arrow-double-right arrow-noline-right arrow-lrg-left arrow-lrg-right arrow-med-down arrow-med-left arrow-med-right arrow-med-up arrow-sml-right checkmark close close-sml contact-card event-clock linkedin menu minus outbound-link phone plus print search-lrg search-sml twitter Winthrop-mark

Federal Banking Agencies Propose Overhaul of Third-Party Risk Management Guidance, Issue Community Bank Guide, and Heighten Focus on Core Service Providers

On September 11, 2026, the federal banking agencies issued three significant actions that would collectively reshape the regulatory landscape for third-party risk management:

  • First, the FDIC (Federal Deposit Insurance Corporation), Federal Reserve Board, NCUA (National Credit Union Administration), and OCC (Office of the Comptroller of the Currency) jointly proposed new guidance to replace the agencies’ 2023 third-party risk management framework, emphasizing risk-based, tailored oversight rather than uniform vendor-management requirements.
  • Second, the Federal Reserve Board proposed a companion guide for Federal Reserve-supervised community banks with less than $30 billion in assets, providing practical, non-binding examples for implementing third-party risk management principles. Comments on the proposals are due on or before November 16, 2026.
  • Third, the FDIC, OCC, and Federal Reserve issued a joint statement signaling increased supervisory attention to large core service providers, highlighting concerns regarding transparency, restrictive contract practices, and the potential classification of certain providers as institution-affiliated parties subject to direct enforcement authority.

Proposed Third-Party Risk Management Guidance

The proposed third-party risk management guidance would replace the agencies’ 2023 third-party risk management framework with one centered on risk-based, tailored oversight rather than uniform vendor-management requirements.

Key Changes from the 2023 Guidance

The agencies state that the 2023 guidance has been interpreted too broadly, leading institutions to apply extensive controls regardless of actual risk. The proposal reorients third-party risk management around three themes: (1) tailoring oversight to each relationship based on the institution’s size, complexity, and risk profile, and on the nature and magnitude of potential harm; (2) shifting away from checklist approaches to focus resources where material financial and compliance risks actually exist; and (3) de-emphasizing “critical activities” as a basis for heightened oversight in favor of assessing the specific risks of each relationship and the likelihood and severity of harm.

New Risk Assessment Framework

The guidance proposes that banking organizations consider the following four components when managing third-party risk: (1) identifying and assessing applicable risks; (2) overseeing risks proportionate to their significance; (3) making informed decisions about residual risks and risk acceptance; and (4) establishing appropriate governance practices.

Because not all third-party relationships present the same level of risk, the guidance notes that risk assessments should account for both the magnitude of harm the third-party relationship could cause the banking organization or its customers and the likelihood that the harm will occur. Higher-risk relationships warrant more intensive oversight where there is a material likelihood that such legal or regulatory violation, financial harm, or operational disruption may occur under current or reasonably foreseeable conditions. Lower-risk relationships (e.g., administrative, clerical, consulting, legal, audit, and office support services) may warrant significantly lighter oversight and less extensive documentation.

Greater Flexibility in Due Diligence and Monitoring

Further, institutions need not maintain the same level of inventory and documentation for every third party; large institutions may need detailed inventories, while community banks may use simpler tracking. The guidance notes that due diligence should focus on identifying the most relevant and material risks rather than every conceivable risk.  Monitoring should be proportional to risk, with high-risk relationships warranting more frequent reviews and low-risk relationships requiring less intensive oversight. On-site reviews, audits, and similar tools may not always be practical or necessary.

Contracting and Residual Risk

The agencies also acknowledge the reality that many vendors provide standard contracts, banks may lack negotiating leverage, and some desired protections may be unavailable. Regardless, an institution may still proceed with a relationship when it reasonably understands the risks and determines that residual risk falls within its risk appetite. This is a significant shift from interpretations of the 2023 guidance that led institutions to seek extensive contractual protections regardless of vendor criticality.

Affiliates, Regulated Third Parties, and Fintech

Relationships conducted within an enterprise-wide risk management framework or involving heavily regulated providers may present lower risk, although a provider’s regulated status does not automatically mitigate all risks. The agencies also acknowledge that prior guidance may have discouraged partnerships with newer or innovative firms and seek to avoid unnecessarily impeding bank-fintech relationships through a more flexible, risk-based approach. In practice, banks evaluating fintech partnerships should focus due diligence and oversight on the specific risks presented by the relationship, including data security, regulatory compliance, and operational resilience, rather than applying heightened oversight solely because a provider is newer or non-traditional. At the same time, banks remain responsible for complying with applicable laws and regulations, conducting appropriate risk assessments, and ensuring relationships are consistent with safe and sound banking practices.

Non-Binding Nature of the Guidance

The guidance does not create enforceable requirements, and a failure to follow a particular example is not, in itself, grounds for supervisory criticism. Supervisory action would still be based on legal violations, unsafe or unsound practices, or material risk-management deficiencies. See our prior client alert on supervisory actions here.

Key Takeaway for Legal, Compliance, and Vendor-Management Teams

The proposal represents a significant recalibration of third-party risk management expectations, encouraging institutions to ask whether they have reasonably identified material risks, assessed their significance, and applied proportionate oversight rather than check-the-box exercises. If finalized, the guidance could reduce the burden for lower-risk relationships, focus oversight on genuinely high-risk providers, increase flexibility in due diligence and contracting, encourage bank-fintech partnerships, and support reliance on documented risk-based judgments.

Proposed Third-Party Risk Management Guide for Community Banks

The Federal Reserve Board is also seeking comment on a proposed third-party risk management guide for Federal Reserve-supervised community banks with less than $30 billion in assets.

The guide is a practical, non-binding companion to the broader interagency guidance, translating high-level principles into day-to-day practices for traditional community banking organizations with relatively straightforward business models. It does not create new requirements or supervisory standards. Drawing on supervisory observations, examination materials, and industry practices, the guide focuses on the types of vendors most commonly used by community banks and emphasizes that risk management should be proportionate to each bank’s size, complexity, and risk profile. The Board seeks comment on whether the document strikes the right balance between being helpful and avoiding the creation of de facto examination expectations.

Joint Statement on Community Banks’ Engagement with Core Service Providers

Separately, the FDIC, OCC, and Federal Reserve issued a statement addressing concerns about community banks’ relationships with large core service providers that dominate critical banking infrastructure (such as core processing, payment processing, online banking, customer relationship management, and compliance systems). The agencies recognize that community banks often have limited alternatives and little negotiating power. The statement also acknowledges that core providers unreasonably limit a bank’s ability to conduct initial due diligence and ongoing monitoring or negotiate favorable contract terms that address the bank’s needs to identify, assess, and address risk.

Key regulatory signals include: (1) examiners will account for community banks’ limited leverage when evaluating third-party risk management; (2) the agencies will increase supervisory attention to core providers that limit transparency, such as those failing to provide timely due diligence information or adequate disclosure of outages and cybersecurity incidents; (3) problematic contract provisions—including opaque pricing, excessive deconversion fees, and restrictions on integration with other providers—will influence how supervisory resources are allocated; (4) providers that underinvest in technology and operational resilience can expect greater scrutiny; and (5) certain core providers may be deemed “institution-affiliated parties” under the Federal Deposit Insurance Act (FDIA) because they participate in the conduct of a bank’s affairs, potentially subjecting them to direct enforcement actions.

The agencies’ discussion of enforcement authority may be the most significant legal development in these issuances. If regulators determine that a core provider qualifies as an “institution-affiliated party” under the FDIA, the agencies may have authority to pursue supervisory or enforcement actions directly against the provider, rather than solely against the bank. Banks and core providers should carefully assess whether their relationships could support such a determination.

Additionally, this statement may impact banks’ abilities to conduct due diligence and obtain information related to their core providers as well as assist in negotiation of often extremely one -side master agreements.  It remains to be seen how involved a role the regulatory agencies will take in these long-standing practices, but such a shift could result in substantial transparency and a focus on creating more mutually beneficial partnerships between banks and their core providers.

Despite this increased focus on core providers, the agencies reiterate that outsourcing does not transfer responsibility, and community banks retain accountability for safe and sound operations and legal compliance. For legal, vendor-management, and compliance teams, the most consequential aspects are the focus on vendor transparency, deconversion fees, restrictive contract provisions, interoperability limitations, and the possibility that major core providers may face direct enforcement authority as institution-affiliated parties.

Conclusion and Key Takeaways for Banks

Taken together, the agencies’ September 11, 2026, actions signal a meaningful shift toward risk-based, institution-specific third-party risk management. The proposed interagency guidance emphasizes tailored oversight, while the community bank guide provides practical implementation examples, and the core provider statement addresses longstanding concerns regarding vendor market power and contract practices.

Although the community bank guide is directed to institutions with less than $30 billion in assets, its practical approaches may be useful to larger institutions as well. Banks should consider:

  • Reassess existing vendor-management programs. Boards and senior management should evaluate whether existing third-party risk management frameworks are calibrated to actual risk rather than relying on uniform controls across all vendor relationships. Compliance officers should lead a gap analysis comparing existing programs against the proposed risk-based framework.
  • Right-size due diligence and monitoring. Vendor-management teams have an opportunity to reduce the compliance burden for lower-risk relationships while concentrating oversight resources on genuinely high-risk providers. Documentation and monitoring intensity should be proportionate to the risks each relationship presents. Risk and compliance functions should work together to develop tiered oversight protocols.
  • Document risk-based judgments. As the agencies shift from procedural compliance to substantive risk assessment, institutions should ensure that their risk-based decisions are well-documented and supported by a clear rationale. Legal teams should develop or update templates and approval processes to capture these risk-acceptance decisions in a manner that will withstand examination scrutiny.
  • Review core provider contracts. The joint statement’s focus on opaque pricing, excessive deconversion fees, and interoperability restrictions puts core provider contracts under a regulatory spotlight. Legal and vendor-management teams should review existing agreements for provisions that may attract supervisory attention—particularly pricing transparency, exit and deconversion terms, and restrictions on integration with third-party technology providers—and factor these issues into future contract negotiations and renewals.
  • Leverage new resources. The Federal Reserve’s proposed community bank guide, once finalized, is intended to provide practical tools and examples tailored to smaller institutions. Community banks should monitor the rulemaking process and prepare to incorporate the guide into their vendor-management programs.
  • Submit comments. Banks, trade associations, and other stakeholders should consider submitting comments, particularly on whether the proposals strike the right balance between flexibility and supervisory expectations. Legal and government-affairs teams should coordinate internally to identify priorities for comment.

Looking Ahead

Comments on the proposed interagency guidance and community bank guide are due 60 days after publication in the Federal Register. Following the comment period, the agencies may issue final guidance reflecting stakeholder feedback. In the meantime, banks should expect increasing supervisory focus on risk-based tailoring and proportional oversight and consider whether their current third-party risk management programs align with these emerging expectations.

Our Bank Regulatory team is available to assist institutions in assessing and enhancing their third-party risk management programs to align with the agencies’ proposed framework and evolving supervisory expectations.

Client Alert: Regulators Raise the Bar — New Rules Redefine “Unsafe or Unsound Practices” and MRA Standards for Banks

On September 1, 2026, the Federal Deposit Insurance Corporation (FDIC) and Office of the Comptroller of the Currency (OCC) jointly issued a final rule related to supervisory actions that continues their effort to focus examiners’ and banks’ attention on material financial risks and compliance with banking and banking-related laws and regulations. The final rule becomes effective November 2, 2026.

The final rule is part of a broader effort by the regulators to increase transparency and accountability in the supervisory process. For several years, banks and trade groups have raised concerns regarding inconsistent examination findings, the expanding use of Matters Requiring Attention (MRA) as part of the exam process, and supervisory expectations that were not always tied to material financial risk or clear legal violations. The new rule responds to those concerns by establishing uniform standards governing supervisory criticism.

Key Takeaway

Under the newly issued Rule, the FDIC and OCC have adopted binding standards that limit when examiners may characterize conduct as an unsafe or unsound practice and when they may issue an MRA as part of an exam. The rule is intended to focus supervisory criticism on material financial risk and actual legal violations, potentially reducing supervisory burden associated with technical or low-risk findings. Banks should evaluate how these changes affect examination management, escalation procedures, and board reporting practices.

Uniform Definition of “Unsafe or Unsound Practice”

The final rule establishes the following uniform definition for the term “unsafe or unsound practice” under 12 CFR § 4.92(b) and 12 CFR § 305.1(b):

“a practice, act, or failure to act, alone or together with one or more other practices, acts, or failures to act, that:

(1) (i) Is contrary to generally accepted standards of prudent operation; and

(ii) (A) If continued, is likely to—

(1) Materially harm the financial condition of the institution; or

(2) Present a material risk of loss to the Deposit Insurance Fund; or

(B) Materially harmed the financial condition of the institution; or

(2) Is an actual violation of a banking or banking-related law or regulation.”

This uniform definition is expected to promote greater clarity and certainty regarding enforcement and supervision standards and ensure that examiners prioritize concerns related to material financial risks.

Uniform Standards for Matters Requiring Attention

The final rule also establishes uniform standards for when and how the agencies may, as part of the examination process, issue MRAs and communicate supervisory observations and other violations of laws and regulations under 12 CFR § 4.92(c) and 12 CFR § 305.1(c):

“The [agency] may only issue a matter requiring attention to an institution for a practice, act, or failure to act, alone or together with one or more other practices, acts, or failures to act, that:

(1)   (i) Is contrary to generally accepted standards of prudent operation; and

       (ii) (A) If continued, could reasonably be expected to, under current or reasonably foreseeable conditions:

(1) Materially harm the financial condition of the institution [, which refers to financial losses or other negative impacts to an institution’s capital, asset quality, earnings, liquidity, or sensitivity to market risk]; or

(2) Present a material risk of loss to the Deposit Insurance Fund; or

(B) Materially harmed the financial condition of the institution; or

(2) Is an actual violation of a banking or banking-related law or regulation.”

Importantly, the agencies clarify that they will tailor their use of the unsafe or unsound practices definition and the MRA standard based on the risks associated with the bank’s capital structure, complexity of the bank, bank activities, asset size of the bank, and any other financial risk-related factor deemed appropriate. The final rule further clarifies that supervisory observations concerning weaknesses in a bank’s policies, practices, condition, or operations do not trigger board-reporting or corrective-action requirements. However, the agencies may require remediation of an actual violation of a banking or banking-related law or regulation.

OCC Proposed Rulemaking on Violations

Separately, on September 1, 2026, the OCC issued a notice of proposed rulemaking to revise the supervisory framework for the issuance of MRAs in response to violations of laws or regulations and for addressing violations for which the OCC does not take an enforcement action or issue an MRA. The proposed rule would amend 12 C.F.R. Part 4 to add new sections 4.92(d), (i), and (j) to: (1) clearly define substantive violations of law or regulation; (2) clarify how the OCC will treat technical violations; and (3) clarify that noncompliance with appendices in 12 CFR Part 30 is not a substantive violation. Comments are due on or before October 1, 2026.

The OCC’s proposal may prove equally significant as the final rule. By distinguishing substantive violations from technical violations, the OCC appears to be signaling that supervisory resources should be focused on violations that create meaningful risk or consumer harm rather than isolated procedural deficiencies. Banks should pay close attention to the proposal’s treatment of technical violations because it could materially affect examination findings and remediation obligations.

Practical Implications for Banks

These regulatory changes represent a meaningful shift toward a more risk-focused and proportionate supervisory approach. For banks, this means:

  • Greater Predictability in Examinations: The uniform definitions provide clearer standards for when examiners may cite unsafe or unsound practices or issue MRAs. Banks should experience more consistent and predictable examination outcomes, with enforcement actions focused on practices that pose genuine material risks rather than technical or immaterial concerns.
  • Reduced Burden from Low-Risk Findings: The distinction between formal MRAs and supervisory observations means that not every identified weakness will require board-level attention or formal corrective action plans. This should reduce the compliance burden associated with addressing minor or immaterial issues.
  • Tailored Supervision: The agencies’ commitment to tailoring the application of these standards based on a bank’s capital structure, complexity, activities, and asset size suggests that smaller community banks may benefit from a more proportionate supervisory approach.

How Banks Should Respond

Banks should take the following actions:

  • Review outstanding MRAs and determine whether they would satisfy the new regulatory standard and if not, be ready to reach out to the supervisory agencies about getting them resolved.
  • Reassess current MRA and supervisory finding response processes and board reporting protocols to distinguish between MRAs and supervisory observations.
  • Evaluate examination and issue management procedures.
  • Train management and compliance personnel on the revised standards before the November 2, 2026, effective date.
  • For OCC supervised banks, consider submitting comments on the OCC proposal by October 1, 2026, particularly if the proposal could affect your bank’s compliance framework.

Supervisory Outlook

The final rule is one of the most significant recent attempts to constrain supervisory discretion by tying formal supervisory criticism to material financial risk and actual legal violations. If implemented as intended, banks may see greater consistency, transparency, and predictability in the examination process while preserving regulators’ ability to address significant safety and soundness concerns.

Although the final rule establishes clearer standards, banks should not expect a reduction in supervisory scrutiny of material risk-management weaknesses. The agencies expressly retain discretion to apply the standards based on institution-specific factors, including complexity, capital structure, activities, and risk profile. As a result, similarly situated findings may still be treated differently depending on the bank’s unique circumstances.

If you have questions about these regulatory developments or how they may impact your bank, please contact your Winthrop & Weinstine attorney.

OCC and FDIC Propose Major CRA Rule Overhaul: What Banks Need to Know

On August 12, 2026, the Office of the Comptroller of the Currency (OCC) and Federal Deposit Insurance Corporation (FDIC) jointly proposed amendments to their Community Reinvestment Act (CRA) regulations codified at 12 CFR Parts 5, 24, 25, 35, 345, and 346. The proposal makes targeted changes to the existing 1995 CRA framework while maintaining continuity with the current regulatory structure.

10 Key Takeaways

The key takeaways from the proposed rules and identifies considerations for affected banks are summarized below:

  1. Increased Asset-Size Thresholds – Raises the small bank threshold to $1 billion and large bank threshold to $10 billion, with annual inflation adjustments, reducing regulatory burden for many institutions.
  2. Major Product Line Approach – Introduces a framework for evaluating retail lending in two of four product lines (home mortgage, small business, small farm, and consumer), with consumer lending qualifying only if it constitutes a majority of retail lending.
  3. Modified Rating Framework – Allows intermediate banks to achieve a satisfactory overall rating, even with weaker community development performance, if lending test performance is strong.
  4. Clarified CD Definitions – Provides clearer criteria for community development categories, expands economic development eligibility, and creates a separate definition for CD grants with a 15% indirect cost cap.
  5. Illustrative CD Activities List – Codifies a publicly available, agency-maintained list of qualifying and non-qualifying CD activities to promote transparency and consistency.
  6. CD Activity Confirmation Process – Establishes an optional 90-day agency review process for banks to confirm whether novel activities qualify for CRA consideration.
  7. Geographic Flexibility – Allows CD activities outside assessment areas if banks meet Tier 1 capital thresholds (0.625% for large banks; 1.25% for intermediate, wholesale, and limited purpose banks).
  8. Grandfathering Provision – Protects CRA consideration for CD activities that were eligible when conducted, even if eligibility criteria later change, preserving banks’ reliance interests.
  9. Enhanced Strategic Plans – Modifies strategic plan provisions to provide more meaningful preliminary guidance and substantive feedback, making this evaluation option more attractive.
  10. Significant Burden Reduction – Expected to reduce compliance burden by approximately 86% for FDIC-supervised intermediate banks, with net cost savings for small banks.

How We Got Here

In 2019, the agencies issued a joint notice of proposed rulemaking to update their CRA rules, and in 2020, finalized those rules (the “2020 CRA rules”). In 2021, the OCC rescinded the 2020 CRA rules and replaced them with rules based largely on the 1995 CRA framework. In 2022, the OCC, FDIC, and the Federal Reserve Board issued a joint notice of proposed rulemaking to modernize their CRA rules, which were finalized in 2023 (the “2023 CRA rules”).

The 2023 CRA rules were challenged in federal court, and the agencies were enjoined from enforcing them after the court concluded that plaintiffs had demonstrated a substantial likelihood of success on the merits of their claim that the agencies exceeded their statutory authority. To resolve the pending litigation, in 2025 the agencies proposed rescinding the 2023 CRA rules. The OCC and FDIC are now moving the District Court for entry of a final judgment against them. If entered as proposed, the judgment would declare that future CRA amendments may not be based on (1) an expansive view of “entire community” that assesses retail lending activities outside geographic areas where institutions maintain deposit-taking facilities, or (2) an expansive view of “credit needs” that assesses deposit products.

Against this backdrop, the OCC and FDIC are moving forward with a new rulemaking to refocus supervision on the statutory mandate—encouraging banks to meet the credit needs of their local communities—by increasing emphasis on lending and ensuring that community development activities benefit those communities.

How These Changes Impact Banks

1. Increased Asset-Size Thresholds with Annual Inflation Adjustments

The proposal raises the asset-size thresholds for determining bank classification with increased regulatory burdens when a bank moves from one size category to a larger one.

  • “Small bank” would be defined as a bank with assets of less than $1 billion (up from approximately $600 million currently).
  • “Intermediate bank” would be defined as a bank with assets of at least $1 billion but less than $10 billion (replacing the current “intermediate small bank” category).
  • “Large bank” would be defined as a bank with assets of $10 billion or more.

The thresholds would be adjusted annually based on the year-to-year change in the Consumer Price Index for Urban Wage Earners and Clerical Workers (CPI-W), not seasonally adjusted, for each twelve-month period ending in November, rounded to the nearest million. This change would reclassify many current intermediate small banks as small banks, reducing their regulatory burden through fewer data collection, maintenance, and reporting requirements and removing the community development test. Alternatively, the agencies are considering aligning the small bank threshold with the SBA standard of $850 million, which would include approximately 4% fewer banks.

Why This Matters: Many banks currently approaching regulatory size thresholds may benefit from additional runway before becoming subject to more intensive CRA requirements. The annual inflation adjustment should also reduce the likelihood that banks are pushed into higher regulatory categories solely due to balance sheet growth caused by inflation, allowing management to focus resources on business strategy rather than compliance recalibration. Banks near the current $600 million threshold should model their projected asset growth against the new thresholds to determine whether reclassification timing will change and plan accordingly.

2. Major Product Line Approach

The agencies propose a major product line approach for all banks with two alternatives. Option 1 uses a quantitative, bank-level approach to evaluate retail lending in two of four product lines (home mortgage, small business, small farm, and consumer lending), which become the bank’s major product lines. Option 2 uses an assessment area-level approach that is both qualitative and quantitative, similar to the current methodology for small banks. Under either approach, consumer lending qualifies as a major product line only if it constitutes a majority of retail lending by both dollar amount and loan count, or at the bank’s option.

Why This Matters: The proposed approach could substantially affect how lending performance is evaluated and where banks focus compliance resources. Institutions should assess whether their primary lending activities align with the proposed major product line framework and consider how changes in product mix could influence examination outcomes over time. Banks with significant consumer lending portfolios should pay particular attention to the majority threshold requirement. For example, if consumer lending does not constitute a majority of retail lending by both dollar amount and loan count, it may not qualify as a major product line unless the bank affirmatively elects to include it.

3. Modified Rating Framework for Intermediate Banks

Under the current framework, an intermediate small bank must receive at least a “satisfactory” rating on both the small bank lending test and the community development (CD) test to receive an overall rating of “satisfactory.” The proposal would remove this limitation, allowing stronger performance on the lending test to compensate for weaker performance on the CD test. This change reflects the agencies’ broader objective of refocusing CRA performance evaluation on lending while continuing to recognize CD performance as a component of the overall evaluation.

Why This Matters: This change provides greater flexibility for intermediate banks by reducing the risk that a weaker community development performance score will independently prevent a satisfactory overall rating. Banks that may have historically struggled to identify sufficient qualifying CD activities in their assessment areas may find relief under this framework. However, institutions should not interpret this change as an invitation to abandon CD efforts entirely, as the agencies have signaled that CD performance remains a meaningful component of overall CRA evaluation.

4. Clarified Community Development Definitions

The proposal maintains the four broad categories of community development—(1) affordable housing, (2) community services, (3) economic development, and (4) revitalization and stabilization—but provides clearer and more objective criteria for each category. The proposed definition would codify several aspects of existing agency guidance in the Interagency Questions and Answers while also providing targeted expansions. For example, the economic development category would no longer require an activity to create, improve, or retain jobs for low- and moderate-income (LMI) individuals, and the revitalization and stabilization category would add Indian country and other Tribal and native lands as qualifying targeted geographic areas.

The proposal creates a separate definition for “community development grant,” removing grants from the scope of “CD investment.” The agencies note that grants and donations to non-profit entities may be susceptible to rent extraction, in which entities divert funds away from local communities, including LMI individuals, small businesses, and small farms. The new definition is designed to improve targeting and accountability and ensure that CRA-motivated grant funding is more closely tied to identifiable CD plans, projects, or initiatives. Additionally, indirect costs for administering the grant or donation cannot exceed 15%.

Why This Matters: Clearer and more objective eligibility standards should provide banks with greater certainty when structuring community development activities and investments. The expanded economic development and revitalization categories may create new opportunities for CRA credit, while the separate treatment of grants may require institutions to revisit grantmaking programs and documentation practices. Banks should review existing grant relationships to ensure compliance with the 15% indirect cost cap and evaluate whether current grant recipients can demonstrate the required connection to identifiable CD plans, projects, or initiatives.

5. Publicly Available Illustrative List of CD Activities

The proposal would codify the existence of a publicly available, non-exhaustive, illustrative list of examples of CD activities that qualify for consideration under the applicable CD test. Each agency would maintain its own list on its website and periodically update it. The illustrative list may include examples of activities that the agencies have determined are not CD activities. This “living list” is intended to promote transparency and consistency, provide banks with greater certainty, and help clarify the application of the CD definition.

Why This Matters: A publicly available list could significantly reduce ambiguity surrounding qualifying activities and facilitate more consistent examination outcomes. Banks may be able to develop community development pipelines with greater confidence, particularly when evaluating innovative or less traditional activities. The inclusion of activities that do not qualify may be equally valuable because institutions can avoid investing time and resources in initiatives that will not receive CRA consideration.

6. CD Activity Confirmation Process

The proposal establishes an optional confirmation process through which a bank may request agency review to confirm whether a loan, investment, grant, or service qualifies as a CD activity in a CRA examination. The agency would communicate a response within 90 days after receiving the request, unless additional time is needed. This process is intended primarily for novel potential CD activities that implicate significant legal or policy questions and would provide banks with greater certainty regarding whether specific activities would qualify.

Why This Matters: The confirmation process offers a valuable mechanism for reducing regulatory uncertainty before committing capital or resources to novel community development initiatives. Banks considering innovative products, partnerships, or investments may view this process as a way to obtain greater predictability regarding CRA treatment and examination credit. The 90-day response window provides a reasonable timeline for planning purposes, though banks should build additional buffer time into project schedules given the potential for agency extensions on complex requests.

7. Geographic Flexibility for CD Activities Outside Assessment Areas

The proposal would allow agencies to consider a bank’s CD activities that benefit areas outside of the bank’s assessment area(s), provided the bank meets applicable geographic flexibility standards. For large banks, the proposal would establish geographic flexibility standards of 0.625% of Tier 1 capital for CD loans and the same percentage for CD investments and grants collectively. For intermediate banks, wholesale banks, and limited purpose banks, the standard would be 1.25% of Tier 1 capital. This flexibility is intended to help address “CRA hotspots” (areas with significant competition for CRA activities) and “CRA deserts” (areas where banks engage in limited CRA activities).

Why This Matters: Institutions operating in highly competitive markets may gain additional flexibility to pursue impactful community development opportunities in areas with greater need. This change could help banks diversify CRA activities, improve deployment of community development capital, and alleviate pressure created by competition for a limited number of qualifying projects in traditional assessment areas. Banks in CRA hotspots should evaluate whether the Tier 1 capital thresholds (0.625% for large banks; 1.25% for intermediate, wholesale, and limited purpose banks) align with their current CD activity levels and consider whether geographic expansion would improve both CRA outcomes and community impact.

8. Grandfathering of Previously Eligible CD Activities

The proposal addresses consideration for any CD activity that was eligible for CRA consideration at the time the bank conducted it. If the agency later determines that an activity is not eligible, the bank will continue to receive consideration for the activity if (1) it was eligible at the time the bank conducted it and is being considered in the evaluation period in which it was conducted, or (2) it is a loan or investment that remains on the bank’s balance sheet. This provision recognizes banks’ reliance interests and codifies existing agency practice.

Why This Matters: This provision provides important protection for banks that reasonably relied on existing CRA guidance when undertaking community development activities. By preserving CRA consideration for previously qualifying loans and investments, the proposal reduces the risk that future interpretive changes could undermine the expected regulatory benefit of long-term commitments. Banks with multi-year CD investments or loans originated under prior guidance should document the eligibility criteria that applied at the time of origination to support continued CRA consideration if questions arise during future examinations.

9. Enhanced Strategic Plan Requirements

The proposal modifies strategic plan provisions to improve flexibility and clarity. The agencies would provide preliminary guidance on the adequacy of a proposed plan and be more forthcoming with substantive feedback. Banks evaluated under strategic plans would continue to have their performance assessed based on measurable goals specified in the plan, including any annual interim measurable goals. The agencies expect more banks may elect to be evaluated under a strategic plan as a result of these modifications, which are designed to provide greater flexibility in how banks demonstrate their CRA performance.

Why This Matters: More meaningful agency feedback and clearer expectations could make the strategic plan option more attractive, particularly for banks with unique business models or specialized market footprints. Institutions that have previously viewed the strategic plan process as cumbersome may wish to reevaluate whether a customized approach could better align with their CRA objectives. Community development financial institutions (CDFIs), banks serving rural or underserved markets, and institutions with nontraditional branch networks may find the strategic plan option particularly well-suited to demonstrating CRA performance in ways that standard evaluation criteria may not fully capture.

10. Significant Regulatory Burden Reduction

The proposal is expected to result in significant burden reduction, particularly for smaller institutions. For FDIC-supervised intermediate banks, including banks reclassified from large to intermediate, the FDIC estimates a decrease of approximately 114,775 annual burden hours (an 86% reduction). The agencies certify that the proposal would not have a significant economic impact on a substantial number of small entities and would result in net cost savings for small banks. The proposal would also allow banks that were devoting resources to prepare for the 2023 CRA rules (which were enjoined by court order) to redeploy those resources.

Why This Matters: The estimated 86% reduction in burden hours for intermediate banks represents a substantial shift in compliance expectations. Banks should consider how freed-up resources can be reallocated to lending activities, customer service, or other strategic priorities. Institutions that invested in systems and processes to comply with the 2023 CRA rules may be able to simplify or streamline those investments. For banks currently classified as large that may be reclassified as intermediate, the burden reduction could be even more significant, and management should begin evaluating which current compliance activities could be scaled back if the proposal is finalized.

Next Steps

Taken together, the proposal signals a shift toward a more streamlined and pragmatic CRA framework that emphasizes lending performance, provides greater regulatory certainty, and reduces compliance burden while preserving incentives for meaningful community development activities.

Although the proposal is not yet final, early preparation can reduce implementation risk and position banks to adapt more efficiently if the amendments are adopted substantially as proposed. Management should begin assessing strategic, operational, and governance implications rather than waiting for a final rule.

The proposal signals continued regulatory focus on measurable community reinvestment outcomes while seeking to address concerns raised regarding prior modernization efforts. Institutions should begin evaluating how the potential operational and strategic effects may materially affect their business model, particularly those that may be reclassified under the new asset-size thresholds. Banks can take the following steps now:

  • Evaluate how the proposed changes may affect assessment areas and CRA strategy.
  • Review current community development activities for continued eligibility and effectiveness.
  • Assess data collection, reporting, and technology capabilities.
  • Brief senior management and the board on potential impacts.
  • Consider submitting comments on provisions that may significantly affect operations or business strategy.

Comments on the proposed rule are due October 13, 2026.

For questions about the proposed CRA amendments or assistance with submitting comments, please contact the Community Banking team at Winthrop & Weinstine.

Tax Court Applies Anti-Abuse Rule to Basket Swap Transaction: Implications for Hedge Fund Strategies

On August 6, 2026, the U.S. Tax Court issued its decision in SIH Partners LLLP v. Commissioner[1], denying approximately $170.8 million in qualified dividend income (“QDI”) treatment and roughly $25.6 million in foreign tax credits (“FTCs”) arising from a basket swap transaction in Swiss equities. The Court held that even though the taxpayer’s swap passed the mechanical “substantial overlap” test under the Treasury Regulations, the anti-abuse rule of Treasury Regulation § 1.246-5(c)(1)(vi) independently applied because the transaction was designed primarily to generate tax benefits rather than economic profit.

Although SIH Partners arose under the QDI and FTC holding-period rules, its implications for the taxation of hedge funds and other securities market participants are broader. Basket swaps are also used in loss-harvesting strategies under section 1091[2] and gain-deferral strategies under section 1259. Although SIH Partners did not decide the application of those provisions to basket swaps, it shows that formal differences in basket composition may not be enough where the positions are expected to track closely and the tax benefits materially exceed expected pre-tax economics.

Background

The taxpayer, SIH Partners LLLP, held long positions in four Swiss equities. Simultaneously, the taxpayer entered into a portfolio swap that gave it short exposure to those same Swiss equities, along with other equity positions that were part of a longstanding firm risk hedge. The swap substantially offset the economic exposure of the long positions while the taxpayer continued to hold the shares and receive the dividends. The key rule here was section 246(c)(4): days when a taxpayer’s risk of loss is reduced by positions in substantially similar or related property do not count toward the relevant holding period. Section 246(c) was originally enacted to prevent dividend stripping for purposes of the dividends-received deduction (DRD), but it also supplies the holding period rule for QDI treatment under section 1(h)(11)(B)(iii) and for FTCs on dividends under section 901(k)(5).

The transaction at issue involved what practitioners refer to as “70/30 baskets.” The taxpayer structured its portfolio swap so that the short side of the swap did not substantially overlap the long equity positions. The mechanical test under Treasury Regulation § 1.246-5(c)(1)(iii) treats positions as substantially similar or related property only if the overlap equals or exceeds 70%. The taxpayer’s long positions had only a 64% overlap with the swap’s reference portfolio, which was below the 70% threshold and thus passed the mechanical test.

The Tax Court’s Holding

Despite the taxpayer’s compliance with the mechanical “substantial overlap” test, the Tax Court separately applied the anti-abuse rule under Treasury Regulation § 1.246-5(c)(1)(vi). The anti-abuse rule is a backstop provision that allows the IRS to treat positions as substantially similar or related property, regardless of the 70% rule. The Court’s analysis turned on two findings:

  1. Virtual tracking. The Swiss equities and the short positions in the swap were reasonably expected to virtually track each other. Even though the mechanical overlap was below 70%, the long and short positions moved in lockstep as a practical matter, effectively neutralizing the taxpayer’s real economic risk in such investments.
  2. Tax savings exceeded economic profit. The transaction was part of a plan with a principal purpose of obtaining tax savings that were significantly in excess of the expected pre-tax economic benefits.

Because the anti-abuse rule was triggered, the Court treated the swap as a position in substantially similar or related property. The anti-abuse rule under Treasury Regulation § 1.246-5(c)(1)(vi) reaches QDI and FTC treatment because sections 1(h)(11) and 901(k)(1) each cross-references section 246(c) for their holding-period requirements, incorporating the full regulatory framework. This reduced the taxpayer’s holding period to zero, rendering the dividends ineligible for reduced tax rates under section 1(h)(11) and barring the FTCs generated by withholding taxes on those dividends under section 901(k)(1).

Implications for Other Tax Rules Related to Continued or Reduced Economic Exposure

Wash Sale Rules

Section 1091 generally disallows a loss if, during the 61-day period around a sale, the taxpayer acquires, or enters into a contract or option to acquire, “substantially identical” stock or securities. A basket swap loss-harvesting strategy may seek to preserve economic exposure while varying the reference basket enough to avoid that standard. SIH Partners does not define “substantially identical” under section 1091, but its focus on virtual tracking and tax-driven economics may give the IRS a stronger argument where the basket differs in form but closely replicates the sold position.

Constructive Sale Rules

Section 1259 is the closer statutory analogue. It generally treats an appreciated position as constructively sold when the taxpayer enters into an offsetting notional principal contract with respect to the “same or substantially identical” property, and it authorizes Treasury to reach other transactions with substantially the same effect. Hedge funds may use diversified basket swaps to reduce the overlap between an appreciated position and the offsetting basket while still materially hedging the economics. SIH Partners is especially relevant because section 1259(c)(3)’s closed-transaction exception expressly cross-references section 246(c)(4). Although SIH Partners did not involve section 1259, that cross-reference makes the Court’s focus on virtual tracking and reduced economic risk worth watching.

The takeaway is not that the 70% test in Treasury Regulation § 1.246-5 governs sections 1091 or 1259; it does not. Rather, SIH Partners cautions against treating basket composition as a stand-alone safe harbor. In either context, a basket with non-overlapping securities or positions may still draw added scrutiny if it closely tracks or offsets the original position or positions.

Broader Implications

  • A 70/30 structure is not a general safe harbor. The 70% test in SIH Partners belongs to the section 246 regulations, not sections 1091 or 1259. Still, the decision cautions against relying on a numerical overlap threshold where the basket’s economics closely replicate the direct position.
  • Listed transaction developments. The IRS has identified certain basket option contracts as listed transactions under Notice 2015-73 and as transactions of interest under Notice 2015-74. In July 2024, the IRS published proposed regulations (REG-102161-23) that would expand listed transaction treatment to a broader range of basket contract transactions. Participants in listed transactions are subject to mandatory disclosure and reporting obligations under sections 6011, 6111, and 6112, with significant penalties for noncompliance.

Hedge funds and other market participants using basket swaps for loss harvesting or gain deferral should review whether the non-overlapping components create meaningful economic differences or mainly formal ones. Relevant factors include how closely the basket tracks the sold or appreciated position, how much market risk remains, how the expected tax benefits compare with pre-tax economics, and whether any basket-contract disclosure rules apply. SIH Partners does not extend the section 246 anti-abuse rule to sections 1091 or 1259, but it makes the economic rationale for basket construction more important to document.

Our tax team is monitoring these developments closely and is available to assist clients in evaluating the impact of this decision on their existing and planned transactions.

We express special thanks to Sara Mungo, who contributed to the research and content of this update.


[1] 167 T.C. No. 8 (August 6, 2026).

[2] “Section” references are to sections of the Internal Revenue Code of 1986, as amended.

Notice of Proposed Changes to Insider Lending Regulations

Earlier this month, the Federal Reserve Board (the “Federal Reserve”) and the Federal Deposit Insurance Corporation (the “FDIC”) each issued a notice of proposed rulemaking (collectively, the “Proposed Rules”) that would modernize and revise regulations governing extensions of credit by banking organizations to executive officers, directors, principal shareholders, and their related interests, commonly referred to as Reg O lending requirements. These Proposed Rules from the Federal Reserve and the FDIC would, among other things, substantially increase several longstanding dollar thresholds, provide for periodic adjustments to those thresholds, and clarify and modernize certain existing regulatory provisions and interpretations.  The last time meaningful updates to insider lending requirements took place was in 1979.

Key Proposed Changes

1. Increased Dollar Thresholds. The Proposed Rules would increase several dollar thresholds that have remained unchanged for many years as show below:

Requirement / Exception Current Proposed
Credit card indebtedness excluded from “extension of credit” $15,000 $60,000
Interest-bearing overdraft credit plan exception $5,000 $20,000
Inadvertent overdraft exception $1,000 $4,000
Executive officer loans for “other purposes” $100,000 Lesser of (i) $400,000 or (ii) 2.5% of unimpaired capital and surplus
Insider credit threshold requiring prior board approval $500,000 Lesser of (i) $2,000,000 or (ii) 5% of unimpaired capital and surplus
Public disclosure threshold $500,000 $2,000,000


2. Periodic Adjustment of Dollar Thresholds.
Rather than allowing these thresholds to remain static, the Proposed Rules would also provide for their adjustment every five years based on cumulative growth in nominal gross domestic product. This mechanism is intended to prevent the thresholds from becoming outdated as the economy grows.

3. Modernization of Definitions and Clarification of Existing Interpretations. The Federal Reserve’s proposal would make a number of additional changes intended to modernize Regulation O and conform the regulation to statutory requirements and existing regulatory interpretations. These include revisions to certain definitions and other technical and clarifying amendments.

Impact of the Proposed Rules

If adopted, the Proposed Rules could meaningfully reduce the compliance and administrative burdens associated with insider lending, particularly for community banks. In its proposal, the FDIC noted that existing prior-approval requirements may divert a bank board’s attention from other important responsibilities, including oversight of material financial risks. The FDIC also observed that the existing thresholds may disproportionately affect community banks operating in areas with limited banking alternatives, where directors and other insiders may have fewer options for obtaining credit from another institution.

At the same time, the Proposed Rules would leave the fundamental framework governing insider lending largely intact, including restrictions on preferential terms, lending limits, and prior board approval requirements for larger extensions of credit.

Comments on both Proposed Rules are due October 5, 2026.

For questions about the proposed amendments on insider lending, how the same may impact your organization, or assistance with submitting comments, feel free to connect with any member of Winthrop & Weinstine’s Community Banking team.

Facing the Music: Business Lessons from the Live Nation/Ticketmaster Antitrust Case

Earlier this year, a federal jury found Live Nation and Ticketmaster liable for illegally monopolizing the live-entertainment industry, just weeks after the U.S. Department of Justice had settled its own claims against the company. More than 30 state attorneys general rejected the federal deal as inadequate, proceeded with litigation, and prevailed. Those states are now pursuing remedies that could exceed what the federal settlement requires.

The practical lessons from this case extend well beyond the live event industry. They are relevant to any company that grows through acquisitions, uses exclusive or preferred-vendor arrangements, bundles services, or operates across state lines.

The Case

In May 2024, the U.S. Department of Justice and 39 state attorneys general sued Live Nation Entertainment, Inc. and its subsidiary Ticketmaster LLC, alleging violations of Sections 1 and 2 of the Sherman Act. The complaint charged that the defendants engaged in anticompetitive practices, including exclusionary conduct, unlawful tying arrangements, and market allocation that stifled competition, restricted consumer choice, and drove up ticket prices.[1]

In March 2026, just one week into trial, the DOJ announced a $280 million settlement with Live Nation. However, more than 30 of the 39 state attorneys general rejected the federal settlement as inadequate and elected to continue litigating their claims.

In April 2026, a federal jury in the Southern District of New York found that Live Nation and Ticketmaster had operated an illegal monopoly in the live entertainment industry, notwithstanding the federal settlement. As one state attorney general observed, the verdict “shows just how far states can go to protect [their] residents.”[2]

The states that prevailed at trial are now pursuing a range of remedies including limits on Live Nation’s reentry into the ticketing market, restrictions on Ticketmaster’s exclusive contracting practices, ongoing compliance monitoring, and, in the most aggressive proposals, full divestiture of Ticketmaster. The federal settlement may ultimately serve as a floor rather than a ceiling for Live Nation’s liability exposure.

The DOJ’s settlement remains subject to court approval under the Tunney Act. A public comment period is open through early September 2026, and the proposed consent decree has drawn significant opposition, including from state attorneys general, consumer advocacy groups, and independent music-industry stakeholders, who argue it does not adequately address the competitive harms alleged in the complaint.

Why Should Other Businesses Care?

Federal Settlement Does Not Resolve Liability Risk

One important lesson from this litigation is that settling with the federal government does not necessarily resolve a business’s litigation risk.

A federal settlement binds only the settling parties (in this case, the DOJ and Live Nation). State attorneys general retain independent enforcement authority under their own consumer protection and antitrust statutes, and they are not obligated to accept a federal resolution they view as inadequate. As the Live Nation litigation demonstrates, states may proceed with their own claims, litigate to judgment, and seek additional remedies beyond those negotiated by the federal government.

Antitrust Enforcement Does Not End When the Deal Closes

Modern merger enforcement increasingly includes post-closing behavioral conditions that regulate how the combined entity operates. The Live Nation case illustrates the full range of such restrictions such as multi-year operating conditions including fee caps, limits on exclusivity arrangements, and extension of an existing consent decree by eight years. The states’ requested remedies could impose even stricter requirements.

For acquirers, this means that closing a transaction is often not the end of the antitrust compliance timeline. Before signing, deal teams should evaluate how the combined company will operate post-closing. Will its operations raise antitrust concerns? Could the combined entity be characterized as a monopolist in any relevant market? If regulators imposed fee caps or interoperability requirements, could the business still operate profitably? Is there a plan for ongoing compliance?

These questions often receive insufficient attention during transaction planning. But as enforcement increasingly extends beyond closing and into ongoing operations, antitrust diligence must remain a priority throughout integration and well into the long-term operation of the combined business.

Exclusivity, Bundled Services, and Pressure to Stay Loyal Can Create Scrutiny

The Live Nation case reflects a pattern familiar across industries: long-term exclusive contracts with key partners, preferred-vendor arrangements, product or service bundling, and pressure on customers and suppliers to remain loyal. These arrangements can attract significant antitrust scrutiny, particularly where a company holds a strong position across multiple vertically related markets.

As Live Nation illustrates, when one company vertically integrates venues, ticketing, and artist promotion, even through nominally separate subsidiaries, regulators will scrutinize the potential for foreclosure and self-preferencing.

Operating Across State Lines Triggers Multi-State Enforcement

The Live Nation case also highlights the risks of multi-state enforcement. Here, the DOJ and six states reached one resolution, while more than 30 other states reached another. This divergence presents a significant risk for companies operating nationally: the possibility of parallel investigations, inconsistent enforcement actions, and conflicting remedial obligations from state regulators with different enforcement priorities.

Smaller transactions are not exempt from this scrutiny. Although the federal HSR filing thresholds increased to $126.4 million in February 2025 (and again to $134 million in February 2026), states have begun enacting their own premerger notification requirements, sometimes called “baby-HSR” laws, that apply regardless of whether the federal threshold is met.[3] This means deal teams must evaluate state-level filing obligations on a jurisdiction-by-jurisdiction basis, even for transactions below the federal threshold.

It is Crucial to Plan Ahead

The Live Nation case serves as a lesson that advance planning, ongoing compliance monitoring, and antitrust diligence are crucial to avoiding liability as a business expands. And it shows that striking a deal with one or more governments does not mean the remaining will fall in line.

We express special thanks to Claire Leach, who contributed to the research and content of this update.

 

[1] United States v. Live Nation Ent., Inc., No. 1:24-cv-03973 (S.D.N.Y.).

[2] https://www.cbsnews.com/news/live-nation-ticketmaster-anticompetitive-monopoly-ticketing-industry/

[3] For example, in Minnesota, the Attorney General reviews proposed hospital system transactions. See https://www.ag.state.mn.us/Health-Care/Transactions/ProposedMergers.asp.

Recent Third Circuit Case Highlights Business Risks of AI-Driven Algorithmic Pricing

Companies of all sizes and across every sector, including banking and financial services, have been scrambling to integrate artificial intelligence into their business models and day-to-day workflows. The possibilities offered by AI have seemingly driven companies and employees into an adoption frenzy. But the rush to drink from this digital fountain of youth is not without risk, as a recent case shows.

Imagine that sales teams at competing companies use the same AI-driven pricing model. Each team uploads their company’s confidential price lists and rates, planned discounts, forecasts, and customer population data, then asks the model to recommend pricing. The model provider retains the uploaded content, uses that content to improve its AI-driven pricing services, and allows the model to account for what it learns from one user to influence the pricing guidance given to a user at a competing company. The companies then adhere to the model’s pricing recommendations, even though those  terms may be different than what each company would have otherwise adopted. Could the companies later be dragged into court based on allegations of anticompetitive conduct?

The U.S. Court of Appeals for the Third Circuit has answered that question with a “yes.”[1] On July 29, 2026, the Third Circuit held that when an AI-driven “algorithm is in effect collecting non-public commercial information from [competitors] and utilizing the collective pot of data to ‘suggest’ prices to each [competitor],” that “surely raise[s] a plausible inference of collusion under Section 1 of the Sherman Act.”[2] The court’s holding, discussed further below, should serve as a cautionary tale for businesses of the risks that should be considered when deciding whether (and how) to use AI to compete in the marketplace.

The Third Circuit’s Decision in Cornish-Adebiyi v. Caesars Ent. Inc.

Casino-hotel guests brought a putative class action against several Atlantic City casino hotels, alleging a horizontal price-fixing conspiracy under § 1 of the Sherman Act. The plaintiffs claimed the defendant casino hotels and their shared algorithmic software provider, Cendyn, conspired to fix hotel room prices.

Each casino hotel fed its room pricing and occupancy data into Cendyn’s AI-driven dynamic pricing program called “Rainmaker,” which then processed that data—along with  data from competing casino hotels—and generated suggested room rates that were then uploaded into the participants’ systems. Although hotels allegedly retained ultimate pricing authority, deviations required special override permissions, and hotels followed Rainmaker’s recommendations 90% of the time.

The plaintiffs alleged this was a stark departure from the casino hotels’ historical practice of offering deeply discounted room rates (such as to draw gamblers onto the casino floor). The plaintiffs alleged that this arrangement replaced historically independent pricing, enabled hotels to avoid competition in undercutting one another, and led to rising room rates despite declining occupancy.

On appeal, the Third Circuit examined how AI-powered dynamic pricing algorithms can facilitate anticompetitive behavior. The court acknowledged that there is nothing inherently anticompetitive about using algorithms. However, it emphasized that AI software can facilitate collusion by enabling competitors to coordinate prices and share information without ever directly communicating with one another, and that real-time price monitoring enables “cartels” to more effectively police each other’s pricing behavior. The court noted that historically, collusion was hindered by communication gaps and enforcement costs, but that today’s AI algorithms have the capacity to bridge those gaps—making widespread coordination possible. Thus, the court held that the plaintiffs plausibly alleged the hotel casinos violated the antitrust laws.

Invoking a notable analogy from former FTC Acting Chair Maureen Ohlhausen, the court summarized: if it is not permissible for a person named Bob to collect confidential pricing strategy information from all market participants and then tell each one how to price, it is probably not permissible for an algorithm to do it either.

Practical Takeaways

The Third Circuit’s decision illustrates why companies, including banks and financial institutions, must be conscious of the risks of developing and using AI-driven pricing models and algorithms. Indeed, the message to companies is clear—using AI to automate competitive information sharing and coordinated decision-making is subject to antitrust scrutiny. Those looking to account for those risks should avoid over-use of information-sharing AI platforms; document independent decision-making; limit competitors’ data inputs on the platform; and audit AI tools for synchronized pricing, reduced competition, and other potentially collusive outcomes.

Banks and other financial institutions should be particularly careful when deploying AI tools that influence pricing, rates, fees, discounts, or other competitive terms. Before providing proprietary pricing information, customer data, forecasts, or other competitively sensitive information to a third-party AI platform, financial institutions should understand how the provider retains, uses, and combines that information—including whether it may be used to train the model or inform recommendations provided to competitors. Institutions should also consider contractual and technical safeguards that prevent the commingling of competitively sensitive data, maintain meaningful oversight over pricing decisions, and document the independent business reasons supporting departures from—or acceptance of—algorithmic recommendations. Put simply, financial institutions should treat an AI pricing platform not merely as another piece of software, but one that warrants special antitrust, compliance, and data-governance review.

[1] Cornish-Adebiyi v. Caesars Ent., Inc., — F.4th —-, 2026 WL 2182291 (3d Cir. July 29, 2026).
[2] Id. at *12.

MPCA Opens Applications for 2025 Industrial Stormwater Permit Coverage

The Minnesota Pollution Control Agency (MPCA) announced yesterday, August 19, 2026, that industrial facilities subject to the State’s industrial stormwater regulations may now apply for coverage under the 2025 Multi-sector General Permit (MSGP) for Industrial Stormwater through the MPCA’s e-Services application. While the 2025 MSGP was effective as of June 1, 2025, facilities were not able to apply for coverage under the 2025 Permit before yesterday’s MPCA announcement. Coverage under the 2020 MSGP will expire on September 30, 2026.

Facilities in certain regulated industries may be subject to industrial stormwater requirements when materials, waste, equipment, or other industrial activities are stored outdoors and exposed to natural precipitation. The MPCA’s industrial stormwater program is intended to limit the discharge of pollutants that can be picked up by stormwater runoff, including metals, petroleum products, salts, and other contaminants. Regulated facilities generally obtain coverage under Minnesota’s industrial stormwater general permit, which the MPCA reissues on a five-year cycle.

Additionally, as of yesterday’s announcement, all “No Exposure” certifications in Minnesota are now considered expired, and facilities that believe they qualify for such a certification must also reapply through e-Services. A facility qualifies for a “No Exposure” certification if its activities are within a standard industrial classification (SIC) code that subject to industrial stormwater regulation, but all industrial activities are conducted in areas that are not exposed to stormwater.

If you have questions about the applicability of industrial stormwater regulations to your facility or the MPCA’s latest announcement, please feel free to connect with any member of Winthrop’s Environmental law team.

Minnesota’s Primary Election Results

On Tuesday, August 11, 2026, Minnesota’s primary election delivered a return to mass appeal for Republicans and a slate of largely progressive Democrats running statewide.

Governor’s Race

Current House Speaker Lisa Demuth won out over Trump endorsee Mike Lindell and GOP-endorsed candidate Kendall Qualls by a significant margin, besting her nearest opponent (Lindell) by 11 percentage points. Demuth, a small business owner, has focused much of her campaign on fighting back against DFL overreach in state government. Heading into the general election, expect Demuth to continue making government fraud a central theme of her campaign.

Meanwhile, U.S. Senator Amy Klobuchar handily won the DFL party’s primary with nearly 90% of the vote. Klobuchar comes with none of the baggage of state government and enjoys widespread popularity but faces the most formidable candidate Republicans have put up in a decade.

U.S. Senate

In the race to replace outgoing U.S. Senator Tina Smith, Lt. Governor Peggy Flanagan won over Congresswoman Angie Craig by a nearly 20-point margin. Apparently DFLers were jaded by Craig’s vote on the Laken Riley Act–which may have set the stage for Operation Metro Surge–and campaign messaging targeting her “dark money” support. Instead, voters chose the progressive candidate in Flanagan.

The GOP again bucked their party’s endorsement in their pick for U.S. Senate. Former sports broadcaster Michele Tafoya ran away with 53% of the vote, to endorsed candidate Adam Schwarze’s 24%. Tafoya, with no experience in politics, will have to face Flanagan in a race where neither candidate has a federal issue voting record. Flanagan will have to defend herself against blame for everything that happened during Governor Tim Walz’s 8 years, while Tafoya will have to define herself beyond simple name ID and find a way to excite the far-right.

Other Races

Sleepy congressional district contests between strong incumbents and long-shot challengers delivered little excitement. In CD2, former state Senator Matt Little won the nomination with 47% of the vote and will go on to face current state Senator Eric Pratt in the general election.

Many eyes were on the race to replace outgoing Hennepin County Attorney Mary Moriarty. Current state Rep. Cedrick Frazier (36% of the vote) and Minneapolis attorney Anders Folk (23%) advance to the general election.

A couple of competitive primaries in the state Legislature are summarized below:

SD 46: Sen. Ron Latz vs. Lynette Dumalag

Longtime moderate Senator Latz faced off against former St. Louis Park councilmember Lynette Dumalag, whose progressive vision ultimately failed to resonate with the district. Latz won with just shy of 60% of the vote.

SD 5: Sen. Paul Utke vs. Rep. Mike Wiener

Rep. Wiener challenged sitting Senator Paul Utke from the right, defeating Utke by less than 200 votes.

What Employers Need to Know About Minnesota’s ESST Rules

On July 6, 2026, the Minnesota Department of Labor and Industry (“DLI”) issued new Earned Sick and Safe Time (“ESST”) rules. A link to the new rules can be found here, and FAQs about the rules can be found here.

The new rules resolve several questions that have emerged since the ESST statute became effective in 2024. Among other things, they clarify that employers must designate and communicate a 12-month ESST accrual year to employees, or the calendar year will apply by default. The rules also establish that employers may change their accrual year or accrual method. However, advance written notice is required, and a change negatively affecting an employee’s ability to accrue ESST is prohibited.

The rules also provide additional guidance regarding employee eligibility and the administration of ESST. Employers must determine in “good faith” whether an employee is expected to work at least 80 hours in Minnesota during the year and therefore qualifies for ESST. Importantly, ESST applies to any employee who works 80 hours, even if previously expected to work below that threshold. DLI further clarifies how ESST should be credited each pay period, addresses the treatment of exempt employees and employees working indeterminate-length shifts, and establishes requirements for employers that advance ESST, including when additional leave must be provided if an employee ultimately works more hours than anticipated. The rules also confirm that employees rehired within 180 days generally are entitled to reinstatement of up to 80 hours of previously accrued but unused ESST.

In addition, the rules clarify several important issues surrounding employee use of ESST. DLI emphasizes that the decision to use ESST belongs to the employee and that employers may not require employees to use accrued ESST leave for an otherwise qualifying absence. However, if an employee elects not to use available ESST, the absence is not entitled to ESST’s statutory protections. The rules also address attendance incentives, clarifying that employers generally may withhold bonuses or other attendance or productivity-based incentives when an employee misses the applicable benchmarks due to ESST use, provided employees taking other forms of approved leave would not remain eligible for the same incentive.

Finally, the rules provide additional guidance regarding documentation and suspected misuse of ESST. Employers may require reasonable documentation when authorized by the ESST statute, which applies when an employee uses ESST for more than two consecutive scheduled workdays, provided the employee receives reasonable notice of the documentation requirement and an opportunity to comply. The rules also identify examples of conduct that may constitute a pattern of suspected misuse, allowing employers to request documentation before an employee has used ESST for more than two consecutive scheduled workdays. At the same time, DLI makes clear that employers may not deny an employee’s request to use ESST for a qualifying reason based solely on prior or suspected misuse. The rules also confirm that employers may continue to satisfy ESST obligations through more generous PTO policies, provided those policies afford employees the protections required by the ESST statue law when leave is used for a qualifying purpose. Minnesota Paid Leave benefits qualify as “other salary continuation benefits” under the ESST statute.

Although the new rules do not substantially change Minnesota’s ESST obligations, they provide relevant clarification regarding DLI’s interpretation of the statute and employers’ compliance obligations. Minnesota employers should review their leave policies, payroll practices, and ESST administration procedures to ensure they are consistent with the new rules.

If you have questions about the new ESST rules or their impact on your workplace, please contact a member of Winthrop & Weinstine’s Employment & Labor group.