RSS Amplifier

Fabric · Oct 6, 2025

Europe’s chance to lead on AI memory

0
Sign in to vote or save

Eeshita Pande · Fabric

  • We started Fabric to make context portable, and we have found incredible allies in the European Commission. DMA Article 6(9) has already shown that large platforms can implement portability in months. This post outlines our submission to the EU Commission’s DMA Review.

  • We propose expanding the list of Core Platform Services to include fast-growing AI assistants like ChatGPT and Gemini, which are already used by hundreds of millions globally within three years of launch. We expect the biggest dividends of consumer data portability to come from rapid innovation in AI-powered applications once developers can safely incorporate rich user context into their products.

  • Including notable European “segment gatekeepers” like Spotify and Zalando as emerging gatekeepers for overwhelmingly positive articles like Article 6(9) will improve the emerging ecosystem.

  • Introducing a joint trust framework, similar to Open Banking, will increase trust in the personal context ecosystem.

  • Feedback from our experience working with gatekeepers:

    • Google: excellent proactive conduct, we have proposed improvements in the consent experience and missing data scopes (for example, Gemini data).

    • Meta: good conduct, we have proposed improvements in data quality (for example, missing account-level information) and broader user experience.

    • Amazon, LinkedIn, TikTok, Booking: bad conduct with major improvements needed.

Core platform services (CPS) cover traditional categories like search, social networks, browsers, etc.

Notable gaps have emerged since the DMA’s drafting. For example, large AI consumer AI platforms (e.g. OpenAI’s ChatGPT and Google’s Gemini) function as search/assistant platforms to hundreds of millions of users. Neither is explicitly covered by “search engines” or “virtual assistants” today, despite providing rich user data and playing a gateway role. Consumers are increasingly relying on AI to decide which products to use and businesses to trust. Similar to SEO, Answer Engine Optimisation is an emerging industry with companies like Profound helping businesses get discovered on AI platforms.

Their adoption is best in class already: ChatGPT has 700 million weekly active users in under 3 years from launch. Similarly, Gemini has 450 million monthly active users, having launched substantially after ChatGPT.

Similarly, segment leaders are notably missing from the DMA: Spotify, Zalando, and Airbnb might be below currently defined DMA thresholds but are arguably gatekeepers in their segments.

We therefore suggest expanding the CPS list or thresholds to encompass these overlooked gatekeepers:

Google Gemini: Google Gemini functions as an assistant to 450 million users and is integrated with Google Search (AI Mode, AI Overviews), now Chrome, and other Google products. And it isn’t explicitly covered by “search engines” or “virtual assistants” yet.

Therefore, even though Gemini data is available via Takeout (Gemini Apps: MyActivity and images, AI Mode in Search, Gemini Gems and Scheduled Actions), it isn’t made available through the Data Portability API.

In principal, we support bringing all Google Takeout scopes under the scope of their Data Portability APIs, particularly those where the intersection with core platforms services is clear (e.g. the intersection of Gemini with Chrome, Search etc.)

OpenAI ChatGPT: OpenAI’s existing and constantly evolving product portfolio (ChatGPT, Operator Browser, AI hardware, etc.) is enabling it to create unique market dynamics like Google in a significantly shorter time period.

700 million users use ChatGPT weekly. Given the 3 year time horizon in which this shift has happened, it’s clear that OpenAI is collecting vast amounts of valuable user data and is a gatekeeper for both search and AI products. Meeting 6(9) obligations for users’ personal data from the usage of AI products e.g. prompts, full assistant conversations, generated media - images and videos, etc. would be a good starting point to introduce DMA obligations for OpenAI. Introducing gatekeeper obligations for OpenAI at this stage will avoid the market from reaching a state with a 1-2 entrenched players.

Amazon Rufus: According to the Amazon team at their DMA Compliance Workshop, “The functionality that Rufus provides is an integral part of the store and therefore we have ensured that Rufus is compliant with the DMA.”

However, according to Amazon’s Data Portability API documentation, Rufus scopes are not available through the Data Portability API therefore Rufus is not compliant with DMA 6(9).

Zalando: According to Zalando, in 2024, they had 51.8M LTM active customers with 4.8 average annual orders per active customer (this highlights the seasonal nature of their product). 3.5K brands work with Zalando’s marketing services serving 143M impressions to European users daily.

In the European fashion e-commerce digital market, Zalando is by far the largest player and a gatekeeper in its right. Their acquisitions such as Aboutyou and Highsnobiety reflect their growing presence in European fashion e-commerce.

Spotify: Spotify is Europe’s largest audio streaming service with 181 M EU MAUs and €15.6 B revenue in 2024. They gatekeep a uniquely valuable segment: “A large percentage of our Ad-Supported Users are between 18 and 34 years old. This is a highly sought-after demographic that has traditionally been difficult for advertisers to reach.”

From another gatekeeper’s public filing:

  • Spotify has a 56 percent share of Europe’s music streaming market, more than double their closest competitor’s

Even though Spotify’s Ad-Supported revenue is not at the scale of other gatekeepers, it is the dominant audio streaming platform gatekeeping a uniquely valuable segment. And growing fast.

Airbnb Airbnb has a vast user base: in all of EMEA, it had 201M nights and experiences booked in 2024. While the monthly active user metric for Airbnb might fall below 45M (since people typically use it for occasional travel), its annual unique users in the EU are enormous. Airbnb is a clear gatekeeper in the vacation rental segment, it commands such a large share that many short-term hosts now operate almost exclusively through Airbnb. Even if its monthly active user count is below 45M, it’s not far off when considering that tens of millions use it for vacations just not evenly every month.

We propose using the DMA’s emerging gatekeeper concept (Art. 3(8)): e.g. imposing Article 6(9) obligations more liberally on companies that hold substantial customer data.

Another recommendation is creating a broader framework (we have proposed improvements in the designation criteria below) so that important gatekeepers are not missed.

Improved criteria to include missed gatekeepers with important user segments

The DMA’s quantitative thresholds (∼7.5 €B turnover/€75B market cap and ≥45 M monthly users and ≥10K business users) has so far caught only the tech giants, particularly those in the US. This has the unintended consequence of missing many companies with important user segments in Europe. In addition, it has the unwelcome perception of the EU Commission unfairly targeting US companies which couldn’t be further from the truth. We view the DMA, particularly Article 6(9) as pro-innovation.

We recommend making the criteria more flexible so European gatekeepers like Spotify and Zalando are also included. The current thresholds miss gatekeepers which have a substantial market position in an important segment for e.g. Spotify in audio streaming, Zalando in ecommerce, and Airbnb in vacation rentals. We have laid out rationale to include each of these gatekeepers in our response to the first question.

This improvement in criteria can take the form of:

  • Lowering certain thresholds to cover important segment gatekeepers and European gatekeepers whose sizes are typically lower than the US counterparts (e.g. European listed companies trade at lower market caps than US listed companies, number of business users for important segment gatekeepers like Zalando (fashion ecommerce) and Spotify (audio streaming) is less important than the fact that they control a substantial % of an important market segment e.g. +56% of Europe’s streaming market in the case of Spotify)

  • Using OR based thresholds more liberally (e.g. ≥45 M end users OR 10K business users OR ≥€7.5BN revenue OR ≥€75BN market cap) to capture services that are widely used in practice and demonstrate gatekeeper dynamics for important digital markets segments like e-commerce, streaming, and intermediation

    • For e.g. Zalando has 51.8M LTM active customers, 3.5K businesses using Zalando Marketing Services to serve 143M daily impressions, and €10.5bn revenue. Using reasonable OR thresholds would classify Zalando as a gatekeeper for an important segment.

  • Using KPIs reported by gatekeepers or using broader definitions (e.g. the greater of monthly actives, total customers, LTM actives, experiences booked or whichever user volume KPI is used by the gatekeeper in investor reporting) is also a reasonable strategy.

    • This would mean not using ‘monthly active end users’ but rather self-reported user volume KPIs for gatekeepers like Zalando and Airbnb where their service by definition is not monthly.

Using the Emerging Gatekeeper categorisation

Where applicable for non-AI gatekeepers, it might be reasonable to also use the emerging gatekeeper categorisation, particularly when it might be procedurally easier to have a subset of relevant obligations apply to them. However, in this section, we primarily focus on AI companies given our response to previous sections and questions.

As it pertains to AI services, the EU Commission should name emerging gatekeepers and enforce proportional obligations, particularly for overwhelmingly positive clauses like 6(9) for consumer data portability.

“When a company does not yet enjoy an entrenched and durable position, but it is foreseeable that it will in the near future, a proportionate subset of obligations may apply, to ensure that the services in question remain contestable and to avoid the risk of unfair conditions and practices.”

We support consumer data portability as defined under Article 6(9) for such emerging gatekeepers and their core platform services, starting with products like ChatGPT and Gemini but including other strategic products like Anthropic’s Claude and Perplexity.

Our view is supported by the fact that major data holders recognise that user’s AI data meets similar data ownership and portability criteria as other platform data (e.g. search) by including them in user data export tools. As of the time of this submission, Google Gemini (via Takeout) and ChatGPT data export tool make user prompts, conversation history, user uploaded images, user generated images etc. available to users.

Given our business, we are responding with relation to article 6(9):

Legal certainty for intermediaries

The success of Article 6(9) is not automatic. Consumer data portability depends entirely on the emergence of a vibrant ecosystem of third-party services that can use the portable data to create tangible value for consumers. Fabric and companies like it are essential to this ecosystem, acting as the infrastructure layer that makes portability practical and scalable. Creating a successful data ecosystem will give rise to wide ranging businesses focusing on consumer use cases, intermediation, enrichment, etc. Therefore, it’s important to ensure protection of diverse business models by default. Gatekeepers retain immense power to undermine third parties through subtle changes to API terms of service or the imposition of restrictive conditions on data use.

Proposal: Introduce obligations for business model guarantees

The Commission should issue clear guidance, or propose targeted amendments, clarifying that gatekeepers cannot impose terms that unreasonably restrict the commercial use of data transferred under Article 6(9). Considering the diverse nature of digital markets data, there is a need for specialised third parties in the ecosystem (like with Open Banking) which enable consumer companies to use digital data. For such parties (including Fabric) to exist, build successful businesses, and attract venture capital investment, we need strong legal protections (particularly around wide ranging business models e.g. legal protection on data use with a degree of business model agnosticity). In this area, verbal assurances do not mitigate the platform risk to startups that legal amendments and published guidance can.

Uncertainty in verification requirements

Integrating with multiple data providers under DMA 6(9) with each provider having arbitrary approval criteria creates a non-transparent process which is creating significant challenges to successful consumer data portability. We acknowledge the requirement for comprehensive verification given the sensitivity of the data in question.

Proposal: Introduce an industry body to run a joint trust framework and obligations for gatekeepers to abide by it

Similar to the Open Banking Europe framework, there is a need for an industry/regulatory body to run a joint trust framework so intermediaries seeking to serve businesses by providing a data portability service (multi-provider access and enrichment) can reliably faciliate it while proving the safety of user data through licensing and inclusion in the joint trust framework.

This does not mean that companies/intermediaries bypass the individual gatekeeper registration and integration but rather that there is a transparent verification process through a joint trust framework. The DTI’s Trust Registry is an industry backed initiative and an excellent step in that direction but going further in the direction of Open Banking would satisfy gatekeepers about the legitimacy of intermediaries while increasing consumer and business trust in the ecosystem.

We elaborate on how certain gatekeepers are not meeting their DMA 6(9) obligations in the next response.

Regular feedback (e.g. Commission workshops) has led to improvements in gatekeepers meeting obligations but for some, portability is a compliance box checking exercise rather than a practical exercise of data subject rights.

Providing SLAs and uptime guarantees would be desirable from all gatekeepers. Currently, when APIs go down, our service becomes unusable. To create a thriving data portability ecosystem, these guarantees are required.

Google - excellent conduct, improvements in consent and data scope needed In our experience, Google has been the best gatekeeper to work with, consistently taking our feedback on board and improving the data portability API.

  • Verification, communication, and support: Google has been easy to reach and communicate with, our verification and re-verification was extremely quick, and we have received consistent support from the team.

  • Reduction in latency: The API’s latency went down from hours to minutes which has been extremely helpful for us.

  • Excellent data quality: Generally, Google has the best data quality providing clean, structured data with timestamps and most of the information related to the data.

The following are key improvement areas required to fully support the user’s rights to data portability. Google has expressed a willingness to work on these.

  • Improving the consent and broader user experience: There are various improvements needed on Google’s data portability consent and user experience. We discussed these with the Google team and they are open to working on the user experience. Reducing the number of consent screens particularly multiple warning screens, improving the choice architecture to allow the developer to set specific scopes which are pre-selected in the consent, and reducing the number of emails received upon consent (currently 2 per scope) are some of the key friction points.

  • Increasing data scopes to include all user generated data (i.e. Takeout data): key data scopes such as Google Gemini are currently available to the user via Google Takeout but not via Google’s Data Portability API yet. Given the intricate links between Search, Chrome, and Gemini and the data generated by them, we expect Gemini data to be made available via the Data Portability API and will be requesting Google to provide us with this data.

Meta - good conduct, improvements in consent and data quality needed In our experience, Meta has been one of the best gatekeepers to work with, consistently taking our feedback on board and improving the data portability API.

  • Unifying DYI and TYI into a single flow

  • Fixing emergent bugs

  • Meta AI data is proactively available through the Data Portability API

However, there are substantial improvement areas required, especially on data quality which are not being worked on:

  • Key data on many interactions scopes is missing. Examples included in last response.

    • Generally, interactions are at an account level rather than at a post level. Getting more information at the individual interaction level: urls, data: text, mentions, tags etc., metadata would make the data usable.

  • There are various improvements needed on Meta’s data portability consent and user experience. We discussed these with the team and they are open to working on the user experience. Examples included in last response.

Amazon - bad conduct, some intervention required

  • Amazon’s communication has been terrible, taking weeks to respond to emails. They didn’t turn up on organised calls for verification. This makes getting verified extremely challenging.

  • Missing data: Amazon Rufus. Explained in last response.

LinkedIn - bad conduct, some intervention required

  • Data needs substantial works. Snapshot data (initial transfer) provides detailed information but changelog data (follow-on transfers) are missing key information which makes it unusable.

TikTok - bad conduct, major intervention required

  • Simple verification, good consent, but bad communication. Rarely respond to emails and the main way to communicate is via a feedback form in their footnote.

  • Data needs substantial work. Most of it is unusable due to missing information (e.g. comments without the resource being commented on, urls sent with no data, no information regarding user viewing time etc.)

Booking - bad conduct, major intervention required

  • Easily the worst consent experience with the user needing to manually send a URL to the developer in order to initiate a transfer. Completely out of line with all other gatekeepers and reasonable practices around consent management. It’s a case study in UX dark patterns.

  • Key information is missing e.g. no interactions made available after the initial search. Key marketplace information relates to inventory displayed post a search and subsequent clicks, page visits which then lead to a checkout action. This is not available. Ads and sponsored content related to searches and interactions is also missing.

The Commission’s fines, penalties, and other steps (e.g. compliance workshops) are a good starting point for DMA enforcement.

However, as it concerns 6(9), which so far is one of the DMA success stories particularly from the point of view of gatekeepers like Google and Meta who provide good portability tools and are improving them over time, we haven’t seen non-compliance actions against those that aren’t complying with 6(9). This is unfair to the gatekeepers who are prioritising compliance.

Compliance as a checkbox exercise vs practical compliance to support portability are very different and most gatekeepers fall in the former category.

Google and Meta are collaborative, developer friendly companies. They are part of the DTI and therefore a collaborative approach works well with them.

However, for gatekeepers who not collaborative, a different approach is required. We have proposed some enforcement measures for 6(9) in the relevant section.

We propose that the Commission outline major 6(9) breaches by gatekeepers and remedies to be accomplished within a reasonable time frame.

The main ones from our perspective at this stage would be:

  • Booking’s consent experience is the embodiment of UX dark patterns and when combined with the extremely poor (unusable) data quality makes customer data portability and use impossible

  • Amazon’s insufficient communication is restricting customer data portability. Core platform data (e.g. Rufus) is also missing

  • TikTok’s unusable data and limited feedback mechanism

  • LinkedIn’s poor data quality

In addition, we would propose that the Commission provide formal guidance on the following undefined aspects of 6(9) so that gatekeepers have the obligation to build towards it:

  • Consent architecture: there is no consistency in the user experience as it relates to number of screens, content and copy, and even the number of notifications received by the user. Preventing dark patters in user experience is critical in ensuring consumer data portability. Gatekeepers should provide secure, transparent, and clear authorisation mechanisms. When a user is asked for data access by a third party, the data holder’s interface (e.g., an authentication screen on a social media platform) should mainly focus on authentication and authorisation rather than including consent mechanisms and to some extent scope selection, which should take place on the third party application’s side. There should be no misleading warnings or “dark patterns” that confuse users including unnecessarily hampering the authorisation experience. Some early DMA implementations are overly complex (for instance, Booking requiring users to copy and paste URLs manually into a different experience, Google displaying multiple warning screens in the experience).

  • Data quality: Ensuring the accuracy and completeness of data is another responsibility which is not being observed by many platforms under the DMA, given the differences in the data collected by each platform and the enforcement nuances. This can be formalised as making all available data (and metadata) about a unique user’s online events accessible programmatically so that data provided is usable by third parties. We are not proposing a common schema as that would be unreasonable, just that all user data collected by CPS be made available. Guidance can be supplemented with concrete examples of events which are missing accompanying data. We have included some examples in the last response.

  • Providing SLAs and uptime guarantees would be desirable: currently, when APIs go down (sometimes for a day), our service becomes unusable. To create a thriving data portability ecosystem, these guarantees are required.

Our personal experience building with multiple gatekeeper data portability tools (and publicly available Digital Markets Act workshop recordings and compliance reports) shows that gatekeepers such as Google and Meta understand and align on the need for consumer data portability. And that involved stakeholders view broader data portability as an extremely positive development. This is also reflected in their involvement in the Data Transfer Project (DTP) and subsequently, the Data Transfer Initiative (DTI).

However, for other gatekeepers like Booking, Amazon, TikTok, and LinkedIn, DMA 6(9) compliance seems to be a checkbox exercise without real consideration given to user experience, developer experience, and the need for consumer data portability.

We hope the Commission will consider our feedback and proposed improvements seriously as they outline next steps for gatekeepers DMA compliance and particularly 6(9).

Fabric is a Smart Data Platform which exists because of the DMA. Like the European Commission, we understand the importance of competition in digital markets, specifically consumer data portability and its expected positive impact on innovation and competition. As a result of the DMA, Fabric now works with the largest online platforms, (particularly Google and Meta) to facilitate consumer data portability.

In some experiments, this has led to European end users being able to port their own data to other platforms resulting in payouts of tens of thousands of euros in a matter of weeks. Or users being able to interact with their ‘Digital Memories’ in an interactive Whatsapp experience.

However, we expect the biggest dividends of consumer data portability to come from rapid innovation especially in areas like AI-powered applications (e.g. personalised digital assistants) once developers can safely incorporate rich user data (with consent) into their products. The Open Banking experience has shown how data-sharing led to the development of hundreds of new financial apps (budgeting tools, alternative lenders, payment initiators, etc.) that were not possible before. The pace of innovation will likely accelerate in digital markets, because these markets move even faster and touch every aspect of life (social, shopping, entertainment, productivity).

The availability of cross-platform data means consumer services can be smarter, for example, a travel app that automatically recommends a trip based on your Google search history, Youtube videos, and Instagram photos. Many such ideas have been blocked by lack of data access and even now that the data is “available” there are still many roadblocks that prevent these use cases from being developed. Fabric’s goal as a Digital Markets Smart Data platform is to enable thousands of new, context-rich applications for consumers.

Similar to how fintech boomed post Open Banking, we expect to see increased venture capital interest in companies building services on top of Digital Markets data. Our personal experience raising millions in weeks from top Silicon Valley investors post DMA demonstrates the value of a regulatory “why now” moment. As data portability is starting in Europe, an effective context portability infrastructure will attract a lot of investors to Europe looking for companies that build innovative AI use cases.

We are excited to continue working with the Commission and gatekeepers to faciliate cross-platform consumer data portability and use.

DMA 6(9) has proven that large platforms can technically implement portability in a relatively short timeframe (months, not years). The DMA’s success in creating API access is a lesson for regulators worldwide. For example, the UK also passed the Data Use and Access Act in 2025 and is working on a Smart Data Scheme which is inspired partly by the success of the DMA and partly by the success of Open Banking.

The UK CMA’s investigation into Google’s Strategic Market Status proposed data portability as a Category 1 measure, providing a robust basis for continued access to Google’s DMA Data Portability APIs in the UK.

Active enforcement practiced by the EU is building to meaningful compliance with the DMA. As noted previously, each of the gatekeepers did roll out data portability tools to meet DMA obligations, but early assessments found most tools lacking in usability or completeness. Regular feedback from industry participants and the European Commission has led to steady improvements which still have a long way to go.

Selected: I offer new products and services based on AI models

Fabric is a Smart Data platform for context portability. Using DMA-enabled data portability APIs, we let consumers securely share their consented data across search, social, and, prospectively, AI assistants, with the apps they choose.

Our AI work underpins this. We run AI-powered data pipelines and enrichment using leading foundation models (Gemini, GPT, Claude, Llama) to parse, normalise, and semantically enrich raw activity streams, including searches, page visits, posts, conversations, and related interactions, so they are usable in downstream products.

Other (Smart Data / AI infrastructure)

Fabric operates at the intersection of digital markets, data portability, and AI infrastructure. We integrate multiple portability APIs, including those provided to comply with DMA 6(9), and provide secure, user-controlled transfer, enrichment, and developer access across platforms.

We function as a portable context layer, translating heterogeneous data across search, social, shopping, and prospectively AI assistant interactions into structured context that downstream AI products can use.

  • Do you use any of those products or services offered by the DMA gatekeepers?

    • We use gatekeepers’ and non-gatekeepers’ AI extensively. On the gatekeeper side, we rely on Google Vertex AI, including the Gemini model family and related services, alongside broader Google products.

  • Do you use any of those products or services offered by other companies than the DMA gatekeepers?

    • Beyond gatekeepers, we make extensive use of OpenAI models and products, Anthropic Claude, Meta Llama, and developer-facing AI tools such as Perplexity and Cursor.

  • How do you choose which AI-based product or service to use?

    • We select models on the basis of capability, latency, cost, enterprise-grade tooling and support, and performance on our enrichment tasks.

  • What is the main way you use AI-based products and services?

    • Our primary use of AI is to build Fabric itself, powering our data pipelines for retrieval and enrichment, and to improve engineering productivity through coding assistance.

    • We also use AI extensively for research and general search. ChatGPT, Gemini, Perplexity, and Claude assistants heavily augment our workflows, both personally and professionally.

Yes. We rely on Data Portability APIs pursuant to Article 6(9).

In practice, this means using gatekeepers’ APIs to receive end user data, such as search queries, page visits, YouTube history, Instagram stories and interactions, and adjacent scopes where available, so we can deliver Fabric’s product.

Yes, extensively. Beyond Google’s stack, we use OpenAI, Anthropic, and Meta, as well as multiple developer AI tools such as Perplexity and Cursor.

From our firsthand experience building Fabric, one of the central obstacles to commercialising AI is data and context access. AI products are only as useful as the personal context they can lawfully use. Today, much of the user’s AI data, such as prompts, chats, and generated media, remains siloed and is not exposed programmatically. This drives vendor lock-in that is even stronger in AI than in prior Big Tech categories.

Conversational memory and user profiles compound over time, increasing switching costs and undermining competition. While compute and cloud costs matter, they are secondary to the gating effect of context unavailability with respect to commercialising AI based prouducts and services.

The remedy is clear. Designate AI gatekeepers and enforce DMA 6(9) to require continuous, real-time portability for AI data.

From our perspective as power users of AI products, personalisation accumulates inside single AI products and there is no easy way to take one’s AI memory elsewhere, which makes multi-homing difficult and strengthens lock-in.

Users also cannot readily combine, own, and port their search, social, and AI data into new services to obtain the most useful and truly personal experiences.

Most AI powered products (except ChatGPT, Gemini, Perplexity, Claude) don’t know anything about me and therefore remain boring chatbots causing all consumer AI usage to eventually be concentrated in a few companies as they expand to various verticals.

The impact is two sided. On the positive side, prouducts like Vertex AI and Gemini accelerate our product development and will enable even richer use cases when AI data is made available via DP APIs. On the negative side, wherever AI data is not portable, for example prompts and chats absent from DP APIs, we face product gaps and increased platform risk.

The next generation of consumer experiences are being built using AI. These experiences have the potential to be hyper-personalised to each individual consumer. However, if AI data continues to stay siloed, these incredible consumer experiences will lack the “rich user context” that they need to be truly lifechanging for consumers. Or a single/handful of platform will verticalise and serve all major AI use cases with no room for competition.

Major data holders recognise that user’s AI data meets similar data ownership and portability criteria as other platform data (e.g. search) by including them in user data export tools. As of the time of this submission, Google Gemini (through Takeout) and ChatGPT data export tool make user prompts, conversation history, user uploaded images, user generated images etc. available manually to users.

Consumer behaviour is shifting massively with almost a billion consumers worldwide using AI products like ChatGPT and Gemini over a time period of 3 years.

At the same time, browsers like Chrome, Comet, and OpenAI’s browser are (or will be) vertically integrated with their search and AI products. Large AI assistants already function as user gateways and combined with browsers, their position will be even more entrenched.

To ensure contestability, the Commission should designate AI gatekeepers such as ChatGPT and Gemini, with proportionate treatment for fast-growing services like Claude and Perplexity, expand CPS definitions or thresholds to include AI assistants and AI browsers, and require continuous, real-time access to AI prompts, conversations, and generated media. This should be coupled with consent UX standards, including neutral tone, fewer steps, developer preselected scopes, consolidated notifications, and reasonable authentication durations, a joint trust framework for verification, minimum data-quality requirements so event level data is actually usable, and baseline SLRs so portability behaves like dependable infrastructure rather than a box-ticking exercise.

Yes. For portability, Article 6(9) is decisive. It should explicitly cover AI products, including assistants and AI native browsers, so that users and their authorised third parties can access AI context on a continuous, real-time basis.

We urge the Commission to include AI gatekeepers and their core services in scope, for example ChatGPT, Gemini, Amazon Rufus, and emerging gatekeepers such as Claude and Perplexity, and to apply proportionate 6(9) obligations to emerging gatekeepers to prevent early entrenchment while markets are still forming. Making AI memory portable will increase competition and innovation across the European ecosystem.

No posts

Read the original on onfabric.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.