DROPLETS
Digital asset issuers, trading platforms, and broker-dealers must track a merged Senate market-structure bill, new SEC guidance on tokenized securities, and federal momentum toward round-the-clock trading.
Senate Republicans released a 616-page updated Digital Asset Market Clarity Act merging Banking and Agriculture Committee texts, adding a federal-ethics title barring officials from issuing or sponsoring digital assets during public service. Seven Democrats raised concerns, and Majority Leader Thune cast doubt on passage before August recess, signaling continued negotiation risk. The SEC's Division of Corporation Finance confirmed that issuers conducting Rule 506(c) offerings of tokenized securities may collect accredited-investor representations via digital attestation, easing compliance for tokenized offerings. Commissioner Peirce reiterated that onchain activity remains within federal securities laws. The SEC will hold a September roundtable on 24-hour equity trading, and the CFTC extended its comment period on 24/7 futures trading, indicating likely regulatory accommodation. A Washington state court enjoined a prediction-markets platform, rejecting CEA preemption of state gambling law. In-house counsel should monitor bill text changes, prepare for tokenized-offering workflows, an
…
Multinationals operating in France with anti-corruption compliance gaps face direct monetary exposure after the AFA Sanctions Committee's first Sapin II fines.
The French Anti-Corruption Agency's Sanctions Committee has issued its first monetary penalties under Article 17 of the Sapin II Act, fining a company €350,000 and its president €60,000 for failing to implement required anti-corruption measures. The breaches, identified during a 2024–2025 inspection, spanned seven of the eight Article 17 obligations, including risk mapping, third-party due diligence, accounting controls, training, and a code of conduct. Two doctrinal shifts carry significant implications for in-house counsel. First, the AFA director referred the matter directly for sanction without a prior injunction, confirming that Article 17(IV) does not require a graduated enforcement approach. Second, breaches are now assessed as of the date of the final inspection report rather than the Committee's ruling date, meaning post-inspection remediation no longer erases the violation—only mitigates the penalty amount. Personal liability for executives was also affirmed, with the Committee holding the founder-chairman accountable as a 'skilled professional' in a high-risk sector. Compa
…
Employers previously required to submit EEO-1 demographic reports must revise their data collection and compliance protocols to align with imminent federal regulatory changes.
The EEOC is set to discontinue longstanding EEO-1 reporting requirements, which currently require employers to collect and submit annual demographic data (covering race, sex, and ethnicity) sorted by job category for both employees and job applicants. A recent executive order has also rescinded prior federal agency guidance on disparate impact discrimination claims tied to this collected demographic data. While employers will no longer be required to file EEO-1 reports with the EEOC, they must still ensure any voluntary demographic data collection practices comply with existing federal, state, and local anti-discrimination laws, avoid creating unintended disparate impacts, and align with any state or local reporting mandates that still require similar demographic disclosures. Employers should also review their internal DEI and hiring programs to ensure they do not rely on the now-rescinded federal disparate impact guidance frameworks.
In-house counsel for regulated businesses must update compliance and enforcement strategies to address an expected surge of state attorney general-led challenges to federal agency rules following the overturning of Chevron deference.
The 2024 Supreme Court ruling in Loper Bright Enterprises v. Raimondo overturned the 40-year-old Chevron deference doctrine, which previously required courts to defer to reasonable federal agency interpretations of ambiguous statutes. With that precedent eliminated, state attorneys general—who already regularly challenge federal regulations on policy and partisan grounds—are poised to lead both defensive enforcement of state-level rules and offensive litigation against federal agency actions they oppose. Regulated industries should anticipate increased parallel state and federal regulatory scrutiny, more frequent challenges to existing compliance obligations, and divergent state-level rulemaking. In-house counsel should audit current compliance frameworks, monitor state AG policy priorities in their operating jurisdictions, and build cross-jurisdictional litigation response plans to navigate this fragmented enforcement environment.
Private employers and in-house employment counsel must monitor this EEOC rulemaking proposal, as it would eliminate long-standing mandatory EEO-1 workforce demographic reporting requirements if finalized.
On July 21, 2026, the EEOC issued a proposed rule to rescind regulations mandating EEO-1 through EEO-6 workforce demographic reporting, as well as recordkeeping rules tied specifically to preparing those reports. Current EEO-1 compliance obligations remain fully in effect until a final rule is adopted, so employers should not adjust existing demographic data collection or recordkeeping practices based solely on the proposal. Even if finalized, broader personnel record retention requirements for employment claims will still apply, and many employers may still be subject to state or local demographic reporting mandates. In-house counsel should track the rulemaking process and review overlapping jurisdictional compliance requirements.
In-house counsel and deal teams at global tech companies with Korean supply chain, AI infrastructure or regional partnership exposure must address immediate legal and operational risks from South Korea’s $518B coordinated semiconductor, AI and robotics industrial build-out.
South Korea has announced a compressed, $518B public-private semiconductor cluster build-out across the Gwangju/Jeolla and Chungcheong regions, paired with a $341B AI data center rollout and humanoid robotics push targeting 20% of the global market by the mid-2030s, years ahead of its original 2040s timeline. The initiative streamlines permitting, allocates 30 trillion won over 15 years to support the full semiconductor value chain from design through advanced packaging, and is capitalized primarily by Samsung and SK. For global tech companies, this creates urgent needs to revise long-term supply agreements to include take-or-pay protections, infrastructure delay force majeure terms, and jointly developed IP ownership clauses, while also mapping all related transactions against U.S. semiconductor export controls, Korean technology transfer rules and cross-border investment review regimes to avoid compliance gaps from the accelerated construction timeline.
Defense contractors and suppliers must reassess cybersecurity compliance, supply-chain vetting, and FCA exposure as DoD enforcement tightens.
The Department of Defense has paused the CMMC cybersecurity certification rollout, creating uncertainty for primes and subcontractors awaiting assessment timelines. Meanwhile, supply-chain chokepoints—particularly around critical components and foreign-sourced materials—continue to draw scrutiny under procurement integrity rules. Compounding the risk, False Claims Act enforcement is escalating, with DOJ targeting misrepresentations in cybersecurity self-assessments, country-of-origin disclosures, and tariff-related certifications. Recent qui tam settlements signal that contractors should expect heightened whistleblower activity. Practical steps: document CMMC readiness gaps, audit supply-chain disclosures, refresh FCA compliance training, and review representations made in recent solicitations. Companies should also evaluate voluntary disclosure options where noncompliance is identified, as cooperation credit is increasingly material to penalty outcomes.
In-house counsel for consumer financial services firms must act because recent Regulation E electronic delivery rule changes create new compliance obligations with CFPB enforcement risk for non-compliance.
The publication analyzes recent amendments to Regulation E, the federal rule governing consumer electronic fund transfers, that modify permitted methods for delivering required consumer disclosures electronically. It evaluates whether the changes represent a significant relaxation of prior delivery restrictions or a modest adjustment with ongoing compliance constraints. Financial institutions offering consumer debit products, peer-to-peer payment tools, or other electronic fund transfer services must audit existing disclosure delivery workflows for alignment with the updated rule, revise consumer-facing disclosure language as needed, and train relevant staff on revised requirements to avoid CFPB enforcement penalties.
Broker-dealer compliance and litigation teams should track FINRA's pending adoption of 24 expert recommendations reshaping Rule 8210 requests, Wells submissions, cooperation credit, and AWC transparency.
FINRA's outside experts delivered a 24-recommendation report under the FINRA Forward initiative, covering eight areas from governance to settlements. The most consequential changes for member firms include: a neutral decision-maker forum to challenge overly broad Rule 8210 requests; pre-issuance consultation and senior-level approval for information requests; enhanced Wells procedures featuring reverse proffers, immediate access to on-the-record testimony, and post-Wells meetings with enforcement leadership; a published enforcement manual modeled on the SEC's; expanded Rapid Remediation and expedited resolution of technical violations; broader cooperation credit not requiring 'extraordinary' efforts; and AWC reforms including Mitigation Statements, transparent sanction calculations, and curbing Rule 2010 'tag-along' charges. FINRA CEO Robert Cook signaled a deliberate, holistic review. Firms should reassess Wells response playbooks, document cooperation efforts, and prepare for potential Rule 8210 challenges while monitoring FINRA's implementation timeline.
Companies that develop, deploy, or monetize AI-powered offerings face active enforcement from state attorneys general using existing consumer protection, privacy, and licensing laws, rather than waiting for new AI-specific regulations.
A growing number of state attorneys general are leveraging pre-existing legal frameworks—including state consumer protection statutes, data privacy laws, and professional licensing requirements—to investigate and penalize AI business practices, rather than holding off for the passage of new AI-specific legislation. This trend eliminates the buffer companies may have expected while AI regulatory rules were still being drafted at the state and federal levels. In-house counsel for organizations that build, integrate, or sell AI tools should immediately audit their AI workflows, data handling practices, and marketing claims against all applicable existing state laws, and update compliance programs to address AI-specific risk factors under these longstanding frameworks.
Third Circuit employers gain clearer authority to discipline ADA-protected misconduct when workers first raise a disability during disciplinary proceedings.
In Hileman v. West Penn Allegheny Health System, the Third Circuit held that ADA plaintiffs must clearly and timely communicate their accommodation needs, and that employers are not required to excuse misconduct connected to a disability, especially when the employee first identifies the disability as part of a disciplinary process. The decision reinforces two practical principles for HR and in-house counsel: documentation of an employee's failure to request accommodation matters, and disciplinary records need not be softened simply because an employee later attributes misconduct to a medical condition. Employers should review accommodation-request intake procedures, ensure managers are trained to recognize and route requests promptly, and coordinate counsel early when discipline intersects with a newly disclosed disability. The ruling narrows the gap between accommodation and accountability in the Third Circuit.
California policyholders with layered excess insurance coverage and their counsel may now bring declaratory relief and bad faith claims against excess insurers without first exhausting all underlying lower-layer policies, removing the prior mandate to file serial lawsuits up the coverage tower.
The California Supreme Court unanimously ruled in Fox Paine & Co. v. Twin City Fire Insurance Co. that exhaustion of underlying insurance policies is not a categorical bar to insureds pursuing claims against excess insurers. The Court held policyholders may seek declaratory relief by alleging a covered loss that reasonably likely reaches the excess policy’s attachment point, and may bring bad faith claims by showing the excess insurer’s misconduct impaired their recovery, even before lower layers are exhausted. Insureds with layered California insurance policies can now consolidate coverage disputes across all tiers in a single action, rather than filing sequential lawsuits for each coverage layer.
In-house counsel for consumer-facing digital businesses must act because plaintiffs are increasingly pairing CCPA claims with wiretapping allegations, creating expanded statutory damage exposure.
Recent reporting from Troutman Pepper Locke attorneys highlights a growing trend of plaintiffs leveraging the California Consumer Privacy Act’s private right of action and statutory damages provisions to support wiretapping claims, rather than relying exclusively on traditional state and federal wiretapping laws. This shift expands litigation risk for companies that collect user data via websites, apps, and other digital channels, as CCPA’s higher damage caps can lead to far larger payouts in these cases. In-house counsel should audit existing data collection and user consent workflows for CCPA compliance gaps that could be weaponized in these suits, and update litigation risk forecasting to account for this emerging claim strategy.
Healthcare providers and Medicaid participants face heightened exclusion risk and payment disruption following HHS’s new CMS authority grant and targeted payment pauses.
The U.S. Department of Health and Human Services (HHS) has formally granted the Centers for Medicare & Medicaid Services (CMS) expanded authority to impose healthcare program exclusions, while simultaneously pausing $1 billion in Medicaid payments for California and Minnesota providers over suspected fraud. The shift centralizes exclusion enforcement power at CMS, eliminating prior barriers to pursuing exclusion actions for Medicaid-related misconduct. Affected entities should immediately review their compliance programs for Medicaid billing and fraud prevention gaps, prepare documentation to respond to potential exclusion inquiries, and monitor state-level Medicaid payment status updates to mitigate operational and revenue risks.
Energy companies, commodity traders, and any party with WTI-linked contracts, hedges, or fuel cost exposure must monitor developments because Cushing, the global WTI delivery hub, is near tank-bottom inventory levels, eliminating the standard WTI-Brent discount and distorting the world’s most traded oil benchmark.
Cushing, the global delivery point for West Texas Intermediate (WTI) crude futures, saw inventories fall to 19.4 million barrels as of mid-July 2026, the lowest level since October 2014, driven by surging global demand for U.S. crude exports following Strait of Hormuz disruptions that drew down 800,000 barrels weekly for eight consecutive weeks. The hub is now near its minimum operational “tank bottom” level, meaning reported inventory overstates deliverable supply, and the long-standing WTI discount to Brent has flipped to a premium for the first time since January 2022. Parties with WTI-priced contracts, hedges, or storage arrangements should review force majeure clauses, pricing adjustment mechanisms, and supply contingency plans, as the hub’s reduced buffer will increase price volatility and limit supply responsiveness to sudden market disruptions.
All New York City employers must update their policies and practices to comply with new expanded leave entitlements, mandatory 32-hour unpaid leave bank requirements, and strengthened recordkeeping rules under the amended Earned Safe and Sick Time Act, which took effect July 23, 2026.
The New York City Department of Consumer and Worker Protection finalized amendments to the Earned Safe and Sick Time Act (ESSTA) after a public comment period, effective July 23, 2026. Key updates expand eligible leave reasons to include caring for children or care recipients, attending legal proceedings, addressing housing or subsistence benefit issues, responding to public disasters, and reacting to workplace violence. A new mandate requires employers to provide a separate 32-hour bank of immediately available protected unpaid leave to all employees on their first day of work and at the start of each calendar year, with unused hours required to be restored for employees rehired in the same year. The rules also confirm a separate 20-hour paid prenatal leave bank, require paid leave to be applied before unpaid leave unless an employee requests otherwise, and strengthen requirements for written policies, pay statement disclosures, and recordkeeping. All NYC employers should review and update their ESSTA policies, distribute revised staff notices, and adjust payroll and recordkeeping s
…
In-house counsel for crypto, fintech, and financial services firms must prioritize compliance reviews and business strategy adjustments amid new SEC regulatory guidance on crypto vaults, active federal enforcement actions, and rapidly evolving institutional crypto market infrastructure.
This update covers key July 2026 crypto industry developments: SEC Commissioner Hester Peirce issued guidance clarifying that parties managing crypto vaults or onchain lending strategies may trigger federal securities law obligations if they exercise discretion over asset allocations, interest rates, or liquidation thresholds. The SEC and DOJ also announced multiple enforcement actions targeting crypto fraud, including charges against a Florida operator accused of misappropriating $22 million in investor funds and seizure of $25 million tied to international scam networks. On the market side, multiple U.S. financial institutions launched regulated spot crypto trading for clients, a U.S. crypto payment processor secured an EU MiCA license for cross-border stablecoin services, and major firms announced partnerships to launch tokenized securities IPOs and onchain prime brokerage products. Two crypto bridge exploits resulted in $31.6 million in stolen funds, underscoring cross-chain cybersecurity risks. In-house counsel should assess whether their firm’s crypto yield products fall under
…
U.S. technology companies pursuing or currently holding federal government contracts must assess new procurement rule changes that create untapped market opportunities alongside unaddressed compliance risks.
The Trump administration has issued a series of executive orders and directives overhauling U.S. federal procurement processes to prioritize agility, efficiency, and expansion of the federal contractor pool, including deregulation of requirements for commercial and non-traditional contractors. These changes apply to all existing and prospective federal contractors, but are explicitly designed to lower barriers for technology companies that have not previously worked with the government. Firms must review updated procurement priorities, evaluate risk areas tied to new contracting pathways, and assess how their existing or proposed offerings align with the administration’s streamlined buying goals to capitalize on opportunities while avoiding compliance gaps.
Life sciences manufacturers and distributors selling into the EU must redesign packaging now to meet new recyclability, reuse, and substance-restriction mandates before phased deadlines hit.
The EU's Packaging and Packaging Waste Regulation (PPWR) replaces the 1994 Directive with binding, directly applicable rules covering all packaging formats. Life sciences companies face heightened scrutiny: primary, secondary, and transport packaging for pharmaceuticals, medical devices, diagnostics, and cosmetics must meet minimum recycled-content thresholds, design-for-recycling criteria, and reuse targets that scale by format. Certain PFAS and other substances of concern are restricted. Deadlines begin in 2026 with full applicability by 2030, and national authorities will enforce via market surveillance and eco-modulated fees. Companies should audit their packaging portfolios, map substances against restricted lists, engage suppliers on recycled-content availability, and update technical files and labeling. Early action reduces redesign costs and avoids market-access disruption across all 27 member states.
Cross-border deal teams using common-law R&W drafting in civil-law jurisdictions must reassess remedy framing after Chile's first-ever LACI annulment.
The Santiago Court of Appeals annulled a USD 217 million award in Food Investment SpA v. Asesorías e Inversiones Benjamín, marking the first set-aside under Chile's 2004 international arbitration statute (Law 19,971). The tribunal granted a price-reduction remedy drawn from the Chilean Civil Code's hidden-defects provisions, even though buyers had only requested termination or damages. The court held this was extra petita under Article 34(2)(a)(iii), which mirrors the UNCITRAL Model Law. The decision does not signal hostility to arbitration—Chile's courts had rejected all prior annulment petitions since 2007—but it does enforce strict adherence to the scope of submission. Practitioners should ensure SPA dispute-resolution clauses expressly enumerate available remedies, including price reduction, when drafting for civil-law jurisdictions.
Companies with Russia or Belarus exposure must reassess contracts, shipping, and financial flows after the EU's 21st sanctions package and OFAC's Lukoil license update.
On July 23, 2026, the EU Council adopted its 21st sanctions package against Russia, expanding measures targeting energy revenues, the military-industrial complex, financial services, the shadow fleet, and critical infrastructure. The package amends Regulation 269 (asset freezes) and Regulation 833 (trade restrictions), and adds parallel Belarus restrictions under new Council regulations and decisions, including asset freeze designations and trade measures mirroring those against Russia. Separately, on July 24, 2026, OFAC issued Russia-related General License 131H, authorizing certain transactions tied to negotiating and entering contingent contracts for the sale of Lukoil International GmbH and related maintenance activities, and amended FAQs 1224 and 1225. In-house counsel should map counterparties against the new EU designations, review shipping and financial arrangements for shadow-fleet and critical-infrastructure exposure, and evaluate any Lukoil-related transactions for GL 131H eligibility.
In-house counsel and deal teams at global tech companies with Korean supply chain, AI infrastructure or regional partnership exposure must address immediate legal and operational risks from South Korea’s $518B coordinated semiconductor, AI and robotics industrial build-out.
South Korea has announced a compressed, $518B public-private semiconductor cluster build-out across the Gwangju/Jeolla and Chungcheong regions, paired with a $341B AI data center rollout and humanoid robotics push targeting 20% of the global market by the mid-2030s, years ahead of its original 2040s timeline. The initiative streamlines permitting, allocates 30 trillion won over 15 years to support the full semiconductor value chain from design through advanced packaging, and is capitalized primarily by Samsung and SK. For global tech companies, this creates urgent needs to revise long-term supply agreements to include take-or-pay protections, infrastructure delay force majeure terms, and jointly developed IP ownership clauses, while also mapping all related transactions against U.S. semiconductor export controls, Korean technology transfer rules and cross-border investment review regimes to avoid compliance gaps from the accelerated construction timeline.
In-house counsel for consumer financial services firms must act because recent Regulation E electronic delivery rule changes create new compliance obligations with CFPB enforcement risk for non-compliance.
The publication analyzes recent amendments to Regulation E, the federal rule governing consumer electronic fund transfers, that modify permitted methods for delivering required consumer disclosures electronically. It evaluates whether the changes represent a significant relaxation of prior delivery restrictions or a modest adjustment with ongoing compliance constraints. Financial institutions offering consumer debit products, peer-to-peer payment tools, or other electronic fund transfer services must audit existing disclosure delivery workflows for alignment with the updated rule, revise consumer-facing disclosure language as needed, and train relevant staff on revised requirements to avoid CFPB enforcement penalties.
Cross-border deal teams using common-law R&W drafting in civil-law jurisdictions must reassess remedy framing after Chile's first-ever LACI annulment.
The Santiago Court of Appeals annulled a USD 217 million award in Food Investment SpA v. Asesorías e Inversiones Benjamín, marking the first set-aside under Chile's 2004 international arbitration statute (Law 19,971). The tribunal granted a price-reduction remedy drawn from the Chilean Civil Code's hidden-defects provisions, even though buyers had only requested termination or damages. The court held this was extra petita under Article 34(2)(a)(iii), which mirrors the UNCITRAL Model Law. The decision does not signal hostility to arbitration—Chile's courts had rejected all prior annulment petitions since 2007—but it does enforce strict adherence to the scope of submission. Practitioners should ensure SPA dispute-resolution clauses expressly enumerate available remedies, including price reduction, when drafting for civil-law jurisdictions.
Employers previously required to submit EEO-1 demographic reports must revise their data collection and compliance protocols to align with imminent federal regulatory changes.
The EEOC is set to discontinue longstanding EEO-1 reporting requirements, which currently require employers to collect and submit annual demographic data (covering race, sex, and ethnicity) sorted by job category for both employees and job applicants. A recent executive order has also rescinded prior federal agency guidance on disparate impact discrimination claims tied to this collected demographic data. While employers will no longer be required to file EEO-1 reports with the EEOC, they must still ensure any voluntary demographic data collection practices comply with existing federal, state, and local anti-discrimination laws, avoid creating unintended disparate impacts, and align with any state or local reporting mandates that still require similar demographic disclosures. Employers should also review their internal DEI and hiring programs to ensure they do not rely on the now-rescinded federal disparate impact guidance frameworks.
Private employers and in-house employment counsel must monitor this EEOC rulemaking proposal, as it would eliminate long-standing mandatory EEO-1 workforce demographic reporting requirements if finalized.
On July 21, 2026, the EEOC issued a proposed rule to rescind regulations mandating EEO-1 through EEO-6 workforce demographic reporting, as well as recordkeeping rules tied specifically to preparing those reports. Current EEO-1 compliance obligations remain fully in effect until a final rule is adopted, so employers should not adjust existing demographic data collection or recordkeeping practices based solely on the proposal. Even if finalized, broader personnel record retention requirements for employment claims will still apply, and many employers may still be subject to state or local demographic reporting mandates. In-house counsel should track the rulemaking process and review overlapping jurisdictional compliance requirements.
Third Circuit employers gain clearer authority to discipline ADA-protected misconduct when workers first raise a disability during disciplinary proceedings.
In Hileman v. West Penn Allegheny Health System, the Third Circuit held that ADA plaintiffs must clearly and timely communicate their accommodation needs, and that employers are not required to excuse misconduct connected to a disability, especially when the employee first identifies the disability as part of a disciplinary process. The decision reinforces two practical principles for HR and in-house counsel: documentation of an employee's failure to request accommodation matters, and disciplinary records need not be softened simply because an employee later attributes misconduct to a medical condition. Employers should review accommodation-request intake procedures, ensure managers are trained to recognize and route requests promptly, and coordinate counsel early when discipline intersects with a newly disclosed disability. The ruling narrows the gap between accommodation and accountability in the Third Circuit.
All New York City employers must update their policies and practices to comply with new expanded leave entitlements, mandatory 32-hour unpaid leave bank requirements, and strengthened recordkeeping rules under the amended Earned Safe and Sick Time Act, which took effect July 23, 2026.
The New York City Department of Consumer and Worker Protection finalized amendments to the Earned Safe and Sick Time Act (ESSTA) after a public comment period, effective July 23, 2026. Key updates expand eligible leave reasons to include caring for children or care recipients, attending legal proceedings, addressing housing or subsistence benefit issues, responding to public disasters, and reacting to workplace violence. A new mandate requires employers to provide a separate 32-hour bank of immediately available protected unpaid leave to all employees on their first day of work and at the start of each calendar year, with unused hours required to be restored for employees rehired in the same year. The rules also confirm a separate 20-hour paid prenatal leave bank, require paid leave to be applied before unpaid leave unless an employee requests otherwise, and strengthen requirements for written policies, pay statement disclosures, and recordkeeping. All NYC employers should review and update their ESSTA policies, distribute revised staff notices, and adjust payroll and recordkeeping s
…
Life sciences manufacturers and distributors selling into the EU must redesign packaging now to meet new recyclability, reuse, and substance-restriction mandates before phased deadlines hit.
The EU's Packaging and Packaging Waste Regulation (PPWR) replaces the 1994 Directive with binding, directly applicable rules covering all packaging formats. Life sciences companies face heightened scrutiny: primary, secondary, and transport packaging for pharmaceuticals, medical devices, diagnostics, and cosmetics must meet minimum recycled-content thresholds, design-for-recycling criteria, and reuse targets that scale by format. Certain PFAS and other substances of concern are restricted. Deadlines begin in 2026 with full applicability by 2030, and national authorities will enforce via market surveillance and eco-modulated fees. Companies should audit their packaging portfolios, map substances against restricted lists, engage suppliers on recycled-content availability, and update technical files and labeling. Early action reduces redesign costs and avoids market-access disruption across all 27 member states.
Digital asset issuers, trading platforms, and broker-dealers must track a merged Senate market-structure bill, new SEC guidance on tokenized securities, and federal momentum toward round-the-clock trading.
Senate Republicans released a 616-page updated Digital Asset Market Clarity Act merging Banking and Agriculture Committee texts, adding a federal-ethics title barring officials from issuing or sponsoring digital assets during public service. Seven Democrats raised concerns, and Majority Leader Thune cast doubt on passage before August recess, signaling continued negotiation risk. The SEC's Division of Corporation Finance confirmed that issuers conducting Rule 506(c) offerings of tokenized securities may collect accredited-investor representations via digital attestation, easing compliance for tokenized offerings. Commissioner Peirce reiterated that onchain activity remains within federal securities laws. The SEC will hold a September roundtable on 24-hour equity trading, and the CFTC extended its comment period on 24/7 futures trading, indicating likely regulatory accommodation. A Washington state court enjoined a prediction-markets platform, rejecting CEA preemption of state gambling law. In-house counsel should monitor bill text changes, prepare for tokenized-offering workflows, an
…
In-house counsel for crypto, fintech, and financial services firms must prioritize compliance reviews and business strategy adjustments amid new SEC regulatory guidance on crypto vaults, active federal enforcement actions, and rapidly evolving institutional crypto market infrastructure.
This update covers key July 2026 crypto industry developments: SEC Commissioner Hester Peirce issued guidance clarifying that parties managing crypto vaults or onchain lending strategies may trigger federal securities law obligations if they exercise discretion over asset allocations, interest rates, or liquidation thresholds. The SEC and DOJ also announced multiple enforcement actions targeting crypto fraud, including charges against a Florida operator accused of misappropriating $22 million in investor funds and seizure of $25 million tied to international scam networks. On the market side, multiple U.S. financial institutions launched regulated spot crypto trading for clients, a U.S. crypto payment processor secured an EU MiCA license for cross-border stablecoin services, and major firms announced partnerships to launch tokenized securities IPOs and onchain prime brokerage products. Two crypto bridge exploits resulted in $31.6 million in stolen funds, underscoring cross-chain cybersecurity risks. In-house counsel should assess whether their firm’s crypto yield products fall under
…
Defense contractors and suppliers must reassess cybersecurity compliance, supply-chain vetting, and FCA exposure as DoD enforcement tightens.
The Department of Defense has paused the CMMC cybersecurity certification rollout, creating uncertainty for primes and subcontractors awaiting assessment timelines. Meanwhile, supply-chain chokepoints—particularly around critical components and foreign-sourced materials—continue to draw scrutiny under procurement integrity rules. Compounding the risk, False Claims Act enforcement is escalating, with DOJ targeting misrepresentations in cybersecurity self-assessments, country-of-origin disclosures, and tariff-related certifications. Recent qui tam settlements signal that contractors should expect heightened whistleblower activity. Practical steps: document CMMC readiness gaps, audit supply-chain disclosures, refresh FCA compliance training, and review representations made in recent solicitations. Companies should also evaluate voluntary disclosure options where noncompliance is identified, as cooperation credit is increasingly material to penalty outcomes.
U.S. technology companies pursuing or currently holding federal government contracts must assess new procurement rule changes that create untapped market opportunities alongside unaddressed compliance risks.
The Trump administration has issued a series of executive orders and directives overhauling U.S. federal procurement processes to prioritize agility, efficiency, and expansion of the federal contractor pool, including deregulation of requirements for commercial and non-traditional contractors. These changes apply to all existing and prospective federal contractors, but are explicitly designed to lower barriers for technology companies that have not previously worked with the government. Firms must review updated procurement priorities, evaluate risk areas tied to new contracting pathways, and assess how their existing or proposed offerings align with the administration’s streamlined buying goals to capitalize on opportunities while avoiding compliance gaps.
Healthcare providers and Medicaid participants face heightened exclusion risk and payment disruption following HHS’s new CMS authority grant and targeted payment pauses.
The U.S. Department of Health and Human Services (HHS) has formally granted the Centers for Medicare & Medicaid Services (CMS) expanded authority to impose healthcare program exclusions, while simultaneously pausing $1 billion in Medicaid payments for California and Minnesota providers over suspected fraud. The shift centralizes exclusion enforcement power at CMS, eliminating prior barriers to pursuing exclusion actions for Medicaid-related misconduct. Affected entities should immediately review their compliance programs for Medicaid billing and fraud prevention gaps, prepare documentation to respond to potential exclusion inquiries, and monitor state-level Medicaid payment status updates to mitigate operational and revenue risks.
California policyholders with layered excess insurance coverage and their counsel may now bring declaratory relief and bad faith claims against excess insurers without first exhausting all underlying lower-layer policies, removing the prior mandate to file serial lawsuits up the coverage tower.
The California Supreme Court unanimously ruled in Fox Paine & Co. v. Twin City Fire Insurance Co. that exhaustion of underlying insurance policies is not a categorical bar to insureds pursuing claims against excess insurers. The Court held policyholders may seek declaratory relief by alleging a covered loss that reasonably likely reaches the excess policy’s attachment point, and may bring bad faith claims by showing the excess insurer’s misconduct impaired their recovery, even before lower layers are exhausted. Insureds with layered California insurance policies can now consolidate coverage disputes across all tiers in a single action, rather than filing sequential lawsuits for each coverage layer.
Energy companies, commodity traders, and any party with WTI-linked contracts, hedges, or fuel cost exposure must monitor developments because Cushing, the global WTI delivery hub, is near tank-bottom inventory levels, eliminating the standard WTI-Brent discount and distorting the world’s most traded oil benchmark.
Cushing, the global delivery point for West Texas Intermediate (WTI) crude futures, saw inventories fall to 19.4 million barrels as of mid-July 2026, the lowest level since October 2014, driven by surging global demand for U.S. crude exports following Strait of Hormuz disruptions that drew down 800,000 barrels weekly for eight consecutive weeks. The hub is now near its minimum operational “tank bottom” level, meaning reported inventory overstates deliverable supply, and the long-standing WTI discount to Brent has flipped to a premium for the first time since January 2022. Parties with WTI-priced contracts, hedges, or storage arrangements should review force majeure clauses, pricing adjustment mechanisms, and supply contingency plans, as the hub’s reduced buffer will increase price volatility and limit supply responsiveness to sudden market disruptions.
In-house counsel for consumer-facing digital businesses must act because plaintiffs are increasingly pairing CCPA claims with wiretapping allegations, creating expanded statutory damage exposure.
Recent reporting from Troutman Pepper Locke attorneys highlights a growing trend of plaintiffs leveraging the California Consumer Privacy Act’s private right of action and statutory damages provisions to support wiretapping claims, rather than relying exclusively on traditional state and federal wiretapping laws. This shift expands litigation risk for companies that collect user data via websites, apps, and other digital channels, as CCPA’s higher damage caps can lead to far larger payouts in these cases. In-house counsel should audit existing data collection and user consent workflows for CCPA compliance gaps that could be weaponized in these suits, and update litigation risk forecasting to account for this emerging claim strategy.
In-house counsel for regulated businesses must update compliance and enforcement strategies to address an expected surge of state attorney general-led challenges to federal agency rules following the overturning of Chevron deference.
The 2024 Supreme Court ruling in Loper Bright Enterprises v. Raimondo overturned the 40-year-old Chevron deference doctrine, which previously required courts to defer to reasonable federal agency interpretations of ambiguous statutes. With that precedent eliminated, state attorneys general—who already regularly challenge federal regulations on policy and partisan grounds—are poised to lead both defensive enforcement of state-level rules and offensive litigation against federal agency actions they oppose. Regulated industries should anticipate increased parallel state and federal regulatory scrutiny, more frequent challenges to existing compliance obligations, and divergent state-level rulemaking. In-house counsel should audit current compliance frameworks, monitor state AG policy priorities in their operating jurisdictions, and build cross-jurisdictional litigation response plans to navigate this fragmented enforcement environment.
Companies with Russia or Belarus exposure must reassess contracts, shipping, and financial flows after the EU's 21st sanctions package and OFAC's Lukoil license update.
On July 23, 2026, the EU Council adopted its 21st sanctions package against Russia, expanding measures targeting energy revenues, the military-industrial complex, financial services, the shadow fleet, and critical infrastructure. The package amends Regulation 269 (asset freezes) and Regulation 833 (trade restrictions), and adds parallel Belarus restrictions under new Council regulations and decisions, including asset freeze designations and trade measures mirroring those against Russia. Separately, on July 24, 2026, OFAC issued Russia-related General License 131H, authorizing certain transactions tied to negotiating and entering contingent contracts for the sale of Lukoil International GmbH and related maintenance activities, and amended FAQs 1224 and 1225. In-house counsel should map counterparties against the new EU designations, review shipping and financial arrangements for shadow-fleet and critical-infrastructure exposure, and evaluate any Lukoil-related transactions for GL 131H eligibility.
Broker-dealer compliance and litigation teams should track FINRA's pending adoption of 24 expert recommendations reshaping Rule 8210 requests, Wells submissions, cooperation credit, and AWC transparency.
FINRA's outside experts delivered a 24-recommendation report under the FINRA Forward initiative, covering eight areas from governance to settlements. The most consequential changes for member firms include: a neutral decision-maker forum to challenge overly broad Rule 8210 requests; pre-issuance consultation and senior-level approval for information requests; enhanced Wells procedures featuring reverse proffers, immediate access to on-the-record testimony, and post-Wells meetings with enforcement leadership; a published enforcement manual modeled on the SEC's; expanded Rapid Remediation and expedited resolution of technical violations; broader cooperation credit not requiring 'extraordinary' efforts; and AWC reforms including Mitigation Statements, transparent sanction calculations, and curbing Rule 2010 'tag-along' charges. FINRA CEO Robert Cook signaled a deliberate, holistic review. Firms should reassess Wells response playbooks, document cooperation efforts, and prepare for potential Rule 8210 challenges while monitoring FINRA's implementation timeline.
In-house counsel and deal teams at global tech companies with Korean supply chain, AI infrastructure or regional partnership exposure must address immediate legal and operational risks from South Korea’s $518B coordinated semiconductor, AI and robotics industrial build-out.
South Korea has announced a compressed, $518B public-private semiconductor cluster build-out across the Gwangju/Jeolla and Chungcheong regions, paired with a $341B AI data center rollout and humanoid robotics push targeting 20% of the global market by the mid-2030s, years ahead of its original 2040s timeline. The initiative streamlines permitting, allocates 30 trillion won over 15 years to support the full semiconductor value chain from design through advanced packaging, and is capitalized primarily by Samsung and SK. For global tech companies, this creates urgent needs to revise long-term supply agreements to include take-or-pay protections, infrastructure delay force majeure terms, and jointly developed IP ownership clauses, while also mapping all related transactions against U.S. semiconductor export controls, Korean technology transfer rules and cross-border investment review regimes to avoid compliance gaps from the accelerated construction timeline.
Companies that develop, deploy, or monetize AI-powered offerings face active enforcement from state attorneys general using existing consumer protection, privacy, and licensing laws, rather than waiting for new AI-specific regulations.
A growing number of state attorneys general are leveraging pre-existing legal frameworks—including state consumer protection statutes, data privacy laws, and professional licensing requirements—to investigate and penalize AI business practices, rather than holding off for the passage of new AI-specific legislation. This trend eliminates the buffer companies may have expected while AI regulatory rules were still being drafted at the state and federal levels. In-house counsel for organizations that build, integrate, or sell AI tools should immediately audit their AI workflows, data handling practices, and marketing claims against all applicable existing state laws, and update compliance programs to address AI-specific risk factors under these longstanding frameworks.
Multinationals operating in France with anti-corruption compliance gaps face direct monetary exposure after the AFA Sanctions Committee's first Sapin II fines.
The French Anti-Corruption Agency's Sanctions Committee has issued its first monetary penalties under Article 17 of the Sapin II Act, fining a company €350,000 and its president €60,000 for failing to implement required anti-corruption measures. The breaches, identified during a 2024–2025 inspection, spanned seven of the eight Article 17 obligations, including risk mapping, third-party due diligence, accounting controls, training, and a code of conduct. Two doctrinal shifts carry significant implications for in-house counsel. First, the AFA director referred the matter directly for sanction without a prior injunction, confirming that Article 17(IV) does not require a graduated enforcement approach. Second, breaches are now assessed as of the date of the final inspection report rather than the Committee's ruling date, meaning post-inspection remediation no longer erases the violation—only mitigates the penalty amount. Personal liability for executives was also affirmed, with the Committee holding the founder-chairman accountable as a 'skilled professional' in a high-risk sector. Compa
…
Grade 3 — worth a glance, not the full analysis.
- Amended SF Fair Chance Ordinance Imposes New Employer Obligations Effective 2026
Covered San Francisco employers must adhere to expanded fair chance hiring requirements effective August 10, 2026, which impose stricter limits on criminal record use in employment decisions than California state law.
- Leading GP Stakes, Asset Management M&A Lawyer Christopher Scavone Joins New York Firm
In-house counsel for private equity sponsors, asset managers and strategic capital providers should note this hire, as it adds a leading specialist to a top-tier platform for the fast-growing, high-demand GP stakes and asset management M&A niche.
- Germany Requires Day-One Sick Leave Medical Certificates Starting July 2026
Employers with workforces in Germany must update their absence policies and HR procedures ahead of July 2026, when new rules mandate medical certificates for all sick leave and eliminate telephone-based verification options.
- RACC SPAC to Combine With Oak Hill Bio in $175M Rare Disease Biotech Deal
In-house counsel for biotech companies, SPAC sponsors, and life sciences investors must monitor this $175M SPAC combination, which will take a rare disease antisense therapy developer public on Nasdaq by year-end 2026 and set precedent for similar rare disease biotech listings.
- Evolving Adtech Rules, Privacy Enforcement Target Consumer Data Users
Companies that leverage consumer data for advertising technology operations must track evolving privacy rules and enforcement trends to mitigate compliance risk.
- NAIC AI Pilot to Shape 2026 Insurance Industry Regulatory Rules
Insurance carrier in-house counsel and legal advisors to insurtech and insurance sector clients must monitor the NAIC’s AI Evaluation Tool pilot, as it will establish the binding regulatory framework for all AI use in insurance operations starting in 2026.