DROPLETS
A bill awaiting the governor's signature would retroactively eliminate the private right of action for thousands of class actions under California's CIPA.
The California Legislature has unanimously passed SB 690, a bill that would eliminate the private right of action for claims that common website and app tracking technologies function as illegal "pen registers" under the California Invasion of Privacy Act (CIPA). This legislation is a direct response to a surge of nearly 4,000 proposed class actions filed since early 2025 targeting companies for using tools like tracking pixels, cookies, and session-replay software.
For corporate counsel and their outside firms, this is a critical development. With statutory damages of up to $5,000 per violation, CIPA pen-register claims created enormous potential exposure. The bill, if signed into law, would apply retroactively to cases filed on or after January 1, 2025, potentially extinguishing thousands of pending lawsuits. It is important to note, however, that the bill is narrowly tailored and does not affect other CIPA claims, such as wiretapping allegations under § 631, which are often brought in the same complaints.
…
The US Securities and Exchange Commission has proposed "Regulation Crypto Assets," a new framework that would create two new offering exemptions and a safe harbor for certain investment contracts involving digital assets.
The US Securities and Exchange Commission (SEC) has proposed "Regulation Crypto Assets," a new and comprehensive framework for offerings of certain crypto assets deemed to be securities. The proposal distinguishes between a crypto asset and the "covered investment contract" to which it is subject, applying only when the asset itself is not a security like tokenized equity.
The proposed rules establish two new transactional exemptions from registration. A "startup exemption" would permit offerings up to $5 million over four years with streamlined, website-based disclosures. A tiered "fundraising exemption," modeled on Regulation A, would allow for offerings of up to $20 million (Tier 1) or $75 million (Tier 2) in a 12-month period, with ongoing reporting obligations.
…
The Treasury Department expanded secondary sanctions to Iran's aviation, tech, and shipping sectors, suspended general licenses, and designated third-country banks for facilitating Iranian transactions, creating broad new compliance risks.
The U.S. government has unveiled a significant expansion of its Iran sanctions program, creating new risks for companies operating globally. In a series of actions, the Treasury's Office of Foreign Assets Control (OFAC) authorized the imposition of secondary sanctions on entities involved with Iran's aviation, technology, digital asset, gold, and shipping sectors. This move exposes non-U.S. persons to potential U.S. sanctions for transacting with these sectors, even with no other U.S. nexus. The measures also include the designation of nearly 60 new parties, the suspension of several general licenses, and a new policy of presumptive denial for most specific license applications.
…
Federal bank regulators will now need to show a connection to material financial harm before taking supervisory or enforcement action based on an unsafe or unsound practice, a significant shift in the examination framework.
The Office of the Comptroller of the Currency (OCC) and the Federal Deposit Insurance Corporation (FDIC) have adopted a joint final rule that establishes a binding definition for an “unsafe or unsound practice” for the first time. Effective November 2, 2026, the rule institutes a two-part test requiring that conduct be contrary to generally accepted standards of prudent operation and also create a material risk of financial harm to the institution or the Deposit Insurance Fund. The Federal Reserve did not join the rulemaking but has issued separate, similar guidance.
…
A Dubai International Financial Centre court set aside an entire arbitral award for the first time after finding the tribunal decided the case on legal arguments the parties themselves had never raised.
The Dubai International Financial Centre (DIFC) Court of First Instance has set aside a Dubai International Arbitration Centre (DIAC) arbitral award in its entirety, finding the tribunal decided the dispute on legal grounds that had not been pleaded or argued by the parties. In Princeton v Persephone, the court held that the tribunal's reliance on unargued theories of waiver and estoppel denied the applicant a reasonable opportunity to present its case, a fundamental tenet of procedural fairness.
…
The Securities and Exchange Commission has released a proposed update to the rules for registered transfer agents to reflect technological advancements, including the use of blockchain.
The SEC has proposed a comprehensive update to the rules governing registered transfer agents, marking the first major overhaul in this area in decades. The proposal aims to modernize regulations to account for technological changes, including electronic recordkeeping, uncertificated securities, and the use of blockchain or distributed ledger technology. Key changes would update requirements for processing times, risk management, business continuity planning, and the safeguarding of securities and funds. For clients in the financial services and technology sectors, this is a critical development. The rules could pave a clearer regulatory path for issuing and transferring tokenized securities, while also imposing new operational and compliance burdens on transfer agents. Counsel should advise affected clients to closely review the proposed rule changes, assess their potential impact on current and future business operations, and consider submitting comments to the SEC during the public comment period.
The SEC has proposed the first comprehensive update to transfer agent regulations in decades, seeking to address technological advancements and impose new standards for risk management and compliance.
The U.S. Securities and Exchange Commission has proposed a comprehensive overhaul of the rules governing registered transfer agents, which have not been substantively updated in over 40 years. The proposal aims to modernize the regulatory framework to reflect significant technological advancements in securities recordkeeping, including the use of electronic communications and blockchain or distributed ledger technology. Key elements of the proposal include new requirements for transfer agents to establish and maintain written risk management and compliance policies, new standards for processing securities transfers and removing restrictive legends, and updated rules for handling inactive securityholder accounts. For public companies and other issuers, these changes could impact how their securities are transferred and serviced. The proposal will directly affect the operations of all registered transfer agents, requiring investment in new systems and compliance protocols. The SEC will accept public comments for 60 days after the proposal is published in the Federal Register.
A new New York law taking effect November 8, 2026, requires employers to provide employees with copies of their personnel records within five business days of a request and to notify them of any new negative information.
New York has enacted a law requiring all public and private employers in the state to provide current and former employees with access to their personnel records. Signed by Governor Hochul, the legislation takes effect on November 8, 2026, and introduces several new compliance obligations that require immediate attention.
The law mandates that employers provide a copy of an employee's personnel record, at no cost, within five business days of a written request. It also requires employers to notify an employee within ten days of placing any information in their file that could negatively affect their employment status, compensation, or disciplinary standing. The definition of "personnel record" is broad, extending to certain records maintained by third-party HR and payroll vendors. The statute also establishes a process for employees to dispute information, sets record-retention requirements, and includes robust anti-retaliation protections.
…
Federal and state agencies are stepping up enforcement actions against telehealth platforms and wellness clinics, focusing on standard-of-care violations, marketing claims, and prescribing practices.
Federal agencies and state medical boards are escalating enforcement against the burgeoning wellness industry, targeting telehealth platforms, IV therapy bars, ketamine clinics, and weight-management providers. This heightened scrutiny follows the expiration of many pandemic-era telehealth prescribing flexibilities, exposing a range of compliance gaps. Regulators are focusing on standard-of-care violations, improper supervision of non-physician practitioners, unsubstantiated marketing claims targeted by the FTC, and DEA requirements for prescribing controlled substances like ketamine. For innovative health platforms, especially those using direct-to-consumer and cash-pay models, the risks include significant civil penalties, license discipline, and operational disruption. The trend signals a tougher environment for a high-growth sector. Counsel should advise clients to promptly conduct comprehensive compliance assessments of their prescribing and marketing protocols, provider licensing, data privacy practices, and corporate structures to mitigate exposure to this coordinated multi-ju
…
Mexico's president has introduced a legislative proposal to Congress aimed at regulating digital payments, establishing digital identities, and promoting cashless sectors.
On September 8, 2026, the President of Mexico submitted a proposed Digital Economy Law for Digital and Electronic Payments to the national Congress, signaling a major regulatory push to modernize the country's payment systems. The initiative aims to address key aspects of the digital ecosystem, including digital identity verification, rules for the acceptance of electronic payments, and the promotion of cashless transactions in certain sectors.
This proposed legislation could create significant new compliance obligations and market opportunities for financial institutions, e-commerce companies, payment processors, and other businesses with operations in Mexico. For sophisticated counsel and clients, the bill represents a critical development that could reshape the competitive landscape and require adjustments to existing business models. International companies will need to evaluate how the law, if passed, would affect their operations, customer interactions, and data-handling practices.
…
The U.S. Court of Appeals for the Federal Circuit will soon have an opportunity to limit the application of obviousness-type double patenting, a move that could simplify patent law and incentivize follow-on innovation.
The U.S. Court of Appeals for the Federal Circuit is poised to consider a significant limitation on the doctrine of obviousness-type double patenting (OTDP), a complex, judicially created concept in U.S. patent law. The core issue is whether the doctrine, which prevents an inventor from improperly extending patent exclusivity with claims that are not patentably distinct from those in an earlier patent, should apply only when a patent's term has been artificially extended.
…
A decade after its enactment, the Defend Trade Secrets Act has increased federal filings but also created significant circuit splits on pleading standards, damages, and other key issues.
A decade after its passage, the Defend Trade Secrets Act (DTSA) has successfully shifted more trade secret litigation into federal court but has failed to create the single, national standard Congress envisioned. Analysis of the statute's first ten years reveals significant and unresolved circuit splits on fundamental issues, creating strategic complexity for businesses. For example, courts are divided on how specifically a plaintiff must identify an alleged trade secret at the pleading stage and whether a defendant's "avoided costs" can be recovered as unjust-enrichment damages without the plaintiff proving its own corresponding loss. The Seventh Circuit has also endorsed a broad extraterritorial reach for the statute, a position not yet tested elsewhere, creating further uncertainty for global companies. Looking ahead, the rise of artificial intelligence presents new challenges, raising questions about whether AI-generated output can be a trade secret and what security measures are now considered "reasonable." Businesses should monitor these splits and emerging AI-related doctrines
…
The head of the Federal Trade Commission has outlined five factors the agency will use to scrutinize the sale process of a financially distressed target in a merger, raising the bar for parties asserting the 'failing firm' defense.
In a statement prompted by a scuttled Ohio hospital merger, Federal Trade Commission Chairman Andrew Ferguson has detailed five factors the agency will scrutinize when evaluating the adequacy of a 'shop' process for a company asserting the 'failing firm' defense. The new guidance focuses on the third prong of the defense, which requires a good-faith effort to find an alternative buyer. The FTC will now explicitly assess whether the seller solicited a full set of potential buyers, gave them sufficient time and data for diligence, engaged in good-faith negotiations, and properly weighed less anticompetitive offers. This signals a more demanding standard for parties in all industries, not just healthcare. For sophisticated counsel, it means a pre-deal 'shop' process that is merely adequate may no longer suffice. Failure to conduct and document a robust and impartial search for alternative acquirers before signing with a direct competitor could prove fatal to a deal during the subsequent antitrust review, or at least cause significant delays and added expense.
New FCC rules prohibit equipment authorization for end products containing 'covered' hardware components and impose verification duties on e-commerce platforms.
The Federal Communications Commission (FCC) has significantly expanded its equipment authorization prohibitions to further secure U.S. communications supply chains. Under a new Third Report and Order, the FCC will now deny authorization to any end product containing "logic-bearing hardware components," such as chipsets, produced by an entity on its national-security Covered List. This rule applies regardless of whether the final product manufacturer itself is on the list, creating substantial new diligence obligations for technology companies.
…
New regulations effective September 29 restore prohibitions on Iran's shipping, aviation, oil, and gas sectors, creating significant new compliance burdens for maritime and financial firms.
The United Kingdom will reimpose extensive sectoral sanctions against Iran on September 29, 2026, re-establishing prohibitions previously lifted under the Joint Comprehensive Plan of Action (JCPOA). The new rules create significant compliance challenges, particularly for the global maritime industry, by introducing powers to designate 'specified ships' and banning their charter, operation, and servicing. The regulations also broadly prohibit providing insurance or reinsurance to any person 'connected with Iran' and restrict port access for designated vessels. Further financial measures bar UK institutions from activities like opening accounts for or establishing correspondent banking relationships with Iranian counterparts. While the direct impact on aviation is narrower, targeting specific cargo aircraft, the overall regulatory shift requires clients in the shipping, energy, insurance, and banking sectors to urgently review their Iran exposure. Counsel should advise on enhanced diligence for vessels and counterparties and assess existing contracts before the imminent effective date.
Manufacturers of connected products sold in the EU must now report actively exploited vulnerabilities and severe security incidents within 24 hours of awareness, with potential fines of up to €15 million or 2.5% of global turnover.
The EU's Cyber Resilience Act (CRA) reporting regime took effect on September 11, 2026, imposing stringent new obligations on manufacturers of connected products. The act covers a vast range of "products with digital elements" (PDEs), including software, hardware, and IoT devices, that are made available on the EU market. The key change is an exceptionally fast reporting timeline: manufacturers must provide an "early warning" to the EU's cybersecurity agency (ENISA) and national authorities within 24 hours of becoming aware of either an actively exploited vulnerability or a severe security incident impacting their product. A more detailed notification is required within 72 hours.
…
Two House committees are investigating the national security, cybersecurity, and economic risks of U.S. companies integrating AI models developed by PRC-based entities.
Two U.S. House committees are jointly investigating American companies for their use of AI models developed in the People's Republic of China, citing significant national security, cybersecurity, and economic stability risks. The inquiry focuses on allegations that Chinese AI labs used techniques like “adversarial distillation” to extract capabilities from U.S. models, potentially without their safety guardrails against malicious use.
Corporate counsel should note that Anysphere (developer of the Cursor coding platform), Airbnb, and DoorDash have already received detailed inquiry letters demanding internal documents, data policies, vendor agreements, and in-person briefings. The development signals a new front in U.S.-China tech scrutiny with serious compliance and reputational stakes for any company using third-party AI, particularly lower-cost foreign alternatives that handle user data. Clients should proactively assess their vendor contracts, data security protocols, and customer disclosures related to foreign-developed AI. The key development to watch is whether the investigatio
…
New European Commission guidance clarifies the scope and compliance steps for the Cyber Resilience Act, emphasizing strict incident and vulnerability reporting deadlines.
The European Commission has published new guidance clarifying the scope and compliance obligations under the European Union’s expansive Cyber Resilience Act (CRA). This development is critical for any company manufacturing or selling products with digital components in the EU market. The guidance addresses key definitions and the act's reach, but legal commentators highlight the immediate challenge of its strict reporting timelines.
According to legal experts, companies are particularly focused on the requirements to report actively exploited vulnerabilities and severe security incidents to regulators within very short deadlines. The guidance also sheds light on the substantial effort required to meet the CRA’s vulnerability-testing and security-by-design mandates. Cloud services and cybersecurity providers, who may not be used to reporting to regulatory bodies, must now adapt their processes. Counsel should advise clients to promptly assess the CRA's applicability to their product portfolios and establish the necessary internal procedures for monitoring and reporting to ensure comp
…
New European Commission guidance on the Pay Transparency Directive clarifies the scope of covered employers and pay, but leaves significant ambiguity around determining work of equal value.
The European Commission has issued new guidance on the EU Pay Transparency Directive (2023/970), clarifying some obligations for employers but leaving other key areas unresolved. The guidance, presented as FAQs, confirms the directive's broad application to both public and private sector employers and specifies that initial pay information must be disclosed before a job interview, though not necessarily in the public job posting. It also provides a framework for what counts as "pay" and addresses the directive's interplay with GDPR, designating equal pay compliance a "public interest" that can justify data processing.
…
A new analysis offers guidance for US employers on balancing Title VII's protections for transgender employees with a shifting federal enforcement environment targeting certain DEI initiatives.
A new guide advises US employers on navigating the complex legal environment surrounding workplace protections for transgender employees. While the Supreme Court's 2020 decision in Bostock v. Clayton County still prohibits discrimination based on transgender status under Title VII, the guide highlights a growing tension with a shifting federal enforcement posture that scrutinizes certain diversity, equity, and inclusion (DEI) initiatives. This creates particular risks for federal contractors, who may face DOJ scrutiny or False Claims Act exposure for programs deemed to be "illegal DEI."
…
Maryland's attorney general has sued Optum and parent UnitedHealth Group, alleging a failed claims-processing system led to over $126 million in improper payments and years of provider audits.
Maryland’s attorney general has sued Optum and its parent, UnitedHealth Group, over a catastrophic failure of the state's behavioral health Medicaid claims system. The complaint alleges the state paid Optum more than $126 million for a system that never became fully functional after the company secretly substituted an untested software platform for the robust system promised in its contract. The system crashed upon its 2020 launch, forcing the state to issue $1.6 billion in emergency estimated payments to providers to prevent a total collapse of the payment infrastructure.
…
A critical materials supplier has secured a landmark $450M investment from a new defense economic unit, signaling a fresh government strategy to accelerate industrial production and secure supply chains.
Akin Gump advised The Elmet Group, a U.S. critical materials supplier, in securing a $450 million investment from the U.S. Department of War. The transaction is described as a pioneer deal under the department's newly established Economic Defense Unit, which was created to accelerate domestic defense production. Separately, an Elmet subsidiary was awarded an indefinite delivery/indefinite quantity contract with a ceiling of $2 billion to help rebuild the U.S. National Defense Stockpile's tungsten supply. As a condition, Elmet adopted a compliance plan to prevent 'restricted entities' from acquiring a significant stake. Sophisticated counsel should see this as a template for a new, well-funded government strategy to onshore critical supply chains. The creation of the dedicated unit suggests a more proactive government role in private-sector industrial capacity. Clients in the defense, manufacturing, and technology sectors should monitor this unit's activities for funding opportunities and be prepared for novel compliance obligations, like the ownership restrictions seen here.
The UK government has launched a consultation on wide-ranging reforms to the corporate reporting, distributable profits, and capital maintenance rules under the Companies Act 2006.
The UK government has published a consultation paper proposing what it calls a 'once-in-a-generation' overhaul of the country's corporate reporting framework. The proposals, issued by the Department for Business, Innovation, Science and Trade, aim to simplify the reporting landscape under the Companies Act 2006 and refocus disclosures on information that is financially material to investors and creditors. A key change under consideration is replacing the complex rules on distributable profits with a more straightforward solvency-based test for dividends. Other proposals include overhauling the strategic report, streamlining corporate governance and remuneration disclosures, and simplifying company-size thresholds. The reforms would affect a wide range of public and private UK companies by potentially reducing their compliance burden and altering how they report on strategy, governance, and shareholder distributions. The consultation period is open until November 30, 2026, and affected companies should review the proposals to assess their potential operational impact.
New guidance from the New York Department of Financial Services details specific expectations for cybersecurity risk assessments required under its Part 500 regulations.
The New York Department of Financial Services (NYDFS) has published extensive new guidance for covered entities regarding the cybersecurity risk assessments required under 23 NYCRR Part 500. The guidance clarifies and significantly details the regulator’s expectations, providing a more granular framework than the original rule for how firms should identify and assess their cybersecurity risks.
This development is important for the wide range of banks, insurers, and other financial services firms regulated by NYDFS, as it establishes a heightened standard that examiners will likely use to scrutinize compliance. Given that NYDFS cybersecurity standards often serve as a model for other state and federal regulators, the guidance may also influence compliance expectations well beyond New York.
…
Recent revisions to the SEC's Rule 14a-8 process have reportedly led to an increase in litigation over company decisions to exclude shareholder proposals from proxy materials.
Following the SEC's revision of its Rule 14a-8 process, a growing number of disputes over the exclusion of shareholder proposals are being resolved in court rather than through the agency's traditional no-action letter channel. This trend suggests that companies and shareholder proponents are increasingly willing to litigate over the rule's new interpretations.
For corporate counsel, this development changes the strategic calculus for responding to shareholder proposals. The shift from a largely administrative process to active litigation introduces greater costs, longer timelines, and heightened uncertainty. Companies that relied on securing SEC staff concurrence for exclusion may now face federal court challenges, requiring a different set of legal skills and risk assessments.
…
Florida's Attorney General has proposed legislation that would hold tech companies liable if their AI chatbots are used to facilitate criminal activity.
Florida Attorney General James Uthmeier has proposed legislation that would create liability for companies that own, control, or distribute artificial intelligence chatbots when those systems are involved in criminal activities. While specific details of the bill were not provided, the proposal targets the role of AI in facilitating crime, potentially moving beyond existing legal frameworks for intermediary liability.
This development is critical for technology companies and their counsel as it signals a potential major shift in risk allocation for AI products. If enacted, such a law could expose AI developers and providers to significant liability for the misuse of their technology by third-party users, a departure from traditional product liability standards. It would necessitate a re-evaluation of AI system safeguards, acceptable use policies, and user monitoring protocols. The law could also have a chilling effect on the development and deployment of open-source or less restricted AI models.
…
Recent federal appellate decisions clarify the plaintiff's burden to prove secrets are not readily ascertainable, the specificity required to identify a secret, and the DTSA's extraterritorial reach.
Three US Courts of Appeals recently issued significant decisions interpreting the federal Defend Trade Secrets Act (DTSA). The Ninth Circuit reversed a $57 million judgment, holding that the trial court improperly placed the burden on the defendant to prove alleged secrets were "readily ascertainable." Under the DTSA, the court clarified, the plaintiff bears the burden of proving its information was not readily ascertainable by proper means. In another case, the Fourth Circuit affirmed a preliminary injunction against a Dutch company, holding that the DTSA applies extraterritorially to conduct outside the US so long as an act furthering the offense was committed in the United States. Finally, the Eighth Circuit affirmed summary judgment against a plaintiff for failing to identify its alleged trade secrets with sufficient particularity, reinforcing that vague references to "customer information" are inadequate.
…
Contrary to a 2025 proposal that would have tightened registration requirements, the DOJ now indicates a final rule will "expand the availability of exemptions."
The Department of Justice has signaled an unexpected reversal in its approach to rulemaking under the Foreign Agents Registration Act (FARA). A January 2025 Notice of Proposed Rulemaking had proposed to narrow key exemptions, but a recent entry in the government’s Unified Agenda indicates the DOJ’s National Security Division is now considering a final rule that will "expand the availability of exemptions commonly relied upon by corporations and law firms."
…
A sweeping new UK law will significantly expand employee protections by reducing the qualifying period for unfair dismissal claims, removing the cap on awards, and imposing new duties on employers to prevent harassment.
The UK's Employment Rights Act 2025 is introducing one of the most significant reforms to national employment law in decades, with changes taking effect in phases through 2026 and 2027. Counsel for employers should note several key developments. From October 2026, the time limit for most tribunal claims will double to six months, and employers will face a stricter duty to take "all reasonable steps" to prevent sexual harassment, including by third parties like clients. In a major shift from January 2027, the qualifying service period for unfair dismissal protection will be cut from two years to just six months. The statutory cap on compensatory awards for unfair dismissal will also be eliminated entirely, increasing potential liability, especially in cases involving high earners. The law also strengthens trade union access rights and restricts "fire and rehire" tactics. Employers must review and update their contracts, handbooks, and management training to mitigate increased litigation risk and ensure compliance with the new regime.
Germany's financial regulator is requiring institutions to conduct due diligence on the end-users of virtual IBANs, anticipating a new EU-wide anti-money laundering framework that will codify these transparency obligations.
Germany's financial regulator, BaFin, has issued a supervisory statement requiring institutions to heighten their anti-money laundering (AML) scrutiny of virtual International Bank Account Numbers (IBANs). The guidance directs institutions to conduct risk-based due diligence on the actual end-users of virtual IBANs, not just on the formal holder of the primary "master account." BaFin views these products as carrying significant transparency risks that can facilitate illicit finance.
…
A proposed Digital Economy Law would empower Mexico's finance ministry to designate strategic sectors as cash-free and give the central bank new authority to regulate payment apps and terminals.
Mexico's president has submitted a draft Digital Economy Law to Congress to accelerate the country's transition away from cash. The bill, if passed, would grant the Ministry of Finance (SHCP) the power to designate "strategic sectors," such as gas stations or toll roads, where digital payments become the only acceptable form of payment. It would also compel financial institutions to accept new government-issued digital identity credentials for remote customer onboarding and contracting.
…
A multi-year overhaul of the Delaware General Corporation Law responds to recent Court of Chancery decisions, creating new statutory safe harbors for conflicted transactions and clarifying rules for M&A agreements and corporate governance.
Delaware has enacted significant amendments to its General Corporation Law (DGCL) over the past three years, largely in direct response to court decisions that had unsettled established market practices. The changes provide transactional and corporate governance lawyers with updated rules of the road. Key amendments from 2024 legislatively overrule recent case law by validating common stockholder governance agreements (reversing Moelis), permitting board approval of documents in 'substantially final' form (addressing Activision), and expressly allowing merger agreements to provide for lost-premium damages (clarifying Crispo).
…
A bill awaiting the governor's signature would retroactively eliminate the private right of action for thousands of class actions under California's CIPA.
The California Legislature has unanimously passed SB 690, a bill that would eliminate the private right of action for claims that common website and app tracking technologies function as illegal "pen registers" under the California Invasion of Privacy Act (CIPA). This legislation is a direct response to a surge of nearly 4,000 proposed class actions filed since early 2025 targeting companies for using tools like tracking pixels, cookies, and session-replay software.
For corporate counsel and their outside firms, this is a critical development. With statutory damages of up to $5,000 per violation, CIPA pen-register claims created enormous potential exposure. The bill, if signed into law, would apply retroactively to cases filed on or after January 1, 2025, potentially extinguishing thousands of pending lawsuits. It is important to note, however, that the bill is narrowly tailored and does not affect other CIPA claims, such as wiretapping allegations under § 631, which are often brought in the same complaints.
…
The head of the Federal Trade Commission has outlined five factors the agency will use to scrutinize the sale process of a financially distressed target in a merger, raising the bar for parties asserting the 'failing firm' defense.
In a statement prompted by a scuttled Ohio hospital merger, Federal Trade Commission Chairman Andrew Ferguson has detailed five factors the agency will scrutinize when evaluating the adequacy of a 'shop' process for a company asserting the 'failing firm' defense. The new guidance focuses on the third prong of the defense, which requires a good-faith effort to find an alternative buyer. The FTC will now explicitly assess whether the seller solicited a full set of potential buyers, gave them sufficient time and data for diligence, engaged in good-faith negotiations, and properly weighed less anticompetitive offers. This signals a more demanding standard for parties in all industries, not just healthcare. For sophisticated counsel, it means a pre-deal 'shop' process that is merely adequate may no longer suffice. Failure to conduct and document a robust and impartial search for alternative acquirers before signing with a direct competitor could prove fatal to a deal during the subsequent antitrust review, or at least cause significant delays and added expense.
The UK government has launched a consultation on wide-ranging reforms to the corporate reporting, distributable profits, and capital maintenance rules under the Companies Act 2006.
The UK government has published a consultation paper proposing what it calls a 'once-in-a-generation' overhaul of the country's corporate reporting framework. The proposals, issued by the Department for Business, Innovation, Science and Trade, aim to simplify the reporting landscape under the Companies Act 2006 and refocus disclosures on information that is financially material to investors and creditors. A key change under consideration is replacing the complex rules on distributable profits with a more straightforward solvency-based test for dividends. Other proposals include overhauling the strategic report, streamlining corporate governance and remuneration disclosures, and simplifying company-size thresholds. The reforms would affect a wide range of public and private UK companies by potentially reducing their compliance burden and altering how they report on strategy, governance, and shareholder distributions. The consultation period is open until November 30, 2026, and affected companies should review the proposals to assess their potential operational impact.
A multi-year overhaul of the Delaware General Corporation Law responds to recent Court of Chancery decisions, creating new statutory safe harbors for conflicted transactions and clarifying rules for M&A agreements and corporate governance.
Delaware has enacted significant amendments to its General Corporation Law (DGCL) over the past three years, largely in direct response to court decisions that had unsettled established market practices. The changes provide transactional and corporate governance lawyers with updated rules of the road. Key amendments from 2024 legislatively overrule recent case law by validating common stockholder governance agreements (reversing Moelis), permitting board approval of documents in 'substantially final' form (addressing Activision), and expressly allowing merger agreements to provide for lost-premium damages (clarifying Crispo).
…
New European Commission guidance clarifies the scope and compliance steps for the Cyber Resilience Act, emphasizing strict incident and vulnerability reporting deadlines.
The European Commission has published new guidance clarifying the scope and compliance obligations under the European Union’s expansive Cyber Resilience Act (CRA). This development is critical for any company manufacturing or selling products with digital components in the EU market. The guidance addresses key definitions and the act's reach, but legal commentators highlight the immediate challenge of its strict reporting timelines.
According to legal experts, companies are particularly focused on the requirements to report actively exploited vulnerabilities and severe security incidents to regulators within very short deadlines. The guidance also sheds light on the substantial effort required to meet the CRA’s vulnerability-testing and security-by-design mandates. Cloud services and cybersecurity providers, who may not be used to reporting to regulatory bodies, must now adapt their processes. Counsel should advise clients to promptly assess the CRA's applicability to their product portfolios and establish the necessary internal procedures for monitoring and reporting to ensure comp
…
New guidance from the New York Department of Financial Services details specific expectations for cybersecurity risk assessments required under its Part 500 regulations.
The New York Department of Financial Services (NYDFS) has published extensive new guidance for covered entities regarding the cybersecurity risk assessments required under 23 NYCRR Part 500. The guidance clarifies and significantly details the regulator’s expectations, providing a more granular framework than the original rule for how firms should identify and assess their cybersecurity risks.
This development is important for the wide range of banks, insurers, and other financial services firms regulated by NYDFS, as it establishes a heightened standard that examiners will likely use to scrutinize compliance. Given that NYDFS cybersecurity standards often serve as a model for other state and federal regulators, the guidance may also influence compliance expectations well beyond New York.
…
A new New York law taking effect November 8, 2026, requires employers to provide employees with copies of their personnel records within five business days of a request and to notify them of any new negative information.
New York has enacted a law requiring all public and private employers in the state to provide current and former employees with access to their personnel records. Signed by Governor Hochul, the legislation takes effect on November 8, 2026, and introduces several new compliance obligations that require immediate attention.
The law mandates that employers provide a copy of an employee's personnel record, at no cost, within five business days of a written request. It also requires employers to notify an employee within ten days of placing any information in their file that could negatively affect their employment status, compensation, or disciplinary standing. The definition of "personnel record" is broad, extending to certain records maintained by third-party HR and payroll vendors. The statute also establishes a process for employees to dispute information, sets record-retention requirements, and includes robust anti-retaliation protections.
…
New European Commission guidance on the Pay Transparency Directive clarifies the scope of covered employers and pay, but leaves significant ambiguity around determining work of equal value.
The European Commission has issued new guidance on the EU Pay Transparency Directive (2023/970), clarifying some obligations for employers but leaving other key areas unresolved. The guidance, presented as FAQs, confirms the directive's broad application to both public and private sector employers and specifies that initial pay information must be disclosed before a job interview, though not necessarily in the public job posting. It also provides a framework for what counts as "pay" and addresses the directive's interplay with GDPR, designating equal pay compliance a "public interest" that can justify data processing.
…
A new analysis offers guidance for US employers on balancing Title VII's protections for transgender employees with a shifting federal enforcement environment targeting certain DEI initiatives.
A new guide advises US employers on navigating the complex legal environment surrounding workplace protections for transgender employees. While the Supreme Court's 2020 decision in Bostock v. Clayton County still prohibits discrimination based on transgender status under Title VII, the guide highlights a growing tension with a shifting federal enforcement posture that scrutinizes certain diversity, equity, and inclusion (DEI) initiatives. This creates particular risks for federal contractors, who may face DOJ scrutiny or False Claims Act exposure for programs deemed to be "illegal DEI."
…
A sweeping new UK law will significantly expand employee protections by reducing the qualifying period for unfair dismissal claims, removing the cap on awards, and imposing new duties on employers to prevent harassment.
The UK's Employment Rights Act 2025 is introducing one of the most significant reforms to national employment law in decades, with changes taking effect in phases through 2026 and 2027. Counsel for employers should note several key developments. From October 2026, the time limit for most tribunal claims will double to six months, and employers will face a stricter duty to take "all reasonable steps" to prevent sexual harassment, including by third parties like clients. In a major shift from January 2027, the qualifying service period for unfair dismissal protection will be cut from two years to just six months. The statutory cap on compensatory awards for unfair dismissal will also be eliminated entirely, increasing potential liability, especially in cases involving high earners. The law also strengthens trade union access rights and restricts "fire and rehire" tactics. Employers must review and update their contracts, handbooks, and management training to mitigate increased litigation risk and ensure compliance with the new regime.
Federal bank regulators will now need to show a connection to material financial harm before taking supervisory or enforcement action based on an unsafe or unsound practice, a significant shift in the examination framework.
The Office of the Comptroller of the Currency (OCC) and the Federal Deposit Insurance Corporation (FDIC) have adopted a joint final rule that establishes a binding definition for an “unsafe or unsound practice” for the first time. Effective November 2, 2026, the rule institutes a two-part test requiring that conduct be contrary to generally accepted standards of prudent operation and also create a material risk of financial harm to the institution or the Deposit Insurance Fund. The Federal Reserve did not join the rulemaking but has issued separate, similar guidance.
…
Germany's financial regulator is requiring institutions to conduct due diligence on the end-users of virtual IBANs, anticipating a new EU-wide anti-money laundering framework that will codify these transparency obligations.
Germany's financial regulator, BaFin, has issued a supervisory statement requiring institutions to heighten their anti-money laundering (AML) scrutiny of virtual International Bank Account Numbers (IBANs). The guidance directs institutions to conduct risk-based due diligence on the actual end-users of virtual IBANs, not just on the formal holder of the primary "master account." BaFin views these products as carrying significant transparency risks that can facilitate illicit finance.
…
Mexico's president has introduced a legislative proposal to Congress aimed at regulating digital payments, establishing digital identities, and promoting cashless sectors.
On September 8, 2026, the President of Mexico submitted a proposed Digital Economy Law for Digital and Electronic Payments to the national Congress, signaling a major regulatory push to modernize the country's payment systems. The initiative aims to address key aspects of the digital ecosystem, including digital identity verification, rules for the acceptance of electronic payments, and the promotion of cashless transactions in certain sectors.
This proposed legislation could create significant new compliance obligations and market opportunities for financial institutions, e-commerce companies, payment processors, and other businesses with operations in Mexico. For sophisticated counsel and clients, the bill represents a critical development that could reshape the competitive landscape and require adjustments to existing business models. International companies will need to evaluate how the law, if passed, would affect their operations, customer interactions, and data-handling practices.
…
A proposed Digital Economy Law would empower Mexico's finance ministry to designate strategic sectors as cash-free and give the central bank new authority to regulate payment apps and terminals.
Mexico's president has submitted a draft Digital Economy Law to Congress to accelerate the country's transition away from cash. The bill, if passed, would grant the Ministry of Finance (SHCP) the power to designate "strategic sectors," such as gas stations or toll roads, where digital payments become the only acceptable form of payment. It would also compel financial institutions to accept new government-issued digital identity credentials for remote customer onboarding and contracting.
…
A critical materials supplier has secured a landmark $450M investment from a new defense economic unit, signaling a fresh government strategy to accelerate industrial production and secure supply chains.
Akin Gump advised The Elmet Group, a U.S. critical materials supplier, in securing a $450 million investment from the U.S. Department of War. The transaction is described as a pioneer deal under the department's newly established Economic Defense Unit, which was created to accelerate domestic defense production. Separately, an Elmet subsidiary was awarded an indefinite delivery/indefinite quantity contract with a ceiling of $2 billion to help rebuild the U.S. National Defense Stockpile's tungsten supply. As a condition, Elmet adopted a compliance plan to prevent 'restricted entities' from acquiring a significant stake. Sophisticated counsel should see this as a template for a new, well-funded government strategy to onshore critical supply chains. The creation of the dedicated unit suggests a more proactive government role in private-sector industrial capacity. Clients in the defense, manufacturing, and technology sectors should monitor this unit's activities for funding opportunities and be prepared for novel compliance obligations, like the ownership restrictions seen here.
Federal and state agencies are stepping up enforcement actions against telehealth platforms and wellness clinics, focusing on standard-of-care violations, marketing claims, and prescribing practices.
Federal agencies and state medical boards are escalating enforcement against the burgeoning wellness industry, targeting telehealth platforms, IV therapy bars, ketamine clinics, and weight-management providers. This heightened scrutiny follows the expiration of many pandemic-era telehealth prescribing flexibilities, exposing a range of compliance gaps. Regulators are focusing on standard-of-care violations, improper supervision of non-physician practitioners, unsubstantiated marketing claims targeted by the FTC, and DEA requirements for prescribing controlled substances like ketamine. For innovative health platforms, especially those using direct-to-consumer and cash-pay models, the risks include significant civil penalties, license discipline, and operational disruption. The trend signals a tougher environment for a high-growth sector. Counsel should advise clients to promptly conduct comprehensive compliance assessments of their prescribing and marketing protocols, provider licensing, data privacy practices, and corporate structures to mitigate exposure to this coordinated multi-ju
…
The U.S. Court of Appeals for the Federal Circuit will soon have an opportunity to limit the application of obviousness-type double patenting, a move that could simplify patent law and incentivize follow-on innovation.
The U.S. Court of Appeals for the Federal Circuit is poised to consider a significant limitation on the doctrine of obviousness-type double patenting (OTDP), a complex, judicially created concept in U.S. patent law. The core issue is whether the doctrine, which prevents an inventor from improperly extending patent exclusivity with claims that are not patentably distinct from those in an earlier patent, should apply only when a patent's term has been artificially extended.
…
A Dubai International Financial Centre court set aside an entire arbitral award for the first time after finding the tribunal decided the case on legal arguments the parties themselves had never raised.
The Dubai International Financial Centre (DIFC) Court of First Instance has set aside a Dubai International Arbitration Centre (DIAC) arbitral award in its entirety, finding the tribunal decided the dispute on legal grounds that had not been pleaded or argued by the parties. In Princeton v Persephone, the court held that the tribunal's reliance on unargued theories of waiver and estoppel denied the applicant a reasonable opportunity to present its case, a fundamental tenet of procedural fairness.
…
A bill awaiting the governor's signature would retroactively eliminate the private right of action for thousands of class actions under California's CIPA.
The California Legislature has unanimously passed SB 690, a bill that would eliminate the private right of action for claims that common website and app tracking technologies function as illegal "pen registers" under the California Invasion of Privacy Act (CIPA). This legislation is a direct response to a surge of nearly 4,000 proposed class actions filed since early 2025 targeting companies for using tools like tracking pixels, cookies, and session-replay software.
For corporate counsel and their outside firms, this is a critical development. With statutory damages of up to $5,000 per violation, CIPA pen-register claims created enormous potential exposure. The bill, if signed into law, would apply retroactively to cases filed on or after January 1, 2025, potentially extinguishing thousands of pending lawsuits. It is important to note, however, that the bill is narrowly tailored and does not affect other CIPA claims, such as wiretapping allegations under § 631, which are often brought in the same complaints.
…
Manufacturers of connected products sold in the EU must now report actively exploited vulnerabilities and severe security incidents within 24 hours of awareness, with potential fines of up to €15 million or 2.5% of global turnover.
The EU's Cyber Resilience Act (CRA) reporting regime took effect on September 11, 2026, imposing stringent new obligations on manufacturers of connected products. The act covers a vast range of "products with digital elements" (PDEs), including software, hardware, and IoT devices, that are made available on the EU market. The key change is an exceptionally fast reporting timeline: manufacturers must provide an "early warning" to the EU's cybersecurity agency (ENISA) and national authorities within 24 hours of becoming aware of either an actively exploited vulnerability or a severe security incident impacting their product. A more detailed notification is required within 72 hours.
…
New FCC rules prohibit equipment authorization for end products containing 'covered' hardware components and impose verification duties on e-commerce platforms.
The Federal Communications Commission (FCC) has significantly expanded its equipment authorization prohibitions to further secure U.S. communications supply chains. Under a new Third Report and Order, the FCC will now deny authorization to any end product containing "logic-bearing hardware components," such as chipsets, produced by an entity on its national-security Covered List. This rule applies regardless of whether the final product manufacturer itself is on the list, creating substantial new diligence obligations for technology companies.
…
Contrary to a 2025 proposal that would have tightened registration requirements, the DOJ now indicates a final rule will "expand the availability of exemptions."
The Department of Justice has signaled an unexpected reversal in its approach to rulemaking under the Foreign Agents Registration Act (FARA). A January 2025 Notice of Proposed Rulemaking had proposed to narrow key exemptions, but a recent entry in the government’s Unified Agenda indicates the DOJ’s National Security Division is now considering a final rule that will "expand the availability of exemptions commonly relied upon by corporations and law firms."
…
The Treasury Department expanded secondary sanctions to Iran's aviation, tech, and shipping sectors, suspended general licenses, and designated third-country banks for facilitating Iranian transactions, creating broad new compliance risks.
The U.S. government has unveiled a significant expansion of its Iran sanctions program, creating new risks for companies operating globally. In a series of actions, the Treasury's Office of Foreign Assets Control (OFAC) authorized the imposition of secondary sanctions on entities involved with Iran's aviation, technology, digital asset, gold, and shipping sectors. This move exposes non-U.S. persons to potential U.S. sanctions for transacting with these sectors, even with no other U.S. nexus. The measures also include the designation of nearly 60 new parties, the suspension of several general licenses, and a new policy of presumptive denial for most specific license applications.
…
New regulations effective September 29 restore prohibitions on Iran's shipping, aviation, oil, and gas sectors, creating significant new compliance burdens for maritime and financial firms.
The United Kingdom will reimpose extensive sectoral sanctions against Iran on September 29, 2026, re-establishing prohibitions previously lifted under the Joint Comprehensive Plan of Action (JCPOA). The new rules create significant compliance challenges, particularly for the global maritime industry, by introducing powers to designate 'specified ships' and banning their charter, operation, and servicing. The regulations also broadly prohibit providing insurance or reinsurance to any person 'connected with Iran' and restrict port access for designated vessels. Further financial measures bar UK institutions from activities like opening accounts for or establishing correspondent banking relationships with Iranian counterparts. While the direct impact on aviation is narrower, targeting specific cargo aircraft, the overall regulatory shift requires clients in the shipping, energy, insurance, and banking sectors to urgently review their Iran exposure. Counsel should advise on enhanced diligence for vessels and counterparties and assess existing contracts before the imminent effective date.
The US Securities and Exchange Commission has proposed "Regulation Crypto Assets," a new framework that would create two new offering exemptions and a safe harbor for certain investment contracts involving digital assets.
The US Securities and Exchange Commission (SEC) has proposed "Regulation Crypto Assets," a new and comprehensive framework for offerings of certain crypto assets deemed to be securities. The proposal distinguishes between a crypto asset and the "covered investment contract" to which it is subject, applying only when the asset itself is not a security like tokenized equity.
The proposed rules establish two new transactional exemptions from registration. A "startup exemption" would permit offerings up to $5 million over four years with streamlined, website-based disclosures. A tiered "fundraising exemption," modeled on Regulation A, would allow for offerings of up to $20 million (Tier 1) or $75 million (Tier 2) in a 12-month period, with ongoing reporting obligations.
…
The Securities and Exchange Commission has released a proposed update to the rules for registered transfer agents to reflect technological advancements, including the use of blockchain.
The SEC has proposed a comprehensive update to the rules governing registered transfer agents, marking the first major overhaul in this area in decades. The proposal aims to modernize regulations to account for technological changes, including electronic recordkeeping, uncertificated securities, and the use of blockchain or distributed ledger technology. Key changes would update requirements for processing times, risk management, business continuity planning, and the safeguarding of securities and funds. For clients in the financial services and technology sectors, this is a critical development. The rules could pave a clearer regulatory path for issuing and transferring tokenized securities, while also imposing new operational and compliance burdens on transfer agents. Counsel should advise affected clients to closely review the proposed rule changes, assess their potential impact on current and future business operations, and consider submitting comments to the SEC during the public comment period.
The SEC has proposed the first comprehensive update to transfer agent regulations in decades, seeking to address technological advancements and impose new standards for risk management and compliance.
The U.S. Securities and Exchange Commission has proposed a comprehensive overhaul of the rules governing registered transfer agents, which have not been substantively updated in over 40 years. The proposal aims to modernize the regulatory framework to reflect significant technological advancements in securities recordkeeping, including the use of electronic communications and blockchain or distributed ledger technology. Key elements of the proposal include new requirements for transfer agents to establish and maintain written risk management and compliance policies, new standards for processing securities transfers and removing restrictive legends, and updated rules for handling inactive securityholder accounts. For public companies and other issuers, these changes could impact how their securities are transferred and serviced. The proposal will directly affect the operations of all registered transfer agents, requiring investment in new systems and compliance protocols. The SEC will accept public comments for 60 days after the proposal is published in the Federal Register.
Recent revisions to the SEC's Rule 14a-8 process have reportedly led to an increase in litigation over company decisions to exclude shareholder proposals from proxy materials.
Following the SEC's revision of its Rule 14a-8 process, a growing number of disputes over the exclusion of shareholder proposals are being resolved in court rather than through the agency's traditional no-action letter channel. This trend suggests that companies and shareholder proponents are increasingly willing to litigate over the rule's new interpretations.
For corporate counsel, this development changes the strategic calculus for responding to shareholder proposals. The shift from a largely administrative process to active litigation introduces greater costs, longer timelines, and heightened uncertainty. Companies that relied on securing SEC staff concurrence for exclusion may now face federal court challenges, requiring a different set of legal skills and risk assessments.
…
Two House committees are investigating the national security, cybersecurity, and economic risks of U.S. companies integrating AI models developed by PRC-based entities.
Two U.S. House committees are jointly investigating American companies for their use of AI models developed in the People's Republic of China, citing significant national security, cybersecurity, and economic stability risks. The inquiry focuses on allegations that Chinese AI labs used techniques like “adversarial distillation” to extract capabilities from U.S. models, potentially without their safety guardrails against malicious use.
Corporate counsel should note that Anysphere (developer of the Cursor coding platform), Airbnb, and DoorDash have already received detailed inquiry letters demanding internal documents, data policies, vendor agreements, and in-person briefings. The development signals a new front in U.S.-China tech scrutiny with serious compliance and reputational stakes for any company using third-party AI, particularly lower-cost foreign alternatives that handle user data. Clients should proactively assess their vendor contracts, data security protocols, and customer disclosures related to foreign-developed AI. The key development to watch is whether the investigatio
…
Florida's Attorney General has proposed legislation that would hold tech companies liable if their AI chatbots are used to facilitate criminal activity.
Florida Attorney General James Uthmeier has proposed legislation that would create liability for companies that own, control, or distribute artificial intelligence chatbots when those systems are involved in criminal activities. While specific details of the bill were not provided, the proposal targets the role of AI in facilitating crime, potentially moving beyond existing legal frameworks for intermediary liability.
This development is critical for technology companies and their counsel as it signals a potential major shift in risk allocation for AI products. If enacted, such a law could expose AI developers and providers to significant liability for the misuse of their technology by third-party users, a departure from traditional product liability standards. It would necessitate a re-evaluation of AI system safeguards, acceptable use policies, and user monitoring protocols. The law could also have a chilling effect on the development and deployment of open-source or less restricted AI models.
…
A decade after its enactment, the Defend Trade Secrets Act has increased federal filings but also created significant circuit splits on pleading standards, damages, and other key issues.
A decade after its passage, the Defend Trade Secrets Act (DTSA) has successfully shifted more trade secret litigation into federal court but has failed to create the single, national standard Congress envisioned. Analysis of the statute's first ten years reveals significant and unresolved circuit splits on fundamental issues, creating strategic complexity for businesses. For example, courts are divided on how specifically a plaintiff must identify an alleged trade secret at the pleading stage and whether a defendant's "avoided costs" can be recovered as unjust-enrichment damages without the plaintiff proving its own corresponding loss. The Seventh Circuit has also endorsed a broad extraterritorial reach for the statute, a position not yet tested elsewhere, creating further uncertainty for global companies. Looking ahead, the rise of artificial intelligence presents new challenges, raising questions about whether AI-generated output can be a trade secret and what security measures are now considered "reasonable." Businesses should monitor these splits and emerging AI-related doctrines
…
Recent federal appellate decisions clarify the plaintiff's burden to prove secrets are not readily ascertainable, the specificity required to identify a secret, and the DTSA's extraterritorial reach.
Three US Courts of Appeals recently issued significant decisions interpreting the federal Defend Trade Secrets Act (DTSA). The Ninth Circuit reversed a $57 million judgment, holding that the trial court improperly placed the burden on the defendant to prove alleged secrets were "readily ascertainable." Under the DTSA, the court clarified, the plaintiff bears the burden of proving its information was not readily ascertainable by proper means. In another case, the Fourth Circuit affirmed a preliminary injunction against a Dutch company, holding that the DTSA applies extraterritorially to conduct outside the US so long as an act furthering the offense was committed in the United States. Finally, the Eighth Circuit affirmed summary judgment against a plaintiff for failing to identify its alleged trade secrets with sufficient particularity, reinforcing that vague references to "customer information" are inadequate.
…
Maryland's attorney general has sued Optum and parent UnitedHealth Group, alleging a failed claims-processing system led to over $126 million in improper payments and years of provider audits.
Maryland’s attorney general has sued Optum and its parent, UnitedHealth Group, over a catastrophic failure of the state's behavioral health Medicaid claims system. The complaint alleges the state paid Optum more than $126 million for a system that never became fully functional after the company secretly substituted an untested software platform for the robust system promised in its contract. The system crashed upon its 2020 launch, forcing the state to issue $1.6 billion in emergency estimated payments to providers to prevent a total collapse of the payment infrastructure.
…
Grade 3 — worth a glance, not the full analysis.
- Connecticut Mandates Pay and Benefits Disclosure in Job Postings
Beginning October 1, 2026, all internal and external job postings for employers in Connecticut must include the position's wage range and a general description of benefits.
- UK Pensions Regulator Unveils New Enforcement Strategy
The UK's Pensions Regulator has published its evolved enforcement approach, prioritizing high-impact and high-scale cases while emphasizing earlier intervention and human decision-making.
- Fannie Mae and Freddie Mac expand VantageScore 4.0 to all lenders
GSEs announce immediate expansion of VantageScore 4.0 from pilot to all approved sellers for single-family mortgage origination, with updated pricing and automated underwriting systems.
- US Agencies Clarify Banks Can Use Digital IDs for Identity Checks
Federal financial regulators have issued joint guidance confirming that banks and credit unions may accept mobile driver's licenses and other verifiable digital credentials to satisfy Customer Identification Program requirements.
- SEC proposes rescinding pay-to-play rule for investment advisers
The SEC has proposed eliminating Rule 206(4)-5, the 15-year-old restriction on political contributions by advisers to government clients, citing unintended consequences including blanket bans on employee political giving.
- Data Center Leases Evolve into Hybrid Tech Agreements
Driven by AI and global scaling, data center leases are shifting from traditional property contracts to hybrid MSA structures that blend real estate and technology service terms.
- Proposed Rule Targets Private School Nondiscrimination
A newly proposed federal rule aims to expand nondiscrimination requirements for private schools in areas including admissions and financial aid programs.
- New York Amends Clinical Laboratory, Blood Bank Regulations
The NY State Department of Health has amended regulations for clinical laboratories and blood banks, aligning them with federal CLIA standards and imposing new requirements for director qualifications, personnel, and operational oversight.
- New York Enacts Employee Access to Personnel Files Law
New York employers must provide personnel record copies within five business days of written request and notify employees within ten days of adding negative information under a new law taking effect November 8, 2026.
- PTAB institutes four IPRs against Janssen Simponi patents in biosimilar dispute
PTAB Director instituted four inter partes reviews challenging Janssen's Simponi golimumab patents brought by biosimilar makers Accord and Bio-Thera, tied to ongoing BPCIA litigation with $1.2B at stake.
- EU Forced Labour Regulation compliance roadmap published
Mayer Brown releases practical guidance for companies to comply with the EU's forced labour regulation, which bans products made with forced labour from entering the EU market.
- Mass AG seeks permanent bar on debt buyer over deceptive practices
Massachusetts AG filed a consent judgment to permanently bar a debt buyer and its operator from collection activity, alleging violations including unlicensed collection, misrepresenting creditor identities, and collecting time-barred debts.
- DOL Bars Managers from Tip Pools, Even for Tipped Shifts
A new Department of Labor opinion letter confirms that employees who qualify as supervisors under the FLSA's duties test cannot participate in a tip-sharing arrangement, regardless of whether they also perform tipped work like bartending.
- Banking regulators propose third-party risk management guidance
FDIC, Federal Reserve, NCUA, and OCC seek comment on proposed guidance to help financial institutions manage risks associated with third-party relationships, including community bank engagement with core service providers.
- Connecticut fines EWA provider $200K for unlicensed small loans
The Connecticut Banking Department ordered an earned wage access provider to pay a $200,000 civil penalty and reimburse borrower fees since January 2024 for operating without a required small loan company license.
- FTC, Connecticut Finalize $4M 'Junk Fee' Dealership Settlement
A Connecticut car dealership will pay $4 million and overhaul its pricing disclosures to resolve joint federal and state allegations of charging consumers unauthorized fees.
- Mitigating Growing Dispute Risk in Data Center Builds
A new guide outlines proactive contractual and administrative strategies to prevent and manage conflicts arising from data center construction and operation.
- Texas SB 140 Text Message Marketing Compliance Remains Unclear
One year after Texas SB 140 expanded telemarketing rules to text messages, the state's position allows consent-based messaging without Chapter 302 registration, but no binding court precedent exists to confirm this interpretation.
- Congress probes Economy Act use as executive spending tool
House appropriators will examine interagency agreements and whether Congress is losing visibility into executive branch spending through Economy Act authorities.
- California Supreme Court boosts judicial review in private utility condemnations
In Town of Apple Valley v. Apple Valley Ranchos Water, the court held that trial courts must independently weigh evidence when private utilities challenge condemnations, departing from prior deferential review.
- FMC allows charge complaints via traditional processes not just interim email
The Federal Maritime Commission's September 2026 rule confirms shippers can pursue demurrage and detention charge complaints through formal or small claims procedures while retaining OSRA's favorable burden-shifting framework.
- AI Data Center Boom Creates New Power Litigation Risks
An analysis examines the contractual and litigation risks that arise when promised power supplies for new, energy-intensive AI data centers are delayed or fail to materialize.
- Court Rejects Class Certification in Mortgage Rate-Lock Fee Case
A California federal court found individual questions about who caused loan-closing delays predominated over common issues for a proposed class of 350,000 borrowers.
- Minnesota AG sues over predatory contract-for-deed "reverse redlining"
Minnesota's attorney general filed a complaint alleging a company used predatory seller-financed contracts for deed to target a religious and ethnic community, violating TILA, ECOA, CFPA and Minnesota state laws.
- FTC settles $12M with processor for facilitating billing scams
The FTC obtained a $12M settlement from a payment processor for knowingly processing $100M+ through 1,000+ shell entities used as fronts for unauthorized billing scams.
- SDNY Favors State Creditor Assignment Over Chapter 11
A Southern District of New York bankruptcy court dismissed two law firms' Chapter 11 cases, deferring to a pending state-law assignment for the benefit of creditors and offering new guidance on the choice between the two proceedings.
- Court Denies MSJ in FCRA 'Dispute Flag' Case
An Illinois federal court ruled a mortgage servicer could have willfully violated the FCRA by not flagging indirect credit disputes, holding that following industry guidance does not excuse statutory non-compliance.
- EPA grants 18 small refinery exemptions, reallocates more RINs
EPA's August 2026 decisions on 34 small refinery exemption petitions for 2025 resulted in 1.76 million RINs exempted, with the agency now planning to reallocate 100% of exempted volumes to 2026-2027 obligations.
- Ontario Court Shields Layoff Clauses From Waksdale Rule
Ontario's Court of Appeal held that an ESA-compliant temporary layoff clause is not a termination provision and remains enforceable even if another termination clause in the same contract is invalid.
- UK Court Upholds FLOWERBX Trademark Against 'Descriptive' Challenge
The High Court of England and Wales found the FLOWERBX mark, though phonetically identical to "flower box," is inherently distinctive and was infringed by a competitor.
- CPPA Targets Inaccurate Data Broker Registrations
California's privacy agency has issued an enforcement advisory warning data brokers that even unintentional errors in their annual registration disclosures can trigger daily fines of $200.
- California Employment Bills Await Governor's Decision
California employers face potential new AI disclosure, bereavement leave, and workplace surveillance requirements as Governor Newsom weighs pending legislation.
- New Jersey Changes HCSF Registration and Reporting Rules
Health care service firms providing services in New Jersey face a new Sept. 30 registration deadline and temporarily suspended financial reporting rules under a new state law.
- Texas Comptroller May Reverse Data Processing Tax Rules
Texas Comptroller Don Huffines signals willingness to revisit aggressive data processing tax interpretations following business community criticism.
- Guide to Key Risks in Student-Housing P3s
A new guide outlines key considerations for universities in public-private partnerships for student housing, emphasizing institutional control over rates and assignments.
- CARB Extends SB 253 Climate Reporting Deadline to November 2026
CARB's proposed 15-day modifications to California's climate disclosure rules delay the first SB 253 reporting deadline and provide first-year reporting flexibility for companies newly subject to emissions disclosure.
- ESMA shifts to annex-based test for prospectus supplements
ESMA's new Guidelines replace a principles-based approach with a prescriptive annex-based test determining when a prospectus supplement introduces a new type of security requiring a fresh base prospectus.
- Texas Court Dismisses Patent Suit for Deficient Claim Charts
A federal court in Texas dismissed a patent infringement complaint against Apple, finding its claim charts were conclusory and failed to plead sufficient facts under Twombly/Iqbal.
- Alaska Takes RCRA Hazardous Waste Primacy
Alaska is now the primary regulator for hazardous waste permits and enforcement, shifting day-to-day authority from EPA Region 10 to the Alaska Department of Environmental Conservation.
- ITC Offers Fast Trade Secret Relief via Exclusion Orders
Trade secret owners seeking to block infringing imports may find the ITC's Section 337 process faster than federal court, averaging 14 months versus 2+ years to summary judgment.
- Day-1 Preferred Equity for Horizontal Rated Note Feeders
A law firm guide explains a structuring technique using day-1 preferred equity in horizontal rated note feeder transactions, relevant for CLO and securitization specialists.
- GAO urges Congress to fix bank disclosure oversight gaps
GAO report finds 11 public banks lack SEC disclosure review due to no holding company structure, with regulators' reviews lacking qualitative investor protection assessment.
- NY court applies earth movement exclusion to adjacent construction damage
New York Supreme Court dismissed an insured's claim for cracking and settlement damage caused by neighboring construction, holding the loss fell squarely within the policy's earth movement exclusion.
- US cargo mandate in FY2027 NDAA would require US-flag shipping
The House-passed provision would mandate that covered shippers ensure 3%+ of imported cargo arrives on US-flag vessels, with penalties of at least 10% of cargo value for non-compliance.