DROPLETS
New York healthcare providers and Medicaid stakeholders must act because HHS's denial of MFCU recertification signals intensified federal oversight and potential compliance exposure.
HHS has denied recertification of New York's Medicaid Fraud Control Unit, the state agency responsible for investigating and prosecuting Medicaid provider fraud and patient abuse in facilities. Recertification is required annually under federal law for states to receive the federal matching share of MFCU operating costs. Denial typically reflects findings that the unit fails to meet operational, staffing, or case-quality standards set by CMS. The decision places New York's MFCU on a corrective action track and could trigger funding reductions, federal takeover of certain functions, or heightened direct federal enforcement against providers in the state. Healthcare entities operating in New York should expect increased audit activity, expanded False Claims Act scrutiny, and closer coordination between federal and any successor state investigators. Providers should reassess compliance programs, billing controls, and self-disclosure posture in anticipation of accelerated enforcement.
Lenders, sponsors, and distressed-debt investors must reassess uptier and drop-down LME transactions after a court pierced the participating-lender shield.
The U.S. Bankruptcy Court for the Southern District of Texas ruled that lenders who participated in Serta Simmons' 2020 uptier liability management exchange are liable for roughly $400 million, rejecting arguments that the transaction was a permissible pro rata lien subordination. The decision signals that courts will scrutinize whether non-participating lenders were economically primed or their rights meaningfully impaired, and that majority-lender steering of collateral can be unwound where the structure functions as a non-pro rata transfer. For sponsors and lender groups, the ruling narrows the safe harbor for similar exchanges and raises exposure for arrangers, agents, and backstop providers. Practitioners should expect increased litigation over legacy uptier deals and tighter documentation on future LMEs, including clearer pro rata protections and disclosure of priming economics.
Multinational importers must reassess supply chains as CBP consolidates enforcement guidance under three forced labor statutes.
On June 12, 2026, U.S. Customs and Border Protection released a guide clarifying how it enforces U.S. import restrictions on goods produced with forced labor. The guidance consolidates three principal authorities: Section 307 of the Tariff Act (19 U.S.C. § 1307), the Uyghur Forced Labor Prevention Act (UFLPA), and the Countering America's Adversaries Through Sanctions Act (CAATSA). CBP's framework signals heightened scrutiny of supply chains, particularly those with ties to Xinjiang and other high-risk regions. Importers should expect increased detention rates, expanded use of withhold release orders, and more rigorous documentation demands. Companies should map tier-2 and tier-3 suppliers, audit labor practices, and prepare due-diligence records demonstrating that inputs are fully divorced from forced labor sources to mitigate detention and seizure risk.
Companies planning new or expanded large-scale data center projects in New York face an immediate, year-long freeze on discretionary construction permits while the state develops binding environmental and operational standards for the facilities.
On July 14, 2026, New York Governor Kathy Hochul signed Executive Order No. 62, implementing the nation’s first statewide moratorium on new large-scale data centers consuming 50MW or more of electricity. The order, which took effect immediately, directs the state Department of Environmental Conservation to pause all discretionary construction and expansion permits for covered facilities while the Department of Public Service completes a report assessing their environmental impacts, including energy demand, water use, air quality, and disproportionate effects on disadvantaged communities. The moratorium will remain in place until final regulatory standards are issued, a process expected to take up to one year. Companies with pending large data center projects in New York must pause permit applications, track the state’s ongoing regulatory assessments, and evaluate potential legal challenges to the moratorium if their project timelines are delayed.
Cross-border deal teams executing transactions with EU exposure must account for overlapping merger control, FDI screening and FSR requirements that can derail deals even after EU merger clearance is granted.
The EU has released draft merger guidelines (consultation closed June 2026, final expected Q4 2026) that expand merger control analysis to include economic security, resilience and competitiveness goals alongside traditional consumer welfare tests, while revised EU FDI screening rules (effective 2027) expand national security review scope to low-threshold minority investments, and FSR enforcement is ramping up for foreign subsidies that distort EU markets. Previously siloed, the three regimes now operate as an interconnected toolkit with overlapping jurisdiction for many transactions, creating risk of conflicting outcomes (e.g., a deal cleared by EU merger authorities may still be blocked by national FDI powers). Deal teams should conduct early, comprehensive regulatory mapping to identify all applicable filing obligations across the three regimes, sequence reviews strategically, and build risk allocation for conflicting regulatory outcomes into transaction documents.
All publicly traded, private equity-backed, and pass-through U.S. defense contractors must evaluate exposure to a proposed categorical ban on stock buybacks and dividends as a condition of Department of War contract eligibility.
The Senate’s FY2027 National Defense Authorization Act includes Section 815, a provision that would prohibit the Secretary of War from awarding procurement contracts to any defense contractor that conducts stock buybacks or pays dividends, with waivers only available for contractors with approved qualifying defense investment plans. Unlike a prior executive order restricting distributions only for underperforming contractors, this rule applies categorically to all defense contractors regardless of performance, contract value, or program criticality, with no dollar threshold. It also bars parent companies of defense contracting subsidiaries from conducting buybacks, and imposes penalties including payment suspension and contract termination for violations. The House-passed NDAA does not include a matching provision, so the rule’s future will be determined in conference committee negotiations.
Swap dealers, clearing members, and clearing organizations dealing in physical commodity swaps must adjust compliance workflows to reflect the CFTC’s elimination of routine daily and event-based Part 20 large trader position reports, removing a longstanding regulatory filing burden.
On July 17, 2026, the CFTC issued a final order fully repealing routine position-reporting requirements under Part 20, the large trader reporting rules applicable to physical commodity swaps. The order applies to all covered market participants including swap dealers, clearing members, and derivatives clearing organizations, which will no longer be required to submit daily position reports or event-based filings for covered physical commodity swap positions effective immediately. Affected entities should review existing reporting infrastructure and compliance policies to remove redundant Part 20 filing steps, confirm no overlapping reporting obligations apply to affected positions, and update internal recordkeeping practices to align with the revised requirements. The update also notes additional recent regulatory actions including a CFTC stay of a KalshiEX emergency rule change, amended uncleared swap margin rules, and new EU derivatives market transparency and crypto supervisory initiatives from ESMA.
Corporate compliance and legal teams must monitor 2026 state AG elections across 30+ states, as outcomes will directly alter enforcement priorities, multistate coalition membership, and sector-specific regulatory risk for businesses operating in those jurisdictions.
The 2026 election cycle features attorney general contests across 30 states plus the District of Columbia, with a high volume of open seats driven by constitutional term limits and incumbents seeking higher office in major economic engines including Colorado, Georgia, Michigan, Nevada, Ohio, and Oklahoma. New AG leadership routinely adjusts administrative priorities and enforcement personnel, shifting baseline regulatory risk for businesses. Competitive reelection bids for incumbents in swing states such as Arizona, Minnesota, and Wisconsin also carry weight, as those offices have historically led high-impact consumer protection and technology-focused enforcement actions. Election outcomes will determine whether states lead, join, or exit multi-million dollar multistate corporate investigations and federal legal challenges, requiring compliance teams to track race developments and candidate policy positions aligned with their operational footprints.
Organizations that collect, process, or monetize consumer personal data must update compliance programs immediately, as Q2 2026 brought two new comprehensive state privacy laws, amended existing frameworks, and a record $12.75 million CCPA settlement signaling heightened regulatory scrutiny of sensitive data use and secondary data sharing.
Q2 2026 brought significant shifts to U.S. state privacy regulation: Louisiana and Vermont became the 22nd and 23rd states to enact comprehensive consumer privacy laws, with unique provisions including Louisiana’s $25 million revenue applicability threshold and Vermont’s ban on broad nonprofit exemptions, with effective dates of January 1, 2027 and January 1, 2028 respectively. Existing state privacy laws were amended across Maryland, Tennessee, Virginia, and Connecticut to tighten sensitive data definitions, ban precise geolocation data sales, lower applicability thresholds, and add minor data protections. California regulators also secured a record $12.75 million CCPA settlement against an automaker for undisclosed sale of precise geolocation data to data brokers, reinforcing enforcement focus on purpose limitation and data minimization. New Jersey and Connecticut enacted new data broker rules, including New Jersey’s tiered registration fees tied to volume of brokered consumer data. Organizations should review data collection, sharing, and retention practices to align with new and
…
In-house counsel at banks and consumer-finance companies must track shifting CFPB oversight and new federal banking-agency protocols for handling sensitive exam materials.
The Senate Banking Committee held a hearing on the CFPB's semi-annual report, featuring Acting Director Vought's testimony on the bureau's reform direction. Minority staff released a report claiming that cuts to the CFPB have cost Americans up to $26.5 billion, signaling continued partisan friction over the agency's scope and funding. Separately, the Federal Reserve, FDIC, and OCC issued a joint statement on enhanced security procedures for highly sensitive information during bank examinations, favoring on-site review over transferring materials onto agency systems. The OCC also released a revised handbook booklet on allowances for credit losses. Together, these developments point to evolving supervisory expectations and examination-handling practices that banks and their counsel should monitor closely.
Importers seeking refunds of IEEPA tariffs must complete a specific ACE portal action or risk forfeiting recovery of significant working capital.
Following the Supreme Court's invalidation of certain IEEPA-based tariffs, U.S. Customs and Border Protection is processing refunds for importers who paid duties under those authorities. However, CBP will not automatically issue refunds; importers must affirmatively request them through the Automated Commercial Environment (ACE) portal. Many businesses with global supply chains that paid substantial IEEPA tariffs stand to recover meaningful cash, but those who overlook the required ACE filing risk losing the refund entirely. In-house counsel and trade compliance teams should immediately audit prior entries paid under IEEPA, confirm whether refund requests have been submitted, and coordinate with customs brokers to ensure filings are completed before applicable deadlines. Acting promptly is critical to preserving the recovery.
Multinationals operating in Mexico's priority sectors should reassess compliance and deal strategies as COFECE prepares for aggressive enforcement.
Mexico's Federal Economic Competition Commission (COFECE) has identified six strategic markets where it plans to intensify antitrust oversight, signaling a shift toward more proactive and aggressive enforcement. The move reflects the agency's broader mandate to tackle concentration, anti-competitive practices, and barriers to entry in sectors deemed critical to the Mexican economy. Companies with operations, joint ventures, or pending transactions in these markets should expect closer scrutiny of pricing, distribution arrangements, exclusivity clauses, and M&A filings. In-house counsel should conduct internal antitrust audits, review existing agreements for compliance gaps, and factor longer review timelines into transaction planning. Early engagement with counsel and proactive remediation can reduce exposure to investigations, fines, and remedies.
Multinational deal teams must align remedy packages across FTC, DOJ, EC, and UK CMA reviews to avoid conflicting divestiture obligations.
Rising parallel enforcement by the FTC, DOJ, European Commission, and UK CMA is forcing merging parties to negotiate overlapping but inconsistent remedies—divestiture buyers, asset scopes, and timing often diverge by jurisdiction. Recent matters show agencies rarely defer to one another's analyses, increasing the risk that a remedy accepted in one forum triggers non-compliance in another. Practitioners recommend early pre-clearance mapping of likely remedy demands, harmonized purchaser searches, and explicit carve-outs in consent decrees to preserve flexibility. In-house counsel should build cross-border remedy playbooks before signing, identify jurisdiction-specific deal-breakers, and engage local counsel in parallel to stress-test divestiture commitments against each agency's stated preferences and recent precedent.
AI deployers and developers face unresolved compliance exposure after the FTC's recent statement on output 'steering' failed to clarify liability boundaries.
The FTC issued a statement addressing how 'steering' AI model outputs—shaping or constraining what generative systems produce—intersects with existing consumer protection and antitrust frameworks. While the agency signaled scrutiny of practices that distort competition or deceive users, it stopped short of defining prohibited conduct, leaving deployers uncertain about where permissible product design ends and unfair method-of-competition liability begins. The statement notably omits safe harbors, documentation expectations, and thresholds for when steering crosses into Section 5 violation territory. In-house counsel at companies building, fine-tuning, or integrating generative AI tools should reassess model governance documentation, vendor contracts, and disclosure practices now, rather than waiting for enforcement actions to draw clearer lines. Expect follow-on rulemaking or guidance.
Federal prosecutors nationwide must now carry a minimum number of open matters, signaling DOJ's push for sustained enforcement throughput that companies facing investigations should expect to outlast any single case team.
Reports indicate the Department of Justice has directed all federal prosecutors to maintain a baseline number of active cases at any given time, formalizing productivity expectations across U.S. Attorney's Offices. The policy reframes case management from a reactive posture to a quota-driven pipeline, with line prosecutors evaluated on sustained throughput rather than individual dispositions. For in-house counsel, this means investigations are less likely to be closed quietly or deprioritized mid-cycle, and parallel or successor matters may be opened even where an existing case is winding down. Companies under scrutiny should anticipate more aggressive timeline pressure, broader use of supplemental subpoenas, and reduced willingness by DOJ to negotiate narrow resolutions. Practical steps include preserving investigative readiness, pre-clearing key custodians, and budgeting for multi-stage document production rather than a single sweep.
In-house IP and brand protection counsel must avoid overreaching UDRP complaints, as a WIPO panel’s RDNH finding against the CREDITGPT trademark complainant sets a clear precedent for penalizing bad faith domain dispute filings.
A WIPO panel ruled that a trademark complaint filed over the CREDITGPT domain name constituted reverse domain name hijacking (RDNH), calling the filing a “poster child” for the prohibited practice. The decision reinforces that UDRP complainants must demonstrate both valid, enforceable trademark rights and bad faith conduct by the domain registrant, rather than filing speculative or overbroad complaints to seize domains tied to emerging AI-related branding. In-house counsel should review their teams’ UDRP filing protocols to ensure all submissions are supported by clear evidence of registrant bad faith, to avoid RDNH findings that carry reputational harm and bar future UDRP participation.
In-house counsel overseeing California-facing consumer credit, background screening, and FCRA compliance programs must monitor the appellate split, as divergent state court standing rules will increase FCRA litigation risk and create inconsistent defense obligations across the state.
On June 4, 2026, California’s First District Court of Appeal held in Askins v. CRST Expedited that state standing rules do not require plaintiffs to prove a concrete injury to pursue Fair Credit Reporting Act (FCRA) claims in state court, a lower threshold than the federal standing requirement. The ruling deepens an existing split between California appellate districts on the issue, so the applicable standing standard for FCRA state court claims varies by jurisdiction. In-house counsel should review FCRA compliance protocols for California operations, update state court defense strategies to account for divergent rules, and track further appellate developments that may resolve the split.
In-house counsel managing private arbitrations pending or filed in Connecticut must revise arbitrator selection processes to comply with a 2026 state law requiring all arbitrators to be Connecticut-admitted attorneys in good standing.
Effective July 1, 2026, Connecticut Public Act 26-92 will require all arbitrators in private arbitrations conducted in the state to be attorneys admitted to practice in Connecticut in good standing. The rule applies not only to new arbitrations filed after the effective date, but also to pending matters where an evidentiary hearing has not yet commenced as of July 1, 2026. In-house counsel with active or anticipated Connecticut private arbitrations should review existing arbitration agreements and pending dockets now to confirm arbitrator eligibility, update selection workflows, and adjust pending matters as needed to meet the new requirement ahead of the effective date.
Unionized employers and their in-house labor counsel must revise post-employment dispute processes after a Second Circuit ruling found unions lack authority to bind former employees to arbitration terms in later-negotiated collective bargaining agreements.
The U.S. Court of Appeals for the Second Circuit recently held that labor unions have no authority to bind former employees to arbitration and alternate dispute resolution provisions included in collective bargaining agreements (CBAs) negotiated after the employees’ separation from the workforce. The ruling rejects the longstanding practice of unionized employers relying on these post-employment CBA terms to resolve ex-employee claims including wrongful termination and wage disputes outside of court. In-house counsel for unionized employers should review existing CBA language and current post-separation dispute protocols, and work with labor counsel to modify future CBA negotiations to address this limitation, including exploring alternative dispute resolution frameworks for post-employment claims that do not depend on union binding authority.
In-house counsel for multi-state businesses must monitor 2026 state AG elections, as winning candidates will shift enforcement priorities across consumer protection, antitrust, privacy and other core business oversight areas.
The article explains that state attorneys general have become some of the most influential public legal actors shaping the national business environment over the past decade, with broad authority to lead enforcement actions, multistate litigation and policy guidance across consumer protection, antitrust, privacy, healthcare, environmental and ESG issues. 2026 election cycles, particularly open-seat races in high-impact states, will create leadership transitions that can quickly shift an office’s tone, staffing, coalition strategy and enforcement focus. In-house counsel should map their state-level exposure across operations, customer bases and regulatory obligations, audit compliance protocols for multistate scrutiny, and monitor post-election transition signals to adjust risk strategies for 2027 and beyond.
Life sciences companies and patent counsel filing method of treatment claims before clinical data is available must revise drafting strategies, after a Federal Circuit ruling invalidated a $107.5 million verdict by finding such claims unenabled when they lack patient-level dosing guidance and rely solely on unvalidated in vitro results.
On July 9, 2026, the U.S. Court of Appeals for the Federal Circuit issued a precedential ruling in Wyeth LLC v. AstraZeneca Pharmaceuticals LP, affirming a district court’s finding that Wyeth’s patents for methods of treating EGFR inhibitor-resistant non-small cell lung cancer were invalid for lack of enablement. The court held the patents’ in vitro cell assay data and broad, unvalidated dose ranges were insufficient to enable the claimed “unit dosage” requirement for patient administration, as disclosed doses for two of three candidate drugs exceeded safe human tolerance levels. The ruling clarifies method of treatment claims require more than lab efficacy data when claim language mandates patient-level therapeutic effect, and that specification language emphasizing dosing variability can support non-enablement findings. Life sciences innovators should avoid overbroad claim language importing patient efficacy requirements without corresponding specification support, limit language highlighting dosing unpredictability, and prioritize filing dosing claims after clinical trial data is
…
In-house counsel overseeing marketing, compliance, and TCPA litigation risk for organizations that send text messages must account for the Seventh Circuit’s ruling, which bars a common private TCPA claim for unwanted texts in that circuit and reduces class action exposure.
On July 14, 2026, the Seventh Circuit held in Steidinger v. Blackstone Medical Services that the TCPA’s private right of action under 47 U.S.C. § 227(c)(5), which authorizes suits for unwanted telephone calls, does not extend to text messages. The ruling is binding only in the Seventh Circuit, and does not impact TCPA claims brought under § 227(b) for texts sent via an automatic telephone dialing system without consent, nor does it preempt state “mini-TCPA” laws that explicitly include text messages in their prohibitions. Organizations operating in the Seventh Circuit facing TCPA text claims under § 227(c)(5) can cite this decision to seek dismissal, while those outside the circuit may use it as persuasive authority to argue against similar claims.
Manufacturers, importers, and distributors of DOE-regulated products must weigh in on a proposed rule that would reshape how federal energy efficiency standards are developed and amended.
On July 7, 2026, the Department of Energy issued a notice of proposed rulemaking seeking substantial revisions to its 'Process Rule,' the framework governing development of energy conservation standards and test procedures under the Energy Policy and Conservation Act. The proposal would alter DOE's analytical methodology, stakeholder engagement, and criteria for setting or amending standards across a wide range of consumer products and commercial/industrial equipment. If finalized, affected manufacturers, importers, and distributors could face new compliance burdens, shifting cost-benefit benchmarks, and revised test procedures. Companies should review the NOPR, assess product-line exposure, and prepare comments before the close of the public comment period to influence the final rule.
Issuers, advisers, and broker-dealers should prepare now for a shift from opt-in to opt-out electronic delivery of regulatory disclosures.
On July 16, 2026, the SEC proposed Regulation E-Delivery, which would replace the current opt-in framework with an opt-out default for electronic delivery of covered information under the federal securities laws. Covered entities—including issuers, investment advisers, and broker-dealers—could deliver prospectuses, proxy materials, information statements, tender offer documents, and shareholder reports electronically if the recipient has provided an electronic address, received prominent notice, and has not opted out. Information containing personal financial information would require a notice-and-access approach via email link. The rule permits, but does not require, reliance on e-delivery, preserving flexibility. The 60-day comment period opens upon Federal Register publication. In-house counsel should assess delivery workflows, investor communications, website hosting requirements, and cost-saving opportunities while preparing compliance plans for the transition.
UK investment managers and advisers must prepare for sweeping FSMA reforms reshaping senior-manager accountability, appointed-representative oversight, AML supervision, and overseas recognition rules.
The Financial Services and Markets Bill, introduced in the House of Lords on 19 May 2026, would overhaul UK financial-services regulation under the government's Financial Services Growth and Competitiveness Strategy. For investment managers, the most consequential changes include: (i) streamlining the Senior Managers and Certification Regime by removing pre-approval requirements for certain senior management functions and repealing the statutory certification regime, with substance retained via FCA/PRA rulebooks; (ii) bringing appointed representatives within the SM&CR and tightening the AR regime; (iii) consolidating AML/CTF supervision under the FCA; (iv) introducing a provisional licences authorisation regime; and (v) creating new overseas recognition regimes. In-house counsel at UK-authorised managers should map current SM&CR and AR structures against the proposed reforms, prepare for AR onboarding and oversight changes, and monitor parliamentary progress ahead of likely enactment later this year.
Organizations that collect, process, or monetize consumer personal data must update compliance programs immediately, as Q2 2026 brought two new comprehensive state privacy laws, amended existing frameworks, and a record $12.75 million CCPA settlement signaling heightened regulatory scrutiny of sensitive data use and secondary data sharing.
Q2 2026 brought significant shifts to U.S. state privacy regulation: Louisiana and Vermont became the 22nd and 23rd states to enact comprehensive consumer privacy laws, with unique provisions including Louisiana’s $25 million revenue applicability threshold and Vermont’s ban on broad nonprofit exemptions, with effective dates of January 1, 2027 and January 1, 2028 respectively. Existing state privacy laws were amended across Maryland, Tennessee, Virginia, and Connecticut to tighten sensitive data definitions, ban precise geolocation data sales, lower applicability thresholds, and add minor data protections. California regulators also secured a record $12.75 million CCPA settlement against an automaker for undisclosed sale of precise geolocation data to data brokers, reinforcing enforcement focus on purpose limitation and data minimization. New Jersey and Connecticut enacted new data broker rules, including New Jersey’s tiered registration fees tied to volume of brokered consumer data. Organizations should review data collection, sharing, and retention practices to align with new and
…
Multinationals operating in Mexico's priority sectors should reassess compliance and deal strategies as COFECE prepares for aggressive enforcement.
Mexico's Federal Economic Competition Commission (COFECE) has identified six strategic markets where it plans to intensify antitrust oversight, signaling a shift toward more proactive and aggressive enforcement. The move reflects the agency's broader mandate to tackle concentration, anti-competitive practices, and barriers to entry in sectors deemed critical to the Mexican economy. Companies with operations, joint ventures, or pending transactions in these markets should expect closer scrutiny of pricing, distribution arrangements, exclusivity clauses, and M&A filings. In-house counsel should conduct internal antitrust audits, review existing agreements for compliance gaps, and factor longer review timelines into transaction planning. Early engagement with counsel and proactive remediation can reduce exposure to investigations, fines, and remedies.
Multinational deal teams must align remedy packages across FTC, DOJ, EC, and UK CMA reviews to avoid conflicting divestiture obligations.
Rising parallel enforcement by the FTC, DOJ, European Commission, and UK CMA is forcing merging parties to negotiate overlapping but inconsistent remedies—divestiture buyers, asset scopes, and timing often diverge by jurisdiction. Recent matters show agencies rarely defer to one another's analyses, increasing the risk that a remedy accepted in one forum triggers non-compliance in another. Practitioners recommend early pre-clearance mapping of likely remedy demands, harmonized purchaser searches, and explicit carve-outs in consent decrees to preserve flexibility. In-house counsel should build cross-border remedy playbooks before signing, identify jurisdiction-specific deal-breakers, and engage local counsel in parallel to stress-test divestiture commitments against each agency's stated preferences and recent precedent.
Lenders, sponsors, and distressed-debt investors must reassess uptier and drop-down LME transactions after a court pierced the participating-lender shield.
The U.S. Bankruptcy Court for the Southern District of Texas ruled that lenders who participated in Serta Simmons' 2020 uptier liability management exchange are liable for roughly $400 million, rejecting arguments that the transaction was a permissible pro rata lien subordination. The decision signals that courts will scrutinize whether non-participating lenders were economically primed or their rights meaningfully impaired, and that majority-lender steering of collateral can be unwound where the structure functions as a non-pro rata transfer. For sponsors and lender groups, the ruling narrows the safe harbor for similar exchanges and raises exposure for arrangers, agents, and backstop providers. Practitioners should expect increased litigation over legacy uptier deals and tighter documentation on future LMEs, including clearer pro rata protections and disclosure of priming economics.
In-house counsel overseeing California-facing consumer credit, background screening, and FCRA compliance programs must monitor the appellate split, as divergent state court standing rules will increase FCRA litigation risk and create inconsistent defense obligations across the state.
On June 4, 2026, California’s First District Court of Appeal held in Askins v. CRST Expedited that state standing rules do not require plaintiffs to prove a concrete injury to pursue Fair Credit Reporting Act (FCRA) claims in state court, a lower threshold than the federal standing requirement. The ruling deepens an existing split between California appellate districts on the issue, so the applicable standing standard for FCRA state court claims varies by jurisdiction. In-house counsel should review FCRA compliance protocols for California operations, update state court defense strategies to account for divergent rules, and track further appellate developments that may resolve the split.
In-house counsel overseeing marketing, compliance, and TCPA litigation risk for organizations that send text messages must account for the Seventh Circuit’s ruling, which bars a common private TCPA claim for unwanted texts in that circuit and reduces class action exposure.
On July 14, 2026, the Seventh Circuit held in Steidinger v. Blackstone Medical Services that the TCPA’s private right of action under 47 U.S.C. § 227(c)(5), which authorizes suits for unwanted telephone calls, does not extend to text messages. The ruling is binding only in the Seventh Circuit, and does not impact TCPA claims brought under § 227(b) for texts sent via an automatic telephone dialing system without consent, nor does it preempt state “mini-TCPA” laws that explicitly include text messages in their prohibitions. Organizations operating in the Seventh Circuit facing TCPA text claims under § 227(c)(5) can cite this decision to seek dismissal, while those outside the circuit may use it as persuasive authority to argue against similar claims.
Cross-border deal teams executing transactions with EU exposure must account for overlapping merger control, FDI screening and FSR requirements that can derail deals even after EU merger clearance is granted.
The EU has released draft merger guidelines (consultation closed June 2026, final expected Q4 2026) that expand merger control analysis to include economic security, resilience and competitiveness goals alongside traditional consumer welfare tests, while revised EU FDI screening rules (effective 2027) expand national security review scope to low-threshold minority investments, and FSR enforcement is ramping up for foreign subsidies that distort EU markets. Previously siloed, the three regimes now operate as an interconnected toolkit with overlapping jurisdiction for many transactions, creating risk of conflicting outcomes (e.g., a deal cleared by EU merger authorities may still be blocked by national FDI powers). Deal teams should conduct early, comprehensive regulatory mapping to identify all applicable filing obligations across the three regimes, sequence reviews strategically, and build risk allocation for conflicting regulatory outcomes into transaction documents.
Unionized employers and their in-house labor counsel must revise post-employment dispute processes after a Second Circuit ruling found unions lack authority to bind former employees to arbitration terms in later-negotiated collective bargaining agreements.
The U.S. Court of Appeals for the Second Circuit recently held that labor unions have no authority to bind former employees to arbitration and alternate dispute resolution provisions included in collective bargaining agreements (CBAs) negotiated after the employees’ separation from the workforce. The ruling rejects the longstanding practice of unionized employers relying on these post-employment CBA terms to resolve ex-employee claims including wrongful termination and wage disputes outside of court. In-house counsel for unionized employers should review existing CBA language and current post-separation dispute protocols, and work with labor counsel to modify future CBA negotiations to address this limitation, including exploring alternative dispute resolution frameworks for post-employment claims that do not depend on union binding authority.
Manufacturers, importers, and distributors of DOE-regulated products must weigh in on a proposed rule that would reshape how federal energy efficiency standards are developed and amended.
On July 7, 2026, the Department of Energy issued a notice of proposed rulemaking seeking substantial revisions to its 'Process Rule,' the framework governing development of energy conservation standards and test procedures under the Energy Policy and Conservation Act. The proposal would alter DOE's analytical methodology, stakeholder engagement, and criteria for setting or amending standards across a wide range of consumer products and commercial/industrial equipment. If finalized, affected manufacturers, importers, and distributors could face new compliance burdens, shifting cost-benefit benchmarks, and revised test procedures. Companies should review the NOPR, assess product-line exposure, and prepare comments before the close of the public comment period to influence the final rule.
Companies planning new or expanded large-scale data center projects in New York face an immediate, year-long freeze on discretionary construction permits while the state develops binding environmental and operational standards for the facilities.
On July 14, 2026, New York Governor Kathy Hochul signed Executive Order No. 62, implementing the nation’s first statewide moratorium on new large-scale data centers consuming 50MW or more of electricity. The order, which took effect immediately, directs the state Department of Environmental Conservation to pause all discretionary construction and expansion permits for covered facilities while the Department of Public Service completes a report assessing their environmental impacts, including energy demand, water use, air quality, and disproportionate effects on disadvantaged communities. The moratorium will remain in place until final regulatory standards are issued, a process expected to take up to one year. Companies with pending large data center projects in New York must pause permit applications, track the state’s ongoing regulatory assessments, and evaluate potential legal challenges to the moratorium if their project timelines are delayed.
Swap dealers, clearing members, and clearing organizations dealing in physical commodity swaps must adjust compliance workflows to reflect the CFTC’s elimination of routine daily and event-based Part 20 large trader position reports, removing a longstanding regulatory filing burden.
On July 17, 2026, the CFTC issued a final order fully repealing routine position-reporting requirements under Part 20, the large trader reporting rules applicable to physical commodity swaps. The order applies to all covered market participants including swap dealers, clearing members, and derivatives clearing organizations, which will no longer be required to submit daily position reports or event-based filings for covered physical commodity swap positions effective immediately. Affected entities should review existing reporting infrastructure and compliance policies to remove redundant Part 20 filing steps, confirm no overlapping reporting obligations apply to affected positions, and update internal recordkeeping practices to align with the revised requirements. The update also notes additional recent regulatory actions including a CFTC stay of a KalshiEX emergency rule change, amended uncleared swap margin rules, and new EU derivatives market transparency and crypto supervisory initiatives from ESMA.
In-house counsel at banks and consumer-finance companies must track shifting CFPB oversight and new federal banking-agency protocols for handling sensitive exam materials.
The Senate Banking Committee held a hearing on the CFPB's semi-annual report, featuring Acting Director Vought's testimony on the bureau's reform direction. Minority staff released a report claiming that cuts to the CFPB have cost Americans up to $26.5 billion, signaling continued partisan friction over the agency's scope and funding. Separately, the Federal Reserve, FDIC, and OCC issued a joint statement on enhanced security procedures for highly sensitive information during bank examinations, favoring on-site review over transferring materials onto agency systems. The OCC also released a revised handbook booklet on allowances for credit losses. Together, these developments point to evolving supervisory expectations and examination-handling practices that banks and their counsel should monitor closely.
UK investment managers and advisers must prepare for sweeping FSMA reforms reshaping senior-manager accountability, appointed-representative oversight, AML supervision, and overseas recognition rules.
The Financial Services and Markets Bill, introduced in the House of Lords on 19 May 2026, would overhaul UK financial-services regulation under the government's Financial Services Growth and Competitiveness Strategy. For investment managers, the most consequential changes include: (i) streamlining the Senior Managers and Certification Regime by removing pre-approval requirements for certain senior management functions and repealing the statutory certification regime, with substance retained via FCA/PRA rulebooks; (ii) bringing appointed representatives within the SM&CR and tightening the AR regime; (iii) consolidating AML/CTF supervision under the FCA; (iv) introducing a provisional licences authorisation regime; and (v) creating new overseas recognition regimes. In-house counsel at UK-authorised managers should map current SM&CR and AR structures against the proposed reforms, prepare for AR onboarding and oversight changes, and monitor parliamentary progress ahead of likely enactment later this year.
All publicly traded, private equity-backed, and pass-through U.S. defense contractors must evaluate exposure to a proposed categorical ban on stock buybacks and dividends as a condition of Department of War contract eligibility.
The Senate’s FY2027 National Defense Authorization Act includes Section 815, a provision that would prohibit the Secretary of War from awarding procurement contracts to any defense contractor that conducts stock buybacks or pays dividends, with waivers only available for contractors with approved qualifying defense investment plans. Unlike a prior executive order restricting distributions only for underperforming contractors, this rule applies categorically to all defense contractors regardless of performance, contract value, or program criticality, with no dollar threshold. It also bars parent companies of defense contracting subsidiaries from conducting buybacks, and imposes penalties including payment suspension and contract termination for violations. The House-passed NDAA does not include a matching provision, so the rule’s future will be determined in conference committee negotiations.
New York healthcare providers and Medicaid stakeholders must act because HHS's denial of MFCU recertification signals intensified federal oversight and potential compliance exposure.
HHS has denied recertification of New York's Medicaid Fraud Control Unit, the state agency responsible for investigating and prosecuting Medicaid provider fraud and patient abuse in facilities. Recertification is required annually under federal law for states to receive the federal matching share of MFCU operating costs. Denial typically reflects findings that the unit fails to meet operational, staffing, or case-quality standards set by CMS. The decision places New York's MFCU on a corrective action track and could trigger funding reductions, federal takeover of certain functions, or heightened direct federal enforcement against providers in the state. Healthcare entities operating in New York should expect increased audit activity, expanded False Claims Act scrutiny, and closer coordination between federal and any successor state investigators. Providers should reassess compliance programs, billing controls, and self-disclosure posture in anticipation of accelerated enforcement.
Life sciences companies and patent counsel filing method of treatment claims before clinical data is available must revise drafting strategies, after a Federal Circuit ruling invalidated a $107.5 million verdict by finding such claims unenabled when they lack patient-level dosing guidance and rely solely on unvalidated in vitro results.
On July 9, 2026, the U.S. Court of Appeals for the Federal Circuit issued a precedential ruling in Wyeth LLC v. AstraZeneca Pharmaceuticals LP, affirming a district court’s finding that Wyeth’s patents for methods of treating EGFR inhibitor-resistant non-small cell lung cancer were invalid for lack of enablement. The court held the patents’ in vitro cell assay data and broad, unvalidated dose ranges were insufficient to enable the claimed “unit dosage” requirement for patient administration, as disclosed doses for two of three candidate drugs exceeded safe human tolerance levels. The ruling clarifies method of treatment claims require more than lab efficacy data when claim language mandates patient-level therapeutic effect, and that specification language emphasizing dosing variability can support non-enablement findings. Life sciences innovators should avoid overbroad claim language importing patient efficacy requirements without corresponding specification support, limit language highlighting dosing unpredictability, and prioritize filing dosing claims after clinical trial data is
…
In-house IP and brand protection counsel must avoid overreaching UDRP complaints, as a WIPO panel’s RDNH finding against the CREDITGPT trademark complainant sets a clear precedent for penalizing bad faith domain dispute filings.
A WIPO panel ruled that a trademark complaint filed over the CREDITGPT domain name constituted reverse domain name hijacking (RDNH), calling the filing a “poster child” for the prohibited practice. The decision reinforces that UDRP complainants must demonstrate both valid, enforceable trademark rights and bad faith conduct by the domain registrant, rather than filing speculative or overbroad complaints to seize domains tied to emerging AI-related branding. In-house counsel should review their teams’ UDRP filing protocols to ensure all submissions are supported by clear evidence of registrant bad faith, to avoid RDNH findings that carry reputational harm and bar future UDRP participation.
Multinational importers must reassess supply chains as CBP consolidates enforcement guidance under three forced labor statutes.
On June 12, 2026, U.S. Customs and Border Protection released a guide clarifying how it enforces U.S. import restrictions on goods produced with forced labor. The guidance consolidates three principal authorities: Section 307 of the Tariff Act (19 U.S.C. § 1307), the Uyghur Forced Labor Prevention Act (UFLPA), and the Countering America's Adversaries Through Sanctions Act (CAATSA). CBP's framework signals heightened scrutiny of supply chains, particularly those with ties to Xinjiang and other high-risk regions. Importers should expect increased detention rates, expanded use of withhold release orders, and more rigorous documentation demands. Companies should map tier-2 and tier-3 suppliers, audit labor practices, and prepare due-diligence records demonstrating that inputs are fully divorced from forced labor sources to mitigate detention and seizure risk.
Importers seeking refunds of IEEPA tariffs must complete a specific ACE portal action or risk forfeiting recovery of significant working capital.
Following the Supreme Court's invalidation of certain IEEPA-based tariffs, U.S. Customs and Border Protection is processing refunds for importers who paid duties under those authorities. However, CBP will not automatically issue refunds; importers must affirmatively request them through the Automated Commercial Environment (ACE) portal. Many businesses with global supply chains that paid substantial IEEPA tariffs stand to recover meaningful cash, but those who overlook the required ACE filing risk losing the refund entirely. In-house counsel and trade compliance teams should immediately audit prior entries paid under IEEPA, confirm whether refund requests have been submitted, and coordinate with customs brokers to ensure filings are completed before applicable deadlines. Acting promptly is critical to preserving the recovery.
In-house counsel managing private arbitrations pending or filed in Connecticut must revise arbitrator selection processes to comply with a 2026 state law requiring all arbitrators to be Connecticut-admitted attorneys in good standing.
Effective July 1, 2026, Connecticut Public Act 26-92 will require all arbitrators in private arbitrations conducted in the state to be attorneys admitted to practice in Connecticut in good standing. The rule applies not only to new arbitrations filed after the effective date, but also to pending matters where an evidentiary hearing has not yet commenced as of July 1, 2026. In-house counsel with active or anticipated Connecticut private arbitrations should review existing arbitration agreements and pending dockets now to confirm arbitrator eligibility, update selection workflows, and adjust pending matters as needed to meet the new requirement ahead of the effective date.
Organizations that collect, process, or monetize consumer personal data must update compliance programs immediately, as Q2 2026 brought two new comprehensive state privacy laws, amended existing frameworks, and a record $12.75 million CCPA settlement signaling heightened regulatory scrutiny of sensitive data use and secondary data sharing.
Q2 2026 brought significant shifts to U.S. state privacy regulation: Louisiana and Vermont became the 22nd and 23rd states to enact comprehensive consumer privacy laws, with unique provisions including Louisiana’s $25 million revenue applicability threshold and Vermont’s ban on broad nonprofit exemptions, with effective dates of January 1, 2027 and January 1, 2028 respectively. Existing state privacy laws were amended across Maryland, Tennessee, Virginia, and Connecticut to tighten sensitive data definitions, ban precise geolocation data sales, lower applicability thresholds, and add minor data protections. California regulators also secured a record $12.75 million CCPA settlement against an automaker for undisclosed sale of precise geolocation data to data brokers, reinforcing enforcement focus on purpose limitation and data minimization. New Jersey and Connecticut enacted new data broker rules, including New Jersey’s tiered registration fees tied to volume of brokered consumer data. Organizations should review data collection, sharing, and retention practices to align with new and
…
Corporate compliance and legal teams must monitor 2026 state AG elections across 30+ states, as outcomes will directly alter enforcement priorities, multistate coalition membership, and sector-specific regulatory risk for businesses operating in those jurisdictions.
The 2026 election cycle features attorney general contests across 30 states plus the District of Columbia, with a high volume of open seats driven by constitutional term limits and incumbents seeking higher office in major economic engines including Colorado, Georgia, Michigan, Nevada, Ohio, and Oklahoma. New AG leadership routinely adjusts administrative priorities and enforcement personnel, shifting baseline regulatory risk for businesses. Competitive reelection bids for incumbents in swing states such as Arizona, Minnesota, and Wisconsin also carry weight, as those offices have historically led high-impact consumer protection and technology-focused enforcement actions. Election outcomes will determine whether states lead, join, or exit multi-million dollar multistate corporate investigations and federal legal challenges, requiring compliance teams to track race developments and candidate policy positions aligned with their operational footprints.
In-house counsel for multi-state businesses must monitor 2026 state AG elections, as winning candidates will shift enforcement priorities across consumer protection, antitrust, privacy and other core business oversight areas.
The article explains that state attorneys general have become some of the most influential public legal actors shaping the national business environment over the past decade, with broad authority to lead enforcement actions, multistate litigation and policy guidance across consumer protection, antitrust, privacy, healthcare, environmental and ESG issues. 2026 election cycles, particularly open-seat races in high-impact states, will create leadership transitions that can quickly shift an office’s tone, staffing, coalition strategy and enforcement focus. In-house counsel should map their state-level exposure across operations, customer bases and regulatory obligations, audit compliance protocols for multistate scrutiny, and monitor post-election transition signals to adjust risk strategies for 2027 and beyond.
Issuers, advisers, and broker-dealers should prepare now for a shift from opt-in to opt-out electronic delivery of regulatory disclosures.
On July 16, 2026, the SEC proposed Regulation E-Delivery, which would replace the current opt-in framework with an opt-out default for electronic delivery of covered information under the federal securities laws. Covered entities—including issuers, investment advisers, and broker-dealers—could deliver prospectuses, proxy materials, information statements, tender offer documents, and shareholder reports electronically if the recipient has provided an electronic address, received prominent notice, and has not opted out. Information containing personal financial information would require a notice-and-access approach via email link. The rule permits, but does not require, reliance on e-delivery, preserving flexibility. The 60-day comment period opens upon Federal Register publication. In-house counsel should assess delivery workflows, investor communications, website hosting requirements, and cost-saving opportunities while preparing compliance plans for the transition.
AI deployers and developers face unresolved compliance exposure after the FTC's recent statement on output 'steering' failed to clarify liability boundaries.
The FTC issued a statement addressing how 'steering' AI model outputs—shaping or constraining what generative systems produce—intersects with existing consumer protection and antitrust frameworks. While the agency signaled scrutiny of practices that distort competition or deceive users, it stopped short of defining prohibited conduct, leaving deployers uncertain about where permissible product design ends and unfair method-of-competition liability begins. The statement notably omits safe harbors, documentation expectations, and thresholds for when steering crosses into Section 5 violation territory. In-house counsel at companies building, fine-tuning, or integrating generative AI tools should reassess model governance documentation, vendor contracts, and disclosure practices now, rather than waiting for enforcement actions to draw clearer lines. Expect follow-on rulemaking or guidance.
Federal prosecutors nationwide must now carry a minimum number of open matters, signaling DOJ's push for sustained enforcement throughput that companies facing investigations should expect to outlast any single case team.
Reports indicate the Department of Justice has directed all federal prosecutors to maintain a baseline number of active cases at any given time, formalizing productivity expectations across U.S. Attorney's Offices. The policy reframes case management from a reactive posture to a quota-driven pipeline, with line prosecutors evaluated on sustained throughput rather than individual dispositions. For in-house counsel, this means investigations are less likely to be closed quietly or deprioritized mid-cycle, and parallel or successor matters may be opened even where an existing case is winding down. Companies under scrutiny should anticipate more aggressive timeline pressure, broader use of supplemental subpoenas, and reduced willingness by DOJ to negotiate narrow resolutions. Practical steps include preserving investigative readiness, pre-clearing key custodians, and budgeting for multi-stage document production rather than a single sweep.
Grade 3 — worth a glance, not the full analysis.
- Amazon Secures Terminating Sanctions Against Supplier Over Fabricated Damages Evidence
In-house counsel managing supplier relationships and commercial litigation must take note of this ruling, which confirms courts will impose terminating sanctions and fee-shifting against parties that commit fraud on the court by fabricating damages evidence.
- Energy Capital Stacks Now Layer Project, Holdco, and NAV Debt
Energy sponsors and their lenders must coordinate project, holdco, and NAV facilities so cash controls, LTV triggers, and intercreditor terms prevent liquidity stress from cascading up the ownership chain.
- Upcoming EPR Think Tank to Cover U.S. Packaging Producer Responsibility Trends
Consumer goods manufacturers, retail operators, and packaging suppliers must monitor evolving U.S. state packaging EPR rules to avoid noncompliance penalties and unplanned supply chain cost increases.
- DOL Secretary Nominee Sonderling Testifies at Senate Confirmation Hearing
In-house counsel overseeing U.S. labor compliance must track Sonderling’s stated policy priorities to anticipate upcoming Department of Labor regulatory and enforcement shifts.