This is the new MLex platform. Existing customers should continue to use the existing MLex platform until migrated.
For any queries, please contact Customer Services or your Account Manager.
Dismiss

CFIUS to focus on merger target vulnerabilities, even if investor is from allied nation

By Curtis Eichelberger

February 13, 2026, 15:42 GMT | Comment
National security reviews of US mergers in 2026 are expected to focus on the vulnerabilities of the target company, while giving less consideration to the national origin of the foreign investor — even long-standing allies like Canada and members of the European Union.
National security reviews of US mergers in 2026 are expected to focus on the vulnerabilities of the target company, while giving less consideration to the national origin of the foreign investor — even long-standing allies like Canada and members of the European Union.  

The most common example of a vulnerability is data security, where theft could expose the private information of American citizens, military personnel, or even US defense systems to an enemy.

Experts say the risk of merger delays and costly mitigation agreements is rising and that companies should plan to address these hidden concerns at the earliest stages of an M&A transaction. 

“This is not the kind of thing where you want to be far along in your deal and someone goes, ‘Hey, did we do a CFIUS analysis?’ And now you're having to do in-depth diligence and you're discovering things that are going to be huge triggers,” said Colin Costello, the Committee on Foreign Investment in the United States (CFIUS) and national security advisor at the law firm Freshfields. “Your deal, which looked like it might be on an easy glide path, is now going sideways.”

Target vulnerability analysis has become an important focus of CFIUS investigations, and companies can expect the government to enter into mitigation settlements to resolve concerns regardless of who is buying the company.

“That's really what you see a lot in these, what I'll call friendly transaction mitigation scenarios, is the risk that's being mitigated has very little to do with the foreign investor or the jurisdiction it's coming from,” Costello said.

The target doesn’t need a long-standing relationship with a Chinese company for it to be of concern to CFIUS, lawyers say. The threats can be hard to identify in an initial review. 

It could be one of 10,000 suppliers providing components for the merger target’s products, and the political hires responsible for signing off on the CFIUS investigation will call for a mediation agreement — something national security lawyers say isn’t always necessary and is sometimes designed to protect themselves politically.

The areas of concern are expanding rapidly.

Christine Laciak, a special counsel in Freshfields’ CFIUS practice who advises clients on global foreign investment review regulations, said critical technology is “used to generally align with export control technologies, but it’s sort of moving into more frontier technology like quantum and AI that are not necessarily captured by export controls, so there’s what we might call sensitive technologies.”

She said that included industries like medical technologies, biotechnology, self-driving cars, a lot of products and technology used in the commercial sector, and not just the defense sector.

Mitigation agreements can add unexpected costs and delay deal approvals. 

US President Donald Trump said earlier this year that economic security now equates to national security. And that changed everything.

The line between commercial products and military applications blurs what might seem like an innocuous investment from a European friend, turning it into a concern requiring a mitigation agreement.

Freshfields published a report last month titled, “Clarity in Antitrust: Insights that bring focus to the defining competition challenges of 2026,” that said protection of critical technologies will remain CFIUS’s primary concern in 2026 to prevent technology transfers to US adversaries and, “increasingly, to protect and promote domestic production as a national security priority.”

Direction from the White House, combined with personnel changes and the appointment of more aggressive technology hawks, signal an expansive application of CFIUS’s definition of critical technology, the report said. 
 
Freshfields said investors should also expect increased scrutiny in critical national infrastructure investments, including communications infrastructure such as 5G and satellite systems that could be the focus of foreign espionage or cyberattacks; and energy investments, including renewables and nuclear, that are important for energy insecurity.

And that is coupled with Trump’s goal to onshore production of essential technologies and federal participation in trusted-supply initiatives.

The law firm, which has one of the top CFIUS practices, says it “signals that the US government views its promotion of domestic capacity as complementary to CFIUS’s deal-specific risk mitigation. The result is a policy landscape where foreign investment reviews and industrial policy increasingly reinforce one another: CFIUS focuses on safeguarding vulnerable supply-chain nodes, while separate federal programs aim to ensure the most strategic technologies are developed, manufactured and secured on US soil.”

Please email editors@mlex.com to contact the editorial staff regarding this story, or to submit the names of lawyers and advisers.

Tags