Insights

Professional
Practice
Industry
Region
Trending Topics
Location
Type

Sort by:

Client Alerts 438 results

Client Alert | 5 min read | 08.21.26

FTC Proposes Enforcement Policy Statement on Personalized Pricing: What Businesses Need to Know

On August 19, 2026, the Federal Trade Commission (FTC) announced a proposed Enforcement Policy Statement on personalized pricing — the practice of companies using consumers’ personal data to set individualized prices, discounts, coupons, or other incentives. The proposed statement, which is open for public comment for 30 days following publication in the Federal Register, marks a major step up in the FTC’s focus on data-driven pricing strategies and puts businesses across industries on notice that undisclosed or inadequately disclosed personalized pricing will not be tolerated. Importantly, while the proposed statement is not a binding legal requirement and does not create new legal obligations, it serves as an enforcement warning that the FTC is prepared to use its existing enforcement authority under Section 5 of the FTC Act (Section 5) and is also a potential harbinger of rulemaking. Businesses that engage in — or are considering — personalized pricing should carefully assess their disclosure practices and data collection procedures against the standards articulated in this statement.
...

Client Alert | 4 min read | 08.14.26

License to Hack? The White House Greenlights Private-Sector Offensive Cyber Operations

On August 12, 2026, the White House released a National Security Presidential Memorandum (NSPM), marking a seismic shift in U.S. cybersecurity policy and establishing a framework to authorize private-sector companies to conduct offensive cyber operations—historically strictly prohibited by federal law—against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs).  It builds on an executive order issued in March 2026 that directed federal agencies to develop plans to combat cyber-crimes against Americans.
...

Client Alert | 2 min read | 08.03.26

New York Becomes First State to Restrict Addictive Social Media Features for Minors

New York is set to become the first state in the nation to restrict algorithmically-driven “addictive” social media features for users under 18. On July 29, 2026, the State published the final rules implementing the Stop Addictive Feeds Exploitation (SAFE) for Kids Act, which takes effect January 25, 2027.
...

Client Alert | 4 min read | 08.03.26

Short-Circuited: FCC Updates Covered List to Prohibit Foreign Power Inverters and Advanced Robotic Devices

On July 28, 2026, the Federal Communications Commission (FCC) updated its Covered List, established through the Secure and Trusted Communications Networks Act to include foreign-produced connected power inverters and advanced robotic devices. The designation of these products to the Covered List follows an Executive Branch national security determination that they “pose unacceptable risks to the national security of the United States or the safety and security of United States persons.” Equipment listed on the Covered List is ineligible for FCC equipment authorization, effectively prohibiting the import, sale, or marketing of those products absent an exception or approval. This action comes only months after the FCC added consumer-grade routers to the Covered List on March 23, 2026 and uncrewed aircraft systems (UAS) on December 22, 2025. Taken together, these actions reflect the FCC’s increasingly expansive approach to using its authorities to guard against foreign produced connected technologies that may create vulnerabilities enabling disruption of critical infrastructure, unauthorized access to sensitive information, or cyber intrusions. The shift is a departure from the FCC’s previous focus on equipment and services produced by certain PRC and Russian companies.
...

Client Alert | 5 min read | 07.20.26

DOJ and DHS Issue Interim Final Rule on State and Local Counter-Drone Authority Under the SAFER SKIES Act

On July 6, 2026, the U.S. Department of Justice (DOJ) and the U.S. Department of Homeland Security (DHS) published an Interim Final Rule (IFR) setting up a new federal framework that allows state, local, Tribal, and territorial (SLTT) law enforcement and correctional agencies to detect, track, and, in some cases, disable or seize drones. The rule directly affects SLTT agencies looking to stand up counter-drone programs, as well as drone and counter-drone technology companies whose products will be subject to federal review and approval. Although the IFR bypassed the Administrative Procedure Act’s standard notice-and-comment process on good cause grounds — citing the statutory 180-day deadline and urgent public safety needs — the rule is already legally binding and effective as of July 1, 2026. The Departments are nonetheless accepting post-promulgation comments through September 4, 2026.
...

Client Alert | 2 min read | 07.13.26

Department of War Immediately Suspends CMMC Phase II Requirements, Launches 60-Day Reform Review

The Department of War (DoW) is immediately suspending Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which had been scheduled to take effect on November 10, 2026.
...

Client Alert | 1 min read | 07.08.26

Crowell & Moring and Crowell GovCon Strategies at Farnborough International Airshow 2026

We are pleased to announce that Crowell & Moring and Crowell GovCon Strategies will be exhibiting at Farnborough International Airshow (FIA 2026), one of the world's premier aerospace, defence and space events. FIA is where the aerospace, defence and space industry comes together. It is where deals are made, partnerships are formed, and the future direction of the sector takes shape. For businesses operating in this environment, navigating complex regulation, competing for government contracts, protecting critical intellectual property and managing international trade across multiple jurisdictions demands the right legal and strategic counsel.
...

Client Alert | 7 min read | 07.08.26

Illinois Imposes Transparency and Safety Obligations on Frontier AI Systems

On July 6, 2026, Illinois Governor JB Pritzker signed SB 315, the Artificial Intelligence (AI) Safety Measures Act (the Illinois Act), to establish a framework for AI safety, transparency, and accountability for the world’s most powerful AI models. The governor’s approval follows unanimous passage of the bill by the Illinois House and nearly-unanimous support in the Illinois Senate in May. 
...

Client Alert | 2 min read | 07.07.26

Time for a Change: FedRAMP Fundamentally Revamps Program With Consolidated Rules for 2026

On June 25, 2026, the Federal Risk & Authorization Management Program (FedRAMP) launched its Consolidated Rules for 2026, marking a significant turning point in how the U.S. government administers security authorizations of private sector cloud offerings. The Consolidated Rules apply to all variants of the FedRAMP ecosystem, including legacy "Rev5" authorization holders, as well as future certifications under the new 20x program. Importantly, the Rules are intended in part to transition Rev5 authorizations over to 20x, with the Rev5 authorization status expected to terminate by the end of 2028. 
...

Client Alert | 4 min read | 07.06.26

House Advances Bipartisan Kids' Online Safety Bill, But Senate Showdown Looms

On June 22, 2026, House Energy and Commerce Committee Chairman Brett Guthrie (R-Ky.) and Ranking Member Frank Pallone (D-N.J.) announced a bipartisan agreement on a revised version of the KIDS Act (H.R. 7757), marking the most significant congressional advance on children's online safety legislation in years. The House passed H.R. 7757, as amended, on June 29, 2026, setting up a potential showdown with the Senate. The revised KIDS Act consolidates elements of 14 pending legislative proposals — including KOSA and COPPA 2.0, both of which have previously passed the Senate and cleared the House Energy and Commerce Committee — into a single, comprehensive framework. The announcement, however, was met immediately with objections from Senate sponsors and civil liberties groups, underscoring the difficult legislative road ahead.
...

Client Alert | 4 min read | 06.25.26

Twin Executive Orders Seek to Spur Quantum Leap in Technology and Cybersecurity

On June 22, 2026, President Trump signed two executive orders, “Securing the Nation Against Advanced Cryptographic Attacks” (Quantum Security EO) and “Ushering in the Next Frontier of Quantum Innovation” (Quantum Innovation EO), marking the most significant federal action on quantum technology since the Quantum Computing Cybersecurity Preparedness Act of 2022, which directed agencies to harden their information systems against quantum-enabled hacking. The orders seek to speed the development of quantum computers, which are advanced processors that can calculate multiple possibilities simultaneously and thus solve problems exponentially faster than traditional computers. At the same time, the orders look to protect against the danger that quantum technology can “break” traditional encryption by easily decoding it. Of particular note for government contractors, the Quantum Security EO directs agencies to update federal acquisition regulations to require contractors by 2031 to adopt information processing standards that resist quantum-enabled codebreaking.
...

Client Alert | 6 min read | 06.17.26

GSA Issues Proposed AI Contract Clause, Seeks Feedback

The General Services Administration (GSA) is seeking public comment on a new GSA Regulation clause, 552.239-7001, Basic Safeguarding of Data within Large Language Model Artificial Intelligence Systems (LLMs), governing data safeguards and requirements prime contractors must comply with when providing or using LLMs under federal contracts. This updated clause (Revised Clause) reflects substantial revisions from an earlier version released in March 2026 (Original Clause) that faced substantial pushback from industry. Where the Original Clause cast a wide net — imposing obligations broadly across AI systems with little differentiation among supply-chain participants — the Revised Clause is more narrowly tailored. The Revised Clause:
...

Client Alert | 13 min read | 06.12.26

EU Cyber Resilience Act Countdown: 11 September 2026 Incident/Vulnerability Reporting Deadline Less Than 100 Days Away

The EU Cyber Resilience Act (CRA) is an EU product cybersecurity law for connected products (formally, “products with digital elements” under the CRA) commercialized in the EU; it entered into force on 10 December 2024, with direct application across the EU. Full application begins 11 December 2027, but one of its most operationally demanding provisions takes effect in just under 100 days, on 11 September 2026: the mandatory vulnerability and incident reporting under Article 14 CRA.
...

Client Alert | 4 min read | 06.12.26

National Security Memorandum Aims to Accelerate Deployment of AI and Streamline Procurement Aligned to Administration Policies

On June 5, 2026, President Trump issued National Security Presidential Memorandum (NSPM) 11 (NSPM-11) to accelerate AI adoption by the U.S. military and intelligence agencies. It directs updated AI management, acquisition, and use policies and seeks to compel AI companies to comply with Trump administration policies.  It calls for expanded training and enhanced security in collaboration with the private sector and orders the “termination for default or for convenience” of government contracts with AI companies that wish to limit how the government uses their products. NSPM-11 could also herald a major change in autonomous warfighting policy by directing the update of the Pentagon’s primary directive on autonomous weapon systems.
...

Client Alert | 6 min read | 06.03.26

Executive Order Creates Voluntary Regulatory Regime of Frontier AI Models

On June 2, 2026, President Trump signed a highly anticipated artificial intelligence and cybersecurity Executive Order, “Promoting Advanced Artificial Intelligence Innovation and Security” (the EO), directing several national security and civilian agencies to ramp up scrutiny of cutting-edge AI models and bolster federal cybersecurity defenses against AI-enabled threats.
...

Client Alert | 8 min read | 05.28.26

Texas Targets Big Tech With Wave of Suits and Investigations, Part of Nationwide Trend

Texas Attorney General (AG) Ken Paxton has embarked on an aggressive campaign of regulation through enforcement against some of the world’s largest technology companies.
...

Client Alert | 7 min read | 05.27.26

Colorado Hits Reset on AI Regulation: SB 26-189 Repeals and Reenacts the Colorado AI Act

Colorado’s original AI Act (SB 24-205), signed in May 2024, imposed broad obligations on developers and deployers of “high-risk AI systems” — including requiring risk management programs, impact assessments, and affirmative steps to prevent algorithmic discrimination across employment, housing, lending, insurance, health care, and education decisions. The operative date for SB 24-205 was extended twice, and a court temporarily suspended enforcement in early 2026, following a lawsuit filed by xAI, which the U.S. Department of Justice (DOJ) intervened to support. Industry feedback on SB 24-205 was generally negative. In response to this environment, Colorado’s legislature undertook a rewrite, drafting and passing SB 26-189 in a matter of weeks. SB 26-189 reflects the legislature’s effort to preserve the policy goal of filling the AI oversight vacuum given the lack of a comprehensive federal law, but within a more workable compliance framework.
...

Client Alert | 7 min read | 05.19.26

American and Allied Cyber Agencies Issue First Joint Guidance on Securing Agentic AI

On May 1, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the U.S. National Security Agency (NSA), the Australian Cyber Security Centre, the UK National Cyber Security Centre, the Canadian Centre for Cyber Security, and the New Zealand National Cyber Security Centre, published joint guidance on the “Careful Adoption of Agentic AI Services” (Guidance).
...

Client Alert | 3 min read | 05.14.26

CISA’s “CI Fortify” Initiative Signals New Expectations for Critical Infrastructure Resilience: What Operators and Vendors Need to Know

On May 5, 2026, CISA announced CI Fortify — an initiative directing critical infrastructure owners and operators to prepare for geopolitical conflict in which OT networks are actively targeted while communications infrastructure is simultaneously degraded.
...

Client Alert | 7 min read | 05.06.26

Artificial Intelligence and Human Resources in the EU - Part 2: AI Literacy - Employer AI Literacy Obligations under the EU AI Act

The EU AI Act defines ‘AI literacy’ as the skills, knowledge and understanding to enable the informed use and operation of AI systems and increase awareness of the opportunities, risks and possible harm that AI systems may present — with the ultimate purpose being to ensure that staff (and other relevant individuals) are able to take informed decisions in relation to AI, such as how to interpret AI output and decision-making processes and their impact on natural persons.
...