Comparative experience suggests there is no single optimal model for research security governance. However, Australia, Japan and Canada demonstrate the value of stronger cross-government coordination, government support for universities, and clearer risk frameworks.
International experience demonstrates that there is no single ideal model for research security governance. However, several comparable countries have developed approaches that offer useful lessons for the UK as it seeks to strengthen and modernize its own framework. While each country in the examples below operates within its own legal, political and higher education context, Australia, Japan and Canada illustrate different approaches to balancing research openness, national security and economic competitiveness.
Australia
Australia is frequently characterized as a ‘first mover’ in research security due to its early adoption of counter-foreign interference and espionage reforms in 2018 as a result of heightened concerns over Chinese political interference and espionage. A defining feature of the Australian response was the establishment of the University Foreign Interference Taskforce (UFIT), which brought together government and universities to co-design the ‘Guidelines to Counter Foreign Interference in the Australian University Sector’. This collaborative model was complemented by an Australian Security Intelligence Organisation (ASIO) campaign, ‘collaborate with care’, which sought to raise awareness of national security risks in international research collaboration across academia.
Australia’s experience highlights both the strengths and limitations of a voluntary, guidance-based approach. While UFIT improved awareness and built trust between government and universities, policy development has ‘languished’ after early progress and implementation has remained uneven. The guidelines have not been substantially updated since 2021, and universities have continued to call for more detailed operational guidance to support decision-making. Critically, Australia’s approach has until recently remained largely voluntary and guidance-driven, with no uniform national baseline for compliance.
Australia is frequently characterized as a ‘first mover’ in research security due to its early adoption of counter-foreign interference and espionage reforms in 2018.
Australia has sought to address these shortcomings by embedding research security more directly into the public funding system. The Australian Research Council (ARC), Australia’s primary public funding body for research, now plays a more active role in assessing foreign interference, defence and national security risks associated with grant applications, explicitly recognizing that publicly funded research, and the protection thereof, should advance Australia’s national interest. ARC grant applicants are subject to extensive disclosure requirements relating to foreign affiliations, appointments, associations and sources of funding, and are required to cooperate with additional information requests where national security concerns arise. In May 2026, Australia’s minister for education refused 13 ARC grant applications on grounds relating to security, defence or international relations. A further significant development has been proposed through reforms to Australia’s Foreign Arrangements Scheme, which grants the minister for foreign affairs powers to cancel, vary or impose conditions on foreign arrangements (including university partnerships) deemed to undermine Australia’s foreign policy. The Foreign Relations (State and Territory Arrangements) Amendment Bill 2026, introduced in July 2026 and currently before parliament, would strengthen oversight of foreign arrangements involving public universities by broadening the scope of legislation to capture foreign arrangements that adversely affect the ‘national interest’, expanding information disclosure requirements and enabling ASIO security advice to inform the foreign minister’s decisions.
Lessons for the UK
- The UK’s collaborative approach to advising universities on research security risks, including on a case-by-case basis through RCAT, remains a strength and should continue to be prioritized.
- Research security guidance should be regularly reviewed and updated so that it remains relevant to emerging risks. To be useful for universities, advice needs to be as specific and actionable as possible.
- Consideration should be given to whether UKRI and other public funders should play a more active role in research security assurance, rather than relying primarily on institutional self-assessment and risk management.
- Voluntary guidance alone is unlikely to deliver consistent implementation across the sector without clearer baseline expectations and appropriate enforcement capacity. Where approaches characterized by voluntary guidance and institutional self-assessment become ill suited to an evolving threat landscape and national security objectives, the government should consider enabling targeted intervention in cases of concern, informed by security advice.
Japan
Japan’s approach to research security is best understood as part of its prioritization of economic security as a strategic imperative. The Economic Security Promotion Act (2022) links the protection of critical technologies, supply chains and research capability directly to national resilience and competitiveness. Coordination is overseen centrally through the Cabinet Office’s Economic Security Secretariat, which helps align policy across economic, science and technology, and national security portfolios.
A defining feature of Japan’s approach is the emphasis on ‘strategic indispensability’ – the pursuit of a national innovation base that is so embedded in global technology networks that it becomes irreplaceable to key partners, and therefore a bulwark against economic coercion and overdependence. This has been accompanied by significant investment in technology partnerships with allies, particularly in semiconductors, advanced computing and AI.
Japan’s model is notable for its coherence, integrating research security into thinking on industrial policy, supply-chain resilience and geo-economic planning. While implementation at the university sector level remains uneven due to reliance on self-assessment and limited compliance infrastructure, Japan’s centrally coordinated model has in effect embedded research security within broader strategic goals.
Lessons for the UK
- Research security should be integrated within wider economic security, industrial strategy and S&T policy objectives.
- Stronger central coordination across government, including at the ministerial and cabinet level, could improve coherence between S&T, trade, industrial and national security policy domains.
- Research security should be viewed not only as a defensive activity but also as a means of strengthening strategic advantage and technological competitiveness.
- Trusted international partnerships can reduce strategic dependencies and bolster sovereign autonomy and the national innovation ecosystem.
Canada
Canada has adopted one of the most structured research security frameworks among peer countries. Its Sensitive Technology Research and Affiliations of Concern (STRAC) policy prohibits federal funding of research projects that involve designated foreign entities or rely on affiliations of national security concern. To support implementation of the STRAC policy, the Canadian government maintains publicly available lists of sensitive technology areas and foreign institutions assessed as presenting elevated risk due to state or military linkages; this provides researchers and institutions with clear criteria for what constitutes an intolerable security risk in the eyes of the government and warrants enhanced scrutiny.
Alongside regulatory tools, Canada has established the Research Support Fund to meet the institutional costs of implementing this increasingly detailed framework. The fund provides financial support to universities and research organizations for developing internal research security systems, including enhanced due diligence, risk assessment tools, governance structures and staff training.
Canada’s approach offers greater clarity and consistency than many peer systems; however, concerns have been raised that static lists may struggle to keep pace with evolving threats and could encourage a complacent security culture within universities, should they remain overly reliant on prescriptive government guidance.
Lessons for the UK
- Clearer guidance on high-risk technology and foreign entities of concern can improve the consistency of decision-making across institutions. Furthermore, more transparent risk assessment criteria can improve institutional confidence. However, static list-based approaches have limitations, and may not be appropriate in all contexts.
- The UK government should allocate dedicated funding to support research security capability within universities.