AWS and Azure DMA Designation Brings Cloud Lock-In Under EU Scrutiny
Microsoft Azure and Amazon Web Services are reportedly one decision away from joining the European Union’s strictest Big Tech regulatory regime.
The expected AWS and Azure DMA designation would bring cloud infrastructure under the Digital Markets Act, or DMA, for the first time. According to an October 2 cloud regulation report, regulators are preparing a final decision for November. The timing remains subject to change, and the European Commission says its assessment is still underway.
This is more than another dispute over technology regulation. The Commission is testing whether cloud platforms function as gateways between businesses and their customers, even without meeting the DMA’s normal quantitative thresholds. That theory would subject AWS and Azure to obligations involving interoperability, customer lock-in, data access, and self-preferencing.
The central conflict is between two descriptions of the same cloud market. Regulators see durable market power reinforced by switching costs, integrated software, and expanding artificial intelligence portfolios. Amazon and Microsoft describe an active market where customers can combine multiple providers and move workloads when business needs change.
That disagreement matters because modern cloud contracts reach far beyond rented servers. They increasingly combine databases, identity systems, developer tools, security services, business software, and AI models. A rule aimed at cloud infrastructure can therefore influence how European companies build and operate their entire technology stack.
What the Reported AWS and Azure DMA Designation Changes
The immediate change is regulatory status, not an order to dismantle either cloud platform.
The Commission opened separate investigations into AWS and Azure in November 2025. It wanted to determine whether they act as important gateways between businesses and consumers, despite missing the DMA’s standard designation thresholds.
Those thresholds were designed around consumer-facing platforms with large numbers of active users. Enterprise cloud services have fewer direct customers, but each customer can support millions of downstream users. That makes simple account counts a poor measure of influence.
The Commission reached a preliminary view in June 2026. Its preliminary findings identified AWS as Europe’s largest cloud computing service and Azure as the second largest.
Regulators also described both services as important gateways between businesses and their customers. They cited entrenched user bases, large surrounding ecosystems, high switching costs, and customer lock-in.
AI became part of that assessment. The Commission said each company’s AI tools and partnerships had become decisive factors in cloud purchasing decisions. That observation connects the investigation directly to the next phase of cloud competition.
The October report says officials are finalizing a decision that would confirm the AWS and Azure DMA designation. However, the Commission has emphasized that no final decision has been taken. The reported November timetable can still move.
A final designation would start a six-month compliance period. AWS and Azure would then need to explain how their European operations satisfy the applicable DMA obligations.
That process would probably require detailed compliance plans rather than one universal technical change. Cloud services differ from app stores, social networks, and search engines already covered by the law.
The Commission must therefore translate broad principles into cloud-specific requirements. The relevant questions include which interfaces require interoperability and how far portability obligations should reach.
Another question concerns self-preferencing. A cloud provider can favor its own databases, marketplaces, AI services, or software through technical integration, commercial terms, and default configurations.
The investigation does not establish that every integrated service violates the DMA. It does place those integrations under a tougher legal framework, with the provider responsible for demonstrating compliance.
Noncompliance can trigger fines reaching 10 percent of worldwide annual turnover. Repeated violations can produce penalties reaching 20 percent, giving the designation consequences beyond ordinary supervisory review.
For customers, no immediate migration decision follows from the report. Existing workloads, contracts, and service configurations continue operating while the investigation proceeds.
The significance lies in the direction of travel. Europe is preparing to treat infrastructure platforms as possible gatekeepers, not merely suppliers competing for enterprise contracts.
Why Europe Now Sees Cloud Infrastructure as a Gateway
Cloud power comes from the accumulated difficulty of leaving, not simply from the number of companies opening accounts.
A business rarely adopts every cloud component at once. It might begin with storage and computing, then add managed databases, identity controls, analytics, cybersecurity, and machine learning.
Each additional service can improve performance and reduce operational work. It can also deepen dependence on proprietary interfaces, data formats, and management systems.
This dynamic creates vendor lock-in, meaning the financial or technical burden of changing suppliers becomes large enough to discourage switching. Lock-in does not require an explicit contractual prohibition.
A company may be legally free to leave while facing months of engineering work. Data movement, application rewriting, staff retraining, security reviews, and downtime risks all raise the practical cost.
The Commission’s original cloud investigations focused on these structural barriers. Officials highlighted interoperability obstacles, restricted data access, tying, bundling, and potentially imbalanced contractual terms.
AI makes the problem more urgent. Enterprises now choose clouds partly by examining model access, accelerators, agent platforms, data tools, and partnerships with AI developers.
Once a company builds applications around one provider’s model endpoints and governance controls, migration involves more than moving files. Teams may need to redesign prompts, evaluations, permissions, monitoring, and retrieval pipelines.
That expands the meaning of cloud dependence. Infrastructure decisions increasingly shape which AI services employees and customers can use.
The Commission’s gateway theory reflects this reality. AWS and Azure do not need direct relationships with every end user to influence the services those users receive.
A retailer’s website may run on AWS. A manufacturer’s customer portal may depend on Azure identity and database services. Consumers see the application, while the cloud platform remains invisible underneath it.
Amazon disputes this interpretation. It argues that AWS provides technical components and does not control how business customers reach their users.
That distinction is legally important. The DMA was built primarily for platforms that connect business users directly with consumers, such as marketplaces and app stores.
Cloud infrastructure has a different architecture. It supports the connection without necessarily setting the customer’s prices, content rules, or consumer access terms.
The Commission’s position treats infrastructure control as enough when a provider becomes an unavoidable commercial gateway. Amazon’s position requires a more direct intermediary relationship.
A final AWS and Azure DMA designation would resolve that issue for these investigations, but it would not eliminate the underlying debate. Courts may eventually examine whether the Commission stretched the gateway concept too far.
Meanwhile, the market remains concentrated. European market research estimated that Amazon, Microsoft, and Google controlled about 70 percent of regional cloud infrastructure revenue in 2025.
European providers held about 15 percent. Their revenue had grown, but the overall market expanded faster, leaving their collective share well below its 2017 level.
Those figures do not prove misconduct. They do explain why European officials view cloud switching and interoperability as strategic competition issues.
Customer Freedom Versus the Integrated Cloud Stack
The core tradeoff is whether regulation can reduce lock-in without weakening the integrations customers deliberately chose.
AWS and Azure compete by offering broad collections of services under one operational system. Customers can combine computing, storage, networking, databases, security, and AI through common billing and management tools.
That integration delivers real benefits. Developers can deploy applications faster when identity controls, monitoring, and databases already work together.
Large organizations also value one provider handling reliability, compliance documentation, and support across connected services. Replacing that structure with many vendors can create coordination costs.
Yet the same integration can become a defensive barrier. A competing database or AI service may struggle when the cloud operator controls placement, defaults, technical interfaces, and purchasing incentives.
Self-preferencing becomes relevant here. It means a gatekeeper gives its own products better treatment than competing products using the same platform.
In cloud services, such treatment might appear through marketplace rankings, bundled discounts, licensing rules, performance advantages, or easier integration. Not every difference amounts to unlawful preference.
The compliance challenge will be separating legitimate engineering choices from conduct that closes the market. Regulators need evidence about how customers actually select and replace services.
Microsoft faces particular attention because Azure connects with a wide business software portfolio. Windows Server, Microsoft 365, identity products, databases, security tools, and AI services can all influence cloud procurement.
AWS has a different advantage. It offers a deep infrastructure catalog and has held Europe’s leading cloud position for years.
Its customers may build applications around proprietary managed services that would require substantial redesign elsewhere. That dependence can exist even when alternative suppliers offer comparable raw computing capacity.
The AWS and Azure DMA designation would shift responsibility toward both providers. They would need to show that business users can interoperate with outside services on fair terms.
The likely effect is not complete technical standardization. Cloud platforms differ in architecture, performance, and service design, and the DMA does not require them to become identical.
More realistic changes could involve clearer interfaces, improved export tools, fewer contractual restrictions, and equal access to selected platform capabilities. Regulators may also examine how bundled products affect independent suppliers.
Customers should not assume regulation will make complex migrations simple. Moving a production system still requires application mapping, security testing, data validation, and operational planning.
Rules can remove artificial barriers, but they cannot erase every engineering dependency. A database designed around one provider’s proprietary behavior will remain difficult to replace.
This distinction matters for enterprise buyers. Compliance announcements may promise portability while excluding the services that create the strongest dependencies.
Buyers will need to examine what can actually move. Data export is only one layer. Application logic, identity policies, observability records, and AI evaluation systems matter too.
The most useful test is whether a team can transfer a representative workload without rebuilding it from scratch. That evidence would reveal more than a provider’s general statement about openness.
Why the EU Data Act Does Not End the Argument
Europe already regulates cloud switching, but the Commission believes platform power requires a second layer of oversight.
The EU Data Act began applying in September 2025. Its cloud provisions address switching, interoperability, contractual transparency, and data portability.
Providers must help customers change data-processing services. The law also phases out certain switching charges, including data egress costs associated with leaving a provider.
Amazon argues that these rules already target the Commission’s concerns. In its DMA response, the company called additional gatekeeper regulation duplicative and potentially contradictory.
AWS says Europe’s cloud sector has abundant customer choice and continued investment. It also argues that multicloud use demonstrates competition rather than entrenched control.
The company cites research indicating that more than 70 percent of European customers use multiple cloud providers. It says customers can combine AWS with Azure, Google Cloud, Oracle, European providers, and on-premises systems.
Multicloud statistics require careful interpretation. A company using separate providers for different departments is not necessarily able to move a specific workload between them.
Using one provider for office software and another for application hosting also says little about application portability. The relevant question is whether competing services constrain each other at the workload level.
AWS says it waived data transfer charges for customers leaving its platform in 2024. It also offers a data export registry and contractual provisions supporting switching.
Those steps reduce one visible migration cost. They do not automatically solve application dependencies, licensing restrictions, or the operational burden of replacing managed services.
The Commission views the DMA as a competition tool, while the Data Act establishes broader rules for data access and switching. Officials can therefore argue that the two laws address different dimensions.
The Data Act asks whether customers can move data and services under fair contractual conditions. The DMA asks whether a designated gatekeeper uses control over a platform to restrict contestability.
That distinction supports overlapping regulation, but it also creates uncertainty. A cloud provider may face different interoperability expectations under two laws covering related technical systems.
Amazon warns that ambiguity could delay investment and new service deployment. This claim has not been independently demonstrated, but regulatory complexity can affect product planning.
The skeptical case against the AWS and Azure DMA designation rests on fit and proportionality. Cloud platforms do not mediate consumer transactions in the same direct way as app stores.
They also serve internal workloads with no consumer-facing component. Manufacturing controls, accounting systems, and private analytics platforms challenge a broad gateway definition.
The Commission must explain why those differences do not defeat designation. It also needs to show which DMA obligations make sense for infrastructure services.
A poorly adapted remedy might increase compliance work without making workloads easier to move. It could also encourage formal portability measures that customers rarely use.
A well-designed remedy would focus on barriers providers control. It would avoid treating genuine technical complexity as proof of anticompetitive conduct.
Google Cloud and European Providers Complicate the Case
Regulating the two leaders while excluding their closest global rival creates both an opening and a new competitive imbalance.
Google Cloud ranks behind AWS and Azure in Europe, but it competes for many of the same enterprise and AI workloads. It also operates an extensive platform of proprietary services.
The Commission’s preliminary findings apply to Amazon and Microsoft, not Google. That difference follows its assessment of market position and gateway power.
However, any new obligation can change competitive behavior. If AWS and Azure must open interfaces or modify bundles, Google could gain access without accepting equivalent restrictions.
That outcome might improve competition in the short term. It could also shift customers toward another American hyperscaler rather than strengthening European alternatives.
European providers include OVHcloud, IONOS, Scaleway, STACKIT, Deutsche Telekom, and Orange. Their smaller scale limits their ability to match every hyperscaler service.
They can still compete through data location, sovereignty controls, specialized hosting, and local support. Improved interoperability could make those services easier to combine with large global clouds.
This is where cloud regulation differs from a simple market-share contest. A smaller provider does not need to replace AWS or Azure entirely to become commercially relevant.
It might host sensitive records while a customer runs analytics elsewhere. It might supply computing capacity that connects to a hyperscaler’s identity or management tools.
Interoperability determines whether such combinations remain practical. Poor compatibility can turn a technically viable alternative into an expensive integration project.
European regulators also have evidence from outside the EU. The United Kingdom’s Competition and Markets Authority completed a major cloud investigation in July 2025.
The UK cloud decision found adverse effects on competition and recommended considering strategic market status investigations for AWS and Microsoft.
By March 2026, the British regulator had chosen a more targeted path. It opened an investigation into Microsoft’s business software ecosystem while continuing to monitor cloud developments.
The authority also said Microsoft and Amazon had taken material steps concerning interoperability and data-transfer charges. That approach gives the Commission a useful comparison.
The UK experience supports concerns about market power, but it does not establish that identical remedies fit every jurisdiction. It shows regulators can combine formal investigations with negotiated changes.
Microsoft’s position adds another complication. The company says cloud competition is changing quickly and points to Google’s growth as evidence that entry and expansion remain possible.
Rapid growth by a third hyperscaler does not necessarily help smaller providers. It may instead confirm that only companies with enormous infrastructure and software resources can compete broadly.
AI reinforces that scale advantage. Training infrastructure, accelerator access, foundation-model partnerships, and enterprise distribution now influence the same procurement decision.
The Commission specifically cited AI portfolios when explaining its preliminary view. That suggests compliance discussions may reach beyond traditional computing and storage.
Developers should watch whether remedies cover AI marketplaces, model access, and connections between cloud data and proprietary assistants. Those areas can create dependencies faster than older infrastructure services.
Enterprise buyers should also avoid assuming that a European provider automatically removes every sovereignty concern. Ownership, subcontractors, encryption control, support access, and applicable law all require separate review.
The designation debate is therefore not simply Europe against American technology companies. It concerns which technical and commercial conditions let multiple providers compete around the same customer.
What to Watch Before the November Decision
Three signals will show whether the reported designation becomes a practical cloud policy or remains a broad regulatory warning.
The first signal is the final decision itself. The October report points to November, but regulators have not confirmed that date publicly.
A final AWS and Azure DMA designation would strengthen the Commission’s gateway theory. A delay or narrower conclusion would signal unresolved questions about applying the law to infrastructure.
The legal reasoning matters as much as the outcome. Buyers should look for how the Commission connects enterprise cloud services with downstream consumers.
That explanation will shape future cases involving other infrastructure and AI platforms. It may also determine the strength of any appeal by Amazon or Microsoft.
The second signal is the compliance scope. The companies would receive six months to meet applicable obligations after designation.
Watch for specific commitments involving interoperability, export tools, marketplace access, software licensing, bundled services, and technical documentation. General promises of customer choice will reveal little.
The strongest evidence would include measurable migration results. Regulators could examine the time, engineering work, and retained functionality involved in moving representative workloads.
Cloud customers should also note which products remain outside each commitment. Narrow portability for basic storage will not address dependence on databases, identity services, or AI platforms.
The third signal is the competitive response. Google Cloud, Oracle, and European providers will decide whether the remedies create openings worth pursuing.
New connectors, migration services, compatible interfaces, and cross-cloud management products would strengthen the Commission’s case. They would show that access changes produced practical competition.
Limited adoption would weaken it. That result might mean remedies were too narrow, customer demand was overstated, or technical dependencies remained stronger than regulatory changes.
Amazon and Microsoft could also adjust contracts before formal deadlines. Such changes may reduce regulatory risk while preserving the main value of their integrated platforms.
For developers, the safest response is not an immediate migration. It is better documentation of dependencies, data formats, identity controls, and proprietary services.
Teams can test a small workload on another provider and measure what breaks. That exercise creates useful evidence for procurement discussions, regardless of the final legal outcome.
Enterprise buyers should revisit exit clauses and architecture assumptions during renewals. They should ask providers to identify the services that lack direct equivalents or tested export paths.
Knowledge workers will experience the consequences indirectly. Their AI assistants, collaboration tools, and internal search systems increasingly depend on cloud identity, storage, and model services.
The AWS and Azure DMA designation could eventually expand customer choice around those systems. It will not produce that result through a label alone.
The real test is whether European organizations gain credible alternatives without losing the security, reliability, and integration they depend upon. Watch the final decision, the six-month compliance plans, and actual cross-cloud adoption. Those signals will show whether EU scrutiny changes cloud behavior or mainly changes its paperwork.



