The Regulatory Reckoning That Has Arrived for Big Tech
The technology industry’s decade-and-a-half of relatively light regulatory scrutiny — during which the dominant platforms expanded from search and social networking to commerce, communications, cloud computing, and operating system control — has given way to a sustained and coordinated regulatory effort across multiple jurisdictions. The EU, the US, the UK, and major Asian jurisdictions have all launched significant regulatory initiatives targeting different aspects of large technology company power: competition practices, data privacy, content moderation, AI safety, and platform terms for third-party developers. The regulatory wave that has arrived is not a temporary political moment but a structural shift in how governments view technology companies’ relationship with society.
The regulatory philosophy difference between the EU and the US that most explains why European regulation has moved faster and more comprehensively: the EU’s approach treats certain technology harms as structural risks that warrant preventive regulation rather than waiting for demonstrated harm before intervening, while the US approach has traditionally relied on ex post antitrust enforcement and market competition to address technology harms. The EU’s willingness to impose requirements before harm is proven has produced the GDPR (data privacy), the Digital Markets Act (platform competition), the Digital Services Act (content moderation), and the AI Act (artificial intelligence) — a comprehensive regulatory framework that the US has not matched with equivalent federal legislation.
Antitrust Enforcement Against Tech Platforms
The antitrust enforcement actions against technology companies that have most directly changed how products work: the US Department of Justice’s case against Google’s search distribution agreements (which resulted in a 2024 ruling that Google had illegally maintained its search monopoly through exclusive deals with Apple, Mozilla, and device manufacturers), the EU’s enforcement of the Digital Markets Act against Apple (which required Apple to allow alternative browser engines on iOS in the EU, open iMessage to third-party services, and enable sideloading of apps from outside the App Store), and the FTC’s ongoing cases against Amazon and Meta (which challenge the acquisition strategies that built those companies’ dominant positions).
The antitrust enforcement outcome that most affects the technology landscape for consumers: the interoperability requirements that regulatory action is increasingly imposing on dominant platforms. The messaging platform required to interoperate with competing messaging services, the mobile operating system required to allow alternative app stores, and the search engine required to offer competitive conditions to rival services represent structural changes that increase competition for the specific products that regulatory action targets. Whether these requirements produce genuine consumer benefit depends on whether competing services emerge to take advantage of the interoperability mandates — a question that the early implementation of the EU’s Digital Markets Act is beginning to answer.
AI Regulation: The EU AI Act and Its Global Implications
The EU AI Act, which entered into force in August 2024 and begins applying requirements to different AI system categories on a phased schedule, establishes the world’s first comprehensive legal framework for regulating artificial intelligence. The Act’s risk-based approach categorises AI systems from unacceptable risk (systems that are prohibited, including social scoring systems, real-time biometric identification in public spaces, and manipulation of human behaviour through subliminal techniques) through high risk (systems in categories including employment, education, law enforcement, and critical infrastructure, which require conformity assessments, technical documentation, and human oversight) to limited and minimal risk systems (which face transparency obligations or no specific requirements).
The EU AI Act compliance requirement that most affects the global technology industry: the obligations on general-purpose AI models (the foundation models and large language models that underpin most current AI applications). General-purpose AI models released after August 2024 must provide technical documentation, comply with EU copyright law, and publish summaries of training data. Models deemed to pose systemic risk (determined by the compute threshold used for training) face additional requirements including adversarial testing, reporting of serious incidents, and cybersecurity measures. These requirements apply to any model made available in the EU market, regardless of where the developer is based — making EU compliance a global consideration for all major AI model developers.
Data Privacy Regulation: GDPR and Its Successors
The GDPR (General Data Protection Regulation), which became enforceable in May 2018, has been the most influential data privacy regulation in history — not only because of its direct application to organisations processing EU residents’ personal data but because of its influence on the privacy regulations enacted subsequently in California (CCPA/CPRA), Brazil (LGPD), India (DPDPA), and dozens of other jurisdictions. The global harmonisation of data privacy regulation around GDPR-like principles — data minimisation, purpose limitation, consent requirements, data subject rights, and breach notification obligations — has created a de facto global privacy standard for organisations that serve customers across multiple jurisdictions.
The GDPR enforcement action that most clearly revealed the regulation’s practical consequences for major technology companies: the Irish Data Protection Commission’s 1.2 billion euro fine against Meta in May 2023 for transferring EU user data to the United States without adequate protections — the largest GDPR fine issued to date. The enforcement action illustrated both the regulation’s extraterritorial reach (applying to US companies processing EU data) and the genuine financial consequences for non-compliance, making GDPR compliance a board-level risk management issue rather than only a legal and technical matter.
The Digital Markets Act: Forcing Open the Walled Gardens
The EU Digital Markets Act (DMA), which began applying to designated gatekeepers in March 2024, is the most significant structural intervention in technology markets since the antitrust enforcement of the 1990s. The DMA designates large technology platforms as gatekeepers based on specific thresholds of size and market position, and imposes a list of specific obligations (things they must do) and prohibitions (things they must not do) without requiring proof of specific harm in each case. The designated gatekeepers include Apple, Google, Meta, Amazon, Microsoft, ByteDance, and Booking.com — required to comply with requirements including interoperability of messaging services, fair treatment of third-party services, and prohibition of self-preferencing.
The DMA requirement with the most consequential long-term implications for the technology industry: the interoperability mandate for messaging platforms, which requires WhatsApp and Messenger to enable third-party messaging clients to communicate with their users. The technical implementation of cross-platform encrypted messaging interoperability is complex and is still being worked out, but if successfully implemented, it would allow users of different messaging platforms to communicate without switching platforms — potentially breaking the network effects that have kept messaging platforms fragmented. This is the kind of structural change that competition regulators have historically found it very difficult to achieve through ex post antitrust enforcement, but that the DMA’s ex ante obligations may actually deliver.
