How Structural Reforms Can Fix Modern Tech Regulation

How Structural Reforms Can Fix Modern Tech Regulation

Desiree Sainthrope is a distinguished legal expert whose work sits at the critical intersection of global trade agreements and the rapidly shifting landscape of emerging technologies. With years of experience drafting complex international frameworks and navigating the intricacies of intellectual property, she has become a leading voice on how legal systems must adapt to the challenges posed by artificial intelligence and digital platforms. Her perspective moves beyond the common complaint that “law moves too slow,” instead identifying a deep-seated structural misalignment between corporate incentives and the public good. In this conversation, we explore the multifaceted reasons why tech regulation often fails to meet our expectations—ranging from the ambiguity of legal language and the opacity of neural networks to the overwhelming influence of industry lobbying on the policy cycle. Through a detailed analysis of recent enforcement actions in the European Union and the United States, we discuss a potential roadmap for reclaiming digital sovereignty through transparency, decentralization, and technical standards that prioritize human agency over algorithmic efficiency.

Legal standards like “meaningful consent” or “singling out” are often interpreted in ways that favor industry rather than the public. How do you see these fuzzy legal terms impacting our ability to hold platforms accountable?

The ambiguity inherent in our legal vocabulary creates a playground for corporate lawyers to redefine the boundaries of what is permissible, often to the detriment of the average user. When we look at the European Union’s General Data Protection Regulation, or GDPR, it introduces the concept of “singling out” as a threshold for whether a person has been effectively anonymized within a dataset. However, “singling out” means something very different to a data scientist trying to optimize an ad-targeting algorithm than it does to a privacy advocate. This fuzziness allows companies to claim they are protecting privacy while continuing to profile individuals with surgical precision. We saw this play out vividly with the requirement for “meaningful consent” before personal information is processed. For years, the tech industry reduced this profound legal principle to a standard practice of clicking “Accept” on a pop-up banner that no one actually reads. It took a Belgian court to step in and finally reject this industry standard as fundamentally inconsistent with the spirit of the GDPR. When the law is this vague, it places a heavy burden on the judiciary to correct systemic abuses after they have already happened, rather than preventing them at the source. This is precisely why we are seeing similar patterns of “legal fuzziness” in the new EU AI Act and China’s Generative AI Interim Measures, where terms are left open enough for companies to twist compliance into a mere marketing exercise.

We often hear that technology moves too fast for the law, but you suggest the issue is more about a lack of visibility into these systems. Could you elaborate on the hurdles regulators face when trying to monitor opaque algorithms?

The “pacing problem” is a convenient myth that allows us to ignore the fact that we have allowed technology to become a black box. The real challenge is that tech companies have a massive financial incentive to keep their internal workings hidden, and they are becoming increasingly aggressive about defending that opacity. Consider the case of the NYU Ad Observatory; when researchers tried to gain a glimpse into how Facebook actually delivers and targets ads to its users, the platform responded by shutting down their accounts. This wasn’t an isolated incident of technical friction, but a deliberate move to prevent external scrutiny. This trend toward secrecy is only accelerating with the rise of large language models like ChatGPT. While OpenAI started with an ethos of transparency, they quickly closed their models to the public once they achieved mass popularity, citing competitive and safety reasons. The result is that regulators are left guessing about the data used to train these models, the weights that determine their output, and the complex neural connections they build to deliver answers. Without direct access to these inner workings, regulators cannot detect “mission creep”—where a tool designed for one purpose is quietly repurposed for something more invasive. We are essentially asking the police to monitor a city where every building is invisible and the blueprints are locked in a safe to which only the landlord has the key.

There seems to be an inherent conflict between a company’s bottom line and the privacy requirements set by regulators. How do you bridge the gap when compliance feels like an existential threat to a business model?

This is perhaps the most difficult hurdle to clear because many of our current regulatory goals strike directly at the heart of how these companies make their money. We are asking digital advertisers to preserve the privacy of the very people they need to profile to sell high-value ads. We are asking search engine creators to decentralize their power, or requesting that commercial spyware firms limit their own client base. When a regulation demands that a tech company reclassify itself under a stricter legal rubric—like “health services”—it introduces costs and liabilities that can fundamentally break their existing profit margins. Because of this, empirical research shows that tech companies don’t just struggle with compliance; they actively look for ways to evade it. It’s not just a matter of “doing the right thing”; it’s a structural conflict where “doing the right thing” might mean losing billions of dollars in market valuation. Until we can create a world where a company’s success is measured by its social utility rather than its ability to harvest data, we will continue to see this cat-and-mouse game where companies provide the bare minimum of compliance while continuing to exploit every loophole they can find.

Regulators often seem outmatched by the sheer scale and resources of Silicon Valley. What specific steps can be taken to level the playing field so that enforcement isn’t just a game of catch-up?

The asymmetry in capacity is staggering, and it’s not just about the number of lawyers; it’s about the depth of technical expertise. Regulators are often trying to investigate a violation with a fraction of the computing power and data science talent that a single mid-sized tech firm possesses. To fix this, we have to move toward a more collaborative and institutionalized model of enforcement. We are starting to see this in Europe, where the European Commission has taken over the enforcement of the Digital Markets Act and the Digital Services Act because national data protection authorities simply didn’t have the muscle to take on the giants. But we also need to bring civil society and academia into the fold as “regulatory intermediaries.” Non-governmental organizations have already proven in Europe that they can successfully tilt the implementation of the GDPR by bringing strategic lawsuits that force the hand of regulators. We need to formalize this, creating a system where whistleblowers, researchers, and public interest groups are empowered to monitor these systems in real-time. We cannot expect a handful of government employees in a basement office to police the entire digital economy; we need a broad-based coalition that treats tech accountability as a shared social responsibility.

The influence of tech lobbyists on the policy cycle is well-documented, from the Digital Services Act to the AI market. How does this close relationship between the regulator and the regulated undermine the public interest?

The level of capture we see in the tech sector is unprecedented, largely because these companies have positioned themselves as the sole architects of our digital future. Tech firms are among the biggest lobbyists in the U.S. Congress, and they don’t just influence laws—they often write them. During the legislative process for the Digital Services Act in the EU, the fingerprints of industry lobbyists were everywhere, shaping how problems were defined and which solutions were even considered. This influence extends to the personnel level, where tech lobbyists frequently secure critical appointments within the very agencies meant to oversee them. This leads to a culture of hesitation; for example, the UK’s data protection authority has been criticized for being too slow to ban problematic data processing practices in the advertising industry even after clear violations were found. When the regulated have this much power over the regulator, the “public interest” becomes a secondary concern to “innovation” and “economic growth.” We end up with a system that is designed to protect the status quo of a few dominant players rather than fostering a digital ecosystem that serves the many.

Many of us feel trapped by addictive platforms or vulnerable infrastructures because it’s hard to imagine an alternative. How can we begin to shift toward a future where technology is a public good rather than a commercial product?

Breaking this “path dependency” is incredibly hard because these systems are now woven into the fabric of our daily lives. We are using networking protocols that were designed decades ago and are inherently vulnerable to cyber-attacks, yet the cost of moving to something like IPv6 or secure BGP is so high that we drag our feet. Similarly, we are stuck with toxic social media business models because it’s hard to imagine an internet that isn’t funded by stripping users of their privacy. However, we can start by demanding technical standards that make these shifts easier. Solutions like data portability are essential; if I can move my entire digital history to a new platform as easily as I can switch my phone number to a new carrier, the “addiction” to a specific platform loses its grip. We also need to fund “civic technologies” from the bottom up. Instead of letting a handful of giants decide what the next version of AI looks like, we should be using public or non-profit funding to develop algorithms that prioritize transparency and consent. It’s about creating a “digital commons” where the technology is built to be a public utility, much like our roads or water systems, rather than a walled garden owned by a billionaire.

What is your forecast for the future of tech regulation over the next decade?

I believe we are entering an era of “algorithmic accountability” where the era of the “move fast and break things” wild west is finally coming to an end, but it will be a messy transition. Over the next ten years, I expect to see a shift away from vague legal text toward “machine-readable” indicators of compliance. Imagine a world where the law isn’t just a document in a drawer, but a set of technical standards that a company’s software must automatically verify and report on. The EU’s proposed Digital Omnibus Regulation is a hint of this future, as it pushes for concrete technical ways to interpret user choices. However, the success of this shift depends on whether we can decentralize the power currently held by a few firms. If we continue to let three or four companies control the world’s data and compute power, no amount of regulation will be enough. My forecast is that we will see a rise in “state-sponsored” or “civic” tech alternatives that force the commercial giants to actually compete on privacy and ethics. We will likely see a few major antitrust breakups or massive structural changes that force platforms to separate their data-gathering arms from their service-delivery arms. It won’t be a pleasant or easy road, and we may lose more battles along the way, but the public awareness of these harms has reached a tipping point that makes the current status quo unsustainable.

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later