Paper deep dive
Scaling, Lock-In, and Proxy Compliance: A Political Economy of Responsible AI
Florian A. D. Burnat, Brittany I. Davidson
Intelligence
Status: succeeded | Model: Gemma-4-26B-A4B | Prompt: intel-v1 | Confidence: 95%
Last extracted: 8/3/2026, 9:29:34 AM
Summary
The paper 'Scaling, Lock-In, and Proxy Compliance: A Political Economy of Responsible AI' by Florian A. D. Burnat and Brittany I. Davidson presents a sequential political-economy model explaining the gap between formal AI compliance and actual harm reduction. The authors argue that AI vendors often engage in 'proxy compliance,' where they satisfy observable procurement requirements (auditability) while providing insufficient substantive mitigation. This equilibrium is sustained by deployer lock-in (switching costs), which weakens monitoring incentives, and evidence-dependent enforcement mechanisms. The study identifies independent audit rights, portability, incident reporting, and outcome-linked liability as key policy levers to restore accountability and mitigate post-deployment harms.
Entities (9)
Relation Signals (7)
Florian A. D. Burnat → affiliatedwith → University of Bath
confidence 99% · University of Bath, Bath, UK. Email: fadb20@bath.ac.uk.
Brittany I. Davidson → affiliatedwith → University of Bath
confidence 99% · University of Bath, Bath, UK. Email: bid23@bath.ac.uk.
Independent Audit Rights → mitigates → Proxy Compliance
confidence 95% · Independent audit rights raise enforcement exposure directly
Outcome-Linked Liability → createsincentivesfor → Substantive Mitigation
confidence 93% · outcome-linked liability creates incentives that do not depend on vendor-controlled detection
Proxy Compliance → causedby → Switching Costs
confidence 92% · Lock-in reduces monitoring; weaker monitoring lowers verifiable detection; and lower enforcement exposure reduces the vendor’s return to substantive mitigation.
Portability → restores → Deployer Leverage
confidence 91% · portability restores deployer leverage
Proxy Compliance → characterizedby → Visible Compliance
confidence 90% · visible compliance can coexist with low mitigation
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Abstract:AI accountability at scale is an institutional problem: who can observe, verify, and change deployed systems. We develop a sequential political-economy model in which an AI vendor chooses auditability and substantive mitigation, a deployer monitors after adoption while facing switching costs, and enforcement depends on verifiable evidence. Anticipating the deployer's monitoring response, the vendor may stop at an observable procurement floor while mitigating below the social first best, producing a proxy-compliance equilibrium. We characterize the unique interior equilibrium and the corner in which harm is fully mitigated. Independent audit rights raise enforcement exposure directly; portability restores deployer leverage; incident reporting adds a regulator-visible evidence channel; and outcome-linked liability creates incentives that do not depend on vendor-controlled detection. The results explain why documentation and standardized evaluations can coexist with persistent post-deployment harms, and generate testable implications for monitoring, mitigation, and the gap between formal compliance and operational outcomes.
Tags
Links
- Source: https://arxiv.org/abs/2607.28023v1
- Canonical: https://arxiv.org/abs/2607.28023v1
Trouble viewing inline? Open PDF directly →
Full Text
59,999 characters extracted from source content.
Expand or collapse full text
Scaling, Lock-In, and Proxy Compliance: A Political Economy of Responsible AI Florian A. D. Burnat ∗ Brittany I. Davidson † 30 July 2026 Abstract AI accountability at scale is an institutional problem: who can observe, verify, and change deployed systems. We develop a sequential political-economy model in which an AI vendor chooses auditability and substantive mitigation, a deployer monitors after adoption while facing switching costs, and enforcement depends on verifiable evidence. Anticipating the deployer’s monitoring response, the vendor may stop at an observable procurement floor while mitigating below the social first best, producing aproxy-compliance equilibrium. We characterize the unique interior equilibrium and the corner in which harm is fully mitigated. Independent audit rights raise enforcement exposure directly; portability restores deployer leverage; incident reporting adds a regulator-visible evidence channel; and outcome-linked liability creates incentives that do not depend on vendor-controlled detection. The results explain why documentation and standardized evaluations can coexist with persistent post-deployment harms, and generate testable implications for monitor- ing, mitigation, and the gap between formal compliance and operational outcomes. Keywords:Responsible AI; algorithmic auditing; AI governance and accountabil- ity; lock-in and switching costs. ∗ University of Bath, Bath, UK. Email: fadb20@bath.ac.uk. † University of Bath, Bath, UK. Email: bid23@bath.ac.uk. arXiv:2607.28023v1 [cs.CY] 30 Jul 2026 1Introduction Motivating puzzle.Responsible AI checklists, model cards, conformity documenta- tion, and standardized evaluations have become common; however, recurring harms and accountability gaps remain. Four observations sharpen this puzzle.First, the EU AI Act places extensive documentation and risk-management obligations on providers, but many relevant inputs—training data, evaluation protocols, red-team logs, and ac- cess conditions—remain under provider control (Veale and Zuiderveen Borgesius, 2021; Schuett,2023).Second, independent reproduction of vendor-reported safety and fair- ness claims is often infeasible under black-box or contractually restricted access (Mitchell et al.,2019; Mokander et al.,2023; Casper et al.,2024).Third, audits can be scoped around negotiated data, metrics, and publication rights rather than independently im- posed tests (Raji and Buolamwini, 2019; Costanza-Chock et al.,2022).Fourth, once a deployer has integrated a model into workflows, fine-tuning pipelines, prompt libraries, and downstream tooling, switching providers can be costly. Evidence from frontier-AI firms’ voluntary commitments is consistent with the resulting gap between visible report- ing and underlying performance (Wang et al.,2025). The puzzle is therefore not merely why organizations fail to implement an otherwise complete ethics framework, but why visible compliance and limited mitigation may coexist as rational choices. Thesis.We argue that proxy compliance can arise when enforcement requires verifiable evidence, the vendor controls part of the evidence-generating infrastructure, and post- integration switching costs weaken the deployer’s recourse. Lock-in reduces monitoring; weaker monitoring lowers verifiable detection; and lower enforcement exposure reduces the vendor’s return to substantive mitigation. Lock-in is an amplifier rather than a necessary primitive; constrained independent detection can sustain the mechanism even when switching costs are moderate. Contributions.First, we develop a vendor–deployer model in which auditability, mit- igation, and monitoring are endogenous, conditional on institutional parameters for pro- 1 Table 1: Main results and policy interpretation. Formal derivations are in the appendices. Result Formal claimInstitutional interpretation Prop.4.4weak baseline detection plus high lock- in yields proxy compliance visible compliance can coexist with low mitigation Prop.4.5more independent detection or less lock- in raises mitigation accountability needs evidence and credi- ble recourse Thm.5.1sufficiently strong audit rights work at any lock-in level independent evaluation can bypass de- ployer weakness Prop.5.2portability raises mitigation through monitoring standards restore deployer leverage Prop.5.3incident reporting adds an independent evidence channel credible reports reduce dependence on vendor-gated access Prop. 5.4outcome-linked exposure raises mitiga- tion independently of detection liability retains bite when verification is weak curement, switching costs, and enforcement. Second, we solve the sequential game while allowing the vendor to anticipate how mitigation changes the deployer’s monitoring re- sponse. This yields a unique interior equilibrium, a transparent full-mitigation corner, and policy comparative statics. Third, we connect the formal levers to current gover- nance institutions and specify empirical measures and settings in which the mechanism can be tested. The contribution is a tractable institutional explanation of the gap between observable responsibility signals and harm reduction, not a claim that any single gover- nance instrument is sufficient. In this paper, scale is the institutional setting rather than an endogenous variable; the formal analysis isolates how auditability, switching costs, and evidence-dependent enforcement shape mitigation once AI systems are embedded in organizational workflows. Roadmap.Section2positions the argument. Section3introduces the model. Section4 characterizes the equilibrium. Section5studies policy levers and welfare. Section6 develops empirical implications, and Section7discusses the scope and limitations. 2Related Work This argument relates to responsible AI governance, algorithmic auditing, the economics of switching costs and lock-in, and the political economy of regulation under asymmetric 2 information. Responsible AI as institutional practice.A growing body of work documents the gap between Responsible AI principles and practice. Jobin et al. (2019) survey 84 AI ethics guidelines, finding convergence on high-level principles but divergence in inter- pretation and a near-universal absence of enforcement mechanisms. This landscape has been characterized as “ethics washing”—voluntary frameworks that create reputational benefits without constraining behavior (Hagendorff,2020). Raji, Kumar, et al. (2022) sharpen the diagnosis by cataloging functionality failures that no current audit regime reliably detects, and ML research incentives empirically select against harm-reduction methodology (Birhane et al.,2022)—both findings consistent with a system in which signals of responsibility are easier to produce than the underlying substance. Crawford (2021) maps the political economy of AI production, documenting how concentration of compute, data, and infrastructure creates the power asymmetries that enable this dy- namic. At the organizational level, internal accountability practices are shaped more by what is demonstrable to external audiences than by what effectively reduces harm (Raji, Smart, et al., 2020; Moss et al.,2021). Selbst et al. (2019) identify “abstraction traps”— when responsible AI is operationalized through portable, formalized metrics detached from deployment context, it produces the appearance of compliance without addressing situated harms. In our model, proxy compliance is the equilibrium where observable signals are cheaper than substantive mitigation and enforcement depends on verifiable evidence. Signaling and corporate social responsibility.The mechanism we labelproxy com- pliancehas a well-developed formal ancestor in the economics of signaling and corporate social responsibility. Bénabou and Tirole (2010) decompose visibly responsible behavior into intrinsic, material, and reputational-signaling motives, and show that in equilib- rium the observable action can dominate the unobservable effort when audiences con- dition on the action alone—even when the two are conceptually distinct. This is the structure we specialize: when deployers, regulators, and civil society condition onob- 3 servabledocumentation and standardized evaluations, vendors face an incentive problem in which producing the visible signal is strategically separable from substantive harm reduction. The contribution relative to Bénabou and Tirole (2010) is domain-specific: we embed the signaling mechanism in a vendor–deployer–regulator game with switching costs and evidence-based enforcement, and derive comparative statics for policy levers that are specific to the AI value chain (audit rights, portability, incident reporting, and outcome-linked liability) rather than generic CSR. Recent empirical work on frontier-AI firms’ voluntary White House commitments documents widespread partial compliance and reporting-via-marketing (Wang et al.,2025)—a pattern our equilibrium predicts when audit rights and portability are weak. Audits, evaluation, and verifiability.Algorithmic auditing has been proposed as a key accountability mechanism (Sandvig et al.,2014; Raji and Buolamwini,2019); how- ever, it faces structural limitations when vendors control access. Mökander et al. (2022) provide a taxonomy of audit types that underwrites our auditability variable푡: their distinction between vendor self-assessment and third-party conformity assessment maps directly onto the detection function푝(푡, 푚). The auditing ecosystem itself lacks stan- dardization, independence guarantees, and enforcement power (Costanza-Chock et al., 2022); Floridi et al. (2022) propose an operational conformity-assessment procedure (ca- pAI) whose feasibility rests on the same vendor cooperation that our model treats as endogenous. For large language models, auditability constraints are severe (Mokander et al.,2023): model opacity, generality, and absent harm benchmarks. Documentation standards such as model cards (Mitchell et al.,2019) are necessary but insufficient—they are only as reliable as the information vendors choose to include, making them vulner- able to strategic disclosure. Wachter et al. (2021) provide the doctrinal ground for this limitation: automated compliance checks are evidentiarily incomplete substitutes for con- textual legal assessment, which justifies treating푝(푡, 푚)as a proxy rather than a truth function. In our framework, these observations correspond to the detection probability 푝(푡, 푚)being substantially vendor-determined, giving vendors scope to limit auditabil- ity and thereby constrain enforcement. Casper et al. ( 2024) show that black-box API 4 access isinsufficientfor rigorous audits of frontier systems—internal access to weights, training data, and evaluation logs is required for safety and fairness claims to be credi- bly tested. Consistent with this, Burnat and Davidson (2026) document concrete “audit blind-spots” across major platforms (X, Reddit, TikTok, Meta) where API restrictions block the independent verification that transparency mandates presume—an empirical instance of vendor-controlled푝(푡, 푚). Raji, Xu, et al. (2022) argue on this basis for a de- signed third-party audit ecosystem with enforcement powers, and Schuett (2025) argues for a standing internal-audit function inside frontier-AI firms with direct board access. Our model treats the auditability variable푡as precisely the lever these authors identify: moving from vendor-gated black-box evaluation toward independent internal access raises 푝(푡, 푚)at the margin and, under conditions we characterize, tips the equilibrium from proxy compliance to accountability. Market structure, lock-in, and bargaining power.The economics of switching costs provides the foundation for our lock-in mechanism. Switching costs give firms ex post market power over locked-in customers (Klemperer, 1995), and dynamic competi- tion with switching costs leads to an “invest then harvest” pattern (Farrell and Shapiro, 1988). Network externalities create self-reinforcing concentration (Katz and Shapiro, 1985), which in AI manifests as ecosystem lock-in around dominant foundation-model providers; foundation-model scale concentrates development capacity among a few well- resourced actors (Bender et al., 2021), supplying the market-structure precondition for the switching cost푠we formalize. “Openness” in AI is often strategically deployed to con- solidate rather than democratize power (Widder et al.,2023), and regulatory compliance costs can paradoxically reinforce concentration (Engler,2023). Procurement frameworks are poorly suited to evaluating AI systems (Mulligan and Bamberger,2019), weakening deployer-side discipline even before lock-in takes effect. Our model integrates these in- sights: switching cost푠dampens effective recourse from monitoring, removing the market discipline that would otherwise incentivize vendor mitigation. 5 Evidence-based enforcement.The political economy of regulation under asymmet- ric information is well established: regulation may be captured by industry (Stigler,1971); principal-agent rents distort outcomes when information is asymmetric (Laffont and Ti- role,1993); and optimal enforcement institutions depend on the power asymmetry be- tween regulators and firms (Glaeser and Shleifer,2003). Intermediary auditors can them- selves be captured, reducing rather than raising oversight effectiveness (Tirole,1986). The choice between liability and safety regulation depends on information structures (Shavell, 1984)—directly relevant to our comparison of evidence-based enforcement versus outcome- linked liability. In the AI context, the Act’s heavy reliance on vendor self-assessment and harmonized-standard compliance is well documented, as is its broader risk-management architecture (Veale and Zuiderveen Borgesius,2021; Schuett,2023). Subsequent 2024– 2025 scholarship has identified three structural weaknesses. First, scholarship on the AI Office, AI Board, and Scientific Panel flags under-resourcing relative to the Act’s eviden- tiary burden (Hacker et al.,2023; Novelli et al.,2025). Second, harmonized-standard delegation routes the regulator’s burden of proof through vendor-influenced standards bodies (Gornet and Maxwell, 2024; Laux et al.,2024). Third, the Fundamental Rights Impact Assessment adds a rights-based layer above conformity assessment, and incor- porating civil society into the audit ecosystem can guard against capture (Mantelero, 2024; Hartmann et al.,2025). The NIST AI Risk Management Framework’s generative- AI profile (National Institute of Standards and Technology,2024) is now the operational benchmark against which AI risk management is graded in practice. Pulling these threads together, evidence-based enforcement makes penalties contingent on detection probabil- ity, so vendors face an incentive to limit transparency whenever the marginal adoption benefit from auditability falls below the marginal increase in expected penalties. 3Model The model separates visible compliance from substantive mitigation . Auditability 푡 helps the vendor satisfy procurement requirements but also facilitates enforcement; mitigation푒 6 Proxy-compliance mechanism 푠 ↑⇒ 훿 eff ↓⇒ 푚 ∗ ↓⇒ 푝 ↓⇒ 푒 ∗ ↓⇒ 피[ℎ] ↑ Detection-independent policy channels Δ ↑,휇휌 ↑,휆 푂 퐹 푂 ↑ ⟹푒 ∗ ↑ Figure 1: Lock-in weakens the deployer-monitoring channel. Audit rightsΔ, effective incident-reporting coverage휌with sanction scale휇, and outcome-linked exposure휆 푂 퐹 푂 add enforcement channels that the vendor cannot suppress through ordinary auditability choices. Portability works by lowering푠. directly reduces harm. The deployer can monitor after adoption, but monitoring is valu- able only when evidence creates credible recourse. Switching cost푠weakens that recourse. Independent audit capacityΔ, reporting-generated exposure휇휌, and outcome-linked ex- posure휆 푂 퐹 푂 act through different institutional channels (Figure 1). 3.1Players and Timeline An institutional environment fixes the procurement floor ̄ 푡, evidence-based penalty scale휆퐹, independent audit capacityΔ, and switching-cost environment푠. The strategic subgame is: 1.The vendor chooses auditability푡 ∈ [0, 1]and mitigation푒 ≥ 0. 2.The deployer observes(푡, 푒), chooses adoption푎 ∈ 0, 1, and if adopting chooses monitoring푚 ≥ 0. Integration creates switching costs represented by푠. 3.Harmℎ ∈ 0, 1is realized. Evidence is generated with probability푝(푡, 푚), and the regulator applies the specified enforcement rule when actionable evidence exists. 3.2Risk, Detection, and Payoffs We condition on a common-knowledge risk parameter휃 ∈ (0, 1). Mitigation reduces the probability of harm,ℙ(ℎ = 1 ∣ 휃, 푒) = 푞(휃, 푒), and actionable evidence arises with probability푝(푡, 푚), which increases in both auditability and monitoring. The vendor earns adoption benefit퐵 > 0and incurs convex auditability and mitiga- 7 Table 2: Key notation. SymbolMeaning 푡, 푒, 푚vendor auditability, vendor mitigation, deployer monitoring 푠switching cost;훿 eff = 훿/(1 + 푠)is effective recourse 푞(휃, 푒)harm probability 푝(푡, 푚)vendor/deployer evidence-generation probability Δindependent audit exposure, added to푝 휆퐹evidence-based penalty scale 휇휌reporting-generated exposure (휌: effective coverage) 휆 푂 퐹 푂 outcome-linked exposure ̄ 푡procurement/compliance floor 휅deployer harm exposure 훼, 훽 sensitivity of detection to 푡, 푚 푘 푡 , 푘 푒 , 푘 푚 quadratic cost coefficients tion costs: 푈 푉 = 푎퐵 − 푐 푡 (푡) − 푐 푒 (푒) − 휆퐹 푞(휃, 푒) [푝(푡, 푚) + Δ].(3.1) Here푝 + Δis an enforcement-exposure index rather than necessarily a literal probability. The deployer obtains value푉, pays integration cost퐼and monitoring cost푐 푚 (푚), and can recover a fraction훿of harm exposure when evidence creates recourse. Lock-in reduces effective recourse to훿 eff = 훿/(1 + 푠): 푈 퐷 = 푎[푉 − 퐼 − 푐 푚 (푚) − 휅푞(휃, 푒)(1 − 훿 eff 푝(푡, 푚))] .(3.2) The regulator is represented through the institutional parameters(휆퐹 , Δ); Section5asks how changing those parameters alters equilibrium. 3.3Tractable Specification Assumption 3.1(Functional forms).For the comparative statics, 푞(휃, 푒) =max0, 휃 − 푒, 푝(푡, 푚) = 1 −exp(−훼푡 − 훽푚), and푐 푗 (푥) = 푘 푗 푥 2 /2for푗 ∈ 푡, 푒, 푚, with all cost and sensitivity parameters positive. 8 Assumption 3.2(Procurement threshold).Adoption occurs if and only if푡 ≥ ̄ 푡. The floor ̄ 푡is an exogenous procurement or certification requirement. We condition on adop- tion and state the vendor participation condition in AppendixA. We use subgame-perfect equilibrium: the deployer chooses monitoring after observing vendor actions, and the vendor anticipates that monitoring response. 4Equilibrium Analysis 4.1Deployer Monitoring Lemma 4.1(Deployer best response).For푞(휃, 푒) > 0and훿 eff > 0, the deployer has a unique interior monitoring choice푚 ∗ satisfying 푘 푚 푚 ∗ = 휅푞(휃, 푒)훿 eff 훽exp(−훼푡 − 훽푚 ∗ ).(4.1) Monitoring decreases with switching cost푠and increases with deployer harm exposure휅. Proof sketch.Marginal monitoring cost is increasing and marginal recourse is decreasing, giving a unique crossing. Implicit differentiation of (4.1) yields the signs. AppendixA gives the derivatives. Lock-in makes information less useful: when the deployer’s exit or compensation threat is not credible, evidence has less strategic value and monitoring falls. 4.2Vendor Choices Define the vendor’s marginal enforcement exposure after anticipating the monitoring response: 퐻(푡, 푚) ≡ 푝(푡, 푚) + (1 − 푝(푡, 푚)) 훽푚 1 + 훽푚 = 1 − exp(−훼푡 − 훽푚) 1 + 훽푚 . (4.2) Lemma 4.2(Vendor best response).Suppose adoption benefit퐵is large enough that the vendor meets the procurement floor. 9 (a)The vendor chooses푡 ∗ = ̄ 푡. (b)In the interior region푒 ∗ < 휃, mitigation satisfies 푒 ∗ = 휆퐹 푘 푒 [퐻( ̄ 푡, 푚 ∗ ) + Δ].(4.3) If the right-hand side reaches휃, mitigation clamps at푒 ∗ = 휃and harm is zero. Proof sketch.Higher푡beyond the procurement floor raises both cost and total detection, even after the induced fall in monitoring. For mitigation, implicit differentiation of (4.1) gives휕푚 ∗ /휕푒 = −푚 ∗ /[(휃 − 푒)(1 + 훽푚 ∗ )] < 0. Substitution adds(1 − 푝)훽푚 ∗ /(1 + 훽푚 ∗ ) to the direct detection term in퐻, yielding ( 4.3): the monitoring response is anadditional private returnto mitigation. The second derivative is negative; AppendixAgives the full derivation. Therefore, the vendor satisfies the visible requirement and stops increasing auditabil- ity, while choosing mitigation according to the expected enforcement exposure created by both auditability and deployer monitoring. 4.3Proxy Compliance and Accountability Definition 4.3(Proxy compliance).An equilibrium exhibitsproxy compliancewhen 푡 ∗ = ̄ 푡but푒 ∗ < 푒 퐹 퐵 , where the social first-best mitigation is 푒 퐹 퐵 =min1/푘 푒 , 휃. The equilibrium is characterized by 푡 ∗ = ̄ 푡,(4.4) 푒 ∗ =min 휃, 휆퐹 푘 푒 [퐻( ̄ 푡, 푚 ∗ ) + Δ] ,(4.5) 푘 푚 푚 ∗ = 휅(휃 − 푒 ∗ )훿 eff 훽exp(−훼 ̄ 푡 − 훽푚 ∗ ),(4.6) 10 Table 3: Equilibrium values in three institutional settings. Setting푠 Δ푚 ∗ 푒 ∗ 피[ℎ] 1. High lock-in, no audit 9 0 0.03 0.23 0.37 2. Portability only1 0 0.10 0.33 0.27 3. Combined reform1 1 0.00 0.60 0.00 with푚 ∗ = 0at the full-mitigation corner. In the interior, the right-hand side of (4.5) is strictly decreasing in푒through the monitoring response, so the equilibrium is unique. Proposition 4.4(Existence of proxy compliance).SupposeΔ = 0and baseline enforce- ment is weak enough that 휆퐹 푘 푒 (1 − exp(−훼 ̄ 푡)) < 푒 퐹 퐵 . Then there exists̄푠such that sufficiently high switching cost yields proxy compliance. As 푠 → ∞,푚 ∗ → 0and 푒 ∗ → 휆퐹 푘 푒 (1 −exp(−훼 ̄ 푡)). Proposition 4.5(Accountability under stronger institutions).Within the interior equi- librium: (a)푑푒 ∗ /푑Δ > 0, although monitoring feedback attenuates the direct effect; (b) 푑푒 ∗ /푑푠 < 0, so reducing switching costs raises mitigation; and (c) sufficiently strong independent detection reaches푒 퐹 퐵 , with portability reinforcing the transition. 4.4Worked Example Let휃 = 0.6,푘 푡 = 푘 푒 = 푘 푚 = 1,훼 = 훽 = 휅 = 훿 = 휆퐹 = 1, and ̄ 푡 = 0.2. Then푒 퐹 퐵 = 0.6. Solving (4.5)–(4.6) yields Table3. Portability alone produces a meaningful but incomplete improvement: Setting 2 moves above half of the first best but does not reach accountability. Under combined reform, the desired interior mitigation exceeds휃; harm is eliminated and the deployer no longer monitors because there is no residual harm to investigate. 11 0246810 Switching cost s 0.00 0.25 0.50 0.75 1.00 Independent-audit intensity Δ 12 3 Proxy-dominant Mixed Accountability e * =e FB /2 e * =e FB Figure 2: Illustrative regimes in the(푠, Δ)plane under the worked-example parameters. Proxy compliance formally includes every point below first best; for visualization, the lower region is labeledproxy-dominantwhen푒 ∗ < 푒 퐹 퐵 /2, the middle region is mixed, and the upper region reaches푒 퐹 퐵 . Markers correspond to Table 3. 4.5Comparative Statics The total equilibrium effects differ from partial effects because policy-induced mitigation changes monitoring. Higher푠lowers both monitoring and mitigation; higherΔ,휆퐹, or ̄ 푡raises mitigation and reduces residual monitoring; higher mitigation cost푘 푒 has the opposite effect; and higher deployer harm exposure휅raises monitoring and thereby mitigation. Appendix Dprovides derivatives and a summary table. 12 5Policy Levers and Welfare 5.1Audit Rights and Independent Evaluation Independent audit capacity raises enforcement exposure byΔwithout relying on deployer monitoring or ordinary vendor-controlled access. Theorem 5.1(Audit rights eliminate proxy compliance).For every fixed lock-in level푠 and휆퐹 > 0, a finite audit threshold ̄ Δ(푠)exists such thatΔ ≥ ̄ Δ(푠)yields푒 ∗ ≥ 푒 퐹 퐵 . A uniform sufficient condition is Δ ≥ 푘 푒 푒 퐹 퐵 휆퐹 . Thus sufficiently strong independent detection eliminates proxy compliance at any lock-in level. The exact threshold is lower because baseline detection and the monitoring-response term also contribute to mitigation. Audit rights are therefore the strongest single lever in the model, but their practical effect depends on genuinely independent access and credible enforcement rather than the formal existence of an audit process. 5.2Portability and Standards Proposition 5.2(Portability raises mitigation).Reducing switching cost푠raises equi- librium monitoring and mitigation and lowers expected harm. The effect is stronger when deployer harm exposure휅and monitoring productivity훽are high. Portability works indirectly: compatible interfaces, exportable artifacts, and credible re-tendering make exit and recourse more credible, raising the value of monitoring and, therefore, the vendor’s mitigation incentive. 5.3Incident Reporting Let휌 ∈ [0, 1]denote the effective coverage of a mandatory reporting channel: the proba- bility that a reportable incident reaches the regulator in actionable form. Let휇 > 0be 13 the associated enforcement-exposure scale. The vendor then faces additional expected exposure휇휌 푞(휃, 푒). Proposition 5.3(Incident reporting substitutes for vendor-gated evidence).Under ef- fective incident reporting, the mitigation condition becomes 푒 ∗ 푅 =min휃, 휆퐹 [퐻( ̄ 푡, 푚 ∗ 푅 ) + Δ] + 휇휌 푘 푒 .(5.1) Hence푒 ∗ 푅 > 푒 ∗ whenever휇휌 > 0and the baseline is below the mitigation corner. The product휇휌is deliberately aneffectivechannel: a nominal reporting duty with narrow scope, under-reporting, or weak follow-up contributes little. 5.4Outcome-Linked Liability Let휆 푂 퐹 푂 denote the exposure tied directly to realized harm rather than to the separate evidence-generation channel푝(푡, 푚). Proposition 5.4(Outcome-linked exposure raises mitigation).The mitigation condition becomes 푒 ∗ 퐿 =min휃, 휆퐹 [퐻( ̄ 푡, 푚 ∗ 퐿 ) + Δ] + 휆 푂 퐹 푂 푘 푒 ,(5.2) so any positive outcome-linked exposure raises mitigation below the corner. Its direct component is unaffected by vendor-controlled auditability. This is a stylized benchmark, not a claim that existing liability laws automatically observe or compensate for every harm. 5.5Welfare Social welfare equals adoption value minus expected harm and real resource costs. Below first best, an increase in independent audit exposure raises mitigation and lowers both harm and residual monitoring; therefore, its total welfare effect is positive. Portability has an additional trade-off: it raises beneficial mitigation but can also raise costly monitoring. The precise condition is stated in AppendixH. 14 5.6Mapping to Current EU Regulation The AI Act combines provider documentation and risk-management duties with differenti- ated conformity-assessment procedures. Article 43 and Annex VI permit internal-control routes for relevant classes of high-risk systems, while Articles 53 and 55 impose obliga- tions on general-purpose model providers and systemic-risk models; the AI Office has information and evaluation powers under Articles 91–93 (European Union,2024b). In the model, documentation that remains provider-controlled primarily affects푡, whereas regulator-controlled evaluation capacity raisesΔ. Article 40 of the Digital Services Act (DSA) provides an analogousΔ-raising design for very large online platforms and search engines (European Union, 2022b). Portability and interoperability duties under the Digital Markets Act (DMA) illustrate instruments that can lower switching costs, although they are not an AI-specific portability regime (European Union,2022a). AI Act Article 73 serious-incident reporting can create a휇휌 channel when reports are complete, actionable, and credibly enforced. The proposed AI Liability Directive was a fault-based evidentiary instrument centered on disclosure and rebuttable presumptions rather than the outcome-linked benchmark in Proposition 5.4; it was formally withdrawn in October 2025 (European Commission, 2025). The revised Product Liability Directive covers software and provides no-fault liability for defective products but still requires defect, damage, and causation (European Union, 2024a). It is therefore closer to, but not identical with, the model’s direct outcome- exposure channel. 6Predictions and Measurement Implications Because푡 ∗ = ̄ 푡, the model’s direct comparative statics concern monitoring, mitigation, and harm; claims about contract terms or documentation are institutional hypotheses motivated by the mechanism. 15 6.1Predictions 1.Lock-in weakens monitoring and mitigation.Greater integration depth and fewer credible alternatives predict lower monitoring, lower effective detection, and lower mitigation. 2.Visible compliance can remain stable while outcomes deteriorate.As푠rises, auditability remains pinned to the procurement floor, while mitigation falls, producing documentation without commensurate reductions in incident rates. 3.Independent access shifts operational effort.Exogenous increases in regulator or third-party evaluation capacity should narrow the gap between vendor-reported and independently measured performance and raise mitigation investment. 4.Portability is sector-dependent.Its effect should be largest where deployer harm exposure is high and monitoring technology is mature; audit rights should bind more strongly where those conditions are absent. 6.2Operationalization Auditability can be measured through contractual audit clauses, API evaluation terms, disclosure completeness, and third-party publication rights. Lock-in can be proxied by fine-tuned endpoints, provider-specific tool wrappers, checkpoint or prompt-format porta- bility, retraining costs, and observed switching. Independent exposure can be measured through regulator access, evaluation budgets, researcher-access programs, and enforce- ment actions. Candidate settings include medical-device AI, credit scoring, public-sector hiring, DSA audit and transparency records for very large online platforms (VLOPs), provider migration and re-tender data, and incident databases supplemented by AI Act Article 73 reports. Appendix Fdevelops the measurement strategy. 16 7Discussion and Limitations Audit is not a panacea.Third-party audit can itself become proxy compliance. Au- dits may operate as rational myths—adopted for legitimacy rather than demonstrated efficacy—and auditors and auditees can share an interest in the appearance of rigor (Suchman and Edelman,1996; Eckstein and Shapira,2024). In the model, ceremonial or captured auditing contributes little to effectiveΔ; independence, access, publication rights, and enforcement determine whether the threshold in Theorem5.1is reached. How central is lock-in?The mechanism does not require extreme switching costs. Lock-in matters because it disables a monitoring channel that could otherwise substitute for weak independent detection. When deployer harm exposure is low, monitoring is immature, or vendor-independent access is constrained, the system can remain near proxy compliance, even at moderate푠. Conversely, credible portability is powerful in high- exposure sectors with mature monitoring. Modeling scope.The model is deliberately static and single-vendor. The title’s ref- erences to “scaling” and “political economy” describe the motivating institutional envi- ronment, not endogenous scale or market structure. Switching cost, enforcement, and the procurement floor are parameters rather than outcomes of competition or regulatory choice. The common-knowledge risk benchmark omits private information; multidimen- sional harms, civil-society evidence production, adversarial misuse, multi-vendor compe- tition, and repeated reputation dynamics are left to extensions. These abstractions make the policy channels transparent but limit quantitative interpretation. Empirical status.The numerical example is illustrative rather than calibrated. The comparative statics generate hypotheses and measurement targets, not estimates of pol- icy effect sizes. Cross-sector variation in procurement floors, audit access, and integration depth can support empirical tests; however, those variables may be correlated with un- derlying risk and institutional capacity; therefore, identification requires careful design 17 rather than a simple cross-sectional comparison. 8Conclusion Responsible AI commitments can coexist with inadequate mitigation because visible com- pliance, verifiable evidence, and substantive harm reduction are distinct strategic goals. A vendor that controls ordinary auditability meets the procurement floor; a locked-in de- ployer monitors less; and evidence-dependent enforcement then supplies too little mitiga- tion incentive. Independent audit rights bypass the weakened monitoring channel, porta- bility restores deployer leverage, incident reporting creates regulator-visible evidence, and outcome-linked exposure retains bite when ordinary detection is weak. None are au- tomatically effective: audit independence, reporting coverage, credible sanctions, and sector-specific monitoring capacity determine whether formal rules change equilibrium behavior. The central policy implication is therefore institutional rather than procedural: accountability requires both verifiability and power to act on what is verified. AMathematical Derivations and Equilibrium Proofs Throughout this appendix, consider the interior region0 < 푒 < 휃and write 퐸(푡, 푚) ≡exp(−훼푡 − 훽푚) = 1 − 푝(푡, 푚),퐴 ≡ 휆퐹 푘 푒 . A.1Deployer Best Response Proof of Lemma4.1.The deployer’s first-order condition is 휕푈 퐷 휕푚 = −푘 푚 푚 + 휅푞(휃, 푒)훿 eff 훽퐸(푡, 푚) = 0, which is (4.1). Its second derivative is −푘 푚 − 휅푞(휃, 푒)훿 eff 훽 2 퐸(푡, 푚) < 0, 18 so the solution is unique. Let 퐺(푚; 푡, 푒, 푠, 휅) = 푘 푚 푚 − 휅(휃 − 푒)훿 eff 훽퐸(푡, 푚). At the optimum, use (4.1) to obtain 퐺 푚 = 푘 푚 + 휅(휃 − 푒)훿 eff 훽 2 퐸 = 푘 푚 (1 + 훽푚 ∗ ) > 0. Implicit differentiation gives 푚 ∗ 푒 = − 푚 ∗ (휃 − 푒)(1 + 훽푚 ∗ ) < 0,(A.1) 푚 ∗ 푡 = − 훼푚 ∗ 1 + 훽푚 ∗ < 0,(A.2) 푚 ∗ 푠 ∣ 푒,푡 = − 푚 ∗ (1 + 푠)(1 + 훽푚 ∗ ) < 0,(A.3) 푚 ∗ 휅 ∣ 푒,푡,푠 = 푚 ∗ 휅(1 + 훽푚 ∗ ) > 0.(A.4) The first two derivatives describe how the deployer’s best response changes when vendor choices change; the latter two are partial institutional effects holding vendor mitigation fixed. A.2Vendor Auditability and Mitigation Proof of Lemma4.2.Auditability.Conditional on adoption, substitute푚 ∗ (푡, 푒)into (3.1). From (A.2), 푑 푑푡 푝(푡, 푚 ∗ (푡, 푒)) = 푝 푡 + 푝 푚 푚 ∗ 푡 = 훼퐸(푡, 푚 ∗ ) 1 + 훽푚 ∗ > 0. Consequently, 푑푈 푉 푑푡 = −푘 푡 푡 − 휆퐹 푞(휃, 푒) 훼퐸(푡, 푚 ∗ ) 1 + 훽푚 ∗ < 0(푡 ≥ ̄ 푡). Once adoption is secured, every further increase in푡raises both cost and expected en- forcement exposure. Therefore푡 ∗ = ̄ 푡. 19 Mitigation.Using푞 푒 = −1and (A.1), 푑푈 푉 푑푒 = −푘 푒 푒 + 휆퐹 [푝( ̄ 푡, 푚 ∗ ) + Δ] − 휆퐹 푞 푝 푚 푚 ∗ 푒 = −푘 푒 푒 + 휆퐹 [푝( ̄ 푡, 푚 ∗ ) + Δ + (1 − 푝( ̄ 푡, 푚 ∗ )) 훽푚 ∗ 1 + 훽푚 ∗ ]. This is (4.3). The bracket is퐻( ̄ 푡, 푚 ∗ ) + Δ. For the second-order condition, 퐻 푚 (푡, 푚) = 훽퐸(푡, 푚)(2 + 훽푚) (1 + 훽푚) 2 > 0. Because푚 ∗ 푒 < 0, 푑 2 푈 푉 푑푒 2 = −푘 푒 + 휆퐹 퐻 푚 ( ̄ 푡, 푚 ∗ )푚 ∗ 푒 < −푘 푒 < 0. Thus the interior solution is the unique vendor optimum; if its unconstrained value reaches휃, the optimum is the full-mitigation corner. RemarkA.1 (Vendor participation).The vendor meets the floor when 퐵 > 푘 푡 2 ̄ 푡 2 + 푘 푒 2 (푒 ∗ ) 2 + 휆퐹 (휃 − 푒 ∗ )[푝( ̄ 푡, 푚 ∗ ) + Δ]. This holds for sufficiently large adoption benefit퐵. Otherwise the model’s conditional- on-adoption equilibrium is not reached. A.3Uniqueness and Comparative Responses For a fixed institutional environment, substitute the deployer response푚 ∗ (푒)into the vendor condition: Φ(푒; Δ, 푠) = 퐴[퐻( ̄ 푡, 푚 ∗ (푒, 푠)) + Δ]. 20 Equation (4.5) is푒 ∗ =min휃, Φ(푒 ∗ ). Since Φ 푒 = 퐴퐻 푚 푚 ∗ 푒 < 0, Φis strictly decreasing while the identity is increasing. Hence there is at most one interior crossing. IfΦ(휃 − ) < 휃, continuity yields one interior equilibrium; ifΦ(휃 − ) ≥ 휃, the unique equilibrium is the corner푒 ∗ = 휃,푚 ∗ = 0. Define 퐷 ≡ 1 − 퐴퐻 푚 푚 ∗ 푒 > 1. The equilibrium response to independent audit capacity is 푑푒 ∗ 푑Δ = 퐴 퐷 > 0.(A.5) The direct fixed-monitoring effect is퐴; the fall in monitoring attenuates but never reverses it. At fixed mitigation, ( A.3) gives푚 ∗ 푠 | 푒,푡 < 0. Therefore 푑푒 ∗ 푑푠 = 퐴퐻 푚 퐷 푚 ∗ 푠 | 푒,푡 < 0.(A.6) The total monitoring response is also negative. One direct proof substitutes푒 = 퐴[퐻( ̄ 푡, 푚)+ Δ]into ( 4.6) and defines Ψ(푚, 푠) = 푘 푚 푚 − 휅[휃 − 퐴(퐻( ̄ 푡, 푚) + Δ)] × 훿 1 + 푠 훽퐸( ̄ 푡, 푚). HereΨ 푚 > 0andΨ 푠 > 0, so푑푚 ∗ /푑푠 = −Ψ 푠 /Ψ 푚 < 0. Proof of Proposition4.4.As푠 → ∞,훿 eff → 0. Equation (4.6) then forces푚 ∗ → 0, so 퐻( ̄ 푡, 푚 ∗ ) → 퐻( ̄ 푡, 0) = 1 −exp(−훼 ̄ 푡). Under the stated weak-enforcement condition, the limiting mitigation is below first best. Equation (A.6) shows that mitigation is decreasing in푠, so by continuity it remains below first best for all sufficiently large푠. When ̄ 푡is 21 small,1 −exp(−훼 ̄ 푡) ≃ 훼 ̄ 푡, making the limiting mitigation correspondingly small. Proof of Proposition4.5.Part (a) follows from (A.5). Part (b) follows from (A.6). For part (c), Theorem5.1supplies a finite audit threshold for every푠; lowering푠raises퐻 through monitoring, weakly reducing the audit intensity needed to reach first best. BAudit Rights and Other Policy Proofs Proof of Theorem5.1.Fix푠. Let푚 퐹 퐵 (푠)be the deployer best response when mitigation equals푒 퐹 퐵 ; if푒 퐹 퐵 = 휃, then푚 퐹 퐵 = 0. The exact smallest audit boost that makes the vendor weakly prefer first-best mitigation is ̄ Δ(푠) =max 0, 푘 푒 푒 퐹 퐵 휆퐹 − 퐻( ̄ 푡, 푚 퐹 퐵 (푠)) .(B.1) This threshold is finite. Since퐻 ≥ 0, ̄ Δ(푠) ≤ 푘 푒 푒 퐹 퐵 휆퐹 for every푠, yielding the uniform sufficient condition in the theorem. At any proxy- compliance baseline푒 ∗ < 푒 퐹 퐵 , reaching푒 퐹 퐵 strictly reduces expected harm. In the worked-example corner푒 퐹 퐵 = 휃, the exact threshold is independent of푠: ̄ Δ = 푘 푒 휃 휆퐹 − [1 −exp(−훼 ̄ 푡)] = 0.418731 ... . Proof of Proposition5.2.Equation (A.6) gives푑푒 ∗ /푑푠 < 0. The m-only equationΨ(푚, 푠) = 0above gives푑푚 ∗ /푑푠 < 0. Thus reducing푠raises monitoring and mitigation. Since ex- pected harm is휃 − 푒 ∗ in the interior, it falls. Proof of Proposition5.3.Let푧 푅 = 휇휌. The reporting regime shifts the vendor condition 22 to 푒 = Φ(푒; Δ, 푠) + 푧 푅 푘 푒 . Implicit differentiation yields 푑푒 ∗ 푅 푑푧 푅 = 1/푘 푒 1 − 퐴퐻 푚 푚 ∗ 푒 > 0. The monitoring response attenuates the direct shift but cannot reverse it. The result holds until the full-mitigation corner is reached. Proof of Proposition5.4.Let푧 푂 = 휆 푂 퐹 푂 . The outcome-linked term enters the vendor condition additively and independently of푝(푡, 푚): 푒 = Φ(푒; Δ, 푠) + 푧 푂 푘 푒 . The same implicit derivative as above gives푑푒 ∗ 퐿 /푑푧 푂 > 0. The auditability derivative remains negative because푧 푂 does not depend on푡, so푡 ∗ = ̄ 푡. CWorked-Example Calculations The worked example uses 휃 = 0.6,푘 푡 = 푘 푒 = 푘 푚 = 1, ̄ 푡 = 0.2, 훼 = 훽 = 휅 = 훿 = 휆퐹 = 1. For an interior setting, solve 푚 ∗ = (0.6 − 푒 ∗ ) 1 1 + 푠 exp(−0.2 − 푚 ∗ ), 푒 ∗ = 1 − exp(−0.2 − 푚 ∗ ) 1 + 푚 ∗ + Δ. The resulting values before rounding are: In the combined setting, even the limiting marginal exposure at푚 = 0is퐻( ̄ 푡, 0)+Δ = 23 Table 4: Unrounded worked-example solutions. Setting푚 ∗ 푝( ̄ 푡, 푚 ∗ )푒 ∗ 피[ℎ] High lock-in0.029573 0.205127 0.227958 0.372042 Portability only0.100822 0.259791 0.327585 0.272415 Combined reform0 0.181269 0.6000000 0.181269 + 1 > 0.6, so mitigation clamps at휃. With푞 = 0, Equation (4.1) then gives 푚 ∗ = 0. Portability alone reduces expected harm by approximately26.8%relative to the high-lock-in baseline. Figure2is generated from the same equations. At a target mitigation푒 0 < 휃, moni- toring has the Lambert-푊representation 푚(푒 0 , 푠) = 1 훽 푊 ( 휅(휃 − 푒 0 )훿훽 2 푒 −훼 ̄ 푡 푘 푚 (1 + 푠) ) , and the audit boost required to support that target is Δ(푒 0 , 푠) =max0, 푘 푒 푒 0 휆퐹 − 퐻( ̄ 푡, 푚(푒 0 , 푠)) . The plotted contours use푒 0 = 푒 퐹 퐵 /2and푒 0 = 푒 퐹 퐵 . DComparative Statics The denominator퐷 = 1 − 퐴퐻 푚 푚 ∗ 푒 is positive. Besides ( A.5) and (A.6), the following derivatives hold in the interior: 푑푒 ∗ 푑 ̄ 푡 = 퐴 퐷 훼퐸( ̄ 푡, 푚 ∗ ) (1 + 훽푚 ∗ ) 3 > 0, 푑푒 ∗ 푑푘 푒 = − 푒 ∗ 푘 푒 퐷 < 0, 푑푒 ∗ 푑(휆퐹 ) = 푒 ∗ 휆퐹 퐷 > 0, 푑푒 ∗ 푑휅 = 퐴퐻 푚 퐷 푚 ∗ 휅(1 + 훽푚 ∗ ) > 0. 24 Table 5: Total equilibrium effects in the interior. A dash denotes a decrease, a plus an increase, and zero no change. Monitoring effects include the endogenous mitigation response. Parameter increase푚 ∗ 푡 ∗ 푒 ∗ 피[ℎ] 푠(lock-in)−0−+ Δ(independent audit)−0+− 휆퐹(evidence-based exposure)−0+− ̄ 푡(procurement floor)−++− 푘 푒 (mitigation cost)+0−+ 휅(deployer harm exposure)+0+− For the ̄ 푡derivative, the direct increase in detection dominates the induced reduction in monitoring: 푑퐻 푑 ̄ 푡 ∣ 푒 = 퐻 푡 + 퐻 푚 푚 ∗ 푡 = 훼퐸 (1 + 훽푚 ∗ ) 3 > 0. The negative monitoring response to stronger audit or enforcement is not a policy failure: higher mitigation lowers residual harm, reducing the deployer’s need to monitor. ERegulatory Mapping in Greater Detail AI Act conformity and model oversight.Article 43 of Regulation (EU) 2024/1689 specifies conformity-assessment routes for high-risk systems; Annex VI sets out internal control, while product-linked systems may follow sectoral third-party procedures. Ar- ticles 53 and 55 govern general-purpose model providers and models with systemic risk. Articles 91–93 grant the AI Office powers to request documentation and information, con- duct evaluations, and require measures. The model distinguishes provider auditability푡 from genuinely independent capacityΔ: adding documentation to a provider-controlled process need not equal independent verification. Post-market monitoring and incident reporting.Articles 72–73 create post-market monitoring and serious-incident reporting obligations for high-risk systems. Their effec- tive model counterpart is휇휌, not the nominal duty alone. Coverage, causal attribution, timeliness, regulator capacity, and sanctions for non-compliance determine휌and휇. 25 Researcher access and portability analogies.DSA Article 40 provides vetted- researcher access for VLOPs and very large online search engines (VLOSEs) and there- fore illustrates an access right that can raise independent detection. DMA Articles 5–6 illustrate data-portability and interoperability obligations that can lower switching costs. Neither regime maps mechanically onto foundation-model procurement; they identify the institutional form of the levers. Liability.The withdrawn AI Liability Directive proposal would have eased proof through disclosure and rebuttable presumptions in fault-based claims. It was not automatic lia- bility for every adverse outcome. Directive (EU) 2024/2853 modernizes strict product liability and expressly encompasses software; however, claimants still need to prove a defective product, covered damage, and causation. Proposition 5.4should therefore be read as a benchmark for exposure that is less dependent on the paper’s separate evidence channel, not as a literal description of current EU law. FOperationalization and Empirical Designs Three empirical designs are particularly natural. First, procurement-threshold changes can be studied with difference-in-differences or event-study designs when comparable sectors adopt requirements at different times. Second, provider migrations or interoper- ability mandates create settings for measuring whether reduced lock-in raises monitoring and remediation. Third, changes in independent access rights can be linked to the gap between vendor-reported and independently reproduced performance. In each case, un- derlying sector risk and institutional capacity are likely confounders; the model identifies directional hypotheses, not a ready-made causal instrument. GModeling Choices and Extensions Common-knowledge risk.Conditioning on휃isolates evidence scarcity from adverse selection. A private-information extension would let the vendor signal risk through(푡, 푒) 26 Table 6: Illustrative measures for the model’s institutional parameters. Construct Candidate measuresCandidate data sources or settings Auditability 푡 contractual audit clauses; API rate and logging terms; repro- ducibility permissions; model- card and system-card complete- ness; publication restrictions procurement contracts; platform terms; model documentation; DSA audit re- ports; researcher-access scorecards Independent capacityΔ regulator testing rights; third- party access independent of provider permission; evaluation staffing and budgets; ability to publish adverse findings AI Office and national authority records; AI Safety Institute programs; DSA Arti- cle 40 access decisions Lock-in푠provider-specific fine-tuning arti- facts; prompt and tool wrappers; data-egress and retraining costs; switching and re-tender rates machine-learning operations (MLOps) telemetry; procurement records; vendor- migration projects; surveys of deployers Monitoring 푚 continuous evaluation frequency; red-team budget; incident triage; external audit expenditure internal governance records; audit con- tracts; safety-case updates; regulated- sector supervision Mitigation 푒 patching and retraining effort; safety engineering headcount; post-incident remediation; in- dependently measured perfor- mance improvements change logs; technical reports; incident investigations; independent benchmarks Reporting 휌 report completeness, timeliness, scope, and match between inter- nal incidents and regulator fil- ings AI Act Article 73 reports when available; sectoral incident registers; AI Incident Database and could add pooling or separating equilibria, but it is not required for the proxy- compliance mechanism. Static, single-vendor structure.Repeated interaction could make reputation an additional enforcement channel or, conversely, institutionalize symbolic compliance. A multi-vendor model would endogenize switching opportunities and market concentration. The present푠summarizes these forces rather than deriving them. Harm technology.The linear specification makes the monitoring response and policy thresholds transparent. More general decreasing harm functions preserve the mechanism when the vendor objective remains concave and the deployer best response is well-behaved, but the threshold formulas change. 27 Non-market evidence producers.Journalists, civil society organizations, and aca- demic researchers can be represented as contributors toΔ. Their access, publication incentives, and vulnerability to legal or contractual restriction are themselves strategic objects and deserve a separate model. Scaling and political economy.The paper’s title identifies the application domain. Scale, compute concentration, and regulatory capacity are not endogenous primitives. They motivate why audit access and switching costs may be consequential, but the formal results should not be read as comparative statics in model scale. HWelfare Effects Treating penalties as transfers and abstracting from policy-administration costs, define welfare conditional on adoption as 푊 = 푉 − (휃 − 푒 ∗ ) − 푘 푒 2 (푒 ∗ ) 2 − 푘 푡 2 ̄ 푡 2 − 푘 푚 2 (푚 ∗ ) 2 .(H.1) Because the deployer best response depends on policy only through equilibrium mitigation for an audit change,푚 ∗ Δ = 푚 ∗ 푒 푒 ∗ Δ . Therefore 푑푊 푑Δ = [(1 − 푘 푒 푒 ∗ ) − 푘 푚 푚 ∗ 푚 ∗ 푒 ] 푑푒 ∗ 푑Δ . When푒 ∗ < 푒 퐹 퐵 ,1−푘 푒 푒 ∗ > 0; because푚 ∗ 푒 < 0and푑푒 ∗ /푑Δ > 0, the audit effect is strictly positive. Stronger audit capacity raises beneficial mitigation and reduces the monitoring cost required to manage residual harm. For switching costs, 푑푊 푑푠 = (1 − 푘 푒 푒 ∗ ) 푑푒 ∗ 푑푠 − 푘 푚 푚 ∗ 푑푚 ∗ 푑푠 . 28 Both derivatives are negative. A marginal reduction in푠improves welfare precisely when (1 − 푘 푒 푒 ∗ ) ∣ 푑푒 ∗ 푑푠 ∣ > 푘 푚 푚 ∗ ∣ 푑푚 ∗ 푑푠 ∣ . The left side is the net benefit from additional mitigation; the right side is the extra monitoring resource cost. This condition replaces the stronger and generally unjustified claim that portability is always welfare-improving. Ethical Statement This paper develops a stylized institutional model and uses no human participants, per- sonal data, or deployed AI systems. Its principal adverse-impact risk is overgeneralization: the comparative statics do not establish that any specific firm, sector, or legal regime nec- essarily exhibits proxy compliance, nor that audit, reporting, portability, or liability is sufficient on its own. We therefore separate the model’s benchmark mechanisms from claims about current law and stress that implementation depends on audit independence, due process, confidentiality safeguards, civil-society access, distributional effects, and regulator capacity. References Bénabou, R., and Tirole, J. (2010) Individual and Corporate Social Responsibility.Eco- nomica,77(305), p. 1–19. Available at:https://doi.org/10.1111/j.1468-0335.2009. 00843.x . Bender, E. M., Gebru, T., McMillan-Major, A., and Shmitchell, S. (2021) On the Dangers of Stochastic Parrots: Can Language Models Be Too Big? In:Proceedings of the 2021 ACM Conference on Fairness, Accountability, and Transparency. Available at: https: //doi.org/10.1145/3442188.3445922. Birhane, A., Kalluri, P., Card, D., Agnew, W., Dotan, R., and Bao, M. (2022) The Values Encoded in Machine Learning Research. In:2022 ACM Conference on Fairness, Accountability, and Transparency. Available at: https://doi.org/10.1145/3531146. 3533083. Burnat, F. A. D., and Davidson, B. I. (June 2026) The accountability paradox: How platform API restrictions undermine AI transparency mandates. In:Proceedings of the 2026 ACM Conference on Fairness, Accountability, and Transparency. New York, NY, USA: ACM, p. 2416–2433. Available at: https://doi.org/10.1145/3805689.3812289. 29 Casper, S., Ezell, C., Siegmann, C., Kolt, N., Curtis, T. L., Bucknall, B., Haupt, A., Wei, K., Scheurer, J., Hobbhahn, M., Sharkey, L., Krishna, S., Von Hagen, M., Alberti, S., Chan, A., Sun, Q., Gerovitch, M., Bau, D., Tegmark, M., and Krueger, D. (2024) Black-Box Access is Insufficient for Rigorous AI Audits. In:The 2024 ACM Conference on Fairness, Accountability, and Transparency (FAccT ’24). Available at:https://doi. org/10.1145/3630106.3659037. Costanza-Chock, S., Raji, I. D., and Buolamwini, J. (2022) Who Audits the Auditors? Recommendations from a Field Scan of the Algorithmic Auditing Ecosystem. In: Proceedings of the 2022 ACM Conference on Fairness, Accountability, and Trans- parency. FAccT ’22. New York, NY, USA: ACM, p. 1571–1583. Available at:https: //doi.org/10.1145/3531146.3533213. Crawford, K. (2021)Atlas of AI: Power, Politics, and the Planetary Costs of Artificial Intelligence. New Haven, CT: Yale University Press. Eckstein, A., and Shapira, R. (2024) Compliance gatekeepers.Yale Journal on Regulation, 41, p. 469–523. Engler, A. (2023)The EU AI Act and Emerging AI Market Concentration. Report. Brook- ings Institution. European Commission (Oct. 2025)Withdrawal of Commission Proposals: COM(2022) 496 final, 2022/0303 (COD). Available at: Official Journal of the European Union, C/2025/5423. Available at: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri= CELEX:52025XC05423. European Union (2022a)Regulation (EU) 2022/1925 on Contestable and Fair Markets in the Digital Sector. Available at: Official Journal of the European Union, L 265. Available at:https://eur-lex.europa.eu/eli/reg/2022/1925/oj/eng. European Union (2022b)Regulation (EU) 2022/2065 on a Single Market for Digital Services. Available at: Official Journal of the European Union, L 277. Available at: https://eur-lex.europa.eu/eli/reg/2022/2065/oj/eng. European Union (Nov. 2024a)Directive (EU) 2024/2853 on Liability for Defective Prod- ucts. Available at: Official Journal of the European Union, L 2024/2853. Available at: https://eur-lex.europa.eu/eli/dir/2024/2853/oj/eng. European Union (July 2024b)Regulation (EU) 2024/1689 Laying Down Harmonised Rules on Artificial Intelligence. Available at: Official Journal of the European Union, L 2024/1689. Available at: https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng. Farrell, J., and Shapiro, C. (1988) Dynamic Competition with Switching Costs. The RAND Journal of Economics,19(1), p. 123–137. Available at: https://doi.org/10. 2307/2555402. Floridi, L., Holweg, M., Taddeo, M., Silva, J. A., Mökander, J., and Wen, Y. (2022)capAI - A Procedure for Conducting Conformity Assessment of AI Systems in Line with the EU AI Act. Available at: SSRN Working Paper. Available at:https://doi.org/10. 2139/ssrn.4064091 . Glaeser, E. L., and Shleifer, A. (2003) The Rise of the Regulatory State.Journal of Economic Literature,41(2), p. 401–425. Available at:https://doi.org/10.1257/jel. 41.2.401 . Gornet, M., and Maxwell, W. (2024) The European Approach to Regulating AI Through Technical Standards.Internet Policy Review,13(3). Available at:https://doi.org/10. 14763/2024.3.1784. Hacker, P., Engel, A., and Mauer, M. (2023) Regulating ChatGPT and Other Large Generative AI Models. In:Proceedings of the 2023 ACM Conference on Fairness, 30 Accountability, and Transparency (FAccT ’23). Available at:https://doi.org/10.1145/ 3593013.3594067. Hagendorff, T. (2020) The Ethics of AI Ethics: An Evaluation of Guidelines.Minds and Machines,30(1), p. 99–120. Available at:https://doi.org/10.1007/s11023- 020- 09517-8. Hartmann, D., Laranjeira de Pereira, J. R., Streitbörger, C., and Berendt, B. (2025) Addressing the Regulatory Gap: Moving Towards an EU AI Audit Ecosystem Beyond the AI Act by Including Civil Society.AI and Ethics. Available at:https://doi.org/ 10.1007/s43681-024-00595-3. Jobin, A., Ienca, M., and Vayena, E. (2019) The Global Landscape of AI Ethics Guidelines. Nature Machine Intelligence,1(9), p. 389–399. Available at:https://doi.org/10.1038/ s42256-019-0088-2. Katz, M. L., and Shapiro, C. (1985) Network Externalities, Competition, and Compati- bility.The American Economic Review,75(3), p. 424–440. Klemperer, P. (1995) Competition when Consumers Have Switching Costs: An Overview with Applications to Industrial Organization, Macroeconomics, and International Trade.The Review of Economic Studies,62(4), p. 515–539. Available at:https : //doi.org/10.2307/2298075. Laffont, J.-J., and Tirole, J. (1993)A Theory of Incentives in Procurement and Regulation. Cambridge, MA: MIT Press. Laux, J., Wachter, S., and Mittelstadt, B. (2024) Three Pathways for Standardisation and Ethical Disclosure by Default Under the European Union Artificial Intelligence Act.Computer Law & Security Review,53. Available at: https://doi.org/10.1016/j. clsr.2024.105957. Mantelero, A. (2024) The Fundamental Rights Impact Assessment (FRIA) in the AI Act: Roots, Legal Obligations and Key Elements for a Model Template.Computer Law & Security Review,54. Available at:https://doi.org/10.1016/j.clsr.2024.106020. Mitchell, M., Wu, S., Zaldivar, A., Barnes, P., Vasserman, L., Hutchinson, B., Spitzer, E., Raji, I. D., and Gebru, T. (2019) Model Cards for Model Reporting. In:Proceedings of the Conference on Fairness, Accountability, and Transparency. FAT* ’19. New York, NY, USA: ACM, p. 220–229. Available at: https://doi.org/10.1145/3287560.3287596. Mökander, J., Axente, M., Casolari, F., and Floridi, L. (2022) Conformity Assessments and Post-market Monitoring: A Guide to the Role of Auditing in the Proposed Eu- ropean AI Regulation.Minds and Machines,32, p. 241–268. Available at: https: //doi.org/10.1007/s11023-021-09577-4. Mokander, J., Schuett, J., Kirk, H. R., and Floridi, L. (2023) Auditing Large Language Models: A Three-Layered Approach.AI and Ethics,3(4), p. 1085–1115. Available at:https://doi.org/10.1007/s43681-023-00289-2. Moss, E., Metcalf, J., Watkins, E. A., Singh, R., and Elish, M. C. (2021)Assembling Accountability: Algorithmic Impact Assessment for the Public Interest. Tech. rep. Data & Society Research Institute. Available at: https://doi.org/10.2139/ssrn.3877437. Mulligan, D. K., and Bamberger, K. A. (2019) Procurement as Policy: Administrative Process for Machine Learning.Berkeley Technology Law Journal,34(3), p. 773–851. Available at: https://doi.org/10.15779/Z38RN30793. National Institute of Standards and Technology (2024)Artificial Intelligence Risk Man- agement Framework: Generative AI Profile. Tech. rep. NIST AI 600-1. NIST. Available at: https://doi.org/10.6028/nist.ai.600-1. 31 Novelli, C., Hacker, P., Morley, J., Trondal, J., and Floridi, L. (2025) A Robust Gover- nance for the AI Act: AI Office, AI Board, Scientific Panel, and National Authorities. European Journal of Risk Regulation. Available at:https://doi.org/10.1017/err.2024. 57. Raji, I. D., and Buolamwini, J. (2019) Actionable Auditing: Investigating the Impact of Publicly Naming Biased Performance Results of Commercial AI Products. In:Pro- ceedings of the 2019 AAAI/ACM Conference on AI, Ethics, and Society. AIES ’19. New York, NY, USA: ACM, p. 429–435. Available at:https://doi.org/10.1145/ 3306618.3314244. Raji, I. D., Kumar, I. E., Horowitz, A., and Selbst, A. (2022) The Fallacy of AI Function- ality. In:Proceedings of the 2022 ACM Conference on Fairness, Accountability, and Transparency. Available at:https://doi.org/10.1145/3531146.3533158. Raji, I. D., Smart, A., White, R. N., Mitchell, M., Gebru, T., Hutchinson, B., Smith-Loud, J., Theron, D., and Barnes, P. (2020) Closing the AI Accountability Gap: Defining an End-to-End Framework for Internal Algorithmic Auditing. In:Proceedings of the 2020 Conference on Fairness, Accountability, and Transparency. FAT* ’20. New York, NY, USA: ACM, p. 33–44. Available at:https://doi.org/10.1145/3351095.3372873. Raji, I. D., Xu, P., Honigsberg, C., and Ho, D. (2022) Outsider Oversight: Designing a Third Party Audit Ecosystem for AI Governance. In:Proceedings of the 2022 AAAI/ACM Conference on AI, Ethics, and Society (AIES). Available at: https : //doi.org/10.1145/3514094.3534181. Sandvig, C., Hamilton, K., Karahalios, K., and Langbort, C. (2014) Auditing Algorithms: Research Methods for Detecting Discrimination on Internet Platforms. In:Data and Discrimination: Converting Critical Concerns into Productive Inquiry, a preconference at the 64th Annual Meeting of the International Communication Association. Seattle, WA. Schuett, J. (2023) Risk Management in the Artificial Intelligence Act.European Journal of Risk Regulation,14(2), p. 367–385. Available at: https://doi.org/10.1017/err.2023.1. Schuett, J. (2025) Frontier AI Developers Need an Internal Audit Function.Risk Analysis. Available at:https://doi.org/10.1111/risa.17665. Selbst, A. D., Boyd, d., Friedler, S. A., Venkatasubramanian, S., and Vertesi, J. (2019) Fairness and Abstraction in Sociotechnical Systems. In:Proceedings of the Conference on Fairness, Accountability, and Transparency. FAT* ’19. New York, NY, USA: ACM, p. 59–68. Available at: https://doi.org/10.1145/3287560.3287598. Shavell, S. (1984) Liability for Harm versus Regulation of Safety.Journal of Legal Studies, 13(2), p. 357–374. Available at:https://doi.org/10.1086/467745. Stigler, G. J. (1971) The Theory of Economic Regulation.The Bell Journal of Economics and Management Science,2(1), p. 3–21. Available at:https://doi.org/10.2307/ 3003160. Suchman, M. C., and Edelman, L. B. (Oct. 1996) Legal rational myths: The new insti- tutionalism and the law and society tradition.Law & Social Inquiry Journal of the American Bar Foundation,21(04), p. 903–941. Available at:https://doi.org/10. 1111/j.1747-4469.1996.tb00100.x . Tirole, J. (1986) Hierarchies and Bureaucracies: On the Role of Collusion in Organizations. Journal of Law, Economics, & Organization,2(2), p. 181–214. Available at:https: //doi.org/10.1093/oxfordjournals.jleo.a036907. 32 Veale, M., and Zuiderveen Borgesius, F. (2021) Demystifying the Draft EU Artificial Intelligence Act.Computer Law Review International,22(4), p. 97–112. Available at:https://doi.org/10.9785/cri-2021-220402. Wachter, S., Mittelstadt, B., and Russell, C. (2021) Why fairness cannot be automated: Bridging the gap between EU non-discrimination law and AI.Computer Law & Secu- rity Review,41, p. 105567. Available at:https://doi.org/10.1016/j.clsr.2021.105567. Wang, J., Huang, K., Klyman, K., and Bommasani, R. (2025) Do AI Companies Make Good on Voluntary Commitments to the White House? In:Proceedings of the AAAI/ACM Conference on AI, Ethics, and Society (AIES). Available at:https://doi.org/10.1609/ aies.v8i3.36743. Widder, D. G., West, S. M., and Whittaker, M. (2023) “Open (For Business): Big Tech, Concentrated Power, and the Political Economy of Open AI”. Available at:https: //doi.org/10.2139/ssrn.4543807. 33