Legal & Compliance — 2026年9月14日 週次レポート
Legal & Complianceのニュース&アップデート — すべての記述に一次ソースのリンク付き。
重要な発見
エグゼクティブサマリー(5件)
- •The SEC's rulemaking agenda this week represents a structural pivot in US securities regulation: simultaneously proposing semiannual reporting, crypto asset exemptions, and pay-to-play rule rescission signals that the deregulatory direction established in prior weeks is accelerating into consequential, multi-front rulemaking that will reshape compliance obligations for public companies, investment advisers, and crypto issuers alike.
- •The EU's digital compliance environment reached a new enforcement threshold this week — the Cyber Resilience Act's reporting obligations took effect, the Dutch DPA issued a near-billion-euro GDPR fine against Uber for automated decision-making violations, and Delaware expanded its state privacy law — collectively signaling that both EU and US state-level privacy and cybersecurity enforcement are entering a more demanding phase.
- •The FTC's dual-track posture — escalating payment processor enforcement while rescinding policy statements on health app breaches and disparate impact — reflects a selective enforcement philosophy that concentrates resources on fraud facilitation while withdrawing from broader regulatory theories, a pattern that compliance programs must now account for in risk prioritization.
- •International legal institutions produced significant outputs this week: the ICJ concluded Nicaragua v. Germany hearings on Palestinian territory obligations, the CJEU upheld EU sanctions and merger prohibitions, and UNCITRAL completed its 10th ISDS reform meeting — together these developments signal that international dispute resolution and treaty-based compliance obligations are evolving rapidly across multiple forums simultaneously.
- •The activation of the US Alien Terrorist Removal Court for the first time, combined with the H-2B cap being reached for FY2027, illustrates that immigration enforcement is operating at maximum institutional capacity across both national security and labor migration channels — organizations with immigration-dependent workforces or national security exposure face a compressed and high-stakes compliance environment.
今回の要点(15件)
- 1.Humboldt Merchant Services agreed to pay $12 million and accept a permanent ban from processing payments for high-fraud-risk merchants to settle FTC charges of knowingly facilitating payment processing for sham merchants [3].
- 2.The FTC rescinded the 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices on September 9, 2026, continuing a pattern of policy statement withdrawals that narrows the FTC's enforcement theories [3].
- 3.The SEC proposed Regulation Crypto Assets on August 18, 2026, creating the first registration-exempt offering framework for crypto assets, with a startup exemption capped at $5 million and a fundraising exemption of up to $75 million per 12-month period [6a].
- 4.The SEC proposed sweeping public company reporting changes that would allow semiannual reporting via a new Form 10-S and exempt an estimated 81% of public companies from SOX Section 404(b) auditor attestation requirements, potentially effective as early as 2027 or 2028 [6b].
- 5.The SEC proposed rescinding Rule 206(4)-5 (the pay-to-play rule) for investment advisers in its entirety on September 3, 2026, citing overbroad definitions and a de facto strict-liability standard that raises First Amendment concerns [6c].
- 6.The SEC issued new Schedule 13G guidance on September 2, 2026, clarifying that passive investors can engage with issuers and other investors without losing 13G eligibility when engagement is issuer-initiated or aimed at understanding issuer disclosures [6d].
- 7.The EU Cyber Resilience Act's incident reporting obligations took effect on September 11, 2026, creating mandatory compliance requirements for manufacturers of products with digital elements in the EU market [7].
- 8.The Dutch Data Protection Authority fined Uber €824,990,000 on August 21, 2026 for infringing GDPR rules on solely automated decision-making affecting drivers, one of the largest GDPR enforcement actions recorded [7].
- 9.Delaware expanded its Personal Data Privacy Act on September 2, 2026, with Governor Meyer signing House Bill 380, effective January 1, 2027 [7].
- 10.The DOJ completed the first-ever case before the United States Alien Terrorist Removal Court on September 11, 2026, removing an Afghan national who conceded alien terrorist status [9].
- 11.The CJEU General Court upheld the prohibition of Booking Holdings' acquisition of Etraveli Group and dismissed Roman Abramovich's challenge to EU restrictive measures on September 9, 2026 [8].
- 12.UNCITRAL Working Group III's 10th Intersessional meeting on ISDS reform concluded on September 11, 2026 after three days of sessions jointly organized with the Government of Vietnam [16].
- 13.The UK Law Commission published recommendations for modernizing friendly societies rules on September 10, 2026, adding to its active reform agenda that includes the homicide consultation deadline of September 30, 2026 [2].
- 14.SEC Chairman Atkins addressed the Investor Advisory Committee on September 12, 2026, cautioning that AI should complement rather than substitute for human judgment in disclosures and that the SEC will not prescribe specific AI models [6e].
- 15.A federal cybersecurity agency issued guidance treating autonomous AI agents as a distinct attack vector requiring new controls, prompting companies to review incident response plans and upgrade monitoring capabilities [6b].
市場動向
FTC Accelerates Payment Processor Enforcement and Policy Rollbacks Simultaneously
The FTC's enforcement posture this week reveals a dual-track pattern: aggressive action against payment processors combined with policy retrenchment. Humboldt Merchant Services agreed to pay $12 million and accept a permanent ban from processing payments for high-fraud-risk merchants [3]. Simultaneously, the FTC rescinded the 2021 Policy Statement on Breaches by Health Apps on September 9, 2026, and on August 7, 2026 announced it will no longer pursue disparate-impact discrimination claims [3]. …
SEC Deregulatory Rulemaking Intensifies Across Securities and Crypto Markets
The SEC proposed a sweeping overhaul of public company reporting that would allow semiannual reporting via a new Form 10-S and exempt an estimated 81% of public companies (representing only 6.5% of total public float) from SOX Section 404(b) auditor attestation requirements, with proposals potentially effective as early as 2027 or 2028 [6b]. The SEC also proposed Regulation Crypto Assets on August 18, 2026, creating the first registration-exempt offering pathway for crypto assets with a startup …
Proxy Advisor Scrutiny and Shareholder Proposal Dynamics Shift Further
The DOJ withdrew the 1987 ISS Business Review Letter during the week of September 4-10, 2026, signaling continued antitrust scrutiny of proxy advisory firms [6f]. According to D.F. King analysis published September 8, 2026, the SEC's withdrawal from the Rule 14a-8 no-action process resulted in approximately 170 exclusion notices in the first half of 2026 compared to approximately 335 no-action requests in the comparable prior period, with proponents responding by launching public campaigns and l…
AI Governance and Cybersecurity Compliance Demands Escalate for Boards
SEC Chairman Atkins addressed the Investor Advisory Committee on September 12, 2026, cautioning that AI should complement rather than substitute for human judgment in disclosures, and that the SEC will not prescribe specific AI models firms must use [6e]. Separately, Latham & Watkins analysis published September 13, 2026 noted that autonomous AI cyberattacks have prompted a federal cybersecurity agency to issue guidance treating autonomous AI agents as a distinct attack vector requiring new cont…
EU Digital Compliance Obligations Expand with CRA and DSA Enforcement
As of September 11, 2026, manufacturers of products with digital elements became subject to new incident reporting obligations under the EU Cyber Resilience Act [7]. The Dutch Data Protection Authority fined Uber €824,990,000 on August 21, 2026 for infringing GDPR rules on solely automated decision-making [7]. Delaware also expanded its state privacy law on September 2, 2026, with Governor Meyer signing House Bill 380 significantly expanding the Delaware Personal Data Privacy Act, effective Janu…
競合動向
Delaware Caremark Standard Continues Narrowing After Boeing Dismissal
The Boeing Caremark dismissal (In re Boeing, August 14, 2026) — analyzed by both Fried Frank (September 6, 2026) and Skadden — continues to generate practitioner commentary this week confirming that the Delaware Court of Chancery reaffirmed that pleading a bad faith claim remains difficult even after headline-grabbing events [13]. The court's holding that regular safety reports may indicate the information system is working, not a red flag, is being interpreted as a return to the historically na…
SEC Guidance Clarifies Schedule 13G Passive Investor Engagement Rights
On September 2, 2026, the SEC issued new Corporation Finance Interpretations clarifying that Schedule 13G filers can engage with issuers and other investors without losing passive status, provided engagement is issuer-initiated, responsive to issuer requests about past voting, or aimed at understanding issuer disclosures [6d]. This guidance supplements earlier February 2025 CFIs that had broadly chilled engagement between passive shareholders and issuers. The new CFIs are expected to ease concer…
SEC Proposes Rescission of Investment Adviser Pay-to-Play Rule
On September 3, 2026, the SEC proposed rescinding Rule 206(4)-5 under the Investment Advisers Act in its entirety, citing the rule's overbroad definitions, low de minimis contribution limits, and what it describes as a 'de facto' strict-liability standard that imposes an automatic two-year compensation ban even for inadvertent small-dollar contributions [6c]. The SEC also raised First Amendment concerns about the rule's chilling effect on employee political contributions. Public comments are due…
CJEU Issues Significant Rulings on Procurement, Sanctions, and Merger Control
On September 8, 2026, Advocate General Biondi opined that exclusion from procurement procedures for national security reasons is compatible with EU law provided EU principles are respected [8]. On September 9, 2026, the General Court upheld the prohibition of Booking Holdings' acquisition of Etraveli Group and dismissed Roman Abramovich's challenge to EU restrictive measures [8]. The General Court also dismissed Hungary's challenge to the EPF Committee's allocation of frozen Russian asset revenu…
ICJ Concludes Nicaragua v. Germany Hearings on Occupied Palestinian Territory Obligations
The International Court of Justice concluded public hearings from September 7-10, 2026 in Nicaragua v. Germany concerning alleged breaches of international obligations in respect of the Occupied Palestinian Territory, with Germany having raised preliminary objections [15]. This case, alongside the ongoing South Africa v. Israel genocide convention proceedings with multiple state interventions, signals that international judicial scrutiny of state conduct in the Palestinian territory is intensify…
制度・規制動向
EU Cyber Resilience Act Reporting Obligations Now in Force
As of September 11, 2026, manufacturers of products with digital elements are subject to new incident reporting obligations under the EU Cyber Resilience Act, marking a key compliance milestone for hardware and software manufacturers operating in the EU market [7]. Privacy World Blog also noted September 11, 2026 as the key starting point for CRA reporting obligations, with Skadden publishing a reporting FAQ and checklist on September 3, 2026 to assist companies in preparing [13]. This represent…
UK Law Commission Publishes Friendly Societies Modernization Recommendations
On September 10, 2026, the UK Law Commission published recommendations that friendly societies should benefit from simpler, modernized rules [2]. This follows the Commission's active reform agenda this year including homicide offences consultation (response deadline September 30, 2026), weddings law reform consultation (July 2026), kinship families rights proposals (July 2026), and commercial leasehold reform consultations (June 2026) [2]. The breadth of simultaneous Law Commission reform activi…
UNCITRAL Completes ISDS Reform Intersessional Meeting
UNCITRAL Working Group III's 10th Intersessional meeting on Investor-State Dispute Settlement reform, jointly organized with the Government of Vietnam, concluded on September 11, 2026 after three days of productive sessions [16]. This follows UNCITRAL's July 2026 adoption of key texts facilitating use of arbitral awards and notices of arbitration in electronic form, and the finalization of significant ISDS reforms at its 59th session [16]. The sustained ISDS reform activity signals that internat…
US Immigration Enforcement Reaches New Milestone with First ATRC Removal
On September 11, 2026, the Department of Justice completed the first-ever case before the United States Alien Terrorist Removal Court, removing Nazira Haji Zada, an Afghan national, after she conceded she is an alien terrorist [9]. USCIS also announced it has reached the H-2B cap for the first half of fiscal year 2027 on September 11, 2026 [9]. The ATRC's first operational use signals that previously dormant national security immigration enforcement mechanisms are now being activated.
SEC Proposes Semiannual Reporting and Broad Regulatory Relief for Public Companies
The SEC proposed sweeping changes to public company reporting that would allow companies to choose semiannual reporting via a new Form 10-S, with proposals potentially effective as early as 2027 or 2028 [6b]. An estimated 81% of public companies would become exempt from SOX Section 404(b) auditor attestation, automatic shelf registration would become available after one year of SEC reporting, and IPO on-ramp accommodations would extend to all newly public companies for at least five years [6b]. …
ソース活動
先週からの変化
EU Cyber Resilience Act Incident Reporting Obligations Take Effect
As of September 11, 2026, manufacturers of products with digital elements are subject to new mandatory incident reporting obligations under the EU Cyber Resilience Act, creating an immediate compliance requirement for hardware and software manufacturers in the EU market [7]. Both Skadden and Privacy World Blog published guidance this week to assist companies in meeting the new obligations [13].
FTC Rescinds 2021 Health App Breach Policy Statement
On September 9, 2026, the FTC rescinded the 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices, which had purported to apply the FTC's Health Breach Notification Rule broadly to health apps [3]. This follows the FTC's August 7, 2026 announcement that it will no longer pursue disparate-impact discrimination claims, continuing a pattern of policy statement withdrawals that narrows the FTC's enforcement theories.
SEC Proposes Regulation Crypto Assets and Semiannual Reporting Overhaul
The SEC proposed Regulation Crypto Assets on August 18, 2026, creating the first registration-exempt offering framework for crypto assets with a startup exemption capped at $5 million and a fundraising exemption of up to $75 million per 12-month period [6a]. Separately, the SEC proposed allowing semiannual reporting via a new Form 10-S and exempting an estimated 81% of public companies from SOX 404(b) attestation requirements [6b]. Both proposals are open for public comment.
First Use of US Alien Terrorist Removal Court Completes Removal
On September 11, 2026, the Department of Justice completed the first-ever case before the United States Alien Terrorist Removal Court, removing an Afghan national after she conceded alien terrorist status [9]. This marks the operational activation of a previously dormant national security immigration enforcement mechanism and signals a new phase of immigration enforcement capability.
Dutch DPA Fines Uber €824,990,000 for Automated Decision-Making Violations
On August 21, 2026, the Dutch Data Protection Authority announced a fine of €824,990,000 against Uber for infringing GDPR rules on solely automated decision-making affecting drivers [7]. This is among the largest GDPR enforcement actions recorded and signals that automated decision-making affecting workers is a priority enforcement area for European data protection authorities.
ウォッチリスト — 今後の締切
EU Empowering Consumers Directive: New Rules on Green Claims Apply From 27 September 2026
ソース: Latham & Watkins LLPUK Law Commission homicide offences consultation response deadline
ソース: Law Commission (UK)China new Measures for Public Security Organs' Supervision and Inspection of Cyberspace Security take effect
ソース: Hunton Privacy BlogFTC 2027 Telemarketer Fees for National Do Not Call Registry take effect (FY2027 begins)
ソース: FTC Press ReleasesDelaware Personal Data Privacy Act expansion (House Bill 380) takes effect
ソース: Hunton Privacy Blog示唆・見るべき論点(10件)
- 1.The SEC's simultaneous proposals on semiannual reporting, crypto asset exemptions, and pay-to-play rule rescission represent a coherent deregulatory philosophy: reduce compliance burdens on smaller issuers and advisers while creating structured pathways for emerging asset classes. Organizations should treat these as a package rather than isolated proposals, as the combined effect would materially reshape the regulatory landscape for approximately 81% of public companies and the entire investment…
- 2.The Dutch DPA's €824,990,000 Uber fine for automated decision-making violations is a landmark enforcement signal: GDPR Article 22 (solely automated decisions) is now a priority enforcement target for European regulators, and organizations using algorithmic systems to make consequential decisions affecting workers or consumers should conduct immediate compliance reviews of their automated decision-making processes.
- 3.The EU Cyber Resilience Act's reporting obligations taking effect on September 11, 2026 creates a new mandatory compliance layer that operates alongside GDPR and NIS2 — manufacturers of digital products must now maintain incident reporting capabilities specifically calibrated to CRA requirements, which differ from existing GDPR breach notification timelines and thresholds.
- 4.The SEC's new Schedule 13G guidance restoring engagement rights for passive investors is a meaningful correction to the February 2025 CFIs that had chilled shareholder-issuer dialogue. Investment managers maintaining 13G status should update their engagement protocols to take advantage of the clarified safe harbors, particularly for proxy contest contexts where the new guidance explicitly permits discussions with dissident investors.
- 5.The first operational use of the Alien Terrorist Removal Court signals that previously dormant national security immigration enforcement mechanisms are now active. Organizations employing foreign nationals in sensitive roles should review their immigration compliance programs against the expanded enforcement environment, including the ATRC's activation and the H-2B cap being reached for FY2027.
- 6.The Boeing Caremark dismissal's continued practitioner commentary this week — from both Fried Frank and Skadden — confirms that the decision is being read as a durable signal, not an outlier. Boards should use this moment to document their oversight processes with specificity: the distinction between 'ongoing risk being managed' and 'red flag requiring board action' is now the operative legal test, and documentation should reflect that distinction explicitly.
- 7.The DOJ's withdrawal of the 1987 ISS Business Review Letter, combined with state attorney general investigations and the D.C. Circuit's ISS v. SEC decision, indicates that proxy advisory firms face a multi-front regulatory and antitrust challenge that is unlikely to resolve quickly. Companies relying on ISS or Glass Lewis recommendations should develop contingency governance strategies that do not depend on proxy advisor stability.
- 8.The SEC's proposed rescission of the pay-to-play rule raises a practical compliance question: if rescinded, investment advisers will need to develop their own policies and procedures to address pay-to-play risks, as the SEC has indicated it may require minimum elements or interpretive guidance. Advisers should begin designing principles-based pay-to-play frameworks now rather than waiting for final rule guidance.
- 9.The UNCITRAL ISDS reform process — now at its 10th intersessional meeting — is producing concrete outputs including electronic arbitral award frameworks and significant ISDS reforms. Organizations with treaty-based investment protections or exposure to investor-state arbitration should monitor the reform outputs closely, as changes to ISDS procedures will affect the practical availability and cost of treaty arbitration.
- 10.The autonomous AI cyberattack guidance from a federal cybersecurity agency — treating AI agents as a distinct attack vector — creates a new board-level governance obligation: cybersecurity disclosures required by SEC rules must now reflect autonomous AI capabilities and companies' defenses against them, meaning boards need to understand and document their AI-specific cybersecurity posture, not just traditional threat models.
信頼度サマリー
今週引用したソース 17 件あなたが選んだ 30 件の監視URLから検出(1つのURLから複数記事が出ることがあります)。
各ソースは信頼度レベルに応じて重み付けされています。単独ソースの主張は AI 合成時に未検証としてフラグ付けされます。
参照ソース一覧
Wolters Kluwer released its 2026 Half-Year Report during the reporting period; the source provided no substantive legal or regulatory content for analysis beyond the corporate announcement.
Source for UK Law Commission news including the September 10, 2026 publication of friendly societies modernization recommendations, the homicide reform consultation (September 30, 2026 deadline), and the government's weddings law reform consultation.
Primary source for FTC enforcement actions including the Humboldt Merchant Services $12 million settlement and permanent ban (September 8), rescission of the 2021 Health App Breach Policy Statement (September 9), Horseracing Integrity and Safety Authority budget comment period (September 10), and the personalized pricing comment period extension (September 3).
Primary source for SEC actions including the joint US-UK readout on central counterparty resolution (September 11), $16 million Ponzi scheme charges (September 10), political contribution rule rescission proposal (September 3), Regulation Crypto Assets proposal (August 18), and the Financial Reporting and Accounting Unit establishment (August 5).
Source for UN news during the reporting period including UN human rights chief Türk's call for AI controls (September 7), Security Council counter-terrorism meeting marking 9/11 anniversary (September 12), UN General Assembly 81st session opening, and Secretary-General Guterres's call for global order reform (September 13).
Primary source for corporate governance analysis including the Boeing Caremark dismissal analysis (September 6), SEC Schedule 13G guidance analysis (September 7), 2026 proxy season investor behavior trends (September 8), SEC pay-to-play rule rescission analysis (September 9), ESG ratings market research (September 9), SEC Regulation Crypto Assets analysis (September 11), individual investor shareholder resolution impact (September 10), private equity pay gaps research (September 10), SEC Chairman Atkins remarks on AI and Regulation NMS (September 12), and Latham & Watkins recent developments for directors (September 13).
Source for privacy and cybersecurity regulatory developments including the EU Cyber Resilience Act reporting obligations taking effect September 11, 2026, the Dutch DPA's €824,990,000 fine against Uber for automated decision-making violations (August 21), Delaware's expansion of its Personal Data Privacy Act (September 2), and the European Commission's DSA designations of ChatGPT, Reddit, and Roblox (August 31).
Source for CJEU rulings including the September 8 Advocate General opinion on national security procurement exclusions (Autovici/Skinest Baltija), Advocate General Spielmann's opinions on Single Resolution Fund contribution calculations, the September 9 General Court ruling upholding prohibition of Booking Holdings' acquisition of Etraveli Group, dismissal of Abramovich's sanctions challenge, and dismissal of Hungary's challenge to frozen Russian asset allocation.
Source for USCIS developments including the H-2B cap being reached for the first half of FY2027 (September 11) and the first-ever use of the United States Alien Terrorist Removal Court to remove an Afghan national (September 11).
Source for legal profession news including the ABA Legal Education council's repeal of its DEI standard (September 8), AI hallucination issues in court filings, the DC appeals court blaming Deutsche Bank lawyers for AI hallucinations, and law firm crisis management team developments.
Source for privacy and cybersecurity developments including the September 7, 2026 analysis of EU Cyber Resilience Act reporting obligations taking effect September 11, and the September 9 launch of an AI Perspectives video series on responsible AI governance.
Source for Latham & Watkins analysis including the EU Empowering Consumers Directive green claims rules applying from September 27, 2026 (September 9), SEC pay-to-play rule rescission proposal (September 11), Eleventh Circuit FCA qui tam constitutional ruling (September 11), and the September 13 recent developments for directors covering SEC semiannual reporting proposals and autonomous AI cybersecurity threats.
Source for Skadden analysis including the Boeing Caremark dismissal, FTC personalized pricing enforcement policy statement, SEC Regulation Crypto Assets analysis, UK stablecoin regulatory framework, EU Cyber Resilience Act reporting FAQs (September 3), and SEC Financial Reporting and Accounting Unit announcement (September 10).
Source for Gibson Dunn analysis including the antiboycott compliance enforcement era analysis covering four 2026 Commerce Department settlements, SEC Division of Corporation Finance withdrawal from the shareholder proposal process, and SEC Regulation Crypto Assets exempt offering framework.
Source for ICJ developments including the conclusion of public hearings in Nicaragua v. Germany (Occupied Palestinian Territory) on September 10, 2026, and Vanuatu's application against France filed September 1, 2026.
Source for UNCITRAL developments including the conclusion of the 10th Intersessional meeting of Working Group III on ISDS reform on September 11, 2026, jointly organized with the Government of Vietnam, and Mauritius's ratification of the Singapore Convention on Mediation (August 18).
Source for HCCH developments including the sixth working meeting of the Experts' Group on Central Bank Digital Currencies held September 1-4, 2026, with over 35 delegates representing 13 HCCH Members and seven Observers.
Legal & Complianceを毎週、自動で監視
このレポートは一次ソースのみから生成されています。テーマとソースを選べば、引用付きレポートが毎週届きます。7日間無料トライアル・$33/月から。
無料トライアルを始める