By John Gruber
WorkOS: How to give an agent a task instead of a token.
Wesley Hilliard, reporting for AppleInsider last week:
A report from Irish Independent detailed the European Commission’s response to Apple’s new business terms for the EU. They share that they welcome the changes and will monitor Apple’s implementation of the terms.
Here is the EC’s full statement:
“The Commission welcomes Apple’s changes to their business terms, which follow a close dialogue between the Commission and Apple after the Commission issued a non-compliance decision related to Apple’s steering terms as well as preliminary findings related to alternative app distribution, both in April 2025,” the spokesperson said.
“Following today’s announcement, the Commission will monitor Apple’s effective implementation of the new terms. Under the DMA, users in the EU have a right to full and effective choice of alternative app distribution channels.”
The point of the DMA was to open up competition and choice for developers, which the EC seems to believe Apple’s terms have accomplished.
I don’t think that was ever the point of the DMA. It’s what a lot of developers who themselves wanted more competition and choice — and freedom — on iOS presumed to be the point of the DMA. The European Commission paid lip service to these ideals, which encouraged people to think these ideals were the point of the DMA. But what I’ve consistently argued is that the only actual point of the DMA is for the European Commission to impose unnecessary bureaucracy and inconvenience on major markets where it previously had no footprint. They had no noble goal. They just wanted to erect a bureaucratic structure that clearly shows “The European Commission was here and did something.” Impose copious fines on Apple, Google, Microsoft, and Meta; inconvenience those companies and their users in the EU; all to show that something has been done. (And to cash the checks from the fines they eventually collect.)
That’s why the text of the DMA itself is so hard to read and understand. There is no clear intent of “opening up competition and choice” hidden in the murky, impenetrable prose of the DMA. The murky impenetrableness of the law is a reflection of its actual intent: murky impenetrable bureaucracy.1
Here’s a commenter on Hacker News (via Michael Tsai’s roundup) who can’t believe it:
This is bonkers, I can’t believe the EU Commission agreed to it. The main issue that the DMA was about still remains: Apple retains ultimate control over app developers’ dealings with users.
The status quo that the EU should have pushed for, and which Article 6(7) of the DMA requires, is one where a developer can distribute iOS apps to users without ever entering into any contractual relationship with Apple. The OS APIs that most apps use are already paid-for by the user when they buy the device. Apple wants to double-dip and charge developers for the value that the users already have by virtue of owning their iDevices with all the necessary iOS paraphernalia in them.
If you believed that the point of the DMA was to open up competition, choice, and freedom for developers, yeah, I bet it does seem bonkers that the European Commission has signed off on compliance where Apple charges 15 percent commissions on links to the web from apps distributed on the App Store, and that Apple will collect a 5 percent Core Technology Commission even for apps distributed on third-party app marketplaces, using third-party payment processing. But if you believe, as I do, that the point of the DMA is to impose obvious regulatory burdens and bureaucracy upon Apple (and Google, and Microsoft) — and upon the EU citizens who use those companies’ “gatekeeping” platforms — then it is completely unsurprising that the European Commission “welcomed” these changes. The Commission has gotten everything it wanted from Apple:
I’m sure some of you think I’m all wet in my argument that the point of the DMA was merely to impose ongoing bureaucratic complexity. But my view jibes with the reality of how it’s worked out. Compare and contrast with the Mobile Software Competition Act in Japan. Apple complied with the clearly stated requirements of the MSCA with no drama, Japanese users aren’t missing out on features like iPhone Mirroring, and the only delay for Siri AI in Japan is language support. Japanese iOS users get all the “good parts” of Apple’s regulatory compliance that EU users do, with none of the rather severe hindrances.
This also explains the European Commission’s obvious satisfaction with the GDPR’s “cookie” regulations for the web. Defenders of this aspect of the GDPR always retort with the same argument, correctly pointing out that the GDPR does not require annoying cookie-permission dickovers and dickbars. The GDPR presents websites with a choice: don’t track users with cookies, or, get their permission before you do. And it just turned out that the overwhelming majority of the commercial web has chosen the latter option. Like, the intention might have been for most websites to face this choice and decide, “Oh, jeez, we don’t want to badger our visitors with endless annoying dickovers, so we better scrap all our tracking cookies.” But of course that’s not what these websites did. The result we now face — especially within the EU, where the web experience is positively lousy with cookie-permission prompts — was entirely predictable given the options presented by the GDPR. Defenders of the GDPR defend it on the grounds that it presents a good intention — reducing the practice of unnecessary tracking on the web. And those defenders pin the blame for the infestation of cookie-permission banners on the websites that choose to present them. Critics of the GDPR (and you know which side I’m on) simply point to the actual practical effects of the law. Before the GDPR, there were no cookie-permission dickovers; after, they’re everywhere, especially in the EU, but they’re also quite prevalent outside the EU. And, the practice of unnecessary tracking on the web is completely unchanged. If anything it’s probably more widespread now than before the GDPR. The best way to handle unnecessary tracking is to encourage users to use better web browsers with effective content-blocking extensions installed.
The GDPR is a wide-ranging set of regulations and some of them are truly excellent, giving EU citizens rights to control their own data. But the “cookie permission” nonsense has, in practice, done nothing for the web except make it worse. It hasn’t done a thing to improve personal privacy, and has resulted in a veritable deluge of annoying cookie-permission prompts. The main result of those ubiquitous prompts has been to encourage more people to spend their time using native mobile apps in lieu of the web. But the European Commission looks at this situation and pats itself on the back. If they saw the deluge of cookie-permission prompts as a problem, an unintended consequence worth fixing, they would fix it. The GDPR went into effect 10 years ago. By their inaction, they obviously think it’s working just fine. I think they look at the situation and realize, with satisfaction, that every time any website presents a cookie-permission dickover, that dickover effectively has a “Brought to you by the European Commission” badge on it. They were here, they did something, and everyone around the world sees the fruits of the GDPR cookie regulations every time they open their web browser. Job well done. ↩︎