DROPLETS
Manufacturers of hardware and software sold in the EU must now report actively exploited vulnerabilities and severe incidents to ENISA, with initial notifications due within 24 hours of awareness.
The first major compliance deadline under the EU's Cyber Resilience Act (CRA) is now in effect. As of September 11, 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents that impact their "products with digital elements" (PDEs). The CRA's scope is extensive, covering most software and hardware products placed on the EU market, irrespective of the manufacturer's location, size, or sector.
This creates an immediate and critical compliance burden for global businesses. The reporting timelines are extremely aggressive: an 'early warning' notification must be submitted to the EU's cybersecurity agency, ENISA, via its Single Reporting Platform within 24 hours of awareness. A more detailed notification must follow within 72 hours. These obligations are distinct from and apply more broadly than those under the existing NIS2 Directive.
…
A draft statutory instrument laid before the UK Parliament and new FCA perimeter guidance clarify the scope of regulated cryptoasset activities, including staking and stablecoins, ahead of a 2027 effective date.
The UK government has laid a draft statutory instrument before Parliament to govern cryptoassets, while the Financial Conduct Authority (FCA) has published corresponding perimeter guidance. The new framework, part of the Financial Services and Markets Act, is set to commence on October 25, 2027, with the firm authorisation window opening in September 2026.
This development is critical for all firms in the digital asset space operating in or providing services to the UK. The publications provide significant clarity on the scope of regulated activities, addressing key industry concerns around territoriality, staking, safeguarding, and stablecoins. The statutory instrument introduces important exclusions, including for certain technical service providers and proprietary trading, to avoid stifling innovation and placing UK firms at a competitive disadvantage. It also clarifies rules for stablecoin backing and nominee-operated safeguarding arrangements.
…
The agency has proposed eliminating the 80-year-old federal framework that requires companies to include qualifying shareholder proposals in their proxy materials.
The US Securities and Exchange Commission has proposed rescinding Rule 14a-8, the framework that for over 80 years has allowed shareholders to require companies to include qualifying proposals in corporate proxy materials. Citing a belief that the rule exceeds its statutory authority and displaces state corporate law, the SEC's proposal would remove the uniform federal mechanism for shareholder-initiated proposals. If adopted, this would fundamentally alter the landscape for shareholder activism, shifting the focus to state law, company-specific bylaws, and other tactics like director “vote-no” campaigns and independent solicitations.
…
The proposed changes would end decades of federal oversight and shift the regulation of shareholder proposals to state law and individual company governing documents.
On September 16, 2026, the U.S. Securities and Exchange Commission proposed a fundamental overhaul of the shareholder proposal process by rescinding Rule 14a-8 of the Exchange Act. For decades, this rule has provided the federal framework for shareholders to include proposals in company proxy statements. The SEC's move, justified as a response to the rule exceeding its statutory authority, would shift this regulatory arena entirely to state law and individual companies’ governing documents.
This creates significant uncertainty for public companies and institutional investors. Key corporate law jurisdictions like Delaware have underdeveloped case law on the matter, potentially leading to a fragmented and unpredictable legal landscape. The change could spur litigation as companies and shareholders test the boundaries of new state-level regimes and corporate bylaws. Other proposed amendments aim to modernize proxy solicitations, including eliminating the mandatory delivery of glossy annual reports and shortening certain deadlines.
…
The UK's Competition and Markets Authority is proposing to use data-driven screening tools on Ministry of Defence procurement data to detect and deter bid-rigging.
The UK's Competition and Markets Authority (CMA) is intensifying its fight against bid-rigging in public procurement, proposing to use data analytics to scrutinize Ministry of Defence (MoD) contracts. The initiative reflects the CMA's view that tackling collusion is a key priority, especially within the UK's £400 billion public purchasing market. The agency plans to expand the use of its Bid Rigging Intelligence Tool (BRIT) to detect suspicious patterns, and it is calling for the mandatory, centralized collection of bid-level data—including from losing bidders—to make this screening effective. For government contractors, particularly in the defense sector, this signals a significant increase in enforcement risk. The consequences for cartel conduct are severe, ranging from heavy fines and director disqualifications to potential criminal prosecution and, crucially, mandatory debarment from future public contracts under the new Procurement Act 2023. Counsel should advise clients in this space to anticipate heightened scrutiny and ensure their bidding practices and compliance programs ar
…
A new law firm guide advises public companies on a complex risk environment, highlighting a new SEC financial reporting enforcement unit, aggressive state attorneys general, and fragmented state-level AI laws.
A Skadden client briefing outlines a converging set of risks for public company boards, demanding heightened oversight. The guide points to the SEC's creation of a new, consolidated enforcement unit dedicated to financial reporting, which is expected to pursue more numerous and complex investigations. Concurrently, state attorneys general are becoming more aggressive in filling perceived federal voids, launching their own antitrust, consumer protection, and privacy enforcement actions. This trend is amplified by the growing patchwork of state-level AI regulations, which creates significant compliance challenges for companies operating nationwide. For corporate counsel and their clients, this environment means preparing for scrutiny on multiple fronts. The firm advises boards to re-examine financial disclosure processes, develop adaptable compliance frameworks for divergent state laws, and prepare for potential investigations initiated by a wider range of government actors.
In a key victory for Merck, the Patent Trial and Appeal Board invalidated a Halozyme patent related to Keytruda Qlex™ technology, finding the claims unpatentable for lack of written description and enablement.
The US Patent Trial and Appeal Board (PTAB) delivered a significant win for Merck, issuing a final written decision that invalidates all challenged claims of a Halozyme patent for its PH20 hyaluronidase technology. The Board found the patent unpatentable for lacking adequate written description and enablement, siding with Merck’s arguments in the post-grant review. However, the PTAB rejected Merck's separate arguments that the claims were obvious.
…
New UK deforestation rules and EU regulations on sustainable packaging and greenwashing are creating significant new due diligence hurdles and potential liabilities for corporate transactions.
A trio of regulatory developments in the UK and EU is set to reshape ESG compliance and transaction diligence. The UK government announced it will expand mandatory due diligence requirements to cover a wide range of "forest risk commodities" beyond timber, including soy, palm oil, and beef, aligning with the EU’s Deforestation Regulation (EUDR). In parallel, the EU’s Packaging and Packaging Waste Regulation (PPWR) began to take effect in August 2026, imposing new standards for recyclability and waste reduction. Finally, the EU’s directive against greenwashing (ECGTD) comes into force September 27, 2026, prohibiting vague environmental claims like "eco-friendly" and sustainability labels not based on official certification. For corporate and private equity deal teams, these rules introduce critical new diligence streams. Acquirers must now rigorously assess a target’s supply-chain exposure, packaging compliance, and marketing claims to avoid inheriting significant post-closing liabilities and remediation costs. Counsel should watch for UK legislation implementing the deforestation reg
…
An amendment to Delaware's data breach notification law requires earlier notice to the Attorney General in some cases and narrows the compliance safe harbor for entities regulated by GLBA and HIPAA.
Delaware has amended its data breach notification statute, effective immediately, creating new obligations for companies holding personal information of state residents. The law, HB 381, introduces an early reporting requirement, obligating entities to notify the Attorney General within 60 days of discovering a breach if they cannot identify the specific affected residents within that timeframe. This change could accelerate regulatory reporting deadlines, particularly in complex incidents requiring prolonged forensic analysis.
…
A UK Employment Rights Act provision effective January 2027 will make it automatically unfair to dismiss an employee and replace them with a non-employee, creating significant new risks for any business restructure.
A new provision in the UK's Employment Rights Act, effective January 2027, will introduce significant risk for employers undertaking workforce restructures. The incoming section 104K will create a new category of automatically unfair dismissal if the main reason for termination is to have the employee's work done by a non-employee, such as a contractor, consultant, or agency worker. Sophisticated counsel and clients should care because this type of claim requires no qualifying service period from the employee and compensation for a finding of unfair dismissal is uncapped. This creates a hidden trap where a dismissal for what an employer considers a genuine redundancy could be re-characterized as a prohibited 'workforce replacement,' even if the restructure has a strong commercial rationale. Ambiguities remain regarding the provision's interaction with existing TUPE regulations and its application to complex group structures. Employers planning any restructure that involves replacing permanent roles with flexible resources must now carefully document that the need for employees has ge
…
A UK appellate court held that an employer’s vicarious liability for employee torts against a third party does not transfer to the buyer of a business under the country's employee-protection regulations.
The UK Court of Appeal has ruled that a business acquirer does not inherit the seller's vicarious liability for employee torts committed against third parties. The decision clarifies the scope of the Transfer of Undertakings (Protection of Employment) Regulations 2006 (TUPE), which are designed to protect employee rights during a business transfer. In ABC v Huntercombe, the court rejected a claimant's "opportunistic" attempt to hold the new owner of a hospital liable for alleged abuse by the former owner's staff, especially after the former owner entered liquidation. The court held that TUPE's provision transferring liabilities "under or in connection with" a contract of employment applies only to liabilities owed to employees, not to third parties. This ruling provides significant certainty for buyers in UK asset deals, confirming that they do not step into the shoes of the seller for pre-transfer torts against non-employees. The immediate impact is on over fifty similar claims awaiting case management, but the precedent will shape risk allocation in UK M&A going forward.
In one of the first major enforcement actions under the EU's Foreign Subsidies Regulation, a Belgian court suspended the award of a €750 million casino concession due to the winning bidder's non-compliance.
A Belgian court has suspended the award of a €750 million casino concession, marking one of the first significant enforcement actions under the EU's Foreign Subsidies Regulation (FSR). The decision was reportedly based on the winning bidder's failure to comply with the FSR's mandatory disclosure requirements for foreign financial contributions in large public procurement procedures.
This ruling is a critical development for global businesses operating in the European Union. It demonstrates that national authorities are actively enforcing the FSR and are willing to halt major, high-value contracts for procedural non-compliance. The case underscores the serious risks for companies that receive financial support from non-EU governments, highlighting the importance of meticulously tracking such contributions and adhering to the regulation's reporting obligations. Sophisticated counsel should advise clients to immediately review and strengthen their internal FSR compliance programs. The market will be closely watching for further enforcement actions at the national level and any responsi
…
With no federal AI law, states are creating a complex patchwork of rules for developers and users, posing significant cross-border compliance challenges.
In the absence of a comprehensive federal framework, a growing number of U.S. states, including California, New York, and Colorado, have enacted their own laws governing artificial intelligence. This has created a fragmented regulatory landscape with widely divergent approaches. Some laws focus on the developers of advanced AI models, imposing transparency and safety obligations, while others target companies that deploy AI for "consequential decisions" in areas like employment, lending, and healthcare, often focusing on algorithmic discrimination and disclosure. This state-by-state approach presents significant compliance challenges for companies operating nationally, forcing them to navigate a complex web of potentially conflicting requirements. The situation is further complicated by reports that the federal administration prefers a unified national standard and may challenge certain state laws. Boards and in-house counsel must now establish robust governance processes to monitor these developments, identify applicable state regimes, and create compliance frameworks that can adapt
…
The court joined every other circuit to have ruled on the issue in holding that whistleblower relators are not "officers" under the Appointments Clause, preserving a key government anti-fraud tool.
The US Court of Appeals for the Eleventh Circuit, in United States ex rel. Zafirov v. Florida Medical Associates, reversed a district court and held that the False Claims Act's (FCA) qui tam provisions do not violate the Constitution's Appointments Clause. Defendants have increasingly argued that allowing private whistleblowers, or "relators," to sue on the government's behalf unconstitutionally grants executive power to individuals who are not appointed as federal officers. This decision aligns the Eleventh Circuit with the Fifth, Sixth, Ninth, and Tenth Circuits, preventing a circuit split that might have forced Supreme Court review. With billions of dollars recovered annually through qui tam actions, the ruling preserves a critical tool for government fraud enforcement.
…
A federal district court ruling has created a September 28, 2026, deadline for civil claims against companies for allegedly aiding and abetting terrorism as far back as September 11, 2001.
A 2025 federal district court decision has opened a litigation window that is expected to close on September 28, 2026, for civil claims under the Justice Against Sponsors of Terrorism Act (JASTA). The ruling in Moses v. BNP Paribas held that JASTA’s ten-year statute of limitations runs from the date of the law's enactment in 2016, not from the date of the underlying injury. This interpretation makes claims timely for conduct related to terrorist acts as far back as September 11, 2001.
…
A new EU law will use procurement preferences and financial aid to incentivize local production of critical medicines, shifting the market to favor supply-chain resilience over lowest cost.
The EU has reached a provisional political agreement on its Critical Medicines Act, a significant legislative effort to secure the bloc's supply of essential pharmaceuticals. The Act introduces a "stick and carrot" approach to incentivize onshoring. Contracting authorities in public procurement procedures will be required to implement resilience-related criteria that establish a preference for EU-manufactured critical medicines. For non-EU producers, this could dilute the appeal of cheaper generics and may necessitate establishing EU production facilities or partnerships. To further support this shift, the Act allows member states and the EU to designate certain projects as "strategic," granting them access to fast-track permits, streamlined administrative processes, and direct financial support. Pharmaceutical manufacturers and their investors should now assess their supply chains and EU manufacturing capacity, as the legislation signals a structural shift away from lowest-price models toward rewarding local production and supply-chain security. The final text is expected by late 20
…
The proposed regulation would harmonize rules for protecting minors online, introducing strict age verification, account bans for users under 13, and 'safety by design' mandates.
The European Commission has proposed a new regulation, the 'EU Kids Act,' to create a unified framework for protecting minors online, superseding fragmented national laws. The draft regulation would apply broadly to social networks, video-sharing platforms, app stores, online games, and AI chatbots serving EU users, regardless of where the providers are established. Key provisions include mandatory age verification through certified solutions, a general prohibition on accounts for children under 13, and parent-controlled, feature-limited accounts for those aged 13-15. Sophisticated clients care because the act imposes 'safety by design' obligations for all users under 18, expressly prohibiting features deemed addictive, such as infinite scroll and autoplay. Non-compliance could lead to fines of up to 6% of global annual turnover. The proposal now enters the EU legislative process for negotiation between the Parliament and Council. While adoption is not expected before 2028, affected companies must now track the bill's progress and prepare for a potentially stringent new compliance re
…
A growing number of African governments are tightening control over strategic mineral resources through new taxes, local ownership rules, and license revocations, creating significant new risks for foreign investors.
Several African nations, including the Democratic Republic of the Congo, Mali, Zambia, and Ghana, are increasingly asserting sovereign control over their natural resources, particularly minerals critical for the global energy transition. This wave of 'resource nationalism' includes measures such as increasing royalty rates and taxes, mandating higher state or local shareholdings in mining projects, banning the export of unprocessed minerals to force domestic refining, and, in some cases, cancelling licenses and nationalizing assets.
…
The Senate Banking, Housing, and Urban Affairs Committee's vote on Brian Johnson's nomination is a key hurdle in the process of appointing a new leader for the consumer finance watchdog.
The Senate Banking, Housing, and Urban Affairs Committee is scheduled to vote on whether to advance the nomination of Brian Johnson to be the next Director of the Consumer Financial Protection Bureau (CFPB). This committee vote is a critical gateway, determining if the nomination proceeds to the full Senate for a final confirmation vote. The outcome is highly consequential for the financial services industry, as the CFPB Director wields significant power to set the agency's enforcement and rulemaking agenda. A change in leadership could signal a major shift in the Bureau's approach to supervision and its stance on fair lending, debt collection, and emerging financial technology. Financial institutions and their counsel are closely watching, as a new director can reshape the regulatory landscape, affecting compliance programs and litigation risk. If the committee approves the nomination, the next step will be consideration by the full Senate, with a potential vote ahead of a scheduled pre-election recess in early October.
An August 13 memo from the Department of Justice's reconstituted National Fraud Enforcement Division signals a new focus on tax-related crimes affecting companies across all industries.
The U.S. Department of Justice's Fraud Division has signaled a significant shift in its enforcement strategy, placing a heightened emphasis on tax-related offenses. An August 13 memorandum announced the priorities for the newly reconstituted National Fraud Enforcement Division, making clear that tax crimes are a central focus. Sophisticated counsel should advise clients that this is not a niche concern for the financial industry; the memo indicates that scrutiny will apply to companies across all sectors. This development increases the risk profile for corporate tax positions and reporting methodologies. In-house legal, finance, and tax departments should anticipate more aggressive federal investigations and prosecutions in this area. Prudent companies may wish to review their existing tax compliance programs and ensure their reporting structures can withstand increased government scrutiny. The key development to watch is how the DOJ begins to implement this policy through new investigations and charging decisions.
A federal appeals court has struck down parts of the methodology for calculating out-of-network payment rates, adding new complexity for payors and providers navigating the federal dispute resolution process.
The US Court of Appeals for the Fifth Circuit has invalidated key federal regulations governing how insurers calculate the Qualifying Payment Amount (QPA), a crucial benchmark in out-of-network billing disputes under the No Surprises Act (NSA). Affirming a lower court, the panel ruled insurers may not include non-negotiated "ghost rates" and must include bonus and incentive payments in their QPA calculations, a decision expected to shift leverage in payment negotiations and the Independent Dispute Resolution (IDR) process.
…
The SEC has proposed replacing its prescriptive ban on political contributions by investment advisers with a principles-based approach relying on existing anti-fraud and compliance rules.
The U.S. Securities and Exchange Commission has proposed a full rescission of its 'pay-to-play' rule for investment advisers, Rule 206(4)-5 under the Investment Advisers Act. The 2010 rule currently prohibits advisers from receiving compensation from government-entity clients for two years after the adviser or a covered employee makes a political contribution to an official who could influence the awarding of advisory contracts. Citing concerns that the rule unduly suppresses political speech, imposes significant operational complexity, and creates a 'de facto strict liability' framework, the SEC is advocating a shift to a principles-based approach. Instead of the prescriptive ban, advisers would rely on existing anti-fraud provisions and their own compliance programs to mitigate pay-to-play risks. While this offers flexibility, it places the onus on firms to design and implement defensible policies. Advisers with government clients must also remember that numerous state and local pay-to-play laws would remain in effect regardless of federal action. The proposal, which also eliminate
…
While fewer contests went to a vote, activists gained dozens of board seats via settlements, increasingly using AI adoption as a campaign theme and navigating new SEC disclosure rules for SPVs.
Shareholder activism in the U.S. reached a record high in the first half of 2026, but the tactics and themes are evolving significantly. While only four proxy contests went to a vote, activists secured 51 board seats, mostly through settlements. Campaigns increasingly target technology and consumer companies, with slow AI adoption emerging as a key complaint. Sophisticated counsel should note two major shifts creating uncertainty. First, new SEC staff guidance from July 2026 requires disclosure of investors in special purpose vehicles (SPVs) formed to target a specific company, which could chill fundraising for smaller activist funds that rely on anonymous backers. Second, the proxy advisory landscape is fracturing under regulatory pressure and market changes, with major institutions like JPMorgan turning to AI for voting decisions instead of relying on traditional advisors. This unpredictability, coupled with the rise of off-cycle pressure campaigns, requires boards to prepare for earlier, more direct, and more tailored shareholder engagement to avoid costly public fights.
The European Securities and Markets Authority's latest risk report highlights concerns about investor protection, insider trading, and market manipulation, signaling future regulatory action.
For the first time, the European Securities and Markets Authority (ESMA) has spotlighted prediction markets in its Trends, Risks, and Vulnerabilities report, flagging significant dangers for market participants. The agency raised concerns about retail investor harm from "speculative gambling environments," the potential for insider trading, and data manipulation affecting contract settlements. The report also noted that decentralized finance (DeFi) and AI could amplify these risks.
…
Australian regulators have warned digital asset providers that they must apply for or vary a financial services licence by September 30, 2026, or risk illegal operation under a new framework.
Australia's securities regulator, ASIC, has issued a final reminder for digital asset businesses to apply for or vary an Australian financial services licence (AFSL) by the upcoming September 30, 2026 deadline. This action is a key implementation step for the new Corporations Amendment (Digital Assets Framework) Act 2026, which is set to come into force on April 9, 2027, and establishes a comprehensive regulatory framework for the sector.
…
Peru's executive branch has asked Congress for a 120-day grant of authority to issue legislative decrees affecting finance, mining, energy, and supply-chain rules.
Peru's executive branch has submitted a bill seeking a 120-day grant of delegated power from Congress to enact sweeping regulatory reforms by decree. This would allow the government to bypass the ordinary legislative process to implement changes across eight policy areas. For sophisticated counsel and their clients, the proposal creates both uncertainty and potential opportunity. Key measures under consideration include the elimination of statutory interest rate caps, the modification of rules for mining concessions, and the streamlining of environmental and infrastructure project permitting. The bill also contemplates new compliance obligations, including a prohibition on importing goods made with forced labor and a framework for designating certain criminal organizations as terrorist entities, which would affect AML and screening protocols. The bill faces an uncertain path in Congress, with several committees having issued unfavorable opinions, and the final scope of any delegated authority may be narrower than requested. Companies with Peruvian interests should monitor the bill's
…
The EU's General Court has upheld the European Commission's decision to block Booking's acquisition of Etraveli, endorsing a novel "ecosystem" theory of competitive harm with broad implications for digital platform M&A.
The EU's General Court has affirmed the European Commission's 2023 decision to prohibit Booking Holdings' proposed acquisition of Etraveli. The Commission blocked the deal based on a novel "ecosystem" theory of harm, arguing that the merger would allow the already-dominant hotel online travel agent (OTA), Booking, to entrench its position by acquiring a leading flight OTA and cross-selling services to a wider captive audience. This "reverse leveraging," where an acquisition in an adjacent market reinforces dominance in a core market, is not explicitly detailed in current non-horizontal merger guidelines.
…
An exposure draft bill would require a broad range of online service providers to take reasonably practicable steps to ensure a safe online environment for users.
The Australian government has released an exposure draft of the Online Safety Amendment (Digital Duty of Care) Bill 2026, proposing a significant shift in the country's platform regulation. The bill would move from a co-regulatory model to a direct one, imposing a broad "digital duty of care" on online services—including social media, search engines, AI providers, and device manufacturers—to ensure a safe environment for users.
Sophisticated clients and counsel care because the duty is expansive, requiring providers to take all "reasonably practicable" steps to protect users in Australia from a wide range of harmful materials and conduct. The proposal also includes specific prohibitions on design features like recommender systems and endless feeds for users under 16. The eSafety Commissioner would gain new enforcement powers, including the authority to issue directions and impose penalties of up to approximately AUD 109 million for non-compliance. The short consultation period suggests the government intends to advance the legislation quickly, requiring affected companies to prepare
…
Five federal financial regulators have jointly clarified that banks can communicate with customers about the underlying facts and transactions of suspected fraud without violating rules on Suspicious Activity Report confidentiality.
In a significant clarification for financial institutions, five U.S. federal regulators jointly stated that banks and credit unions may discuss the underlying facts of suspicious transactions with customers without violating Bank Secrecy Act confidentiality rules. The September 2, 2026, statement from the Federal Reserve, FDIC, OCC, NCUA, and FinCEN addresses a long-standing tension between transparency and the prohibition against disclosing the existence of a Suspicious Activity Report (SAR). The guidance confirms that while an institution can never reveal that a SAR has been or will be filed, it is permitted to discuss the specific transactions, dates, amounts, and other facts that prompted the concern. This allows banks to provide customers, including potential fraud victims, with clearer explanations for account restrictions, rejected deposits, or account closures. The agencies noted that a customer deducing a SAR might be filed from these facts does not constitute an improper disclosure. Financial institutions should now review and update customer-communication scripts and staff
…
Cooley has launched a proprietary offering for ChatGPT Enterprise, developed with OpenAI, to accelerate the research and drafting of Form S-1 registration statements for companies going public.
Cooley announced the launch of Cooley GO Public, an AI-powered tool developed in partnership with OpenAI to streamline the initial public offering process. The system uses purpose-built AI agents inside ChatGPT Enterprise to generate a bespoke first draft of a Form S-1 registration statement, drawing on client-specific information and Cooley's curated precedents and drafting guidance. The firm claims this technology can reduce initial drafting time from days to minutes.
For corporate counsel and management teams, the tool aims to shift focus away from document assembly and toward critical strategic questions earlier in the IPO timeline, promising greater efficiency and cost predictability. For law firms, this represents a significant real-world application of generative AI to a core, high-stakes transactional practice. Cooley's lawyers remain involved for legal analysis and the final work product, but the development signals a major shift in legal service delivery. The firm plans to extend this AI model to other practice areas, including M&A and fund formation.
The next phase of the UK's Employment Rights Act 2025 will impose enhanced duties on employers to prevent sexual harassment and introduce new trade union provisions.
A significant new phase of the UK's Employment Rights Act 2025 is set to take effect in October 2026, introducing substantial new obligations for employers. The changes include an enhanced, proactive duty for employers to take reasonable steps to prevent sexual harassment in the workplace. This marks a shift from a reactive to a preventative compliance model. The reforms also signal the potential reintroduction of employer liability for harassment of their employees by third parties, such as clients or customers, which would significantly broaden the scope of an employer's legal responsibilities. Additionally, the act will implement wide-ranging provisions related to trade unions, further altering the labor relations landscape. For corporate counsel, these developments necessitate a preemptive review of existing anti-harassment policies, workplace training modules, and incident reporting mechanisms. UK employers should prepare for heightened compliance standards and increased litigation risk, particularly those in service industries with extensive public interaction. The key action i
…
The Securities and Exchange Commission granted a five-year conditional exemption allowing venues to trade tokenized National Market System stocks using blockchain-based systems.
The U.S. Securities and Exchange Commission has issued an order granting a five-year conditional exemption to certain trading venues from the definition of an “exchange” under the Securities Exchange Act of 1934. This exemption allows for the trading of tokenized National Market System (NMS) stock through innovative systems such as permissioned automated market makers and liquidity pools operating over public, permissionless blockchains.
This development is significant for financial services and technology clients as it creates a formal, albeit temporary, pathway for integrating decentralized finance concepts with the trading of traditional, highly regulated securities. The order signals a willingness by the SEC to accommodate innovation by allowing market participants to experiment with new technologies that could potentially enhance market efficiency and liquidity. Major-firm clients in the fintech and capital markets sectors will need to understand the conditions and limitations of the exemption to assess new business opportunities.
…
The U.S. Department of Energy is seeking industry comment on how it should implement a recent executive order intended to secure the nation’s bulk-power system from foreign supply-chain and cybersecurity threats.
Following President Trump’s August 26 executive order declaring a national emergency to secure the U.S. bulk-power system, the Department of Energy (DOE) has issued a formal Request for Information (RFI) seeking stakeholder input on implementation. The order, which invokes the International Emergency Economic Powers Act, aims to counter cyber and supply-chain threats by regulating transactions involving grid equipment sourced from foreign adversaries. The forthcoming rules will heavily impact utilities, equipment manufacturers, and energy project developers, potentially altering procurement practices and increasing compliance costs for critical components like transformers, inverters, and battery storage systems. The RFI presents a crucial opportunity for affected parties to shape the scope of the new regime, including definitions of key terms, supply chain due diligence standards, and the treatment of existing equipment. Interested stakeholders should consider submitting comments to the DOE by the October 9, 2026, deadline to influence the final regulations.
Developers of data centers are encountering significant new obstacles, including stronger public opposition, stricter local planning, and the complex technical demands of AI workloads.
The development of data centers is facing growing complexity and opposition, creating significant hurdles for a sector critical to the expansion of AI and cloud computing. According to one report, project cancellations in the US rose from six in 2024 to 25 in 2025, with an additional 20 projects worth $42 billion halted in early 2026 due to local resistance. This pushback, focused on noise, energy, and water use, is leading to more restrictive zoning and planning conditions.
Sophisticated counsel and their clients care because these challenges introduce substantial risk, cost, and delay into development timelines. The technical demands of AI are also transforming the construction and contracting phases, requiring cooling, power, and structural specifications for high-density computing from the outset. Lease agreements are evolving into complex hybrid real estate and technology service agreements.
…
California’s Office of Health Care Affordability has proposed emergency regulations that would significantly expand transaction notification and disclosure requirements for private equity groups and management services organizations.
California’s Office of Health Care Affordability (OHCA) has advanced emergency regulations that significantly broaden reporting obligations for healthcare transactions involving private equity groups and management services organizations (MSOs). The proposed rules, implementing Assembly Bill 1415, expand the state's existing 90-day pre-closing notice requirement. For sophisticated counsel and clients, these changes introduce substantial new deal friction. OHCA can order a "cost and market impact review" that may significantly delay closings. The proposal also mandates extensive new disclosures, including organizational charts up to the ultimate parent and details of management's deal-contingent financial incentives. The regulations apply broadly, capturing MSO changes of control where a PE fund acquires as little as a 10% interest, as well as certain sales of healthcare-related real estate. The Office of Administrative Law is expected to decide on the emergency action by late September 2026, after a very brief public comment period. If approved, the regulations will be effective for
…
Proposed legislation in the Australian state of Victoria would grant its anti-corruption body new “follow-the-money” powers to investigate private contractors receiving public funds.
The government of Victoria, Australia, has introduced a bill that would significantly expand the investigative powers of its anti-corruption watchdog, the IBAC, into the private sector. If passed, the law would grant IBAC new ‘follow-the-money’ authority to probe contractors, subcontractors, and other "associated entities" that handle public funds, extending the commission's reach deep into project supply chains. The bill also broadens the definition of "corrupt conduct" to capture serious non-criminal misconduct and even actions where an intended benefit was never actually realized. For companies with state government contracts, especially in the construction and infrastructure industries, the reform creates material new compliance risks and signals a tightening enforcement environment. The bill is reportedly being fast-tracked, and affected businesses are advised to proactively strengthen third-party due diligence and review their integrity controls in anticipation of the new regime, which could apply to some existing matters.
The English Court of Appeal held a standard-essential patent owner can satisfy its FRAND licensing obligation by offering terms to be finalized in binding arbitration, even over the licensee's objection.
In Acer v. Nokia, the English Court of Appeal ruled that a standard-essential patent (SEP) owner can satisfy its licensing obligations by offering an immediate license with final global royalty rates to be determined by binding arbitration. The court stayed the underlying English court proceedings sought by the licensees, Acer and ASUS, effectively compelling them to accept arbitration over their objection. This grants a significant strategic advantage to SEP owners, who can now choose arbitration as the dispute resolution forum for setting global FRAND terms, bypassing potentially less favorable court systems. The decision rested on the principle that if multiple sets of terms can be considered FRAND, the SEP owner is entitled to select the option it prefers. For implementers, this ruling complicates the strategy of seeking court intervention to set license terms and may reduce their leverage in negotiations. The court noted arbitration offers advantages, such as global enforceability under the New York Convention. Counsel should monitor whether the UK Supreme Court will review th
…
A new DOL bulletin directs investigators to prioritize three NQTL areas for mental health parity enforcement while a 2024 final rule remains subject to litigation and partial non-enforcement.
The U.S. Department of Labor issued a Field Assistance Bulletin on Sept. 8, 2026, clarifying its near-term enforcement priorities for the Mental Health Parity and Addiction Equity Act (MHPAEA). The guidance directs investigators to focus on three specific types of nonquantitative treatment limitations (NQTLs): blanket exclusions for mental health benefits, standards for medical necessity, and network adequacy. This development offers a clearer compliance roadmap for plan sponsors navigating the uncertainty created by a pending lawsuit that challenges the DOL’s 2024 final parity rule. While the agency has committed not to enforce certain "new" aspects of that rule, the bulletin narrowly defines those aspects, potentially leaving other controversial provisions, such as those relying on outcomes data to prove discrimination, subject to enforcement. The DOL also released a self-compliance tool that encourages plans to monitor outcomes. Plan sponsors should immediately assess their NQTLs against the three prioritized enforcement areas and monitor the ongoing litigation and the expected re
…
The proposal would shift compliance from a strict-liability standard to a principles-based approach rooted in existing antifraud and fiduciary duty rules.
The US Securities and Exchange Commission has proposed rescinding the investment adviser 'pay-to-play' rule, Rule 206(4)-5 under the Advisers Act. The SEC stated that the rule, in place since 2011, has functioned as a strict-liability trap, leading to enforcement actions for minor technical violations—such as small campaign contributions by employees with no client-facing role—rather than preventing genuine quid pro quo corruption. For advisers, the change would remove a significant compliance burden that had led some firms to ban all employee political contributions.
…
The US Food and Drug Administration plans to increase the frequency and intensity of Good Clinical Practice inspections for trials conducted outside the US, with a particular focus on China.
US Food and Drug Administration officials have signaled plans for more frequent and intense Good Clinical Practice (GCP) inspections of foreign clinical trials, including early-stage studies. In a recent article, leaders from FDA's drug, biologics, and device centers warned sponsors not to assume a lower probability of inspection for studies conducted abroad and pledged to increase resources for the agency's Bioresearch Monitoring program.
…
The FTC's Bureau of Consumer Protection has launched a new guidance program inviting stakeholders to identify problems with existing rules, creating a new avenue for regulatory engagement.
The Federal Trade Commission’s Bureau of Consumer Protection (BCP) has launched a new Rule Guidance Program, creating a formal channel for businesses and other stakeholders to raise concerns about existing FTC rules. Unlike requests for advisory opinions, this program expressly invites industry to identify problems with the regulations themselves, such as ambiguities, conflicts with other laws, or requirements made impractical by new technology.
…
A new Department of Labor final rule, effective September 21, eliminates the requirements for federal contractors to invite disability self-identification and meet a 7% utilization goal, citing conflicts with the ADA.
The U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) has issued a final rule eliminating the requirement for federal contractors to invite applicants and employees to self-identify as individuals with disabilities. The rule, which takes effect September 21, 2026, also retires Form CC-305 and removes the 7% disability utilization goal from Section 503 of the Rehabilitation Act.
The OFCCP concluded that these employer-initiated inquiries, even when voluntary, conflict with the Americans with Disabilities Act’s (ADA) restrictions on disability-related questions. This reversal requires contractors to take immediate action to update their hiring and employment workflows to mitigate ADA risk. While general nondiscrimination, accommodation, and recruitment obligations remain, the framework for measuring disability diversity has been fundamentally altered.
…
The Mortgage Bankers Association alleges New Jersey's new anti-discrimination rules for lending and housing are preempted by federal law and violate the Equal Protection Clause.
The Mortgage Bankers Association (MBA) has filed a federal lawsuit challenging New Jersey's disparate impact discrimination rules, which were adopted in late 2025 under the state's Law Against Discrimination. The MBA argues the state's regulations are inconsistent with federal law and unconstitutional.
Lenders, housing providers, and other businesses in New Jersey face heightened litigation risk because the challenged rules allegedly make it easier to bring a disparate impact claim. The MBA's complaint asserts that the state's standard contravenes U.S. Supreme Court precedent by allowing claims based on broad statistics rather than an entity’s specific policy and by improperly shifting the burden of proof to the business to show that no less discriminatory alternative exists. The lawsuit further alleges the rules are preempted by the federal Fair Housing Act and Equal Credit Opportunity Act and violate the Equal Protection Clause.
…
A new Department of Labor bulletin directs EBSA enforcement of mental health parity rules toward three high-risk areas: separate exclusions, medical-necessity review, and network adequacy standards.
The US Department of Labor’s Employee Benefits Security Administration (EBSA) issued a Field Assistance Bulletin outlining its immediate enforcement priorities for the Mental Health Parity and Addiction Equity Act (MHPAEA). The guidance gives group health plan sponsors a clear view of where regulators will focus scrutiny of nonquantitative treatment limitations (NQTLs), despite ongoing litigation and a partial nonenforcement policy related to a separate 2024 rule.
…
Manufacturers of hardware and software sold in the EU must now report actively exploited vulnerabilities and severe incidents to ENISA, with initial notifications due within 24 hours of awareness.
The first major compliance deadline under the EU's Cyber Resilience Act (CRA) is now in effect. As of September 11, 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents that impact their "products with digital elements" (PDEs). The CRA's scope is extensive, covering most software and hardware products placed on the EU market, irrespective of the manufacturer's location, size, or sector.
This creates an immediate and critical compliance burden for global businesses. The reporting timelines are extremely aggressive: an 'early warning' notification must be submitted to the EU's cybersecurity agency, ENISA, via its Single Reporting Platform within 24 hours of awareness. A more detailed notification must follow within 72 hours. These obligations are distinct from and apply more broadly than those under the existing NIS2 Directive.
…
The UK's Competition and Markets Authority is proposing to use data-driven screening tools on Ministry of Defence procurement data to detect and deter bid-rigging.
The UK's Competition and Markets Authority (CMA) is intensifying its fight against bid-rigging in public procurement, proposing to use data analytics to scrutinize Ministry of Defence (MoD) contracts. The initiative reflects the CMA's view that tackling collusion is a key priority, especially within the UK's £400 billion public purchasing market. The agency plans to expand the use of its Bid Rigging Intelligence Tool (BRIT) to detect suspicious patterns, and it is calling for the mandatory, centralized collection of bid-level data—including from losing bidders—to make this screening effective. For government contractors, particularly in the defense sector, this signals a significant increase in enforcement risk. The consequences for cartel conduct are severe, ranging from heavy fines and director disqualifications to potential criminal prosecution and, crucially, mandatory debarment from future public contracts under the new Procurement Act 2023. Counsel should advise clients in this space to anticipate heightened scrutiny and ensure their bidding practices and compliance programs ar
…
In one of the first major enforcement actions under the EU's Foreign Subsidies Regulation, a Belgian court suspended the award of a €750 million casino concession due to the winning bidder's non-compliance.
A Belgian court has suspended the award of a €750 million casino concession, marking one of the first significant enforcement actions under the EU's Foreign Subsidies Regulation (FSR). The decision was reportedly based on the winning bidder's failure to comply with the FSR's mandatory disclosure requirements for foreign financial contributions in large public procurement procedures.
This ruling is a critical development for global businesses operating in the European Union. It demonstrates that national authorities are actively enforcing the FSR and are willing to halt major, high-value contracts for procedural non-compliance. The case underscores the serious risks for companies that receive financial support from non-EU governments, highlighting the importance of meticulously tracking such contributions and adhering to the regulation's reporting obligations. Sophisticated counsel should advise clients to immediately review and strengthen their internal FSR compliance programs. The market will be closely watching for further enforcement actions at the national level and any responsi
…
The EU's General Court has upheld the European Commission's decision to block Booking's acquisition of Etraveli, endorsing a novel "ecosystem" theory of competitive harm with broad implications for digital platform M&A.
The EU's General Court has affirmed the European Commission's 2023 decision to prohibit Booking Holdings' proposed acquisition of Etraveli. The Commission blocked the deal based on a novel "ecosystem" theory of harm, arguing that the merger would allow the already-dominant hotel online travel agent (OTA), Booking, to entrench its position by acquiring a leading flight OTA and cross-selling services to a wider captive audience. This "reverse leveraging," where an acquisition in an adjacent market reinforces dominance in a core market, is not explicitly detailed in current non-horizontal merger guidelines.
…
The Senate Banking, Housing, and Urban Affairs Committee's vote on Brian Johnson's nomination is a key hurdle in the process of appointing a new leader for the consumer finance watchdog.
The Senate Banking, Housing, and Urban Affairs Committee is scheduled to vote on whether to advance the nomination of Brian Johnson to be the next Director of the Consumer Financial Protection Bureau (CFPB). This committee vote is a critical gateway, determining if the nomination proceeds to the full Senate for a final confirmation vote. The outcome is highly consequential for the financial services industry, as the CFPB Director wields significant power to set the agency's enforcement and rulemaking agenda. A change in leadership could signal a major shift in the Bureau's approach to supervision and its stance on fair lending, debt collection, and emerging financial technology. Financial institutions and their counsel are closely watching, as a new director can reshape the regulatory landscape, affecting compliance programs and litigation risk. If the committee approves the nomination, the next step will be consideration by the full Senate, with a potential vote ahead of a scheduled pre-election recess in early October.
The FTC's Bureau of Consumer Protection has launched a new guidance program inviting stakeholders to identify problems with existing rules, creating a new avenue for regulatory engagement.
The Federal Trade Commission’s Bureau of Consumer Protection (BCP) has launched a new Rule Guidance Program, creating a formal channel for businesses and other stakeholders to raise concerns about existing FTC rules. Unlike requests for advisory opinions, this program expressly invites industry to identify problems with the regulations themselves, such as ambiguities, conflicts with other laws, or requirements made impractical by new technology.
…
The Mortgage Bankers Association alleges New Jersey's new anti-discrimination rules for lending and housing are preempted by federal law and violate the Equal Protection Clause.
The Mortgage Bankers Association (MBA) has filed a federal lawsuit challenging New Jersey's disparate impact discrimination rules, which were adopted in late 2025 under the state's Law Against Discrimination. The MBA argues the state's regulations are inconsistent with federal law and unconstitutional.
Lenders, housing providers, and other businesses in New Jersey face heightened litigation risk because the challenged rules allegedly make it easier to bring a disparate impact claim. The MBA's complaint asserts that the state's standard contravenes U.S. Supreme Court precedent by allowing claims based on broad statistics rather than an entity’s specific policy and by improperly shifting the burden of proof to the business to show that no less discriminatory alternative exists. The lawsuit further alleges the rules are preempted by the federal Fair Housing Act and Equal Credit Opportunity Act and violate the Equal Protection Clause.
…
A new law firm guide advises public companies on a complex risk environment, highlighting a new SEC financial reporting enforcement unit, aggressive state attorneys general, and fragmented state-level AI laws.
A Skadden client briefing outlines a converging set of risks for public company boards, demanding heightened oversight. The guide points to the SEC's creation of a new, consolidated enforcement unit dedicated to financial reporting, which is expected to pursue more numerous and complex investigations. Concurrently, state attorneys general are becoming more aggressive in filling perceived federal voids, launching their own antitrust, consumer protection, and privacy enforcement actions. This trend is amplified by the growing patchwork of state-level AI regulations, which creates significant compliance challenges for companies operating nationwide. For corporate counsel and their clients, this environment means preparing for scrutiny on multiple fronts. The firm advises boards to re-examine financial disclosure processes, develop adaptable compliance frameworks for divergent state laws, and prepare for potential investigations initiated by a wider range of government actors.
While fewer contests went to a vote, activists gained dozens of board seats via settlements, increasingly using AI adoption as a campaign theme and navigating new SEC disclosure rules for SPVs.
Shareholder activism in the U.S. reached a record high in the first half of 2026, but the tactics and themes are evolving significantly. While only four proxy contests went to a vote, activists secured 51 board seats, mostly through settlements. Campaigns increasingly target technology and consumer companies, with slow AI adoption emerging as a key complaint. Sophisticated counsel should note two major shifts creating uncertainty. First, new SEC staff guidance from July 2026 requires disclosure of investors in special purpose vehicles (SPVs) formed to target a specific company, which could chill fundraising for smaller activist funds that rely on anonymous backers. Second, the proxy advisory landscape is fracturing under regulatory pressure and market changes, with major institutions like JPMorgan turning to AI for voting decisions instead of relying on traditional advisors. This unpredictability, coupled with the rise of off-cycle pressure campaigns, requires boards to prepare for earlier, more direct, and more tailored shareholder engagement to avoid costly public fights.
Manufacturers of hardware and software sold in the EU must now report actively exploited vulnerabilities and severe incidents to ENISA, with initial notifications due within 24 hours of awareness.
The first major compliance deadline under the EU's Cyber Resilience Act (CRA) is now in effect. As of September 11, 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents that impact their "products with digital elements" (PDEs). The CRA's scope is extensive, covering most software and hardware products placed on the EU market, irrespective of the manufacturer's location, size, or sector.
This creates an immediate and critical compliance burden for global businesses. The reporting timelines are extremely aggressive: an 'early warning' notification must be submitted to the EU's cybersecurity agency, ENISA, via its Single Reporting Platform within 24 hours of awareness. A more detailed notification must follow within 72 hours. These obligations are distinct from and apply more broadly than those under the existing NIS2 Directive.
…
A UK Employment Rights Act provision effective January 2027 will make it automatically unfair to dismiss an employee and replace them with a non-employee, creating significant new risks for any business restructure.
A new provision in the UK's Employment Rights Act, effective January 2027, will introduce significant risk for employers undertaking workforce restructures. The incoming section 104K will create a new category of automatically unfair dismissal if the main reason for termination is to have the employee's work done by a non-employee, such as a contractor, consultant, or agency worker. Sophisticated counsel and clients should care because this type of claim requires no qualifying service period from the employee and compensation for a finding of unfair dismissal is uncapped. This creates a hidden trap where a dismissal for what an employer considers a genuine redundancy could be re-characterized as a prohibited 'workforce replacement,' even if the restructure has a strong commercial rationale. Ambiguities remain regarding the provision's interaction with existing TUPE regulations and its application to complex group structures. Employers planning any restructure that involves replacing permanent roles with flexible resources must now carefully document that the need for employees has ge
…
A UK appellate court held that an employer’s vicarious liability for employee torts against a third party does not transfer to the buyer of a business under the country's employee-protection regulations.
The UK Court of Appeal has ruled that a business acquirer does not inherit the seller's vicarious liability for employee torts committed against third parties. The decision clarifies the scope of the Transfer of Undertakings (Protection of Employment) Regulations 2006 (TUPE), which are designed to protect employee rights during a business transfer. In ABC v Huntercombe, the court rejected a claimant's "opportunistic" attempt to hold the new owner of a hospital liable for alleged abuse by the former owner's staff, especially after the former owner entered liquidation. The court held that TUPE's provision transferring liabilities "under or in connection with" a contract of employment applies only to liabilities owed to employees, not to third parties. This ruling provides significant certainty for buyers in UK asset deals, confirming that they do not step into the shoes of the seller for pre-transfer torts against non-employees. The immediate impact is on over fifty similar claims awaiting case management, but the precedent will shape risk allocation in UK M&A going forward.
The next phase of the UK's Employment Rights Act 2025 will impose enhanced duties on employers to prevent sexual harassment and introduce new trade union provisions.
A significant new phase of the UK's Employment Rights Act 2025 is set to take effect in October 2026, introducing substantial new obligations for employers. The changes include an enhanced, proactive duty for employers to take reasonable steps to prevent sexual harassment in the workplace. This marks a shift from a reactive to a preventative compliance model. The reforms also signal the potential reintroduction of employer liability for harassment of their employees by third parties, such as clients or customers, which would significantly broaden the scope of an employer's legal responsibilities. Additionally, the act will implement wide-ranging provisions related to trade unions, further altering the labor relations landscape. For corporate counsel, these developments necessitate a preemptive review of existing anti-harassment policies, workplace training modules, and incident reporting mechanisms. UK employers should prepare for heightened compliance standards and increased litigation risk, particularly those in service industries with extensive public interaction. The key action i
…
A new DOL bulletin directs investigators to prioritize three NQTL areas for mental health parity enforcement while a 2024 final rule remains subject to litigation and partial non-enforcement.
The U.S. Department of Labor issued a Field Assistance Bulletin on Sept. 8, 2026, clarifying its near-term enforcement priorities for the Mental Health Parity and Addiction Equity Act (MHPAEA). The guidance directs investigators to focus on three specific types of nonquantitative treatment limitations (NQTLs): blanket exclusions for mental health benefits, standards for medical necessity, and network adequacy. This development offers a clearer compliance roadmap for plan sponsors navigating the uncertainty created by a pending lawsuit that challenges the DOL’s 2024 final parity rule. While the agency has committed not to enforce certain "new" aspects of that rule, the bulletin narrowly defines those aspects, potentially leaving other controversial provisions, such as those relying on outcomes data to prove discrimination, subject to enforcement. The DOL also released a self-compliance tool that encourages plans to monitor outcomes. Plan sponsors should immediately assess their NQTLs against the three prioritized enforcement areas and monitor the ongoing litigation and the expected re
…
A new Department of Labor final rule, effective September 21, eliminates the requirements for federal contractors to invite disability self-identification and meet a 7% utilization goal, citing conflicts with the ADA.
The U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) has issued a final rule eliminating the requirement for federal contractors to invite applicants and employees to self-identify as individuals with disabilities. The rule, which takes effect September 21, 2026, also retires Form CC-305 and removes the 7% disability utilization goal from Section 503 of the Rehabilitation Act.
The OFCCP concluded that these employer-initiated inquiries, even when voluntary, conflict with the Americans with Disabilities Act’s (ADA) restrictions on disability-related questions. This reversal requires contractors to take immediate action to update their hiring and employment workflows to mitigate ADA risk. While general nondiscrimination, accommodation, and recruitment obligations remain, the framework for measuring disability diversity has been fundamentally altered.
…
A new Department of Labor bulletin directs EBSA enforcement of mental health parity rules toward three high-risk areas: separate exclusions, medical-necessity review, and network adequacy standards.
The US Department of Labor’s Employee Benefits Security Administration (EBSA) issued a Field Assistance Bulletin outlining its immediate enforcement priorities for the Mental Health Parity and Addiction Equity Act (MHPAEA). The guidance gives group health plan sponsors a clear view of where regulators will focus scrutiny of nonquantitative treatment limitations (NQTLs), despite ongoing litigation and a partial nonenforcement policy related to a separate 2024 rule.
…
The U.S. Department of Energy is seeking industry comment on how it should implement a recent executive order intended to secure the nation’s bulk-power system from foreign supply-chain and cybersecurity threats.
Following President Trump’s August 26 executive order declaring a national emergency to secure the U.S. bulk-power system, the Department of Energy (DOE) has issued a formal Request for Information (RFI) seeking stakeholder input on implementation. The order, which invokes the International Emergency Economic Powers Act, aims to counter cyber and supply-chain threats by regulating transactions involving grid equipment sourced from foreign adversaries. The forthcoming rules will heavily impact utilities, equipment manufacturers, and energy project developers, potentially altering procurement practices and increasing compliance costs for critical components like transformers, inverters, and battery storage systems. The RFI presents a crucial opportunity for affected parties to shape the scope of the new regime, including definitions of key terms, supply chain due diligence standards, and the treatment of existing equipment. Interested stakeholders should consider submitting comments to the DOE by the October 9, 2026, deadline to influence the final regulations.
New UK deforestation rules and EU regulations on sustainable packaging and greenwashing are creating significant new due diligence hurdles and potential liabilities for corporate transactions.
A trio of regulatory developments in the UK and EU is set to reshape ESG compliance and transaction diligence. The UK government announced it will expand mandatory due diligence requirements to cover a wide range of "forest risk commodities" beyond timber, including soy, palm oil, and beef, aligning with the EU’s Deforestation Regulation (EUDR). In parallel, the EU’s Packaging and Packaging Waste Regulation (PPWR) began to take effect in August 2026, imposing new standards for recyclability and waste reduction. Finally, the EU’s directive against greenwashing (ECGTD) comes into force September 27, 2026, prohibiting vague environmental claims like "eco-friendly" and sustainability labels not based on official certification. For corporate and private equity deal teams, these rules introduce critical new diligence streams. Acquirers must now rigorously assess a target’s supply-chain exposure, packaging compliance, and marketing claims to avoid inheriting significant post-closing liabilities and remediation costs. Counsel should watch for UK legislation implementing the deforestation reg
…
A new EU law will use procurement preferences and financial aid to incentivize local production of critical medicines, shifting the market to favor supply-chain resilience over lowest cost.
The EU has reached a provisional political agreement on its Critical Medicines Act, a significant legislative effort to secure the bloc's supply of essential pharmaceuticals. The Act introduces a "stick and carrot" approach to incentivize onshoring. Contracting authorities in public procurement procedures will be required to implement resilience-related criteria that establish a preference for EU-manufactured critical medicines. For non-EU producers, this could dilute the appeal of cheaper generics and may necessitate establishing EU production facilities or partnerships. To further support this shift, the Act allows member states and the EU to designate certain projects as "strategic," granting them access to fast-track permits, streamlined administrative processes, and direct financial support. Pharmaceutical manufacturers and their investors should now assess their supply chains and EU manufacturing capacity, as the legislation signals a structural shift away from lowest-price models toward rewarding local production and supply-chain security. The final text is expected by late 20
…
The US Food and Drug Administration plans to increase the frequency and intensity of Good Clinical Practice inspections for trials conducted outside the US, with a particular focus on China.
US Food and Drug Administration officials have signaled plans for more frequent and intense Good Clinical Practice (GCP) inspections of foreign clinical trials, including early-stage studies. In a recent article, leaders from FDA's drug, biologics, and device centers warned sponsors not to assume a lower probability of inspection for studies conducted abroad and pledged to increase resources for the agency's Bioresearch Monitoring program.
…
The SEC has proposed replacing its prescriptive ban on political contributions by investment advisers with a principles-based approach relying on existing anti-fraud and compliance rules.
The U.S. Securities and Exchange Commission has proposed a full rescission of its 'pay-to-play' rule for investment advisers, Rule 206(4)-5 under the Investment Advisers Act. The 2010 rule currently prohibits advisers from receiving compensation from government-entity clients for two years after the adviser or a covered employee makes a political contribution to an official who could influence the awarding of advisory contracts. Citing concerns that the rule unduly suppresses political speech, imposes significant operational complexity, and creates a 'de facto strict liability' framework, the SEC is advocating a shift to a principles-based approach. Instead of the prescriptive ban, advisers would rely on existing anti-fraud provisions and their own compliance programs to mitigate pay-to-play risks. While this offers flexibility, it places the onus on firms to design and implement defensible policies. Advisers with government clients must also remember that numerous state and local pay-to-play laws would remain in effect regardless of federal action. The proposal, which also eliminate
…
The European Securities and Markets Authority's latest risk report highlights concerns about investor protection, insider trading, and market manipulation, signaling future regulatory action.
For the first time, the European Securities and Markets Authority (ESMA) has spotlighted prediction markets in its Trends, Risks, and Vulnerabilities report, flagging significant dangers for market participants. The agency raised concerns about retail investor harm from "speculative gambling environments," the potential for insider trading, and data manipulation affecting contract settlements. The report also noted that decentralized finance (DeFi) and AI could amplify these risks.
…
Five federal financial regulators have jointly clarified that banks can communicate with customers about the underlying facts and transactions of suspected fraud without violating rules on Suspicious Activity Report confidentiality.
In a significant clarification for financial institutions, five U.S. federal regulators jointly stated that banks and credit unions may discuss the underlying facts of suspicious transactions with customers without violating Bank Secrecy Act confidentiality rules. The September 2, 2026, statement from the Federal Reserve, FDIC, OCC, NCUA, and FinCEN addresses a long-standing tension between transparency and the prohibition against disclosing the existence of a Suspicious Activity Report (SAR). The guidance confirms that while an institution can never reveal that a SAR has been or will be filed, it is permitted to discuss the specific transactions, dates, amounts, and other facts that prompted the concern. This allows banks to provide customers, including potential fraud victims, with clearer explanations for account restrictions, rejected deposits, or account closures. The agencies noted that a customer deducing a SAR might be filed from these facts does not constitute an improper disclosure. Financial institutions should now review and update customer-communication scripts and staff
…
The proposal would shift compliance from a strict-liability standard to a principles-based approach rooted in existing antifraud and fiduciary duty rules.
The US Securities and Exchange Commission has proposed rescinding the investment adviser 'pay-to-play' rule, Rule 206(4)-5 under the Advisers Act. The SEC stated that the rule, in place since 2011, has functioned as a strict-liability trap, leading to enforcement actions for minor technical violations—such as small campaign contributions by employees with no client-facing role—rather than preventing genuine quid pro quo corruption. For advisers, the change would remove a significant compliance burden that had led some firms to ban all employee political contributions.
…
A draft statutory instrument laid before the UK Parliament and new FCA perimeter guidance clarify the scope of regulated cryptoasset activities, including staking and stablecoins, ahead of a 2027 effective date.
The UK government has laid a draft statutory instrument before Parliament to govern cryptoassets, while the Financial Conduct Authority (FCA) has published corresponding perimeter guidance. The new framework, part of the Financial Services and Markets Act, is set to commence on October 25, 2027, with the firm authorisation window opening in September 2026.
This development is critical for all firms in the digital asset space operating in or providing services to the UK. The publications provide significant clarity on the scope of regulated activities, addressing key industry concerns around territoriality, staking, safeguarding, and stablecoins. The statutory instrument introduces important exclusions, including for certain technical service providers and proprietary trading, to avoid stifling innovation and placing UK firms at a competitive disadvantage. It also clarifies rules for stablecoin backing and nominee-operated safeguarding arrangements.
…
Australian regulators have warned digital asset providers that they must apply for or vary a financial services licence by September 30, 2026, or risk illegal operation under a new framework.
Australia's securities regulator, ASIC, has issued a final reminder for digital asset businesses to apply for or vary an Australian financial services licence (AFSL) by the upcoming September 30, 2026 deadline. This action is a key implementation step for the new Corporations Amendment (Digital Assets Framework) Act 2026, which is set to come into force on April 9, 2027, and establishes a comprehensive regulatory framework for the sector.
…
The Securities and Exchange Commission granted a five-year conditional exemption allowing venues to trade tokenized National Market System stocks using blockchain-based systems.
The U.S. Securities and Exchange Commission has issued an order granting a five-year conditional exemption to certain trading venues from the definition of an “exchange” under the Securities Exchange Act of 1934. This exemption allows for the trading of tokenized National Market System (NMS) stock through innovative systems such as permissioned automated market makers and liquidity pools operating over public, permissionless blockchains.
This development is significant for financial services and technology clients as it creates a formal, albeit temporary, pathway for integrating decentralized finance concepts with the trading of traditional, highly regulated securities. The order signals a willingness by the SEC to accommodate innovation by allowing market participants to experiment with new technologies that could potentially enhance market efficiency and liquidity. Major-firm clients in the fintech and capital markets sectors will need to understand the conditions and limitations of the exemption to assess new business opportunities.
…
A federal appeals court has struck down parts of the methodology for calculating out-of-network payment rates, adding new complexity for payors and providers navigating the federal dispute resolution process.
The US Court of Appeals for the Fifth Circuit has invalidated key federal regulations governing how insurers calculate the Qualifying Payment Amount (QPA), a crucial benchmark in out-of-network billing disputes under the No Surprises Act (NSA). Affirming a lower court, the panel ruled insurers may not include non-negotiated "ghost rates" and must include bonus and incentive payments in their QPA calculations, a decision expected to shift leverage in payment negotiations and the Independent Dispute Resolution (IDR) process.
…
California’s Office of Health Care Affordability has proposed emergency regulations that would significantly expand transaction notification and disclosure requirements for private equity groups and management services organizations.
California’s Office of Health Care Affordability (OHCA) has advanced emergency regulations that significantly broaden reporting obligations for healthcare transactions involving private equity groups and management services organizations (MSOs). The proposed rules, implementing Assembly Bill 1415, expand the state's existing 90-day pre-closing notice requirement. For sophisticated counsel and clients, these changes introduce substantial new deal friction. OHCA can order a "cost and market impact review" that may significantly delay closings. The proposal also mandates extensive new disclosures, including organizational charts up to the ultimate parent and details of management's deal-contingent financial incentives. The regulations apply broadly, capturing MSO changes of control where a PE fund acquires as little as a 10% interest, as well as certain sales of healthcare-related real estate. The Office of Administrative Law is expected to decide on the emergency action by late September 2026, after a very brief public comment period. If approved, the regulations will be effective for
…
A growing number of African governments are tightening control over strategic mineral resources through new taxes, local ownership rules, and license revocations, creating significant new risks for foreign investors.
Several African nations, including the Democratic Republic of the Congo, Mali, Zambia, and Ghana, are increasingly asserting sovereign control over their natural resources, particularly minerals critical for the global energy transition. This wave of 'resource nationalism' includes measures such as increasing royalty rates and taxes, mandating higher state or local shareholdings in mining projects, banning the export of unprocessed minerals to force domestic refining, and, in some cases, cancelling licenses and nationalizing assets.
…
In a key victory for Merck, the Patent Trial and Appeal Board invalidated a Halozyme patent related to Keytruda Qlex™ technology, finding the claims unpatentable for lack of written description and enablement.
The US Patent Trial and Appeal Board (PTAB) delivered a significant win for Merck, issuing a final written decision that invalidates all challenged claims of a Halozyme patent for its PH20 hyaluronidase technology. The Board found the patent unpatentable for lacking adequate written description and enablement, siding with Merck’s arguments in the post-grant review. However, the PTAB rejected Merck's separate arguments that the claims were obvious.
…
The English Court of Appeal held a standard-essential patent owner can satisfy its FRAND licensing obligation by offering terms to be finalized in binding arbitration, even over the licensee's objection.
In Acer v. Nokia, the English Court of Appeal ruled that a standard-essential patent (SEP) owner can satisfy its licensing obligations by offering an immediate license with final global royalty rates to be determined by binding arbitration. The court stayed the underlying English court proceedings sought by the licensees, Acer and ASUS, effectively compelling them to accept arbitration over their objection. This grants a significant strategic advantage to SEP owners, who can now choose arbitration as the dispute resolution forum for setting global FRAND terms, bypassing potentially less favorable court systems. The decision rested on the principle that if multiple sets of terms can be considered FRAND, the SEP owner is entitled to select the option it prefers. For implementers, this ruling complicates the strategy of seeking court intervention to set license terms and may reduce their leverage in negotiations. The court noted arbitration offers advantages, such as global enforceability under the New York Convention. Counsel should monitor whether the UK Supreme Court will review th
…
A federal district court ruling has created a September 28, 2026, deadline for civil claims against companies for allegedly aiding and abetting terrorism as far back as September 11, 2001.
A 2025 federal district court decision has opened a litigation window that is expected to close on September 28, 2026, for civil claims under the Justice Against Sponsors of Terrorism Act (JASTA). The ruling in Moses v. BNP Paribas held that JASTA’s ten-year statute of limitations runs from the date of the law's enactment in 2016, not from the date of the underlying injury. This interpretation makes claims timely for conduct related to terrorist acts as far back as September 11, 2001.
…
An amendment to Delaware's data breach notification law requires earlier notice to the Attorney General in some cases and narrows the compliance safe harbor for entities regulated by GLBA and HIPAA.
Delaware has amended its data breach notification statute, effective immediately, creating new obligations for companies holding personal information of state residents. The law, HB 381, introduces an early reporting requirement, obligating entities to notify the Attorney General within 60 days of discovering a breach if they cannot identify the specific affected residents within that timeframe. This change could accelerate regulatory reporting deadlines, particularly in complex incidents requiring prolonged forensic analysis.
…
The proposed regulation would harmonize rules for protecting minors online, introducing strict age verification, account bans for users under 13, and 'safety by design' mandates.
The European Commission has proposed a new regulation, the 'EU Kids Act,' to create a unified framework for protecting minors online, superseding fragmented national laws. The draft regulation would apply broadly to social networks, video-sharing platforms, app stores, online games, and AI chatbots serving EU users, regardless of where the providers are established. Key provisions include mandatory age verification through certified solutions, a general prohibition on accounts for children under 13, and parent-controlled, feature-limited accounts for those aged 13-15. Sophisticated clients care because the act imposes 'safety by design' obligations for all users under 18, expressly prohibiting features deemed addictive, such as infinite scroll and autoplay. Non-compliance could lead to fines of up to 6% of global annual turnover. The proposal now enters the EU legislative process for negotiation between the Parliament and Council. While adoption is not expected before 2028, affected companies must now track the bill's progress and prepare for a potentially stringent new compliance re
…
Developers of data centers are encountering significant new obstacles, including stronger public opposition, stricter local planning, and the complex technical demands of AI workloads.
The development of data centers is facing growing complexity and opposition, creating significant hurdles for a sector critical to the expansion of AI and cloud computing. According to one report, project cancellations in the US rose from six in 2024 to 25 in 2025, with an additional 20 projects worth $42 billion halted in early 2026 due to local resistance. This pushback, focused on noise, energy, and water use, is leading to more restrictive zoning and planning conditions.
Sophisticated counsel and their clients care because these challenges introduce substantial risk, cost, and delay into development timelines. The technical demands of AI are also transforming the construction and contracting phases, requiring cooling, power, and structural specifications for high-density computing from the outset. Lease agreements are evolving into complex hybrid real estate and technology service agreements.
…
Peru's executive branch has asked Congress for a 120-day grant of authority to issue legislative decrees affecting finance, mining, energy, and supply-chain rules.
Peru's executive branch has submitted a bill seeking a 120-day grant of delegated power from Congress to enact sweeping regulatory reforms by decree. This would allow the government to bypass the ordinary legislative process to implement changes across eight policy areas. For sophisticated counsel and their clients, the proposal creates both uncertainty and potential opportunity. Key measures under consideration include the elimination of statutory interest rate caps, the modification of rules for mining concessions, and the streamlining of environmental and infrastructure project permitting. The bill also contemplates new compliance obligations, including a prohibition on importing goods made with forced labor and a framework for designating certain criminal organizations as terrorist entities, which would affect AML and screening protocols. The bill faces an uncertain path in Congress, with several committees having issued unfavorable opinions, and the final scope of any delegated authority may be narrower than requested. Companies with Peruvian interests should monitor the bill's
…
The agency has proposed eliminating the 80-year-old federal framework that requires companies to include qualifying shareholder proposals in their proxy materials.
The US Securities and Exchange Commission has proposed rescinding Rule 14a-8, the framework that for over 80 years has allowed shareholders to require companies to include qualifying proposals in corporate proxy materials. Citing a belief that the rule exceeds its statutory authority and displaces state corporate law, the SEC's proposal would remove the uniform federal mechanism for shareholder-initiated proposals. If adopted, this would fundamentally alter the landscape for shareholder activism, shifting the focus to state law, company-specific bylaws, and other tactics like director “vote-no” campaigns and independent solicitations.
…
The proposed changes would end decades of federal oversight and shift the regulation of shareholder proposals to state law and individual company governing documents.
On September 16, 2026, the U.S. Securities and Exchange Commission proposed a fundamental overhaul of the shareholder proposal process by rescinding Rule 14a-8 of the Exchange Act. For decades, this rule has provided the federal framework for shareholders to include proposals in company proxy statements. The SEC's move, justified as a response to the rule exceeding its statutory authority, would shift this regulatory arena entirely to state law and individual companies’ governing documents.
This creates significant uncertainty for public companies and institutional investors. Key corporate law jurisdictions like Delaware have underdeveloped case law on the matter, potentially leading to a fragmented and unpredictable legal landscape. The change could spur litigation as companies and shareholders test the boundaries of new state-level regimes and corporate bylaws. Other proposed amendments aim to modernize proxy solicitations, including eliminating the mandatory delivery of glossy annual reports and shortening certain deadlines.
…
Cooley has launched a proprietary offering for ChatGPT Enterprise, developed with OpenAI, to accelerate the research and drafting of Form S-1 registration statements for companies going public.
Cooley announced the launch of Cooley GO Public, an AI-powered tool developed in partnership with OpenAI to streamline the initial public offering process. The system uses purpose-built AI agents inside ChatGPT Enterprise to generate a bespoke first draft of a Form S-1 registration statement, drawing on client-specific information and Cooley's curated precedents and drafting guidance. The firm claims this technology can reduce initial drafting time from days to minutes.
For corporate counsel and management teams, the tool aims to shift focus away from document assembly and toward critical strategic questions earlier in the IPO timeline, promising greater efficiency and cost predictability. For law firms, this represents a significant real-world application of generative AI to a core, high-stakes transactional practice. Cooley's lawyers remain involved for legal analysis and the final work product, but the development signals a major shift in legal service delivery. The firm plans to extend this AI model to other practice areas, including M&A and fund formation.
With no federal AI law, states are creating a complex patchwork of rules for developers and users, posing significant cross-border compliance challenges.
In the absence of a comprehensive federal framework, a growing number of U.S. states, including California, New York, and Colorado, have enacted their own laws governing artificial intelligence. This has created a fragmented regulatory landscape with widely divergent approaches. Some laws focus on the developers of advanced AI models, imposing transparency and safety obligations, while others target companies that deploy AI for "consequential decisions" in areas like employment, lending, and healthcare, often focusing on algorithmic discrimination and disclosure. This state-by-state approach presents significant compliance challenges for companies operating nationally, forcing them to navigate a complex web of potentially conflicting requirements. The situation is further complicated by reports that the federal administration prefers a unified national standard and may challenge certain state laws. Boards and in-house counsel must now establish robust governance processes to monitor these developments, identify applicable state regimes, and create compliance frameworks that can adapt
…
An exposure draft bill would require a broad range of online service providers to take reasonably practicable steps to ensure a safe online environment for users.
The Australian government has released an exposure draft of the Online Safety Amendment (Digital Duty of Care) Bill 2026, proposing a significant shift in the country's platform regulation. The bill would move from a co-regulatory model to a direct one, imposing a broad "digital duty of care" on online services—including social media, search engines, AI providers, and device manufacturers—to ensure a safe environment for users.
Sophisticated clients and counsel care because the duty is expansive, requiring providers to take all "reasonably practicable" steps to protect users in Australia from a wide range of harmful materials and conduct. The proposal also includes specific prohibitions on design features like recommender systems and endless feeds for users under 16. The eSafety Commissioner would gain new enforcement powers, including the authority to issue directions and impose penalties of up to approximately AUD 109 million for non-compliance. The short consultation period suggests the government intends to advance the legislation quickly, requiring affected companies to prepare
…
The court joined every other circuit to have ruled on the issue in holding that whistleblower relators are not "officers" under the Appointments Clause, preserving a key government anti-fraud tool.
The US Court of Appeals for the Eleventh Circuit, in United States ex rel. Zafirov v. Florida Medical Associates, reversed a district court and held that the False Claims Act's (FCA) qui tam provisions do not violate the Constitution's Appointments Clause. Defendants have increasingly argued that allowing private whistleblowers, or "relators," to sue on the government's behalf unconstitutionally grants executive power to individuals who are not appointed as federal officers. This decision aligns the Eleventh Circuit with the Fifth, Sixth, Ninth, and Tenth Circuits, preventing a circuit split that might have forced Supreme Court review. With billions of dollars recovered annually through qui tam actions, the ruling preserves a critical tool for government fraud enforcement.
…
An August 13 memo from the Department of Justice's reconstituted National Fraud Enforcement Division signals a new focus on tax-related crimes affecting companies across all industries.
The U.S. Department of Justice's Fraud Division has signaled a significant shift in its enforcement strategy, placing a heightened emphasis on tax-related offenses. An August 13 memorandum announced the priorities for the newly reconstituted National Fraud Enforcement Division, making clear that tax crimes are a central focus. Sophisticated counsel should advise clients that this is not a niche concern for the financial industry; the memo indicates that scrutiny will apply to companies across all sectors. This development increases the risk profile for corporate tax positions and reporting methodologies. In-house legal, finance, and tax departments should anticipate more aggressive federal investigations and prosecutions in this area. Prudent companies may wish to review their existing tax compliance programs and ensure their reporting structures can withstand increased government scrutiny. The key development to watch is how the DOJ begins to implement this policy through new investigations and charging decisions.
Proposed legislation in the Australian state of Victoria would grant its anti-corruption body new “follow-the-money” powers to investigate private contractors receiving public funds.
The government of Victoria, Australia, has introduced a bill that would significantly expand the investigative powers of its anti-corruption watchdog, the IBAC, into the private sector. If passed, the law would grant IBAC new ‘follow-the-money’ authority to probe contractors, subcontractors, and other "associated entities" that handle public funds, extending the commission's reach deep into project supply chains. The bill also broadens the definition of "corrupt conduct" to capture serious non-criminal misconduct and even actions where an intended benefit was never actually realized. For companies with state government contracts, especially in the construction and infrastructure industries, the reform creates material new compliance risks and signals a tightening enforcement environment. The bill is reportedly being fast-tracked, and affected businesses are advised to proactively strengthen third-party due diligence and review their integrity controls in anticipation of the new regime, which could apply to some existing matters.
Grade 3 — worth a glance, not the full analysis.
- Germany Proposes New Status for Self-Employed Workers
A German government draft bill would create a 'New Self-Employment' category, aiming to reduce misclassification risk for companies engaging independent contractors.
- NLRB: Gaza Workplace Protests Not Protected Activity
An NLRB Division of Advice memo concludes that employee protests focused on political issues like the Gaza war lack the required connection to working conditions to be protected under federal labor law.
- Saudi Arabia Issues New Copyright Regulations for AI Training
New implementing regulations for the Kingdom's Copyright Law establish a detailed framework for using copyrighted works in AI development, subject to conditions on data use, record-keeping, and commercial exploitation.
- Mexico Issues New Mining Waste Management Standard
A new official standard, NOM-157-SEMARNAT-2026, repeals the 2009 version and imposes updated requirements for mining waste management plans, including expanded waste classifications and joint liability provisions.
- UK employment tribunal backlog pushes some hearings to 2029
A record of over 70,000 single claims has created an unprecedented backlog, requiring employers to preserve evidence for disputes that may not be heard for years.
- FTC's Decade-Old Lead-Gen Guidance Remains Essential
Ten years on, the FTC's staff perspective on online lead generation continues to guide the analysis of consumer protection risks, focusing on specific conduct over labels.
- Maryland FAMLI employer registration opens for 2027 program
Maryland employers must register by deadlines for the state's new Family and Medical Leave Insurance program, with private plan declarations due November 15 and payroll deductions starting January 1, 2027.
- FDIC OCC Unveil Sweeping Bank Supervision Reforms
FDIC and OCC propose major updates to confidential information sharing, deposit insurance applications, and MRA enforcement standards, with comments due this fall.
- Ninth Circuit Expands Personal Jurisdiction Over Foreign Manufacturers
Foreign manufacturers whose goods flow through California ports may now face personal jurisdiction in the state, following a Ninth Circuit ruling that could reshape product liability litigation strategy.
- Firm Issues Guide to Antiboycott Compliance Self-Checks
A new practitioner guide outlines the steps for multinational companies to self-assess compliance with complex US antiboycott regulations, a specialized risk in cross-border trade.
- FTC Launches Guidance Program for Rule Ambiguities
The FTC's Bureau of Consumer Protection will now accept stakeholder questions about genuine ambiguities in FTC rules, offering businesses a new compliance pathway—but one fraught with litigation risk.
- SEC Risk Alert Details Six Common Investment Adviser Compliance Deficiencies
The SEC's Division of Examinations issued a Risk Alert on September 14, 2026 identifying recurring deficiencies in how registered investment advisers conduct their required annual compliance reviews under Rule 206(4)-7.
- Trump administration launches new employer enforcement in H-1B PERM fraud probes
Employers sponsoring H-1B workers and undergoing PERM labor certification should anticipate heightened scrutiny as the administration expands fraud enforcement actions.
- How to Structure Corporate Investigations to Preserve Privilege
A new guide details three critical elements courts examine when determining whether internal investigation reports are protected by attorney-client privilege, based on a recent Utah federal case.
- Australia's Unfair Trading Practices Act 2026: What eHarmony ruling reveals
Australia's new UTP regime taking effect July 1, 2027 will impose penalties up to $100M or 30% of turnover for subscription misconduct, with the eHarmony decision previewing enforcement targets.
- CBP CAPE Phase 3 for IEEPA refunds launches October 6
CBP will deploy Phase 3 of its Consolidated Administration and Processing of Entries system on October 6, 2026, enabling plaintiffs with CIT-ordered reliquidation to file declarations for IEEPA tariff refunds.
- German Cartel Office finds 50+1 rule restricts competition but may be justified
The FCO closed its eight-year investigation concluding the Bundesliga's fan-ownership rule limits investor control but could survive legal challenge if applied consistently and without unjustified exceptions.
- Regulators Clarify Use of Digital IDs Under CIP Rule
US financial regulators confirmed that verifiable digital credentials like mobile driver's licenses can satisfy Customer Identification Program requirements, provided the institution can reasonably verify the customer's true identity.
- Bristol-Myers Squibb Files First BPCIA Suit Over Opdivo Biosimilar
Bristol-Myers Squibb has initiated the first patent infringement litigation under the BPCIA against Amgen over its proposed biosimilar to the blockbuster cancer drug Opdivo®.
- SEC opens nonpublic review for ABS issuers on Forms SF-1 and SF-3
ABS issuers can now request confidential SEC staff review before public filing, with Tier 1 offering full review for first-time depositors and Tier 2 a single pass for repeat filers.
- Federal Circuit lacks jurisdiction over patent settlement contract dispute
The Federal Circuit transferred a T-Mobile contract dispute from a patent settlement to the Fifth Circuit, holding the breach of contract claim did not require deciding a substantial patent law issue under Gunn v. Minton.
- UK University Insolvency Regime Lacks Dedicated Framework
Analysis examines why existing UK restructuring tools are inadequate for higher education institutions and explores whether the further education special administration regime could serve as a model.
- IRS Clarifies Employer Paid-Leave Tax Credit Rules Under WFTC
Employers offering paid family and medical leave may claim a business credit under Section 45S, and new IRS guidance explains how the credit works after the Working Families Tax Cuts Act made it permanent and more generous.
- Form PF Amendments Compliance Date Moved to July 2027
The SEC and CFTC have jointly extended the compliance date for recent Form PF amendments to July 1, 2027, giving the agencies more time to consider proposed modifications.
- Providers win 85% of IDR disputes under No Surprises Act
Georgetown analysis shows providers recovering median awards 315%-3,239% of qualifying payment amounts through Independent Dispute Resolution in 2025.
- Unimplemented Billing Review Can Support FCA Knowledge
A federal court found a hospital's failure to act on consultant reports could support an inference of institutional knowledge for False Claims Act liability, even while dismissing claims against individual officials.
- US Employers Face Unique Employee Termination Risks in the UAE
US 'at-will' employment concepts do not apply in the United Arab Emirates, where employers face mandatory gratuity payments, notice periods, repatriation costs, and other liabilities.
- 9th Circ. Reverses $40M Trade Secret Verdict Over Jury Instruction
The Ninth Circuit reversed a $40 million trade secret award after finding the jury was improperly instructed on the differing burdens of proof under federal and California law.
- Hawaii Spa Worker Lawsuit Prompts Contractor Risk Review
A federal lawsuit by spa workers at a Hawaiian resort, alleging they were misclassified as independent contractors, highlights wage-and-hour risks for hospitality employers who exercise significant control over scheduling and job duties.
- DOL narrows mental health parity enforcement to three priority areas
EBSA's Field Assistance Bulletin No. 2026-03 focuses enforcement on treatment exclusions, medical necessity standards, and network adequacy, signaling a more collaborative compliance posture for group health plans.
- PACCAR ruling reshapes UK litigation funding landscape
The Supreme Court's PACCAR decision reclassified litigation funding agreements as damages-based agreements, sparking regulatory reform efforts and uncertainty for funders, claimants, and defendants in England and Wales.
- SBA Bars 870K Suspected COVID Loan Fraudsters from Future Federal Loans
Vice President JD Vance announced the Trump administration's coordinated SBA-DOJ action suspending 870,000 individuals suspected of PPP and EIDL program fraud from receiving future federal loans.
- FTC Consumer Bureau Invites Input on Flawed Rules
The FTC's Bureau of Consumer Protection has launched a new program for industry and the public to identify problems with its rules, though submissions may carry confidentiality risks.
- hybrid-power-platforms-data-center-energy-integration
Lawyers advising data center developers on integrated power platforms must coordinate real estate, energy regulation, and project finance across co-located generation, BESS, and potential nuclear SMRs.
- Four Antitrust Pathways for AI Lab Coordination
Law firms advising AI companies should understand four legal pathways for competitor coordination on AI safety, from rule of reason analysis to statutory exemptions.
- FTC shifts AI enforcement away from innovation burden toward deceptive claims focus
Holland & Knight podcast examines how Trump's AI executive order and America's AI Action Plan have reshaped FTC regulatory priorities, using the Rytr LLC case as a key example.
- $604M C.H. Robinson Verdict: Retained Control, Not Negligent Selection
A Dallas jury found freight broker C.H. Robinson vicariously liable under borrowed-employee and special-mission theories, rejecting negligent-selection claims and exposing a post-Montgomery catch-22 for broker practices.
- HUSTLE Act Proposes Tax-Advantaged NIL Savings Accounts
A recently introduced bill in Congress would create tax-advantaged investment accounts for college athletes to save their name, image, and likeness earnings.
- DOJ FCA Cybersecurity Settlement Shows Enforcement Priority
The DOJ's latest False Claims Act settlement with a federal contractor underscores the government's continued focus on cybersecurity enforcement in government contracts.
- DHS Proposes Eliminating 60-Day Grace Period for Nonimmigrant Workers
DHS published a proposed rule September 11, 2026 to eliminate the discretionary 60-day grace period for employment-based nonimmigrant workers in E, H, L, O, and TN classifications; comments due November 10, 2026.
- Guide Compares Five Key Post-Default Remedies
A new guide offers a comparative framework for five out-of-court post-default remedies, analyzing each from the lender and equity owner perspectives.
- Lawyers Offer AI Governance Guide for Hospice Providers
A new podcast series outlines concrete steps for hospice leaders to manage emerging compliance and liability risks from AI in clinical documentation, vendor contracting, and billing.
- Board Crisis Preparedness: A Director’s Playbook
A veteran CLO and board director shares hard-won wisdom on preparing boards for crises they cannot predict—identifying independent investigators, pre-clearing outside counsel, and balancing privilege with employee communication needs.
- New York Employers Face New Personnel Record Access Obligations
New York employers must prepare for expanded obligations regarding employee access to personnel records under regulatory changes effective in the state.
- Belgium delays private-sector EU pay transparency rules
Belgium has partially transposed the EU Pay Transparency Directive for public sector but federal private-sector legislation remains pending, giving employers time to prepare.
- French Regulator Issues Guide for Clearer Investor Disclosures
France's financial markets authority has published a non-binding guide with concrete recommendations for improving the readability of Key Information Documents for retail investment products.
- UK launches major corporate reporting reform consultation
UK Government published a September 7, 2026 consultation on modernising corporate reporting, including moving financial reporting from Companies Act 2006 to accounting standards.
- Australian Administrators Can Sell Assets Without Shareholder Vote
Australian case law confirms that a company administrator's statutory power to dispose of assets overrides shareholder approval requirements in company constitutions, listing rules, or other statutes.
- Japan PE Fund Expense Rules Tighten After METI Model LPA Revision
The revised Japan model LPA now requires more granular fund expense disclosure, aligning with US standards—Japan GPs must build stronger governance practices or face LP scrutiny and potential regulatory exposure.
- Prepare Now for Potential Congressional Investigations in 2027
Skadden advises companies to assess exposure to congressional oversight now, as Democrats may gain subpoena power after 2026 midterms.
- SBA resumes 8(a) applications with new social disadvantage standard
SBA guidance effective September 10, 2026 returns pending 8(a) applications for resubmission under newly finalized eligibility requirements, reinstates potential for success reviews, and prioritizes defense-critical NAICS codes.