The European Commission is preparing to designate Amazon Web Services and Microsoft Azure as gatekeepers under the Digital Markets Act, Bloomberg reported on 2 October 2026, according to The Next Web, which did not independently confirm the report. What makes the case unusual is the basis. Both services fall short of the DMA's quantitative thresholds, according to the Commission's own June 2026 statement of its preliminary view. If a final decision follows, the EU would be regulating its two largest cloud providers on a qualitative judgement about how hard they are to leave.
This explainer separates what is established from what is still a draft, sets out the qualitative test the Commission is using, walks through what the three reported obligation types could mean for cloud buyers, and gives the strongest argument against. It relies on The Next Web's relay of Bloomberg, on the Society for Computers and Law's account of the Commission's June notice, and on Freevacy's summary of the same notice. We did not read the Bloomberg article itself.
What is established, and what is still a draft
The established part is the June notice. Freevacy reported on 26 June 2026, and the Society for Computers and Law on 30 June, that the Commission told Amazon and Microsoft of its preliminary view that AWS and Azure should be designated as gatekeepers. Two market investigations into designating the services were opened on 18 November 2025, and a third, opened the same day, asks whether the DMA's existing obligations adequately address cloud practices that limit contestability or are unfair. The Dutch Authority for Consumers and Markets supports all three through a joint team. The Commission said the preliminary findings do not prejudge the outcome.
The reported part is the timetable. Citing people familiar with the matter, Bloomberg said the Commission plans to name both services in November 2026. The Next Web says the decision is still a draft, its timing could slip and the Commission has not publicly set a date. The DMA allows about a year for such investigations, which would run to roughly November 2026 from the opening date; that is our reading of the reported timeline, not a stated deadline. The final text, including how each obligation applies to cloud, has not been published.
How a cloud provider becomes a gatekeeper without the numbers
The ordinary DMA route is quantitative: turnover or market-value thresholds, plus user counts in the EU. Per the Society for Computers and Law, the Commission can designate a provider that misses them where the provider has a significant impact on the internal market, serves as an important gateway for business users to reach end users, and holds an entrenched and durable position. Factors it may weigh include size, user numbers, network and scale effects, lock-in and switching costs, and vertical integration.
On the Commission's account, as relayed by those sources, AWS and Azure meet that test for several reasons. They have significant turnover, and their investment and operational capacity has outpaced competitors. They have held leading positions for years. They have large, entrenched user bases that appear to benefit from lock-in, high switching costs and ecosystem advantages. And AI tools and partnerships have become decisive in cloud procurement, with the two providers able to keep much of the growing AI-driven demand inside their own ecosystems. Freevacy adds that both companies are already designated gatekeepers for other services.
The AI point is the forward-looking one. A customer's data and applications already sit with a provider, so adopting AI services there is the path of least resistance, and the new workloads inherit the old lock-in. That is a claim about direction of travel, and the sources provide no figures on how much AI demand AWS and Azure retain, so we cannot say how strong the effect is. The Next Web describes AWS and Azure as the EU's largest and second-largest cloud services. Size is therefore part of the picture, even though the formal thresholds are not met.
What changes for customers
Once designated, a gatekeeper has six months to comply, per both The Next Web and the Society for Computers and Law. By our calculation, a November 2026 designation would imply compliance around May 2027. The Next Web lists three obligation types: no self-preferencing, interoperability with rival services, and data portability to make switching easier. None of the reporting specifies how these would apply to cloud, so the descriptions below are inferences about direction, not summaries of any rule.
- Self-preferencing: a ban could limit a provider favouring its own managed databases, AI models or analytics tools over third-party alternatives in ranking, bundling or pricing. How favouring would be measured in a cloud marketplace is not specified.
- Interoperability: this could require a provider's services to work with competing clouds' services, which matters most for multi-cloud deployments that today depend on custom integration. Which interfaces, and who pays for building them, is not stated.
- Data portability: this could make leaving easier by requiring standardised export. It overlaps with the EU Data Act, which AWS cites, and how far the DMA would go beyond it is the open question.
Penalties are heavy on paper. Fines can reach 10% of global sales, or 20% for repeat breaches, per The Next Web. The third investigation matters here as well. The reporting does not say what would follow if the Commission concludes that existing obligations do not fit cloud practices, or when that investigation would conclude, so buyers should watch it separately from the designation.
Why this is not a size story
Most coverage of gatekeeper rules concentrates on big numbers. This case turns on the opposite: the Commission is asserting that structure can create gatekeeper power without the thresholds being crossed. In cloud, structure means egress and migration costs, proprietary managed services that applications are written against, committed-spend discounts that reward concentration, and certifications and skills tied to one provider. The sources we read do not quantify any of these, so the lock-in thesis rests on the way the market is organised and not on measured harm.
That is also what makes the designation more contestable. A numerical threshold is simple to verify. A finding of an entrenched and durable position based on switching costs invites argument over how the costs are measured and whether customers actually face them. Whether a court would defer to the Commission's qualitative assessment is not something the reporting can answer, and we make no prediction.
The case against
AWS has argued, per The Next Web's paraphrase of its June position, that the EU already regulates cloud through the Data Act and that additional DMA rules could discourage investment in Europe. When the investigations opened, Microsoft said Europe's cloud sector is innovative and highly competitive, again per The Next Web's paraphrase.
There are two parts to that argument and they should be judged separately. The first, that the Data Act already addresses switching, is a claim about overlap. The test is whether the DMA adds obligations, such as limits on self-preferencing and interoperability with rivals, that the Data Act does not. The second, that regulation deters investment, is an empirical claim about future behaviour. The reporting offers no evidence for or against it. Nor do the sources give figures on customer harm, such as price increases or failed migrations. The Commission's own stated rationale, as relayed, relies on market position and lock-in effects and not on documented price harm.
What the evidence does not establish
- Whether the decision will happen in November. It is a draft reported by one outlet from anonymous sources.
- What the obligations will require in practice. They have not been published for cloud services.
- Whether customers have been harmed in measurable ways. The reporting describes switching costs but quantifies none.
- Whether a designation would withstand appeal, since it relies on a qualitative route that has less precedent than the numerical thresholds.
For buyers, the practical question is timing. If designation arrives in November, compliance deadlines fall in mid-2027, so changes to egress, bundling and AI-service terms would most plausibly appear in contract terms after that. Procurement teams signing multi-year commitments now are doing so before the rules take shape, which is a reason to preserve exit and portability terms in current contracts and to keep a record of what each workload depends on. None of this is legal advice, and the final decision may look different from the draft described.

