A numbered research series

Threshold Effects

Rules change what organizations are required to do. They rarely change what they are. Each numbered issue examines that gap — regulation, disclosure, governance, and the organizational capacity that decides outcomes. Sources are linked in the text. Subscribe by RSS.

Issues before No. 011 were first published under an earlier series name; numbering was applied retroactively from the beginning of the record when the archive moved here.

  1. No. 011

    Five Years to Fiber

    Gulf Coast ·

    BEAD is finally putting fiber in the ground around northwest Florida and south Alabama. Five years of process decided who gets to build — and it wasn't construction capability that decided.

  2. No. 010

    A Fair Fight with SOX 404

    Regulation ·

    Arguing against myself: SOX Section 404 is the strongest counterexample to this series' thesis. The argument survives — but comes out more precise than it went in.

  3. No. 009

    Say Something vs. Build Something

    Regulation ·

    There are rules that require organizations to say something and rules that require them to build something. Only the second kind has a track record of changing what organizations are.

  4. No. 008

    The Dashboard Is Green

    Metrics ·

    Goodhart's Law and Campbell's Law warned us fifty years ago: the metric changes what the organization reports, not what the organization is. We built the dashboards anyway.

  5. No. 007

    What the Broadband Labels Revealed

    Telecom ·

    The FCC's broadband nutrition labels were identical for all 35 ISPs a 2025 study scored. What the mandate produced depended entirely on what each organization already was.

  6. No. 006

    Wanted: The Best Counterexample

    Regulation ·

    The honest version of an argument has to survive its best counterexample. So: what's the strongest case of a rule that actually changed what organizations are?

  7. No. 005

    Three Rules, Same Outcome

    Regulation ·

    AI governance, compliance programs, mandatory disclosure: three domains, three rules, same outcome. The rule changes what organizations are required to do. It rarely changes what they are.

  8. No. 004

    Shadow IT Was the Rehearsal

    AI Governance ·

    Shadow IT persisted because unsanctioned tools solved real problems faster than approved ones. AI governance is replaying the same dynamic — in months instead of years.

  9. No. 003

    Paper Trails and Shadow AI

    AI Governance ·

    Only 37% of compliance leaders can measure whether their programs work — and half the U.S. workforce is using AI at work without knowing if it's allowed. Why did we think a document was going to govern a behavior?

  10. No. 002

    Cover-Yourself 8-Ks

    Disclosure ·

    When the SEC required four-business-day incident disclosure, firms responded with “cover yourself 8-Ks.” Organizations don't respond to regulatory intent — they respond to regulatory incentives.

  11. No. 001

    The Faster-Is-Better Assumption

    Disclosure ·

    The assumption behind mandatory breach disclosure timing is that faster equals better. Across 1,054 breach events and three empirical channels, that assumption doesn't hold up well.