arrow-double-right arrow-noline-right arrow-lrg-left arrow-lrg-right arrow-med-down arrow-med-left arrow-med-right arrow-med-up arrow-sml-right checkmark close close-sml contact-card event-clock linkedin menu minus outbound-link phone plus print search-lrg search-sml twitter Winthrop-mark

Facing the Music: Business Lessons from the Live Nation/Ticketmaster Antitrust Case

Earlier this year, a federal jury found Live Nation and Ticketmaster liable for illegally monopolizing the live-entertainment industry, just weeks after the U.S. Department of Justice had settled its own claims against the company. More than 30 state attorneys general rejected the federal deal as inadequate, proceeded with litigation, and prevailed. Those states are now pursuing remedies that could exceed what the federal settlement requires.

The practical lessons from this case extend well beyond the live event industry. They are relevant to any company that grows through acquisitions, uses exclusive or preferred-vendor arrangements, bundles services, or operates across state lines.

The Case

In May 2024, the U.S. Department of Justice and 39 state attorneys general sued Live Nation Entertainment, Inc. and its subsidiary Ticketmaster LLC, alleging violations of Sections 1 and 2 of the Sherman Act. The complaint charged that the defendants engaged in anticompetitive practices, including exclusionary conduct, unlawful tying arrangements, and market allocation that stifled competition, restricted consumer choice, and drove up ticket prices.[1]

In March 2026, just one week into trial, the DOJ announced a $280 million settlement with Live Nation. However, more than 30 of the 39 state attorneys general rejected the federal settlement as inadequate and elected to continue litigating their claims.

In April 2026, a federal jury in the Southern District of New York found that Live Nation and Ticketmaster had operated an illegal monopoly in the live entertainment industry, notwithstanding the federal settlement. As one state attorney general observed, the verdict “shows just how far states can go to protect [their] residents.”[2]

The states that prevailed at trial are now pursuing a range of remedies including limits on Live Nation’s reentry into the ticketing market, restrictions on Ticketmaster’s exclusive contracting practices, ongoing compliance monitoring, and, in the most aggressive proposals, full divestiture of Ticketmaster. The federal settlement may ultimately serve as a floor rather than a ceiling for Live Nation’s liability exposure.

The DOJ’s settlement remains subject to court approval under the Tunney Act. A public comment period is open through early September 2026, and the proposed consent decree has drawn significant opposition, including from state attorneys general, consumer advocacy groups, and independent music-industry stakeholders, who argue it does not adequately address the competitive harms alleged in the complaint.

Why Should Other Businesses Care?

Federal Settlement Does Not Resolve Liability Risk

One important lesson from this litigation is that settling with the federal government does not necessarily resolve a business’s litigation risk.

A federal settlement binds only the settling parties (in this case, the DOJ and Live Nation). State attorneys general retain independent enforcement authority under their own consumer protection and antitrust statutes, and they are not obligated to accept a federal resolution they view as inadequate. As the Live Nation litigation demonstrates, states may proceed with their own claims, litigate to judgment, and seek additional remedies beyond those negotiated by the federal government.

Antitrust Enforcement Does Not End When the Deal Closes

Modern merger enforcement increasingly includes post-closing behavioral conditions that regulate how the combined entity operates. The Live Nation case illustrates the full range of such restrictions such as multi-year operating conditions including fee caps, limits on exclusivity arrangements, and extension of an existing consent decree by eight years. The states’ requested remedies could impose even stricter requirements.

For acquirers, this means that closing a transaction is often not the end of the antitrust compliance timeline. Before signing, deal teams should evaluate how the combined company will operate post-closing. Will its operations raise antitrust concerns? Could the combined entity be characterized as a monopolist in any relevant market? If regulators imposed fee caps or interoperability requirements, could the business still operate profitably? Is there a plan for ongoing compliance?

These questions often receive insufficient attention during transaction planning. But as enforcement increasingly extends beyond closing and into ongoing operations, antitrust diligence must remain a priority throughout integration and well into the long-term operation of the combined business.

Exclusivity, Bundled Services, and Pressure to Stay Loyal Can Create Scrutiny

The Live Nation case reflects a pattern familiar across industries: long-term exclusive contracts with key partners, preferred-vendor arrangements, product or service bundling, and pressure on customers and suppliers to remain loyal. These arrangements can attract significant antitrust scrutiny, particularly where a company holds a strong position across multiple vertically related markets.

As Live Nation illustrates, when one company vertically integrates venues, ticketing, and artist promotion, even through nominally separate subsidiaries, regulators will scrutinize the potential for foreclosure and self-preferencing.

Operating Across State Lines Triggers Multi-State Enforcement

The Live Nation case also highlights the risks of multi-state enforcement. Here, the DOJ and six states reached one resolution, while more than 30 other states reached another. This divergence presents a significant risk for companies operating nationally: the possibility of parallel investigations, inconsistent enforcement actions, and conflicting remedial obligations from state regulators with different enforcement priorities.

Smaller transactions are not exempt from this scrutiny. Although the federal HSR filing thresholds increased to $126.4 million in February 2025 (and again to $134 million in February 2026), states have begun enacting their own premerger notification requirements, sometimes called “baby-HSR” laws, that apply regardless of whether the federal threshold is met.[3] This means deal teams must evaluate state-level filing obligations on a jurisdiction-by-jurisdiction basis, even for transactions below the federal threshold.

It is Crucial to Plan Ahead

The Live Nation case serves as a lesson that advance planning, ongoing compliance monitoring, and antitrust diligence are crucial to avoiding liability as a business expands. And it shows that striking a deal with one or more governments does not mean the remaining will fall in line.

[1] United States v. Live Nation Ent., Inc., No. 1:24-cv-03973 (S.D.N.Y.).

[2] https://www.cbsnews.com/news/live-nation-ticketmaster-anticompetitive-monopoly-ticketing-industry/

[3] For example, in Minnesota, the Attorney General reviews proposed hospital system transactions. See https://www.ag.state.mn.us/Health-Care/Transactions/ProposedMergers.asp.

Recent Third Circuit Case Highlights Business Risks of AI-Driven Algorithmic Pricing

Companies of all sizes and across every sector, including banking and financial services, have been scrambling to integrate artificial intelligence into their business models and day-to-day workflows. The possibilities offered by AI have seemingly driven companies and employees into an adoption frenzy. But the rush to drink from this digital fountain of youth is not without risk, as a recent case shows.

Imagine that sales teams at competing companies use the same AI-driven pricing model. Each team uploads their company’s confidential price lists and rates, planned discounts, forecasts, and customer population data, then asks the model to recommend pricing. The model provider retains the uploaded content, uses that content to improve its AI-driven pricing services, and allows the model to account for what it learns from one user to influence the pricing guidance given to a user at a competing company. The companies then adhere to the model’s pricing recommendations, even though those  terms may be different than what each company would have otherwise adopted. Could the companies later be dragged into court based on allegations of anticompetitive conduct?

The U.S. Court of Appeals for the Third Circuit has answered that question with a “yes.”[1] On July 29, 2026, the Third Circuit held that when an AI-driven “algorithm is in effect collecting non-public commercial information from [competitors] and utilizing the collective pot of data to ‘suggest’ prices to each [competitor],” that “surely raise[s] a plausible inference of collusion under Section 1 of the Sherman Act.”[2] The court’s holding, discussed further below, should serve as a cautionary tale for businesses of the risks that should be considered when deciding whether (and how) to use AI to compete in the marketplace.

The Third Circuit’s Decision in Cornish-Adebiyi v. Caesars Ent. Inc.

Casino-hotel guests brought a putative class action against several Atlantic City casino hotels, alleging a horizontal price-fixing conspiracy under § 1 of the Sherman Act. The plaintiffs claimed the defendant casino hotels and their shared algorithmic software provider, Cendyn, conspired to fix hotel room prices.

Each casino hotel fed its room pricing and occupancy data into Cendyn’s AI-driven dynamic pricing program called “Rainmaker,” which then processed that data—along with  data from competing casino hotels—and generated suggested room rates that were then uploaded into the participants’ systems. Although hotels allegedly retained ultimate pricing authority, deviations required special override permissions, and hotels followed Rainmaker’s recommendations 90% of the time.

The plaintiffs alleged this was a stark departure from the casino hotels’ historical practice of offering deeply discounted room rates (such as to draw gamblers onto the casino floor). The plaintiffs alleged that this arrangement replaced historically independent pricing, enabled hotels to avoid competition in undercutting one another, and led to rising room rates despite declining occupancy.

On appeal, the Third Circuit examined how AI-powered dynamic pricing algorithms can facilitate anticompetitive behavior. The court acknowledged that there is nothing inherently anticompetitive about using algorithms. However, it emphasized that AI software can facilitate collusion by enabling competitors to coordinate prices and share information without ever directly communicating with one another, and that real-time price monitoring enables “cartels” to more effectively police each other’s pricing behavior. The court noted that historically, collusion was hindered by communication gaps and enforcement costs, but that today’s AI algorithms have the capacity to bridge those gaps—making widespread coordination possible. Thus, the court held that the plaintiffs plausibly alleged the hotel casinos violated the antitrust laws.

Invoking a notable analogy from former FTC Acting Chair Maureen Ohlhausen, the court summarized: if it is not permissible for a person named Bob to collect confidential pricing strategy information from all market participants and then tell each one how to price, it is probably not permissible for an algorithm to do it either.

Practical Takeaways

The Third Circuit’s decision illustrates why companies, including banks and financial institutions, must be conscious of the risks of developing and using AI-driven pricing models and algorithms. Indeed, the message to companies is clear—using AI to automate competitive information sharing and coordinated decision-making is subject to antitrust scrutiny. Those looking to account for those risks should avoid over-use of information-sharing AI platforms; document independent decision-making; limit competitors’ data inputs on the platform; and audit AI tools for synchronized pricing, reduced competition, and other potentially collusive outcomes.

Banks and other financial institutions should be particularly careful when deploying AI tools that influence pricing, rates, fees, discounts, or other competitive terms. Before providing proprietary pricing information, customer data, forecasts, or other competitively sensitive information to a third-party AI platform, financial institutions should understand how the provider retains, uses, and combines that information—including whether it may be used to train the model or inform recommendations provided to competitors. Institutions should also consider contractual and technical safeguards that prevent the commingling of competitively sensitive data, maintain meaningful oversight over pricing decisions, and document the independent business reasons supporting departures from—or acceptance of—algorithmic recommendations. Put simply, financial institutions should treat an AI pricing platform not merely as another piece of software, but one that warrants special antitrust, compliance, and data-governance review.

[1] Cornish-Adebiyi v. Caesars Ent., Inc., — F.4th —-, 2026 WL 2182291 (3d Cir. July 29, 2026).
[2] Id. at *12.

MPCA Opens Applications for 2025 Industrial Stormwater Permit Coverage

The Minnesota Pollution Control Agency (MPCA) announced yesterday, August 19, 2026, that industrial facilities subject to the State’s industrial stormwater regulations may now apply for coverage under the 2025 Multi-sector General Permit (MSGP) for Industrial Stormwater through the MPCA’s e-Services application. While the 2025 MSGP was effective as of June 1, 2025, facilities were not able to apply for coverage under the 2025 Permit before yesterday’s MPCA announcement. Coverage under the 2020 MSGP will expire on September 30, 2026.

Facilities in certain regulated industries may be subject to industrial stormwater requirements when materials, waste, equipment, or other industrial activities are stored outdoors and exposed to natural precipitation. The MPCA’s industrial stormwater program is intended to limit the discharge of pollutants that can be picked up by stormwater runoff, including metals, petroleum products, salts, and other contaminants. Regulated facilities generally obtain coverage under Minnesota’s industrial stormwater general permit, which the MPCA reissues on a five-year cycle.

Additionally, as of yesterday’s announcement, all “No Exposure” certifications in Minnesota are now considered expired, and facilities that believe they qualify for such a certification must also reapply through e-Services. A facility qualifies for a “No Exposure” certification if its activities are within a standard industrial classification (SIC) code that subject to industrial stormwater regulation, but all industrial activities are conducted in areas that are not exposed to stormwater.

If you have questions about the applicability of industrial stormwater regulations to your facility or the MPCA’s latest announcement, please feel free to connect with any member of Winthrop’s Environmental law team.

Minnesota’s Primary Election Results

On Tuesday, August 11, 2026, Minnesota’s primary election delivered a return to mass appeal for Republicans and a slate of largely progressive Democrats running statewide.

Governor’s Race

Current House Speaker Lisa Demuth won out over Trump endorsee Mike Lindell and GOP-endorsed candidate Kendall Qualls by a significant margin, besting her nearest opponent (Lindell) by 11 percentage points. Demuth, a small business owner, has focused much of her campaign on fighting back against DFL overreach in state government. Heading into the general election, expect Demuth to continue making government fraud a central theme of her campaign.

Meanwhile, U.S. Senator Amy Klobuchar handily won the DFL party’s primary with nearly 90% of the vote. Klobuchar comes with none of the baggage of state government and enjoys widespread popularity but faces the most formidable candidate Republicans have put up in a decade.

U.S. Senate

In the race to replace outgoing U.S. Senator Tina Smith, Lt. Governor Peggy Flanagan won over Congresswoman Angie Craig by a nearly 20-point margin. Apparently DFLers were jaded by Craig’s vote on the Laken Riley Act–which may have set the stage for Operation Metro Surge–and campaign messaging targeting her “dark money” support. Instead, voters chose the progressive candidate in Flanagan.

The GOP again bucked their party’s endorsement in their pick for U.S. Senate. Former sports broadcaster Michele Tafoya ran away with 53% of the vote, to endorsed candidate Adam Schwarze’s 24%. Tafoya, with no experience in politics, will have to face Flanagan in a race where neither candidate has a federal issue voting record. Flanagan will have to defend herself against blame for everything that happened during Governor Tim Walz’s 8 years, while Tafoya will have to define herself beyond simple name ID and find a way to excite the far-right.

Other Races

Sleepy congressional district contests between strong incumbents and long-shot challengers delivered little excitement. In CD2, former state Senator Matt Little won the nomination with 47% of the vote and will go on to face current state Senator Eric Pratt in the general election.

Many eyes were on the race to replace outgoing Hennepin County Attorney Mary Moriarty. Current state Rep. Cedrick Frazier (36% of the vote) and Minneapolis attorney Anders Folk (23%) advance to the general election.

A couple of competitive primaries in the state Legislature are summarized below:

SD 46: Sen. Ron Latz vs. Lynette Dumalag

Longtime moderate Senator Latz faced off against former St. Louis Park councilmember Lynette Dumalag, whose progressive vision ultimately failed to resonate with the district. Latz won with just shy of 60% of the vote.

SD 5: Sen. Paul Utke vs. Rep. Mike Wiener

Rep. Wiener challenged sitting Senator Paul Utke from the right, defeating Utke by less than 200 votes.

What Employers Need to Know About Minnesota’s ESST Rules

On July 6, 2026, the Minnesota Department of Labor and Industry (“DLI”) issued new Earned Sick and Safe Time (“ESST”) rules. A link to the new rules can be found here, and FAQs about the rules can be found here.

The new rules resolve several questions that have emerged since the ESST statute became effective in 2024. Among other things, they clarify that employers must designate and communicate a 12-month ESST accrual year to employees, or the calendar year will apply by default. The rules also establish that employers may change their accrual year or accrual method. However, advance written notice is required, and a change negatively affecting an employee’s ability to accrue ESST is prohibited.

The rules also provide additional guidance regarding employee eligibility and the administration of ESST. Employers must determine in “good faith” whether an employee is expected to work at least 80 hours in Minnesota during the year and therefore qualifies for ESST. Importantly, ESST applies to any employee who works 80 hours, even if previously expected to work below that threshold. DLI further clarifies how ESST should be credited each pay period, addresses the treatment of exempt employees and employees working indeterminate-length shifts, and establishes requirements for employers that advance ESST, including when additional leave must be provided if an employee ultimately works more hours than anticipated. The rules also confirm that employees rehired within 180 days generally are entitled to reinstatement of up to 80 hours of previously accrued but unused ESST.

In addition, the rules clarify several important issues surrounding employee use of ESST. DLI emphasizes that the decision to use ESST belongs to the employee and that employers may not require employees to use accrued ESST leave for an otherwise qualifying absence. However, if an employee elects not to use available ESST, the absence is not entitled to ESST’s statutory protections. The rules also address attendance incentives, clarifying that employers generally may withhold bonuses or other attendance or productivity-based incentives when an employee misses the applicable benchmarks due to ESST use, provided employees taking other forms of approved leave would not remain eligible for the same incentive.

Finally, the rules provide additional guidance regarding documentation and suspected misuse of ESST. Employers may require reasonable documentation when authorized by the ESST statute, which applies when an employee uses ESST for more than two consecutive scheduled workdays, provided the employee receives reasonable notice of the documentation requirement and an opportunity to comply. The rules also identify examples of conduct that may constitute a pattern of suspected misuse, allowing employers to request documentation before an employee has used ESST for more than two consecutive scheduled workdays. At the same time, DLI makes clear that employers may not deny an employee’s request to use ESST for a qualifying reason based solely on prior or suspected misuse. The rules also confirm that employers may continue to satisfy ESST obligations through more generous PTO policies, provided those policies afford employees the protections required by the ESST statue law when leave is used for a qualifying purpose. Minnesota Paid Leave benefits qualify as “other salary continuation benefits” under the ESST statute.

Although the new rules do not substantially change Minnesota’s ESST obligations, they provide relevant clarification regarding DLI’s interpretation of the statute and employers’ compliance obligations. Minnesota employers should review their leave policies, payroll practices, and ESST administration procedures to ensure they are consistent with the new rules.

If you have questions about the new ESST rules or their impact on your workplace, please contact a member of Winthrop & Weinstine’s Employment & Labor group.

Executive Order No. 14398 May Impose Penalties on Employers Receiving Federal Grants or Working with Federal Contractors

On March 26, 2026, President Trump signed Executive Order No. 14398, “Addressing DEI Discrimination by Federal Contractors.” The Order seeks to minimize and eliminate certain DEI practices. Specifically, the Order requires that all federal contracts and “contract-like” instruments include a new clause that prohibits “racially discriminatory DEI activities” and imposes additional compliance and reporting obligations. Violation of the Order may result in penalties for those businesses who are federal contractors, subcontractors, lower-tier contract holders, and parties subject to “contract-like instruments.”

The following frequently asked questions address common questions from employers relating to this Order.

What Does the Order Require?

The Order provides a new mandatory clause for all federal contracts, subcontracts, lower-tier subcontracts, and “contract-like” instruments. Beginning April 24, 2026, contracting agencies were required to include the clause in all new solicitations and resulting contracts. By July 24, 2026, agencies were also required to incorporate the clause into existing covered contracts.

The clause prohibits federal contractors and subcontractors from engaging in “racially discriminatory DEI activities.” The clause also requires each federal contractor, subcontractor, and lower-tier subcontractor to provide the contracting agency with information, reports, and access to records that allow for verification of compliance. Further, federal contractors, subcontractors, and entities subject to “contract-like instruments” must acknowledge that noncompliance may lead to suspension of contracts and disqualification from any future government contracts, and that compliance is “material to the Government’s payment decisions” for purposes of the False Claims Act. The Order also requires that federal contractors inform the relevant executive agency of any subcontractors “known or reasonably knowable” conduct that violates the clause or if any subcontractor sues the federal contractor to challenge the validity of the Order.

What Constitutes “Racially Discriminatory DEI Activities”?

The Order defines “racially discriminatory DEI activities” as disparate treatment of any given person on the basis of race or ethnicity in recruitment, hiring, promotion, contracting, program participation, or allocation or deployment of resources. The Order further defines “program participation” as membership, participation, or access to any training, mentoring, leadership development programs, educational opportunities, clubs, association, or similar opportunities if sponsored or established by the contractor or subcontractor.

What are the Consequences of Non-Compliance with the Order?

The contracting agency may cancel, terminate, or suspend any contract or contract-like instrument held with that contracting entity if the contracting party fails to comply with the Order. The contracting agency may also “suspend or debar” any contractors or subcontractors that fail to comply, meaning they will likely be ineligible for future federal contracts. Further, the Attorney General is authorized to consult with the relevant contracting agency and may bring actions against the contracting entity under the False Claims Act for violation of the Order.

What Businesses are Covered by the Order?

The Order expressly covers any business holding contracts, subcontracts, and lower-tier subcontracts with the federal government. Thus, businesses working with federal contractors should be aware of the risks; working relations with federal contractors may establish a relationship as a subcontractor or “lower-tier subcontractor.”

The Order also covers businesses holding “contract-like instruments.” This term is not clearly defined. However, “contract-like instruments” may include any federal grants that a business receives from the federal government, as well as any other funds, assistance, or benefits that a business receives as a result of an agreement with the federal government. As a result, such businesses should carefully review their practices to determine potential exposure.

What Steps Should Businesses Take Now?

First, businesses should take steps to identify whether they are affected by the Order. Businesses should evaluate whether they receive any grants, assistance, or benefits resulting from an agreement with the federal government, or whether they work closely with another entity that is a contractor or subcontractor for the federal government.

If affected by the Order, businesses should consider taking the following steps:

  1. Audit existing programs, policies and initiatives to determine any that may be considered “racially discriminatory DEI activities” under the order;
  2. Review all existing and upcoming federal contracts, subcontracts, or contract-like instruments and ensure that they include the new compliance clause mandated by the Order;
  3. Assess reporting obligations, including any obligation to report a subcontractor’s violations to the contracting agency;
  4. Ensure that recordkeeping systems are adequate to demonstrate compliance with the Order if requested by the contracting agency; and
  5. Monitor the Office of Management and Budget and other agency guidance, which may provide additional detail regarding compliance expectations and enforcement priorities.

Given the breadth of the Order’s definitions and the severity of the penalties associated with noncompliance, affected or potentially affected businesses should act promptly to evaluate their exposure and adjust practices as necessary. Please reach out to any member of the Winthrop & Weinstine’s employment team for assistance in tailoring a compliance strategy to your organization.

Interagency Guidance on Lending to Individuals Not Legally Authorized to Work in the United States

Recently, the Federal Deposit Insurance Corporation (FDIC), National Credit Union Administration (NCUA), and Office of the Comptroller of the Currency (OCC) jointly issued guidance reminding supervised financial institutions of their obligations to maintain sound credit risk management practices when extending credit to individuals who are not legally authorized to work in the United States. Although the regulators do not prohibit lending to these borrowers, the guidance emphasizes that institutions should recognize and appropriately manage the elevated credit, concentration, and compliance risks that may arise when a borrower’s repayment capacity depends on income derived from employment that may be interrupted or terminated due to a lack of work authorization.

Joint Guidance

As part of the joint guidance, the agencies emphasize that safe and sound underwriting requires institutions to first assess a borrower’s capacity and willingness to repay, including the stability and sustainability of income relied upon as the primary source of repayment.

Source of Repayment

The guidance notes that financial institutions should evaluate whether a borrower’s income is current, verifiable, stable, sustainable, and reasonably likely to continue throughout the loan term. Several scenarios are highlighted that may adversely affect repayment capacity, including:

  • Loss of employment due to lack of work authorization;
  • Expiration of employment authorization;
  • Inability to obtain lawful future employment; and
  • Removal from the United States.

Institutions are encouraged to consider whether repayment capacity would remain adequate under potential employment and income disruptions arising from any of these circumstances. The guidance encourages institutions to consider obtaining and reviewing documentation supporting income and repayment capacity, including pay stubs, Forms W-2, tax returns, employer verifications, bank statements, and evidence of continuing work authorization, as appropriate.

Collateral and Collection Risk

The agencies also note that collateralized lending may present heightened risk where borrowers become difficult to locate or leave the United States. Institutions may face increased challenges enforcing security interests and repossessing movable collateral, such as automobiles, recreational vehicles, and boats.

Allowances for Credit Losses

The agencies advise institutions to assess whether loans to non-work-authorized borrowers demonstrate indicators of credit weakness, regardless of delinquency status. Where warranted, those risks should be reflected in loan classification decisions and the institution’s allowance for credit losses methodology.

Concentration Risk

The guidance also highlights the potential for concentration risk. Institutions with significant exposure to borrowers concentrated in certain industries, employers, or geographic regions may be particularly vulnerable to changes in immigration enforcement, employment verification requirements, or labor market disruptions. Such events could result in correlated credit deterioration across affected borrower segments rather than isolated defaults.

Consumer Compliance Considerations

As it relates to compliance considerations, the agencies specifically reference the June 8, 2026 Statement on Ability to Repay and Immigration Status, from the Consumer Financial Protection Bureau (CFPB) emphasizing that creditors must continue to satisfy applicable consumer protection requirements when evaluating credit applications.

Among other things, the CFPB’s statement emphasizes that:

  • Under the Truth in Lending Act (TILA) and Regulation Z, creditors must make a reasonable, good-faith determination that a consumer has the ability to repay a covered credit obligation.
  • In evaluating a consumer’s ability-to-repay, creditor may consider information bearing on the consumer’s ongoing ability to earn income, including circumstances where continued residence in the United States is necessary to maintain employment that serves as the source of repayment.
  • Under the Equal Credit Opportunity Act (ECOA) and Regulation B, creditors may consider an applicant’s immigration status and obtain additional information necessary to assess the creditor’s rights and remedies with respect to repayment, provided such considerations are applied consistent with applicable fair lending requirements.

The CFPB’s statement underscores that immigration status may be relevant to a creditor’s ability-to-repay analysis where legal residency or work authorization directly affects the consumer’s capacity to continue earning income used to satisfy the credit obligation.

Guidance Issued Pursuant to Executive Order

The interagency guidance was issued in response to President Trump’s May 19, 2026, Executive Order, Restoring Integrity to America’s Financial System, which directed the federal banking agencies and other financial regulators to address risks associated with the extension of credit and financial services to individuals who are not legally authorized to work in the United States. Specifically, the Executive Order called on the federal functional regulators to issue guidance regarding the identification and management of credit risks associated with lending to this population and directed the Secretary of the Treasury to provide financial institutions with an advisory addressing risks related to the potential exploitation of the U.S. financial system by non-work-authorized individuals and their employers. The Executive Order also directed Treasury to propose amendments to Bank Secrecy Act regulations designed to strengthen risk-based customer due diligence requirements. It further directed the CFPB to clarify how creditors should apply Regulation Z’s ability-to-repay requirements when a consumer’s income depends on employment affected by immigration or work authorization status, prompting the CFPB’s statement referenced above.

This guidance, together with the CFPB statement and any forthcoming Treasury actions, reflects a broader federal policy initiative focused on the risks that immigration and work authorization issues may present to financial institutions.

Key Takeaways

While the guidance does not create new legal requirements or prohibit lending to individuals who are not legally authorized to work in the United States, it clearly signals increased regulatory attention to the underwriting, monitoring, and reserving practices associated with these loans.

Financial institutions should consider reviewing:

  • Underwriting policies and procedures for assessing employment authorization-related risks;
  • Income verification and documentation requirements;
  • Loan grading and allowance for credit losses methodologies;
  • Portfolio concentration monitoring practices; and
  • Compliance management systems addressing TILA, Regulation Z, ECOA, and Regulation B considerations.

The core message of the guidance is that institutions may continue to lend to these borrowers, but they should ensure that credit decisions are supported by prudent underwriting, appropriate risk management controls, and documented assessments of repayment capacity.

SEC Proposed Rule: Electronic Delivery as the New Default for Investor Communications

What Does the Proposed SEC Rule Do?

The Securities and Exchange Commission (“SEC”) has proposed new Regulation E‑Delivery (“Reg E‑Delivery”) as a comprehensive framework for electronic delivery (“e-delivery”) of regulatory disclosures, reports, and other required information under the federal securities laws.

For the first time, the proposal would allow companies to default to e-delivery without requiring investors to opt in first. This represents a major shift from the SEC’s longstanding consent-based approach. The framework includes robust notice, opt‑out, and security safeguards while preserving investors’ right to receive paper free of charge.

Key features include replacing existing SEC interpretive guidance with uniform rules-based conditions, providing a detailed transition process for investors currently receiving paper, rescinding Rule 30e‑3 and amending proxy and tender offer rules, and establishing an exemption from the Electronic Signatures in Global and National Commerce Act (the “E‑SIGN Act”) consumer consent requirements.

What Information and Parties Are Covered?

The rule applies broadly to “covered entities” issuing “covered information” to “covered recipients.” Covered entities have delivery obligations under the federal securities laws, including issuers, investment companies (mutual funds, ETFs, closed‑end funds), broker‑dealers, investment advisers, and obligors and trustees under indentures.

“Covered information” under the proposed rule is defined broadly to include any information required to be delivered under the Securities Act of 1933, as amended (the “Securities Act”), the Securities Exchange Act of 1934, as amended (the “Exchange Act”), the Investment Company Act of 1940 (the “ICA”), the Investment Advisers Act of 1940, the Trust Indenture Act of 1939, or other federal securities laws, subject to express exclusions. Examples of “covered information” under the proposed rule include, without limitation, for each category of reporting entity:

  • Investment companies: Prospectuses, annual and semi‑annual shareholder reports, notices under Rule 19a‑1 under the ICA, proxy statements, and information statements.
  • Issuers and soliciting persons: Prospectuses under the Securities Act, annual reports to security holders, proxy statements, information statements, tender offer statements, and offering circulars.
  • Obligors and trustees: Bondholders’ lists and reports to security holders under indentures.
  • Broker‑dealers: Trade confirmations, Form CRS disclosures, Regulation S‑AM disclosures, and other required customer communications.
  • Investment advisers: Form ADV Part 2 brochures, marketing and testimonial disclosures, agency cross‑transaction disclosures, and custody‑rule account statement notices.

A “covered recipient” under the proposed rule includes any current or prospective customer, client, investor, security holder, counterparty, or similar recipient to whom a covered entity must deliver covered information.

The rule excludes information under Regulation Crowdfunding, Exchange Act Rule 15c2‑11, trade acknowledgments for security‑based swap transactions, filings required to be publicly available but not delivered to specific recipients (such as Regulation FD disclosures or Form ADV Part 1), and disclosures required solely under state or SRO rules.

What Are the Core Elements of the Proposed Framework?

Default Electronic Delivery Without Prior Consent. Reg E‑Delivery would permit covered entities to use e-delivery to satisfy federal delivery obligations without first obtaining recipient consent. Use of Reg E‑Delivery is optional. Covered entities can continue paper delivery or use other compliant electronic methods. The substantive disclosure and liability standards under the securities laws apply equally to electronic and paper delivery.

Technology-Neutral Approach. The proposed definitions are technology‑neutral. “Electronic address” includes email addresses, mobile phone numbers, web portals, app‑based notifications, or blockchain messaging. “Electronic delivery” means delivery of covered information to a covered recipient’s electronic address. The definitions are designed to be adaptable to future innovations. The SEC explicitly contemplates that blockchain and other distributed‑ledger technologies could be used, provided the messaging meets the rule’s requirements.

Two Permitted Electronic Delivery Methods. Reg E‑Delivery provides two principal methods for satisfying delivery requirements electronically:

  1. Statement of Availability. Under this “notice and access” approach, the covered entity sends a statement to the recipient’s electronic address that covered information is available online. The statement must prominently identify the covered entity and type of information, describe whether it requires time‑sensitive action, provide a direct website link (with secure access for personal financial information (“PFI”)), and explain the recipient’s rights to paper copies, opt‑out, and address updates, each of which must be provided free of charge. Covered entities must maintain covered information on a website for a minimum period, which must be at least three years for materials containing PFI and at least one year for materials that do not contain PFI (unless a different period is provided under federal securities laws). Information must be convenient for reading online, printing, and electronic retention.
  2. Direct Delivery. The second method permits direct electronic delivery (e.g., email with attachments) of covered information that does not include PFI. The communication must include the same core content as a statement of availability, with all covered information in the body or as an attachment.

Personal Financial Information. PFI (account numbers, transaction details) cannot be delivered via direct delivery and must be accessed through a secure process such as a secure portal or authenticated app.

Timing and Right to Paper. E-delivery must occur no later than the required delivery date under securities law. Covered entities must send paper copies free of charge upon request within three business days. Recipients may opt out of e-delivery at any time and receive paper, and may choose paper for some document types while receiving others electronically.

E‑Delivery Failures. Covered entities must adopt written policies to identify and remediate e-delivery failures (including any “bounce-backs”), including obtaining a new electronic address or delivering in paper format until the recipient provides an updated address.

How Will Investors Currently Receiving Paper Be Transitioned to Default E-Delivery?

The proposal includes a transition regime for covered recipients currently receiving paper copies. Covered entities must send an initial paper notice at least 180 days before the transition date, followed by a follow-up notice 30 days before such date. The notices must alert the recipient to the upcoming transition, describe the covered information that will move to e-delivery, explain opt-out rights, and provide contact details (toll-free number and website) to opt out or update an electronic address. If a recipient updates or confirms an address after the initial notice, the follow-up notice is not required.

How Does the Proposal Interact with the E‑SIGN Act?

Under the E‑SIGN Act, certain consumer disclosures delivered electronically are subject to special consent requirements. The proposal would exempt covered information delivered under Reg E-Delivery from these requirements, effectively replacing the E‑SIGN consent procedures with the rule’s own notice, opt-out, and access framework.

What Changes Are Proposed to Existing SEC Rules and Guidance?

Rescission of Rule 30e‑3. The SEC proposes to rescind Rule 30e‑3, which currently allows investment companies to satisfy shareholder report delivery by posting reports online and mailing a paper notice. Under Reg E-Delivery, default e-delivery would be available for recipients with electronic addresses, with paper reserved for those who opt out or never respond.

Amendments to Proxy and Tender Offer Rules. The proposal would substantially revise the proxy “notice and access” framework in Exchange Act Regulation 14A, Regulation 14C, and tender offer dissemination rules to harmonize them with Reg E-Delivery. The existing Notice of Internet Availability of Proxy Materials would be replaced by a statement of availability that must comply with Reg E‑Delivery’s requirements plus proxy‑specific content, including a prominent legend regarding proxy material availability for the shareholder meeting and required control/identification numbers for accessing the proxy card. Certain historically important but now less necessary content requirements would be eliminated. Any electronic delivery of proxy materials would be required to comply with Reg E-Delivery.

Next Steps

The proposal remains subject to public comment and may change before adoption, but public companies and other covered entities may wish to begin assessing readiness now. Useful early steps may include, depending on your unique circumstances:

  • Take Inventory of Current Practices: Inventorying which SEC-required communications (e.g., prospectuses, proxy materials, annual reports, and other shareholder communications) are currently delivered in paper versus electronically, and identifying the business units and service providers responsible for those processes.
  • Assess Electronic Records: Assessing the completeness and accuracy of electronic contact information on file for shareholders, investors, and other covered recipients.
  • Evaluate Existing E-Delivery Media for Compliance with Proposed Rule: Evaluating whether existing investor portals, websites, mobile applications, and authentication procedures would meet the proposal’s requirements, particularly for materials containing PFI.
  • Review E-Delivery Policies and Procedures: Reviewing policies and procedures addressing e-delivery failures, website availability, investor delivery preferences, and paper copy requests.
  • Consider Commenting on the Proposed Rule: Considering whether to submit comments to the SEC, alone or through an industry group, on aspects of the proposal that would affect your business.

If adopted substantially as proposed, Reg E-Delivery would be the SEC’s most significant modernization of disclosure delivery since the notice-and-access framework was adopted nearly two decades ago, and could meaningfully reduce printing and mailing costs while establishing a single, rules-based e-delivery framework across the federal securities laws.

If you have questions about this alert or would like to discuss the proposal and its potential impact, please contact Vince Pecora or another Winthrop securities law attorney.

Minnesota Campaign Finance and Public Disclosure Board Removes Certain Restrictions on Party Unit Support of Candidates

On July 9, the Minnesota Campaign Finance and Public Disclosure Board (the “Board”) voted to stop enforcing contribution limits on coordinated expenditures by political parties to state candidates. The Board’s action responds to the June 30, 2026, U.S. Supreme Court decision in National Republican Senatorial Committee v. Federal Election Commission, which held that federal limits on coordinated party expenditures violate the First Amendment.

Minnesota Statute § 10A.27 governs contribution limits to candidates, including limits on the aggregate amount a candidate’s principal campaign committee may accept from political party units and dissolving principal campaign committees. In addition, Minnesota law treats certain approved expenditures, including coordinated expenditures, as contributions to candidates. The Board concluded that NRSC v. FEC likely invalidates current Minnesota limits on in-kind contributions and coordinated expenditures from political parties to candidates.  The Board determined that the aggregate party limits set forth in Minnesota Statute 10A.27 should still apply to cash contributions from party units and to all contributions from terminating candidate committees.

In practice, this decision opens the door to political party units making more significant expenditures in coordination with their candidates. However, candidates who have signed public subsidy agreements should be aware that in-kind contributions will still count toward their campaign expenditure limits. This decision comes in the middle of a busy campaign season in which all Minnesota state legislators and constitutional officers are on the ballot in November.  We expect the Board to issue further guidance in the coming weeks so that candidates and party units better understand the new rules.

Further background information provided by the Board may be found on its website or here.

Website Tracking Technologies Remain a Litigation Target

Most websites collect information about visitors to enhance user experience and support marketing and sales efforts. Common website technologies – such as cookies, pixels, session replay tools, and chatbots – help businesses improve their website functionality, analytics, and advertising.  However, businesses of all sizes that use these technologies are increasingly becoming targets of website wiretapping claims.

Overview of the Claims

 For the past several years, plaintiffs have sought to apply decades-old wiretapping statutes to modern website technologies.  Claims are being brought in particular under the California Invasion of Privacy Act of 1967 (“CIPA”), the federal Electronic Communications Privacy Act of 1986, and the Florida Security of Communications Act, all of which provide private rights of action and statutory damages between $100-5,000 per violation.  Plaintiffs allege that by deploying website technologies before receiving a visitor’s express consent, companies are unlawfully intercepting or disclosing electronic communications in violation of these statutes.

These claims continue to increase nationwide.  Although most wiretapping claims are brought under California or Florida law, they are not limited to companies headquartered in those states.  Any company using website technologies may become a target.  A small number of plaintiffs’ firms and pro se litigants are fueling huge waves of demand letters and litigation, affecting organizations of all sizes across industries.

Mitigation Considerations

 Website technologies evolve rapidly, as does the legal landscape applicable to those websites. Regularly reviewing and auditing website technologies can help ensure that they remain aligned with business objectives while identifying ways to reduce potential legal risks.

The California Legislature is currently considering Senate Bill 690 which, if enacted, could narrow the scope of certain CIPA-based website tracking claims.  Until the legal landscape becomes clearer, however, companies should work closely with their legal, technology, and marketing teams to proactively identify risk areas, evaluate the necessity of existing website technologies, and implement appropriate governance and consent practices.

Companies that receive wiretapping demand letters or website-tracking complaints should contact experienced counsel to evaluate facts and defenses and develop a strategy for response.  For any questions about assessing or mitigating wiretapping claim risk for your website, please contact Lisa Ellingson or another member of Winthrop & Weinstine’s Data Privacy, Cybersecurity & Artificial Intelligence (AI) team.