertaking affecting trade between Member States. It is not limited to designated gatekeepers or core platform services. The Commission, national competition authorities, and national courts may apply it within their respective powers. TFEU art. 102; Regulation (EC) No 1/2003.

A final Commission infringement decision may order conduct needed to end the abuse. Behavioural or structural remedies must be proportionate and necessary. Structural relief requires the conditions stated in Article 7(1). Regulation (EC) No 1/2003, art. 7(1).

Article 8 supports temporary access before the merits decision. Urgency and serious, irreparable harm to competition are essential. The order must rest on a prima facie infringement and last for a specified period. Regulation (EC) No 1/2003, art. 8.

Article 9 permits binding commitments when the Commission intends to require an infringement to cease. A platform may offer API access, non-discrimination, portability, or interoperability commitments. The Commission may bind those promises without making a final infringement finding. Regulation (EC) No 1/2003, art. 9; Commission v Alrosa, C-441/07 P, EU:C:2010:377.

Possible Article 102 theories include discriminatory access, self-preferencing, tying, unfair trading conditions, and exclusionary refusal. The governing theory matters. A pure demand for access to closed infrastructure faces a demanding test. A discriminatory restriction on an established third-party interface may not.

The Meta matter illustrates the distinction. The Commission did not claim a free-standing right to Meta’s internal AI assets. It targeted exclusion from an existing business interface and user channel. The announced measure restored the prior access position while the investigation proceeded.

Platform design controls the compulsory-access threshold

Oscar Bronner governs a true demand for compulsory access to infrastructure developed for the dominant undertaking’s own business. The requester must show that access is indispensable. The refusal must be capable of eliminating all effective competition by the requester. The refusal must also lack objective justification. Oscar Bronner, C-7/97, EU:C:1998:569.

The Court has confined that exceptional test to genuine access refusals. It does not govern every unfair access condition, leveraging practice, or discriminatory design choice. Slovak Telekom, C-165/19 P, EU:C:2021:239; Google and Alphabet v Commission, C-48/22 P, EU:C:2024:726.

Alphabet v AGCM is especially relevant to AI interfaces. A dominant undertaking had developed Android Auto for third-party applications. The Court held that an interoperability refusal may be abusive even without indispensability. The platform’s third-party purpose and the app’s added consumer attractiveness mattered. Alphabet and Others v AGCM, C-233/23, EU:C:2025:110.

The Court also recognised objective limits. The absence of a suitable template does not suffice alone. Security, platform integrity, or technical impossibility may justify refusal. Otherwise, the dominant undertaking may need to develop a template within a reasonable period. Appropriate financial consideration may be due. Alphabet and Others v AGCM, C-233/23, EU:C:2025:110.

This distinction changes the AI analysis. A request for an existing API, invocation feature, or established channel is easier to frame. A demand for raw model parameters or a newly built data pipeline is harder. Prior third-party access, technical parity, and discriminatory withdrawal strengthen the enforcement case.

The remedy must match the breach and the asset

A lawful order must identify the covered asset and its connection to the breach. “Data access” is too broad. Search logs, user-portability data, business-user transaction data, model parameters, training text, and source code raise different rules.

The strongest DMA claims track express categories. Article 6(11) names four search-data types. Articles 6(9) and 6(10) identify user and business-user data. Article 6(7) targets operating-system and virtual-assistant features needed for interoperability.

The strongest Article 102 claim usually targets an established route to market. Relevant facts include prior openness, platform rules, comparable access for the platform’s own AI, technical feasibility, switching options, and foreclosure. Evidence of rapid market tipping may support urgency. Evidence of viable alternative channels weakens indispensability and harm.

The remedy should restore competitive conditions rather than transfer an unconnected advantage. An order may require API parity, documented specifications, equal latency, stable quality, technical support, non-discriminatory eligibility, and a dispute process. A data order may define fields, frequency, retention period, anonymisation, price, permitted uses, and audit rights.

A broader disclosure order requires a stronger record. Model weights and source code may contain trade secrets and protected expression. Training corpora may contain copyrighted works, personal data, licensed material, and confidential information. Those interests do not create absolute immunity. They increase the need for necessity, tailoring, confidentiality, and lawful processing.

Copyright-protected assets face an additional exceptional-circumstances test. The requester must seek a new product or service with potential demand. The refusal must lack objective justification and eliminate competition on the relevant market. IMS Health GmbH & Co. OHG v NDC Health GmbH & Co. KG, C-418/01, EU:C:2004:257.

Current EU materials support a limit on general model access. The Commission’s 2026 DMA review records proposals to extend data-sharing duties to model parameters and chatbot history. That treatment suggests those rights are not clearly present as general duties today. It is an inference from the review record, not a judicial holding.

Privacy, security, confidentiality, and ownership constrain the order

EU enforcement cannot disregard Regulation (EU) 2016/679. A remedy involving personal data needs a lawful basis, purpose limits, data minimisation, security, and defined controller roles. Consent may be required under the applicable DMA provision or the GDPR.

The GDPR is not an automatic defense to exclusionary conduct. A competition authority may consider GDPR compliance when assessing abuse. It must respect the powers and prior decisions of data-protection authorities. Meta Platforms v Bundeskartellamt, C-252/21, EU:C:2023:537.

The DMA incorporates data safeguards. Article 6(11) requires anonymisation of personal search data. Article 6(10) limits personal-data access to directly connected use and user choice. Article 6(7) permits strictly necessary and proportionate integrity protections.

Security objections require evidence. The platform should identify the threat, affected component, probability, and less restrictive controls. Rate limits, sandboxing, permission prompts, scoped tokens, logging, certification, and revocation may address a real risk. A blanket exclusion is harder to defend when the platform grants equivalent access to its own AI.

Trade-secret and copyright interests also affect design. Restricted environments, clean teams, use limits, confidentiality duties, and compensation may protect legitimate interests. Microsoft v Commission confirms that competition relief can require interoperability information on reasonable and non-discriminatory terms. Microsoft v Commission, T-201/04, EU:T:2007:289.

Proportionality remains central. A final Article 102 remedy must end the identified abuse without exceeding what is necessary. A commitment decision may accept broader promises, subject to the limits stated in Alrosa. DMA measures must remain tied to the operative duty and the service’s designation.

Adjacent EU statutes create different access rights

Other EU statutes create targeted access without giving every AI competitor a general platform claim. Their beneficiary, purpose, and data categories differ.

Article 40 of Regulation (EU) 2022/2065 grants supervisory data access for very large online platforms and search engines. It also permits access for vetted researchers under stated conditions. The purpose is systemic-risk monitoring and research, not commercial model training or competitive parity. Regulation (EU) 2022/2065, art. 40.

Regulation (EU) 2023/2854 gives users access to certain connected-product and related-service data. Users may direct a data holder to provide covered data to a third party. Those rights do not create general access to platform search logs, model weights, or training corpora. Regulation (EU) 2023/2854, arts. 3–5.

Regulation (EU) 2024/1689 gives the Commission and AI Office information and evaluation powers over general-purpose AI models. Those supervisory powers may involve documentation, technical interfaces, or evaluations. They do not create a competitor entitlement to the same materials. Regulation (EU) 2024/1689, arts. 91–92.

The practical forecast favors interfaces over model internals

EU enforcement is most likely to compel access to an existing interface or distribution channel. The Meta order supplies a current example. The Android and Search proceedings show the same direction under the DMA.

A discrete operational data feed is also plausible when a statute names the data. Article 6(11) supplies the clearest case. Articles 6(9) and 6(10) may support portability or business-user access within their defined limits.

A demand for model weights, source code, or a complete training corpus is materially weaker. It lacks a general DMA entitlement. Article 102 may reach a fact-specific refusal, but necessity and proportionality would require a demanding record.

The decisive questions are concrete. Is the platform designated or dominant? Which service and asset are involved? Was access previously available? Does the platform favor its own AI? Can rivals reach users elsewhere? What data are personal or protected? Which safeguards can preserve competition without transferring unrelated assets?

Illia Prokopiev

Written by

Illia Prokopiev

Co-Founder and CEO

Illia is the Managing Partner and founder of Licentium. With over 11 years of practice, he has guided innovators through cross-border M&A deals and the disputes that follow, combining transactional skill with courtroom resolve. Admitted to the bar in 2017, he pivoted early to Web3, serving as legal advisor to prominent crypto projects and carrying AML/MLRO duties that anchored complex token, DAO, and compliance questions on solid regulatory ground. Certified in money laundering prevention and an active crypto investor, Illia blends market intuition with a global network of specialists, enabling Licentium to untangle licensing knots for crypto and AI ventures anywhere in the world.

More from the journal

See all

Finland Gambling Act Ends State Monopoly, Opens Licensed iGaming Market from July 2027

Finland's Gambling Act, approved by the President on 16 January 2026, ends the state monopoly held by Veikkaus Oy and introduces competitive licensing for private iGaming operators in online sports betting and casino verticals. The Finnish Gambling Authority accepts licence applications from 1 March 2026; licensed market operations begin 1 July 2027. Licensed operators pay a flat gross-gaming-revenue tax of 22%.

SEC Adds Regulation Crypto to Rulemaking Agenda with Token Safe Harbor, July 2026

On 7 July 2026, the U.S. Securities and Exchange Commission placed Regulation Crypto on its regulatory priority agenda, the first crypto-specific rulemaking in the agency's history under Chair Paul Atkins. The proposal would create a time-limited registration exemption for early-stage token projects, permit capital raises up to $75 million in a 12-month period, and establish a decentralisation safe harbor for tokens whose issuers have ceased all essential managerial efforts.

Delaware Enacts Stablecoin Modernization Package Aligning State Licensing with Federal GENIUS Act

Delaware Governor Matt Meyer signed the Banking, Money Transmission, and Stablecoin Modernization Package on 6 July 2026, creating a state licensing regime for payment stablecoin issuers under the Delaware Payment Stablecoin Act. Senate Bill 19 establishes reserve requirements, redemption standards, and capital obligations aligned with the federal GENIUS Act and directs the Commissioner of Banks to seek nationwide operating authority through a substantial-similarity certification.