I've just finished recording a Cybershow episode with two experts in compliance (ISO42001 coming on the AI regulatory side - to be broadcast in January).
The conversation turned to what carrots can be used instead of sticks? Problem being that large corps simply incorporate huge fines as the cost of doing business (that probably is relevant to this thread)
So to legally innovate, instead, give assistance (legal aid, expert advisor) to smaller firms struggling with compliance. After all governments want companies to comply. It's not a punitive game.
Big companies pay their own way.
The point being to allow members of the public to submit a pull request and have their contributions incorporated into the officially-certified codebase if it's accepted, so the code ends up being actually good because the users (i.e. the public) are given the opportunity to fix what irks them.