Why CFIUS matters more for Saudi-touching deals than most dealmakers assume

The Committee on Foreign Investment in the United States is, in 2026, one of the most consequential single regulatory bodies for any cross-border transaction touching Saudi capital and US AI, semiconductor, biotech, or critical-infrastructure assets. The 2018 FIRRMA expansion, the 2020 critical-technologies and TID-business definitions, the 2022 critical-technology mandatory-declaration framework, and the 2024-2025 outbound-investment overlay have collectively expanded CFIUS’s effective jurisdiction far beyond classical M&A. Saudi-anchored transactions — whether Humain investing in a US AI firm, PIF taking a strategic stake in a US semiconductor company, Sanabil anchoring a venture round in a covered TID business, or Mubadala (Saudi-adjacent in coordination terms) running a parallel transaction — routinely trigger CFIUS mandatory declarations or attract voluntary-notice scrutiny.

Dealmakers who assume CFIUS is a routine sign-off because Saudi Arabia is a US ally are wrong on three counts. First, CFIUS analyzes transactions on national-security grounds, not foreign-policy grounds, and Saudi-aligned vehicles are increasingly scrutinized for Chinese-coordination risks under the AI Diffusion framework. Second, the TID-business mandatory-declaration regime applies regardless of foreign-policy posture. Third, CFIUS mitigation orders — the negotiated conditions under which a deal is allowed to proceed — have become substantially more onerous post-2024 for Saudi-touching transactions in AI, advanced silicon, and quantum.

The 2024 statistics, where publicly disclosed, are instructive. CFIUS reviewed approximately 280 to 320 covered transactions in 2024 with formal notices, an additional 120 to 150 mandatory declarations, and an estimated several hundred non-notified transactions reviewed under the residual jurisdiction. Saudi-anchored deals comprised roughly 6 to 10 percent of the formal-notice volume — a smaller share than China but rising materially since 2022. The 2025-2026 cadence has continued to accelerate.

This guide walks through when CFIUS applies, the two-track filing process, the mitigation patterns that have actually worked, what gets blocked, and a practical compliance roadmap.

When CFIUS applies

CFIUS jurisdiction attaches to “covered transactions,” which include both control transactions (any foreign-person acquisition of control in a US business) and the narrower category of covered investments in TID businesses (technology, infrastructure, data — non-controlling but non-passive investments granting access to material non-public technical information, board rights, or substantive decision-making in a TID business). The TID definition is expansive in 2026 and includes essentially every US AI lab, semiconductor designer, advanced packaging firm, semiconductor manufacturing equipment vendor, model-deploying enterprise SaaS firm with sensitive personal data, and a long list of biotech, energy, and quantum players.

For Saudi-touching deals, CFIUS jurisdiction is triggered in several recurring patterns. PIF, Sanabil, or Humain taking a non-passive minority stake in a US AI firm. A US AI firm being acquired by a Humain JV. A Saudi-anchored fund-of-funds with US LP exposure investing in a TID-business portfolio company. A US semiconductor or AI firm establishing a Saudi JV that involves any US-side asset transfer. A Saudi sovereign vehicle anchoring a SPAC merger with a US TID target. In each pattern, the question is not whether CFIUS could review but whether the deal triggers a mandatory declaration, justifies a voluntary notice, or sits below the materiality threshold for either.

A subtle but important nuance: CFIUS jurisdiction over real-estate transactions adjacent to sensitive US installations also applies to Saudi-anchored real estate investments and has tripped up several 2024-2025 transactions that were not initially flagged as CFIUS exposure. Saudi real-estate funds investing in commercial property near US military installations, FBI facilities, or DOE national laboratories now routinely face CFIUS review under the FIRRMA real-estate jurisdiction.

The two-track filing process

CFIUS has two formal filing tracks. Mandatory declarations are required when a foreign-government-controlled entity acquires a “substantial interest” (25 percent or greater voting) in a TID business, or when any foreign person acquires a covered investment in a TID business that produces, designs, tests, manufactures, fabricates, or develops one or more critical technologies. PIF, Humain, and Sanabil all qualify as foreign-government-controlled for this purpose. Mandatory declarations are short-form filings (a few pages) with a 30-day review window. The Committee can clear, request a full notice, or unilaterally initiate a full review.

Voluntary notices are longer-form filings (typically 50 to 200 pages including exhibits) used either when a mandatory declaration is not required but the parties want CFIUS clearance for deal certainty, or when CFIUS has requested a notice following a declaration. The voluntary-notice review runs in two phases: a 45-day review and an optional 45-day investigation, with a possible 15-day extension. Outcomes are clearance, clearance with mitigation, abandonment under pressure, or a Presidential block (rare but real).

The strategic question for any Saudi-touching deal is which track to use. Practitioners’ rule of thumb in 2026: if the deal triggers a mandatory declaration, file the declaration and prepare a voluntary notice in parallel because CFIUS will request the notice in roughly 70 percent of Saudi-anchored TID transactions. If the deal does not trigger a mandatory declaration but involves any AI, advanced-silicon, biotech, or quantum element, file a voluntary notice for deal certainty rather than relying on CFIUS’s three-year residual jurisdiction over non-notified transactions.

A common strategic mistake is over-relying on the “no jurisdiction” memo. CFIUS counsel can, in principle, conclude that a transaction does not constitute a covered transaction or covered investment, and the parties can proceed without filing. But the residual jurisdiction means CFIUS retains the right to “non-notified” review for the life of the deal plus three years. For high-profile Saudi-touching deals, the deal-certainty value of a clean CFIUS clearance generally outweighs the time cost of a voluntary notice.

Mitigation patterns that work

CFIUS-cleared Saudi-touching deals in 2024-2026 have converged on a recurring set of mitigation provisions. Governance restrictions: the Saudi investor accepts a non-voting board observer in lieu of a director seat, or a director seat with reserved-matter restrictions excluding access to specified categories of technical and customer information. Information firewalls: specified categories of technical information (model weights, customer-data access, classified-program-adjacent IP) are walled off from the Saudi investor and its affiliates, with documented procedural controls. Personnel restrictions: Saudi national employees are barred from specified roles (typically classified-program work and certain critical-technology development teams), with documented HR processes. Audit and reporting: the US business commits to annual CFIUS compliance reports and triennial third-party audits. Government-and-officer access: the Saudi shareholder commits not to seek security clearances or access to classified information.

Beyond these standard patterns, AI-specific mitigation has emerged in 2025-2026: model-weight export restrictions, data-residency commitments preventing US-customer data from being processed in Saudi facilities without separate authorization, and explicit restrictions on the Saudi investor’s ability to direct R&D priorities in covered-technology categories. These provisions are becoming standard rather than negotiated.

A 2025-2026 trend worth flagging: the National Security Agreement (NSA) increasingly includes “downstream-investor” provisions that bind the Saudi sovereign vehicle’s portfolio companies and not just the immediate transaction parties. A PIF investment in a US AI lab can carry mitigation obligations on the AI lab’s own commercial relationships in third countries, particularly any Chinese-touching commercial activity. Negotiating the scope of downstream provisions is now a meaningful component of mitigation negotiation.

What gets blocked

CFIUS rarely formally blocks deals — most concerning transactions are abandoned under pressure during the review or restructured to avoid review entirely. The fact pattern that produces formal block recommendations or forced abandonment in Saudi-touching deals is consistent: targets working in classified US Department of Defense programs; targets with sensitive personal-data holdings of US persons exceeding the FIRRMA thresholds; targets in advanced-semiconductor design or fabrication where the deal would meaningfully advance Saudi (or by extension, Chinese-aligned) capability; and targets in critical-infrastructure categories such as power-grid technology and undersea-cable systems with national-security implications.

Two further patterns produce blocks despite seemingly clean Saudi parties: deals where the Saudi investor’s LP base or co-investor structure includes Chinese state-aligned capital (the “back-door” risk that 2024-2025 CFIUS reviews have aggressively pursued), and deals where the post-transaction governance gives the Saudi side practical control even if formal voting rights stay below thresholds.

A specific 2025 reference case: the unnamed Saudi-anchored bid for a US advanced-packaging firm that was withdrawn after 90 days of mitigation negotiation when CFIUS staff signaled that the only acceptable mitigation would have eliminated the Saudi side’s commercial rationale for the deal. The case reinforced what counsel had been warning for two years: in advanced-packaging and front-end-fabrication targets, the mitigation envelope is essentially closed for Saudi-controlled vehicles.

Practical compliance roadmap

A clean CFIUS process for a Saudi-touching deal follows seven steps. Step 1 — pre-LOI risk assessment: specialist CFIUS counsel reviews the target’s TID classification, the Saudi vehicle’s foreign-government-control status, the LP-and-co-investor structure, and the deal’s technology touchpoints. Output: a written risk memo classifying the deal as no-filing, mandatory declaration, or voluntary notice. Step 2 — pre-filing diplomacy: for material deals, informal consultations with Treasury staff, Commerce, and (where relevant) DOD or DOJ representatives on the CFIUS staff committee can pre-empt 30 to 60 days of review surprises. Step 3 — declaration or notice preparation: counsel drafts the filing in close coordination with the target’s technical and HR teams; the document needs to anticipate CFIUS’s likely concerns rather than minimize them. Step 4 — filing and the 30-day declaration clock or 45-day notice clock. Step 5 — mitigation negotiation: if mitigation is requested, expect 6 to 12 weeks of back-and-forth on the National Security Agreement (NSA) or letter of assurance. Step 6 — closing under mitigation: the deal closes subject to ongoing compliance obligations. Step 7 — post-closing compliance: annual reports, audits, and a designated compliance officer for the duration of the mitigation order, which is typically perpetual.

The largest single execution risk in Saudi CFIUS deals is timeline slippage. Mandatory declarations frequently convert to voluntary notices, which add 60 to 90 days. Voluntary notices frequently extend into investigation phase, which add 45 to 60 days. Mitigation negotiation frequently extends another 45 to 90 days. Build a deal timeline that contemplates a worst-case 9-month CFIUS path; deals that assume a 30-day clearance routinely fail to close on the original schedule.

A discipline that pays dividends: the post-closing compliance function. Companies that build a real CFIUS-compliance function — a designated compliance officer with documented escalation paths, the technical infrastructure to enforce information firewalls, the HR processes to enforce personnel restrictions, and an annual third-party audit cadence — pass the periodic CFIUS compliance reviews cleanly. Companies that treat the NSA as a paper compliance exercise routinely fail subsequent reviews and trigger material penalties including divestiture orders. The compliance function is a continuous operating cost; budget for it as such.

What this means for Saudi dealmakers

The strategic implication for Saudi-side dealmakers is straightforward: structure the deal to be CFIUS-clearable rather than CFIUS-litigable. Voluntary withdrawal under pressure is far more common than formal blocks, and a deal that requires aggressive CFIUS litigation will not close. Pre-clear governance, info firewalls, and personnel restrictions before signing rather than negotiating them in the mitigation phase. Engage specialist CFIUS counsel before, not after, the term sheet.

For the Saudi sovereign vehicles in particular, a long-game implication: the cumulative pattern of CFIUS-cleared transactions is itself reputational capital. PIF and Sanabil have, through 2024-2026, built a substantial track record of clean CFIUS clearances that materially de-risks their reputation as US-side counterparties. Maintaining that track record by walking away from transactions where mitigation cannot be cleanly negotiated is more strategically valuable than pushing marginal transactions through.

The interaction with outbound-investment controls

A 2024-2025 development that materially changes the CFIUS calculus for Saudi-touching deals is the rollout of the US outbound-investment regulatory regime under the Treasury’s Section 1758 framework, which restricts US-person investments in specified Chinese technology categories. While the immediate target is China, the framework’s “covered foreign person” definition reaches beyond Chinese-domiciled entities to capture any foreign entity meaningfully controlled by Chinese persons. Saudi-anchored vehicles with material Chinese co-investment, Saudi-China joint ventures with US-person investors, and Saudi sovereign investments where the Saudi-side LP base includes Chinese state-aligned capital can all touch the outbound-investment perimeter. The interaction with CFIUS is non-trivial: a transaction might clear CFIUS on its inbound dimension and still trigger outbound-investment compliance on the structural dimension. Saudi-side dealmakers who understand only the inbound CFIUS framework miss the outbound exposure, and the Treasury enforcement posture in 2025-2026 has shown willingness to pursue outbound violations even when the inbound transaction was independently cleared. Build the compliance architecture around both regimes simultaneously rather than treating them as independent workstreams.

For deeper reading: How to structure a Saudi tech deal, How to export AI products to Saudi, Capital Flows, Geopolitics.