TL;DR
On Wednesday 30 September MI5 publicly named CGTRI, short for China General Technology Research Institute, as a funding channel for China’s Ministry of State Security (MSS), the country’s civilian intelligence service. MI5 counts upward of 100 academics with UK links among contributors to work CGTRI paid for, some of it on AI. Universities have been told to review any collaboration immediately.
What the alert says
MI5’s position is that CGTRI exists mainly to pay for academic work that sharpens the MSS’s technical capability for spying. CGTRI, also translated as CAGT (for China Academy of General Technology), backs Chinese research into AI, covert communications, cybersecurity and steganography, the craft of hiding information inside other messages or files.
MI5 accepts that many researchers will have taken part without knowing who was paying. The alert asks academics to trace the ultimate funder of any Chinese research collaboration, and reminds institutions and staff of the National Security Act 2023. Anyone who keeps working on CGTRI-funded projects now that the link is public may risk prosecution under that Act, Reuters reports, and MI5 advises them to get independent legal advice.
Reuters notes this is the first alert MI5 has published on its own account. Security minister Dan Jarvis has written to the heads of every UK university asking them to make sure staff end any relationship with the institute.
China’s embassy in London called the claims “imaginary and purely fabricated” and said it had lodged “solemn representations”.
Part of a pattern
The alert follows earlier warnings: one from MI5 to MPs last November about Chinese agents posing as headhunters, and a Five Eyes advisory in June about recruitment through online job platforms. It also lands while ministers pursue closer trade ties with Beijing.
What is different this time is the target. Those two warnings were about individuals being approached. This one concerns funding flows into ordinary-looking research partnerships, which is far harder for a busy academic to spot.
Looking forward
For UK universities with active AI and cyber groups, the immediate work is a funding audit, not a policy statement. Companies that sponsor or license university AI research should expect to ask the same question of their academic partners. The National Protective Security Authority’s Trusted Research guidance, linked from the alert, is the obvious starting point.