Law, Regulation & Liability · 2026-08-06

Taking Scale Seriously in Technology Law

Wake Forest Law Review, Vol. 61 (2026), pp. 393-433Original paperMarkdown source
legal theoryregulatory policythresholdsinfrastructure governancerisk assessmentregulators
Key Insight

Scale is not merely an amplifier of technological harm; it can change who is affected, what kind of harm exists, which actors hold power, and which remedies remain viable. Regulation that treats scale as multiplication will repeatedly arrive with the wrong problem definition, the wrong institution, and too little authority to intervene.

Review

McKenna and Hartzog argue that technology law relies on an underspecified idea of scale. Courts and regulators often treat scale as a quantitative question: more users, more transactions, more infringements, more damage. The article distinguishes that logic, described as “scale is more,” from cases where scale changes the character of the system itself. Under “scale is different,” increased adoption or aggregation can alter the population affected, generate emergent harms, invalidate the assumptions used to frame the original problem, and make previously plausible remedies ineffective.

This distinction matters because technology systems do not merely repeat discrete acts at higher volume. At sufficient scale they become infrastructure. Data collected from one group generates population-level inferences applied to others. Repeated algorithmic decisions can close entire opportunity pathways rather than produce isolated errors. Facial recognition can move from occasional misidentification to the elimination of practical anonymity. Manipulative interface choices can accumulate into an environment in which meaningful consent is structurally unavailable. Misinformation can shift from false claims to an attack on the possibility of shared truth. Each transition redistributes decision rights and expands the power of actors capable of operating across the resulting system.

The article identifies three recurring regulatory failures. Recognition failure occurs when individually minor effects conceal a qualitatively different collective harm. Framing failure occurs when an individual-rights or sector-specific lens excludes relational, structural, environmental, or market effects. Intervention failure occurs when regulators wait for evidence of mature harm and discover that the technology has already become economically, socially, or administratively entrenched. Scale therefore changes the timing, object, and institutional location of regulation, not merely the size of penalties.

The authors assemble examples from privacy, platform governance, AI training, automated decision-making, facial recognition, misinformation, scraping, copyright, electric vehicles, public health, and complex systems scholarship. These examples demonstrate that the same technology can cross from repeated individual effects into higher-order phenomena. Its contribution is a framework for asking what changes with scale before law selects an intervention.

That framework exposes the limits of prevailing governance models. Notice and consent assume that an individual can meaningfully manage repeated information choices. Private litigation assumes identifiable plaintiffs, attributable harms, and remedies that benefit the affected population. Linear penalties assume that multiplying the sanction by the number of violations tracks the resulting power or social damage. Sectoral regulation assumes that the relevant harm remains inside the jurisdiction that first recognised it. These assumptions fail when scale changes affected populations, creates cross-domain externalities, embeds dependencies, and gives a small number of firms infrastructural control.

The paper stops before turning its diagnosis into an operational regulatory method. “Start with scale” is directionally correct but insufficient for implementation. Regulators still need criteria for identifying a transition from quantity to qualitative change, evidence requirements for anticipated emergent harm, procedures for revisiting thresholds, and authority to intervene before full causal proof is available. Without those elements, scale remains a persuasive interpretive lens rather than a repeatable governance instrument.

The treatment of adaptive regulation also needs a clearer institutional model. Periodic reassessment requires data access, technical expertise, independent research capacity, cross-agency coordination, protected budgets, and the power to modify or revoke permissions. The paper recognises that complex systems cannot be governed through one-time ex ante rules, but does not specify who conducts the reassessment, how frequently it occurs, what triggers escalation, or how regulatory capture is constrained. Adaptive governance without allocated authority can become permanent observation without intervention.

The paper’s deeper implication is that scale changes the proper unit of governance. Once a technology functions as infrastructure, the central questions are no longer limited to whether individual conduct was lawful or whether a particular person suffered compensable loss. Governance must address who can alter system conditions, which populations are exposed without participation, how concentrated operators can be constrained, what forms of failure require suspension, and where affected parties obtain collective redress. This shifts law from incident processing toward institutional design.

A practical extension would translate the framework into a scale-transition assessment. Such an assessment should test for population spillovers, emergence, normalisation, path dependence, concentration of control, cross-sector externalities, remedy collapse, and reversibility. It should identify the evidence needed at each stage, assign a responsible regulator, define review intervals, and specify intervention options ranging from disclosure and design duties to deployment limits, structural separation, taxation, injunctions, or prohibition. It should also require an explicit account of who bears the cost of waiting.

The article establishes that scale is a governance variable because it can transform activity into authority. Its durable contribution is to show why legal systems that count harms without examining system transformation will repeatedly regulate the residue of technological power rather than the infrastructure producing it.

Key Insight

Scale is not merely an amplifier of technological harm; it can change who is affected, what kind of harm exists, which actors hold power, and which remedies remain viable. Regulation that treats scale as multiplication will repeatedly arrive with the wrong problem definition, the wrong institution, and too little authority to intervene.

Continue exploring

Related reviews

More in Law, Regulation & Liability
Law, Regulation & Liability · 2026-07-28

Targeted Report on Regulatory Challenges from Decentralised Finance

Financial Action Task Force (FATF)

FATF reframes DeFi regulation around observable control rather than claims of decentralisation, but its fallback for systems without an identifiable controller shifts enforcement toward adjacent intermediaries without defining the legitimacy, evidence standards, or redress required for that indirect control regime.

Law, Regulation & Liability · 2026-05-04

AI Agents Under EU Law: A Compliance Architecture for AI Providers

arXiv working paper

The paper’s decisive analytical move is to relocate AI agent compliance from model classification to action inventory: what the agent can touch, change, disclose, delegate, or trigger is the real regulatory map. Its unresolved weakness is that it treats provider compliance architecture as the main control surface while leaving legitimacy, redress, and affected-party power underdeveloped.

Law, Regulation & Liability · 2026-03-26

Legal Frictions for Data Openness: Reflections from a Case-Study on Re-use of the Open Web for AI Training

HAL / CNRS / Open Knowledge Foundation

The report’s deepest contribution is to show that openness without enforceable constraints is not neutral openness at all, but a governance vacuum in which shared informational resources are converted into proprietary advantage by actors with the scale to extract without reciprocating.