Evergreen
Regulatory Arbitrage vs. Evasion: A Product Governance Guide
Learn how regulatory arbitrage differs from evasion, why concealment changes the analysis, and which evidence a product team should preserve before launch.
Regulatory Arbitrage or Regulatory Evasion?
Regulatory arbitrage uses a real difference between rules, jurisdictions, classifications, or legal structures. Regulatory evasion tries to avoid a rule that applies, often through concealment, misrepresentation, obstruction, or a system designed to keep the relevant conduct out of view.
That distinction is useful for product governance, but it is not a legal safe harbor. Whether a rule applies and whether conduct violates it depend on the jurisdiction, facts, authority, and procedural record. Calling a strategy "arbitrage" does not make it lawful. Calling conduct "evasion" does not replace an agency or court finding.
The practical question for a product team is not which flattering label fits. It is whether the company can identify the rule, disclose the material facts, show the actual product to accountable reviewers, preserve the legal interpretation, and accept a decision that narrows or stops the launch.
flowchart LR
A["Clear compliant path"] --> B["Good-faith legal uncertainty"]
B --> C["Documented regulatory arbitrage"]
C --> D["Open noncompliance or challenge"]
D --> E["Material concealment"]
E --> F["Possible obstruction or adjudicated misconduct"]
B --> G["Qualified interpretation"]
C --> G
D --> H["Executive and legal escalation"]
E --> I["Stop and investigate through authorized channels"]
F --> J["Follow controlling process and remediate"]
Why the terms get confused
Startups often enter markets organized around older technology. A platform may connect participants in a way that does not fit a familiar license. A software product may cross borders before its team has built a jurisdiction map. A financial product may look like one category to its designers and another to a regulator.
Those conflicts can involve genuine uncertainty. They can also involve a known rule that the company would prefer not to follow. The external story may sound identical in both cases: the company is moving fast, incumbents dislike it, and the law has not caught up.
The difference appears in the evidence. A team operating in good faith should be able to show which rule it analyzed, which facts it gave the advice owner, how the product actually works, what contrary interpretations exist, who bears the downside, and what happens if the position is rejected.
The evidence becomes weaker when the business case depends on an official, auditor, customer, or counterparty seeing a different reality from the one the company knows to be true.
What regulatory arbitrage means
Regulatory arbitrage takes advantage of a meaningful difference in legal treatment. The difference may arise between countries, states, entity types, licenses, product definitions, capital rules, tax rules, or reporting regimes.
Some arbitrage is expected. Legislatures and agencies create categories, thresholds, and exemptions. Organizations arrange their affairs within them. A company may choose one permissible charter, market, or product structure over another because the rules differ.
The governance risk is that form can drift away from substance. A team may select the label that produces the preferred result while leaving the actual function unchanged. A cross-border structure may appear lawful only because reviewers never received the full operating facts. A temporary interpretation may continue after the authority or product changes.
A defensible arbitrage record therefore includes both form and substance. It identifies the rule difference, why it applies, who supplied the interpretation, which facts were material, what could make the position fail, and when it must be refreshed.
What changes the analysis toward evasion
Concealment is the clearest warning. It can take the form of false statements, incomplete records, hidden counterparties, alternate interfaces, disabled logs, selected data views, misleading tests, or instructions that prevent an accountable reviewer from seeing the real operation.
Not every confidentiality control is concealment. A company can protect personal data, security methods, legal advice, or trade secrets while still giving authorized reviewers the evidence they need. The question is whether restricted access protects a legitimate interest or defeats the very oversight the review is supposed to provide.
The current Justice Department principles for corporate compliance programs focus on whether a program is well designed, adequately resourced and empowered, and working in practice. The guidance asks prosecutors to consider culture, incentives, discipline, internal complaints, monitoring, testing, and remediation. It also says the existence of a compliance program does not by itself justify declining charges.
That is a useful warning for product teams. A legal memo, code of conduct, or executive approval cannot cure missing facts or a product state that the reviewer was never allowed to see.
A six-question evidence test
The first question is jurisdiction. Which country, state, city, regulator, license, contract, or platform rule governs the exact activity? A broad statement that "the law is unclear" is not enough.
The second question is the product fact pattern. What does the system do for an ordinary user, a selected cohort, an administrator, an auditor, and a regulator? Which data selects each path?
The third question is disclosure. Did the accountable legal and domain reviewers receive the material facts, working flow, data map, failure states, and business objective? Advice based on a partial story should remain conditional.
The fourth question is authority. Who owns the interpretation, and what qualifies that person or body to make it? An internal preference, outside-counsel view, regulator statement, agency order, and court judgment do not carry the same weight.
The fifth question is affected risk. Who can lose money, access, safety, privacy, due process, or a legal right if the interpretation fails? A reversible software flag may still create irreversible harm.
The sixth question is outcome and procedure. Was the position accepted, challenged, enjoined, settled, changed, or adjudicated? An allegation is not a finding. A reported inquiry is not a charge. A policy change is not a legal ruling.
Where Greyball fits
Uber's March 2017 statement acknowledged technology that could hide the standard city view from an individual rider and show a different version. Uber described legitimate and protective uses, then said it would prohibit use to target local regulator action going forward.
Portland's Greyball audit report found that 17 accounts had been tagged during the city's December 2014 unauthorized-operation period and identified 16 as government officials. The report is available through a third-party mirror and describes limits in the city's access to records.
Those sources make Greyball a strong governance example because the product's alternate state and the identity of selected users were central to the oversight question. They do not create a universal legal verdict for every market or every use of the technology.
The right lesson is narrower. When the product identifies an oversight actor and changes what that actor can observe, the team has crossed out of ordinary feature management. The decision needs immediate legal, compliance, security, privacy, and executive review.
Why disclosure and counsel are not magic words
A company can disclose a plan and still be wrong. A lawyer can advise on facts that later change. A regulator can disagree with counsel. A reversible pilot can still violate a rule. An executive can approve a decision without having authority to waive the law.
The value of disclosure and advice is evidentiary and operational. They expose assumptions, create accountable ownership, and give the organization a chance to change course. They do not guarantee legality.
The Justice Department's September 2024 Evaluation of Corporate Compliance Programs is explicit that compliance is evaluated in design, resourcing, operation, and results. Product governance should use the same discipline. The working system and the operating evidence matter more than a polished policy alone.
The stop point
A product leader should stop the launch when material facts were withheld from the advice owner, when no accountable reviewer has seen the actual flow, when the feature depends on misleading an oversight actor, when controls cannot be tested, or when no one has authority and willingness to sign the decision record.
Stopping is not a declaration that a crime occurred. It is a decision that the organization lacks a defensible basis to proceed.
Use [[How to Design a Product Compliance Review]] to assemble the evidence. Use [[How to Build an Accountable Innovation Decision Record]] to preserve the decision, dissent, boundaries, and later outcome.
Editorial note
This governance explainer was developed with AI assistance from Venture Step E047 and the linked sources. Dalton Anderson remains the author. It is not legal advice and does not determine whether any reader's conduct is lawful. Legal, domain, source, and founder review are required. Publication is not authorized.
Sources
Follow the evidence.
- daltonanderson.ghost.io: ubers greyball the dark side of tech innovationdaltonanderson.ghost.io
- whistleblowers.gov: complaint pagewhistleblowers.gov
- uber.com: an update on greyballinguber.com
- theguardian.com: uber used greyball fake app to evade police across europe leak revealstheguardian.com
- courthousenews.com: GREYBALL AUDIT REPORTcourthousenews.com
- justice.gov: jm 9 28000 principles federal prosecution business organizationsjustice.gov
- youtu.be: TiC4GmwZ nsyoutu.be
- sec.gov: whistleblower protectionssec.gov
- open.spotify.com: 32iYem7RXAQ2R7WyHdRrscopen.spotify.com
- justice.gov: dljustice.gov
- justice.gov: corporate enforcementjustice.gov
- whistleblowers.gov: faqwhistleblowers.gov
- NLRB protected concerted activitynlrb.gov
- portland.gov: statement mayor ted wheeler allegations uber used greyball tool sidestepportland.gov
- sec.gov: report possible securities law violationssec.gov
- ftc.gov: bringing dark patterns lightftc.gov
- justice.gov: criminal division announces publication guidance evaluating corporate compliance programsjustice.gov
- whistleblowers.govwhistleblowers.gov
- content.govdelivery.com: 198c3edcontent.govdelivery.com
- portland.gov: 631393portland.gov
- yahoo.com: exclusive uber faces criminal probe 083701705yahoo.com