MI5 Warning: Do You Really Know Who Is Funding Your Research?
IT Club — Powered by Altitude IT (opens in a new tab)

Keep up with IT Club
Add IT Club as a preferred source in Google Search.
MI5 says more than 100 UK-linked academics contributed to projects funded through China General Technology Research Institute. This article explains what the alert alleges, includes China’s response and offers practical partnership checks for research organisations and businesses.
On 30 September 2026, MI5 issued an espionage alert about research funding linked to the China General Technology Research Institute (CGTRI). MI5 says more than 100 UK-linked academics have contributed to research projects funded by China’s Ministry of State Security through CGTRI, including work involving artificial intelligence and cyber security.
That is an intelligence-service allegation, not a public court finding. MI5 says some academics may not have known CGTRI was behind the funding. China has rejected the allegations. None of this is a basis for treating researchers, institutions or partners as guilty because of their nationality or because they took part in ordinary international collaboration.
What does the alert say?
MI5’s public alert describes CGTRI as an organisation whose primary purpose is to fund research that could improve the technical capability of the Chinese Ministry of State Security. It advises UK academic institutions to review ongoing and planned collaborations involving the institute, and asks researchers to establish the ultimate source of funding when working with Chinese institutions.
The concern is about the funding chain and what a project may expose—not simply who appears on a university agreement. A grant can pass through an intermediary, a joint venture or a subcontractor. Researchers and businesses may also share data, prototypes, code, equipment or unpublished results before they understand who ultimately supports the work.
Check the relationship, not someone’s identity
For universities, technology firms and SMEs working with research groups, due diligence should focus on the specific collaboration. Ask who provides the funding, whether there are intermediaries, who can access project data, what the contract permits and where intellectual property or technical outputs may go. A legitimate partner should be able to explain the funding and responsibilities clearly.
- 1Follow the funding chain to its ultimate source, including sponsors and subcontractors.
- 2Define what information, systems, samples or equipment each partner can access—and restrict it to what the work needs.
- 3Review ownership, publication, licensing, confidentiality and onward-sharing terms before exchanging sensitive material.
- 4Check whether export controls, security classifications or other sector rules apply to the technology or data.
- 5Record the decision and review it if the funder, partner, scope or access changes.
Make those checks proportionate to the work. A routine, low-sensitivity collaboration may need a lighter review than a project involving unpublished defence-related research, source code, personal data or restricted equipment. If a funder will not explain its role, a partner requests access beyond the project’s needs or contract terms leave onward sharing unclear, pause the exchange and ask the organisation’s security or legal lead to review it.
The National Protective Security Authority’s Trusted Research guidance points organisations towards checklists for industry and research collaborations. These are more useful than a one-time “safe/unsafe” label: the risk depends on the work, information, access and controls in place.
Where a project involves valuable code, datasets or prototypes, keep working copies in an access-controlled project space, use named accounts and remove access when a person’s role ends. Agree in advance how results can be published or reused. These steps protect the work without treating ordinary international research as suspicious.
What about the National Security Act?
MI5’s alert reminds institutions to be aware of the National Security Act 2023. Section 3 concerns assisting a foreign intelligence service and has specific legal elements relating to knowledge and assistance. A person’s involvement in a project or a funding relationship alone does not establish that an offence has occurred. If a real partnership raises concerns, get independent legal and security advice rather than trying to reach a conclusion from a news headline.
The practical lesson is straightforward: transparency about funders and access protects research, organisations and people who may be working in good faith. Do proportionate checks, document the safeguards and keep the conversation open. Security is not a reason to stereotype; it is a reason to understand the relationship in front of you.
Sources and further reading
MI5: 30 September 2026 CGTRI espionage alert →
BBC News: reporting on MI5’s research-funding warning and China’s response →
Plain-English Takeaway
Security includes understanding who ultimately funds a partnership and what information they can reach. Check the funding chain, contract, data access and intellectual-property terms, and seek specialist advice when the risk is material.
Related Articles
When Your IT Provider Finds a Compliance Problem, Who Benefits From the Fix?
Your IT provider finds six compliance gaps and can sell you six fixes. That is not automatically a problem — but it is a reason to ask what is required, what is recommended and who benefits from the decision.
Read articleAI Privacy Is Becoming a Competitive Advantage
The business AI question is changing from 'Can it do this?' to 'What happens to the data it needs?' This independent UK guide explains training defaults, retention, residency, connectors, account types, shadow AI and the controls that make useful adoption possible.
Read articleWhen Data Protection Training Fails: Lessons from the Metropolitan Police
The ICO’s findings show why a policy and a training record matter only when staff know how to handle real information safely.
Read articleNeed help putting this into practice?
IT Club helps you understand the technology. If you need implementation, support or consultancy, the teams behind IT Club can help.
Altitude IT (opens in a new tab) — IT support, cyber security, Microsoft 365 and technology operations.
Altitude AI (opens in a new tab) — AI discovery, automation, governance and implementation.