Cicero Intelligent Minds

DROPLETS

AmLaw 100 Legal Intelligence — Distilled
Tuesday, September 15, 202632 featured44 also noted32 firms17 practice areasgrade 3–5
Quick Scan — Why It Matters
Akin GumpPrivacy / Data Security+ Expand
California Legislature Passes Bill to Kill Website Tracking Lawsuits

A bill awaiting the governor's signature would retroactively eliminate the private right of action for thousands of class actions under California's CIPA.

The California Legislature has unanimously passed SB 690, a bill that would eliminate the private right of action for claims that common website and app tracking technologies function as illegal "pen registers" under the California Invasion of Privacy Act (CIPA). This legislation is a direct response to a surge of nearly 4,000 proposed class actions filed since early 2025 targeting companies for using tools like tracking pixels, cookies, and session-replay software.

For corporate counsel and their outside firms, this is a critical development. With statutory damages of up to $5,000 per violation, CIPA pen-register claims created enormous potential exposure. The bill, if signed into law, would apply retroactively to cases filed on or after January 1, 2025, potentially extinguishing thousands of pending lawsuits. It is important to note, however, that the bill is narrowly tailored and does not affect other CIPA claims, such as wiretapping allegations under § 631, which are often brought in the same complaints.

Read the full dispatch →
DLA PiperSecurities / Capital Markets+ Expand
SEC Proposes Tailored Registration Exemptions for Crypto Assets

The US Securities and Exchange Commission has proposed "Regulation Crypto Assets," a new framework that would create two new offering exemptions and a safe harbor for certain investment contracts involving digital assets.

The US Securities and Exchange Commission (SEC) has proposed "Regulation Crypto Assets," a new and comprehensive framework for offerings of certain crypto assets deemed to be securities. The proposal distinguishes between a crypto asset and the "covered investment contract" to which it is subject, applying only when the asset itself is not a security like tokenized equity.

The proposed rules establish two new transactional exemptions from registration. A "startup exemption" would permit offerings up to $5 million over four years with streamlined, website-based disclosures. A tiered "fundraising exemption," modeled on Regulation A, would allow for offerings of up to $20 million (Tier 1) or $75 million (Tier 2) in a 12-month period, with ongoing reporting obligations.

Read the full dispatch →
Skadden, Arps, Slate, Meagher & FlomSanctions / Export Controls+ Expand
US Expands Iran Sanctions, Targeting New Sectors and Foreign Banks

The Treasury Department expanded secondary sanctions to Iran's aviation, tech, and shipping sectors, suspended general licenses, and designated third-country banks for facilitating Iranian transactions, creating broad new compliance risks.

The U.S. government has unveiled a significant expansion of its Iran sanctions program, creating new risks for companies operating globally. In a series of actions, the Treasury's Office of Foreign Assets Control (OFAC) authorized the imposition of secondary sanctions on entities involved with Iran's aviation, technology, digital asset, gold, and shipping sectors. This move exposes non-U.S. persons to potential U.S. sanctions for transacting with these sectors, even with no other U.S. nexus. The measures also include the designation of nearly 60 new parties, the suspension of several general licenses, and a new policy of presumptive denial for most specific license applications.

Read the full dispatch →
DLA PiperFinancial Regulation+ Expand
OCC, FDIC Define 'Unsafe or Unsound Practice' in Final Rule

Federal bank regulators will now need to show a connection to material financial harm before taking supervisory or enforcement action based on an unsafe or unsound practice, a significant shift in the examination framework.

The Office of the Comptroller of the Currency (OCC) and the Federal Deposit Insurance Corporation (FDIC) have adopted a joint final rule that establishes a binding definition for an “unsafe or unsound practice” for the first time. Effective November 2, 2026, the rule institutes a two-part test requiring that conduct be contrary to generally accepted standards of prudent operation and also create a material risk of financial harm to the institution or the Deposit Insurance Fund. The Federal Reserve did not join the rulemaking but has issued separate, similar guidance.

Read the full dispatch →
K&L GatesLitigation / Appellate+ Expand
DIFC Court Annuls DIAC Award for Unpleaded Reasoning

A Dubai International Financial Centre court set aside an entire arbitral award for the first time after finding the tribunal decided the case on legal arguments the parties themselves had never raised.

The Dubai International Financial Centre (DIFC) Court of First Instance has set aside a Dubai International Arbitration Centre (DIAC) arbitral award in its entirety, finding the tribunal decided the dispute on legal grounds that had not been pleaded or argued by the parties. In Princeton v Persephone, the court held that the tribunal's reliance on unargued theories of waiver and estoppel denied the applicant a reasonable opportunity to present its case, a fundamental tenet of procedural fairness.

Read the full dispatch →
BakerHostetlerSecurities / Capital Markets+ Expand
SEC Proposes Modernizing Transfer Agent Rules for Digital Assets

The Securities and Exchange Commission has released a proposed update to the rules for registered transfer agents to reflect technological advancements, including the use of blockchain.

The SEC has proposed a comprehensive update to the rules governing registered transfer agents, marking the first major overhaul in this area in decades. The proposal aims to modernize regulations to account for technological changes, including electronic recordkeeping, uncertificated securities, and the use of blockchain or distributed ledger technology. Key changes would update requirements for processing times, risk management, business continuity planning, and the safeguarding of securities and funds. For clients in the financial services and technology sectors, this is a critical development. The rules could pave a clearer regulatory path for issuing and transferring tokenized securities, while also imposing new operational and compliance burdens on transfer agents. Counsel should advise affected clients to closely review the proposed rule changes, assess their potential impact on current and future business operations, and consider submitting comments to the SEC during the public comment period.

Read the full dispatch →
Goodwin ProcterSecurities / Capital Markets+ Expand
SEC Proposes to Modernize Transfer Agent Rules

The SEC has proposed the first comprehensive update to transfer agent regulations in decades, seeking to address technological advancements and impose new standards for risk management and compliance.

The U.S. Securities and Exchange Commission has proposed a comprehensive overhaul of the rules governing registered transfer agents, which have not been substantively updated in over 40 years. The proposal aims to modernize the regulatory framework to reflect significant technological advancements in securities recordkeeping, including the use of electronic communications and blockchain or distributed ledger technology. Key elements of the proposal include new requirements for transfer agents to establish and maintain written risk management and compliance policies, new standards for processing securities transfers and removing restrictive legends, and updated rules for handling inactive securityholder accounts. For public companies and other issuers, these changes could impact how their securities are transferred and serviced. The proposal will directly affect the operations of all registered transfer agents, requiring investment in new systems and compliance protocols. The SEC will accept public comments for 60 days after the proposal is published in the Federal Register.

Read the full dispatch →
Seyfarth ShawEmployment / Labor+ Expand
NY Enacts Employee Personnel File Access Law

A new New York law taking effect November 8, 2026, requires employers to provide employees with copies of their personnel records within five business days of a request and to notify them of any new negative information.

New York has enacted a law requiring all public and private employers in the state to provide current and former employees with access to their personnel records. Signed by Governor Hochul, the legislation takes effect on November 8, 2026, and introduces several new compliance obligations that require immediate attention.

The law mandates that employers provide a copy of an employee's personnel record, at no cost, within five business days of a written request. It also requires employers to notify an employee within ten days of placing any information in their file that could negatively affect their employment status, compensation, or disciplinary standing. The definition of "personnel record" is broad, extending to certain records maintained by third-party HR and payroll vendors. The statute also establishes a process for employees to dispute information, sets record-retention requirements, and includes robust anti-retaliation protections.

Read the full dispatch →
Holland & KnightHealthcare+ Expand
Regulators Increase Scrutiny of Wellness and Telehealth Providers

Federal and state agencies are stepping up enforcement actions against telehealth platforms and wellness clinics, focusing on standard-of-care violations, marketing claims, and prescribing practices.

Federal agencies and state medical boards are escalating enforcement against the burgeoning wellness industry, targeting telehealth platforms, IV therapy bars, ketamine clinics, and weight-management providers. This heightened scrutiny follows the expiration of many pandemic-era telehealth prescribing flexibilities, exposing a range of compliance gaps. Regulators are focusing on standard-of-care violations, improper supervision of non-physician practitioners, unsubstantiated marketing claims targeted by the FTC, and DEA requirements for prescribing controlled substances like ketamine. For innovative health platforms, especially those using direct-to-consumer and cash-pay models, the risks include significant civil penalties, license discipline, and operational disruption. The trend signals a tougher environment for a high-growth sector. Counsel should advise clients to promptly conduct comprehensive compliance assessments of their prescribing and marketing protocols, provider licensing, data privacy practices, and corporate structures to mitigate exposure to this coordinated multi-ju

Read the full dispatch →
White & CaseFintech / Crypto+ Expand
Mexico Proposes Comprehensive Digital Economy and Payments Law

Mexico's president has introduced a legislative proposal to Congress aimed at regulating digital payments, establishing digital identities, and promoting cashless sectors.

On September 8, 2026, the President of Mexico submitted a proposed Digital Economy Law for Digital and Electronic Payments to the national Congress, signaling a major regulatory push to modernize the country's payment systems. The initiative aims to address key aspects of the digital ecosystem, including digital identity verification, rules for the acceptance of electronic payments, and the promotion of cashless transactions in certain sectors.

This proposed legislation could create significant new compliance obligations and market opportunities for financial institutions, e-commerce companies, payment processors, and other businesses with operations in Mexico. For sophisticated counsel and clients, the bill represents a critical development that could reshape the competitive landscape and require adjustments to existing business models. International companies will need to evaluate how the law, if passed, would affect their operations, customer interactions, and data-handling practices.

Read the full dispatch →
Foley & LardnerIP / Patent+ Expand
Federal Circuit to Revisit Obviousness-Type Double Patenting Doctrine

The U.S. Court of Appeals for the Federal Circuit will soon have an opportunity to limit the application of obviousness-type double patenting, a move that could simplify patent law and incentivize follow-on innovation.

The U.S. Court of Appeals for the Federal Circuit is poised to consider a significant limitation on the doctrine of obviousness-type double patenting (OTDP), a complex, judicially created concept in U.S. patent law. The core issue is whether the doctrine, which prevents an inventor from improperly extending patent exclusivity with claims that are not patentably distinct from those in an earlier patent, should apply only when a patent's term has been artificially extended.

Read the full dispatch →
Goodwin ProcterTrade Secrets+ Expand
DTSA at 10: Uniform Standard Remains Elusive Amid Circuit Splits

A decade after its enactment, the Defend Trade Secrets Act has increased federal filings but also created significant circuit splits on pleading standards, damages, and other key issues.

A decade after its passage, the Defend Trade Secrets Act (DTSA) has successfully shifted more trade secret litigation into federal court but has failed to create the single, national standard Congress envisioned. Analysis of the statute's first ten years reveals significant and unresolved circuit splits on fundamental issues, creating strategic complexity for businesses. For example, courts are divided on how specifically a plaintiff must identify an alleged trade secret at the pleading stage and whether a defendant's "avoided costs" can be recovered as unjust-enrichment damages without the plaintiff proving its own corresponding loss. The Seventh Circuit has also endorsed a broad extraterritorial reach for the statute, a position not yet tested elsewhere, creating further uncertainty for global companies. Looking ahead, the rise of artificial intelligence presents new challenges, raising questions about whether AI-generated output can be a trade secret and what security measures are now considered "reasonable." Businesses should monitor these splits and emerging AI-related doctrines

Read the full dispatch →
McDermott Will & EmeryAntitrust / Competition+ Expand
FTC Details Scrutiny of 'Shop' Process for Failing Firm Defense

The head of the Federal Trade Commission has outlined five factors the agency will use to scrutinize the sale process of a financially distressed target in a merger, raising the bar for parties asserting the 'failing firm' defense.

In a statement prompted by a scuttled Ohio hospital merger, Federal Trade Commission Chairman Andrew Ferguson has detailed five factors the agency will scrutinize when evaluating the adequacy of a 'shop' process for a company asserting the 'failing firm' defense. The new guidance focuses on the third prong of the defense, which requires a good-faith effort to find an alternative buyer. The FTC will now explicitly assess whether the seller solicited a full set of potential buyers, gave them sufficient time and data for diligence, engaged in good-faith negotiations, and properly weighed less anticompetitive offers. This signals a more demanding standard for parties in all industries, not just healthcare. For sophisticated counsel, it means a pre-deal 'shop' process that is merely adequate may no longer suffice. Failure to conduct and document a robust and impartial search for alternative acquirers before signing with a direct competitor could prove fatal to a deal during the subsequent antitrust review, or at least cause significant delays and added expense.

Read the full dispatch →
Akin GumpRegulatory / Government+ Expand
FCC Expands Supply Chain Ban to Components and Online Marketplaces

New FCC rules prohibit equipment authorization for end products containing 'covered' hardware components and impose verification duties on e-commerce platforms.

The Federal Communications Commission (FCC) has significantly expanded its equipment authorization prohibitions to further secure U.S. communications supply chains. Under a new Third Report and Order, the FCC will now deny authorization to any end product containing "logic-bearing hardware components," such as chipsets, produced by an entity on its national-security Covered List. This rule applies regardless of whether the final product manufacturer itself is on the list, creating substantial new diligence obligations for technology companies.

Read the full dispatch →
Holland & KnightSanctions / Export Controls+ Expand
UK Reimposes Broad Sectoral Sanctions on Iran

New regulations effective September 29 restore prohibitions on Iran's shipping, aviation, oil, and gas sectors, creating significant new compliance burdens for maritime and financial firms.

The United Kingdom will reimpose extensive sectoral sanctions against Iran on September 29, 2026, re-establishing prohibitions previously lifted under the Joint Comprehensive Plan of Action (JCPOA). The new rules create significant compliance challenges, particularly for the global maritime industry, by introducing powers to designate 'specified ships' and banning their charter, operation, and servicing. The regulations also broadly prohibit providing insurance or reinsurance to any person 'connected with Iran' and restrict port access for designated vessels. Further financial measures bar UK institutions from activities like opening accounts for or establishing correspondent banking relationships with Iranian counterparts. While the direct impact on aviation is narrower, targeting specific cargo aircraft, the overall regulatory shift requires clients in the shipping, energy, insurance, and banking sectors to urgently review their Iran exposure. Counsel should advise on enhanced diligence for vessels and counterparties and assess existing contracts before the imminent effective date.

Read the full dispatch →
McDermott Will & EmeryPrivacy / Data Security+ Expand
EU's Cyber Resilience Act Imposes 24-Hour Reporting Deadline

Manufacturers of connected products sold in the EU must now report actively exploited vulnerabilities and severe security incidents within 24 hours of awareness, with potential fines of up to €15 million or 2.5% of global turnover.

The EU's Cyber Resilience Act (CRA) reporting regime took effect on September 11, 2026, imposing stringent new obligations on manufacturers of connected products. The act covers a vast range of "products with digital elements" (PDEs), including software, hardware, and IoT devices, that are made available on the EU market. The key change is an exceptionally fast reporting timeline: manufacturers must provide an "early warning" to the EU's cybersecurity agency (ENISA) and national authorities within 24 hours of becoming aware of either an actively exploited vulnerability or a severe security incident impacting their product. A more detailed notification is required within 72 hours.

Read the full dispatch →
McGuireWoodsTechnology / AI+ Expand
US Firms Face Congressional Inquiry Over Use of Chinese AI

Two House committees are investigating the national security, cybersecurity, and economic risks of U.S. companies integrating AI models developed by PRC-based entities.

Two U.S. House committees are jointly investigating American companies for their use of AI models developed in the People's Republic of China, citing significant national security, cybersecurity, and economic stability risks. The inquiry focuses on allegations that Chinese AI labs used techniques like “adversarial distillation” to extract capabilities from U.S. models, potentially without their safety guardrails against malicious use.

Corporate counsel should note that Anysphere (developer of the Cursor coding platform), Airbnb, and DoorDash have already received detailed inquiry letters demanding internal documents, data policies, vendor agreements, and in-person briefings. The development signals a new front in U.S.-China tech scrutiny with serious compliance and reputational stakes for any company using third-party AI, particularly lower-cost foreign alternatives that handle user data. Clients should proactively assess their vendor contracts, data security protocols, and customer disclosures related to foreign-developed AI. The key development to watch is whether the investigatio

Read the full dispatch →
Akin GumpCybersecurity+ Expand
New EU Guidance Clarifies Cyber Resilience Act Obligations

New European Commission guidance clarifies the scope and compliance steps for the Cyber Resilience Act, emphasizing strict incident and vulnerability reporting deadlines.

The European Commission has published new guidance clarifying the scope and compliance obligations under the European Union’s expansive Cyber Resilience Act (CRA). This development is critical for any company manufacturing or selling products with digital components in the EU market. The guidance addresses key definitions and the act's reach, but legal commentators highlight the immediate challenge of its strict reporting timelines.

According to legal experts, companies are particularly focused on the requirements to report actively exploited vulnerabilities and severe security incidents to regulators within very short deadlines. The guidance also sheds light on the substantial effort required to meet the CRA’s vulnerability-testing and security-by-design mandates. Cloud services and cybersecurity providers, who may not be used to reporting to regulatory bodies, must now adapt their processes. Counsel should advise clients to promptly assess the CRA's applicability to their product portfolios and establish the necessary internal procedures for monitoring and reporting to ensure comp

Read the full dispatch →
Ogletree DeakinsEmployment / Labor+ Expand
EU Pay Transparency Guidance Leaves Key Questions Open

New European Commission guidance on the Pay Transparency Directive clarifies the scope of covered employers and pay, but leaves significant ambiguity around determining work of equal value.

The European Commission has issued new guidance on the EU Pay Transparency Directive (2023/970), clarifying some obligations for employers but leaving other key areas unresolved. The guidance, presented as FAQs, confirms the directive's broad application to both public and private sector employers and specifies that initial pay information must be disclosed before a job interview, though not necessarily in the public job posting. It also provides a framework for what counts as "pay" and addresses the directive's interplay with GDPR, designating equal pay compliance a "public interest" that can justify data processing.

Read the full dispatch →
Husch BlackwellEmployment / Labor+ Expand
Guide: Defensible Workplace Policies for Transgender Staff

A new analysis offers guidance for US employers on balancing Title VII's protections for transgender employees with a shifting federal enforcement environment targeting certain DEI initiatives.

A new guide advises US employers on navigating the complex legal environment surrounding workplace protections for transgender employees. While the Supreme Court's 2020 decision in Bostock v. Clayton County still prohibits discrimination based on transgender status under Title VII, the guide highlights a growing tension with a shifting federal enforcement posture that scrutinizes certain diversity, equity, and inclusion (DEI) initiatives. This creates particular risks for federal contractors, who may face DOJ scrutiny or False Claims Act exposure for programs deemed to be "illegal DEI."

Read the full dispatch →
PolsinelliWhite Collar / Investigations+ Expand
Maryland Sues UnitedHealth Over Alleged $126M Medicaid Fraud

Maryland's attorney general has sued Optum and parent UnitedHealth Group, alleging a failed claims-processing system led to over $126 million in improper payments and years of provider audits.

Maryland’s attorney general has sued Optum and its parent, UnitedHealth Group, over a catastrophic failure of the state's behavioral health Medicaid claims system. The complaint alleges the state paid Optum more than $126 million for a system that never became fully functional after the company secretly substituted an untested software platform for the robust system promised in its contract. The system crashed upon its 2020 launch, forcing the state to issue $1.6 billion in emergency estimated payments to providers to prevent a total collapse of the payment infrastructure.

Read the full dispatch →
Akin GumpGovernment Contracts / Defense+ Expand
US Funds $450M Expansion of Defense Manufacturing Base

A critical materials supplier has secured a landmark $450M investment from a new defense economic unit, signaling a fresh government strategy to accelerate industrial production and secure supply chains.

Akin Gump advised The Elmet Group, a U.S. critical materials supplier, in securing a $450 million investment from the U.S. Department of War. The transaction is described as a pioneer deal under the department's newly established Economic Defense Unit, which was created to accelerate domestic defense production. Separately, an Elmet subsidiary was awarded an indefinite delivery/indefinite quantity contract with a ceiling of $2 billion to help rebuild the U.S. National Defense Stockpile's tungsten supply. As a condition, Elmet adopted a compliance plan to prevent 'restricted entities' from acquiring a significant stake. Sophisticated counsel should see this as a template for a new, well-funded government strategy to onshore critical supply chains. The creation of the dedicated unit suggests a more proactive government role in private-sector industrial capacity. Clients in the defense, manufacturing, and technology sectors should monitor this unit's activities for funding opportunities and be prepared for novel compliance obligations, like the ownership restrictions seen here.

Read the full dispatch →
Skadden, Arps, Slate, Meagher & FlomCorporate / M&A+ Expand
UK Proposes 'Once-in-a-Generation' Corporate Reporting Overhaul

The UK government has launched a consultation on wide-ranging reforms to the corporate reporting, distributable profits, and capital maintenance rules under the Companies Act 2006.

The UK government has published a consultation paper proposing what it calls a 'once-in-a-generation' overhaul of the country's corporate reporting framework. The proposals, issued by the Department for Business, Innovation, Science and Trade, aim to simplify the reporting landscape under the Companies Act 2006 and refocus disclosures on information that is financially material to investors and creditors. A key change under consideration is replacing the complex rules on distributable profits with a more straightforward solvency-based test for dividends. Other proposals include overhauling the strategic report, streamlining corporate governance and remuneration disclosures, and simplifying company-size thresholds. The reforms would affect a wide range of public and private UK companies by potentially reducing their compliance burden and altering how they report on strategy, governance, and shareholder distributions. The consultation period is open until November 30, 2026, and affected companies should review the proposals to assess their potential operational impact.

Read the full dispatch →
Mayer BrownCybersecurity+ Expand
NYDFS Releases New Cybersecurity Risk Assessment Guidance

New guidance from the New York Department of Financial Services details specific expectations for cybersecurity risk assessments required under its Part 500 regulations.

The New York Department of Financial Services (NYDFS) has published extensive new guidance for covered entities regarding the cybersecurity risk assessments required under 23 NYCRR Part 500. The guidance clarifies and significantly details the regulator’s expectations, providing a more granular framework than the original rule for how firms should identify and assess their cybersecurity risks.

This development is important for the wide range of banks, insurers, and other financial services firms regulated by NYDFS, as it establishes a heightened standard that examiners will likely use to scrutinize compliance. Given that NYDFS cybersecurity standards often serve as a model for other state and federal regulators, the guidance may also influence compliance expectations well beyond New York.

Read the full dispatch →
Jones DaySecurities / Capital Markets+ Expand
Litigation Increases on Shareholder Proposal Exclusions

Recent revisions to the SEC's Rule 14a-8 process have reportedly led to an increase in litigation over company decisions to exclude shareholder proposals from proxy materials.

Following the SEC's revision of its Rule 14a-8 process, a growing number of disputes over the exclusion of shareholder proposals are being resolved in court rather than through the agency's traditional no-action letter channel. This trend suggests that companies and shareholder proponents are increasingly willing to litigate over the rule's new interpretations.

For corporate counsel, this development changes the strategic calculus for responding to shareholder proposals. The shift from a largely administrative process to active litigation introduces greater costs, longer timelines, and heightened uncertainty. Companies that relied on securing SEC staff concurrence for exclusion may now face federal court challenges, requiring a different set of legal skills and risk assessments.

Read the full dispatch →
Cozen O'ConnorTechnology / AI+ Expand
Florida AG Proposes AI Chatbot Criminal Liability Law

Florida's Attorney General has proposed legislation that would hold tech companies liable if their AI chatbots are used to facilitate criminal activity.

Florida Attorney General James Uthmeier has proposed legislation that would create liability for companies that own, control, or distribute artificial intelligence chatbots when those systems are involved in criminal activities. While specific details of the bill were not provided, the proposal targets the role of AI in facilitating crime, potentially moving beyond existing legal frameworks for intermediary liability.

This development is critical for technology companies and their counsel as it signals a potential major shift in risk allocation for AI products. If enacted, such a law could expose AI developers and providers to significant liability for the misuse of their technology by third-party users, a departure from traditional product liability standards. It would necessitate a re-evaluation of AI system safeguards, acceptable use policies, and user monitoring protocols. The law could also have a chilling effect on the development and deployment of open-source or less restricted AI models.

Read the full dispatch →
Wilmer Cutler Pickering Hale and DorrTrade Secrets+ Expand
US Circuit Courts Refine DTSA Proof, Scope, and Specificity

Recent federal appellate decisions clarify the plaintiff's burden to prove secrets are not readily ascertainable, the specificity required to identify a secret, and the DTSA's extraterritorial reach.

Three US Courts of Appeals recently issued significant decisions interpreting the federal Defend Trade Secrets Act (DTSA). The Ninth Circuit reversed a $57 million judgment, holding that the trial court improperly placed the burden on the defendant to prove alleged secrets were "readily ascertainable." Under the DTSA, the court clarified, the plaintiff bears the burden of proving its information was not readily ascertainable by proper means. In another case, the Fourth Circuit affirmed a preliminary injunction against a Dutch company, holding that the DTSA applies extraterritorially to conduct outside the US so long as an act furthering the offense was committed in the United States. Finally, the Eighth Circuit affirmed summary judgment against a plaintiff for failing to identify its alleged trade secrets with sufficient particularity, reinforcing that vague references to "customer information" are inadequate.

Read the full dispatch →
BakerHostetlerRegulatory / Government+ Expand
DOJ Poised to Expand FARA Commercial, Legal Exemptions

Contrary to a 2025 proposal that would have tightened registration requirements, the DOJ now indicates a final rule will "expand the availability of exemptions."

The Department of Justice has signaled an unexpected reversal in its approach to rulemaking under the Foreign Agents Registration Act (FARA). A January 2025 Notice of Proposed Rulemaking had proposed to narrow key exemptions, but a recent entry in the government’s Unified Agenda indicates the DOJ’s National Security Division is now considering a final rule that will "expand the availability of exemptions commonly relied upon by corporations and law firms."

Read the full dispatch →
Seyfarth ShawEmployment / Labor+ Expand
UK Overhauls Employment Law With Phased 2025 Rights Act

A sweeping new UK law will significantly expand employee protections by reducing the qualifying period for unfair dismissal claims, removing the cap on awards, and imposing new duties on employers to prevent harassment.

The UK's Employment Rights Act 2025 is introducing one of the most significant reforms to national employment law in decades, with changes taking effect in phases through 2026 and 2027. Counsel for employers should note several key developments. From October 2026, the time limit for most tribunal claims will double to six months, and employers will face a stricter duty to take "all reasonable steps" to prevent sexual harassment, including by third parties like clients. In a major shift from January 2027, the qualifying service period for unfair dismissal protection will be cut from two years to just six months. The statutory cap on compensatory awards for unfair dismissal will also be eliminated entirely, increasing potential liability, especially in cases involving high earners. The law also strengthens trade union access rights and restricts "fire and rehire" tactics. Employers must review and update their contracts, handbooks, and management training to mitigate increased litigation risk and ensure compliance with the new regime.

Read the full dispatch →
Hogan LovellsFinancial Regulation+ Expand
BaFin Signals Tougher EU AML Rules for Virtual IBANs

Germany's financial regulator is requiring institutions to conduct due diligence on the end-users of virtual IBANs, anticipating a new EU-wide anti-money laundering framework that will codify these transparency obligations.

Germany's financial regulator, BaFin, has issued a supervisory statement requiring institutions to heighten their anti-money laundering (AML) scrutiny of virtual International Bank Account Numbers (IBANs). The guidance directs institutions to conduct risk-based due diligence on the actual end-users of virtual IBANs, not just on the formal holder of the primary "master account." BaFin views these products as carrying significant transparency risks that can facilitate illicit finance.

Read the full dispatch →
White & CaseFintech / Crypto+ Expand
Mexico Drafts Law to Create Cash-Free Sectors

A proposed Digital Economy Law would empower Mexico's finance ministry to designate strategic sectors as cash-free and give the central bank new authority to regulate payment apps and terminals.

Mexico's president has submitted a draft Digital Economy Law to Congress to accelerate the country's transition away from cash. The bill, if passed, would grant the Ministry of Finance (SHCP) the power to designate "strategic sectors," such as gas stations or toll roads, where digital payments become the only acceptable form of payment. It would also compel financial institutions to accept new government-issued digital identity credentials for remote customer onboarding and contracting.

Read the full dispatch →
McDermott Will & EmeryCorporate / M&A+ Expand
Guide to Delaware's 2024-2026 Corporate Law Amendments

A multi-year overhaul of the Delaware General Corporation Law responds to recent Court of Chancery decisions, creating new statutory safe harbors for conflicted transactions and clarifying rules for M&A agreements and corporate governance.

Delaware has enacted significant amendments to its General Corporation Law (DGCL) over the past three years, largely in direct response to court decisions that had unsettled established market practices. The changes provide transactional and corporate governance lawyers with updated rules of the road. Key amendments from 2024 legislatively overrule recent case law by validating common stockholder governance agreements (reversing Moelis), permitting board approval of documents in 'substantially final' form (addressing Activision), and expressly allowing merger agreements to provide for lost-premium damages (clarifying Crispo).

Read the full dispatch →
DIG DEEPER
MOST CONSEQUENTIALCalifornia Legislature Passes Bill to Kill Website Tracking Lawsuits

A bill awaiting the governor's signature would retroactively eliminate the private right of action for thousands of class actions under California's CIPA.

The California Legislature has unanimously passed SB 690, a bill that would eliminate the private right of action for claims that common website and app tracking technologies function as illegal "pen registers" under the California Invasion of Privacy Act (CIPA). This legislation is a direct response to a surge of nearly 4,000 proposed class actions filed since early 2025 targeting companies for using tools like tracking pixels, cookies, and session-replay software.

For corporate counsel and their outside firms, this is a critical development. With statutory damages of up to $5,000 per violation, CIPA pen-register claims created enormous potential exposure. The bill, if signed into law, would apply retroactively to cases filed on or after January 1, 2025, potentially extinguishing thousands of pending lawsuits. It is important to note, however, that the bill is narrowly tailored and does not affect other CIPA claims, such as wiretapping allegations under § 631, which are often brought in the same complaints.

Akin GumpPrivacy / Data Security
cipasb-690pen-registerwebsite-trackingclass-actioncalifornia
AR
Today's Curator
Arthur Rodrigues. Corporate Counsel & Corporate Secretary at Teachable, Inc. Founder of Cicero Intelligent Minds. Former BigLaw (O'Melveny, Weil, Hughes Hubbard). JD/LLM Michigan Law.
Full Analysis — The Details
01 — ANTITRUST / COMPETITION1
McDermott Will & Emery+ Expand
FTC Details Scrutiny of 'Shop' Process for Failing Firm Defense

The head of the Federal Trade Commission has outlined five factors the agency will use to scrutinize the sale process of a financially distressed target in a merger, raising the bar for parties asserting the 'failing firm' defense.

In a statement prompted by a scuttled Ohio hospital merger, Federal Trade Commission Chairman Andrew Ferguson has detailed five factors the agency will scrutinize when evaluating the adequacy of a 'shop' process for a company asserting the 'failing firm' defense. The new guidance focuses on the third prong of the defense, which requires a good-faith effort to find an alternative buyer. The FTC will now explicitly assess whether the seller solicited a full set of potential buyers, gave them sufficient time and data for diligence, engaged in good-faith negotiations, and properly weighed less anticompetitive offers. This signals a more demanding standard for parties in all industries, not just healthcare. For sophisticated counsel, it means a pre-deal 'shop' process that is merely adequate may no longer suffice. Failure to conduct and document a robust and impartial search for alternative acquirers before signing with a direct competitor could prove fatal to a deal during the subsequent antitrust review, or at least cause significant delays and added expense.

ftcmerger-reviewantitrustfailing-firm-defensemahospital-mergers
Read the full dispatch →
02 — CORPORATE / M&A2
Skadden, Arps, Slate, Meagher & Flom+ Expand
UK Proposes 'Once-in-a-Generation' Corporate Reporting Overhaul

The UK government has launched a consultation on wide-ranging reforms to the corporate reporting, distributable profits, and capital maintenance rules under the Companies Act 2006.

The UK government has published a consultation paper proposing what it calls a 'once-in-a-generation' overhaul of the country's corporate reporting framework. The proposals, issued by the Department for Business, Innovation, Science and Trade, aim to simplify the reporting landscape under the Companies Act 2006 and refocus disclosures on information that is financially material to investors and creditors. A key change under consideration is replacing the complex rules on distributable profits with a more straightforward solvency-based test for dividends. Other proposals include overhauling the strategic report, streamlining corporate governance and remuneration disclosures, and simplifying company-size thresholds. The reforms would affect a wide range of public and private UK companies by potentially reducing their compliance burden and altering how they report on strategy, governance, and shareholder distributions. The consultation period is open until November 30, 2026, and affected companies should review the proposals to assess their potential operational impact.

corporate-reportingukcompanies-actcorporate-governancedividendsfinancial-reporting
Read the full dispatch →
McDermott Will & Emery+ Expand
Guide to Delaware's 2024-2026 Corporate Law Amendments

A multi-year overhaul of the Delaware General Corporation Law responds to recent Court of Chancery decisions, creating new statutory safe harbors for conflicted transactions and clarifying rules for M&A agreements and corporate governance.

Delaware has enacted significant amendments to its General Corporation Law (DGCL) over the past three years, largely in direct response to court decisions that had unsettled established market practices. The changes provide transactional and corporate governance lawyers with updated rules of the road. Key amendments from 2024 legislatively overrule recent case law by validating common stockholder governance agreements (reversing Moelis), permitting board approval of documents in 'substantially final' form (addressing Activision), and expressly allowing merger agreements to provide for lost-premium damages (clarifying Crispo).

dgclcorporate-governancemergers-acquisitionsfiduciary-dutiessafe-harborstockholder-agreementssection-144
Read the full dispatch →
03 — CYBERSECURITY2
Akin Gump+ Expand
New EU Guidance Clarifies Cyber Resilience Act Obligations

New European Commission guidance clarifies the scope and compliance steps for the Cyber Resilience Act, emphasizing strict incident and vulnerability reporting deadlines.

The European Commission has published new guidance clarifying the scope and compliance obligations under the European Union’s expansive Cyber Resilience Act (CRA). This development is critical for any company manufacturing or selling products with digital components in the EU market. The guidance addresses key definitions and the act's reach, but legal commentators highlight the immediate challenge of its strict reporting timelines.

According to legal experts, companies are particularly focused on the requirements to report actively exploited vulnerabilities and severe security incidents to regulators within very short deadlines. The guidance also sheds light on the substantial effort required to meet the CRA’s vulnerability-testing and security-by-design mandates. Cloud services and cybersecurity providers, who may not be used to reporting to regulatory bodies, must now adapt their processes. Counsel should advise clients to promptly assess the CRA's applicability to their product portfolios and establish the necessary internal procedures for monitoring and reporting to ensure comp

cyber-resilience-acteuropean-unioncybersecurityproduct-liabilityregulatory-complianceincident-reporting
Read the full dispatch →
Mayer Brown+ Expand
NYDFS Releases New Cybersecurity Risk Assessment Guidance

New guidance from the New York Department of Financial Services details specific expectations for cybersecurity risk assessments required under its Part 500 regulations.

The New York Department of Financial Services (NYDFS) has published extensive new guidance for covered entities regarding the cybersecurity risk assessments required under 23 NYCRR Part 500. The guidance clarifies and significantly details the regulator’s expectations, providing a more granular framework than the original rule for how firms should identify and assess their cybersecurity risks.

This development is important for the wide range of banks, insurers, and other financial services firms regulated by NYDFS, as it establishes a heightened standard that examiners will likely use to scrutinize compliance. Given that NYDFS cybersecurity standards often serve as a model for other state and federal regulators, the guidance may also influence compliance expectations well beyond New York.

nydfscybersecuritypart-500risk-assessmentnew-yorkfinancial-regulation
Read the full dispatch →
04 — EMPLOYMENT / LABOR4
Seyfarth Shaw+ Expand
NY Enacts Employee Personnel File Access Law

A new New York law taking effect November 8, 2026, requires employers to provide employees with copies of their personnel records within five business days of a request and to notify them of any new negative information.

New York has enacted a law requiring all public and private employers in the state to provide current and former employees with access to their personnel records. Signed by Governor Hochul, the legislation takes effect on November 8, 2026, and introduces several new compliance obligations that require immediate attention.

The law mandates that employers provide a copy of an employee's personnel record, at no cost, within five business days of a written request. It also requires employers to notify an employee within ten days of placing any information in their file that could negatively affect their employment status, compensation, or disciplinary standing. The definition of "personnel record" is broad, extending to certain records maintained by third-party HR and payroll vendors. The statute also establishes a process for employees to dispute information, sets record-retention requirements, and includes robust anti-retaliation protections.

employment-lawnew-yorkpersonnel-recordshr-complianceemployee-rightsrecordkeeping
Read the full dispatch →
Ogletree Deakins+ Expand
EU Pay Transparency Guidance Leaves Key Questions Open

New European Commission guidance on the Pay Transparency Directive clarifies the scope of covered employers and pay, but leaves significant ambiguity around determining work of equal value.

The European Commission has issued new guidance on the EU Pay Transparency Directive (2023/970), clarifying some obligations for employers but leaving other key areas unresolved. The guidance, presented as FAQs, confirms the directive's broad application to both public and private sector employers and specifies that initial pay information must be disclosed before a job interview, though not necessarily in the public job posting. It also provides a framework for what counts as "pay" and addresses the directive's interplay with GDPR, designating equal pay compliance a "public interest" that can justify data processing.

eu-pay-transparency-directivepay-equityemployment-lawcompensationgender-pay-gapeuropean-union
Read the full dispatch →
Husch Blackwell+ Expand
Guide: Defensible Workplace Policies for Transgender Staff

A new analysis offers guidance for US employers on balancing Title VII's protections for transgender employees with a shifting federal enforcement environment targeting certain DEI initiatives.

A new guide advises US employers on navigating the complex legal environment surrounding workplace protections for transgender employees. While the Supreme Court's 2020 decision in Bostock v. Clayton County still prohibits discrimination based on transgender status under Title VII, the guide highlights a growing tension with a shifting federal enforcement posture that scrutinizes certain diversity, equity, and inclusion (DEI) initiatives. This creates particular risks for federal contractors, who may face DOJ scrutiny or False Claims Act exposure for programs deemed to be "illegal DEI."

employment-lawtransgender-rightstitle-viibostockdeifederal-contractorsrisk-managementworkplace-policy
Read the full dispatch →
Seyfarth Shaw+ Expand
UK Overhauls Employment Law With Phased 2025 Rights Act

A sweeping new UK law will significantly expand employee protections by reducing the qualifying period for unfair dismissal claims, removing the cap on awards, and imposing new duties on employers to prevent harassment.

The UK's Employment Rights Act 2025 is introducing one of the most significant reforms to national employment law in decades, with changes taking effect in phases through 2026 and 2027. Counsel for employers should note several key developments. From October 2026, the time limit for most tribunal claims will double to six months, and employers will face a stricter duty to take "all reasonable steps" to prevent sexual harassment, including by third parties like clients. In a major shift from January 2027, the qualifying service period for unfair dismissal protection will be cut from two years to just six months. The statutory cap on compensatory awards for unfair dismissal will also be eliminated entirely, increasing potential liability, especially in cases involving high earners. The law also strengthens trade union access rights and restricts "fire and rehire" tactics. Employers must review and update their contracts, handbooks, and management training to mitigate increased litigation risk and ensure compliance with the new regime.

ukemployment-lawlabor-lawunfair-dismissalworkplace-harassmenttrade-unionsnew-legislation
Read the full dispatch →
05 — FINANCIAL REGULATION2
DLA Piper+ Expand
OCC, FDIC Define 'Unsafe or Unsound Practice' in Final Rule

Federal bank regulators will now need to show a connection to material financial harm before taking supervisory or enforcement action based on an unsafe or unsound practice, a significant shift in the examination framework.

The Office of the Comptroller of the Currency (OCC) and the Federal Deposit Insurance Corporation (FDIC) have adopted a joint final rule that establishes a binding definition for an “unsafe or unsound practice” for the first time. Effective November 2, 2026, the rule institutes a two-part test requiring that conduct be contrary to generally accepted standards of prudent operation and also create a material risk of financial harm to the institution or the Deposit Insurance Fund. The Federal Reserve did not join the rulemaking but has issued separate, similar guidance.

occfdicfinancial-regulationbank-supervisionunsafe-or-unsound-practices
Read the full dispatch →
Hogan Lovells+ Expand
BaFin Signals Tougher EU AML Rules for Virtual IBANs

Germany's financial regulator is requiring institutions to conduct due diligence on the end-users of virtual IBANs, anticipating a new EU-wide anti-money laundering framework that will codify these transparency obligations.

Germany's financial regulator, BaFin, has issued a supervisory statement requiring institutions to heighten their anti-money laundering (AML) scrutiny of virtual International Bank Account Numbers (IBANs). The guidance directs institutions to conduct risk-based due diligence on the actual end-users of virtual IBANs, not just on the formal holder of the primary "master account." BaFin views these products as carrying significant transparency risks that can facilitate illicit finance.

anti-money-launderingbafinvirtual-ibanspayment-systemsfinancial-regulationeu
Read the full dispatch →
06 — FINTECH / CRYPTO2
White & Case+ Expand
Mexico Proposes Comprehensive Digital Economy and Payments Law

Mexico's president has introduced a legislative proposal to Congress aimed at regulating digital payments, establishing digital identities, and promoting cashless sectors.

On September 8, 2026, the President of Mexico submitted a proposed Digital Economy Law for Digital and Electronic Payments to the national Congress, signaling a major regulatory push to modernize the country's payment systems. The initiative aims to address key aspects of the digital ecosystem, including digital identity verification, rules for the acceptance of electronic payments, and the promotion of cashless transactions in certain sectors.

This proposed legislation could create significant new compliance obligations and market opportunities for financial institutions, e-commerce companies, payment processors, and other businesses with operations in Mexico. For sophisticated counsel and clients, the bill represents a critical development that could reshape the competitive landscape and require adjustments to existing business models. International companies will need to evaluate how the law, if passed, would affect their operations, customer interactions, and data-handling practices.

mexicofintechdigital-paymentsfinancial-regulationlegislationlatam
Read the full dispatch →
White & Case+ Expand
Mexico Drafts Law to Create Cash-Free Sectors

A proposed Digital Economy Law would empower Mexico's finance ministry to designate strategic sectors as cash-free and give the central bank new authority to regulate payment apps and terminals.

Mexico's president has submitted a draft Digital Economy Law to Congress to accelerate the country's transition away from cash. The bill, if passed, would grant the Ministry of Finance (SHCP) the power to designate "strategic sectors," such as gas stations or toll roads, where digital payments become the only acceptable form of payment. It would also compel financial institutions to accept new government-issued digital identity credentials for remote customer onboarding and contracting.

mexicodigital-paymentsfintechfinancial-regulationlegislationcashless-economydigital-identity
Read the full dispatch →
07 — GOVERNMENT CONTRACTS / DEFENSE1
Akin Gump+ Expand
US Funds $450M Expansion of Defense Manufacturing Base

A critical materials supplier has secured a landmark $450M investment from a new defense economic unit, signaling a fresh government strategy to accelerate industrial production and secure supply chains.

Akin Gump advised The Elmet Group, a U.S. critical materials supplier, in securing a $450 million investment from the U.S. Department of War. The transaction is described as a pioneer deal under the department's newly established Economic Defense Unit, which was created to accelerate domestic defense production. Separately, an Elmet subsidiary was awarded an indefinite delivery/indefinite quantity contract with a ceiling of $2 billion to help rebuild the U.S. National Defense Stockpile's tungsten supply. As a condition, Elmet adopted a compliance plan to prevent 'restricted entities' from acquiring a significant stake. Sophisticated counsel should see this as a template for a new, well-funded government strategy to onshore critical supply chains. The creation of the dedicated unit suggests a more proactive government role in private-sector industrial capacity. Clients in the defense, manufacturing, and technology sectors should monitor this unit's activities for funding opportunities and be prepared for novel compliance obligations, like the ownership restrictions seen here.

government-contractsdefense-industrial-basesupply-chainnational-securityus-department-of-defensecritical-mineralsakin-gump
Read the full dispatch →
08 — HEALTHCARE1
Holland & Knight+ Expand
Regulators Increase Scrutiny of Wellness and Telehealth Providers

Federal and state agencies are stepping up enforcement actions against telehealth platforms and wellness clinics, focusing on standard-of-care violations, marketing claims, and prescribing practices.

Federal agencies and state medical boards are escalating enforcement against the burgeoning wellness industry, targeting telehealth platforms, IV therapy bars, ketamine clinics, and weight-management providers. This heightened scrutiny follows the expiration of many pandemic-era telehealth prescribing flexibilities, exposing a range of compliance gaps. Regulators are focusing on standard-of-care violations, improper supervision of non-physician practitioners, unsubstantiated marketing claims targeted by the FTC, and DEA requirements for prescribing controlled substances like ketamine. For innovative health platforms, especially those using direct-to-consumer and cash-pay models, the risks include significant civil penalties, license discipline, and operational disruption. The trend signals a tougher environment for a high-growth sector. Counsel should advise clients to promptly conduct comprehensive compliance assessments of their prescribing and marketing protocols, provider licensing, data privacy practices, and corporate structures to mitigate exposure to this coordinated multi-ju

wellnesstelehealthhealthcare-regulationftcdeaenforcementketaminestandard-of-care
Read the full dispatch →
09 — IP / PATENT1
Foley & Lardner+ Expand
Federal Circuit to Revisit Obviousness-Type Double Patenting Doctrine

The U.S. Court of Appeals for the Federal Circuit will soon have an opportunity to limit the application of obviousness-type double patenting, a move that could simplify patent law and incentivize follow-on innovation.

The U.S. Court of Appeals for the Federal Circuit is poised to consider a significant limitation on the doctrine of obviousness-type double patenting (OTDP), a complex, judicially created concept in U.S. patent law. The core issue is whether the doctrine, which prevents an inventor from improperly extending patent exclusivity with claims that are not patentably distinct from those in an earlier patent, should apply only when a patent's term has been artificially extended.

patent-lawfederal-circuitobviousnessdouble-patentingpatent-prosecutionotdp
Read the full dispatch →
10 — LITIGATION / APPELLATE1
K&L Gates+ Expand
DIFC Court Annuls DIAC Award for Unpleaded Reasoning

A Dubai International Financial Centre court set aside an entire arbitral award for the first time after finding the tribunal decided the case on legal arguments the parties themselves had never raised.

The Dubai International Financial Centre (DIFC) Court of First Instance has set aside a Dubai International Arbitration Centre (DIAC) arbitral award in its entirety, finding the tribunal decided the dispute on legal grounds that had not been pleaded or argued by the parties. In Princeton v Persephone, the court held that the tribunal's reliance on unargued theories of waiver and estoppel denied the applicant a reasonable opportunity to present its case, a fundamental tenet of procedural fairness.

international-arbitrationdifcdiacset-asideannulmentprocedural-fairnessdue-process
Read the full dispatch →
11 — PRIVACY / DATA SECURITY2
Akin Gump+ Expand
California Legislature Passes Bill to Kill Website Tracking Lawsuits

A bill awaiting the governor's signature would retroactively eliminate the private right of action for thousands of class actions under California's CIPA.

The California Legislature has unanimously passed SB 690, a bill that would eliminate the private right of action for claims that common website and app tracking technologies function as illegal "pen registers" under the California Invasion of Privacy Act (CIPA). This legislation is a direct response to a surge of nearly 4,000 proposed class actions filed since early 2025 targeting companies for using tools like tracking pixels, cookies, and session-replay software.

For corporate counsel and their outside firms, this is a critical development. With statutory damages of up to $5,000 per violation, CIPA pen-register claims created enormous potential exposure. The bill, if signed into law, would apply retroactively to cases filed on or after January 1, 2025, potentially extinguishing thousands of pending lawsuits. It is important to note, however, that the bill is narrowly tailored and does not affect other CIPA claims, such as wiretapping allegations under § 631, which are often brought in the same complaints.

cipasb-690pen-registerwebsite-trackingclass-actioncalifornia
Read the full dispatch →
McDermott Will & Emery+ Expand
EU's Cyber Resilience Act Imposes 24-Hour Reporting Deadline

Manufacturers of connected products sold in the EU must now report actively exploited vulnerabilities and severe security incidents within 24 hours of awareness, with potential fines of up to €15 million or 2.5% of global turnover.

The EU's Cyber Resilience Act (CRA) reporting regime took effect on September 11, 2026, imposing stringent new obligations on manufacturers of connected products. The act covers a vast range of "products with digital elements" (PDEs), including software, hardware, and IoT devices, that are made available on the EU market. The key change is an exceptionally fast reporting timeline: manufacturers must provide an "early warning" to the EU's cybersecurity agency (ENISA) and national authorities within 24 hours of becoming aware of either an actively exploited vulnerability or a severe security incident impacting their product. A more detailed notification is required within 72 hours.

cyber-resilience-actincident-responsecybersecurityenisaproduct-securityeu
Read the full dispatch →
12 — REGULATORY / GOVERNMENT2
Akin Gump+ Expand
FCC Expands Supply Chain Ban to Components and Online Marketplaces

New FCC rules prohibit equipment authorization for end products containing 'covered' hardware components and impose verification duties on e-commerce platforms.

The Federal Communications Commission (FCC) has significantly expanded its equipment authorization prohibitions to further secure U.S. communications supply chains. Under a new Third Report and Order, the FCC will now deny authorization to any end product containing "logic-bearing hardware components," such as chipsets, produced by an entity on its national-security Covered List. This rule applies regardless of whether the final product manufacturer itself is on the list, creating substantial new diligence obligations for technology companies.

fccsupply-chainnational-securitytelecommunicationsecommerceregulatorycovered-list
Read the full dispatch →
BakerHostetler+ Expand
DOJ Poised to Expand FARA Commercial, Legal Exemptions

Contrary to a 2025 proposal that would have tightened registration requirements, the DOJ now indicates a final rule will "expand the availability of exemptions."

The Department of Justice has signaled an unexpected reversal in its approach to rulemaking under the Foreign Agents Registration Act (FARA). A January 2025 Notice of Proposed Rulemaking had proposed to narrow key exemptions, but a recent entry in the government’s Unified Agenda indicates the DOJ’s National Security Division is now considering a final rule that will "expand the availability of exemptions commonly relied upon by corporations and law firms."

faradojrulemakingnational-securitylobbyingforeign-influence
Read the full dispatch →
13 — SANCTIONS / EXPORT CONTROLS2
Skadden, Arps, Slate, Meagher & Flom+ Expand
US Expands Iran Sanctions, Targeting New Sectors and Foreign Banks

The Treasury Department expanded secondary sanctions to Iran's aviation, tech, and shipping sectors, suspended general licenses, and designated third-country banks for facilitating Iranian transactions, creating broad new compliance risks.

The U.S. government has unveiled a significant expansion of its Iran sanctions program, creating new risks for companies operating globally. In a series of actions, the Treasury's Office of Foreign Assets Control (OFAC) authorized the imposition of secondary sanctions on entities involved with Iran's aviation, technology, digital asset, gold, and shipping sectors. This move exposes non-U.S. persons to potential U.S. sanctions for transacting with these sectors, even with no other U.S. nexus. The measures also include the designation of nearly 60 new parties, the suspension of several general licenses, and a new policy of presumptive denial for most specific license applications.

iran-sanctionsofacsecondary-sanctionsfincenexport-controlsinternational-trade
Read the full dispatch →
Holland & Knight+ Expand
UK Reimposes Broad Sectoral Sanctions on Iran

New regulations effective September 29 restore prohibitions on Iran's shipping, aviation, oil, and gas sectors, creating significant new compliance burdens for maritime and financial firms.

The United Kingdom will reimpose extensive sectoral sanctions against Iran on September 29, 2026, re-establishing prohibitions previously lifted under the Joint Comprehensive Plan of Action (JCPOA). The new rules create significant compliance challenges, particularly for the global maritime industry, by introducing powers to designate 'specified ships' and banning their charter, operation, and servicing. The regulations also broadly prohibit providing insurance or reinsurance to any person 'connected with Iran' and restrict port access for designated vessels. Further financial measures bar UK institutions from activities like opening accounts for or establishing correspondent banking relationships with Iranian counterparts. While the direct impact on aviation is narrower, targeting specific cargo aircraft, the overall regulatory shift requires clients in the shipping, energy, insurance, and banking sectors to urgently review their Iran exposure. Counsel should advise on enhanced diligence for vessels and counterparties and assess existing contracts before the imminent effective date.

ukiransanctionsshippingmaritimeinsurancefinancial-regulation
Read the full dispatch →
14 — SECURITIES / CAPITAL MARKETS4
DLA Piper+ Expand
SEC Proposes Tailored Registration Exemptions for Crypto Assets

The US Securities and Exchange Commission has proposed "Regulation Crypto Assets," a new framework that would create two new offering exemptions and a safe harbor for certain investment contracts involving digital assets.

The US Securities and Exchange Commission (SEC) has proposed "Regulation Crypto Assets," a new and comprehensive framework for offerings of certain crypto assets deemed to be securities. The proposal distinguishes between a crypto asset and the "covered investment contract" to which it is subject, applying only when the asset itself is not a security like tokenized equity.

The proposed rules establish two new transactional exemptions from registration. A "startup exemption" would permit offerings up to $5 million over four years with streamlined, website-based disclosures. A tiered "fundraising exemption," modeled on Regulation A, would allow for offerings of up to $20 million (Tier 1) or $75 million (Tier 2) in a 12-month period, with ongoing reporting obligations.

seccryptodigital-assetssecurities-regulationregulation-crypto-assetscapital-marketsexempt-offerings
Read the full dispatch →
BakerHostetler+ Expand
SEC Proposes Modernizing Transfer Agent Rules for Digital Assets

The Securities and Exchange Commission has released a proposed update to the rules for registered transfer agents to reflect technological advancements, including the use of blockchain.

The SEC has proposed a comprehensive update to the rules governing registered transfer agents, marking the first major overhaul in this area in decades. The proposal aims to modernize regulations to account for technological changes, including electronic recordkeeping, uncertificated securities, and the use of blockchain or distributed ledger technology. Key changes would update requirements for processing times, risk management, business continuity planning, and the safeguarding of securities and funds. For clients in the financial services and technology sectors, this is a critical development. The rules could pave a clearer regulatory path for issuing and transferring tokenized securities, while also imposing new operational and compliance burdens on transfer agents. Counsel should advise affected clients to closely review the proposed rule changes, assess their potential impact on current and future business operations, and consider submitting comments to the SEC during the public comment period.

sectransfer-agentsrulemakingblockchaintokenizationdigital-assetssecurities-regulation
Read the full dispatch →
Goodwin Procter+ Expand
SEC Proposes to Modernize Transfer Agent Rules

The SEC has proposed the first comprehensive update to transfer agent regulations in decades, seeking to address technological advancements and impose new standards for risk management and compliance.

The U.S. Securities and Exchange Commission has proposed a comprehensive overhaul of the rules governing registered transfer agents, which have not been substantively updated in over 40 years. The proposal aims to modernize the regulatory framework to reflect significant technological advancements in securities recordkeeping, including the use of electronic communications and blockchain or distributed ledger technology. Key elements of the proposal include new requirements for transfer agents to establish and maintain written risk management and compliance policies, new standards for processing securities transfers and removing restrictive legends, and updated rules for handling inactive securityholder accounts. For public companies and other issuers, these changes could impact how their securities are transferred and serviced. The proposal will directly affect the operations of all registered transfer agents, requiring investment in new systems and compliance protocols. The SEC will accept public comments for 60 days after the proposal is published in the Federal Register.

sectransfer-agentsrulemakingsecurities-regulationblockchaincapital-marketscompliance
Read the full dispatch →
Jones Day+ Expand
Litigation Increases on Shareholder Proposal Exclusions

Recent revisions to the SEC's Rule 14a-8 process have reportedly led to an increase in litigation over company decisions to exclude shareholder proposals from proxy materials.

Following the SEC's revision of its Rule 14a-8 process, a growing number of disputes over the exclusion of shareholder proposals are being resolved in court rather than through the agency's traditional no-action letter channel. This trend suggests that companies and shareholder proponents are increasingly willing to litigate over the rule's new interpretations.

For corporate counsel, this development changes the strategic calculus for responding to shareholder proposals. The shift from a largely administrative process to active litigation introduces greater costs, longer timelines, and heightened uncertainty. Companies that relied on securing SEC staff concurrence for exclusion may now face federal court challenges, requiring a different set of legal skills and risk assessments.

secrule-14a-8shareholder-proposalsno-action-lettersproxy-statementscorporate-governance
Read the full dispatch →
15 — TECHNOLOGY / AI2
McGuireWoods+ Expand
US Firms Face Congressional Inquiry Over Use of Chinese AI

Two House committees are investigating the national security, cybersecurity, and economic risks of U.S. companies integrating AI models developed by PRC-based entities.

Two U.S. House committees are jointly investigating American companies for their use of AI models developed in the People's Republic of China, citing significant national security, cybersecurity, and economic stability risks. The inquiry focuses on allegations that Chinese AI labs used techniques like “adversarial distillation” to extract capabilities from U.S. models, potentially without their safety guardrails against malicious use.

Corporate counsel should note that Anysphere (developer of the Cursor coding platform), Airbnb, and DoorDash have already received detailed inquiry letters demanding internal documents, data policies, vendor agreements, and in-person briefings. The development signals a new front in U.S.-China tech scrutiny with serious compliance and reputational stakes for any company using third-party AI, particularly lower-cost foreign alternatives that handle user data. Clients should proactively assess their vendor contracts, data security protocols, and customer disclosures related to foreign-developed AI. The key development to watch is whether the investigatio

artificial-intelligencechinacongressional-investigationnational-securitycybersecuritysupply-chain-riskus-house
Read the full dispatch →
Cozen O'Connor+ Expand
Florida AG Proposes AI Chatbot Criminal Liability Law

Florida's Attorney General has proposed legislation that would hold tech companies liable if their AI chatbots are used to facilitate criminal activity.

Florida Attorney General James Uthmeier has proposed legislation that would create liability for companies that own, control, or distribute artificial intelligence chatbots when those systems are involved in criminal activities. While specific details of the bill were not provided, the proposal targets the role of AI in facilitating crime, potentially moving beyond existing legal frameworks for intermediary liability.

This development is critical for technology companies and their counsel as it signals a potential major shift in risk allocation for AI products. If enacted, such a law could expose AI developers and providers to significant liability for the misuse of their technology by third-party users, a departure from traditional product liability standards. It would necessitate a re-evaluation of AI system safeguards, acceptable use policies, and user monitoring protocols. The law could also have a chilling effect on the development and deployment of open-source or less restricted AI models.

aitech-liabilityfloridastate-aggenerative-aiintermediary-liability
Read the full dispatch →
16 — TRADE SECRETS2
Goodwin Procter+ Expand
DTSA at 10: Uniform Standard Remains Elusive Amid Circuit Splits

A decade after its enactment, the Defend Trade Secrets Act has increased federal filings but also created significant circuit splits on pleading standards, damages, and other key issues.

A decade after its passage, the Defend Trade Secrets Act (DTSA) has successfully shifted more trade secret litigation into federal court but has failed to create the single, national standard Congress envisioned. Analysis of the statute's first ten years reveals significant and unresolved circuit splits on fundamental issues, creating strategic complexity for businesses. For example, courts are divided on how specifically a plaintiff must identify an alleged trade secret at the pleading stage and whether a defendant's "avoided costs" can be recovered as unjust-enrichment damages without the plaintiff proving its own corresponding loss. The Seventh Circuit has also endorsed a broad extraterritorial reach for the statute, a position not yet tested elsewhere, creating further uncertainty for global companies. Looking ahead, the rise of artificial intelligence presents new challenges, raising questions about whether AI-generated output can be a trade secret and what security measures are now considered "reasonable." Businesses should monitor these splits and emerging AI-related doctrines

dtsatrade-secretscircuit-splitlitigationintellectual-propertyunjust-enrichmentpleading-standardsai
Read the full dispatch →
Wilmer Cutler Pickering Hale and Dorr+ Expand
US Circuit Courts Refine DTSA Proof, Scope, and Specificity

Recent federal appellate decisions clarify the plaintiff's burden to prove secrets are not readily ascertainable, the specificity required to identify a secret, and the DTSA's extraterritorial reach.

Three US Courts of Appeals recently issued significant decisions interpreting the federal Defend Trade Secrets Act (DTSA). The Ninth Circuit reversed a $57 million judgment, holding that the trial court improperly placed the burden on the defendant to prove alleged secrets were "readily ascertainable." Under the DTSA, the court clarified, the plaintiff bears the burden of proving its information was not readily ascertainable by proper means. In another case, the Fourth Circuit affirmed a preliminary injunction against a Dutch company, holding that the DTSA applies extraterritorially to conduct outside the US so long as an act furthering the offense was committed in the United States. Finally, the Eighth Circuit affirmed summary judgment against a plaintiff for failing to identify its alleged trade secrets with sufficient particularity, reinforcing that vague references to "customer information" are inadequate.

trade-secretsdtsalitigationburden-of-proofextraterritorialityninth-circuitfourth-circuit
Read the full dispatch →
17 — WHITE COLLAR / INVESTIGATIONS1
Polsinelli+ Expand
Maryland Sues UnitedHealth Over Alleged $126M Medicaid Fraud

Maryland's attorney general has sued Optum and parent UnitedHealth Group, alleging a failed claims-processing system led to over $126 million in improper payments and years of provider audits.

Maryland’s attorney general has sued Optum and its parent, UnitedHealth Group, over a catastrophic failure of the state's behavioral health Medicaid claims system. The complaint alleges the state paid Optum more than $126 million for a system that never became fully functional after the company secretly substituted an untested software platform for the robust system promised in its contract. The system crashed upon its 2020 launch, forcing the state to issue $1.6 billion in emergency estimated payments to providers to prevent a total collapse of the payment infrastructure.

marylandunitedhealth-groupoptummedicaid-fraudfalse-claimshealthcare-litigationgovernment-contracts
Read the full dispatch →
Also noted

Grade 3 — worth a glance, not the full analysis.

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.