Brussels vs. Brussels: The EU’s Data Act and the DMA’s Clash Over Cloud
Photo: Noah Berger/Getty Images/Amazon Web Services
On June 24, for the first time, the European Commission turned its Digital Markets Act (DMA) on cloud infrastructure by preliminarily designating Amazon Web Services (AWS) and Microsoft Azure as gatekeepers, although neither firm met the law’s quantitative thresholds. The move was also unusual because cloud services regulation was previously thought to fall under the European Union’s Data Act, rather than the DMA. Serious regulatory differences between the two acts could put AWS and Microsoft in the position of trying to follow two regulatory regimes that differ on topics including enforcement, timelines, and data portability. And while European concerns around sovereignty and market concentration are valid, such regulatory uncertainty risks stifling Europe’s cloud buildout, handicapping its economy, and entrenching its cloud dependence on the United States.
The Acts in Question
The DMA entered into force with much fanfare on November 1, 2022. Using ex ante regulations designed to ensure competition in European digital markets, the act empowers the commission to designate a company as a gatekeeper if it “provide[s] an important gateway between businesses and consumers in relation to core platform services” and requires that designated firms not favor their own services and allow interoperability with third parties.
The European Union’s Data Act, in turn, started to come into force on January 11, 2024, with key provisions of the act subsequently becoming applicable in stages. Among other objectives, the Data Act mandates greater access and transferability of data, reshapes data ownership and monetization strategies, and—of particular relevance here—“allows consumers to easily transfer data and switch between cloud providers.”
There are a number of broad philosophical and functional differences between the DMA and the Data Act. The Data Act requires providers to ensure data portability and interoperability, while the DMA’s primary focus is preventing dominant companies from using their position to lock out competitors or self-preference their own products. Also noteworthy is that the Data Act is heavily focused on business-to-business (B2B) dynamics, while the DMA is oriented around the relationship between gatekeepers and individual consumers. But most importantly, the Data Act applies to all relevant firms operating in the European Union regardless of size and market position, while the DMA applies only to designated gatekeepers.
The Issue: Conflicting Rules, No Guidance
In the European Commission’s report preliminarily designating AWS and Microsoft as gatekeepers, the commission noted that the two companies’ “cloud computing services . . . have achieved significant turnover” and that “[t]hey both have vast and entrenched user bases and appear to benefit from lock-in effects and high switching costs, in addition to a large ecosystem. . . .Whilst AI is significantly increasing the demand for cloud-related services, AWS and Azure appear to retain a large proportion of this increased demand within their respective ecosystems.”
Pushback against the preliminary designations falls largely into two buckets. First, while the commission is not legally mandated to follow the DMA’s quantitative guidance when designating gatekeepers, it almost always has in the past. The guidelines provide clear, objective guidance about when firms would be considered eligible for gatekeeper status. Departing from that guidance exposes the commission to allegations of a politically motivated, predetermined outcome. Other analyses explore whether AWS and Azure even fit the qualitative metrics the commission relies on and note that neither AWS nor Azure holds the 40-plus percent market share needed to be considered dominant under EU competition law. But beyond that, the DMA’s quantitative metrics were designed for consumer-facing platforms rather than cloud computing, which is primarily B2B and characterized by enterprise sales. Applying a consumer-centric framework to determine whether a primarily B2B firm qualifies as a gatekeeper presents a fundamental structural mismatch, akin to deciding the results of a 100-meter sprint by the runner’s bench press.
The second objection concerns the usage of the DMA to regulate cloud service providers at all. As an AWS spokesperson said following the release of the preliminary determination, “The EU already has comprehensive cloud regulation through the Data Act.” The Data Act expressly addresses cloud computing issues such as switching costs, interoperability, and egress fees, among others. And although the DMA and the Data Act largely pursue similar goals, they diverge in meaningful ways that impose conflicting compliance obligations on cloud providers and create significant investment uncertainty.
For instance, under the Data Act, enforcement is delegated to member state authorities, while DMA enforcement is centralized under the European Commission. And while key Data Act provisions phase in gradually until 2027—giving businesses time to plan compliance—DMA obligations attach immediately upon gatekeeper designation, giving firms a maximum of six months to comply. In addition, while the Data Act requires cloud providers to allow data to move between different data spaces, building the pipelines required by its interoperability mandates may require processing personal data in ways that conflict with DMA consent requirements and General Data Protection Regulation (GDPR) data minimization principles—a conflict that the commission itself has acknowledged. More broadly, the commission’s willingness to abandon its quantitative designation process leaves every cloud provider uncertain of whether it could be designated as a gatekeeper and then face two regulatory regimes without guidance for how to satisfy one without violating the other.
The Impacts of Conflicting Cloud Regulation
The costs of regulatory overlap are not lost on European policymakers. The famous September 2024 Draghi Report argued that the European Union’s “inconsistent and restrictive regulations” harm the bloc’s competitiveness, innovation, and growth, using overlaps between the GDPR and the European Union’s Artificial Intelligence Act (AI Act) as an example. Following the report, the European Parliament sought proposals to simplify EU digital economy laws and reduce companies’ administrative burdens. In October 2025, the European Parliament published a report assessing the overlaps between the AI Act and other pieces of EU digital legislation, including the Data Act, and found that “their interplay creates significant regulatory complexity.” There are three likely consequences of the regulatory confusion caused by the overlap between the Data Act and DMA on European cloud capability: slowed buildout, entrenched foreign market leadership, and foreign dependence.
Consequence 1: Slowed Cloud Compute Buildout
The Draghi Report illustrates clearly how duplicative regulation can stifle innovation and competitiveness. Designating AWS and Azure as gatekeepers would subject two of the three largest investors in Europe’s data center buildout to contradictory obligations under separate regulatory frameworks. As AWS noted in its statement, the preliminary rulings “risk deterring European investment and innovation.” AWS’s warning is more than corporate posturing—a large body of academic scholarship shows that policy uncertainty makes firms more cautious about large capital commitments and can delay such investments. Closer to home, the European Investment Report for 2024 and 2025 found that 74 percent of firms cited regulatory inconsistency as a barrier to expanding their business in the European Union. If AWS and Microsoft scale back their European investment, the European Union’s ambitious plan to triple data center capacity in five to seven years would become even more difficult.
Duplicative regulation could also reduce the availability of cutting-edge services to European businesses while suppressing adoption of those that do reach the market. European regulations have already prompted U.S. firms to delay or withhold new products from the European market, leaving businesses without tools available to their global competitors. One study found that 11 percent of advanced large language model releases were delayed or withheld from the European Union compared to the United States due to regulatory reasons. European AI firms may avoid the most capable and cost-competitive cloud services offered by AWS and Azure to sidestep regulatory uncertainty. Pushed toward domestic alternatives, they would face more limited cloud AI infrastructure capacity, further widening the competitiveness gap with their foreign counterparts.
Consequence 2: Entrenching the Leaders
A second consequence of the commission’s decision could, ironically, be to cement AWS’s and Azure’s leading positions in the European market. Regulatory compliance is expensive, and large firms are generally better positioned to absorb its costs than smaller competitors. This dynamic occurred during the European Union’s implementation of the GDPR, when U.S. firms gained European market share while European firms lost it, owing to U.S. firms’ ability to pay the regulation’s fines. In FY 2025, AWS reported revenue of $128.7 billion; Microsoft reported over $75 billion from Azure alone. SAP and Deutsche Telekom, the two European cloud service providers with the largest share of the European market, reported cloud revenue of €21 billion and €4.1 billion, respectively. If compliance with both the DMA and the Data Act becomes a battle of resources, AWS and Microsoft are better equipped than European firms. While the commission is unlikely to subject SAP or Deutsche Telecom to gatekeeper status, the ambiguity surrounding its qualitative threshold approach means European firms cannot be certain. Faced with that uncertainty, they may avoid the aggressive growth strategies that could bring them within the commission’s sights.
The preliminary designations could entrench AWS and Azure’s advantage in a second, more subtle way: Regardless of the designation’s outcome, AWS and Azure will soon have defined regulatory obligations and the resources to meet them. European enterprises, navigating an uncertain and overlapping regulatory environment, may come to see that defined compliance position as a competitive advantage favoring AWS and Azure over less-resourced European alternatives. The cumulative effect could be a European cloud market more concentrated around the very U.S. incumbents that EU digital sovereignty policy is designed to counterbalance against.
Consequence 3: A Lack of Domestic European Alternatives and Foreign Dependence
Limiting the growth of U.S. hyperscalers could make sense if there were European providers able to fill the investment vacuum. Unfortunately, the evidence suggests that there is not. European providers’ share of the European cloud computing market declined from 29 percent in 2017 to 15 percent in 2022 and remained there until 2025, and it is unclear whether European firms have the resources necessary to reverse this trend. Additionally, European providers are ill-equipped to provide the AI-specific infrastructure necessary to meet Europe’s rapidly growing cloud demand. Without viable European alternatives, European firms dependent on cloud infrastructure could find themselves increasingly reliant on providers based outside the European Union. The result could be the opposite of digital sovereignty: deeper European dependence on non-EU providers at a moment when geopolitical ties are fraying. And while the European Union has stated its goal to triple total data center capacity within five to seven years, many independent analysts consider the target unrealistic. Moreover, the European Union’s plans rely largely on private investment to reach that goal, and European cloud providers lack the balance sheets to supply the estimated €200 billion the European Union is targeting for its AI buildout.
Policy Suggestions
Cloud computing is a quickly evolving technology that is foundational for competitiveness in the new AI economy. In the face of such dramatic economic change, the European Commission is implementing new tools such as the Data Act and others to mitigate possible harms. The commission should give its new tools a chance to combat the negative externalities they were designed to prevent and use traditional antitrust powers to ensure competitive markets if necessary. Likewise, the commission should encourage the growth of European cloud providers to address sovereignty concerns. However, if the commission decides to proceed with gatekeeper designations for AWS and Azure, below are two possible recommendations to mitigate regulatory friction between the DMA and the Data Act.
- Provide DMA and Data Act Implementation Guidance: In the short term, the commission should release joint implementation guidance clarifying how cloud service providers designated as gatekeepers can meet their obligations under both the DMA and Data Act. Such guidance could focus on four specific policy areas: (1) compliance timeline conflicts between egress fees and switching and interoperability requirements under the two laws; (2) guidance regarding ongoing data interoperability standards-setting discussions; (3) details about how national authorities and the commission will coordinate enforcement; and (4) the specific quantitative and qualitative factors the commission will use in weighing future cloud service provider gatekeeper designations. Issuing such guidance now, prior to the final designation decisions, would benefit all parties. AWS and Azure could begin their compliance preparation, and European cloud providers would receive a regulatory roadmap to follow while building out their own capabilities.
- Establish a Sovereignty Certification Framework: To mitigate the sovereignty concerns raised by reliance on U.S. companies, the European Commission could expand the sovereignty risk-tiered framework introduced in the proposed Cloud and Development AI Act beyond its current scope into a certification framework explicitly cross-referenced with DMA and Data Act obligations. This expansion could be accompanied by formal guidance clarifying what partitioned hyperscaler infrastructure does and does not achieve at each sovereignty tier and matching task categories to the appropriate tier. Such a framework would give both providers and cloud consumers a clear map of where sovereignty concerns apply and where they do not, offering AWS and Microsoft the regulatory certainty needed to continue their European infrastructure investment. Such clarity would also incentivize European providers to invest specifically in the highest sensitivity tiers where U.S.-headquartered providers raise insurmountable sovereignty issues.
Christopher Gundermann is a fellow in the Economics Program and Scholl Chair in International Business at the Center for Strategic and International Studies in Washington, D.C.