Skip to main content
v2026.11,610 entries · CC-BY 4.0

Editorial · CASRAI · Research security

Department of War Orders Research Security Audits at 30 Universities

The Department of War ordered research security audits at 30 U.S. academic institutions on 17 August 2026, giving them until 31 August to report on foreign collaborations tied to Section 1286 entities and rebranded Confucius Institutes, or risk losing eligibility for future federal research funding.

Published 25 Aug 2026· Last updated 25 Aug 2026· 5 minute read

Ask about this story

Answers are drawn from this article and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

CASRAI is the reference for research administration — bookmark it for the next question.

The Department of War ordered research security audits at 30 U.S. academic institutions on 17 August 2026, giving each until 31 August 2026 to report findings or risk losing eligibility for future federal research funding. The order came from Emil Michael, Under Secretary of War for Research and Engineering, and it is the most concrete near-term compliance deadline the research-security push has produced this year.

The Department has not published a public list of the 30 institutions, but student and local reporting has independently confirmed several, including the University of Illinois, Penn State, and Oklahoma State University; separate reporting names Harvard and NYU among the institutions notified. Given that spread — large public land-grants alongside private research universities — this is not a narrowly targeted action against a single type of institution.

What the audit actually requires

The notification directs institutions to review active academic, financial, and research collaborations against two specific categories:

  • Foreign entities of concern under Section 1286 of the FY19 NDAA — the same list already underlying NSF’s Notice 149 research security certifications and most institutional restricted-party screening programs.
  • Organizations linked to rebranded Confucius Institutes — entities that dissolved their original Confucius Institute branding after the 2020s wave of institutional closures but that the Department considers functionally continuous with the original programs.

Named institutions must complete a comprehensive audit of every identified foreign collaboration, assess whether sensitive or export-controlled research has been exposed through those ties, and put mitigation plans in place — including, where warranted, terminating the partnership. Findings and actions are due back to the Department by 31 August 2026. “The Department of War has zero tolerance for academic partnerships that compromise our national security,” Michael said in the Department’s statement. “Institutions that receive funding from American taxpayers must uphold the highest standards of research security.”

The strategic backdrop

The audit order followed the White House’s National Security Science and Technology Strategy, released in mid-August 2026 to satisfy OSTP’s statutory obligation to support the 2025 National Security Strategy. That document names intellectual-property theft and adversarial exploitation of the U.S. research base as one of the primary risks to maintaining technological advantage, alongside supply-chain disruption and the convergence of quantum, biotech, and AI research. The audit order operationalizes that framing directly: it is the Department converting a strategy document’s stated concern into a dated compliance action against named institutions.

What this means for research offices, on or off the named list

  1. Fourteen days is not enough time to build a foreign-collaboration inventory from scratch. Institutions that already maintain a current register of international agreements, MOUs, subaward relationships, and visiting-scholar affiliations mapped against Section 1286 and Commerce/State restricted-party lists can respond to a request like this in days. Institutions without one cannot build it credibly in the time given. If your institution was not named this round, treat the 31 August deadline as a preview of what a future request would demand, and build the inventory now rather than under the same time pressure.
  2. “Rebranded Confucius Institute” is a harder screening category than the entity-list checks most offices already run. Standard restricted-party screening tools flag named entities on published lists. Identifying an organization as a functional successor to a dissolved Confucius Institute requires research into corporate and institutional lineage that a standard screening subscription will not surface automatically. This is a genuine gap between what most research-security programs currently screen for and what this specific audit demands.
  3. The consequence is funding eligibility, not just this audit’s outcome. The Department tied noncompliance to eligibility for future federal research funding broadly, not only Department of War awards — consistent with how NSPM-33-derived research security requirements have generally been enforced across agencies. A weak or late response carries a cost well beyond the specific audit.

This sits alongside the existing federal research-security architecture: sanctions, embargoes, and countries-of-concern screening that most offices already run for export-controlled work, and the broader set of institutional research security obligations that NSPM-33 and agency-specific rules (NSF Notice 149, NIH, DOE) have layered on since 2022. An EAR99 classification on a piece of equipment or software doesn’t answer the Section 1286 question this audit is asking — the two screening regimes are related but not interchangeable, and an office that has only built out export-control screening should not assume it has this covered.

Frequently asked questions

Is this a new law or regulation?

No. It is a Department of War compliance directive applying existing authority under Section 1286 of the FY19 NDAA and the Department’s own funding-eligibility discretion. It does not create new statutory obligations beyond what Section 1286-based research security requirements already impose.

What happens if an institution misses the 31 August deadline?

The Department has stated that institutions failing to complete the audit and report findings risk losing eligibility for future federal research funding. The Department has not published a specific penalty schedule beyond that statement.

Does this only apply to Department of War-funded research?

The Department’s language ties compliance to eligibility for future federal research funding generally, which is consistent with how other NSPM-33-derived research security enforcement has operated across agencies rather than being confined to a single funder’s awards.

How is a “rebranded Confucius Institute” identified?

The Department has not published a specific list or methodology. Institutions are expected to assess organizational lineage and functional continuity with dissolved Confucius Institute programs as part of the audit, which is a materially different task from checking a name against a published restricted-entity list.

Primary sources: Department of War statements reported by Military Times (“Pentagon scrutinizes foreign research ties at 30 US academic institutions,” 17 August 2026) and ExecutiveGov (“DOW Orders Research Partner Audits From 30 Universities,” 18 August 2026), both quoting Under Secretary of War for Research and Engineering Emil Michael; institution-specific confirmation via The Daily Illini, Onward State (Penn State), and the O’Colly (Oklahoma State); White House, National Security Science and Technology Strategy (mid-August 2026, per reporting from Defense One, USNI News, and Lawfare).

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 44,322 indexed passages, and every answer cites the ones it drew on.