On September 2, 2026, the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (“FinCEN”), the Board of Governors of the Federal Reserve System (“Federal Reserve”), the Federal Deposit Insurance Corporation (“FDIC”), the National Credit Union Administration (“NCUA”), and the Office of the Comptroller of the Currency (“OCC”) issued a joint statement on a question that has long vexed financial institutions: how much can a bank tell a customer once the customer is the subject of a Suspicious Activity Report (“SAR”)? The answer: likely more than some institutions have considered permissible.
Department of War Launches Research Security Audits: Key Compliance Steps for Higher Education Institutions
Background
On August 17, 2026, the Department of War issued formal notifications to 30 domestic academic institutions directing them to initiate immediate and comprehensive reviews of their academic, financial, and research collaborations with foreign entities of concern. The notifications were executed by the Office of the Under Secretary of War for Research and Engineering and announced in a press release from the Department.
The action targets active institutional ties and collaborations with foreign entities identified under Section 1286 of the FY19 National Defense Authorization Act, as well as organizations associated with rebranded Confucius Institutes. Confucius Institutes, funded by the Chinese government, were established on campuses nationwide ostensibly as cultural exchange programs. The Department’s focus on “rebranded” institutes suggests concern that some programs may have continued operating under different names.
The Department’s list of problematic entities reportedly includes 130 organizations from China, Russia, and Iran, ranging from electronic measurement laboratories to scientific research centers.
FinCEN Kills Beneficial Ownership Reporting for U.S. Companies, but Foreign Filers Should Beware
The long saga of the Corporate Transparency Act’s (“CTA”) beneficial ownership reporting requirements has reached its final chapter — at least for domestic businesses. On August 11, 2026, the Financial Crimes Enforcement Network (“FinCEN”) issued a final rule permanently exempting all U.S. companies and U.S. persons from reporting beneficial ownership information (“BOI”), which was the primary purpose of the CTA. The rule is effective immediately. FinCEN will also delete previously reported data for U.S. entities. But the CTA is not dead for everyone. Foreign entities registered to do business in the United States remain squarely in scope.
New Frontiers in Spoliation: Preserving AI Records in Litigation
The explosion of generative AI in the workplace has created a new and largely unaddressed category of litigation risk. In May 2025, a federal court in the Southern District of New York ordered OpenAI to preserve and segregate all ChatGPT output log data that would otherwise be destroyed under its default 30-day deletion policy, marking one of the first judicial orders to treat AI-generated content as electronically stored information subject to legal holds (i.e., the obligation to preserve potentially relevant evidence once litigation is reasonably anticipated). The order, issued over OpenAI’s objections grounded in user privacy and regulatory compliance, signals that courts will expect litigants to preserve AI artifacts with the same rigor applied to email, documents, and structured data.
Read on for an analysis of how existing discovery rules already reach AI-generated content, the sanctions companies may face for failing to preserve it, and the practical steps clients should take now to close the gap.
DoW Suspends CMMC Phase II Requirements – Launches 60-Day Review
Overview
On July 13, 2026, the Department of War (DoW) announced the immediate suspension of all Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which had originally been scheduled to take effect November 10, 2026, including the transition to mandatory third-party assessments by CMMC Third-Party Assessment Organizations (C3PAOs) for contractors handling Controlled Unclassified Information (CUI). The DoW simultaneously established a CMMC Reform Task Force charged with delivering a comprehensive report within 60 days recommending “realistic, scalable security measures” for the Defense Industrial Base (DIB).
The suspension, announced by DoW Chief Information Officer Kirsten A. Davies, aligns with Secretary of War Pete Hegseth’s Acquisition Transformation System (ATS) directives and the broader “Arsenal of Freedom” initiative. Critically, the action does not relieve contractors of their underlying obligations to protect federal data, which includes the current DFARS 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting) and the NIST SP 800-171 Rev. 2 security controls upon which the CMMC Phase II requirements are based.
OFAC Details Sanctions Compliance Expectations for the Stablecoin Industry
The Office of Foreign Assets Control (“OFAC”) recently issued a proposed rule that will require the implementation and maintenance of a sanctions compliance program (“SCP”) for permitted payment stablecoin issuers (“PPSIs”).
The proposed rule, which directs that PPSIs put in place a SCP that includes at least five specific elements, deserves immediate attention from the stablecoin industry because, even if the rule is not ultimately adopted, it describes the compliance measures OFAC currently expects from issuers of payment stablecoins. More generally, this proposal is the first time that OFAC was directed by Congress to adopt rules for a mandatory SCP. OFAC responded to that direction by drafting a rule describing the required SCP with some precision. The resulting proposed rule impacts PPSIs directly, but also represents an opportunity for all businesses that face sanctions risk to evaluate their compliance efforts against OFAC’s detailed SCP expectations.
AI-Assisted Billing Could Create FCA Pitfalls: How Healthcare Companies Can Get Ahead of Risk
Across the healthcare industry, providers are increasingly relying on AI-assisted billing tools to automate medical coding, prior authorization workflows, and the submission of claims to Medicare, Medicaid, and other federal payors. Some vendors advertise “clean” claim rates exceeding 98%, meaning payors almost always accept submitted claims without further intervention or correction. But a high clean-claim rate is an operational metric, not a compliance safe harbor. It does not establish that the claim was properly coded, medically necessary, supported by documentation, or free from overpayment risk. The efficiency gains can be substantial, as can the heightened False Claims Act (“FCA”) exposure these systems can create. At the same time, many of these tools may improve consistency and reduce certain forms of human error when implemented and monitored appropriately. As AI continues to develop and becomes more widely integrated into healthcare billing, relators and prosecutors are likely to explore new avenues for evaluating, and litigating, how these tools are deployed, monitored, and overseen.
Federal Circuit Stays Injunctions Against Section 122 ‘Balance-of-Payments’ Tariffs Pending Appeal
On June 11, 2026, the U.S. Court of Appeals for the Federal Circuit granted the federal government’s motions for a stay pending appeal in State of Oregon v. Trump (Nos. 2026-1804, 2026-1805), consolidated appeals from two decisions of the U.S. Court of International Trade (CIT) that had enjoined enforcement of tariffs imposed under Proclamation No. 11012 and Section 122 of the Trade Act of 1974. While the appeal proceeds on the merits, the government may continue to collect the Section 122 “balance-of-payments” tariffs as to the parties covered by the underlying injunctions, including the State of Washington, Burlap and Barrel, Inc., and Basic Fun, Inc., pending further order of the Federal Circuit.
The Great American AI Act: What It Means — and Doesn’t Mean — for Companies Using AI
On June 4, 2026, Representatives Jay Obernolte and Lori Trahan released a discussion draft of the Great American Artificial Intelligence Act (GAAIA). The proposal has generated significant attention, but many organizations may be overestimating its practical significance for their day-to-day operations. The bill is directed primarily at developers of “frontier” AI models, so for most companies using AI models in their daily operations, these requirements will not apply. Nonetheless, the bill has sparked conversation—it incorporates multiple bipartisan bills on AI, its drafters wrote an op-ed calling on the U.S. to create a national framework covering AI, and the U.S. House Democratic Commission on AI and the Innovation Economy released a statement that the draft “does not meet the enormity of the moment.”
Key Takeaways
- The bill is primarily aimed at the biggest AI developers with more than $500 million in revenue that are building cutting-edge AI models rather than most typical businesses developing in-house AI or deploying commercial AI models.
- The proposed preemption provision would leave many state-law obligations governing AI deployment intact, including employment, privacy, consumer protection, healthcare, financial services, and common-law claims.
- The draft would increase fraud-related penalties and reflects a broader enforcement trend toward applying existing fraud and misconduct frameworks to AI-enabled conduct.
- If this bill passes, many of the legal risks businesses face when using AI will remain unchanged.
As Courts Wrestle With Tariff Refund Cases, Importers Should Confirm Submission of Key Information and Assess Options
Parallel proceedings in two U.S. Court of International Trade cases, Euro-Notions Florida, Inc. v. United States (No. 25-00595) and V.O.S. Selections, Inc. v. United States (No. 25-00066), are rapidly converging on what may be the central unresolved question in the IEEPA tariff refund process: must the government refund duties on entries that have liquidated and become final, even for importers who have not filed suit?