On June 23, 2026, the Federal Acquisition Regulatory Council (“FAR Council”) issued proposed rules covering several parts of the Federal Acquisition Regulation (“FAR”). The proposed rules mark the beginning of the long-awaited notice-and-comment phase of the Revolutionary FAR Overhaul (“RFO”). This blog post, focusing on FAR Part 40, provides an overview of the proposed changes to the regulations and the associated contract clauses in FAR Part 52, including the inclusion of requirements around the handling of Controlled Unclassified Information (“CUI”).
Irish NCSC Issues Cyber Governance Guidance for Management Boards Ahead of NIS2 Implementation
On July 7, 2026, the Irish National Cyber Security Centre (“NCSC”) published guidance for management boards and senior executives of organizations subject to the EU’s Network and Information Security Directive (“NIS2”). Reflecting a central theme of NIS2, the Guidance makes it clear that cybersecurity is no longer solely a technical issue, but a governance and risk-management matter that requires active oversight at “the highest levels of executive management.” It is a helpful document for organizations that are likely to be subject to NIS2, expect to be supervised in Ireland, and that are considering their governance structures and board-level oversight mechanisms.
FTC Seeks Comment on Proposed Policy Statement Addressing AI Accuracy and Output Steering
On July 1, 2026, the Federal Trade Commission (“FTC”) issued a proposed policy statement addressing what it describes as the “suppression of accuracy” in artificial intelligence (“AI”) systems and is seeking public comment through July 31, 2026. The proposal was issued pursuant to Executive Order 14365, Ensuring a National Policy Framework for Artificial Intelligence, which directed the FTC to explain how Section 5 of the FTC Act applies when AI developers alter model outputs in response to state law requirements.[1]
GSA Issues RFI to Explore Ideas to Promote Domestic Procurement on GSA Advantage
On June 24, 2026, the General Services Administration (“GSA”) issued a Request for Information (“RFI”) seeking input on two proposals for promoting the purchase of American-made products on GSA Advantage, an online shopping and ordering system, which GSA advertises as providing access to thousands of contractors with millions of products and services. Comments in response to the RFI are due by July 24, 2026.
Citing Executive Order 14392, which Covington previously covered in a client alert, the RFI reflects a broader push by the Trump administration to increase focus on domestic sourcing, including in federal procurement, and to ensure that “Made in America” representations are accurate.[1] As part of that effort, the Small Business Administration and GSA recently de-listed 22 product offerings from the GSA Advantage platform based on false Made in America representations, and President Trump declared that all federal agencies must buy American. Consistent with this policy direction, the RFI seeks input on ways to “make it easier for federal agencies to buy American-made products.” This blog post focuses on the mechanics of GSA’s two proposals, the information sought by GSA in the RFI, and considerations for contractors.
California Court Dismisses Amended Complaint in Hotel Website Wiretapping Suit for Lack of Article III Standing
Recently, a California federal judge dismissed—for the second time—a suit asserting that Sojern, Inc., a travel marketing platform, violated the Federal Wiretap Act and California privacy laws by allegedly deploying “tracking technology” on two hotel websites. Crano v. Sojern, Inc., 2026 WL 1670136 (N.D. Cal. June 9, 2026).
Illinois Enacts Frontier Model Safety Law
On July 6, 2026, Illinois Governor JB Pritzker signed into law SB 315, a frontier model safety act that resembles the New York RAISE Act, discussed in our prior blog post here, and California’s Transparency in Frontier Artificial Intelligence Act (TFAIA), discussed in our prior blog post here. The law takes effect January 1, 2027, with transparency-reporting and audit obligations beginning January 1, 2028. Similar to the New York and California laws, SB 315 will apply to frontier developers (i.e., persons that train, or initiate the training of, a frontier model using computing power greater than 10^26 integer or floating point operations), with certain provisions applicable only to large frontier developers (i.e., frontier developers with annual gross revenue over $500 million in the preceding year). SB 315 also includes public safety disclosure and reporting requirements. Notably, SB 315 also imposes a third-party audit requirement not found in either the New York or the California law.
Government Contractors Face Unique Risks Amid Growing Congressional Scrutiny
In recent years, investigators in Congress have ramped up scrutiny of government contractors and other recipients of federal funds. This trend has only accelerated in the current Congress, with Republican-led committees pursuing expansive inquiries targeting a wide variety of federal contractors and grantees. Along with familiar allegations of waste or misuse of federal funds, these…
Backlash to Bipartisan AI Omnibus Illustrates Preemption Impasse
On June 4, Representatives Jay Obernolte (R-CA) and Lori Trahan (D-MA) released a sweeping discussion draft of their Great American Artificial Intelligence Act. The latest bipartisan AI legislation quickly met bipartisan skepticism, particularly concerning the draft’s approach to federal preemption of state AI rules, with many House Democrats opposing the broad preemption for frontier model developers, while many House Republicans and other stakeholders lamented the bill’s omission of preemption for state laws reaching other parts of the AI ecosystem.
The bill would also establish mandatory disclosure and risk-mitigation requirements for frontier models and task the Center for Artificial Intelligence Standards and Innovation (CAISI) at the National Institute of Standards and Technology (NIST) with oversight of federal AI-related research and analysis, standards and guidelines development, and risk-mitigation activities.
The Numbers Are In: What Financing has the Nagoya Protocol Delivered for Biodiversity After a Decade?
Bart Van Vooren and Yuliya Gevrenova
The Nagoya Protocol was adopted under the Convention on Biological Diversity (“CBD”) and is built on the idea that the commercial use of materials from nature (“genetic resources”) should translate into fair and equitable benefits for countries providing and protecting nature in their jurisdictions. For the first time since…
Brazil delays SISGEN 3.0 Foreign-User Functionality while Government Advances alternative pathway for foreign ABS Compliance
Anderson Ribeiro, Aline Ferreira and Henryk Trelinski of Souto Correa Advogados contributed to the preparation of this article.
Foreign companies have long faced a practical challenge under Brazil’s access and benefit-sharing (“ABS”) regime: although registration obligations apply to activities involving Brazilian genetic heritage, foreign legal entities still cannot register directly in SisGen, Brazil’s…