Cicero Intelligent Minds

DROPLETS

AmLaw 100 Legal Intelligence — Distilled
Saturday, August 1, 202610 featured4 also noted7 firms8 practice areasgrade 3–5
Quick Scan — Why It Matters
Mayer BrownImmigration+ Expand
ICE-TSA Data Sharing Drives Airport Detentions of Domestic Travelers

Employers with traveling workforces face new exposure as ICE uses TSA data to question and detain passengers on domestic flights, including green-card holders and visa holders.

ICE has materially expanded its airport enforcement footprint by leveraging real-time data-sharing arrangements with TSA, enabling agents to identify, question, and detain travelers passing through security checkpoints. The shift affects not only undocumented individuals but also lawful permanent residents, nonimmigrant visa holders (H-1B, L-1, O-1, TN), and employees with pending applications, particularly those with prior orders of removal, criminal history, or expired status. Detentions can occur on outbound, connecting, or return flights, disrupting business travel and creating immediate workforce continuity risks. Recommended employer actions include auditing employee travel rosters for immigration-vulnerable staff, issuing domestic-travel guidance, preparing emergency-response protocols for detained employees, training managers on what to do if an employee is taken into custody, and reviewing I-9 and visa-status files for compliance gaps. Counsel should also assess whether any recent policy shifts affect remote-worker relocations or cross-border assignments.

Read the full dispatch →
BakerHostetlerEmployment / Labor+ Expand
D.C. Circuit Strikes Down NLRB 'Successor Bar' Doctrine After Loper Bright

Acquiring employers and M&A counsel can now present evidence that an incumbent union lacks majority support, ending the NLRB's automatic one-year recognition bar.

The D.C. Circuit, on remand from the Supreme Court in light of Loper Bright, ruled 2-1 in Hospital Menonita de Guayama, Inc. v. NLRB that the Board's 'successor bar' doctrine is inconsistent with the National Labor Relations Act. The doctrine had required successor employers to recognize and bargain with an incumbent union for up to one year, irrebuttably presuming continued majority status. The majority (Rao and Walker) held that the bar impermissibly suspends Section 7 employee-freedom guarantees and majority-rule principles, and that the Board lacks statutory authority to impose it. The decision signals broader judicial willingness to scrutinize NLRB presumptions and doctrines not grounded in the Act's text. Acquiring employers should reassess diligence on union representation, document employee sentiment, and evaluate options to withdraw recognition where objective evidence shows loss of majority support. The ruling also foreshadows challenges to other Board-created bars and presumptions across labor law.

Read the full dispatch →
Gibson DunnCorporate / M&A+ Expand
Delaware Chancery: PBC Directors Shielded by Statutory Safe Harbor; Revlon Does Not Apply

Delaware PBC boards and their counsel now have first judicial guidance confirming that Revlon's exclusive stockholder-value mandate does not govern change-of-control transactions and that DGCL Section 365(b) safe harbor can dismiss fiduciary-duty claims at the pleading stage.

In Drakes Landing Associates v. Tilden Park Capital Management, Vice Chancellor Cook held that DGCL Section 365(a)'s balancing mandate displaces Revlon's single-minded value-maximization standard of conduct for PBC directors, while leaving open whether a modified 'PBC enhanced scrutiny' standard of review applies. The court dismissed all claims under Section 365(b)'s safe harbor, finding plaintiffs failed to plead facts showing the special committee's rescue-financing decision was uninformed, interested, or beyond ordinary sound judgment. The opinion also extends Section 365(b) to defeat aiding-and-abetting claims, since the safe harbor deems fiduciary duties satisfied rather than merely barring relief. PBC boards should expect heightened pleading burdens on the informed prong—covering all three Section 365(a) interests, not just pecuniary ones—and should document balancing analyses and committee processes accordingly. The decision materially reduces litigation risk for PBC boards in M&A and rescue financings, but the unresolved 'PBC enhanced scrutiny' question warrants continued mon

Read the full dispatch →
BakerHostetlerInternational Trade / Tariffs+ Expand
CBP 2026 Forced Labor Guidance Tightens Supply Chain Traceability Demands

Retail importers face heightened UFLPA enforcement as CBP's 2026 operational guidance expands documentation expectations across every tier of the supply chain.

U.S. Customs and Border Protection's new Forced Labor Enforcement Operational Guidance for Importers formalizes how the agency will apply the Uyghur Forced Labor Prevention Act, withhold release orders, and CAATSA to inbound shipments. Importers must now demonstrate granular traceability—mapping each material, supplier, and shipment node—particularly for goods appearing on the Bureau of International Labor Affairs' List of Goods Produced by Child Labor or Forced Labor. The guidance signals broader use of entity-based and commodity-based enforcement, not just port-level detention. In-house counsel at retailers and consumer brands should audit supplier disclosures, refresh due-diligence questionnaires, and prepare rebuttal packages before shipments are detained. Proactive mapping of high-risk inputs (cotton, polysilicon, tomatoes, seafood) is now a baseline compliance expectation rather than a best practice.

Read the full dispatch →
Troutman Pepper LockeHealthcare+ Expand
HHS HIPAA Security Rule Update Faces Continued Rulemaking Delays

Healthcare privacy and security teams should expect the long-pending HIPAA Security Rule NPRM to slip further, reshaping breach-prevention priorities and compliance timelines.

The article tracks the multi-year delay in HHS's HIPAA Security Rule update, originally proposed in 2024 and now stalled in OMB review. It attributes the slowdown to shifting administration priorities, interagency coordination on cybersecurity harmonization, and resource constraints at OCR. For covered entities and business associates, the practical effect is continued reliance on the 2013 Security Rule while preparing for likely mandates on multi-factor authentication, encryption of data at rest, annual technical risk analyses, and tighter breach notification timelines. The piece also flags that any final rule could impose 12-month compliance windows, leaving little runway. In-house counsel should reassess security program gaps, vendor contracts, and incident response playbooks now rather than wait for publication.

Read the full dispatch →
LittlerEmployment / Labor+ Expand
UK Consults on Workplace Monitoring Tech Rules; Responses Due Sept. 30

UK employers using keystroke, GPS, biometric or AI-driven monitoring tools face three potential regulatory paths — including a new duty to consult unions before deployment — and should weigh in before the September 30, 2026 deadline.

On July 8, 2026, the UK Government opened a consultation on workplace monitoring technologies (WMT), defined broadly to include GPS tracking, keystroke logging, biometrics, video surveillance, and automated performance scoring. Three intervention options are on the table: (1) a statutory Code of Practice that Employment Tribunals could consider, raising compensation up to 25% for non-compliance; (2) a primary-legislation duty to consult and negotiate with trade unions or elected staff representatives before introducing or materially changing WMT, enforceable via protective awards; or (3) non-statutory guidance alone. Eight guiding principles — covering transparency, proportionality, human oversight, fairness and dignity — would underpin any chosen path. Existing UK data protection, equality and employment law already apply, but the Government views enforcement as inconsistent. The consultation closes September 30, 2026, and sits alongside the Employment Rights Act 2025 reforms expanding worker voice. Multinational employers should map current WMT deployments against the proposed prin

Read the full dispatch →
Jones DayIP / Patent+ Expand
PTAB Director Squires Issues Precedential Denial Curbing Duplicative IPR Challenges

Patent owners facing serial IPR petitions should expect PTAB to reject follow-on challenges that recycle prior arguments.

In a precedential decision in Magnolia Medical Technologies, Inc. v. Kurin, Inc. (IPR2026-00097), PTAB Director Squires denied institution of inter partes review, reinforcing that the AIA review framework exists as a litigation alternative rather than a forum for duplicative patent challenges. The ruling signals heightened scrutiny of petitioners seeking a 'second bite at the apple' through repeat filings, particularly where prior proceedings or arguments already addressed the same issues. For patent owners, this strengthens defenses against serial IPR attacks and supports motions to deny institution. For petitioners and accused infringers, it raises the bar for crafting original, non-redundant grounds and may push more disputes back toward district court litigation. Counsel should reassess pending and contemplated IPR strategies in light of this precedential guidance.

Read the full dispatch →
Arnold & PorterHealthcare+ Expand
DOJ Charges 455 in $6.5B Health Fraud Sweep; FTC Targets AI Accuracy

Digital health, telehealth, and AI-in-medicine leaders face fresh enforcement and regulatory signals from DOJ's June takedown, the FTC's AI accuracy proposal, and CMS's new AI office.

The DOJ's 2026 National Health Care Fraud Takedown charged 455 defendants tied to over $6.5 billion in alleged false claims, with telemedicine, DME, and genetic-testing schemes prominently featured. A nurse practitioner was sentenced to 10 years for a $136 million Medicare fraud, and CMS suspended or revoked billing privileges for more than 2,400 providers. Separately, the FTC released a proposed policy statement warning that AI developers may train models to suppress accuracy, with comments due July 31, 2026. CMS launched a new Office of Health Technology and Products to coordinate AI strategy, while the House Appropriations Committee advanced an FY27 spending bill prohibiting CMS funding for the WISeR AI prior-authorization model. The FDA issued a warning letter on unauthorized software changes to a patient monitoring device and announced a public meeting on medical device user-fee reauthorization focused on digital health oversight. In-house counsel should review telehealth compliance programs, AI governance disclosures, and prior-authorization exposure.

Read the full dispatch →
Mayer BrownCybersecurity+ Expand
AI Cuts Code Vulnerability Review Time From 8 Years To 8 Weeks

In-house counsel leading cybersecurity, technology product, and enterprise risk functions for organizations with large codebases must update vulnerability management and patch cycle policies to account for AI-driven acceleration of code review timelines.

This episode features Cisco Senior Director of Technology Policy Eric Wenger sharing results from Project Glasswing and Project Daybreak, where frontier AI models reviewed 1.8 billion lines of code in 8 weeks, a task previously estimated to require 8 years, with a false positive rate of roughly 3%. Wenger outlines ongoing policy tensions around providing cybersecurity defenders early access to advanced AI models versus accelerating commercial model releases, and notes emerging government initiatives including an AI vulnerability clearinghouse. He emphasizes that while AI drastically speeds vulnerability detection, organizations must retain focus on foundational security controls including multi-factor authentication and least-privilege access, and adjust internal patch cadence policies to align with faster AI-powered detection timelines.

Read the full dispatch →
Mayer BrownSanctions / Export Controls+ Expand
UK Sanctions Update: New Designations and Rule Changes for July 13–20 2026

In-house counsel for entities operating in the UK, with UK-linked supply chains, or transacting with newly designated parties must review the latest updates to avoid non-compliance enforcement penalties.

The July 13 and 20 2026 UK weekly sanctions update publishes new asset freeze and travel ban designations targeting individuals and entities tied to Russian defense procurement, Iranian ballistic missile development, and third-party networks facilitating sanctions evasion. The update also revises guidance on humanitarian licensing exemptions for agricultural and medical trade with sanctioned jurisdictions, and updates due diligence requirements for UK financial institutions handling transactions for high-risk non-designated counterparties. In-house counsel should update internal blocked party lists to reflect new designations, review existing sanctions compliance policies against the revised rules, and train relevant commercial, finance, and logistics teams to mitigate enforcement risk.

Read the full dispatch →
DIG DEEPER
MOST CONSEQUENTIALCBP 2026 Forced Labor Guidance Tightens Supply Chain Traceability Demands

Retail importers face heightened UFLPA enforcement as CBP's 2026 operational guidance expands documentation expectations across every tier of the supply chain.

U.S. Customs and Border Protection's new Forced Labor Enforcement Operational Guidance for Importers formalizes how the agency will apply the Uyghur Forced Labor Prevention Act, withhold release orders, and CAATSA to inbound shipments. Importers must now demonstrate granular traceability—mapping each material, supplier, and shipment node—particularly for goods appearing on the Bureau of International Labor Affairs' List of Goods Produced by Child Labor or Forced Labor. The guidance signals broader use of entity-based and commodity-based enforcement, not just port-level detention. In-house counsel at retailers and consumer brands should audit supplier disclosures, refresh due-diligence questionnaires, and prepare rebuttal packages before shipments are detained. Proactive mapping of high-risk inputs (cotton, polysilicon, tomatoes, seafood) is now a baseline compliance expectation rather than a best practice.

BakerHostetlerInternational Trade / Tariffs
forced-laboruflpasupply-chaincbp-enforcementimport-compliance
AR
Today's Curator
Arthur Rodrigues. Corporate Counsel & Corporate Secretary at Teachable, Inc. Founder of Cicero Intelligent Minds. Former BigLaw (O'Melveny, Weil, Hughes Hubbard). JD/LLM Michigan Law.
Full Analysis — The Details
01 — CORPORATE / M&A1
Gibson Dunn+ Expand
Delaware Chancery: PBC Directors Shielded by Statutory Safe Harbor; Revlon Does Not Apply

Delaware PBC boards and their counsel now have first judicial guidance confirming that Revlon's exclusive stockholder-value mandate does not govern change-of-control transactions and that DGCL Section 365(b) safe harbor can dismiss fiduciary-duty claims at the pleading stage.

In Drakes Landing Associates v. Tilden Park Capital Management, Vice Chancellor Cook held that DGCL Section 365(a)'s balancing mandate displaces Revlon's single-minded value-maximization standard of conduct for PBC directors, while leaving open whether a modified 'PBC enhanced scrutiny' standard of review applies. The court dismissed all claims under Section 365(b)'s safe harbor, finding plaintiffs failed to plead facts showing the special committee's rescue-financing decision was uninformed, interested, or beyond ordinary sound judgment. The opinion also extends Section 365(b) to defeat aiding-and-abetting claims, since the safe harbor deems fiduciary duties satisfied rather than merely barring relief. PBC boards should expect heightened pleading burdens on the informed prong—covering all three Section 365(a) interests, not just pecuniary ones—and should document balancing analyses and committee processes accordingly. The decision materially reduces litigation risk for PBC boards in M&A and rescue financings, but the unresolved 'PBC enhanced scrutiny' question warrants continued mon

public-benefit-corporationdelaware-chanceryrevlon-dutysection-365-safe-harborchange-of-control
Read the full dispatch →
02 — CYBERSECURITY1
Mayer Brown+ Expand
AI Cuts Code Vulnerability Review Time From 8 Years To 8 Weeks

In-house counsel leading cybersecurity, technology product, and enterprise risk functions for organizations with large codebases must update vulnerability management and patch cycle policies to account for AI-driven acceleration of code review timelines.

This episode features Cisco Senior Director of Technology Policy Eric Wenger sharing results from Project Glasswing and Project Daybreak, where frontier AI models reviewed 1.8 billion lines of code in 8 weeks, a task previously estimated to require 8 years, with a false positive rate of roughly 3%. Wenger outlines ongoing policy tensions around providing cybersecurity defenders early access to advanced AI models versus accelerating commercial model releases, and notes emerging government initiatives including an AI vulnerability clearinghouse. He emphasizes that while AI drastically speeds vulnerability detection, organizations must retain focus on foundational security controls including multi-factor authentication and least-privilege access, and adjust internal patch cadence policies to align with faster AI-powered detection timelines.

ai-vulnerability-managementcybersecurity-operationspatch-cadenceai-security-policy
Read the full dispatch →
03 — EMPLOYMENT / LABOR2
BakerHostetler+ Expand
D.C. Circuit Strikes Down NLRB 'Successor Bar' Doctrine After Loper Bright

Acquiring employers and M&A counsel can now present evidence that an incumbent union lacks majority support, ending the NLRB's automatic one-year recognition bar.

The D.C. Circuit, on remand from the Supreme Court in light of Loper Bright, ruled 2-1 in Hospital Menonita de Guayama, Inc. v. NLRB that the Board's 'successor bar' doctrine is inconsistent with the National Labor Relations Act. The doctrine had required successor employers to recognize and bargain with an incumbent union for up to one year, irrebuttably presuming continued majority status. The majority (Rao and Walker) held that the bar impermissibly suspends Section 7 employee-freedom guarantees and majority-rule principles, and that the Board lacks statutory authority to impose it. The decision signals broader judicial willingness to scrutinize NLRB presumptions and doctrines not grounded in the Act's text. Acquiring employers should reassess diligence on union representation, document employee sentiment, and evaluate options to withdraw recognition where objective evidence shows loss of majority support. The ruling also foreshadows challenges to other Board-created bars and presumptions across labor law.

nlrasuccessor-barloper-brightunion-recognitionmergers-acquisitions
Read the full dispatch →
Littler+ Expand
UK Consults on Workplace Monitoring Tech Rules; Responses Due Sept. 30

UK employers using keystroke, GPS, biometric or AI-driven monitoring tools face three potential regulatory paths — including a new duty to consult unions before deployment — and should weigh in before the September 30, 2026 deadline.

On July 8, 2026, the UK Government opened a consultation on workplace monitoring technologies (WMT), defined broadly to include GPS tracking, keystroke logging, biometrics, video surveillance, and automated performance scoring. Three intervention options are on the table: (1) a statutory Code of Practice that Employment Tribunals could consider, raising compensation up to 25% for non-compliance; (2) a primary-legislation duty to consult and negotiate with trade unions or elected staff representatives before introducing or materially changing WMT, enforceable via protective awards; or (3) non-statutory guidance alone. Eight guiding principles — covering transparency, proportionality, human oversight, fairness and dignity — would underpin any chosen path. Existing UK data protection, equality and employment law already apply, but the Government views enforcement as inconsistent. The consultation closes September 30, 2026, and sits alongside the Employment Rights Act 2025 reforms expanding worker voice. Multinational employers should map current WMT deployments against the proposed prin

workplace-monitoringuk-employment-lawai-regulationworker-consultationdata-protection
Read the full dispatch →
04 — HEALTHCARE2
Troutman Pepper Locke+ Expand
HHS HIPAA Security Rule Update Faces Continued Rulemaking Delays

Healthcare privacy and security teams should expect the long-pending HIPAA Security Rule NPRM to slip further, reshaping breach-prevention priorities and compliance timelines.

The article tracks the multi-year delay in HHS's HIPAA Security Rule update, originally proposed in 2024 and now stalled in OMB review. It attributes the slowdown to shifting administration priorities, interagency coordination on cybersecurity harmonization, and resource constraints at OCR. For covered entities and business associates, the practical effect is continued reliance on the 2013 Security Rule while preparing for likely mandates on multi-factor authentication, encryption of data at rest, annual technical risk analyses, and tighter breach notification timelines. The piece also flags that any final rule could impose 12-month compliance windows, leaving little runway. In-house counsel should reassess security program gaps, vendor contracts, and incident response playbooks now rather than wait for publication.

hipaa-security-rulehealthcare-compliancecybersecuritybreach-notificationregulatory-delay
Read the full dispatch →
Arnold & Porter+ Expand
DOJ Charges 455 in $6.5B Health Fraud Sweep; FTC Targets AI Accuracy

Digital health, telehealth, and AI-in-medicine leaders face fresh enforcement and regulatory signals from DOJ's June takedown, the FTC's AI accuracy proposal, and CMS's new AI office.

The DOJ's 2026 National Health Care Fraud Takedown charged 455 defendants tied to over $6.5 billion in alleged false claims, with telemedicine, DME, and genetic-testing schemes prominently featured. A nurse practitioner was sentenced to 10 years for a $136 million Medicare fraud, and CMS suspended or revoked billing privileges for more than 2,400 providers. Separately, the FTC released a proposed policy statement warning that AI developers may train models to suppress accuracy, with comments due July 31, 2026. CMS launched a new Office of Health Technology and Products to coordinate AI strategy, while the House Appropriations Committee advanced an FY27 spending bill prohibiting CMS funding for the WISeR AI prior-authorization model. The FDA issued a warning letter on unauthorized software changes to a patient monitoring device and announced a public meeting on medical device user-fee reauthorization focused on digital health oversight. In-house counsel should review telehealth compliance programs, AI governance disclosures, and prior-authorization exposure.

digital-healthtelehealth-fraudai-accuracycms-policyfda-software
Read the full dispatch →
05 — IP / PATENT1
Jones Day+ Expand
PTAB Director Squires Issues Precedential Denial Curbing Duplicative IPR Challenges

Patent owners facing serial IPR petitions should expect PTAB to reject follow-on challenges that recycle prior arguments.

In a precedential decision in Magnolia Medical Technologies, Inc. v. Kurin, Inc. (IPR2026-00097), PTAB Director Squires denied institution of inter partes review, reinforcing that the AIA review framework exists as a litigation alternative rather than a forum for duplicative patent challenges. The ruling signals heightened scrutiny of petitioners seeking a 'second bite at the apple' through repeat filings, particularly where prior proceedings or arguments already addressed the same issues. For patent owners, this strengthens defenses against serial IPR attacks and supports motions to deny institution. For petitioners and accused infringers, it raises the bar for crafting original, non-redundant grounds and may push more disputes back toward district court litigation. Counsel should reassess pending and contemplated IPR strategies in light of this precedential guidance.

ptab-discretionary-denialsipr-institutionprecedential-decisionpatent-litigation-strategyaia-review
Read the full dispatch →
06 — IMMIGRATION1
Mayer Brown+ Expand
ICE-TSA Data Sharing Drives Airport Detentions of Domestic Travelers

Employers with traveling workforces face new exposure as ICE uses TSA data to question and detain passengers on domestic flights, including green-card holders and visa holders.

ICE has materially expanded its airport enforcement footprint by leveraging real-time data-sharing arrangements with TSA, enabling agents to identify, question, and detain travelers passing through security checkpoints. The shift affects not only undocumented individuals but also lawful permanent residents, nonimmigrant visa holders (H-1B, L-1, O-1, TN), and employees with pending applications, particularly those with prior orders of removal, criminal history, or expired status. Detentions can occur on outbound, connecting, or return flights, disrupting business travel and creating immediate workforce continuity risks. Recommended employer actions include auditing employee travel rosters for immigration-vulnerable staff, issuing domestic-travel guidance, preparing emergency-response protocols for detained employees, training managers on what to do if an employee is taken into custody, and reviewing I-9 and visa-status files for compliance gaps. Counsel should also assess whether any recent policy shifts affect remote-worker relocations or cross-border assignments.

ice-tsa-data-sharingairport-enforcementworkforce-travel-riskimmigration-complianceemployer-response
Read the full dispatch →
07 — INTERNATIONAL TRADE / TARIFFS1
BakerHostetler+ Expand
CBP 2026 Forced Labor Guidance Tightens Supply Chain Traceability Demands

Retail importers face heightened UFLPA enforcement as CBP's 2026 operational guidance expands documentation expectations across every tier of the supply chain.

U.S. Customs and Border Protection's new Forced Labor Enforcement Operational Guidance for Importers formalizes how the agency will apply the Uyghur Forced Labor Prevention Act, withhold release orders, and CAATSA to inbound shipments. Importers must now demonstrate granular traceability—mapping each material, supplier, and shipment node—particularly for goods appearing on the Bureau of International Labor Affairs' List of Goods Produced by Child Labor or Forced Labor. The guidance signals broader use of entity-based and commodity-based enforcement, not just port-level detention. In-house counsel at retailers and consumer brands should audit supplier disclosures, refresh due-diligence questionnaires, and prepare rebuttal packages before shipments are detained. Proactive mapping of high-risk inputs (cotton, polysilicon, tomatoes, seafood) is now a baseline compliance expectation rather than a best practice.

forced-laboruflpasupply-chaincbp-enforcementimport-compliance
Read the full dispatch →
08 — SANCTIONS / EXPORT CONTROLS1
Mayer Brown+ Expand
UK Sanctions Update: New Designations and Rule Changes for July 13–20 2026

In-house counsel for entities operating in the UK, with UK-linked supply chains, or transacting with newly designated parties must review the latest updates to avoid non-compliance enforcement penalties.

The July 13 and 20 2026 UK weekly sanctions update publishes new asset freeze and travel ban designations targeting individuals and entities tied to Russian defense procurement, Iranian ballistic missile development, and third-party networks facilitating sanctions evasion. The update also revises guidance on humanitarian licensing exemptions for agricultural and medical trade with sanctioned jurisdictions, and updates due diligence requirements for UK financial institutions handling transactions for high-risk non-designated counterparties. In-house counsel should update internal blocked party lists to reflect new designations, review existing sanctions compliance policies against the revised rules, and train relevant commercial, finance, and logistics teams to mitigate enforcement risk.

uk-sanctionssanctions-designationsexport-controlscomplianceenforcement-risk
Read the full dispatch →
Also noted

Grade 3 — worth a glance, not the full analysis.

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.