Author: Lawyer Zhang Jingxinyue, PRC-qualified Lawyer | Singapore Registered Foreign Lawyer
Editor's Note: Recently, the Foreign Investment Security Review Working Mechanism Office rendered a decision under the law to prohibit investment in a cross-border M&A project in the AI sector and ordered the parties to rescind the acquisition and perform their transaction unwinding obligations. This case has drawn further market attention to cross-border structures, technology flows, and data compliance boundaries, and has prompted enterprises to re-examine where procedural arrangements and risk control should be positioned in cross-border transactions.
Under current regulatory practice, the place of registration is no longer the only dimension to examine—transaction substance, technology origin, data pathways, and control relationships are becoming increasingly important. Substance over form is the core yardstick of look-through review.
01 Case Review: Compliance Blind Spots Behind Structural Migration
In recent years, many technology enterprises with domestic backgrounds have chosen to relocate their headquarters functions to jurisdictions such as Singapore in order to enhance their acceptability for international financing and cross-border M&A. This commercial arrangement is inherently reasonable, but equating “completion of re-domiciliation” with a change in compliance status is a typical misjudgment of the current regulatory framework.
The AI unicorn involved in this case launched an M&A transaction with an overseas giant immediately after completing its headquarters relocation, drawing significant market attention. Regulators explicitly stated that enterprises conducting technology exports, data exports, and other foreign-related activities must strictly comply with local law and complete statutory procedures. Ultimately, the regulator made a prohibition decision in accordance with the law and required all parties to perform their transaction unwinding obligations and restore the pre-transaction status.
The core proposition revealed by this result is as follows: in the context of look-through regulation, a mere physical re-domiciliation is not sufficient to automatically sever the jurisdictional nexus with the original legal jurisdiction. If asset transfers, technology licensing, and personnel reporting relationships have not first undergone compliance assessment and approval, the re-domiciliation itself may constitute an unlicensed substantive technology export, adding significant uncertainty to subsequent transaction approval and implementation.
02 Coordinated Application of the Three Legal Frameworks
In recent years, technology, data, and control issues in cross-border technology transactions have drawn greater attention. In regulatory practice, review requirements regarding transaction substance, control relationships, and procedural compliance have continued to increase, and the importance of conducting compliance assessments at the structural design stage has become significantly greater.
This case is not an isolated foreign investment security review matter; rather, it is a typical example of the coordinated application of three major regimes—technology export control, data export compliance, and foreign investment security review—in cross-border technology M&A.
1. Technology Export Control: Re-domiciliation Does Not Equal Licensing Exemption
Under the Export Control Law and the Regulations on the Administration of the Import and Export of Technologies, restricted export technologies—regardless of the form of cross-border transfer, such as code sharing, personnel secondment, business migration, or M&A closing—must obtain prior approval from the competent authorities. An unauthorized cross-border transfer cannot be cured merely because the subsequent transaction form is lawful.
Practical focus: Has the substantive ownership of core technology been transferred across borders during the structural migration? From the perspective of regulatory look-through review, code synchronization, intangible asset licensing, technical support, and similar activities during the re-domiciliation process carry a high compliance risk of being deemed “substantive technology exports.” Relevant licensing procedures must be completed before the migration itself; otherwise, the risk arises on the date of migration, regardless of whether the M&A transaction is completed.
2. Data Export Compliance: Training Data Is the “Invisible Core”
Under the Data Security Law and the Personal Information Protection Law, a cross-border change of the data controller itself can constitute a data export trigger scenario. According to the Measures for Security Assessment of Data Exports, where a data processor processing personal information of more than one million individuals provides personal information abroad, it must submit a security assessment to the cyberspace administration and may proceed only after passing the assessment.
Practical focus: Control over domestic data used in product research and development and iteration will substantively transfer to an overseas entity upon completion of the acquisition. Data compliance obligations and technology export obligations are independent of each other and must be assessed and performed separately; they cannot replace or be conflated with each other.
3. Foreign Investment Security Review: An Important Consideration in National Security Review
Under the Measures for the Security Review of Foreign Investment, the security review working mechanism office has the final veto power over foreign-invested M&A transactions that may affect areas such as technology security and data security. The conclusion of this case with “prohibition plus ordered unwinding” rather than “conditional approval” sends a clear signal: for technology enterprises holding critical core technologies, an offshore structure does not constitute a ground for a security review exemption.
03 Practical Challenges of Transaction Unwinding
After a regulatory prohibition decision, the transaction parties will face highly complex unwinding procedures. Transaction unwinding is usually accompanied by substantial commercial costs and execution complexity, and may give rise to prolonged coordination and dispute resolution problems. The value of compliance is reflected not only in the transaction advancement stage but also in exit arrangements after risks materialize.
- Equity and capital reversal: This involves tracing share change registrations across multiple jurisdictions and returning cross-border funds along the original path, requiring precise alignment with foreign exchange administration procedures.
- Asset and personnel segregation: For already integrated R&D teams, synchronized technical code, and shared underlying data, achieving physical isolation and thorough removal is extremely difficult in practice.
- Allocation of breach liability: Whether the sale and purchase agreement (SPA) provides for a reverse breakup fee for regulatory risks and a clear risk-sharing and loss mitigation mechanism directly determines how losses are borne and the direction of disputes.
Mishandling of any step may trigger cascading legal liability. This also confirms that the value of compliance lies not only in facilitating transaction completion, but also in enabling an orderly exit and controlled loss mitigation when the transaction is blocked.
04 Practical Warning: Three Typical Compliance Missteps in Cross-border Structures
Misconception 1: Re-domiciliation = Decoupling
Some assume that re-domiciling to Singapore automatically confers jurisdictional immunity. However, if the substantive technology origin, data sources, and core team remain onshore, regulators will still exercise look-through jurisdiction.
Misconception 2: Self-developed = Free to Export
Self-developed technology is not automatically free to leave the country. Algorithms, models, parameters, and training methods are all restricted as long as they are listed in the catalogue.
Misconception 3: Data on Overseas Servers = Not a Data Export
Where data originates from within China, is used for domestic business, or is generated domestically, a transfer of control constitutes a data export regardless of server location.
05 Four-Step Compliance Self-Assessment for Enterprises Going Global
Based on the warnings from this case, technology enterprises that intend to advance or have already implemented overseas structures should immediately complete the following four levels of compliance look-through self-assessment:
Technology inventory: Does your core technology qualify for export?
Check the latest Catalogue of Technologies Prohibited or Restricted from Export item by item to verify whether underlying algorithms, model architecture, core code, and key parameters fall within the prohibited or restricted categories. This work must be completed before financing, M&A, or equity adjustments, and commercial judgment must not replace legal assessment. Practical note: Enterprises often mistakenly believe that “self-developed algorithms are not restricted.” In practice, if the underlying architecture relied upon by an algorithm or optimized specific parameters fall within the restricted catalogue, export controls may still be triggered even if they are deployed on servers in Singapore.
Pathway assessment: Has the migration itself already constituted a technology export?
Code synchronization, personnel transfers, technology licensing, and overseas use may all be deemed substantive technology exports in regulatory practice. Compliance procedures must be completed in advance; any delayed remediation faces irreversible legal risk.
Data review: Can your training data be exported?
Clarify the sources of R&D data and verify whether they involve personal information of more than one million people within China or important data. Where a security assessment is triggered, the assessment must be completed and passed before data may be exported. Where export conditions are not yet met, a mechanism for physical isolation and access control between domestic and overseas data should be established.
Structure review: Does your overseas entity have genuine operating substance?
The Singapore entity must have a genuine local management team, independent decision-making mechanisms, and business premises and operational functions consistent with commercial logic. Under look-through review, a non-substantive “shell structure” lacking compliance connections after the structural migration cannot isolate onshore compliance risks and may also face greater uncertainty during cross-border investment review and overseas due diligence. At the same time, the Singapore entity must comply with the local Cybersecurity Act and the upcoming AI regulatory framework to ensure two-way compliance and stability on both ends.
Three compliance documents that must be issued before a cross-border M&A transaction:
- Special legal opinion on technology export control—to determine whether core technology is restricted, whether licensing is required, and whether the migration path is lawful.
- Data export compliance assessment report—to cover personal information, important data, and training data, and to specify the export pathway and approval requirements.
- Foreign investment security review pre-assessment and response plan—to assess in advance the risk of prohibition, the possibility of conditional approval, and the design of transaction unwinding and loss mitigation clauses.
06 Lawyer's Perspective: Cross-border Compliance Enters the Era of “Substantive Review”
For legal service institutions and enterprises going global, this case provides landmark guidance on maximizing value within the rule-of-law framework:
- Technology export compliance due diligence should become a mandatory precondition for cross-border transactions, rather than an optional risk reminder. An independent special legal opinion on technology compliance has become an essential document for major transactions.
- An independent compliance audit should be conducted throughout the entire structural migration process, covering technology flows, personnel attribution, data pathways, and authorization boundaries in a dedicated assessment.
- Multi-jurisdictional coordinated compliance capability has become a core competitive advantage for corporate internationalization. Building a compliance system that can withstand look-through review is the core value of cross-border legal services.
Conclusion
Compliance is not a cost; it is the lifeline of a transaction. Look-through is not obstruction; it is a mandatory course for going global. Proactive compliance is the greatest protection of valuation.
Exempting technology export compliance obligations is not a shortcut to going global. True internationalization lies in achieving the long-term stability and maximization of asset value within the rule-of-law framework.
This is not a slogan; it is the compliance proposition that every enterprise determined to go global must confront before launching each cross-border transaction.
- For case-specific consultation on Singapore corporate governance structure design, tax compliance optimization, and other matters, please contact the professional team at China-Singapore Legal Bulletin.
Author | Cross-border Compliance Team
This article is general information and not legal advice. Specific matters require assessment by appropriately qualified professionals.