Essays & Research Notes

Threshold Effects

Rules change what organizations are required to do. They rarely change what they are. A weekly research series on the gap between the two — regulation, disclosure, governance, and the organizational capacity that actually decides outcomes.

by Timothy D. Spivey · RSS feed
1 min read

Why “Threshold Effects”

The name comes from econometrics — a relationship that changes character once a variable crosses a critical value. It is also a fair description of everything this blog will be about.

Meta
Read the post →
2 min read

Gulf Coast: Who the Money Moves Through

BEAD is finally putting fiber in the ground around northwest Florida and south Alabama. Five years of process decided who gets to build — and it wasn't construction capability that decided.

BEADBroadbandGulf CoastTelecom
Read the post →
2 min read

A Fair Fight with SOX 404

Arguing against myself: SOX Section 404 is the strongest counterexample to this series' thesis. The argument survives — but comes out more precise than it went in.

SOXRegulatory PolicyCompliance
Read the post →
2 min read

Say Something vs. Build Something

There are rules that require organizations to say something and rules that require them to build something. Only the second kind has a track record of changing what organizations are.

Regulatory PolicySOXTelecom
Read the post →
2 min read

The Dashboard Is Green

Goodhart's Law and Campbell's Law warned us fifty years ago: the metric changes what the organization reports, not what the organization is. We built the dashboards anyway.

MetricsGoodhart's LawData Governance
Read the post →
2 min read

What the Broadband Labels Revealed

The FCC's broadband nutrition labels were identical for all 35 ISPs a 2025 study scored. What the mandate produced depended entirely on what each organization already was.

TelecomFCCMandatory Disclosure
Read the post →
1 min read

Wanted: The Best Counterexample

The honest version of an argument has to survive its best counterexample. So: what's the strongest case of a rule that actually changed what organizations are?

Regulatory PolicyOrganizational Behavior
Read the post →
2 min read

Three Rules, Same Outcome

AI governance, compliance programs, mandatory disclosure: three domains, three rules, same outcome. The rule changes what organizations are required to do. It rarely changes what they are.

Regulatory PolicyMandatory DisclosureOrganizational Behavior
Read the post →
1 min read

Shadow IT Was the Rehearsal

Shadow IT persisted because unsanctioned tools solved real problems faster than approved ones. AI governance is replaying the same dynamic — in months instead of years.

Shadow ITAI GovernanceISACA
Read the post →
2 min read

Paper Trails and Shadow AI

Only 37% of compliance leaders can measure whether their programs work — and half the U.S. workforce is using AI at work without knowing if it's allowed. Why did we think a document was going to govern a behavior?

AI GovernanceShadow AICompliance
Read the post →
1 min read

Cover-Yourself 8-Ks

When the SEC required four-business-day incident disclosure, firms responded with “cover yourself 8-Ks.” Organizations don't respond to regulatory intent — they respond to regulatory incentives.

Mandatory DisclosureRegulatory PolicyCybersecurity
Read the post →
1 min read

The Faster-Is-Better Assumption

The assumption behind mandatory breach disclosure timing is that faster equals better. Across 1,054 breach events and three empirical channels, that assumption doesn't hold up well.

Mandatory DisclosureCybersecurityResearch
Read the post →