Sources: the US-TikTok national security deal faces further delays as US officials fret over the app's risks; both sides agree Oracle will host TikTok's US data
Officials and executives had hoped for year-end deal to address national-security concerns over social-media platform
Context & Ripple Effects
This is the second time an Oracle-centered rescue has stalled. In 2020, sources reported Oracle's bid for TikTok fell short of the Trump administration's national-security bar, and ByteDance floated a standalone US company with Oracle and Walmart as minority shareholders instead. The current track restarted in March 2022, when TikTok was reportedly nearing a deal for Oracle to store US users' data and ringfence it from ByteDance.
By September, the US government and TikTok had reached a preliminary agreement without a ByteDance sale, and talks accelerated ahead of the midterms as Republicans vowed hearings. Today's report is that slippage: the year-end target both sides hoped for is gone, though they now agree on the core technical fix — Oracle hosting TikTok's US data.
First-order effects
- TikTok enters 2023 still operating in the US without a signed national-security agreement, leaving its roughly year-old preliminary deal unratified while officials continue to fret over the app's risks.
- Oracle's role narrows from would-be rescuer-investor (the 2020 structure) to trusted infrastructure provider, anchoring its position as the designated custodian of TikTok's US data even as the political terms stay open.
Second-order effects
- TikTok is forced to sweeten the offer rather than wait it out — days later it proposed operating more of its business at arm's length and opening itself to outside scrutiny by Oracle and others, effectively bidding against its own regulators' doubts.
- Republican lawmakers' promised hearings gain leverage from each delay, giving congressional critics a running argument that executive-branch negotiation alone cannot close the national-security gap.
Third-order effects
- If the pattern holds, the remedy for foreign-owned consumer apps hardens into a template — domestic data custody by a designated US vendor plus third-party audit — applied case by case rather than through forced divestiture, which both the 2020 and 2022 tracks avoided.
- The two-year negotiation sets a precedent that data localization alone may not satisfy national-security reviewers, pushing future scrutiny toward algorithmic control and corporate governance links to China — precisely the concerns the reported deal leaves unresolved.
The trend: US review of Chinese-owned apps is converging on a model of negotiated operational ringfencing — US-hosted data, outside auditors, arm's-length governance — that trades divestiture for prolonged, incomplete oversight.