Why Is Tech Regulation so Hard?

Structural change is needed before tech regulation can truly serve the public interest.

Tech regulation is difficult. We expect privacy from our platforms, integrity from our content providers, accountability from our algorithms, and security from our infrastructures, but we often end up disappointed.

The difficulty of regulating digital technologies has been commonly attributed to the “pacing problem”­—according to which the law cannot keep up with the pace of technology development and will forever be behind. I want to offer an alternative to this simplistic framing of the problem. I would argue that our inability to control the undesired consequences of digital technologies, probably the greatest policy failure of our time, is not due to an impossible race between regulators and tech entrepreneurs. It is a problem of misaligned interests, a hostile political and economic environment, and asymmetrical power and capacities between regulators and the regulated.

Tech regulation involves rulemaking, rule monitoring, and rule enforcement for digital technologies. To holistically understand the tech regulation problem, we need to follow six factors that play a role in explaining why regulating technology is so difficult:

First, rulemaking is often ambiguous and unclear. Policymakers are tasked with designing policies that reduce societal values such as privacy and security to fuzzy legal terms that are often interpreted in ways that do not benefit society. The European Union’s General Data Privacy Regulation (GDPR), for example, warns of “singling out”—a way for individuals in a dataset to be rendered no longer anonymous—but the concept means different things to different actors. Similarly, the GDPR’s requirement for “meaningful consent” before the processing of an individual’s personal information was reduced to a common, standard industry practice, until a Belgian court rejected it as inconsistent with the GDPR. The EU’s Artificial Intelligence (AI) Act and China’s Generative AI Interim Measures similarly employ vague language. When the law is vague and fuzzy, companies can twist what it means. This is usually bad news for society.

Second, tech regulators lack effective and independent rule monitoring. Technology is too opaque and complex to be unpacked and monitored, especially when monitors lack access to its inner workings. Companies have a clear interest in masking how their algorithms make decisions and support their business models. When the NYU Ad Observatory, for example, wanted a glimpse into how Facebook delivers ads, Facebook quickly shut the researchers’ accounts down. Similarly, when ChatGPT exploded in popularity, OpenAI quickly closed its models, reportedly to prevent scrutiny. Others followed, and currently, the large language models underlying popular AI chatbots lack transparency. Regulators have little insight into the data used to train leading models, the weights they use, and the connections they construct to build their neural networks and deliver probabilistic answers to their users. Such opacity in technology often leads to mission creep, where a tool is used for purposes beyond what was originally intended. Regulators are left with a very partial understanding of how our technology works and to what extent its creators comply with regulatory requirements.

Third, companies lack sufficient incentives to meaningfully comply with existing regulations. Tech regulatory requirements often conflict with their business interests. Regulators ask digital advertisers to preserve users’ privacy, authors of search engines to decentralize, creators of commercial spyware to limit their client base, or expect tech companies to fall under specific legal rubrics such as ‘health services’ in order to be regulated . Regulatory requirements often strike at the heart of the way technology companies make money, and our expectation for meaningful compliance can never be fully fulfilled. Compliance, then, is inherently problematic for tech companies, and empirical research demonstrates that they are likely to try to evade meaningful compliance as much as possible.

Fourth, there is a clear asymmetry in capacities between regulators and the regulated, which questions effective regulatory enforcement. Regulators lack the capacity and expertise to monitor and enforce regulatory requirements from tech companies. They cannot, therefore, be proactive or investigate each and every case of potential regulatory violation. Regulators struggle to create a culture of tech policy compliance and end up heavily relying on companies to do the right thing.

Fifth, tech regulators work within a pro-business political and economic environment. The U.S. Congress’s biggest lobbyists are tech companies. They control the AI market and determine which future models will be developed for society. They shape the problem and often the solution during policy discussions, as demonstrated in the legislative process of the Digital Services Act in the EU. Tech lobbyists are getting critical appointments within regulatory agencies. Regulators hesitate to stop or ban problematic data processing practices, even after regulatory violations have been detected, as demonstrated in the inspection of the digital advertising industry by UK’s data protection authority. The heavy influence of tech companies on each and every step of the policy cycle makes it very hard to design and enforce tech regulations that put the public interest as a top priority.

Finally, because technology has been institutionalized in very certain ways and become ingrained in society, it is hard to diverge from harmful existing arrangements. It is hard to imagine, for instance, new secure protocols to communicate between cyber infrastructures despite existing ones being vulnerable to cyber-attacks; society struggles to imagine new ways to develop AI that puts the public interest as a top priority, instead of current private AI giants that train their algorithms on users’ data without consent and focus on fulfilling their mission of producing a commercial, rather than public, product; Our society is unable to shift to new business models that fund online content without totally stripping users of their privacy; users struggle to stop using traditional and toxic social media platforms, despite a growing awareness that their algorithms are addictive and tend to amplify extreme content. These are all examples of decisions at the intersection of technology, society, and the economy that looked very arbitrary decades ago but are now hard to diverge from. It is becoming extremely difficult to imagine a different future with Tech, and it has become too costly to shift to a new vision of tech and society.

So, what can be done?

The people who work for tech are not malicious, but they work in a structure that rewards societal harm. The pressing question is whether regulators can change that structure and create a convergence in corporate and social interests for tech usage and development.

Legal ambiguities should be substituted with a call for machine-readable indicators of compliance. This would allow automatic verification of tech regulation. The EU’s proposed Digital Omnibus Regulation, for instance, would require companies processing data to adhere to more concrete, technical standards for interpreting users’ choices about how their data may be used. Governments, such as U.S. Social Security Administration,  proposing to use AI to decide individuals’ eligibility for welfare, should formalize the legal requirements for the AI they buy so that we can automatically assess its legal accountability.  We need to directly address the fuzziness of the law—otherwise the discretion that companies apply will continue to work against us.

The opaqueness of technology has been successfully addressed in other contexts. An emerging sub-field of research is using computational tools to measure the regulatory compliance of technology. We need more academics, non-governmental organizations, and whistleblowers to evaluate and report to the public how those systems work. Put simply, we need stronger regulatory intermediaries to advance rule monitoring and deter wrongdoers.

Even though the data-driven business models of tech are here to stay, consumers deserve more transparency on the business models and data management policies of leading technology companies. Regulatory innovations, like those requiring data brokers to register with the state, are just a starting point. Consumers need better insight on how our data travels, to whom, and why. We are still unable to develop independent, trustworthy actors who can mediate our data before it makes decisions about us.

To address the asymmetries in power and capacity between regulators and technology companies, regulators should systematically receive assistance from other stakeholders. The EU has acknowledged the weakness of national data protection authorities by allowing the European Commission to enforce the Digital Market Act and Digital Services Act, EU regulations that aim to make technology platforms more competitive and transparent. For the first time, the European Commission enjoys enforcement authority over tech policies. Non-governmental organizations in Europe advocating privacy rights have proved that they can tilt the meaning and implementation of the GDPR.  We cannot leave regulators to solve everything for us. We, academics and civil society, must be an institutionalized part of any tech regulatory solution.

The concentration of power over data, computation, and lobbying power within a handful of tech companies and individuals must be diluted. Recent antitrust cases are steps in the right direction, but without decentralized tech development, market competition alone will always struggle to bring about overall social welfare. Big tech companies are the ones that exclusively decide on the next AI development. They have a problematic record of priorities, to say the least. Smaller companies and consumers have the power to take this decisionmaking authority out of big tech companies’ hands by developing civic technologies bottom-up, with funding from public or non-profit authorities. Regulators need to be able to clearly state what is ethically forbidden to develop and sell, and what can be used as a weapon against society.

Finally, at this point in time, it can be difficult to envision a complete paradigm shift in the way technology is embedded in society. Still, the gradual shift to more secure networking protocols, such as IPv6, secure DNS, and secure BGP shows that it is possible to diverge from the networking protocols that enabled the Internet in the first place. These are all examples of how society was able to move toward more secure ways for connecting digital infrastructures. We should also advocate for solutions to data portability, allowing us to move with our data to different platform services, or create frameworks to collect information on how our historical online engagements shape our tech future. This would allow us to recognize the places where our digital habits backfire on us and society.

Tech regulation is hard but not impossible. Still, we have a lot of work to do. We currently win a few battles but lose the war. Without a structural change across the six factors I have identified, the tech future will not and cannot be a pleasant one.

Ido Sivan-Sevilla

Ido Sivan-Sevilla is an assistant professor of computer science & public policy at the Hebrew University of Jerusalem and the University of Maryland.