# Regulation as the Timing Argument
## Retention is shifting from a cost line to a control point
Three pressures arrive at the same buyer at the same time.
**Volume.** DNS, firewall, authentication and application logs are growing faster than ingestion-priced tools can absorb economically. Cost pressure creates dropped logs and blind spots.
**Regulation.** DORA, PSD2, GDPR, NIS2 and telecom retention rules require auditability and the ability to reconstruct an incident. Compliance now depends on holding complete evidence, not on holding a summary.
**AI.** Security copilots and analytics need clean, contextual, retained telemetry rather than raw noise. The routing layer becomes the thing that prepares data for them.
> [!important] Why regulation is the strongest of the three
> Cost pressure can be deferred and AI plans can slip. ==A regulator's request for records has a date on it.== DORA in particular puts operational resilience evidence on a schedule for European financial entities, which converts retention from good practice into an obligation with a deadline.
This is also what makes the Belgian bank conversation more interesting than its size suggests. It is compliance-led demand rather than cost-led, and compliance-led buyers move on timelines they do not control.
## Why it matters
A cost-saving product competes with doing nothing. A compliance product competes with a deadline. The second is a far better place to sell from, and it is the argument that most clearly supports acting now rather than in two years.
## Related
- [[Red Onion MOC]]
- [[Sovereign Intelligence and the Copy That Stays]]
- [[Who Buys and Why]]
- [[The Cost of Keeping Everything]]
- [[ESG Due Diligence Frameworks]]