Amazon, New York City, and the Governance Gap Between Rules and Controls
Summary: New York City has issued cease-and-desist letters to more than 40 major retailers over the alleged sale of prohibited motorized scooters and e-bikes. Amazon says it is reviewing the identified listings and points to existing safety and compliance requirements. But the dispute raises a broader governance issue: having a policy is not the same as demonstrating that the underlying controls are operating effectively. This article examines the gap between documented requirements, marketplace enforcement, operational evidence, and defensible compliance.
Amazon’s response to New York City’s latest crackdown on prohibited e-bikes and motorized scooters raises a governance question that reaches far beyond micromobility, online retail, or municipal regulation.
It is a question organizations confront every day:
When a company says it has policies and controls designed to ensure compliance, what evidence demonstrates that those controls actually work?
That question becomes particularly significant in Amazon’s case because this is not the first time New York City has raised micromobility compliance concerns with the company.
The conversation goes back at least three years.
New York City Puts Online Retailers on Notice
Mayor Zohran Mamdani’s administration has issued cease-and-desist orders to 42 online retailers, including Amazon, Walmart, Target, Wayfair, and Temu’s parent company, alleging that they are selling high-speed e-bikes and scooters that cannot legally be operated in New York City. (New York City Government)
The city’s action targets several categories of devices, including stand-up scooters that exceed applicable weight or speed limits, e-bikes with motors exceeding 750 watts or capable of exceeding permitted speeds, and certain seated devices lacking required vehicle identification numbers. Retailers have been given until August 18, 2026, to comply, with potential penalties of $2,000 per illegal sale. (New York Post)
Amazon responded by emphasizing its existing requirements.
A company spokesperson said safety is a priority and that Amazon requires e-bikes sold through its store to meet applicable safety standards and Amazon policies. The company said it is investigating the products identified and expects to work with the mayor and City Council. (News 12 – Default)
That sounds reasonable.
But from a governance perspective, it is only the beginning of the answer.
A policy requiring compliance establishes what is supposed to happen.
It does not establish what actually happened.
This Conversation Started in 2023
The history matters.
On October 13, 2023, then-FDNY Commissioner Laura Kavanagh publicly released a letter to Amazon concerning lithium-ion batteries and powered micromobility devices being sold through the company’s marketplace.
New York City’s Local Law 39 had gone into effect on September 16, 2023. It prohibited the sale, lease, rental, or distribution of certain powered micromobility devices unless their electrical systems had been certified by an accredited laboratory to the applicable Underwriters Laboratories standard. Batteries were subject to corresponding certification requirements. (New York City Government)
The issue was not theoretical.
FDNY said at the time that it had already responded to 101 injuries connected to micromobility-device fires during 2023 and that 14 people had died. The department said uncertified batteries and devices remained available through Amazon. (New York City Government)
But one portion of Kavanagh’s letter is particularly important from a governance standpoint.
New York City officials had already met with Amazon’s public-policy team on June 1, 2023.
According to the FDNY, Amazon responded on June 26 that it was in the process of updating its policy and controls to align with New York City law by September 16. The October letter asked Amazon to confirm that only devices meeting the legal standards were being sold to New Yorkers. (New York City Government)
That changes the context considerably.
The issue was no longer simply:
Does Amazon know what the law requires?
There had already been a discussion about translating the law into marketplace policy and controls.
And There Was Some Progress
It would be inaccurate to suggest that Amazon simply ignored the 2023 concerns.
There is evidence that the company responded.
A December 2024 micromobility report from New York City Councilmember Gale Brewer noted that FDNY had sent letters in 2023 to Amazon, eBay, and Walmart asking them to remove micromobility products that did not comply with Local Law 39.
According to that report, Amazon agreed partially, while Walmart and eBay still appeared to offer e-bikes that violated the city’s safety standards. The report nevertheless recommended greater regulation of online sellers because online marketplaces remained an important channel through which noncompliant products could reach New Yorkers. (New York City Council)
That distinction is important.
Governance analysis should not begin with a predetermined conclusion.
Amazon appears to have made changes.
The relevant question is whether those changes became part of a sufficiently comprehensive, sustainable, and testable control environment.
2023 and 2026 Are Not the Same Compliance Issue
There is another distinction that needs to be made.
The 2023 dispute centered heavily on battery and electrical-system safety certification, particularly compliance with UL standards designed to reduce lithium-ion battery fire risk. (New York City Government)
The 2026 cease-and-desist action is broader. It concerns devices that the city says violate rules involving speed, motor power, weight, vehicle classification, and other requirements. (New York Post)
Therefore, the existence of allegedly prohibited products in 2026 does not, by itself, prove that Amazon failed to implement the specific battery-certification controls discussed in 2023.
That would be an evidentiary leap.
But the history does raise a more sophisticated governance question.
Once an organization has created marketplace controls for jurisdiction-specific micromobility regulation, how extensible is that control architecture when regulatory requirements change or expand?
Can it accommodate certification?
Motor wattage?
Maximum speed?
Vehicle weight?
VIN requirements?
Product classification?
Delivery jurisdiction?
Changes to seller descriptions?
Attempts to circumvent product restrictions?
That is where this story becomes much more important than a dispute over e-bikes.
Policy Is Not Control
Organizations regularly produce policies as evidence of governance.
They have cybersecurity policies.
Vendor policies.
Artificial intelligence policies.
Product-safety policies.
Data-retention policies.
Acceptable-use policies.
Marketplace seller requirements.
Those documents matter. Governance requires clear expression of organizational expectations.
But a policy is not the same thing as a control.
Suppose an online marketplace establishes the following requirement:
Products offered for sale must comply with all laws and regulations applicable in the jurisdiction where they are sold.
That is an entirely sensible policy.
Now the governance work begins.
How does the platform determine which regulations apply to which product?
How does it know the technical specifications of the product?
Who validates the seller’s representations?
What happens when the seller changes a listing after approval?
Can a product be displayed nationally but blocked from purchase in particular jurisdictions?
Does the control operate at listing creation, search, checkout, shipping—or all four?
How are newly enacted regulations incorporated?
Who verifies that the rules engine was updated correctly?
How are false negatives identified?
What happens when regulators identify products the marketplace did not?
What evidence is retained?
Those are control questions.
Control Is Not Evidence
Even the existence of a sophisticated control does not complete the governance chain.
The organization must be able to demonstrate that the control operated.
Consider a hypothetical automated control preventing a prohibited e-bike from being delivered to a New York City ZIP code.
The existence of the software rule is useful.
But defensible governance requires more.
What requirement caused the control to be created?
Who approved the rule?
When was it implemented?
Which products does it cover?
What attributes cause a listing to be blocked?
When was the rule last tested?
What were the results?
How many prohibited transactions did it prevent?
How many exceptions occurred?
Who investigated those exceptions?
Were similar listings searched for after an exception was discovered?
Was remediation completed?
Was the control retested afterward?
Now we are no longer discussing policy.
We are discussing evidence.
The Governance Chain
A mature compliance environment should establish a traceable relationship between:
Regulatory Obligation → Policy → Control Design → Operational Control → Monitoring → Evidence → Exception → Remediation → Validation

Every link matters.
A regulatory requirement without a mapped policy can be overlooked.
A policy without an operational control relies on human intention.
A control without monitoring may quietly stop working.
Monitoring without retained evidence creates assertions that may be difficult to defend.
Evidence without exception management records a problem but does not solve it.
Remediation without validation assumes the fix worked.
And a validated fix that is never fed back into the control architecture allows institutional learning to disappear.
Governance is therefore not a document repository.
It is a system of connected decisions, actions, controls, evidence, and outcomes.
Marketplace Governance Is Particularly Difficult
Amazon and other large marketplaces face a formidable control problem.
They operate at enormous scale while allowing third-party sellers to create and modify product listings across numerous product categories and jurisdictions.
Regulatory requirements may vary by city, state, country, product type, certification, performance characteristic, and intended use.
That makes a simple policy such as “sellers must comply with applicable laws” operationally inadequate by itself.
The marketplace must determine how compliance will actually be enforced.
Some controls may depend on seller attestations.
Others may require laboratory certifications.
Some may depend on product metadata.
Others may require automated text or image analysis.
Still others may require geographical restrictions at checkout.
And each introduces its own failure modes.
A seller could misclassify a product.
Technical specifications could be incomplete.
A listing could advertise one specification while the delivered product has another.
A seller could use language designed to avoid automated detection.
A regulatory requirement could change without the corresponding platform rule being updated.
A prohibited product could simply fall outside the taxonomy used by the control.
Governance therefore requires more than a rule.
It requires a control system capable of finding its own weaknesses.
Exceptions Are Not Necessarily Evidence of Governance Failure
This is another area where governance discussions often become too simplistic.
Finding a prohibited product on a large marketplace does not necessarily prove that the entire governance system failed.
No control environment is perfect.
The more revealing question is what the organization does when an exception occurs.
Did Amazon discover the listing, or did New York City?
How long had it been available?
How many units were sold?
Were they shipped into New York City?
Was the seller information accurate?
Did an existing control fail?
Was the product outside the scope of the control?
Did someone override a restriction?
Were comparable products immediately identified?
Was the root cause determined?
Was the control changed?
Was that change tested?
Was evidence retained showing the entire sequence?
Those questions turn an isolated compliance event into information about control effectiveness.
A mature governance organization learns from exceptions.
An immature one merely closes them.
A Control Should Be Able to Produce Its Own Defense
This is where the concept of Evidentiary Architecture™ becomes relevant.
Organizations have spent decades building architectures for systems, networks, applications, data, cybersecurity, and business processes.
But they frequently have no corresponding architecture for governance evidence.
The policy exists in one repository.
The regulatory obligation is tracked somewhere else.
A technical control operates in a platform.
Testing results live in a spreadsheet.
An exception becomes a service ticket.
An executive decision sits in email.
A remediation project appears in another system.
Committee minutes document part of the discussion.
Months or years later, someone asks:
What happened?
The organization then begins reconstructing governance.
That is backwards.
Evidence should not have to be manufactured after a regulator, auditor, insurer, board member, or attorney asks for it.
Evidence should be created naturally as governance operates.
The architecture should allow the organization to trace:
Obligation → Decision → Control → Execution → Exception → Response → Outcome

That is evidentiary architecture.
The Three-Year Question
This is why the earlier FDNY interaction matters so much.
In 2023, New York City explicitly discussed micromobility compliance with Amazon.
Amazon told city officials that it was updating its policies and controls.
The city later reported that Amazon had made at least partial progress.
Now, in 2026, New York City is again challenging Amazon and dozens of other retailers over allegedly prohibited micromobility products.
The regulatory details are not identical.
But the governance question is unavoidable:
What did the organization learn from the first encounter, and how was that learning incorporated into the control environment?
That is the question boards should ask whenever a compliance issue reappears in a related domain.
Not:
Didn’t we already fix this?
But:
What changed in the system because this happened before?
There should be an evidentiary answer.
The Same Problem Exists Everywhere
Replace e-bikes with artificial intelligence.
An organization establishes an AI acceptable-use policy.
Months later, employees are discovered using unauthorized AI tools.
Management points to the policy.
That does not answer the governance question.
Replace e-bikes with privileged-access management.
The policy requires multifactor authentication.
An administrator account is later discovered without it.
The organization produces the policy.
Again, wrong evidence.
Replace e-bikes with third-party risk.
Vendors are required to undergo annual reviews.
An incident occurs involving a vendor whose assessment expired nine months earlier.
The vendor policy is not the answer.
In each case:
The policy establishes intent.
The control is supposed to produce behavior.
The evidence demonstrates whether that behavior occurred.
What Boards Should Ask
When management tells a board, “We have a policy for that,” the discussion should not end.
It should begin.
The next questions are:
What controls implement the policy?
What evidence demonstrates that those controls are operating?
How are exceptions detected?
What happens when a control fails?
How do we verify remediation?
How does the organization incorporate lessons from previous failures into future controls?
Those questions change governance from documentation into accountability.
The Amazon/New York City dispute provides a useful case study precisely because the record extends beyond one cease-and-desist letter.
There was legislation.
There was an earlier government inquiry.
There was direct discussion with Amazon.
There was an expressed commitment to update policy and controls.
There was subsequent partial compliance.
And now there is another regulatory challenge involving the same general product ecosystem, although broader legal requirements are at issue.
That chronology is what makes the story significant.
It allows us to ask not merely whether a policy exists, but whether the governance architecture surrounding that policy is capable of adapting, detecting failure, producing evidence, and learning over time.
Because ultimately:
Policies state intent. Controls drive action. Evidence demonstrates effectiveness.
And when regulators return three years later, the most important thing an organization can produce is not another policy.
It is evidence of what happened after the first conversation.



