On 16 July 2026, the European Commission adopted two specification decisions against Alphabet under the Digital Markets Act. The first, DMA.100220, requires Alphabet to open eleven features of Android and its AI stack to third-party AI assistants under Article 6(7). The second, DMA.100209, requires Google to share search ranking, query, click and view data with competing search services under Article 6(11).
A specification decision, under Article 8(2) of the DMA, finds no infringement and imposes no fine. It writes out what compliance means for one gatekeeper, in operative detail. That detail is where the legal questions sit, and several of the central choices deserve closer scrutiny than the coverage has given them. This piece takes the key provisions one by one. Two threads run through them. Some provisions extend the law beyond anything the Union courts have held. Others take positions that the Commission itself rejected or abandoned in its own recent practice, without acknowledging the change.
The equal-effectiveness standard. Article 6(7) entitles third parties to free and effective interoperability with the hardware and software features accessed or controlled via Alphabet’s operating system and available to Alphabet’s own services. The interoperability decision converts that into a different test. Every solution must be as effective as the one available to Alphabet’s own services. Paragraph 141 of the operative measures extends this parity requirement to every dimension of the interaction. The list covers the end user journey, ease of use, device and software setup, data transmission speed, and energy consumption. Paragraph 143 adds a companion rule. Access to a feature cannot be conditioned on an app holding a default role, including the default assistant role. The move from an effectiveness floor to a parity benchmark indexed to the gatekeeper’s own services is the load-bearing interpretive choice of the whole decision, and it is a choice, not a restatement. The nearest judicial support is the General Court’s Microsoft judgment (T‑201/04), which required interoperability on an equal footing and refused, in the same passage, to read that requirement as meaning that competitors’ systems must function in every respect like the dominant firm’s. The dimension list, particularly energy consumption, pushes toward the parity of outcome that Microsoft stopped short of. Since the scope of a statutory obligation is a question of law, the Court will review this de novo, with no deference. Alphabet’s first ground of challenge writes itself.
AI chatbots as beneficiaries of search data. The search-data decision treats AI chatbots with search functionality as eligible recipients under Article 6(11), correcting what the Commission describes as a defect in Google’s narrower reading. The published measures tie this to existing law. Alphabet may not exclude undertakings that provide AI chatbots with search functionalities when those chatbots meet the definition of an online search engine in Article 2(5) of Regulation 2019/1150. The exclusion is barred even where the search engine forms part of a broader service. The anchor is real, and it relocates the question rather than answering it. Whether a chatbot’s retrieval function satisfies a definition drafted in 2019, before such products existed, is a genuinely open question of statutory scope. It will decide who the DMA’s data-access right is for, in the middle of the AI transition.
The integrity ceiling. Paragraph 115 of the measures states that an integrity measure cannot be considered strictly necessary and proportionate if it seeks a higher integrity standard than the one Alphabet applies to its own services or hardware. As drafted, this is a conclusive presumption. The case law treats security and integrity justifications as matters for case-by-case assessment, and Microsoft held that a requirement of reasonable and non-discriminatory conditions does not oblige a dominant firm to impose the same conditions on every undertaking seeking access. The sharper problem is the Commission’s own recent position. Market-test respondents in the Microsoft Teams commitments (AT.40721 and AT.40873), concluded in September 2025, asked for precisely this benchmark. Their complaint was that the throttling safeguards ran between third parties without binding Microsoft’s own service. The Commission declined to impose it, accepting instead a softer benchmark referenced to normal usage consistent with how Teams itself interacts with Microsoft’s products. Ten months later, the same institution states the strict self-comparison rule as the plain application of a statutory phrase. Nothing in the decision acknowledges the change.
The certification and monitoring architecture. Alphabet must create a program certifying AI assistants, accept certificates from Trusted Certification Authorities, submit to audits, and notify the Commission at least four weeks before deploying any integrity measure. Two pieces of history matter here. Union courts have seen this movie before. The Commission once designed oversight machinery of the same kind, a monitoring trustee for Microsoft. The General Court annulled it in the same Microsoft judgment, T-201/04. The Commission had handed a private party powers that were not the Commission’s to give. And nothing in the law let it send Microsoft the bill for its own surveillance. The Commission’s own remedies practice has respected that boundary ever since. The closest prior notification duty, in the Amazon Marketplace commitments (AT.40462), states expressly that notice to the trustee does not constitute an approval requirement. The four-week gate in the Alphabet decision builds the approval-shaped mechanism that the Amazon text was drafted to disclaim. The DMA changes the statutory landscape, and the Commission will argue that Article 8(2) covers all of this. Perhaps it does. But the certification authorities appear nowhere in the DMA’s text, and the institution constructing them has both an annulment and its own contrary drafting practice behind it.
The anonymization standard. The Commission’s public account describes a three-step anonymization process before any search data leaves Google. The final step dissolves each user into a group of at least 1,000 users who share the same location, device type and query language. This parameter is the entire ballgame. Set too strict, the data is worthless, which is the Commission’s own criticism of Google’s first proposal, recorded as removing between 90 and 100 percent of unique queries. Set too loose, the sharing violates the GDPR. The published measures state the governing standard. Re-identification risk must be reduced to an insignificant level. No instrument is cited for that formulation. And the specific thresholds are redacted from the non-confidential version as business secrets. The Commission’s public account presented the method as closely following a draft guidance document that neither it nor the European Data Protection Board has adopted. And the Commission’s one prior operative treatment of anonymization ran in the opposite direction. The Amazon Marketplace commitments swept anonymized data into the scope of the restrictions. There, anonymization was a circumvention risk, not a safeguard. There may be good reasons to treat search-query anonymization differently. The decision does not give them.
The price of the data. Article 6(11) requires access on fair, reasonable and non-discriminatory terms. The decision specifies this as incremental cost plus a reasonable return, capped at Alphabet’s weighted average cost of capital. Whatever the economics of that formula, it sits against a methodological position the Commission held for two decades. In Port of Helsingborg (COMP/A.36.568/D3, 2004, paragraph 97), the Commission wrote that a price is not abusive merely because it is not cost-based. In the Visa MIF decision (AT.39398, 2010), it stated that it no longer examines cost-based justifications for interchange fees. Cost-plus now returns as the construction of an administered price, without a word about the departure. A second departure sits beside it. The decision imposes quantitative eligibility thresholds, two years of operation or fifty million euros of capital investment, and fifty thousand monthly EU users. In Insurance Ireland (AT.40511, 2022), the Commission’s objection targeted eligibility criteria that excluded certain operators from a data system, quoting the Court of Justice’s requirement that such systems be accessible to all operators active in the relevant sphere. The institution that quoted that standard in 2022 does not explain why numerical gates satisfy it in 2026.
The Commission has an answer, and it is the obvious one. This is the DMA, not competition law. Different legal basis, different objectives, and Article 1(6) says the regulation applies without prejudice to Articles 101 and 102 TFEU, so nothing in the antitrust practice binds a specification decision. The separation is less clean than that answer assumes, as Godefroy de Boiscuillé and I argue in Questioning the Digital Markets Act’s Legality, since the Commission administers the DMA as a standing regime of unilateral conduct control operating alongside Article 102. Grant the answer anyway, because nothing here depends on defeating it. The aim is not to supply grounds for annulling these two decisions. It is to mark where they depart from what the Commission has done before in comparable competition cases.
In the end, specification is the Commission’s power under the DMA, and using it boldly is legitimate. What is harder to defend is the silence. Strip the two decisions down to their most consequential provisions and a pattern appears. Where the courts have spoken, the Commission goes further. Where the Commission has spoken, it goes the other way. Both moves may be perfectly defensible under a new instrument with different objectives, but both are presented as business as usual, in operative measures that cite not one decision and not one judgment. Novelty travels here under diplomatic plates. For practitioners, that gap is a map of the appeal. For the Commission, it is worth fixing before the next specification. If the General Court annuls one of these decisions, the ruling will not be read as the correction of a single document. It will be read as a verdict on the specification mechanism itself, at the moment the DMA most needs that mechanism to be credible.
For paid subscribers, the audit follows. Every antecedent and every contrary authority is reproduced verbatim, with recital and paragraph numbers, so that you can read the operative language without opening a single decision. It closes with the five documented departures from the Commission’s prior practice, dated, the counterarguments the Commission will run, and an assessment of how each provision fares under the standard of review that will apply to it.



