Information-Producing Regulation: Certification and Delegated Enforcement
This paper develops a theoretical framework analyzing how information-producing regulations, such as certification and delegated enforcement, shape firms' incentives to invest in private evidence capacity and how the interplay between public and private information influences optimal regulatory design and institutional implementation.
Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
In the modern world, many critical decisions rely on information that no single person or organization holds completely. A company might know the intricate details of its own computer systems, while a government agency might possess a broader picture of threats gathered from across the globe. The challenge arises when these two parties must work together to stop a cyberattack or manage a crisis. Traditional rules often focus only on what companies are allowed to do, but a new line of thinking asks a deeper question: who should be responsible for gathering the necessary facts, and who should have the final say in acting on them? This is the core of a field known as information-producing regulation, which studies how rules change not just behavior, but the very incentives people have to learn and share what they know.
Taylor Canann, an economist at Louisiana Tech University, has developed a new theory to map out how these interactions play out. The research focuses on a specific scenario where a firm has the technical skill to respond to a threat, but the government holds vital context—such as whether an attack is linked to a foreign nation or if a response might accidentally harm innocent third parties. The paper explores four different ways a society could organize this relationship: banning all private action, letting firms act freely, creating a licensed system where the government certifies capable firms to act, or having the government take over the response entirely. By building a mathematical model of these choices, the study reveals that the rules governing information and the rules governing action are deeply intertwined; changing one inevitably reshapes the other.
One of the most striking findings is that government information does not always help private experts do their jobs better. Depending on how the rules are written, public information can either encourage firms to invest more in their own expertise or discourage them from doing so. If the government sets a rule that requires both its own data and a firm's data to agree before action is taken, firms are motivated to gather more evidence to ensure they meet that high bar. This is a "crowding-in" effect. However, if the rule is looser—allowing action if either the government or the firm has a positive signal—firms may feel they can rely on the government's data and stop investing in their own. This "crowding-out" effect means that simply providing more public data can sometimes make the private sector less capable, leaving the system weaker overall.
The study also uncovers how certification works as a filter for capability. When the government requires firms to produce auditable evidence before they are allowed to act, it naturally sorts companies based on their ability to produce that evidence. Because more capable firms can generate high-quality proof at a lower cost, a standard requirement effectively selects for the most competent organizations. This happens not because the government is guessing who is good, but because the cost of proving competence is simply cheaper for those who are already skilled. The result is a system where only the most capable firms get licensed, creating a natural barrier that separates the experts from the rest.
Perhaps the most practical insight concerns who should actually pull the trigger when a decision is made. The paper argues that having the government know more does not automatically mean the government should act. Even if the government has superior information, it may still be better to let a certified firm execute the response, provided the firm has a specific operational advantage, such as speed or local knowledge. The decision comes down to a trade-off: if the government takes over, it avoids the risk of the firm acting too aggressively, but it loses the efficiency of the firm's specialized skills. If the firm acts, it retains that efficiency but might be tempted to act too quickly. The optimal choice depends on which of these two losses is smaller.
Finally, the research addresses the issue of trust and transparency. It distinguishes between a regulator's chosen policy of secrecy—such as withholding certain sources to protect intelligence—and an agency secretly hiding information against the rules. The study suggests that a credible institution does not need to be fully transparent to be effective. It can operate with a deliberate, approved level of opacity to protect sensitive methods, as long as there are strong checks to prevent unauthorized hiding of information. The goal is not total disclosure, but faithful adherence to the rules the regulator has set.
In the end, this work provides a roadmap for designing regulatory systems that do more than just punish bad behavior. It shows that effective regulation must account for how rules change the way people learn and share information. Whether in cybersecurity or other complex fields, the best approach is not a one-size-fits-all mandate, but a carefully balanced system where public and private information complement each other, certification rewards genuine capability, and the authority to act is assigned to whoever can execute the decision with the least amount of waste or risk.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.