DROPLETS
Employers with traveling workforces face new exposure as ICE uses TSA data to question and detain passengers on domestic flights, including green-card holders and visa holders.
ICE has materially expanded its airport enforcement footprint by leveraging real-time data-sharing arrangements with TSA, enabling agents to identify, question, and detain travelers passing through security checkpoints. The shift affects not only undocumented individuals but also lawful permanent residents, nonimmigrant visa holders (H-1B, L-1, O-1, TN), and employees with pending applications, particularly those with prior orders of removal, criminal history, or expired status. Detentions can occur on outbound, connecting, or return flights, disrupting business travel and creating immediate workforce continuity risks. Recommended employer actions include auditing employee travel rosters for immigration-vulnerable staff, issuing domestic-travel guidance, preparing emergency-response protocols for detained employees, training managers on what to do if an employee is taken into custody, and reviewing I-9 and visa-status files for compliance gaps. Counsel should also assess whether any recent policy shifts affect remote-worker relocations or cross-border assignments.
Acquiring employers and M&A counsel can now present evidence that an incumbent union lacks majority support, ending the NLRB's automatic one-year recognition bar.
The D.C. Circuit, on remand from the Supreme Court in light of Loper Bright, ruled 2-1 in Hospital Menonita de Guayama, Inc. v. NLRB that the Board's 'successor bar' doctrine is inconsistent with the National Labor Relations Act. The doctrine had required successor employers to recognize and bargain with an incumbent union for up to one year, irrebuttably presuming continued majority status. The majority (Rao and Walker) held that the bar impermissibly suspends Section 7 employee-freedom guarantees and majority-rule principles, and that the Board lacks statutory authority to impose it. The decision signals broader judicial willingness to scrutinize NLRB presumptions and doctrines not grounded in the Act's text. Acquiring employers should reassess diligence on union representation, document employee sentiment, and evaluate options to withdraw recognition where objective evidence shows loss of majority support. The ruling also foreshadows challenges to other Board-created bars and presumptions across labor law.
Delaware PBC boards and their counsel now have first judicial guidance confirming that Revlon's exclusive stockholder-value mandate does not govern change-of-control transactions and that DGCL Section 365(b) safe harbor can dismiss fiduciary-duty claims at the pleading stage.
In Drakes Landing Associates v. Tilden Park Capital Management, Vice Chancellor Cook held that DGCL Section 365(a)'s balancing mandate displaces Revlon's single-minded value-maximization standard of conduct for PBC directors, while leaving open whether a modified 'PBC enhanced scrutiny' standard of review applies. The court dismissed all claims under Section 365(b)'s safe harbor, finding plaintiffs failed to plead facts showing the special committee's rescue-financing decision was uninformed, interested, or beyond ordinary sound judgment. The opinion also extends Section 365(b) to defeat aiding-and-abetting claims, since the safe harbor deems fiduciary duties satisfied rather than merely barring relief. PBC boards should expect heightened pleading burdens on the informed prong—covering all three Section 365(a) interests, not just pecuniary ones—and should document balancing analyses and committee processes accordingly. The decision materially reduces litigation risk for PBC boards in M&A and rescue financings, but the unresolved 'PBC enhanced scrutiny' question warrants continued mon
…
Retail importers face heightened UFLPA enforcement as CBP's 2026 operational guidance expands documentation expectations across every tier of the supply chain.
U.S. Customs and Border Protection's new Forced Labor Enforcement Operational Guidance for Importers formalizes how the agency will apply the Uyghur Forced Labor Prevention Act, withhold release orders, and CAATSA to inbound shipments. Importers must now demonstrate granular traceability—mapping each material, supplier, and shipment node—particularly for goods appearing on the Bureau of International Labor Affairs' List of Goods Produced by Child Labor or Forced Labor. The guidance signals broader use of entity-based and commodity-based enforcement, not just port-level detention. In-house counsel at retailers and consumer brands should audit supplier disclosures, refresh due-diligence questionnaires, and prepare rebuttal packages before shipments are detained. Proactive mapping of high-risk inputs (cotton, polysilicon, tomatoes, seafood) is now a baseline compliance expectation rather than a best practice.
Healthcare privacy and security teams should expect the long-pending HIPAA Security Rule NPRM to slip further, reshaping breach-prevention priorities and compliance timelines.
The article tracks the multi-year delay in HHS's HIPAA Security Rule update, originally proposed in 2024 and now stalled in OMB review. It attributes the slowdown to shifting administration priorities, interagency coordination on cybersecurity harmonization, and resource constraints at OCR. For covered entities and business associates, the practical effect is continued reliance on the 2013 Security Rule while preparing for likely mandates on multi-factor authentication, encryption of data at rest, annual technical risk analyses, and tighter breach notification timelines. The piece also flags that any final rule could impose 12-month compliance windows, leaving little runway. In-house counsel should reassess security program gaps, vendor contracts, and incident response playbooks now rather than wait for publication.
UK employers using keystroke, GPS, biometric or AI-driven monitoring tools face three potential regulatory paths — including a new duty to consult unions before deployment — and should weigh in before the September 30, 2026 deadline.
On July 8, 2026, the UK Government opened a consultation on workplace monitoring technologies (WMT), defined broadly to include GPS tracking, keystroke logging, biometrics, video surveillance, and automated performance scoring. Three intervention options are on the table: (1) a statutory Code of Practice that Employment Tribunals could consider, raising compensation up to 25% for non-compliance; (2) a primary-legislation duty to consult and negotiate with trade unions or elected staff representatives before introducing or materially changing WMT, enforceable via protective awards; or (3) non-statutory guidance alone. Eight guiding principles — covering transparency, proportionality, human oversight, fairness and dignity — would underpin any chosen path. Existing UK data protection, equality and employment law already apply, but the Government views enforcement as inconsistent. The consultation closes September 30, 2026, and sits alongside the Employment Rights Act 2025 reforms expanding worker voice. Multinational employers should map current WMT deployments against the proposed prin
…
Patent owners facing serial IPR petitions should expect PTAB to reject follow-on challenges that recycle prior arguments.
In a precedential decision in Magnolia Medical Technologies, Inc. v. Kurin, Inc. (IPR2026-00097), PTAB Director Squires denied institution of inter partes review, reinforcing that the AIA review framework exists as a litigation alternative rather than a forum for duplicative patent challenges. The ruling signals heightened scrutiny of petitioners seeking a 'second bite at the apple' through repeat filings, particularly where prior proceedings or arguments already addressed the same issues. For patent owners, this strengthens defenses against serial IPR attacks and supports motions to deny institution. For petitioners and accused infringers, it raises the bar for crafting original, non-redundant grounds and may push more disputes back toward district court litigation. Counsel should reassess pending and contemplated IPR strategies in light of this precedential guidance.
Digital health, telehealth, and AI-in-medicine leaders face fresh enforcement and regulatory signals from DOJ's June takedown, the FTC's AI accuracy proposal, and CMS's new AI office.
The DOJ's 2026 National Health Care Fraud Takedown charged 455 defendants tied to over $6.5 billion in alleged false claims, with telemedicine, DME, and genetic-testing schemes prominently featured. A nurse practitioner was sentenced to 10 years for a $136 million Medicare fraud, and CMS suspended or revoked billing privileges for more than 2,400 providers. Separately, the FTC released a proposed policy statement warning that AI developers may train models to suppress accuracy, with comments due July 31, 2026. CMS launched a new Office of Health Technology and Products to coordinate AI strategy, while the House Appropriations Committee advanced an FY27 spending bill prohibiting CMS funding for the WISeR AI prior-authorization model. The FDA issued a warning letter on unauthorized software changes to a patient monitoring device and announced a public meeting on medical device user-fee reauthorization focused on digital health oversight. In-house counsel should review telehealth compliance programs, AI governance disclosures, and prior-authorization exposure.
In-house counsel leading cybersecurity, technology product, and enterprise risk functions for organizations with large codebases must update vulnerability management and patch cycle policies to account for AI-driven acceleration of code review timelines.
This episode features Cisco Senior Director of Technology Policy Eric Wenger sharing results from Project Glasswing and Project Daybreak, where frontier AI models reviewed 1.8 billion lines of code in 8 weeks, a task previously estimated to require 8 years, with a false positive rate of roughly 3%. Wenger outlines ongoing policy tensions around providing cybersecurity defenders early access to advanced AI models versus accelerating commercial model releases, and notes emerging government initiatives including an AI vulnerability clearinghouse. He emphasizes that while AI drastically speeds vulnerability detection, organizations must retain focus on foundational security controls including multi-factor authentication and least-privilege access, and adjust internal patch cadence policies to align with faster AI-powered detection timelines.
In-house counsel for entities operating in the UK, with UK-linked supply chains, or transacting with newly designated parties must review the latest updates to avoid non-compliance enforcement penalties.
The July 13 and 20 2026 UK weekly sanctions update publishes new asset freeze and travel ban designations targeting individuals and entities tied to Russian defense procurement, Iranian ballistic missile development, and third-party networks facilitating sanctions evasion. The update also revises guidance on humanitarian licensing exemptions for agricultural and medical trade with sanctioned jurisdictions, and updates due diligence requirements for UK financial institutions handling transactions for high-risk non-designated counterparties. In-house counsel should update internal blocked party lists to reflect new designations, review existing sanctions compliance policies against the revised rules, and train relevant commercial, finance, and logistics teams to mitigate enforcement risk.
Retail importers face heightened UFLPA enforcement as CBP's 2026 operational guidance expands documentation expectations across every tier of the supply chain.
U.S. Customs and Border Protection's new Forced Labor Enforcement Operational Guidance for Importers formalizes how the agency will apply the Uyghur Forced Labor Prevention Act, withhold release orders, and CAATSA to inbound shipments. Importers must now demonstrate granular traceability—mapping each material, supplier, and shipment node—particularly for goods appearing on the Bureau of International Labor Affairs' List of Goods Produced by Child Labor or Forced Labor. The guidance signals broader use of entity-based and commodity-based enforcement, not just port-level detention. In-house counsel at retailers and consumer brands should audit supplier disclosures, refresh due-diligence questionnaires, and prepare rebuttal packages before shipments are detained. Proactive mapping of high-risk inputs (cotton, polysilicon, tomatoes, seafood) is now a baseline compliance expectation rather than a best practice.
Delaware PBC boards and their counsel now have first judicial guidance confirming that Revlon's exclusive stockholder-value mandate does not govern change-of-control transactions and that DGCL Section 365(b) safe harbor can dismiss fiduciary-duty claims at the pleading stage.
In Drakes Landing Associates v. Tilden Park Capital Management, Vice Chancellor Cook held that DGCL Section 365(a)'s balancing mandate displaces Revlon's single-minded value-maximization standard of conduct for PBC directors, while leaving open whether a modified 'PBC enhanced scrutiny' standard of review applies. The court dismissed all claims under Section 365(b)'s safe harbor, finding plaintiffs failed to plead facts showing the special committee's rescue-financing decision was uninformed, interested, or beyond ordinary sound judgment. The opinion also extends Section 365(b) to defeat aiding-and-abetting claims, since the safe harbor deems fiduciary duties satisfied rather than merely barring relief. PBC boards should expect heightened pleading burdens on the informed prong—covering all three Section 365(a) interests, not just pecuniary ones—and should document balancing analyses and committee processes accordingly. The decision materially reduces litigation risk for PBC boards in M&A and rescue financings, but the unresolved 'PBC enhanced scrutiny' question warrants continued mon
…
In-house counsel leading cybersecurity, technology product, and enterprise risk functions for organizations with large codebases must update vulnerability management and patch cycle policies to account for AI-driven acceleration of code review timelines.
This episode features Cisco Senior Director of Technology Policy Eric Wenger sharing results from Project Glasswing and Project Daybreak, where frontier AI models reviewed 1.8 billion lines of code in 8 weeks, a task previously estimated to require 8 years, with a false positive rate of roughly 3%. Wenger outlines ongoing policy tensions around providing cybersecurity defenders early access to advanced AI models versus accelerating commercial model releases, and notes emerging government initiatives including an AI vulnerability clearinghouse. He emphasizes that while AI drastically speeds vulnerability detection, organizations must retain focus on foundational security controls including multi-factor authentication and least-privilege access, and adjust internal patch cadence policies to align with faster AI-powered detection timelines.
Acquiring employers and M&A counsel can now present evidence that an incumbent union lacks majority support, ending the NLRB's automatic one-year recognition bar.
The D.C. Circuit, on remand from the Supreme Court in light of Loper Bright, ruled 2-1 in Hospital Menonita de Guayama, Inc. v. NLRB that the Board's 'successor bar' doctrine is inconsistent with the National Labor Relations Act. The doctrine had required successor employers to recognize and bargain with an incumbent union for up to one year, irrebuttably presuming continued majority status. The majority (Rao and Walker) held that the bar impermissibly suspends Section 7 employee-freedom guarantees and majority-rule principles, and that the Board lacks statutory authority to impose it. The decision signals broader judicial willingness to scrutinize NLRB presumptions and doctrines not grounded in the Act's text. Acquiring employers should reassess diligence on union representation, document employee sentiment, and evaluate options to withdraw recognition where objective evidence shows loss of majority support. The ruling also foreshadows challenges to other Board-created bars and presumptions across labor law.
UK employers using keystroke, GPS, biometric or AI-driven monitoring tools face three potential regulatory paths — including a new duty to consult unions before deployment — and should weigh in before the September 30, 2026 deadline.
On July 8, 2026, the UK Government opened a consultation on workplace monitoring technologies (WMT), defined broadly to include GPS tracking, keystroke logging, biometrics, video surveillance, and automated performance scoring. Three intervention options are on the table: (1) a statutory Code of Practice that Employment Tribunals could consider, raising compensation up to 25% for non-compliance; (2) a primary-legislation duty to consult and negotiate with trade unions or elected staff representatives before introducing or materially changing WMT, enforceable via protective awards; or (3) non-statutory guidance alone. Eight guiding principles — covering transparency, proportionality, human oversight, fairness and dignity — would underpin any chosen path. Existing UK data protection, equality and employment law already apply, but the Government views enforcement as inconsistent. The consultation closes September 30, 2026, and sits alongside the Employment Rights Act 2025 reforms expanding worker voice. Multinational employers should map current WMT deployments against the proposed prin
…
Healthcare privacy and security teams should expect the long-pending HIPAA Security Rule NPRM to slip further, reshaping breach-prevention priorities and compliance timelines.
The article tracks the multi-year delay in HHS's HIPAA Security Rule update, originally proposed in 2024 and now stalled in OMB review. It attributes the slowdown to shifting administration priorities, interagency coordination on cybersecurity harmonization, and resource constraints at OCR. For covered entities and business associates, the practical effect is continued reliance on the 2013 Security Rule while preparing for likely mandates on multi-factor authentication, encryption of data at rest, annual technical risk analyses, and tighter breach notification timelines. The piece also flags that any final rule could impose 12-month compliance windows, leaving little runway. In-house counsel should reassess security program gaps, vendor contracts, and incident response playbooks now rather than wait for publication.
Digital health, telehealth, and AI-in-medicine leaders face fresh enforcement and regulatory signals from DOJ's June takedown, the FTC's AI accuracy proposal, and CMS's new AI office.
The DOJ's 2026 National Health Care Fraud Takedown charged 455 defendants tied to over $6.5 billion in alleged false claims, with telemedicine, DME, and genetic-testing schemes prominently featured. A nurse practitioner was sentenced to 10 years for a $136 million Medicare fraud, and CMS suspended or revoked billing privileges for more than 2,400 providers. Separately, the FTC released a proposed policy statement warning that AI developers may train models to suppress accuracy, with comments due July 31, 2026. CMS launched a new Office of Health Technology and Products to coordinate AI strategy, while the House Appropriations Committee advanced an FY27 spending bill prohibiting CMS funding for the WISeR AI prior-authorization model. The FDA issued a warning letter on unauthorized software changes to a patient monitoring device and announced a public meeting on medical device user-fee reauthorization focused on digital health oversight. In-house counsel should review telehealth compliance programs, AI governance disclosures, and prior-authorization exposure.
Patent owners facing serial IPR petitions should expect PTAB to reject follow-on challenges that recycle prior arguments.
In a precedential decision in Magnolia Medical Technologies, Inc. v. Kurin, Inc. (IPR2026-00097), PTAB Director Squires denied institution of inter partes review, reinforcing that the AIA review framework exists as a litigation alternative rather than a forum for duplicative patent challenges. The ruling signals heightened scrutiny of petitioners seeking a 'second bite at the apple' through repeat filings, particularly where prior proceedings or arguments already addressed the same issues. For patent owners, this strengthens defenses against serial IPR attacks and supports motions to deny institution. For petitioners and accused infringers, it raises the bar for crafting original, non-redundant grounds and may push more disputes back toward district court litigation. Counsel should reassess pending and contemplated IPR strategies in light of this precedential guidance.
Employers with traveling workforces face new exposure as ICE uses TSA data to question and detain passengers on domestic flights, including green-card holders and visa holders.
ICE has materially expanded its airport enforcement footprint by leveraging real-time data-sharing arrangements with TSA, enabling agents to identify, question, and detain travelers passing through security checkpoints. The shift affects not only undocumented individuals but also lawful permanent residents, nonimmigrant visa holders (H-1B, L-1, O-1, TN), and employees with pending applications, particularly those with prior orders of removal, criminal history, or expired status. Detentions can occur on outbound, connecting, or return flights, disrupting business travel and creating immediate workforce continuity risks. Recommended employer actions include auditing employee travel rosters for immigration-vulnerable staff, issuing domestic-travel guidance, preparing emergency-response protocols for detained employees, training managers on what to do if an employee is taken into custody, and reviewing I-9 and visa-status files for compliance gaps. Counsel should also assess whether any recent policy shifts affect remote-worker relocations or cross-border assignments.
Retail importers face heightened UFLPA enforcement as CBP's 2026 operational guidance expands documentation expectations across every tier of the supply chain.
U.S. Customs and Border Protection's new Forced Labor Enforcement Operational Guidance for Importers formalizes how the agency will apply the Uyghur Forced Labor Prevention Act, withhold release orders, and CAATSA to inbound shipments. Importers must now demonstrate granular traceability—mapping each material, supplier, and shipment node—particularly for goods appearing on the Bureau of International Labor Affairs' List of Goods Produced by Child Labor or Forced Labor. The guidance signals broader use of entity-based and commodity-based enforcement, not just port-level detention. In-house counsel at retailers and consumer brands should audit supplier disclosures, refresh due-diligence questionnaires, and prepare rebuttal packages before shipments are detained. Proactive mapping of high-risk inputs (cotton, polysilicon, tomatoes, seafood) is now a baseline compliance expectation rather than a best practice.
In-house counsel for entities operating in the UK, with UK-linked supply chains, or transacting with newly designated parties must review the latest updates to avoid non-compliance enforcement penalties.
The July 13 and 20 2026 UK weekly sanctions update publishes new asset freeze and travel ban designations targeting individuals and entities tied to Russian defense procurement, Iranian ballistic missile development, and third-party networks facilitating sanctions evasion. The update also revises guidance on humanitarian licensing exemptions for agricultural and medical trade with sanctioned jurisdictions, and updates due diligence requirements for UK financial institutions handling transactions for high-risk non-designated counterparties. In-house counsel should update internal blocked party lists to reflect new designations, review existing sanctions compliance policies against the revised rules, and train relevant commercial, finance, and logistics teams to mitigate enforcement risk.
Grade 3 — worth a glance, not the full analysis.
- CFTC Proposes Affiliation Rules, Sunsets Swap Large-Trader Reports; ESMA Sets T+1 Deadline
CFTC-regulated entities and swap dealers face a 60-day comment window on proposed affiliation amendments and immediate relief from Part 20 large-trader reporting, while EU firms must prepare for the December 7, 2026 T+1 settlement milestone.
- Democrats Reintroduce Bill to Ban Employment Arbitration Agreements
Multiemployer HR and legal teams should track the proposed FAIR Act, which would void pre-dispute arbitration and class-waiver clauses in employment contracts nationwide.
- UK Court Refuses Summary Judgment in Building Safety Act Remediation Dispute
Developers and freeholders handling Building Safety Act remediation agreements must reassess termination rights, as the TCC confirmed repudiatory breach claims require full trial.
- State AGs Stepping Into Merger Reviews Where Federal Enforcers Decline
Deal teams should expect state attorneys general to investigate transactions the DOJ or FTC decline to challenge, adding a second front of antitrust risk.