It’s a common scenario: An employee receives a text from a friend asking them to contribute to the campaign of a candidate the friend supports. Without thinking much about it, the employee makes a $500 contribution. Though the employee has been trained on their company’s political contributions policy, it doesn’t

Continue Reading Election Year Reminder: Pay-to-Play Risks Are Easy to Miss and Costly to Fix

On 3 June 2026, the European Commission published several legislative and policy measures wrapped up in one “tech sovereignty” package (see our posts summarising the package as a whole here, and diving deeper into the Cloud and AI Development Act here). But the EU’s tech sovereignty drive has a long history, and is by no means limited to this package.

In this post, we take a closer look at the current and forthcoming EU legislative measures aimed at increasing the resilience of services provided in the EU against external, malicious influence, a key aspect of tech sovereignty. Relevant legislation falls into two broad categories: (1) laws promoting cyber resilience generally, to prevent malicious actors from disrupting services and critical infrastructure; and (2) laws focused on building supply chain resilience and reducing dependencies on certain external actors by building European industrial capacity in key tech sectors.

Continue Reading Looking beyond the tech sovereignty package: how the EU is moving to ensure tech sector resilience

What’s changing, and why is it important?

In July 2026, the Ministry of Economy & Tourism of the United Arab Emirates (the “Ministry” and “UAE”) published its Guidelines on Relevant Market Definition (the “Guidelines”), providing a detailed look into the Ministry’s framework for market definition assessment. The Ministry considers market definition to be a “fundamental pillar” to the competitive assessment across all competition enforcement contexts and a “crucial stage” in competition enforcement.

The issuance of the Guidelines marks a further important step in the implementation of the UAE’s competition law regime. It follows the introduction of revised merger control thresholds in 2025 and the adoption in April 2026 of implementing regulations for the 2023 Federal Competition Law (see our previous blog on these reforms).

The Guidelines are particularly important for the UAE’s merger control regime, where filing obligations are dependent on parties meeting revenue and/or market share thresholds in the “relevant market” in the UAE. The introduction of the Guidelines provides a crucial tool to merging parties and advisers for determining when transactions may require mandatory notification to the Ministry. More substantively, the Guidelines will provide an important source to help merging parties prepare the “economic report” on the competitive effects of a merger required by the UAE merger notification rules. Beyond merger control, the Guidelines will also provide an important tool for self-assessment of behavioural competition law compliance.

Continue Reading UAE Antitrust Regime Marks an Important Step with the Introduction of Market Definition Guidelines

This update highlights key legislative and regulatory developments in the second quarter of 2026 related to artificial intelligence (“AI”), connected and automated vehicles (“CAVs”), and Internet of Things (“IoT”).

Continue Reading U.S. Tech Legislative & Regulatory Update – Second Quarter 2026

On June 16, 2026, the Delaware General Assembly passed HB 380, which would amend the Delaware Personal Data Privacy Act (DPDPA). The bill is currently awaiting the Delaware governor’s signature, and if signed, the amendments would take effect on January 1, 2027. The amendment would impose the following:

Continue Reading Delaware General Assembly Passes HB 380, an Amendment to the Delaware Personal Data Privacy Act

On July 7, 2026, the Irish National Cyber Security Centre (“NCSC”) published guidance for management boards and senior executives of organizations subject to the EU’s Network and Information Security Directive (“NIS2”). Reflecting a central theme of NIS2, the Guidance makes it clear that cybersecurity is no longer solely a technical issue, but a governance and risk-management matter that requires active oversight at “the highest levels of executive management.”  It is a helpful document for organizations that are likely to be subject to NIS2, expect to be supervised in Ireland, and that are considering their governance structures and board-level oversight mechanisms.

Continue Reading Irish NCSC Issues Cyber Governance Guidance for Management Boards Ahead of NIS2 Implementation

On July 6, 2026, Illinois Governor JB Pritzker signed into law SB 315, a frontier model safety act that resembles the New York RAISE Act, discussed in our prior blog post here, and California’s Transparency in Frontier Artificial Intelligence Act (TFAIA), discussed in our prior blog post here. The law takes effect January 1, 2027, with transparency-reporting and audit obligations beginning January 1, 2028.  Similar to the New York and California laws, SB 315 will apply to frontier developers (i.e., persons that train, or initiate the training of, a frontier model using computing power greater than 10^26 integer or floating point operations), with certain provisions applicable only to large frontier developers (i.e., frontier developers with annual gross revenue over $500 million in the preceding year). SB 315 also includes public safety disclosure and reporting requirements. Notably, SB 315 also imposes a third-party audit requirement not found in either the New York or the California law.

Continue Reading Illinois Enacts Frontier Model Safety Law

In recent years, investigators in Congress have ramped up scrutiny of government contractors and other recipients of federal funds. This trend has only accelerated in the current Congress, with Republican-led committees pursuing expansive inquiries targeting a wide variety of federal contractors and grantees. Along with familiar allegations of waste or

Continue Reading Government Contractors Face Unique Risks Amid Growing Congressional Scrutiny

On June 4, Representatives Jay Obernolte (R-CA) and Lori Trahan (D-MA) released a sweeping discussion draft of their Great American Artificial Intelligence Act. The latest bipartisan AI legislation quickly met bipartisan skepticism, particularly concerning the draft’s approach to federal preemption of state AI rules, with many House Democrats opposing the broad preemption for frontier model developers, while many House Republicans and other stakeholders lamented the bill’s omission of preemption for state laws reaching other parts of the AI ecosystem. 

The bill would also establish mandatory disclosure and risk-mitigation requirements for frontier models and task the Center for Artificial Intelligence Standards and Innovation (CAISI) at the National Institute of Standards and Technology (NIST) with oversight of federal AI-related research and analysis, standards and guidelines development, and risk-mitigation activities.  

Continue Reading Backlash to Bipartisan AI Omnibus Illustrates Preemption Impasse

On June 29, 2026, in a 6-3 decision, the U.S. Supreme Court held that (1) the Federal Trade Commission’s (FTC) statutory “for‑cause” removal protection for Commissioners violates the Constitution’s separation of powers and (2) President Trump lawfully removed Rebecca Slaughter from the FTC. The Court concluded that because FTC Commissioners exercise executive power, they must be removable by the President at will rather than only for “inefficiency, neglect of duty, or malfeasance in office.”

Continue Reading Supreme Court Holds FTC Removal Protections Unconstitutional