Examples
Worked examples
- Is an instance
A foreign-headquartered technology company acquires a controlling equity stake in a university spinout holding an exclusive license to an EAR-controlled sensor technology developed under a federally sponsored research agreement — a covered control transaction, likely also subject to a mandatory CFIUS declaration because the underlying technology is export-controlled and therefore a critical technology.
- Is an instance
A foreign venture capital fund takes a 12% non-controlling position in a university spinout developing an emerging quantum-sensing technology, with a contractual right to appoint a board observer — under FIRRMA's non-controlling-investment jurisdiction, this can be a CFIUS-covered investment even though the fund never gains control of the company.
Counter-examples
Looks similar, but isn't
- Not an instance
A university admits an international PhD student into a lab that works with export-controlled equipment — managing that student's access is a deemed-export question addressed through export licensing or a Technology Control Plan, not a CFIUS matter, because no equity investment, acquisition, or governance right in a US business is involved.
Editorial commentary
CFIUS — the Committee on Foreign Investment in the United States — is the US federal interagency committee that reviews certain transactions by foreign persons for national security risk. It is chaired by the Secretary of the Treasury, with the Departments of Defense, State, Commerce, Justice, Homeland Security, and Energy among its member agencies. CFIUS acts under Section 721 of the Defense Production Act of 1950 (originally added as the 1988 Exon-Florio Amendment, substantially revised by the Foreign Investment and National Security Act of 2007 and again by the Foreign Investment Risk Review Modernization Act of 2018, or FIRRMA), codified at 50 U.S.C. § 4565 and implemented through regulations at 31 CFR Part 800. CFIUS does not review every foreign transaction in the US economy — only “covered transactions” that fall within its statutory jurisdiction.
What makes a transaction “CFIUS-covered”
Two categories of transaction fall within CFIUS jurisdiction:
- Covered control transactions — any transaction that could result in foreign “control” of a US business, regardless of industry.
- Covered investments — a category FIRRMA added in 2018 that reaches certain non-controlling investments by a foreign person in a “TID US business” (a US business involved in critical Technology, critical Infrastructure, or sensitive personal Data), where the investment grants the foreign investor board or observer rights, the right to nominate a board member, access to the business’s material nonpublic technical information, or involvement in substantive decision-making regarding the TID business’s critical technology, infrastructure, or data.
This second category — non-controlling investment jurisdiction — is the most consequential change FIRRMA made for research institutions and their spinouts. Before 2018, a foreign investor taking a small, non-controlling equity stake in a US company was generally outside CFIUS’s reach; a foreign VC fund taking a 10–15% stake with a board observer seat in a critical-technology startup can now be a covered transaction in its own right. Certain covered transactions involving critical technologies or a foreign government’s “substantial interest” also trigger a mandatory declaration to CFIUS rather than a purely voluntary filing (31 CFR § 800.401).
Why this matters for university technology transfer specifically
University spinout companies — formed to commercialize faculty or lab-originated intellectual property, often through an exclusive license from the institution’s technology transfer office — are a genuine, frequently overlooked point of CFIUS exposure. Two conditions combine to create it:
- Spinouts built around federally sponsored research in defense-adjacent, semiconductor, biotechnology, AI, quantum, advanced materials, or similar fields often hold or develop technology that meets CFIUS’s definition of “critical technology” — a definition that explicitly includes items controlled under US export control regulations (the EAR and ITAR), certain nuclear- and defense-related items, and the “emerging and foundational technologies” identified under the Export Control Reform Act of 2018. A spinout meeting that definition is a TID US business.
- Early-stage spinouts routinely raise capital from non-US investors — foreign corporate strategic partners, foreign-domiciled venture funds, or funds with foreign limited partners who hold governance rights — well before they are large enough to attract a controlling acquirer.
Put together: a seed or Series A round in a university spinout that brings in a foreign investor with a board seat, board-observer rights, or access to the company’s technical data can be a CFIUS-covered investment even though no one is acquiring control of the company. Since FIRRMA took effect, CFIUS filing volume tied to venture financings of this kind has risen substantially. For a technology transfer office, this means the export-control classification work already done on a licensed technology — whether it is subject to the EAR or ITAR, and whether a Technology Control Plan is in place — is not just an institutional compliance question. It becomes an input the spinout and its counsel need when screening a later funding round for CFIUS exposure, because export-control status is one of the tests for whether the company counts as a critical-technology TID business at all. TTOs negotiating license and equity terms for a spinout are increasingly asked, as part of that company’s own diligence process, to confirm the licensed technology’s export classification for exactly this reason.
CFIUS vs. export control (EAR/ITAR) — related but legally distinct regimes
CFIUS and US export control law are frequently confused because they address overlapping national-security concerns, but they are separate legal regimes, administered by different agencies, triggered by different facts, and carrying different remedies:
- CFIUS governs foreign investment — who owns, controls, or holds governance/information rights in a US business. It is triggered by a transaction: an acquisition, merger, or qualifying investment.
- EAR and ITAR govern the export or transfer of controlled technology and technical data — who may access, receive, or be shown controlled items or information, including a release to a foreign national within the United States (a deemed export). They are triggered by an act of transfer or disclosure, independent of who owns the company.
A transaction can trigger one regime without the other. A foreign national graduate student granted access to export-controlled research materials in a US university lab raises a deemed-export question under the EAR or ITAR — no foreign investment or acquisition of a business is involved, so CFIUS has no jurisdiction over it at all. Conversely, a foreign investor buying a passive, governance-free minority stake in a spinout that holds no critical technology, critical infrastructure, or sensitive personal data generally falls outside CFIUS’s TID jurisdiction, even though ownership has changed. In practice, the two regimes overlap most often for exactly the university-spinout scenario above, because export-control classification is one of the definitional building blocks of CFIUS’s “critical technology” test — meaning the same underlying export-control determination frequently answers a question in both reviews, even though the reviews themselves, their filings, and their potential remedies (an EAR/ITAR license or debarment action versus a CFIUS mitigation agreement or presidential divestment order) remain entirely separate.
Worked examples
- A foreign-headquartered technology company acquires a controlling equity stake in a university spinout that holds an exclusive license to an EAR-controlled sensor technology developed under a federally sponsored research agreement. This is a covered control transaction, and because the underlying technology is export-controlled (and therefore a critical technology under CFIUS’s definition), it is also likely subject to a mandatory CFIUS declaration rather than a purely voluntary filing.
- A foreign venture capital fund takes a 12% non-controlling position in a university spinout developing an emerging quantum-sensing technology, with a contractual right to appoint a board observer. Even though the fund never gains control of the company, this can be a CFIUS-covered investment under FIRRMA’s non-controlling-investment jurisdiction, because the observer right gives the foreign investor involvement in the TID business’s decision-making.
Counter-example
A university admits an international PhD student into a lab that works with export-controlled equipment. Managing that student’s access is a deemed-export question addressed through export licensing or a Technology Control Plan — it is not a CFIUS matter, because no equity investment, acquisition, or governance right in a US business is involved at any point.
Review process, briefly
Parties file either a short-form declaration (CFIUS generally responds within 30 days) or a full written notice (an initial 45-day review). If concerns remain after a notice review, CFIUS can open a further 45-day investigation, with a limited extension available in extraordinary circumstances. If CFIUS refers a transaction to the President, the President has 15 days to clear, condition, or block it. Most filings are cleared without escalating that far, often subject to a mitigation agreement rather than an outright block.
Frequently asked questions
Does CFIUS apply to a university itself, or only to its spinout companies?
CFIUS reviews transactions involving US businesses, not academic institutions as such. A nonprofit university is not typically the direct subject of a CFIUS filing, but a for-profit spinout company it has licensed technology to — and in which it may hold an equity stake — can be.
Does a university’s own equity stake in a spinout trigger CFIUS?
No — CFIUS jurisdiction depends on the involvement of a foreign person. A US university taking equity in its own spinout, without a foreign investor also participating on qualifying terms, does not by itself raise a CFIUS question.
Is a CFIUS filing always mandatory?
No. Most CFIUS filings are voluntary, made to obtain a safe-harbor clearance. A mandatory short-form declaration applies only to a narrower set of transactions — principally certain critical-technology TID businesses and transactions involving a foreign government’s substantial interest — defined in 31 CFR § 800.401.
References
- U.S. Department of the Treasury, “The Committee on Foreign Investment in the United States (CFIUS)” (home.treasury.gov/policy-issues/international/the-committee-on-foreign-investment-in-the-united-states-cfius)
- 31 CFR Part 800, “Regulations Pertaining to Certain Investments in the United States by Foreign Persons” (ecfr.gov)
- Section 721 of the Defense Production Act of 1950, as amended by FIRRMA (2018), codified at 50 U.S.C. § 4565
- U.S. Department of the Treasury, “CFIUS Laws and Guidance”
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="CFIUS (Committee on Foreign Investment in US)"
vocab-term-identifier="https://casrai.org/dictionary/term/cfius" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/cfius",
"name": "CFIUS (Committee on Foreign Investment in US)",
"identifier": "https://casrai.org/dictionary/term/cfius",
"description": "CFIUS (the Committee on Foreign Investment in the United States) is the US federal interagency committee, chaired by the Secretary of the Treasury and acting under Section 721 of the Defense Production Act of 1950 (as amended by FIRRMA in 2018) and its implementing regulations at 31 CFR Part 800, that reviews “covered transactions” — foreign acquisitions of control of a US business, and, since FIRRMA, certain non-controlling foreign investments granting governance or information rights in a critical-technology, critical-infrastructure, or sensitive-personal-data US business (a “TID US business”) — for national security risk.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
"url": "https://casrai.org/dictionary/term/cfius",
"sameAs": [],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"dateModified": "2026-07-17T07:19:17",
"inLanguage": "en"
}






