Dentons Law Firm Releases Research Report: "National Security Review Process, Regulatory Red Lines, and Corporate Compliance Practice in Light of Meta's Blocked Acquisition"

Based on two major regulatory events—the NDRC's blocking of Meta's acquisition of the Chinese AI platform Manus and the illegal graphite export by a domestic company—this report systematically analyzes the legal grounds and review mechanisms of China's foreign investment security review and export controls. It highlights regulatory red lines across five core security sectors (technology, industry, resources, data, and national defense) and provides full-process cross-border compliance guidance and risk prevention frameworks for domestic enterprises, foreign acquirers, and strategic material exporters.

Dentons Law Firm Releases Research Report:

         In late April 2026, Chinese regulators issued two landmark regulatory decisions, directly targeting two core security areas: key technologies acquired by foreign companies and the illegal export of strategic materials. These decisions drew clear red lines for global cross-border transactions and the compliant operation of Chinese companies.

(I) Case 1: Meta's acquisition of Manus was banned (April 27, 2026, National Development and Reform Commission)

Transaction entities: Acquirer Meta Platforms, Inc. (formerly Facebook, a global technology giant); Target company Manus (Butterfly Effect, a Chinese original general-purpose artificial intelligence AGI platform).

Transaction Background: The Chinese team was established in Beijing in 2024. In March 2025, Manus was launched and became a global phenomenon in AGI products. In June 2025, the company moved its headquarters to Singapore, laid off its domestic team, and ceased services in China. In December 2025, Meta completed the acquisition for $2 billion, planning to completely sever ties with China.

Illegal structures: Attempts to circumvent China's foreign investment security review by relocating business registrations offshore, separating domestic assets, and transferring technology and data overseas.

Regulatory outcome: The Office of the Working Mechanism for Security Review of Foreign Investment (led by the National Development and Reform Commission) formally prohibited investment, ordered the cancellation of the transaction, ordered the restoration of the original state within a specified period, returned all transaction consideration, and deleted domestic data.

Core risks: The core AGI algorithm, training data, technical team, and intellectual property are 100% sourced from China, involving key technology security, data security, industrial sovereignty, and supply chain security.

(II) Case 2: Pu Mou Co., Ltd. was criminally liable for illegally exporting graphite (April 25, 2026, Yingkou Municipal People's Procuratorate)

The parties involved are: listed company Puyang Co., Ltd. (002225), Yingkou Wanmou Logistics, and four senior executives (Deputy General Manager of the Steel Division, Minister of Overseas Marketing, and Head of Documentation Section, etc.).

Illegal facts: Since December 1, 2023, natural flake graphite has been included in the "Export Control Catalogue of Dual-Use Items" and requires a license from the Ministry of Commerce for export; the company falsely declared the tariff code (changing the controlled tariff code 2504101000 to the uncontrolled 2504109900) and smuggled 1,243.55 tons without a license, involving a case amount of RMB 5.9847 million.

The company was prosecuted for smuggling goods prohibited from import and export by the state. The company and its executives face criminal liability, huge fines, market bans, and credit sanctions. The stock price fell to the daily limit for two consecutive days.

Core risks: Natural flake graphite is a core strategic resource for new energy, semiconductors, and military industries. Illegal outflow of natural flake graphite endangers national resource security, the independent control of the industrial chain, and national defense security.

This article systematically analyzes the legal basis, review mechanism, full-process rules, regulatory red lines, and global comparisons of China's foreign investment security review and export control from three dimensions: top-level design of national security, perspectives from legal experts from multiple countries, and practical operations of domestic and foreign enterprises. It provides full-process compliance guidance and risk prevention solutions for primary/secondary markets, controlling shareholders, overseas investors, and listed companies.

II. Top-level Logic: The Strategic Positioning and Legal Basis of National Security Review

(I) The essence of the system: a core defense line that emphasizes both openness and security.

National security review is a statutory regulatory system established by the National Security Law and the Foreign Investment Law. Its core is to firmly safeguard the bottom line of national security while opening up to the outside world at a high level, and to balance "bringing in" and "preventing risks". It is not about being closed and conservative.

(II) Targets of Protection: Five Core Security Areas

1. Technological Security: Key core technologies such as AI, chips, quantum technology, biomedicine, and high-end equipment.

2. Industrial security: strategic emerging industries, independent control of industrial and supply chains, and control over leading enterprises.

3. Resource security: strategic minerals and key raw materials such as rare earth, graphite, lithium, gallium, and germanium.

4. Data security: core business data, population/healthcare/finance/geographic information, and critical infrastructure data.

5. National defense and security: military industry, military supporting facilities, and the surrounding areas of military facilities.

(III) Underlying Principles: Substance over form, and comprehensive long-arm jurisdiction

Substantive review: Regardless of the place of registration or delivery of the transaction entity, as long as the technology/data/resources/team originates from China and affects China's national security, it will be included in the review.

Avoidance is prohibited: Offshore relocation, VIE structures, and the separation of domestic assets are all invalid.

Consequences of violations: The transaction is invalid from the outset, and if it has already been implemented, it must be revoked, the original state restored, the assets returned, and those responsible held accountable and punished.

(iv) Regulatory trends: normalization, stricter enforcement, and full-chain coverage

  • The scope of the review has expanded from traditional military industry to all fields including high technology, data, and strategic resources.

  • The focus has shifted from post-event penalties to a full-cycle approach encompassing pre-event reporting, in-event supervision, and post-event accountability.

  • Foreign investment security review, export control, and technology control are integrated into a closed-loop regulatory system.

III. Review Mechanism and Applicable Rules

(I) Three statutory review standards (Article 4 of the Measures for Security Review of Foreign Investment)

1. Sensitive Areas: Does it involve national security sensitive areas such as military industry, key technologies, important energy resources, critical infrastructure, important data, and cybersecurity?

2. Acquisition of Control: Whether foreign capital has acquired actual control (equity ≥ 50%, significant voting rights, control over operations/technology/data, and dominance over personnel appointments and removals).

3. Security risks: Whether it affects or may affect national security (technology loss, data loss, supply chain disruption, resource depletion, defense risks).

(ii) Rules for the application of long-arm jurisdiction

Applicable scenarios: The core technology, training data, intellectual property, key team, and strategic resources of the target are sourced in China; the transaction circumvents domestic supervision through offshore structures, indirect control, and relocation of registration.

Regulatory effect: Chinese law has extraterritorial effect, and illegal transactions must be revoked and the original state restored regardless of where the transaction is settled.

(III) Dual regulatory system: foreign investment review + export control

Foreign mergers and acquisitions: The "Measures for Security Review of Foreign Investment" apply, prohibiting the outflow of control over key technologies/data/resources.

Export of goods/technology: Subject to the Export Control Act and the Dual-Use Items Catalogue, export without a license is prohibited and false declarations are suspected of being criminal offenses.

IV. Regulatory Red Lines: Key Sensitive Areas and Prohibited/Restricted Lists

(I) High-tech and key technologies (core red line of primary market)

Artificial intelligence: AGI, large models, general intelligent agents, algorithmic frameworks, training data (such as Manus).

Semiconductors: chip design/manufacturing/packaging and testing, EDA, lithography machines, semiconductor materials.

Cutting-edge technologies: quantum computing, brain-computer interface, 6G, aerospace, and deep-sea equipment.

Biopharmaceuticals: Innovative drugs, gene technology, vaccines, and high-end medical equipment.

Cybersecurity: Critical information infrastructure, data security, cryptography.

(II) Strategic Resources and Critical Materials (High Risk in the Secondary Market)

Rare earth elements and rare metals: rare earth permanent magnets, tungsten, antimony, indium, germanium, gallium.

New energy minerals: natural flake graphite, lithium, cobalt, nickel, vanadium (the categories involved in the case of Puyang Refractories).

Key raw materials: special steel, high-end ceramics, nuclear materials, and military chemical products.

(III) Core Data and Infrastructure

Critical information infrastructure: energy, transportation, communications, finance, government affairs, and defense facilities.

Core data: population health, financial credit, geospatial data, supply chain data, and industrial control data.

V. Practical Operation Guidelines for Multiple Parties

(a) Chinese enterprises/actual controllers (sellers/technology holders)

1. Beforehand: Risk assessment and compliance preparation

  • Before transferring core assets, a national security review and assessment should be conducted to determine whether they fall into sensitive areas.

  • Avoidance behaviors such as relocating registrations offshore, cutting off domestic operations, and transferring technical data overseas are strictly prohibited.

  • We hired professional lawyers and accountants to conduct compliance due diligence and design transaction plans.

2. During the process: Standardizing transactions and proactive reporting

  • Those who meet the application criteria must proactively apply before investing; no one should act first and then inform the applicant.

  • The transaction documents clearly stipulate compliance terms, applicable Chinese law, and regulatory compliance obligations.

  • Technology/data shall be stored and controlled within the country, and illegal export shall be prohibited.

3. Post-event: Enforcing decisions and long-term compliance

  • Upon receiving the review decision, it shall be executed immediately, and delay or disguised resistance is prohibited.

  • Establish an internal control list for core technologies, data, and resources, and conduct annual audits.

(ii) Overseas acquirer (buyer/foreign investor)

1. Due Diligence: Comprehensive Assessment of Security Review Risks in China

  • The key areas of investigation include tracing the origins of technology, data, and resources; linking domestic assets; and identifying the core team.

  • Confirm whether the reporting obligation, sensitive areas, and control standards have been triggered.

2. Transactions: Abandon illegal structures and proactively cooperate.

  • It does not employ illegal structures such as offshore registration transfer, VIE, nominee shareholding, or separation from domestic entities.

  • Actively seek advice, declare in accordance with the law, and fully cooperate with regulatory review.

  • The contract stipulates compliance responsibilities, compensation for breach of contract, and clauses for the enforcement of regulatory decisions.

3. Implementation: Strictly adhere to the decision without any compromise.

  • The investment ban must be immediately revoked, the equity assets returned, the data deleted, and the original state restored.

  • For those approved under conditions, the additional conditions must be strictly enforced, and regular reporting is required.

(iii) Strategic material/technology export enterprises (such as Puyang Co., Ltd.)