A rule creates the appearance of control the moment it is passed. Whether that control is real depends on enforcement, and enforcement is almost always slower, softer, and more self-reported than the rule implies and intends it to be. That gap is the single most useful thing to understand about how institutional crises unfold, and it's why reputational damage and formal verdicts almost never arrive on the same schedule.

The gap is structural, not accidental. This does not usually come down to incompetence. It's a design trade-off regulators make deliberately, often for defensible reasons. A rule that's easy to verify, a label exists, a form was filed, is cheap to enforce at scale but says nothing about whether the underlying claim is true. A rule that actually tests for harm or accuracy is more meaningful but requires case-by-case judgment that doesn't scale to every company, every claim, every year. Regulators consistently choose the cheaper, broader trigger over the narrower, truer one, because the alternative is enforcing almost nothing well rather than everything loosely. GDPR shows this clearly: strict on paper, backed by fines of up to 4% of global turnover, unevenly enforced in practice, concentrated through Ireland's Data Protection Commission, which regulates most major US tech companies' EU operations and has been repeatedly criticised by other regulators for slow, under-resourced enforcement relative to complaint volume.

Reputation moves faster than any formal process, and it moves first. When Volkswagen's emissions cheating became public in 2015, the stock lost roughly a third of its value within days, and "dieselgate" entered common use before a single jurisdiction had formally concluded anything. The actual legal resolution took years, in some jurisdictions the better part of a decade, and none of it changed the public verdict. It had already been reached, almost instantly, on far less complete information than a court eventually had.

A rule's formal enforcement operates on a legal clock, careful and evidence-based; reputation operates on a public-attention clock, fast and largely irreversible once it moves. An organisation waiting for the legal process to vindicate it before addressing the public one has already lost the window that mattered.

The practical implication: don't wait for the verdict to tell you what happened. By the time it arrives, it's usually just confirming a story the public already decided. The genuinely interesting analytical and investment work happens in the gap itself, while a rule exists but its enforcement is untested, while a company is still deciding how to respond, while the public narrative is still being actively contested rather than settled.

What this means in practice

  • When assessing regulatory risk, price the enforcement mechanism separately from the rule's stated penalty; the two are frequently uncorrelated, and the fine amount alone tells you little about how consistently a rule actually gets applied.
  • Treat the period between a rule taking effect and its first real enforcement test as the highest-information window, not a quiet one, since that's when the gap between the rule's promise and its practice becomes visible for the first time.
  • For governance and reputational risk specifically, the relevant question is never just "what does the rule require," it's "how far short of that does actual enforcement fall," because that gap is where cost quietly accumulates before anyone official says a word about it.