MI5 names one Chinese funder and over 100 UK-linked academics, but no university, project or case
MI5's one-page alert says more than 100 UK-linked academics contributed to projects funded by China's civilian spy service through a body called CGTRI. It names no university, project or case, and the law it cites turns on what a person ought reasonably to know.
By Parminder Kumar Sharma · · 19 min read

One page, one funder, one count: the alert is an assertion, not a case file
MI5's Security Service Espionage Alert, published on 30 September 2026, is one page and about 470 words (469 by my count of its extracted text, which includes one repeated pull-quote; derived). It names one organisation, the China General Technology Research Institute (CGTRI, 中国通用技术研究院). It gives one count, "more than 100 UK-linked academics". It gives the same status to each of its three central claims, in the same three words: "MI5 has identified". Then it names no university, no project, no project date, no sum of money, no person and no case. The Register covered it on 1 October under a headline saying UK academics' research "may have helped Chinese spies". The Register is the pointer here. This briefing reads the alert itself, the two sections of the National Security Act 2023 it cites, NPSA's guidance, the Chinese embassy's reply and RCAT's own figures.
What that does not establish is that any UK research reached China's Ministry of State Security (MSS), or that any named person did anything wrong. The alert's hedges are about state of mind: "in some cases" academics "may not be aware" who is paying, and "many" will have engaged "in good faith". The sentence about harm, "This activity supports MSS espionage", carries no hedge and no mechanism. The headline's "may have helped" puts the doubt in a different place from MI5's, and that matters because the offences the alert cites turn on what a person knows or "ought reasonably to know". Everything below is as at the evening of 1 October 2026, BST.
What MI5 stated, who said it, and in what form
The format matters. This is not a speech or a statement by the Director General. It is a one-page PDF headed "Security Service Espionage Alert", linked from a news page on mi5.gov.uk with a published date of 30 September 2026. The PDF's own metadata gives a creation time of 23 September and a last-modified time of 29 September, 7 days and 1 day before publication (derived); metadata says when a file was saved, not when MI5 reached its assessment. Reuters, as relayed by The Next Web, called it the first Espionage Alert MI5 has published independently. I could not check that against an MI5 page. It follows MI5's alert about fake recruiters, announced on GOV.UK on 18 November 2025, and the Five Eyes bulletin of 3 June 2026 on China's use of professional networking sites. Both were about approaches to individuals online. This one is about money.
What the alert states and what it does not. The middle column is quoted from MI5, Security Service Espionage Alert, 30 September 2026 (one page), and the MI5 news page. The right column is absent from both.
| Topic | Stated by MI5 | Not stated |
|---|---|---|
| The funder | CGTRI, also "China Academy of General Technology (CAGT)". "Very strong ties" to the MSS. Its "primary purpose" is to fund academic research that "directly improves MSS technical capability for espionage". | Any evidence for the ties or the purpose. Who owns or runs CGTRI, where, how large. |
| The count | "More than 100 UK-linked academics" contributed to "projects funded by MSS via CGTRI". | What "UK-linked" means. How many projects or institutions. Over what dates. How MI5 counted. |
| The subjects | "Topics including" AI, cybersecurity, covert communications systems and steganography. | Which projects. Whether any output was sensitive or export-controlled. The list is open, and no quantum, semiconductor, biotechnology or defence work is named. |
| The harm | "This activity supports MSS espionage." Institutions should review so the MSS "derives no further benefit". | What any UK contribution gave the MSS, in what form, or what it changed. |
| The money | The research is in China and "funded by MSS via CGTRI". The academics "contributed". | Whether any UK institution or person was paid, by whom, or how much. |
| The people | "In some cases" academics "may not be aware". Many engaged "in good faith given CGTRI's obfuscated links". | Whether any academic knew. Any individual or institution by name. Any accusation against a person. |
| The law | National Security Act 2023, "particularly" section 3 and section 17. Take "independent legal advice". | Any prosecution, investigation or charging view. Whether CGTRI itself counts as a foreign intelligence service in the Act's terms. |
| The asks | Institutions: "immediately review any ongoing or planned collaboration with CGTRI". Academics: "establish the ultimate funding source" of collaborations with Chinese institutions. Use RCAT and Trusted Research. | A deadline, a reporting route, a list of related bodies or grant identifiers, or how to find a partner project's funder. |
| Other mechanisms | RCAT, NPSA Trusted Research, the National Security Act 2023. | ATAS, export controls, the Foreign Influence Registration Scheme, research-funder conditions, or NPSA's Think Before You Link. |
Drawn from the alert alone, the funding chain is asserted at both ends and silent in the middle. Every link is MI5's wording. Under each box is what the alert does not say.
Where the hedge sits: "may have helped" is not MI5's sentence
The phrase "may have helped" does not appear in the alert. The alert's one "may" is "academics may not be aware that CGTRI is funding the Chinese research project they are contributing to", which hedges what the academics knew. It states the harm flatly, and it asks institutions to act so the MSS "derives no further benefit", a phrase that presupposes some benefit already derived without saying what. So the certainty, the doubt and the silence are in different places from where the headline puts them:
- Certain, as MI5's assessment: CGTRI's ties and purpose, the count of more than 100, and that "this activity supports MSS espionage".
- Hedged: whether the academics knew who was paying, and "many" institutions and individuals having engaged "in good faith".
- Silent: what any UK contribution was, whether it reached the MSS, and whether anything changed as a result.
What the headline sentence can support is narrow. It supports: MI5 has published an assessment that a Chinese funder it links to the MSS paid for research projects that more than 100 UK-linked academics contributed to. It cannot support: that any identified academic's output improved any identified MSS capability, because the alert gives neither the output nor the capability. And it cannot support any suggestion that the academics acted knowingly, because MI5 says the opposite for many of them.
The press wordings that followed drift further. The Register's body text is closer to the alert than its headline: it says the projects were "allegedly funded". Others move the verbs.
The same count in five wordings. Wording from each outlet's own page or headline as read on 1 October 2026; the right column is the alert's text.
| Outlet and date | Wording | What the alert says instead |
|---|---|---|
| The Register, 1 Oct (headline) | Research "may have helped Chinese spies". | No sentence says UK research helped. It says the activity "supports MSS espionage". |
| Al Jazeera, 30 Sep (AFP and Reuters) | CGTRI "targeted more than 100 UK-based academics". | "Contributed", not targeted. "UK-linked", not UK-based. |
| Times Higher Education, 30 Sep | Academics "unknowingly contributed". | "In some cases" academics "may not be aware". |
| UPI, 30 Sep, citing The Guardian | Money to "at least 100 researchers", in return for access to the research. | "More than 100". No payment to academics and no exchange for access is stated. |
| Research Professional News, September 2026 (headline only; article not readable) | Academics "funded via Chinese spy agency". | The projects are funded by the MSS via CGTRI. No UK academic is said to have been funded. |
The legal hook: two offences, one fault standard, and no "good faith" defence in the text
The alert names section 3 and section 17 of the National Security Act 2023. Both came into force on 20 December 2023, 1,015 days before the alert (derived). The alert spells out only section 3(2), conduct "likely to materially assist" a foreign intelligence service in UK-related activities, plus knowing or "ought reasonably to know". Section 17 appears in it by title only, so The Register's description of section 17 comes from the Act, not from MI5.
Section 3 and section 17 of the National Security Act 2023 side by side. Source: legislation.gov.uk, latest revised text, both in force 20 December 2023 (SI 2023/1272).
| Feature | Section 3: assisting | Section 17: material benefit |
|---|---|---|
| Conduct | Conduct likely to materially assist a foreign intelligence service in UK-related activities (s.3(2)). The same with intent is s.3(1). | Obtains, accepts or retains a material benefit that is not an "excluded benefit" (s.17(1)). Agreeing to accept one is s.17(2). |
| Fault | Knows, or "having regard to other matters known to them ought reasonably to know". | The same words, about the benefit coming from a foreign intelligence service. |
| What counts | Providing, directly or indirectly, information, goods, services or financial benefits (s.3(3)). No need to identify the service (s.3(5)). | Financial benefits, anything with the potential to result in one, and information (s.17(3)). Direct or indirect, for example through companies (s.17(5)). |
| Maximum | 14 years or a fine (s.3(9)). | 14 years for s.17(1), 10 years for s.17(2) (s.17(10) and (11)). |
| Carve-outs | Defences in s.3(7): legal obligation, public functions, lawyers, agreements to which the UK is a party. | Excluded benefit: reasonable consideration for goods or services whose provision is not an offence (s.17(4)). Reasonable excuse for retaining (s.17(7)). Defences in s.17(8). |
Neither section lists "good faith" as a defence. Their fault element asks what the person knew or ought reasonably to have known, which is why the alert says MI5 "has placed the fact" of CGTRI's ties "in the public domain" and tells anyone "continuing to conduct research ultimately funded by CGTRI following publication" to take legal advice. My reading, and it is inference: from 30 September it will be hard for anyone continuing work on a CGTRI-funded project to say the ties were unknown. The alert says nothing about the position before that date beyond "good faith".
Three questions the alert leaves open. First, "foreign intelligence service" is defined in the Act as "any person whose functions include carrying out intelligence activities for or on behalf of a foreign power". The MSS, which MI5 describes as China's civilian intelligence and security service, fits that on its face. Whether CGTRI does, or whether its money is a benefit provided "by or on behalf of" the MSS, is not addressed. Second, section 17 needs a benefit received, and the alert does not say any UK party received one; but information counts as a material benefit, so even that is not a clean line. Third, no prosecution, investigation or charging view is cited.
The friendly-name fallacy: collaboration, research institute and open science do not say who pays
Five labels carry the weight in this story and none of them describes a control.
- "Research institute". The name tells a reader that research happens there. MI5 says its primary purpose is to fund research that improves the MSS's technical capability for espionage. The alert gives three forms of the name, CGTRI, China Academy of General Technology (CAGT) and 中国通用技术研究院, so a search for one string misses the other two.
- "Collaboration". Co-authorship, hosted visitors, shared data, joint grants and network accounts are all called collaboration. None of those records names the funder of the partner's project unless someone asks. NPSA's checklist itself speaks of informal as well as formal collaborations.
- "UK-linked". The alert uses it in one sentence and "UK academics" in the next, and defines neither. It could cover current staff, former staff, visitors or co-authors. The count of more than 100 cannot be audited without the definition.
- "Good faith". MI5 concedes it, for the past, for many. It describes a state of mind. It is not a control, and the two sections do not list it as a defence.
- "Academic freedom" and "open science". NPSA's checklist uses them in a question about the partner's country. They describe a policy environment. They cannot tell you who is paying for the project in front of you.
There is a second, quieter label: "due diligence". NPSA's guidance for academics says an internet search "can provide a lot of information about a partner, their relationship with a state or state military". MI5's explanation for why so many engaged in good faith is that CGTRI's links were "obfuscated". My inference: public-information checks on the partner, which is the method NPSA recommends, would not necessarily have found this link. The same shape, a feeling standing in for a control, showed up in the government's skills survey, where 57 per cent confidence is not capability. NPSA's June 2024 Countries and Conferences guide also already warns that China's 2017 National Intelligence Law allows its intelligence agencies to compel Chinese organisations and individuals to assist, which affects how much control you keep over anything shared. The structural risk was published. A named entity is new.
Where NPSA's own checklist stops short of the ask
The alert tells institutions to "make full use of" RCAT and NPSA's Trusted Research guidance. I read the collaboration checklist NPSA links from its Trusted Research page. It has 48 question marks across eight headed sections (derived; each sentence ending in a question mark counted). None asks who funds the partner's project or who funds the funder. The word "ultimate" appears once, in "Who is the ultimate beneficial owner of any IP resulting from the collaboration?", which is about ownership of outputs, not the source of money. The checklist's metadata dates it to January 2024, 2 years and 8 months before the alert (derived), and it says it "does not intend to be an exhaustive list".
The checklist's legal section names ATAS, export licences, the government end-user list, the 17 sensitive areas of the National Security and Investment Act, and sanctions. Those are controls on people who come to the UK, technology that leaves it, acquisitions and listed names. ATAS, for instance, covers certain foreign students and researchers who want to study or research in specific sensitive fields in the UK; on my reading, research done in China with UK contributors does not obviously engage it. None of the five asks who funds a partner's project, and the two that work from lists, the end-user list and sanctions, catch only names someone has already listed.
NPSA's evaluation framework does reach funders, at the "Intermediate" level of its three levels (Foundation, Intermediate, Developed). Due diligence "extend to research funders and sponsored positions", an institutional record holds "funding and funders for all research projects", and the risk group reviews "funding and philanthropy". At "Developed", due diligence includes complying with UKRI funding terms "particularly RGC 2.6.2". All three funder criteria sit at Intermediate, none at Foundation, and all three face inward: the funders of your own research and posts. The alert's ask faces outward, at the money behind a partner's project.
Capacity is the other half. RCAT's March 2026 update reports 19 staff, 13 of them advisers, over 155 research institutions engaged since March 2022, over 3,800 engagements and over 500 cases. Cumulatively that is at least 11.9 institutions per adviser (155 divided by 13; derived, and a history, not a caseload). Its five most common advice topics were export control, specific queries, other, governance and policies, and the National Security and Investment Act. Neither funder tracing nor the National Security Act is a named topic, though "specific queries" and "other" could hold anything. RCAT describes itself as "not an enforcement body" and says contact goes through an institution's nominated point of contact. The alert asks institutions to review any collaboration with CGTRI "immediately", and academics to establish the funder behind any collaboration with a Chinese institution, which is a far wider task. No source I read says how many collaborations that covers or how RCAT will triage.
Who has answered, and what rests on press reports
China. The embassy spokesperson's reply is dated 30 September, 18:23 on the page. It calls the accusations "imaginary and purely fabricated", says the embassy has lodged "solemn representations", and says university exchanges "have always been conducted on a voluntary basis and in compliance with laws and regulations". In three short paragraphs it does not say whether CGTRI funds academic research or has ties to the MSS; it refers to "the relevant Chinese entity". That is a denial of the accusation, not an answer to the specifics. MI5 and the embassy are both parties, and neither has published evidence.
UK ministers, as reported. Times Higher Education and AFP and Reuters (via Al Jazeera) report that Security Minister Dan Jarvis wrote to all university vice-chancellors; THE says urging them to "end all arrangements" with CGTRI, and Al Jazeera says to ensure staff ended any relationship. THE also quotes science and innovation minister Chris McDonald on protecting the research base. I found no GOV.UK page, letter or parliamentary statement for these as at the evening of 1 October, so the wording rests on press reports. The difference is worth noting: the alert asks institutions to "review", while the reported letter asks them to end. Institutions will have to reconcile the two.
Universities. Universities UK told the BBC it was reviewing the alert, according to The Next Web, and its chief executive said the sector had invested in due diligence, risk assessment and research security, according to UPI. Named institutions. MI5 names none. One campaign group has published its own list of institutions it says should assess their exposure on 30 September. That list is not MI5's or the government's, I have not verified it, and this briefing does not repeat it.
What a UK research office can do, in order
The order matters: find what you have, fix the question you ask, then control access and report. Items marked "my step" are mine, derived from what the alert and NPSA leave out. The rest follow the alert or NPSA's published guidance.
Take this with you
Ordered actions for a UK research office
- Name one owner for the alert today and date-stamp the start of the review. The alert is dated 30 September 2026. A record of when you read it and what you did next is the evidence you will want if the fault standard is ever tested (my step).
- Search every award, contract, memorandum of understanding, sponsored position, visiting-researcher and data-sharing record, and the funding acknowledgements on co-authored outputs, for all three forms the alert gives: CGTRI, China Academy of General Technology (CAGT) and 中国通用技术研究院. A search for one form misses the others (my step).
- For each hit, write down what the UK side actually did: money received, people hosted, data or code shared, network or lab access, co-authorship. The alert does not say which of these happened, and the two offences it cites turn on different conduct (my step).
- Take independent legal advice before continuing any work ultimately funded by CGTRI, as the alert says, and pause new commitments while you do. Do not leave that decision to the research office alone. Pausing is my addition.
- For every active collaboration with a Chinese institution, ask the partner in writing who funds the project and who funds that funder. Record the answer in a central register of funding and funders (NPSA evaluation framework, Recording). Ask again at each renewal and whenever a partner joins part way through. Treat "not known" as a reason to escalate (my step, adding the question NPSA's checklist lacks).
- Run NPSA's full collaboration checklist on each active China-linked collaboration, escalate according to your risk appetite, and take complex cases to RCAT through your institution's nominated point of contact.
- List which partners hold network accounts, shared-workspace or data access, and cut each to what there is a valid requirement for (NPSA guidance for academics). Monitor for unusual access.
- For staff visiting or hosting Chinese partners, issue NPSA's Countries and Conferences advice: carry only the data a trip needs, encrypt devices, never leave them unattended, and report unusual approaches to the university.
- Check what your funders' terms require before you change a partner. For UKRI awards, read UKRI's Trusted Research and Innovation principles, which UKRI's funding pages say set expectations for due diligence on international collaboration, and the grant conditions it cites (RGC 2.6.2, 2.7.1, 2.7.2). For other funders, check notification clauses.
- Tell academics what the alert says and does not say: it does not accuse every academic, it says many engaged in good faith, and it asks them to establish the ultimate funding source. Give them one internal contact.
- Know the reporting routes. RCAT is the first point of contact for institutions. MI5's contact page lists "I would like to report a national security concern" and a contact form for non-urgent matters, and warns messages are not monitored live. For an imminent threat call 999 or the Anti Terrorist Hotline on 0800 789 321. The alert gives no reporting route of its own, and I could not read an NPSA reporting page.
What this list does not do is settle whether any particular project is within the alert. That depends on facts MI5 has not published: which projects, which people, what was exchanged.
The question that exposes the gap
If MI5 names the next funder on a Thursday, which record in your institution tells you by Friday whether anyone has already worked on a project it pays for, and who is responsible for knowing?
Key facts
Sources
- PrimaryNews page for the Espionage Alert on CGTRI, published date 30 September 2026, read in full: the summary, the three asks, the link to Trusted Research guidanceMI5, the Security Serviceaccessed 2026-10-01
- PrimarySecurity Service Espionage Alert, China General Technology Research Institute (CGTRI), one page, read in full: every claim, the expected actions and the criminal consequences sectionMI5, the Security Serviceaccessed 2026-10-01
- PrimaryNational Security Act 2023 section 3, Assisting a foreign intelligence service, read in full: the fault standard, what counts as assistance, defences, penalty, commencement 20 December 2023legislation.gov.ukaccessed 2026-10-01
- PrimaryNational Security Act 2023 section 17, Obtaining etc material benefits from a foreign intelligence service, read in full: benefit, excluded benefit, direct and indirect provision, penalties, defenceslegislation.gov.ukaccessed 2026-10-01
- PrimaryTrusted Research landing page, read in a browser: the guidance set, the downloadable checklist and evaluation framework, and NPSA's UK to China collaboration growth figuresNational Protective Security Authority (NPSA)accessed 2026-10-01
- PrimaryImplementation, collaboration checklist (PDF, file metadata January 2024), read in full: all eight sections, used for the question count and the funding questionsNPSA and NCSCaccessed 2026-10-01
- PrimaryTrusted Research Evaluation Framework (PDF, file metadata January 2024), read in full: the due diligence, recording and institutional risk appetite criteria that mention fundersNPSA and NCSCaccessed 2026-10-01
- PrimaryTrusted Research Guidance for Academics (PDF, July 2024 file), read in full: partner due diligence, access control, legal frameworks and further informationNPSA and NCSCaccessed 2026-10-01
- PrimaryTrusted Research, Countries and Conferences (PDF, June 2024), read in full: travel, device and jurisdiction advice, including its statement on China's National Intelligence LawNPSA and NCSCaccessed 2026-10-01
- PrimaryAbout the Research Collaboration Advice Team: its role, that it is not an enforcement body, and how institutions contact itDepartment for Science, Innovation and Technology (RCAT)accessed 2026-10-01
- PrimaryRCAT 2026 update, 20 March 2026, read in full: staff, institutions engaged, engagements, cases and the most common advice topicsResearch Collaboration Advice Team (GOV.UK)accessed 2026-10-01
- PrimaryEmbassy Spokesperson on the So-called Espionage Alert Issued by UK Intelligence Agency, dated 30 September 2026 on the page: the Chinese side's reply, read in full (English page, checked against the Chinese page)Embassy of the People's Republic of China in the United Kingdomaccessed 2026-10-01
- PrimaryContact page, read in a browser: the national security concern route, the contact form and the warning that messages are not monitored liveMI5, the Security Serviceaccessed 2026-10-01
- PrimaryFive Eyes Joint Bulletin, Safeguarding Our Secrets, news page dated 3 June 2026, used only to place this alert beside MI5's earlier warning about online approachesMI5, the Security Serviceaccessed 2026-10-01
- PrimaryAction to disrupt and deter threats to UK as MI5 issues spy alert, 18 November 2025, used only to date MI5's earlier alert about fake recruitersCabinet Office and Home Office (GOV.UK)accessed 2026-10-01
- PrimaryEPSRC funding opportunity page, last updated 2 June 2026, used for UKRI's wording on Trusted Research and Innovation principles and grant conditions RGC 2.6.2, 2.7.1 and 2.7.2UK Research and Innovationaccessed 2026-10-01
- PrimaryAcademic Technology Approval Scheme guidance, last updated 24 March 2026, used for what ATAS coversForeign, Commonwealth and Development Office (GOV.UK)accessed 2026-10-01
- Reported byMI5 warns UK academics their research may have helped Chinese spies, 1 October 2026: the news pointer, read in full, and the headline whose hedge this briefing examinesThe Registeraccessed 2026-10-01
- Reported byMI5 issues China espionage warning to UK universities, 30 September 2026: reported ministerial statements and the wording compared in the briefingTimes Higher Educationaccessed 2026-10-01
- Reported byMI5 warns UK academics to cut ties with Chinese group over alleged spying, 30 September 2026: the wording compared and the Security Minister's statement as reportedAl Jazeera, from AFP and Reutersaccessed 2026-10-01
- Reported byMI5: Group funded British research, gave it to China's government, 30 September 2026: the wording compared and Universities UK's reported responseUPIaccessed 2026-10-01
- Reported byChina rejects MI5 espionage alert, 1 October 2026: relays Reuters on the alert being MI5's first independently published one and the BBC on Universities UKThe Next Webaccessed 2026-10-01


