France's competition regulator just did what most market commentary hasn't: it put a hard number on how concentrated the AI-agent market already is. On 17 July 2026, the Autorité de la concurrence published Opinion No. 26-A-05, concluding that OpenAI, Google, and Anthropic together hold more than 84% of the AI-agent market (Autorité de la concurrence; PPC Land). The read for a founder is not the headline. It's the three levers the regulator says it would pull — because those three levers are a precise map of where your own business is most exposed.
The number, and how they got it#
The Autorité opened the inquiry on 8 January 2026 and produced an opinion that runs past 3,700 pages with its annexes. What makes it worth reading is the method. Rather than trust the labs' own market claims, the regulator built its own AI shopping agents and put roughly 550 purchase-related questions to them, then logged which websites the agents actually visited and cited in their answers (PPC Land).
That is the important move. It measures the market at the layer that matters commercially — where the agent routes demand, which merchant or service gets the transaction — not just which lab trained the underlying model. The 84% is a statement about the distribution chokepoint, and distribution is exactly what a startup rarely controls. The report notes other integrated players (Amazon, Microsoft, Nvidia) and sector-native firms (Mistral AI, Perplexity, xAI) exist, but they share the sliver next to the three pillars.
The regulator didn't measure who builds the best model. It measured who the agents reach for — and three companies own that reach.
The three levers are your three risks#
The opinion flags three areas where competition is at risk. Read them not as policy, but as a checklist of dependencies to audit in your own stack.
1. Data access. The incumbents train and ground their agents on data that rivals can't reach. You can't out-spend that. What you can do is own a proprietary data or workflow slice — a vertical, a first-party dataset, a system of record — that the big three have no path to replicate. That's the wedge we keep pointing founders toward, and this report is the reason why: general capability is commoditizing toward three vendors, so your defensibility has to live somewhere they won't follow.
2. Interoperability. The regulator's second concern is whether third-party agents and services can plug in, or whether the platform keeps the whole transaction inside its own walls. This is the most actionable item on the list, because there's already a structural counter-move: open protocols. Building your service so it's callable from any agent — via MCP, whose stateless spec finalizes this week — is how you avoid being locked out of a market three companies gate. Interoperability is the founder-friendly outcome the regulator wants; you don't have to wait for the mandate to build for it.
3. Default placement. The third lever is which tool, model, or merchant an agent reaches for by default. If your business works only because you're the default inside one big agent, you have built on rented land — and the report is a signal that regulators, and the platforms themselves, will keep renegotiating those defaults. A default you didn't earn structurally can be revoked in a product update.
What it means#
An Autorité opinion is advisory. It imposes nothing today, and it's French-scoped. But it is the clearest public articulation yet of how regulators will frame agent markets, and EU competition logic travels — treat it as a forward indicator of where interoperability requirements and default-choice rules are heading. We called the governance fracture forming around AI; this is the competition-policy edge of the same shift.
The strategic takeaway is narrower and more useful than "the market is concentrated." It's this: your platform risk is not which model you call — it's the distribution and default layer three companies control. The defensible positions are the two the regulator is trying to protect: a data or workflow wedge the incumbents won't chase, and interoperability that keeps you reachable from any agent instead of trapped behind one. Build both now, while the standards are still being set in your favor — the same week the agent stack itself is consolidating.



