Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

US-China Research Collaboration: Research Security and Compliance Concerns

US-China research collaboration compliance spans four overlapping regimes — undisclosed foreign talent programs, export control, federal/statutory disclosure requirements, and CFIUS investment screening. This guide orients institutions to how they fit together.

US-China research collaboration sits at the intersection of several distinct compliance regimes, not a single “China rule.” An institution assessing risk in a specific collaboration — a joint publication, a visiting-scholar appointment, a subaward to a Chinese institution, a material transfer, a licensing deal with a China-based company — typically has to work through undisclosed foreign talent program restrictions, export control law, federal funder disclosure requirements, and in some cases foreign-investment screening, simultaneously and separately. This page is an orientation to how those pieces fit together. For the mechanics of any one piece in depth, see the linked guides and dictionary terms below rather than treating this as the complete rulebook for any single requirement.

Why This Became a Compliance Priority

Federal concern about undisclosed foreign ties in US research grew through the 2010s and became acute compliance priority after 2018, when the Department of Justice launched the “China Initiative,” a prosecutorial program aimed at economic espionage and research-integrity violations connected to China. The initiative drew sustained criticism — several prosecutions ended in acquittal or dismissal, and critics argued it disproportionately targeted researchers of Chinese descent for what were, in a number of cases, disclosure paperwork failures rather than espionage. DOJ ended the China Initiative by name in February 2022.

What replaced it was not a retreat from the underlying concern but a shift in legal footing: from individual criminal prosecution toward statutory disclosure requirements, civil False Claims Act enforcement, and institutional research-security program mandates. The Foreign talent recruitment programme concept and the disclosure infrastructure built around it (see below) are the direct legal descendants of that shift. Two real, publicly reported settlements illustrate the civil-enforcement direction this has taken: Stanford University paid $1.9 million in October 2023 to resolve allegations that PIs with Fudan University and National Natural Science Foundation of China ties omitted required foreign current-and-pending support disclosures across 16 federal proposals, and Cleveland Clinic Foundation paid $7.6 million in May 2024 (including $3.8 million in restitution) over a PI’s undisclosed foreign “other support” across three NIH grants. Both were False Claims Act settlements over a disclosure failure, not findings of espionage — a useful illustration that the operative legal risk for most institutions today is a compliance failure, not the underlying collaboration itself.

The Four Overlapping Risk Areas

1. Undisclosed Foreign Talent Programs

The Malign Foreign Talent Recruitment Program (MFTRP) prohibition, codified at 42 U.S.C. section 19237(4) by the CHIPS and Science Act of 2022, defines a specific category of arrangement: compensation from a foreign country of concern (China among them) to a targeted individual in exchange for unauthorized transfer of US-owned IP, data, or materials, with disqualifying features such as a required foreign “shadow lab,” an inability to terminate the arrangement, or duplication with an existing federal award. Not every foreign appointment or collaboration is an MFTRP — the statute explicitly protects ordinary scholarly publication, presentation, and open reciprocal exchange. Since 20 May 2024, federal awardees have been barred from MFTRP participation, and NSF’s Important Notice No. 149 (effective 2 December 2025) layers pre-award and annual post-award certification on top of that prohibition. See Malign Foreign Talent Recruitment Program (MFTRP): Definition, Disclosure, and Consequences for the full statutory definition, certification mechanics, and consequences of noncompliance.

2. Export Control (EAR/ITAR and Deemed Exports)

Independent of talent-program status, sharing controlled technology, software, or technical data with a foreign national — including a Chinese national working inside a US lab — can itself require a license under the Export Administration Regulations (EAR, 15 CFR Parts 730-774, US Department of Commerce) or the International Traffic in Arms Regulations (ITAR, 22 CFR Parts 120-130, US Department of State). This applies to deemed exports (release of controlled technology to a foreign person physically present in the US) as readily as to a literal shipment abroad, and it is determined by the substance of what is shared, not by whether money changes hands. See Export Control (EAR/ITAR) and International Research Collaboration and Export Control Reform and Research Security for how classification and licensing actually work, and Export-controlled research and Software export controls for the underlying definitions.

3. Federal Funder and Statutory Disclosure Requirements

Both NIH and NSF require disclosure of all foreign and domestic research support, affiliations, and in-kind resources through Biographical Sketch and Current and Pending (Other) Support forms built on the NSPM-33 Common Form architecture — the framework behind the Stanford and Cleveland Clinic settlements above. NSF’s Important Notice No. 149 adds a Foreign Financial Disclosure Reporting requirement for gifts or contracts of $50,000 or more from a “country of concern” (China, North Korea, Russia, Iran, or others so designated), and bars NSF funding to institutions maintaining a Confucius Institute contract, subject to a waiver process. Separately, Section 117 of the Higher Education Act (20 U.S.C. section 1011f) requires any institution to report to the Department of Education, twice yearly, any gift from or contract with a foreign source — China-based sources included — once the cumulative value reaches $250,000 in a calendar year. See Section 117 Foreign Gift and Contract Reporting, Foreign component disclosure, and, for the subaward-specific mechanics that often carry China-collaboration risk, NIH Foreign Subawards: Requirements, Monitoring, and the 2025 Policy Overhaul.

4. Foreign Investment and Technology-Transfer Risk (CFIUS)

Where a China-based entity is not just collaborating on research but investing in, acquiring, or licensing technology from a US institution or a university-affiliated startup, a fourth regime can apply: the Committee on Foreign Investment in the United States (CFIUS) screens foreign investment transactions for national-security risk and can block or unwind a deal. This is an investment/acquisition-based regime, distinct in trigger and mechanism from the item-based export control regime and the disclosure-based funder and statutory requirements above — an institution’s technology-transfer office is typically the one that needs to track it, alongside its research-security office tracking the other three.

Building an Institutional Risk-Assessment Framework

National Security Presidential Memorandum 33 (NSPM-33) directs federal research agencies to require standardized disclosure and directs institutions receiving federal research funding to stand up institutional research-security programs. In practice, most institutions build risk assessment for China (and other countries-of-concern) collaborations around a common set of elements:

  • Centralized disclosure review — reconciling what a researcher discloses on Current and Pending Support, Section 117 filings, conflict-of-interest disclosures, and travel forms, since gaps between these are what enforcement actions have actually targeted.
  • Restricted-party screening — checking prospective collaborators, institutions, and funders against OFAC’s Specially Designated Nationals list, the Commerce Department’s Entity List, and comparable restricted-party lists before a collaboration, subaward, or MTA is finalized; this is a separate check from export-control item classification.
  • Export-control review — classifying the technology, software, or data involved and determining whether a license is required before any transfer, consistent with the item-based analysis above.
  • Conflict of interest and conflict of commitment review — foreign appointments and outside positions can raise both a financial conflict of interest and a separate conflict of commitment concern about time and loyalty owed to the home institution.
  • Research security training — required of covered senior/key personnel under NSF, DOE, and comparable agency policies tied to CHIPS and Science Act Section 10634, covering foreign interference awareness alongside cybersecurity and disclosure obligations.

The common failure mode institutions are trying to design around is not a single missed rule but the compounding effect of several small, unreconciled disclosure gaps across these forms — exactly the pattern in the settlements described above.

Frequently Asked Questions

Is the DOJ China Initiative still in effect?

No. DOJ ended the China Initiative by name in February 2022 following sustained criticism, including a number of prosecutions that ended in acquittal or dismissal. The underlying disclosure and research-security concerns that motivated it did not go away, but the current compliance framework rests on statute (the CHIPS and Science Act of 2022), presidential policy (NSPM-33), and civil False Claims Act enforcement rather than the earlier criminal-prosecution program.

Does every US-China research collaboration require special disclosure?

No. Ordinary scholarly collaboration, co-authorship, conference participation, and open academic exchange are not, by themselves, MFTRP violations or export-control events, and the MFTRP statute explicitly protects them. What triggers additional obligations is a specific fact pattern: compensation from a foreign country of concern in exchange for transferring nonpublic IP or data, the transfer of export-controlled technology to a foreign national, or support/affiliations that must be disclosed on federal forms or under Section 117 — not the mere existence of a China-affiliated co-author or collaborator.

What is the difference between export control and research security requirements?

Export control (EAR/ITAR) is item- and technology-based: it governs the transfer of specific controlled technology, software, or technical data regardless of funding source or nationality of the recipient institution. Research security requirements (NSPM-33, MFTRP, funder disclosure rules) are relationship- and disclosure-based: they govern what a federally funded researcher must disclose about foreign support, affiliations, and compensation. A single collaboration can implicate both independently.

Does CFIUS apply to university research?

CFIUS applies specifically to foreign investment, acquisition, or certain licensing transactions involving a US business — including university-affiliated startups and, in some structures, technology licensed out of a university’s technology-transfer office — where the transaction could give a foreign person control over, or access to sensitive data or technology through, that business. It is not a general screen on academic research collaboration or federal grant activity; that is the role of the disclosure and export-control regimes described above.

Related CASRAI Resources

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →