TL;DR: The SAFE Research Act — a provision that would have blocked federal funding, across every federal agency, to any U.S. researcher found to have collaborated with an entity “affiliated with” China, Russia, North Korea, or Iran — was stripped from the final FY2026 National Defense Authorization Act (NDAA) conference agreement after months of organized opposition from research universities and scholarly associations. President Trump signed the FY2026 NDAA into law on December 18, 2025 without the provision. This piece covers what the SAFE Research Act would actually have required, why the research community objected to it, and which research-security provisions did survive into the enacted law.
What the SAFE Research Act Would Have Done
The SAFE Research Act was attached to the House-passed version of the FY2026 NDAA. As described in reporting and analysis from the Association of American Universities (AAU) and the American Institute of Physics’ FYI service, the provision would have:
- Applied government-wide, not just to DoD. Unlike existing research-security authorities such as NSPM-33-derived foreign travel and disclosure requirements, which largely run through specific funding agencies, the SAFE Research Act would have barred any federal agency from funding an institution or individual researcher found to have an “affiliation” with a designated hostile foreign entity.
- Used a broad definition of “affiliation.” AAU’s letter to the House and Senate Armed Services Committees warned the bill’s language was broad enough to capture “every single research agreement, every study abroad program, every language program, every professional conference” involving a partner in a covered country — not only formal talent-recruitment-program participation, which is the narrower target of existing Section 1286 list restrictions.
- Applied retroactively. The bill’s compliance window looked back five years, meaning agreements or collaborations that were lawful and disclosed at the time they occurred could have triggered a funding bar under the new standard.
- Imposed a multi-year funding bar. Institutions and individual researchers found in violation would have been required to sever the flagged relationship and remain ineligible for federal funding for a period reported at five years, with post-award certification obligations extending well beyond a grant’s period of performance.
Covered countries named in reporting on the bill text were China, Russia, North Korea, and Iran — broadly the same set of countries flagged under existing frameworks such as the CHIPS and Science Act’s “countries of concern” list, but the SAFE Research Act would have layered a much broader, government-wide funding bar on top of those existing, narrower mechanisms.
Why the Research Community Opposed It
Opposition built through the fall of 2025 and came from a wide cross-section of the research community, not a single interest group:
- AAU and APLU (the Association of American Universities and the Association of Public and Land-Grant Universities) sent formal letters to the House and Senate Armed Services Committees urging the SAFE Research Act be struck from any final NDAA text, arguing it “undermines and actually conflicts with” definitions and compliance frameworks already built around NSPM-33 and existing disclosure rules, and would create compliance burdens research-security offices — already stretched thin — could not realistically absorb.
- The American Physical Society (APS) and other scientific societies raised concerns about the chilling effect on legitimate international scientific collaboration and co-authored publication, distinct from the narrower, already-regulated category of malign foreign talent recruitment programs.
- The Asian American Scholar Forum (AASF) organized a letter, signed by more than 750 scholars and researchers, spotlighting the risk that an overly broad definition of “affiliation” would disproportionately affect researchers of Chinese and other Asian descent through guilt-by-association mechanics rather than evidence of an actual security threat.
- COSSA (the Consortium of Social Science Associations) and other scholarly-society coalitions echoed the concern that the bill conflated ordinary international academic exchange — conferences, study-abroad programs, co-authorship — with the undisclosed foreign-talent-program participation that existing research-security rules are actually designed to catch.
The common thread across this coalition was not opposition to research-security screening as such — most of these same organizations have publicly supported narrower, disclosure-based mechanisms like Section 889 and the existing Section 1286 list — but opposition to a mechanism they characterized as both overbroad (retroactive, activity-agnostic, government-wide) and duplicative of frameworks federal agencies had already spent years building out.
How the Provision Was Removed
The SAFE Research Act was not enacted through a standalone up-or-down vote; it was resolved during the House-Senate conference process that reconciles the House and Senate versions of the NDAA into a single bill. According to reporting from the Asian American Scholar Forum and confirmed by AAU’s own tracking of the conference agreement, the provision was dropped during conference negotiations rather than carried into the final text — meaning it never reached a dedicated floor vote on its own merits in either the House or Senate version that was ultimately enacted. The FY2026 NDAA conference agreement was finalized in early December 2025, passed both chambers, and was signed into law on December 18, 2025 without the SAFE Research Act provision.
This outcome is consistent with how narrower, more targeted research-security language has tended to survive NDAA conference negotiations in recent cycles, while broader or more novel restrictions have more often been trimmed back or dropped — the same pattern CASRAI has covered with the government-wide “countries of concern” list and with agency-level implementation such as NSF’s restricted-entity collaboration ban, both of which took the narrower, agency-specific path that the SAFE Research Act’s critics argued the bill itself failed to follow.
What Did Stay in the FY2026 NDAA
The SAFE Research Act’s removal does not mean the FY2026 NDAA was quiet on research security. Provisions that research administrators should still be tracking from the enacted law include:
- Section 1286 list funding restrictions, extended. The FY2026 NDAA continued and extended the existing prohibition on DoD funding for fundamental research involving collaboration with an entity on the current Section 1286 list of flagged foreign talent programs and institutions — the same mechanism behind the Confucius Institute funding-eligibility pressure CASRAI has covered separately. A new case-by-case waiver authority for the Assistant Secretary of Defense for Science and Technology was also added, letting DoD exempt a specific grant or contract from the restriction where a waiver is determined to serve U.S. national security interests.
- BIOSECURE Act provisions. The enacted NDAA incorporated BIOSECURE Act-related restrictions targeting DoD contracting with named biotechnology companies with ties to designated foreign adversaries — a narrower, named-entity approach rather than the SAFE Research Act’s broad affiliation-based standard.
- Existing disclosure and certification frameworks untouched. NSPM-33-derived requirements — foreign talent recruitment program disclosure, current-and-pending-support certification, research security training mandates now rolling out at NSF and NIH — remain in force independent of the NDAA and were not displaced by either the SAFE Research Act’s proposal or its removal.
What This Means for Research Administrators
For research security offices and sponsored-programs administrators, the practical takeaway is continuity rather than a new compliance regime to stand up. The disclosure, certification, and screening obligations already in effect — restricted-party and Section 1286 list checks, foreign talent recruitment program disclosure, foreign travel security policies, current-and-pending-support certification — remain exactly what they were before the FY2026 NDAA was signed. What did not materialize is a government-wide, retroactive, activity-agnostic funding bar layered on top of those existing mechanisms.
That said, the SAFE Research Act is unlikely to be the last attempt at a broader statutory research-security mechanism. The coalition that opposed it — AAU, APLU, COSSA, AASF, and others — has been explicit that its objection was to the bill’s breadth and retroactivity, not to research-security screening in principle, which suggests future proposals narrower in scope could see a different reception. Research administrators should continue monitoring both future NDAA cycles and standalone research-security legislation rather than treating this outcome as a closed question.
Related CASRAI Coverage
For the broader research-security compliance landscape referenced above, see CASRAI’s coverage of the CHIPS and Science Act countries-of-concern list, Confucius Institute closures and GAO findings, NSF’s restricted-entity collaboration ban (NSF 26-022), Executive Order 14292 on biological research security, foreign travel security policy requirements, and whistleblower protections for reporting export-control violations.







