Why More Rules Often Strengthen the Biggest Companies
Every large company now runs two operations at once. One makes the product. The other exists to prove, in writing, that the product was made correctly. The second operation is expensive, and a large share of its cost has little to do with how big the company is. That gap is a big part of why regulation, more often than anyone intends, ends up helping the largest companies in an industry while raising the price of entry for everyone trying to break in.
This isn’t true of every rule. Many regulatory regimes are explicitly tiered, with revenue thresholds, phase-in periods, or exemptions built in to protect smaller businesses. Regulators know the fixed-cost problem exists and often try to design around it. The more interesting finding, and the one this piece focuses on, is how often those protections turn out to be incomplete. Even where lawmakers tried to scale a rule to company size, the underlying cost still tends to fall harder on the smaller players it was built to shield.
The economics of a fixed cost
Congress passed the Dodd-Frank Act after the 2008 financial crisis to rein in the largest, riskiest banks. A 2019 study by economist Thomas Hogan and Scott Burns, published through Rice University’s Baker Institute for Public Policy, found that total noninterest bank expenses rose by an estimated $64.5 billion a year relative to their pre-Dodd-Frank trend, driven by new compliance staff, legal fees, auditing and data processing. Large banks absorbed a large share of that increase in absolute dollars, spending over twelve billion a year more on legal fees alone. But the same study found the increases were proportionally steeper and more statistically significant for small banks.
The pattern shows up in market share too. A Harvard Kennedy School study by Marshall Lux and Robert Greene found that community banks lost about six percent of their share of U.S. banking assets in the four years before Dodd-Frank passed, a period that included the 2008 crisis itself. In the years after the law took effect, that share fell by more than twelve percent, roughly double the earlier rate. Fed economists have studied a related but distinct question directly, and it’s worth being precise about what it does and doesn’t tell us before laying out the numbers: it measures new bank formation, not what happens to banks that already exist, so it can inform the comparison above without settling it. A 2016 Federal Reserve Board paper by Robert Adams and Jacob Gramlich modeled new bank formation, meaning the rate at which new charters were issued, not the market share of existing community banks, from 1976 to 2013 and found that at least seventy-five percent of the post-2010 collapse in new bank charters would have happened anyway, driven by low interest rates and weak demand rather than regulation. The paper is explicit that the standalone effect of regulation was hard to isolate from that noise, not that the effect was zero, and it doesn’t directly measure the asset-share figures above since new-charter activity and the shrinkage of existing banks are different phenomena that can move for different reasons. Taken together, the two strands of research point toward a real but modest regulatory push, layered on top of a decline that had other, larger causes: the banks Dodd-Frank targeted didn’t disappear, and the ones it never meant to touch shrank faster than before, even if regulation wasn’t the main reason.
When a rule is built to scale, and still doesn’t
The Food Safety Modernization Act is a useful test case precisely because it tried to do the tiering that critics of this argument correctly point out is possible. The law’s Produce Rule gave small farms extra years to comply and exempted the very smallest operations from parts of the requirement. Despite that, the USDA’s Economic Research Service found that compliance still cost small and very small farms between six and seven percent of their annual sales, compared to well under one percent for the largest farms. The rule was written with fixed-cost asymmetry in mind, and the cost curve stayed regressive anyway, because inspections, water testing and recordkeeping systems cost close to the same dollar amount whether a farm sells $30,000 or $30 million a year. Careful regulatory design can blunt the fixed-cost problem. It rarely eliminates it.
What happened when Europe tried to rein in big tech
The clearest recent demonstration of the same pattern shows up in the rollout of the EU’s GDPR in 2018, a law aimed squarely at the largest data collectors, chiefly Google and Facebook. Economists Garrett Johnson, Scott Shriver and Samuel Goldberg tracked more than 27,000 websites and found that market concentration among web technology vendors jumped by roughly seventeen percent in the week the law took effect, as sites dropped smaller vendors they no longer had the staff to vet, while the largest Google and Facebook-owned vendors gained share. That timing is not a coincidence worth explaining away. The same researchers’ own tracking data shows the drop wasn’t a slow drift: comparing their scan of sites just before enforcement, on May 23 and 24, to their scan just after, on May 25 through 28, they measured an eleven percent fall in vendor use in that single four-day window, out of a roughly fifteen percent total decline the study tracked over the following weeks. That means most of the total drop, on the order of three-quarters of it, happened in the four days straddling the deadline itself, which is exactly what you’d expect if the law was the trigger, not some unrelated shift in the market. A separate figure has circulated since, cited in testimony to the Senate Judiciary Committee, claiming small and mid-sized ad technology firms lost as much as a third of their market position within the following year. That figure comes from an unnamed source cited in the testimony and shouldn’t be read as comparable in reliability to the Johnson, Shriver and Goldberg figure above it, which is peer-reviewed and traceable to a specific dataset.
Two named companies illustrate the pattern, though they should be read as illustration rather than proof of a single cause. Klout, the San Francisco social-analytics firm, shut down on the exact day GDPR took effect, though it had also been losing relevance for years beforehand, so the law is best understood as one pressure among several rather than the sole reason it closed. Drawbridge, an identity-management company, wound down its European operations around the same time. What’s harder to explain away with other factors is the aggregate data: a measurable jump in concentration in the small-vendor segment specifically, exactly where the fixed-cost story predicts it.
Google, meanwhile, had already consolidated dozens of separate privacy policies into one broad framework years earlier, which let it keep sharing data across its own products without the friction it imposed on outside vendors trying to access the same data. A law built to constrain the biggest platform in digital advertising left that platform in a stronger position relative to everyone smaller than it.
An industry built to help you comply
Wherever compliance costs rise, a market appears to help companies manage them. Governance, risk and compliance software is now a real product category with its own large, established vendors, among them ServiceNow, IBM, SAP, MetricStream, NAVEX and OneTrust, alongside identity verification, anti-money-laundering screening and newer AI governance platforms. Big Four accounting and major law firms generate real revenue from advisory work tied to regulatory complexity too. It’s tempting to conclude that this industry actively lobbies to keep rules complicated, and it’s a plausible incentive to point out. But that’s an inference about motive, not a documented claim, and there isn’t strong public evidence of coordinated lobbying for complexity as such. What’s better supported is the narrower fact: an entire commercial ecosystem now exists that would not exist if compliance were simple, and large companies can afford the best of it while smaller ones pay a proportionally higher price for the same protection.
Where compliance actually helps the small player
It would be dishonest to stop there, because compliance doesn’t always work against smaller companies. In business software, a certification called SOC 2 has become something closer to a bridge than a barrier. Enterprise buyers routinely refuse to sign with a vendor that can’t produce one, regardless of the vendor’s size. For an early-stage company with no brand recognition, a SOC 2 report is often the only way to convince a large customer that its data is safe in the hands of a team nobody has heard of. It replaces months of back-and-forth security questionnaires with a single third-party audit both sides trust. Industry estimates for a first-year SOC 2 report vary, but most cluster in the range of twenty to sixty thousand dollars and three to six months for a young company, which is real money for an early-stage team but is small next to the cost of losing an enterprise contract over a missing certification. Founders who complete it early frequently describe it less as a compliance cost and more as a growth requirement, on the same list as building a sales team or setting pricing.
This case sharpens the thesis rather than complicating it. Compliance hurts small companies when the requirement is expensive to meet and delivers no signal the market already values, as with GDPR’s data infrastructure requirements for a small ad-tech firm. It helps them when it substitutes for something the market was already demanding, in this case trust, and lets a small team prove it credibly instead of relying on a reputation they haven’t built yet. The line isn’t the size of the company facing the rule. It’s whether the fixed cost buys a return the market recognizes.
From obligation to advantage
Once a large company has built its compliance infrastructure, new regulation can stop being purely a cost and start becoming a tool. This isn’t a new observation. Economist George Stigler argued in 1971 that regulation is often acquired by the industry it targets and operated for that industry’s benefit, a theory now generally known as regulatory capture. The GDPR rollout offers a documented instance of the mechanism, not just the general pattern. In the weeks before the law took effect, the digital advertising trade group IAB Europe published its own industry-authored compliance standard, the Transparency and Consent Framework, meant to show publishers and ad vendors how to gather user consent within the law. Regulators did not accept it as sufficient. The UK’s data protection authority publicly called the framework inadequate, and in 2022 Belgium’s data protection authority ruled that it failed to meet GDPR’s own requirements. The legal fight that followed dragged on for years, through a 2022 referral to the EU’s top court, which ruled in 2024, and further Belgian court proceedings into 2026, with the two sides disputing exactly how much of the original finding survived on appeal. What isn’t in dispute is the years in between: the framework was the industry’s de facto standard from 2018 onward, adopted widely including by Google, giving cover to exactly the kind of large-scale data sharing the law was meant to constrain while the companies without the resources to build a rival framework had no comparable seat at the table. That’s the mechanism in miniature: firms with existing compliance infrastructure sit on the panels that write new technical standards, and lobbying for stricter rules can coexist comfortably with protecting market position, since a firm that has already paid the fixed cost has every reason to see that cost applied to its competitors too.
The next frontier is digital
Artificial intelligence regulation is a live test of whether this pattern repeats, and it’s no longer purely hypothetical. The EU’s AI Act is real law, not a proposal: it entered into force in 2024, and its rules on general-purpose AI models have applied since August 2025. Most of its transparency obligations, including disclosing AI-generated content and telling people when they’re talking to a chatbot, take effect this month as originally scheduled. One piece got its own grace period: watermarking requirements for AI content on systems already on the market got pushed to December 2026. The Act’s heavier obligations for high-risk systems, covering model documentation, bias testing, human oversight and provenance records for uses like hiring and credit scoring, were also supposed to land this month. They didn’t. A Digital Omnibus that the EU Council formally adopted on June 29, 2026 pushed those deadlines back to December 2027 for standalone high-risk systems and August 2028 for high-risk AI embedded in regulated products, after European standards bodies fell behind on finishing the technical benchmarks compliance was supposed to be measured against. There’s a small irony worth naming without overstating it: the rule got delayed because the compliance infrastructure needed to enforce it wasn’t ready in time, which is close to a live example of this piece’s own argument, just one step removed, since it’s regulators rather than companies who found the fixed costs of building the standard harder to absorb on schedule than expected. Whether the eventual rules end up entrenching the largest AI labs the way GDPR entrenched the largest ad platforms is still a forecast, not yet a documented outcome. Unlike older regulation, this framework is also being amended on a rolling basis even after taking effect, and it applies differently across jurisdictions, so a company selling one AI product globally may need separate compliance processes for the EU, the US, the UK, India and Australia at once.
What gets lost
Some of the cost of this system is hard to measure by nature: a product that’s never launched because the compliance math doesn’t work leaves no data trail to study. A related pattern is that developing economies often adopt regulatory frameworks modeled on wealthier countries, and local businesses can lack the resources to meet them in ways that leave multinational firms best equipped to operate under the new rules. That pattern is worth researching further. It is not a settled finding on the scale of the Dodd-Frank or GDPR data above, and it’s included here as a plausible extension of the mechanism rather than a proven instance of it.
None of this means regulation itself is the problem. Financial rules have prevented real harm. Privacy law has given people control over their data they didn’t have before. Food and drug safety standards have saved lives that would otherwise have been lost to preventable failures, and the FSMA data above still represents farms paying to prevent contamination that has sickened and killed people in the past. The honest conclusion is not that rules are bad. It’s that nearly every rule has a distributional effect that goes undebated when the rule is proposed, and that effect tends to run toward whoever was already largest before the ink dried.
The real competitive question
For most of the last century, the central question for a business was whether it could build something people wanted. That question hasn’t disappeared, but it now sits behind a longer one: can this be built, launched and operated legally, in every market it needs to reach, under rules that are still being written and that change every year.
The public debate around a new regulation is almost always about whether it will control a big company. The private effect, based on the clearest cases we have, is that the rule frequently becomes something only a big company can fully satisfy, which is the question worth asking about the next one before it passes.
