Home EconomyEurope Wants Tech Champions, Then Makes Them Share the Trophy

Europe Wants Tech Champions, Then Makes Them Share the Trophy

by Staff Reporter
0 comments

Europe wants its own technology champions. It just seems less comfortable with what champions look like once they arrive.

The European Commission’s latest Digital Markets Act (DMA) decisions capture that tension. Europe wants more innovation, investment, and globally competitive digital platforms. Yet when a company assembles the data, technology, distribution, and complementary services needed to compete worldwide, Brussels increasingly treats those advantages as inputs to be shared with rivals.

On July 16, the Commission adopted binding measures requiring Google to give eligible search engines, including AI chatbots with search functions, access to anonymized Google Search data. A parallel decision requires Google to open 11 categories of Android functionality to competing AI assistants. These include sensor inputs, app data, operating-system controls, screen automation, on-device computing resources, background execution, and hotword activation.

The Commission says these mandates will promote contestability, consumer choice, and innovation. The immediate gains are easy to see. Rivals receive valuable inputs, developers gain access to Android features, and consumers may encounter more services competing within Google’s platform.

The costs are harder to spot and easier to ignore. Forced access may weaken incentives to build proprietary datasets, reduce returns on risky platform investments, increase cybersecurity risks, and push competing systems toward the same design. It may also lead companies to delay, degrade, or withhold future products in Europe.

These decisions therefore deserve scrutiny as more than access mandates. They alter the rules governing who bears the cost of innovation and who receives the reward.

The Algorithm by Other Means

The Commission stresses that Article 6(11) does not require Google to disclose its source code, algorithms, or technology. Formally, that is true. The mandate instead covers anonymized ranking, query, click, and view data generated through paid and unpaid search.

Google must generally provide information it collects and uses to improve Search, including entered queries, language and device metadata, viewed URLs, user interactions, and result positions. The public measures contemplate a delay of at least seven days and allow each eligible recipient to receive the data for up to five years.

That source code remains private does not resolve the intellectual-property problem. In a data-driven business, valuable know-how appears in more than written algorithms. It also emerges from the feedback generated when those algorithms operate across billions of searches.

Query reformulations, click patterns, result positions, dwell times, and other behavioral signals can reveal how a system reacts to particular inputs. Combined with a recipient’s own models, experiments, and datasets, that information can reduce the cost of approximating aspects of the incumbent’s ranking behavior.

The meaningful distinction concerns direct access to technical instructions and access to the behavioral data from which competitors may infer parts of those instructions. The second form of access will not recreate Google Search. Search quality also depends on crawling, indexing, engineering talent, experimentation, brand, distribution, computing infrastructure, and other complementary assets.

The International Center for Law & Economics (ICLE) has therefore cautioned that shared data may not transfer much value and that the returns from additional search data may decline. Even so, mandated access can capture part of the return on Google’s past investment by lowering rivals’ costs of experimentation, error correction, and imitation.

Search data did not materialize on its own. Google generated it through decades of investment in crawling, indexing, infrastructure, cybersecurity, user interfaces, quality testing, and fraud prevention. Individual facts may not qualify as intellectual property, but the organized stream of information produced by the platform remains an economically valuable asset. Its value reflects both Google’s technological investment and the trust of users who chose to submit their queries.

The Commission’s pricing rule deepens the problem. Google generally may recover only the incremental costs of preparing, storing, and transmitting the dataset, plus a return on incremental capital capped at its weighted average cost of capital. An additional margin is available only in exceptional circumstances.

That formula largely excludes the sunk costs of creating the underlying information asset and the option value of keeping it exclusive. For information goods, those omissions are substantial. Innovation-intensive products often require high fixed and sunk costs, face uncertain commercial prospects, and cost little to reproduce once created.

A price based mainly on delivery expenses therefore ignores the investments that created the value being shared. As ICLE has warned, a fair, reasonable, and nondiscriminatory (FRAND) access rule can become a subsidy for competitors.

The decision does not amount to uncompensated expropriation. Access remains limited, Google must anonymize the data, recipients must meet eligibility requirements, and some compensation is available. Economically, though, the mandate resembles a compulsory license priced without full regard for the investment that produced the licensed advantage.

It transfers part of Google’s informational returns to rivals while leaving Google responsible for the costs, liabilities, and security risks of creating and maintaining the asset.

The Mandate That Keeps on Mandating

The Commission argues in its search-data Q&A that Google will retain ample incentives to innovate. Recipients will receive only a modified subset of its data, may not systematically reproduce Google’s search results, and may not use the dataset to train general-purpose AI models. Those safeguards limit the mandate’s reach, but they do not establish that it will leave investment unchanged.

Investment incentives operate at the margin. A rule need not capture every return to alter a company’s behavior. It need only reduce the expected payoff from the next dollar spent improving search quality, collecting data, developing behavioral signals, or launching a new feature.

A company that expects regulators to make valuable feedback available to competitors at a controlled price may invest less in producing that feedback. It may also reserve its most commercially sensitive innovations for products or jurisdictions where it can retain more of the resulting value.

The effects reach beyond Google. An aspiring platform must now account for the possibility that success in Europe will turn the scale economies it created into duties to assist rivals. Investors will discount expected returns to reflect that risk. Some firms will still invest, but they will demand higher projected returns before doing so. Marginal projects will lose funding, ambitious forms of integration will become less attractive, and business models that depend on long-term cross-subsidies will become harder to finance.

The mandate also creates a predictable regulatory ratchet. If recipients fail to gain market share, they can argue that the dataset is too narrow, delayed, anonymized, or expensive. If privacy protections make rare queries less useful, beneficiaries can press the Commission to relax them. If access does not allow rivals to match Google’s quality, they can demand more data fields, shorter delays, or technical assistance.

ICLE warned in its comments on Article 6(11) that judging “effective compliance” by competitors’ commercial results rather than the availability of workable access would encourage exactly this progression. Each disappointing competitive outcome could become evidence that the previous mandate did not go far enough.

The Commission’s own Q&A gives that concern some force. It rejected Google’s initial implementation in part because the company removed 90% to 100% of unique queries and attracted little meaningful uptake. Uptake may help show whether rivals find the data useful, but it does not measure consumer welfare. A dataset can satisfy an access requirement even when competitors decide it lacks commercial value. A highly valuable dataset can also impose greater costs on privacy, security, and future innovation.

Once competitor use and market share become measures of regulatory success, the Commission moves beyond opening access. It begins designing the competitive outcome.

Anonymized, With an Asterisk

The Commission has taken privacy seriously. Its system removes direct identifiers and some metadata, suppresses rare or unusually long queries, generalizes locations, aggregates interaction times, and strips out advertising URLs. Contracts, independent audits, limits on onward transfers, retention rules, and use restrictions add further protection.

Those safeguards matter. The decision does not authorize an unrestricted transfer of identifiable search histories. It also does not automatically open the data to every Chinese, Russian, or other foreign-controlled company. The Commission allows Google to exclude sanctioned entities and firms controlled by countries that pose serious and structural cybersecurity or data-protection risks. It also permits public-security exemptions and requires processing in the European Economic Area or under protections deemed essentially equivalent.

These measures reduce the danger. They do not make it disappear.

Search queries can reveal sensitive information about health, finances, travel, employment, political activity, intimate relationships, business strategy, and personal vulnerabilities. Removing direct identifiers may not prevent recipients from combining query data with their own logs, public records, advertising data, leaked datasets, or inference models.

Mikolaj Barczentewicz’s analysis of the preliminary proposal made the central point. Anonymity depends on more than what appears in the dataset itself. It also depends on the auxiliary information and technical capabilities available to each recipient.

That concern follows directly from Article 6(11)’s competitive premise. Recipients are expected to possess the complementary tools needed to extract commercial value from the data. The same expertise may also help them reconstruct sensitive information. Contracts and annual audits can deter abuse, but they may detect it only after data have been copied, inferred, compromised, or transferred.

National-security concerns also require precision. The public materials do not show that raw, identified searches by U.S. military officials or diplomats will reach hostile governments. But searches by American personnel in Europe may still form part of the larger pool from which the shared dataset is drawn. If the data remain sufficiently granular or are poorly anonymized, they could reveal patterns involving travel, facilities, vendors, technical problems, operational interests, or personnel concerns.

The Commission’s high-risk-country and public-security provisions address some recipient risks, but they do not necessarily match U.S. national-security judgments. They also cannot eliminate cyber intrusions, hidden beneficial ownership, acquisitions after certification, insider threats, or inferences drawn from multiple lawful datasets.

Google’s July 16 response argues that the measures expose private searches without adequate anonymization, knowledge, or consent and create risks to privacy, business secrets, and national security. That remains Google’s position rather than an adjudicated finding. Even so, the costs it identifies deserve analysis rather than dismissal as the grumbling of a regulated firm.

Privacy and security are part of service quality. A competition rule that expands rival access by weakening users’ expected confidentiality may produce more competitors and a worse product.

A Remedy With Guardrails—and One Without

The American search-remedies litigation offers a useful comparison. The U.S. district court imposed its remedy in United States v. Google only after finding specific exclusionary conduct. Its user-side data mandate covers the underlying information used the Generalized Learned User Embeddings (GLUE) and RankEmbed models and requires at least two disclosures. The court will determine the final number and timing after consulting a technical committee.

The judgment also draws firm boundaries around what Google must share. It excludes algorithms, ranking signals, scores, post-trained large language models, intellectual property, and trade secrets.

Recipients must satisfy court-approved security standards, pass regular audits, show a credible plan to invest and compete, undergo annual recertification, and pose no threat to U.S. national security. Google may object to a recipient’s initial or continued eligibility and receive a hearing. The court also recognized that anonymized user-side data could remain highly sensitive, so it restricted sales and onward sharing.

The American remedy still invites criticism. It prices access at marginal cost and may weaken incentives to invest. Yet it remains more closely tied to adjudicated conduct, defined datasets, judicial oversight, trade-secret protection, national-security screening, and recipient-by-recipient review.

The DMA decision reaches further in both duration and ambition. It does not respond to a finding that Google unlawfully acquired a particular dataset. It treats Google’s continuing accumulation of search data as a structural advantage that regulators may redistribute for as long as Search remains designated.

The decision also extends eligibility to AI chatbots with search functions and seeks, where technically feasible, to approximate the methods and speed with which Google uses the data itself. The U.S. judgment remains an antitrust remedy, even if an interventionist one. The European model looks increasingly like continuing public-utility regulation of information.

Leveling the Platform Down

The Android decision presents a related but distinct problem for innovation. The Commission requires Google to give third-party AI services free access, on equally effective terms, to Android functions involving invocation, context, actions, and computing resources.

That access is extensive. Third-party assistants may receive real-time input from microphones, cameras, screens, and speakers. They may interact with apps and Google services, automate tasks in virtual windows, change system settings, use on-device AI models, run in the background, and activate through always-on hotwords. Google must document the interfaces, provide testing and technical support, extend future functionality to third parties, and avoid unnecessary friction for users.

These rules could help independent AI developers. An assistant with deep device access can do far more than one confined to an ordinary app sandbox, the restricted environment that limits what an app may see and control. Consumers may gain more choice, and developers may create features Google would never have pursued.

The longer-term cost is weaker competition between integrated systems. Tight integration between Gemini and Android is itself a product feature. It gives Google a way to challenge rival AI providers and distinguish Android from Apple’s model. Requiring Google to reproduce those advantages for competitors may increase competition within Android while reducing competition between rival AI systems.

ICLE’s comments on Article 6(7) identify this neglected distinction. Giving equivalent Android access to leading AI providers could soften competition across the broader AI market by limiting Google’s ability to use operating-system integration as a competitive response. The main beneficiaries may be powerful incumbents rather than scrappy startups. They receive a regulated route into a platform they did not build.

Security risks make equal treatment harder still. Google can inspect its own code, impose internal development rules, revoke credentials immediately, test security throughout the development process, and coordinate responses across Android. It cannot exercise the same control over every outside provider. Equal technical access does not produce equal risk.

The Commission permits integrity measures that are strictly necessary and proportionate. For several sensitive functions, it also allows objective eligibility requirements and independent certification. Yet rules demanding transparent, objectively verifiable, and broadly symmetric restrictions may fit poorly with new threats.

Security teams often must act before they possess conclusive proof. Waiting for demonstrated exploitation can mean waiting until users have already suffered harm. ICLE therefore warns that Google may face a stark choice. It can expose sensitive functions broadly or remove them from its own services so that equal-treatment duties no longer apply.

That creates a predictable form of defensive leveling down. Google may narrow functionality, reduce the sensitivity of available application programming interfaces, delay integrated features, or withhold some services from Europe. Smaller platform developers watching the result may avoid close integration altogether.

When Brussels Becomes the Product Manager

My July 8 analysis of the Court of Justice of the European Union’s (CJEU) Google Android judgment offers a broader frame for evaluating these decisions. Intervention becomes especially risky when regulators treat successful platform design as presumptively suspect and fail to ask what would have existed without the challenged integration.

Android’s compatibility rules, monetization arrangements, defaults, and complementary services helped coordinate handset manufacturers, developers, advertisers, and users. Weakening one part can impose costs on the others.

The July 16 decisions extend that logic beyond retrospective antitrust liability. They prescribe data fields, anonymization methods, recipient eligibility, prices, interface design, access quality, documentation, technical support, timelines, and future functionality. This goes well beyond barring exclusionary conduct. It amounts to continuing administrative control over platform technology.

My related analysis of the DMA’s rule-of-law problems describes this shift from competition law toward product management and industrial administration. Because the DMA does not require the same case-specific proof of competitive harm as traditional antitrust law, procedural discipline and economic evidence become more important.

The formal specification proceedings ran from Jan. 27 to July 16, with preliminary search measures released April 16. The Commission says the process followed two years of discussions with Alphabet and included consultations, testing, and expert input. Google therefore received a process, but the deeper concern remains.

A compressed administrative proceeding under a statute designed to bypass much of traditional antitrust’s effects analysis now determines technical, privacy, security, and intellectual-property questions whose consequences may extend far beyond one product cycle.

The asymmetry in error costs should give regulators pause. The state can revise a mistaken rule. Google cannot fully reverse a data disclosure, undo a security breach, or recover innovation returns once regulators have transferred them to competitors. Under those conditions, “move fast” makes for a poor governing principle.

A Mandate With Brakes

A more economically defensible approach would treat dynamic competition, privacy, security, and firms’ ability to retain returns on investment as core design constraints.

Search-data access should begin narrowly. The Commission should tie it to evidence of specific competitive bottlenecks and initially limit disclosure to synthetic, sampled, or heavily filtered data. It should cap the frequency and duration of access, then expand the mandate only when evidence shows consumer benefits. Competitor uptake alone is a poor measure.

The ban on systematic replication also needs teeth. Recipients should face enforceable limits on reverse engineering, model extraction, combining the data with outside datasets, onward transfers, and changes in ownership or control.

Eligibility should include a recipient-specific national-security review conducted with relevant allied authorities. General country-risk categories cannot capture hidden ownership, personnel access, cybersecurity capabilities, prior incidents, acquisition risk, or the sensitivity of a proposed use. Google should also have a meaningful chance to challenge access before disclosure, when harm can still be prevented.

Pricing should reflect the fixed and sunk investments that created the dataset, the value of the access granted, and the effect on future investment. A rule confined to incremental delivery costs tells prospective innovators that regulators may convert successful investments into inputs for rivals without paying for their creation.

Android interoperability should rely on risk tiers. Ordinary invocation presents different concerns than persistent microphone access, screen automation, system controls, aggregation of app data, or background execution. Regulators should permit different treatment of first-party and third-party services when their governance, auditability, revocation procedures, and security responsibilities differ. New capabilities should undergo controlled testing before general release.

Both decisions also need meaningful sunset provisions and empirical review. The test should focus on consumer outcomes. Did users receive better products, lower quality-adjusted prices, stronger security, more innovation, and greater competition among business models? Giving rivals better inputs answers a different question.

When Success Stops Paying

The Commission sees Google’s search data and Android integration as barriers that keep rivals from competing. A dynamic law & economics analysis sees something else as well—the accumulated returns to investment, experimentation, coordination, and risk-taking.

Both views contain part of the story. Data and operating-system access can ease entry, and dominant platforms can use control over important assets to obstruct competition. Yet the mere existence of a valuable advantage does not show that sharing it will improve consumer welfare. It certainly does not show that rivals should receive it at a price largely detached from the cost and risk of creating it.

The July 16 decisions define competition too narrowly, as rival access to the fruits of an incumbent’s investment. They also define innovation too statically, as the number of firms able to use assets that already exist.

Sound innovation policy must ask who will build the next set of assets. A legal regime that promises successful platforms years of administrative redesign, compelled technical support, regulated access prices, and recurring disclosure of sensitive data will not end innovation. It will push firms to design around Europe, delay launches, collect less useful data, integrate less ambitiously, and invest where returns are more secure.

Europe does not lack rules requiring successful platforms to help their competitors. It lacks confidence that success will remain worth the trouble.

You may also like

Leave a Comment

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More