Summary
- MI5 alleges that CGTRI funds research intended to improve the technical capabilities of China’s Ministry of State Security.
- More than 100 UK-linked academics contributed to affected projects, while MI5 says some may not have known the ultimate funding source.
- Universities are being urged to examine funding provenance more closely in sensitive research including AI and cybersecurity.
British universities are being urged to review research relationships involving a Chinese institute after MI5 said more than 100 UK-linked academics contributed to projects ultimately funded through an organisation the Security Service alleges supports China’s intelligence capabilities.
The Security Service issued an Espionage Alert on 30 September concerning the China General Technology Research Institute, or CGTRI. MI5 says the organisation’s primary purpose is to fund academic work that directly improves the technical capability of China’s Ministry of State Security, including research in artificial intelligence and cybersecurity.
MI5 says more than 100 UK-linked academics contributed to projects funded through CGTRI, while also stating that researchers may in some cases have been unaware of the organisation’s involvement. The alert tells universities to review current or planned collaboration and advises researchers to establish the ultimate funding source behind work with Chinese institutions.
China rejects the allegations. Its embassy in London described them as fabricated and said they damaged educational exchange and research cooperation. Reuters also reported that Security Minister Dan Jarvis had written to UK university leaders urging them to end relationships with CGTRI.
Research security is moving deeper into funding chains
The alert does not accuse the more than 100 academics of knowingly assisting Chinese intelligence, and MI5 explicitly acknowledges that researchers may have participated in good faith. Its warning focuses on the provenance of funding and the possibility that conventional academic collaboration can produce technical knowledge useful to a foreign intelligence service.
Artificial intelligence and cybersecurity make such assessments difficult because the same underlying research can support civilian, commercial, defensive, and intelligence applications. Work on machine learning, software vulnerabilities, communications, or data analysis does not acquire a single purpose simply because it is funded by one organisation.
Universities therefore have to assess relationships around the research rather than relying solely on the subject. Collaborators, funding sources, institutional ownership, potential downstream use, and legal obligations can all affect the risk even when the academic work itself is openly published.
MI5 has told institutions and researchers continuing with work ultimately funded by CGTRI to consider their obligations under the National Security Act 2023 and obtain independent legal advice. The agency also directs universities towards Trusted Research guidance from the National Protective Security Authority.
Due diligence is becoming part of research administration
British universities already operate under export controls, sanctions, research security guidance, and other rules governing sensitive technology. International academic projects can nevertheless move knowledge through papers, visiting researchers, datasets, code, conferences, and joint programmes in ways that look very different from exporting a finished commercial product.
Funding can be equally indirect. The organisation named in a collaboration agreement may not be the body ultimately paying for the work, leaving individual researchers with little visibility of relationships further up the chain unless the university checks them deliberately.
The CGTRI warning therefore pushes research offices towards deeper provenance checks before collaboration begins, particularly where work involves strategically sensitive technology. Universities may need to examine the ownership and funding of partner institutions as well as the immediate project proposal.
Those checks carry their own cost. UK universities depend heavily on international collaboration, and technical research commonly involves teams spread across several countries. Broad restrictions can obstruct legitimate work as well as activity that creates a national security concern, especially when institutional relationships are difficult to classify neatly.
Technology businesses are exposed to the same shift because universities supply research, intellectual property, startups, specialists, and licensing opportunities into the commercial economy. Tighter scrutiny can influence how spinouts handle investment and collaboration, while companies working with academics may be asked to provide greater visibility into funding and ownership.
MI5 has not publicly named the individual academics or universities involved, nor does its public material establish that those researchers knowingly supported Chinese intelligence. The distinction is important as institutions respond to the alert: participation in an affected project is not, by itself, evidence of intent.
The operational change for universities is clearer. In sensitive technology fields, knowing the immediate collaborator is becoming insufficient. Funding provenance and institutional relationships are moving into the ordinary administration of research because commercial innovation and national security increasingly depend on the same underlying technical knowledge.












