A framework is drafted to address a problem. It is far less often drafted against how the market will interpret, price, and operationalize it. The second-order response is frequently larger than the first, and rarely what was intended.
A framework is drafted to address a problem. It is far less often drafted with a model of how the market will interpret, price, and operationalize it. Legislation is evaluated mainly against its stated objective. The behavioural response (thousands of firms optimizing against the text: over-complying where ambiguity creates risk, under-complying where enforcement is unlikely, building industries around the requirement) is much harder to anticipate and is usually not modelled at all.
Regulation sets incentives, not outcomes. What the market does with those incentives is a separate question the text seldom answers.
When a term is vague and penalties are large, the rational firm over-complies. It adopts the most conservative reading, because the cost of guessing wrong is asymmetric. Multiplied across a market, that produces friction the legislator never intended and did not price: the cookie banner again, blanket data minimization that strips useful features, or simply refusing to serve EU users rather than interpret an unclear rule.
Every major framework mints a service industry: data protection officers, consent platforms, AI-governance tooling, MiCA authorization advisers. That industry then has an interest in the requirement’s complexity persisting. Interpretation drifts toward what is billable, which is not always what the framework intended.
The most consequential effects are structural. A rule can entrench incumbents who can absorb compliance cost against entrants who cannot, push activity offshore, or standardize a market around one vendor’s interpretation. These are real outcomes of the regulation, even though the text describes none of them. To understand a framework’s real effect, model the response, not just the rule.