# Regulation as the Timing Argument ## Retention is shifting from a cost line to a control point Three pressures arrive at the same buyer at the same time. **Volume.** DNS, firewall, authentication and application logs are growing faster than ingestion-priced tools can absorb economically. Cost pressure creates dropped logs and blind spots. **Regulation.** DORA, PSD2, GDPR, NIS2 and telecom retention rules require auditability and the ability to reconstruct an incident. Compliance now depends on holding complete evidence, not on holding a summary. **AI.** Security copilots and analytics need clean, contextual, retained telemetry rather than raw noise. The routing layer becomes the thing that prepares data for them. > [!important] Why regulation is the strongest of the three > Cost pressure can be deferred and AI plans can slip. ==A regulator's request for records has a date on it.== DORA in particular puts operational resilience evidence on a schedule for European financial entities, which converts retention from good practice into an obligation with a deadline. This is also what makes the Belgian bank conversation more interesting than its size suggests. It is compliance-led demand rather than cost-led, and compliance-led buyers move on timelines they do not control. ## Why it matters A cost-saving product competes with doing nothing. A compliance product competes with a deadline. The second is a far better place to sell from, and it is the argument that most clearly supports acting now rather than in two years. ## Related - [[Red Onion MOC]] - [[Sovereign Intelligence and the Copy That Stays]] - [[Who Buys and Why]] - [[The Cost of Keeping Everything]] - [[ESG Due Diligence Frameworks]]