Why It Matters
The Committee on Foreign Investment in the U.S. (CFIUS) can clear covered transactions, impose mitigation conditions, or refer them to the President when the risks require presidential action. A September 10 Congressional Research Service (CRS) report titled “CFIUS: Executive Branch Actions on Evolving National Security Risks and Enforcement,” describes how the CFIUS is adapting its review factors and enforcement tools as national-security risks change. The body is chaired by the Secretary of the Treasury, and its decision-making is not public in order to protect transaction confidentiality.
For Congress, the report frames the policy question as a balance between preserving open investment and giving the executive branch enough information and authority to address risks tied to foreign investment. For the public, the stakes include transactions involving technologies, infrastructure, supply chains, and sensitive personal information, even though the underlying reviews generally remain confidential.
The Big Picture
Executive Order 14083 elaborated on existing statutory factors rather than otherwise changing CFIUS authorities or jurisdiction, according to the report. The order broadened supply-chain consideration beyond the defense industrial base to include microelectronics, artificial intelligence, biotechnology, quantum computing, advanced clean energy, climate technologies, critical materials, agriculture, and food security. It directs CFIUS to assess potential losses of U.S. national capabilities and potential capability gains by a foreign acquirer, and it directs the Office of Science and Technology Policy to periodically publish a list of additional sectors considered key to U.S. technological leadership.
Three additional new factors are aggregate industry investment trends, cybersecurity, and U.S. persons' sensitive data. The factors include whether a transaction affects national security in the context of the broader industry and a series of investments over time, which could give foreign persons or third parties access to capabilities, databases, or systems for cyber intrusions or malicious cyber-enabled activity, or involves a U.S. business with access to health, digital-identity, biological, or other data that could be identified or deanonymized and exploited.
The Bottom Line
The enforcement chapter gives Congress a clearer view of how CFIUS can police compliance after a transaction receives scrutiny. The guidelines say CFIUS can use government data, public information, auditors, and other third-party providers, tips, and information supplied by transaction parties to determine violations.
The guidelines strongly encourage self-disclosure of potential violations by persons subject to CFIUS, while leaving CFIUS discretion to determine appropriate remedies and identifying national-security harm, the timing of self-disclosure, intentionality, concealment or delayed information sharing, personnel seniority, actions taken in response to the violation, and compliance records and internal policies as penalty considerations. Treasury’s 2024 regulatory updates extended penalties for material misstatements or omissions to certain responses to CFIUS information requests and increased the maximum civil penalty from $250,000 to $5 million.
Spot something wrong? Report an issue with this article