June 2026

Vermont recently enacted two privacy bills to regulate health-related information. These include H.639, a genetic privacy bill regulating direct-to-consumer genetic testing companies, and the Vermont Data Privacy and Online Surveillance Act (S.71), a comprehensive privacy law that extends heightened protections to “consumer health data.” You can read our full analysis of S.71 here.

The Fourth Circuit recently vacated a district court’s grant of class certification based on a lack of commonality and predominance.  See Overby v. Anheuser-Busch, LLC, 2026 WL 1718962 (4th Cir. June 15, 2026).  The plaintiffs sought to represent a class of hourly employees asserting claims based on allegations that their employer had a corporate policy

On June 12, 2026, the European Commission (“Commission”) launched its public consultation on guidelines (“Guidelines”) that will significantly shape the implementation of the EU’s Corporate Sustainability Due Diligence Directive (“CSDDD;” more details about the CSDDD available here). The consultation, presented in the form of a detailed questionnaire, is open until July 24, 2026. The

Since our prior post on Singapore’s Model AI Governance Framework for Agentic AI, Singapore’s Infocomm Media Development Authority (“IMDA”) has published an updated version (Version 1.5) (the “Updated Framework”), incorporating feedback from over 60 organizations.

The Updated Framework, published on May 20, 2026, retains the same four-pillar structure—(1) assess and bound the risks upfront, (2)

In January 2025, Covington issued a client alert noting that the National Defense Authorization Act (“NDAA”) for Fiscal Year (“FY”) 2025, which sets annual spending and policy for the Pentagon, introduced new China-related prohibitions on defense contractors and their consultants. The provision is finally set to take effect on June 30, 2026. Covington’s latest

On June 10, the Cybersecurity & Infrastructure Security Agency (CISA) released Binding Operational Directive (BOD) 26-04 on Prioritizing Security Updates Based on Risk and the accompanying Implementation Guidance. In releasing the BOD and Implementation Guidance, CISA noted that the documents are “part of CISA’s response to the current threat landscape” and the impact of