Internet regulation is increasingly a form of economic governance. It shapes safety, rights, and sovereignty while also influencing how markets function and where economic value accrues. The internet no longer sits beside the economy as a discrete communications sector. It is embedded across production and trade, financial activity, labor markets, public administration, and the infrastructure through which other industries operate.

Across that economy, scale and inequality coexist. About 6 billion people, or 74 percent of the world’s population, were online in 2025, while another 2.2 billion remained offline. Internet use reaches 94 percent in high-income economies but only 23 percent in low-income ones.
Rules can correct market failures, reduce externalized harms, strengthen trust, and preserve competition. They can also raise transaction costs, discourage entry, protect incumbents able to absorb fixed compliance expenses, and fragment markets whose value depends on scale and interoperability. The defining regulatory question in 2026 is therefore not how much governance the internet requires, but which institutional arrangements improve economic and social outcomes once firms, governments, and users adapt.
Here are the most pressing and contemporary issues:
Artificial Intelligence From Rules for Machines to Rules for Markets
Artificial intelligence confronts regulators with an unusual sequencing problem: the institutions intended to govern it are being constructed while the technology itself is still changing. Telecommunications and privacy rules largely developed after their commercial structures became recognizable. AI governance is emerging while the technology’s capabilities, uses, and underlying economics continue to shift.
Early governance consequently emphasized broad principles of transparency and accountability, with additional safeguards built around identifiable applications. General-purpose AI weakened that approach because a single foundation model can operate across industries and public functions that historically faced different legal regimes. Regulation is moving from governing a specific automated decision toward governing a reusable technological capability whose eventual applications may not be known when it is created.

Capital and adoption are moving faster than the institutional response. Private AI investment grew 127.5 percent in 2025, while generative AI investment increased by more than 200 percent and captured nearly half of private AI funding. U.S. private investment reached $285.9 billion compared with $12.4 billion in China, although that measure does not capture the full scale of Chinese state-supported investment. Newly funded AI companies increased 71 percent, while 88 percent of surveyed organizations reported using AI. The United States produced 59 notable models compared with China’s 35. Rapid diffusion therefore coexists with significant concentration in frontier development and its supporting infrastructure.
Within that environment, regulatory interoperability becomes an economic variable. Governments will legitimately differ over how AI risks are assigned, evaluated, and governed. Friction rises when those differences require firms to duplicate testing and documentation or maintain separate product and compliance systems for each market. Much of that expense is fixed rather than proportional to revenue. A multinational may absorb it; a startup may conclude that entering the jurisdiction no longer makes economic sense. Regulation intended partly to constrain technological concentration can therefore reinforce incumbents if compliance capacity becomes another economy of scale.
National sovereignty faces a related constraint. Governments may possess legal authority over AI while depending on foreign infrastructure and expertise to exercise it effectively. Major cloud providers sharply increased capital expenditure during 2025, with Google alone reporting more than $150 billion in the AI Index’s discussion of frontier-compute economics. Regulatory sovereignty and technological capacity are not interchangeable.
Predictable governance can nevertheless reduce costs that markets would otherwise bear as uncertainty. Clear rules can make adoption easier for institutions that cannot deploy consequential technologies without knowing how responsibility will be assigned. Compatible evaluations and mutual recognition can similarly lower the cost of regulatory diversity without requiring a universal AI code. The economic test is whether governance broadens responsible participation or leaves frontier AI increasingly concentrated among the firms and countries already wealthy enough to build, access, and regulate it.
AI Investment and Market Capacity
| Country | Private AI Investment, 2025 | Newly Funded AI Companies |
|---|---|---|
| United States | $285.9B | 1,953 |
| China | $12.4B | 161 |
| United Kingdom | $5.9B | 172 |
| France | $4.4B | — |
| Canada | $4.3B | — |
Sources: Stanford Institute for Human-Centered AI
Cybersecurity and the Price of Trust
Cybersecurity has moved from a specialized problem of computer misuse to a condition of ordinary economic continuity. Early cybercrime law concentrated on unauthorized access and fraud, with additional rules addressing malicious software and electronic evidence. Digital dependence has changed the scale of the problem because failures can now transmit losses through organizations and public services far removed from the system first compromised.
Visible losses are already substantial. The FBI’s Internet Crime Complaint Center recorded more than 1 million complaints in 2025 involving $20.877 billion in reported losses, up 26 percent from the previous year. That partial U.S. record alone captures significant economic damage. Many breaches also begin with exploited vulnerabilities or involve ransomware, but payment represents only part of the cost. Disruption and recovery can impose substantial losses even when no ransom is paid.

As firms rely on systems they do not control, cybersecurity increasingly resembles a network externality. A hospital can lose patient-record access because a supplier is compromised, while a retailer can lose payment capacity through an external service failure. Underinvestment by one organization can impose costs on businesses and people who had no role in choosing its level of protection. Software supply chains magnify that exposure because a vulnerability in a widely used component can propagate across thousands of organizations.
Those externalities help explain why cybersecurity regulation has expanded beyond criminal law toward broader corporate responsibility and infrastructure resilience. Disclosure requirements and supply-chain standards increasingly support the same objective. International cooperation is evolving for a similar reason. The United Nations Convention against Cybercrime was adopted in December 2024 and opened for signature in October 2025, when 72 states signed during the opening ceremony. It addresses the persistent mismatch between globally distributed cybercrime and territorially bounded investigative power. Stronger cooperation can improve enforcement, but cross-border evidence mechanisms can also expand state access to information and intensify legitimate concerns over privacy and civil liberties.
The economics resist a single headline measure. Direct losses differ from the broader costs of defense, disruption, and recovery, as well as from the economic activity made possible by greater security. Payment protection and encryption raise operating expenses, as do backups and incident response, but those measures also support transactions that customers might otherwise consider too risky. Defensive spending is therefore not automatically deadweight loss.
Reporting mandates and treaty signatures reveal institutional activity; resilience appears further downstream. Changes in losses and operational disruption provide one measure, while recovery performance and security costs reveal whether incentives actually changed. The objective is not to eliminate cyber risk, which is unrealistic, but to allocate responsibility so that digital dependence does not make one organization’s weakness an unaffordable risk for everyone connected to it.
Internet Crime Losses by Age Group
| Age Group | Complaints, 2025 | Reported Losses |
|---|---|---|
| Under 20 | 31,254 | $67M |
| 20–29 | 112,069 | $563M |
| 30–39 | 153,293 | $1.7B |
| 40–49 | 167,066 | $3.0B |
| 50–59 | 124,820 | $3.7B |
| 60+ | 201,266 | $7.7B |
Sources: FBI Internet Crime Complaint Center
Data Governance and the Economics of Trust
Data governance is often framed as a contest between privacy and commercial efficiency, but the deeper problem is how economies govern an input that crosses borders easily while the laws controlling it remain territorial. Information increasingly participates directly in production, from fraud detection to cloud services and artificial intelligence. Data policy consequently extends well beyond privacy into the broader economic and strategic environment.
Governments have legitimate reasons to care where sensitive information is stored, which courts can compel access, and whether strategically valuable data become inputs into foreign systems. Yet localization and incompatible transfer requirements can also duplicate infrastructure and raise the cost of serving customers across borders. A small retailer selling internationally may depend on payment processing in one jurisdiction and cloud infrastructure in another. A regulatory difference that appears to concern privacy can therefore become a market-entry decision.
OECD-WTO modeling shows why neither maximal openness nor maximal control provides a straightforward economic answer. Complete global data autarky is modeled to reduce global GDP by 4.5 percent and exports by 8.5 percent. These are scenarios rather than observed outcomes, but they capture the economic value associated with cross-border information flows. Eliminating data-flow regulation altogether also performs poorly: global GDP falls by nearly 1 percent and exports by just over 2 percent because lower transaction costs are offset by diminished trust. High-income economies could experience GDP losses exceeding 2 percent.

The strongest modeled results sit between those extremes. Relatively open regimes with safeguards produce gains of 1.77 percent in global GDP and 3.6 percent in exports, with increases above 4 percent of GDP for some low- and lower-middle-income economies. Trusted openness captures the underlying mechanism more accurately than either unrestricted flows or complete localization. Data remain sufficiently mobile to preserve scale while institutions provide enough protection to sustain confidence in that mobility.
Trust then feeds back into economic behavior. Consumers who fear misuse of financial information may transact less online, while companies may hesitate to move sensitive workloads into the cloud. Governments may respond to weak protections abroad with localization. Incidence also differs by market size. A large economy can impose expensive requirements while retaining provider interest; a smaller one applying the same rule may instead experience service withdrawal. Even localization varies materially by design, with OECD modeling placing the global GDP effect of storage requirements without outright flow prohibition below 0.1 percent in one scenario.
Artificial intelligence adds another layer because domestic data storage does not guarantee domestic control over economically valuable processing. Information can remain inside national borders while computation depends on foreign cloud infrastructure or external models. The emerging economic boundary is therefore wider than data residency. Effective governance must preserve enough trust for information to move without making participation or cross-border exchange uneconomic in the markets that stand to gain most from digital integration.
Economic Effects of Data Governance Regimes
| Modeled Regime | Global GDP Effect | Global Export Effect |
|---|---|---|
| Complete fragmentation | −4.5% | −8.5% |
| Removal of safeguards | Nearly −1% | Just over −2% |
| Trusted openness | +1.77% | +3.6% |
Sources: OECD, World Trade Organization
Platform Governance and the Economics of Visibility
Most public debate about internet platforms begins with content, but economically the more revealing concept may be visibility. Modern platforms do more than host information. They organize digital markets through ranking and recommendation systems that reduce search costs while determining who gets discovered.
The scale of that allocation is enormous. Business e-commerce sales across 43 economies representing about three-quarters of global GDP reached roughly $27 trillion in 2022, almost 60 percent above 2016. Meanwhile, the five largest digital multinational enterprises increased their combined share of sales from 21 percent in 2017 to 48 percent in 2025. More than 70 percent of global digital advertising revenue is estimated to be captured by five platforms. Concentration alone does not establish misconduct, but it shows how much economic intermediation increasingly passes through a limited number of firms.
Local markets make that dependence more tangible. Pigu accounted for 68 percent of seller-side traffic among core general marketplaces in Lithuania in 2025. After Temu’s entry, a broader market definition produced shares of 42 percent for Temu, 32 percent for Pigu, and 18 percent for Varle. Those figures are specific to the studied market, but they illustrate how concentrated discovery can shape the commercial options available to sellers.
A restaurant can remain technically listed while becoming commercially invisible after a ranking change. A publisher can remain online while referral traffic collapses. Formal access is therefore not the same as economically meaningful access. Platforms increasingly resemble privately governed markets because they control participation and visibility while often competing with firms operating inside the same environment.
That structure creates a pronounced information imbalance. A platform may know far more about a merchant’s commercial performance than the merchant knows about how visibility is allocated. Discovery itself can become monetizable when businesses that lose organic prominence purchase advertising to recover customer access. Advertising can improve matching, but control over the route between seller and customer remains an economically valuable form of power.
Recommendation is not an unfortunate side effect of scale. Without it, vast digital catalogs become less useful and search costs rise. Governance therefore has to distinguish the efficiency created by ranking from the risks created by opaque allocative power. Generative AI may sharpen that tension because traditional search displays alternatives while an assistant may synthesize them into one or two answers. Businesses could move from competing for rank to competing merely for inclusion. The question is ultimately whether digital intermediaries can retain the efficiencies of discovery without making access to customers dependent on systems whose economic decisions remain largely invisible to the firms living under them.
Concentration Among the Largest Digital Enterprises
| Measure | 2017 | 2025 | Change |
|---|---|---|---|
| Top five share of sales | 21% | 48% | +27 pts |
| Top five share of assets | 17% | 35% | +18 pts |
Sources: UN Trade and Development
Digital Competition When Scale Becomes Structure
Digital competition requires separate treatment from platform governance because the underlying question is different. Platform governance examines how intermediaries exercise power inside their markets; competition policy asks whether credible alternatives can emerge at all. Digital markets complicate that question because many characteristics that make incumbents difficult to challenge also make their services valuable.
Network effects provide the clearest example. Communications systems become more useful as participation rises, marketplaces gain value as buyers attract sellers, and cloud providers spread expensive infrastructure across enormous customer bases. Scale is therefore not inherently evidence of market failure. Concern begins when scale hardens into structure. A new social network competes against an accumulated community, while a merchant leaving a dominant marketplace can lose customer access along with surrounding commercial services. Cloud migration can become expensive enough to outweigh a rival provider’s lower nominal price.
Contestability is consequently more revealing than firm size alone. A concentrated market can remain competitive when switching is easy and entry realistic. Several firms can occupy a market that remains effectively closed when structural advantages prevent meaningful challenge.
The concentration trend is nonetheless substantial. The five largest digital multinational enterprises increased their combined sales share from 21 percent in 2017 to 48 percent in 2025, showing how quickly economic power has consolidated. Investment is also shifting toward the infrastructure required to support advanced digital systems. AI infrastructure alone attracted an estimated $341 billion in 2025, while semiconductor investment grew rapidly over the previous five years. Future competition may therefore depend as much on access to capital-intensive upstream assets as on the quality of a new application or model.
A technically innovative startup can still depend on incumbents for much of the infrastructure and distribution needed to reach customers. Regulation therefore faces a genuine dilemma. Weak enforcement can allow temporary technological leadership to harden into durable control, while excessive intervention can damage efficiencies or discourage the investment required to build expensive infrastructure. The objective is not a predetermined firm size, but a market in which customers can switch and better products retain a credible route to demand.
The distribution of digital value makes the problem global. Digitally deliverable services represented 56 percent of global services exports in 2024 but only 16 percent in least-developed economies; another breakdown places advanced economies above 60 percent and developing economies around 44 percent. Platforms can expand export opportunities for smaller firms while high-margin revenues from intermediation and infrastructure continue to accrue elsewhere.
Participation and value capture are not synonymous.
Competition remains meaningful only when digital participation creates a plausible path to economic advancement rather than deeper dependence on established intermediaries. The decisive test is whether the next firm with a better product can obtain the resources needed to reach customers and capture enough of the value it creates to become a genuine competitor rather than another tenant inside somebody else’s market.
Capital Intensity and Digital Contestability
| Indicator | Value | Scope |
|---|---|---|
| AI infrastructure investment | $341B | 2025 |
| Semiconductor investment growth | 54% CAGR | 2020–2025 |
| Digital economy share of global FDI | 8.3% | Up from 5.5% |
| Digitally deliverable services | 56% | Global services exports |
| Digitally deliverable services | 16% | Least-developed economies |
Sources: UN Trade and Development
Children’s Online Safety and the Verification Paradox
Children’s online safety exposes one of internet regulation’s most direct economic questions: who bears the costs created by digital systems? Contemporary policy has moved beyond illegal material and parental controls toward the design of services themselves. The shift reflects a broader recognition that harm can arise from the incentives embedded in a product rather than only from individual pieces of content.
Digital participation is already too pervasive for simple exclusion to provide an easy answer. Ninety-eight percent of 15-year-olds in OECD countries owned an internet-connected smartphone, while 96 percent had access to a computer or tablet at home. About 40 percent of 10-year-olds already owned a smartphone. Protecting children therefore means governing environments in which they are deeply embedded rather than separating them from a marginal technology.
Age assurance has become a prominent response, but policy activity remains far more widespread than implementation. Twenty-five countries had age-restriction activity as of April 2026, while only Australia, Brazil, and Indonesia had laws then in force. An examination of 50 services used by children found that only two routinely assured age at account creation, revealing how often nominal minimum ages existed without reliable verification.

Australia provides the clearest large-scale test. Its minimum-age rules took effect on December 10, 2025, and major platforms restricted about 4.7 million accounts identified as belonging to children under 16. Australia has roughly 2.5 million children aged 8 to 15, so the account total greatly exceeded the number of individuals. The figure demonstrates implementation at scale, but cannot by itself establish whether children circumvented restrictions or experienced less harm after moving elsewhere.
The underlying technical problem is a verification paradox: identifying minors reliably can require assessing everyone. Government identification increases disclosure, while facial estimation and behavioral inference create different privacy concerns. Third-party verification introduces another institution that must be trusted. A rule intended to determine whether a 14-year-old belongs on a service can therefore require a 40-year-old to establish that they are not 14.
Economic effects also run in both directions. Verification requirements create demand for compliance technology and product redesign while imposing fixed costs that large platforms can absorb more easily than smaller services. Weak safeguards, however, can leave costs with families and public institutions rather than the firms whose designs contribute to the harm. Regulation may internalize some of those costs while creating new risks for privacy and competition.
Account removals are therefore only the beginning of the evidence. The more difficult test is whether underage use and measurable harm decline without producing widespread circumvention, privacy failures, or service withdrawal. Child-safety governance succeeds only if protection improves enough to justify the burdens placed not just on children, but on every user required to prove something about who they are.
Age Assurance: Exposure and Implementation
| Indicator | Observed Level |
|---|---|
| 15-year-olds with internet-connected smartphone | 98% |
| 10-year-olds owning a smartphone | About 40% |
| Countries with age-restriction activity | 25 |
| Countries with laws in force | 3 |
| Services routinely assuring age at signup | 2 of 50 |
| Australian under-16 accounts restricted | About 4.7M |
Sources: OECD, Australian eSafety Commissioner
Internet Openness and the Splinternet Without a Firewall
The internet does not need to break technically to fragment economically. Traditional discussion of the splinternet emphasizes firewalls and shutdowns, but a subtler form of fragmentation is emerging above the network. Countries can remain connected through common protocols while adopting increasingly different rules for digital activity.
Technical connectivity also conceals enormous differences in economic participation. About 6 billion people, or 74 percent of the world, were online in 2025 while 2.2 billion remained offline. Internet use reaches 94 percent in high-income economies but only 23 percent in low-income economies, and 96 percent of the offline population lives in low- and middle-income countries. Globally, 85 percent of urban residents are online compared with 58 percent of rural residents; in low-income economies, rural connectivity falls to 14 percent.
Even the category “online” describes radically different economic circumstances. Someone with stable broadband and modern digital tools is statistically equivalent to a person relying on an intermittent mobile connection, although their productive opportunities are not. More than half the global population is covered by 5G, and the technology accounts for more than one-third of mobile broadband subscriptions, but higher-quality connectivity remains concentrated in wealthier economies. Access is therefore a question of affordability and reliability as much as physical connection.
Sovereignty adds another layer because governments legitimately seek authority over domestic economic and security priorities. The economic question is how much regulatory differentiation a global network can absorb before interoperability loses value. The WTO’s 2026 e-commerce negotiations provide a concrete example. Members failed to continue the longstanding moratorium on customs duties on electronic transmissions, which lapsed on March 30, 2026. At almost the same time, 66 WTO members representing roughly 70 percent of global trade pursued an interim pathway for an E-Commerce Agreement. Universal consensus weakened while a narrower coalition pursued deeper alignment.
The resulting splinternet can be layered rather than technical. Different domestic rules may each serve defensible objectives while cumulatively increasing the fixed cost of international participation. A multinational can manage that complexity through specialized compliance operations. A five-person software exporter may simply abandon the market. Regulatory fragmentation can therefore behave like a non-tariff barrier without blocking a single packet.
Nor is sovereignty economically irrational. Digitally deliverable services account for only 16 percent of service exports in least-developed countries compared with 56 percent globally. Openness can create aggregate value while distributing it unevenly. The durable policy challenge is therefore interoperability rather than uniformity: enough compatibility for countries to retain legitimate regulatory differences without forcing firms to reconstruct their commercial operations at every border. The internet remains global in an economically meaningful sense only while people and businesses can still afford to use it that way.
Global Internet Participation Gaps
| Population Group | Internet Use | Gap from Comparison Group |
|---|---|---|
| High-income economies | 94% | +71 pts vs low-income |
| Low-income economies | 23% | −71 pts vs high-income |
| Global urban population | 85% | +27 pts vs rural |
| Global rural population | 58% | −27 pts vs urban |
| Low-income rural population | 14% | −44 pts vs global rural |
Sources: International Telecommunication Union
From Regulatory Activity to Regulatory Performance
Different areas of internet regulation appear to occupy separate domains. Economically, they increasingly share the same problem: governance has become part of the operating architecture of the digital economy.
Neither regulation nor restraint is inherently pro-growth. Data modeling produces losses under both complete fragmentation and complete removal of safeguards. Cybersecurity requirements impose costs while sustaining trust. Platform scale creates efficiencies alongside dependence, while child-safety rules can address externalities and create new burdens of their own.
The distinction that matters is between institutional activity and economic performance. Government and corporate actions describe what institutions are doing. Economic outcomes reveal what happened afterward, including whether markets became more productive, whether trust improved, and whether targeted harms declined.
Internet regulation increasingly resembles other economic infrastructure. Its value cannot be judged by how much of it exists, but by the activity it enables. The challenge beyond 2026 is to preserve the internet’s capacity to generate value while governing the risks created by that same scale, then judge institutions by whether outcomes actually improve.
TL;DR Summary
- Internet regulation increasingly functions as economic governance because digital rules shape investment, competition, productivity, trust, access, and value distribution.
- Regulatory performance is better measured through downstream outcomes than through the number of laws, investigations, fines, or compliance actions.
- AI governance can reduce uncertainty while fixed compliance costs may reinforce firms and countries already possessing scale and infrastructure.
- Cybersecurity rules address externalized risk, but their value depends on reducing losses, disruption, and systemic vulnerability.
- Data governance shows that both excessive fragmentation and insufficient safeguards can impose economic costs.
- Platform governance increasingly concerns visibility because recommendation systems allocate commercial opportunity as well as information.
- Digital competition depends on contestability, switching, infrastructure access, and the ability of new firms to reach customers.
- Children’s online safety creates a verification paradox because identifying minors can require age assessment across the wider population.
- The internet can fragment economically even while its underlying technical network remains connected.
- Regulatory interoperability can preserve legitimate national differences while reducing duplicated compliance and cross-border transaction costs.
- Lower-income economies face unequal connectivity and unequal capture of digital value, making openness and sovereignty distributional questions.
- Across all seven areas, the central test is whether governance produces better economic and human outcomes after firms and users adapt.
Sources
Artificial Intelligence From Rules for Machines to Rules for Markets
- Stanford Institute for Human-Centered AI; The 2026 AI Index Report; – Link
- European Commission; Governance and Enforcement of the AI Act; – Link
- European Commission; Standardisation of the AI Act; – Link
Cybersecurity and the Price of Trust
- FBI Internet Crime Complaint Center; 2025 IC3 Annual Report; – Link
- Verizon; 2026 Data Breach Investigations Report; – Link
- United Nations Office on Drugs and Crime; United Nations Convention against Cybercrime; – Link
Data Governance and the Economics of Trust
- OECD and World Trade Organization; Economic Implications of Data Regulation: Balancing Openness and Trust; – Link
- OECD; Cross-border Data Flows; – Link
- OECD; Data Free Flow with Trust; – Link
Platform Governance and the Economics of Visibility
- OECD; Competition and Consumer Policy in Digital Markets; – Link
- European Commission; Digital Markets Act Annual Reports; – Link
- UN Trade and Development; Digital Economy Report 2024; – Link
Digital Competition When Scale Becomes Structure
- UN Trade and Development; World Investment Report 2025: International Investment in the Digital Economy; – Link
- Competition and Markets Authority; Cloud Services Market Investigation; – Link
- UN Trade and Development; International Investment in the Digital Economy: A Toolkit for Policymakers; – Link
Children’s Online Safety and the Verification Paradox
- OECD; How’s Life for Children in the Digital Age?; – Link
- OECD; Age Assurance Practices of 50 Online Services Used by Children; – Link
- OECD; Social Media Age Restrictions for Children: Why They Are Rising and What Comes Next; – Link
- Australian eSafety Commissioner; Social Media Minimum Age Compliance Update; – Link
Internet Openness and the Splinternet Without a Firewall
- International Telecommunication Union; Facts and Figures 2025; – Link
- World Trade Organization; Agreement on Electronic Commerce; – Link
- World Trade Organization; Great Expectations: Quantifying the Potential Economic Impact of the WTO Agreement on E-Commerce; – Link