DROPLETS
Cross-border M&A and investment teams must reassess deal risk: Treasury's new CFIUS matrix signals heightened scrutiny—and likely non-notified enforcement—against foreign acquirers in critical infrastructure, data, and sensitive-tech sectors.
On July 29, 2026, Treasury, as CFIUS chair, released a Risk Matrix cataloguing eight transaction profiles that pose elevated national security risk: critical infrastructure, cybersecurity, information security, personal data, product integrity, proximity to sensitive government sites, supply assurance, and technology transfer. For each profile, the matrix sets out the threat-vulnerability-consequence calculus under 31 C.F.R. § 800.102 and lists illustrative mitigation measures—governance restrictions, source-code reviews, third-party monitorships, segregation of protected technology, supply-continuation commitments, and CFIUS access and audit rights. The release aligns with the America First Investment Policy and a stated push to 'demystify' the process, but it also signals broader enforcement reach, including non-notified outreach. Counsel advising foreign investors, sponsors, and U.S. targets should map deal profiles against the matrix, weigh voluntary filings where risk indicators are present, and prepare for more standardized mitigation expectations rather than bespoke negotiatio
…
Manufacturers of products with digital elements face binding 24-hour vulnerability and incident reporting to ENISA starting September 11, 2026, with fines up to €15M or 2.5% of global turnover.
The European Commission released 80+ pages of non-binding guidance on the Cyber Resilience Act on July 27, 2026, weeks before the regulation's reporting obligations take effect. Manufacturers must notify ENISA and the designated CSIRT through the Single Reporting Platform of any actively exploited vulnerability or severe incident affecting products with digital elements, including those placed on the market before December 11, 2027. The reporting clock starts when the manufacturer, after initial assessment, has reasonable degree of certainty of active exploitation or a severe incident. Timelines: 24-hour early warning, 72-hour notification, and a final report within 14 days (vulnerabilities) or one month (severe incidents). Manufacturers must also inform impacted users. Pre-September 11, 2026 known exploitations are excluded from retroactive reporting. Market surveillance authorities and notified bodies will rely on the guidance for consistent interpretation, making early alignment with its examples and flowcharts advisable.
DOJ is on pace for a record-breaking False Claims Act year, with $1.8B in H1 2026 recoveries, 780+ qui tam filings already, and a brand-new anti-discrimination enforcement theory that exposes federal contractors and grantees to treble-damages liability.
The first half of 2026 confirmed the FCA's role as the federal government's primary civil fraud weapon. DOJ announced more than $1.8 billion in settlements and judgments, including two nine-figure Medicare Advantage resolutions ($556M and $117.7M) and a record-setting $500M+ customs-duty settlement—the largest ever. Qui tam filings already exceed 780 in FY 2026, putting DOJ on track to surpass FY 2025's $6.8B total. DOJ also formalized its relator data-mining initiative and directed fast-tracking of fraud allegations involving federally funded, state-administered benefits programs. For the first time, DOJ settled an FCA case under the Civil Rights Fraud Initiative, signaling that contractors, grantees, and recipients of federal funds face expanded exposure for alleged discrimination. Structurally, FCA enforcement may move from the Civil Division into the new National Fraud Enforcement Division. States are also expanding their FCA statutes—Minnesota's proposal would expressly impose liability on private equity investors in FCA-violating entities. In-house counsel should reassess compl
…
Companies using shared revenue-management or pricing software face heightened Sherman Act exposure after the Third Circuit revived hotel-room price-fixing claims and diverged sharply from other circuits on pleading standards.
In Cornish-Adebiyi v. Caesars Entertainment, the Third Circuit reversed dismissal of a putative class action alleging that nine Atlantic City casino-hotels conspired through Cendyn's Rainmaker pricing software. The court held that staggered adoption over 14 years, the ability to override recommendations, and lack of detail on proprietary algorithm mechanics do not defeat conspiracy inferences at the pleading stage. It credited allegations of roughly 90% adherence to recommendations, synchronized rate increases during declining occupancy, and executive statements about avoiding 'price wars' as sufficient plus factors. The decision departs from other courts that have required more concrete allegations of horizontal agreement and algorithm function, creating a likely circuit split and moving closer to a near-strict-liability framework for algorithmic collusion. Companies using third-party pricing platforms should audit data inputs, override mechanics, compliance rates, and demand-versus-price patterns, and assess antitrust compliance for AI and pricing tools.
HR leaders and EEO compliance teams should reassess data-collection practices now that the EEOC has proposed ending mandatory workforce diversity reporting.
The EEOC has proposed a rule that would relieve employers of the obligation to gather and report race and gender workforce data, a longstanding component of EEO-1 and similar filings. The change signals a shift away from federal-level demographic tracking and could reshape how organizations approach DEI programs, internal audits, and OFCCP-style reviews. Employers should evaluate whether to continue voluntary data collection for risk management, pay-equity analysis, and state or local compliance, since several jurisdictions still require demographic reporting. Counsel should also review vendor contracts, applicant-tracking system configurations, and internal policies that assume federal reporting mandates remain in place. Comments on the proposal are likely to draw significant stakeholder input before any final rule.
UK-based employers and any multinational with UK staff must reassess harassment-prevention policies before October 2026, when the reasonable-steps threshold becomes materially stricter.
The Worker Protection (Amendment of Equality Act 2010) Act 2023 already imposes a proactive duty on UK employers to take reasonable steps to prevent sexual harassment. From October 2026, that duty is strengthened: enforcement will be more rigorous, and tribunals will weigh employer conduct more heavily when assessing remedies. Practical steps include updating harassment and bystander-intervention policies, refreshing mandatory training, documenting risk assessments, and reviewing complaint-handling procedures. Multinationals with UK workforces should align global standards with the heightened UK benchmark. Failure to demonstrate reasonable preventive steps can now expose employers to uplifted damages in discrimination claims.
Employers relying on AI to handle discretionary tasks risk reclassifying administrative staff as nonexempt under the FLSA, exposing them to overtime liability.
Under the Fair Labor Standards Act, the administrative exemption requires employees to exercise independent judgment and discretion on matters of significance. As employers deploy AI to automate analytical decision-making, scheduling, and problem-solving tasks traditionally performed by exempt administrative staff, those workers may no longer meet the duties test. Reclassification would trigger overtime pay obligations, potential back-wage claims, and class action exposure. In-house counsel should audit job descriptions and actual workflows for AI-augmented roles, document the discretionary elements that remain human-driven, and reassess exemption classifications before litigation or DOL audits surface the gap.
Pharma and biotech deal teams must reassess valuations, licensing terms, and M&A structures as Medicare/Medicaid Most Favored Nation demonstration programs advance.
Federal Most Favored Nation pricing initiatives, including contemplated Medicare and Medicaid demonstration programs, are injecting material uncertainty into life sciences transactions. International reference pricing and domestic price-control mechanisms now affect asset valuations, commercialization plans, licensing and collaboration economics, and risk allocation in M&A. Counsel advising pharma and biotech clients should pressure-test diligence frameworks for pricing exposure, reprice earn-outs and milestones tied to government reimbursement, and revisit representations, indemnities, and MAC clauses. Strategic considerations include restructuring co-development and royalty arrangements, evaluating geographic launch sequencing, and preparing for shifting regulatory and reimbursement landscapes. With policy still evolving, proactive deal structuring and scenario planning are essential to mitigate downside and preserve transaction value.
Lenders must adjust credit underwriting protocols to align with new federal guidance on permissible immigration status considerations, reducing regulatory compliance risk.
Recent federal guidance has clarified permissible parameters for considering applicants’ immigration status during credit underwriting, resolving prior regulatory ambiguity in the space. The guidance distinguishes between allowable immigration-related factors for creditworthiness assessment and prohibited considerations that may violate fair lending rules. Lenders should immediately audit existing underwriting policies, employee training materials, and decision-making workflows to ensure alignment with the new standards, remove prohibited immigration status considerations from evaluation processes, and maintain detailed documentation of compliance steps to reduce enforcement risk if subject to regulatory review.
Brands seeking to partner with college athletes via NIL deals must adhere to evolving compliance rules and structured contract terms to avoid legal and reputational risk.
NIL compensation for college athletes became permissible following a series of antitrust challenges to NCAA amateurism rules, including the 2021 NCAA interim policy and 2025 House v. NCAA settlement, which established a new compensation framework for student-athlete endorsements. For brands, this creates both marketing opportunity and distinct compliance risk: NIL deals are subject to fair market value requirements, mandatory disclosure for deals over $600 via NIL Go, and school-specific category restrictions. Brands should structure direct contracts with athletes that tie compensation to legitimate promotional services, include clear deliverables, FTC disclosure requirements, morals and pause clauses, and separate provisions for AI-generated digital replica rights, while building lead time for required review processes.
In-house counsel for regulated businesses, financial services firms, and brokerages must track shifting state AG enforcement priorities to avoid emerging regulatory and litigation risk.
The July 2026 State AG Monitor outlines a major shift in U.S. enforcement following the Supreme Court’s Chevron deference reversal, positioning state attorneys general as the primary enforcers of federal regulatory rules. Key outlined priorities include targeted enforcement against AI development and deployment, filling regulatory gaps in point-of-sale finance, and expanded consumer fraud liability for brokers under New Jersey’s Consumer Fraud Act. In-house counsel should review existing compliance programs to address these emerging state-level enforcement risks, monitor relevant AG office guidance, and assess potential liability for operations involving broker services or POS finance products.
Trademark owners and accused infringers must track this Supreme Court case, as its ruling will determine whether inherent mark strength is decided by judges or juries, directly changing summary judgment eligibility and litigation costs for infringement claims.
The Supreme Court granted certiorari in Rise and Shine Corp. v. PepsiCo to resolve a circuit split over whether a trademark’s inherent strength, a core component of likelihood-of-confusion analyses, is a question of law for judges or a question of fact for juries. The Second Circuit currently treats the inquiry as a legal question, permitting summary judgment resolutions before trial, while multiple other circuits classify it as a factual issue requiring jury consideration. The ruling will standardize federal trademark litigation practice, impact how often infringement claims proceed to trial, shape forum-selection strategies, and affect costs tied to discovery, expert testimony, and consumer perception surveys for all parties in trademark disputes.
Companies using shared revenue-management or pricing software face heightened Sherman Act exposure after the Third Circuit revived hotel-room price-fixing claims and diverged sharply from other circuits on pleading standards.
In Cornish-Adebiyi v. Caesars Entertainment, the Third Circuit reversed dismissal of a putative class action alleging that nine Atlantic City casino-hotels conspired through Cendyn's Rainmaker pricing software. The court held that staggered adoption over 14 years, the ability to override recommendations, and lack of detail on proprietary algorithm mechanics do not defeat conspiracy inferences at the pleading stage. It credited allegations of roughly 90% adherence to recommendations, synchronized rate increases during declining occupancy, and executive statements about avoiding 'price wars' as sufficient plus factors. The decision departs from other courts that have required more concrete allegations of horizontal agreement and algorithm function, creating a likely circuit split and moving closer to a near-strict-liability framework for algorithmic collusion. Companies using third-party pricing platforms should audit data inputs, override mechanics, compliance rates, and demand-versus-price patterns, and assess antitrust compliance for AI and pricing tools.
Companies using shared revenue-management or pricing software face heightened Sherman Act exposure after the Third Circuit revived hotel-room price-fixing claims and diverged sharply from other circuits on pleading standards.
In Cornish-Adebiyi v. Caesars Entertainment, the Third Circuit reversed dismissal of a putative class action alleging that nine Atlantic City casino-hotels conspired through Cendyn's Rainmaker pricing software. The court held that staggered adoption over 14 years, the ability to override recommendations, and lack of detail on proprietary algorithm mechanics do not defeat conspiracy inferences at the pleading stage. It credited allegations of roughly 90% adherence to recommendations, synchronized rate increases during declining occupancy, and executive statements about avoiding 'price wars' as sufficient plus factors. The decision departs from other courts that have required more concrete allegations of horizontal agreement and algorithm function, creating a likely circuit split and moving closer to a near-strict-liability framework for algorithmic collusion. Companies using third-party pricing platforms should audit data inputs, override mechanics, compliance rates, and demand-versus-price patterns, and assess antitrust compliance for AI and pricing tools.
Manufacturers of products with digital elements face binding 24-hour vulnerability and incident reporting to ENISA starting September 11, 2026, with fines up to €15M or 2.5% of global turnover.
The European Commission released 80+ pages of non-binding guidance on the Cyber Resilience Act on July 27, 2026, weeks before the regulation's reporting obligations take effect. Manufacturers must notify ENISA and the designated CSIRT through the Single Reporting Platform of any actively exploited vulnerability or severe incident affecting products with digital elements, including those placed on the market before December 11, 2027. The reporting clock starts when the manufacturer, after initial assessment, has reasonable degree of certainty of active exploitation or a severe incident. Timelines: 24-hour early warning, 72-hour notification, and a final report within 14 days (vulnerabilities) or one month (severe incidents). Manufacturers must also inform impacted users. Pre-September 11, 2026 known exploitations are excluded from retroactive reporting. Market surveillance authorities and notified bodies will rely on the guidance for consistent interpretation, making early alignment with its examples and flowcharts advisable.
HR leaders and EEO compliance teams should reassess data-collection practices now that the EEOC has proposed ending mandatory workforce diversity reporting.
The EEOC has proposed a rule that would relieve employers of the obligation to gather and report race and gender workforce data, a longstanding component of EEO-1 and similar filings. The change signals a shift away from federal-level demographic tracking and could reshape how organizations approach DEI programs, internal audits, and OFCCP-style reviews. Employers should evaluate whether to continue voluntary data collection for risk management, pay-equity analysis, and state or local compliance, since several jurisdictions still require demographic reporting. Counsel should also review vendor contracts, applicant-tracking system configurations, and internal policies that assume federal reporting mandates remain in place. Comments on the proposal are likely to draw significant stakeholder input before any final rule.
UK-based employers and any multinational with UK staff must reassess harassment-prevention policies before October 2026, when the reasonable-steps threshold becomes materially stricter.
The Worker Protection (Amendment of Equality Act 2010) Act 2023 already imposes a proactive duty on UK employers to take reasonable steps to prevent sexual harassment. From October 2026, that duty is strengthened: enforcement will be more rigorous, and tribunals will weigh employer conduct more heavily when assessing remedies. Practical steps include updating harassment and bystander-intervention policies, refreshing mandatory training, documenting risk assessments, and reviewing complaint-handling procedures. Multinationals with UK workforces should align global standards with the heightened UK benchmark. Failure to demonstrate reasonable preventive steps can now expose employers to uplifted damages in discrimination claims.
Employers relying on AI to handle discretionary tasks risk reclassifying administrative staff as nonexempt under the FLSA, exposing them to overtime liability.
Under the Fair Labor Standards Act, the administrative exemption requires employees to exercise independent judgment and discretion on matters of significance. As employers deploy AI to automate analytical decision-making, scheduling, and problem-solving tasks traditionally performed by exempt administrative staff, those workers may no longer meet the duties test. Reclassification would trigger overtime pay obligations, potential back-wage claims, and class action exposure. In-house counsel should audit job descriptions and actual workflows for AI-augmented roles, document the discretionary elements that remain human-driven, and reassess exemption classifications before litigation or DOL audits surface the gap.
Brands seeking to partner with college athletes via NIL deals must adhere to evolving compliance rules and structured contract terms to avoid legal and reputational risk.
NIL compensation for college athletes became permissible following a series of antitrust challenges to NCAA amateurism rules, including the 2021 NCAA interim policy and 2025 House v. NCAA settlement, which established a new compensation framework for student-athlete endorsements. For brands, this creates both marketing opportunity and distinct compliance risk: NIL deals are subject to fair market value requirements, mandatory disclosure for deals over $600 via NIL Go, and school-specific category restrictions. Brands should structure direct contracts with athletes that tie compensation to legitimate promotional services, include clear deliverables, FTC disclosure requirements, morals and pause clauses, and separate provisions for AI-generated digital replica rights, while building lead time for required review processes.
Trademark owners and accused infringers must track this Supreme Court case, as its ruling will determine whether inherent mark strength is decided by judges or juries, directly changing summary judgment eligibility and litigation costs for infringement claims.
The Supreme Court granted certiorari in Rise and Shine Corp. v. PepsiCo to resolve a circuit split over whether a trademark’s inherent strength, a core component of likelihood-of-confusion analyses, is a question of law for judges or a question of fact for juries. The Second Circuit currently treats the inquiry as a legal question, permitting summary judgment resolutions before trial, while multiple other circuits classify it as a factual issue requiring jury consideration. The ruling will standardize federal trademark litigation practice, impact how often infringement claims proceed to trial, shape forum-selection strategies, and affect costs tied to discovery, expert testimony, and consumer perception surveys for all parties in trademark disputes.
Lenders must adjust credit underwriting protocols to align with new federal guidance on permissible immigration status considerations, reducing regulatory compliance risk.
Recent federal guidance has clarified permissible parameters for considering applicants’ immigration status during credit underwriting, resolving prior regulatory ambiguity in the space. The guidance distinguishes between allowable immigration-related factors for creditworthiness assessment and prohibited considerations that may violate fair lending rules. Lenders should immediately audit existing underwriting policies, employee training materials, and decision-making workflows to ensure alignment with the new standards, remove prohibited immigration status considerations from evaluation processes, and maintain detailed documentation of compliance steps to reduce enforcement risk if subject to regulatory review.
Pharma and biotech deal teams must reassess valuations, licensing terms, and M&A structures as Medicare/Medicaid Most Favored Nation demonstration programs advance.
Federal Most Favored Nation pricing initiatives, including contemplated Medicare and Medicaid demonstration programs, are injecting material uncertainty into life sciences transactions. International reference pricing and domestic price-control mechanisms now affect asset valuations, commercialization plans, licensing and collaboration economics, and risk allocation in M&A. Counsel advising pharma and biotech clients should pressure-test diligence frameworks for pricing exposure, reprice earn-outs and milestones tied to government reimbursement, and revisit representations, indemnities, and MAC clauses. Strategic considerations include restructuring co-development and royalty arrangements, evaluating geographic launch sequencing, and preparing for shifting regulatory and reimbursement landscapes. With policy still evolving, proactive deal structuring and scenario planning are essential to mitigate downside and preserve transaction value.
Cross-border M&A and investment teams must reassess deal risk: Treasury's new CFIUS matrix signals heightened scrutiny—and likely non-notified enforcement—against foreign acquirers in critical infrastructure, data, and sensitive-tech sectors.
On July 29, 2026, Treasury, as CFIUS chair, released a Risk Matrix cataloguing eight transaction profiles that pose elevated national security risk: critical infrastructure, cybersecurity, information security, personal data, product integrity, proximity to sensitive government sites, supply assurance, and technology transfer. For each profile, the matrix sets out the threat-vulnerability-consequence calculus under 31 C.F.R. § 800.102 and lists illustrative mitigation measures—governance restrictions, source-code reviews, third-party monitorships, segregation of protected technology, supply-continuation commitments, and CFIUS access and audit rights. The release aligns with the America First Investment Policy and a stated push to 'demystify' the process, but it also signals broader enforcement reach, including non-notified outreach. Counsel advising foreign investors, sponsors, and U.S. targets should map deal profiles against the matrix, weigh voluntary filings where risk indicators are present, and prepare for more standardized mitigation expectations rather than bespoke negotiatio
…
In-house counsel for regulated businesses, financial services firms, and brokerages must track shifting state AG enforcement priorities to avoid emerging regulatory and litigation risk.
The July 2026 State AG Monitor outlines a major shift in U.S. enforcement following the Supreme Court’s Chevron deference reversal, positioning state attorneys general as the primary enforcers of federal regulatory rules. Key outlined priorities include targeted enforcement against AI development and deployment, filling regulatory gaps in point-of-sale finance, and expanded consumer fraud liability for brokers under New Jersey’s Consumer Fraud Act. In-house counsel should review existing compliance programs to address these emerging state-level enforcement risks, monitor relevant AG office guidance, and assess potential liability for operations involving broker services or POS finance products.
DOJ is on pace for a record-breaking False Claims Act year, with $1.8B in H1 2026 recoveries, 780+ qui tam filings already, and a brand-new anti-discrimination enforcement theory that exposes federal contractors and grantees to treble-damages liability.
The first half of 2026 confirmed the FCA's role as the federal government's primary civil fraud weapon. DOJ announced more than $1.8 billion in settlements and judgments, including two nine-figure Medicare Advantage resolutions ($556M and $117.7M) and a record-setting $500M+ customs-duty settlement—the largest ever. Qui tam filings already exceed 780 in FY 2026, putting DOJ on track to surpass FY 2025's $6.8B total. DOJ also formalized its relator data-mining initiative and directed fast-tracking of fraud allegations involving federally funded, state-administered benefits programs. For the first time, DOJ settled an FCA case under the Civil Rights Fraud Initiative, signaling that contractors, grantees, and recipients of federal funds face expanded exposure for alleged discrimination. Structurally, FCA enforcement may move from the Civil Division into the new National Fraud Enforcement Division. States are also expanding their FCA statutes—Minnesota's proposal would expressly impose liability on private equity investors in FCA-violating entities. In-house counsel should reassess compl
…
Grade 3 — worth a glance, not the full analysis.
- Habeas Win Forces ICE Release After Unlawful Local Arrest
Immigration practitioners should note a federal habeas ruling that ICE must release a detainee when the underlying local arrest violated the Fourth Amendment, even where ICE could rearrest on a valid removal order.
- German Court Reconsiders Email Validity for U.S.-Sent Terminations
Multinational employers relying on emailed termination notices from U.S. offices to German staff must reassess their cross-border HR workflows after a recent court ruling.
- DOL Clarifies Midday Commutes Are Non-Working Time
Nonexempt-employee managers can now permit split-day remote work without triggering extra pay, after DOL confirmed midday home-to-office trips remain non-compensable commutes.
- 10 Key Drafting Issues for Executive Employment Agreements
In-house counsel and corporate HR teams drafting or updating executive employment contracts must address interconnected compensation, restrictive covenant, and change-in-control provisions to avoid costly tax liabilities, severance disputes, and compliance gaps.
- Procore to Acquire DroneDeploy for ~$845M, Secures $700M Bridge Financing
Construction tech in-house counsel and M&A advisors must track this $845M Procore-DroneDeploy acquisition as a signal of accelerating consolidation in the construction management software and jobsite robotics sectors.