Board of Directors: Fiduciary Duties and Balancing Risk, Reputation, and Long-Term Value

The fiduciary duties of the board of directors form the cornerstone of corporate governance in the United States and most common-law jurisdictions. These duties are primarily comprised of the duty of care, the duty of loyalty, and, increasingly, the duty of good faith. Directors are legally obligated to act in the best interests of the corporation and its shareholders, exercising their responsibilities with diligence, prudence, and integrity. The legal framework governing these duties is largely shaped by state corporate statutes—most notably the Delaware General Corporation Law (“DGCL”)—and an evolving body of case law that interprets and enforces these obligations.

Duty of Care

The duty of care requires directors to make informed decisions after reasonable inquiry, relying on adequate information and deliberation. Courts typically apply the “business judgment rule,” which presumes that directors acted in good faith and in the best interests of the corporation unless there is evidence of gross negligence or misconduct. Directors are expected to stay apprised of material facts, consult with experts when necessary, and actively participate in board meetings. Failure to meet the duty of care can result in personal liability if harm to the corporation or its shareholders occurs as a result.

Duty of Loyalty

The duty of loyalty obligates directors to place the corporation’s interests above their own personal interests, avoiding conflicts of interest and self-dealing. Directors must disclose any potential conflicts and recuse themselves from decisions where their impartiality may be compromised. Breaches of the duty of loyalty are treated seriously by courts, often resulting in heightened scrutiny and potential liability. The duty of loyalty has been extended to encompass not only direct conflicts but also situations where directors may be influenced by relationships or affiliations that could impair their independent judgment.

Duty of Good Faith

Although often considered a subset of the duty of loyalty, the duty of good faith has emerged as a distinct fiduciary obligation. Directors must act with honesty and integrity, eschewing actions taken with improper motives or intent to harm the corporation. Courts have held that intentional dereliction of duty or conscious disregard for responsibilities can constitute a breach of good faith, giving rise to liability even in the absence of self-interest or negligence.

Balancing Risk, Reputation, and Long-Term Value

Modern corporate governance increasingly demands that boards of directors balance risk management, reputational concerns, and the pursuit of long-term value. Directors are expected to implement robust risk oversight mechanisms, identify and mitigate material risks, and foster a culture of compliance throughout the organization. This includes financial, operational, regulatory, cyber, and environmental risks, among others. The board’s role is not to eliminate risk but to ensure that risk-taking aligns with the corporation’s strategic objectives and risk appetite.

Reputation management has become a critical component of fiduciary duty, as public perception and stakeholder expectations can significantly impact corporate value. Directors must monitor and respond to reputational threats, including those posed by social, environmental, and governance (“ESG”) issues. Effective communication, ethical conduct, and responsiveness to stakeholder concerns are essential to safeguarding the corporation’s reputation and sustaining trust in the marketplace.

The pursuit of long-term value requires directors to look beyond short-term financial performance and consider the sustainability of corporate practices. This involves integrating ESG factors into decision-making, assessing the impact of corporate actions on employees, communities, and the environment, and promoting innovation and adaptability. Courts have recognized that boards may legitimately consider long-term interests and broader stakeholder impacts, so long as these considerations ultimately serve the best interests of the corporation and its shareholders.

Legal Trends and Practical Guidance

Recent legal developments emphasize the importance of board oversight and proactive engagement. Directors are increasingly held accountable for failures in risk oversight, particularly in areas such as cybersecurity, regulatory compliance, and crisis management. Shareholder activism and litigation have expanded the scope of potential liability, making it imperative for boards to document their decision-making processes, seek expert advice where appropriate, and maintain transparent communication with stakeholders.

In practice, boards should regularly review and update governance policies, establish clear protocols for managing conflicts of interest, and ensure that directors possess the necessary expertise and independence. Training and education on fiduciary duties, risk management, and evolving legal standards can help directors fulfill their obligations and adapt to changing expectations. Ultimately, balancing risk, reputation, and long-term value is a dynamic process that requires vigilance, integrity, and a commitment to ethical leadership.

This article is related to a CLE program that took place during the ABA Business Law Section’s 2026 Spring Meeting. To learn more about this topic, listen to a recording of the program, free for members.

The views and opinions expressed in this article are solely the author’s own and are presented in the author’s personal capacity. They do not necessarily reflect the views, positions, or policies of the author’s employer or any organization with which the author is affiliated.


Sources

Abuse of Power: A New Ground in France for Declaring Corporate Decisions Null and Void

In a ruling handed down on November 26, 2025,[1] the Commercial Chamber of the French Cour de Cassation (Supreme Court for Judicial Matters) held that an abuse of power (abus de pouvoir) by a corporation’s board of directors may result in the board’s decisions being declared null and void. Although it did not find that such an abuse of power was established in the case before it, the French supreme court nevertheless formally recognized a new ground for nullity in corporate law. This development aligns with the well-established principle of corporate veil and serves as a reminder that the company’s interest must always guide decision-making within corporations.

Case Facts

A French société anonyme (public limited liability company) operated a casino under a public service delegation agreement and owned the buildings in which the casino was located. As the agreement was coming to an end, the company’s board of directors concluded that the corporation faced a risk of losing the buildings, as they could potentially be classified as “reversion assets” belonging to the public domain. To mitigate this risk, the board decided to separate ownership of the real estate from the operation of the casino. Acting on this decision, the company did not apply for renewal of the service contract for the casino and instead leased the premises to a newly incorporated “sister” company specially set up by the majority shareholder, which was subsequently awarded the new public service delegation by the municipality.

Minority shareholders contended that the board’s decision effectively caused the corporation to relinquish a profitable line of business in favor of a newly formed entity controlled exclusively by the majority shareholder. On this basis, they initiated litigation against the corporation and its controlling shareholder, seeking annulment of the corporate decision and related agreements on the ground of abuse of majority power.

Statement of Principle

The court set forth the following principle:

[I]n accordance with Article 1833 of the French Civil Code, a decision of the board of directors of a limited company may be declared null and void for abuse of power only if it is demonstrated that such decision is contrary to the company’s interests and was taken for the exclusive benefit of members of the board of directors or any other specific person, in particular shareholders. The existence of an abuse of power is assessed as of the date on which the challenged decision was made.[2]

In this case, the Commercial Chamber dismissed the appeal, declining to find that abuse of power had occurred. Even though the restructuring adopted by the board resulted in lower corporate profits and benefited the controlling shareholder, it was not demonstrated that the decision was contrary to the corporation’s interest, since it enabled the company to protect a strategic asset.

Scope of the Ruling

This ruling establishes a new ground for declaring corporate decisions null and void. The scope of the ruling extends beyond the mere board of directors of the French société anonyme. The broadened reach of the abuse-of-power doctrine therefore calls for heightened vigilance from corporate managers and their advisers, including where decision-making rules are governed by shareholder agreements or voting agreements. However, the concept remains difficult to establish in practice, as the case at hand illustrates. While the court’s confirmation that an abuse of power may give rise to nullity is unsurprising, the decision raises significant questions, particularly in light of the recent legislative reform governing the nullity of corporate decisions under French law.

Definition of Abuse of Power in a Board of Directors: Substantive Conditions and Terminology

In this ruling, the Cour de Cassation draws on terminology from criminal law[3] to establish a new concept, as evidenced by the extensive publicity given to its decision. The ruling’s statement of principle clearly sets out two cumulative conditions for a board decision to be characterized as abusive. The decision must be

  1. contrary to the corporation’s interest (intérêt social); and
  2. taken for the exclusive benefit of certain persons, such as directors or shareholders.

This definition is close to that of the concept of abuse of majority power (abus de majorité), though it is not identical.

Abuse of Majority Power

In the well-known principle laid down in the judgment of April 18, 1961,[4] the court defined the conditions required to characterize an abuse of majority power: a decision taken (i) for the exclusive benefit of the majority shareholder, (ii) to the detriment of the company’s interest.

In the past, French case law has used the concept of abuse of majority power to examine decisions made by a board of directors,[5] or even by a noncollegial body such as a managing partner,[6] and determine whether such decisions should be declared null and void.

In substance, the conditions for abuse of power closely parallel those of abuse of majority power. It should be noted that the claimants actually brought their case on the basis of an alleged abuse of majority power.

Abuse of Power: Clarifying the Terminology

The terminological distinction between abuse of majority power (abus de majorité) and abuse of power (abus de pouvoir) reflects the need to differentiate between decisions made by a board of directors and decisions made by shareholders. Accordingly, abuse of power refers to a decision taken in the interests of “specific persons,” with board members cited first among them.

As stated in the explanatory note to the judgment, directors “are not, legally speaking, the representatives of the shareholders who appointed them”;[7] they must exercise their mandate in the interests of the company and not in the interests of shareholders,[8] with the legal entity acting as a buffer between the board and the shareholders.

Beyond a terminological clarification, the court appears to confirm the view that directors are vested with a specific “power,” the abuse of which may lead to judicial sanction.[9]

Date of Assessment of the Abuse of Power

The court further clarifies that the abuse of power is assessed as of the date on which the challenged decision was made. This distinction is significant because it precludes the court from considering the actual consequences of the alleged abusive decision when determining whether an abuse of power occurred.

The Broad Scope of Abuse of Power: Vigilance Needed

Applicability to Other Corporate Forms

The ruling was rendered in relation to decisions made by the board of directors of a société anonyme. However, the court’s decision to provide extensive publicity for the judgment suggests that its scope may go beyond this specific context. Substantively, the reference to Article 1833 of the French Civil Code, a provision falling under the section known as “common corporate law,” reinforces the idea that the ruling on abuse of power could apply to all types of corporations.[10]

Extending Abuse of Power to Other Corporate Bodies

This shift from abuse in the exercise of a shareholder’s voting rights to abuse in the exercise of powers attached to a corporate function suggests that abuse of power could extend to all corporate bodies, whether collegial or not. Accordingly, it could apply to the decisions made by the president of a simplified joint stock company (société par actions simplifiée) or the manager of a limited liability company (société à responsabilité limitée).

Ultimately, abuse relates to the exercise of power by any corporate officer, regardless of the legal form of the corporation.

Abuse of Power: No Contractual Avoidance

The likely mandatory nature of this prohibition should serve as a warning to practitioners. Indeed, nothing appears to allow directors, or the shareholders who appoint them, to contractually shield themselves from the risk of a decision being characterized as an abuse of power. This is particularly relevant to shareholder agreements, which often reserve special rights for certain shareholders within management bodies, such as the boards or committees of sociétés par actions simplifiées, whose functions are similar to those of the board of directors of a société anonyme. It is also relevant to individual commitments, voting agreements, etc.

As such, it appears that the contractual agreements among shareholders, whose primary purpose is to protect the company itself, may not prevent a decision from being challenged as an abuse of power. A corporate decision may be challenged on the grounds of abuse of power if it meets both required conditions, even if it complies with the provisions of a shareholder agreement.

Challenges in Establishing the Concept on the Merits

Judicial Reluctance to Recognize Abuse of Majority Power

An examination of case law shows that it is rare for courts to find abuse of majority power[11] and to declare corporate decisions of a shareholder’s meeting null and void on that basis. This reluctance can be explained by the principle that judges should not interfere in the natural affairs of a company. Considering that this case addresses the validity of a decision by a management body (rather than a general meeting), one could expect even greater judicial caution.

The case at hand illustrates precisely the difficulty plaintiffs face in having abuse recognized in the context of a decision adopted by a director.

In this case, the contemplated restructuring involved ending the direct operation of the casino by the corporation that owned the premises—due to the risk to the real estate ownership—and entrusting the operation to a corporation wholly owned by the majority shareholder. The project, which was adopted by the board of directors within the framework of related party transactions, was clearly in the interests of the controlling shareholder. However, its objective was to preserve the company’s strategic real estate assets. Therefore, in the eyes of the judges, abuse of power was not established as the decision did not go against the company’s interests.

Practical Challenge: Should Any Reference to a Majority Be Abandoned?

Through its choice of the term abuse of power, the Cour de Cassation shifted the focus away from the notion of a majority and toward the exercise of an individual director’s prerogatives. In this case, it was the misuse of these prerogatives that the court sought to sanction.

Does this mean that reference to a majority is no longer necessary? That does not appear to be the case since, without the support of a majority, a collective body cannot adopt a resolution. The question of calculating a majority therefore remains in practice when assessing abuse of power. For the purpose of this calculation, the court appears to apply an individualized vote-counting approach, i.e., one vote per director.

Yet, it is legitimate to consider the board’s specific composition. For example, how should the majority of votes be calculated on a board composed partly of independent directors and/or of employee representatives? And what if the directors were pursuing their own separate interests while adopting the same resolution?

Defining the Scope of Nullity

A New Ground for Nullity Without a Statutory Basis

While rejecting the plaintiff’s arguments, the judges affirmed that a decision taken by company directors or officers could be declared null and void where an abuse of power is established. This outcome comes as no surprise, as it is consistent with prior case law related to abuse of majority power.[12] In both cases, the decision may be declared null and void without a specific statutory provision.

Abuse of Power and Reform of the Rules Governing Nullity

Although the decision was rendered under the legal framework in force prior to the entry into force of Order No. 2025-229 of March 12, 2025, which reformed the rules governing nullity of corporate decisions, nothing appears to prevent the sanction from being applied to corporate decisions under the new regime.

That said, applying the “triple test” under Article 1844-12-1 of the French Civil Code regarding the nullity of a corporate decision challenged for abuse of power raises legitimate questions:

  • In its preliminary review of an alleged abuse of power, the judge will have to verify, in particular, that “the consequences of nullity for the company’s interests are not excessive, as of the date of the ruling, compared to the harm to the interests it is meant to protect.”[13] Where abuse of power is established, could the judge refuse to declare the decision null and void, on the grounds that doing so would disproportionately harm the company’s interests at the time the sanction is pronounced, even though the challenged decision itself impaired those very interests at the time it was taken?
  • What about chains of nullities? Could a judge limit the effects of the nullity of a decision for abuse of power, in accordance with the discretionary power granted under Order No. 2025-229 of March 12, 2025?

Irrespective of how these questions may ultimately be settled by future case law, directors and officers are bound to ensure that their decisions are made solely in the interest of the company, without favoring any third party, be it shareholders or directors. The corporate interest must remain the abiding compass guiding all decision-making within the company.


  1. Cass. com., Nov. 26, 2025, No. 23-23363, FS-BR.

  2. Id. ¶¶ 10–11.

  3. The term abuse of power is not new as such. It is used to refer to several criminal offenses, including those attributable to company directors who, “in bad faith, make use of the powers they possess or the votes they hold in that capacity in a manner they know to be contrary to the interests of the company, for personal gain or to benefit another company or undertaking in which they have a direct or indirect interest.” Code de commerce [C. com.] [Commercial Code] art. L. 242-6 (Fr.).

  4. Cass. com., Apr. 18, 1961, Bull. civ. III, No. 175. The principle states that “there is abuse of majority when a resolution has been taken contrary to the general interest and with the sole aim of favoring the members of the majority to the detriment of those of the minority.”

  5. For an example of refusal to annul a board decision on the grounds of abuse of majority, see Cass. com., Feb. 24, 1975, No. 73-14.141.

  6. Cass. com., Jan. 21, 1997, No. 94-18.883.

  7. Notice No. 593 of Nov. 26, 2025.

  8. Id.

  9. According to established doctrine, the prerogatives granted to company directors are based on authority whose misuse must be sanctioned. See, in this regard, Gérard Cornu, Preface to Emmanuel Gaillard, Le pouvoir en droit privé (Economica 1985).

  10. In this regard, see B. Dondero, Note on Cass. com., Nov. 26, 2025, No. 23-23363, JCP E 2025, 1345, FS-BR.

  11. See, for example, the refusal to characterize an abuse of majority power in the case of a merger. Cass. com., June 3, 2003, No. 99-18707.

  12. Nullity confirmed in the context of abuse of majority power in relation to compulsory distribution of profits. See Cass. 3e civ., Feb. 7, 2012, No. 10-17.812, F-D.

  13. Code civil [C. civ.] [Civil Code] art. 1844-12-1, 3° (Fr.).

Emerging Data Center Litigation

This article examines a rapidly emerging wave of litigation targeting data centers on environmental, land use, nuisance, tort, and civil rights grounds and the mass tort, personal injury, and property damage claims likely to follow.

Background

The AI boom has fueled an unprecedented expansion of data centers—particularly “hyperscalers” consuming over one hundred megawatts of continuous power. As these facilities proliferate, they have drawn opposition from local residents, environmental groups, and the “Not In My Backyard” (“NIMBY”) movement, which has begun organizing community groups specifically to oppose data center development.[1] The result is a new and growing class of litigation bringing environmental, land use, nuisance, tort, and civil rights claims against data center projects.

Current Litigation Landscape

Since late 2024, lawsuits challenging data center development have increased across the country. The claims generally fall into four categories: zoning and environmental review challenges, transparency and open-records claims, nuisance and property damage claims, and Clean Air Act and emissions claims.

Zoning and Environmental Review Challenges

Beginning with Coalition for Responsible Data Center Development v. City of Farmington (December 2024), communities have challenged the approvals of data center construction.[2] The Minnesota Center for Environmental Advocacy alone filed four separate actions in 2025 alleging cities bypassed mandatory environmental review.[3] Similar zoning challenges have since been filed in California, West Virginia, New York, South Carolina, Georgia, North Carolina, and Kentucky, collectively targeting facilities ranging from 147 acres to 1,845 acres.[4]

Transparency and Open-Records Claims

A separate line of cases targets the alleged secrecy surrounding data center approvals. In Wisconsin, Midwest Environmental Advocates sued the Public Service Commission for refusing to disclose electrical load data for Meta’s AI campus.[5] In Missouri, residents filed a twelve-count Sunshine Law complaint alleging that city officials held private briefings and released a twenty-nine-page development agreement on a Friday for a vote the following Monday.[6]

Nuisance and Property Damage Claims

Post-construction claims have also emerged. In Newsom & Central VA Marine v. Amazon Data Services, plaintiffs allege that an Amazon data center caused brown water, diminished air quality, excessive noise, and constant blue light flashes.[7] In Oregon, Amazon paid $20.5 million to settle a class action alleging nitrate contamination of a county’s sole drinking water source.[8]

Clean Air Act and Emissions Claims

In a landmark April 2026 case, the Southern Environmental Law Center filed a Clean Air Act citizen suit on behalf of the NAACP against Elon Musk’s xAI, alleging that twenty-seven unpermitted gas turbines powering its Memphis-area data center have the potential to emit over 1,700 tons of nitrogen oxides, 19 tons of formaldehyde, and 180 tons of fine particulate matter annually—in an area already graded “F” for ozone pollution. The NAACP seeks injunctive relief and civil penalties of up to $124,426 per day of violation.[9]

Future Litigation Risks

Data center litigation is still in its infancy, but the claims are likely to escalate. Plaintiffs will almost certainly bring noise and light pollution claims—some residents near data centers claim a pervasive “high-pitched whine” that deters them from going outside.[10] Health-related personal injury claims are also probable, as some research links chronic noise and light exposure to hearing loss, insomnia, and diminished quality of life.[11] Nuisance, mass tort, and class action claims alleging personal injury, property damage, and/or natural resource damages from land temperature increases and contamination of surface water and groundwater from cooling water discharge represent a significant emerging risk.[12] Some research indicates that data center cooling-tower discharge may contain concentrated salts, corrosion inhibitors, biocides, heavy metals, and potentially per- and polyfluoroalkyl substances (“PFAS”). A separate study using NASA satellite data found that data centers may raise surrounding land temperatures by an average of 3.6°F—with extreme cases reaching 16.4°F—affecting over 340 million people globally.[13]

Economic harm claims—driven by the increased electricity and water demand that data centers impose on local infrastructure—are also likely to follow, with one report projecting $225 in additional annual electric costs per household in affected communities.[14] Given these increased costs, plaintiffs are likely to bring claims under utility statutes,[15] or under consumer protection statutes alleging unfair trade practices through shifting of infrastructure costs to ordinary customers.[16] A recent complaint filed before the Federal Energy Regulatory Commission (“FERC”) alleging that data centers unjustly shift electricity costs to consumers is an early indicator of the nature of these potential claims.[17]


  1. Ryan Murphy & Emily Feng, Why More Residents Are Saying “No” to AI Data Centers in Their Backyard, NPR (July 17, 2025).

  2. Complaint ¶ 35, Coal. for Responsible Data Ctr. Dev. v. City of Farmington, No. 19HA-CV-24-5838 (Minn. Dist. Ct., Dakota Cnty. filed Nov. 29, 2024); Our Story, Coal. for Responsible Data Ctr. Dev. (last visited Mar. 17, 2026).

  3. Complaint, Minn. Ctr. for Env’t Advoc. v. City of Hermantown, No. 69DU‑CV‑25‑3448 (Minn. Dist. Ct., St. Louis Cnty. filed Nov. 5, 2025); Complaint, Minn. Ctr. for Env’t Advoc. v. City of Pine Island, No. 25-CV-25-2298 (Minn. Dist. Ct., Goodhue Cnty. filed Oct. 16, 2025); Complaint, Minn. Ctr. for Env’t Advoc. v. City of Lakeville, No. 19HA‑CV‑25‑5103 (Minn. Dist. Ct., Dakota Cnty. filed Aug. 5, 2025); Complaint, Minn. Ctr. for Env’t Advoc. v. City of North Mankato, No. 52‑CV‑25‑568 (Minn. Dist. Ct., Nicollet Cnty. filed Aug. 5, 2025).

  4. City of Imperial v. County of Imperial, No. ECU-004457 (Cal. Sup. Ct. filed Dec. 4, 2025); Hatfield v. TransGas Dev. Sys., LLC, No. 3:25-cv-00714 (S.D. W. Va. filed Dec. 3, 2025); In re FLX Strong v. Town of Lansing Zoning Bd. of Appeals, Index No. EF2026-0069 (N.Y. Sup. Ct., Tompkins Cnty. filed Jan. 29, 2026); Crosby v. Colleton County, No. 2026CP1500021 (S.C. Ct. C.P. filed Jan. 9, 2026); Guido v. Columbia Cnty. Bd. of Comm’rs, No. 2026ECV0297 (Ga. Super. Ct., Columbia Cnty. filed Feb. 25, 2026); Guido v. Columbia Cnty. Bd. of Comm’rs, No. 2026ECV0298 (Ga. Super. Ct., Columbia Cnty. filed Feb. 25, 2026); Hairston Clan v. Stokes Cnty., No. 26CV000198-840 (N.C. Super. Ct., Stokes Cnty. filed Mar. 12, 2026); Franklin Citizens for Responsible Dev. v. City of Franklin Planning & Zoning Comm’n, No. 26-CI-00123 (Ky. Cir. Ct. filed Apr. 2, 2026).

  5. Complaint, Midwest Env’t Advocs., Inc. v. Wis. Pub. Serv. Comm’n, No. 2025-cv-004023 (Wis. Cir. Ct. filed Dec. 9, 2025).

  6. Petition, State of Missouri ex rel. Wake Up Jeffco, LLC v. City of Festus, No. 26SL-CC03024 (Mo. Cir. Ct. filed Apr. 8, 2026).

  7. Complaint, Newsom & Cent. VA Marine v. Amazon Data Servs., Inc., No. 3:25‑cv‑00074 (W.D. Va. filed Sept. 15, 2025).

  8. Alex Baumhardt, Amazon to Pay $20.5 Million Settlement over Northeast Oregon Nitrate Pollution, Or. Cap. Chron. (Mar. 31, 2026).

  9. Complaint, NAACP v. xAI Corp., No. 3:26-cv-74-MPM-JMV (N.D. Miss. filed Apr. 14, 2026).

  10. Ryan Heath, A Data Center Opened Next Door. Then Came the High‑Pitched Whine, Politico (Mar. 11, 2026).

  11. Elan Justice Pavlinich, The Dangers of Data Centers, Env’t Health Project (Feb. 27, 2026).

  12. Laura Paddison, Scientists Have Found an Alarming Environmental Impact of Vast Data Centers, CNN (Mar. 30, 2026).

  13. Id.

  14. Sean O’Leary, Why Data Centers Will Be Economic Development Duds, Ohio River Valley Inst. (Nov. 11, 2025).

  15. For example, claims could be brought under Texas Senate Bill 6, California Senate Bill 57, or Oregon’s POWER Act, among others.

  16. See, e.g., 815 Ill. Comp. Stat. 505; Cal. Bus. & Prof. Code § 17200.

  17. Complaint, Md. Off. of People’s Couns. v. PJM Interconnection, L.L.C., FERC Docket No. EL26-63-000 (filed May 7, 2026) (“PJM’s hybrid methodology broadly socializes to all customers costs that data centers, not existing customers, are driving. That result is unjust and unreasonable and violates the cost causation principles that have long governed transmission cost allocation and that this Commission has repeatedly affirmed.”).

Is Now the Time to Convert Your Farming Partnership to an LLC or S Corporation?

There has been a significant change in the laws governing how farms may be owned and operated. The “how” and “why” are somewhat involved, so bear with us as we explain why reorganizing those properties and operations into limited liability companies (“LLCs”), limited partnerships, or S corporations should now be considered.

Agricultural Real Estate Ownership Issues

There are a variety of issues that must be considered in connection with the ownership and operation of agricultural real estate. Certain states impose limitations on the ownership of agricultural real estate. For example, South Dakota has adopted policies against the ownership of agricultural land by corporations or LLCs, irrespective of whether domestic or foreign,[1] and states such as Iowa have adopted integrated statutes as to “family farms.”[2] Other states have adopted laws that preclude ownership of real estate, agricultural or otherwise, by business organizations that include a “foreign adversary.”[3] At the federal level, acquisitions and transfers of interests in “agricultural land”[4] by a “foreign person”[5] trigger certain reporting obligations,[6] with civil penalties for failure to do so.[7]

Practically speaking, it has been common to hold and operate agricultural real estate in partnership consequent to how certain farm support programs—namely, the Price Loss Coverage and the Agricultural Risk Coverage, each created by the Agricultural Act of 2014 (also known as the “2014 Farm Bill”)—have determined who can receive payments.[8] Until recently, each has provided for certain payments to each person “actively engaged in farming”; where a partnership was used, separate payments (now up to $155,000 per annum) could be made to each partner. However, where a farm was operated through a business entity such as a corporation or an LLC, there was no “look-through” to the natural persons who are themselves actively engaged in farming, and the entity would be treated as a single farmer.[9] This treatment had the effect of dissuading the operation of certain farming operations through business organizations that afford limited liability and, on particular facts, other benefits.

Changes Under the One Big Beautiful Bill Act

This treatment changed under the One Big Beautiful Bill Act (“OBBBA”), which at section 10306 created a new category of entity, a “qualified pass-through entity,” namely:

(A) a partnership . . . ;

(B) an S corporation . . . ;

(C) a limited liability company that does not affirmatively elect to be treated as a corporation; and

(D) a joint venture or general partnership.[10]

It was then provided that:

Payments made to a qualified pass-through entity shall not exceed, for each payment specified in subsections (b) and (c), the amount determined by multiplying the maximum payment amount specified in subsections (b) and (c) by the number of persons and legal entities (other than qualified pass-through entities) that comprise the ownership of the qualified pass-through entity.[11]

This provides a look-through of the qualified pass-through entity to those persons who are themselves “actively engaged in farming,”[12] equivalent to what had previously been reserved for partnerships and joint ventures.[13]

Regulations as to this change in the law were issued on June 2, 2026.[14] Therein it is provided:

Section 10306 of OBBBA amended Section 1001 of the Food Security Act of 1985 to provide equitable treatment of certain entities under the provisions for payment limitations. Payment limitations are the maximum amount that a person or legal entity can receive for any crop year, directly or indirectly, under certain CCC, FSA, and NRCS programs, and payments to legal entities are tracked (“attributed”) through four levels of ownership. Attribution of payments through four levels of ownership of legal entities is applied. When a legal entity is a payment applicant, then the entity itself (the “payment entity”) is attributed the full payment amount and all owners in the first three member levels are attributed an amount equal to their indirect ownership share in the payment entity. In this way, payments are limited to eligible participants comprising the payment entity and owners through the fourth level of ownership. Owners at the member level may be persons or other legal entities, including qualified pass-through entities.[15]

It would appear, although it is less than clear, that an LLC electing to be treated as an S corporation by filing a Form 2553 (Election by a Small Business Corporation),[16] which has the effect of electing into corporate classification even absent a Form 8832 (Entity Classification Election),[17] is not a qualified pass-through entity as contemplated by these rules. The qualified pass-through entity rules encompass “a limited liability company that does not affirmatively elect to be treated as a corporation,” and an LLC filing a Form 2553 does elect into treatment as a corporation. Yes, it is true that the intention is to be treated as a corporation under Subchapter S of the Internal Revenue Code, but Subchapter S is not “a corporation taxed as a partnership”; rather an S corporation is a tax corporation subject to the particular rules of Subchapter S, and, “[e]xcept as otherwise provided in this title, and except to the extent inconsistent with this subchapter, subchapter C shall apply to an S corporation and its shareholders.”[18] Ergo, it would appear that the inclusion of S corporations within the “qualified pass-through entity” category is limited to those organizations ab initio classified as corporations[19] that then elect into Subchapter S.

The Planning Opportunity

This change in the law represents a significant loosening of the effective limitations on owning and operating agricultural real estate as a limited partnership, an S corporation, or an LLC. For example, a farm may now be operated as a corporation or an LLC, thereby yielding the benefits of limited liability. Prior issues with respect to partition of property owned in joint tenancy or in partnership may not exist if held by a corporation, LLC, or limited partnership. Furthermore, in some circumstances, what was once a complex planning framework can evolve into a more streamlined model, lowering administrative costs and allowing farm operators and their advisers to focus less on entity-level compliance and more on core business activities.

As a result of this change in the law, there may be estate planning opportunities available for LLC- or corporate-owned farming operations that may have not previously been available. Every situation is different, and the business and tax laws at issue will need be considered before any reorganization is undertaken.


  1. See S.D. Codified Laws § 47-9A-1.

  2. See Iowa Code §§ 9H.1–9H.5A.

  3. See, e.g., Ariz. Rev. Stat. § 33-443; Ky. Rev. Stat. Ann. § 247.018; Mont. Code § 35-30-103; Va. Code § 55.1-508.

  4. Defined at 7 U.S.C. § 3508(1).

  5. Defined at 7 U.S.C. § 3508(3).

  6. See 7 U.S.C. § 3501; see also 7 C.F.R. § 781.

  7. See 7 U.S.C. § 3502. See generally Federal and State Bills Restricting Property Ownership by Foreign Entities, Committee of 100 (last visited July 9, 2026); Foreign Ownership of Agricultural Land: FAQs & Resource Library, Nat’l Agric. L. Ctr. (last visited July 9, 2026); April J. Anderson, Jason J. Hawkins & Steve P. Mulligan, Cong. Rsch. Serv., LSB11013, State Regulation of Foreign Ownership of U.S. Land: January 2023 to July 2024 (updated Aug. 28, 2024); Margy Eckelkamp, Foreign-Owned Farmland Faces Growing Scrutiny from States and USDA, AgWeb (July 17, 2026).

  8. Pub. L. No. 113-79, 128 Stat. 649; see also Agriculture Risk Coverage (ARC) & Price Loss Coverage (PLC), USDA Farm Serv. Agency (last visited July 9, 2026); Agriculture Risk Coverage (ARC) and Price Loss Coverage (PLC) 2025, USDA Farm Serv. Agency (last visited July 9, 2026); How PLC Works, HarvestFile (last visited July 9, 2026); The Ultimate Guide to Agriculture Risk Coverage (ARC), U.S. L. Explained (last visited July 9, 2026).

  9. Pub. L. No. 119-21.

  10. 7 U.S.C. § 1308(a)(5) (created by OBBBA § 10306).

  11. 7 U.S.C. § 1308(e)(3)(b)(ii).

  12. See 7 C.F.R. § 1400.201; see also Actively Engaged in Farming, USDA Farm Serv. Agency (last visited July 9, 2026); Payment Eligibility, USDA Farm Serv. Agency (last visited July 9, 2026).

  13. See also OBBBA § 10306(b)(2) (“by striking ‘a joint venture or a general partnership’ and inserting ‘a qualified pass-through entity’”).

  14. See Payment Limitation and Payment Eligibility, 91 Fed. Reg. 328800.

  15. Id.; see also Press Release, USDA Farm Serv. Agency, USDA Expands Payment Limitation and Payment Eligibility Provisions for Farmers (June 3, 2026):

    Starting with the 2026 crop year, for payment eligibility purposes, FSA will treat applicable limited liability companies (LLCs) and S-Corporations (S-Corps), and other similar entities, as “pass through entities.” Each member of the qualified pass-through entity who meets actively engaged in farming criteria will help qualify the entity for expanded payments.

    Previously, farm operations that were structured as an LLC or an S-Corp were limited to a single payment limitation, which varies by program. Now, partnerships, S-Corps, qualifying LLCs, and joint ventures or general partnerships will be treated the same.

    For program year 2026 only, farm operations that are structured as LLCs or S-Corps or one of the new qualified pass-through entities must file updated farm operating plans with FSA for program year 2026 by Sept. 15, 2026. After program year 2026, FSA will continue to use June 1 as the date for determining ownership interest in an entity. Producers who have crop insurance or Noninsured Crop Disaster Assistance Program coverage should contact their crop insurance agent or local FSA office before restructuring their farm operation to ensure appropriate timing for restructuring without impacting current insurance coverage.

    Members of qualified pass-through entities must provide contributions and be engaged in farming for the entity to be considered actively engaged in farming.

    An additional change allows members of all entity types to receive compensation for labor and management contributions and use the same contribution to qualify as “actively engaged in farming.” This update provides consistent treatment of member contributions across all entity types.

  16. See About Form 2553, Election by a Small Business Corporation, Internal Revenue Serv. (last visited July 9, 2026).

  17. Internal Revenue Serv., Form 8832; see also About Form 8832: Entity Classification Election, Internal Revenue Serv. (last visited July 9, 2026); Larry R. Ribstein, Robert R. Keatinge & Thomas E. Rutledge, Ribstein and Keatinge on Limited Liability Companies § 19:16 (June 2026).

  18. 26 U.S.C. § 1371(a); Ribstein et al., supra note 17.

  19. See 31 C.F.R. § 301.7701-2(b).

 

Further Assurances Clauses: Making the Implied Covenant Express

This article is Part XIII of the Musings on Contracts series by Glenn D. West, which explores the unique contract law issues the author has been contemplating, some focused on the specifics of M&A practice, and some just random.

It could simply be the Baader-Meinhof phenomenon (i.e., the “frequency illusion”), but I seem to be running into the implied covenant of good faith and fair dealing at every turn lately.[1] Indeed, in a recent Delaware Court of Chancery decision, Facilities Holdings, LLC v. ASM Global Parent, LLC,[2] an express version of the implied covenant was invoked via a standard boilerplate provision—the “further assurances clause.”

While further assurances clauses are generally used to obtain an additional document necessary to fully evidence a transfer of assets in connection with the closing of a sale and purchase transaction,[3] they are not necessarily limited to that purpose,[4] particularly when they appear in an agreement governing an ongoing relationship.

Further assurances clauses have generally been described as “catchall contract provision[s] by which a party, after making a precise commitment to perform in some manner, makes a vague, more general commitment to take other actions that are incidental to, and necessary for, the performance of the core commitment.”[5] While “[s]uch a provision does not create a new obligation,”[6] it may require parties to take additional actions that are consistent with the other express terms of the contract. One commentator has even described a further assurances clause as follows:

A further assurances provision is the exclamation point on the parties’ agreement. In the other parts of the agreement, the parties define their mutual objectives and detail their specific commitments to each other. By contrast, a further assurances provision is a general provision designed to require the parties to exercise a certain degree of effort to achieve the agreement’s overall objectives. It recognizes that parties do not and cannot contemplate and draft for every contingency. Thus, the further assurances provision serves as a gap filler and a back stop.[7]

If that sounds a bit like an express version of the implied covenant’s gap-filling function,[8] it should. One court has even suggested that “how other courts interpret the obligation to behave in good faith may suggest how a court should interpret the language contained in the Agreement’s further assurances clause.”[9]

In Facilities Holdings, the operator and lessee (“Operator”) of certain sports and entertainment venues entered into a concession agreement for each venue and a master agreement covering all venues with the vendor (“Vendor”), who was granted the right to be the exclusive food and beverage vendor at the venues. Each concession agreement provided that if the Operator was sold to a third party, the term would be extended by five years, subject to the approval of the landlord of the applicable venue.

When the Operator was sold to one of the Vendor’s competitors, the Vendor sought to extend the term of the concession agreements as contemplated by their express provisions. The Operator, however, claimed that the landlord of each venue had refused to approve the extension. 

But the Vendor claimed “that behind closed doors, the Operator convinced the landlords to withhold consent so the Operator could replace the Vendor with affiliates of the new owner.”[10] The Vendor alleged that the concession agreements and the master agreement contained an implied covenant of good faith and fair dealing that required the Operator “not to intentionally undermine the landlord’s willingness to consent, such as by advocating that the landlord withhold its consent.”[11]

The Vendor did not suggest that the implied covenant required the Operator “to use affirmative efforts to obtain landlord consent.”[12]

The Vendor claimed, however, that the Operator had breached the express terms of the further assurances clause. That clause (labeled as a “Further Action Provision”) stated:

Subject to the terms and conditions provided in this Agreement, following the date hereof each of the parties shall, as and when requested by another party hereto, execute and deliver, or cause to be executed and delivered, such further certificates, instruments and other documents, and to take, or cause to be taken, such further actions, as may be necessary, proper or advisable under applicable law to evidence and effectuate the transactions contemplated by this Agreement.[13]

Unlike the implied covenant claim, the further assurances claim suggested the Operator had an affirmative obligation to assist the Vendor in obtaining the landlord’s consent.

The Delaware Court of Chancery denied the Operator’s motion to dismiss both claims:

Here, an obligation to “take, or cause to be taken, such further actions, as may be necessary, proper or advisable under applicable law to . . . effectuate the transactions contemplated by this Agreement” required that the Operator provided some level of support for the Vendor in obtaining landlord consent for its extension request. The Further Action Provision did not permit the Operator to seek to convince or induce a landlord to withhold its consent.

For the same reasons that it is reasonably conceivable that the [Operator] breached the implied covenant, it is reasonably conceivable that the [Operator] breached the Further Action Provision. The former only required neutrality and non-harm, yet the Complaint supports an inference that the Operator breached that obligation by engaging in harmful conduct. The Further Action Provision requires affirmative support, so the same alleged conduct supports a breach of that provision.[14]

There can be both peril and delight in contract boilerplate.[15] And it is a transactional lawyer’s job to identify both, preferably at the time of contracting:

Transactional lawyers are not, and should never become, mere “document processors.” They should not be merely filling in the blanks. And boilerplate is not sacred text that must remain unchanged for fear of altering some established meaning. . . . After all, the form doesn’t know anything, but the transactional lawyer must.[16]

Read and understand the potential impact of the seemingly innocuous further assurances clause. Regardless of how they are labeled, such clauses may contain more than is typical. Note that the clause in this case required not only the execution of documents to “evidence” the transactions contemplated by the agreement but also “actions” necessary to “effectuate” those transactions.


  1. See, e.g., Glenn D. West, Is New York ‘Reimagining’ the Implied Covenant of Good Faith and Fair Dealing?, Bus. L. Today (June 18, 2026); Glenn D. West, The ‘Officious Bystander’ and the Implied Covenant of Good Faith and Fair Dealing, Bus. L. Today (May 20, 2026).

  2. Facilities Holdings, LLC v. ASM Glob. Parent, LLC, No. CV 2025-0670-JTL, 2026 WL 1815842 (Del. Ch. June 24, 2026).

  3. And they can be specific or general. See, e.g., Stock and Asset Purchase Agreement by and Among Exodus Movement, Inc., Baanx Corp., W3C Corp., and Garth Howat § 5.04(a) (May 1, 2026) (“Following the Closing, each of the parties hereto shall, and shall cause their respective affiliates to (to the extent such party is legally able to direct such action, or shall otherwise instruct), execute and deliver such additional documents, instruments, conveyances, and assurances and take such further actions as may be reasonably required to carry out the provisions hereof and give effect to the transactions contemplated by this Agreement and the other Transaction Documents. Without limitation to the foregoing, at and after the Closing, and without further consideration thereof, Seller shall execute and deliver to Buyer such further instruments and certificates as shall be necessary to vest, perfect or confirm ownership (of record or otherwise) in Buyer or its designees, Seller’s right, title or interest in, to or under any of the Purchased Assets and Company Intellectual Property, free and clear of all Encumbrances. . . .”); Asset Purchase Agreement Between Red Robin International, Inc., as Seller, and Op Burger LLC, as Buyer § 2.3(c) (June 11, 2026) (“If the parties identify, prior to Closing or within one (1) year after Closing, any assets (tangible or intangible) which are owned by Seller and not included as part of the Purchased Assets and Assumed Contracts and were reasonably necessary for Seller to operate the Purchased Restaurants prior to the Closing in Seller’s ordinary course of business, then Seller shall use commercially reasonable efforts to promptly transfer, convey and/or assign such tangible assets to Purchaser, at no additional cost to Purchaser; provided Seller shall not be obligated to transfer, convey and/or assign any such tangible assets that are Excluded Assets or otherwise set forth on Schedule 3.17.”).

  4. See, e.g., Purchase Agreement Between FireFish TopCo, LLC, as Seller, and Aspire Biopharma Holdings, Inc., as Purchaser § 11.16 (June 10, 2026) (“Each party agrees to execute such additional instruments, agreements and documents and to take such other actions as may be necessary to effect the purposes of this Agreement.”).

  5. Lighthouse Behav. Health Sols., LLC v. Milestone Addiction Counseling, LLC, No. 2022-0979-MTZ, 2023 WL 3486671, at *8 (Del. Ch. May 17, 2023) (citations omitted).

  6. Id.

  7. Tina L. Stark, Negotiating and Drafting Contract Boilerplate 607 (2003), quoted in Facilities Holdings, 2026 WL 1815842, at *21 (emphasis added).

  8. See Johnson & Johnson v. Fortis Advisors LLC, 352 A.3d 229, 251 (Del. 2026) (“The covenant functions as a limited ‘gap-filler’: it enforces the parties’ reasonable expectations in circumstances that they could not foresee and did not address in their written agreement, but it may not be used to rewrite or contradict express terms.”).

  9. Madera Prod. Co. v. Atl. Richfield Co., No. CA 3-96-CV-2951-R, 1998 WL 292872, at *7 (N.D. Tex. June 1, 1998).

  10. Facilities Holdings, 2026 WL 1815842, at *1.

  11. Id. at *12.

  12. Id.

  13. Id *19 (emphasis added).

  14. Id. at *22.

  15. See generally Glenn D. West, The Perils and Delight of Contractual Boilerplate, Bus. L. Today (Apr. 15, 2025).

  16. Glenn D. West, The Form Doesn’t Know Anything: A Response to Chowdhury, Chudkowski & Gulati, 79 U. Miami L. Rev. 628, 630 (2025).

When Selling Gift Cards Makes You a Money Transmitter

A foreign luxury brand decides to sell gift cards in the United States. The cards can be redeemed at any of the brand’s affiliated boutiques, hotels, or restaurants—independently owned businesses that share the brand name and pay the parent a licensing fee. The brand’s headquarters collects the money when the card is sold. Months later, when a customer redeems the card at a participating establishment, the brand wires the redemption value to the establishment, less a small commission.

Read that sequence again. The brand is collecting funds from one person. It is later transmitting those funds to another person. Under federal law (31 C.F.R. § 1010.100(ff)) and the money transmission statutes of essentially every U.S. state, that is the textbook definition of a regulated activity. The brand has—without realizing it, without intending to, without ever calling itself a financial institution—wandered into a regulatory regime built for Western Union.

This is the multi-merchant gift card trap, and it is the most underappreciated compliance risk in cross-border consumer commerce. The trap is not technical. It is conceptual. Lawyers who have correctly concluded that the product is exempt from money transmission rules—because it is closed-loop, because it cannot be cashed out, because it is just a gift card—fail to ask a separate and equally important question about the operator. The product can be exempt while the operator is not. That is the problem.

The Exemption Everyone Reaches For

The instinctive defense is the closed-loop prepaid access exemption at 31 C.F.R. § 1010.100(ff)(4)(iii)(A). The Financial Crimes Enforcement Network (“FinCEN”) does not regulate prepaid access usable only at a defined merchant or set of locations, capped at $2,000 per device per day. A normal gift card fits comfortably inside the exemption.

But this exemption is about the instrument. It says the gift card is not a regulated prepaid access product. It does not say anything about the company issuing the gift card. FinCEN has been explicit on this point: money transmitter status is a facts and circumstances inquiry directed at the entity. An operator can sell perfectly compliant closed-loop instruments and still be a money transmitter—because, separately and independently, it is engaged in the transfer of funds between the cardholder and the merchant.

This is where most analyses stop and most clients get exposed. The law firm tells the client the gift card is a closed-loop instrument. The client hears that and stops worrying. But the closed-loop analysis is one question. The operator-status analysis is another.

The Exemption That Actually Saves You

The exemption that does the real work is harder to invoke and almost never appears in the marketing materials of fintech consultants: the agent-of-the-payee doctrine.

The doctrine is straightforward in concept. If I, as an operator, am collecting money from a customer not on my own behalf but as the appointed agent of the merchant who will eventually deliver the goods or services, then the customer’s payment to me is—in the eyes of the law—a payment to the merchant. The merchant’s obligation to the customer is extinguished at that moment. What I do later, when I send the merchant their share, is not a transmission of funds between strangers; it is an internal settlement between principal and agent.

FinCEN recognizes a federal version of this concept through the payment processor exemption, articulated in administrative rulings FIN-2013-R002 and FIN-2014-R009. Several states have codified an explicit agent-of-the-payee exemption: Texas in Finance Code § 152.004(2), and California in Financial Code § 2010(l). The federal version requires four cumulative conditions: facilitation of a purchase or bill payment, operation through a clearance and settlement system, conduct under a formal agreement, and that agreement existing with the seller or creditor. The state versions follow similar lines, with one critical addition: the payment to the agent must immediately extinguish the customer’s obligation to the merchant.

The doctrine works. But—and this is the part that gets clients into trouble—it does not work automatically. It has to be built. Specifically, it has to be built into the contracts between the operator and the participating merchants, in advance, with language that does precise work.

What the Contracts Actually Have to Say

Here is what makes a multi-merchant program look like an agent-of-the-payee arrangement, and what makes it look like unlicensed money transmission instead.

The first thing the contracts must do is appoint the operator as agent. Not implicitly, not by course of dealing, not through the inference that operating a network creates an agency relationship. Explicitly. The merchant agreement must contain language designating the operator as the merchant’s authorized collection agent for purposes of accepting customer payments under the program.

The second thing the contracts must do is collapse the timing of payment. The agreement must state that the customer’s payment to the operator constitutes payment to the merchant for purposes of the underlying transaction, and that the customer’s obligation to the merchant is extinguished at that moment. This is the legal fiction that turns the operator’s later remittance into an internal settlement rather than a separate financial transmission. Without this language, the operator is sitting on the customer’s money for weeks or months as a kind of escrow agent, which is functionally indistinguishable from money transmission.

The third thing the contracts must do is constrain the destination of the funds. Settlement may flow only to the merchant who actually delivered the goods or services to the customer. Any flexibility in the operator’s discretion to send funds elsewhere—to other merchants, to third parties, to customer refunds outside the program—undermines the agency characterization. The agent has authority only to do what the principal authorized.

The fourth thing—and this one is structural rather than contractual—is that the settlement flow must use the regulated banking system. FIN-2014-R009 is explicit: where disbursement occurs outside a clearance and settlement system populated by Bank Secrecy Act–regulated financial institutions, the payment processor exemption is unavailable. Settlement by bank wire to the merchant satisfies this. Settlement by some bespoke mechanism—internal balance transfers, holding-account redirections, anything that bypasses regulated intermediaries—does not.

These four elements, taken together, are the architecture of compliance. None of them shows up in a “consumer terms and conditions” review. All of them must be in place before the first card is sold.

Why Florida Is the State That Matters

The agent-of-the-payee defense is not equally available everywhere. Most states either codify the exemption (Texas and California) or recognize it through interpretive practice (New York). One state does not, and that state is Florida.

The Florida Money Transmitters’ Code (chapter 560) lacks both an explicit agent-of-the-payee exemption and a clean closed-loop exemption. The Office of Financial Regulation has indicated, in declaratory statements addressed to similar fact patterns, that an entity that receives funds before transmitting them to a third party may qualify as a money transmitter even when contractually structured as the merchant’s agent. Florida looks at the economics—was money received and then sent onward?—rather than at the contract papering.

For a national program, this means Florida is the residual risk point. The contractual mitigations that solve the problem in Texas, California, and New York are not bulletproof in Florida. The structural mitigations—settlement through regulated channels, demonstrable absence of operator control over funds, ideally a payment-processing intermediary that holds the customer’s money rather than the operator itself—have to do more work in Florida than elsewhere. Counsel advising on national rollouts should treat the Florida analysis as the binding constraint, not the average state.

The Sentence That Should Appear in Every Memo

Here is the sentence that should appear, in some form, in every legal memo regarding a multi-merchant gift card program: “The product is closed-loop. The operator may not be.”

The product analysis and the operator analysis are different analyses. They reach different exemptions, require different evidence, and need to be performed in parallel. A program that has answered only the product question has addressed only half the problem.

The clients who get this wrong are not negligent. They are well-advised by lawyers who answered exactly the question they were asked. The question they were asked was “Is this gift card legal?”—and the answer was “Yes, it is closed-loop.” The question they were not asked, and that no one thought to raise, was “And what about the company selling them?”

In a multi-merchant network, that second question is the entire ball game. If the merchant agreements were drafted by someone thinking about brand standards and revenue share—which is to say, by someone who was not thinking about the Bank Secrecy Act—the operator is exposed. Not theoretically. Actually. The federal and state money transmission regimes do not require an intent to operate as a money transmitter, and they do not forgive operators who happened not to know what they were doing.

The fix exists. The fix is the agent-of-the-payee doctrine, properly papered, structurally consistent, and tested against the strictest applicable state regime. But the fix has to be built before the first card is sold. After the fact, what counsel can offer is not a defense but a remediation project—and an explanation, to a regulator, of what the company thought it was doing.

That is a conversation no general counsel wants to have. It is also a conversation that becomes inevitable the moment someone in the boardroom says, “Don’t worry, it’s just a gift card.”

Germany Market Entry for U.S. Companies: Structure Considerations

Germany remains one of the most attractive European markets for U.S. companies seeking international expansion. Its central location, strong industrial base, sophisticated customer markets, and access to the wider European Union make it a natural choice for businesses looking to establish a European presence. At the same time, a successful entry strategy involves more than commercial planning. Legal structure, company formation, liability allocation, tax coordination, employment compliance, data protection, and corporate governance should be addressed at an early stage.

For U.S. companies, the key question is often not whether Germany is an attractive market, but how the German presence should be structured. A business may begin with sales activities, local employees, a distribution arrangement, a branch office, or a German subsidiary. Each option has different legal, operational, and governance implications.

Why Germany remains a key market entry destination for U.S. companies

Germany offers U.S. companies access to one of Europe’s largest economies and to a highly developed business environment. For technology providers, industrial suppliers, healthcare businesses, professional service providers, and consumer brands, the German market can serve both as a stand-alone target market and as a gateway for broader EU expansion. The choice of a Germany market entry structure is often driven by practical considerations: proximity to customers, regulatory requirements, local contracting expectations, employment plans, distribution channels, and the need to demonstrate a long-term commitment to European business partners. In many sectors, German customers and public-sector clients also expect a reliable local presence, clear points of contact, and a legally robust contractual setup.

From a legal perspective, market entry in Germany should therefore be planned as a structured process. The right vehicle depends on the business model, expected revenue, risk exposure, staffing plans, and regulatory environment, and the relationship between the U.S. parent company and the German operation.

Choosing the right structure for market entry in Germany

U.S. companies typically consider several options when entering the German market. These include direct cross-border sales, commercial agents or distributors, a representative office, a registered branch office, or a German subsidiary. For U.S. readers, the terminology can be important: a representative office is generally limited to preparatory or auxiliary activities and should not operate as a full trading business; a branch office is an extension of the U.S. company registered for German business activity; and a subsidiary, such as a GmbH, is a separate German legal entity.

Direct sales may be sufficient for a first market test, particularly where the business does not require local personnel, warehousing, or regulated activities. However, once the company establishes a more permanent presence, hires employees, signs local contracts, or assumes operational obligations in Germany, a more formal structure is often advisable. These developments may also raise permanent establishment or taxable presence questions and should be coordinated with German and U.S. tax advisers before operations expand.

For many businesses, planning for company formation in Germany focuses on whether to establish a German subsidiary or register a branch office with the German commercial register (Handelsregister). A subsidiary creates a separate German legal entity, while a branch remains legally part of the foreign company. This distinction is important for liability, contracting, accounting, governance, tax, and market perception.

There is no single structure that fits every U.S. business; the decision should be based on the intended market role of the German operation. A sales office with limited functions may require a different setup than a production site, a regulated service provider, or a European headquarters.

When a GmbH is the most practical entry vehicle

The most common corporate form for foreign investors in Germany is the Gesellschaft mit beschränkter Haftung, or GmbH. For many U.S. companies, a GmbH is the most practical vehicle because it is familiar to German customers, banks, suppliers, and authorities. It also provides a clear liability structure and can be operated as a wholly owned subsidiary of the U.S. parent company.

A GmbH structure is commonly used for sales operations, service delivery, holding functions, product distribution, software businesses, manufacturing support, and local management structures. The statutory minimum share capital of a GmbH is EUR 25,000, with at least EUR 12,500 generally required to be paid in before registration.

Forming a GmbH usually requires notarized articles of association, the appointment of one or more managing directors, the opening of a German bank account, payment of the share capital, and registration with the commercial register. Depending on the ownership structure, U.S. corporate documents may need to be provided in suitable form, potentially with notarization, apostille, and certified translation.

For U.S. parent companies, it is important to define early who will act as managing director of the German GmbH. German managing directors have their own statutory duties and responsibilities, so they are not merely local representatives of the U.S. parent company. In certain circumstances, they can face personal liability exposure, particularly in relation to insolvency filing obligations, tax compliance, and social security contributions. This can create practical governance questions where decision-making is intended to remain centralized with the U.S. entity.

Branch office or subsidiary: What matters in practice

A registered branch office can be attractive where a U.S. company wants to establish a German presence without incorporating a separate legal entity. It may conduct business locally and enter into contracts, but it is not legally independent from the U.S. parent company. By contrast, a representative office should generally be understood as a limited local presence for preparatory or liaison activities rather than a vehicle for full commercial operations.

That distinction has practical consequences. Because the branch is part of the foreign company, liabilities arising from the German branch generally remain liabilities of the U.S. company. The branch must also be registered with the German commercial register if it qualifies as an independent branch. In addition, local trade registration, tax registration, permanent establishment analysis, and business correspondence requirements may apply.

A branch office may be suitable for certain market-entry scenarios, particularly where the German activity is closely integrated into the foreign company and the business does not require a separate German liability shield. However, many U.S. companies prefer a subsidiary when they want clearer separation between the German business and the U.S. parent, or when German customers, investors, or contractual partners expect a local company.

The choice between branch office and subsidiary should therefore not be made solely on perceived setup speed or cost. Liability, tax, and accounting issues, regulatory requirements, customer expectations, and future exit options should all be considered.

Company formation in Germany: Issues U.S. businesses should address early

Foreign investors can establish German companies, including a GmbH, but the formal requirements should be prepared carefully in advance. A U.S. corporation or limited liability company may act as shareholder of a German GmbH, and foreign individuals may also hold shares. The required documentation, proof of representation authority, and any notarization or legalization steps should be coordinated before the German notary appointment.

U.S. companies should address the following points early in the formation process:

  1. The ownership structure of the German company must be clear. If the shareholder is a U.S. corporation or LLC, German notaries and the commercial register will usually require evidence of existence and representation authority. This can involve business registry extracts, certificates of good standing, secretary certificates, notarized documents, apostilles, and translations.
  2. The managing director structure should be planned carefully. A German GmbH may have one or more managing directors. They do not necessarily have to be German citizens or German residents, but practical issues such as bank onboarding, tax communication, immigration status, and operational availability should be considered when deciding whether to appoint a German citizen or resident.
  3. When completing the formation paperwork in Germany, the company name and business purpose should be reviewed before notarization. The name must generally be distinguishable and suitable for entry in the commercial register. The business purpose should be broad enough to support the intended activities, but sufficiently clear for commercial register and licensing purposes.
  4. Opening a bank account for the German company can pose timing issues: German banks may conduct detailed know-your-customer checks, especially where foreign shareholders are involved. Delays in bank onboarding can affect the payment of share capital and therefore the registration timeline.
  5. Tax registration, Value Added Tax (“VAT”) treatment, permanent establishment questions, payroll setup, and accounting processes should not be treated as afterthoughts. For many U.S. businesses, German tax and employment compliance begins shortly after incorporation or even before active trading starts.

Corporate governance in Germany: What U.S. parent companies should keep in mind

Corporate governance considerations are particularly important where the German entity is part of a U.S.-led group. German law distinguishes between shareholder control and management responsibility. In a GmbH, the shareholders may issue instructions to the managing directors, but the managing directors remain subject to their own legal duties.

This can differ from the way some U.S. businesses manage subsidiaries internally. A German managing director must consider German corporate law, capital maintenance rules, insolvency filing obligations, tax duties, accounting obligations, social security matters, and employment-related responsibilities. Internal group reporting lines do not override these statutory obligations, and failures in these areas may create personal liability risks for managing directors.

For German listed stock corporations, the German Corporate Governance Code sets out principles, recommendations, and suggestions for management and supervision. A typical GmbH subsidiary or German branch is not a listed company and is not the primary target of the Code. However, its broader concepts—transparent management, effective supervision, conflict management, and reliable reporting—can still be useful reference points for larger private groups.

For a U.S. parent company, corporate governance in Germany should be translated into practical internal rules. These may include approval thresholds, reserved matters, reporting duties, signing authorities, escalation procedures, compliance policies, and documentation standards. The goal is to allow the U.S. parent to maintain strategic oversight while ensuring that the German management can meet its local legal obligations.

A robust German corporate governance structure is especially important where the German company hires employees, enters into long-term contracts, handles regulated products, processes personal data, or assumes financial risk. For U.S. companies that process customer, employee, or marketing data in Germany, the EU General Data Protection Regulation (“GDPR”) and German data protection rules may require a local compliance concept for notices, lawful bases, processor agreements, data transfers, retention, and incident response.

Common mistakes in planning Germany market entry

Many market entry projects face difficulties not because the commercial strategy is flawed, but because legal and governance issues are addressed too late.

A common mistake is choosing the legal structure based only on initial setup costs. A branch office may appear simpler, but it may not provide the liability separation, customer confidence, or governance clarity that a subsidiary can offer. Conversely, a GmbH may be more than is needed for a limited market test.

Another recurring issue is underestimating formation timelines. Notarization, document legalization, bank onboarding, commercial register review, and tax registration can take time, especially where U.S. entities are involved in the ownership chain.

U.S. companies also sometimes appoint managing directors without clearly defining their authority, reporting lines, and internal approval requirements. This can create uncertainty in day-to-day operations and may expose the German management to avoidable risks.

Tax and employment issues are also frequently considered too late. Hiring employees in Germany, creating a local sales function, or signing German customer contracts can trigger compliance obligations that should be coordinated before those operations begin. German employee protection rules, notice periods, payroll withholding, social security registration, and, depending on the size and structure of the workforce, works council considerations can become relevant practical issues for U.S. businesses.

Finally, some businesses assume that U.S. templates can simply be rolled out in Germany. In practice, group policies and contract standards often need to be adapted to German law and local market practice, including employment rules, data protection requirements, corporate formalities, consumer protection rules where relevant, and mandatory German-language or disclosure requirements.

For U.S. companies, entering the German market is both a commercial opportunity and a legal structuring exercise. Whether a business begins with direct sales, a representative office, a branch office, or a German subsidiary, the decision should be based on a clear understanding of liability, governance, tax, employment, data protection, and operational requirements.

In many cases, a GmbH offers the most practical and credible structure for a long-term presence in Germany. That said, the right approach will always depend on the company’s entry strategy, risk profile, and growth plans. Planning these issues early can help avoid delays, governance gaps, and unnecessary restructuring. Businesses that address company formation, management duties, and corporate governance from the outset are usually in a much stronger position to build a stable and scalable presence in Germany.


FAQ: Germany market entry, GmbH formation, and corporate governance

What is a GmbH in Germany?

A GmbH is a German limited liability company. It is one of the most widely used corporate forms for foreign investors and is commonly chosen by U.S. companies establishing a German subsidiary. The GmbH has its own legal entity status, separate from its shareholders.

Can a foreigner create a GmbH in Germany?

Yes. Foreign individuals and foreign companies can establish a GmbH in Germany. A U.S. company can be the sole shareholder of a German GmbH. However, foreign corporate documents must usually be prepared in a form acceptable to the German notary and the commercial register.

How much does it cost to set up a GmbH in Germany?

The statutory minimum share capital of a GmbH is EUR 25,000. In addition to share capital, formation costs usually include notary fees, commercial register fees, translation or legalization costs where required, tax and accounting setup costs, and legal support if the structure is more complex.

What is the corporate governance code in Germany?

The German Corporate Governance Code sets out principles, recommendations, and suggestions for the management and supervision of German listed stock corporations. For listed companies, certain statutory disclosure obligations relate to the Code. A typical GmbH subsidiary is not itself a listed company, but the Code can still provide useful guidance on broader governance standards.

What is the corporate governance structure in Germany?

German corporate governance depends on the legal form. In a GmbH, shareholders exercise control through shareholder resolutions, while managing directors conduct the business and are subject to statutory duties. Larger companies or stock corporations may involve supervisory boards and more formal governance structures.

Mishandling Gender Identity Information Could Cost Your Life Sciences Company Millions

Pharmaceutical and medical device companies increasingly collect gender identity data in clinical trials, patient support programs, and direct-to-patient (“DTP”) marketing. The aim is usually positive: increase representation, improve inclusion, or meet regulatory expectations. But mishandling this data carries real risks.

Under modern privacy frameworks, gender identity is treated as a form of sensitive data. Improper collection, storage, or use can trigger regulatory fines, lawsuits, reputational harm, and even investor scrutiny. For companies regulated by the Food and Drug Administration (“FDA”), those risks overlap with advertising, research integrity, and fraud/abuse oversight requirements. This means that what begins as a privacy misstep can quickly escalate into a full-blown business risk.

The Legal Regime: Data Privacy and Gender Identity

European Data Protection: The GDPR

The European Union’s General Data Protection Regulation (“GDPR”) applies to some activities originating within the United States, and U.S. life sciences companies need to pay attention to how it may affect their handling of gender identity data. The GDPR explicitly protects “special categories” of personal data, including health, sexual orientation, and biometric data. The EU generally legally recognizes that an individual can express a gender identity different from the one assigned to them at birth. Failure to accurately record a person’s chosen gender identity or not processing it where assigned sex at birth is not relevant would generally be seen as inconsistent with the GDPR principle of data accuracy.

U.S. State Laws: CCPA/CPRA and Beyond

A growing number of U.S. states have enacted privacy laws that may apply to gender identity data. In California, for example, the California Privacy Rights Act (“CPRA”) expanded the California Consumer Privacy Act (“CCPA”) to cover “sensitive personal information.” This includes traits such as sexual orientation and other markers tied to identity. Consumers can limit use of sensitive information to only what is “necessary” to deliver expected services.

The California attorney general has pursued California privacy law enforcement aggressively. Virginia, Colorado, and more than a dozen other states have adopted similarly comprehensive privacy laws. Depending on the jurisdictions they operate in, companies that mishandle identity data may risk scrutiny from multiple regulators simultaneously.

Data Mishandling and Discrimination Claims

As discussed, company policies for handling gender identity data should consider privacy law risks. However, they should also consider potential antidiscrimination law risks. Common pitfalls in the life sciences context include those below:

Scope Creep and Reuse

Clinical trial sponsors may initially collect gender identity for inclusion tracking but later reuse it for targeted marketing without consent. Vendors may repurpose identity data for unrelated analytics. Such actions are increasingly framed not as privacy errors but as profiling and discrimination.

Tokenism in Clinical Research

Claiming that a clinical trial is inclusive of transgender people without conducting meaningful subgroup analysis or including related endpoints can also lead to reputational and legal risk. Plaintiffs may argue that data was collected under false pretenses, creating exposure for deceptive or discriminatory practices.

Business Consequences of Mishandling Gender Identity Data

Regulatory Penalties

  • GDPR fines: up to 4 percent of global turnover.
  • CCPA/CPRA enforcement: fines up to $7,500 per violation.
  • Corrective actions: regulators may require ongoing audits or data protection impact assessments (“DPIAs”).

Litigation Exposure

Privacy claims are increasingly bundled with discrimination and emotional distress allegations. Class actions can demand wide discovery, exposing vendor contracts and internal emails, and settlements often result simply to avoid reputational damage.

Reputational Fallout

Stories about companies and even government agencies allegedly mishandling or not adequately protecting gender identity data attract significant media coverage. Environmental, social, and governance (“ESG”) investors track governance issues related to marginalized groups closely, and activist campaigns can magnify even small missteps. Additionally, in the context of clinical research, subjects are supposed to be anonymized, and sponsors who turn over data to governmental authorities in response to a subpoena without mounting a significant challenge, or otherwise mounting a loud retreat, may discover that passive turnover of data constitutes a loss of trust and could result in reputational damage not only with targeted subjects, but also with patients as a whole.

Investor and Board Scrutiny

In M&A or private equity due diligence, weak gender identity data governance may be flagged as a material risk. Whistleblowers or employee advocates can raise red flags that disrupt deals or trigger post-closing disputes.

Best Practices for Life Sciences Companies

  1. Data Mapping and Classification: Treat gender identity data as high-risk data, similar to medical or biometric information.
  2. Purpose Limitation and Consent: Obtain explicit consent for collection and secondary use, especially in marketing.
  3. Access Controls: Compartmentalize data access and log usage. Consider anonymization or encryption.
  4. Vendor Oversight: Require contracts to limit use, enforce deletion in accordance with legal and policy requirements, and permit audits. Flow obligations down to subcontractors.
  5. Correction and Inclusion: Allow participants to update their gender identity data and offer options that enable them to indicate their gender identity accurately, including nonbinary or self-describe options.
  6. Transparency: Update privacy notices with clear language on why gender identity data is collected and how it is shared.
  7. Audits and Data Protection Impact Assessments (“DPIAs”): Conduct regular privacy impact assessments that specifically evaluate gender identity data risks.
  8. Training and Governance: Educate clinical, marketing, and IT teams on sensitive data risks. Establish a privacy governance committee with oversight over gender identity data.

Conclusion

For companies working in life sciences and adjacent sectors, mishandling gender identity data is more than a privacy problem and can escalate to become a trust problem. With regulators, plaintiffs’ attorneys, and investors watching closely, the business consequences are steep.

California Court Finalizes Summary Judgment in Favor of OppFi, Rejects DFPI’s ‘True Lender’ Theory

On May 19, 2026, the Superior Court of California, County of Los Angeles, granted summary judgment in favor of Opportunity Financial, LLC (“OppFi”) in its dispute with Clothilde Hewlett, in her official capacity as Commissioner of the Department of Financial Protection and Innovation for the state of California (“DFPI”) at the time of filing. Opportunity Fin., LLC v. Hewlett, No. 22STCV08163 (L.A. Cnty. Sup. Ct. May 19, 2026). This finalized ruling comes shortly after the tentative decision granting summary judgment in favor of OppFi on February 24, 2026.

Dating back to 2022, the litigation focused on whether OppFi violated California’s interest rate caps under the Fair Access to Credit Act (AB 539), which capped interest rates at 36 percent on consumer loans between $2,500 and $9,999 made by “finance lenders” under the California Financing Law. The DFPI filed a cross-complaint alleging that OppFi was the “true lender” on loans originated through its partnership with FinWise Bank, a Utah state-chartered bank. It further described the arrangement as a “rent-a-bank” scheme to evade California’s rate cap, noting that Utah does not impose an interest rate cap. The DFPI sought penalties of at least $100 million and restitution for approximately 38,000 California borrowers. OppFi filed its own cross-complaint in response, arguing that the DFPI’s adoption of the true lender doctrine without notice-and-comment rulemaking constituted an invalid “underground regulation” under California’s Administrative Procedure Act (“APA”).

In what will be a precedent-setting decision respective to the treatment of bank partner programs, the court granted summary judgment that rejected the DFPI’s true lender claims on the grounds that the DFPI could not demonstrate FinWise was “merely a dummy” lender. Applying the framework of Janisse v. Winston Investment Co. (154 Cal. App. 2d 580 (1957)), the court found the undisputed evidence showed that FinWise controls the application and underwriting process, funds loans with its own money, retains title and ownership, bears 100 percent of the risk of loss at origination, retains a 2 percent to 5 percent interest in receivables, controls marketing, and oversees legal and regulatory compliance.

The court found that the DFPI failed to raise a triable issue of material fact. On receivables, the court held that FinWise’s post-origination sale of loan receivables could not render the loans usurious because under California law, “a contract, not usurious in its inception, does not become usurious by subsequent events.” The court relied upon Section 27 of the Federal Deposit Insurance Act and the FDIC’s “valid when made” rule, 12 C.F.R. § 331.4(e), which provides that the sale, assignment, or transfer of a loan does not affect the permissibility of interest, and such interest is determined when the loan is made. On the issue of underwriting, the court rejected the argument that OppFi’s ownership of the intellectual property to its credit model made it the lender, noting that banks routinely use third-party models such as FICO scores without making the model owner the lender. On funding, the court found no evidence that OppFi’s collateral account was ever used to fund loans, observing that OppFi provided unrebutted evidence that the account was “almost always insufficient” to cover FinWise’s funding obligations. The court also noted that the collateral account merely secured OppFi’s obligation to purchase receivables and was not used to fund the program loans.

Due to the primary ruling, OppFi’s cross-complaint challenging the true lender doctrine as an underground regulation was dismissed, without prejudice, as being moot. Even so, the claim remains significant because it leaves a broader question undetermined: whether the DFPI’s asserted “true lender” doctrine is even lawful under the APA. As Scott Hyman, Justin Bradley, and Paul Soter have observed, California’s APA prohibits state agencies from enforcing rules not adopted through notice-and-comment rulemaking, and courts afford “no deference at all” to noncompliant regulations. As federal deregulation reduces enforcement at the national level, states are expected to pursue more aggressive theories, making the underground regulation doctrine “more critical for regulated companies.” Further, “application of a ‘regulation-by-enforcement’ philosophy similar to that of the former [Consumer Financial Protection Bureau] Chairman’s famous ‘compliance malpractice’ statement would run afoul of California’s prohibition against underground regulation.” The court’s treatment of the underground regulation issue may signal a warning to the DFPI against pursuing the industry under unwritten rules.

This decision is significant to financial services companies and fintech programs involving contractual partnerships with depository institutions, as it upheld the validity of these programs against “true lender” claims. OppFi illustrates the importance of well-developed programs and specified key indicators of the requisite bank involvement, including independent underwriting authority, funding with the bank’s own capital, economic risk retention, and marketing and regulatory compliance oversight. These key indicators, coupled with evaluating for usury at inception, are instructive criteria for bank partner programs operating in California. While this ruling would make it more difficult for the DFPI to pursue true lender actions in the future, we would expect the DFPI to appeal the ruling, and it has sixty days to do so.

Legal Ethics and Practical Considerations for Business Lawyers Using AI in Modern Legal Practice

In recent years, the topic of artificial intelligence (“AI”) has quickly dominated conversations across various industries, institutions, and sectors. The legal profession is no exception; AI usage is embedded in nearly every aspect of modern legal practice.

At the ABA Business Law Section’s Spring Meeting in Atlanta, GA, Monika McCarthy, Managing Director & General Counsel at CrossCheck Compliance LLC, moderated a CLE program offering actionable insights for this era, titled “AI, Esq.? Legal Ethics and Practical Considerations for Business Lawyers.” The panel included speakers César Escovar, Senior Manager of Compliance Advisory at Capital One; Sarah Gatti, Head of Legal at Zappi; Tammy Malvin, Partner at Akerman LLP; and Drédeir Roberts, Founding Member at Drédeir Law. Drawing on their combined experience from governance, regulatory, litigation, and transactional practice, the panel explored how lawyers can responsibly integrate AI into their practices in compliance with legal ethics obligations, while also emphasizing certain nondelegable aspects and limitations of AI.

As background, ABA Formal Opinion 512 provides that “to ensure clients are protected, lawyers using generative [AI] tools must fully consider their applicable ethical obligations, including their duties to provide competent legal representation, to protect client information, to communicate with clients, to supervise their employees and agents, to advance only meritorious claims and contentions, to ensure candor toward the tribunal, and to charge reasonable fees.” Formal Opinion 512’s guidance confirms that lawyers’ use of generative AI does not relieve them of existing ethical rules and that there is no “AI exception” to professional responsibility.

The panel presented examples and key takeaways drawn from ABA Model Rules of Professional Conduct to demonstrate the various instances where lawyers, as well as judges, have professional responsibilities to ensure accuracy, informed judgment, and supervision of AI-generated content.

As the panel’s slides noted, “AI tools are increasingly used for legal research, drafting, discovery, litigation strategy, transactional work, and enterprise governance.” While Model Rule 1.1 (competence) means it is crucial for lawyers to know how generative AI works conceptually, it is not necessary for lawyers to understand the technical aspects of it, such as coding. By having a working knowledge of AI tools, lawyers can show that they are continuously staying abreast of how technological advancements are impacting the way they serve their clients and their ability to provide effective representation. However, consulting or relying solely on AI experts is not enough; the panel encouraged lawyers to also consult with information security and privacy experts as part of their AI literacy training in order to draw on new perspectives and establish greater competency to meet enterprise or client needs.

From a compliance standpoint, the panel noted that while AI is not considered a legal entity, courts have a tendency to treat it as an operational agency acting on behalf of the company. When inputting data into generative AI, lawyers are bound by strict confidentiality (Model Rule 1.6) and must protect against third-party data usage. They should be able to map the data flow and understand how pass-through data are being handled, including aggregate or anonymized data. To ensure proper handling of AI data, lawyers must establish vetting protocols to ensure the third-party vendor’s management processes and data policies do not pose risks to the enterprise and client.

When communicating with clients (Model Rule 1.4) or submitting legal documents to the courts (Model Rule 3.3), it is important to note that AI “amplifies both good and bad lawyering,” the panel noted. Presenters highlighted two AI-assisted litigation cases, Warner vs. Gilbarco, Inc. and U.S. vs. Heppner, to demonstrate that courts are still grappling with how traditional privilege and work-product doctrines apply to AI-generated materials. One thing that has been clear is that AI is viewed as a nonlawyer assistant, and if a lawyer or judge directed the AI use, then their supervisory obligations (Model Rules 5.1 and 5.3) apply. Otherwise, lawyers and judges run the risk of letting inadvertent citation or reliance on bad law to result in cascading effects if they are not vigilant about their AI use.

With the increased use of AI tools in the modern legal practice comes the lawyers’ responsibility to also adopt new billing practices that reflect their obligation under Model Rule 1.5 to charge reasonable fees. Although lawyers are not required to describe hourly work done with granular specificity, the panel encouraged lawyers to develop a standard practice of including an AI section in the client engagement letter, describing the scope of AI use and providing full disclosure regarding their handling of client data generated by AI.

In summary, generative AI is a powerful tool that has spread through modern legal practice, but when using it to build efficiency, lawyers and courts must be vigilant in complying with the ABA Model Rules of Professional Conduct. Lawyers must adhere to their ethical responsibilities when using AI by exercising informed judgement, establishing rigorous verification processes, adopting clear AI governance, and ensuring continuous human oversight over AI-generated content.