Advertisement

Silicon Secrets: How the U.S. Government Vets Foreign Ties in Tech Contracts

Silicon Secrets: How the U.S. Government Vets Foreign Ties in Tech Contracts

In 2018, a relatively obscure committee delivered a verdict that sent shockwaves through the global semiconductor industry. The Committee on Foreign Investment in the United States, known as CFIUS, blocked a $117 billion hostile takeover bid by Broadcom, then headquartered in Singapore, for the American chipmaker Qualcomm. President Trump signed the order in March of that year. The official rationale was stark: allowing a foreign-influenced company to control Qualcomm could erode U.S. leadership in 5G technology and hand strategic advantage to China.

That decision marked a turning point. It was a rare intervention against a bid before the deal was ever completed. And it signaled to the broader technology sector that the era of uncomplicated cross-border dealmaking was over.

Today, the mechanisms the U.S. government uses to vet foreign ties in technology contracts and investments have grown more numerous, more aggressive, and considerably more sophisticated. They span multiple agencies, two major legal frameworks, and a growing body of executive orders and regulatory guidance. Understanding how they work, where they succeed, and where critics say they fall short, is essential for anyone doing business at the intersection of technology and government.

The Architecture of Oversight: CFIUS and Its Expanding Mandate

CFIUS was established by executive order in 1975 and formalized by Congress in 1988, but for most of its history it operated as a sleepy interagency body that rarely made headlines. The 2018 Foreign Investment Risk Review Modernization Act, known as FIRRMA, changed that fundamentally. The legislation expanded the committee’s jurisdiction to cover not just full acquisitions but minority investments in companies dealing with critical technology, critical infrastructure, and sensitive personal data.

The committee now includes representatives from several cabinet departments, including Defense, Treasury, State, Commerce, Justice, and Homeland Security, as well as the Director of National Intelligence. Treasury serves as chair. Any covered transaction involving a foreign person can be reviewed, and certain transactions, particularly those involving foreign government-linked investors in sensitive tech sectors, must be declared to the committee.

The numbers reflect the surge in activity. In 2022, CFIUS reviewed 286 transactions, more than double the volume from a decade earlier, according to annual reports submitted to Congress. The technology sector consistently accounts for the largest share of filings, with software, semiconductors, and telecommunications topping the list. China remains the most scrutinized country of origin, though filings from the United Arab Emirates, Saudi Arabia, and even allied nations have drawn attention.

Enforcement has teeth. CFIUS can require divestiture, impose mitigation agreements, and recommend presidential action to block deals outright. In 2020, President Trump, on CFIUS’s recommendation, ordered Beijing Shiji Information Technology to divest its stake in StayNTouch, a hotel management software firm whose guest data could include information on U.S. government travelers and other officials in national security sensitive positions. The case illustrated how seemingly mundane software businesses can carry significant national security implications when they hold sensitive personal data.

FARA: The Other Vetting Tool That Prosecutors Are Dusting Off

While CFIUS governs investment, a separate and older statute governs foreign influence in political and governmental activities: the Foreign Agents Registration Act, or FARA. Enacted in 1938 to counter Nazi propaganda networks in the United States, FARA requires individuals and organizations acting at the direction of a foreign principal to register with the Justice Department and disclose their activities.

For most of the twentieth century, FARA enforcement was sporadic and largely targeted at lobbyists and public relations firms. That changed dramatically after 2016, when special counsel investigations highlighted how inadequately the law had been applied to foreign influence operations involving digital platforms and political consulting.

The connection to technology contracting is less obvious but increasingly significant. Consultants, software developers, and integration firms that work on federal contracts while simultaneously maintaining contractual relationships with foreign governments or state-owned enterprises can trigger FARA obligations. The Justice Department has made clear in guidance documents that the statute is not limited to political operatives. Any person acting as an agent of a foreign principal, including in commercial or technical capacities, may be required to register.

In 2019, Gregory Craig, a former White House counsel, was indicted on a false statements charge tied to alleged concealment of FARA-related work for Ukraine, and was acquitted by a jury. The case nonetheless reflected renewed prosecutorial interest after the Manafort prosecution. The Justice Department has also issued public advisory opinions on how the statute applies to new fact patterns.

The practical implication for tech contractors is real. A software firm that receives direction from a foreign state-owned company while also holding a federal contract may face criminal exposure if it fails to register. The statute carries penalties of up to five years in prison and substantial fines.

How Federal Procurement Rules Add Another Layer

Beyond CFIUS and FARA, the federal acquisition system itself has developed robust mechanisms to screen for foreign ties. The Federal Acquisition Regulation, the FAR, and its Defense counterpart, the DFARS, impose a series of requirements on contractors that touch on country of origin, supply chain provenance, and telecommunications equipment.

Section 889 of the 2019 National Defense Authorization Act became one of the most sweeping supply chain provisions ever enacted. It barred federal agencies from procuring telecommunications equipment or services from five named Chinese companies, including Huawei Technologies and ZTE Corporation. More significantly, it later prohibited agencies from doing business with any contractor that itself uses such equipment anywhere in its operations, not just in the government-facing portion of its work. The compliance burden that provision created for contractors was enormous. Many large integrators spent months auditing their internal networks to verify they could certify compliance.

Contractors must also navigate the Cybersecurity Maturity Model Certification program, known as CMMC, which the Department of Defense has been rolling out since 2020. By requiring independent audits of cybersecurity practices for companies handling controlled unclassified information, CMMC forces contractors to demonstrate that their systems cannot be accessed or compromised through foreign-linked vulnerabilities. The program has faced implementation delays and revisions, but its core architecture remains focused on verifying that sensitive defense information does not flow through compromised systems.

The State Department and intelligence community contracts carry additional restrictions. Prospective contractors seeking access to classified programs undergo personnel security investigations and facility security clearances that explicitly examine foreign national contacts, dual citizenship, and foreign financial interests. An employee with undisclosed financial ties to a foreign government-linked entity can jeopardize an entire company’s clearance.

Where the System Strains: Gaps, Loopholes, and Emerging Threats

For all its breadth, the vetting architecture has genuine blind spots, and national security professionals are candid about them.

Venture capital presents one of the most persistent challenges. Startup companies rarely file for CFIUS review voluntarily, and minority investments from foreign limited partners in American venture funds have historically flown under the radar. FIRRMA took steps to close this gap by covering TID (technology, infrastructure, and data) investments, but enforcement remains challenging. A February 2024 report from the House Select Committee on the Chinese Communist Party found that five American venture capital firms had together invested at least $3 billion in Chinese artificial intelligence and semiconductor companies.

Cloud computing infrastructure introduces another layer of complexity. When a foreign-linked company provides cloud services consumed by federal contractors, the data pathway may not be visible to contracting officers reviewing a vendor’s disclosure forms. The government has addressed this partially through FedRAMP, the authorization program for cloud products used by federal agencies, but FedRAMP does not cover the full ecosystem of subcontractors and third-party integrations that major cloud providers rely on.

Open source software is perhaps the most vexing issue. Federal contractors routinely incorporate open source libraries and components into the software they deliver to agencies. Those components may have been authored or maintained by developers with ties to foreign governments, raising supply chain risk that no current disclosure framework fully addresses. The 2021 Log4Shell vulnerability, discovered in a widely used Java logging library maintained by volunteers, dramatized how catastrophically open source dependencies can be exploited, even without any deliberate foreign interference.

Critics from the technology and business communities argue that the vetting apparatus has grown so complex and unpredictable that it deters legitimate foreign investment in American innovation. The U.S. Chamber of Commerce and other industry groups have repeatedly warned that overly aggressive CFIUS reviews create uncertainty, reduce capital formation in strategic sectors, and push foreign investors toward competitors in Europe and elsewhere. Some legal scholars argue that FARA’s vague definitions of “agent” and “direction” create constitutional due process concerns when applied outside traditional lobbying contexts.

The Enforcement Frontier: Outbound Investment and New Executive Authorities

A significant and relatively recent development in this story is the shift toward scrutinizing not only what comes into American technology but what goes out. In August 2023, President Biden signed an executive order directing Treasury to establish a program to regulate certain outbound investments by American persons into foreign entities in sensitive technology sectors. The order focused specifically on semiconductors, quantum computing, and artificial intelligence, directing Treasury to prohibit or require notification for investments that could accelerate adversaries’ military and intelligence capabilities.

This was a conceptual departure. CFIUS had always operated on the premise that the threat flowed inward, that foreign acquisition of American technology was the danger to be managed. The outbound investment order acknowledged that American capital, knowhow, and technical partnerships flowing to adversarial countries were themselves national security risks, even when no American company was being acquired.

Treasury published its implementing regulations in late 2024, and the program became operational, adding a new compliance obligation for private equity firms, corporate venture arms, and strategic partnerships with entities in covered countries. The scope remains narrower than many national security hawks had wanted, but the framework exists and can be expanded.

Meanwhile, the Biden and subsequent administrations have used export control authorities under the Export Administration Regulations to restrict the transfer of advanced semiconductor technology, particularly extreme ultraviolet lithography equipment and the most advanced chips, to China. These restrictions, coordinated with the Netherlands and Japan in 2023, represent an unprecedented multilateral effort to slow a competitor’s technological advancement through supply chain interdiction.

Looking Ahead: Integration, Automation, and the Limits of Disclosure

The central challenge facing U.S. vetting mechanisms is a structural one. The systems were built in different eras, for different threat models, and they have been extended and patched rather than redesigned. FARA dates to 1938. CFIUS was formalized in 1988. The FAR’s core architecture is older still. Layering FIRRMA, CMMC, Section 889, and the outbound investment order on top of these foundations has created a compliance landscape that is simultaneously overcrowded in some areas and porous in others.

The intelligence and law enforcement communities are increasingly turning to automated tools to surface hidden foreign connections that voluntary disclosure frameworks miss. Analytical tools could help identify undisclosed foreign government links through corporate registry data, beneficial ownership filings, and financial transaction records. The Corporate Transparency Act, which took effect in 2024, created a beneficial ownership database at the Financial Crimes Enforcement Network. Since a March 2025 interim final rule, however, only foreign-formed companies registered to do business in the United States must report, which sharply limits its value for cross-referencing against CFIUS filings and contractor registrations.

Artificial intelligence is both the subject of intense scrutiny and a tool in the vetting process itself. Machine learning systems could in principle be used to analyze contract bids, subcontractor networks, and financial disclosures for anomalous patterns that might indicate undisclosed foreign influence. The irony is not lost on national security professionals: the technology that is most contested between the United States and its adversaries is also the technology being recruited to protect the integrity of the contracting system.

The fundamental tension in all of this is unlikely to be resolved cleanly. American technology companies depend on global supply chains, international talent, and foreign capital markets. The government needs the best technology it can procure, and the best technology often comes from companies with complicated international footprints. The vetting apparatus exists to manage that tension, not to eliminate it.

What has changed since the Broadcom decision in 2018 is the political and institutional seriousness with which that tension is taken. Agencies that once rubber-stamped foreign-linked deals now conduct granular reviews. Contractors that once ignored FARA now have compliance officers studying it. And a generation of technology executives who grew up in the era of frictionless globalization are learning that the infrastructure of national security scrutiny is not going away. If anything, it is becoming the new normal cost of doing business with the world’s largest customer.

Advertisement