Contact
  • Home Page
  • Insights
  • FDI Screening and Export Controls for Technology Companies in the United States, the European Union and Ukraine
Back to Insights

FDI Screening and Export Controls for Technology Companies in the United States, the European Union and Ukraine

September 27, 2026

10 min read

Regulatory, Government Relations & Public Policy

Copy link to the article

Introduction

Know-how, source code, a minority investment or an internal restructuring can trigger export-control or foreign investment screening rules before any physical product crosses the border. Technology businesses operating across the United States, the European Union, and Ukraine should classify sensitive information, map investor rights, and control disclosure before diligence, signing, and closing.

Technology Disclosures Can Be Regulated Exports

Export controls can apply to information as well as physical products. A conversation, screen-sharing session, repository invitation, cloud migration, or technical demonstration may disclose controlled software or technology. The legal analysis turns on what is disclosed, how it is classified, who receives it, where the recipient is located, and the intended end use. A confidentiality agreement may protect trade secrets, but it does not create an export-control exemption.

European Union

Article 2(2)(d) of Regulation (EU) 2021/821 treats the transmission of controlled software or technology by fax, telephone, email, or other electronic means to a destination outside the EU customs territory as an export. The definition includes making the material available electronically and orally describing controlled technology over a voice transmission medium. Article 2(3)(b) identifies the person who decides to make that transmission as the exporter in the circumstances covered by that provision.

The rule does not make every technical conversation licensable. The company must first determine whether the information is controlled and then assess the destination, recipient, end use, end user, applicable authorisation, and any exclusion or exception. Classification should occur before a foreign customer, contractor, investor, or technical adviser receives detailed material.

United States

The Export Administration Regulations use a similarly functional approach. Under 15 C.F.R. sections 734.13 to 734.15, releasing controlled technology or source code to a foreign person in the United States may be a deemed export, and a release abroad to a national of another country may be a deemed reexport. A release can occur through visual inspection or oral or written exchanges. Publicly available information and fundamental research may fall outside relevant controls, but those rules are specific and should not be assumed from the existence of an NDA or a limited-purpose diligence process.

U.S. export controls can also follow technology through a multinational group. U.S.-origin items subject to the EAR generally remain subject to those rules when reexported or transferred abroad. Some foreign-made items may also be subject to the EAR under the de minimis and foreign-produced direct product rules. The conclusion depends on the item, technology, software, destination, parties, and end use; it is not determined by the location of the immediate owner alone.

Ukraine

The Law of Ukraine On State Control over International Transfers of Military and Dual Use Goods, Law No. 549-IV of 20 February 2003, governs international transfers of military and dual-use goods. Its definitions encompass relevant software, technology, and technical assistance. During martial law, Cabinet of Ministers Resolution No. 875 of 1 July 2026 also establishes a special procedure for specified exports of military and dual-use goods. Technology businesses working with drones, navigation, encryption, sensors, aerospace, advanced materials, or defence-related software should therefore classify both the product and the information that supports it before foreign access is granted.

Ukraine Is Building an FDI Screening System

As at September 2026, Ukraine has no comprehensive cross-sector foreign direct investment filing regime in force. Cabinet of Ministers Resolution No. 97 of 28 January 2026 created the Interdepartmental Commission on Foreign Direct Investment Screening, but the resolution defines it as a temporary consultative and advisory body. Its functions include analysing planned or completed investments in businesses of strategic importance and developing proposals for future regulation. The resolution does not itself establish a general mandatory clearance procedure for private transactions.

Draft Law No. 14062-1 on foreign direct investment screening remained under committee consideration in September 2026 after being included in the parliamentary agenda. Parties should monitor that legislation, but they should not treat a draft framework as current filing law.

The absence of one general FDI filing does not remove other regulatory constraints. A foreign investment or restructuring may still require merger-control analysis, corporate registrations, sanctions screening, sector-specific approvals, and an assessment of national-security risk. Export-control obligations may also arise before the ownership step if diligence gives foreign persons access to controlled technology.

EU Transactions Still Require Country-by-Country Planning

Foreign investment screening in the EU remains closely tied to national law. Regulation (EU) 2019/452 provides the cooperation framework, while Member States determine filing thresholds, covered sectors, review periods, and remedies under their domestic regimes. A transaction involving several European subsidiaries may therefore require separate analysis and filings in more than one country.

Regulation (EU) 2026/1386 entered into force on 16 July 2026 and will replace Regulation (EU) 2019/452, but most of its provisions apply from 17 January 2028. The new regulation requires every Member State to establish a screening mechanism and introduces a common minimum scope that includes specified sensitive technologies and infrastructure. Until the transition is complete, transaction planning must account for the existing EU framework, the applicable national regimes, and the changes that may take effect before signing or closing.

Deal teams should map every relevant target entity, business activity, investor, and indirect ownership chain. They should then identify filing triggers, whether notification suspends closing, what information can be shared during review, and whether different national timetables can be coordinated through conditions precedent and the long-stop date.

Minority Rights Can Trigger Investment Review

Investment screening is not limited to majority acquisitions. In sensitive sectors, voting rights, board participation, vetoes, information rights, and indirect ownership may be more important than the headline equity percentage. These rights should be reviewed when the term sheet is drafted, because changing them later may affect valuation and deal governance.

For instance, the Committee on Foreign Investment in the United States can review transactions that confer foreign control of a U.S. business and certain non-controlling investments in a TID U.S. business, meaning a U.S. business involving specified critical technologies, covered investment critical infrastructure, or sensitive personal data. Under 31 C.F.R. section 800.211, a covered investment may arise where a foreign person receives access to material nonpublic technical information, board or observer rights, a nomination right, or involvement in substantive decisions concerning critical technology, covered investment critical infrastructure, or sensitive personal data. The precise definition includes qualifications for excepted investors and other elements that require transaction-specific analysis.

Some transactions require a mandatory declaration. Even where filing is voluntary, CFIUS may identify and review a non-notified transaction after closing. The parties should therefore assess jurisdiction, mandatory filing rules, and national-security risk early enough to adjust investor rights or the timetable before they become contractual commitments.

Corporate Restructurings Require Two Separate Reviews

Founders often place a foreign holding company above an operating company before a financing round. That step should be divided into an ownership analysis and a technology-transfer analysis. The share transfer may engage corporate, merger-control, or investment-screening rules. Moving source code to the parent’s cloud environment, assigning intellectual property, or giving parent personnel repository access may be a separate controlled transfer.

A Ukrainian drone developer operating through a Ukrainian LLC placed under a Delaware holding company illustrates the distinction. The restructuring does not create a standalone Ukrainian FDI filing merely because a foreign holding company is introduced, given the current absence of a comprehensive Ukrainian screening law. It may still require corporate registrations and a merger-control analysis. The transfer of code, technical data, or access credentials must then be assessed independently under Ukrainian and any applicable foreign export-control rules.

The same separation matters in fundraising and M&A diligence. Giving an investor’s technical adviser access to source code or manufacturing instructions may be a technology transfer before the investment is approved. At the same time, information rights or a board seat in the term sheet may bring the investment within an FDI screening regime. One workstream cannot safely be used as a substitute for the other.

Due Diligence Can Continue With Controlled Access

A potential export-control issue does not necessarily require the parties to stop diligence. The data room can be staged so that corporate, financial, and commercial materials are reviewed first, while source code, detailed schematics, production instructions, and other potentially controlled information remain restricted pending classification. Access should be limited by person, nationality, and location, with a record of what each reviewer can see.

Where detailed technical review is necessary, the parties can consider redaction, a clean team, or a controlled review session. These measures do not replace a required licence or authorisation. They can reduce unnecessary disclosure while the classification and licensing analysis is completed.

The transaction documents should reflect the result. Conditions precedent should cover required filings and licences. Information covenants should distinguish ordinary reporting from access to controlled technical material. The long-stop date should allow time for regulatory review, and the agreement should allocate responsibility for any mitigation that limits board access, data flows, or integration.

The analysis should continue after closing. New hires, investors, cloud locations, product changes, and markets can change the classification, destination, end user, or screening position. A short internal approval process for technical disclosures and investor rights is more reliable than reconstructing repository access months later.

Questions to Ask Before Opening the Data Room

What technical information will be disclosed, and has it been classified?

Which Ukrainian, EU, Member State, or U.S. controls may apply?

Who will receive access, what is each person’s nationality, and where will access occur?

What information, board, observer, nomination, or veto rights will the investor receive?

Which licences, notifications, or clearances are required before disclosure, signing, or closing?

Frequently Asked Questions

  • Yes. EU and U.S. rules can treat oral, visual, or electronic disclosure of controlled technology as an export or release. Whether authorisation is required depends on the information, classification, recipient, destination, and end use.

  • No. An NDA protects confidentiality between the parties. It does not determine whether technology is controlled or whether a licence or other authorisation is required.

  • Yes. Some regimes cover investments below control thresholds when the investor receives specified board, observer, veto, information, or decision-making rights. The target’s sector, the investor’s status, and indirect ownership may also matter.

  • As of September 2026, Ukraine has no comprehensive cross-sector FDI filing regime in force. The Interdepartmental Commission created by Resolution No. 97 is advisory, and draft screening legislation remains under parliamentary consideration. Merger control, sanctions, sector-specific rules, and export controls may still apply.

  • Often yes. Parties can stage disclosure, restrict access, use redaction or a clean team, and document permissions. Those safeguards do not replace any required licence, filing, or clearance.

Key Takeaways

Treat conversations, screen sharing, repository access, and cloud transfers as potential exports when controlled technology may be disclosed.

Review investor rights as well as equity percentages because minority stakes can trigger screening in the United States and other jurisdictions.

Run ownership and technology-transfer analyses separately for financings, restructurings, and M&A transactions.

Classify sensitive information and control data-room access before disclosure, then reflect licences, filings, and mitigation in the transaction documents.

How Averites Can Help

Averites advises startups, founders, and international businesses on cross-border technology transfers, export-control compliance, and regulatory screening of investments. Contact us to discuss a proposed disclosure, financing, restructuring, or acquisition.

Book a Meeting

References

1.  Regulation (EU) 2021/821 of 20 May 2021 setting up a Union regime for the control of exports, brokering, technical assistance, transit and transfer of dual-use items, including Articles 2(2)(d) and 2(3)(b)

2.  U.S. Export Administration Regulations Part 734 Scope of the Export Administration Regulations, including sections 734.13 to 734.15

3.  U.S. Bureau of Industry and Security guidance on reexports, exports from abroad and transfers of items subject to the EAR

4.  Law of Ukraine No. 549-IV of 20 February 2003 On State Control over International Transfers of Military and Dual Use Goods

5.  Cabinet of Ministers of Ukraine Resolution No. 875 of 1 July 2026 on the special export procedure during martial law

6.  Cabinet of Ministers of Ukraine Resolution No. 97 of 28 January 2026 establishing the Interdepartmental Commission on Foreign Direct Investment Screening

7.  Draft Law of Ukraine No. 14062-1 of 7 October 2025 on foreign direct investment screening and current parliamentary status

8.  Regulation (EU) 2019/452 of 19 March 2019 establishing a framework for screening foreign direct investments into the Union

9.  Regulation (EU) 2026/1386 of 17 June 2026 on the screening of foreign investments in the Union, including Articles 30 and 31

10.  31 C.F.R. section 800.211 defining a covered investment for CFIUS purposes

11.  Committee on Foreign Investment in the United States guidance on non-notified transactions

This publication provides general information and does not constitute legal advice.