Beyond Academia? Implications of MI5’s First Espionage Alert for Businesses
The National Security Act 2023 (the Act) introduced a range of offences aimed at countering threats from foreign states, including offences relating to assisting a foreign intelligence service (FIS) and obtaining a material benefit from a FIS. On 30 September 2026, the UK Security Service (MI5) published its first Security Service Espionage Alert (the Alert) concerning the China General Technology Research Institute (CGTRI), sometimes translated as the China Academy of General Technology.
The Alert is targeted at universities and academics and states that CGTRI has "very strong ties" to the Chinese Ministry of State Security (the MSS), a FIS. However, it expressly draws attention to offences under the Act that apply to any person, not only academia. This article summarises the Alert and considers its implications for academia and businesses. In short:
The Alert states that CGTRI has “very strong ties” to the MSS, and its “primary purpose” is "to fund academic research that directly improves MSS technical capability for espionage". It further provides that 100 UK-linked academics have contributed to CGTRI-funded projects, including those concerning artificial intelligence, cybersecurity, covert communications systems and steganography. MI5 states that many institutions and individuals will have engaged with CGTRI “in good faith given CGTRI’s obfuscated links to MSS”, and some may not have been aware that CGTRI was the source of funding.
The Alert sets out certain “expected actions” for the academic sector. The Alert advises:
MI5 states that, through the Alert, it has placed CGTRI's "very strong ties to MSS in the public domain", and that any academic institution or individual continuing research ultimately funded by CGTRI should take independent legal advice, in particular in relation to sections 3 and 17 of the Act. These are discussed in the next section.
The Alert draws specific attention to offences under the Act that criminalise a broad spectrum of interactions with a "foreign intelligence service" (FIS)—a term the Act defines as any "person whose functions include carrying out intelligence activities for or on behalf of a foreign power."
Under section 3, a person commits an offence where the person:
Under the Act, a person "may be likely to materially assist" a FIS if they directly or indirectly "provid[e], or provid[e] access to, information, goods, services, or financial benefits."
The Explanatory Notes to the Act show that ostensibly trivial forms of assistance may be in scope, for example, providing IT services or ready access to cash.1 As the Independent Reviewer of State Threats Legislation (the Independent Reviewer) has observed in relation to the offence in section 3(2), this "overbreadth is aggravated by the lesser mental element based on constructive knowledge (reasonably ought to know) which is capable of sweeping up the naïve and ignorant."2
The maximum penalty is 14 years’ imprisonment or a fine. Limited defences may apply, including for lawyers carrying on legal activity, conduct required by UK public-law obligations, or conduct in accordance with arrangements to which the UK is a party.
Under section 17, a person commits an offence if the person obtains, retains, accepts, or agrees to accept a material benefit where they know—or having regard to other matters known to them, ought reasonably to know—that the benefit is or was provided by or on behalf of a FIS. As the Independent Reviewer has noted, section 17 is focused on "precursor conduct". It allows law enforcement to take action against a person who has received funds from a FIS, without needing to prove that they actually provided any material assistance.3
A material benefit may include any financial benefit, anything that has the potential to result in a financial benefit, or information. However, a material benefit is excluded from the offence if it represents reasonable consideration for lawful goods or services.
The maximum penalty is between 10 and 14 years' imprisonment, or a fine. As with section 3, certain limited defences may apply.
For these institutions, the Alert is an immediate call for action. This was underscored by the Security Minister, Dan Jarvis, who wrote to universities "to ensure they support their staff to end all arrangements with this company, preventing further benefit to the Chinese intelligence services and ensuring compliance with" the Act.4
Institutions should promptly review any existing or planned arrangements with CGTRI to ensure compliance with the Act.
Beyond that, institutions should also consider enhancing their compliance processes to address the risks highlighted by the Alert. Depending on the level of their risk exposure under the Act and the Alert, these could include:
Risk-based due diligence is particularly important given the constructive knowledge standard in both offences: a person may be liable for what a reasonable person would have known under similar circumstances.
The Alert is directly targeted at academia. However, the private sector should also pay attention. The offences under the Act apply to all persons and, following the enactment of the Crime and Policing Act 2026, a business organisation can be held criminally liable if a criminal offence is committed by its "senior manager". In that regard, commercial dealings or transactions, in principle, may meet the thresholds for material assistance or material benefit under the Act. Finally, as the Alert puts it, MI5 has now placed CGTRI's "very strong ties to MSS in the public domain". This is likely to colour what a business ought reasonably to know when engaging in dealings with CGTRI.
The Alert is not a sanctions designation (so does not impose an asset freeze on CGTRI). Nevertheless, businesses that have dealings with CGTRI should promptly consider their risk exposure under the Act and take appropriate measures.
More broadly, businesses that develop emerging technologies or operate in sensitive industries from a national security perspective should consider their potential exposure under the Act. The NPSA has published various guidance urging business leaders to integrate national security considerations—including state threats risks—into their security and due diligence frameworks.5 As appropriate, businesses may wish to review their existing compliance and due diligence processes (e.g., in relation to third parties, sanctions and export control) to incorporate FIS-related risks.
The UK’s approach to countering foreign state threats relies on a suite of laws and, in response to these threats, is evolving beyond the traditional toolkit of sanctions, export controls, and foreign direct investment screening which businesses are typically accustomed to navigating. The Act introduced, among other things, the Foreign Influence Registration Scheme and the above-mentioned offences targeted at a broad range of dealings involving FISs. The designation of the Islamic Revolutionary Guard Corps, the Islamic Movement of Companions of the Right, and Russia’s GRU Volunteer Corps as state threats in July 2026 underscored this continued development. Over time, national security considerations may become a more routine part of corporate compliance.
Author: Andris Ivanovs, Partner.
The information provided is not intended to be a comprehensive review of all developments in the law and practice, or to cover all aspects of those referred to.
Readers should take legal advice before applying it to specific issues or transactions.