Acquisition by Other Means: How Strategic Competitors Are Harvesting American Technology Through Legitimate Facades
The Illusion of Legitimate Commerce
The most consequential intelligence operations of the current era do not begin in the shadows. They begin with signed contracts, university enrollment forms, and venture capital term sheets. Strategic competitors—most notably the People's Republic of China, but also Russia, Iran, and a growing roster of state-aligned proxies—have spent decades constructing what analysts increasingly describe as "legitimate-facade" technology acquisition pipelines. These pipelines exploit the very features that make the American innovation ecosystem so productive: its openness, its appetite for foreign capital, and its institutional culture of collaborative research.
For policy makers and security professionals attempting to map these threats, the challenge is not identifying a single adversarial actor but tracing a distributed network of relationships, each individually defensible, that together constitute a systematic transfer of strategic capability.
How the Pipeline Is Built
The architecture of state-sponsored technology acquisition typically operates across three interlocking channels.
Joint ventures and minority investment stakes represent the most commercially normalized entry point. A foreign entity—often several steps removed from direct state affiliation—acquires a minority position in an American firm operating in a sensitive sector. Semiconductor fabrication, aerospace components, quantum computing hardware, and advanced materials manufacturing have all attracted this pattern of investment. The minority stake rarely triggers mandatory review under the Committee on Foreign Investment in the United States (CFIUS) framework, particularly when structured below statutory thresholds or routed through intermediary jurisdictions such as the Cayman Islands, Luxembourg, or Singapore. Over time, board access and technical collaboration agreements create organic channels for knowledge transfer that no single transaction would have authorized.
Academic and research partnerships constitute a second, arguably more durable, channel. Foreign nationals enrolled in STEM doctoral programs at American universities represent a legitimate and economically valuable talent pipeline. The problem arises when a subset of those individuals are operating under undisclosed obligations to state-affiliated research institutions abroad, or when the universities themselves enter into formal collaboration agreements with entities that have direct ties to foreign defense programs. The FBI and Department of Justice have documented numerous cases in which researchers simultaneously held appointments at American institutions and at Chinese military-affiliated universities—a dual affiliation that, under China's Military-Civil Fusion strategy, carries legal obligations to share research outputs with the state.
Supply chain infiltration is the third and perhaps least visible channel. Hardware components sourced from foreign manufacturers, software libraries maintained by developers with opaque affiliations, and managed service providers operating within defense contractor networks all represent potential vectors for both passive collection and active capability insertion. Unlike investment-based acquisition, supply chain infiltration can persist undetected for years, embedded in systems whose provenance is rarely audited with sufficient rigor.
The Sectors Most Exposed
Not all technology sectors carry equal strategic value to a competitor seeking to compress America's technological lead. Global Security Map's threat mapping identifies several domains as disproportionately targeted.
Artificial intelligence and machine learning infrastructure—particularly training data sets, inference hardware, and model architectures with dual-use potential—have attracted sustained acquisition pressure. The commercial AI sector's dependence on global talent pools and international research collaboration creates structural exposure that is difficult to mitigate without significant productivity costs.
Biotechnology and pharmaceutical manufacturing represent a second high-priority target. The COVID-19 pandemic accelerated foreign awareness of how dependent the United States had become on overseas production of active pharmaceutical ingredients and critical biologics. Acquisition campaigns in this sector blend commercial logic with strategic intent in ways that make disentanglement exceptionally difficult.
Quantum computing and advanced cryptography occupy a third priority tier. The nation or coalition that achieves practical quantum advantage first will gain the ability to compromise encrypted communications infrastructure at scale. Foreign investment in American quantum startups has been documented, and several such transactions have drawn belated CFIUS scrutiny only after technical milestones had already been shared with overseas partners.
Why Traditional Counterintelligence Is Struggling
The counterintelligence apparatus the United States built during the Cold War was optimized to detect a different kind of threat: human agents, dead drops, signals intercepts, and defectors. It was designed around the assumption that adversarial acquisition would look like espionage—covert, illegal, and detectable through surveillance of known intelligence actors.
The legitimate-facade model inverts that logic entirely. The individuals executing these operations are not spies in any conventional sense. They are researchers, investors, and business development professionals whose activities are individually lawful. The coordination that gives their collective actions strategic significance exists at a level of abstraction that traditional investigative tools are poorly positioned to map.
There are structural gaps as well. CFIUS review authority, while expanded under the Foreign Investment Risk Review Modernization Act of 2018, still depends on voluntary filing for many transaction types and lacks the resources to conduct comprehensive retrospective analysis of deals that have already closed. Export control enforcement through the Commerce Department's Bureau of Industry and Security operates on a licensing framework that was designed for discrete hardware transfers, not the continuous, relationship-based knowledge flows that characterize modern research collaboration.
The FBI's academic outreach programs have improved awareness on university campuses, but institutional incentives within higher education continue to favor international collaboration and foreign student enrollment in ways that create persistent tension with security objectives.
Mapping the Response
Effective countermeasures require a shift from transaction-focused review toward network-level analysis. Rather than evaluating each investment, partnership, or hiring decision in isolation, security professionals and policy makers need tools capable of mapping the relational graph that connects individual actors to state-affiliated entities and identifying patterns that only become visible in aggregate.
Several initiatives point in this direction. The National Counterintelligence and Security Center has expanded its outreach to private sector firms in sensitive industries. The Department of Defense's Trusted Capital program attempts to connect defense-relevant startups with vetted domestic investors, reducing their dependence on foreign capital. And a small but growing number of research universities have begun conducting enhanced due diligence on foreign gift and contract disclosures.
These efforts are necessary but not yet sufficient. The pace of technology transfer continues to outrun the pace of institutional adaptation. For security professionals assessing organizational exposure, the practical implication is straightforward: any entity operating in a strategically sensitive sector should treat its partner and supplier relationships as part of its threat surface, not merely its commercial ecosystem.
The map of this threat is not drawn in intelligence cables or classified annexes. It is drawn in corporate registries, university collaboration agreements, and venture capital cap tables. Reading it requires analytical frameworks built for the era of economic statecraft—not the era of Cold War espionage.