Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

Editorial · CASRAI · Compliance and regulatory

Texas HB 127: Research-Security Deadline Hits

Texas HB 127 (not SB 1565) sets an August 2026 research-security certification deadline for Texas public university boards.

Published 29 Jul 2026· 6 minute read

TL;DR: Texas HB 127 — not SB 1565 — is the state law putting an August 2026 research-security certification obligation on public university governing boards. Signed in the 89th Legislature’s regular session and effective September 1, 2025, HB 127 layers substantive restrictions (foreign-adversary gift bans, mandatory travel monitoring, foreign-researcher background checks, elevated criminal penalties for trade-secret theft) on top of the procedural governance framework SB 1565 already required. The two laws are complementary, not duplicative, and research administrators at Texas public institutions need to track both.

HB 127 is a different law from SB 1565 — here is the distinction

CASRAI has previously covered Texas SB 1565 against Florida’s HB 905. SB 1565, effective September 1, 2023, is a structural/procedural mandate: it requires public institutions to adopt a written research-security policy framework and designate a trained research security officer. It does not name specific countries, does not restrict specific transactions, and does not create new criminal penalties.

HB 127, passed two years later in the 89th Legislature’s regular session (2025) and signed into law with a September 1, 2025 effective date, is substantive rather than purely procedural. It creates a statewide Higher Education Research Security Council, bans most gifts to institutions and employees from foreign-adversary governments, businesses, and political parties, mandates international travel pre-approval and monitoring programs, requires background checks (including passport and visa history) on foreign-national researchers before they are hired or given research access, requires institutions to eliminate instructional software owned by foreign-adversary entities, and elevates trade-secret theft intended to benefit a foreign government or agent from a third-degree to a second-degree felony. Readers researching this topic should not conflate the two bills — they impose different obligations, on different timelines, with different consequences for noncompliance.

What HB 127 requires of Texas public universities

  • Higher Education Research Security Council: a statewide body overseeing research-security compliance at Tier One research institutions, tasked with issuing a model research-security policy and identifying best practices for vetting foreign gifts and partnerships.
  • Gift and contract restrictions: institutions and employees are barred from accepting gifts of more than de minimis value from foreign-adversary governments, businesses, organizations, or political parties, and institutions generally cannot contract with foreign-adversary or federally banned companies absent a documented lack of reasonable alternative. Vendors must certify they are not prohibited entities; a false certification can trigger contract termination and state debarment.
  • Foreign-researcher screening: institutions must run background checks on foreign-national applicants for research positions, collecting passport copies, visa records, employment history, and publication records, reviewed by a designated research-integrity office before hiring or granting research access.
  • International travel monitoring: institutions must stand up a travel pre-approval program requiring faculty and researchers to obtain research-integrity-office sign-off before traveling abroad on institution-related business.
  • Academic partnerships and software: new partnerships with foreign-adversary institutions require Council approval, and institutions must phase out instructional or research software owned by foreign-adversary entities.
  • Criminal penalties: theft of trade secrets intended to benefit a foreign government, foreign instrumentality, or foreign agent is elevated to a second-degree felony, versus a third-degree felony for trade-secret theft generally.

The implementation timeline

Public reporting and the House Research Organization’s bill analysis point to a staged rollout rather than a single compliance date:

  • September 1, 2025 — HB 127 takes effect.
  • October 1, 2025 — deadline for institutions to designate their Council-facing personnel.
  • January 1, 2026 — the Higher Education Research Security Council’s initial meeting is required.
  • August 2026 — per reporting on a May 2026 Texas Tech University System Board of Regents briefing, institutional research-security officers told regents that a series of certification requirements come due by this month, with governing boards required to complete an initial compliance certification and then recertify annually thereafter.
  • September 1, 2026 — the bill analysis separately identifies this date as when a compliance-certification requirement tied to institutional spending begins.

CASRAI has not been able to independently confirm from primary legislative text exactly how the August 2026 board-certification deadline reported by institutional counsel relates to the September 1, 2026 date in the legislative bill analysis — they may be the same requirement described with rounding, or two related-but-distinct certification obligations under the same statute. Research administrators should treat both dates as live and confirm the exact scope of each with their institution’s general counsel or research-security office rather than assuming either date supersedes the other.

Why the August 2026 deadline matters for research administrators

HB 127 explicitly moves research-security compliance from a staff-level operational matter into what one Texas Tech System briefing characterized as a board governance obligation — meaning the governing board itself, not just the research-security office, now bears certification responsibility. Reporting on the Board of Regents briefing indicates that failure to comply can make an institution ineligible for state formula-funding increases, which raises the stakes of the August 2026 date well beyond a routine compliance filing. For research administrators, sponsored-programs offices, and export-control staff at Texas public institutions, this means:

  • Confirming the institution’s research-security office and legal counsel have a documented, board-ready compliance file ahead of the certification date, not just an internal policy.
  • Verifying gift-vetting and travel-monitoring procedures required under HB 127 are actually operational, not only drafted, since both are inputs to what the board is being asked to certify.
  • Not assuming SB 1565 compliance (a policy framework plus a designated research security officer) satisfies HB 127 — the two laws test different things.
  • Coordinating HB 127 compliance work with existing federal obligations under NSPM-33 and NSPM-33’s four required research-security program elements, and with Section 117 foreign-gift-and-contract reporting, since HB 127’s gift and partnership provisions overlap substantively with those federal regimes even though the certification obligations are separate.

Frequently asked questions

Is Texas HB 127 the same law as Texas SB 1565?

No. SB 1565 (effective September 1, 2023) is a procedural governance mandate — a written policy plus a designated research security officer. HB 127 (effective September 1, 2025) adds substantive restrictions: foreign-adversary gift bans, mandatory travel monitoring, foreign-researcher background checks, software restrictions, a new statewide Research Security Council, and elevated criminal penalties for trade-secret theft. Institutions subject to both must satisfy each separately.

Which Texas institutions does HB 127 apply to?

HB 127 applies broadly to Texas public institutions of higher education, with the Higher Education Research Security Council’s direct oversight role centered on Tier One research institutions (the state’s most research-intensive public universities, including UT Austin, Texas A&M, Texas Tech, the University of Houston, and the University of North Texas).

What happens if a Texas public university misses the certification deadline?

Reporting on the Texas Tech System’s Board of Regents briefing indicates that noncompliance can make an institution ineligible for state formula-funding increases. Institutions should confirm the precise consequences and cure procedures directly with the Texas Higher Education Coordinating Board and their own legal counsel, since state guidance continues to develop as the Council issues model policy.

Does HB 127 replace federal research-security requirements like NSPM-33?

No. HB 127 is a state-law layer that sits alongside, not instead of, federal requirements such as NSPM-33’s research-security program mandate and Section 117 foreign-gift-and-contract reporting. Compliance with one does not substitute for compliance with the other.

Sources

  • Texas Legislature, House Research Organization bill analysis, HB 127, 89th Legislature Regular Session: capitol.texas.gov
  • “Texas Tech Regents Briefed on Research Security Obligations,” Texas Scorecard (reporting on the Texas Tech University System Board of Regents briefing, May 2026): texasscorecard.com
  • “H.B. 127 brings new research security rules to Texas,” The Daily Toreador: dailytoreador.com

This page summarizes public reporting and legislative-analysis text current as of publication; institutions should confirm current compliance obligations directly with the Texas Higher Education Coordinating Board and their own legal counsel, as Council model-policy guidance was still being finalized at the time of writing.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →