The effectiveness of the UK’s research security framework depends not only on formal controls but on the environment in which they are applied. With structural challenges constraining implementation, the UK needs a more coordinated and adaptive approach.
While the UK has strengthened its research security legal and policy architecture, ultimately the effectiveness of a research security framework depends not only on the robustness of formal controls but on the institutional, financial and operational realities in which those controls are implemented. These constraints determine which reforms are feasible and where policy, resources and regulatory attention need to be targeted. This chapter sets out the principal challenges and gaps in the UK’s research security regime, and proposes how policy could be improved.
Lack of coherent strategy
Commentators have increasingly argued that UK research security has been reactive rather than strategic, and that policy often responds to specific incidents only after they have emerged in public or political discourse. This has largely been driven by the absence of a consistently articulated and public whole-of-government strategy on China and, more broadly, by the lack of a long-term vision for the UK’s position within an increasingly competitive global S&T environment. In its 2023 China report, the Intelligence and Security Committee of Parliament noted that overall, the UK government lacked understanding and was slow to identify and protect strategic assets such as emerging technology from exploitation by China.
Strategic coherence has been limited by a lack of policy continuity. Successive UK governments have introduced new strategic frameworks, funding priorities and institutional mechanisms for science and innovation, often without fully embedding or sustaining previous approaches. While periodic policy refreshes are necessary in a rapidly changing technological landscape, excessively frequent shifts can undermine long-term capability-building and reduce clarity for universities and industry partners operating in strategically sensitive areas. This lack of coherence limits the government’s ability to define which areas of research constitute ‘critical’ or ‘sensitive’ technologies, why they matter, and how risk tolerance and protections should vary across different domains.
A more coherent approach would involve systematically identifying where the UK holds, or could realistically develop, a comparative advantage in emerging technology niches, and aligning innovation policy, public funding and research security efforts accordingly. Steps have already been taken in this direction. They include UKRI’s investments in strategic technology, and the programme-based efforts of the Advanced Research and Invention Agency (ARIA) to identify high-impact opportunities. However, these initiatives have generally lacked specificity and have not yet produced a comprehensive, cross-government assessment of the UK’s relative strengths, dependencies and vulnerabilities across the full spectrum of emerging technologies.
Nor have priorities always been clearly communicated across government and to academia, industry and investors in a manner that provides consistent long-term direction. While the recent merging of S&T policy and business and trade functions into a single department – DBIST – may bring greater alignment between industrial and innovation strategy, there is a risk that Prime Minister Burnham’s ‘machinery of government’ reforms further impede momentum in building UK S&T advantage as key areas of government are distracted by bureaucratic restructuring at a time when pace is essential for the UK’s economic growth and geopolitical standing.
More fundamentally, research security cannot be treated as a discrete policy domain separate from broader geopolitical and industrial dynamics. It is indivisible from the global S&T system, which in turn is shaped by supply-chain dependencies, international collaboration networks and intensifying US–China technological competition. Effective policy also requires an integrated understanding of the full innovation life cycle – from ‘upstream’ inputs such as critical minerals and talent to R&D, ‘downstream’ scaling of research innovations, and commercialization. The new prime minister’s initial reforms to the organization of government have explicitly sought to align S&T with industrial policy and economic growth, reflecting the reality that technological advantage depends on translating research and innovation into scaled-up commercial opportunities. However, the reforms do little to resolve the long-standing challenge of integrating S&T policy with national security decision-making. Furthermore, industry leaders have argued that the abolition of DSIT risks diluting the political prominence and strategic focus previously afforded to S&T, potentially slowing decision-making.
Research security cannot be treated as a discrete policy domain separate from broader geopolitical and industrial dynamics. It is indivisible from the global S&T system, which in turn is shaped by supply-chain dependencies, international collaboration networks and intensifying US–China technological competition.
An approach that aligns the UK’s security, S&T and foreign policy imperatives will also require stronger cooperation with like-minded foreign partners through the ‘friendshoring’ of critical technologies – that is, the UK sourcing raw materials, components and technological capabilities from countries it trusts. Given that no state can achieve full self-sufficiency in advanced S&T supply chains, collaboration with trusted partners is increasingly central to resilience and security.
For the UK, this points to a clear need to prioritize deeper integration with Europe’s S&T and defence-industrial base. At present, this agenda remains underdeveloped, despite its potential importance for innovation capacity and national resilience, particularly in the context of the UK’s wider reset with the EU. Although the UK’s rejoining of Horizon Europe as an associate member in 2024 restored UK access to Europe’s flagship research programme, the UK no longer benefits from the same degree of institutional integration with European research, regulatory and industrial ecosystems that it did pre-Brexit. Nor has the UK yet negotiated entry into Horizon Europe’s successor, the 10th Research and Innovation Framework Programme (FP10). More generally, the UK’s lack of sufficient progress in resetting its relationship with the EU has reduced the UK’s ability to operate seamlessly as a bridge between the US and European innovation ecosystems at a time when technological governance is becoming increasingly fragmented.
Beyond Europe, the UK already participates in a range of multilateral groupings – including the G7, Pillar II of AUKUS, and the Comprehensive and Progressive Agreement for Trans-Pacific Partnership (CPTPP) – that provide important foundations for strengthening research security cooperation. In particular, the G7 has made progress through initiatives such as the Common Values and Principles on Research Security and Research Integrity, and through publication of the G7 Best Practices for Secure and Open Research. These initiatives provide a model for shared approaches to research security across the dispersed interests of member states. Pillar II of AUKUS, meanwhile, remains an underused opportunity. As a framework focused on coordinating development of emerging and dual-use technologies, it offers potential for deeper integration between the three partners – Australia, the UK and the US – as demonstrated by the introduction of a streamlined AUKUS export control licence framework in 2024. Yet progress under Pillar II has been slow and uneven, raising questions about whether the scheme is being sufficiently prioritized within the UK’s S&T and defence strategies, given its potential to underpin deeper integration of allied defence-industrial bases.
Recommendations
- The UK government should prioritize funding and S&T policy efforts in strategic areas where the UK possesses, or could realistically develop, comparative advantage. Research security efforts should be calibrated accordingly, with protective measures prioritized towards areas of greatest strategic significance. To inform these efforts, the government should:
- Revive the defunct National Security Technology and Innovation Exchange (NSTIx), with the express mission to undertake cross-government technology forecasting and horizon-scanning. The NSTIx should work closely with the Government Office for Science, the Government Chief Scientific Adviser and the national security community to map national strengths and dependencies, identify vulnerabilities and anticipate future areas of emerging technological competition. Such a capability would provide a stronger evidence base for research security policy, industrial strategy and public investment decisions.
- Develop mechanisms to channel a greater share of long-term pension capital into strategic technologies, building on the 2023 Mansion House reforms. By combining pension fund investment with targeted public co-investment and partnerships with trusted allies, the UK can strengthen its ability to develop and commercialize early-stage research and innovation domestically.
- The UK government should prioritize more robust ‘friendshoring’ of S&T capabilities and critical supply chains with trusted international partners. To these ends, the government should:
- Strengthen UK–EU integration on S&T and industrial policy. The UK should prioritize negotiating associate membership of the EU’s FP10, the successor framework to Horizon Europe. The UK should seek to shape FP10 policies so that these focus on shared strategic technology priorities (e.g. AI, quantum, advanced materials, semiconductors) while embedding common research security standards.
- Strengthen multilateral coordination on research security and S&T collaboration between trusted partners. This should involve the following steps:
- The UK should introduce joint approaches through existing forums such as the G7 and the CPTPP. Such efforts must move beyond shared principles towards promoting interoperability between allied countries’ research and innovation systems, harmonizing export control regimes, expanding information-sharing (again, between trusted partners), horizon-scanning, and developing co-funded R&D missions in strategically important S&T fields.
- Pillar II of AUKUS should be explicitly prioritized as a vehicle for ‘friendshoring’ critical scientific research and technology. Building on efforts to streamline export controls between Australia, the UK and the US, future reforms of the programme should focus on reducing remaining barriers to collaboration, including differences in IP regimes, visa systems and research security frameworks. Greater emphasis should also be placed on coordinating long-term public investment and industrial policy across AUKUS members, with export finance agencies playing a more active role in de-risking joint technology development.
- Work with trusted international partners to map innovation supply chains in strategically important technologies. This will involve identifying dependencies, supply chokepoints and complementarities. It would enable allies to specialize in sectors where they hold comparative advantage, jointly mitigate shared vulnerabilities, and better direct public and private investment towards secure technology ecosystems. This could form part of broader bilateral and multilateral agreements on economic security.
Misaligned incentives
Scientific progress has always depended on openness, collaboration, and the cumulative and iterative development of knowledge across institutions, disciplines and borders. Within Western research systems, this globalized model of open science is reinforced by strong institutional norms of academic freedom. This autonomy is widely regarded as a cornerstone of scientific excellence, as it enables researchers to pursue novel lines of inquiry without undue political intervention.
The evolution of the financial model of higher education threatens the advantages engendered by the UK’s open research model. In the UK specifically, the contemporary university system operates within a set of increasingly pronounced financial constraints that shape institutional incentives and behaviours, sometimes to the detriment of national security objectives. Over recent decades, the financial model of UK higher education has become increasingly dependent on diversified revenue streams, with efforts to increase international student fee income a particular focus. Unlike domestic tuition fees, which are capped by the government, international fees are largely unregulated, enabling universities to charge significantly higher prices and use the resulting income to cross-subsidize teaching, research and the provision of degree courses to the domestic student cohort.
The UK’s income from international student fees has almost trebled in real terms since the early 2000s. Students from China represent one of the largest cohorts of international students in the UK, and are particularly concentrated in postgraduate STEM-related programmes. At the same time, domestic public funding for research has not always kept pace with the rising costs of conducting cutting-edge science. Modern S&T research frequently requires access to expensive instrumentation, advanced computational infrastructure, specialist materials and highly skilled technical staff. As a result, institutions often rely on a combination of public grants, industry partnerships and international funding to sustain activity at the frontier of innovation.
These financial dynamics are complicated by the growing overheads associated with research security compliance. A 2023 analysis by ARMA estimated that UK universities spent between £9.5 million and £10.8 million annually on personnel and tools to meet due diligence and regulatory requirements related to research security. These costs are expected to rise as regulatory frameworks expand, placing additional pressure on university budgets and diverting resources from core research activity and innovation. The government has recognized these challenges and has initiated work to establish a dedicated fund to help support the operational costs of implementing research security measures across the university sector. However, at the time of writing, the fund is not yet in operation, leaving institutions to absorb most compliance costs themselves.
Universities have limited incentives to allocate their own resources to strengthening research security, which is often viewed as an administrative overhead rather than as an activity that generates revenue or enhances competitive advantage.
Moreover, universities have limited incentives to allocate their own resources to strengthening research security, which is often viewed as an administrative overhead rather than as an activity that generates revenue or enhances competitive advantage. Efforts to improve research security should also consider what happens when research is not taken forward for security reasons. Universities report that, in these cases, the underlying research or technology is often abandoned because no alternative domestic funding is available.
These pressures are arguably amplified by government-defined performance metrics. The Research Excellence Framework (REF), the UK’s primary mechanism for assessing research quality and allocating public research funding, exerts a powerful influence over institutional behaviour. The REF’s assessment criteria strongly incentivize activities associated with global academic engagement, including producing internationally recognized research, cultivating globally connected research environments, and demonstrating wide-reaching academic and societal influence. Yet existing assessment frameworks make no reference to research security or to institutional management of the risks associated with international collaboration on sensitive research topics (for example, research with potential dual-use applications). Furthermore, while initiatives focused on higher education policy, such as the government’s 2026 International Education Strategy, strongly encourage the growth of TNE, most make only cursory reference to managing the security risks inherent in operating overseas, or to the long-term financial and legal risks of winding back international partnerships due to national security concerns or geopolitical shifts.
The result is a structural tension at the heart of the UK research system. The openness, international partnerships and global talent flows that underpin scientific excellence are often the same factors that create research security vulnerabilities. Addressing this challenge requires greater coherence between S&T policy and the UK’s wider national security, defence and industrial objectives. Research security should not be treated as a standalone compliance exercise, but as part of a broader effort to ensure that academic research supports the UK’s long-term prosperity, technological advantage and national security.
While proportionate protective mechanisms remain necessary, they are unlikely to generate sustained behavioural change unless accompanied by positive incentives that make secure research practices institutionally attractive and financially viable. As the UK’s civilian research base becomes more integrated with defence innovation – reflecting the government’s ambition for the UK to become a ‘leading tech-enabled defence power’ – universities are likely to face growing expectations to strengthen research security capabilities in order to qualify for roles in strategic defence and dual-use programmes. A more effective model would combine targeted regulatory ‘sticks’ with credible ‘carrots’; the latter would reward strong research security practices with enhanced access to public funding, participation in strategic research programmes, and opportunities within the UK’s defence and national security innovation ecosystem. Initiatives such as the Defence Universities Alliance (DUA) represent an important step in this direction, although broader mechanisms will be required to support institutions with differing levels of research intensity and security capability.
More fundamentally, reducing systemic vulnerabilities will require addressing some of the underlying pressures that can incentivize universities to enter into higher-risk partnerships, such as with military-linked Chinese entities. Ultimately, the goal should be to embed research security into the culture of academia as an enabling factor that delivers greater collaboration opportunities for industry, government and trusted international partners.
Recommendations
- The UK government should make strengthening links between academia and government a central pillar of national S&T strategy, using defence investment as a strategic mechanism to align university research and innovation with long-term national priorities and research security best practice. In particular:
- The DUA should be expanded beyond the initial 35 founding member universities to encompass a wider range of institutions across the UK. An effective long-term model could grade universities across a spectrum of capability, so that some would be identified as ‘centres of excellence’ capable of delivering classified sensitive research with direct defence applicability at the highest level, while less well-equipped institutions that still met baseline criteria for the sophistication and maturity of their safeguards would be allowed to deliver unclassified dual-use research.
- Research assessment frameworks should be aligned with research security objectives. The REF should explicitly recognize adherence to best-practice research security as a metric indicating a strong research environment. Assessment criteria relating to international engagement should be reviewed to ensure they are balanced with appropriate risk management considerations.
- Where a research project is judged strategically valuable enough to be blocked from involving overseas collaboration or funding, the government should facilitate access to alternative domestic funding to retain capability within the UK. This could include streamlined pathways through UKRI, ARIA and the National Security Strategic Investment Fund.
- Policymakers and universities should treat over-reliance on international student fee income as a systemic dependency risk. The government should incorporate contingency plans for income diversification, and for potential reductions in international student levels in sensitive STEM fields, into its higher education and S&T policies so that universities can adapt their funding models accordingly without increasing exposure to research security risk.
- The government should operationalize a dedicated research security fund. This fund should help universities pay for due diligence, compliance with research security obligations, and capability-building.
Fragmented governance
Governance of research security in the UK is fragmented, spanning a complex network of government departments, intelligence agencies, regulators, and funding and sectoral bodies (see Figure 1). At the strategic level, responsibility is divided between cabinet committees rather than consolidated within a single forum. Technology and innovation policy is primarily considered through the Cabinet Committee on Digital and Technology, while responsibility for economic security is subsumed within the National Security Council (NSC). The appointment in July 2026 of a dedicated minister for AI – Kanishka Narayan – within the cabinet represents a positive step in recognizing the strategic importance of AI and strengthening political leadership in this area. However, the role is necessarily focused on AI and does not provide equivalent ministerial leadership across the wider landscape of emerging S&T, nor in the broader early-stage research and innovation ecosystem on which long-term technological capability depends.
The institutional challenge remains the absence of a governance structure that consistently integrates S&T policy, economic policy and national security considerations.
More fundamentally, the institutional challenge remains the absence of a governance structure that consistently integrates S&T policy, economic policy and national security considerations. The NSC’s broad remit – encompassing foreign policy, international relations, resilience, trade, development and economic security – limits the committee’s capacity for sustained focus on cross-cutting issues such as research security. Coordination relies on variable departmental participation and issue-specific escalation rather than on institutionalized integration. This contributes to persistent fragmentation between nominally security- and prosperity-related policy domains. The dissolution in 2023 of the NSC’s Economic Security Sub-Committee further limited the capacity for cabinet-level interaction between policymakers focused on S&T and those responsible for national security.
At the departmental level, the Burnham administration’s ‘machinery of government’ reforms, introduced in July 2026, have the potential to improve coherence across a number of research security functions. The bringing together of the functions of DSIT and the Department for Business and Trade (DBT) within the new DBIST means that more of the policy levers underpinning research security – including S&T policy, oversight of public R&D funding, export controls and RCAT – are now situated within a single department. In principle, this should facilitate closer alignment between industrial strategy, S&T policy, research funding and research security, resembling the more integrated departmental model that existed under the former Department for Business, Energy and Industrial Strategy (BEIS).
However, responsibility for a number of other key regulatory mechanisms remains distributed across different entities, creating administrative complexity. Moreover, even where functions are now housed within the same department, long-established organizational siloes and regulatory regimes are unlikely to integrate rapidly. As a result, universities and research organizations are still required to navigate a complex landscape of overlapping obligations, guidance and regulatory mechanisms. The principal governance challenge is therefore no longer simply one of negotiating departmental boundaries, but of achieving effective coordination on an inherently cross-government issue.
This fragmentation is complicated by the UK’s devolved constitutional governance arrangements, whereby regional responsibility for higher education and aspects of research and innovation policy falls to the national administrations of Scotland, Wales and Northern Ireland, while responsibility for national security remains the preserve of the UK central government. The result is that coordination across multiple governments and regulatory systems is needed to deliver a coherent UK-wide approach to research security.
Within this fragmented landscape, RCAT plays an important practical convening role by providing a first point of contact for universities seeking government advice on international research collaborations. RCAT helps translate a dispersed policy and regulatory framework into a more navigable operational interface, and helps coordinate stakeholders within relevant areas of Whitehall. Furthermore, sectoral organizations have increasingly emerged to fill coordination gaps. Bodies such as UUK and HERSA have developed guidance, shared resources and capacity-building initiatives to support universities in meeting research security expectations. While these developments are widely regarded as constructive and have improved practical awareness and capability across parts of the sector, universities continue to encounter overlapping requirements, differing terminologies and multiple points of engagement; this increases administrative burdens and uncertainty over accountability.
Recommendations
- The government should re-establish the Economic Security Sub-Committee of the NSC, with the secretary of state for business, innovation, science and trade and the new minister for AI as permanent members. The remit of the sub-committee should explicitly include protecting critical and emerging technologies from national security risks.
- The sub-committee should be supported by a dedicated secretariat and working group, bringing together senior representatives from DBIST, RCAT, the FCDO, the Cabinet Office, UKRI, NPSA, the NCSC and the intelligence community. The secretariat and working group should coordinate cross-government policy development, oversee implementation, facilitate information-sharing and support collective ministerial decision-making.
- The government should reactivate the NSTIx, which was dissolved in 2025. The NSTIx should provide cross-government insights on the intersection between national security and S&T, and should seek to foster collaboration and coherence across Whitehall.
Sectoral diversity
The UK’s university sector is highly heterogeneous, with institutions varying significantly in size, availability of resources, research intensity, disciplinary focus, student and academic composition, and international engagement. Universities have adopted research security policies and practices at markedly different speeds, resulting in substantial variation in the sophistication and maturity of their institutional security policies and protocols.
Some universities have taken a proactive approach, often developing their policies before formal government guidance is available, supported by strong senior leadership, dedicated resourcing, the development of specialist teams, and structured due diligence and risk management. Other institutions remain largely reactive in their approaches, formulating research security policies only after reputational or security-related incidents occur. In such cases, research security is often treated primarily as an administrative compliance burden and, at times, as an obstacle to funding opportunities rather than as a strategic institutional function.
Variation is also evident across disciplines within universities. Researchers and managers in fields rooted in fundamental science, or reliant on highly internationalized research networks, may exhibit lower awareness of security risks than their counterparts in applied-science or defence-adjacent disciplines, where risk considerations are more embedded due to regulatory oversight and closer industry engagement. The result is uneven research security both across the university sector and within institutions, reflecting differences in leadership priorities, institutional culture and resource allocation.
Given that responsibility for implementation of research security policies largely rests with universities, these disparities translate into systemic vulnerability. Research security practitioners increasingly highlight the risk of ‘forum shopping’, whereby external actors may seek out institutions perceived as having weaker controls when access is restricted elsewhere. Put simply, the sector is only as strong as its weakest link.
A key cause of this unevenness is the absence of a sufficiently detailed and shared national baseline of standards for research security due diligence. The establishment in 2024 of NPSA’s Trusted Research Evaluation Framework (TREF) has been a step forward, but the robustness and maturity of institutional security systems remain largely self-assessed against broad indicators, such as the existence of training programmes or relevant internal policies. Institutions are left to determine their own risk appetite and develop protocols and practice to meet their own requirements, with limited prescriptive detail from government. Recent initiatives by NPSA and the NCSC, as well as collaboration checklists and UKRI and ARMA due diligence questionnaires, have improved consistency at the margins. However, these tools remain high-level and generic in nature: for example, requiring evidence that a conflict-of-interest policy exists but not details of how the policy has been applied to a specific project.
There are no mandatory, UK-wide standards for minimum evidentiary requirements, verification processes or thresholds for unacceptable risk in international research collaborations.
More broadly, there are no mandatory, UK-wide standards for minimum evidentiary requirements, verification processes or thresholds for unacceptable risk in international research collaborations. The absence of common benchmarks is particularly acute in relation to strategically sensitive dual-use research and partnerships involving Chinese institutions. As a result, different universities may reach materially different risk judgments for similar types of collaboration; these judgments will depend on each institution’s capability, experience and risk tolerance.
Such inconsistencies are compounded by unequal access to the data sources, analytical tools and expertise required for rigorous due diligence. Alongside support from government bodies such as RCAT, universities rely on a wide range of open-source intelligence (OSINT) platforms, commercial databases and proprietary research security tools to conduct due diligence, each with differing methodologies and access to information. Consequently, different institutions may arrive at substantially different assessments of the same foreign research partner or potential partner.
For example, a specialist tool such as ASPI’s Defence Universities Tracker – used widely across the UK university sector to map links between Chinese universities and China’s defence-industrial ecosystem – may produce significantly different risk assessments from those generated from other publicly available OSINT resources. Access in the UK to due diligence capabilities is also uneven. Many advanced platforms are expensive and subscription-based, placing them beyond the reach of smaller or less well-resourced institutions. These universities may lack the financial and analytical capacity to conduct comprehensive risk assessments of complex international partnerships. Strengthening coherence, institutional capability and minimum standards across the sector is essential to improving the consistency and effectiveness of UK research security policy.
Recommendations
- The UK should operationalize a planned research security fund along the lines of Canada’s Research Support Fund (see Chapter 4). The fund should be structured around two complementary pillars:
- Sector-wide capability uplift. The fund should pay for shared infrastructure and common services that foster standardized approaches to due diligence and risk management. The UK should consider the feasibility of setting up a sector-wide due diligence platform – where institutions can share anonymized assessments and indicators – and developing and rolling out training programmes and model governance frameworks endorsed by the government.
- Targeted institutional capability-building. The fund should provide financing to enable academic institutions to (a) establish and grow research security teams with specialized expertise, (b) develop internal compliance and governance systems, (c) invest in cyber and physical security systems, and (d) procure OSINT tools to assist due diligence functions.
- Building on existing ‘Trusted Research’ guidance developed by NPSA and the NCSC, and drawing on established training models created by HERSA (such as its courses on navigating the export control and National Security and Investment Act regimes), the UK government and university sector should co-create a formalized professional accreditation for research security personnel.
- A structured training programme should cover due diligence and risk assessment methodologies, investigation skills for identifying foreign affiliations, funding and influence risks, and key legislative requirements; it should also include briefings from NPSA and the NCSC on emerging research security threats.
Protecting know-how and managing people-centred risks
A persistent challenge for research security policy is that some of the most strategically valuable forms of knowledge are not easily captured through formal regulatory protections. In emerging S&T fields, critical expertise is often tacit in nature: embedded in individual researchers’ skills, judgment, technical know-how and problem-solving practices rather than codified in documents or datasets. This tacit knowledge is frequently transferred through informal human interaction such as laboratory work, mentorship, collaborative experimentation and researcher mobility, making it more difficult to monitor and regulate through conventional compliance mechanisms.
Academics and experts interviewed for this paper consistently identified people-centred risks and tacit knowledge transfer as among the least understood and most difficult-to-mitigate vulnerabilities. Joint PhD programmes, postdoctoral positions and other long-term collaborative arrangements such as talent programmes place researchers, many of whom are international, at the centre of cutting-edge STEM research and embed them within laboratory ecosystems. Through sustained presence in these environments, researchers may acquire technical skills, methodological know-how and exposure to emerging research that is not yet publicly documented or commercially protected. In some cases, individuals may subsequently return to their home institutions or move into industry roles carrying this expertise into different national innovation systems. The risk of unauthorized or otherwise problematic knowledge transfer may be especially pronounced where PhD and postdoctoral researchers are sponsored or funded by foreign government-linked programmes such as the China Scholarship Council (CSC).
From a research security perspective, visa and immigration screening mechanisms represent an important first layer of protection. The UK’s Academic Technology Approval Scheme (ATAS) provides formal vetting of international students and researchers in sensitive STEM disciplines as part of the visa application process. However, coverage is not comprehensive. In particular, newer visa routes – such as the Global Talent visa pathway – do not require an ATAS certificate, creating potential gaps in pre-arrival screening for individuals entering highly sensitive research environments. Anecdotal evidence suggests that international researchers are being encouraged to pursue these visa routes as they are quicker and less administratively burdensome.
In any event, visa screening alone cannot address tacit-knowledge leakage risks. Other regulatory frameworks and institutional due diligence processes in the UK overwhelmingly focus on formal arrangements – such as memorandums of understanding, grant agreements, visiting fellowships or joint ventures – at the point of initiation of a research project or collaboration. Comparatively limited attention is paid to the informal and evolving relationships that develop throughout the life cycle of research collaboration.
As a result, institutions may conduct rigorous due diligence at the commencement of a project but possess limited mechanisms for continuous monitoring once a project or collaboration with foreign entities or researchers is under way. Researchers may acquire additional affiliations, participate in overseas talent or fellowship schemes, engage in informal knowledge exchange, or collaborate across overlapping projects in ways that fall outside the scope of initial risk assessments. These risks are not limited to the movement of researchers into the UK; UK-based researchers may also transfer strategically significant expertise through participation in foreign talent programmes, consultancy arrangements, visiting appointments, or involvement in academic conferences or other forms of engagement overseas. This creates structural blind spots in oversight, particularly in fast-moving fields where knowledge is embedded in individuals rather than formal research outputs.
The challenge for policymakers is not to reduce international collaboration, but to differentiate between valid scientific exchange among trusted partners and higher-risk activities that may contribute to the transfer of strategically significant capabilities.
In this context, effective mitigation depends not only on formal screening mechanisms such as ATAS, but also on sustained, ground-up research security awareness and the embedding of a risk-aware culture within universities themselves, ensuring that researchers understand risk pathways and can identify and escalate concerns as collaborations evolve.
At the same time, the UK’s research excellence depends upon attracting international researchers. The British government has rightly recognized this through initiatives such as the Global Talent Fund and the Global Talent visa, which seek to attract leading researchers in strategically important fields. However, Britain struggles to compete for STEM talent because of relatively low salaries compared with those available in competing markets, and because of the widely held perception among potential applicants that UK visa processes are cumbersome. The challenge for policymakers is therefore not to reduce international collaboration, but to differentiate between valid scientific exchange among trusted partners and higher-risk activities that may contribute to the transfer of strategically significant capabilities. Research security measures must strengthen the UK’s resilience without making Britain a less attractive destination for world-leading researchers.
Recommendations
- The UK government should do more to incentivize trusted international STEM talent to locate to the UK. The government should expand the Global Talent Fund to support the work of leading researchers in key technologies, and should align recruitment with national S&T priorities. Funding should extend beyond individual fellowships to support research teams, laboratory capability and commercialization of research, ensuring that world-class talent can establish long-term research programmes.
- The UK should address potential research security gaps in the Global Talent visa route by ensuring the scheme adopts proportionate screening standards equivalent to those in other STEM visa pathways – including, where appropriate, using ATAS-style checks. Where possible, STEM-relevant visas should be prioritized for fast-tracked processing.
- The government and university sector should require enhanced disclosure and risk assessment for researchers who will be funded through foreign state-sponsored scholarships, talent programmes and other in-kind arrangements when these applicants will be working in sensitive STEM fields. Necessary safeguards should include:
- Ensuring foreign government sponsorship, talent programme participation and associated contractual obligations are appropriately captured and assessed through relevant visa screening mechanisms, including ATAS.
- Revising UKRI’s standard terms and conditions to require mandatory disclosure of collaborators’ foreign affiliations, appointments, associations and sources of funding.
- Universities ensuring that staff conducting due diligence have routine access to conflict-of-interest disclosures, with processes in place to periodically review these records throughout the life cycle of research activity. Where feasible, institutions should develop centralized systems capable of identifying and flagging high-risk indicators. Where elevated risks are identified, universities should apply proportionate safeguards and consider referring such cases to RCAT.
Complexity of the security environment
Universities are increasingly required to operate in a rapidly evolving and contested geopolitical environment, in which both regulatory expectations and underlying threat dynamics are in flux. This challenge is compounded by resource constraints within institutions, and is likely to intensify as highly motivated hostile actors adapt their methods in order to circumvent existing safeguards.
One of the critical difficulties remains assessing the risk posed by the research itself. Emerging domains such as AI, quantum technologies and engineering biology are inherently dual-use. In many cases, the strategic significance of research may not become apparent until years after the initial discovery, particularly in early-stage or fundamental science where downstream applications remain uncertain. While academic researchers are typically best placed to understand the technical implications of their work, translating specialized scientific knowledge into forms usable for risk assessment is often difficult. Professional services staff responsible for research governance may lack the expertise to evaluate rapidly evolving technologies. The design of existing regulatory tools can add to this challenge. For instance, export control regimes were largely designed for industrial contexts involving tangible goods and defined end-users, and are poorly adapted to capturing the security implications of the transfer of cutting-edge, intangible research. This makes the relevant administrative processes particularly burdensome for academia.
Furthermore, institutions face increasing difficulty in accurately assessing the risks associated with international research collaborations. This challenge is particularly acute in relation to China, where the boundaries between civilian, military and security actors are often opaque and difficult to distinguish. As a result, ostensibly low-risk Chinese universities, research institutes or companies may have links to wider defence and national security networks that are not immediately apparent. Consequently, due diligence based primarily on formal institutional affiliation or publicly available information is often insufficient to provide a complete picture of risk.
These challenges create uncertainty regarding what constitutes an acceptable level of risk and how existing research security guidance should be interpreted and put into practice. While RCAT and campaigns such as the UK government’s Trusted Research guidance framework, together with a more proactive approach by the security agencies to raise public awareness of emerging threats, have strengthened institutional awareness and capability, many universities continue to face challenges in translating high-level principles into practical and consistent decision-making. This has generated growing demand within the university sector for more detailed, practical and actionable support from government.
Universities often express frustration that RCAT is unable to provide sufficiently clear or definitive judgments regarding complex collaborations, or to explain in detail why particular entities, technologies or partnerships may present elevated risks. To a significant extent, these limitations are unavoidable. RCAT advice and many related regulatory decisions are often informed by classified intelligence that cannot readily be disclosed, while RCAT itself has no regulatory authority to direct institutional decision-making.
Nevertheless, there remains considerable scope to improve the specificity, consistency and utility of government support, particularly in areas where universities face repeated uncertainty. More broadly, generalized or country-agnostic guidance is increasingly viewed as inadequate for addressing the distinctive characteristics of China’s political, legal and institutional system.
In response to similar challenges, jurisdictions such as Canada have adopted ‘list-based’ approaches, naming entities of concern. Proponents of such mechanisms argue that these provide universities with clarity and reduce the burden on researchers to interpret complex geopolitical and institutional risks independently. However, list-based approaches present limitations. Organizations linked to military or state security systems may conceal their connections through subsidiaries, affiliated institutes, joint ventures or alternative naming structures, making static lists inherently incomplete and quickly outdated. There is also a danger that over-reliance on designated lists may create a false sense of security. This may encourage institutions to assume that unlisted entities are low-risk, thereby weakening due diligence and preventing rigorous risk assessment that would consider all aspects of a collaboration.
Ultimately, the challenge of navigating the complex threat environment cannot be resolved through static compliance mechanisms alone, and a purely list-based approach is unlikely to be appropriate for the UK. The pace of technological change, the evolving nature of geopolitical competition and the growing integration of civilian and military S&T ecosystems require more adaptive, intelligence-informed and institutionally embedded approaches to research security. Despite certain calls from within the university sector for prescriptive and granular guidance from the government, the realities of risk management in the context of ever-evolving state threats mean that universities must accept a certain level of ambiguity. The long-term objective of policy should therefore focus on cultivating durable security awareness, institutional resilience and agile risk-management capabilities. Achieving this may require government to explore more structured mechanisms for sharing appropriately declassified threat information with trusted university personnel.
Recommendations
- The UK government should assess the feasibility of extending security clearances to key personnel in universities. This would allow the sharing of classified intelligence assessments with research security teams to support informed decision-making. Given delays in security clearance processing by UK Security Vetting – the unit in the Cabinet Office that provides vetting for all government departments and many public bodies – such efforts should be accompanied by commensurate resourcing to ensure appropriate clearances are issued in a timely manner.
- The UK government should provide more detailed and actionable research security guidance. Rather than maintaining a public list of prohibited or restricted entities, the government should expand the volume of information available for research organizations and academics.
- Where possible, existing intelligence and analysis should be sanitized and declassified for wider dissemination. Awareness of research risks could be improved across the academic sector by publishing more official assessments on priority S&T fields and their dual-use risks, as well as by issuing country-specific advice outlining how different state actors may seek to acquire, transfer or exploit sensitive S&T research.
- More detailed assessments could be provided at a higher level of classification to cleared key university personnel on the risks associated with particular categories of foreign-linked organizations, such as military-affiliated universities, state-owned enterprises, defence-industrial entities and government-sponsored research institutes.
- Existing regulatory mechanisms should be adapted to the realities of academic research. In particular, export licensing application processes should be reformed to help academics articulate the plausible dual-use implications and realistic downstream applications of their work in terms accessible to non-specialist assessors.
- The UK government should increase funding to expand and empower RCAT. While RCAT plays a vital advisory role, its function should be strengthened to enable the agency to operate with a more proactive research security and risk management capability. In particular:
- RCAT should be granted clearer authority to request structured information and records from higher education institutions on their sensitive research programmes. This would help to identify cumulative and cross-cutting risks that may not be visible at the initiation of individual formal arrangements. To support these efforts, universities should be encouraged and assisted to develop and maintain central records of such research activities.
Limitations of self-regulation
Building resilience in an evolving threat environment requires more than nominal or token compliance at the point of funding or collaboration. It increasingly depends on three mutually reinforcing capabilities: (i) credible external validation of institutional risk assessments; (ii) ongoing monitoring across the life cycle of research activity; and (iii) proportionate enforcement mechanisms where risks or areas of non-compliance are identified.
At present, the UK system is comparatively weak across all three dimensions, creating a structural reliance on institutional self-assessment that is increasingly difficult to sustain given the scale and complexity of international research collaboration.
Furthermore, the question of where regulatory oversight should reside within the UK framework remains unresolved, given that assigning such functions to RCAT would risk undermining its role as a trusted source of advice and guidance.
The system places primary responsibility for identifying and managing research security risk on universities themselves. This means that there is limited external validation of whether assessments are consistently or robustly applied. In practice, institutions act as both risk owners and principal assessors of their own compliance. While this model can be effective in environments characterized by full disclosure and good-faith behaviour, it creates inherent vulnerabilities when risks fall outside institutional visibility or are not captured by regulatory frameworks. It also depends heavily on complete and accurate disclosure of foreign affiliations, funding sources and collaborative arrangements. Where disclosure is incomplete, inconsistent or deliberately withheld, there is limited external capacity to detect or correct gaps in assurance.
Furthermore, there is no systematic mechanism for ongoing review or cumulative risk assessment once research activity is under way. Existing instruments, and internal due diligence functions, largely function as point-in-time assessments at the initiation of formal funding or partnership agreements, without much in the way of structured reassessment as projects evolve. This is a significant weakness given the dynamic nature of research collaboration. Personnel move between institutions and projects, new sub-awards and parallel funding streams emerge, and research trajectories shift over time.
If not identified by institutions at the beginning of an arrangement, risks are often only identified after they have materialized, rather than being managed proactively across the life cycle of research activity. At the strategic policy level – once the government’s forthcoming research security strategy is released and implemented – attention must turn to how the new strategy’s effectiveness will be measured, how success will be evaluated, and how the framework can be adapted as the threat environment, technological landscape and geopolitical context evolve.
Finally, these gaps are reinforced by a reliance on what can be considered ‘soft compliance’ mechanisms, where adherence to research security expectations is largely voluntary and mediated through institutional interpretation of risk appetite rather than through consistent external verification or enforcement. While preserving institutional autonomy and avoiding unnecessary bureaucracy remain important, the absence of meaningful external assurance creates a governance gap. Compliance cannot be reliably tested and may drift towards ‘compliance formalism’, whereby procedural adherence to broadly defined expectations substitutes for substantive risk management.
A useful approach to these challenges is emerging in non-UK jurisdictions. It involves sharing responsibility for research security more explicitly between universities, public funding bodies and government, with funders playing a greater role in scrutinizing and validating institutional risk assessments. While progress has been made on embedding research security principles and expectations within UKRI funding frameworks, the UK’s current assurance mechanisms remain limited in their ability to ensure independent verification of risk. UKRI terms and conditions require institutions to undertake due diligence supported by standardized due diligence questionnaires. However, these instruments primarily test whether appropriate policies and processes exist, rather than how they have been applied to a specific project.
Furthermore, institutions are not currently obligated to disclose to UKRI specific high-risk indicators – such as external consultancy arrangements, participation in foreign talent programmes or overlapping institutional affiliations – that would enable funders to assess risk independently. As a result, UKRI has limited capacity to test whether institutional assessments fully reflect underlying exposure to risk. While some observers may be concerned that expanding UKRI’s role could position the research funder as a de facto regulator, public funders already possess significant leverage through grant eligibility criteria and funding conditions. This creates a strong case for strengthening their assurance function as a complementary layer of oversight alongside institutional due diligence, rather than relying on universities as the primary mechanism of control.
Recommendations
- UKRI should strengthen its ‘trusted research and innovation’ principles and expectations so that they become more of a core component of the research security system, complementing university governance and wider government regulation. In particular, UKRI should:
- Revise its standard terms and conditions so that these expressly require mandatory disclosure of collaborators’ foreign affiliations, appointments, associations and sources of funding.
- Revise and update UKRI’s ‘trusted research and innovation’ principles and accompanying due diligence guidance so that these align more explicitly with the evolving national security context of internationalized research. UKRI should draw on comparable international approaches such as the Australian Research Council’s Research Security Framework, which articulates structured principles for assessing risk in relation to national security, defence and international relations.
- Bolster capacity for conducting post-award monitoring and targeted spot checks in relation to higher-risk grants, to confirm that mitigation protocols remain effective and that emerging risks are identified over the life cycle of the research in question.
- The UK government should ensure UKRI is adequately resourced and empowered to undertake timely and proportionate risk assurance. This should include the capacity to undertake independent checks on applicant disclosures and validate information where necessary.