←back to Blog

When Compliance Workarounds Backfire

John Holcroft/Ikon Images

In 2021, Barcelona-based delivery platform Glovo was faced with a law that threatened its business model. Spain had passed the Rider Law, which introduced a presumption of employment when a digital platform organizes, directs, or controls couriers’ work, including through algorithmic management. Glovo came up with what seemed like a clever fix to avoid having to classify its couriers as employees: emphasizing courier autonomy by redesigning its app so they could log in freely, reject orders without explicit penalties, and choose a daily rate multiplier.

Three years later, however, it was clear that the fix had failed. Glovo and its parent, Delivery Hero, announced that they would hire roughly 15,000 couriers as employees in Spain, incurring a significant financial hit. The workaround had simply delayed the reclassification the company had sought to prevent. During this period, courier protests over lower earnings, along with mounting employment-related penalties and a criminal case against Glovo, increased its exposure.

Glovo reached for a common leadership response to unwanted regulation: minimal compliance. This involves making the narrowest changes a company believes will satisfy a rule while preserving how the business operates. But as algorithms become embedded in how companies deliver services and manage workers, that response is becoming a trap.

Leaders often default to workarounds or temporary fixes because they preserve the existing business model while avoiding a costly redesign. But this leads companies into what we call the algorithmic compliance trap. As Glovo’s case demonstrates, in algorithmic businesses, such fixes expand the audit surface, increase internal complexity, and invite scrutiny that can push the company toward the very redesign it was trying to avoid.

That said, not every regulatory change or instance of enforcement calls for a complete redesign. The hard question for senior leaders is when simple fixes are sufficient or a more significant rethinking of the business model is warranted.

We have developed a practical diagnostic for making that call. Drawing on five cases of algorithmic businesses facing major regulatory challenges in Europe — Glovo, Deliveroo, Airbnb, Uber, and Meta — we identified four signals that can help leaders judge whether workarounds are likely to stabilize a business model or accelerate a costly redesign.

Algorithmic Minimal Compliance: What It Is and Why Leaders Are Drawn to It

When regulation arrives, every business faces the same basic choice: absorb the cost of full compliance or find a way to meet the formal requirements while preserving the existing model. Historically, compliance could be layered onto the organization through policies, training programs, and designated controls while keeping core operations largely intact.

For algorithmic businesses, that separation is harder to maintain. Compliance often has to be built into the product itself: into decision logic, ranking systems, access gates, pricing rules, and automated enforcement. Changes in one part of the system can affect outcomes elsewhere and must continue to work at scale as the product evolves. That can make even genuine, good-faith compliance expensive and disruptive, and it creates a strong pull toward minimal compliance: modifying code, contracts, and workflows just enough to satisfy the formal requirements of a rule while preserving the underlying business model and what the system optimizes.

Algorithmic minimal compliance tends to appear in a few recurring forms:

  • Contract terms designed to pass a specific legal test.
  • Interface redesigns that signal autonomy while the platform continues to coordinate outcomes through incentives and information.
  • Data collection and reporting tools built for recurring obligations.
  • “Human review” steps that satisfy oversight requirements without shifting real decision authority.
  • Compliance programs that produce reports and process artifacts while the system continues to evolve.

None of these moves is necessarily made in bad faith. When rules are new and enforcement standards are still taking shape, a workaround can keep a business operating while leaders learn what regulators will actually test for.

Algorithms make these workarounds harder to contain for two reasons. First, code changes, contract amendments, and workflow redesigns leave auditable traces that a revised policy memo does not. A workaround intended to satisfy a formal requirement becomes a record and, in adversarial settings, may serve as evidence. Second, workarounds in complex, interdependent systems rarely stay contained. A change in one part of the logic can have ripple effects elsewhere, creating new inconsistencies and new exposures. What begins as a targeted fix can expand the audit surface faster than it closes it.

Four Red Flags That Suggest Minimal Compliance May No Longer Hold

Across the five cases, four signals help explain when minimal compliance remained viable and when it began to compound the problem.

1. Tightening legal clarity. Minimal compliance thrives in gray zones. As laws, rulings, and guidance become more specific, loopholes close and the design space for a workaround shrinks.

2. Increasingly visible harm. When social costs become visible to workers, users, communities, journalists, or public officials, regulators become less willing to accept fixes that change the optics without changing outcomes.

3. Intensifying regulatory scrutiny. Regulators often allow room for experimentation while new rules take shape. As they shift from guidance to information requests, investigations, coordinated enforcement, formal proceedings, and demands for proof, the room to rely on a favorable interpretation narrows quickly.

4. Increasing internal complexity. A workaround may begin as a narrow change. But when compliance touches multiple models, markets, and workflows, fixes begin to cascade. Each adjustment creates new inconsistencies, requiring further fixes and expanding the company’s exposure.

These signals reinforce one another. Tightening legal clarity, visible harm, and intensifying scrutiny raise the bar for acceptable compliance, while growing internal complexity makes that bar harder to meet through additional fixes. As the gap widens, the workaround begins to shape the product road map instead of protecting it, and leaders lose control over the timing and scope of redesign.

Consider these rules of thumb when determining your organization’s next move:

  • Zero or one red flag: A workaround may hold. Monitor and reassess as it meets operating reality.
  • Two red flags: The window is closing. Start redesign planning.
  • Three red flags: Escalation is likely. Fund a durable redesign path now.
  • Four red flags: Forced redesign is likely. Treat further workarounds as a cost multiplier and move to redesign.

Now let’s consider how those red flags played out across five cases.

Deliveroo and Glovo: Similar Services, Different Tests

U.K.-based delivery platform Deliveroo provides the clearest contrast to Glovo because, despite being in a similar business, its workaround held whereas Glovo ultimately abandoned its contractor model in Spain.

Deliveroo: A Narrow Fix That Held

In 2016, the Independent Workers’ Union of Great Britain petitioned the U.K.’s Central Arbitration Committee (CAC) for collective bargaining recognition on behalf of Deliveroo couriers. Under the statutory definition applied by the CAC, the dispute turned on “personal service”: couriers could qualify for union recognition only if they were required to perform deliveries themselves.

Shortly before the CAC hearing, Deliveroo introduced new contracts granting couriers a broad right to send substitutes and did not tightly police its use. The CAC examined the terms and actual practice, treated the right as genuine, and rejected the union’s claim. The U.K. Supreme Court later held that the couriers were not in an “employment relationship” for Article 11 trade union rights in that specific context. The decision was limited to the claim before it; it did not settle every employment-status question.

Deliveroo’s minimal-compliance response remained stable because all four red flags remained relatively weak.

  • Legal clarity: It was a narrow legal test focused on “personal service,” which Deliveroo could satisfy through a genuine substitution right.
  • Harm visibility: The dispute was technical and did not trigger broad public salience.
  • Regulatory scrutiny: The CAC accepted the contractual boundary as dispositive for this specific claim.
  • Internal complexity: The fix remained contained and did not require extensive reconfiguration of the platform’s core algorithms.

Glovo: When the Red Flags Stack and the Workaround Touches Core Economics

Glovo faced a broader legal question: whether couriers coordinated through its software were genuinely independent. Spain’s Rider Law was applied to examine whether the platform organized, directed, or controlled couriers’ work, including indirectly or implicitly through algorithmic management.

Glovo redesigned several parts of its app to make courier independence more visible while retaining its contractor model. Couriers could log in freely, reject orders without explicit penalties, choose a daily rate multiplier, and exercise wider substitution rights. Performance rankings were removed, and monitoring was reduced. With those levers loosened, the platform relied more heavily on pay parameters, bonuses, and information flows to balance supply and demand.

Glovo’s minimal-compliance response eventually encountered all four red flags.

  • Legal clarity: The Rider Law left little room for interpretive maneuvering because it reached mechanisms at the center of Glovo’s operating model. Unlike the CAC’s narrow personal-service test, which Deliveroo could address through one contractual change, the law required Glovo to demonstrate genuine independence across the entire operating relationship. Its product design therefore became evidence of organization, direction, and control.
  • Harm visibility: Free log-ins shifted supply-balancing risk to couriers through longer waiting times and greater earnings volatility. The rate multiplier also exposed couriers to price competition. Reports of lower earnings and courier protests made those effects visible.
  • Regulatory scrutiny: Authorities found that the platform still organized, directed, and controlled couriers despite the new autonomy features. They treated the redesigned model as continued false self-employment rather than a good-faith adaptation.
  • Internal complexity: Glovo loosened access and performance controls but still had to match volatile supply and demand. Service problems prompted further adjustments to pay parameters, bonuses, and incentives. Each correction made Glovo’s continuing authority over courier pay and access easier to trace.

As these signals reinforced one another, Spain’s Labor Inspectorate issued its first sanction against Glovo’s post-Rider Law model, and prosecutors opened a criminal investigation into whether the company had continued to deny couriers employment rights. In December 2024 — one day before CEO Oscar Pierre was due to testify in the criminal case — Glovo announced that it would move to an employment model in Spain. The shift would cover roughly 15,000 couriers, and Delivery Hero projected a 100 million euro (about $113 million) impact on Glovo’s adjusted EBITDA business in Spain for 2025.

The diagnostic may have been able to separate the two cases’ paths before the outcomes were known. Deliveroo remained in the zero or one range: Its change was narrow, genuine, and unlikely to spread through the operating system. Glovo entered implementation with two red flags because the law reached core coordination mechanisms and the response required changes across several parts of the platform. Visible harm and intensifying scrutiny then raised the count to four, well before the employment model announcement.

Leaders do not need perfect foresight. They need to count the warning signs early and count them again as their workaround meets operating reality.

Three Design Choices That Make Compliance More Durable

The Deliveroo-Glovo comparison shows why a rule’s reach and a response’s containability matter most. Three shorter cases show what durable compliance requires under different forms of digital regulation: building recurring obligations into the product, giving human reviewers real authority, and making performance continuously verifiable.

Airbnb: Compliance That Becomes Product Architecture

Some obligations are easier to contain because they are specific, recurring, and separable from core marketplace decisions. The European Union’s Directive on Administrative Cooperation in Taxation (DAC7), in effect since Jan. 1, 2023, requires platforms to collect and verify taxpayer information and report host and transaction data annually. The EU’s short-term rental data regulation, in effect since May 20, 2026, adds recurring registration number and activity data obligations where national registration systems apply.

Airbnb’s DAC7 process turns the obligation into a workflow: Collect taxpayer information, and notify hosts when data is missing. If a host still does not provide the information after being notified, Airbnb freezes payouts until the host complies. The newer regulation extends the pattern: Display and check registration numbers, remove listings when ordered to by authorities, and transmit activity data monthly. Because these controls apply to modular functions — identity verification, listing eligibility, payouts, and reporting — rather than core marketplace logic such as ranking, pricing, and allocation, they limit internal complexity and the audit surface.

Specific, recurring duties can become reusable product capabilities when the requirements are stable enough to be standardized across markets. Airbnb applies the same design logic to the newer short-term rental data regulation, although it is too early to judge the outcome. When a rule reaches allocation, pricing, evaluation, or control, reusable infrastructure can support compliance but cannot resolve the underlying operating issue.

Uber: When ‘Human Oversight’ Is Treated as Symbolic

Uber’s GDPR case shows why a human-review step cannot serve as a procedural workaround when the law tests whether oversight is real. Under the General Data Protection Regulation, people generally have the right not to be subject to decisions based solely on automated processing when those decisions produce legal or similarly significant effects, such as permanently losing access to work through a platform. Four drivers from the U.K. and Portugal challenged permanent account deactivations for suspected fraud. Uber argued that members of its operational risk team had manually reviewed each case. The Amsterdam District Court initially accepted that account, but the drivers appealed.

In 2023, the Amsterdam Court of Appeal reached different conclusions for the four drivers. For three, Uber had not shown how reviewers influenced the decision, what information they considered, or whether they had the competence and authority to change the outcome. The court described their intervention as “not much more than a purely symbolic act.” For the fourth, a personal interview before deactivation was sufficient to establish meaningful human involvement.

Uber did not establish meaningful human involvement for three drivers, and the court ordered it to provide information about the logic, significance, and consequences of the decisions within one month, subject to a daily penalty of 4,000 euros ($4,675) for noncompliance.”

In August 2026, the Dutch data protection authority fined Uber nearly 825 million euros ($951 million), finding that it had made fully automated decisions to deactivate drivers and had not adequately informed them. Uber appealed, and the authority said that the violations had stopped.

Meta: When Compliance Must Keep Working

Meta’s experience under the EU’s Digital Services Act (DSA) illustrates why launching a compliance tool may be insufficient when regulation depends on ongoing external scrutiny. The DSA requires very large platforms to provide eligible researchers with access to public data and to address systemic risks to civic discourse and elections. Meta launched its Content Library and API in late 2023 and subsequently announced that CrowdTangle — which enabled real-time data monitoring by researchers, journalists, and civil society groups — would close in August 2024. Access to its replacement required an application and was initially limited to researchers from qualifying academic and nonprofit institutions. The question was not whether Meta had created a replacement but whether it provided adequate access and real-time functionality.

In April 2024, the European Commission opened formal proceedings against Meta after raising concerns that the company planned to close CrowdTangle without an adequate replacement for real-time civic discourse and election monitoring. Researcher access was one part of a broader investigation. Meta added functionality to the Content Library and API but closed CrowdTangle as planned. In October 2025, the commission preliminarily found that Meta’s access procedures were burdensome and that the data made available to researchers was often incomplete or unreliable. The finding remained preliminary, and the proceeding was still open as of August 2026.

The test was practical: Could the replacement provide adequate access and functionality as Meta’s products and policies changed? Launching a tool establishes a process; it does not prove that the process works. When regulation requires ongoing external scrutiny, durable compliance depends on maintaining timely access to usable, reliable data as the product evolves.

What to Do Next: Five Operating Moves That Preserve Management’s Options

The algorithmic compliance trap’s greatest cost is the loss of choice. The diagnostic tells leaders when to escalate; the five moves below can be taken to change how the company evaluates, governs, and implements compliance before the outcome is known.

1. Start with what the rule actually tests. Translate the legal requirement into a concrete operating question. Deliveroo faced a discrete personal-service test; for Glovo, Spain’s broader test implicated nearly every mechanism the platform used to coordinate delivery. That breadth was an early warning. Map the requirement across contracts, algorithms, incentives, interfaces, workflows, and decision rights. Then ask what would have to change under strict, consistent enforcement. If compliance would weaken a core source of control or economic advantage, scope and fund a redesign alongside any limited response.

2. Stress-test whether the change will stay contained. Before scaling, use pilots and scenario tests to assess the combined effects on allocation, pricing, earnings, service quality, fraud, appeals, and adjacent workflows. At Glovo, changes to courier log-ins, rate multipliers, and rejection rights affected several outcomes and prompted further interventions. Treat new bonuses, exceptions, or controls as evidence that the response is spreading. Escalate it as an operating model decision before local corrections become embedded.

3. Set a stopping rule before approving the workaround. Define in advance what will trigger a redesign: a formal proceeding, a limit on financial exposure, sustained deterioration in pay or service, rising complaints, or repeated compensating interventions. Glovo’s successive interventions show why monitoring is not enough unless the threshold is set in advance. Each correction can look cheaper than redesign while cumulative exposure grows. Set the trigger, decision owner, and transition funding when the workaround is approved.

4. Build the proof that the compliance claim requires. Match evidence to the claim. Deliveroo’s substitution right was accepted in the CAC proceeding because couriers could use it in practice. Uber did not establish meaningful human involvement in the deactivation decisions involving three drivers; reviewers need the information and authority to change outcomes. The proceeding against Meta tests whether qualified researchers can obtain timely, usable, and reliable data. Build that proof alongside the response: Record changes and overrides, track affected outcomes, and rehearse what an external reviewer would ask the company to demonstrate.

5. Turn recurring, separable duties into product capabilities. Airbnb’s DAC7 process shows what reusable compliance infrastructure can include: tax data fields, user notifications, payout controls, and reporting workflows. Build such components for reuse only where requirements are genuinely equivalent, with shared specifications, testing, and version control as rules evolve. Reusable components can reduce local inconsistency when duties are separable from core decision logic. They cannot resolve rules that directly constrain allocation, pricing, evaluation, or control; those require an operating model decision.

Alongside these five operating moves, companies can seek clearer rules or interpretations through consultations, coalitions, standards setting, litigation, and engagement with policymakers. Channels vary by jurisdiction. These efforts should complement operational preparation, not delay it. Once authorities request records, inspect operations, or open proceedings, influence cannot replace a verifiable response. A company can challenge an interpretation while preparing to comply should the challenge fail.

Keep the Choice in Management’s Hands

A limited workaround may be sensible when a requirement is narrow, separable, and verifiable. Although these cases involve platforms, the diagnostic applies wherever connected systems shape consequential decisions — when banks allocate credit, insurers price risk, employers screen applicants, or retailers set prices. As generative AI enters these workflows, leaders must identify the model’s role, trace how its output shaped the decision, document the controls applied, and show how the result can be reviewed or challenged.

The risk begins when a limited response becomes part of the operating model. Glovo changed course after its workaround had spread and exposure had grown. Earlier action preserves a genuine choice among a contained fix, reusable compliance infrastructure, and deeper redesign. Once compensating changes shape core operations, redesign is no longer a future possibility; it is already happening. Management can direct it early or let accumulated workarounds dictate its shape.