Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

UFIT and Australia’s Guidelines to Counter Foreign Interference in the University Sector

UFIT is the joint Australian government-university taskforce (established Aug 2019) behind the Guidelines to Counter Foreign Interference in the Australian University Sector — a co-designed, principles-based research-security framework, distinct from the UK’s Trusted Research guidance and the US’s agency-enforced NSPM-33 regime.

The University Foreign Interference Taskforce (UFIT) is the joint Australian government-university body that produced the Guidelines to Counter Foreign Interference in the Australian University Sector — the framework most Australian universities now use to structure their research-security and foreign-interference risk management. Because it was built jointly by government agencies and the university sector rather than issued unilaterally by government, UFIT’s model is frequently cited internationally as a distinct approach alongside the UK’s Trusted Research guidance and the disclosure-and-certification regime under the US’s NSPM-33. This guide covers what UFIT is, how the Guidelines are structured, and how Australia’s co-designed approach compares to more purely government-run research-security models elsewhere.

What is the University Foreign Interference Taskforce (UFIT)?

UFIT was established on 28 August 2019 to strengthen protections for Australian universities against foreign interference. It brings together the Australian university sector and relevant Australian Government agencies — led jointly by the Department of Education and the Department of Home Affairs — into a single collaborative body, rather than having government issue guidance to universities from outside. The Taskforce’s own stated aim is to build an environment of trust and resilience across the sector while explicitly upholding the value of international research collaboration and academic freedom, not treating them as opposed goals.

UFIT sits within a broader Australian Government countering-foreign-interference program administered through Home Affairs, but its specific output — the Guidelines — was developed with universities, not simply for them, which is the structural feature most commonly noted when other countries or institutions reference the Australian model.

The Guidelines to Counter Foreign Interference in the Australian University Sector

UFIT released the first edition of the Guidelines to Counter Foreign Interference in the Australian University Sector in November 2019. A revised edition was released in November 2021, refreshed to reflect developments in the risk environment and lessons from the Guidelines’ initial implementation across the sector. Both editions are published by the Department of Education and remain the reference document universities are expected to work from.

The Guidelines are not a regulatory instrument with independent penalties attached; they function as a sector-wide risk-management framework that universities are expected to integrate into their own existing governance, policy, and risk structures rather than adopt as a bolt-on compliance exercise. The Department of Education frames them as intended to be enduring, specific, and measurable, while remaining adaptable as the foreign-interference risk picture evolves.

The five key principles

The Guidelines are organised around five key principles that universities are expected to apply when assessing and managing foreign-interference risk:

  • Security must safeguard academic freedom, values, and research collaboration — risk mitigation is framed as protecting, not restricting, the sector’s core mission.
  • Research, collaboration, and education activities are mindful of the national interest — decision-makers are expected to weigh national-interest considerations alongside academic and commercial ones.
  • Security is a collaborative responsibility with individual accountability — resilience is treated as a shared obligation across the institution, not solely a compliance-office function, while specific individuals remain accountable for specific decisions.
  • Security should be proportionate to organisational risk — the level of scrutiny and mitigation applied should scale with the actual assessed risk of a given activity, partner, or area of research, not be applied uniformly.
  • The safety of the university community is paramount — protecting staff and students, including from harassment or covert pressure connected to foreign interference, is treated as a first-order concern alongside institutional and research-security risk.

How universities are expected to apply the Guidelines

Rather than prescribing a single mandatory checklist, the Guidelines are designed for universities to build on risk-management policies and security practices they already have, and to help decision-makers assess and mitigate foreign-interference risk within existing frameworks. In practice, Australian universities have used the Guidelines to structure due-diligence processes for international partnerships and collaboration agreements, staff training and awareness activity, escalation pathways for activities assessed as higher risk, and closer engagement with government on cyber security matters — including participating in sector briefings convened by the Australian Cyber Security Centre and considering joint incident-management arrangements with other institutions. Staff involved in establishing international collaborations are generally expected to perform due diligence on a proposed activity or partner and escalate before a project begins where a heightened risk of foreign interference is identified.

Most individual Australian universities have translated the Guidelines into their own internal foreign-interference or national-security-compliance policies, committees, and reporting lines, since the national document is deliberately principles-based rather than a detailed operating procedure.

UFIT’s joint government-university structure, compared internationally

UFIT’s defining structural feature — a standing taskforce that includes both government agencies and university-sector representation, co-producing the guidance rather than government producing it alone — sets it apart from some other national approaches in the same policy space, and is a large part of why the Australian model gets referenced internationally:

  • Australia (UFIT): a joint government-university taskforce, government agencies (led by Education and Home Affairs) plus the sector working together, producing a shared, principles-based framework that individual universities then implement through their own policies.
  • United Kingdom (Trusted Research): guidance developed by the National Protective Security Authority (formerly the Centre for the Protection of National Infrastructure) together with UK Research and Innovation, aimed at researchers and international-partnership staff, oriented more toward awareness-raising and specific due-diligence guidance for individual collaborations than a standing joint operational body. See CASRAI’s Trusted Research framework (UK) entry.
  • United States (NSPM-33): a presidential national-security-policy memorandum implemented through individual federal funding agencies (NSF, NIH, DOE, and others), imposing disclosure, certification, and research-security-program requirements directly on institutions and covered individuals as a condition of federal funding — a government-mandated compliance regime tied to award terms, rather than a jointly co-designed sector framework. See CASRAI’s guide to NSPM-33’s four mandated research security program elements.

The practical difference matters for research administrators benchmarking their institution’s approach: NSPM-33’s mechanics are enforced through funding-agency disclosure and certification requirements with concrete compliance deadlines, whereas the UFIT Guidelines operate more as a shared sector reference point that universities translate into their own binding internal policy — there is no equivalent federal funding-conditionality lever built directly into the national Guidelines document itself. Institutions collaborating across jurisdictions — for example, an Australian university partnering with a US-funded research program, or a UK institution with an Australian one — may need to reconcile a principles-based sector framework against a funding-agency compliance regime with harder deadlines and certifications, rather than assume the two operate the same way.

Why this matters for research administrators outside Australia

Even outside Australia, the UFIT Guidelines are frequently referenced as an early, influential model in the broader development of national research-security frameworks, in part because of the co-design approach and in part because Australia moved relatively early (2019) relative to comparable frameworks in other countries. Research offices assessing international collaborations, due-diligence processes for foreign partnerships, or how to structure a joint government-institution advisory body may find the Guidelines’ five-principles structure — and its explicit framing of security as protecting rather than restricting academic collaboration — a useful reference point regardless of jurisdiction.

Frequently asked questions

When was UFIT established?

UFIT was established on 28 August 2019.

Is UFIT a government body or a university body?

Neither exclusively — it is a joint taskforce bringing together Australian Government agencies (led by the Department of Education and the Department of Home Affairs) and the university sector to collaboratively develop guidance and build sector resilience.

When were the Guidelines released and revised?

The first edition of the Guidelines to Counter Foreign Interference in the Australian University Sector was released in November 2019. A revised edition was released in November 2021.

Are the Guidelines legally binding?

The Guidelines themselves are a sector-wide risk-management framework rather than a standalone regulatory instrument with independent penalties. Universities are expected to integrate them into their own governance and policy structures; separate Australian laws (such as foreign-arrangements and national-security legislation) impose their own distinct legal obligations on universities.

How does UFIT’s approach differ from the US NSPM-33 regime?

NSPM-33 is implemented through individual federal funding agencies as disclosure, certification, and research-security-program conditions attached to federal awards. UFIT’s Guidelines are a jointly developed, principles-based sector framework without an equivalent funding-conditionality mechanism built into the national document itself; individual Australian universities translate the Guidelines into their own binding internal policy.

Sources

Australian Government Department of Education, University Foreign Interference Taskforce and Guidelines to Counter Foreign Interference in the Australian University Sector pages (education.gov.au/countering-foreign-interference-australian-university-sector); Department of Education, Refreshed Guidelines to counter foreign interference in the Australian university sector released (November 2021 announcement); Australian Government Department of Home Affairs, Universities and countering foreign interference (homeaffairs.gov.au).

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →