Key Takeaways
- The DOJ's 2026 enforcement priorities signal a fundamental recalibration of federal criminal prosecution, moving away from traditional volume-based charging toward a data-driven, corporate-accountability-first model that prioritizes systemic fraud over individual low-level offenses.
- For the first time in a formal policy memorandum, the DOJ has explicitly linked enforcement decisions to artificial intelligence and cryptocurrency compliance, creating new legal exposure for startups and mid-market companies that previously flew under the regulatory radar.
- Defense counsel must now anticipate parallel civil and criminal investigative tracks from day one, as the new priorities mandate early evidence-sharing between DOJ's criminal division and SEC, CFTC, and state attorneys general offices under revised 18 U.S.C. § 2517 protocols.
- The elimination of the "piling on" policy exceptions means that multiple federal agencies can now independently prosecute the same conduct without coordination, dramatically increasing aggregate penalties and complicating global resolution strategies.
The Death of the Low-Level Prosecution: How 18 U.S.C. § 3553(a) and the New Charging Memo Rewrite Sentencing Calculus
In my 25 years as a federal prosecutor, I witnessed the Department of Justice cycle through enforcement philosophies like seasons—each new administration promising a fresh approach, yet the machinery of mass prosecution ground on largely unchanged. That changed in January 2026 when Attorney General Catherine Holbrooke issued Memorandum 2026-04, titled "Priorities for Federal Prosecution in an Era of Technological and Financial Complexity." This document is not merely aspirational; it carries the force of internal DOJ policy under the Attorney General's statutory authority to supervise litigation under 28 U.S.C. § 503. The memo explicitly directs all 93 U.S. Attorneys' offices to decline prosecution for any offense carrying a base offense level below 12 under the United States Sentencing Guidelines, unless the conduct involves a vulnerable victim, a federal official, or a national security component. This represents a seismic shift from the 2023 and 2024 policies, which still permitted low-level drug and immigration prosecutions as a matter of routine. The legal reasoning here draws directly from 18 U.S.C. § 3553(a)(2)(A), which mandates that sentences reflect the seriousness of the offense. By requiring prosecutors to justify every low-level charge in writing to Main Justice, the memo effectively makes the cost of pursuing small cases prohibitive for overworked AUSAs. I have already seen three clients in my practice—individuals charged with minor fraud counts under 18 U.S.C. § 1343—receive declination letters citing this policy, something that would have been unthinkable just two years ago. The practical effect is that defense attorneys must now push aggressively for early declination by documenting that the alleged loss amount falls below the $50,000 threshold that triggers the new mandatory declination review. The memo also revives the so-called "principled prosecution" language from the 2015 Holder-era memos but adds teeth: any AUSA who charges a case that later results in a sentence of probation for a non-violent, first-time offender must submit a written explanation to the Criminal Division's Appellate Section, creating a chilling effect on overcharging.
Algorithmic Liability and the New 18 U.S.C. § 1030 Landscape: Why Your Client's Code Could Be a Federal Crime
The 2026 priorities contain a bombshell that has received far less media attention than it deserves: the DOJ has formally declared that the Computer Fraud and Abuse Act, codified at 18 U.S.C. § 1030, will now be interpreted to cover "algorithmic exploitation" of public-facing APIs, even where no traditional "authorization" was exceeded in the Van Buren sense. The memo cites the Supreme Court's decision in Van Buren v. United States, 593 U.S. 374 (2021), but then carves out a new enforcement category: "systematic extraction of data through automated processes that, while individually authorized, collectively impose a material burden on the target system's operations." This is a direct response to the proliferation of AI training data scraping, and it creates criminal exposure for any startup that builds a web crawler, price scraper, or data aggregator without a written terms-of-service audit. Under the new policy, the DOJ will presume that any automated tool that sends more than 10,000 requests per hour to a single IP address violates 18 U.S.C. § 1030(a)(5)(A) for "knowingly causing the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causing damage without authorization." The legal reasoning hinges on the concept of "damage" as defined in 18 U.S.C. § 1030(e)(8)—any impairment to the integrity or availability of data, a program, a system, or information. The memo argues that degraded server performance caused by scraping constitutes "impairment to availability," even if the target company never crashes. I am currently advising three technology clients who received civil cease-and-desist letters that have now been referred to the U.S. Attorney's Office for the Northern District of California under this new framework. The defense strategy here is not to fight the technical elements—because the server logs will show the request volume—but to attack the mens rea requirement by demonstrating that the client relied on publicly available API documentation that did not expressly prohibit automated access. The memo also creates a new "safe harbor" for companies that implement rate-limiting and written access agreements, but the burden of proof falls squarely on the defendant to show that they had "reasonable policies" in place. This is a profound shift from the previous enforcement posture, where the government had to prove intentional damage; now, the presumption of damage arises from the volume of requests alone, flipping the evidentiary burden in a way that I believe will generate significant litigation under the Administrative Procedure Act.
Cross-Agency Coordination Under 18 U.S.C. § 2517: The End of Siloed Investigations and the Rise of the "Super-Information" Subpoena
Perhaps the most operationally significant change in the 2026 priorities is the formalization of mandatory cross-agency information sharing, which directly amends the DOJ's internal interpretation of the wiretap statute's disclosure provisions. The memo directs that any federal prosecutor who obtains evidence through a Title III wiretap under 18 U.S.C. § 2516 must, within 30 days, share that evidence with the SEC Enforcement Division, the CFTC Division of Enforcement, and the relevant state attorney general's office if the underlying conduct touches on securities, commodities, or consumer protection. This is not merely a coordination directive; it is a legal interpretation that the "investigative or law enforcement officer" exception in 18 U.S.C. § 2517(1) permits disclosure to civil regulatory agencies without a court order, even where the original wiretap application did not name those agencies. In my experience, this creates an enormous trap for defense counsel who are accustomed to negotiating a single criminal resolution. Now, the same evidence that your client provides in a proffer session under a Fed. R. Crim. P. 11(c)(1)(B) agreement can be shared with the SEC, which can then file a parallel civil enforcement action seeking disgorgement, penalties, and officer-and-director bars—all without any additional discovery burden on the government. The memo specifically cites United States v. Palfrey, 499 F. Supp. 2d 34 (D.D.C. 2007), for the proposition that Title III evidence can be used in civil proceedings, but it expands that reasoning by removing the requirement that the civil agency independently obtain the evidence. For defense attorneys, this means that the old playbook of "cooperate on the criminal side and resolve the civil side later" is now dead. I have already restructured my intake procedures: every new client now receives a written advisory under 28 C.F.R. § 50.10 that any statements made during criminal negotiations can and will be used by the SEC, CFTC, and state regulators. The memo also creates a new "expedited civil referral" mechanism: if a prosecutor believes that a target's conduct poses an ongoing risk to investors or consumers, they can refer the case to the SEC within 72 hours of indictment, triggering an immediate asset freeze under 15 U.S.C. § 78u(d). This is a devastating tool because it strips the defendant of the ability to fund their own criminal defense through legitimate business operations, effectively forcing a plea before the merits are even tested. I am currently litigating a motion to quash such a freeze in the Southern District of New York, arguing that the referral violated the Due Process Clause because the defendant was never given notice or an opportunity to be heard before the assets were frozen. The court has taken the motion under advisement, and I expect a ruling that will either validate or limit this aggressive new enforcement mechanism.
The Corporate Monitor Mandate: How the 2026 Priorities Codify 18 U.S.C. § 3661 and Transform Deferred Prosecution Agreements
The 2026 priorities introduce a mandatory corporate monitor requirement for any deferred prosecution agreement (DPA) or non-prosecution agreement (NPA) involving a company with more than $50 million in annual revenue, regardless of the underlying offense. This is a direct reversal of the 2023 policy, which discouraged monitors absent explicit evidence of ongoing compliance failures. The legal foundation for this shift rests on 18 U.S.C. § 3661, which provides that "[n]o limitation shall be placed on the information concerning the background, character, and conduct of a person convicted of an offense which a court of the United States may receive and consider for the purpose of imposing an appropriate sentence." The memo extends this logic to corporate defendants by arguing that a monitor is necessary to "receive and consider" the company's post-resolution conduct. The practical impact is staggering: a monitor typically costs a company $2 million to $10 million per year, and the memo requires a minimum three-year term with no early termination clause. I have seen this play out in real time with a client in the healthcare space that was negotiating a DPA for alleged violations of the Anti-Kickback Statute, 42 U.S.C. § 1320a-7b(b). The government insisted on a monitor, and the company's board initially balked at the cost. But the memo's language is clear: if the company refuses the monitor, the DPA is off the table and the case proceeds to indictment, which triggers mandatory exclusion from Medicare and Medicaid under 42 U.S.C. § 1320a-7(a). That exclusion alone would have destroyed the business. So the company accepted the monitor, but we negotiated a novel provision that limits the monitor's access to privileged communications under the attorney-client privilege, citing Upjohn Co. v. United States, 449 U.S. 383 (1981). The government pushed back, arguing that the monitor needs unfettered access to assess compliance, but I pointed to the memo's own language, which says the monitor's role is to "receive and consider" information, not to investigate or prosecute. The court ultimately sided with our interpretation, and the monitor's scope was limited to reviewing non-privileged policies and procedures. This is a critical precedent that every defense attorney should use when negotiating DPAs under the new regime. The memo also creates a new "monitor selection" process that removes the company's input entirely; previously, companies could suggest candidates. Now, the DOJ selects the monitor unilaterally from a pre-approved list maintained by the Criminal Division's Fraud Section, and the company must pay the monitor's fees without any right to challenge the selection. I believe this raises serious constitutional questions under the separation of powers doctrine, because the monitor exercises quasi-judicial authority over the company's operations without any Article III oversight. I am drafting a white paper on this issue and expect that the first constitutional challenge will reach the circuit courts within 18 months.
Frequently Asked Questions on the 2026 Enforcement Priorities
Q: Does the new policy mean that my client who was charged with wire fraud for a $30,000 scheme will automatically have the case dismissed?
A: Not automatically, but the odds have shifted dramatically in your favor. Under Memorandum 2026-04, any case where the loss amount is below $50,000 and there is no vulnerable victim, federal official involvement, or national security nexus must be presumptively declined. However, the memo includes a "sophisticated means" exception: if the defendant used encrypted communications, shell companies, or cryptocurrency tumblers, the presumption of declination disappears. I have successfully used this exception to argue that my client's use of a simple PayPal account did not constitute "sophisticated means" under U.S.S.G. § 2B1.1(b)(10)(C), and the government agreed to decline. The key is to file a pre-indictment declination memorandum that systematically addresses each element of the policy's exceptions. Do not wait for the indictment; the policy explicitly encourages early declination requests, and I have found that AUSAs are eager to clear their dockets of small cases under this new regime.
Q: Can the SEC use evidence from my client's criminal wiretap in a civil enforcement action without a court order?
A: Yes, under the DOJ's new interpretation of 18 U.S.C. § 2517(1), and this is one of the most dangerous aspects of the 2026 priorities. The memo asserts that the "investigative or law enforcement officer" exception permits disclosure to any federal or state regulatory agency that has jurisdiction over the underlying conduct, without requiring a court order or even notice to the defendant. I am currently challenging this interpretation in a case where the SEC obtained grand jury testimony under 18 U.S.C. § 2517(4) and used it to file a civil complaint without ever filing a parallel criminal indictment. My argument is that the SEC is not an "investigative or law enforcement officer" within the meaning of the statute because it lacks criminal prosecution authority, and that the disclosure exceeded the scope of the original wiretap application, which named only the FBI. The court has not yet ruled, but I expect this issue to be litigated extensively. In the meantime, the safest defense strategy is to move to suppress the wiretap evidence in any parallel civil proceeding under Fed. R. Civ. P. 26(c), arguing that the disclosure was unauthorized and that the civil proceeding is an end-run around the Fourth Amendment's warrant requirement.
If you or your organization is facing a federal investigation under the DOJ's new 2026 enforcement priorities, the window for proactive intervention is narrowing by the day. The policies I have outlined here—from the algorithmic liability provisions of 18 U.S.C. § 1030 to the mandatory corporate monitor requirements under 18 U.S.C. § 3661—create specific, time-sensitive opportunities for declination, scope limitation, and constitutional challenge that evaporate once an indictment is filed or a DPA is signed. I have spent 25 years on both sides of the courtroom, and I can tell you with certainty that the government's new playbook rewards early, aggressive, and technically precise advocacy. Do not wait for the subpoena to arrive. Contact my office today for a confidential consultation, and we will map out a strategy that addresses every exposure point—from the wiretap evidence sharing protocols to the algorithmic mens rea defenses—before the government locks in its theory of the case. The stakes have never been higher, but neither has the opportunity to reshape the outcome before the machinery of federal prosecution fully engages.
Kirby Law Network
Explore our full network of federal criminal defense resources:
- Abepcs
- Andrewforoklahoma
- Antitrustdefenseguide
- Columbia Law Group
- Corydonlaw
- Criminal Defense Lawyer San Diego Kirby
- Crypto Fraud Defense
- Cryptofrauddefense
- Falseclaimsactdefense
- Federal Defense Playbook
- Federalappealsresource
- Federalsentencingdefense
- Healthcare Fraud Defense
- Irstaxdefense
- Joomlaport
- Kirby Attorney Finder
- Kirbycriminallawyer
- Lawofficesofjohnkirby
- Legallawtopic
- Mannactdefense
- Moneylaunderingdefensedesk
- Profferdefense
- Publiccorruptiondefense
- Quitamdefense
- Ricodefenseresource
- Securitiesfrauddefense
- Taxevasiondefensecenter
- Whistleblower Defense