

It’s not easy to find a firm of European origin on a chart of the world’s largest corporations (measured by market capitalization). European technology companies are far scarcer on the ground than they should be given the size of Europe’s economy. A major report commissioned by Brussels into the EU’s competitive shortfalls highlighted excessive and misdirected regulation as one cause of its failure to keep up, particularly in the tech sector, and it was right to do so.
Above all, perhaps, the domination of EU regulatory thinking by the precautionary principle has led to heavy-handed regulation under which tradeoffs and opportunity costs merit far too little consideration. In 2023, the EU, which prides itself on its status as a “regulatory superpower” celebrated the passing of its AI Act as “a launchpad for EU startups and researchers to lead the global race for trustworthy AI,” yet another example proving the truth of the jibe that where others innovate, the EU regulates.
As the EU has relatively few tech companies of its own to regulate, its attention has often been focused on the dominant U.S. companies — Apple, Google, Microsoft, etc. — doing business within its borders, for reasons that often owe relatively little to safety and a lot to protectionism. But the effect of the regulatory burdens put on large tech companies does not affect them alone. To take one instance, thanks to EU regulation, users have found the functioning of their smartphones changed in ways they may not welcome and their cybersecurity degraded.
Europe’s Digital Markets Act (DMA) forced mobile devices’ operating systems to allow users to download applications on unvetted third-party app stores, a process known as sideloading. This affected Apple products particularly, as the company’s emphasis on security in its product design led it effectively to ban sideloading on iOS devices (unlike Android devices, which permit the practice). Although banning sideloading limits device users’ decision-making, it improves cybersecurity and assists parental attempts to keep objectionable content from children. Such restraints protect all users. But children — who lack the judgement and experience of adults (which, itself, often proves woefully deficient with respect to technology and cybersecurity) — benefit most.
The DMA’s sideloading mandate has ensured that a pornography app — which Apple bans from its App Store — can now be downloaded on Apple products via a third-party store. Others surely will soon find their way onto digital shelves, and minors are now far likelier to find myriad other dangerous or age-inappropriate applications — e.g., predatory collectors of data, marketplaces for illicit substances, and malware.
Parents find it far easier to monitor and manage their children’s digital activities on devices that have only a single point at which a device allows downloads — particularly given iOS’s parental controls. Forcing open closed app ecosystems might appear a boon for consumer choice — its advocates certainly bill it as such. In practice, however, laws such as the DMA contravene the desires of parents and other users who, preferring the tradeoffs of more restrictive operating systems, have chosen to buy devices that sacrifice maximum flexibility for security or control.
Beyond parental controls, sideloading exposes users to great cybersecurity risk, since third-party stores often vet applications with far less rigor than Apple’s App Store or the Google Play store. These risks have alarmed even DMA-friendly Europeans. According to Apple (as reported by Reuters), some EU and non-EU officials “wanted assurances that they would be able to prevent government employees from sideloading apps onto government-purchased iPhones and that several said they planned to block sideloading on every device they manage.” In other words, the EU knows the benefits of true consumer choice and kept that choice for itself — all while withholding the same privilege from its citizens.
Prior to the DMA, users preferring more flexibility could choose to purchase more devices with more permissive operating systems (Android devices). Now, everybody must buy such devices, irrespective of their preferences, a curious way of expanding their choice.
Despite its departure from the EU, the United Kingdom has also embarked on a dangerous and anti-consumer tech policy. In January, a U.K. agency ordered Apple to provide officials access to encrypted cloud-stored user data. Not content merely to snoop on its own citizens, the officials also seek access to the data of not just U.K. citizens but of users worldwide. To be quite clear, without secure encryption, users lose a substantial degree of privacy. Once flung open, such “backdoors” to encrypted data become accessible to cybercriminals as well as law enforcement. Moreover, granting the government indiscriminate access to all digital data would vitiate the principles of privacy and protection from wanton state snooping — principles that, while embodied in the Fourth Amendment, originated in the English legal tradition.
For American lawmakers, European tech regulations provide the inverse of a handbook. If an idea has been attempted there, it most likely shouldn’t be replicated stateside. It’s said that every dark cloud has a silver lining. Americans shouldn’t waste the silver lining of the EU and U.K.’s blunders — so many case studies on the negative effects of bad tech policy — by ignoring their lessons.
To put it even more simply: When it comes to European tech policy, just say no.