The Expanding Scope of Global FDI Screening
Cross-border M&A has entered an era where national security scrutiny routinely dictates transaction feasibility, timelines, and valuation. Historically, foreign direct investment (FDI) reviews were limited to direct defence contractors and critical heavy infrastructure. Today, regulatory scrutiny focuses just as heavily on the underlying technology, data assets, and supply chain dependencies of target companies as it does on the ultimate beneficial ownership of the acquirer.
The volume of regulatory intervention has scaled rapidly across key global jurisdictions. According to the European Commission's annual reporting on investment screening, the EU cooperation mechanism evaluated 488 foreign direct investment notifications in a single year, with 24 EU Member States actively enforcing national screening frameworks. This heightened vigilance reflects a broader global realignment where governments treat dual-use algorithms, semiconductor intellectual property, sovereign cloud infrastructure, and sensitive personal datasets as strategic national assets.
For transaction teams conducting cross-border due diligence, understanding the fundamental divergence between FDI screening and traditional antitrust clearance is essential. Antitrust regulators evaluate market concentration, pricing power, and consumer welfare within defined product markets. In contrast, national security regulators evaluate sovereignty, geopolitical exposure, technological leakage, and supply chain vulnerability, regardless of transaction value or market share.
| Diligence Dimension | Traditional Antitrust Clearance | Foreign Direct Investment (FDI) Screening |
|---|---|---|
| Primary Mandate | Market competition, consumer pricing, and anti-monopoly prevention | National security, public order, and economic sovereignty |
| Standard Metric | Market share, concentration indices (HHI), and market power | Target asset sensitivity, buyer origin, and foreign state nexus |
| Filing Triggers | Revenue, turnover, or transaction size monetary thresholds | Specific business activities, critical tech, or sensitive data volume |
| Remedy Profile | Structural carve-outs, brand divestitures, and asset sales | Governance firewalls, data localization, and supply continuity pacts |
| Review Timeline | Standard statutory phases (typically 30 days to 6 months) | Variable multi-agency reviews (often 30 days to 18 months) |
Because an FDI review can stall or prohibit a transaction that poses zero competition concerns, deal teams must identify regulatory nexus points during early preliminary screening rather than waiting for formal confirmatory diligence.
CFIUS Review: Mandatory Filings and Hidden Risks
In the United States, the Committee on Foreign Investment in the United States (CFIUS) operates as an interagency committee authorized to review foreign investments and acquisitions of U.S. businesses. Following the implementation of the Foreign Investment Risk Review Modernization Act (FIRRMA), CFIUS jurisdiction expanded significantly beyond controlling acquisitions to include non-controlling, non-passive investments in TID U.S. businesses: companies involved with Technology, Infrastructure, or Data.
Mandatory declarations are triggered when a transaction involves critical technologies that require U.S. export authorization to the foreign acquirer, or when a foreign government holds a substantial interest in an acquirer obtaining a substantial interest in a TID business. In its most recent annual reporting to Congress, CFIUS reviewed or assessed 325 covered transactions in a single calendar year, comprising 116 declarations and 209 notices, while opening 76 formal inquiries into non-notified transactions identified through corporate databases, market intelligence, and public tips.
Evaluating Mandatory Declarations vs. Voluntary Joint Notices
Navigating CFIUS requires dealmakers to weigh the trade-offs between an abbreviated 30-day declaration and a full 45-day joint voluntary notice. While declarations offer a streamlined path with lower filing preparation costs, the Committee can conclude an assessment by requesting a full notice or issuing a 'shrug' (informing parties they cannot conclude action on the declaration), leaving the deal without affirmative safe harbor protection.
- Critical Technologies: Targets that produce, design, test, manufacture, fabricate, or develop one or more items subject to U.S. export controls under EAR or ITAR.
- Critical Infrastructure: Targets that own, operate, or provide systems and assets across 28 distinct covered infrastructure subsectors, from subsea cables to energy grids.
- Sensitive Personal Data: Targets that maintain or collect identifiable data on over one million U.S. individuals across categories such as financial records, biometric data, geolocation, and health profiles.
- Non-Notified Enforcement: CFIUS maintains dedicated monitoring teams that review un-filed transactions and can unilaterally call in deals years post-closing, risking forced divestiture.
Failing to file when mandatory triggers apply exposes transaction parties to civil monetary penalties up to the value of the transaction or statutory caps, making early regulatory scoping an indispensable workstream.
The EU Framework and UK NSI Act
European cross-border M&A faces a multi-layered screening architecture. In the United Kingdom, the National Security and Investment Act (NSI Act) establishes a mandatory notification regime spanning 17 sensitive economic sectors, including artificial intelligence, synthetic biology, advanced robotics, and quantum technologies.
Under the UK government's statutory annual reporting on the NSI Act, the Investment Security Unit received 1,324 notifications in the latest reporting year, up from 1,143 the year before, with call-in notices concentrated on defence, critical suppliers to government, and military and dual-use acquisitions. Transactions completed without required mandatory clearance under the NSI Act are legally void, and acquirers face severe financial and criminal penalties.
Harmonized EU Coordination and Key National Regimes
Unlike the UK's centralized regime, the European Union operates a decentralized model anchored by the EU FDI Screening Regulation. While the European Commission coordinates cross-border notifications and issues opinions, individual Member States enforce distinct national screening laws. Currently, 24 EU Member States have operational FDI screening mechanisms.
- United Kingdom (NSI Act): Mandatory pre-closing notification across 17 defined sectors, with call-in powers extending up to five years for non-notified transactions with national security nexus.
- Germany (AWG & AWV): The Foreign Trade and Payments Act (Außenwirtschaftsgesetz) and Ordinance provide cross-sector reviews and strict sector-specific reviews for defence, IT security, and critical infrastructure (KRITIS).
- France (PACTE & CMF): The French Monetary and Financial Code establishes prior authorization rules for sensitive activities, and since 1 January 2024 the voting rights trigger for non-EU/EEA buyers in listed French companies carrying out covered activities has been permanently set at 10%.
- Italy (Golden Power): Grants the government broad intervention rights over strategic sectors, including energy, transport, communications, and 5G network equipment.
Because European filings often require simultaneous submissions across multiple national ministries, deal teams must harmonize notification narratives to prevent contradictory disclosures across jurisdictions.
Identifying Red Flags: Sensitive Data and Critical Tech
To prevent last-minute closing delays, corporate M&A leads and investment committees must screen the target's operating footprint for regulatory tripwires during the opening phase of a transaction. A target that appears to be a conventional commercial software business may inadvertently maintain classified government subcontracts or process regulated personal data.
Regulatory red flags typically cluster around four primary operational categories: export-controlled software, sovereign customer relationships, sensitive personal data pools, and critical infrastructure dependencies. Diligence teams must systematically evaluate product architectures, client lists, and licensing agreements against statutory control lists.
- Dual-Use & Export Controls: Audit target source code, hardware blueprints, encryption libraries, and export classification control numbers (ECCN) under EAR, ITAR, and EU Dual-Use Regulation (EU) 2021/821.
- Government & Defence Contracting: Identify direct prime contracts, subcontracts, and grant funding with military, intelligence, or law enforcement agencies, including security clearance requirements.
- Sensitive Data Assets: Quantify customer and user data stores to determine whether the target maintains biometric, genetic, financial, healthcare, or precise geolocation records exceeding statutory thresholds.
- Critical Infrastructure Integration: Map software deployments and hardware installations embedded within energy generation, water utilities, telecommunications, financial market infrastructure, or public transport networks.
- Foreign Supply Chain Exposure: Scrutinize R&D centers, outsourced engineering teams, and vendor dependencies located in high-risk foreign jurisdictions.
Uncovering a single unflagged dual-use export classification or sovereign defence subcontract during diligence fundamentally alters the transaction timetable, requiring specialized regulatory counsel to structure appropriate filing strategies.
How FDI Risk Reshapes M&A SPA Terms
The proliferation of FDI screening regimes has transformed the drafting and negotiation of cross-border Share Purchase Agreements (SPAs). Transaction parties can no longer rely on standardized regulatory boilerplate, as foreign investment reviews introduce prolonged interim operating periods and substantial closing uncertainty.
Where cross-border transactions previously utilized 3 to 6 month long-stop dates, complex transactions involving multi-jurisdictional national security reviews now frequently establish drop-dead periods of 12 to 18 months. These extended windows account for pre-notification consultations, formal review phases, national security call-ins, and mitigation negotiations.
Risk Allocation and Deal Protections
The allocation of regulatory risk between buyer and seller centers on three critical contractual mechanisms: regulatory effort standards, reverse termination fees, and closing conditions.
- Effort Standards: Sellers frequently push for 'hell or high water' commitments requiring buyers to accept any condition to secure clearance, while buyers negotiate capped remedies that exclude material structural divestitures or operational restrictions.
- Reverse Break Fees: SPAs increasingly incorporate tailored reverse termination fees, sized as a negotiated percentage of equity value, payable by the buyer if closing fails solely due to foreign investment approval denials or unaccepted mitigation terms.
- FDI Representations & Warranties: Sellers warrant that target operations do not trigger mandatory filing thresholds, while buyers provide warranties regarding their ultimate beneficial ownership, foreign state backing, and sovereign affiliations.
- Interim Covenants: Strict operating covenants balance the seller's need to run the business during an extended pre-closing window against the buyer's risk of asset degradation.
Structuring these contractual safeguards requires precise visibility into the target's regulatory exposure before definitive transaction documentation is executed.
Navigating Mitigation Agreements Post-Closing
When national security authorities identify potential risks in a covered transaction, clearance is frequently granted subject to formal mitigation agreements rather than an outright prohibition. These binding legal pacts impose stringent behavioral and structural covenants on the combined enterprise.
Mitigation agreements are a standard instrument for clearing complex transactions. CFIUS was monitoring 242 mitigation agreements or conditions at the close of the most recent reporting year, with monitoring agencies conducting 79 compliance site visits and the Committee assessing civil penalties for breaches of material mitigation terms.
| Mitigation Archetype | Core Requirements | Operational & Cost Impact |
|---|---|---|
| Governance Firewalls | Establishing proxy boards or security committees composed exclusively of vetted domestic citizens | Limits buyer operational control and excludes foreign executives from sensitive strategic decisions |
| Data & IP Localization | Mandating domestic server hosting, air-gapped systems, and restricted foreign access to source code | Increases IT redundancy costs and prevents unified global technology infrastructure integration |
| Independent Oversight | Appointing government-approved third-party monitors, auditors, and security officers | Generates recurring advisory compliance fees and ongoing operational reporting burdens |
| Supply Continuity Pacts | Binding commitments to maintain domestic production capacity and service critical state contracts | Restricts manufacturing consolidation and prevents offshore supply chain rationalization |
Deal teams must model the recurring compliance overhead and operational frictions of anticipated mitigation agreements directly into their post-closing integration models and investment committee underwriting.
Accelerating Diligence with AI Workflows
Cross-border deal execution demands rapid, auditable discovery of regulatory tripwires across hundreds of thousands of data room pages. M&A advisory firm partners, private equity deal teams, and corporate M&A leads utilize AI diligence workflows to identify sensitive regulatory markers early in the diligence lifecycle.
Using Data Room Ingestion, deal teams rapidly ingest unstructured virtual data room repositories, including technical specifications, patent filings, government contracts, customer master databases, and corporate organizational charts. The AI-Analysis Engine cross-references these records against global export-control lists, sovereign entity registries, and statutory critical technology definitions.
By connecting these signals into Risk Radar, advisors and investment professionals consolidate potential FDI vulnerabilities, such as unannounced defence subcontracts, high-risk foreign shareholding tiers, and sensitive customer data volumes, into structured findings and early risk registers Findings and Risk Intelligence.
Important Advisory Notice: Diligence software and AI-generated outputs automate document discovery and surface potential risk indicators, but they do not provide legal, tax, audit, or regulatory advice, nor do they guarantee regulatory clearance. All AI-generated findings, especially regarding CFIUS, foreign direct investment screening, export controls, licensing, and national security compliance, require formal verification, confirmation, and review by qualified regulatory and legal advisors before being relied upon for transaction structuring or filing determinations.
How Plausity accelerates this workflow
Plausity is an AI-native due diligence platform that helps M&A advisory firms, VC and PE funds, and corporate development teams structure evidence, findings and questions across a data room. It does not replace human advisers, does not guarantee deal outcomes, and does not provide legal, tax, audit or regulatory advice — all AI-generated findings, especially regulatory ones, require confirmation and advisor review by qualified professionals.
To explore the underlying capabilities, see the Plausity AI analysis engine and the findings and risk intelligence product page. For team-level workflows, see how VC and PE funds and M&A advisory firms use Plausity across live deals.



