How to Govern Platforms Without Slowing Innovation

How to Govern Platforms Without Slowing Innovation
How to Govern Platforms Without Slowing Innovation

The governance of digital platforms now stands as one of the most consequential regulatory questions facing policymakers. The European Union's Digital Markets Act (DMA) represents the most ambitious attempt to date to constrain the power of gatekeeper platforms through ex-ante regulation. As of 2026, the DMA is in active enforcement, with substantial fines already issued and compliance-driven business model changes underway. At the same time, a growing body of empirical evidence raises serious questions about whether the regulation is producing unintended negative effects on innovation, market entry, and investment. This post examines the current state of evidence on these questions, provides concrete examples of the DMA's substantive obligations, and considers the practical implications for businesses, startups, and policymakers.

The Substantive Obligations at Stake

Understanding the DMA's enforcement record requires familiarity with the substantive obligations the regulation imposes. The DMA identifies six gatekeeper platforms as of the latest designation round: Alphabet (Google), Amazon, Apple, ByteDance, Meta, and Microsoft. Each of these platforms has obligations across the DMA's core articles, and the practical implications of those obligations are now visible in product features and business models.

Article 5 obligations cover several core prohibitions. Self-preferencing is prohibited, meaning gatekeepers cannot treat their own products more favorably than those of third parties in ranking and display. A concrete example: Amazon cannot place its private-label products at the top of search results in a way that disadvantages third-party sellers. Google's obligations under this article require it to display third-party services (such as flight comparison sites or hotel booking platforms) in the same visual layout as Google's own services within Google Search and Google Flights.

Article 6 obligations concern data-related requirements. Gatekeepers must provide business users with access to data generated through their activity on the platform, support data portability for end users, and refrain from combining personal data across services without consent. A practical illustration: a small business selling products through Amazon's marketplace can now request the data generated by their activity on the platform, including customer reviews and purchase patterns, which they previously could not access.

Article 7 obligations address interoperability and access. Messaging services such as WhatsApp must enable interoperability with competing messaging services upon reasonable request. This obligation has practical implications for how Meta engineers WhatsApp and how competing services like Signal or Telegram can technically integrate with it.

App store obligations under Article 6(4) and related provisions have produced the most visible compliance changes. Apple was required to allow alternative app marketplaces and alternative payment processors on iOS in the European Union. In response, Apple launched the Digital Markets Act-compliant version of iOS in early 2024 and introduced the Core Technology Fee, a per-installation charge on developers distributing apps through alternative channels or the App Store. Meta's "less personalized ads" subscription model for Facebook and Instagram in the EU represents a similar compliance adaptation under Article 5(2), which prohibits combining personal data across services without consent.

The Enforcement Record Is Now Substantial

The DMA's enforcement architecture has moved decisively from design to practice. On 23 April 2025, the European Commission issued its first non-compliance decisions under the regulation. These decisions order gatekeepers to cease and desist infringements, and the Commission may impose fines where violations are established.

Apple was fined €500 million for violating DMA rules by preventing developers from informing users about cheaper options available outside the App Store. Meta was also fined for DMA breaches, confirming that the penalty regime is being applied across multiple gatekeepers rather than selectively. The enforcement activity extends beyond fines: the Commission initiated two sets of specification proceedings to assist Google in complying with its DMA obligations, representing a more collaborative but still formal enforcement mechanism.

The enforcement activity has already produced tangible compliance changes. Following the fine, Apple reduced its App Store fees for developers in the European Union, and the EU welcomed these steps as evidence of meaningful compliance. This sequence illustrates both the financial teeth of the DMA and the potential for compliance-driven business model transformation. The DMA is not a paper tiger. Companies designated as gatekeepers must take compliance seriously or face substantial financial penalties and ongoing regulatory scrutiny.

The financial scale of potential DMA fines warrants emphasis. Under Article 30, fines can reach up to 10 percent of a gatekeeper's total worldwide annual turnover, and up to 20 percent for repeated infringements. For context, Meta's total worldwide revenue in 2024 exceeded $160 billion, meaning a maximum fine under the DMA could theoretically exceed $16 billion for a single infringement. The €500 million Apple fine, while substantial, represents a fraction of the maximum available penalty and signals that the Commission may be reserving the highest fines for the most egregious or persistent violations.

The Innovation Question Is Contested

The most significant tension in the current evidence concerns innovation. Empirical analysis published in August 2025 found that the DMA negatively impacted market new entry and investment in DMA-related industries. This finding suggests that the regulation may be raising barriers or creating uncertainty that discourages new entrants. A 2025 study reported that digital regulations have contributed to increased market concentration and a decline in startup investment, suggesting the opposite of what the DMA was designed to achieve.

These findings are particularly important because they challenge the DMA's stated objectives. The Esade research program is explicitly examining the DMA's effects on incentives to innovation, research and development, and the scaling of European startups, indicating that this question is recognized as central to the policy debate.

The European Commission, however, takes a different view. Its April 2026 review concluded that the DMA remains fit for purpose and was designed to be future-proof, capable of adapting to emerging challenges including those arising from artificial intelligence and cloud computing. This creates a direct divergence between the regulator's institutional position and independent empirical findings, a divergence that may shape future policy adjustments.

A contrarian viewpoint adds further complexity. Industry-funded research argues that digital platform owners solve market failures such as matching inefficiencies, coordination breakdowns, and underinvestment in quality. From this perspective, regulation that constrains platform owners may undermine the value they create, potentially harming the very ecosystems the platforms support. If this argument is correct, then the empirical finding of increased market concentration following digital regulation is not an unintended consequence but a predictable outcome.

A concrete illustration of the innovation tension comes from the mobile app ecosystem. Apple's introduction of the Core Technology Fee in response to DMA requirements has been criticized by developers as a regressive measure. The fee structure charges developers €0.50 per first annual install per year once an app exceeds one million first annual installs. For a small developer whose app achieves one million downloads, this represents a new compliance cost that did not exist before the DMA. Critics argue this fee structure disproportionately affects mid-sized developers who fall into the fee threshold but lack the scale to absorb the cost easily. Apple argues the fee is necessary to reflect the value of the technologies it provides under DMA-compliant distribution models. This single fee illustrates how compliance-driven business model changes can themselves become contested innovation policies.

Regulatory Sandboxes as a Governance Innovation

Regulatory sandboxes have emerged as a prominent tool for balancing innovation and oversight. The EU's Interoperable Europe initiative describes interoperability regulatory sandboxes as instruments that allow innovation to be tested in real-world conditions where unexpected legal questions can be addressed.

Several concrete initiatives launched in 2025 illustrate the institutional commitment to this approach. Germany's Regulatory Sandboxes Innovation Portal began a three- to four-year pilot operation on 22 May 2025, serving as a digital platform for planning, implementing, and conducting sandboxes. From May 2025, the EU's regulatory sandboxes innovation portal began operating as a contact point for sandbox initiatives across member states. Sandbox AgriFoodtech25 was established in 2025 to facilitate requests in the agrifood technology sector.

The stated objectives of sandboxes include improving legal certainty, supporting the sharing of best practices, fostering innovation, and contributing to evidence-based regulatory learning. Research also shows that even non-waiver sandboxes, those that do not exempt participants from legal requirements, can still deliver governance outcomes, suggesting that the value of sandboxes extends beyond the simple provision of regulatory exemptions.

For policymakers, sandboxes represent a middle path between rigid ex-ante regulation and pure self-regulation. They allow regulators to gather evidence about emerging technologies and business models, while allowing innovators to test products without full regulatory exposure. However, outcome evidence remains limited. Most documentation describes sandbox design and launch rather than measured results, leaving open the question of whether sandboxes actually deliver on their stated objectives.

A practical example of sandbox application involves artificial intelligence. Several EU member states have established AI sandboxes under the AI Act, allowing AI providers to test high-risk AI systems in controlled environments with regulatory supervision. These sandboxes function as laboratories where regulators can observe how AI systems perform, where developers can identify compliance issues before full market deployment, and where both parties can develop shared understanding of regulatory expectations. The experience with AI sandboxes may offer transferable lessons for DMA-related sandbox initiatives, particularly as cloud computing and AI intersect with gatekeeper obligations.

The Governance Design Trade-Off

The DMA represents a fundamental shift in regulatory philosophy. The DMA marked a major shift in EU competition and regulatory policy, moving from an effects-based and ex-post approach to an ex-ante framework. This means the DMA imposes obligations on gatekeepers before harm is proven, rather than waiting for harm to occur and then intervening.

This shift creates an inherent trade-off. Ex-ante regulation provides legal certainty and may prevent entrenchment of dominant positions, but it may also impose compliance costs and uncertainty on innovative business models. Ex-post enforcement allows markets to develop freely, but may allow dominant platforms to entrench their positions before intervention becomes possible.

The empirical evidence of negative effects on entry and investment suggests that the ex-ante approach has real costs. However, the Commission's review maintains that the DMA is adaptable, suggesting that regulators believe the benefits outweigh the costs. The fundamental question is whether the regulatory framework can be recalibrated as evidence accumulates, or whether the structural shift to ex-ante regulation will produce persistent effects on market dynamics.

The trade-off is not merely theoretical. Consider the experience of a European startup seeking to compete in digital advertising. Before the DMA, this startup would face the prospect of competing against Google's integrated advertising stack on Google's own platforms, where self-preferencing was common. The DMA prohibits self-preferencing, theoretically leveling the playing field. However, the startup must now navigate a compliance landscape that includes DMA obligations, GDPR requirements, the AI Act for any AI-driven targeting, and the Digital Services Act for content moderation obligations. The cumulative compliance burden may itself constitute a barrier to entry, even when each individual regulation is reasonable in isolation. This is the regulatory stack problem: the interaction of multiple overlapping digital regulations may produce higher barriers than any single regulation intended.

Real-World Cases Illustrate the Pattern

The Apple case provides a clear illustration of the DMA's enforcement-to-compliance pathway. The €500 million fine followed the Commission's conclusion that Apple violated EU rules by preventing developers from steering users to cheaper options outside the App Store. Following the fine, Apple reduced its App Store fees for EU developers, and the EU welcomed these steps. This case demonstrates both the financial consequences of non-compliance and the potential for regulatory pressure to drive business model changes.

The Meta case confirms that the DMA's penalty regime is being applied across multiple gatekeepers, not just a single high-profile target. The Google specification proceedings illustrate a more collaborative enforcement mechanism, where the Commission assists gatekeepers in complying with their obligations rather than moving directly to penalties.

Germany's Regulatory Sandboxes Innovation Portal demonstrates institutional investment in the sandbox approach. The three- to four-year pilot operation signals a long-term commitment to this governance tool. Sandbox AgriFoodtech25 shows how sandbox initiatives can be tailored to specific sectors, in this case agrifood technology.

Beyond these headline cases, several developer-level examples illustrate the DMA's downstream effects. Epic Games, the developer of Fortnite, has been a vocal advocate for app store competition and has navigated the new alternative app marketplace landscape in the EU. Spotify, the music streaming service, has been an active complainant in DMA-related proceedings against Apple, citing the App Store's restrictions on app store rules as a barrier to its growth in the European market. These companies represent the developer perspective that motivated DMA-style regulation, and their post-DMA experiences offer practical evidence of whether the regulation delivers on its promises.

A complementary case comes from the search engine market. Google's search results in the EU now include comparison units for flight booking, hotel booking, and similar verticals, displayed in a manner that does not visually favor Google's own services over third-party providers. This change is visible to any EU user searching for flights or hotels on Google. While the practical impact on user behavior and third-party provider traffic remains to be measured, the change represents a concrete, observable modification of a dominant platform's behavior in response to the DMA.

Sectoral Applications and Differential Effects

The DMA's effects vary considerably across sectors, and understanding this variation is important for assessing the regulation's overall impact.

In the mobile app ecosystem, the effects are most visible. The introduction of alternative app marketplaces on iOS in the EU, such as the Epic Games Store and the AltStore, represents a structural change that did not exist before the DMA. Developers now have multiple distribution channels, and the fee structures vary across channels. However, the fragmentation also creates complexity: developers must manage compliance across multiple app stores, each with its own terms.

In the digital advertising sector, the effects are more diffuse. Google's compliance with DMA Article 5(4), which requires non-discrimination in the Google Play Store, and Article 6(5), which addresses advertising-related obligations, has produced changes in how ads are ranked and displayed. The cumulative effect on advertising market structure is still being assessed.

In the cloud computing sector, the DMA's intersection with cloud-specific regulation is still developing. Microsoft Azure, Amazon Web Services, and Google Cloud Platform are all designated gatekeeper services under the DMA. The DMA's interoperability and data portability obligations apply to these services, but the technical implementation is complex. A 2026 specification proceeding addressed how Microsoft should comply with interoperability obligations for its cloud productivity software, illustrating that cloud compliance is an active and evolving area.

In the messaging sector, WhatsApp's interoperability obligations remain in early implementation. The technical standards for interoperability between WhatsApp and competing messaging services are complex, and competing services must request access. The practical effect on user choice in messaging remains limited as of 2026, but the obligation itself represents a structural shift in how dominant messaging platforms relate to their competitors.

Comparative International Perspective

The DMA does not exist in isolation. Other jurisdictions have developed different approaches to platform governance, and comparison clarifies the DMA's distinctive features.

The United Kingdom has pursued a pro-innovation approach through the Digital Markets, Competition and Consumers Act, which establishes a pro-competition regime administered by the Competition and Markets Authority. The UK regime includes strategic market status designation, which is similar to the DMA's gatekeeper concept, but the enforcement mechanism relies more heavily on conduct requirements and pro-competition interventions tailored to specific market investigations. The UK has explicitly positioned its regime as more flexible and innovation-friendly than the DMA, though it shares the fundamental goal of constraining dominant platform behavior.

The United States has pursued platform governance primarily through antitrust enforcement, with active cases against Google, Apple, and Meta proceeding through the courts. The US approach is ex-post by default, focusing on proving harm in court rather than imposing obligations ex-ante. The 2024 judgment against Google in the search antitrust case and subsequent remedies proceedings represent the most consequential US platform governance actions to date.

Japan, Australia, and other jurisdictions have developed their own approaches, often drawing on EU and UK models while adapting them to local conditions. This global divergence creates complexity for platforms operating across jurisdictions, as compliance with the DMA does not guarantee compliance with other regulatory regimes.

For startups, this divergence is particularly consequential. A European startup building a digital service must navigate DMA compliance if it scales to gatekeeper status, but in the immediate term it faces DMA obligations only as a business user of gatekeeper platforms. A US startup faces different obligations. A startup operating across multiple jurisdictions faces overlapping but not identical regulatory regimes. The cumulative compliance burden varies substantially by jurisdiction and business model.

Final Assessment

The evidence as of 2026 suggests that governing digital platforms without slowing innovation requires a delicate and ongoing balance. The DMA's enforcement regime is operational and credible, with substantial fines and compliance changes already documented. However, empirical evidence indicates negative effects on entry and investment that run counter to the DMA's stated objectives. Regulatory sandboxes offer a promising tool for balancing governance and innovation, but their outcomes are not yet measured. The fundamental trade-off between ex-ante regulation and innovation remains unresolved, and the evidence base is too young to support definitive conclusions about the DMA's long-term effects.

For policymakers, the evidence suggests that enforcement credibility matters, that innovation effects must be monitored alongside compliance metrics, that sandboxes offer a learning mechanism for both regulators and innovators, and that the trade-off between regulation and innovation is real and may fall disproportionately on new entrants and startups. Specifically, policymakers should consider independent evaluation mechanisms for DMA impact assessment, expanded sandbox coverage for AI and cloud services, and regular recalibration of obligations based on accumulated evidence.

For platform companies, the evidence suggests that compliance is now mandatory, that business model changes may be required, and that engagement with regulators through specification proceedings and sandbox initiatives offers a constructive path forward. Companies should invest in dedicated DMA compliance functions, participate actively in sandbox initiatives where available, and document compliance decisions carefully to support both regulatory engagement and potential enforcement defense.

For startups and smaller businesses, the evidence suggests a mixed picture. The DMA creates new rights and opportunities, particularly data access and interoperability rights that were previously unavailable. However, the compliance complexity of operating within the DMA-regulated environment is real, and the documented negative effects on entry and investment should be taken seriously. Startups should understand their rights under the DMA, including the right to request data from gatekeepers and the right to interoperability where applicable. They should also engage with industry associations that represent their interests in DMA-related proceedings.

For investors, the evidence suggests that the DMA affects venture investment dynamics in digital sectors, with potential effects on both deal flow and exit opportunities. Investment due diligence in DMA-affected sectors should account for compliance costs, business model risks, and the potential for regulatory-driven market structure changes.

The DMA represents a live policy experiment whose outcomes will shape platform governance well beyond the European Union. The evidence accumulated to date provides reasons for both confidence in the enforcement regime and concern about innovation effects. Continued monitoring, independent evaluation, and willingness to recalibrate the regulatory framework as evidence emerges will determine whether the DMA achieves its stated goals without imposing unacceptable costs on the innovation dynamics it was designed to support.

The next phase of evidence accumulation will be particularly important. As the DMA's enforcement record matures, as sandbox outcomes become measurable, and as the cumulative effects of the DMA plus other digital regulations become clearer, policymakers will have a richer evidence base for refinement. The question is not whether the DMA will continue to be enforced, but whether it will be enforced with sufficient attention to the innovation effects that empirical research has begun to document. The answer to that question will shape digital markets not only in Europe but globally, as other jurisdictions observe the EU's experiment and draw their own conclusions about the appropriate balance between platform governance and innovation dynamism.

Also read: