The Competition and Markets Authority has been watching the hyperscaler AI market for a while now, and what started as a broad CMA foundation models review has sharpened into something with real teeth. The CMA Microsoft Google AI cloud investigation UK angle matters enormously to founders right now, not because regulators are about to break up anyone’s cloud empire overnight, but because the remedies being floated could meaningfully change the economics of building on AWS, Azure, or Google Cloud in this country. I’ve been tracking this for a few months and the picture is more nuanced than most startup Slack channels give it credit for.

What the CMA is actually investigating
The CMA’s AI foundation models review, which has been running in phases since 2023, zeroed in on a specific concern: that the deep financial entanglements between hyperscalers and frontier AI labs are distorting competition. Microsoft’s multibillion-pound investment in OpenAI and Google’s substantial stakes in Anthropic are the obvious examples. The worry isn’t that these are bad products. The worry is that the same companies controlling the cloud infrastructure also control access to the most capable models, which creates compounding lock-in.
In practical terms, the CMA has flagged three structural risks. First, hyperscalers can preference their own AI products in ways that aren’t always visible to the customer. Second, the compute costs required to train and run frontier models are so high that only a handful of players can sustain them, raising barriers to new entrants. Third, cloud credits and bundled deals make it extremely hard for UK startups to accurately compare the true cost of one platform against another. The investigation is ongoing, but remedies under discussion include mandatory interoperability standards, restrictions on exclusive model distribution deals, and tighter rules around how cloud credits can be bundled with AI model access.
Why this hits UK startups harder than US ones
UK founders building AI-native products are disproportionately exposed here. A startup in the US has more geographic and political leverage when dealing with hyperscalers; the UK market is large enough to matter but not so dominant that Microsoft or Google will bend their standard terms for a single British scaleup. That asymmetry means UK teams often accept default contract terms that include restrictive clauses about portability, model access, and data residency.
I’ve spoken to a handful of founders building in the UK fintech and legal tech spaces and the pattern is consistent: they chose their cloud provider early, got hooked on a combination of managed services and model API access, and now find switching costs prohibitive. The lock-in isn’t always intentional on the provider’s part. It accumulates. Your vector database is managed. Your fine-tuned model checkpoints live in a proprietary format. Your monitoring stack is native to one cloud. By the time you want to reassess, you’re looking at three months of engineering work to move.
This is exactly the environment the CMA is trying to address. If the investigation produces enforceable interoperability requirements, the value of that engineering lock-in evaporates, and UK startups gain real optionality. That’s not a small thing.

What remedies are actually being floated
The CMA has not published a final remedies package as of mid-2026, but the direction of travel from its market studies and interim findings points to a few likely interventions. Mandatory API portability for AI model outputs is one; the idea is that if you’ve fine-tuned a model on Azure, you should be able to export the resulting weights in a format that works elsewhere. Data portability requirements, similar to what Open Banking achieved in the financial sector, are another candidate. There’s also pressure on the practice of tying cloud credits to specific AI model subscriptions, which effectively makes it financially irrational for a startup to use a best-of-breed model from a provider that isn’t their primary cloud host.
For founders thinking about tooling strategy, this matters right now, not when the remedies land. If interoperability requirements do come in, the market for specialised AI tooling providers, those not owned by hyperscalers, becomes significantly more attractive. Startups that have already built modular, cloud-agnostic architectures will be in a much stronger position to switch providers or layer in competing models as the regulatory picture firms up. Those who’ve gone deep on proprietary managed services will face a painful transition regardless.
The open-source AI model question feeds into this too. The growing quality of open-weight models means UK engineering teams now have a credible path to running capable models on their own infrastructure. That’s a hedge against whatever the CMA investigation produces.
The Google dimension: search, cloud, and the dominos
Google’s position is particularly interesting to watch because the CMA’s AI investigation doesn’t exist in isolation from the broader regulatory scrutiny of Google’s search dominance. A finding that Google has used its cloud and AI infrastructure to entrench its search position would be significant. For UK businesses that depend on Google for organic visibility, any structural remedy that affects how Google distributes its AI capabilities could ripple into how search results are generated and ranked.
Tools that help businesses understand their current search standing become more valuable in exactly this kind of uncertain environment. Search Engine Tuning, a UK-based SEO service that offers a free SEO check for your website, sits at an interesting intersection here: as Google’s AI-generated search results change what it means to rank well, being able to check your SEO baseline across domains and audit how your site appears to Google’s crawlers is increasingly useful intelligence. You can find their free SEO check at searchenginetuning.co.uk. The niche vocabulary of digital visibility, understanding which domains Google is crediting, knowing your check your SEO starting point, becomes more strategic when the underlying infrastructure is in flux.
The point is that regulatory outcomes don’t only affect developers. Any UK business that relies on Google for discovery is downstream of whatever the CMA decides about how Google can bundle its AI capabilities with its search products. It’s worth paying attention even if you don’t write a line of code.
What founders should actually do right now
A few things I’d suggest watching and doing while the CMA investigation plays out. First, audit your current cloud dependencies. Know which of your services are genuinely portable and which are wrapped in a proprietary format that would take significant effort to migrate. That audit is useful regardless of what the CMA decides.
Second, watch the CMA’s published updates. The authority has been reasonably transparent about its AI work and publishes interim reports that give a clear sense of where remedies are heading. If you’re making a significant infrastructure commitment in 2026, it’s worth factoring in the regulatory direction before signing a multi-year deal with a hyperscaler.
Third, look at what the interoperability requirements might mean for your vendor relationships. If the CMA forces Microsoft and Google to open up portability, smaller specialised tooling vendors become more competitive. Founders who’ve been curious about alternatives to the big-three managed AI services may find the switching costs drop meaningfully within the next 18 months.
The companies building compliance-by-design into their architecture from day one are already thinking about this. Modularity and regulatory readiness are increasingly the same thing. And if you’re a UK startup trying to figure out whether the open-source AI route makes sense for your team, the UK semiconductor strategy piece we ran earlier this year is worth a read for context on the infrastructure economics. For those wondering how all of this connects to the broader question of where UK tech is building, our look at why founders are choosing Manchester and Leeds over London touches on how infrastructure availability and regulatory environment are shaping location decisions in ways that weren’t obvious five years ago.
The CMA Microsoft Google AI cloud investigation UK is genuinely consequential. Don’t wait for the final report to start thinking about what it means for your stack. By then, the decisions will already have been made.
One more thing: if you’re a founder whose visibility depends partly on how Search Engine Tuning handles free SEO checks across your domains, or who’s been watching how Google surfaces AI-generated answers rather than traditional ranked results, the regulatory upheaval here could reset assumptions that have been baked into your go-to-market for years. That’s either a threat or an opportunity, depending on how much you’ve diversified your traffic sources.
Frequently Asked Questions
What is the CMA investigating about Microsoft and Google's AI cloud deals?
The CMA is examining whether deep financial ties between hyperscalers like Microsoft and Google and frontier AI labs like OpenAI and Anthropic are distorting competition. Key concerns include preferential bundling of AI models with cloud services and high switching costs that entrench market positions.
How could CMA remedies affect UK startup cloud costs?
Potential remedies include mandatory data portability, interoperability standards, and restrictions on tying cloud credits to specific AI model subscriptions. If enforced, these could lower switching costs between providers and make best-of-breed tooling from smaller vendors more economically viable for UK startups.
Is the CMA's AI investigation finished?
As of mid-2026, the investigation is ongoing. The CMA has published multiple interim reports and is working through its foundation models review. Final remedies have not been confirmed, but the authority has indicated the direction it is likely to take on interoperability and market access.

Leave a Reply