App Store antitrust is the regulatory framework that determines how dominant mobile platforms must open app distribution channels to third-party marketplaces and direct installs.
For most of the smartphone era, two gatekeepers controlled how software reached billions of devices: Apple's App Store on iOS and Google Play on Android. Regulators in the European Union concluded that this control had crossed into anticompetitive territory, and the Digital Markets Act (Regulation (EU) 2022/1925, EUR-Lex summary) established legally binding obligations for platforms designated as gatekeepers. The DMA's obligations applied from March 2024, triggering compliance changes across both platforms, along with non-compliance investigations and open questions about whether the mandates achieve their stated goals.
What App Store Antitrust Means

App Store antitrust enforcement centers on three concepts that practitioners and developers frequently conflate. The definition list below separates them.
- Sideloading
- Installing an application directly from a file or external source, bypassing the platform's official marketplace. On Android, this has been the default-enabled behavior for years via APK (Android Package Kit) files. On iOS, it was prohibited outside of enterprise certificates until DMA compliance mandates created a limited EU pathway.
- Alternative app marketplace (AAM)
- A third-party storefront that distributes applications independently of the platform operator's own store. An AAM differs from raw sideloading: it is still a curated distribution layer, just operated by a party other than the platform. The DMA requires designated gatekeepers to allow AAMs; the operator sets approval criteria that the AAM operator must meet.
- Gatekeeper
- Under the Digital Markets Act, a platform designated as a gatekeeper must meet size thresholds and control criteria. Apple and Alphabet (Google's parent) were designated as gatekeepers under the DMA, making them subject to app distribution mandate obligations including AAM access, interoperability requirements, and restrictions on self-preferencing.
The DMA is ex ante regulation, not a court-made antitrust remedy. Unlike US antitrust litigation, which requires proving harm after the fact, the DMA imposes structural obligations in advance on any platform that qualifies as a gatekeeper. Background on algorithmic accountability in platform systems illustrates why regulators moved from reactive enforcement toward preventive structural rules across multiple digital sectors.
How iOS Responded to Sideloading Pressure
iOS compliance with the DMA produced the most visible structural change Apple had made to its App Store model since the platform launched. With iOS 17.4, released in March 2024, Apple enabled alternative app marketplace access for EU users, documented at Apple Developer: DMA and apps in the EU. The accompanying business model introduced the Core Technology Fee (CTF), a per-install charge applied to developers above a usage threshold, which Apple describes as compensation for platform infrastructure. The CTF applies regardless of whether the developer distributes through the App Store or through an AAM, a point that drew substantial criticism from developers who argued it negated the economic value of alternative distribution.
Apple's DMA compliance rolled out in four sequential steps.
- Marketplace operator approval: Apple defined criteria that AAM operators must satisfy, including financial requirements, security standards, and liability commitments. Third-party marketplace operators apply through a formal review process.
- Developer agreement update: iOS developers distributing through any AAM must accept Apple's updated developer agreement, which includes the CTF structure and the new business terms governing alternative distribution.
- Core Technology Fee model: The CTF applies per install beyond a threshold, making cost projections complex for high-volume free apps. Developers choosing to remain exclusively in the App Store use the existing commission structure without the CTF.
- EU-region scope only: The alternative marketplace pathway applies only to devices with EU App Store accounts. Developers outside the EU cannot access third-party iOS distribution under these terms, limiting the geographic reach of the mandate.
The interaction between platform liability frameworks and marketplace operator obligations matters here: under Apple's terms, AAM operators take on responsibility for app review within their storefronts, which shifts the liability surface compared to the traditional App Store model where Apple bears that role centrally.
How Android Handles Alternative Distribution
Android's position relative to DMA sideloading requirements differs structurally from iOS because Google's mobile OS has permitted APK sideloading by default for years. A user can enable installs from unknown sources in device settings without any regulatory mandate requiring it. This means the DMA did not require Google to unlock a previously closed installation pathway the way it did for Apple.
The DMA obligations that apply to Android under Alphabet's gatekeeper designation focus on different dimensions of platform control, documented in Google's stated position on Android openness.
- Default-setting restrictions: The DMA restricts gatekeepers from imposing their own services as mandatory defaults. For Android, this affects how Google Search, Chrome, and Google Play are pre-configured on devices shipped in the EU.
- Self-preferencing in Play rankings: Google Play's search and recommendation algorithms cannot systematically favor Google's own apps over competing alternatives. The DMA's prohibition on self-preferencing applies to ranking signals and placement within the store.
- Interoperability obligations: Gatekeepers must provide interoperability access to third-party services for messaging, operating systems, and other designated services. Android's obligations here overlap with broader ecosystem access requirements.
- Third-party app store access: While APK sideloading was already permitted, Google faced scrutiny over friction in how its systems handle competing app stores, including security warnings that appear when users install apps outside Google Play.
For context on how platform regulation ripples into cloud and device distribution strategies, the article on how platform regulation shapes cloud and device distribution covers the adjacent infrastructure constraints.
iOS vs Android: Side-by-Side Comparison
The table below compares iOS and Android across the key dimensions of App Store antitrust compliance. Sideloading status, gatekeeper obligation scope, and developer fee models diverge significantly between the two platforms.
| Dimension | iOS (Apple) | Android (Google) |
|---|---|---|
| DMA gatekeeper designation | Yes (Apple designated) | Yes (Alphabet designated) |
| Pre-DMA sideloading status | Blocked by default; enterprise certificates only | Permitted via APK installs; user opt-in required |
| Post-DMA marketplace pathway | Alternative app marketplaces permitted in EU only, via Apple approval process | Third-party app stores already supported; DMA adds friction-reduction obligations |
| Developer fee model | App Store commission plus Core Technology Fee for AAM installs above threshold | Google Play commission; separate terms apply for alternative app distribution |
| Geographic applicability | EU accounts only for alternative marketplace access | DMA compliance obligations apply in EU; core sideloading support is global |
| Primary enforcement risk | CTF model under non-compliance scrutiny; Apple-as-sole-reviewer friction | Self-preferencing in Play rankings; default-setting restrictions |
Developer and User Impact
App Store antitrust mandates shifted app distribution choices measurably once the DMA compliance pathways opened, but the impact differs between developers and end users.
Developer impact
- Distribution choices expanded on paper: Developers can now list iOS apps in alternative app marketplaces in EU countries. In practice, the number of approved AAMs remains limited, and each requires its own integration and compliance work.
- Fee structures became more complex: Platform commission rates under the traditional App Store model now compete with the CTF model for alternative distribution. For developers with high install volumes and low average revenue per user, the CTF can exceed the cost of the legacy commission structure, a concern documented by developer groups and cited in regulatory filings.
- Certification burden persists: Even when distributing through an AAM, iOS apps must still pass Apple's notarization review. This keeps Apple in the technical certification chain, which critics argue limits the competitive impact of alternative marketplaces.
User impact
- App availability in the EU: EU users with eligible accounts can access apps through approved AAMs on iOS, including apps that Apple might not carry in its own store. Android users in the EU already had this pathway; the regulatory change reinforces obligations around reducing friction in that access.
- Security tradeoffs: Expanding app distribution beyond vetted storefronts introduces malware exposure risk. Both Apple and Google maintain that their security review processes reduce this risk; independent researchers have documented malicious apps reaching users through unofficial channels on both platforms.
- Unvetted sources: Sideloading directly from unvetted sources carries higher risk than using an AAM with its own review process. Regulators acknowledged this tradeoff during DMA drafting, which is part of why the law targets marketplace access rather than mandating fully unrestricted sideloading.
The contrast between EU ex ante mandates and US reactive enforcement frameworks is covered in depth in the article on how EU ex ante regulation compares to US frameworks.
Enforcement: How Regulators Are Applying Pressure
App Store antitrust enforcement under the Digital Markets Act created binding authority, not just aspirational rules. The European Commission has moved from designation to active scrutiny of whether gatekeeper compliance satisfies the law's requirements.
- Gatekeeper designation: Apple and Alphabet were formally designated as gatekeepers under the DMA, triggering the full set of app distribution, interoperability, and self-preferencing obligations. Designation is the entry point; obligations attach automatically from that point.
- Non-compliance investigations opened: The European Commission opened non-compliance investigations against Apple and Alphabet under the Digital Markets Act, as announced by the Commission's digital strategy unit. The investigations signal that regulators view the initial compliance submissions as insufficient rather than closing the matter.
- Penalty ceiling: The DMA grants the Commission authority to impose fines of up to 10% of a gatekeeper's annual global turnover for violations, with the ceiling rising to 20% for repeated infringements (Regulation (EU) 2022/1925 summary). For companies with revenue in the hundreds of billions, this creates significant financial exposure.
The DMA is still early in its enforcement lifecycle. Whether the non-compliance investigations produce orders that meaningfully change app distribution economics, or whether Apple's CTF model survives regulatory scrutiny, remains unresolved. The framework's design assumes iterative enforcement, not a single compliance checkpoint, which means the pressure on gatekeeper platforms is structural rather than episodic. For context on how EU tech regulation has historically affected companies operating outside the EU, the article on how EU tech regulation affects non-EU companies provides relevant precedent from the GDPR era.
References
- Digital Markets Act: EUR-Lex official summary (Regulation (EU) 2022/1925)
- European Commission: Non-compliance investigations against Alphabet, Apple, and Meta under the DMA
- Apple Developer: DMA and apps in the EU
- Google Blog: Reaffirming choice and openness on Android and Google Play
Further reading
Frequently Asked Questions
Is the DMA achieving its goals for app store competition?
Enforcement is still early: the European Commission opened non-compliance investigations against Apple and Google in 2024, signaling that regulators view initial compliance as insufficient. The DMA gives the Commission authority to impose fines of up to 10% of annual global turnover for violations, so the regulatory pressure on gatekeepers continues to escalate as the framework matures.
Can developers distribute iOS apps outside the App Store in the EU?
Yes, as of iOS 17.4 released in March 2024, Apple allows alternative app marketplaces in EU countries to comply with the Digital Markets Act. Developers must agree to Apple platform terms and a new business model that includes a Core Technology Fee per install beyond a threshold; the exact terms are documented on the Apple Developer DMA and apps in the EU pages and have drawn criticism from some developers as economically prohibitive.
How does Android sideloading differ from what the DMA requires?
Android has permitted direct APK installation by default for years, so Google did not need to restructure its core installation pathway for the DMA. The DMA obligations for Android focus more on interoperability, default-setting restrictions, and self-preferencing in Google Play rankings, rather than unlocking a previously closed sideloading path.









