Introduction: The Acquisition That Became an Export

On April 27, 2026, a transaction that appeared to have already reached its conclusion became something else entirely. Meta had completed its acquisition of Manus, an artificial-intelligence company celebrated for building agents capable of executing complex, multistep digital tasks with minimal human input. The reported purchase price exceeded two billion dollars, making it one of the largest AI exits of the decade and, briefly, one of the most valuable exits in the history of Chinese-origin artificial intelligence.[1] Manus had done everything the conventional playbook of corporate migration prescribes. It had moved its operations from China to Singapore. Its parent company, Butterfly Effect, had been reincorporated there following a $75 million fundraising round led by American venture investors, a restructuring designed to navigate both U.S. restrictions on investment in Chinese AI firms and Chinese rules limiting the outbound transfer of intellectual property and capital.[1] Its earlier Chinese investors had exited. Its China offices had been closed, dozens of employees laid off, and its remaining engineers relocated. Under the conventional geography of corporate law, the company appeared to have changed nationality before changing ownership.

Beijing did not accept that interpretation.

China’s National Development and Reform Commission — acting through the Office of the Working Mechanism for Foreign Investment Security Review — issued a one-line order prohibiting foreign investment in what it pointedly called the Manus “project” and requiring the parties to withdraw from the acquisition.[2] The decision was remarkable not merely because China intervened in a completed acquisition — an action without precedent under the country’s Foreign Investment Security Review mechanism — but because the target was formally headquartered outside China.[41] Chinese authorities looked beyond the corporate registration documents and toward a different collection of facts: where the technology had been developed, where the engineers had trained and worked, which data and infrastructure had supported the company’s rise, and whether a strategically significant Chinese-origin capability was being transferred into American control. The order’s reference to a “project” rather than a legal entity was itself a doctrinal statement — a signal that China was reaching past corporate formalities to the underlying technological substance.[4]

The acquisition had therefore crossed an invisible line. It was no longer being treated merely as the sale of a Singapore-incorporated company. It was being treated as the foreign transfer of a technological capability that China considered partly its own. As one Singapore-based analyst put it in the days after the order:

“The Manus block is a clarifying moment”

— Ke Yan, tech analyst, DZT Research (Singapore), quoted by Bloomberg [2]

What matters, on this view, is not where the legal entity sits, but where the technology, the talent, and the strategic stakes reside. Weiheng Chen, the senior partner who leads the Greater China practice at Wilson Sonsini, drew the practical conclusion for dealmakers almost immediately, predicting that Chinese national-security clearance would now become:

“a regular closing condition for cross-border tech deals”

— Weiheng Chen, Senior Partner and Head of Greater China, Wilson Sonsini, quoted by Reuters [1]

Reversing the transaction was not as simple as returning shares and refunding the purchase price. Lawyers examining the case described the theoretical checklist: reversing equity transfers, returning capital, deleting transferred code and data, restoring intellectual property, separating product operations, and withdrawing personnel.[4] But knowledge-intensive companies cannot be restored to their earlier condition as easily as factories, warehouses, or parcels of land. By the time the order arrived, Meta had enjoyed months of integration. Code may already have been examined. Engineers may already have exchanged ideas. Product plans may have been incorporated into the buyer’s roadmap. Proprietary methods may have become part of institutional memory. As Foreign Policy’s analysts observed, the unwinding order could do little to keep Manus’s knowledge inside China, since Meta had had months to absorb the company’s data and systems — and there was no obvious mechanism to claw back payments already made to investors.[8]

The human dimension was, if anything, more dramatic than the corporate one. In March 2026, Manus co-founders Xiao Hong and Ji Yichao were summoned to Beijing and barred from leaving the country while the review proceeded.[5] The message could not have been clearer: in the new political economy of artificial intelligence, the founders themselves are treated as part of the strategic asset. Duncan Clark, the veteran China-technology adviser and chairman of BDA China, distilled the lesson that founders across the Chinese AI ecosystem drew from what he called “Manusgate”:

“if you start in China, you stay in China”

— Duncan Clark, Chairman, BDA China, quoted by CNBC [3]

By June, Meta had begun dismantling the deal in earnest: completing an operational separation, ordering its employees to stop using Manus tools for internal projects, and blocking Manus staff from accessing Meta’s internal data systems.[9] By July, Tencent and Manus’s original investors — including ZhenFund and HSG, the firm formerly known as Sequoia Capital China — were in talks to buy the company back from Meta at a valuation of no less than $2 billion, with Tencent positioned to become the largest external shareholder while deliberately remaining a minority holder.[10][11] The proposed resolution was therefore not merely financial. It was political and jurisdictional: replace a prohibited American owner with a nationally acceptable Chinese-anchored ownership structure. Meanwhile the founders themselves explored raising roughly $1 billion from external investors to repurchase their own company — an extraordinary spectacle in which entrepreneurs sought capital not to build a business but to un-sell one.[13]


What Exactly Moves When an AI Company Is Acquired?

The Manus controversy reveals a transformation in the meaning of an AI acquisition. In traditional merger analysis, the principal questions concern valuation, competition, shareholder approval, financing, and operational integration. In foreign-investment review, the government may additionally examine national security, critical infrastructure, sensitive information, and technological leadership. Artificial intelligence adds a more complicated and more consequential question: what exactly moves when an AI company is acquired? The answer cannot be found in the company’s capitalization table.

An acquisition can transfer the right to receive profits. It can transfer the power to appoint directors and determine corporate strategy. It can transfer model source code, weights, training procedures, evaluation methods, and the stream of future improvements. It can provide access to customer information, training datasets, user interactions, and proprietary feedback loops. It can also redirect the work of founders, scientists, and engineers whose tacit knowledge may be more strategically important than any identifiable software file. These rights do not always move together. A technology company may purchase a minority stake while acquiring substantial contractual influence. It may hire a startup’s founders and researchers while leaving the corporate shell behind. It may obtain an exclusive model license without acquiring formal ownership. It may provide billions of dollars of cloud credits in exchange for revenue rights, consultation rights, information access, and long-term computing commitments. The Federal Trade Commission’s examination of the Microsoft–OpenAI, Amazon–Anthropic, and Google–Anthropic relationships — partnerships involving more than $20 billion in cumulative investment — found precisely this mixture of equity, revenue-sharing, exclusivity, consultation, sensitive information exchange, and control-related provisions, all sitting outside the formal architecture of a merger.[14][15]

The result is a new regulatory problem. Governments can no longer determine whether strategic technology has crossed a border simply by examining bills of lading, semiconductor serial numbers, software-download records, or the jurisdiction in which a target company is incorporated. They must examine the distribution of rights inside the transaction. They must ask which of the bundle of capabilities the deal actually moves — and to whom.


Why This Paper Is Called “Ownership Embargo”

This paper introduces the term Ownership Embargo to describe the point at which a government determines that transferring control over an artificial-intelligence enterprise would amount to transferring a strategic national capability. Three reasons justify the name. First, the state’s toolkit is embargo-like in character: it may prohibit the transaction outright, require domestic ownership, remove governance rights, restrict access to code or data, mandate the separation of business operations, exclude particular investors, or — as the Manus case demonstrates — order an already completed acquisition to be reversed. These are not the remedies of competition law; they are the instruments of trade control applied to equity. Second, the concept captures a genuine doctrinal migration: the extension of export-control logic into corporate law. In an ownership embargo, the acquisition agreement becomes a transfer instrument, regulatory clearance becomes a political license, and corporate nationality becomes a contested factual determination rather than a simple matter of incorporation. Third, the term names the historical moment accurately. The twentieth century embargoed goods; the early twenty-first century embargoed chips, software, and data flows; the present decade has begun to embargo ownership itself — the legal relationship through which every other strategic right in an AI company is ultimately exercised. A Forbes analysis of the Manus affair captured the underlying shift in how states now regard the technology, describing AI as being treated less like software and more like nuclear technology:

“strategic, scarce, dual-use and too powerful to leave fully to markets”

— Ron Schmelzer, Forbes contributor and AI industry analyst [36]

The Manus transaction, in short, was not only an acquisition that was blocked. It was an acquisition that became an export. The remainder of this paper develops that claim in seven movements. Section 1 traces how the border of export control has migrated upward from goods to chips to compute to weights to data to investment and, finally, to ownership. Section 2 — the analytical core — decomposes AI ownership into Five Transfer Rights and shows how modern transaction structures recombine them in ways that evade label-based regulation. Section 3 confronts the corporate nationality problem and proposes a nine-layer Nationality Stack. Section 4 examines the economic consequences, introducing the Deal-Sovereignty Discount. Section 5 describes the emerging regime of Permissioned Ownership, including an Ownership Remedy Ladder and a proposed Reversible Integration Plan. Section 6 sets out a policy architecture for the United States and its allies. Section 7 distills the argument into five pillars, before the conclusion returns to Manus and to the meaning of the age now beginning.


Section 1: From Product Embargoes to Ownership Embargoes

1.1 The Traditional Border

Classical export control was built around a physical intuition: strategic capability lives in things, and things cross borders at identifiable points. The architecture that grew out of the Cold War — munitions lists, dual-use control lists, licensing offices, end-user certificates — assumed that a government protecting its technological advantage needed to police a finite set of movements. Physical goods were the original object: machine tools, precision instruments, materials with military application. Defense articles occupied a stricter tier, governed in the United States by the International Traffic in Arms Regulations and their munitions list. As electronics became the substrate of military power, the control perimeter expanded to semiconductor manufacturing equipment — the lithography systems, deposition tools, and metrology instruments without which advanced chips cannot be fabricated — and then to the advanced computing chips themselves, whose export to China the United States began restricting in earnest in October 2022 and has repeatedly tightened since. Software joined the lists when code became functionally equivalent to hardware; technical information joined when blueprints and process recipes proved as valuable as the machines they described; and technical assistance joined when regulators recognized that a visiting engineer could transfer in an afternoon what a shipping container never could. The unifying idea, across all of these categories, was that the state controls transfers of identifiable items and knowledge to identifiable foreign recipients. The company that owned the technology was, for the most part, invisible to the regime. Ownership was a matter for corporate law; export was a matter for trade law; and the two bodies of law rarely met.


1.2 The Border Expands Upward

Over the past decade that separation has collapsed, layer by layer, in a progression that can be written almost as a formula: chips → cloud access → model weights → data → investment → ownership. Chip controls came first, on the theory that computation is the feedstock of AI capability. But chips can be rented rather than bought, so attention turned to cloud access — whether a restricted party could simply lease from a data center the computing power it was forbidden to import. Model weights came next: once training runs costing hundreds of millions of dollars compress into a file of parameters, the file itself becomes the strategic artifact, and its transfer resembles the export of a finished weapon system more than the export of a component. Data followed, as governments recognized that training corpora, user interactions, and sensitive personal information constitute both an input to capability and an intelligence exposure; the U.S. Department of Justice’s Data Security Program now restricts bulk transfers of sensitive American data to countries of concern. Then came investment. The U.S. outbound-investment program — implementing Executive Order 14105 through a Treasury final rule effective January 2, 2025 — prohibits or requires notification of defined U.S. investments in semiconductor, quantum, and artificial-intelligence activities in countries of concern, on the express reasoning that capital carries with it intangible benefits: managerial assistance, talent networks, market access, and prestige.[21][22] Congress reinforced and expanded that architecture with the Comprehensive Outbound Investment National Security Act at the start of 2026.[23] Inbound, the Committee on Foreign Investment in the United States (CFIUS) has long been able to review controlling investments, and since FIRRMA it can also reach certain non-controlling investments involving critical technologies, critical infrastructure, and sensitive personal data; in 2024 alone it reviewed 325 covered transactions, 150 of which involved acquisitions of U.S. critical-technology companies.[28][29]

Ownership is the final rung of this ladder, and the Manus order is its clearest expression to date. When China prohibits a completed acquisition of a Singapore company on the ground that the underlying “project” is Chinese, and when Beijing’s new outbound framework — effective July 1, 2026 — creates for the first time a comprehensive legal basis to force the unwinding of completed overseas transactions and to ban cross-border talent transfers in sensitive sectors without approval, the export-control perimeter has ceased to run along the border at all.[9] It now runs through the capitalization table. Han Shen Lin, China country director at The Asia Group, described the effect of Beijing’s new framework on outbound capital in terms that apply, with the names changed, to every major jurisdiction’s direction of travel:

“a retroactive and forward-looking chokehold”

— Han Shen Lin, China Country Director, The Asia Group, quoted by CNBC [9]


1.3 Why AI Companies Are Different

Why has ownership, of all things, become the object of embargo — and why now, and why for AI in particular? The answer lies in what an AI acquisition actually transfers. An ordinary acquisition transfers productive assets: plants, inventories, brands, contracts, a workforce that operates them. Those assets are valuable but static; the buyer acquires what the target has built. An AI acquisition transfers something categorically larger. It transfers present technology — the models, agents, and systems in production today. It transfers future technological direction — the research agenda, the roadmap, the unpublished experiments that determine what the organization will be capable of in three years. It transfers the means of producing new models: training pipelines, evaluation harnesses, data-curation methods, and the accumulated craft knowledge of how to make large-scale training runs succeed. It transfers tacit research knowledge that exists nowhere except in the heads of a few dozen scientists. It transfers strategic data — training corpora, user telemetry, and feedback loops that compound in value. It transfers compute access and the contractual relationships that secure it. And it transfers a network: of researchers, of commercial partners, of government customers, of the informal channels through which frontier knowledge circulates. A government that watches an AI company change hands is therefore not watching an asset sale; it is watching the reassignment of a capability-generating engine, together with its momentum. That is why both Washington and Beijing have converged, from opposite directions, on the same conclusion: AI supremacy is a core national-security objective, and the ownership of AI enterprises is a legitimate object of state control.[4]


1.4 The Convergence of Legal Regimes

A single AI transaction now sits at the intersection of legal regimes that were designed independently and that answer to different masters. Foreign-investment review (CFIUS in the United States, the FISR mechanism in China, the National Security and Investment Act in the United Kingdom, the revised FDI Screening Regulation in the European Union) asks whether the change of ownership threatens security or public order. Export control (the Bureau of Industry and Security in the United States, MOFCOM’s technology-export catalogues in China) asks whether the deal effects a controlled transfer of technology — and China’s catalogues, which restrict the export of certain algorithms and data-processing technologies, were among the instruments observers expected Beijing to invoke against Manus before the NDRC chose the investment-security route instead.[6] Antitrust review (the FTC and DOJ, the European Commission, the CMA) asks whether the combination harms competition, and has already shown — in the Microsoft/Inflection matter discussed below — that it will treat talent-and-license arrangements as mergers in substance. Data-security regulation asks who will hold the users’ information. Sanctions compliance asks whether any party is a prohibited person. Intellectual-property law governs what was actually assigned or licensed. Employment and immigration law determines whether the researchers can physically relocate — a question the Manus founders’ exit bans answered in the starkest possible way. And government-contract restrictions can disqualify a newly foreign-owned supplier from the public-sector revenues that justified the purchase price. The O’Melveny analysis of the Manus case makes the practical point precisely: China’s national-security rules, technology export controls, data-transfer restrictions, and merger control can all be utilized to probe a single transaction, and a comprehensive regulatory risk assessment across all of them is now essential at the earliest stage of deal planning.[4] The ownership embargo is not one regime; it is the emergent behavior of eight regimes converging on the same deal.


1.5 Defining the Threshold: Three Tests

Not every acquisition deserves national-security intervention, and a concept that cannot exclude anything explains nothing. This paper therefore proposes that an ownership embargo is justified, in principle, only when three cumulative tests are satisfied.

  1. The Capability Test. Does the target possess technology capable of materially advancing military, intelligence, surveillance, cyber, critical-infrastructure, or frontier-model capability? The test is about the technology’s ceiling, not its current commercial use: an agentic system that books restaurant reservations today may automate offensive cyber-operations tomorrow, and regulators are entitled to weigh the trajectory.
  2. The Control Test. Would the transaction give the acquirer one or more meaningful Transfer Rights — the equity, governance, code, data, or talent rights defined in Section 2? A passive financial position with no access to any of the five is presumptively outside the embargo’s proper scope, however large the check.
  3. The Irreversibility Test. Would integration create transfers that could not realistically be undone after closing? Where knowledge, code, and personnel would blend irretrievably into the acquirer — the “unscrambling the eggs” problem the Manus unwind has made vivid — pre-closing review is the only review that matters, and governments will insist on it.[4]

Where all three tests are met, an ownership embargo is a coherent exercise of the state’s protective function. Where they are not, it is protectionism wearing a security uniform — a distinction to which Sections 5 and 6 return.


Section 2: The Five Transfer Rights

2.1 Ownership as a Bundle

The central analytical error in current debates about AI acquisitions is the assumption that ownership is binary — that a company is either sold or not sold, either foreign-controlled or not. Property theorists abandoned this picture a century ago: ownership is a bundle of rights, separable, tradable, and re-combinable. Modern AI transactions have rediscovered that insight with entrepreneurial enthusiasm. The deals that matter most in the AI economy today are precisely the ones in which the bundle has been taken apart: minority investments carrying quasi-control, licensing arrangements carrying the entire technology, hiring waves carrying the entire research capability, cloud commitments carrying financial dependency. A regulatory regime that watches only for the transfer of a majority of voting shares will see almost nothing of what is actually moving. This section therefore decomposes an AI acquisition into five distinct Transfer Rights — Equity, Governance, Code, Data, and Talent — and shows how contemporary transaction structures mix and match them. The framework is offered not as a taxonomy for its own sake but as a working instrument: Section 5 shows how regulators can permit some rights while restricting others, and Section 6 proposes that parties to sensitive AI transactions be required to declare, right by right, exactly what is being transferred.


2.2 The Equity Right

The Equity Right is the claim on economic value: the right to receive profits, to participate in appreciation, and to share in proceeds on a sale or liquidation. It is the right that valuation professionals price and that securities law regulates, and it is the least strategically sensitive of the five — yet it is rarely as passive as it appears. Equity comes in instruments whose control implications differ sharply. Straight common stock in a minority amount may carry nothing but economic exposure. Convertible instruments — notes, SAFEs, and the profit-participation structures used in some frontier-lab investments — defer the control question to a future conversion event, which may arrive precisely when the company has become strategically important. Preferred stock typically carries liquidation preferences, anti-dilution protection, and consent rights over fundamental transactions, which convert a minority economic position into a veto over the company’s exit options. And the sheer scale of an investment can create financial dependency that functions as control without any legal instrument at all: a startup that has taken billions from a single strategic investor, and that must return to the same investor for future financing, will weigh that investor’s preferences in every major decision. The FTC’s 6(b) study documented exactly this dynamic in the cloud–AI partnerships, where investment came bundled with commitments requiring the AI developers to spend a large portion of the invested funds on the investor’s own cloud services — a circular structure in which the equity check partially returns to the writer while the dependency remains.[14][15]


2.3 The Governance Right

The Governance Right is the power to decide: to appoint and remove directors, to approve budgets and strategy, to hire and fire the chief executive, to bless or block a sale. Formal voting control is its most visible form, but modern AI deals have become laboratories of informal governance. Contractual consent rights over specified actions — raising capital, licensing technology to competitors, entering new jurisdictions — give an investor decision power without a single board seat. Board observer rights provide information and presence without votes. Consultation rights, of the kind the FTC found in the cloud–AI partnerships, oblige the company to hear the investor’s views on strategic questions, which in a relationship of financial dependency is often indistinguishable from obeying them.[14] Exclusivity provisions — the obligation to use a partner’s cloud, to route API sales through its marketplace, to offer it first negotiation rights over new models — govern conduct as effectively as any bylaw. The regulatory implication is uncomfortable but unavoidable: governance must be assessed functionally, by asking who can in fact cause or prevent the company’s significant actions, rather than formally, by counting votes. Every major screening regime — CFIUS with its “control” and covered-investment concepts, China’s FISR with its “material influence” test, the EU’s revised regulation with its attention to indirect control — has been moving toward that functional view, at different speeds.[41][25]


2.4 The Code Right

The Code Right is the technological heart of the bundle, and it is not one right but a spectrum of seven, each strategically distinct. Possession is holding a copy — of source code, of model weights, of training configurations. Inspection is the right to read and evaluate: due-diligence access, security audits, the code reviews through which an acquirer’s engineers absorb architecture and technique even if no file is ever copied. Modification is the right to alter — to fine-tune a model, to patch a system, to build derivatives. Reproduction is the right to copy and deploy at scale. Commercialization is the right to sell products and services built on the technology. Training of successor systems is the most consequential and least discussed: the right to use the acquired models, data pipelines, and methods to build the next generation, which converts a one-time transfer into a permanent capability. And transfer to affiliates determines whether the right propagates through a corporate group — including affiliates in third countries that the original regulator never contemplated. An exclusive license conveying modification, commercialization, and successor-training rights transfers more strategic capability than the purchase of one hundred percent of the shares of a company whose technology stays ring-fenced. This is why the paper insists that regulatory review must follow the Code Right through the contract, not the equity through the cap table. It is also why post-closing unwinding is so hard: possession can be deleted and licenses terminated, but inspection cannot be un-performed. Once the buyer’s engineers have studied the target’s architecture, the knowledge is theirs — a point the Manus separation, with its blocked system access and prohibited internal use, could mitigate only prospectively.[9]


2.5 The Data Right

The Data Right is similarly plural, and the plurality matters because different data categories raise different sovereign concerns. Pre-transaction data — the corpora on which the target’s existing models were trained — embodies the historical capability and may carry the deepest jurisdictional roots: data gathered in one country does not lose its origin when the company reincorporates elsewhere, which is one reason Beijing regarded Manus’s Singapore domicile as beside the point.[37] Customer data raises privacy and counterintelligence questions, especially where customers include government agencies or critical-infrastructure operators. Training data acquired on an ongoing basis — licensed corpora, synthetic-data pipelines, human-feedback operations — determines future capability. Derived data (embeddings, model outputs, evaluation results, distilled datasets) is the category regulators most often miss: it can reconstruct much of the value of the underlying data while formally being something new. Government-related data — anything touching defense, intelligence, or public-sector deployments — sits at the top of every sensitivity hierarchy. And post-acquisition behavioral information — the ongoing stream of user interactions flowing to the new owner — is a forward-looking transfer that closing documents rarely describe but that may be the most valuable data right of all. The DOJ’s Data Security Program, CFIUS’s sensitive-personal-data jurisdiction, China’s cybersecurity and data-export regimes, and the EU’s attention to data in its revised screening scope all reflect a shared recognition: in AI, data is not an asset on the balance sheet; it is a standing channel between populations and owners.


2.6 The Talent Right

The Talent Right is the right the intellectual-property schedules cannot capture. Michael Polanyi’s old observation that we know more than we can tell is, in frontier AI, an economic fact of the first order: the difference between a lab that can train a competitive model and one that cannot lies substantially in tacit knowledge — the judgment about data mixtures, hyperparameters, infrastructure debugging, and failure diagnosis that resides in experienced researchers and transfers only through working together. A researcher who moves takes this capability with her, lawfully and invisibly; no assignment agreement is needed and no customs post is crossed. That is why acqui-hires have become the signature transaction of the AI era, why the CMA concluded that Microsoft’s hiring of the Inflection team amounted to acquiring the team’s collective know-how, and why China responded to the Manus deal by restricting the movement of the founders themselves and — under its new framework — banning cross-border talent transfers in sensitive sectors without approval.[20][9] Winston Ma, adjunct professor at New York University School of Law and a longtime observer of Chinese capital markets, identified the systemic stake even before the deal closed, warning that a smooth closing would signal to every ambitious Chinese founder that the exit ran through relocation and sale:

“it creates a new path for the young AI startups in China”

— Winston Ma, Adjunct Professor, NYU School of Law, quoted by TechCrunch [40]

The Talent Right also explains the escalating international competition for researchers as such. Stanford’s AI Index reported in 2026 that the performance gap between top U.S. and Chinese models had collapsed to roughly 2.7 percent, from about 31 percent in 2023 — a convergence driven by people, publications, and accumulated craft rather than by any single artifact.[12] When capability lives in talent, controlling talent flows becomes a national strategy, and the employment contract becomes an export document.


2.7 Rights Combinations: Six Transaction Structures

The five rights rarely travel alone, and the art of modern AI dealmaking consists largely of choosing which to move. The table below compares six recurring structures by the intensity of each Transfer Right they typically convey. The point of the comparison is that the structures at the bottom of the table can replicate most of the strategic effect of the structure at the top while presenting, to a label-based regulator, an entirely different face.


Transaction structureEquityGovernanceCodeDataTalent
Full acquisitionHighHighHighHighUsually high
Minority strategic investmentMediumVariableVariableVariableLow–medium
Joint ventureSharedSharedContractualContractualShared
Exclusive licensingLowLowHighVariableLow
Talent-and-license transactionLowLow–mediumMedium–highVariableHigh
Cloud partnershipMediumVariableLow–mediumMediumLow

Table 1. Typical intensity of the Five Transfer Rights across six recurring AI transaction structures.


2.8 Control Without Title

Three real transactions demonstrate how thoroughly the bundle can be disassembled. The first is Microsoft–Inflection. In March 2024, Microsoft hired almost all of Inflection AI’s team — including co-founders Mustafa Suleyman and Karén Simonyan — while paying roughly $650 million, largely structured as a non-exclusive license to Inflection’s intellectual property, and leaving the corporate entity standing.[20] Microsoft argued to the UK Competition and Markets Authority that no merger had occurred: the employees had simply resigned and taken new jobs, and the assets involved were mere “factors of production.” The CMA disagreed, finding that the transfer of employees, know-how, and the IP license enabled Microsoft to substantively acquire Inflection’s pre-transaction foundation-model and chatbot development capabilities, creating economic continuity between the old company and the new team — a merger in substance, cleared only because Inflection’s market position was small.[18][19] The European Commission and the German Federal Cartel Office reached parallel conclusions under their own instruments.[19] In the vocabulary of this paper: the Talent Right and much of the Code Right moved; the Equity and Governance Rights stayed behind; and the first regulator to look at substance rather than label found an acquisition.

The second is the family of cloud–model partnerships the FTC examined under Section 6(b): Microsoft–OpenAI, Amazon–Anthropic, and Google–Anthropic. The staff report found significant equity and revenue-sharing rights for the cloud providers; consultation, control, and exclusivity rights held to varying degrees; commitments obliging the AI developers to spend large portions of the invested capital on the partner’s own cloud; and flows of sensitive information and key resources — compute above all — that could raise switching costs and shape access to critical inputs across the industry.[14][15] Then-Chair Lina Khan summarized the competitive concern in terms that map directly onto the Transfer Rights framework, warning that such partnerships can:

“create lock-in, deprive startups of key AI inputs, and reveal sensitive information”

— Lina M. Khan, then Chair, U.S. Federal Trade Commission [14]

In these partnerships, substantial Equity and Data Rights moved, partial Governance Rights moved through consultation and exclusivity, and the Code Right moved selectively through model-access and hosting arrangements — all without any transaction that a share-transfer-based screening regime would classify as an acquisition.

The third, and analytically the richest, is Meta’s June 2025 investment in Scale AI. Meta paid approximately $14.3 billion for a 49 percent stake, valuing the data-labeling company at about $29 billion — yet took no voting power and no conventional board control, and Scale remained formally independent under a new interim chief executive.[16][17] Simultaneously, Scale’s founder Alexandr Wang and a hand-picked group of employees moved to Meta, where Wang was installed at the head of the new superintelligence organization; reporting at the time indicated that securing Wang was the principal driver of the entire investment.[17] The structure is a nearly clinical separation of the bundle: a High Equity Right, a High Talent Right, a Medium Data Right (through deepened data-production cooperation), and deliberately, conspicuously, no formal Governance Right. Whatever its motivations — and avoiding merger review was widely assumed to be among them — the transaction demonstrates that the rights this paper describes are not academic categories. They are the actual dials that the most sophisticated acquirers in the world are turning, deal by deal. Scholars have given the genre a name: Alexandros Kazimirov, in work published through the Stigler Center’s ProMarket and the American Antitrust Institute, analyzes these “quasi-mergers” — acquihire-plus-license structures descended from what Stanford’s Mark Lemley and Cardozo’s Matthew Wansley call “cooption” strategies — and shows that their structure can shield incumbents from intervention precisely because enforcement agencies cannot use injunctive relief to restrict employee mobility.[30][31] The Federation of American Scientists has warned about where the pattern leads if it becomes the default exit path for promising startups, cautioning against:

“a cycle of defensive consolidation that suppresses innovation”

— Federation of American Scientists, policy analysis on reverse acqui-hires [33]

The lesson of all three cases is the same. Title is optional. Control is composable. And any regulatory regime — competition or national-security — that keys its jurisdiction to labels rather than to Transfer Rights will be arbitraged by transaction design within a single deal cycle.


Section 3: The Corporate Nationality Problem

3.1 Incorporation Is No Longer Enough

For most of modern corporate history, the nationality of a company was a clerical fact. A company was where it was incorporated; secondarily, where its head office sat. Tax treaties, investment treaties, and conflict-of-laws rules were all built on this registrational picture, and generations of transactional lawyers learned that a change of nationality was accomplished by a reincorporation — a filing, a merger into a new shell, a redomiciliation. The Manus case announces, as bluntly as a one-sentence prohibition order can, that this picture no longer governs strategic technology. Manus was Singapore-incorporated, Singapore-headquartered, and — after its 2025 restructuring — largely free of Chinese equity. None of it mattered. The NDRC asserted jurisdiction based on the company’s technological, personnel, data, and developmental roots: its founding in China, its Chinese-citizen founders and workforce, the Chinese provenance of its know-how, and the strategic sensitivity Beijing attaches to the AI sector as such.[1][41] The Shumaker client analysis stated the new doctrine in a single sentence: technological nationality does not follow corporate domicile.[5] Lawyers advising on the case noted its corollary for every company with what practitioners now call “China elements”: relocating a corporate seat abroad does not exempt a company from Chinese scrutiny if its core technologies, founders, or research infrastructure originate from or maintain connections with the mainland.[4] What China did explicitly, other governments do implicitly. CFIUS looks through incorporation to ultimate beneficial ownership and foreign-government relationships; the EU’s revised regulation extends screening to intra-EU acquisitions executed through EU subsidiaries of non-EU owners, closing the loophole exposed by the European Court of Justice’s Xella ruling; the UK’s NSIA reaches acquisitions of entities and assets with only modest UK nexus.[25][26] Everywhere, the question is shifting from “where is the company registered?” to “what is this company actually made of, and who made it?”


3.2 The Nationality Stack

If registration no longer answers the nationality question, something must. This paper proposes that an AI company’s nationality be evaluated across nine layers — a Nationality Stack — each of which a regulator may weigh, and each of which can point in a different direction:

  1. Incorporation — the formal legal seat, still the anchor of corporate-law obligations.
  2. Headquarters — where management actually sits and decisions are actually made.
  3. Founder citizenship and residence — the layer the Manus exit bans placed at the center of the map: founders can be summoned, restrained, and held accountable by the states whose passports they carry.[5]
  4. Research and engineering location — where the technology was and is being developed, and under whose labor, secrecy, and security laws the developers work.
  5. IP ownership — which entities hold the patents, copyrights, and trade secrets, and under which assignment chains, including any obligations owed to former employers or state-funded programs.
  6. Training-data origin — whose populations, platforms, and archives supplied the corpora; data provenance creates jurisdictional claims that survive every reincorporation.
  7. Compute and cloud location — whose data centers train and serve the models, and whose export-control and lawful-access regimes therefore reach them.
  8. Capital and ultimate beneficial ownership — who really owns the equity after tracing through funds, SPVs, and nominees, and which states can influence those owners.
  9. Government, military, and critical-infrastructure customers — whose sensitive missions depend on the company’s products, creating reliance-based claims independent of ownership.

A company like the pre-acquisition Manus scores Singaporean on layers one and two, Chinese on layers three, four, and six, American on parts of layer eight after its U.S.-led fundraising, and mixed everywhere else. The stack does not produce a single answer; it produces an honest map of the overlapping claims — which is precisely what a sensible regulator, and a well-advised buyer, need to see before a transaction rather than after one.


3.3 Paper Domicile versus Operational Domicile

The gap between the top of the stack and the rest of it can be described as the difference between paper domicile and operational domicile. A company may legally relocate — new incorporation, new headquarters lease, new tax residence — without moving its foundational code, whose provenance and authorship are fixed historical facts; without moving its principal researchers, whose citizenship, family ties, and physical location remain what they were; without moving its data history, which records where and from whom every corpus was gathered; without dissolving its investor influence, since exited investors leave networks and expectations behind; without escaping its supply-chain dependencies, from cloud contracts to chip access; and without erasing its government relationships, whether as vendor, licensee, or object of informal guidance. The practice of “Singapore-washing” — the relocation strategy pursued by Manus, Shein, and a generation of China-founded companies seeking to reduce their Chinese regulatory footprint — works precisely to the extent that regulators read only the top layer of the stack.[3] The Manus order is best understood as a declaration that at least one major regulator now reads all nine.


3.4 The Jurisdictional Afterlife of a Startup

It follows that a startup can carry obligations from its country of origin long after it has formally left — a jurisdictional afterlife. Employees may remain bound by secrecy and non-export obligations under origin-country law; founders may remain physically subject to origin-country authority, as Xiao Hong and Ji Yichao discovered; technology developed before relocation may remain subject to origin-country export catalogues, so that its later transfer abroad requires a license the company never sought; and data collected before relocation may remain governed by origin-country data-security law. Commentators on the Manus case noted a further, sharper possibility circulating among Chinese legal academics: that founders who exported restricted technology without authorization could face personal criminal liability.[40] The afterlife concept has uncomfortable implications for acquirers, because it means due diligence must interrogate the target’s history and not merely its present: a clean Singapore entity with a Chinese past may be, in the eyes of the origin state, a Chinese asset temporarily abroad. It also has implications for founders, who may find — as one Foreign Policy analysis of the Chinese AI ecosystem put it — that the forces pulling them home are as strong as the forces pushing them offshore, and that the state regards their departure not as an exit but as an escape.[7]


3.5 Comparative Regulatory Systems

United States. The American architecture is the most elaborate and the most fragmented. CFIUS conducts inbound review of controlling and certain non-controlling investments touching critical technologies, critical infrastructure, and sensitive personal data, backed since 2024 by expanded monitoring powers, record civil penalties, and an active non-notified-transactions program that preliminarily examined thousands of deals and formally pursued dozens.[28][29] Treasury’s outbound-investment program prohibits or requires notification of U.S. investments in Chinese semiconductor, quantum, and AI activities, and has been legislatively entrenched and extended by the COINS Act.[21][23] The Bureau of Industry and Security administers export controls whose AI-relevant reach now extends from chips to certain model-related items; the Department of Justice’s Data Security Program polices bulk data transfers; and the FTC and DOJ conduct competition review that, as the 6(b) study shows, increasingly examines partnership substance.[14]


China. China’s system pairs an inbound FISR mechanism — the instrument used against Meta, applying a “key sectors plus control” test under which even minority investments conferring material influence can require filing — with export-control catalogues restricting the outbound transfer of sensitive technologies, technology-transfer restrictions, and a comprehensive data and cybersecurity regime.[41][6] The newest layer is the July 1, 2026 framework governing overseas transactions: a formalized legal basis to review, condition, and force the unwinding of completed outbound deals, and to prohibit cross-border talent transfers in sensitive sectors without approval — the codification, in effect, of the Manus precedent.[9]


European Union. The EU completed its overhaul in 2026: the Council gave final approval to the new FDI Screening Regulation on June 8, 2026, following the Parliament’s vote in May, replacing the 2019 framework.[25] The new regulation obliges all twenty-seven member states to operate screening mechanisms; establishes a common minimum sectoral scope under which investments in dual-use items, military equipment, and advanced technologies — explicitly including artificial intelligence (aligned with AI Act definitions and focused on general-purpose AI with space or defense relevance), quantum technologies, and semiconductors, down to research-only activities — require prior authorization; extends coverage to indirect foreign control through EU subsidiaries; mandates call-in powers reaching transactions up to years after closing; and harmonizes assessment criteria and mitigation menus while leaving final decisions with member states.[24][25][26] In parallel, the Commission’s January 2025 recommendation asked member states to assess screening of outbound investments in semiconductors, AI, and quantum — the beginnings of a European outbound regime to mirror the American one.[27]

United Kingdom. The National Security and Investment Act gives the government mandatory-notification jurisdiction over acquisitions in seventeen sensitive sectors, artificial intelligence among them, with call-in powers over a far wider field. Alongside it, the Competition and Markets Authority has pioneered the functional analysis of AI arrangements: its Microsoft/Inflection decision established that a hiring wave plus a license can constitute a relevant merger situation, and its parallel reviews of the Microsoft–OpenAI, Microsoft–Mistral, Amazon–Anthropic, and Alphabet–Anthropic relationships confirmed that partnership, licensing, and talent structures will be examined for what they do rather than what they are called.[18][19]


3.6 Corporate Nationality as a Factual Inquiry

The direction of travel across all four systems is unmistakable. Corporate nationality in AI is ceasing to be a registration address and becoming a weighted factual test — an inquiry across the Nationality Stack in which different regulators weight different layers according to their own strategic anxieties. This development has costs: it multiplies overlapping claims, guarantees that some companies will be treated as national assets by two rival states simultaneously, and injects an irreducible political judgment into what used to be a checkbox. But it also has an inescapable logic. When the thing being protected is a capability woven out of people, code, data, and compute, a nationality doctrine that looks only at a filing cabinet in a registry office is not neutral; it is blind. The task for policy — taken up in Sections 5 and 6 — is to make the factual inquiry predictable, proportionate, and honest, so that it disciplines strategic transfers without becoming a license for arbitrary economic nationalism.


Section 4: The New Cross-Border M&A Discount

Every legal transformation described so far has a price, and markets have already begun to compute it. This section introduces a supporting term for that price: the Deal-Sovereignty Discount — the reduction in valuation or transaction certainty caused by the possibility that a government will restrict, condition, or reverse the transfer of strategic ownership rights. The discount is the shadow the ownership embargo casts over every AI capitalization table, and it is payable whether or not any government ever acts: uncertainty alone is enough.


4.1 Components of the Discount

The discount decomposes into at least nine components, each of which a valuation professional can, in principle, estimate. The probability of prohibition — the chance that one or more governments block the deal outright — anchors the calculation; for a China-rooted AI target selling to an American acquirer after April 2026, that probability is no longer a tail risk. The probability of delayed approval imposes time costs, financing costs, and the operational decay of a company held in limbo. The cost of mitigation covers trustees, security officers, audits, and compliance infrastructure demanded as the price of clearance. The cost of maintaining separate operations — clean teams, firewalled systems, duplicated staff — can persist for years and erode the synergies that justified the deal. The risk of code or data restrictions strikes at the strategic rationale itself: an acquisition cleared on condition that the buyer never touch the model weights has bought equity without the Code Right. The risk that founders cannot relocate — vividly demonstrated by the Manus exit bans — devalues every deal whose thesis is talent.[5] The risk of forced divestiture converts a completed purchase into a distressed sale on a regulator’s timetable; Meta’s position — unwinding a $2 billion purchase at, in the best case, the same $2 billion it paid, after months of integration cost and strategic distraction — is the canonical illustration.[10][11] Reduced buyer competition lowers exit prices structurally: every excluded class of acquirer removes a bidder from the auction. And financing uncertainty raises the cost of capital for the entire category, as lenders and limited partners learn to price regulatory reversal.


4.2 The Startup-Exit Problem

The discount’s deepest effects fall not on the tech giants, who can absorb a written-off acquisition, but on the startup ecosystem whose economics depend on exits. Ownership restrictions may genuinely protect national capability, but they simultaneously reduce the number of eligible buyers for any strategically sensitive company; lower founder and investor returns by removing the highest bidders from the table; discourage foreign venture capital, whose entire model presumes that a successful company can eventually be sold to whoever values it most; push entrepreneurs to relocate earlier — or, after Manus, to conclude that relocation itself no longer works and to structure their companies from day one for a single national market; encourage hidden or synthetic transactions, in which the substance of a sale is smuggled through licenses, secondments, and service agreements precisely because the honest form is prohibited; and, at the limit, reduce the incentive to build strategically sensitive companies at all, steering founding talent toward applications too boring to embargo. Chinese AI founders now live this dilemma in its starkest form — caught, as Foreign Policy documented, between global markets, deeper capital pools, and higher-paying customers on one side, and a state determined that the capabilities they build remain national on the other.[7] But the dilemma is not uniquely Chinese. Every jurisdiction that builds an ownership embargo will discover that it has also built an exit tax on its own most ambitious founders, payable in valuation and optionality.


4.3 The New Contractual Architecture

Transaction lawyers respond to risk by drafting, and a new contractual architecture for AI M&A is already visible. Future — and increasingly current — acquisition agreements will contain: national-security closing conditions enumerating not just CFIUS but every plausibly relevant regime, including the target’s countries of origin; reverse termination fees sized to compensate targets for the limbo of a failed review; regulatory-risk allocation clauses specifying precisely which party bears the cost of which government’s intervention, including post-closing intervention of the Manus type; extended outside dates acknowledging that multi-jurisdictional security review runs on political rather than commercial time; clean-team arrangements restricting pre-closing information flows so that a blocked deal does not become a completed intelligence transfer; data-transfer standstills and pre-closing code-access restrictions serving the same function for the Data and Code Rights; founder-mobility conditions making the deal contingent on key people actually being able to move — a clause that would have saved Meta considerable grief; separate-operating covenants committing the parties to run the businesses apart until every approval lands; and mandatory deletion and restoration plans specifying, in advance, how an ordered unwind would actually be executed and verified. The last item converts the bitter lesson of the Manus case into boilerplate: if governments can order eggs unscrambled, prudent parties will agree the recipe for unscrambling before they cook.


4.4 Political-Risk Insurance

Where there is quantifiable risk, insurance follows — in principle. Political-risk insurance has long covered expropriation, currency inconvertibility, and political violence in emerging markets; the question is whether insurers and the infrastructure funds that increasingly finance AI data centers can extend the craft to the ownership embargo. The perils to be priced are novel but not unpriceable: forced divestiture (a Manus-type order, with loss measured as the gap between price paid and unwind proceeds plus integration costs); licensing withdrawal (revocation of the export or operating licenses on which the acquired business depends); sanctions exposure arising from post-closing designations; nationalization in its classical and creeping forms; government-ordered separation short of divestiture — the ring-fences and blocked system access Meta implemented in June 2026, each with measurable ongoing cost;[9] and cross-border IP restrictions that strand acquired technology in the jurisdiction of origin. The obstacles are correlation (a U.S.–China rupture triggers every policy at once), moral hazard (insured buyers may court riskier targets), and information asymmetry (underwriters know less about a deal’s political exposure than either government involved). The likely equilibrium is partial: high premiums, low limits, extensive exclusions — insurance as a signal of residual risk rather than a solvent for it. The truest hedge remains structural: deals designed, right by right, to survive review.


4.5 The Irreversibility Premium

The discount has a mirror image. If ambiguous corporate roots impose a penalty, cleanly separated ones command a premium — an irreversibility premium for targets whose strategic rights have already been demonstrably disentangled from sensitive jurisdictions: code provably developed post-relocation by post-relocation hires; data lawfully exported or freshly gathered; founders resident where they can stay; capital traced and clean; no origin-state license hanging over the IP. Buyers will pay more for such targets for the same reason they pay more for audited financials: the diligence is pre-performed and the tail risk is visibly amputated. The premium will, in turn, reshape founder behavior — rewarding early, genuine, expensive separation over late cosmetic redomiciliation — and will create a professional industry of nationality audit: advisers who traverse the nine layers of the Nationality Stack and certify what they find. The Manus case teaches the negative lesson; the market will now monetize the positive one. In the age of the ownership embargo, regulatory legibility is not a compliance cost. It is an asset.


Section 5: Permissioned Ownership

5.1 Ownership as a Conditional Political License

If Sections 1 through 4 describe a problem, this section describes the settlement that is actually emerging — not open markets, not blanket prohibition, but a middle regime this paper calls permissioned ownership. Under permissioned ownership, a transaction may close while particular rights within it remain restricted, conditioned, monitored, or reserved. The buyer owns the company in the way a licensee holds a license: genuinely, but revocably, and on terms the issuing authority can adjust. This is not as alien to Western legal tradition as it first sounds. Regulated utilities, defense contractors under special security agreements, banks under ownership-control regimes, and broadcasters under foreign-ownership caps have all long held property on political conditions. What is new is the extension of that logic to the commanding heights of a general-purpose technology — and the frank acknowledgment, forced by cases like Manus, that in AI the conditions attach not to the shares but to the Five Transfer Rights individually.


5.2 The Ownership Remedy Ladder

Permissioned ownership requires a graduated toolkit. Drawing on the mitigation practice of CFIUS, the condition menus of the revised EU regulation, the trustee traditions of merger control, and the hard lessons of the Manus unwind, this paper proposes a ten-rung Ownership Remedy Ladder, ascending from transparency to prohibition. Regulators should climb no higher than the risk requires — and should be required to explain each rung they ascend.

  1. Disclosure — the parties reveal the transaction’s full rights structure to the regulator, on the Transfer Rights Declaration model of Section 6.4.
  2. Notification — formal pre- or post-closing filing, creating a review trigger and a record.
  3. Enhanced due diligence — regulator-supervised verification of ultimate beneficial ownership, data flows, and government relationships.
  4. Information-access restrictions — limits on what the acquirer may see: board papers redacted, technical documentation withheld, sensitive customer identities masked.
  5. Board and governance limitations — caps on board seats, voting caps, prohibited officer positions, security-cleared director requirements.
  6. Data or code ring-fencing — technical and organizational firewalls sealing the Code and Data Rights inside the target, with audited access logs.
  7. Domestic trustee or security officer — an approved fiduciary inside the company empowered to enforce the conditions and report to the state.
  8. Separate operations — the businesses run apart indefinitely: distinct systems, staff, and premises, of the kind Meta implemented in June 2026 under Beijing’s order.[9]
  9. Mandatory domestic co-ownership — a required national anchor investor or golden share; the Tencent-led consortium structure now assembling around Manus, with Tencent as largest-but-minority holder, is this rung negotiated in public.[11]
  10. Prohibition or forced unwind — the embargo itself: the deal is blocked, or, post-closing, reversed.

5.3 Partial Approvals: The Five Rights as a Regulatory Instrument

The ladder becomes genuinely useful when combined with the Transfer Rights framework, because it allows approvals to be partial along the rights dimension and not merely conditional along the severity dimension. A government might permit equity without code access — foreign capital in, model weights sealed; economic participation without a board seat — the structure Meta and Scale AI chose voluntarily, here imposed as a condition;[16] model licensing without training data — the product crosses the border, the corpus does not; commercial distribution without model modification — sell it, do not retrain it; talent hiring without transfer of prior-employer IP — the people may move, with audited hygiene around what moves in their heads and laptops; and cloud services without sensitive customer information — infrastructure partnership with data-plane separation. Each formula is a different sentence in the same grammar, and the grammar is the point: once regulators and parties share a vocabulary of five rights and ten rungs, a negotiation that today proceeds by improvisation can proceed by specification. This is where the Five Transfer Rights become directly useful to regulators — not as academic taxonomy, but as the drafting checklist for every mitigation agreement in the AI era.


5.4 The Problem of “Unscrambling the Eggs”

Permissioned ownership’s hardest case is the one that arrives too late. The Manus unwind demonstrates the difficulty of reversing integrated knowledge, code, data, and personnel after a completed transaction: equity can be re-transferred and money returned, but Meta’s engineers cannot unread what they read, unlearn what Manus’s team taught them, or unincorporate the strategic conclusions already folded into their roadmap — which is why analysts judged that the order would do little to keep Manus’s knowledge inside China even as it destroyed the deal.[8][4] The rational response is to move the unwind analysis before the closing. This paper therefore proposes that highly sensitive AI transactions be required to file a Reversible Integration Plan as a condition of clearance. Before closing, the parties would identify: which code may be shared, and which repositories remain sealed; which personnel may transfer, and which must stay; which systems must remain separate, at what technical boundary; which data may be copied, and which only accessed in place; how transferred assets would be deleted or restored if an unwind were ordered, with logging sufficient to make deletion provable; and how an unwind would be independently verified, by an auditor named in advance. The plan converts irreversibility from an ambient catastrophe into a designed variable. It will not make unwinding painless — nothing can — but it makes the Irreversibility Test of Section 1.5 administrable, and it gives a regulator contemplating clearance a concrete answer to the question that haunted the NDRC’s decision: if we are wrong, can this be undone?


5.5 Reciprocal Ownership Restrictions

Should the United States answer foreign ownership embargoes with equivalent limitations of its own — a mirrored regime under which Chinese acquirers face in America exactly what American acquirers face in China? The temptation is real and the symmetry is rhetorically satisfying, and some reciprocity already exists in practice: CFIUS scrutiny of Chinese acquisitions is severe, and the outbound program is explicitly China-directed. But this paper counsels against strict, automatic reciprocity, for five reasons. It would accelerate investment fragmentation, hardening the world into ownership blocs faster than security requires. It would harm allied investors, who are routinely entangled in funds and structures that crude nationality tests misclassify. It would reduce startup financing, since capital that fears symmetrical retaliation stays home. It would encourage retaliation in kind, handing every foreign restriction an automatic American echo and vice versa, with escalation built in. And it would tend to produce fully separate national AI ecosystems — duplicated research, divided talent, and mutually opaque capabilities — an outcome worse for safety as well as prosperity, since rival systems that cannot see each other misjudge each other. Reciprocity should remain a diplomatic instrument, deployed selectively and revocably, not a statutory reflex.


5.6 Safe Harbors

A permissioning regime that reviews everything reviews nothing well. The corollary of climbing the remedy ladder for dangerous deals is descending it — to zero — for safe ones. This paper recommends streamlined, presumptively approved treatment for: truly passive minority investments, holding no Transfer Right beyond bare equity; academic research collaborations conducted for publication; openly published technology, where the code or weights are already public and the transaction can transfer no capability the world lacks; non-sensitive enterprise applications — the vast commercial mid-market of AI that fails the Capability Test of Section 1.5; investments from designated allied jurisdictions, subject to ultimate-beneficial-ownership verification, on the model of CFIUS’s excepted-state mechanism and Treasury’s proposed fast-track known-investor program;[23] and transactions with no access to restricted rights — deals whose Transfer Rights Declaration shows, on its face, that nothing on the sensitive list moves. Safe harbors are not a concession to industry; they are the load-bearing wall of the regime’s legitimacy. They keep review capacity pointed at genuine risk, they give founders and investors a navigable map, and they answer, in advance, the accusation that the ownership embargo is protectionism — by demonstrating, in the statute itself, everything it declines to reach.


Section 6: A Policy Architecture for the United States

6.1 Modernize CFIUS Analysis

CFIUS already addresses critical technology, critical infrastructure, sensitive data, supply-chain resilience, and U.S. technological leadership, and its recent practice — record penalties, near-doubled site visits, an aggressive non-notified program, and the first presidentially ordered divestitures in years — shows an institution fully awake to enforcement.[28][29] What it lacks is an analytical instrument fitted to AI’s disaggregated deal structures. This paper recommends that CFIUS adopt an explicit Five Transfer Rights schedule for covered AI transactions: a standardized annex to every filing, mapping the transaction’s Equity, Governance, Code, Data, and Talent Rights at the level of granularity Section 2 describes — the seven code sub-rights, the six data categories, the identified key personnel. The schedule would discipline the Committee’s own analysis, make mitigation drafting systematic rather than bespoke, create comparability across cases, and — not least — force parties to understand their own transaction before asking the government to bless it. The America First Investment Policy’s stated preference for targeted, time-limited mitigation over open-ended agreements is, in fact, an argument for the schedule: targeting requires a target, and the rights framework supplies one.[28]


6.2 Coordinate Fragmented Regulators

Section 1.4 showed that eight legal regimes converge on a single AI transaction; no American institution currently sees all eight at once. The United States should create a structured review mechanism — a standing AI Transaction Coordination Council or an expanded CFIUS-plus process — connecting Treasury and CFIUS (inbound ownership); Commerce and BIS (export controls and the deemed-export questions that talent transfers raise); Justice and the Data Security Program (data flows); the FTC and DOJ Antitrust (competition substance, including quasi-mergers); the Defense Department and the intelligence agencies (capability assessment against the Capability Test); the State Department (allied coordination and reciprocity diplomacy); and the Department of Energy where critical infrastructure, from grids to national laboratories, is involved. The mechanism’s output should be a single, internally consistent government position per transaction — one set of conditions on one remedy-ladder rung — rather than the current sequence of independent proceedings in which a deal cleared by one agency can be unmade by another, and in which the parties’ lawyers are the only people in the country who have read every file.


6.3 Review Substance Rather Than Labels

The arbitrage engine described in Section 2.8 runs on labels, and the statute should switch it off. A transaction should not escape national-security review simply because it is described as a partnership, a commercial license, a talent agreement, a cloud commitment, a convertible investment, a research collaboration, or a minority stake. The jurisdictional trigger should be the acquisition of any meaningful Transfer Right in a covered AI business, however papered. The competition authorities have already shown the way: the CMA’s conclusion that Microsoft’s hiring-plus-license substantively acquired Inflection’s development capabilities, and the FTC’s revised HSR rules closing the acqui-hire notification gap, are substance-over-label doctrine in action — and there is no reason the national-security regime, with far stronger statutory tools, should remain more formalist than antitrust.[18][19][33]


6.4 Require a Transfer Rights Declaration

For sensitive AI transactions, the buyer and target should be required to file a Transfer Rights Declaration — a sworn, standardized disclosure of what the deal actually moves. The Declaration would state:

  1. Equity obtained — instruments, percentages, preferences, and conversion features.
  2. Governance rights — board seats, observers, vetoes, consent and consultation rights, exclusivity provisions.
  3. Code and model access — mapped against the seven code sub-rights, including successor-training and affiliate-transfer rights.
  4. Data access — mapped against the six data categories, including post-closing behavioral flows.
  5. Personnel transfers — named key individuals, their roles, and any origin-country obligations they carry.
  6. Cloud and compute commitments — capacity, exclusivity, and spend-back obligations.
  7. Rights over future models and discoveries — options, rights of first refusal, and improvement clauses.
  8. Ultimate beneficial ownership — traced through funds and vehicles to natural persons and states.
  9. Foreign-government relationships — of every party, including subsidies, licenses, and informal supervision.
  10. Planned post-closing integration — the intended movement of systems, data, and people, forming the baseline for any Reversible Integration Plan.

The Declaration does for ownership what the export license application has long done for goods: it converts a transfer into a reviewable, falsifiable record. Misstatement would carry the penalties that already attach to CFIUS filings — which the Committee has shown itself willing to impose.[29]


6.5 Allied Coordination

A U.S.-only system will be arbitraged through friendly jurisdictions within a deal cycle: the acquirer of tomorrow buys the sensitive target through a Dublin or Singapore vehicle, or simply closes in a jurisdiction that has not yet built a regime. The remedy is common standards with the states that share both the technology and the threat assessment: the European Union — whose new regulation now mandates screening of AI, quantum, and semiconductor investments in all member states and whose Commission is studying outbound controls on the American model;[25][27] the United Kingdom, with its NSIA and its precedent-setting functional merger analysis; Japan and South Korea, whose semiconductor and materials positions make them indispensable; Australia and Canada, within existing intelligence-sharing structures; Singapore, precisely because it has become the domicile of choice for relocating Asian AI companies and its cooperation determines whether the Nationality Stack can be audited at all; and Taiwan, where legally and diplomatically appropriate, given its unmatched position in the compute supply chain. Coordination should cover, at minimum: shared Transfer Rights disclosure formats, mutual recognition of safe harbors, a common ultimate-beneficial-ownership standard, and a consultation channel for cases — like Manus — where two members’ regimes, or a member’s and a rival’s, collide over the same company.


6.6 Guidelines for Federal and State Policymakers

Finally, ten disciplines for the legislators and officials who will build this regime — offered because the ownership embargo will be only as legitimate as its administration. Policymakers should: protect specific strategic capabilities, not broadly demonize foreign investment, keeping the Capability Test at the center of every intervention; examine rights and control rather than nationality alone, since a passive allied investor is safer than a domestic one acting for a rival; preserve financing and exit opportunities for legitimate startups, treating the Deal-Sovereignty Discount as a policy cost to be minimized, not an externality to be ignored; require pre-closing clearance where integration would be irreversible, because the Manus case proves that post-closing remedies arrive after the knowledge has moved; separate competition concerns from national-security concerns, resisting the temptation to launder ordinary industrial policy through the security vocabulary; publish clear thresholds and appeal procedures, so that the factual nationality inquiry of Section 3 is predictable rather than discretionary; avoid using national security as a disguised protectionist instrument, which corrodes the regime’s credibility abroad and its lawfulness at home; coordinate with allies before imposing unilateral restrictions, for the arbitrage reasons of Section 6.5; demand transparency over ultimate ownership and government influence from every party, including domestic ones; and create safe harbors for low-risk investment, writing into law everything the embargo does not reach. A regime built on these disciplines can defend national capability without strangling the ecosystem that produces it. A regime built without them will discover, too late, that it embargoed its own future.


Section 7: What Have We Learned? The Five Pillars of the Ownership Embargo

Seven sections of doctrine, cases, and mechanism design reduce, in the end, to five propositions. They are stated here as pillars because each can bear weight alone, and because together they support the entire structure of the argument.


Pillar 1: Rights Matter More Than Labels

A transaction’s legal title does not reveal its strategic effect. Investment, licensing, recruitment, and cloud contracts can collectively reproduce an acquisition — as Microsoft–Inflection, the cloud–model partnerships, and Meta–Scale each demonstrated in a different register.[18][14][16] Any regime that keys review to labels invites the arbitrage it exists to prevent. The unit of analysis must be the Transfer Right: who obtains equity, governance, code, data, and talent, in what measure, on what conditions.


Pillar 2: Substance Matters More Than Domicile

Corporate registration is only one layer of nationality. Technology origin, talent, data provenance, compute, ultimate ownership, and government relationships create continuing jurisdictional ties that survive every reincorporation — which is why Singapore incorporation saved Manus nothing, and why the Nationality Stack, not the registry entry, is the honest map of who may claim a company.[1][5]


Pillar 3: Knowledge Transfer Can Be Irreversible

Shares and money can be returned. Knowledge absorbed by engineers, code reviewed by a buyer, and strategy incorporated into an organization cannot always be recalled — the eggs, once scrambled, stay scrambled.[8] The regulatory consequence is temporal: for AI, the only fully effective review is pre-closing review, and irreversibility itself — through the Irreversibility Test and the Reversible Integration Plan — must become an object of regulation rather than an afterthought of it.


Pillar 4: Security Must Be Proportionate

Overbroad ownership restrictions destroy legitimate investment, depress startup valuations through the Deal-Sovereignty Discount, push founders toward early relocation or hidden structures, and accelerate the world’s fragmentation into rival AI blocs.[7] The embargo’s legitimacy depends on everything it declines to reach: the Capability, Control, and Irreversibility Tests at the front door, the safe harbors at the side door, and published thresholds throughout.


Pillar 5: AI Ownership Will Become Permissioned

The future of cross-border AI investment will not be a binary choice between open markets and total prohibition. Governments will permit some rights, restrict others, and continually condition ownership on political and security compliance — climbing and descending the remedy ladder as circumstances change. The Manus resolution taking shape as this paper is written — a Tencent-anchored, deliberately minority-capped consortium repurchasing the company at the acquirer’s price under the supervising eye of the state — is not an aberration of this regime. It is its first mature artifact.[10][11]


Conclusion: The Age of Permissioned Ownership

Return, finally, to where this paper began: to a completed acquisition. In December 2025, by every conventional measure, Meta owned Manus. The purchase agreement was signed, the consideration paid, the investors cashed out, the website amended to read that Manus was now part of Meta. Under the registrational picture of corporate law, the story was over. Under the picture this paper has drawn, it had barely started — because the shares were only the visible portion of the transaction. Beneath them, the real cargo was moving: the Code Right, as Meta’s engineers gained access to agentic systems built by another country’s researchers; the Data Right, as integration connected corpora and telemetry to a new owner’s infrastructure; the Talent Right, as founders and engineers began folding into the acquirer’s organization; the Governance Right, as strategy passed to Menlo Park; and the Equity Right, the only one the registries recorded. When the NDRC ordered the deal unwound on April 27, 2026, it was not disputing the paperwork. It was asserting that the cargo — the capability — belonged, in part, to China, and could not be exported by contract.[1][2]

The aftermath rehearsed every theme of this paper in miniature. The separation Meta implemented in June — blocked systems, prohibited tools, severed data flows — was the remedy ladder climbed in public.[9] The founders’ exit bans were the Talent Right enforced at the border of the human body.[5] The Tencent-led buyback at the original $2 billion valuation, with the largest holder deliberately capped below control, was permissioned ownership negotiated in real time.[11] The billions Meta continues to pour into its AI buildout — capital expenditure guidance of $125 to $145 billion for 2026 alone — measured what was at stake for the acquirer, and why acquirers will keep coming despite everything.[34][35] And the anxiety spreading through every founder chat from Hangzhou to Palo Alto measured what was at stake for everyone else. Governments watched, and drew the same conclusion from opposite trenches: intervene before integration, because afterward there is nothing left to protect. That is why the EU’s new regulation mandates prior authorization for AI investments down to research activities, why the United States entrenched and extended its outbound regime, and why Beijing codified, effective July 1, 2026, its power to reach completed deals and restrained talent.[25][23][9]

The warning must be stated as plainly as the diagnosis. An ownership embargo administered arbitrarily — without published thresholds, without the three threshold tests, without safe harbors, with security language draped over ordinary protectionism — will not protect national capability. It will tax it: through the Deal-Sovereignty Discount, through the flight of founders, through the fragmentation of the research commons on which every national ecosystem secretly depends. The instruments this paper proposes — the Five Transfer Rights as the unit of analysis, the Nationality Stack as the factual method, the Transfer Rights Declaration as the disclosure vehicle, the Remedy Ladder as the proportionality discipline, and the Reversible Integration Plan as the answer to irreversibility — are offered as the difference between an embargo that is governed and an embargo that merely governs.

Why, in the end, Ownership Embargo? Because the term names precisely what has changed. An embargo is the state’s declaration that a category of transfer is too consequential to be left to private consent — and ownership of frontier AI enterprises has now joined that category, alongside the weapons, the chips, and the data that preceded it up the ladder of control. Because the mechanism is embargo-like in every operational detail: lists and thresholds, licenses and conditions, prohibitions and forced reversals, applied not to crates at a port but to rights in a company. And because the name keeps the historical continuity visible: this is not a new instinct of states but the oldest one, arriving at a new object.

The defining question of the next era of artificial intelligence will not be only who invents the model, manufactures the chip, builds the data center, or finances the company. It will also be who is permitted to own the organization in which those capabilities converge. Capital may remain global, corporations may remain privately held, and founders may continue to seek the highest bidder. But ownership will no longer travel as freely as money. Every major AI acquisition will carry an additional question: whether the transaction transfers an economic asset — or exports a strategic capability. When governments decide that the two have become inseparable, the acquisition agreement will become an export document, regulatory approval will become a political license, and private ownership will become what this paper has argued it is already becoming: a permission — granted by states, conditioned on conduct, and revocable at the border where technology, talent, and sovereignty now meet.


Footnotes / Endnotes:

[1] Reuters (Fanny Potkin, Che Pan et al.), “China orders Meta to unwind $2 billion purchase of AI startup Manus,” Reuters, April 27, 2026. https://finance.yahoo.com/sectors/technology/articles/china-orders-meta-unwind-2-154056185.html

[2] Bloomberg News, “China Blocks Meta’s $2 Billion Acquisition of AI Firm Manus,” Bloomberg, April 27, 2026. https://finance.yahoo.com/news/china-blocks-meta-2-billion-095700004.html

[3] CNBC (Beijing bureau), “‘Draconian development’ in Meta-Manus deal draws the line in China’s AI race with the U.S.,” CNBC, April 28, 2026. https://www.cnbc.com/2026/04/28/china-blocks-meta-manus-deal-ai-tech-rivalry.html

[4] O’Melveny & Myers LLP, “China Unwinds Meta’s Acquisition of Manus: Implications for Cross-Border AI Transactions,” Client Alert, May 5, 2026. https://www.omm.com/insights/alerts-publications/china-unwinds-meta-s-acquisition-of-manus-implications-for-cross-border-ai-transactions/

[5] Shumaker, Loop & Kendrick, LLP, “China Made Meta Give Back a $2 Billion Artificial Intelligence Acquisition: What It Means for Your Next Cross-Border Deal,” Client Alert, July 2026. https://www.shumaker.com/insight/china-made-meta-give-back-a-2-billion-artificial-intelligence-acquisition-what-it-means-for-your-next-cross-border-deal/

[6] Trivium China, “China blocks Meta’s Manus acquisition using foreign investment security review,” Trivium China Research, May 18, 2026. https://triviumchina.com/research/china-blocks-metas-manus-acquisition-using-foreign-investment-security-review/

[7] Foreign Policy, “Why Beijing Killed the Manus-Meta Deal,” Foreign Policy, May 6, 2026. https://foreignpolicy.com/2026/05/06/china-ai-singapore-manus-meta-us-competition/

[8] Foreign Policy, “China Pulls the Plug on Meta’s AI Acquisition,” Foreign Policy, April 28, 2026. https://foreignpolicy.com/2026/04/28/china-blocks-ai-meta-manus-deal-national-security/

[9] CNBC, “Meta reportedly begins dismantling $2 billion Manus deal on Beijing’s orders,” CNBC, June 12, 2026 (citing Bloomberg; quotes Han Shen Lin, The Asia Group, and Tilly Zhang, Gavekal Dragonomics). https://www.cnbc.com/2026/06/12/meta-reportedly-begins-dismantling-2-billion-manus-deal-on-beijings-orders.html

[10] Reuters (Fanny Potkin and Kane Wu), “Tencent in talks to become AI startup Manus’ largest shareholder, sources say,” Reuters, July 10, 2026. https://finance.yahoo.com/technology/ai/articles/tencent-talks-become-ai-start-030728722.html

[11] Bloomberg News, “Tencent in Talks to Become Largest Holder of Manus, FT Reports,” Bloomberg, July 11, 2026. https://www.bloomberg.com/news/articles/2026-07-10/tencent-in-talks-to-become-largest-holder-of-manus-ft-reports-mrectviz

[12] TechCrunch, “China is increasingly keeping its best AI talent to itself (citing Stanford AI Index 2026),” TechCrunch, May 27, 2026. https://techcrunch.com/2026/05/27/china-is-increasingly-keeping-its-best-ai-talent-to-itself/

[13] Seeking Alpha, “Manus founders seek $1B to unwind Meta takeover amid Beijing pressure,” Seeking Alpha, May 21, 2026. https://seekingalpha.com/news/4595614-manus-founders-seek-1b-to-unwind-meta-takeover-amid-beijing-pressure-report

[14] U.S. Federal Trade Commission, “FTC Issues Staff Report on AI Partnerships & Investments Study (statement of Chair Lina M. Khan),” FTC Press Release, January 17, 2025. https://www.ftc.gov/news-events/news/press-releases/2025/01/ftc-issues-staff-report-ai-partnerships-investments-study

[15] FTC Office of Technology, “Partnerships Between Cloud Service Providers and AI Developers: FTC Staff Report on AI Partnerships & Investments 6(b) Study,” Federal Trade Commission, January 2025. https://www.ftc.gov/system/files/ftc_gov/pdf/p246201_aipartnerships6breport_redacted_0.pdf

[16] CNBC (Jonathan Vanian), “Scale AI’s Alexandr Wang confirms departure for Meta as part of $14.3 billion deal,” CNBC, June 12, 2025. https://www.cnbc.com/2025/06/12/scale-ai-founder-wang-announces-exit-for-meta-part-of-14-billion-deal.html

[17] Reuters, “Meta poaches 28-year-old Scale AI CEO after taking multibillion-dollar stake in startup,” Reuters, June 2025. https://in.marketscreener.com/quote/stock/META-PLATFORMS-INC-10547141/news/Meta-poaches-28-year-old-Scale-AI-CEO-after-taking-multibillion-dollar-stake-in-startup-50230676/

[18] Computerworld, “Microsoft-Inflection deal is a merger, but that’s OK, says UK,” Computerworld, September 2024. https://www.computerworld.com/article/3504862/microsoft-inflection-deal-is-a-merger-but-thats-ok-says-uk.html

[19] Noerr LLP, “Acqui-hire: The Microsoft/Inflection case and its implications for legal practice and legislation,” Noerr Insights, March 2025. https://www.noerr.com/en/insights/aqui-hire-the-microsoft-inflection-case-and-its-implications

[20] TechCrunch (Paul Sawers), “UK regulator greenlights Microsoft’s Inflection acquihire, but also designates it a merger,” TechCrunch, September 2024. https://techcrunch.com/?p=2847983

[21] U.S. Department of the Treasury, “Outbound Investment Security Program (Executive Order 14105; Final Rule effective January 2, 2025),” Treasury.gov. https://home.treasury.gov/policy-issues/international/outbound-investment-program

[22] Holland & Knight LLP, “Outbound Investment Screening Rule Goes into Effect,” Holland & Knight Insights, January 2025. https://www.hklaw.com/en/insights/publications/2025/01/outbound-investment-screening-rule-goes-into-effect

[23] Sidley Austin LLP, “U.S. Treasury Issues Final Rule Restricting Outbound Investments in Chinese-Affiliated Entities (with updates on the COINS Act of 2025 and the proposed CFIUS Known Investor fast-track program),” Sidley Insights, 2024–2026. https://www.sidley.com/en/insights/newsupdates/2024/12/us-treasury-issues-final-rule-restricting-outbound-investments-in-chinese-affiliated-entities

[24] Council of the European Union, “Foreign direct investment: Council and Parliament reached political agreement to improve FDI screening,” Council Press Release, December 11, 2025 (updated February 11, 2026). https://www.consilium.europa.eu/en/press/press-releases/2025/12/11/foreign-direct-investment-council-and-parliament-reached-political-agreement-to-improve-fdi-screening/

[25] Sheppard Mullin, “Harmonised, But Not Uniform: The EU’s New FDI Screening Regulation,” Sheppard Mullin Insights, June 11, 2026. https://www.sheppard.com/insights/blogs/harmonised-but-not-uniform-the-eus-new-fdi-screening-regulation

[26] Cleary Gottlieb Steen & Hamilton LLP, “The Rise of the New EU FDI Screening Regulation,” Cleary Gottlieb Publications, March 2026. https://www.clearygottlieb.com/news-and-insights/publication-listing/the-rise-of-the-new-eu-fdi-screening-regulation

[27] Mayer Brown, “Shaping investments into EU strategic sectors: The FDI Screening Reform and the Industrial Accelerator Act,” Mayer Brown Insights, March 2026. https://www.mayerbrown.com/en/insights/publications/2026/03/shaping-investments-into-eu-strategic-sectors-the-fdi-screening-reform-and-the-industrial-accelerator-act

[28] DLA Piper, “CFIUS Annual Report: Key trends, enforcement, and considerations for 2025,” DLA Piper Insights, August 2025. https://www.dlapiper.com/en-us/insights/publications/2025/08/cfius-2024-annual-report

[29] Thompson Hine LLP (SmarTrade), “Treasury Releases Annual CFIUS Report (Calendar Year 2024 statistics),” Thompson Hine SmarTrade, August 11, 2025. https://www.thompsonhinesmartrade.com/2025/08/treasury-releases-annual-cfius-report-3/

[30] Alexandros Kazimirov, “Are Big Tech’s Quasi-Mergers With AI Startups Anticompetitive?,” ProMarket (Stigler Center, University of Chicago Booth School of Business), April 28, 2025. https://www.promarket.org/2025/04/28/are-big-techs-quasi-mergers-with-ai-startups-anticompetitive/

[31] American Antitrust Institute (Alexandros Kazimirov), “Working Paper No. 25-01: Mergers & Cooptive Acquisitions (drawing on Mark Lemley, Stanford Law School, and Matthew Wansley, Cardozo School of Law, on ‘cooption’),” AAI Working Paper, April 2025. https://www.antitrustinstitute.org/work-product/mergers-cooptive-acquisitions-working-paper/

[32] ProMarket (Stigler Center, University of Chicago), “Antitrust’s Hydraulic Effects on Startups,” ProMarket, January 7, 2026. https://www.promarket.org/2026/01/07/antitrusts-hydraulic-effects-on-startups/

[33] FastAIJobs (compiling Federation of American Scientists policy analysis), “The Acqui-Hire Map: How Big Tech Is Swallowing AI Startups Without Acquiring Them,” FastAIJobs Career Hacks, April 2026. https://www.fastaijobs.com/career-hacks/ai-acquihire-map-2026

[34] CNBC, “Meta Q1 2026 earnings report,” CNBC, April 29, 2026. https://www.cnbc.com/2026/04/29/meta-q1-earnings-report-2026.html

[35] Fortune, “Meta just bumped its 2026 capex forecast up to as much as $145 billion — and investors flinched,” Fortune, April 29, 2026. https://fortune.com/2026/04/29/meta-zuckerberg-145-billion-ai-spending-roi/

[36] Ron Schmelzer, “AI Is Breaking Silicon Valley’s Global Playbook,” Forbes, April 30, 2026. https://www.forbes.com/sites/ronschmelzer/2026/04/30/ai-is-breaking-silicon-valleys-global-playbook/

[37] TechWire Asia, “China orders Meta to unwind Manus AI acquisition (quoting Han Shen Lin, The Asia Group, and Lam Zhen Guang, Clyde & Co),” TechWire Asia, April 29, 2026. https://techwireasia.com/2026/04/china-orders-meta-to-unwind-manus-ai-acquisition/

[38] Open Magazine, “Why China Forced Meta to Unwind Its $2 Billion Manus AI Deal After Closing (quoting Lian Jye Su, Chief Analyst, Omdia),” Open Magazine, May 3, 2026. https://openthemagazine.com/world/why-china-intervened-in-metas-2-billion-manus-ai-deal-post-completion

[39] CNBC (op-ed), “In blocking Meta-Manus deal, China sent a powerful reminder to Mark Zuckerberg and U.S. market about AI race,” CNBC, April 28, 2026. https://www.cnbc.com/2026/04/28/china-meta-manus-ai-deal.html

[40] TechCrunch, “Meta’s Manus deal and the new path for Chinese AI startups (quoting Winston Ma, Adjunct Professor, NYU School of Law),” TechCrunch, 2026. https://techcrunch.com/?p=3080617

[41] Lexology (Han Kun Law Offices), “China Orders Unwinding of Meta-Manus Deal: A New Precedent Under the Foreign Investment Security Review Mechanism,” Lexology, April 30, 2026. https://www.lexology.com/library/detail.aspx?g=2175a4dd-124d-419d-a93e-d3ea5bd84726