- The Foreign Investment Security Review Measures (NDRC & MOFCOM, issued 19 Dec 2020, effective 18 Jan 2021) are the legal basis; the review working-mechanism office sits in the NDRC, led by NDRC and MOFCOM.
《外商投资安全审查办法》(发改委、商务部,2020年12月19日发布,2021年1月18日施行)是法律依据;安全审查工作机制办公室设在发改委,由发改委、商务部牵头。- Review is mandatory where the investment is in a covered sector (defence; important agriculture/energy/equipment/infrastructure/transport/culture/IT-internet/finance/key tech) AND the foreign investor obtains actual control (50%+ equity, material voting influence, or material influence on decisions/personnel/finance/tech).
当投资位于受涵盖领域(国防;重要农产品/能源/装备/基础设施/运输/文化/信息技术互联网/金融/关键技术)且外国投资者取得实际控制权(50%以上股权、重大表决影响、或对决策/人事/财务/技术重大影响)时须审查。- The timeline: 15 working days to decide whether to review, then 30 working days general review, then 60 working days special review (extendable); implementation is prohibited until a clearance decision.
时间线:15个工作日决定是否审查,再30个工作日一般审查,再60个工作日特别审查(可延长);作出核准决定前不得实施投资。- On 27 April 2026 the working-mechanism office issued a prohibition decision on Meta’s ~USD 2bn acquisition of AI firm Manus — the first publicly halted foreign acquisition in the AI field under the Measures.
2026年4月27日,工作机制办公室就Meta约20亿美元收购AI企业Manus作出禁止投资决定——是该《办法》下首例被公开叫停的AI领域外资收购案。- The Manus case turned on “technology origin” (R&D-location standard) and asset-in-China control: moving core tech/IP offshore without filing triggered review and a forced unwind, with repayment of the ~USD 2bn consideration.
Manus案聚焦”技术原产地”(研发地标准)与境内资产控制:未申报即将核心技术/知识产权转移境外触发审查并被强制撤销,须退还约20亿美元对价。- Practical rule: screen security review before merger control — its control test is broader, it can prohibit where antitrust would clear, and non-filing carries corrective orders, credit blacklisting and joint punishment.
实务规则:先于经营者集中筛查安全审查——其控制标准更宽、可在反垄断通过时禁止,且未申报将招致责令申报、信用黑名单与联合惩戒。
National Security Review of Foreign M&A in 2026: Scope, Process and the Meta–Manus Precedent | 2026年外资并购国家安全审查:范围、程序与Meta–Manus先例
The legal backbone
China’s foreign-investment national security review is founded on the *Foreign Investment Law* (Art. 35) and implemented through the *Measures for Foreign Investment Security Review* (外商投资安全审查办法), issued jointly by the National Development and Reform Commission (NDRC) and MOFCOM on 19 December 2020 and effective 18 January 2021. The security-review working mechanism is led by the NDRC and MOFCOM, with its office housed in the NDRC. The mechanism coordinates and guides review work and, where needed, can require a party to file even where the party has not self-identified a trigger.
For a foreign acquirer, the single most important behavioural point is sequencing: security review can prohibit a deal that merger control would have cleared, and its “actual control” test is broader than antitrust’s. Screen it first.
When review is mandatory
Review is required before implementation where the investment falls in a covered scope AND the foreign investor obtains actual control:
- Covered scope — investment in defence and defence-supporting areas, and around military facilities; or investment in important agriculture, energy and resources, major equipment manufacturing, important infrastructure, important transport services, important culture, important IT and internet products/services, important financial services, key technologies and other important areas.
- Actual control — the investor holds 50%+ equity; or holds under 50% but its voting rights can materially influence board/shareholder resolutions; or other circumstances where the investor can materially influence the target’s business decisions, personnel, finance or technology.
Where the deal is in scope but control is not obtained, filing is generally not mandated — though the mechanism may still call it in. And where a deal is below the merger-control turnover thresholds, security review can still be triggered independently by scope and control. This is the trap: size alone never settles the security question.
The process and its clock
The procedure is staged. Upon receiving a complete filing, the working-mechanism office decides within 15 working days whether a review is needed; the parties may not implement the investment before that decision. If a review proceeds, general review is completed within 30 working days. If general review finds a possible national-security effect, a special review is launched and completed within 60 working days (extendable in special circumstances, with written notice). Decisions are: pass; prohibit; or pass with conditions (where conditions can eliminate the effect and the party accepts them in writing). During all review stages, implementation is suspended, and the parties may modify or withdraw the scheme.
A prohibited decision requires the party to unwind — dispose of equity/assets and take other necessary steps to restore the pre-investment state and eliminate the national-security effect. Non-filing where filing was required draws a corrective order to file; refusal leads to an order to dispose of equity/assets and restore the prior state, plus inclusion in the national credit system as a bad-records entry and joint punishment under relevant rules.
The 2026 Meta–Manus precedent
The most consequential 2026 development is the Meta–Manus case. Manus is a general-purpose AI agent product launched in China in March 2025 and quickly became a high-profile domestic AI success. In December 2025, US tech giant Meta announced a roughly USD 2 billion acquisition. On 8 January 2026, MOFCOM spokesperson He Yadong said authorities would assess the transaction’s consistency with export-control, technology import/export and outward-investment rules; on 2 April 2026 MOFCOM reiterated that relevant conduct must comply with Chinese law and procedures. On 27 April 2026, the NDRC security-review working-mechanism office issued a prohibition decision on the foreign acquisition of the Manus project, requiring the parties to rescind the transaction.
This is the first AI-field foreign acquisition publicly halted under the Measures in the nearly six years since their issuance. The stated logic: although the transacting entities were formally offshore, Manus’s core technology, team and data were deeply rooted in China; restructuring the entity offshore while moving core code, documentation and IP out of China without filing constituted, in substance, transferring key Chinese assets to foreign control — squarely within the covered “key technologies / important IT and internet” scope with actual control obtained.
The case also invoked the export-control dimension: China applies a “technology origin” (technology nationality by R&D location) standard, so moving China-developed technology offshore can constitute a de facto technology export requiring a licence. Parties that fail to obtain one risk civil, administrative or even criminal liability under export-control law. For foreign acquirers, the lesson is that the form of an offshore red-chip-style restructuring does not remove the substance of China-based assets from review.
Interaction with merger control and the negative list
Security review operates alongside — not instead of — merger control and the negative list. A strategic investment in a listed company, for example, must respect the negative list (no prohibited sectors; restricted sectors meet list conditions) and, if it constitutes a concentration above the thresholds, clear SAMR; and if it affects national security, clear security review. The three gates are independent: a pass from one does not substitute for another, and security review can override the others. This is why the deal team should run a security-review scope-and-control screen at term-sheet stage, in parallel with the antitrust analysis.
What to do next
- Screen the target’s sector against the covered-security list; if in scope and control is likely, assume a mandatory filing.
- Map “actual control” broadly — minority stakes with veto/influence rights can qualify; do not assume only majority ownership triggers review.
- File and wait: no implementation before the 15-working-day decision, and stay suspended through general/special review.
- For China-origin technology or data assets, assess export-control licensing alongside security review — offshore restructuring does not escape either.
- Expect the security screen to run in parallel with, and potentially override, merger control and sector licensing.
- Build the long-stop around the full 15+30+60 (extendable) path, and reserve the right to modify or withdraw the scheme during review.
Cross-border structuring lessons
The Meta–Manus outcome reframes how offshore restructurings are read in China. Moving an operating company’s domicile or IP offshore, while the technology, team and data remain in China, does not remove the assets from the security-review and export-control net — the “technology origin” standard looks to where R&D occurred, not where the entity is registered. Acquirers should therefore map China-based intangible assets and key personnel explicitly, and treat any transfer of them as a potential review and licensing event, not a purely corporate step.
Coordination across agencies
Security review does not sit alone. In the Manus matter, MOFCOM assessed consistency with export-control, technology import/export and outward-investment rules alongside the NDRC security review — a multi-agency lens. Deal teams should expect the same: a sensitive technology or data transaction will be examined by the security-review mechanism, the export-control authority and, if a concentration, SAMR, often on overlapping facts. Building one consistent factual and legal narrative across all three is cheaper than retrofitting it after a challenge.
A practical pre-filing screen
Before term sheet, run four questions: (1) Is the target in a covered-security sector (defence, key tech, IT/internet, energy, infrastructure, finance, etc.)? (2) Will the foreign investor obtain actual control — including minority veto or material-influence rights? (3) Does the deal move China-origin technology, data or IP offshore, triggering export-control licensing? (4) Could it also be a concentration above the SAMR thresholds? If any answer is yes, build the review/licence track into the deal timeline and budget, and keep implementation suspended until clearance. This screen, done early, prevents the late rediscovery that doomed the Manus transaction.
2026年外资并购国家安全审查:范围、程序与Meta–Manus先例
法律主干
中国外商投资国家安全审查以《外商投资法》(第35条)为基础,通过《外商投资安全审查办法》实施。该办法由国家发展改革委、商务部于2020年12月19日联合发布,2021年1月18日施行。安全审查工作机制由发改委、商务部牵头,办公室设在发改委,负责组织协调指导审查工作,并在必要时可要求当事人申报,即便当事人未自行识别触发情形。
对外国收购方而言,最关键的行为要点是排序:安全审查可在经营者集中通过时禁止交易,且其”实际控制”标准宽于反垄断。应首先筛查。
何时须审查
当投资落入受涵盖范围且外国投资者取得实际控制权时,须在实施前审查:
- 受涵盖范围——军工、军工配套及军事设施周边;或重要农产品、能源资源、重大装备制造、重要基础设施、重要运输服务、重要文化、重要信息技术和互联网产品与服务、重要金融服务、关键技术等重要领域。
- 实际控制——投资者持股50%以上;或持股不足50%但表决权对董事会/股东会决议产生重大影响;或其他对经营决策、人事、财务、技术产生重大影响的情形。
交易在范围内但未取得控制权的,一般不强制申报——但机制仍可要求申报。而未达经营者集中营业额门槛的交易,亦可因范围与控制独立触发安全审查。这就是陷阱:规模本身从不决定安全问题。
程序与时钟
程序分阶段。收到齐备材料后,工作机制办公室于15个工作日内决定是否审查;当事人在该决定前不得实施投资。若进入审查,一般审查于30个工作日内完成。若一般审查认为可能影响国家安全,启动特别审查并于60个工作日内完成(特殊情况可延长并书面通知)。决定为:通过、禁止、或附条件通过(条件可消除影响且当事人书面接受)。各审查阶段均暂停实施,当事人可修改或撤销方案。
禁止决定要求当事人撤销——处分股权/资产并采取其他必要措施,恢复投资前状态、消除国家安全影响。应申报而未申报的,责令申报;拒不申报的,责令处分股权/资产恢复前状,并作为不良信用记录纳入国家信用系统、依规定联合惩戒。
2026年Meta–Manus先例
2026年最具影响的进展是Meta–Manus案。Manus是2025年3月在中国发布的通用AI智能体产品,迅速成为国内AI标杆。2025年12月,美国科技巨头Meta宣布约20亿美元收购。2026年1月8日,商务部发言人何亚东表示将同相关部门评估该交易与出口管制、技术进出口、对外投资规则的一致性;2026年4月2日商务部重申相关行为须遵守中国法律与程序。2026年4月27日,发改委外商投资安全审查工作机制办公室就外资收购Manus项目作出禁止投资决定,要求当事人撤销交易。
这是该《办法》发布近6年来首例被公开叫停的AI领域外资收购案。其逻辑:尽管交易主体形式在境外,Manus核心技术、团队与数据深植中国;在境外重组实体并将核心代码、文档与知识产权移出中国而未申报,实质上构成将中国关键技术资产转移给外国控制——正落入”关键技术/重要信息技术互联网”受涵盖范围并取得实际控制。
该案亦触及出口管制维度:中国采用”技术原产地”(按研发地认定技术国籍)标准,将中国研发技术转移境外可构成事实上的技术出口,须申领许可。未获许可者面临出口管制法下的民事、行政乃至刑事责任。对外国收购方的启示是:离岸红筹式重组的形式,并不使基于中国的资产脱离审查。
与安全审查、负面清单的衔接
安全审查与经营者集中、负面清单并行而非替代。例如对上市公司战略投资,须遵守负面清单(禁止领域不得投资、限制领域满足清单条件),若构成达门槛的集中须通过SAMR,若影响国家安全须通过安全审查。三道关口相互独立:一道通过不替代另一道,安全审查可推翻其他。因此交易团队应在条款书阶段并行启动安全审查的范围与控制筛查与反垄断分析。
下一步
- 将目标行业对照受涵盖安全清单筛查;若在范围内且可能取得控制,按强制申报处理。
- 广义界定”实际控制”——具否决权/影响力的少数股权亦可触发;勿假设仅控股才触发审查。
- 先申报后等待:15个工作日决定前不得实施,并贯穿一般/特别审查保持暂停。
- 对中国原产地技术或数据资产,将出口管制许可与安全审查并行评估——离岸重组不脱逃任一者。
- 预期安全筛查与经营者集中、行业许可并行,且可能推翻后两者。
- 长停日围绕完整15+30+60(可延长)路径设定,并保留审查期间修改或撤销方案的权利。
跨境重组的启示
Meta–Manus的结果重塑了中国对离岸重组的解读。将运营主体的注册地或知识产权移至境外,而技术、团队与数据仍留在中国,并不能使资产脱离安全审查与出口管制之网——”技术原产地”标准看研发发生地,而非实体注册地。因此收购方应明确梳理基于中国的无形资产与关键人员,并将任何转移视为潜在的审查与许可事件,而非纯粹的公司行为。
跨机构协调
安全审查并不孤立。在Manus案中,商务部就出口管制、技术进出口、对外投资规则的一致性,与发改委安全审查一并评估——一种多机构视角。交易团队应预期同样情形:敏感技术或数据交易将被安全审查机制、出口管制主管部门,以及(若构成集中)SAMR就重叠事实审查。在三方面构建一致的事实与法律叙事,远比事后补建更省成本。
实务申报前筛查
签约前自问四题:(1)目标是否处受涵盖安全领域(国防、关键技术、信息技术互联网、能源、基础设施、金融等)?(2)外国投资者是否会取得实际控制——含少数否决权或重大影响权?(3)交易是否将中国原产地技术、数据或知识产权转移境外,触发出口管制许可?(4)是否同时构成达SAMR门槛的集中?任一为是,即将审查/许可轨道纳入交易时间表与预算,并在核准前保持实施暂停。此筛查若早做,可避免Manus交易那种后期才发现的窘境。
Sources
