Regulatory Calibration: The Right Model At The Right Time
~10 min read
Imagine a financial institution in Chișinău trying to move a core service onto public cloud infrastructure in an EU data center. Moldova has spent years building out its digital transformation agenda, and the cloud provider meets international security certifications. But the government’s security rules — written for a smaller and more contained IT environment — weren’t built to assess a request like this. The rules aren’t wrong, exactly — they were built for a different time.
Multiply that hypothetical scene across the agencies and countries trying to leapfrog into the digital economy, and a defining regulatory tension emerges: governments are setting ambitious digital and AI strategies while the agencies implementing them are ill-equipped to do so. The challenge is not simply choosing the right regulatory model — it is putting the law, institutional capacity and enforcement in the right order. Ongoing miscalibrations aren't necessarily a matter of wrong model for the wrong market — more often, it's the right model at the wrong time.
Not the Wrong Rulebook — The Wrong Order
Mondato has previously examined “AI readiness” requires technically and institutionally. The harder question is what happens when a country has the ambition and infrastructure, but its regulators are still applying standards built for a different context.
The instinct is often to reach for a first-mover framework and adapt it. Europe’s GDPR has become the default template for data protection in much of the world, much as the Basel Accords became a model for banking supervision:
Source: UNCTAD
The results have varied, with timing often being the common denominator for success. Kenya’s Data Protection Act, modeled closely on GDPR, became enforceable immediately upon passage in 2019 — unlike GDPR, which gave the EU two years to prepare — while the regulator meant to enforce it had not yet been formed. South Africa took a different route with its own GDPR-style law: passed in 2013, POPIA’s substantive provisions did not take effect until 2020, giving the newly created Information Regulator time to become operational. South Africa's Information Regulator has since begun exercising its enforcement powers, issuing a R5 million fine against the Department of Justice — and reaching a negotiated settlement with WhatsApp.
Miriam Stankovich, who has spent years advising governments from Pakistan to Moldova to Ukraine on AI and digital governance, sees the same pattern across markets.
“Governments sometimes adopt quite demanding data protection rules before the regulator has enough staff or agencies have enough guidance to apply them consistently. That is when projects slow down and businesses start hearing different interpretations from different officials. People then blame the law.”
Miriam Stankovich, AI and Data Governance Advisor
The World Bank’s research echoes almost exactly the same gap: emerging economies “face a challenging gap to effectively implement and enforce” the regulatory policies they adopt. The gap is between ambition and administrative capacity, not between legal traditions.
Flávia Rebello Pereira, who heads the technology, data and IP practice at Trench Rossi Watanabe and has ranked among Brazil's top data protection lawyers for over a decade, has tracked that gap from the inside — having filed comments on several of ANPD's own public consultations as it built out its rulebook. The framework fits naturally, she said, in sectors already running compliance-heavy operations — like finance, healthcare, telecoms and large technology companies — where “concepts such as accountability, data governance, security-by-design, and risk management have translated relatively naturally”. It fits less easily where the surrounding institutional and commercial machinery hasn’t caught up.
“Challenges arise in highly relationship-driven commercial environments and among smaller businesses... [that] do not always align with traditional business practices in Brazil.”
Flávia Rebello Pereira - Partner, Technology, Data and IP Practice, Trench Rossi Watanabe
Rebello says it isn’t a European rule failing to fit a non-European market in the abstract — it’s simply a rule exceeding the capacity built to receive it. The answer isn’t necessarily a bespoke national alternative to GDPR — rather, the goal must be to build the implementation capacity and enforcement consistency to apply the model well, and in the right order.
What Investors Prize: Certainty
When Safaricom launched M-Pesa in 2007, Kenya’s central bank had no mobile money framework. It issued a provisional “letter of no-objection” and let the product prove itself before legislating — a “test-and-learn” approach that became a global template.
Financial Access in Kenya
Source: FinAccess
Nearly two decades later, Indonesia’s OJK is doing something similar by design rather than improvisation. Instead of imposing new equity rules on peer-to-peer lending platforms all at once, POJK 40/2024 phased in the equity threshold over eighteen months and grandfathered platforms already above the ownership cap, avoiding an abrupt restructuring.
When that learning doesn’t happen, the friction is usually invisible — until it isn’t. “Investment rarely disappears in one dramatic moment,” Stankovich said. “Often it gets smaller, slower, and more conditional.” Rebello echoed that point in the Brazilian context:
“Regulatory certainty typically functions as an enabling condition. It rarely wins the investment by itself, but regulatory uncertainty can absolutely prevent investment from happening.”
Flávia Rebello Pereira - Partner, Technology, Data and IP Practice, Trench Rossi Watanabe
For investors, certainty and stringency are different questions. A demanding rule can be workable when its scope, timing and enforcement are clear. Uncertainty, however, about which regulator’s approval is needed, or when obligations will take effect, can make a project harder to price and plan.
In South Africa, digital-only lender TymeBank spent three years securing its license — not because any one regulator objected, but because three separate bodies each had a legitimate remit: the Reserve Bank on prudential capital, the Financial Sector Conduct Authority on deposit-taking conduct, and the National Credit Regulator on lending. Each regulator had a legitimate role, but none was positioned to move the process along alone.
Nigeria’s dispute with Meta offers another cautionary tale. Between 2024 and 2025, three regulators — the Federal Competition and Consumer Protection Commission, the Data Protection Commission, and the Advertising Regulatory Council — each asserted jurisdiction over overlapping aspects of Meta’s conduct in Nigeria, issuing combined fines of roughly $290 million. Meta threatened to withdraw Facebook and Instagram entirely. After more than a year of litigation, the dispute ended not with a clear resolution, but a negotiated settlement in which Meta paid nothing on the largest fine. The underlying jurisdictional question remained unsettled, alongside years of uncertainty and a real exit threat.
When Politics Produce Bureaucratic Bloat
No market illustrates fragmented digital governance more sharply than India. Deepak Maheshwari, Senior Policy Advisor at the Centre for Social and Economic Progress (CSEP), catalogued at least seven central bodies with overlapping digital mandates in his Governing Digital India report: MeitY, DoT, MIB, TRAI, CCI, RBI and SEBI, alongside a new AI Governance and Economic Group.
The report organizes the regulatory landscape around a 3C framework: Carriage (infrastructure), Content (data and media), and Conduct (competition, cybersecurity and data protection).
Source: CSEP
The report describes India’s approach as “techno-nationalism”: using digital infrastructure for inclusive growth and exporting its own public-infrastructure model — distinct from America’s market-first approach, the EU’s rights-first approach, or China’s control-first focus.
As Maheshwari points out, India had 17 ministers in the central cabinet at independence in 1947; today, it has more than 50. That reflects the demands of governing a vast country — but by his account, political bargaining has also shaped the expansion.
“Today it’s the National Democratic Alliance, BJP plus many small parties, and those parties also have representation in government. That’s the political bargain — you have to create multiple departments and ministries to accommodate senior politicians.”
Deepak Maheshwari - Senior Policy Advisor, CSEP
Many companies have adapted to this environment, relying less on consistent regulation than on political relationships and regulatory navigation. “They do not want that structure to be broken,” Maheshwari said.
In the case of the National Payments Corporation of India, which runs the UPI payments rail, NPCI proposed years ago that no single provider hold more than 30% of UPI market share. The compliance deadline, however, “has kept on deferring — at least five or six times,” according to Maheshwari. Today, Google Pay and Walmart-owned PhonePe account for about 80% of UPI volume, more than 20 billion transactions a month.
CSEP’s analysis lays out three reform paths, differing in how much institutional disruption India can absorb:
- Preserve the current structure but improve information-sharing between agencies
- Create two ministries for carriage and content, consolidating today’s telecom, IT and broadcasting split
- Pursue full convergence — “One Ministry, One Law, One Regulator, One Tribunal” — in a single Ministry of Digital Ecosystem.
Maheshwari sees the middle path as the most achievable: “first, you consolidate all carriage in one place, and all content at one place.”
Yet even as these questions persist, India’s data centers are in their largest build-out cycle to date, with Microsoft committing $17.5 billion, AWS $35 billion, and Google $15 billion, while operators navigate more than 30 separate approvals. States have begun reducing that friction, with most now offering single-window digital portals to fast-track approvals, paired with a 20-year national tax holiday for foreign cloud providers. But these are narrower fixes for the barriers that investors encounter, rather than a more ambitious redesign of the ministerial architecture that runs against political considerations.
Brazil’s Deliberate Build
If India shows fragmentation calcified by incumbency, Brazil offers something closer to the opposite: institutional accretion by deliberate design. The GDPR-like LGPD was enacted in Brazil in 2018, and its enforcing agency, the ANPD, arrived folded inside the Presidency, with no independent budget, staff or legal personality of its own. The law took effect in September 2020, with administrative sanctions following in August 2021. What followed was a sequence of upgrades that tracked the regulator's growing capacity rather than getting ahead of it.
A 2022 provisional measure upgraded it to a “special autarchy,” giving it independent legal standing and the ability to litigate on its own behalf for the first time. September 2025 brought an interim measure, later converted into Law 15,352, that gave ANPD full regulatory agency status, created 200 permanent specialist posts, and established technical and financial autonomy comparable to Brazil's other major independent regulators.
Rebello frames the change not as a sudden leap, but as formalizing years of groundwork:
“The transformation came roughly five years after the LGPD was published. By then, many key issues had already been regulated, supervisory tools had matured, and strategic priorities had become clearer.”
Flávia Rebello Pereira - Partner, Technology, Data and IP Practice, Trench Rossi Watanabe
That interval allowed the regulator’s tools and priorities to develop as the law was implemented. Where mandates genuinely overlap, the friction is rarely legal contradiction. “The requirements are generally complementary,” Rebello said. “The practical challenge is governance rather than legal conflict.”
In January 2026, the European Commission granted Brazil an adequacy decision for EU-Brazil data transfers, covering personal data in both commercial and law-enforcement contexts across a combined population of about 670 million.
Source: European Commission
The Sandbox Reckoning
Regulatory sandboxes were meant to be exactly this kind of calibration mechanism — buying time for capacity to catch up. But more than a decade in, a reckoning is underway: many were a venture without an exit plan. And that temporary space only works if firms and regulators know what comes next.
“The better sandboxes tell firms at the beginning what the exit looks like. The [UK’s] FCA is a good example: testing lasts for a defined period, and if the firm needs authorization to keep operating, it has to obtain it. The harder cases are the ones where nobody really planned for the end — you get extensions, informal tolerance, or a company sitting in limbo waiting for rules that have not been written.”
Miriam Stankovich, AI and Data Governance Advisor
Where a sandbox has led to durable regulation, Stankovich says the difference comes down to institutional proximity. Kenya’s Capital Markets Authority ran a sandbox that included the crowdfunding platform Pezesha; Kenya subsequently adopted formal crowdfunding regulations. “The regulator running the sandbox was also close to the licensing and rulemaking process,” she said.
Her skepticism extends to the coordinating bodies that governments often create instead: “When the meeting ends, does somebody have a job to do? Is there a budget? Is there a date? If the answer is no,” she remarked, “you probably have a discussion forum.”
One practical way to address problems early, according to Stankovich, is procurement: governments can consider coordination requirements when they specify and select a vendor’s system, before it is embedded and costly to change. The point is to build a path from experimentation to an operational decision — not leave firms in a temporary regime indefinitely.
A Blank Slate Doesn’t Stay Blank
As Mondato has discussed previously, AI — unlike the digital public infrastructure projects that preceded it — arrives as something closer to a blank slate, at least in terms of dedicated institutional ownership. Steve Haley of the Mojaloop Foundation, whose payments work required bringing together central banks, mobile money regulators and microfinance supervisors that could each “torpedo initiatives,” told Mondato that AI “doesn’t have to contend with any of that.” It inherits 15 years of data-governance groundwork without the same entrenched regulatory turf.
That advantage won't last by itself. Malaysia's AI coordinating body — established in 2024 and formalized this year as AI Malaysia Berhad under the Ministry of Digital — is one attempt to fill that institutional space deliberately. Maheshwari notes that Malaysia built this capacity decades earlier with the Malaysian Communications and Multimedia Commission, created in 1998, which brought the country's separate telecom, broadcasting and postal regulators into a single body under one converged law — a version of the "One Ministry, One Law, One Regulator" model he sees as India's most ambitious, but least achievable, option. Malaysia had built that institutional muscle long before AI made the question urgent elsewhere. As Maheshwari put it, "for them it's not that difficult" to stand up a body like AI Malaysia today.
The countries using AI's narrow, unclaimed window to build that coordination architecture first — deciding early who decides, who pays, and what happens when legitimate mandates disagree — are the ones likely to avoid discovering, years from now, that they've built another India: well-intentioned agencies, each defending a legitimate piece of the mandate, yet unable to move as one; or another Nigeria, where three regulators each act correctly within their own remit — and the result is a multinational threatening to leave entirely.
Image courtesy of Conny Schneider
Click here to subscribe and receive a weekly Mondato Insight directly to your inbox.

When Your Identity Is Gone - And There's No One To Call