On September 1, 2026, the U.S. Department of Justice (“DOJ”) announced a $2,042,518 False Claims Act (“FCA”) settlement with Honeywell Aerospace Inc. (“Honeywell Aerospace” or “Honeywell” or “the company”), resolving allegations that the company failed to comply with certain cybersecurity requirements in a contract with the U.S. Department of War (“DoW”). This settlement is the latest in a growing line of enforcement actions under DOJ’s Civil Cyber-Fraud Initiative and underscores the government’s continued willingness to use the FCA to hold defense contractors accountable for apparent failures to comply with cybersecurity-related requirements.
Could Using Cheaper Chinese AI Lead to Costly Congressional Scrutiny?
U.S. companies using AI models developed by companies based in the People’s Republic of China, including DeepSeek, Moonshot AI or MiniMax, should be aware of potential congressional scrutiny in this Congress and the next. Two House committees are conducting a joint investigation into the national security, cybersecurity and economic security implications of U.S. companies’ adoption of PRC-developed AI models, including low-cost, open-weight models and models accessible through application programming interfaces. The House panels have already expressed interest in investigating actions at Anysphere, Airbnb and DoorDash.
Read on to learn more about expected congressional interest in corporate use of PRC-developed AI models.
Talk to Your Customers: Five Agencies Clarify What SAR Confidentiality Actually Prohibits
On September 2, 2026, the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (“FinCEN”), the Board of Governors of the Federal Reserve System (“Federal Reserve”), the Federal Deposit Insurance Corporation (“FDIC”), the National Credit Union Administration (“NCUA”), and the Office of the Comptroller of the Currency (“OCC”) issued a joint statement on a question that has long vexed financial institutions: how much can a bank tell a customer once the customer is the subject of a Suspicious Activity Report (“SAR”)? The answer: likely more than some institutions have considered permissible.
Department of War Launches Research Security Audits: Key Compliance Steps for Higher Education Institutions
Background
On August 17, 2026, the Department of War issued formal notifications to 30 domestic academic institutions directing them to initiate immediate and comprehensive reviews of their academic, financial, and research collaborations with foreign entities of concern. The notifications were executed by the Office of the Under Secretary of War for Research and Engineering and announced in a press release from the Department.
The action targets active institutional ties and collaborations with foreign entities identified under Section 1286 of the FY19 National Defense Authorization Act, as well as organizations associated with rebranded Confucius Institutes. Confucius Institutes, funded by the Chinese government, were established on campuses nationwide ostensibly as cultural exchange programs. The Department’s focus on “rebranded” institutes suggests concern that some programs may have continued operating under different names.
The Department’s list of problematic entities reportedly includes 130 organizations from China, Russia, and Iran, ranging from electronic measurement laboratories to scientific research centers.
FinCEN Kills Beneficial Ownership Reporting for U.S. Companies, but Foreign Filers Should Beware
The long saga of the Corporate Transparency Act’s (“CTA”) beneficial ownership reporting requirements has reached its final chapter — at least for domestic businesses. On August 11, 2026, the Financial Crimes Enforcement Network (“FinCEN”) issued a final rule permanently exempting all U.S. companies and U.S. persons from reporting beneficial ownership information (“BOI”), which was the primary purpose of the CTA. The rule is effective immediately. FinCEN will also delete previously reported data for U.S. entities. But the CTA is not dead for everyone. Foreign entities registered to do business in the United States remain squarely in scope.
New Frontiers in Spoliation: Preserving AI Records in Litigation
The explosion of generative AI in the workplace has created a new and largely unaddressed category of litigation risk. In May 2025, a federal court in the Southern District of New York ordered OpenAI to preserve and segregate all ChatGPT output log data that would otherwise be destroyed under its default 30-day deletion policy, marking one of the first judicial orders to treat AI-generated content as electronically stored information subject to legal holds (i.e., the obligation to preserve potentially relevant evidence once litigation is reasonably anticipated). The order, issued over OpenAI’s objections grounded in user privacy and regulatory compliance, signals that courts will expect litigants to preserve AI artifacts with the same rigor applied to email, documents, and structured data.
Read on for an analysis of how existing discovery rules already reach AI-generated content, the sanctions companies may face for failing to preserve it, and the practical steps clients should take now to close the gap.
DoW Suspends CMMC Phase II Requirements – Launches 60-Day Review
Overview
On July 13, 2026, the Department of War (DoW) announced the immediate suspension of all Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which had originally been scheduled to take effect November 10, 2026, including the transition to mandatory third-party assessments by CMMC Third-Party Assessment Organizations (C3PAOs) for contractors handling Controlled Unclassified Information (CUI). The DoW simultaneously established a CMMC Reform Task Force charged with delivering a comprehensive report within 60 days recommending “realistic, scalable security measures” for the Defense Industrial Base (DIB).
The suspension, announced by DoW Chief Information Officer Kirsten A. Davies, aligns with Secretary of War Pete Hegseth’s Acquisition Transformation System (ATS) directives and the broader “Arsenal of Freedom” initiative. Critically, the action does not relieve contractors of their underlying obligations to protect federal data, which includes the current DFARS 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting) and the NIST SP 800-171 Rev. 2 security controls upon which the CMMC Phase II requirements are based.
OFAC Details Sanctions Compliance Expectations for the Stablecoin Industry
The Office of Foreign Assets Control (“OFAC”) recently issued a proposed rule that will require the implementation and maintenance of a sanctions compliance program (“SCP”) for permitted payment stablecoin issuers (“PPSIs”).
The proposed rule, which directs that PPSIs put in place a SCP that includes at least five specific elements, deserves immediate attention from the stablecoin industry because, even if the rule is not ultimately adopted, it describes the compliance measures OFAC currently expects from issuers of payment stablecoins. More generally, this proposal is the first time that OFAC was directed by Congress to adopt rules for a mandatory SCP. OFAC responded to that direction by drafting a rule describing the required SCP with some precision. The resulting proposed rule impacts PPSIs directly, but also represents an opportunity for all businesses that face sanctions risk to evaluate their compliance efforts against OFAC’s detailed SCP expectations.
AI-Assisted Billing Could Create FCA Pitfalls: How Healthcare Companies Can Get Ahead of Risk
Across the healthcare industry, providers are increasingly relying on AI-assisted billing tools to automate medical coding, prior authorization workflows, and the submission of claims to Medicare, Medicaid, and other federal payors. Some vendors advertise “clean” claim rates exceeding 98%, meaning payors almost always accept submitted claims without further intervention or correction. But a high clean-claim rate is an operational metric, not a compliance safe harbor. It does not establish that the claim was properly coded, medically necessary, supported by documentation, or free from overpayment risk. The efficiency gains can be substantial, as can the heightened False Claims Act (“FCA”) exposure these systems can create. At the same time, many of these tools may improve consistency and reduce certain forms of human error when implemented and monitored appropriately. As AI continues to develop and becomes more widely integrated into healthcare billing, relators and prosecutors are likely to explore new avenues for evaluating, and litigating, how these tools are deployed, monitored, and overseen.
Federal Circuit Stays Injunctions Against Section 122 ‘Balance-of-Payments’ Tariffs Pending Appeal
On June 11, 2026, the U.S. Court of Appeals for the Federal Circuit granted the federal government’s motions for a stay pending appeal in State of Oregon v. Trump (Nos. 2026-1804, 2026-1805), consolidated appeals from two decisions of the U.S. Court of International Trade (CIT) that had enjoined enforcement of tariffs imposed under Proclamation No. 11012 and Section 122 of the Trade Act of 1974. While the appeal proceeds on the merits, the government may continue to collect the Section 122 “balance-of-payments” tariffs as to the parties covered by the underlying injunctions, including the State of Washington, Burlap and Barrel, Inc., and Basic Fun, Inc., pending further order of the Federal Circuit.