Mandatory Counterfactual Modeling Disclosure Rule

Mandatory API Access as a Merger Remedy Enforcement Tool

Introduction

Mandatory API access can be understood as a merger remedy requiring a merged digital platform, technology provider, operating system, cloud provider, marketplace, or other infrastructure operator to provide competitors, customers, or qualifying third parties with standardised, non-discriminatory, technically usable access to application programming interfaces (APIs).

The remedy is particularly important in digital markets because a merger may create or strengthen control over an essential interface through which rivals need to interact with users, data, operating systems, cloud infrastructure, payment systems, identity systems, or complementary applications.

Instead of merely preventing the merger, a competition authority may permit the transaction subject to an obligation that the merged firm:

  • maintain specified APIs;
  • provide access on fair and reasonable terms;
  • preserve interoperability;
  • refrain from discriminatory throttling;
  • disclose technical specifications;
  • provide equivalent functionality to rivals;
  • maintain service quality;
  • avoid degrading competitors' API access;
  • permit reasonable authentication and security arrangements; and
  • submit to monitoring and enforcement.

The central competition-law question is therefore:

When can compulsory API access transform a potentially anticompetitive merger into a transaction capable of producing sustainable competitive conditions?

1. Meaning of Mandatory API Access

An API is a technical interface that allows one software system to communicate with another.

In merger-control terms, mandatory API access may require the merged undertaking to expose or maintain interfaces that allow competitors or complementary businesses to interact with:

  • operating-system functionality;
  • cloud services;
  • payment infrastructure;
  • search functionality;
  • advertising infrastructure;
  • marketplace services;
  • identity systems;
  • interoperability protocols;
  • communication services;
  • data portability systems;
  • smart-device ecosystems;
  • AI or machine-learning services.

For example, if a merger places a dominant platform in control of an API required by competing applications, the authority could require continued access to that API on specified terms.

2. Why API Access Can Become a Merger Remedy

Digital mergers frequently create competitive problems that are not adequately addressed by traditional divestiture.

A merged company may possess:

  1. Network effects
  2. Large user bases
  3. Data advantages
  4. Operating-system control
  5. Technical infrastructure
  6. Interoperability advantages
  7. Switching-cost advantages
  8. Developer ecosystems
  9. Cloud or computing infrastructure
  10. Control over technical standards

The merged undertaking may then have the ability to discriminate against rivals through technical rather than contractual exclusion.

For example:

Competitor A technically remains independent but its application suddenly receives slower API responses, reduced functionality, restricted data fields, or delayed access to new API versions.

Traditional non-discrimination clauses may not detect these practices effectively.

A properly designed API remedy therefore seeks to preserve technical contestability.

3. API Access as a Structural-Behavioral Hybrid Remedy

Mandatory API access occupies an interesting position between structural and behavioural remedies.

Structural component

The authority preserves an independent competitive pathway by ensuring that rivals retain access to an important technological interface.

Behavioural component

The merged firm must continuously comply with:

  • access obligations;
  • quality standards;
  • interoperability requirements;
  • non-discrimination rules;
  • technical specifications;
  • monitoring obligations.

Consequently, API access can be described as a:

technology-enabled behavioural remedy designed to preserve structural contestability.

4. Competition Problems Addressed by Mandatory API Access

A. Foreclosure

A merged company may deny or degrade access to an API required by competitors.

Mandatory access prevents the merged firm from converting technological control into exclusionary power.

B. Raising Rivals' Costs

Even where access technically remains available, the merged firm may impose:

  • excessive authentication requirements;
  • unreasonable fees;
  • restrictive rate limits;
  • delayed approvals;
  • unnecessary technical certification;
  • inferior service levels.

An effective remedy must therefore regulate quality as well as availability.

C. Interoperability Reduction

A merger may allow the combined firm to make its products increasingly interoperable internally while reducing interoperability with competing systems.

Mandatory API access can preserve interoperability.

D. Network-Effect Entrenchment

API access may prevent a dominant platform from using network effects to make market entry practically impossible.

The remedy can allow rival applications to connect to the incumbent's ecosystem without having to recreate the entire ecosystem.

E. Data-Based Exclusion

APIs can determine who can access:

  • user-authorised data;
  • transaction information;
  • performance information;
  • interoperability data;
  • functional capabilities.

An API remedy can therefore preserve data-driven competition while respecting privacy and security constraints.

5. Legal Test for Imposing Mandatory API Access

A competition authority should normally examine several questions.

1. Is the API competitively significant?

The authority must establish that the interface is sufficiently important to competition.

2. Does the merged entity control the interface?

The remedy becomes more compelling where the merged firm possesses substantial technical and commercial control.

3. Are rivals dependent upon it?

Dependence may be demonstrated through:

  • technical necessity;
  • switching costs;
  • network effects;
  • lack of substitutes;
  • ecosystem dependency.

4. Can the merged entity discriminate?

The authority should assess whether the merged undertaking has incentives and ability to:

  • deny access;
  • degrade access;
  • delay access;
  • alter functionality;
  • discriminate among API users.

5. Is mandatory access proportionate?

The remedy should address the identified competitive harm without unnecessarily converting the authority into a permanent technology regulator.

6. Mandatory API Access and Essential-Facilities Doctrine

API remedies have conceptual similarities with the essential-facilities doctrine, although the two should not be treated as identical.

The traditional essential-facilities inquiry generally concerns whether control over an indispensable facility can justify compulsory access.

An API may be functionally critical without being literally an "essential facility."

This distinction matters because merger remedies can be imposed prospectively to prevent competitive harm, whereas an abuse-of-dominance case ordinarily asks whether existing conduct violates competition law.

Therefore:

Merger control can sometimes justify an API-access remedy before the legal threshold for an independent refusal-to-deal violation has been conclusively established.

7. Case Law

1. United States v. Microsoft Corp. (2001)

The Microsoft litigation is one of the most important precedents for understanding technological interoperability and access remedies.

Microsoft's control over the Windows operating-system environment gave it substantial power over software developers and competing technologies.

The litigation demonstrated that control over technical interfaces can become a mechanism for preserving monopoly power.

Relevance to API remedies

The case illustrates several principles:

  • technical interfaces can have competitive significance;
  • interoperability can influence market entry;
  • control over an operating system can affect adjacent markets;
  • technical restrictions may function as exclusionary conduct.

Merger-remedy significance

A future merger involving an operating system and an adjacent digital service could potentially require preservation of interoperability through API access.

8. European Commission — Microsoft (2004)

The European Commission's Microsoft decision provides an especially important conceptual foundation for interoperability remedies.

The Commission required Microsoft to provide interoperability information to competing work-group server operating systems.

The underlying concern was that Microsoft possessed information necessary for competitors to achieve effective interoperability with Windows.

Relevance

This is closely analogous to mandatory API access because the remedy was designed to prevent control over technical interoperability information from becoming a competitive bottleneck.

Principle

Control over technical interoperability can confer competitive power that competition law may legitimately constrain.

9. European Commission — Google Android (2018)

The Google Android decision concerned Google's contractual arrangements surrounding Android, search, browsers, and application distribution.

The Commission examined how restrictions affecting access to the Android ecosystem could reinforce Google's position in related markets.

Relevance to API remedies

The case illustrates the importance of:

  • ecosystem access;
  • default arrangements;
  • application distribution;
  • interoperability;
  • technical dependence;
  • leveraging between connected digital markets.

A merger involving an operating-system platform and an important application or API provider could create similar concerns.

Remedy implication

Mandatory API access could preserve the ability of rival services to compete within the ecosystem.

10. European Commission — Google Search (Shopping) (2017)

Although this was an abuse-of-dominance case rather than a merger case, it is important for understanding digital-platform leveraging.

The Commission found that Google had favoured its comparison-shopping service in general search results.

API-remedy relevance

The case demonstrates that control over a platform's central technological architecture can affect competitive opportunities in adjacent markets.

An API remedy can therefore be designed to prevent a merged platform from using technical control to favour its own downstream products.

11. United States v. AT&T Inc. / Time Warner

The AT&T–Time Warner litigation is significant for vertical merger analysis.

The dispute concerned the ability of a vertically integrated company to use control over important content to disadvantage distributors.

Although the case did not establish a conventional API-access remedy, it provides an important framework for understanding vertical foreclosure and access discrimination.

Relevance to API remedies

The same economic logic can arise digitally:

Upstream infrastructure → API → downstream competitors

If the merged firm controls the upstream interface, it may have incentives to discriminate against downstream rivals.

Mandatory API access can therefore operate as an anti-foreclosure mechanism.

12. United States v. Google — Search and Digital Advertising Litigation

The modern Google litigation provides important context for analysing technological bottlenecks, defaults, distribution channels and platform control.

Although these cases are not themselves classic API-access merger precedents, they demonstrate why competition authorities increasingly examine the architecture through which digital platforms control access to markets.

Relevance

An API can function as a technological gatekeeper where it determines:

  • who can access functionality;
  • what data can be accessed;
  • how quickly systems can interact;
  • which competitors can integrate;
  • what technical capabilities competitors receive.

This makes API governance relevant to both merger review and monopolization analysis.

13. European Commission — Microsoft/LinkedIn (2016)

The Microsoft/LinkedIn merger was cleared subject to commitments addressing interoperability and access concerns.

The transaction was particularly significant because it combined Microsoft's software ecosystem with LinkedIn's professional-networking data and services.

The Commission considered whether the transaction could harm competition in areas including customer relationship management and professional social-networking services.

Relevance

The case demonstrates how merger remedies can address concerns arising from:

  • interoperability;
  • access to ecosystems;
  • data;
  • software integration;
  • potential foreclosure.

It therefore provides a useful precedent for thinking about API access as a merger-control instrument.

14. Microsoft/Activision Blizzard

The Microsoft/Activision Blizzard transaction is highly relevant to modern digital merger-remedy theory.

Competition authorities examined the possibility that Microsoft could use control over Activision's content to disadvantage competing gaming platforms and cloud-gaming providers.

Remedies involved commitments concerning access to gaming content and cloud-streaming services.

API significance

Although not simply an API-access case, it illustrates the broader principle:

When a merger combines control over an important technological ecosystem with strategically important complementary content or functionality, access commitments may preserve downstream competition.

This is structurally analogous to mandatory API access.

15. Sabam v. Scarlet Extended

The European Court of Justice examined obligations imposed on intermediaries concerning technological filtering and intellectual-property enforcement.

Although not a merger case, the decision is useful because it demonstrates judicial concern with technologically intensive obligations imposed on network intermediaries.

Relevance to API remedies

API mandates must account for:

  • technical feasibility;
  • proportionality;
  • security;
  • privacy;
  • fundamental rights;
  • implementation costs.

A competition authority cannot simply say "provide access"; it must specify an administrable obligation.

16. Key Legal Principles Emerging from the Cases

The cases collectively suggest several important principles.

Principle 1 — Technical control can constitute competitive leverage

Competition law is increasingly concerned with technical architecture, not merely contractual terms.

Principle 2 — Interoperability can be competitively significant

Where interoperability determines whether rivals can effectively compete, preserving interoperability can be a legitimate competition remedy.

Principle 3 — Access must be effective

A formal right of access is insufficient if the merged company can undermine it through:

  • latency;
  • throttling;
  • functionality differences;
  • discriminatory updates;
  • technical incompatibility.

Principle 4 — API remedies must be measurable

The remedy should specify objective metrics.

For example:

API availability ≥ 99.9%

Latency ≤ specified benchmark

Equal release timing

Equivalent functionality

Defined response periods

This transforms an abstract access commitment into an enforceable competition obligation.

17. Designing an Effective Mandatory API Remedy

A sophisticated remedy should contain at least eight components.

1. Scope of API

Identify precisely which APIs are covered.

2. Eligible users

Specify which competitors or third parties can obtain access.

3. Technical documentation

The merged firm must provide adequate documentation.

4. Non-discrimination

The merged company should not provide materially superior functionality to its own services.

5. Service-level requirements

The authority should establish minimum standards for:

  • uptime;
  • latency;
  • reliability;
  • capacity.

6. Change-management obligations

The merged company should provide advance notice of material API changes.

7. Monitoring

An independent monitoring trustee or technical auditor may be required.

8. Enforcement

The remedy should contain:

  • complaint procedures;
  • investigation mechanisms;
  • periodic reporting;
  • penalties for non-compliance;
  • escalation procedures.

18. API Parity

One of the most important concepts is API parity.

Suppose the merged company provides:

API Version 5 to its own application

but provides:

API Version 4 to competitors.

Formal API access technically exists, but competitive parity has disappeared.

Therefore, the remedy should address:

Functional parity

Competitors receive substantially equivalent functionality.

Timing parity

Competitors receive important updates without discriminatory delays.

Performance parity

Competitors receive comparable speed and reliability.

Information parity

Competitors receive necessary technical documentation.

19. The Problem of "Degradation by Design"

A sophisticated platform may comply formally while undermining competition technologically.

Examples include:

  • reducing API rate limits;
  • introducing artificial latency;
  • restricting data fields;
  • changing authentication requirements;
  • breaking compatibility;
  • delaying certification;
  • frequently changing specifications.

This is sometimes more difficult to detect than an outright refusal.

Consequently, API remedies require continuous technical monitoring.

20. API Access and Data Protection

Mandatory API access cannot override privacy law.

A remedy should distinguish between:

User-authorised data

Potentially accessible subject to appropriate consent and legal safeguards.

Personal data

Subject to applicable data-protection requirements.

Proprietary algorithms

Not necessarily required to be disclosed merely because API access is mandated.

Aggregated or anonymised information

Potentially easier to make available.

Thus:

Competition law may mandate interoperability without necessarily mandating disclosure of the merged firm's source code or proprietary algorithms.

21. API Access and Cybersecurity

A mandatory API can create security risks.

The remedy should therefore allow:

  • authentication;
  • rate limiting;
  • security certification;
  • abuse prevention;
  • encryption;
  • monitoring;
  • emergency suspension for genuine security threats.

However, cybersecurity cannot become a pretext for arbitrary exclusion.

A company claiming security concerns should ordinarily be required to demonstrate that the restriction is:

necessary + proportionate + technically justified.

22. API Access and AI Mergers

Mandatory API access is especially relevant to AI mergers.

Consider a merger involving:

Foundation model + cloud provider + AI application platform.

The merged entity could potentially control:

  • model APIs;
  • inference access;
  • compute;
  • training infrastructure;
  • developer tools;
  • distribution.

A remedy could require continued access to model APIs for competing developers.

Similarly, a cloud/AI merger could require interoperability between competing AI models and cloud services.

23. API Access and Cloud Markets

Cloud markets create particularly strong interoperability concerns.

A merger can increase switching costs by controlling:

  • APIs;
  • proprietary data formats;
  • identity systems;
  • orchestration tools;
  • storage interfaces;
  • machine-learning infrastructure.

Mandatory API access can therefore facilitate multi-cloud competition.

The ultimate objective is not necessarily to make every system identical but to prevent technical incompatibility from becoming an artificial barrier to switching.

24. API Access as an Alternative to Divestiture

Divestiture remains attractive where the competitive problem can be solved by separating assets.

But digital businesses can be difficult to divide.

For example, separating:

  • code;
  • engineers;
  • data;
  • infrastructure;
  • users;
  • algorithms

may destroy important efficiencies.

API access can therefore be considered where:

The competition problem is concentrated at an interface rather than in ownership of the entire business.

This makes API access potentially less disruptive than divestiture.

25. Limitations of Mandatory API Access

The remedy also has serious weaknesses.

A. Regulatory complexity

The authority may effectively become a technical regulator.

B. Innovation concerns

Mandatory access may reduce incentives to develop new functionality.

C. Security risks

Opening interfaces can create vulnerabilities.

D. Circumvention

The merged company may comply formally while undermining access technologically.

E. Monitoring costs

Continuous technical auditing can be expensive.

F. Information asymmetry

The regulator may lack the technical knowledge possessed by the merged company.

G. Remedy duration

Digital markets evolve rapidly, making fixed commitments obsolete.

26. When API Access Is Most Appropriate

Mandatory API access is particularly suitable where:

  1. the API is commercially important;
  2. competitors depend upon it;
  3. substitutes are limited;
  4. the merged firm controls the interface;
  5. foreclosure incentives are substantial;
  6. interoperability is technically feasible;
  7. the remedy can be objectively measured;
  8. monitoring is realistically possible.

It is less suitable where:

  • the API is constantly changing;
  • security risks are exceptionally high;
  • access would require disclosure of core intellectual property;
  • competitors can readily build alternatives;
  • the authority cannot meaningfully monitor compliance.

27. Enforcement Framework

A robust enforcement architecture can be represented as:

Merger

↓

Identification of API bottleneck

↓

Competitive foreclosure analysis

↓

Necessity and proportionality assessment

↓

Mandatory API-access commitment

↓

Technical specifications

↓

Non-discrimination + parity

↓

Independent monitoring

↓

Complaint mechanism

↓

Periodic compliance review

↓

Penalty / corrective action

↓

Remedy modification or termination

This transforms API access from a general promise into an enforceable competition instrument.

28. Overall Legal Assessment

Mandatory API access represents a shift from traditional merger remedies toward technological contestability remedies.

Its significance lies in recognising that modern market power can arise not merely from ownership of physical assets, but from control over the interfaces through which economic actors communicate.

The strongest legal rationale is therefore not simply:

"Competitors must be allowed to use the API."

It is:

The merged undertaking must not be permitted to convert control over a strategically important technical interface into durable exclusionary power.

The remedy should consequently protect effective interoperability, not merely formal access.

Conclusion

Mandatory API access can become a powerful merger-remedy enforcement tool in digital markets where control over a technical interface creates the ability to foreclose competitors.

The principal lessons from Microsoft, Android, Microsoft/LinkedIn, AT&T/Time Warner, Microsoft/Activision Blizzard and related interoperability and platform cases are that competition authorities increasingly need to consider the technological architecture through which market power is exercised.

An effective API remedy should therefore include:

  • compulsory access;
  • technical interoperability;
  • non-discrimination;
  • API parity;
  • service-quality obligations;
  • transparent specifications;
  • change-management procedures;
  • privacy and cybersecurity safeguards;
  • independent technical monitoring;
  • complaint mechanisms; and
  • meaningful sanctions.

The ultimate objective is not to force technological equality, but to prevent a merger from transforming control over a critical digital interface into an unavoidable competitive bottleneck.

LEAVE A COMMENT