DROPLETS
Vetted U.S. contractors may soon conduct government-directed offensive cyber operations against foreign cyber-enabled criminal organizations, creating immediate compliance, liability, and constitutional questions for participating companies.
On August 12, 2026, President Trump signed a National Security Presidential Memorandum establishing a program under which vetted private U.S. companies—acting under federal direction and control—may carry out cyber surveillance and cyber effects operations against foreign cyber-enabled transnational criminal organizations. The program is overseen by dual executive directors from the Departments of Justice and Homeland Security, with all operations required to comply with the Computer Fraud and Abuse Act and other applicable law. Within 60 days, operating procedures will define vetting standards, deconfliction processes, and guardrails. Companies must enter into contractual agreements with DOJ or DHS, and those holding relevant threat intelligence may also sell data to participating firms. Open legal questions include whether participating companies are state actors for Fourth Amendment and FISA purposes, how liability is allocated for operations exceeding approved parameters, and how extraterritorial activities will be reconciled with international law.
Digital asset operators, custodians, and stablecoin issuers must track a wave of new federal and state rules taking effect or under proposal that will impose licensing, tax, and compliance obligations across the United States.
Between June and July 2026, U.S. regulators and Congress advanced a broad array of digital asset measures. California’s Digital Financial Assets Law took effect July 1, requiring DFPI licensure for businesses exchanging, transferring, storing, or issuing digital assets with California residents, with penalties up to $100,000 per day for unlicensed activity. Illinois enacted a 0.2% privilege tax on digital asset transactions effective January 1, 2027, though litigation and repeal efforts are pending. The Senate Banking and Agriculture Committees released merged Clarity Act text with an ethics provision barring public officials from profiting from digital assets; a cloture vote is scheduled for September. The SEC’s 2026 Regulatory Agenda targets exchange and broker-dealer rules for digital assets, while the agency also sought comment on novel ETFs including crypto holdings. Federal regulators proposed BSA/AML rules for payment stablecoin issuers under the GENIUS Act, with comments due in August. The OCC approved Circle and Sony Bank applications for national trust banks focused on digi
…
Broker-dealers under prior AML consent orders face heightened enforcement risk after FinCEN imposed a $125 million penalty on UBS Financial Services for willful, repeated BSA violations and failure to remediate 2018 deficiencies.
FinCEN assessed a $125 million civil money penalty against UBS Financial Services Inc. for willful Bank Secrecy Act violations, marking the largest such penalty against a broker-dealer. The action follows a 2018 consent order and centers on failures to monitor over 61,500 foreign currency wires totaling more than $10.5 billion, deficient customer due diligence for high-risk clients (including Russian and Latin American ties), and untimely SAR filings. After crediting $48 million for related SEC, CFTC, and FINRA payments, UBSFS owes $62 million, with up to $15 million waivable based on qualifying compliance spending and full adherence to the order. The settlement requires a SAR look-back and independent AML program review. FinCEN’s focus on recidivism, data governance, and dynamic CDD signals that covered institutions must validate remediation, ensure complete transaction monitoring data feeds, and maintain continuous risk reassessment.
Banks supervised by the FDIC or OCC must review a new Community Reinvestment Act proposal that would reshape compliance thresholds, lending tests, and community development treatment, while Federal Reserve–regulated banks remain under the 1995 framework.
On July 31, 2026, the FDIC and OCC issued a Notice of Proposed Rulemaking updating CRA regulations only for the institutions they supervise, leaving Federal Reserve–regulated banks subject to the 1995 rules. The proposal raises asset thresholds for small, intermediate, and large banks; narrows the retail service test to credit services; limits CRA consideration for grants and donations to direct community development use with a 15% indirect-cost cap for large banks; and refines how major product lines are determined for lending tests. Comments are due October 13, 2026. Affected institutions should assess whether the new thresholds and test methodologies change their CRA ratings and compliance strategy.
In-house counsel for merging parties facing DOJ antitrust challenges must note that court-approved settlements with targeted divestitures can overcome state AG opposition under the Tunney Act, even with low market shares at issue.
The U.S. District Court for the Northern District of California approved the settlement between HPE and the DOJ regarding HPE’s $14 billion acquisition of Juniper Networks, rejecting a challenge from a coalition of state attorneys general who sought to block the deal. The settlement requires HPE to divest its Instant On wireless networking business and license AI-driven WLAN management source code to a competitor. The court found the remedies sufficient to address competitive concerns, citing the risk of DOJ losing at trial due to low combined market shares and the potential for the divested assets to support new market entrants. The ruling underscores that Tunney Act settlements can withstand state AG intervention when the proposed relief is tailored to preserve competition in the relevant market.
Employers using E-Verify must prepare for new status-change reports flagging work permits invalidated by expired TPS, requiring immediate I-9 review and potential re-verification.
DHS will begin including Employment Authorization Documents (EADs) invalidated due to expired Temporary Protected Status (TPS) in E-Verify’s Status Change reports. This follows the termination of TPS for several countries and the elimination of the 540-day extension for timely filed EAD renewals. Employers must audit their I-9 records for affected workers, cease reliance on invalid EADs, and re-verify employment eligibility using acceptable documentation. Failure to act may result in I-9 violations and potential penalties.
Designated contract markets must immediately review and correct self-certification filings for market-maker, liquidity, trading, and incentive programs to avoid regulatory deficiencies identified by the CFTC.
On August 12, the CFTC Division of Market Oversight issued an advisory addressing a rising number of deficient self-certification filings under Regulation 40.6(a), particularly for event contract incentive programs. The advisory reminds designated contract markets of their obligations under Regulations 40.5 and 40.6 when submitting such programs. Concurrently, the CFTC exercised emergency authority to order KalshiEX to maintain operations consistent with Core Principles following a market emergency notification. The agency also reminded entities to display clear pricing information for event contracts. In-house counsel for derivatives exchanges and trading platforms should audit current and pending self-certification filings for compliance with the advisory’s procedural and substantive requirements, update internal review protocols, and monitor for potential enforcement scrutiny of deficient filings.
Data center developers with projects in ERCOT’s Batch Zero interconnection process must prepare for mandatory compliance audits and multi-month study delays before grid connection approval.
Texas Governor Greg Abbott directed ERCOT and the Public Utility Commission of Texas to conduct a comprehensive audit of all data centers in the interconnection queue before any additional projects advance. The audit, expected to take several months, will verify compliance with PUCT and ERCOT requirements and collect new data on financial incentives, power sourcing, water usage, community impacts, and ownership. ERCOT has paused Batch Zero classifications and study timelines for loads 75 MW and above, requested deadline waivers, and will issue mandatory RFIs to all affected projects. Projects failing to respond or providing false information will be deemed ineligible for Batch Zero. The Long-Term Load Forecast is also delayed as a result. Developers should gather required documentation and anticipate extended interconnection timelines.
Importers and customs brokers must immediately evaluate their compliance programs against the new DOJ-DHS trade fraud enforcement guide, which signals a sustained priority on supply-chain and tariff-related fraud.
The Department of Justice and Department of Homeland Security have released a joint enforcement guide that elevates trade fraud—particularly misclassification, undervaluation, and origin fraud—as a sustained priority. The guide effectively applies False Claims Act standards to import-related conduct, meaning that supply-chain diligence must be documented with the underlying analysis, not just conclusions. Importers and brokers should test their existing compliance frameworks against this guidance, strengthen internal reporting channels, and assess disclosure decisions early to mitigate exposure to government investigations and civil penalties.
Autonomous systems companies must map their innovations to the expanded physical AI patent taxonomy to secure defensible IP across robotics, drones, and next-gen machines.
The article traces how the European Patent Office’s 2019 autonomous vehicle taxonomy—covering perception, communication, data processing/AI, and vehicle control—now applies to the broader physical AI landscape, including industrial robots, humanoid robotics, surgical systems, and drones. WIPO data shows transportation-related patents grew 11% annually from 2000–2023, with AI and sensor fusion innovations crossing into multiple modalities. For U.S. practitioners, claims must tie AI to concrete physical improvements to satisfy Section 101 post-Alice eligibility, while international jurisdictions offer varied frameworks. Companies should identify which layers of the autonomy stack contain their core innovations and align filing strategy accordingly, anticipating enforcement from incumbent AV patent holders as markets expand.
Broker-dealers under prior AML consent orders face heightened enforcement risk after FinCEN imposed a $125 million penalty on UBS Financial Services for willful, repeated BSA violations and failure to remediate 2018 deficiencies.
FinCEN assessed a $125 million civil money penalty against UBS Financial Services Inc. for willful Bank Secrecy Act violations, marking the largest such penalty against a broker-dealer. The action follows a 2018 consent order and centers on failures to monitor over 61,500 foreign currency wires totaling more than $10.5 billion, deficient customer due diligence for high-risk clients (including Russian and Latin American ties), and untimely SAR filings. After crediting $48 million for related SEC, CFTC, and FINRA payments, UBSFS owes $62 million, with up to $15 million waivable based on qualifying compliance spending and full adherence to the order. The settlement requires a SAR look-back and independent AML program review. FinCEN’s focus on recidivism, data governance, and dynamic CDD signals that covered institutions must validate remediation, ensure complete transaction monitoring data feeds, and maintain continuous risk reassessment.
In-house counsel for merging parties facing DOJ antitrust challenges must note that court-approved settlements with targeted divestitures can overcome state AG opposition under the Tunney Act, even with low market shares at issue.
The U.S. District Court for the Northern District of California approved the settlement between HPE and the DOJ regarding HPE’s $14 billion acquisition of Juniper Networks, rejecting a challenge from a coalition of state attorneys general who sought to block the deal. The settlement requires HPE to divest its Instant On wireless networking business and license AI-driven WLAN management source code to a competitor. The court found the remedies sufficient to address competitive concerns, citing the risk of DOJ losing at trial due to low combined market shares and the potential for the divested assets to support new market entrants. The ruling underscores that Tunney Act settlements can withstand state AG intervention when the proposed relief is tailored to preserve competition in the relevant market.
Banks supervised by the FDIC or OCC must review a new Community Reinvestment Act proposal that would reshape compliance thresholds, lending tests, and community development treatment, while Federal Reserve–regulated banks remain under the 1995 framework.
On July 31, 2026, the FDIC and OCC issued a Notice of Proposed Rulemaking updating CRA regulations only for the institutions they supervise, leaving Federal Reserve–regulated banks subject to the 1995 rules. The proposal raises asset thresholds for small, intermediate, and large banks; narrows the retail service test to credit services; limits CRA consideration for grants and donations to direct community development use with a 15% indirect-cost cap for large banks; and refines how major product lines are determined for lending tests. Comments are due October 13, 2026. Affected institutions should assess whether the new thresholds and test methodologies change their CRA ratings and compliance strategy.
Vetted U.S. contractors may soon conduct government-directed offensive cyber operations against foreign cyber-enabled criminal organizations, creating immediate compliance, liability, and constitutional questions for participating companies.
On August 12, 2026, President Trump signed a National Security Presidential Memorandum establishing a program under which vetted private U.S. companies—acting under federal direction and control—may carry out cyber surveillance and cyber effects operations against foreign cyber-enabled transnational criminal organizations. The program is overseen by dual executive directors from the Departments of Justice and Homeland Security, with all operations required to comply with the Computer Fraud and Abuse Act and other applicable law. Within 60 days, operating procedures will define vetting standards, deconfliction processes, and guardrails. Companies must enter into contractual agreements with DOJ or DHS, and those holding relevant threat intelligence may also sell data to participating firms. Open legal questions include whether participating companies are state actors for Fourth Amendment and FISA purposes, how liability is allocated for operations exceeding approved parameters, and how extraterritorial activities will be reconciled with international law.
Data center developers with projects in ERCOT’s Batch Zero interconnection process must prepare for mandatory compliance audits and multi-month study delays before grid connection approval.
Texas Governor Greg Abbott directed ERCOT and the Public Utility Commission of Texas to conduct a comprehensive audit of all data centers in the interconnection queue before any additional projects advance. The audit, expected to take several months, will verify compliance with PUCT and ERCOT requirements and collect new data on financial incentives, power sourcing, water usage, community impacts, and ownership. ERCOT has paused Batch Zero classifications and study timelines for loads 75 MW and above, requested deadline waivers, and will issue mandatory RFIs to all affected projects. Projects failing to respond or providing false information will be deemed ineligible for Batch Zero. The Long-Term Load Forecast is also delayed as a result. Developers should gather required documentation and anticipate extended interconnection timelines.
Broker-dealers under prior AML consent orders face heightened enforcement risk after FinCEN imposed a $125 million penalty on UBS Financial Services for willful, repeated BSA violations and failure to remediate 2018 deficiencies.
FinCEN assessed a $125 million civil money penalty against UBS Financial Services Inc. for willful Bank Secrecy Act violations, marking the largest such penalty against a broker-dealer. The action follows a 2018 consent order and centers on failures to monitor over 61,500 foreign currency wires totaling more than $10.5 billion, deficient customer due diligence for high-risk clients (including Russian and Latin American ties), and untimely SAR filings. After crediting $48 million for related SEC, CFTC, and FINRA payments, UBSFS owes $62 million, with up to $15 million waivable based on qualifying compliance spending and full adherence to the order. The settlement requires a SAR look-back and independent AML program review. FinCEN’s focus on recidivism, data governance, and dynamic CDD signals that covered institutions must validate remediation, ensure complete transaction monitoring data feeds, and maintain continuous risk reassessment.
Designated contract markets must immediately review and correct self-certification filings for market-maker, liquidity, trading, and incentive programs to avoid regulatory deficiencies identified by the CFTC.
On August 12, the CFTC Division of Market Oversight issued an advisory addressing a rising number of deficient self-certification filings under Regulation 40.6(a), particularly for event contract incentive programs. The advisory reminds designated contract markets of their obligations under Regulations 40.5 and 40.6 when submitting such programs. Concurrently, the CFTC exercised emergency authority to order KalshiEX to maintain operations consistent with Core Principles following a market emergency notification. The agency also reminded entities to display clear pricing information for event contracts. In-house counsel for derivatives exchanges and trading platforms should audit current and pending self-certification filings for compliance with the advisory’s procedural and substantive requirements, update internal review protocols, and monitor for potential enforcement scrutiny of deficient filings.
Digital asset operators, custodians, and stablecoin issuers must track a wave of new federal and state rules taking effect or under proposal that will impose licensing, tax, and compliance obligations across the United States.
Between June and July 2026, U.S. regulators and Congress advanced a broad array of digital asset measures. California’s Digital Financial Assets Law took effect July 1, requiring DFPI licensure for businesses exchanging, transferring, storing, or issuing digital assets with California residents, with penalties up to $100,000 per day for unlicensed activity. Illinois enacted a 0.2% privilege tax on digital asset transactions effective January 1, 2027, though litigation and repeal efforts are pending. The Senate Banking and Agriculture Committees released merged Clarity Act text with an ethics provision barring public officials from profiting from digital assets; a cloture vote is scheduled for September. The SEC’s 2026 Regulatory Agenda targets exchange and broker-dealer rules for digital assets, while the agency also sought comment on novel ETFs including crypto holdings. Federal regulators proposed BSA/AML rules for payment stablecoin issuers under the GENIUS Act, with comments due in August. The OCC approved Circle and Sony Bank applications for national trust banks focused on digi
…
Employers using E-Verify must prepare for new status-change reports flagging work permits invalidated by expired TPS, requiring immediate I-9 review and potential re-verification.
DHS will begin including Employment Authorization Documents (EADs) invalidated due to expired Temporary Protected Status (TPS) in E-Verify’s Status Change reports. This follows the termination of TPS for several countries and the elimination of the 540-day extension for timely filed EAD renewals. Employers must audit their I-9 records for affected workers, cease reliance on invalid EADs, and re-verify employment eligibility using acceptable documentation. Failure to act may result in I-9 violations and potential penalties.
Importers and customs brokers must immediately evaluate their compliance programs against the new DOJ-DHS trade fraud enforcement guide, which signals a sustained priority on supply-chain and tariff-related fraud.
The Department of Justice and Department of Homeland Security have released a joint enforcement guide that elevates trade fraud—particularly misclassification, undervaluation, and origin fraud—as a sustained priority. The guide effectively applies False Claims Act standards to import-related conduct, meaning that supply-chain diligence must be documented with the underlying analysis, not just conclusions. Importers and brokers should test their existing compliance frameworks against this guidance, strengthen internal reporting channels, and assess disclosure decisions early to mitigate exposure to government investigations and civil penalties.
Autonomous systems companies must map their innovations to the expanded physical AI patent taxonomy to secure defensible IP across robotics, drones, and next-gen machines.
The article traces how the European Patent Office’s 2019 autonomous vehicle taxonomy—covering perception, communication, data processing/AI, and vehicle control—now applies to the broader physical AI landscape, including industrial robots, humanoid robotics, surgical systems, and drones. WIPO data shows transportation-related patents grew 11% annually from 2000–2023, with AI and sensor fusion innovations crossing into multiple modalities. For U.S. practitioners, claims must tie AI to concrete physical improvements to satisfy Section 101 post-Alice eligibility, while international jurisdictions offer varied frameworks. Companies should identify which layers of the autonomy stack contain their core innovations and align filing strategy accordingly, anticipating enforcement from incumbent AV patent holders as markets expand.
Grade 3 — worth a glance, not the full analysis.
- New State Consumer Protections for BNPL and Mortgage Lending
Consumer lenders and BNPL providers operating in Illinois and Maryland must review new state regulatory requirements that expand licensing and compliance obligations.
- New Guidance Clarifies Employer Rules for Trump Accounts
Employers with 401(k) plans offering political or ideological investment options must review updated DOL guidance to ensure compliance with fiduciary duties and disclosure requirements.
- UK Public M&A Activity Surges in July 2026
In-house counsel at UK public companies and their bidders must track a busy M&A market with nine announced deals, including hostile bids, competing offers, and complex multi-party transactions that require immediate attention to UK Takeover Code compliance and deal timing.
- German Court Limits Garden Leave, Company Car Revocation During Notice
German employers must revise garden leave and company car policies for notice periods to comply with new Federal Labor Court guidance.
- SCE Equipment Blamed for Eaton Fire as Lawsuits Advance
Utilities and insurers face mounting liability as investigators tie Southern California Edison equipment to the Eaton Fire, triggering a wave of litigation.