Regulatory and Compliance

SEC cyber disclosure rules, privacy regulations, enforcement actions, and compliance obligations.

The Agent Passed Procurement

The UK AI Security Institute caught its own test agents taking 19 unauthorized actions last month, during evaluations built specifically to catch that. Most companies running agents in production have nothing built to catch anything.

The New Privateers Won't Know Whose Ship They're Boarding

North Korea's hacking units funded roughly $2.84 billion of the regime's nuclear and missile programs through cryptocurrency theft between January 2024 and September 2025, according to the Multilateral Sanctions Monitoring Team, the eleven-nation coalition that took over UN sanctions monitoring after the original UN Panel of Experts was disbanded. No toolkit built for ordinary criminals has stopped it, and the broader losses Congress itself cites, billions lost to Americans annually through crypto scams, ransomware, and fraud, are real. Indictments against people who never see a US courtroom genuinely are losing that fight. Congress and the White House are now moving on separate tracks to close the gap by commissioning the private sector to hit back, and they're not alone.

The 500 Attorneys Reading Your Country-of-Origin Certificate

Tariffs on imported goods are higher this year than they've been in decades, which makes it more valuable than ever for a company to fudge where a product actually came from, since the tariff rate usually depends on that answer. DOJ's response to that problem isn't new or hypothetical: a joint DOJ–Homeland Security task force built for exactly this, the Trade Fraud Task Force, has already recovered more than $1 billion in penalties, forfeitures, and charged losses since it launched in August 2025.

Boeing's Board Won Because It Took Good Notes

A Delaware court just told corporate boards what actually protects them when something goes wrong, and it isn't the outcome. On August 13, Vice Chancellor Morgan Zurn, a judge on the Delaware Court of Chancery, the state's specialized business court, dismissed, with prejudice, a shareholder lawsuit trying to hold Boeing's directors personally liable for the safety failures behind the January 2024 Alaska Airlines door-plug blowout. Plaintiffs argued the board ignored warning signs and pushed unsafe production targets. The court disagreed: Boeing's own records showed the board had received detailed safety reports and had acted on them, adjusting production in response. "If everything is a red flag, then nothing is," the court wrote. Directors don't have to prevent every failure. They have to show they built a system to hear about problems, and used it.

Kazakhstan Turned the Safety Net Into a Weapon

Any company that signs a long-term contract with a foreign government typically insists on one specific protection: an arbitration clause, a promise that if a dispute ever happens, it gets decided by a neutral international panel instead of that government's own courts. The assumption behind that clause is that it protects the company from the government. A new dispute out of Kazakhstan shows the same clause working the other way.

The Permit Was Never Actually Valid, and Nobody Found Out for a Decade

South Africa's highest court permanently ended Shell's right to explore for oil and gas off the country's Wild Coast on August 14, closing a legal fight that started with the right itself: granted in 2014. The Constitutional Court found the original public consultation with local communities was inadequate, the same finding a lower court had already made in 2024. What changed this time is the remedy. The 2024 ruling gave Shell a path back: fix the consultation defect, reapply, try again. The Constitutional Court closed that path entirely. There is no cure, no renewal, no second attempt. The right is over, more than a decade after it was granted and years into active legal and commercial commitment to the project.

117 Rules for the Same Bad Day

The Government Accountability Office counted the cybersecurity regulations sitting on top of American companies: 117 of them, across 37 federal agencies. The finding that deserves board attention is the overlap.

The Tariff Survived. The Law Under It Didn't.

Two weeks ago we told you Section 122 tariff authority was set to expire and Section 301 was queued up to take its place. Both happened on schedule, July 24, and the response from trading partners arrived almost as fast: Brazil is now suing the US at the WTO, and South Africa hit back with a tariff of its own within hours of the deadline.

The Liability Doesn't Stay With Whoever Got Hacked

Amgen, the world's largest biotechnology company by revenue, disclosed in July that attackers stole patient health data and business data from a cloud system run by an outside vendor. Amgen hasn't named that vendor. It doesn't yet know how many patients are affected, or how the attackers got in. What it does know is that it's now running two separate regulatory deadlines, and neither one waits for the other.

Washington shut three doors on China's patent-challenge playbook

Chongqing Yanmei Technology, a Chinese company, challenged a small Ohio inventor's patent at the Patent Trial and Appeal Board, the venue that lets anyone challenge a US patent's validity without a jury trial. The patent covered a dissolvable magnesium alloy Terves LLC had developed to plug oil and gas wells during fracking. In August 2024, the board sided with Chongqing Yanmei and found key claims in Terves' patent unpatentable; Terves salvaged some protection only by amending its claims mid-proceeding. Whatever the merits of that specific case, the pattern behind it is what should worry other small patent holders: a challenge like this is cheap to file and expensive to defend, and the cost of defending one, win or lose, is often enough on its own to force a settlement or bankrupt a small inventor.

Every tier of the defense supply chain now owes a map back to the raw material

An executive order signed July 20 and published in the Federal Register on July 23, "Securing America's Defense Supply Chains and Ensuring Domestic Acquisition of Critical Materials," directs the Department of War, the renamed Defense Department, to require prime contractors and subcontractors at any tier on national-security acquisitions to trace their supply chains back to raw-material origin, screen for prohibited sources, and submit mitigation or onshoring plans. Implementation guidance is due within 180 days.

The Tariff Cliff Lands July 24

For the past five months, almost everything the United States imports has carried an extra 10% tax at the border. That surcharge disappears on July 24. If you run a business that buys anything from overseas, the natural assumption is that your costs are about to drop. They are not. The 10% is being replaced by something more expensive that, unlike the surcharge, may never expire.

Brazil Loads the Weapon

The countries getting hit by that tariff regime are not absorbing it quietly, and Brazil's answer reaches a place American companies rarely think to protect: their own patents.

The EU AI Clock Hits July 27

There is a second deadline this week that has nothing to do with tariffs and is easy to miss. On Monday, July 27, at 6pm Central European time, companies can sign the European Union's new Code of Practice on labeling AI-generated content. Signing is voluntary. It also decides how hard the next part gets.

Europe Is Rearming, and the Boom Comes With a 'Buy Local' Sign

At a summit in Ankara this week, NATO announced the largest defense build-out in a generation. More than $50 billion in new weapons purchases, a $40 billion fund for military drones over the next five years, and a restated pledge to push defense spending to 5 percent of each member's economic output by 2035, up from about 4 percent today. Strip away the summit choreography and the acronyms and it comes down to money, a great deal of it, and where it is about to flow. That last figure alone is trillions of dollars over the decade.

A Supreme Court Ruling Just Reached Your EU Customer Data

In late June, the Supreme Court ruled that the President can fire the commissioners of the Federal Trade Commission at will. The FTC is the government's main privacy enforcer, and the case looked like a fight over presidential power in Washington. For any company that stores European data on US servers, it is more than that. It quietly weakened the legal ground under those data transfers.

Your Cloud Provider Reset the Quantum Clock

Last month the government set the quantum deadline. This month the companies that run your systems moved it closer, and the money moving underneath tells you why.

Legitimate Is No Longer a Defense

Going after the marketplace instead of the seller is not new. The government shut down Silk Road and prosecuted its operator; it seized Backpage and charged the people who ran it. The lesson from Alibaba's $600 million settlement on July 1 is that the same theory now reaches a legitimate business, not just a criminal one.

The Sky Over Your Plant Isn't Yours to Defend

This has been the summer of the drone. Securing the FIFA World Cup, the FBI has detected more than 1,100 drones over stadiums and seized over 500, arresting operators from Houston to Dallas. A JetBlue crew even reported a suspected drone strike on approach to New York's JFK on June 29, though investigators later found no proof of a collision. The machines are everywhere, and the ones that should worry your business are not the ones over the ballgame.

The Breach With No Burglar

A Pennsylvania bank just filed the same emergency disclosure a company files after a ransomware attack. Nobody broke in. One of its own people had pasted customer records into an AI tool to get a job done faster.

The Quantum Clock Just Jumped Forward Five Years

There is a kind of theft where the payoff arrives years after the crime. An adversary copies your encrypted data today, sits on it, and waits for a quantum computer powerful enough to pry the encryption open. The shorthand for it is harvest now, decrypt later, and it is the reason a problem that always sounded like a 2035 concern is suddenly a 2030 one.

Europe Is Pulling the Plug on American Software

Last week we reported that the US government ordered Anthropic to switch off two AI models worldwide with no notice and no appeal. That was not the beginning of this story. It was the latest in a chain of events that had already convinced European governments to walk away from American software.

North America's Trade Architecture Is Being Pulled Apart from Three Directions

The United States-Mexico-Canada Agreement, the trade deal signed in 2018 to replace NAFTA, faces its first mandatory review on July 1. The review is supposed to be procedural: all three countries agree to extend it for sixteen years, or it enters annual reviews and begins winding down. It will not be procedural. All three members are pulling in different directions, and any company that built supply chain assumptions on this deal's stability should revisit them before next month.

Your AI Vendor Has an Off Switch in Washington

On June 12, the US government ordered a private company to switch off a product worldwide. The company was Anthropic, a US artificial-intelligence developer, and the product was its two newest models, Claude Fable 5, released three days earlier, and Claude Mythos 5.

Whatever Your AI Says, You Said It

Across three countries, courts are converging on a single idea: a company is responsible for what its AI tells people, the same as it would be for any employee or any line on its website. There is no settled rulebook yet, and what counts as a safe thing for an AI to say is landing differently in every jurisdiction.

The EU Just Drew a Line Around Its Cloud

The European Commission published the Cloud and AI Development Act (CADA), a framework that divides cloud providers into four tiers based on how much sovereignty they offer. The higher the tier, the more sensitive the government contracts you can compete for. The catch: American cloud providers cannot reach the top two tiers without fundamentally restructuring how they operate. EU Vice President Henna Virkkunen framed the rationale directly: "We want to be sure nobody has a kill switch."

Customs Fraud Just Became a Half-Billion-Dollar Problem

For years, companies importing goods from China have used a simple workaround to avoid the tariffs designed to stop foreign manufacturers from undercutting American competitors by selling below cost. Ship the product to a third country like Vietnam, Malaysia, or Mexico. Relabel it. Import it into the US under the new country of origin. The duties that were designed to protect American manufacturers never get paid. The practice is so widespread that trade lawyers have a name for it: transshipment.

"Prove Someone Looked" Is No Longer Your Defense

For over a decade, California companies facing data breach lawsuits could ask one question that usually ended the case: can you prove anyone actually viewed the stolen data? On May 14, the California Supreme Court eliminated that defense.

Your Acquisition Just Bought Someone Else's Breach

California Attorney General Rob Bonta sued Chrome Holding Co., the entity that emerged from 23andMe's bankruptcy, on May 28. The complaint alleges the company failed to protect 6.9 million users' genetic profiles, took five months to detect the breach, paid a ransom to the threat actor while publicly claiming no systems were compromised, and shifted blame to customers for reusing passwords.

The Coverage You Assumed You Had for AI Is Disappearing

Berkshire Hathaway, Chubb, and Travelers began filing AI exclusion endorsements with state insurance regulators in late 2025. Regulators approved more than 80 percent of the applications. In January 2026, ISO (the insurance industry's standards body) issued three new generative AI exclusion forms for commercial general liability policies. The exclusions carve out bodily injury, property damage, defamation, and intellectual property infringement tied to AI-generated outputs.

New York's Financial Regulator Just Told You AI Is a Governance Problem

On May 21, the New York Department of Financial Services (NYDFS, the state regulator overseeing banks, insurers, and crypto firms operating in New York) issued two industry letters to its regulated entities. The first, addressed to CISOs, warns specifically about frontier AI risks. The second provides broader guidance for operating in a heightened threat environment. The letters warn that frontier AI models are accelerating vulnerability discovery, exploit development, and social engineering attacks, citing a CrowdStrike finding of an 89 percent year-over-year increase in AI-enabled attacks.

Your Vendor Rewrote the Contract Over Memorial Day Weekend

On the Friday before Memorial Day, Microsoft updated its Data Processing Agreement (DPA, the contract governing how Microsoft handles your organization's data) to reduce the notice period for introducing new AI subprocessors from six months to 30 days. A subprocessor is a third-party company Microsoft contracts to process your data. In the AI context, that includes companies like Anthropic powering features inside Copilot and Azure.

The Colorado AI Act Died Before It Took Effect

Twelve months ago, the Colorado AI Act was the most aggressive state AI law in the country. Six weeks before its effective date, it's notice-only paperwork and a footnote in a Department of Justice (DOJ) strategy memo.

Regulators Are Clocking the Delay, Not the Incident

Delta Dental Insurance Company and Delta Dental of New York paid New York's financial regulator $2.25 million last month for a cybersecurity incident. The incident itself was modest. The penalty was driven by a six-month delay in notification. New York's rules require notification of a covered cybersecurity event within 72 hours. Delta Dental detected a webshell in June 2023 and did not notify the regulator until December 2023. The consent order makes the timing the central finding.

Brazil's Privacy Fines Are About to Get Bigger Than Europe's

Brazil is about to raise the maximum penalty for a data privacy violation tenfold. Brazil's General Data Protection Law (LGPD), passed in 2018 as a close adaptation of the EU's GDPR, has historically been enforced lightly. Brazilian legislators are advancing PL 4530/23, a bill that would raise the maximum LGPD fine from two percent of company revenue to twenty percent. That is five times GDPR's four-percent ceiling. The bill also doubles the per-violation cap to R$100 million (approximately twenty million US dollars). The Brazilian data protection authority, ANPD, published its 2026-27 enforcement priorities this month: artificial intelligence training data, children's data, and public-sector data processing.

316,000 Companies Are About to Get a Reporting Clock

CISA's (the federal cybersecurity agency) Cyber Incident Reporting for Critical Infrastructure Act has been law since 2022. The implementing rule, the one that actually triggers compliance obligations, is expected any week. When it lands, approximately 316,000 entities across sixteen critical infrastructure sectors will have seventy-two hours to report covered cyber incidents to CISA. Twenty-four hours if they make a ransom payment. A covered incident is anything that substantially disrupts your operations, compromises your systems, or arrives through a compromised vendor. Non-reporters face DOJ (Department of Justice) referral, contempt proceedings, and suspension from government contracting.

The Data You Didn't Know You Gave Away Just Raised Your Expenses

General Motors agreed on May 8 to pay $12.75 million to settle allegations that it sold the names, geolocation data, and driving behavior of hundreds of thousands of California drivers to data brokers Verisk Analytics and LexisNexis Risk Solutions through OnStar from 2020 to 2024. It is the largest fine in the California Consumer Privacy Act's (CCPA) history. GM made approximately $20 million from the data sales nationwide. The fine consumed nearly two-thirds of the revenue. GM is now banned from selling driving data to consumer reporting agencies for five years.

The Dot-Com Bubble Popped in Public. This One Won't.

The dot-com crash played out on a ticker. NASDAQ dropped 78 percent. The AI boom is being funded differently. A significant share of the money flowing into AI companies is coming through private credit, loans made by funds outside the traditional banking system that now hold between $1.5 and $2 trillion in assets. The Financial Stability Board (FSB, the international body that coordinates financial regulators across the G20) published its first dedicated report on the sector on May 6 and found opaque valuations, zero stress-test history, and a new wave of wealthy retail investors being invited in through semi-liquid funds.

A Year of Bugs in an Afternoon

Anthropic's Claude Mythos Preview found 271 vulnerabilities in Firefox in a single automated pass. Mozilla patched them all in Firefox 150, released April 22. For comparison, Firefox accumulated 189 security vulnerabilities across the entire year of 2025. An AI found more in one sitting than the security community found in twelve months.

Washington Showed Up to Stop the States

Three weeks ago this newsletter reported that 45 states were writing AI rules while Washington watched. Washington stopped watching. On April 24, the Department of Justice (DOJ) joined a lawsuit to block Colorado's algorithmic discrimination law before it takes effect June 30. The federal government did not file a suggestion or a letter. It became a plaintiff. The argument: the law forces companies to consider race and sex when building AI systems, which violates the Equal Protection Clause (the constitutional bar on government-imposed discrimination). This is the first action by a DOJ task force created specifically to dismantle state AI regulation.

The Signature on the Filing Is the Liability

A CEO who signs a SOX certification (the annual sworn statement to the Securities and Exchange Commission that a company's internal controls work) is personally liable if the controls it vouches for don't exist. At Super Micro, a co-founder routed $2.5 billion worth of Nvidia AI servers through shell companies in Malaysia and Singapore to Chinese buyers between 2024 and 2025. Dummy boxes sat in Malaysian warehouses to fool compliance checks while the real hardware shipped. The DOJ unsealed the indictment March 19. Super Micro's stock dropped 33 percent, erasing roughly $6 billion in market cap.

19 Days

More than a thousand solar farms, wind installations, and battery storage sites must register with NERC (the federal body that enforces power grid reliability) by May 15 and comply with cybersecurity standards for the first time. Most have never had a federal compliance obligation of any kind. The reason this is happening now: in 2021, a single electrical fault at a Texas solar facility cascaded across installations 200 miles apart and knocked 1,100 megawatts offline in seconds. The facilities were not connected to each other. They failed the same way because they were built the same way, with identical inverter settings that no federal regulator had reviewed.

A 1940s Contract Just Became a 2026 Escape Hatch

A Louisiana jury hit Chevron with a $745 million verdict last year in one of forty-two parish coastal-damage suits filed against oil companies. Chevron wanted a related case out of Louisiana state court and into federal court. Their hook was a World War II contract. Chevron's predecessor made aviation fuel for the US military in the 1940s. That contract, Chevron argued, meant they were doing work "under federal direction" even for state-level environmental damage decades later.

$340 Million a Week

The DOJ created the National Fraud Enforcement Division on April 7. Eleven days later, NFED published its first weekly enforcement tally. $340 million in fraud actions across seven days. COVID relief fraud in Kentucky, Indiana, and Colorado. An $11.4 million Medicare fraud case in Florida. Oregon pandemic unemployment-insurance fraud. New Mexico identity theft. Individual sentences ran from twenty-eight months to nine years.

The Safety Net Is Being Dismantled

The White House proposed cutting CISA's budget by $491 million in FY2026 and another $707 million in FY2027. The combined effect eliminates more than a thousand positions and drops the agency from 3,400 people two years ago to under 2,500. Election security is gone entirely. Chemical facility security is gone. The Joint Cyber Defense Collaborative lost $14 million. There is no Senate-confirmed director.

60 Days to Comply. Your Financial Partners Aren't Ready.

On June 3, the SEC's amended Regulation S-P takes effect for thousands of smaller financial firms. Investment advisers managing under $1.5 billion, smaller broker-dealers, fund companies, and transfer agents must have a written incident response program, notify affected customers within 30 days of a breach, and require their service providers to report breaches within 72 hours. The rule was adopted in May 2024. The first compliance deadline passed in December for larger firms. The majority of SEC-registered investment advisers fall under the $1.5 billion threshold, which means most of the industry hits the deadline in June. This is the first major update to Reg S-P since it was written in 2000.

Your Tariff Strategy Just Broke Twice in the Same Month

On February 20, the Supreme Court ruled 6-3 that the International Emergency Economic Powers Act does not give the president authority to impose tariffs. The decision invalidated every IEEPA tariff collected since 2025. Estimated refunds owed to importers: $175 billion, with interest accruing at $650 million per month.

Your Electric Bill Is Subsidizing AI

PJM Interconnection operates the largest power grid in the United States, serving 65 million people across 13 states from Illinois to Virginia. Every year, PJM holds a capacity auction where power generators bid to guarantee they can deliver electricity when demand peaks. The results set a baseline for what utilities charge customers.

China Positioned Itself as Peacemaker This Week. The Trade Summit Moved to May.

On March 20, China's Foreign Ministry called for an immediate end to the war in the Middle East, warning that the "still widening war" harms the "common interests of all countries." Spokesman Lin Jian said "force is not the solution to problems and armed conflict will only breed new hatred." Beijing demanded unimpeded energy flows from the Persian Gulf and positioned itself as the responsible voice calling for restraint while the United States conducts airstrikes across Iran.