The SEC Just Deleted 38 Advisers That Never Really Existed
Last week a bank picked up the phone and found the trades weren't real. This week a regulator found the advisers weren't real either.
SEC cyber disclosure rules, privacy regulations, enforcement actions, and compliance obligations.
Last week a bank picked up the phone and found the trades weren't real. This week a regulator found the advisers weren't real either.
Boston Scientific has not shipped an order since Tuesday. The SEC filing calls it "Other Events."
KKR, one of the world's largest private equity firms, just paid the largest fine ever issued under a federal merger-review law, and none of it has to do with whether its deals were bad for competition.
The UK AI Security Institute caught its own test agents taking 19 unauthorized actions last month, during evaluations built specifically to catch that. Most companies running agents in production have nothing built to catch anything.
North Korea's hacking units funded roughly $2.84 billion of the regime's nuclear and missile programs through cryptocurrency theft between January 2024 and September 2025, according to the Multilateral Sanctions Monitoring Team, the eleven-nation coalition that took over UN sanctions monitoring after the original UN Panel of Experts was disbanded. No toolkit built for ordinary criminals has stopped it, and the broader losses Congress itself cites, billions lost to Americans annually through crypto scams, ransomware, and fraud, are real. Indictments against people who never see a US courtroom genuinely are losing that fight. Congress and the White House are now moving on separate tracks to close the gap by commissioning the private sector to hit back, and they're not alone.
Tariffs on imported goods are higher this year than they've been in decades, which makes it more valuable than ever for a company to fudge where a product actually came from, since the tariff rate usually depends on that answer. DOJ's response to that problem isn't new or hypothetical: a joint DOJ–Homeland Security task force built for exactly this, the Trade Fraud Task Force, has already recovered more than $1 billion in penalties, forfeitures, and charged losses since it launched in August 2025.
A Delaware court just told corporate boards what actually protects them when something goes wrong, and it isn't the outcome. On August 13, Vice Chancellor Morgan Zurn, a judge on the Delaware Court of Chancery, the state's specialized business court, dismissed, with prejudice, a shareholder lawsuit trying to hold Boeing's directors personally liable for the safety failures behind the January 2024 Alaska Airlines door-plug blowout. Plaintiffs argued the board ignored warning signs and pushed unsafe production targets. The court disagreed: Boeing's own records showed the board had received detailed safety reports and had acted on them, adjusting production in response. "If everything is a red flag, then nothing is," the court wrote. Directors don't have to prevent every failure. They have to show they built a system to hear about problems, and used it.
Any company that signs a long-term contract with a foreign government typically insists on one specific protection: an arbitration clause, a promise that if a dispute ever happens, it gets decided by a neutral international panel instead of that government's own courts. The assumption behind that clause is that it protects the company from the government. A new dispute out of Kazakhstan shows the same clause working the other way.
South Africa's highest court permanently ended Shell's right to explore for oil and gas off the country's Wild Coast on August 14, closing a legal fight that started with the right itself: granted in 2014. The Constitutional Court found the original public consultation with local communities was inadequate, the same finding a lower court had already made in 2024. What changed this time is the remedy. The 2024 ruling gave Shell a path back: fix the consultation defect, reapply, try again. The Constitutional Court closed that path entirely. There is no cure, no renewal, no second attempt. The right is over, more than a decade after it was granted and years into active legal and commercial commitment to the project.
The Army admits the AI got it wrong. It says that didn't matter.
For 39 years, ISS had the Justice Department's word it wouldn't come after it. That word is gone.
You can still buy this material from anywhere. You just can't sell it anywhere but here.
The Government Accountability Office counted the cybersecurity regulations sitting on top of American companies: 117 of them, across 37 federal agencies. The finding that deserves board attention is the overlap.
Two weeks ago we told you Section 122 tariff authority was set to expire and Section 301 was queued up to take its place. Both happened on schedule, July 24, and the response from trading partners arrived almost as fast: Brazil is now suing the US at the WTO, and South Africa hit back with a tariff of its own within hours of the deadline.
Amgen, the world's largest biotechnology company by revenue, disclosed in July that attackers stole patient health data and business data from a cloud system run by an outside vendor. Amgen hasn't named that vendor. It doesn't yet know how many patients are affected, or how the attackers got in. What it does know is that it's now running two separate regulatory deadlines, and neither one waits for the other.
Chongqing Yanmei Technology, a Chinese company, challenged a small Ohio inventor's patent at the Patent Trial and Appeal Board, the venue that lets anyone challenge a US patent's validity without a jury trial. The patent covered a dissolvable magnesium alloy Terves LLC had developed to plug oil and gas wells during fracking. In August 2024, the board sided with Chongqing Yanmei and found key claims in Terves' patent unpatentable; Terves salvaged some protection only by amending its claims mid-proceeding. Whatever the merits of that specific case, the pattern behind it is what should worry other small patent holders: a challenge like this is cheap to file and expensive to defend, and the cost of defending one, win or lose, is often enough on its own to force a settlement or bankrupt a small inventor.
An executive order signed July 20 and published in the Federal Register on July 23, "Securing America's Defense Supply Chains and Ensuring Domestic Acquisition of Critical Materials," directs the Department of War, the renamed Defense Department, to require prime contractors and subcontractors at any tier on national-security acquisitions to trace their supply chains back to raw-material origin, screen for prohibited sources, and submit mitigation or onshoring plans. Implementation guidance is due within 180 days.
For the past five months, almost everything the United States imports has carried an extra 10% tax at the border. That surcharge disappears on July 24. If you run a business that buys anything from overseas, the natural assumption is that your costs are about to drop. They are not. The 10% is being replaced by something more expensive that, unlike the surcharge, may never expire.
The countries getting hit by that tariff regime are not absorbing it quietly, and Brazil's answer reaches a place American companies rarely think to protect: their own patents.
There is a second deadline this week that has nothing to do with tariffs and is easy to miss. On Monday, July 27, at 6pm Central European time, companies can sign the European Union's new Code of Practice on labeling AI-generated content. Signing is voluntary. It also decides how hard the next part gets.
At a summit in Ankara this week, NATO announced the largest defense build-out in a generation. More than $50 billion in new weapons purchases, a $40 billion fund for military drones over the next five years, and a restated pledge to push defense spending to 5 percent of each member's economic output by 2035, up from about 4 percent today. Strip away the summit choreography and the acronyms and it comes down to money, a great deal of it, and where it is about to flow. That last figure alone is trillions of dollars over the decade.
In late June, the Supreme Court ruled that the President can fire the commissioners of the Federal Trade Commission at will. The FTC is the government's main privacy enforcer, and the case looked like a fight over presidential power in Washington. For any company that stores European data on US servers, it is more than that. It quietly weakened the legal ground under those data transfers.
Washington has spent the past year trying to stop states from regulating artificial intelligence. It has not worked, and the states are not waiting.
Last month the government set the quantum deadline. This month the companies that run your systems moved it closer, and the money moving underneath tells you why.
A 2019 bank robbery in Midlothian, Virginia just changed the legal status of the location data sitting in your company's servers.
Going after the marketplace instead of the seller is not new. The government shut down Silk Road and prosecuted its operator; it seized Backpage and charged the people who ran it. The lesson from Alibaba's $600 million settlement on July 1 is that the same theory now reaches a legitimate business, not just a criminal one.
This has been the summer of the drone. Securing the FIFA World Cup, the FBI has detected more than 1,100 drones over stadiums and seized over 500, arresting operators from Houston to Dallas. A JetBlue crew even reported a suspected drone strike on approach to New York's JFK on June 29, though investigators later found no proof of a collision. The machines are everywhere, and the ones that should worry your business are not the ones over the ballgame.
A Pennsylvania bank just filed the same emergency disclosure a company files after a ransomware attack. Nobody broke in. One of its own people had pasted customer records into an AI tool to get a job done faster.
There is a kind of theft where the payoff arrives years after the crime. An adversary copies your encrypted data today, sits on it, and waits for a quantum computer powerful enough to pry the encryption open. The shorthand for it is harvest now, decrypt later, and it is the reason a problem that always sounded like a 2035 concern is suddenly a 2030 one.
Last week we reported that the US government ordered Anthropic to switch off two AI models worldwide with no notice and no appeal. That was not the beginning of this story. It was the latest in a chain of events that had already convinced European governments to walk away from American software.
The threat intelligence that feeds your security program has a supply chain, and three links in it just got thinner.
The United States-Mexico-Canada Agreement, the trade deal signed in 2018 to replace NAFTA, faces its first mandatory review on July 1. The review is supposed to be procedural: all three countries agree to extend it for sixteen years, or it enters annual reviews and begins winding down. It will not be procedural. All three members are pulling in different directions, and any company that built supply chain assumptions on this deal's stability should revisit them before next month.
Last week we wrote about the cyber insurance market and the gap between having a policy and collecting on it. This is a different policy and a different gap.
On June 12, the US government ordered a private company to switch off a product worldwide. The company was Anthropic, a US artificial-intelligence developer, and the product was its two newest models, Claude Fable 5, released three days earlier, and Claude Mythos 5.
Across three countries, courts are converging on a single idea: a company is responsible for what its AI tells people, the same as it would be for any employee or any line on its website. There is no settled rulebook yet, and what counts as a safe thing for an AI to say is landing differently in every jurisdiction.
The legal exposure from artificial intelligence is becoming personal to the board members and senior executives who oversee and run a company, and it is arriving at the moment the insurance meant to protect them begins to carve AI out.
A transaction you signed, funded, and closed in Europe can now be reopened by a government up to five years later.
On June 4 and 5, the Supreme Court issued two rulings that changed how federal agencies can come after companies.
The European Commission published the Cloud and AI Development Act (CADA), a framework that divides cloud providers into four tiers based on how much sovereignty they offer. The higher the tier, the more sensitive the government contracts you can compete for. The catch: American cloud providers cannot reach the top two tiers without fundamentally restructuring how they operate. EU Vice President Henna Virkkunen framed the rationale directly: "We want to be sure nobody has a kill switch."
For years, companies importing goods from China have used a simple workaround to avoid the tariffs designed to stop foreign manufacturers from undercutting American competitors by selling below cost. Ship the product to a third country like Vietnam, Malaysia, or Mexico. Relabel it. Import it into the US under the new country of origin. The duties that were designed to protect American manufacturers never get paid. The practice is so widespread that trade lawyers have a name for it: transshipment.
For over a decade, California companies facing data breach lawsuits could ask one question that usually ended the case: can you prove anyone actually viewed the stolen data? On May 14, the California Supreme Court eliminated that defense.
California Attorney General Rob Bonta sued Chrome Holding Co., the entity that emerged from 23andMe's bankruptcy, on May 28. The complaint alleges the company failed to protect 6.9 million users' genetic profiles, took five months to detect the breach, paid a ransom to the threat actor while publicly claiming no systems were compromised, and shifted blame to customers for reusing passwords.
Three things happened in May that turned commercial location data from a business asset into a liability.
Berkshire Hathaway, Chubb, and Travelers began filing AI exclusion endorsements with state insurance regulators in late 2025. Regulators approved more than 80 percent of the applications. In January 2026, ISO (the insurance industry's standards body) issued three new generative AI exclusion forms for commercial general liability policies. The exclusions carve out bodily injury, property damage, defamation, and intellectual property infringement tied to AI-generated outputs.
On May 21, the New York Department of Financial Services (NYDFS, the state regulator overseeing banks, insurers, and crypto firms operating in New York) issued two industry letters to its regulated entities. The first, addressed to CISOs, warns specifically about frontier AI risks. The second provides broader guidance for operating in a heightened threat environment. The letters warn that frontier AI models are accelerating vulnerability discovery, exploit development, and social engineering attacks, citing a CrowdStrike finding of an 89 percent year-over-year increase in AI-enabled attacks.
On the Friday before Memorial Day, Microsoft updated its Data Processing Agreement (DPA, the contract governing how Microsoft handles your organization's data) to reduce the notice period for introducing new AI subprocessors from six months to 30 days. A subprocessor is a third-party company Microsoft contracts to process your data. In the AI context, that includes companies like Anthropic powering features inside Copilot and Azure.
Twelve months ago, the Colorado AI Act was the most aggressive state AI law in the country. Six weeks before its effective date, it's notice-only paperwork and a footnote in a Department of Justice (DOJ) strategy memo.
Delta Dental Insurance Company and Delta Dental of New York paid New York's financial regulator $2.25 million last month for a cybersecurity incident. The incident itself was modest. The penalty was driven by a six-month delay in notification. New York's rules require notification of a covered cybersecurity event within 72 hours. Delta Dental detected a webshell in June 2023 and did not notify the regulator until December 2023. The consent order makes the timing the central finding.
Brazil is about to raise the maximum penalty for a data privacy violation tenfold. Brazil's General Data Protection Law (LGPD), passed in 2018 as a close adaptation of the EU's GDPR, has historically been enforced lightly. Brazilian legislators are advancing PL 4530/23, a bill that would raise the maximum LGPD fine from two percent of company revenue to twenty percent. That is five times GDPR's four-percent ceiling. The bill also doubles the per-violation cap to R$100 million (approximately twenty million US dollars). The Brazilian data protection authority, ANPD, published its 2026-27 enforcement priorities this month: artificial intelligence training data, children's data, and public-sector data processing.
CISA's (the federal cybersecurity agency) Cyber Incident Reporting for Critical Infrastructure Act has been law since 2022. The implementing rule, the one that actually triggers compliance obligations, is expected any week. When it lands, approximately 316,000 entities across sixteen critical infrastructure sectors will have seventy-two hours to report covered cyber incidents to CISA. Twenty-four hours if they make a ransom payment. A covered incident is anything that substantially disrupts your operations, compromises your systems, or arrives through a compromised vendor. Non-reporters face DOJ (Department of Justice) referral, contempt proceedings, and suspension from government contracting.
General Motors agreed on May 8 to pay $12.75 million to settle allegations that it sold the names, geolocation data, and driving behavior of hundreds of thousands of California drivers to data brokers Verisk Analytics and LexisNexis Risk Solutions through OnStar from 2020 to 2024. It is the largest fine in the California Consumer Privacy Act's (CCPA) history. GM made approximately $20 million from the data sales nationwide. The fine consumed nearly two-thirds of the revenue. GM is now banned from selling driving data to consumer reporting agencies for five years.
The dot-com crash played out on a ticker. NASDAQ dropped 78 percent. The AI boom is being funded differently. A significant share of the money flowing into AI companies is coming through private credit, loans made by funds outside the traditional banking system that now hold between $1.5 and $2 trillion in assets. The Financial Stability Board (FSB, the international body that coordinates financial regulators across the G20) published its first dedicated report on the sector on May 6 and found opaque valuations, zero stress-test history, and a new wave of wealthy retail investors being invited in through semi-liquid funds.
Anthropic's Claude Mythos Preview found 271 vulnerabilities in Firefox in a single automated pass. Mozilla patched them all in Firefox 150, released April 22. For comparison, Firefox accumulated 189 security vulnerabilities across the entire year of 2025. An AI found more in one sitting than the security community found in twelve months.
Three weeks ago this newsletter reported that 45 states were writing AI rules while Washington watched. Washington stopped watching. On April 24, the Department of Justice (DOJ) joined a lawsuit to block Colorado's algorithmic discrimination law before it takes effect June 30. The federal government did not file a suggestion or a letter. It became a plaintiff. The argument: the law forces companies to consider race and sex when building AI systems, which violates the Equal Protection Clause (the constitutional bar on government-imposed discrimination). This is the first action by a DOJ task force created specifically to dismantle state AI regulation.
A CEO who signs a SOX certification (the annual sworn statement to the Securities and Exchange Commission that a company's internal controls work) is personally liable if the controls it vouches for don't exist. At Super Micro, a co-founder routed $2.5 billion worth of Nvidia AI servers through shell companies in Malaysia and Singapore to Chinese buyers between 2024 and 2025. Dummy boxes sat in Malaysian warehouses to fool compliance checks while the real hardware shipped. The DOJ unsealed the indictment March 19. Super Micro's stock dropped 33 percent, erasing roughly $6 billion in market cap.
More than a thousand solar farms, wind installations, and battery storage sites must register with NERC (the federal body that enforces power grid reliability) by May 15 and comply with cybersecurity standards for the first time. Most have never had a federal compliance obligation of any kind. The reason this is happening now: in 2021, a single electrical fault at a Texas solar facility cascaded across installations 200 miles apart and knocked 1,100 megawatts offline in seconds. The facilities were not connected to each other. They failed the same way because they were built the same way, with identical inverter settings that no federal regulator had reviewed.
A Louisiana jury hit Chevron with a $745 million verdict last year in one of forty-two parish coastal-damage suits filed against oil companies. Chevron wanted a related case out of Louisiana state court and into federal court. Their hook was a World War II contract. Chevron's predecessor made aviation fuel for the US military in the 1940s. That contract, Chevron argued, meant they were doing work "under federal direction" even for state-level environmental damage decades later.
The DOJ created the National Fraud Enforcement Division on April 7. Eleven days later, NFED published its first weekly enforcement tally. $340 million in fraud actions across seven days. COVID relief fraud in Kentucky, Indiana, and Colorado. An $11.4 million Medicare fraud case in Florida. Oregon pandemic unemployment-insurance fraud. New Mexico identity theft. Individual sentences ran from twenty-eight months to nine years.
The White House proposed cutting CISA's budget by $491 million in FY2026 and another $707 million in FY2027. The combined effect eliminates more than a thousand positions and drops the agency from 3,400 people two years ago to under 2,500. Election security is gone entirely. Chemical facility security is gone. The Joint Cyber Defense Collaborative lost $14 million. There is no Senate-confirmed director.
As of March 2026, state legislators have introduced 1,561 bills regulating artificial intelligence across 45 states. In 2023, the number was fewer than 200. There is no federal AI law. There is no indication one is coming soon enough to matter.
On June 3, the SEC's amended Regulation S-P takes effect for thousands of smaller financial firms. Investment advisers managing under $1.5 billion, smaller broker-dealers, fund companies, and transfer agents must have a written incident response program, notify affected customers within 30 days of a breach, and require their service providers to report breaches within 72 hours. The rule was adopted in May 2024. The first compliance deadline passed in December for larger firms. The majority of SEC-registered investment advisers fall under the $1.5 billion threshold, which means most of the industry hits the deadline in June. This is the first major update to Reg S-P since it was written in 2000.
On February 20, the Supreme Court ruled 6-3 that the International Emergency Economic Powers Act does not give the president authority to impose tariffs. The decision invalidated every IEEPA tariff collected since 2025. Estimated refunds owed to importers: $175 billion, with interest accruing at $650 million per month.
PJM Interconnection operates the largest power grid in the United States, serving 65 million people across 13 states from Illinois to Virginia. Every year, PJM holds a capacity auction where power generators bid to guarantee they can deliver electricity when demand peaks. The results set a baseline for what utilities charge customers.
On March 20, China's Foreign Ministry called for an immediate end to the war in the Middle East, warning that the "still widening war" harms the "common interests of all countries." Spokesman Lin Jian said "force is not the solution to problems and armed conflict will only breed new hatred." Beijing demanded unimpeded energy flows from the Persian Gulf and positioned itself as the responsible voice calling for restraint while the United States conducts airstrikes across Iran.
On March 6, the White House released "President Trump's Cyber Strategy for America" alongside an executive order elevating cybercrime to the same priority level as nation-state threats. The document is four pages. It is worth reading in full.
Last week we reported that more than half of cyber insurance claims were denied. This week, the war that just started may have voided your policy entirely.
The EU wants to ban high-risk technology suppliers from 18 critical sectors. China has spent a decade embedding its equipment in networks worldwide. Brussels just fired the starting gun on a forced divorce.