Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC
Regulation

Regulation

Government and agency rules that mandate how APIs must behave

Regulation is where the politics of APIs gets the force of law, and it’s become one of the most consequential dynamics in the entire API economy. Regulation, in the API context, runs in two directions that are deeply intertwined: government rules that mandate how APIs must behave (data protection, security, access requirements), and government use of API mandates as a tool to regulate entire industries. I’ve watched both develop over fifteen years, and the through-line is that regulation has shifted from being a constraint that the API world worried about to being one of the most powerful drivers of API adoption there is. When a regulator decides that an industry must expose APIs — as happened with banking, healthcare, and others — regulation becomes the lever that forces openness, standardization, and access against the wishes of incumbents. The politics of regulation is the politics of using state power to shape how the API economy works.

The idea of API-driven regulation is one I was exploring remarkably early, and it’s held up. I wrote in 2011 about an API-driven government regulatory framework — the then-novel proposal that APIs could be a mechanism of regulation, letting industry demonstrate compliance through standardized data and APIs, and letting regulators verify it programmatically. This was a genuinely forward-looking idea: instead of regulation as paperwork and audits, regulation as machine-readable, API-mediated, continuously-verifiable compliance. By 2015 I was writing that talk of API-driven regulation was increasing, tracking how government was moving from merely defining standards to actively mandating APIs across industries. The vision that started as speculation in 2011 became reality over the following decade, as regulators increasingly used API mandates to achieve regulatory goals — transparency, access, standardization, competition.

The regulatory-beast dynamic is the political pattern I’ve found most instructive, and it explains why regulation keeps expanding. I wrote in 2016 that the Internet of Things shows us how regulatory beasts are created — the pattern where an industry’s failure to self-regulate (around security, privacy, safety) creates the conditions for regulation to emerge. When industries don’t govern themselves responsibly, regulators step in, and the regulation that results is often blunter and more burdensome than self-regulation would have been. I extended this to AI, ML, and algorithms in 2017, noting that regulations were creeping in on these fronts as the industry failed to self-regulate. The political lesson is that regulation is, in part, a consequence of industry irresponsibility — the regulatory beast is created by the failures that make regulation necessary. Industries that want to avoid heavy regulation have to govern themselves well enough that regulation isn’t needed, and most don’t.

The historical analogies are how I’ve tried to understand where API regulation is heading, and they’re genuinely illuminating. I dug into railroad regulation, the telegraph, and the telephone in the Gilded Age — writing in 2022 and 2023 about looking for lessons from railroad regulation to apply to API regulation and deregulation, and studying the political economy of the early telephone network. These historical parallels matter because the dynamics are so similar: a powerful new network technology creates enormous value, concentrates power in a few dominant players, raises questions of access and fairness, and eventually attracts regulation to constrain the power and ensure broad access. The railroads, the telegraph, the telephone all went through cycles of monopoly, public concern, and regulation, and APIs and the platforms built on them are following a recognizable version of the same path. Understanding the history helps me see that API regulation isn’t novel — it’s the latest instance of a recurring pattern in how society regulates powerful network technologies.

The platform-regulation question is the most politically charged current application, and I’ve argued that the tools already exist. I wrote in 2018 that a regulatory framework for Facebook and other platforms is already in place — meaning that the API management mechanisms (keys, logging, rate limits, audit trails, access controls) that the industry already uses are exactly the technical infrastructure regulation would need to constrain platform power. What’s missing isn’t the technical capability but the political will and the policy framework. This is a crucial insight: regulating platforms doesn’t require inventing new technology; it requires applying the existing API governance and management tools in service of public oversight rather than private control. The politics of platform regulation is fundamentally about whether society will use the tools it already has to hold platform power accountable.

The honest current assessment, which I sharpened in 2025, is that some industries genuinely need API regulation and that regulation is one of the most powerful forces shaping the API economy. I wrote about the top three industries in need of API regulation — payments, healthcare, and advertising — because these are industries where a few powerful players control data and access that affects everyone, and where API regulation is the lever for forcing standardization, transparency, and consumer access. The emphasis on the politics of APIs that I’ve increasingly brought to my work centers substantially on regulation, because regulation is where the political questions about APIs get resolved with the force of law. The deepest political truth about API regulation is that it’s the mechanism through which society decides whether the power that platforms and industries wield through APIs will be constrained in the public interest or left to private control. Regulation is the blunt but powerful instrument that appears when market forces and self-regulation fail to protect the public — when banking won’t open up, when healthcare locks patients out of their data, when platforms abuse their power, when industries refuse to govern themselves. The history of network technologies suggests that significant API regulation is not just likely but inevitable, because the concentration of power that APIs enable eventually attracts the regulation that power always attracts. The political question isn’t whether APIs will be regulated, but whether that regulation will be smart, effective, and genuinely in the public interest — or blunt, burdensome, and captured by the very interests it’s meant to constrain. That’s the politics of API regulation, and it’s one of the defining battles over how the digital economy will be governed.

References