Legal development

Beyond Academia?  Implications of MI5’s First Espionage Alert for Businesses

    Summary

    The National Security Act 2023 (the Act) introduced a range of offences aimed at countering threats from foreign states, including offences relating to assisting a foreign intelligence service (FIS) and obtaining a material benefit from a FIS. On 30 September 2026, the UK Security Service (MI5) published its first Security Service Espionage Alert (the Alert) concerning the China General Technology Research Institute (CGTRI), sometimes translated as the China Academy of General Technology.   

    The Alert is targeted at universities and academics and states that CGTRI has "very strong ties" to the Chinese Ministry of State Security (the MSS), a FIS. However, it expressly draws attention to offences under the Act that apply to any person, not only academia. This article summarises the Alert and considers its implications for academia and businesses. In short:

    • The Alert puts CGTRI's links to MSS "in the public domain."  This affects what persons "ought reasonably to know" for the purposes of offences under the Act.
    • Academic institutions with any CGTRI connection should immediately review their exposure and consider enhancing their due diligence procedures in response to the Alert. 
    • Although the Alert is targeted at academia, businesses with exposure to CGTRI should consider their potential risks under the Act.  They may wish to monitor how FIS-related risks develop alongside established sanctions and export control frameworks.

    Overview of the Alert

    The Alert states that CGTRI has “very strong ties” to the MSS, and its “primary purpose” is "to fund academic research that directly improves MSS technical capability for espionage".  It further provides that 100 UK-linked academics have contributed to CGTRI-funded projects, including those concerning artificial intelligence, cybersecurity, covert communications systems and steganography.  MI5 states that many institutions and individuals will have engaged with CGTRI “in good faith given CGTRI’s obfuscated links to MSS”, and some may not have been aware that CGTRI was the source of funding.

    The Alert sets out certain “expected actions” for the academic sector. The Alert advises:

    • institutions to “immediately review any ongoing or planned collaboration with CGTRI” to ensure that CGTRI derives no benefit from UK universities or research institutions;
    • academics to “establish the ultimate funding source when conducting any research collaboration with Chinese institutions” to rule out CGTRI's involvement; and
    • institutions to make full use of the Research Collaboration Advice Team and the National Protective Security Authority (NPSA) Trusted Research guidance, and consider independent legal advice.

    MI5 states that, through the Alert, it has placed CGTRI's "very strong ties to MSS in the public domain", and that any academic institution or individual continuing research ultimately funded by CGTRI should take independent legal advice, in particular in relation to sections 3 and 17 of the Act. These are discussed in the next section. 

    Relevant Offences

    The Alert draws specific attention to offences under the Act that criminalise a broad spectrum of interactions with a "foreign intelligence service" (FIS)—a term the Act defines as any "person whose functions include carrying out intelligence activities for or on behalf of a foreign power."

    Section 3

    Under section 3, a person commits an offence where the person:

    • engages in any conduct with the intention that it will materially assist a FIS in carrying out UK-related activities (section 3(1)); or
    • engages in conduct that is likely to materially assist a FIS in carrying out UK-related activities, where the person knows—or having regard to other matters known to them, ought reasonably to know—that their conduct is likely to have that effect (section 3(2)).

    Under the Act, a person "may be likely to materially assist" a FIS if they directly or indirectly "provid[e], or provid[e] access to, information, goods, services, or financial benefits."

    The Explanatory Notes to the Act show that ostensibly trivial forms of assistance may be in scope, for example, providing IT services or ready access to cash.1 As the Independent Reviewer of State Threats Legislation (the Independent Reviewer) has observed in relation to the offence in section 3(2), this "overbreadth is aggravated by the lesser mental element based on constructive knowledge (reasonably ought to know) which is capable of sweeping up the naïve and ignorant."2

    The maximum penalty is 14 years’ imprisonment or a fine. Limited defences may apply, including for lawyers carrying on legal activity, conduct required by UK public-law obligations, or conduct in accordance with arrangements to which the UK is a party.

    Section 17

    Under section 17, a person commits an offence if the person obtains, retains, accepts, or agrees to accept a material benefit where they know—or having regard to other matters known to them, ought reasonably to know—that the benefit is or was provided by or on behalf of a FIS.  As the Independent Reviewer has noted, section 17 is focused on "precursor conduct". It allows law enforcement to take action against a person who has received funds from a FIS, without needing to prove that they actually provided any material assistance.3

    A material benefit may include any financial benefit, anything that has the potential to result in a financial benefit, or information. However, a material benefit is excluded from the offence if it represents reasonable consideration for lawful goods or services.

    The maximum penalty is between 10 and 14 years' imprisonment, or a fine.  As with section 3, certain limited defences may apply.

    Compliance Considerations

    Academic and research institutions

    For these institutions, the Alert is an immediate call for action. This was underscored by the Security Minister, Dan Jarvis, who wrote to universities "to ensure they support their staff to end all arrangements with this company, preventing further benefit to the Chinese intelligence services and ensuring compliance with" the Act.4

    Institutions should promptly review any existing or planned arrangements with CGTRI to ensure compliance with the Act.

    Beyond that, institutions should also consider enhancing their compliance processes to address the risks highlighted by the Alert.  Depending on the level of their risk exposure under the Act and the Alert, these could include:

    • Updating internal risk assessments and compliance policies and procedures relating to national security and related risks (e.g., sanctions and export controls) in view of the Alert;
    • Raising awareness among relevant academic staff (e.g., through training or otherwise) concerning dealings with CGTRI;
    • Implementing due diligence procedures, including when collaborating with Chinese institutions, to:
      • confirm and document the owners and controllers of the institution, the (ultimate) end-users of research output, and providers of any funding, and 
      • assess any potential connections of such parties to CGTRI or a FIS, including based on publicly available information; and
    • Incorporating robust provisions in future collaboration agreements to ensure they may suspend or terminate these arrangements to mitigate their risks under the Act.

    Risk-based due diligence is particularly important given the constructive knowledge standard in both offences: a person may be liable for what a reasonable person would have known under similar circumstances.

    Businesses

    The Alert is directly targeted at academia. However, the private sector should also pay attention. The offences under the Act apply to all persons and, following the enactment of the Crime and Policing Act 2026, a business organisation can be held criminally liable if a criminal offence is committed by its "senior manager". In that regard, commercial dealings or transactions, in principle, may meet the thresholds for material assistance or material benefit under the Act. Finally, as the Alert puts it, MI5 has now placed CGTRI's "very strong ties to MSS in the public domain".  This is likely to colour what a business ought reasonably to know when engaging in dealings with CGTRI.

    The Alert is not a sanctions designation (so does not impose an asset freeze on CGTRI).  Nevertheless, businesses that have dealings with CGTRI should promptly consider their risk exposure under the Act and take appropriate measures.

    More broadly, businesses that develop emerging technologies or operate in sensitive industries from a national security perspective should consider their potential exposure under the Act.  The NPSA has published various guidance urging business leaders to integrate national security considerations—including state threats risks—into their security and due diligence frameworks.5 As appropriate, businesses may wish to review their existing compliance and due diligence processes (e.g., in relation to third parties, sanctions and export control) to incorporate FIS-related risks.

    The UK’s approach to countering foreign state threats relies on a suite of laws and, in response to these threats, is evolving beyond the traditional toolkit of sanctions, export controls, and foreign direct investment screening which businesses are typically accustomed to navigating.  The Act introduced, among other things, the Foreign Influence Registration Scheme and the above-mentioned offences targeted at a broad range of dealings involving FISs. The designation of the Islamic Revolutionary Guard Corps, the Islamic Movement of Companions of the Right, and Russia’s GRU Volunteer Corps as state threats in July 2026 underscored this continued development.  Over time, national security considerations may become a more routine part of corporate compliance.


    1. Explanatory Notes to the National Security Act 2023, para 84.
    2. Independent Reviewer of State Threats Legislation, Report of the Independent Reviewer of State Threats Legislation on the Operation of Parts 1 and 2 of the National Security Act 2023 and Schedule 3 to the Counter-Terrorism and Border Security Act 2019 (December 2025) (the Independent Reviewer's Report), para 3.56.
    3. Independent Reviewer's Report, para 3.64.
    4. Mike Taylor, 'MI5 issues rare Chinese spy warning to UK universities' The Independent (30 September 2026) <https://www.independent.co.uk/news/uk/home-news/spy-alert-mi5-chinese-intelligence-uk-universities-b3059051.html> accessed 4 October 2026.
    5. See, for example, NPSA, 'Secure Business: Considering Risks' (25 February 2023) <https://www.npsa.gov.uk/specialised-guidance/secure-business/considering-risks> accessed 5 October 2026 and NPSA, 'Company Guidance: Secure Innovation' (24 August 2026) <https://www.npsa.gov.uk/specialised-guidance/secure-innovation/company-guidance> accessed 5 October 2026.

    Author: Andris Ivanovs, Partner.

    The information provided is not intended to be a comprehensive review of all developments in the law and practice, or to cover all aspects of those referred to.
    Readers should take legal advice before applying it to specific issues or transactions.