Setting the table…
In probably the most deregulatory Administration in history, I worked in the White House reg. office.
As an abstract maxim, I have for a long time believed minimizing the aggregate costs of regulations is a necessary condition for maximizing economic growth—for prudential and institutional incentive reasons.
My office used to be down the hall from the guy who coined “Bootleggers and Baptists.”
All of which is to explain this article’s title is meant to be mildly provocative. And also to hint it is a view arrived at from a very distant ideological origin. But what I mean “regulatory costs” is only within a specific category or condition, which I explain below—not a blanket advocacy for regulatory takeover of the economy. lol
Okay, How Much for a Single Toilet Seat?
For good reason we expect the government to economize wherever possible. Not that we believe it is good at doing so, but given the choice between the Defense Department buying $600 toilet seats and $7,600 coffeemakers or cheaper ones, the American public has a pretty obvious preference.
The infamous coffeemaker was the kind that goes on antisubmarine aircraft and akin to what commercial airlines pay because “you can’t just put Mr. Coffee in an airline.” The price of the other, not actually a toilet seat, was partly an artifact of government budgeting.
So it’s understandable that for years our military industrial base (MIB) defaulted to the cheapest options when it came to telecom equipment and security cameras. After all, they were still fairly high quality and got the job done.
Unfortunately the “price” does not reflect the “cost.” Just ask the victims of 2025’s DC mid-air crash advocating for mandatory ADS-B systems against concerns about the price.
Can You Hear Me Now?
As wireless communications, mobile phones, 5G, and wifi became a necessary part of the economy, DoD had to source all the equipment that makes that possible. When you’re talking about DoD-wide needs, you’re really talking about the broader MIB. Bases, dual-use airports, duty stations, commissaries, and all the contractors and vendors intertwined needed this communications infrastructure.
Except in highly-specialized, unusually sensitive settings it made sense to buy the lowest cost item that does what you need. Which is fairly simple in most cases.
Turned out the equipment best satisfying both conditions by far was all made in China. Chinese companies Huawei and ZTE (and various subsidiaries) ended up supplying most of the telecom tech for this purpose. Why?
notwithstanding what we know now, they tended to be pretty high quality
they priced 30-50 percent lower than anyone else
Base stations, routers, switches and much of the adjunct equipment used by our MIB came from these companies—as it does for much of the world. Outside of the MIB context, many rural areas which rely on a few or one wireless carrier were dependent on Chinese tech. Moreover many of these areas are adjacent to bases so it’s a double whammy. Of course it’s not limited to the domestic footprint: we have bases located across the world. Beyond the same integrated Chinese tech, Huawei phones and the like, quite popular in much of the world, were sold in on/near-base retailers. And why not? They were cheap and reliable.
As you may know we eventually learned that much of this technology permitted “backdoors” allowing outside parties to compromise security conditions even to the point of fully taking control.
All because we wanted to save on costs.
Some of these risks were known early on, but not widely accepted and far from universally understood. But cybersecurity risks are not conceptually new, and as I’ve written elsewhere, the specific nature leads to systematic deprioritization in both private and public sectors.
But that’s not regulatory, right?
Rip-and-Replace
Years on with the vulnerability now well-documented, savings or no this could not go on. Something had to be done.
For the government (including military) and all its contractors, the 2019 NDAA’s Sec. 889 mandated a regulation to address this. All federal acquisition is subject to a specific area of the federal regulatory code called appropriately Federal Acquisition Regulation. This is an incredibly dense, unintuitive, specialized body of rules that technically governs all government purchases.1
Most small vendors don’t ever immerse themselves in it because most sub-agencies and offices focus on particular sections of the code and make those available to the types of businesses focused on their specialty. But these rules also include government-wide conditions—things that should be applicable no matter what the product or use. There are security requirements in there for sure, including cases requiring domestic-based vendors.
The thing is…when it came to cameras, the kind used for perimeter monitoring and the like, used at bases and civilian federal buildings, we almost exclusively used equipment from Chinese company Hikvision, with the same backdoor vulnerabilities as the telecom equipment. But they didn’t have that name on the box. Hikvision is an OEM which makes essential components in cameras sold throughout the world by US and European companies like Honeywell, Carrier, and Bosch. Even some of those components don’t have giveaway brandingj, as they’re made for intermediaries and end-sellers using blank or custom branding. Many companies didn’t even know they were selling Chinese-originated products.
So along with the NDAA provision, which required through a rulemaking that all MIB contractors certify they have removed any elements from a list of blacklisted companies from their government-nexus footprint, Congress appropriated $1.9 billion to aid rural and small carriers in replacing their telecom stack. Collectively we call this process rip-and-replace. And it’s as disruptive as it sounds.
In theory the regulation means a contractor could violate federal law, or at least risk blacklisting, by falsely certifying compliance. But there’s no operative enforcement mechanism and no meaningful way to audit. The largest vendors risk a lot so they probably complied in good faith, but smaller ones bear less risk and may be ignorant of the rule.
One shouldn’t hazard a guess as to the degree of remaining exposure of our defense infrastructure, not to speak of the whole government. It’s unknowable. Confidently claiming full compliance would probably come at a nearly infinite cost.
To date there isn’t a fully domestic end-to-end telecommunications stack. The closest is Nokia and Ericsson so defaulting to “American providers” isn’t an option.
Just Own Up to It
I posit a defense of regulatory costs because all of this would have been feasible, and waaaay cheaper, if applied ex ante. The point is that these security costs are real and borne one way or another, either in the explicit recognition in policies including regulatory benefit-cost accounting, or later in painful retro-correction. More costly correction.
Fortunately some of the universal security risks like cybersecurity have become more salient but only quite recently. The story of Anthropic/Mythos - which BTW is still designated a “supply-chain risk” by the Pentagon - is about AI yes but cybersecurity risk in particular. And in an odd way it’s fortunate the risk framing isn’t about a specific vulnerability but a more global notion of cybersecurity risk. That’s a necessary condition for more earnest accounting for it in policy generally.
It means Congress as it appropriates acknowledges the trade-off of getting less of what they want because they’re actually paying a “cybersecurity markup.” Again, they’ll be getting less either way, and costing it up front is cheaper.2
It means regulatory analyses face up to the difficult truth of full cost accounting when developing rulemakings. Part of this process involves considering then deciding among multiple approaches (e.g., performance standards vs. design rules) and this should absolutely continue to favor the least costly option that accomplishes the policy aim. But “least costly” still applies when fulsomely acknowledging security risks.
Going forward this is absolutely germane to AI specifically. Mythos and Fable and the ensuing fallout finally took aim at the illusion of gob-smacking innovative AI capabilities will self-correct latent risks like cybersecurity. It could! But it’s not axiomatic. Markets are incredible at arriving at optimal solutions along multiple dimensions: costs, price, availability, aesthetics, and indeed safety. Further, many regulations as designed lead to consumer/business responses which actually inverts the purpose. Think of drivers being more reckless in response to safety features. But some externalities exist and are not foreseeably addressable through market mechanisms. At risk of tedious repetition: the resultant costs are borne somewhere at some point—consumer prices, national security, fiscal costs,…
There’s been a vocal and highly influential cadre of AI policy voices who exhort a kind of knee-jerk rejection of regulation in terms of imposing unnecessary costs on innovators. [Insert misapplication of “regulatory capture” here as one vector of this argumentation] Beyond the demonstrative internal contradictions, fallacies, and logical incoherence in much of this, these risks (read: costs) are already imposed. So think of it as displacing those costs with explicit regulatory costs if it makes it more palatable.
The author is Nonresident Senior Fellow at the Foundation for American Innovation
It’s why specialists in this arcane policy area make extremely good money and have extremely robust job security as consultants.
For some reason this reminded me of a time where I fruitlessly advocated for a regulatory budgeting bill with my fully uninterested committee colleagues (akin to but not this). Under no illusion of them going along, I perfunctorily responded to their skeptical questions in turn. But when it came to their criticism that my proposal was only structured around costs, and wouldn’t it be incomplete as a budget without accounting benefits? I didn’t have the heart to tell them that’s not how literally any budget works.



