跳到主要內容

Not Every Tool Fits: Realigning Policy Tension through Anti-Fraud Governance

Lesson 2.5 of Ten Lessons in Public Policy

This is a continuation of previous essays in this series—Lesson 2.5 presents a case. Not every tool works. Let us examine how anti-fraud governance reveals the deeper alignment between policy goals and policy instruments.

As previously mentioned, stability in aerial yoga does not come from elaborate poses, but from core activation and structural alignment. Yes, one can hang with one hand, rotate midair, or invert—but only if the cloth is firmly hooked, the core engaged, and gravitational tension channeled along a stable axis. If the anchor point is unstable, or the center of mass drifts, no amount of strength can hold the posture. One falls.

Policy governance is no different. Tools are not menus, not checklists, not an accumulation of technical fixes. They are structured institutional responses. They must align with policy intentions, embed within defined responsibility frameworks, and produce sustained governance tension. Without such alignment, no number of tools can stabilize a policy. Even the grandest goals will remain suspended, unable to anchor—there will be no elegant choreography of public action.

So once we have identified a problem and entered institutional space, the critical questions are:

  1. Can the policy goal be structurally positioned within existing governance?
  2. Can the tool bear the intended governance tension?
  3. If not, how must we redesign the system so that institutional strength can carry our intentions?

I. Combating Fraud: Not a Matter of Insufficient Effort

Today, “combating fraud” is among the most consensual and politically legitimate goals. Romance scams, false investments, impersonations, deepfake videos, overseas fraud syndicates—the velocity of fraud far exceeds the pace of laws, policy cycles, and platform accountability.

The government has been active: banks issue in-person reminders, telecom regulators monitor SIM registration, police hunt down money mules, the Ministry of Education promotes awareness materials, hotlines are deployed, the NCC and telecoms block suspicious signals. All the tools are in motion.

Yet cases do not abate. Fraud languages mutate. Media shift. Social trust thins.

The issue is not effort. Rather, it is effort without anchoring. When the aerial cloth isn’t secured, rotating midair is futile. As the previous lesson emphasized, governance is not about how much we do—but whether we act from the right position.

II. Why the Problem Persists: A Diagnostic

1. Blurred Objectives: Goals such as “increase awareness,” “reduce case numbers,” or “raise detection rates” sound intuitive. But from an institutional perspective, these are non-operational and non-positional. Institutions cannot absorb abstract emotions or ambiguous expectations. Without concrete mechanisms, there is no entry into budgeting, accountability, or policy memory. These become political phrases, not governable goals.

2. Tool Overuse: When tools become default responses to public pressure, the system enters a state of “instrumental clutter.” More campaigns, more patrols, more legislation—but if they do not align with structural goals, they do not generate governance tension. Policy becomes restless: much effort, little structure; high cost, low coherence.

3. Responsibility Misplacement: Governance rests on the balance of responsibility, risk, and resource. When telecom platforms passively respond to police requests without being embedded in law; when schools are tasked with outreach without interagency support—tools are activated without structural anchoring. The system is mobilized, but fragmented.

Platforms act on goodwill rather than obligation; government units lack synchronization. Early warnings lack systemicity, data remains siloed, and enforcement is domain-bound. The issue isn’t intention—it is the absence of institutional syntax. Everyone acts, no one aligns.

III. What Counts as a Structurally Supportable Goal?

A policy goal is not a vision statement—it is a piece of institutional engineering. It must meet three structural conditions:

  1. Positionability: Can it be assigned within a governance node and held accountable?
  2. Decomposability: Can it be translated into tasks concrete enough for budgeting, staffing, and scheduling?
  3. Tension Compatibility: Can it generate sustainable tension with existing risk frameworks and tool configurations?

Examples include:

  1. “Establish a blacklist API mechanism for reporting and freezing accounts.”
  2. “Create a shared database of scam-related keywords across platforms.”
  3. “Implement mandatory anti-fraud protocols within corporate compliance systems.”

These are actionable, durable, and absorbable by the system.

IV. Tools Are Not Selections—They Are Translated Syntaxes

Policy tools are not mere options. They are operational translations of responsibility. Activating a tool means activating a part of the system. If the tool cannot be understood by the institutional language, if it cannot be borne by the structure of accountability, or absorbed by the resource system—it remains inert. It spins, rather than supports.

V. The UK’s Governance Shift: From Prosecution to Preventive Obligation

In 2023, the UK enacted the Economic Crime and Corporate Transparency Act. One of the most structurally significant designs—at least from my own institutional bias—is the introduction of a new offense: Failure to Prevent Fraud.

It does not rely on harsher penalties. Instead, it requires corporations to prove that anti-fraud systems are in place. If they fail to demonstrate adequate preventive structures, they are criminally liable.

This marks a systemic reframing. The question is no longer: “Did you commit wrongdoing?” but “Did you build an internal structure to prevent wrongdoing?”

Governance shifts from state-centric enforcement to distributed institutional responsibility. Risk is no longer external—it is internalized. Systems are self-built. Accountability becomes endogenous. This is not just legal reform—it is a syntax shift in governance: from reactive enforcement to anticipatory design; from isolated functions to coupled structures.

VI. Governance Is About Precision, Not Volume

Aerial yoga teaches that movement succeeds not through effort alone, but through precision of force. Institutions are the same. Governance is not a question of scale, but of alignment.

Policy failure is rarely the result of laziness. It stems from misaligned entry points—problems misframed, goals unpositioned, tools uncoupled, and responsibilities dangling.

Governance is not about the number of things we do. It is about doing things at points where structure can carry weight.

If governance fails to hold, it may not be because we lack strength—only that we have yet to anchor it where it counts.

留言

這個網誌中的熱門文章

當法律跑在能力前面,執法就變成賭局

When law outruns capability, enforcement becomes a gamble. 歐盟最新提出的「數位綜合方案」,將原本預計自 2026 年起陸續落地的 AI Act 高風險義務整體延後,並對 GDPR 的若干適用標準作出調整。這一系列時間表與技術條文的修改;從法制運作角度看,其實是歐盟試圖重新修正過去幾年高度前傾的監管節奏。核心訊息很直接: 當規範在行政能力、標準體系與產業準備都尚未到位時提前生效,制度本身便會成為新的風險來源,同時對 法律確定性(Rechtssicherheit)與可執行性(Vollzugstauglichkeit)產生損害。 過去十年,歐盟在數位領域採取的是一套高度主動的立法模式:先以框架性規範設定邊界,再透過技術標準、指引與執法實務慢慢填補細節。GDPR、DMA、DSA 乃至 AI Act 無不如此。這樣的作法在政治上具有明顯的宣示效果,也強化了歐盟作為「規則輸出者」的角色。但在 AI 與資料治理領域,這種先立架構、後補能力的路線,逐步暴露出其結構性限制: Regelungsdichte(規範密度)可以很高,Vollzugskapazität(實際執行能力)卻未必能跟上。 AI Act 的高風險義務便是一個典型例子。法條要求涵蓋技術文件完整性、訓練資料可追溯性、模型行為監測機制、風險管理流程等多重層面,每一項都假設存在一套成熟的標準體系與行政審查機制。然而,相關技術標準仍在制定過程中,各國主管機關的準備度明顯不一,企業端也尚未形成穩定的 best practice。在這樣的條件下,法規若在原定時程強行生效,實務上極易出現「義務已存在,但合格標準與審查方式未臻明確」的狀態。 對企業而言,這意味著法規遵循被迫建立在猜測之上:不知道做到何種程度才足以被認定為合規,卻必須提前調整內部結構與資源配置。對主管機關而言,則是在執法時缺乏穩定的判準,不同成員國之間的差異難以避免。這種情形直接侵蝕了 Rechtssicherheit,使法律本身成為一種額外的不確定性,而不是降低不確定性的工具。從這個角度看,延後義務並非削弱監管,而是試圖讓規範重新落在與現實能力大致相稱的水位,回到 Verhältnismäßigkeit(比例原則)可接受的範圍之內。 GDPR 的調整呈現出相同的邏輯,只是焦點從 AI 行為,轉移到資...

The price of waiting: what Taiwan’s AI law reveals about regulatory uncertainty

As Taiwan advances its proposed Artificial Intelligence Basic Act, the debate has largely focused on familiar themes: ethics, principles, and the need for “responsible AI”. These questions matter. But they are not the most consequential ones. The more important issue is economic rather than moral. It concerns how law structures expectations, how uncertainty is distributed, and how delay becomes a rational response when judgement is deferred. Taiwan’s AI legislation offers a revealing case study in the political economy of regulatory uncertainty — and in the costs of asking markets to decide first. At a symbolic level, the Basic Act marks a clear shift. Artificial intelligence is no longer treated merely as a technical input or an industrial productivity tool, but as an object of public governance. Its deployment is recognised as having implications for legal responsibility, administrative authority and decision-making frameworks. Yet symbol and structure are not the same. The law’s...

REGULATE ONLY WHAT YOU CAN ENFORCE

The EU’s Digital Omnibus signals a critical pivot: admitting that premature regulation endangers the very certainty it seeks to create. The European Union’s introduction of the "Digital Omnibus" package—which proposes delaying key high-risk obligations under the AI Act and recalibrating GDPR standards—is more than a mere adjustment of timetables. From the perspective of legal operations, it represents a structural correction to a regulatory rhythm that has become dangerously front-loaded. The core message from Brussels is blunt: when regulations enter into force before administrative capacity, technical standards, and industrial readiness are established, the institution itself becomes a source of risk. Instead of fostering order, premature regulation simultaneously damages Legal Certainty ( Rechtssicherheit ) and Executability ( Vollzugstauglichkeit ) . The Structural Deficit: Density vs. Capacity For the past decade, the EU has pursued a hyper-active legislative model: set...