Key Takeaways
- National security regulation is broadening, but not uniformly. This quarter combined expanded sanctions authorities and a proposed extension of FOCI review with targeted regulatory relief and efforts to make investment-security processes more efficient. The existing outbound investment rules remain operative while Treasury develops regulations implementing the COINS Act, but recent White House policy statements expressly contemplate broader restrictions.
- Companies should prepare for the possible implementation of BIS’s Affiliates Rule, scheduled to enter into effect on November 10, 2026, while monitoring whether BIS extends the current suspension. Recent reports suggest the Rule may be suspended for two additional months (until January 10, 2027).
- Enforcement continues to focus on known weaknesses and indirect channels. Treasury also brought the first enforcement action under the outbound investment regime, involving an unreported investment by a controlled foreign entity. Recent actions targeted recidivist institutions, individual executives, third-country distributors, intermediaries, and failures to remediate previously identified compliance deficiencies. Policy updates similarly emphasize a sharper focus on conduct implicating national security, government contracts, and regulatory or audit concealment.
- Transaction strategy increasingly matters as much as technical jurisdiction. CFIUS is providing parties with more information and opportunities for early engagement, but its 2025 data reinforce the importance of choosing deliberately between a declaration and a full notice and identifying potential national security issues before signing or filing.
- Compliance should follow the risk beyond the immediate transaction. Sponsors, financial institutions, and multinational companies should extend diligence and controls through portfolio companies, subsidiaries, distribution chains, intermediaries, governance arrangements, and financial channels.
CFIUS
Redesigned CFIUS Website, Risk Matrix, and New Filing Resources
On July 29, 2026, Treasury, as chair of the Committee on Foreign Investment in the United States (“CFIUS” or the “Committee”), launched a redesigned CFIUS.gov website in furtherance of the America First Investment Policy’s directives on transparency and stakeholder engagement. Key additions include a pre-filing consultation portal for raising process questions and submitting transaction context before a formal filing; a public Risk Matrix identifying eight common categories of national security risk with illustrative mitigation measures; expanded filing guidance distinguishing regulatory completeness requirements from materials CFIUS frequently requests; and dedicated pages for Office of Investment Security initiatives such as the Known Investor Program. The portal does not yield advisory opinions or exemptions from jurisdiction or filing requirements, and staff feedback is non-binding, but it formalizes an early engagement channel that can help parties prepare more complete, review-ready filings.
Parties considering transactions that may raise national security considerations should build CFIUS analysis into deal planning from the outset and may use the pre-filing consultation channel to clarify process expectations. Consultations remain voluntary and do not provide jurisdictional or substantive advisory opinions.
2025 Annual Report: More Filings and a Lower Declaration Clearance Rate
CFIUS assessed 140 declarations in 2025, up from 116 in 2024. It concluded action on 92 declarations, or approximately 66%, compared with 91 of 116, or approximately 78%, in 2024, while requests for full notices increased from 17 to 36. CFIUS also opened official inquiries into 62 non-notified transactions and requested filings in nine cases. The data do not suggest that declarations have become disfavored, but they reinforce that the abbreviated process should be selected deliberately, particularly where the parties have a well-developed factual record, limited apparent national security sensitivity, and sufficient transaction flexibility to absorb a request for a full notice.
Outbound Investment
Policy Direction Points to Expansion, but Existing Rules Remain Operative
The White House's August 2026 National Security Science and Technology Strategy signals that the Administration intends to strengthen and potentially expand the Outbound Investment Security Program, including by refining restrictions involving artificial intelligence, quantum technologies, semiconductors, supercomputing, and hypersonics and considering additional areas implicated by China's military-civil fusion strategy. The Strategy also places outbound investment alongside CFIUS, export controls, and data-transfer restrictions as part of a broader technology-security framework.
The Strategy is directional; it does not itself change the operative outbound investment rules. U.S. persons remain subject to the Outbound Investment Security Program ("OISP") as currently in effect until Treasury issues regulations implementing the COINS Act. Investors should therefore continue applying the current rules while tracking Treasury rulemaking and should avoid treating broader policy statements as if they already expand the scope of prohibited or notifiable transactions.
For the investment community, the practical implication is not to diligence against anticipated future rules, but to preserve sufficient visibility into portfolio-company activities and sufficient contractual and governance flexibility to respond when Treasury implements the statutory expansion.
Treasury Brings First Outbound Investment Enforcement Action
On October 7, 2026, Treasury announced the first civil penalty under the OISP, imposing a $200,000 penalty on Amidi, LLC for failing to notify Treasury of an approximately $92,000 investment by its controlled Chinese fund subsidiary in Noematrix, a Chinese artificial intelligence and robotics company. Treasury identified the transaction through its own compliance and market-monitoring activities. The action confirms that Treasury is actively enforcing the OISP and highlights the importance of extending outbound investment controls beyond U.S. entities to controlled foreign subsidiaries and investment vehicles. U.S. investors should have processes to identify potentially covered foreign-entity investments, escalate transactions involving covered technologies and countries of concern, and determine whether a transaction is prohibited or notifiable before closing.
FOCI
Proposed DFARS Rule Would Extend FOCI Review to Uncleared Contractors
On May 7, 2026, the Department of Defense (“DoD”) published a proposed DFARS rule implementing Section 847 of the FY 2020 National Defense Authorization Act (“NDAA”), as amended by Section 819 of the FY 2021 NDAA. The rule, when final, will extend foreign ownership, control, or influence (“FOCI”) and beneficial ownership disclosure and potential mitigation requirements beyond contractors holding security clearances to many contractors and subcontractors performing unclassified DoD work under contracts or subcontracts valued above $5 million.
Contracts for commercial products and commercial services generally will be excluded. A designated senior DoD official could, however, apply the requirements to a commercial contract that presents a risk or potential risk to national security because of sensitive data, systems, or processes.
An “eligible” status generally would be required before covered awards, modifications, option exercises, or extensions are issued. Where mitigation is required, offerors would agree to the mitigation strategies at award and implement them within 90 calendar days. The proposal would also include ongoing disclosure and subcontract flowdown requirements.
Once finalized, the rule is expected to bring thousands of previously uncleared contractors into the FOCI disclosure and mitigation process. Private equity sponsors and other investors in defense-adjacent businesses should assess foreign ownership, beneficial ownership, governance rights, foreign-person relationships, and the potential application of the proposed requirements to portfolio-company contracts and subcontracts.
Sanctions
Iran: Heightened Restrictions under Operation Economic Outcast
Iran sanctions policy did not merely expand through new secondary sanctions; OFAC also withdrew relief that had existed at the beginning of the prior quarter. On July 7, 2026, OFAC revoked Iran General License X, which had authorized certain transactions involving Iranian-origin crude oil, petroleum products, and petrochemical products, and provided only a limited wind-down period through July 17. On August 24, 2026, Treasury launched Operation Economic Outcast, a whole-of-government economic campaign targeting the Iranian regime. Treasury expressly described the initial actions as expanding secondary-sanctions exposure, authorizing blocking sanctions against persons—including non-U.S. persons acting without a U.S. nexus—determined to operate in five newly designated sectors of the Iranian economy: digital assets, technology, gold, aviation, and shipping.
The sector determinations do not automatically block every person operating in those sectors, but they authorize OFAC to impose sanctions on persons determined to operate in those sectors. Additionally, OFAC sanctioned nearly 60 persons and indefinitely suspended several general licenses that had authorized personal remittance payments to Iran and Iranian access to the U.S. cultural and academic system. On September 10, OFAC adopted a presumption of denial for Iran-related specific-license applications, except as required by law or in limited circumstances involving risks to life or safety.
The cumulative effect is a substantially more expansive Iran sanctions posture than existed at the start of the quarter. Companies should evaluate any potential Iran exposure—including through supply chains, third parties, subsidiaries, shipping, and financial services—against the expanded secondary sanctions framework.
Russia: Sanctions Reinforced by Congress
On September 18, President Trump signed the bipartisan Lindsey O. Graham Sanctioning Russia and Iran Act of 2026 (the “Act”). The Act places significant Russia-related restrictions on a statutory footing and imposes additional measures, including restrictions on new U.S.-person investment in Russia and certain energy-related activity, sanctions targeting specified Russian officials, financial institutions, and state-linked entities, and duties of up to 100 percent on goods from certain countries that are major purchasers of Russian energy or facilitators of sanctions evasion. The Act preserves specified waiver and termination authorities, although termination is subject to statutory conditions and congressional review procedures. For companies and investors, the practical significance is greater durability in the Russia sanctions architecture: sanctions policy remains subject to specified executive authorities, but a larger portion of the framework now rests on statutory rather than exclusively executive authority.
Separately, Section 201 of the Act extends the Iran Sanctions Act of 1996 (P.L. 104-172) from 2026 through 2031, continuing the secondary sanctions—which can apply in certain circumstances without a U.S. person or U.S. nexus—authorized under that law, including banking restrictions, asset freezes, and other measures against foreign entities that invest in Iran’s petroleum sector or provide goods or services to the Iranian military.
Cuba: Expanded Secondary Sanctions Risk
Since January 2026, the Trump administration has taken several measures to significantly expand U.S. sanctions against Cuba. These actions materially increase secondary sanctions risk for non-U.S. persons, particularly persons operating in designated Cuban economic sectors and foreign financial institutions facilitating significant transactions for persons blocked under the new authorities.
In Executive Order 14380 of January 29, 2026 (“E.O. 14380”), President Trump declared a national emergency with respect to Cuba under the International Emergency Economic Powers Act (“IEEPA”) and the National Emergencies Act (“NEA”). Previously, Cuba had been subject to sanctions only under older legislation and regulations. The new national emergency brings many of the types of sanctions measures imposed on other jurisdictions, such as Iran and Russia, to bear on Cuba. E.O. 14380 also established a mechanism for imposing additional tariffs on goods imported from countries that directly or indirectly supply oil to Cuba.
On May 1, 2026, President Trump issued Executive Order 14404 (“E.O. 14404”). E.O. 14404 authorizes blocking sanctions against foreign persons determined to operate in specified sectors of the Cuban economy but does not automatically sanction all persons operating in those sectors. It separately authorizes correspondent-account restrictions or blocking sanctions against foreign financial institutions determined to have conducted or facilitated significant transactions for persons blocked pursuant to the order. OFAC has since added multiple entities and individuals to its List of Specially Designated Nationals and Blocked Persons under E.O. 14404, including Cuban state-owned entities, government officials, and persons operating in the financial services, energy, defense and related materiel, metals and mining, and security sectors.
Non-U.S. financial institutions and other non-U.S. persons should identify their potential exposure to Cuba to evaluate their sanctions risk under the expanded sanctions program.
AML/CFT
FinCEN: CTA Rollback and AML Program Reform
FinCEN issued a final rule on August 11, 2026 permanently narrowing the Corporate Transparency Act’s (“CTA”) beneficial ownership reporting requirements. The rule exempts all domestic companies from beneficial ownership information reporting, making permanent the interim rollback adopted in March 2025. Nonexempt foreign-formed entities registered to do business in the United States remain subject to reporting requirements for their foreign beneficial owners, while U.S. persons are exempt from reporting. The reporting relief does not itself remove covered financial institutions’ separate customer due diligence obligations. Separately, FinCEN has proposed a rule to fundamentally reform AML program requirements under the BSA, refocusing compliance on risk-based effectiveness rather than technical checklist adherence, discussed further here.
The CTA rollback reduces reporting burden for domestic entities, but it does not alter covered financial institutions’ separate customer due diligence obligations. FinCEN’s proposed AML/CFT program rule would place greater emphasis on risk-based, reasonably designed programs and consistency in how those programs are evaluated. Financial institutions should assess whether their risk assessments, customer diligence, transaction monitoring, and testing frameworks are aligned with that direction while continuing to satisfy existing requirements.
Export Controls (EAR and ITAR)
BIS Affiliates Rule: Preparing for Reimplementation
The BIS Affiliates Rule, which is set to come into effect on November 10, 2026, following a one-year suspension, would automatically extend applicable EAR restrictions to foreign entities owned 50 percent or more, directly or indirectly, individually or in the aggregate, by one or more Entity List or Military End-User List parties or certain persons on OFAC’s List of Specially Designated Nationals and Blocked Persons. Companies should use the remainder of the suspension period to strengthen ownership diligence across counterparties and distribution chains, while monitoring BIS actions for a reported two-month extension of the suspension beyond the November 10, 2026, implementation date. As of October 7, however, BIS has not published a rule extending the suspension, and November 10, 2026 remains the operative implementation date.
BIS FY2025 Annual Report: Enforcement Surge
BIS released its FY2025 Annual Report to Congress, reporting an increase in EAR penalties from approximately $16 million in calendar year 2024 to approximately $324 million in 2025, with administrative penalties of $108 million and criminal fines and forfeitures of $216 million. Indictments rose from 112 to 162. Recent enforcement matters include a $95 million penalty on Cadence Design Systems in July 2025 for electronic design automation software exports tied to China’s nuclear weapons modernization; a $252 million penalty on Applied Materials in February 2026 for semiconductor equipment exports to an Entity List party; and the March 2026 criminal indictment of two individuals associated with Super Micro, along with a third-party broker, in what BIS described as the largest semiconductor smuggling case ever brought.
For private equity sponsors, the enforcement shift has direct portfolio implications. Recent export-control resolutions demonstrate that aggregate enforcement exposure can reach hundreds of millions of dollars, and the Super Micro indictment confirms that BIS is prepared to pursue individual executives, not just corporate entities. Sponsors acquiring or holding companies that manufacture, export, or distribute controlled dual-use items—including semiconductors, scientific instruments, aerospace components, and industrial equipment—should treat export compliance diligence as a core element of the acquisition process and ongoing portfolio oversight. Key areas include product classification accuracy, restricted-party screening across the full distribution chain, Entity List and end-user diligence, internal escalation protocols, and whether the company’s compliance program is calibrated to the current enforcement environment rather than the materially less restrictive posture of prior years.
BIS Enforcement: Russia Diversion and Entity List Violations
BIS reached two notable settlements this quarter. In the first, BIS settled for $1 million with Container Manufacturing Ltd., an Ohio-based equipment supplier, for 10 alleged EAR violations involving exports to a Russian end user—including transactions rerouted through a third-country distributor after the company’s bank flagged the payments as potentially restricted.
Separately, BIS settled with Plexon, Inc., a Dallas-based neuroscience technology company, for eight unlicensed exports of neural recording systems to the Academy of Military Medical Sciences, a Chinese military-linked Entity List designee, through an Asia-based distributor.
Both cases illustrate a common enforcement pattern: items reaching sanctioned or restricted end users through indirect channels—third-country distributors, intermediary buyers, and rerouted payment flows. Companies should screen not only direct counterparties but also ultimate end users and distribution chains and should treat a financial institution’s refusal to process a payment as a red flag requiring resolution before proceeding.
DDTC Settlement: BAE Systems, Inc. ($36 Million)
On August 13, 2026, the State Department’s Directorate of Defense Trade Controls (“DDTC”) entered into a $36 million administrative settlement with BAE Systems, Inc. resolving 104 alleged violations of the Arms Export Control Act and the International Traffic in Arms Regulations (“ITAR”). The alleged conduct included unauthorized exports of technical data to multiple countries, including China; violations of existing authorization terms and provisos; and unauthorized exports of defense articles designated as Significant Military Equipment.
BAE voluntarily disclosed most of the alleged violations; three arose from a directed disclosure. DDTC suspended $18 million of the penalty on the condition that BAE use those funds for approved compliance measures, including an external Special Compliance Officer for at least 24 months and at least one external compliance audit.
The settlement shows how voluntary disclosure and remediation can affect the structure of an ITAR resolution even when the underlying conduct is extensive. The consent agreement also contains express acquisition and successor provisions—requiring BAE to incorporate remedial measures into newly acquired ITAR businesses within six months and binding covered purchasers and successors to its terms for affected ITAR businesses, unless DDTC approves an exception—underscoring the need to assess continuing compliance obligations in transactions involving businesses subject to consent agreements.
Anti-Corruption (FCPA) and Fraud Enforcement
DOJ’s First 2026 FCPA Corporate Resolution: The Scoular Company
On July 17, the Department of Justice (“DOJ”) announced a three-year deferred prosecution agreement with The Scoular Company, an Omaha-based agricultural supply-chain company, concerning a conspiracy to violate the Foreign Corrupt Practices Act’s (“FCPA”) anti-bribery provisions. DOJ alleged that, between 2013 and 2019, Scoular used third-party customs brokers to pay approximately $2,000 per rail shipment to Mexican officials to permit shipments to cross the border despite failed inspections at the U.S.-Mexico border, authorizing more than $400,000 in bribes and avoiding more than $6.5 million in fees and costs. Scoular agreed to a $9,769,521 criminal penalty and $414,351 in forfeiture. DOJ applied a 25 percent reduction based on cooperation and remediation but did not award voluntary-disclosure credit because the company did not timely report the conduct.
The resolution is DOJ’s first FCPA corporate resolution of 2026. Companies operating through customs brokers, freight forwarders, and other border intermediaries should include those parties—not only sales agents and consultants—in anti-corruption diligence, contractual controls, payment review, and audit procedures.
DOJ Corporate Fraud Enforcement Priorities
On October 1, 2026, the DOJ’s National Fraud Enforcement Division issued a new directive on corporate fraud enforcement. In charging and resolution decisions, prosecutors are directed to give “great weight” to a specified non-exhaustive list of aggravating factors that map closely onto the risk profile of portfolio companies and regulated financial institutions, including conduct involving the exfiltration of U.S. dollars to support foreign adversaries or otherwise threatening U.S. safety or security, including military readiness; efforts to conceal misconduct from regulators or auditors; and conduct causing $25 million or more in loss or affecting 25 or more victims. The directive also prioritizes investigations involving health care fraud, significant tax evasion, and tariff or forced-labor-related fraud, and requires coordination with the Division’s Corporate Enforcement Section throughout its corporate matters. The directive also calls for additional whistleblower incentives and reaffirms the application of DOJ’s Corporate Enforcement and Voluntary Self-Disclosure Policy.
For sponsors and financial institutions, this framework underscores the value of coordinated fraud and national security diligence and compliance oversight across portfolio companies and counterparties—particularly for businesses with government contracts, cross-border payment flows, or exposure to sanctioned or adversarial jurisdictions. Diligence and integration planning should also assess whether a target’s or counterparty’s compliance program and disclosure history would support cooperation credit if an issue is later identified.
Conclusion
Taken together, the quarter's developments show a national security regulatory environment that is increasingly interconnected but not uniformly restrictive. The appropriate response is therefore not simply more compliance, but more discriminating compliance: identifying where regulatory exposure is actually increasing, choosing transaction and filing strategies deliberately, and maintaining controls that follow relevant risk through portfolio companies, subsidiaries, supply chains, intermediaries, governance arrangements, and financial channels.
Dechert’s National Security Group advises clients across CFIUS, outbound investment, export controls, sanctions, AML/CFT, FOCI mitigation, government contracts, and white-collar enforcement. We work with institutional investors, financial institutions, and multinational businesses to provide advice that is legally grounded, commercially practical, and sensitive to regulatory, geopolitical, and reputational risk. If any of the developments discussed in this update raise questions for your business or a pending transaction, we welcome the opportunity to discuss how we can assist.
Contributors
The authors would like to thank Erin Bruce, National Security Advisor, for her contributions to this OnPoint.