A new warning from MI5 underlines why research security should now be treated as a legal and governance issue for in-house lawyers and senior leadership teams of UK universities.
MI5 has warned that more than 100 academics linked to British institutions have unwittingly contributed to projects funded through the China General Technology Research Institute (CGTRI). MI5 says CGTRI has “very strong ties” to China’s Ministry of State Security (MSS) and that its primary purpose is to fund academic research that directly improves the MSS’s technical capability for espionage. Areas of research identified include AI, cyber-security, covert communications and steganography.
Importantly, MI5 acknowledges that many institutions and researchers may have engaged with CGTRI in good faith because its connection to Chinese state security was obscured. Nevertheless, universities are strongly advised to review immediately any existing or proposed collaborations with CGTRI. The Security Minister has reportedly written to university vice-chancellors calling for relationships with CGTRI to end. But the issue is wider than that. The alert also recommends due diligence on any research collaboration with Chinese institutions to ensure CGTRI are not involved. Universities should have robust systems in place to identify high-risk foreign research funders or collaboration partners.
The potential legal exposure includes criminal offences. For example, the National Security Act 2023 outlaws assisting a foreign intelligence service and deriving a benefit from a foreign intelligence service if the person knew, or ought reasonably to know, that their conduct assisted, or derived a benefit from, a foreign intelligence service. Essentially, MI5’s warning puts universities and academics “on notice”.
There is also a separate export-control dimension which universities should not overlook. The Export Control Act 2002 and the Export Control Order 2008 set the controls over the export of goods, transfers of technology and overseas technical assistance. Failure to comply with these controls is a criminal offence.
For universities, “export” risk is therefore not confined to shipping physical equipment overseas. Research involving controlled technology can engage export-control requirements, and transferring controlled technology without the necessary authorisation can constitute a criminal offence under the applicable regime. The precise position depends on the technology, destination, end-user and end-use.
The National Security and Investment Act 2021 (NSIA) is also relevant to universities active in areas of research that are critical to UK’s national security and infrastructure. NSIA gives the UK Government the power to call-in for review acquisitions of control over businesses and assets key to the UK’s national security and infrastructure, and depending on the risk, to impose conditions or to prohibit such transactions.
Other potentially relevant regimes include the Foreign Influence Registration Scheme and any designation under the National Security (State Threats) Act 2026.
The practical message for university leadership is clear
International research due diligence should bring together research security, export controls, National Security Act and NSIA alongside other regimes. Current CGTRI relationships and research collaborations with Chinese institutions merit immediate review, but the wider lesson is the need to understand who ultimately funds, receives and may use sensitive research before collaboration begins.
Our content explained
Every piece of content we create is correct on the date it’s published but please don’t rely on it as legal advice. If you’d like to speak to us about your own legal requirements, please contact one of our expert lawyers.