ProductsIntelligencePricingMethodologyContact
TECHNOLOGY, AI & COMPETITION

Whistleblower program compliance

Whistleblower program compliance in the Technology, AI and Competition sector is under active scrutiny from multiple directions, with the U.S. Securities and Exchange Commission's whistleblower program imposing specific requirements on how firms handle internal reporting channels, and the U.S. Department of Justice's Corporate Enforcement Policy creating direct incentives for companies to self-disclose before a whistleblower beats them to it. The European Commission's Whistleblower Protection Directive, now transposed across EU member states, extends mandatory internal reporting obligations to technology firms operating in Europe, including those handling AI systems flagged as high-risk under the EU AI Act. Compliance teams at technology companies are currently auditing their internal reporting procedures against these overlapping regimes, particularly where antitrust conduct, algorithmic decision-making, and data handling create novel disclosure questions.

Watch

  • DOJ Corporate Enforcement Policy: self-disclosure credit vs. whistleblower filing timing
  • EU Whistleblower Protection Directive national transposition gaps still unresolved in several member states
  • SEC Rule 21F-17: enforcement pattern targeting NDAs that chill protected reporting
  • AI Act Article 87 whistleblower protections for reporting non-compliant high-risk AI systems
  • FTC noncompete rule interaction with whistleblower retaliation claims in tech workforce disputes

Recent material activity in Technology, AI & Competition

  • Sep 4, 2026MATERIAL

    FTC settles with payment processor Nuvei for $4.85 million over facilitated merchant fraud and tech support scams

    The FTC filed a complaint and proposed settlement order against Nuvei Corporation and four subsidiaries on September 4, 2026, for opening payment processing accounts for merchants engaged in deception. The $4.85 million …

    Read a full sample brief →
  • Sep 4, 2026MATERIAL

    CISA adds Google Chromium V8 type confusion vulnerability to Known Exploited Vulnerabilities catalog with federal remediation deadline of September 18 2026

    CISA added CVE-2026-85046, a type confusion vulnerability in Google Chromium V8, to its Known Exploited Vulnerabilities catalog on September 4, 2026. Federal agencies face a mandatory remediation deadline of September 18…

    Read a full sample brief →
  • Sep 4, 2026MATERIAL

    DOJ files proposed final judgment against KKR in antitrust consent decree proceeding

    The Department of Justice filed a proposed final judgment and competitive impact statement in United States v. KKR & Co. Inc., et al., published in the Federal Register on September 4, 2026. This filing opens the Tunney …

    Read a full sample brief →
  • Sep 4, 2026MATERIAL

    European Commission adopts final guidelines on exclusionary abuses of dominance, replacing 2009 enforcement priorities

    The European Commission's Directorate-General for Competition published final guidelines on exclusionary abuses of dominance on September 3, 2026. The guidelines replace the 2009 enforcement priorities paper and establis…

    Read a full sample brief →
  • Sep 4, 2026MATERIAL

    China's SAMR publishes second batch of administrative monopoly enforcement cases targeting local protectionism in pharmaceuticals, internet services, and coal

    China's State Administration for Market Regulation (SAMR) released the second batch of cases under its national campaign to eliminate barriers to unified market competition, published September 4, 2026. All three cases i…

    Read a full sample brief →
  • Sep 3, 2026MATERIAL

    FTC extends personalized pricing policy comment period by seven days to September 25, 2026

    The FTC extended the public comment deadline on its proposed enforcement policy statement on personalized pricing from September 18 to September 25, 2026. The proposed statement addresses the use of personal data to set …

    Read a full sample brief →
  • Sep 3, 2026MATERIAL

    FCC issues technical correction to broadband data collection final rule effective July 24, 2026

    On September 3, 2026, the FCC published a correcting amendment to its final rule on the Digital Opportunity Data Collection and modernized Form 477 broadband data program. The correction restores a defined term that was …

    Read a full sample brief →
  • Sep 3, 2026MATERIAL

    CMA finalizes revised merger efficiencies guidance, replacing existing assessment framework under its 4Ps reform programme

    The Competition and Markets Authority published final revised guidance on rivalry-enhancing efficiencies in mergers on September 3, 2026. The guidance replaces the existing text in the Merger Assessment Guidelines and co…

    Read a full sample brief →
  • Sep 3, 2026MATERIAL

    CNIL fines Hôpital Privé de la Loire €500,000 for inadequate patient data security under GDPR

    The CNIL sanctioned Hôpital Privé de la Loire €500,000 on September 3, 2026, for failing to implement adequate security measures protecting patient and related-party health data. The decision sets an enforcement benchmar…

    Read a full sample brief →
  • Sep 2, 2026MATERIAL

    CISA adds SonicWall SMA1000 OS command injection flaw to Known Exploited Vulnerabilities catalog with September 5 federal remediation deadline

    CISA added CVE-2026-83549, an OS command injection vulnerability in SonicWall SMA1000 Appliances, to its Known Exploited Vulnerabilities catalog on September 2, 2026. The addition imposes a federal remediation deadline o…

    Read a full sample brief →