The Autorite de la concurrence did something unusual to prepare for this report. It built its own AI agents, pointed them at the French internet, and asked 550 questions about buying things: electronics, hotel rooms, transport tickets, household appliances. It logged every website each agent consulted, then cross-referenced which ones actually showed up in the answers. The experiment ran from May 20 to May 30, 2026. The results are in Annex 2 of Opinion 26-A-05.
That methodological choice matters. France's competition authority did not take vendor self-reporting at face value and did not rely on general AI anxiety. It built a measurement tool. The resulting 3,700-page opinion is credible in a way most regulatory documents about AI are not.
The headline finding: OpenAI, Google and Anthropic together held more than 84 percent of the global AI agent market in May 2026, according to Sensor Tower data the Authority cited. Three companies. 84 percent. In a market that barely existed two years ago.
TL;DR: France's Autorite de la concurrence published Opinion 26-A-05 on July 17, 2026, finding OpenAI, Google and Anthropic hold over 84% of the global AI agent market. The report documents three structural risks: default integration lock-in, data portability gaps, and protocol fragmentation between Google's UCP and OpenAI's ACP. It is advisory, not punitive, but enterprise teams buying AI agent tools now are making vendor decisions that will be harder to reverse in 18 months than they appear today.
The opinion is advisory. It accuses no one of breaking the law and notes explicitly it is not assessing conduct against Articles 101 and 102 of the Treaty on the Functioning of the European Union. What it does instead is describe how a market built as a tool becomes a gateway, and which structural features make that transition hard to reverse.
What changed between a chatbot and an agent
The Authority draws a clear line between the category it reviewed in Opinion 24-A-05 from June 2024, which looked upstream at model training and infrastructure, and what it examined here. Opinion 26-A-05 moves downstream to the layer where AI tools plan, reason, and take actions across multiple steps without moment-to-moment human direction.
The European Commission's own definition, quoted in the report, describes AI agents as software that "perceive and interact with a virtual environment" and "operate autonomously, that is to say, without being directly controlled by a human." This is not a semantic distinction. The lock-in implications are different when a tool is executing a workflow rather than answering a question.
A chatbot you can replace with a different chatbot. The prompts carry over, the context resets, the outputs are roughly comparable. An AI agent that has been running your procurement process for six months, or scheduling your team's calendar for a quarter, has accumulated something closer to institutional memory. Switching means rebuilding accumulated context, reintegrating with connected tools, and accepting some loss of workflow continuity. The Authority found no standard mechanism exists to migrate that context between vendors. It recommended one should exist.
Why entry is easy but growth is not
One of the opinion's more careful arguments distinguishes between market entry and market scale. Building an AI agent has become comparatively accessible. Capable models are available through APIs. Open-weight releases lower the technical floor. Mistral AI, a French company, is cited repeatedly as the only European provider of meaningful scale, though the Authority notes Mistral "does not benefit from the same investment capacity, infrastructure and large-scale adoption as the global US players."
The gap between building something and reaching users is where the 84 percent figure starts to make sense. Google's Gemini is integrated into Android by default. Microsoft's Copilot ships inside Office 365. Meta AI is baked into WhatsApp, which is the primary messaging platform for a substantial portion of the global population. The French Authority was watching what happened in January 2026, when Meta restricted third-party AI chatbots from the WhatsApp Business API, leaving Meta AI as the sole assistant on the platform. The European Commission imposed binding interim measures in June 2026 requiring Meta to reopen access. The French opinion cites this as the pattern to watch.
Two structural advantages compound for the incumbents beyond distribution. Access to usage data at scale improves model quality in ways smaller providers cannot replicate from a standing start. Inference costs, the compute required to run a model in real time, now exceed training costs for providers running at scale, and the Authority cites an EY study showing the average cost of "orchestration" by an AI agent grew from four US cents per response in 2023 to 1.20 US dollars per task in 2026. At that cost level, a new entrant needs revenue to fund the compute required to serve users at quality, but needs quality to attract the users who generate the revenue.
The Authority's own experiment captured one dimension of this concretely. ChatGPT, in the Authority's testing, consulted Reddit for 87.4 percent of its discoverability questions, yet cited Reddit directly in only 1.0 percent of its responses. The sources an agent visits most are not necessarily the sources it tells users it used. Gemini diverged sharply from ChatGPT in which sites it consulted, yet neither was transparent about the full picture of what shaped its answers.
Three sets of concerns the Authority documented
The opinion closes with three sets of recommendations rather than binding orders.
The first is not really a recommendation: apply what already exists. The AI Act, the Digital Markets Act, the Digital Services Act, GDPR and the Data Act provide a meaningful toolkit, the Authority argues, and the priority is enforcement speed rather than new legislation. The EU's framework is largely in place. Using it quickly is the issue.
The second set focuses on three specific risks the Authority wants regulators to monitor. First, equity investments and partnership agreements between major digital platforms and competing AI agent publishers, where a platform company takes a stake in a potential competitor and gains conflicting incentives about how prominently to surface it. Second, default placement: whether users can actually choose and use an AI agent other than the one pre-integrated into a platform they already depend on. Third, ranking and recommendation procedures: how an agent decides which services, products and sources to present to a user, and whether those procedures are disclosed.
The third set addresses infrastructure. "Model as a Service" platforms, the cloud-hosted marketplaces through which businesses access third-party AI models, should be monitored closely, the Authority says, and the European Commission should consider whether to designate the most significant ones as "essential platform services" under the Digital Markets Act. The opinion also calls for users to be able to migrate between AI agents "without any significant loss of information or functionality," and for commercial protocols governing agentic commerce to be "developed and maintained in a transparent, open and collaborative manner, in order to avoid any situation of excessive control or influence by a dominant player."
That last requirement directly addresses a split the market has not resolved. Google's Universal Commerce Protocol launched in January 2026 with Shopify, Walmart, Visa and Stripe as co-developers. OpenAI's Agentic Commerce Protocol, developed with Stripe, has been live since September 2025. Both govern how AI agents complete purchases on behalf of users. They are not interoperable. An enterprise that integrates its procurement workflow with one and wants to switch AI vendors later faces a protocol problem alongside the data problem.
The commerce projection is the number to track
The Authority estimates that traffic from AI agents to e-commerce websites in France currently sits below 5 percent. It projects this could reach nearly 25 percent by 2030. If that trajectory is even roughly accurate, the vendor an enterprise has integrated into its purchasing workflows by late 2026 will be embedded deeply enough by 2028 that switching becomes a significant project, not a checkbox item.
ChatGPT reached over 900 million weekly active users and 50 million subscribers worldwide as of March 2026, according to OpenAI's own figures. Google reported in May 2026 it was processing more than 3.2 quadrillion tokens per month, seven times the volume of a year earlier. These numbers are growing faster than enterprise procurement cycles typically move. The lock-in question is not theoretical. It is a function of how quickly your current integration becomes load-bearing before your next vendor review date.
The opinion also documented that advertising is starting to appear inside AI agents. OpenAI began testing ads in ChatGPT in January 2026. Perplexity dropped its own advertising tests early in 2026. Anthropic announced in February 2026 its intention to keep Claude ad-free. The divergence in monetisation strategy matters for enterprise use cases: an agent that serves ads may not have the same response priorities as one funded entirely by subscriptions.
What to ask before signing an AI agent contract
The Authority's findings describe a structural situation. The procurement question is what to do about it before you are inside it.
Before integrating an AI agent into any workflow where switching would be disruptive, ask the vendor three things in writing.
First: what data can be exported, in what format, and on what timeline? That includes historical conversation records, usage preferences, any fine-tuned context the agent has built from your team's patterns, and integration configurations. If the vendor cannot specify a standard export format, the implicit answer is that the data stays with the vendor.
Second: which agentic commerce protocols does the product support? UCP, ACP, both, or neither? If neither, and the vendor says it plans to support one eventually, get the commitment in the contract with a specific timeline and a termination right if the timeline slips. Two parallel, non-interoperable standards mean your protocol choice today is also a vendor choice.
Third: what is the actual exit path? The cost of vendor migration is rarely the subscription fee. It is rebuilding the connections to your other tools and reconstructing the process context the agent has accumulated. Ask the vendor to estimate this explicitly. If they cannot or will not, that is a useful signal about how they think about retention.
The Autorite de la concurrence did not conclude that any company is doing something illegal. The opinion is an early warning about market structure, issued by a regulator that went to the trouble of building its own agents to see what was actually happening. That level of care is worth taking seriously by the enterprise teams making these vendor decisions now.
Related Reading
- Vetting AI Tools: Fake Apps, Malware, and Typosquatting Risks
- AI Vendor Contract Red Flags: What to Check Before Signing
- Anthropic Export Ban: What the 17-Day Fable 5 Shutdown Means for Your AI Vendor Policy
- MCP Server Security Governance Checklist 2026
- FTC AI Enforcement Actions 2026: What the Pattern Means for Small Teams
- AI Spend Governance: Token Budget Controls and Cost Management 2026
Sources: Autorite de la concurrence, Opinion 26-A-05, July 17, 2026, ppc.land coverage of Opinion 26-A-05, Concurrences summary.
