The Drawing Board for a prosperous future
Menu
Designed for the eighty: a senior managers regime for designated platforms
The Drawing Board
The drawing board for a prosperous future.
Paper 10
Technology
7,300 words
Rev. B · Aug 2026
TechnologyPaper 10

Designed for the eighty: a senior managers regime for designated platforms

The largest fine in European competition history came to fourteen days of Alphabet's revenue. By the time the appeals ended, revenue growth had cut it to just over four.

By Darach Ó Braonáin Aug 2026 · 7,300 words
The ask

That the senior manager architecture be extended to designated platforms: approved role-holders for user safety, data and privacy, algorithmic systems and novel-technology deployment, a responsibilities map with no gaps, and a personal duty to take reasonable steps. A five-year statutory evaluation should be legislated with it.

Decision sits with Ofcom for the mapping layer, under existing Online Safety Act powers, and with Parliament for the approval gateway and the personal duty.

Regulation of the largest technology firms is failing for a reason that has nothing to do with technology. The fines run to billions and amount to days of revenue. A penalty on that scale never reaches the person who made the decision, and was never built to. Most people, including most executives, do the right thing more reliably when the consequences of not doing it are real, personal and probable.

The United Kingdom has already built the instrument that makes consequences personal. The Senior Managers and Certification Regime, created for banking after 2008, attaches named individual accountability to specific responsibilities inside large firms. Extend that architecture to the technology platforms the UK already designates by law. Give a named senior manager personal accountability for deploying new and inadequately tested technologies, artificial intelligence (AI) foremost. The regime is not proven, and the pages below return to that. The case for it is that this is the only instrument on the table that reaches the person who decides, and that it can be built with a measurement commitment attached, so that within five years there would be an answer.

Three responses to incentives

Watch how people respond to any rule and three patterns appear. A minority do the right thing because it is the right thing, and would do it with no enforcement at all. A minority will do the wrong thing whatever the rules say, and can only be stopped, not persuaded. Everyone else, the large majority in the middle, does the right thing when doing the wrong thing carries consequences they believe in. Call it ten, eighty and ten. It is an observation from a working life, and the numbers circulate as a rule of thumb in the fraud-prevention literature with no measured study behind them. The precise split matters less than the design principle that follows. Rules exist for the middle group. The intrinsically honest do not need them and the determined defector ignores them, so a rule succeeds or fails on whether the conditional majority finds its consequences credible.

The research refines the observation instead of confirming it, and the refinements run in an instructive direction. The most useful finding is that the three groups are modes people move between, not fixed tribes. In a 2022 study by Baader, Gächter, Lee and Sefton, subjects played eight prisoner's dilemmas with systematically varied payoffs and no feedback between them, and more than 70% changed strategy at least once. A conditional cooperator in one game was a free rider in the next. The proportions move with the setting too. Pooled data from seventeen replication studies of the standard public goods game, covering more than 7,000 subjects, classifies roughly 61% of people as conditional cooperators and 19% as free riders, with the rest showing hump-shaped or mixed patterns, and finds genuinely unconditional cooperation rare. Where the test is a private lie instead of a group contribution, principled behaviour is commoner. In the canonical honesty experiment, 39% of subjects stayed fully honest when they could lie undetected at no cost. Aggregate data points the same way. Voluntary compliance with US federal tax sits around 85%, and all enforcement activity moves it about two percentage points, which is not what a world of eight-in-ten conditional compliers would look like. Where the heuristic errs, then, it errs on both ends. More than one in ten do the right thing unprompted, roughly two in ten will defect in a benign setting, and the conditional middle is closer to six in ten than eight. The middle remains the largest group and the decisive one, and its size is set by the structure it operates in.

Two further findings turn the principle into something a regulator can use. The first is that opportunity, not character, drives most observed wrongdoing. In a randomised audit study of more than 40,000 Danish taxpayers, evasion ran at 0.3% on income the authorities could verify against third-party reports and 37% on income they could not. The distribution of moral types barely matters next to the structure of verification. Half the UK tax gap, on the tax authority's own analysis, is carelessness and error, not defiance, a category a morality tale has no slot for. The second is the oldest result in criminology, restated by every modern review. The certainty of consequence deters; the severity largely does not. Adding police, which raises the chance of being caught, measurably reduces crime, while lengthening sentences barely moves it. Beccaria wrote that down in 1764 and the evidence has held ever since.

The corporate evidence points the same way, and it sets a limit on what any regime of this kind can claim. A systematic review of 106 studies of corporate crime deterrence found punitive sanctions alone, at company or individual level, showed few significant effects. The one intervention type with a consistent effect at both levels was the use of several at once, law plus regulation plus inspection plus engagement, and even there the effect sizes are small, around 0.10. No governance regime will transform behaviour. The most one can produce is a measurable shift.

The design principle assembles from these parts. A regime for powerful institutions verifies instead of trusting. Certainty that the responsible person will be identified matters more than the severity of what follows. The components have to arrive together, because single instruments show few significant effects on their own. What the conditional middle watches most closely is what it sees others doing. A single letter telling late taxpayers that nine out of ten people pay on time raised payment rates measurably across field experiments with more than 200,000 UK taxpayers, with no change to any penalty. The principle is general, which is why tax authorities moved to third-party reporting instead of bigger fines. Applied to the regulation of large technology firms, it exposes the current model as the design most likely to fail.

Consequences stop at the corporate veil

Measure the sanctions actually imposed on the largest technology firms against the scale of those firms, and the word "punishment" stops fitting.

The largest fine in European competition history, €4.34bn against Google over Android in 2018, amounted to just under fourteen days of Alphabet's revenue in the year it was imposed. Google appealed, as every firm does, and by the time the European Court of Justice issued its final judgment on 2 Jul 2026, seven years and eleven months later, revenue growth had shrunk the penalty to 4.3 days. The largest fine ever imposed under the General Data Protection Regulation, €1.2bn against Meta in 2023, was three and a half days of Meta's revenue. The first fines under the Digital Markets Act, in Apr 2025, were roughly twelve hours of revenue for Apple and ten hours for Meta. Four standing fines survive from nine years of European enforcement against Google, across five major cases with one annulled outright, and together they come to under eleven days of one recent year's revenue. In the United Kingdom, no large platform has been fined under the Online Safety Act at all. Ofcom's enforcement to date, roughly £5.5m across a series of small operators by Aug 2026, adds up to about nineteen minutes of Meta's revenue. The fined firms are tiny, so the comparison is not like for like. It still measures the distance between what the regime reaches and what it could reach, a ceiling of thirty-six days of Meta's revenue that has never been approached.

The standard response is that the ceilings should be raised. The record shows the ceilings are not the constraint. The Digital Markets Act permits fines of up to 10% of global turnover, yet every fine imposed under it so far has used between 1% and 3% of that maximum. The Online Safety Act permits £18m or 10% of qualifying worldwide revenue, whichever is higher, and the largest fine imposed under it is £1.35m. The law provides severe instruments; enforcement practice does not reach for them, and when it does the appeal process runs for most of a decade. Google Shopping took seven years and two months from decision to final judgment. Google's AdSense fine of €1.49bn was annulled in full after five and a half years. Intel's case ran fifteen years, ended with the original fine replaced by a fraction of itself, and left the Commission paying over €500m in default interest on the sum it had to repay.

The strongest counter-argument to all of this is that a fine is also a finding, and the finding can cost more than the penalty. When the European Court of Justice confirmed the Android judgment in Jul 2026 it activated the Antitrust Damages Directive, opening Google to follow-on claims from rivals and device makers that may in the end exceed the fine itself. The former president of the French competition authority has made the general version of the argument, that a fine's function is partly declaratory, establishing an illegality that grounds everything which follows. The reply is that this describes competition law, where a rival with a quantifiable loss is waiting to sue, and describes online safety and data protection barely at all. A teenager served self-harm content has no follow-on damages claim worth a law firm's time.

None of this is secret, and the people running the system have said so. Margrethe Vestager, the commissioner who imposed the three great Google fines, told the European Parliament in 2019 that "fines are not doing the trick and fines are not enough". In 2022 she observed that Apple "essentially prefers paying periodic fines, rather than comply" with a Dutch competition ruling, the cost-of-doing-business thesis stated on the record by the regulator watching it happen. When the US Federal Trade Commission announced its $5bn penalty against Facebook in 2019, the largest privacy penalty ever imposed anywhere and still, at twenty-six days of revenue, the most severe monetary sanction any major platform has faced, Facebook's share price rose. Commissioner Rebecca Kelly Slaughter's dissent drew the only available conclusion, that the market believed a penalty at this level made the violation profitable.

The deeper problem sits behind the arithmetic. Even a fine that stung the company would not touch the person whose decision caused the harm, and the insulation is structural. Under English law a company cannot indemnify a director against a regulatory penalty. In practice such penalties are not charged to directors at all, because conduct regimes address undertakings, not individuals. The company cannot recover its own fine from the individuals responsible either, as the Court of Appeal confirmed in the Safeway milk price-fixing case. It can lawfully buy insurance covering their defence costs. The loop is closed at every point. When Meta's shareholders sued its directors personally over the years of privacy failures behind the FTC penalty, in the first case of its kind to reach trial in Delaware, the claim settled on day two for $190m, paid entirely by the directors' insurance. No individual contributed anything.

The public record contains no case of a named senior executive at a major platform personally paying a regulatory penalty for a platform-conduct failure. The nearest is Uber's former security chief, convicted for obstructing the regulator's investigation, not for the conduct being investigated. The calibration of personal exposure makes the point arithmetically. The UK's digital markets regime caps personal penalties on a designated firm's nominated officer at £30,000, plus £15,000 a day where a failure continues, a headline figure worth under five hours of the annual pay of Apple's chief executive. At the other end of the ledger, chief-executive equity packages at the largest platforms now run to hundreds of millions over a single award cycle. Alphabet's board approved one in Mar 2026 worth up to $692m over three years, which converts to about two-thirds of the €890m that stands as the largest fine the European Union has imposed under the Digital Markets Act. The reward for growth is set by a remuneration committee and the personal penalty for harm by statute, and the two are four orders of magnitude apart.

The disconnection matters most where the reach is greatest. At a platform with tens of millions of users, a single product decision reaches more people than most legislation, and the commercial reward for the wrong one, shipped early, tested lightly, left running, scales with every user it touches. The personal consequence does not scale with anything. It is fixed at zero by the corporate design, however far the decision travels. This is the disconnection the whole section describes, decision-makers separated from the consequences of their decisions by the structure that employs them, and it is widest where the consequences are largest.

This is not an argument about bad people. Most of the people running these firms belong to the same conditional majority as everyone else. One Colombian public-goods experiment found that lower-status participants matched others' cooperation more readily than higher-status ones, which if it generalises is an argument for better structures and not for a worse opinion of the people. They operate inside an incentive field where shipping the unsafe feature or tolerating the known harm carries personal consequences of approximately zero, while the personal rewards for growth are among the largest ever offered to salaried employees. The conscientious executive who wants to slow a launch until the safety work is done gets no help from a system that will, at most, fine the shareholders half a day of revenue seven years from now. A structure like that recruits the conditional middle into the behaviour of the bottom ten. The fault is in the design.

The regime the UK already built

Connecting the decision-maker to the consequence is not an exotic demand. Medicine has never worked any other way. A hospital inpatient has a named consultant who is accountable for their care and safety, holds personal registration, and answers to a regulator that can end a career, and nobody argues that this deters people from becoming doctors. Banking is the sector that severed the connection and was made to restore it.

The United Kingdom has confronted this design failure before, in banking, and the diagnosis then reads as if written about technology now.

After the financial crisis, exactly one senior banker was held individually accountable for institutional failures of historic scale. HBOS's corporate division head was fined £500,000 and banned for life in 2012, and the regulator's own later review found that statutory time limits had barred proceedings against anyone else. The Parliamentary Commission on Banking Standards, reporting in Jun 2013, identified the mechanism. Top bankers dodged accountability "by claiming ignorance or hiding behind collective decision-making". Where ignorance was implausible, everyone had been party to the decision, so no one was to blame, a pattern the Commission called the Murder on the Orient Express defence. Responsibility had never been assigned to anyone in particular, so it could never be found anywhere in particular. The Commission concluded that senior executives needed "an incentive to know what is happening on their watch — not an incentive to remain ignorant in case the regulator comes calling". Corporate fines had been tried at scale and had failed; banks paid roughly $321bn in fines globally between the crisis and 2016, on Boston Consulting Group's count, with no clear relationship between the fines and the firms' subsequent performance. The regulatory response was to stop pricing wrongdoing at the corporate level and start assigning it at the personal level, restoring the connection between risk taken for profit and consequence carried by the person who took it.

The Senior Managers and Certification Regime, in force for banks from Mar 2016 and extended across the regulated financial sector by the end of 2019, has five load-bearing parts. The first is a closed list of senior management functions that no one may perform without regulator approval. The second is a statement of responsibilities, a signed document in which a named individual accepts named responsibilities. The third is a responsibilities map showing that every significant activity of the firm is owned by someone, with no blank spaces. The fourth is a duty to take reasonable steps, under which a senior manager answers personally where the firm fails in their area and they did not take the steps a person in their position reasonably should have. The fifth is a set of personal sanctions, running from fines set as a share of the individual's income to prohibition from the industry for life. Beneath the approved roles sits a certification tier for staff whose work can cause significant harm, which the UK is now removing from statute. One design choice was contested from the start. As the Commission recommended and Parliament first legislated, the duty carried a presumption of responsibility, with the burden on the senior manager to show they had taken reasonable steps. A 2016 Act reversed that before it ever commenced, placing the burden on the regulator, a softening the regime's leading academic critic argues may have neutered it.

The enforcement record is thin, and the thinness is the strongest objection this proposal will face. In the decade the statutory duty of responsibility has been in force, it has never once been the basis of a concluded enforcement case. The regulators have sanctioned four individuals for oversight failures of the kind the regime was built to catch. Barclays' chief executive Jes Staley was fined £642,430 in 2018 for his handling of a whistleblowing complaint. TSB's chief information officer Carlos Abarca was fined £81,620 in 2023 after the bank's catastrophic technology migration, for relying on assurances from an outsourced supplier without adequate independent verification. The chief executive of Wyelands Bank and one of its non-executive directors followed. On the Financial Conduct Authority's own count it has imposed eight financial penalties on individuals under the regime's conduct rules, across a regulated population of some 37,000 firms. It has sanctioned more than three times as many since 2022 under the regime this one replaced, for conduct predating it. The leading academic assessment answers its own title question, whether the regime is changing banking for good, with "at present, it is not", citing inconsistent messaging from the regulator and irresolute enforcement as the impediments, with the softened burden of proof compounding both. The firms themselves told the regulators in 2023 that there had been too few enforcement outcomes, and that a waning threat would weaken the regime.

Against the deterrence evidence, the record looks different. The regime's designers did not build an enforcement machine; the Financial Conduct Authority's own position is that the regime "should not be seen as primarily an enforcement tool". What the pre-2016 architecture had engineered to zero was not the size of any punishment but the probability that a failure would ever be traced to a person. The regime raised that probability sharply, from effectively nil to something every senior manager must reckon with, because a named person signed for the area and a map says so. Certainty is what deters, and under the old architecture the certainty of personal identification was the thing set to zero. That reading is consistent with the deterrence evidence. It is also untested, and no study directly compares individual liability against corporate fines as deterrents. When the Prudential Regulation Authority surveyed 120 firms in 2020, around 95% said the regime was having a positive effect on individual behaviour; in the 2023 review, 89% of respondents agreed it had made it easier to hold individuals to account. Those are perceptions, reported by interested parties. No independent measurement of changed decision-making exists.

The testimony consistently reports one mechanism. A named senior manager who has signed for an area changes what they demand before approving anything in it. They ask for independent verification instead of the delivering team's assurance, written confirmation from suppliers, documented go and no-go criteria, and a record of who dissented. An entire practice has grown up around evidencing reasonable steps, and the same practice has a defensive face, executives building files to protect themselves, which the regulator has recorded as a risk and nobody has measured against the verification face. The platform case tilts the balance toward verification, because the harms at issue are technical and testable, and a file is worthless if the test it documents was never run. That is the Abarca holding in one line, a personal penalty for accepting a supplier's word where independent verification was called for, and any technology executive who has signed off a major migration will recognise exactly what that precedent demands.

Two further facts matter here. Ireland and Australia have adopted close structural copies, and Hong Kong and Singapore lighter variants. The UK is meanwhile streamlining the original, with a stated ambition to halve its administrative burden, and the reform is unflattering to everyone involved. The government published no evidence for the changes, the driver is a competitiveness agenda with a numerical target, and one of the cuts replaces regulator pre-approval with notification for some roles. The Treasury is also removing the certification tier from statute with no replacement yet designed, and its own consultation response concedes that this could weaken firms' internal controls against misconduct. What survives is nonetheless telling. The named individuals, the allocated responsibilities, the reasonable-steps duty and the prohibition power all stay. The parts being cut are the parts that generated paperwork, and the parts being kept are the parts that create personal exposure. That is a revealed preference and not a finding, weaker evidence than a measurement, and still the best guide available to which parts of the architecture carry the load.

Banking is not the only place the UK has made this move. Without a second precedent, the charge that a finance-sector oddity is being bolted onto technology would be a fair one. After Grenfell, the Building Safety Act 2022 gave every occupied higher-risk building a named Accountable Person, with responsibility allocated to a defined part of a defined structure. That person carries a statutory duty to take all reasonable steps to stop building safety risks materialising, must maintain a documented evidence trail in the golden thread and the safety case report, and faces personal criminal liability that reaches corporate officers where an offence is attributable to their neglect. That is four of the financial regime's five components, in a sector with no connection to financial services. The component it lacks is the approval gateway, since the Building Safety Regulator is told who the Accountable Persons are and does not vet them. That piece exists elsewhere again, in health and social care, where the Care Quality Commission must be satisfied of a named registered manager's fitness before they may run a service and can prosecute them personally afterwards. Parliament has therefore already legislated both halves of what this proposal asks for, in two unrelated sectors, and has simply never combined them. Building safety is a caution as well as a precedent, because no Accountable Person has yet been prosecuted, so the argument from it is legislative and not proven in court.

A senior managers regime for designated platforms

The United Kingdom is well placed to act. The hardest design problem, deciding who a regime applies to, is largely solved in statute, and the pieces of personal accountability are already on the books, dormant.

Two designation machines are running. Under the Online Safety Act, Ofcom published its register of categorised services in Jul 2026, naming eleven Category 1 services, TikTok, Facebook, Instagram, YouTube and X among them, four Category 2A search services including Google, Bing and ChatGPT's search function, and twenty-four smaller Category 2B services. Under the Digital Markets, Competition and Consumers Act, the Competition and Markets Authority has designated Google for search and Google and Apple for mobile platforms as holding strategic market status, with a Microsoft investigation under way. The scope of the proposal follows the designations, in two tiers. The full architecture applies to Category 1 and Category 2A services and to firms with strategic market status, a population of roughly a dozen corporate groups. The tiering follows the diagnosis. The consequences of a decision scale with reach, so the duty to connect the decision to a person is heaviest where the reach is greatest. Category 2B services carry only a lighter duty that Ofcom's codes already gesture at, a named individual accountable to the service's most senior governance body, formalised and filed. Designation is contestable and sometimes contested, the register arrived a year late, and a court annulled part of Meta's parallel EU designation in Jun 2026 on procedural grounds. The machinery exists and is populated. It is not frictionless.

The politics of the proposal change once it is seen as completion. Parliament has already legislated personal senior-manager liability for platforms, four separate ways. Ofcom can require a provider to name a senior manager, who then commits a criminal offence if the company fails its information duties and the individual failed to take all reasonable steps to prevent it, with prison available for obstruction. Corporate officers face criminal liability where child-safety enforcement is defied. Designated digital-markets firms must appoint a nominated officer with personal civil penalties. Ofcom's illegal-content codes require every in-scope service to name an individual accountable for compliance at board level.

Every one of these mechanisms is dormant, and not only from regulatory reticence. The statute gates the senior-manager offence behind the full corporate enforcement sequence, and forces Ofcom to choose between fining a firm and prosecuting it, so the personal provisions sit at the end of a queue that never reaches them. The naming is reactive, the penalties are trivial against platform pay, and nothing involves approving anyone in advance or mapping who owns what. The pieces exist as fragments. The proposal assembles them into the standing architecture that banking has shown carries the load. The evidence supports reading it as a multi-component regulatory regime, approval plus mapping plus documented evidence plus supervisory engagement, with sanctions as the residual backstop.

Concretely, the regime places five obligations on the designated firm, three of them lifted from the banking regime. The state machinery behind them is set out in the next section.

Name the owners in advance. The regime defines a closed set of senior management functions for platform risk, each held by a regulator-approved individual with a filed statement of responsibilities. The functions track where the harm arises, not the corporate organogram, covering user safety, data and privacy, algorithmic and recommender systems and the deployment of novel technology.

Ownership has to mean something specific, and the safety function shows it most clearly. Bullying and harassment campaigns, intimate images shared without consent, and AI-generated deepfakes are harms whose damage compounds by the hour they remain live. The named safety executive answers personally for two things: whether the service took every step a person in their position reasonably could to prevent the harm arising, and whether each report was acted on at the speed the harm demands. Both must be demonstrable from contemporaneous records. None of the underlying duties is new. Parliament added intimate-image requirements to the Online Safety Act's enforcement provisions in Jun 2026, and Ofcom's open investigation into X concerns AI-generated sexualised imagery. What is missing is a named individual whose own position depends on those duties being met, which is the difference between a policy the firm has and a standard someone owns.

Map every significant activity to a person. The UK-regulated service files a responsibilities map with no blank spaces, so that the Murder on the Orient Express defence is structurally unavailable. Where harm is emergent and undecided, nobody having chosen the behaviour a recommender learned, the map still answers, because what it assigns in that case is ownership of the monitoring and rollback apparatus. The question "who decided this?" sometimes has no answer on a platform. The question "who owns detecting it and turning it off?" always does.

Make novel technology someone's signature. The senior manager for novel-technology deployment signs, before a new or materially changed technology reaches UK users at scale, that it has been tested against the firm's own risk assessment as the regulator has accepted it. The evidence must be documented, independently verified and open to inspection by Ofcom, which already holds audit, entry and inspection powers. That last point carries more weight than it looks. A file the firm generates and nobody outside ever opens is self-reported income in the Danish sense, and the tax evidence says self-reported is where the leakage happens; a file the regulator can and does inspect is verification by a third party. Anchoring the standard to the risk assessment the Act already requires makes the duty ascertainable rather than an invitation to hindsight, and anchoring it to the version the regulator has accepted stops a firm setting itself an easy examination. The statute, not the firm, has to define what counts as material and what counts as scale. Continuous deployment needs a matching shape, a standing attestation cycle instead of a signature per release, since a recommender retrained nightly has no go-live date.

This is the TSB precedent generalised. A bank's chief information officer was held personally accountable for accepting assurances about a systems migration without independent verification, and no principle explains why the executive shipping a frontier model or a recommender change to millions of children should carry less. Hong Kong already names information technology as one of eight functions requiring an accountable manager-in-charge, so the objection that technology is too fluid to own has been tested in another jurisdiction and rejected. A generative-AI product already sits on Ofcom's register in ChatGPT's search function. The designation machinery has arrived and the accountability layer has not.

Prove the authority behind the signature. A statement of responsibilities is invalid unless the firm can show that the named individual holds authority to discharge it. What counts should be specific. The individual sits in the documented approval chain for UK-affecting releases, the release process cannot proceed to UK users without their recorded decision, and the regulator can test both by inspection. A board resolution and a delegation letter are not enough, for the same reason a reasonable-steps file is worthless if the test was never run. This answers the structural difference between a bank and a platform. A UK bank subsidiary holds a balance sheet and a local board with real decision rights; a platform's UK entity typically does not control the recommender, and a signature without authority would manufacture scapegoats instead of accountability. The banking regime reaches the same problem from the other side, pulling a group executive who exercises significant influence over the UK business into the UK regime as a senior manager of it, and that route belongs here too for the cases where the real decision-maker sits abroad. The demand is extraterritorial in effect, since it obliges global firms to gate UK-affecting deployments on an executive answerable in the UK, and that is the price of the regime meaning anything. It also needs a stated consequence, because a gateway that never closes is not a gateway. If the authority is not granted and the role cannot be filled, the service is operating without a person the statute requires it to have, and the Online Safety Act's business disruption powers are the existing answer to a service operating outside its duties.

Attach the duty, gateway first, sanctions last. Where the firm breaches a regulatory requirement in a senior manager's area and the individual failed to take reasonable steps, the consequences are personal. The approval gateway does the quiet work, since an executive who cannot show a defensible control environment cannot take up the role. Why impose a gateway on a dozen platform firms at the moment the UK is removing it from thousands of financial ones? The answer is that the case for a gateway scales inversely with the population. Pre-approving individuals across 37,000 firms is an administrative burden with little supervisory return. Pre-approving a few hundred people at a dozen firms is a conversation a regulator can actually have. Below the gateway, the instrument that best fits a regime built on incentives is not a penalty at all but pay. Deferral of a meaningful share of the accountable individual's variable remuneration, with clawback where a failure in their area emerges later, is how the Australian regime does it, and it prices the risk into the reward instead of bolting a punishment on afterwards. Disqualification from senior roles in designated firms sits behind that. Its value is not severity, which the deterrence evidence says would matter little on its own, but that it makes identification consequential. Being named has to be worth avoiding for the certainty channel to work at all. Financial penalties come last and should be calibrated as a percentage of total remuneration, because a fixed cap of £30,000 is not a sanction at platform pay levels. On the burden of proof, a platform regime covering a dozen firms with the largest compliance functions on earth can defensibly sit closer to the Parliamentary Commission's original presumption of responsibility than to the softened compromise that commenced, and the choice should be made in the open.

What the state has to build

Three things are needed, and none of them is free.

Make one filing serve three regulators. Ofcom hosts the safety-facing functions, as the only regulator whose named-manager mechanism is already backed by personal criminal liability. The Competition and Markets Authority runs the competition-facing side through its nominated-officer machinery. The Information Commissioner's Office holds data and privacy, and starts closer than either, since the data protection officer is already a statutory named role with protected independence, though the role is advisory by design and would have to become an accountable one here. Three regulators reaching one executive will produce incoherence unless the statute prevents it, so the regime needs a joint footing of the kind the financial regulators already share. One statement of responsibilities, filed once, recognised by all three. Google, designated under two regimes at once, is the base case and not the exception.

Ofcom has to build a capability it does not have. An approval gateway with fitness assessments and regulatory references is new institutional capability for Ofcom, which today issues information notices and levies penalties and has never operated an approval function. For scale, the Financial Conduct Authority put one-off familiarisation costs at £43.6m across 37,000 firms for the streamlining alone. A gateway for a dozen firms is a far smaller undertaking, but it is not small enough to absorb, and it should be funded before it is legislated.

Legislate in two stages, and measure the result. The mapping and named-individual layer is reachable through regulator rules under existing Online Safety Act powers. The gateway, the duty and disqualification need primary legislation. Parliament has been moving the same way, because the Crime and Policing Act 2026 now makes companies criminally liable for their senior managers' offences, accepting the senior manager as the locus of corporate fault, and this proposal runs the same premise the other way. That Act is also the vehicle that carried the intimate-image requirements into the Online Safety Act's enforcement provisions. Since the original regime's besetting weakness was that nobody ever measured it, this one should be built to be measured. That means a baseline captured before commencement, a statutory independent evaluation at five years with published methodology, and four quantities counted from the start: documented pre-deployment evidence, escalation rates, launch delays for safety work, and time from harm report to action.

Who it catches

The obvious objection is that this is a law aimed at American companies. The criteria are origin-blind, scale, function and market power, and they catch whoever meets them. TikTok sits in the full tier today; British and European firms, Auto Trader and Mumsnet, Vinted and SoundCloud, sit in the lighter tier on the same statutory tests. It is true that the full tier lands almost entirely on US groups. Ten of the eleven Category 1 services and every strategic-market-status designation are American-owned, which describes where scale in consumer internet services currently sits, not a preference written into the rule. The same thresholds would capture a British or European platform the day it reached the same scale, and a regime built on designation criteria follows the market wherever it concentrates next. Compare the Senior Managers Regime itself, which applies to every bank above the threshold regardless of where its parent is headquartered, and which no one calls an anti-American statute.

The point of the regime is that its sanctions are rarely needed, because the conditional majority inside designated firms starts operating the way the conditional majority inside banks now reports operating. Safety work gets finished before launch because a named person will not sign until it is. Internal challenge gets heard because the senior manager who owns the area has a personal reason to want dissent on the record. Obstruction already carries personal criminal exposure, so the regulator gets answered. None of that requires a single enforcement case, and the five-year evaluation exists to test whether it is happening and not merely being reported.

Objections

Two objections arrive first in any room: investment chilling and the thin enforcement record.

"This will chill investment in the UK." The same argument was made against the banking regime, and no evidence of exit has emerged in a decade of its operation, through introduction, extension and copying abroad. That does not settle the question, since much else happened to the City in those years, but it puts the burden on the objector. The platform version's full tier applies to roughly a dozen firms designated for entrenched scale in UK markets. Firms with tens of millions of UK users do not exit a market that size over governance obligations their banking peers have carried for years; the register already names them, with the categorisation duties now in draft, and none has left. The chilling argument genuinely bites lower down, at the Category 2B threshold and the emerging-category watchlist, where a growing UK firm faces a step change in obligation. That is why the lighter tier must stay genuinely light, one named accountable individual and nothing else, and why the watchlist should work as a phase-in ramp, not a cliff.

"The banking regime barely enforces, so this is theatre." The record is four oversight cases and a never-used statutory duty, the regime's positive evidence is self-reported by the firms it regulates, and its leading academic assessment is negative. All three are set out above. The response is comparative. The alternative on offer is not a proven success either. It is corporate fines, tried at scale for two decades, and their failure is the better-evidenced of the two propositions. Nobody has run the direct comparison between individual liability and corporate penalty. What can be said is that one instrument demonstrably never reaches the decision-maker and the other is designed to, and that the untested option comes with a five-year measurement attached. The proposal also answers the academic critique on its own terms, calibrating sanctions to the population, restoring the burden-of-proof choice to open debate and putting the accountability message beyond regulatory equivocation by writing it into an approval gateway.

"Use the powers you already have." The first question any official will ask, and the dormancy argument invites it. Parliament has legislated four routes to personal liability. Ofcom has used none of them, has never made a business disruption order, has never approached the penalty ceiling, and delivered its register a year late. Why new law rather than enforcement of the old? The existing hooks are built to fail in ways that more of the same would repeat. They are reactive, triggered only when the regulator sends an information notice, so no standing map of who owns what ever comes into existence. They are gated behind the full corporate enforcement sequence, so the personal route sits at the end of a queue that rarely reaches it. The statute forces Ofcom to elect between fining a firm and prosecuting it. They attach to obstructing the regulator, not to the harm, and the digital-markets equivalent is priced at £30,000. Using the existing powers harder would produce more prosecutions for not answering letters. It would not produce an executive who has to be satisfied a system is safe before it ships.

"Executives will refuse the roles." The financial sector reports this friction, and the government's own consultation records that candidates from the US in particular are deterred by the UK's accountability framework, so the objection is real. Two things follow. The friction is partly the mechanism working, because a role that cannot be filled until the firm can show an incoming executive a defensible control environment is a role generating pressure for the improvement the regime exists to produce. The ask also stays proportionate, a few hundred individuals at a dozen firms, in some of the best-paid jobs in the world. Personal accountability commensurate with that reward is a fair term of trade, and the banking experience is that the roles fill.

"The UK cannot reach executives in California." The authority requirement is the answer. The regime does not pretend a UK signature controls a Californian decision. It obliges the firm to grant its UK-accountable executive the power to withhold UK deployment before the regulator accepts the statement of responsibilities, and it can reach a group executive directly where the real decision sits abroad. The limit is real at the margins. Small offshore operators have defied Ofcom, and 4chan has refused to pay its fines. The regime proposed here is for designated firms with billions in UK revenue, UK offices and UK payrolls, for whom an unfillable senior role or a disqualification order is a genuine cost. The firms most able to ignore the UK are precisely the ones designation excludes.

"Deterrence signals do not work on elites." A Minnesota field experiment raised audit certainty by letter, and the high-income group's reported tax liability then fell relative to control, the authors' own explanation being that sophisticated actors treat an audit as an opening position to negotiate against. The finding is real. The answer is that the regime's decisive instruments have nothing to negotiate over. There is no quantum in an unfilled approval or a disqualification, and reasonable steps are evidenced from records made before anything went wrong, which is a poor surface for bargaining afterwards.

"This moves the litigation upstream." Three things mitigate it. Whether obligations run pending appeal is a drafting choice, and the statute should say they do, which reverses the current position where categorisation duties are suspended once an appeal is filed. Disqualification's deterrent force depends less on speed than a fine's does. The ex ante components operate regardless of what is being litigated. The diagnosis of delay cuts against the proposal unless the drafting anticipates it. An appeal against a register entry or an approval decision becomes far more valuable once personal accountability hangs on it, and the banking regime's own longest-running individual case took nearly six years from the regulator's first letter to a final outcome.

"This is speech regulation by the back door." The regime governs who owns which process, and who answers for risk assessments being honest, for testing having happened, for the regulator being answered truthfully. It takes no position on any item of content. The serious version of the objection is the opposite one, that a personally exposed safety executive will over-remove to protect themselves, and the design answers it structurally, because the executive's exposure runs to process integrity, not to content outcomes. Taking more content down does nothing for a reasonable-steps file. What helps is evidence that the risk assessment was honest and the response apparatus worked.

Download as A4 PDF

Tell us where this paper is wrong, or where it could be stronger, at feedback@thedrawingboard.org.uk.

Papers are working drawings rather than final words. We revise them as events move and as better thinking arrives, and every revision is recorded at the foot of the paper.

Change history
  • Rev. B, 25 Aug 2026. Added the argument that the disconnection between decision and consequence is widest, and matters most, at firms with the greatest reach; the medical and banking framing of reconnection; and the note that the two-tier scope follows the same logic. Substance otherwise unchanged. Standfirst corrected to match the body's account of how the Android fine shrank.