Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

Editorial · CASRAI · Compliance and regulatory

GAO: Research-Security Screening Needs Bias Review

GAO: 5 top research-funding agencies havent assessed whether security screening risks discriminating against Chinese and Asian-descent scientists.

Published 29 Jul 2026· 6 minute read

A January 2026 report from the U.S. Government Accountability Office, GAO-26-107544, Research Security: Agencies Should Assess Safeguards Against Discrimination, examined the five federal agencies that fund the largest amounts of extramural research — the Department of Defense (DOD), the Department of Energy (DOE), NASA, the National Institutes of Health (NIH), and the National Science Foundation (NSF) — and found that none of them had assessed whether their research-security screening processes create a risk of discriminating against scientists of Chinese or Asian descent.

This is an accountability finding about a gap in oversight, not a finding that discrimination occurred. GAO did not conclude that any agency’s screening practices are discriminatory; it concluded that the agencies have not checked. That distinction matters for how research administrators, compliance officers, and institutional leadership should read the report, and it is the focus of this page.

What GAO reviewed

GAO examined how DOD, DOE, NASA, NIH, and NSF review federally funded researchers and applications for signs of improper foreign influence — the screening and disclosure-review processes that sit underneath research-security program requirements such as those established by NSPM-33 and the CHIPS and Science Act. The report’s stated premise is that foreign governments, primarily China, have attempted to improperly influence U.S.-based scientists conducting federally funded research, creating risks to research integrity and to the security of federally funded work. Agencies have built research-security review processes to address that risk. GAO’s question was narrower than whether those processes are justified: it asked whether the agencies had checked their own processes for a specific side effect — unfairly targeting researchers because of their Chinese or Asian ethnicity or national origin, rather than because of individualized risk indicators.

What GAO found

GAO’s central finding, in its own language, is that no agency had assessed the potential for discrimination in their research security processes. Every agency in scope has a review process; none had evaluated whether that process, in practice, provides reasonable assurance that discrimination against Chinese and Asian-descent scientists will not occur.

GAO identified five safeguards that can help an agency avoid discrimination in this kind of review, and assessed how consistently each of the five agencies used them:

  • Transparent improper-foreign-influence review processes — documented, published, or otherwise knowable criteria for how a case gets flagged and reviewed.
  • Collection and use of demographic data to assess whether the agency’s own process disproportionately affects researchers of a particular ethnicity or national origin.
  • Multiple levels of review in improper-foreign-influence cases, rather than a single reviewer’s judgment determining an outcome.
  • Staff training in non-discrimination specific to research-security review work.
  • Leadership commitment to non-discrimination, visible in policy and practice.

Adoption of these five safeguards varied across the five agencies; GAO reported that NIH and NSF had implemented more of them than DOD, DOE, and NASA. None of the five agencies had all five in place, and — independent of how many safeguards each had — none had actually assessed whether the safeguards they did have were sufficient to provide reasonable assurance against discrimination.

GAO’s recommendations and agency responses

GAO issued seven recommendations across the five agencies, directing them to document their research-security review processes more fully and to formally assess whether their existing safeguards provide reasonable assurance that discrimination will not occur. Agency responses to the recommendations were mixed: NASA and NIH agreed with GAO’s recommendations; NSF said it would consider them; DOE disagreed, stating its process is already designed to ensure nondiscrimination; DOD did not provide comments captured in the report.

Why this matters for research administrators

Research-security compliance work at U.S. institutions — disclosure review, foreign-talent-program screening, malign-foreign-talent-recruitment-program (MFTRP) certifications, and the broader NSPM-33 research security program elements — sits downstream of exactly the federal review processes GAO examined. Institutions have generally built their own compliance programs to satisfy agency requirements as agencies define them; GAO’s report is a signal that the agencies’ own definitions of “improper foreign influence” and their review mechanics are themselves under active congressional and oversight scrutiny for a specific failure mode: disparate impact on researchers of Chinese or Asian descent, independent of individualized risk.

For institutions, this does not change any current disclosure or certification obligation under NSPM-33, CHIPS Act Section 10634 training requirements, or agency-specific research-security policies (NSF Notice 149, DOE PF 2025-04, and similar). It does add relevant context for institutional research-security officers and legal counsel: the federal screening apparatus that institutional compliance programs are built to satisfy is itself being told, by its own oversight body, to check its work for discriminatory effect. Institutions with their own concerns about how internal research-security or export-control reviews affect specific researcher populations may find GAO’s five safeguards — transparency, demographic-impact review, multi-level review, training, and leadership commitment — a useful internal checklist, independent of what the federal agencies ultimately do with the recommendations.

Background: why this concern predates the report

Concerns that U.S. research-security enforcement disproportionately affects scientists of Chinese descent are not new to this report. The Department of Justice’s China Initiative (2018–2022) drew sustained criticism, including from Asian American advocacy organizations and civil-liberties groups, over prosecutions that were later dropped or resulted in acquittals, and the program was formally ended in February 2022. Academic and civil-society research published in the years since has continued to document a “chilling effect” — scientists of Chinese descent reporting reluctance to collaborate internationally, apply for federal funding, or remain in U.S. academic research, out of fear of scrutiny disconnected from any individualized conduct. GAO-26-107544 is the first report to formally examine, at the level of the five largest federal research funders, whether the successor research-security screening infrastructure — built under NSPM-33 and the CHIPS and Science Act rather than under the China Initiative’s criminal-enforcement model — has itself been checked for the same risk.

What the report does not say

It is worth being precise about scope. GAO did not audit individual disclosure or enforcement cases and did not report finding that any agency’s process has in fact produced discriminatory outcomes. Its finding is that agencies have not done the assessment that would tell them either way. Readers should not characterize this report as GAO concluding that federal research-security screening is discriminatory; the accurate characterization is that GAO found an unaddressed risk-assessment gap, with seven specific recommendations to close it.

Source: U.S. Government Accountability Office, GAO-26-107544, “Research Security: Agencies Should Assess Safeguards Against Discrimination”, published January 21, 2026, publicly released January 22, 2026.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →