In regulated markets, “compliance” is not the goal.
The goal is to turn regulatory change into timing advantage: lower cost of capital, faster distribution, cleaner partnerships, and higher switching costs.
2026 is shaping up to be a hinge year because multiple regimes are moving from framework to enforcement + operationalization across payments, AI, data, resilience, and platform distribution.
Below are the five debates that matter most worldwide for US-based tech and financial services leaders - and a practical way to map, prepare, influence, and get ahead.
1) Payment stablecoins: issuer perimeter, reserve rules, and distribution control
What’s being decided
Stablecoins stopped being a “crypto category” and became a payments and settlement perimeter.
Across jurisdictions, regulators are converging on three levers:
Issuer eligibility: Who is allowed to issue “payment stablecoins” at scale.
Reserve composition + redemption rights: What reserves must be held, how they’re disclosed, and what happens in stress.
Distribution and embedded rails: Whether stablecoins become rails inside platforms (wallets, exchanges, marketplaces, fintech apps) or remain ring-fenced.
Europe has already set a two-step reality under Markets in Crypto-Assets Regulation (MiCA): stablecoin-related rules for Electronic Money Tokens (EMTs) and Asset-Referenced Tokens (ARTs), applied from 30 June 2024, and MiCA became fully applicable from 30 December 2024.
In the US, the policy direction hardened into statute: the GENIUS Act was enacted as Public Law 119–27 on July 18, 2025 to regulate payment stablecoins. Globally, the Financial Stability Board (FSB) is explicitly flagging gaps and inconsistencies in implementation, creating arbitrage and oversight risk.
The economic shift
Stablecoins compress margins where the “old tolls” were distribution-friction tolls (cross-border, settlement delay, intermediated liquidity).
The profit pool migrates to: trusted issuance + governance, distribution access, and compliance operations that large counterparties can underwrite.
How to map it (board-level, not legal-level)
Build a one-page “stablecoin operating map”:
Issuance path: do you issue, partner, or avoid?
Reserves: who holds them, what instruments, what audit cadence?
Redemption: what is guaranteed, when, and under what conditions?
Distribution: which channel truly controls the customer?
Compliance: sanctions, AML monitoring, incident response, reporting.
If your answers depend on “we’ll figure it out once we scale,” you’re already behind. Regimes are being designed to prevent exactly that.
How to prepare (what creates moat, not just compliance)
Make controls a product capability.
Operational proof beats marketing claims: reserve reporting, reconciliation, exception handling, and tested redemption workflows.
Design distribution defensibly: the winner is usually the firm that owns a durable channel and can pass bank-grade due diligence, not the one with the best token design.
How to influence
Regulators listen to operational evidence: fraud rates, false positives, redemption behavior, reserve constraints and their consumer pricing impact.
Bring data. Propose executable standards. That is influence.
The moat
In stablecoins, the moat is old-fashioned: license + trust + distribution + low-cost compliance.
Once enterprises and banks standardize on a short list of issuers and on/off-ramps, switching becomes painful and reputationally risky.
2) AI governance: accountability, auditability, and the “right to operate” in high-stakes workflows
What’s being decided
The core question is not model performance.
It’s liability and governance: who is accountable when AI makes or shapes a decision.
The EU AI Act is the clearest global signal because it’s already on a phased timeline: entered into force August 1, 2024, first requirements applied February 2, 2025, GPAI obligations apply August 2, 2025, and it becomes fully applicable August 2, 2026 (with some longer transitions). Even if you are US-first, your enterprise customers will import this into procurement and risk committees.
In the US, the debate iss about who sets the rules and where liability lands: federal agencies and Congress versus a growing patchwork of state laws. That federal–state tension is now explicit policy: a December 11, 2025 White House executive order directs DOJ to stand up an AI Litigation Task Force to challenge state AI laws deemed inconsistent with national policy, while states keep moving anyway - Colorado, for example, pushed its AI Act compliance date to June 30, 2026.
At the same time, the US is building AI governance through impact-assessment proposals + enforcement + standards rather than one statute. The Algorithmic Accountability Act of 2025 (S.2164) would push the Federal Trade Commission (FTC) toward mandatory impact assessments for automated decision systems, and the FTC is already policing “AI-washing” via Operation AI Comply.
In US consumer finance, the Consumer Financial Protection Bureau (CFPB) has been explicit that using complex or “black-box” models does not reduce a lender’s obligations: if a credit decision triggers adverse action, lenders still must provide specific and accurate reasons under the Equal Credit Opportunity Act and Regulation B.
Separately, many enterprise buyers are converging on the National Institute of Standards and Technology (NIST) Artificial Intelligence Risk Management Framework (AI RMF) and its Generative Artificial Intelligence Profile as a practical baseline for “reasonable controls” in procurement and diligence.
And in securities markets, the Securities and Exchange Commission (SEC) withdrew its proposed rule on conflicts tied to “predictive data analytics,” a reminder that prescriptive rulemaking on AI will likely remain uneven across financial domains.
The economic shift
AI is moving from “software spend” to “risk-managed automation.”
The biggest winners are not the firms with the most impressive demos. They are the firms that can operate AI in regulated contexts:
credit decisions, fraud and AML
customer communications
debt collection / receivables management
trading/risk analytics.
How to map it
Inventory AI by decision impact, not by model vendor.
For every AI-enabled workflow, document: What decision does it influence? What is the harm if wrong? Where is human override? What evidence can you produce after the fact?
Then score “auditability”: Can you reproduce outputs later? Can you explain in plain language why the output happened? Can you show monitoring, drift detection, and incident response?
How to prepare
Treat governance as an engineering discipline:
Decision logs + lineage by design: Versioning, prompts/configs, model changes, data provenance.
Monitoring tied to harm, not vanity: False positives, false negatives, escalation rates, complaint rates, loss events.
Kill switches and degraded modes: Rollback paths, “rules-based fallback,” and documented triggers.
Vendor contracts that match your risk: Audit support, disclosure of material changes, security commitments.
How to influence
The best influence is preventing unworkable rules.
Share operating data on override rates, drift timelines, and error cost. Help define what “reasonable controls” look like in real systems.
The moat
The moat is not “the model.”
It’s the ability to sell AI into regulated environments with low friction: audit artifacts, credible controls, board-ready incident response.
That becomes a distribution advantage.
3) Data sovereignty and cross-border transfers: data architecture becomes strategy
What’s being decided
Whether you can move data across borders reliably and what the default constraints are when you cannot.
The EU-US Data Privacy Framework adequacy decision is in force from July 10, 2023. In September 2025, the EU General Court dismissed a challenge to that adequacy decision, reinforcing its legal footing (at least for now). Inside the EU, security obligations are tightening with NIS2; Member States had to transpose it by October 17, 2024.
China is adding new requirements for certifying outbound personal data transfers, with rules scheduled to take effect January 1, 2026.
India notified DPDP Rules, 2025 in November 2025, moving from law to operational compliance reality.
The economic shift
Data constraints change unit economics through: higher infra duplication, regionalization cost, model performance loss from fragmented datasets, slower launch cycles, vendor and subprocessor risk.
Most firms underestimate where they truly move data: observability tooling, customer support systems, analytics SDKs, fraud/identity vendors.
How to map it
Build a “data flow map” that answers:
Which data is business-critical? Identity, transaction, device/behavioral signals, biometrics, support transcripts.
Where does it live and who touches it? Cloud regions, vendors, subprocessors, logging/monitoring tools.
What is your transfer mechanism per flow? Adequacy, contractual mechanisms, local processing, certification regimes.
How to prepare
Architect for jurisdictional variance:
Regional data planes with a shared control plane: Keep sensitive data local when needed, manage policy centrally.
Encryption + key separation by jurisdiction: Often the difference between “acceptable” and “not acceptable.”
Data minimization as a performance strategy: Less collection and transfer reduces exposure and cost.
Vendor contracting as risk control: Audit rights, subprocessor transparency, portability, breach reporting timelines.
How to influence
Localization debates often ignore operational trade-offs.
Operators can influence by quantifying: fraud outcomes under localized vs global models, security implications, real costs and launch delays.
The moat
A resilient global data architecture is a fixed-cost capability.
Smaller competitors struggle to replicate it, and large enterprises prefer partners who can expand internationally without creating compliance debt.
4) Operational resilience and third-party oversight: regulators are supervising your vendors
What’s being decided
Regulators are moving up the supply chain because concentrated tech dependencies behave like systemic risk.
In the EU, DORA has applied since January 17, 2025. In November 2025, the European Supervisory Authorities designated critical ICT third-party providers under DORA’s oversight framework.
In the US, capital markets expectations tightened via SEC cybersecurity disclosure rules adopted July 26, 2023: Item 1.05 Form 8-K is generally due four business days after materiality determination.
The economic shift
“Vendor risk management” is shifting from checkbox compliance to operational truth: tested recovery, provable controls, and credible disclosure readiness.
If you sell to financial institutions, you are now in their regulator’s line of sight.
How to map it
Create a “critical services register”:
Which services cannot fail without stopping money movement or risk controls? Payments, authentication, KYC, fraud scoring, core ledger, market data.
Which vendors power them? Cloud, identity, network, data providers, devops tooling.
What is the real recovery plan - and has it been tested?
How to prepare
Resilience is built, not asserted:
Design for failure and degraded modes: Not just multi-region. Also: partial operation, queueing, manual fallback.
Prove recoverability: Exercises with executives, runbooks, postmortems that change architecture.
Treat reporting as part of incident response: Speed to a materiality view and credible communication is now a discipline, not a PR scramble.
How to influence
Regulators overcorrect after high-profile outages.
You influence by showing what tests and metrics correlate with real resilience, and what timelines produce signal instead of noise.
The moat
Operational trust compounds: faster procurement, better partnership terms, lower insurance friction, and fewer deal-killing diligence surprises.
For vendors, “audit-ready resilience” is a product feature that earns premium pricing.
5) Digital competition regimes: distribution, defaults, and platform taxes
What’s being decided
Competition regimes are regulating the choke points that determine CAC and margin: app store rules, anti-steering, default settings, interoperability, data combination.
In the EU, gatekeepers had to comply with DMA obligations as of March 7, 2024. The European Commission fined Apple (€500m) and Meta (€200m) for DMA breaches in April 2025 In the UK, new CMA responsibilities under the Digital Markets, Competition and Consumers Act 2024 came into force from January 2025.
In the United States, there isn’t an EU-style ex-ante “gatekeeper rulebook” like the Digital Markets Act; instead, platform competition is being shaped through antitrust litigation and targeted bills, which makes timing and remedies less predictable but still economically meaningful. The DOJ sued Apple in March 2024, alleging monopolization tied in part to Apple’s control over iPhone app distribution and platform access points. In parallel, major DOJ cases against Google are pushing the conversation toward behavioral remedies rather than structural breakups.
On the legislative side, Congress is actively revisiting app-store rules via the Open App Markets Act (S.2153) and the App Store Freedom Act (H.R.3209), both aimed at reducing gatekeeper control over distribution and in-app payments.
The economic shift
For fintech and payments, distribution is often mediated by: mobile OS defaults, wallet access, in-app payment rules, identity and authentication rails.
Rule changes can directly move: take rates, conversion, and the feasibility of alternative checkout/payment routing.
How to map it
For each major channel, answer:
What is the effective platform tax? Fees + rules + friction.
Where do defaults lock behavior? Wallet default, browser default, payment default.
What is your escape hatch? Web funnel, enterprise partnerships, embedded distribution, multi-rail payments.
How to prepare
Build distribution optionality:
Multi-channel acquisition as a hedge: Direct web funnels, partnerships, embedded distribution.
Payment and identity modularity: So you can pivot quickly when platform rules change.
Compliance-to-execution speed: When a regulatory window opens, first movers capture habits and partner shelf space.
How to influence
Competition authorities respond to evidence.
Bring measurable impacts: fee incidence on end prices, conversion losses from steering restrictions, security/fraud implications of forced design choices.
The moat
In distribution regimes, the moat is execution speed plus partner lock-in.
When rules shift, the first credible operator becomes the default option for enterprises and ecosystems trying to reduce risk.
BONUS debate: Data centers + energy as a regulatory constraint on AI scale
What’s being decided
This isn’t “energy policy.” It’s who gets permission to add large, always-on load - and on what terms (location, interconnection priority, on-site generation, reporting, efficiency, water).
In the United States, the U.S. Department of Energy (DOE) and Lawrence Berkeley National Laboratory (LBNL) have already put the core numbers on the table: data centers were ~4.4% of U.S. electricity use in 2023 and could reach 6.7%-12% by 2028 (176 TWh → 325–580 TWh).
As load pressure rises, regulators are responding through grid process and access rules, most visibly via the Federal Energy Regulatory Commission (FERC) interconnection reforms (Order 2023), which aim to change how projects enter and move through queues.
In Europe, the debate is becoming more explicit: the revised European Union (EU) Energy Efficiency Directive (EED) introduces mandatory monitoring and reporting of data center energy performance into a European database. And some countries are effectively turning grid access into a gating mechanism: Ireland’s Commission for Regulation of Utilities (CRU) policy requires new data centers seeking grid connection to provide new renewable and dispatchable generation (a direct “you bring supply if you want load” rule).
Why it matters for tech and finance leaders
AI scaling is becoming a two-input problem: compute and deliverable megawatts. When megawatts become scarce, the scarce asset earns the rent. That rent shows up as higher capex, longer timelines, more contractual complexity, and - critically - regulatory risk that sits outside your product roadmap.
For financial institutions and investors, it changes underwriting: execution risk is no longer “can you build the building,” it’s “can you secure power on schedule, under evolving rules, without blowing covenants.”
How to map it
Create a “Power-to-Compute” map for every AI growth plan:
Load profile: peak MW, baseload vs burst, and flexibility (can you shift inference / do demand response?).
Access path: interconnection status, queue position, and realistic timeline under the relevant grid operator.
Constraint set: permitting, water/heat rules, reporting obligations (EU EED-style), and local zoning.
Supply strategy: grid-only vs co-located generation vs on-site backup/batteries (and what regulators require, as in Ireland).
Commercial structure: PPAs, take-or-pay, curtailment clauses, and who bears delay risk.
How to prepare
Treat “secured power” as a product capability, not a real-estate detail.
Build load flexibility into architecture (it reduces your marginal cost of compliance and improves siting options). Design contracts and financing around delay as a base case, not a tail risk. If you operate internationally, standardize energy and water performance reporting so EU-style disclosure doesn’t become a scramble later.
How to influence
This is one of the few areas where operator input can materially shape outcomes because regulators are trying to separate real projects from speculative ones and reduce systemic bottlenecks.
Engage where rules are written: interconnection proceedings, utility commissions, local permitting - bringing operational data on timelines, curtailment behavior, and reliability needs.
The moat
In 2026, “AI scale” will increasingly be gated by regulatory permission to consume power.
In the data center + energy debate, the moat is having permissioned, financeable power - and the operational ability to keep it.
That moat is built from a small set of hard-to-copy assets: an interconnection path that’s real and executable (not just an application in a queue), sites where permitting is already de-risked so approvals don’t drag out for 12–24 months, power contracts that are truly bankable under grid volatility (PPAs with realistic curtailment and delay terms, plus clear take-or-pay allocation), and load flexibility in the stack (demand response, workload shifting, efficiency) that makes your facility easier to approve and cheaper to operate on constrained grids.
Putting it simply, the moat is the ability to secure megawatts reliably - faster, cleaner, and with less execution risk - than the next competitor.
The competitive payoff is simple: when power becomes the bottleneck, firms that can secure megawatts reliably ship AI capacity earlier, sign longer enterprise contracts with confidence, and price risk lower, while competitors get trapped in permitting, queues, and renegotiations.
The operating system: how to convert regulatory change into competitive advantage
Most companies lose because they treat regulation as a legal inbox.
Winning firms build a lightweight machine that turns policy into decisions.
A practical setup for 2026:
One owner per theme: Business owns it. Legal supports. Risk signs off.
A monthly “Regulatory Radar” (one page each): What changed? What might change next? What it does to unit economics? What decisions it forces this quarter?
Scenario math, not narrative debates: Base case, fast enforcement case, fragmented-jurisdiction case. Then quantify: cost, CAC, margin, time-to-market, capital/risk buffers.
Apply the Kelly Criterion to those scenario-weighted outcomes: treat each regulatory bet (market entry, product launch, vendor dependency, lobbying spend) as a portfolio position sized by expected value and downside volatility, not conviction.
Build “compliance as product capabilities”: Audit logs, governance tooling, resilience runbooks, data controls, reporting readiness. These reduce sales friction and raise competitor costs.
Influence early with operational evidence: Comment letters and consultations matter most when you bring real metrics and real failure modes.
Final takeaway
Regulatory debates don’t “arrive” all at once. They tip, then they propagate through procurement, bank partner due diligence, auditor expectations, and eventually enforcement. By the time the headlines are loud, the economics have already shifted.
The practical play is to treat regulation as a portfolio of constraints you can design around early.
If you build issuance and compliance rails before stablecoin rules harden, you get distribution partners first.
If you make AI auditability and governance real before buyers demand it, you win the RFPs that define categories.
If you engineer data flows for cross-border friction before localization hits, you expand faster while others stall.
If you operationalize resilience before regulators and markets force it, you lower your cost of capital and shorten sales cycles.
If you build distribution optionality before platform rules change, you capture upside without rewriting your stack.
And if you secure permissioned power, you don’t just scale AI, you control the timeline.
In other words: this is not about “keeping up.” It’s about buying time. Time to ship, time to partner, time to compound trust.
In 2026, that time advantage will be the moat, built on barriers your competitors can’t cross cheaply.
𝘈𝘯𝘺 𝘷𝘪𝘦𝘸𝘴 𝘰𝘳 𝘴𝘵𝘢𝘵𝘦𝘮𝘦𝘯𝘵𝘴 𝘦𝘹𝘱𝘳𝘦𝘴𝘴𝘦𝘥 𝘢𝘳𝘦 𝘮𝘪𝘯𝘦 𝘢𝘯𝘥 𝘯𝘰𝘵 𝘵𝘩𝘰𝘴𝘦 𝘰𝘧 𝘮𝘺 𝘦𝘮𝘱𝘭𝘰𝘺𝘦𝘳
Thanks for reading Allan's Substack! Subscribe for free to receive new posts and support my work.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.