1 · Concept overview

Established Research security is four different instruments wearing one name. Disclosure rules require a researcher to declare foreign appointments, contracts and support. Export-control rules decide which technical information may cross a border or reach a foreign national standing in the laboratory. Partnership screening decides which institutions a funded project may work with. Talent-mobility rules decide who gets a visa, a clearance or a place on a grant. They have different legal bases, different enforcement machinery and different error modes, and almost every public argument about “research security” slides between them mid-sentence.

Established Both cases in this dispute are real, and each is strongest where the other is weakest. The security case rests on adjudicated facts: contracts that paid named academics to duplicate laboratories abroad, undeclared foreign grants found in a funder’s own audit of its own grantees, and results whose publication cannot be recalled. The openness case rests on different measured facts: prosecutions that closed without conviction, survey evidence of fear and departure concentrated in one ethnic group, and the finding that international collaboration is where a mid-sized national research system gets most of its frontier output. The security case has documented incidents and no denominator; the openness case has a denominator and only weak identification of cause.

Frontier The asymmetry this brief lands on is one of measurement, not of merit. The costs of research-security regimes are partially measured — in researcher-hours, in collaboration counts, in survey-reported intention to leave. The benefits are not measured at all. No government anywhere has published an estimate of risk reduced per instrument, per dollar, or per screened application, and no research-security policy this brief could identify carries an evaluation clause that could return a null. A sensitive-technology list and a named-organisation list are scope decisions: they state what is in the regime, not how much harm it prevents.

Frontier The structural finding is inherited rather than invented here. Scientific Governance Models reports the sharpest regularity in the metascience record: interventions that apply a fixed rule to every item work, and interventions that try to improve a fine-grained human judgement do not. Research-security regimes are, almost without exception, fine-grained judgement applied to people. The one instrument in the adjacent literature with measured performance — automated screening of every synthesis order against a hazard database — is a rule applied to every item, and it achieves a security function without asking anybody’s nationality. The contrast is an analogy, not a result: nobody has run the comparison inside research security itself.

Established A note on sourcing. This brief was commissioned in September 2026 from the Institute’s research base. Reading-list entries without links are cited from the bibliographic record rather than re-fetched, and claims are dated no later than early 2026 unless carried by a linked source.

2 · Current scientific position

Established The open-publication rule in the largest research system is a policy choice with a date and a stated escape hatch. National Security Decision Directive 189, signed in 1985, states that the products of fundamental research shall remain unrestricted to the maximum extent possible, and that where restriction is necessary the mechanism is classification and no other. It has been reaffirmed by administrations of both parties. Its operative consequence is in export-control law: the fundamental-research exclusion removes published or publishable research at accredited institutions from the licensing regime, which is why a physics seminar is not an export event and a proprietary process design is. Everything argued since 2018 is argued against this baseline.

Established The documented-incident record exists, is smaller than the rhetoric and larger than zero. The clearest adjudicated case is the 2021 conviction of a Harvard chemistry department chair on false-statement and tax counts arising from an undeclared talent-programme contract with a Chinese university, the payment terms in the court record running to tens of thousands of dollars a month plus a seven-figure sum to establish a laboratory. A 2019 United States Senate investigations subcommittee report reproduced contract terms requiring recruitment, duplication of laboratory capability and assignment of intellectual property. Most consequential, because it was an audit rather than a prosecution: the principal American biomedical funder reviewed its own grantee population, contacted roughly a hundred institutions about some 250 named scientists, and by mid-2020 reported 54 resignations or removals, overwhelmingly over undisclosed foreign grant support. Frontier The same reporting recorded that about four in five of the scientists reviewed were of Asian descent. Both halves come from the funder’s own account; neither has an independent audit behind it.

Frontier The prosecution record is where the security case is weakest, and the disposition data is the reason. The United States Department of Justice initiative announced in November 2018 was closed in February 2022 by a successor administration, the closing statement citing the perception and risk of profiling. Independent compilations by journalists and legal scholars — there is no official complete case list, which is itself a finding — put the population at roughly eighty cases and under two hundred defendants, about a quarter resolved in conviction, with academic charges brought overwhelmingly under grant-fraud and false-statement statutes rather than espionage. Two prominent academic prosecutions collapsed: a professor in Tennessee was acquitted after a federal agent conceded false statements in the investigation, and charges against a department head at a Massachusetts institute were dropped in January 2022. These are not counter-anecdotes to the audit findings; they are evidence about a different instrument — criminal rather than administrative enforcement of the same disclosure rules.

Frontier The chilling-effect evidence is the best-measured cost and still not a causal estimate. Survey work published in the United States national academy proceedings in 2023, covering roughly 1,300 scientists of Chinese descent at American institutions, reported about 35 per cent feeling unwelcome, a large majority not feeling safe as academic researchers, and a substantial minority avoiding federal grant applications; a 2021 survey of about 1,900 respondents circulated through a scholars’ advocacy organisation reported roughly two in five feeling racially profiled by the government. Both are self-selected online samples run by interested parties, and should be read as evidence of the distribution of fear rather than as prevalence estimates. The harder series is administrative: publication-metadata analyses report departures of scientists of Chinese descent from American institutions roughly tripling between 2010 and 2021, and a 2024 paper reports reduced collaboration and output among affected researchers. Handwave Attributing any of this to a specific instrument is where the literature stops being evidence: the enforcement initiative, pandemic border closures, visa-processing collapse and a Chinese domestic funding expansion all arrive in the same window.

Established The collaboration series itself is solid and is routinely misread. Co-authorship between the two largest research systems grew for three decades, peaked in the early 2020s at tens of thousands of joint papers a year, and then declined in absolute terms for the first time, visibly in multiple databases. What it does not carry is a cause: the same period shows the smaller partner’s share of world output and of highly cited work rising and its domestic co-authorship deepening, all of which predict a falling bilateral rate under no policy at all. Frontier The decline is measured, the policy contribution to it is not, and anyone quoting the series as proof that security measures worked, or that they backfired, is quoting a number that cannot answer either question.

Established Policy scope, by contrast, is fully documented, because scope is what governments publish. Canada names sensitive technology research areas and named research organisations and conditions federal grant eligibility on the combination: a project touching a listed area, with a listed partner, is ineligible. The United States operates disclosure harmonisation under a 2021 presidential memorandum, with 2022 guidance requiring institutional research-security programmes above a federal funding threshold and statutory prohibitions on malign foreign talent recruitment programmes. The European Union adopted an advisory Council recommendation in May 2024. The United Kingdom runs an approval scheme for visa applicants in sensitive subjects; the Netherlands has been preparing a statutory screening act covering thousands of applicants a year. Frontier Not one of these instruments has published a measured effect on either side of the ledger — no incident rate before and after, no application volumes broken out by scope, no appeal-and-overturn statistics.

Established The Canadian institutional record is unusually legible, which is why this brief leans on it. The national academy body was asked by a defence research agency and a public health agency to assess the balance between research security and open science, and reported in 2025. The federal chief science advisor’s office states a mandate under which government science is publicly available and federal scientists may speak about their work. That same office, auditing compliance with its own model integrity policy across twenty-five departments and agencies, found nineteen had yet to implement a monitoring plan. A policy without monitoring is a policy of unknown effect, and that finding, made about scientific integrity, describes the research-security regime exactly.

3 · Frontier questions

Frontier Does personnel screening catch anything that artefact screening misses? This is the sharpest open question in the subject. Artefact-level checkpoints act on the thing — the synthesis order, the controlled design file, the compute allocation — and apply one rule to everyone. Personnel screening acts on the person and requires an official to judge an affiliation history. The published record contains a working artefact-level system in the adjacent biosecurity domain and no published performance data for any personnel-screening regime anywhere. Until a regime publishes hit rates, false-positive rates and appeal outcomes, the comparison cannot be made.

Frontier Is disclosure enforcement deterrence or displacement? The audit finding that dozens of grantees held undeclared foreign support is consistent with enforcement having removed genuine conflicts, and equally with the same arrangements continuing under different paperwork. The funder’s own amendment and audit-hit series would separate them; none has been published.

Frontier What is the actual harm function of open publication? The security case assumes a monotone relationship between openness and adversary capability; the economics-of-science literature finds the opposite for the publishing system as a whole. Both hold if harm is concentrated in a thin tail — pathogen enhancement protocols, weapons-relevant design data, certain model weights. Identifying that tail in advance is an unsolved problem, and the failure of pre-publication review to do it consistently is why the fundamental-research exclusion has survived forty years of pressure.

Speculative Does the regime change what gets researched? If listed areas carry compliance burden, rational applicants move to unlisted ones — a field-level shift measurable with data funders already hold, and unpublished, so the effect is unknown.

4 · Technological bottlenecks

Established Entity resolution is the binding technical constraint on every screening regime. A named-organisation list is a list of strings, and the objects it must match are affiliations, partner names, subsidiary structures and laboratory names that change, transliterate inconsistently and nest several levels deep. No open, maintained, machine-readable crosswalk exists between national sensitive-entity lists and the affiliation strings in bibliographic and grant databases, so every institution does this matching by hand, repeatedly.

Frontier The deemed-export concept does not survive contact with shared computing. Export-control doctrine treats release of controlled technical data to a foreign national as an export to that person’s country. Applied to a cloud tenancy, a shared model checkpoint or a hosted multinational collaboration, it generates determinations that are expensive, slow and often unresolvable — a legal-technical mismatch, and where compliance cost concentrates in computationally intensive fields.

Established Institutional capacity is the limiting factor, and the adjacent measurement is discouraging. In the closest measured analogue, biosafety oversight, published work finds offices with fewer than three full-time staff carrying oversight for entire universities. Research-security offices are newer, typically smaller, and in most systems were created without new appropriations.

Established Export controls on materials and on research information behave differently and are constantly conflated. Controls on refined materials leave a price signature — the critical-minerals record shows multiple-fold divergence between controlled and uncontrolled markets after the 2025 controls — and controls on information leave no comparable observable.

5 · Research dependencies

Established The first dependency is a denominator. Every claim about incident rates requires a population: how many international collaborations, of what kind, over what period, produced how many documented harms. No jurisdiction publishes an incident series with a denominator attached. Until one does, the security case rests on a numerator of vivid cases and the openness case on a denominator of ordinary ones, and the two never meet.

Frontier The second is a harm taxonomy distinguishing four things now merged. Undisclosed conflict of interest, intellectual property misappropriation, export-controlled technology transfer and state-directed intelligence collection have different frequencies, detection methods and remedies, and present instruments address them with one form and one list. Counts under each heading are a prerequisite for any cost-effectiveness statement.

Established The third is bibliometric causal identification rather than description. The collaboration series is descriptive. What is needed is a design — staggered policy adoption across countries, field-specific list coverage, discontinuities at funding thresholds — that separates policy effect from secular trend. The data are held by funders and commercial bibliometric vendors and are already linkable.

6 · Required experiments

Frontier The decisive test is a natural experiment already running that nobody has analysed: the staggered introduction of field-specific research-security lists. Canada conditioned federal grant eligibility on a published list of sensitive technology research areas combined with a published list of named research organisations, with dates of effect and a clear in-scope boundary. That is a difference-in-differences design handed to the research community intact: compare in-scope with out-of-scope research areas, before and after the date of effect, on grant application volumes, awarded-project partner composition, international co-authorship and time-to-award. Run it also against the European recommendation of May 2024 and the American programme requirement, and cross-country variation separates policy effect from global trend. The data already exist in funder administrative records and in bibliometric databases, no new instrument is required, and the cost is an analyst-year. Nobody has funded it.

Frontier The second is an audit study of disclosure enforcement. Publishing the series funders already hold — amendments filed per thousand awards, audits initiated, audits sustained, by year — would distinguish deterrence from displacement without releasing any individual record. A publication decision rather than a research project.

Established The third is already done, in the adjacent domain, and functions as an existence proof. A screening system for synthetic nucleic acid orders operates against a hazard database with exact-match architecture, a false-positive rate of roughly one order in five thousand, an operational sample measured in tens of millions of nucleotides, and a key-custody and signed-receipt design that makes the check auditable without exposing customer sequences. It delivers a security function at the artefact level, at scale, without asking who the customer is — the only working counterexample to the claim that security requires identity-based judgement, and an analogy rather than a demonstration.

Frontier The fourth is a randomised evaluation of research-security training, randomising module content or timing across departments with disclosure completeness and subsequent audit findings as outcomes. No funder has commissioned it, which is notable because the same funders require randomised evidence of far smaller interventions elsewhere.

Speculative The fifth is an adversarial red-team against a screening regime itself: give a team the published lists and ask it to design a collaboration that transfers the targeted capability while remaining fully compliant. If that succeeds cheaply and repeatedly, the regime is a paperwork filter. The biosecurity analogue, where generative design routed toxin sequences past existing filters in silico, suggests the result would be uncomfortable.

7 · Engineering requirements

Established A common disclosure form with persistent identifiers is the one engineering fix with an existing implementation path. Researcher identifiers, machine-readable biosketches and a single common form across agencies remove the duplication that generates most measured compliance cost without changing the substantive rule. Where agencies have not moved to common forms, each multiplies the burden by its own template.

Frontier A maintained crosswalk from entity lists to affiliation identifiers is the second — a public, versioned mapping that would convert thousands of independent manual determinations into one artefact. A data-engineering task of modest size that no institution owns.

Established Tiering is the standard engineering answer to a capacity constraint and is under-used here. The biosafety literature argues explicitly for functional risk tiering rather than blanket surveillance on capacity grounds. Applied here, tiering means most projects clear on a declaration, a small band gets documentary review and a very small band individual assessment, with published thresholds. Present regimes are closer to flat, so burden lands on the median project rather than the risky one.

Frontier An appeal mechanism with published statistics is a design requirement, not a courtesy. Without overturn rates there is no error estimate, without an error estimate no way to tune a threshold, and without a tunable threshold the regime is not an engineered system at all.

8 · Adjacent technologies

Established The nearest working relative is biosecurity screening, covered in AI & Biology Governance and Synthetic Biology. That domain has what this one lacks: a deployed checkpoint with published performance figures, a documented attack against it, and an argument about tiering grounded in measured institutional capacity. Research security should be read against it rather than against national-security rhetoric.

Frontier Export control on physical inputs is the sibling instrument, and Technological Sovereignty owns the cost accounting. That brief reports what this one cannot: localisation costs above five per cent of global real GDP, a domestic fabrication cost gap of twenty-five to fifty per cent on the industry’s own figures, and roughly $130 billion of market value lost by the firms of the country imposing controls, against a benefit never written as a falsifiable quantity.

Established The allocation machinery this regime sits on top of belongs to Scientific Governance Models, and the national systems it constrains to Innovation Ecosystems. The second reports an inverted evidence ranking in innovation policy: clean quasi-experimental designs where nobody expects them, no credible design at all where the money goes. Research security sits at the far end of that spectrum — high burden, zero design.

Frontier Multilateral instruments are the other half of the picture and belong to Global Cooperation Models. Speculative Information Integrity reports that its field measures supply and barely measures transmission; research security has the identical pathology one domain over.

9 · Institutional requirements

Established Canada’s arrangement is a useful reference because its parts are publicly named. A safeguarding-research portal publishes the sensitive technology research areas and the named research organisations; a research security centre inside the public safety department advises institutions; the tri-agency and infrastructure funders apply the eligibility condition; and the national academy body assessed the balance in 2025 at the request of a defence research agency and a public health agency. The structure is complete on paper, and what is missing is what is missing everywhere: a published series of determinations, appeals and outcomes.

Frontier The American arrangement is the largest and the most administratively expensive. Institutional research-security programmes are required above a federal funding threshold and must cover cybersecurity, foreign travel security, research-security training and export-control training. The compliance architecture is now larger than the enforcement record that motivated it — defensible if the deterrent works, expensive if it does not, and no published evidence distinguishes the cases.

Established The European instrument is advisory by design, which is a substantive choice rather than a weakness. The May 2024 Council recommendation sets expectations without creating an eligibility bar, relying on institutional autonomy — distributing judgement to the level with the most context and the least capacity. Whether that beats a central list is what the staggered-adoption design in section 6 could answer.

10 · Ethical & societal considerations

Established The distributional facts are not in dispute and are the ethical centre of the subject. In the American funder audit, roughly four in five reviewed scientists were of Asian descent; in the criminal enforcement initiative, the great majority of defendants were of Chinese heritage. Whether that reflects where the conduct was or where the attention was cannot be settled from published data, because the selection mechanism was never published. That unresolvability is itself a harm: a regime that cannot demonstrate it was not profiling imposes a reputational cost on a whole population of researchers regardless of the truth.

Frontier Steelmanning the security case honestly requires conceding that some transfers are irreversible. A protocol, once published, cannot be recalled; a model weight, once released, cannot be unreleased. For the thin tail of results where the marginal contribution to a weapons capability is real, the openness argument has no answer beyond the empirical claim that the tail is thin and hard to identify in advance. That claim is probably true and is not a refutation.

Frontier Steelmanning the openness case honestly requires conceding that the norm is a choice, not a law of nature. Universalism — that claims are assessed without regard to the nationality or personal attributes of their author — is one of four norms stated in 1942 as a description of how science holds together. It is a normative commitment with instrumental benefits, not an empirical finding that restriction never works, and arguing it as self-evidently binding weakens it.

Established The duty of care to early-career researchers is the most neglected obligation here. A doctoral student who chooses a listed area and finds partnership eligibility withdrawn two years later bears a career cost created entirely by policy timing, and no regime this brief could identify publishes transition provisions or remedies.

Frontier There is a historical precedent for nationality screening in science and it flatters neither side. The post-war American programme to recruit German specialists proceeded under a written standard excluding persons with objectionable political records, while recruiting people whose records were exactly that. The lesson is not that screening is always a sham; it is that a standard written in general terms and administered without published outcomes drifts toward whatever the agency wants.

11 · Civilizational implications

Frontier The civilizational stake is the throughput of the world research system, and the fragmentation literature gives the only quantified bound. Estimates of the cost of geoeconomic fragmentation span from about 0.2 per cent to about 7 per cent of world output, with low-income countries facing up to four times the average loss. The thirty-five-fold spread is the honest finding, and it is a bound on knowledge rather than a forecast. Research fragmentation is a component of that number and has never been separated out.

Frontier The dependencies that cannot be nationalised are what eventually binds. Pandemic surveillance, climate observation, particle physics and deep-space navigation are systems where no single national programme can produce the observable, and costs imposed there are not visible in any national accounting. Speculative The longer-run risk runs through talent stocks rather than papers: a policy that reduces inward doctoral flow by a few per cent a year compounds into a different research workforce twenty years later, and no country publishes a projection of that effect.

Handwave The claim that research security is an existential-scale question does not survive inspection. It is an important policy question with real costs on both sides, and the instruments in dispute are forms, lists and eligibility rules. Treating them as civilization-deciding inflates a governance argument into a survival argument, and the flag marks exactly where the inflation happens.

12 · Timelines

These horizons track policy effective dates, published-evidence milestones and institutional capacity rather than technology:

  • 10 yr: Frontier The staggered-adoption evidence base either exists or does not. Canadian list conditions have been in force since 2024, American and European instruments since 2022 and 2024, so by the mid-2030s there will be a decade of post-adoption administrative data. Either somebody publishes the difference-in-differences, or these regimes will have run for a decade with no measured effect on either side. Speculative Expect at least one jurisdiction to publish appeal statistics, because the first serious legal challenge to an adverse determination will force disclosure.
  • 25 yr: Speculative The composition question resolves visibly. If listed areas carry persistent burden, a generation will have sorted away from them and the shift will be legible in field-level output shares; direction is predictable, magnitude is not, and could be negligible. Frontier Artefact-level screening either generalises beyond nucleic-acid synthesis to compute allocation and controlled design data, or it does not; the biosecurity case will have twenty-five years of operating record to settle whether the model transfers.
  • 50 yr: Speculative Talent-stock effects become the dominant term, because doctoral pipelines are decade-scale and policies applied now show up in the composition of senior faculty around mid-century. Handwave Any specific claim about the size of that effect at fifty years is assertion: no country has published a projection, and compounding assumptions dominate the result.
  • 100 / 250+ yr: Handwave At this horizon disclosure forms, technology lists and visa schemes will not exist in recognisable form. Statements about whether the world research system is open in 2126 are statements about geopolitics, and nothing in the measured record of research-security policy constrains them.

13 · Technology tree & dependencies

  • Depends on The governance evidence in Scientific Governance Models, which supplies the checkpoint-versus-judgement regularity this brief applies, and the cost accounting for the sibling instrument in Technological Sovereignty. No scientific result blocks this topic. Everything missing is an administrative series that institutions already hold and have not published.
  • Requires (not on this map) Five things, four of them publication decisions rather than research. First, a published incident series with a collaboration denominator: documented harms per thousand international collaborations per year, by harm type. Governments publish case narratives and scope lists; none publishes the ratio, the only quantity from which a cost-effectiveness statement could be built. Second, appeal and overturn statistics for screening determinations: without an overturn rate there is no error estimate, and no threshold in any of these regimes can be tuned or defended. Third, a causal estimate separating policy effect from secular collaboration decline — the one genuinely scientific requirement here, and feasible from existing data through staggered national adoption plus field-specific list coverage. Fourth, a maintained crosswalk from entity lists to affiliation identifiers, so thousands of institutions stop performing the same string-matching task independently. Fifth, a ranked sensitivity list with stated evidence per entry: present lists are flat, so burden falls equally on the highest-risk and the marginal entry, and proportionality is impossible by construction.
  • Enables A measured research-security regime would let the disputes in Global Cooperation Models and Innovation Ecosystems be argued with numbers on both sides rather than with incidents on one side and burden on the other. No typed enabling edge is claimed, because the relationship has never been measured.
  • Adjacent Biosecurity screening and dual-use oversight in AI & Biology Governance and Synthetic Biology; the controlled-access technology stack in Privacy-Enhancing Computation; the measurement pathology shared with Information Integrity; and the historical screening precedent in Operation Paperclip.

14 · Common misconceptions & speculative claims

Frontier Claim: the enforcement initiative was a spy hunt and it caught spies. The adjudicated record does not support it as stated. Independent compilations put the population at roughly eighty cases and under two hundred defendants, about a quarter resolved in conviction, with academic charges brought overwhelmingly under grant-fraud and false-statement statutes, and two prominent academic prosecutions collapsed. The correct statement is narrower and still substantive: a funder’s administrative audit found dozens of grantees with undeclared foreign support, a disclosure-enforcement finding rather than an espionage finding.

Frontier Claim: there is no evidence of chilling effects. There is evidence, weaker than its users imply and stronger than its critics allow. Two large surveys report fear, profiling perception and intention to leave concentrated among scientists of Chinese descent; both are self-selected and run by interested parties. Publication-metadata analyses report departures roughly tripling over a decade, which is administrative rather than self-reported. None of it isolates a policy cause, and honest use says exactly that.

Handwave Claim: the fall in bilateral co-authorship proves the policy worked. And the mirror claim, that it proves the policy backfired. Both are handwaves in the precise sense: the argument works by assertion at the step where a counterfactual is needed. The series has no control group, and the smaller partner’s rising domestic capability predicts the same decline under no policy at all.

Established Claim: open science means no restrictions on research exist. False as a description of the law. The open-publication baseline names classification as the mechanism for restriction, and export controls have always applied to research that is not publishable and to controlled technical data. The dispute is about where the boundary sits, not whether one exists.

Established Claim: a sensitive-technology list is a risk assessment. It is not, and no list says it is. A list establishes scope — which research areas and which organisations trigger the regime. It contains no ranking, no stated evidence per entry and no estimate of harm prevented. Reading a scope decision as a measured risk ranking is the most common error in this subject, and advocates on both sides make it.

Frontier Claim: security and openness trade off one for one. The adjacent synthesis-screening system checks every order against a hazard database at scale, with roughly one false positive per five thousand orders, without knowing the customer’s nationality. Whether it transfers to research collaboration is open; that it exists refutes the strong form of the claim.

Handwave Claim: this is a question about one country’s behaviour. Framing research security as a bilateral morality play is the failure mode that makes the evidence unreadable. Every major research system now operates some combination of these four instruments; the interesting variation is across designs, not across national villains, and design variation is what the available data can speak to.