Private regulation of cyber proliferation: from norm entrepreneurship to a quasi-export control regime
Lior Yoffe, Eviatar Matania, Udi SommerAbstract
This article explores the formation of a quasi-export control regime led by private technology and cybersecurity firms, aimed at curbing the proliferation of offensive cyber capabilities. While traditional export control regimes are state-driven and legally binding, this emergent framework is enforced through informal, decentralized mechanisms grounded in industry norms—particularly those articulated by the Cybersecurity Tech Accord (CTA). The article argues that prominent technology companies have evolved from norm entrepreneurs to de facto regulators by deploying enforcement tools that include public attribution reports, denial of digital services, strategic litigation, and collaboration with civil society. By analyzing key enforcement actions and the normative logic behind them, the article shows how this private regime replicates core features of formal export control—target identification, norm articulation, and sanctioning. This article also demonstrates how alignment with human rights principles shapes the application of sanctions in this regime. The asymmetrical treatment of similar firms underscores the conditional nature of market legitimacy in the digital ecosystem. Situated within broader literature on norm entrepreneurship and private authority, the article contends that this regime institutionalizes normative expectations without formal legal instruments. This article concludes by exploring the implications for AI governance and future export control frameworks in dual-use technologies.