Regulations

What Federal Contractors Should Be Watching This Summer

Summer 2026 has arrived with a new wave of artificial intelligence (AI) policy from the White House. On June 2, 2026, President Trump signed an Executive Order titled “Promoting Advanced Artificial Intelligence Innovation and Security” (the Order). The Order directs federal agencies—on aggressive 30‑ and 60‑day timelines, with key deliverables due by July 2, 2026 and August 1, 2026—to harden federal information systems with AI‑enabled defenses, establish a voluntary framework for pre‑release federal access to so‑called “covered frontier models,” and prioritize criminal enforcement against malicious AI‑enabled cyber activity. Although the Order is framed as innovation‑and‑security policy and expressly disclaims any “mandatory governmental licensing, preclearance, or permitting requirement” for new AI models, it will have immediate operational consequences for federal information‑technology and cyber contractors, AI developers, critical‑infrastructure operators, and their service providers.

Continue Reading AI Heats Up: New Executive Order on Promoting Advanced Artificial Intelligence Innovation and Security

In a sharply worded order issued May 18, 2026, the Office of Hearings and Appeals (OHA) of the US Small Business Administration (SBA) remanded the agency’s suspension of ATI Government Solutions, LLC, from the 8(a) Business Development (BD) Program, finding the administrative record so deficient that it could not meaningfully review whether the suspension rested on adequate evidence. The case is Matter of ATI Government Solutions, LLC, SBA No. BDPT-728 (2026), and the decision is a forceful reaffirmation of two bedrock principles of administrative law in the 8(a) suspension context: An agency must articulate its reasoning at the time it acts, and the record it submits on appeal must actually contain the materials the decision-maker relied on. It also arrives at a uniquely fraught moment for 8(a) firms—and ATI, a tribally owned participant suspended on the strength of a hidden-camera video, illustrates exactly the kind of fast, thinly supported enforcement action that seems to have become business as usual for the SBA in recent months.

Continue Reading OHA Remands 8(a) Suspension Built on Hidden-Camera Video

Given the slew of Executive Orders (EOs) last year focusing on diversity, equity, and inclusion (DEI) and roiling the funding and operations of recipients of federal financial assistance such as universities and nonprofits, recipients may be forgiven for passing over EO 14398, dated March 26, 2026. As we’ve been covering (here and here), EO 14398 marks a second phase of the administration’s focus on “racially discriminatory DEI activities.” Where EOs from 2025 focused on broad policy shifts and internal agency operations, 2026 EOs seek prospective operationalization of the administration’s policy preferences by baking restrictions on DEI activities into federal contracts.

Continue Reading Recipients of Federal Financial Assistance Can Look to the New DEI Clause to Prepare for Potential Increased Scrutiny of Their Own Awards

The US Department of Justice’s (DOJ) new Data Security Program (DSP), designed to protect sensitive information and national security-related data from misuse by foreign actors, took full effect on October 6, 2025. The program introduces new restrictions on how companies handle and share sensitive US personal data and government-related data, especially when certain foreign entities are involved. With enforcement underway, companies should understand who is covered, what activities are restricted, and what compliance measures are required. Failure to comply with the rules can result in civil or criminal penalties.

Continue Reading DOJ Launches New Data Security Program—What Your Company Needs to Know

The DoD has finally crossed the CMMC finish line, but for contractors, the race is just beginning. With the Final Rule effective Nov. 10, award eligibility will hinge on a “current” CMMC status in SPRS, backed by annual affirmations and strict compliance. The next two months are critical for getting race-ready. In this Featured Comment

As we have previously covered in this blog, as a result of President Trump’s executive order, Restoring Common Sense to Federal Procurement, the Federal Acquisition Regulation (FAR) is undergoing an extensive and unprecedented rewrite. While many of us were enjoying the relaxation of summer days (drifting away to summer nights), the Trump administration has been busy issuing rolling updates to the FAR, which are poised to dramatically reshape the federal acquisition landscape. On August 14, 2025, the FAR Council told us more (told us more) by issuing draft revisions to FAR Parts 4, 8, 12, and 40. The revisions to FAR Part 12 are particularly noteworthy, as they go to the heart of the executive order’s policy statement that the federal procurement system should be “agile, effective, and efficient” and that “undue barriers” should be removed from federal procurement.

Continue Reading Summer Sun, Something’s Begun, But (Oh, Oh) Those FAR Part 12 Rewrites

For those who grew up gripping a joystick and dodging alien fire in Defender, riding ostriches through floating platforms in Joust, or crossing a hectic freeway in Frogger, winning wasn’t about memorizing rules; it was about adapting fast, reading the patterns, and leveling up. That same urgency now applies to federal information and communication technology (ICT) contractors. A sweeping overhaul of FAR Part 39 has just been released, and while it may not blink and beep like a cabinet in a darkened arcade, it’s just as demanding. There’s no attract mode here. The game has already started.

Continue Reading FAR 2.0 Part 39 in Arcade Mode—How Federal IT Acquisition Just Hit Reset

Over the past few months, the second Trump administration has taken quick actions to suspend and terminate federal awards predating the transition of power. Many of these actions have resulted in the termination of “federal financial assistance”—specifically, grants and cooperative agreements. Organizations that have seen their grants and cooperative agreements terminated have pushed back through the courts with varying success, contending that agencies have acted arbitrarily in violation of the Administrative Procedure Act (APA). While there are many cases, this post provides an overview of three recent decisions in this rapidly developing landscape:

Continue Reading In the Wake of High-Profile Terminations of Grants and Cooperative Agreements, Courts Begin to Weigh In

The U.S. Department of Defense’s Cybersecurity Maturity Model Certification (CMMC) Program will become operational at some point in fiscal year 2025. In October, the DOD issued a Final Rule to address evolving cybersecurity requirements and cyber threats while defining the security controls that DOD intends defense contractors and subcontractors to implement. The program will require