Then the regulations need to have a mechanism to be updated in the case of new knowledge. If the regulations have no process to be updated then that is a more fundamental problem to solve.
After all, Debian is set to give the process of change 2 years. That is plenty of time for updating the regulation and processes.
Any joker can start a company and declare any regulation they like. I could require that all software be written in COBOL by moustachioed developers standing on one foot.
If I did that, I think Debian would not change their software to meet my bizarre "company regulations"
I'm not making this up.