What does the Digital Markets Act require for AI agents handling cross-service data?
The DMA (Regulation EU 2022/1925) applies to designated gatekeepers — large platforms operating core platform services in the EU. Article 5 prohibits combining personal data across separate services without explicit consent, and Article 6 creates interoperability and FRAND-style data access obligations. When AI agents operate across multiple services — querying user data, behavioural signals, or business data from different platforms — each data combination event must be policy-governed. Gatekeepers must be able to demonstrate that their AI systems respect per-service data boundaries and do not silently cross-combine data that users or regulators have restricted. This requires enforcement at the data access layer, not just at model output.
How does AutoPIL help with Digital Markets Act compliance for AI agent deployments?
AutoPIL maps directly to two DMA obligations. For Article 5 cross-service data combination boundaries, AutoPIL policy TEC-DMA-A5-001 enforces which agent roles and registered agents may access data across service boundaries — denying combinations that violate gatekeeper obligations before any data enters the agent's context window. For Article 8 compliance assessments and audits, AutoPIL's tamper-evident audit chain provides a complete, chronologically ordered record of every policy decision, agent identity, and data source accessed. This chain cannot be retroactively altered, making it directly usable as audit evidence in DMA compliance assessments without additional reconstruction steps.
When does the Digital Markets Act apply to an organisation's AI systems?
The DMA applies to companies formally designated as gatekeepers by the European Commission under Article 3 — typically large platforms with annual EEA turnover above €7.5B, a market capitalisation above €75B, and more than 45 million monthly active end users in the EU. Designation is service-specific: a company may be a gatekeeper for its search or messaging service but not for others. Once designated, DMA obligations apply to the specific core platform service. AI agents operating within or on top of those services — for personalisation, recommendations, business analytics, or API access — fall within scope of Articles 5 and 6 obligations.
What are the penalties for non-compliance with the Digital Markets Act?
The European Commission can impose fines of up to 10% of a gatekeeper's total worldwide annual turnover for a first infringement of DMA obligations. For repeated infringements within eight years, the ceiling rises to 20% of global turnover. Periodic penalty payments of up to 5% of average daily worldwide turnover can be imposed for continued non-compliance. In cases of systematic infringement — defined as at least three violations within eight years — the Commission may impose structural or behavioural remedies, including requirements to divest business units. For AI agent deployments, failure to document data access decisions and maintain cross-service combination boundaries could directly expose a gatekeeper to these enforcement actions.
What is the Article 8 compliance audit requirement under the Digital Markets Act?
Article 8 requires gatekeepers to submit compliance reports to the European Commission demonstrating they are fulfilling their obligations under Articles 5, 6, and 7. The Commission can conduct its own audits of gatekeeper practices, including technical audits of how data flows between services. For AI agent environments, this means gatekeepers must maintain auditable records of when and how agents accessed data across service boundaries. A manually assembled audit trail is insufficient if records can be altered — regulators require evidence that logs are tamper-evident and reflect the actual runtime behaviour of agents, not reconstructed summaries.