Authors
Authors
We recently gathered a group of regulatory attorneys from across Reed Smith to provide a rundown of the key trends to watch for in Q3 2026. If you missed the webinar, you can access the recording on demand.
Please see a short summary of our top takeaways below and look out for an invite to the next installment of this quarterly series – we hope you can join us!
AI and whistleblowers: navigating emerging risks and transforming investigations
- Whistleblowers are using AI to draft complaints as well as collect, index, and create “evidence.”
- Although in some instances AI-generated photographs and videos may have markers, watermarks, or metadata tags, it is becoming increasingly difficult to identify AI-generated images as the technology advances.
- Companies can protect themselves against a whistleblower’s use of AI with an effective compliance program. The compliance program should include thirdparty due diligence, real-time monitoring, back-end monitoring, and AI-assisted investigations.
Congressional and political investigations: rising exposure for corporates
- Congressional scrutiny is bipartisan and already focused. With emphasis on areas including data centers and energy infrastructure, China and national security, algorithmic pricing, AI oversight, and health care fraud, exposure doesn’t hinge on which side wins in November.
- Industries in the crosshairs: Technology and AI, energy and utilities, health care and life sciences, government and defense contractors, financial services and digital assets.
- Proactive steps you can take now: Analyze your data, conduct a privileged risk assessment directed by counsel, prepare a response plan, engage key stakeholders, and monitor the political landscape.
Enforcement escalation: trade, sanctions, and export controls in Q3 2026
- Trade enforcement is a priority and liability may extend beyond the importer of record. Companies should recognize that wholesalers, retailers, and resellers now face the same criminal exposure as importers, and should conduct supply chain audits and implement documented due diligence accordingly. Compliance programs should be resourced to match this permanently elevated enforcement environment.
- Sanctions and export control compliance programs need to expand beyond traditional high-risk jurisdictions and sectors. Companies should assess their screening protocols to ensure they address new designation activity targeting non-traditional geographies and sectors, and any company with activities touching comprehensively sanctioned jurisdictions – including humanitarian trade – should reassess its licensing posture in light of newly restrictive licensing policies. On export controls, companies should adopt a dual-track compliance approach that monitors both the tightening of restrictions and the easing of controls on allies and certain commercial technologies, to avoid violations while capturing market opportunities.
- CFIUS is proactively identifying and pursuing non-notified transactions, and parties can no longer avoid review by simply not filing. Companies should assess CFIUS risk before closing any transaction involving foreign investment, as the government is now proactively identifying non-notified deals and has expanded its enforcement toolkit to pursue parties who do not voluntarily file.
A new era at the UK’s SFO? What businesses can learn from recent enforcement activity
- Don’t underestimate the SFO. It still faces challenges, but it is seeking to become faster, more intelligence-led, and more interventionist.
- Prevention matters more than ever. The combination of the failure to prevent fraud offense, expanded corporate attribution, and greater scrutiny of compliance programs has materially changed corporate criminal risk.
- Plan now for what you will do when something goes wrong. The decisions made immediately after suspected misconduct emerges – about preservation, investigation, self-reporting, cooperation, and remediation – may have a significant bearing on the eventual enforcement outcome.
HHS OIG launches information blocking investigations
- Since September 2025, the HHS secretary has directed enforcement resources toward information blocking, and the OIG has begun issuing subpoenas to regulated actors. Complaints in the ONC portal have surged from roughly 1,600 in early 2026 to approximately 2,500 by July 2026. Despite this ramp-up, there have been no public enforcement actions to date – meaning regulated entities still have a window to assess their compliance posture before precedent-setting penalties materialize.
- Entities that receive an OIG subpoena should not treat it as a fait accompli. The OIG evaluates the totality of circumstances, and early-stage enforcement appears to be oriented toward constructive dialogue rather than immediate sanctions. Importantly, failing to satisfy one of the 10 regulatory exceptions under 45 C.F.R. Part 171 does not automatically constitute information blocking, and permissible activities may exist outside those exceptions.
- Know your intent standard. The information blocking rule draws an important distinction between providers, who must know that a practice is unreasonable and likely to interfere with access, exchange, or use of EHI, and ONC-certified developers and HIEs/HINs, who face the broader “know or should know” standard. With civil monetary penalties reaching up to $1 million per violation for developers and HIEs/HINs, as well as Medicare payment disincentives for providers, organizations should confirm their data-sharing practices, fee structures, and health IT configurations now to demonstrate good-faith compliance.
Diverging antitrust and competition priorities: recent developments and key takeaways from the US, UK, and EU
US
- AI-driven collusion, merger review, cross-border cartel enforcement, and whistleblower incentives are all squarely on the DOJ’s radar. The DOJ’s Antitrust Division is actively developing enforcement frameworks to address price-fixing and market allocation facilitated through algorithmic pricing tools and AI, creating new compliance risks for companies that rely on automated pricing software. At the same time, deal teams should expect rigorous review of competitive effects – particularly in health care and technology – while the DOJ’s growing emphasis on international cartel prosecution and enhanced whistleblower programs increases exposure for multinational companies, underscoring the need for robust global antitrust compliance programs.
- The FTC is taking more aggressive approaches when it comes to HSR compliance and director interlock (Section 8). Two transaction parties paid a total of $12 million to settle allegations that they structured their deal around the HSR filing threshold by using the acquisition of non-voting shares as a form of consideration. In a settlement resolving Section 8 issues, the FTC prohibited the use of any independent director who had certain connections to the buyer in the past three years, going beyond what the federal law requires. Both settlements are examples of how antitrust risk can arise even when an HSR-reportable transaction is not expected to have a meaningful competitive impact.
- Antitrust agencies committed to improving second request process. DOJ announced that it would resume a targeted approach to second request compliance, giving transaction parties the option to prioritize production of materials focused on dispositive issues. While not publicized as a new policy, the FTC indicated that it has been using similar “phased” second requests to narrow production requirements and resolve investigations quickly. Both agencies’ statements indicate that transaction parties may be able to limit the time and expense needed to navigate a second request relative to the previous administration, assuming internal documents can address agency concerns.
UK
- Faster, more flexible merger control. The Competition and Markets Authority’s (CMA) "4Ps" (pace, predictability, proportionality, process) bring shorter targets (pre-notification in 40 working days, straightforward Phase 1 in 25), clearer jurisdictional guidance, and more openness to behavioural remedies, including at Phase 1. Reforms are aligned with the government's growth agenda, but complex deals can still face extensive scrutiny.
- Data and AI-driven enforcement against bid rigging. Public procurement sits at the centre of the CMA's growth agenda, with tools like the Bid Rigging Intelligence Tool and AI-based detection used to gather evidence. Algorithmic collusion and AI-enabled harms are an explicit focus, and roofing and construction bid-rigging inquiries have been expanded.
- Consumer enforcement is powerful and increasingly used. Under the Digital Markets, Competition and Consumers Act, the CMA can fine up to 10% of global turnover and order compensation. It favours "few hard cases, many soft nudges" (of 400 businesses reviewed, 100 got advisory letters, 8 were investigated, 3 fined – to date – we expect more). 2026 priorities are fake reviews and drip pricing, with the subscription contract regime and possible exit-charge enforcement following in January 2027.
EU
- Competition enforcement is expanding beyond traditional antitrust. While traditional cartels remain a priority, the European Commission is increasingly targeting new forms of market coordination, including labor market restrictions, information exchange, and strategic control over key assets. Companies should ensure that competition compliance extends beyond sales and procurement functions.
- Market power is increasingly assessed through data, technology, and ecosystems. Market abuse enforcement and digital regulation are placing greater emphasis on platforms, access to data, interoperability, and self-preferencing. Businesses should evaluate whether their sources of competitive advantage create regulatory exposure.
- Transactions require a broader regulatory assessment from the outset. M&A planning must increasingly consider not only merger control, but also foreign investment screening, the Foreign Subsidies Regulation, and digital/technology-related issues. Early regulatory mapping is becoming critical for deal certainty.
- Competition compliance is becoming a board-level governance issue. With more proactive investigations, digital evidence gathering, and cross-border enforcement, companies need robust compliance frameworks, clear internal processes, and investigation readiness.
The SEC’s shifting priorities: recent developments and key takeaways
- Accounting fraud now has a dedicated unit. The SEC’s new Financial Reporting and Accounting Unit is staffed with accountants, not just lawyers, and covers public company accounting and auditor conduct.
- Expect proactive case generation. The SEC’s enforcement director, David Woodcock, is targeting intentional accounting misconduct that causes investor harm – and these matters can quickly expand to include executives, auditors, and the audit committee.
- Rulemaking is reshaping reporting, proxy, and crypto. If approved, an optional semiannual Form 10-S would replace the 10-Qs, the proxy package would rescind Rule 14a-8, and Regulation Crypto Assets would add new fundraising exemptions.
Health care and life sciences enforcement trends
- What’s old is new again – we’ve seen many of the theories and priorities before.
- Data mining for fraud is a powerful new weapon for the government.
- No one is immune to collateral damage from broad-stroke fraud-fighting efforts.
Authors