AICOA is DMA in Translation


Graham Dufault
American Innovation and Choice Online Act (AICOA) proponents insist that AICOA is not the same as the European Union’s (EU’s) Digital Markets Act (DMA). They’ve also argued that AICOA won’t result in degraded products and services. Both claims are inaccurate: AICOA’s operative provisions are nearly identical to DMA’s, and compliance with both requires service degradation. Here’s a quick refresher on what AICOA borrows from DMA and how they both achieve the overarching purpose of degrading popular services to benefit specific competitors.
“Interoperability” (open access to hardware and software features)
Here’s DMA’s provision, Article 6(7):
The gatekeeper shall allow providers of services and providers of hardware, free of charge, effective interoperability with, and access for the purposes of interoperability to, the same hardware and software features accessed or controlled via the operating system or virtual assistant listed in the designation decision pursuant to Article 3(9) as are available to services or hardware provided by the gatekeeper.
Here’s the corresponding AICOA provision:
It shall be unlawful for a person operating a systemically important platform in or affecting commerce to restrict, impede, or unreasonably delay the capacity of a business user to access or interoperate with the same platform, operating system, or hardware or software features that are available to the products, services, or lines of business of the systemically important platform operator that compete or would compete with the products or services offered by business users on the systemically important platform.
The differences are in form rather than function. AICOA prohibits restrictions on access to the same operating system, platform, or hardware or software features as are available to the platform operator’s own services. And DMA mandates provision of access to those same hardware and software features. Can you see how the effect would be the same?
Labeling the provision “interoperability” is a sales pitch that glosses over what it would actually require. Interoperability between device types and operating systems is already in place; this provision demands access to several layers deeper. It is better understood as an antitrust “duty to deal,” under which a platform operator must accept a given third party’s terms by default. The only permissible grounds to refuse a third party’s terms appear in the affirmative defenses, which the operator bears the burden of proving. Mozilla, an AICOA proponent, may insist that its browser engine offers better privacy protections than WebKit’s, and that delivering them requires open access to your device. What it cannot answer is why every other third party should be afforded the same access as a byproduct of forcing Apple to accept the terms it wants from iOS.
That access carries predictable costs. Attackers’ favorite methods — apps disguised as popular ones, and promises of free, pirated versions of apps or content that otherwise cost money — seldom succeed on modern smart devices, where Android and iOS do not grant third parties open access by default. Now that the European Commission is beginning to implement its own “interoperability” provision, successful malware attacks are already on the rise. Experts expect more, mainly in the form of banking trojans like Anatsa and SharkBot, and spyware like SpyFone and Mandrake.
Small business developers lose in this scenario because the threats require consumers to handle more of the curation function, making them rationally less likely to download an app made by a company without a big brand or major name recognition. As we explained in 2022, AICOA’s requirement to maintain open access to device and operating system features would not only give Mozilla what it wants, it would also force operating systems and devices to accommodate attackers such as SpyFone, 1Byte, SharkBot, and Anatsa. These bad actors enjoy only limited success currently because access to all third parties is not the default. AICOA’s “interoperability” would roll out the red carpet for them.
Next, let’s look at the self-preferencing provision.
Here’s DMA’s:
The gatekeeper shall not treat more favourably, in ranking and related indexing and crawling, services and products offered by the gatekeeper itself than similar services or products of a third party.
And AICOA’s:
It shall be unlawful for a person operating a systemically important platform in or affecting commerce to preference the products, services, or lines of business of the systemically important platform over those of another business user in a manner that would materially harm competition.
To be fair, there are only so many ways to prohibit self-preferencing, and two measures that both take it up will likely go about it in similar terms. What is striking is that AICOA borrowed the concept and then reached past it. Unlike the DMA, AICOA is not limited to “ranking and related indexing,” so it presumably sweeps in any distribution term governing how an app reaches a consumer’s device or how a seller connects to a customer. That breadth would keep legal teams busy and nervous, and leave engineers and business units constrained in how they build a better smartphone or marketplace experience.
For anyone wondering how AICOA would affect the popular services tech platforms provide, the text of the bill says it all: it prohibits a marketplace operator from offering complementary services as a bundle. Fulfillment by Amazon (FBA) is a clear example. Amazon features Prime offers above others and protects the consumer experience behind that placement by requiring Prime sellers to commit to two-day shipping. Because FBA is often the most cost-effective way to meet that commitment in a given region, sellers frequently choose it over alternatives, including self-fulfillment. That combination is precisely what AICOA targets, since offering FBA alongside Prime placement “preference[s] the products, services, or lines of business . . . over those of another business user” — namely, the third-party fulfillment services competing for the same sellers.
AICOA proponents’ arguments confirm the intent. They contend that funneling business users toward a marketplace operator’s complementary services, even when those services are better and cheaper than the alternatives, can only distort competition. But the two-day shipping commitment is a benefit that did not exist before Amazon built the system to support it. That is not a distortion of competition. It is what competition policy and antitrust law are meant to let the market produce.
AICOA’s proponents are right about one thing: the two laws are not identical documents. They are, however, identical projects. Both compel a platform operator to grant third parties the same access it gives itself, both prohibit the operator from favoring its own complementary services, and both place the burden on the operator to justify any refusal. The drafting differs; the obligations do not. Where AICOA departs from the DMA, it departs by going further — its self-preferencing provision is not confined to ranking and indexing, which leaves a far wider set of ordinary product and distribution decisions exposed to liability.
That is also why the second claim fails. Degradation is not a risk that careful implementation might avoid; it is the mechanism. A device that must accept any third party’s terms by default is a less secure device, and a marketplace that cannot pair a shipping commitment with a fulfillment service is a less useful marketplace. Consumers absorb those costs directly. Small business developers absorb them twice — once as users of the same platforms, and again as the firms least able to overcome a consumer’s rational new hesitance to install software from a name they don’t recognize. Congress does not need to run this experiment to learn the result. The European Commission is running it now, and the early returns are showing up as banking trojans on European phones.
Share this post

Resources
More action
Resources to understand more on the topic
Keep reading
Others on this topic
Get in touch
Contact ACT
Whether you're a technology company looking to grow, or a policymaker seeking insight, we're here to help.
Get in touch to learn more about our work, explore membership, or connect with our team.
United States
United Kingdom
European Union