The US House Committee on Education and Workforce will mark up H.R. 8747 (K-12 AI Literacy and Readiness Act) and H.R. 8183 (MATCH Act) on July 21, 2026, which could impact AI literacy requirements and hiring practices. Additionally, NLRB nominees have advanced, signaling potential changes in labor law enforcement.
The U.S. Court of Appeals for the Fifth Circuit held that employees can bring hostile work environment claims based on witnessing harassment of coworkers, even if not directly targeted. Employers must ensure prompt and thorough investigations to avoid liability.
The Second Circuit ruled that unions cannot bind former employees to arbitration agreements negotiated after their departure. This limits the reach of collective bargaining agreement arbitration provisions, allowing former employees to pursue statutory claims in court.
The U.S. Department of Labor recovered over $500,000 in back wages for six workers at a San Diego deli who were paid a flat daily rate below minimum wage and denied overtime. This enforcement action underscores FLSA compliance risks for employers paying flat salaries without accounting for overtime.
Edwards Lifesciences must pay a $10 million penalty and implement an antitrust compliance program for failing to notify the FTC about an acquisition, violating the Hart-Scott-Rodino Act. This enforcement action signals increased FTC scrutiny on merger notification compliance.
The California First District Court of Appeal ruled that plaintiffs do not need to show concrete injury to have standing for federal FCRA claims in state court, deepening a split with the Fifth District. This decision increases class action risk for employers using background checks in California.
Connecticut Public Act 26-92 requires arbitrators in private arbitrations conducted in Connecticut to be Connecticut-admitted attorneys in good standing, effective July 1, 2026. The Act applies to newly-filed arbitrations and pending matters where evidentiary hearings have not commenced. Parties may jointly waive the requirement in writing.
The Future of Privacy Forum submitted comments on proposed regulations for California's SB 976, which restricts addictive feeds for minors and requires parental consent. The law takes effect January 1, 2027, and companies must prepare for age assurance, parental consent, and data retention requirements.
The Pentagon has suspended CMMC Phase 2's mandatory third-party assessment requirement due to scalability and cost concerns. Phase 1 self-assessment and DFARS 252.204-7012 obligations remain in effect, and a CMMC Reform Task Force will review the program over 60 days. Industry warns of increased False Claims Act risk from self-attestation without verification.
23andMe agreed to pay $18 million to 43 state attorneys general for failing to protect genetic data in a 2023 breach. The settlement mandates new security measures including a data security advisory board and risk analysis protocols, signaling increased enforcement for inadequate cybersecurity safeguards on sensitive data.
CISA added a critical SharePoint vulnerability (CVE-2026-58644, CVSS 9.8) to its Known Exploited Vulnerabilities catalog, requiring FCEB agencies to patch by July 19, 2026. Active exploitation poses immediate remote code execution risk.
CISA has ordered U.S. federal agencies to patch a critical Oracle E-Business Suite vulnerability (CVE-2026-46817) by July 18, 2026, due to active exploitation. The flaw allows unauthenticated attackers to take over systems via HTTP with a CVSS score of 9.8.
CISA has added two actively exploited Fortinet FortiSandbox vulnerabilities (CVE-2026-39808, CVE-2026-25089) to its Known Exploited Vulnerabilities catalog under BOD 26-04, requiring U.S. federal agencies to patch by July 19, 2026. The flaws allow unauthenticated remote code execution, highlighting the need for timely patch management.
The U.S. Department of Labor's OSHA fined Blazey Construction Services LLC $343,797 after an excavation collapse hospitalized a worker. The company failed to protect the excavation, provide safe egress, and report the hospitalization within 24 hours, resulting in repeat violations and significant penalties.
The SEC has established a new position focused on AI and examinations for broker-dealers and investment advisers, indicating a likely ramp-up in enforcement of the Marketing Rule. This move targets AI use in client communications and advertising, requiring firms to review their AI-driven marketing practices for compliance.
New workplace heat protections have been enacted, reinforcing employer obligations under OSHA's general duty clause. Even without a federal heat standard, employers must take proactive measures to prevent heat-related illnesses, with increased enforcement expected.
OSHA cited FleetPride Inc. for 16 serious safety violations after a worker asphyxiated in a confined space, proposing $264,380 in penalties. This enforcement action underscores OSHA's focus on confined space and respiratory protection standards.
The SEC has approved Regulation E-Delivery, making electronic delivery the default method for satisfying information delivery requirements under federal securities laws. This applies to issuers, broker-dealers, and investment advisers, though investors retain the right to request paper documents.
Several U.S. states are pursuing legislation to mandate transparency in AI use, reflecting a growing regulatory trend at the state level due to the absence of comprehensive federal AI regulation. Companies deploying advanced AI models must monitor and prepare for varying state-level transparency requirements.
The U.S. EEOC is actively enforcing anti-DEI policies under the Trump administration, increasing scrutiny of workplace DEI programs. Employers face heightened legal risks and may need to restructure DEI initiatives to comply with evolving anti-discrimination interpretations.
No articles specifically tagged for United States yet. Check our blog for general compliance coverage.