The Olam
Crypto & Digital Assets

CFIUS: How US Investment Review Applies to Israeli Tech Companies and Deals

By The Olam Editorial Team · Aug 2, 2026

CFIUS: How US Investment Review Applies to Israeli Tech Companies and Deals

The interagency US review body that decides whether foreign acquisitions of US targets threaten national security. How CFIUS applies to Israeli acquirers, to Chinese or Gulf money into Israeli firms with US ops, and to the Delaware C-corps that create the jurisdictional hook.

The Committee on Foreign Investment in the United States (CFIUS) is the interagency review body that decides whether foreign acquisitions of US companies threaten American national security. It has statutory authority to recommend that the President block or unwind covered transactions. It has, in the last decade, blocked or forced the divestiture of high-profile deals involving Chinese acquirers, Russian buyers, and — in specific cases — Israeli-affiliated transactions.

For Israeli technology companies, CFIUS matters in two directions. Outbound: Israeli acquirers of US targets face CFIUS review at the deal-signing stage, with the potential for extended review, mitigation agreements, or outright blocking. Inbound: Israeli targets with US operations, US customers, or US-origin IP face CFIUS review when their acquirer is a covered foreign person — which, in an era of expanded jurisdiction, increasingly includes not just Chinese and Russian money but any acquirer whose ownership structure touches restricted countries.

Understanding CFIUS is not optional for Israeli tech firms operating at the US intersection. It is the single most consequential US regulatory review that operates on the deal-closing timeline — and the one that most often surprises Israeli operators who assumed export-control review ended at the shipping department.

What Is CFIUS, and Which Agencies Sit on the Committee?

CFIUS was established by Executive Order 11858 in 1975 as an interagency committee to review foreign investment for national-security implications. Its statutory authority was codified in the Exon-Florio Amendment to the Defense Production Act in 1988, expanded by the Foreign Investment and National Security Act of 2007 (FINSA), and dramatically expanded by the Foreign Investment Risk Review Modernization Act of 2018 (FIRRMA).

The committee is chaired by the Secretary of the Treasury. Voting members: State, Defense, Justice, Commerce, Energy, Homeland Security, and the Office of Science and Technology Policy. The Director of National Intelligence and the Secretary of Labor participate as non-voting members. The National Security Council, National Economic Council, and other agencies participate as observers.

Treasury's Office of Investment Security runs the day-to-day CFIUS operations. The specific reviewers vary by transaction — a semiconductor deal draws Defense and Energy attention; a media transaction draws Commerce and the intelligence community; a critical infrastructure deal draws DHS and Energy. The multi-agency structure is deliberate: national-security review requires perspectives beyond any single agency's core mission.

CFIUS meets in closed session. Its deliberations are classified. Its final recommendations to the President are not public unless the transaction is blocked and the White House chooses to make the decision public — which, for political reasons, is now common practice on high-profile blocks.

What Made FIRRMA the Most Consequential CFIUS Expansion in Decades?

FIRRMA — signed into law August 13, 2018 — was the most substantive expansion of CFIUS authority since Exon-Florio. Five substantive changes:

  • Covered transactions expanded. CFIUS could review not just controlling acquisitions but also non-controlling investments in specific US businesses involved in critical technology, critical infrastructure, or sensitive personal data of US citizens ("TID" businesses).
  • Real estate transactions covered. Certain real estate transactions in proximity to sensitive US government facilities became CFIUS-reviewable.
  • Mandatory declarations introduced. Certain transactions involving foreign government ownership stakes in critical-technology businesses became mandatory to declare — a shift from purely voluntary filings.
  • Extended timelines. The initial review period was extended from 30 days to 45 days, with the investigation period extended proportionally. In practice, CFIUS review now regularly runs six months or longer.
  • FOCI (Foreign Ownership, Control, or Influence) provisions expanded. Structural mitigation options — Special Security Agreements, Proxy Agreements, Voting Trust Agreements — became standardized tools for cleared-defense-contractor acquisitions.

The regulations implementing FIRRMA took effect in February 2020. The full weight of FIRRMA authority became operational at exactly the moment the US-China technology competition intensified. CFIUS became the single most important US regulatory instrument shaping cross-border technology M&A.

Which Categories of Transactions Get Reviewed Most Closely?

CFIUS review priorities have concentrated in specific categories over the past decade:

Critical technologies. The definition tracks the US export-control lists — items subject to the EAR, ITAR, and specific "emerging and foundational technologies" designations. Semiconductors, AI, quantum, biotechnology, advanced materials, and hypersonics are the sectoral priorities.

Critical infrastructure. Energy, telecommunications, financial systems, transportation, water, and defense industrial base. Deals involving foreign investment in these sectors face heightened scrutiny.

Sensitive personal data. Health records, biometric data, geolocation data, financial data, and consumer records at scale. The Grindr divestiture — where CFIUS forced Chinese owner Kunlun Tech to sell the LGBTQ+ dating app in 2019-2020 — established the precedent for personal-data transactions.

Proximity to sensitive government facilities. Real estate near military installations, sensitive research facilities, or classified sites. The purchase of land near the Naval Air Station in Idaho by a Chinese-linked buyer was the reference case that drove the FIRRMA real-estate expansion.

Government-affiliated acquirers. State-owned enterprises, sovereign wealth funds with government direction, and any acquirer whose ownership structure includes government participation face heightened review regardless of the target sector.

How Does CFIUS Actually Apply to Israeli Acquirers of US Targets?

Israeli acquirers of US targets face CFIUS review under the standard framework — the acquirer is a foreign person, the target is a US business, the transaction is potentially covered. In practice, Israeli acquirers face relatively favorable review outcomes compared to Chinese or Russian counterparts, but the review is not automatic clearance.

Three specific Israeli-transaction categories draw closer scrutiny:

Defense-adjacent US targets. Israeli defense-industry acquirers of US defense-adjacent businesses face FOCI review under the standard cleared-defense-contractor framework. Elbit Systems America, IAI North America, Rafael USA, and other Israeli-parented cleared subsidiaries operate under Special Security Agreements as a matter of course. New acquisitions can trigger fresh FOCI mitigation requirements.

Ownership structures involving Chinese or Russian minority stakes. An Israeli acquirer whose LP base includes Chinese sovereign wealth or Russian oligarchic money may face heightened review. The "look-through" analysis — CFIUS examining the ultimate beneficial ownership of an acquirer regardless of the immediate corporate structure — has become standard.

Critical-technology targets. Semiconductor, AI, and quantum US targets face heightened review regardless of acquirer origin. Israeli acquirers in these categories should assume CFIUS review at the transaction announcement, not at the mitigation stage.

The vast majority of Israeli-led US acquisitions clear CFIUS. Those that do not clear typically face either mitigation agreements (operational restrictions on how the target is integrated) or forced divestment of specific US assets. Outright blocks of Israeli-led transactions are rare but not unprecedented.

How Does CFIUS Apply to Chinese or Gulf Money Flowing Into Israeli Targets With US Operations?

This is the harder question. Israeli technology firms with US operations, US customers, or US-origin IP are US businesses for CFIUS purposes even where the parent entity is Israeli. When such a firm is acquired by a Chinese, Russian, or other restricted-jurisdiction acquirer, CFIUS jurisdiction attaches.

The look-through analysis extends into venture capital as well. A Chinese sovereign LP position in an Israeli venture fund can, in principle, trigger CFIUS-adjacent scrutiny when that fund invests in a US business. The 2020 FIRRMA regulations created explicit mechanisms for reviewing non-controlling investments in critical-technology TID businesses, with US venture fund LP structures within scope where the LP base includes covered foreign persons.

Israeli venture funds have adjusted. Multiple Israeli funds have restructured to exclude Chinese sovereign LPs, moved Chinese LP positions to fund-of-funds structures that provide some insulation, or specifically documented that Chinese LPs do not have information rights or control over investment decisions. None of these workarounds fully eliminates CFIUS exposure, but they materially reduce it.

The Delaware C-corp structure is the standard vehicle Israeli founders use to access US capital markets. It also creates the CFIUS jurisdictional hook — a Delaware C-corp with Israeli R&D is a US business, and its acquisition or majority investment by a covered foreign person triggers CFIUS review.

What Are the Most Consequential Recent CFIUS Cases?

Five reference cases from the past decade shape how Israeli operators should read CFIUS priorities:

MoneyGram (2017-2018). Ant Financial's proposed $1.2 billion acquisition of MoneyGram was withdrawn after CFIUS review indicated it would not clear. Concerns: sensitive personal financial data of US citizens, plus Chinese government affiliation of Ant. The withdrawal established the personal-data precedent that would later drive Grindr.

Broadcom-Qualcomm (2018). Broadcom's hostile bid for Qualcomm was blocked by presidential order following CFIUS review — despite Broadcom being Singapore-headquartered rather than Chinese. Concerns: perceived risk to US semiconductor leadership. The block established the sectoral-priority precedent independent of acquirer nationality.

Grindr (2019-2020). Chinese-owned Kunlun Tech was forced to divest Grindr following CFIUS review of the prior 2016-2018 acquisition. Concerns: sensitive personal data (LGBTQ+ status, HIV status, geolocation). The forced divestment established that CFIUS could unwind completed transactions retroactively.

TikTok (2020-present). The most complex ongoing CFIUS case, involving ByteDance's US operations of TikTok. Multiple executive orders, legislative provisions, and ongoing negotiations. The case has stretched CFIUS authority to new operational and political dimensions.

Magnachip (2021). The Chinese-affiliated Wise Road Capital's proposed acquisition of Korea-headquartered but US-listed Magnachip Semiconductor was terminated after CFIUS review indicated it would not clear. Concerns: semiconductor supply chain and Chinese acquirer origin. The case established CFIUS reach over transactions with limited US-territory nexus.

Each of these cases affected how Israeli operators structure transactions. The MoneyGram precedent shaped Israeli fintech thinking on customer data. The Broadcom precedent affects semiconductor M&A. The Grindr precedent means any Israeli firm with US-user sensitive data assumes CFIUS review. The TikTok precedent shows the extended time-horizon on which CFIUS can operate. The Magnachip precedent extends jurisdiction beyond immediate US-territory targets.

What Is the Outbound Investment Review Order, and How Does It Change the Israeli Picture?

Executive Order 14105, signed in August 2023 and implemented through Treasury regulations effective January 2, 2025, established a US outbound investment review regime for investments by US persons in specified Chinese "countries of concern" entities. It is the mirror image of CFIUS — where CFIUS reviews foreign investment inbound to the US, EO 14105 reviews US investment outbound to China in specified critical categories.

The covered categories: semiconductors and microelectronics, quantum information technologies, and artificial intelligence systems. The covered activities: specified categories of prohibited investment (broad presumption of denial) and notifiable investment (transparency requirement without prohibition).

For Israeli firms, the outbound regime creates a new consideration. Israeli-parented firms with US LP participation — US institutional investors, US venture funds, US corporate strategic investors — may face indirect exposure when the Israeli firm invests in Chinese covered categories. The look-through analysis extends into the LP base for US persons subject to EO 14105.

Delaware C-corp structures with US ownership face direct application of the outbound review. Investments by such structures in Chinese covered-category entities become subject to notification or prohibition depending on the specific activity and Chinese counterparty. The compliance burden is real. The strategic implication is broader: Israeli firms with US investor participation now navigate a substantively expanded US regulatory footprint on their Chinese business.

How Should Israeli Firms Structure Their Approach to CFIUS Exposure?

Five operational priorities:

  1. Map the CFIUS jurisdictional hook before it becomes urgent. Understand whether the Israeli firm's US operations, US customers, US-origin IP, or US LP base creates the hook. The mapping should happen at Series A, not at deal signing.
  2. Document the ownership look-through. Every LP, every co-investor, every strategic partner should be documented with sufficient granularity that a CFIUS reviewer can assess covered-foreign-person exposure. The documentation is not for compliance — it is for the deal team's ability to answer CFIUS questions in real time.
  3. Structure critical-technology exposure deliberately. If the Israeli firm's product falls in semiconductor, AI, quantum, or biotechnology categories, assume CFIUS scrutiny on any covered transaction. Structure the deal architecture (Israeli parent versus US parent, controlling versus non-controlling stakes, information rights and control rights) with CFIUS review in mind.
  4. Anticipate the timeline extension. Standard CFIUS review runs 45 days for initial review plus 45 days for investigation. Complex transactions can run 6-12 months from filing to clearance. Deal timelines and financing arrangements need to accommodate this reality.
  5. Engage CFIUS counsel early. The specialized CFIUS bar in Washington is small and expensive. Engaging counsel at the term-sheet stage rather than after signing is materially less costly and materially more likely to produce successful clearance.

CFIUS is not a rubber stamp. It is the single most consequential regulatory review that operates at deal signing, and it has expanded jurisdiction, longer timelines, and higher scrutiny than at any point in its history. Israeli tech firms that treat it as an afterthought find out too late. Israeli tech firms that engineer around it from Series A onward find themselves with substantial optionality on exit.

What Comes Next in the CFIUS Architecture?

Three trajectories are visible in policy discussion:

  • Expansion of covered technology categories. Biotechnology, additive manufacturing, autonomous systems, and clean energy could all move into higher-scrutiny categories in coming rulemakings.
  • Extension of outbound review scope. EO 14105 could expand beyond the current three categories (semiconductors, quantum, AI) as US-China competition dynamics evolve.
  • Alignment with allied jurisdictions. US-UK, US-EU, US-Japan, and US-Australia coordination on investment review is deepening. Israeli firms operating across multiple jurisdictions may face parallel reviews with substantively similar outcomes.

The direction of travel is consistent: CFIUS jurisdiction expands, review depth increases, and coordination with allied jurisdictions deepens. Israeli tech firms operating at the US intersection should assume the trend continues.


Related in Olam:

Universities & Research

View all →

Olam Research

View all →