Research
Scaling, Lock-In, and Proxy Compliance: A Political Economy of Responsible AI
Overview Research area: AI governance and accountability, algorithmic auditing, and the political economy of regulation; formal game theory applied to AI procurement and enforcement. Technical level:
- arXiv
- 2607.28023
- Published
- 2026-07-30
- Authors
- Florian A. D. Burnat, Brittany I. Davidson
AI summary
Overview
Research area: AI governance and accountability, algorithmic auditing, and the political economy of regulation; formal game theory applied to AI procurement and enforcement.
Technical level: Advanced. The prose is policy-facing, but the core is a sequential game with a unique interior equilibrium, corner solutions, and comparative-statics propositions.
Scope: The paper builds a vendor–deployer–regulator model in which auditability, mitigation, and post-adoption monitoring are chosen strategically, and uses it to explain why visible Responsible AI compliance can coexist with persistent harm.
What This Paper Is About
Responsible AI checklists, model cards, conformity documentation, and standardized evaluations have become common, yet recurring harms and accountability gaps remain. The paper asks why visible compliance and limited mitigation can be rational choices rather than simple implementation failures, arguing that the answer lies in who can observe, verify, and change deployed systems. It develops a sequential political-economy model in which a vendor chooses how auditable and how safe to make a system, a deployer decides how closely to monitor after being locked in, and enforcement only works when verifiable evidence exists.
Key Contributions
- An endogenous vendor–deployer model. Auditability, mitigation, and monitoring are all choice variables, conditional on institutional parameters for procurement requirements, switching costs, and enforcement.
- A solved sequential game with anticipation. The vendor anticipates how its mitigation choice changes the deployer's monitoring response, yielding a unique interior equilibrium, a transparent full-mitigation corner, and policy comparative statics.
- A formal account of "proxy compliance." The paper defines the equilibrium condition under which auditability is pinned at the procurement floor while mitigation falls below the social first best.
- Policy levers mapped to real institutions. Audit rights, portability, incident reporting, and outcome-linked liability are each tied to specific EU instruments (AI Act, DSA, DMA, liability directives) and to measurable empirical proxies.
Main Findings
- Lock-in weakens the deployer-monitoring channel. Switching cost s reduces effective recourse to δ_eff = δ/(1+s). As s rises, monitoring m* falls, detection p falls, mitigation e* falls, and expected harm rises.
- Proxy compliance exists under weak enforcement plus high lock-in (Proposition 4.4). With no independent audit capacity (Δ = 0) and baseline enforcement weak enough that (λF/k_e)(1 − exp(−αt̄)) < e^FB, there is a threshold switching cost above which proxy compliance occurs. As s → ∞, m* → 0 and e* → (λF/k_e)(1 − exp(−αt̄)).
- The vendor stops exactly at the procurement floor. The vendor's optimal auditability is t* = t̄ (Lemma 4.2): once adoption is secured, further auditability raises both cost and expected enforcement exposure.
- The monitoring response is an extra private return to mitigation. The vendor's mitigation equation e* = (λF/k_e)[H(t̄, m*) + Δ] includes a term for the deployer's induced monitoring, not just direct detection.
- More independent detection or less lock-in raises mitigation (Proposition 4.5). de*/dΔ > 0 (though monitoring feedback attenuates the direct effect), and de*/ds < 0.
- Sufficiently strong audit rights work at any lock-in level (Theorem 5.1). A finite threshold Δ̄(s) exists for every fixed s; a uniform sufficient condition is Δ ≥ k_e · e^FB / λF. The paper calls audit rights the strongest single lever in the model.
- Portability raises mitigation indirectly (Proposition 5.2). Lower switching costs raise monitoring and mitigation and lower expected harm; the effect is stronger when deployer harm exposure κ and monitoring productivity β are high.
- Incident reporting substitutes for vendor-gated evidence (Proposition 5.3). A reporting channel adds exposure μρ·q(θ,e), so e_R* > e* whenever μρ > 0 and the baseline is below the mitigation corner. The product μρ is deliberately "effective" coverage: nominal duties with narrow scope or weak follow-up contribute little.
- Outcome-linked liability works independently of detection (Proposition 5.4). Any positive λ_O F_O raises mitigation below the corner, and this component is unaffected by vendor-controlled auditability.
- Worked example (θ = 0.6, k_t = k_e = k_m = 1, α = β = κ = δ = λF = 1, t̄ = 0.2, so e^FB = 0.6). High lock-in with no audit (s = 9, Δ = 0) gives m* = 0.03, e* = 0.23, E[h] = 0.37. Portability only (s = 1, Δ = 0) gives m* = 0.10, e* = 0.33, E[h] = 0.27 — above half of first best but not accountability. Combined reform (s = 1, Δ = 1) gives m* = 0.00, e* = 0.60, E[h] = 0.00, with no residual monitoring because there is no harm left to investigate.
- The formal ancestor is CSR signaling. The mechanism specializes the Bénabou and Tirole (2010) structure — observable action dominating unobservable effort when audiences condition on the action alone — into a vendor–deployer–regulator game with switching costs.
- Welfare. Below first best, raising independent audit exposure raises mitigation and lowers both harm and residual monitoring, so its total welfare effect is positive; portability has an offsetting trade-off because it can raise costly monitoring.
Methodology in Plain English
The authors build a stylized three-step game. First, a vendor picks how auditable (t) and how mitigating (e) its system is. Second, a deployer sees those choices, decides whether to adopt, and if so how much to monitor (m) — knowing that integration creates switching costs that make leaving hard. Third, harm either occurs or does not, evidence either surfaces or does not, and the regulator penalizes the vendor only when actionable evidence exists.
The key trick is that the vendor moves first and knows how the deployer will react. So the vendor's real incentive to mitigate is not just the direct chance of being caught — it is the chance of being caught plus the extra scrutiny its own mitigation triggers from the deployer. The authors use specific functional forms (harm probability q(θ,e) = max{0, θ − e}; evidence probability p(t,m) = 1 − exp(−αt − βm); quadratic costs c_j(x) = k_j x²/2) to get closed-form equilibrium conditions, then sign the derivatives. Policy levers enter as parameters — independent audit capacity Δ, reporting exposure μρ, outcome-linked exposure λ_O F_O — and the paper asks how changing each shifts the equilibrium.
Why This Matters
The paper's central policy claim is institutional rather than procedural: accountability requires both verifiability and the power to act on what is verified. It explains why documentation and standardized evaluations can persist alongside real-world harm, and it generates testable predictions rather than a list of best practices.
Real-world applications:
- Medical-device AI and credit scoring — sectors where deployer harm exposure κ is high, so portability's effect should be largest.
- Public-sector hiring systems — procurement floors and integration depth vary across agencies, giving cross-sectional variation for testing.
- Very large online platforms — DSA Article 40 audit and transparency records, and the "audit blind-spots" documented by Burnat and Davidson (2026) across X, Reddit, TikTok, and Meta as a concrete case of vendor-gated detection.
- Frontier model providers — AI Act Articles 53 and 55 obligations, where documentation remains provider-controlled and therefore affects t rather than Δ.
Industry relevance: For vendors, the model predicts that meeting the procurement floor is optimal and that additional transparency is a cost with no benefit. For deployers, the message is that integration depth converts into bargaining weakness. For regulators, the model suggests that evaluation capacity they control directly (Δ) and outcome-linked exposure (λ_O F_O) retain bite even when ordinary detection does not.
Future Directions
- Endogenize scale and market structure. The authors explicitly note that "scaling" and "political economy" in the title describe the motivating environment, not modeled variables; switching cost, enforcement, and the procurement floor are parameters rather than outcomes of competition or regulatory choice.
- Add private information. The model assumes a common-knowledge risk parameter θ, omitting asymmetric information between vendor, deployer, and regulator.
- Extend to multi-vendor competition and repeated reputation dynamics, plus multidimensional harms, civil-society evidence production, and adversarial misuse — all listed as extensions left open.
- Calibrated empirical work. The numerical example is illustrative rather than calibrated; the comparative statics generate hypotheses and measurement targets, not policy effect sizes, and identification requires careful design because procurement floors, audit access, and integration depth may correlate with underlying risk and institutional capacity.
- Guard against ceremonial auditing. Third-party audit can itself become proxy compliance when auditors and auditees share an interest in the appearance of rigor, in which case it contributes little to effective Δ.
Target Audience
AI governance and policy researchers, regulators and standards bodies working on conformity assessment and audit regimes, legal scholars studying evidence-based enforcement and liability, and economists interested in switching costs and regulation under asymmetric information. Deployer-side procurement and compliance teams in high-stakes sectors (medical devices, credit scoring, public-sector hiring) will also find the lock-in mechanism directly relevant, though the formal sections assume comfort with game theory and comparative statics.
Authors’ abstract
AI accountability at scale is an institutional problem: who can observe, verify, and change deployed systems. We develop a sequential political-economy model in which an AI vendor chooses auditability and substantive mitigation, a deployer monitors after adoption while facing switching costs, and enforcement depends on verifiable evidence. Anticipating the deployer's monitoring response, the vendor may stop at an observable procurement floor while mitigating below the social first best, producing a proxy-compliance equilibrium. We characterize the unique interior equilibrium and the corner in which harm is fully mitigated. Independent audit rights raise enforcement exposure directly; portability restores deployer leverage; incident reporting adds a regulator-visible evidence channel; and outcome-linked liability creates incentives that do not depend on vendor-controlled detection. The results explain why documentation and standardized evaluations can coexist with persistent post-deployment harms, and generate testable implications for monitoring, mitigation, and the gap between formal compliance and operational outcomes.