Home Newsletter Honored Guests Blog About Us Work With Us Sponsor & Advertise Be a Guest The Production Suite Get the Briefing
Cybersecurity

Does the BIOSECURE Act Apply to Private Companies?

By Open Door Salon · June 19, 2026
Does the BIOSECURE Act Apply to Private Companies?

The BIOSECURE Act gets talked about as the wall between American biotech and China. So we put a direct question to someone who maps this kind of exposure for a living: does the law actually cover private companies? Theresa Campobasso, Senior Vice President at Aardwolf Global Solutions and a former U.S. Marine Corps intelligence officer who provided counterintelligence support to the Defense Intelligence Agency, opened our series on China and the life sciences. Her read is that the Act's reach is narrower than most operators assume, and that the gap is sitting in plain sight.

Does the BIOSECURE Act apply to private companies?

Not directly. The BIOSECURE Act binds federal contractors and a short list of named Chinese companies. A private company that does not hold federal contracts sits largely outside its reach, which means the commercial channel between US industry and Chinese biotech is still open. Campobasso laid out the scope plainly:

"The BIOSECURE Act is intended to prohibit federal contractors from using biotechnology products or services from named Chinese companies. And there are a couple companies that are overtly named, but the full list of companies is kind of yet to be determined."

So the law draws a line around government procurement. It does not draw one around the much larger pool of privately funded research, licensing, and development happening every day.

What the law actually covers

The Act is a federal-procurement instrument. It tells organizations that contract with the government what they may not buy and from whom, and it names specific Chinese firms to start. Campobasso called that a reasonable opening move rather than a finished one. The named list is still being worked out, and the mechanism only reaches entities inside the federal contracting relationship. For a company weighing a deal, the practical question is not "is this on a list," but "does any part of this law touch me at all." For most private players, the honest answer today is that it does not.

The commercial channel the law leaves open

This is where the gap lives. A private pharmaceutical company without federal contracts can keep working with Chinese partners across licensing, co-development, and AI-driven research, and none of it is currently covered. In Campobasso's words:

"The private sector is also right now outside the BIOSECURE Act's reach, where the BIOSECURE Act is talking about, hey, federal organizations definitely may not do this, but it really leaves the door open for a private, maybe a pharmaceutical company for example, that doesn't have federal contracts. Right now they can license from any Chinese biotech firm that they want, and they can co-develop intellectual property or basic science research or applied science research with any Chinese GCT [gene and cell therapy] company. They can use a Chinese AI platform to do a lot of their research and modeling, and none of that right now is touched by BIOSECURE."

For an operator, that is the line that matters. The headline framing treats the Act as a barrier; the operational reality is that the most common ways a private company actually engages with Chinese biotech run straight through the opening.

Why the gap matters even if you never sign with a named company

The exposure does not require a deal with an obviously Chinese counterparty. Campobasso's larger point across the conversation is that risk hides below the level where most diligence stops. Companies run solid checks on the partner directly in front of them and then go no further, and the deeper tiers are where the surprises sit.

"Oftentimes tiers three to five are where you're going to find obfuscated state ownership or Chinese government presence, Chinese military technology presence, and maybe some hidden, what we call FOCI, or foreign ownership, control, and influence, that weren't apparent when you just did that third-party check on that first company that you're considering doing business with."

Put the two together and the BIOSECURE gap gets sharper. The law does not reach the private commercial channel, and the private commercial channel can carry hidden state exposure several suppliers deep. A clean first-tier partner is not the same thing as a clean supply chain. The two questions that follow run through the rest of this series: how to map sub-tier supply chain risk below the first tier, and whether there are alternatives to Chinese biotech suppliers at all.

The bigger debate this sits inside

The BIOSECURE Act is one front in a larger argument about how far the United States should go in separating from Chinese biotech, and plenty of serious people think separation is the wrong move. The investment side has pushed back hard. Some have argued that walling off China would weaken American biopharma rather than protect it: that biotech's reliance on China is more about know-how than physical chokepoints, that the country's leverage in medicine is far weaker than in something like rare earth minerals, and that a ban would cost the U.S. industry more than it gains. In that framing, the security concern is real but fairly narrow, mostly a question of the physical drug supply chain.

That is the framing Campobasso's account complicates. Her point is not that the United States should cut China off. It is that the risk is wider and harder to see than the physical supply chain alone. The practical follow-up, whether there are real alternatives to Chinese biotech suppliers, is its own question.

"There's also an intangible supply chain. And we're seeing a lot with the advent of these AI tools... a lot of folks in drug discovery research."

The exposure she describes is also digital, sitting in the AI platforms used for discovery and modeling and in the sub-tier ownership a first-pass check never surfaces, and the BIOSECURE Act does not reach the private commercial channel where much of that happens. So the question the field has not settled is not whether to work with China, but how to do it without treating the security side as a footnote.

Will the market close the gap on its own?

Campobasso did not argue for or against expanding the law. She noted that compliance norms have a way of moving ahead of statute, and she left the outcome open:

"So the law is addressing more of the federal procurement channel, which is a great start. And we may see, much like cybersecurity or much like other areas of compliance, we may see the market decide to shift in that way for their own reasons as well. But right now the commercial channel is still open."

That is the honest place to leave it. Lori Ellis framed the episode around a tension she did not try to resolve: the industry cannot simply wall China off, and it also cannot pretend the current rules cover the real exposure. Whether private industry tightens its own standards the way it eventually did on cybersecurity, or waits for the law to catch up, is the open question operators are living inside right now.

Join the conversation

If you run sourcing, partnerships, compliance, or research strategy, you are already making calls about China exposure that the BIOSECURE Act does not make for you. The people on the other sides of that problem, in government, in diligence, in manufacturing, see parts of it you cannot, and the fastest way to close the gap is to get those views in the same room.

The procurement ban is only one front. On the investment side, the COINS Act would put U.S. capital, licensing, and joint ventures with Chinese biotech under government review, the same China-exposure question approached from deal flow rather than the supply chain.

Open Door Salon convenes those conversations on the record. Watch the full conversation with Theresa Campobasso. And if your company needs to reach the decision-makers weighing these China-exposure calls, that is what sponsorship is for.

← Back to the Blog