DoD Orders 30 Universities to Audit Foreign Research Collaborations
Key Takeaways
-
On August 17, 2026, the Department of Defense (DoD or Department) announced that it had directed approximately 30 U.S. universities to conduct immediate reviews of academic, financial and research collaborations with entities identified under Section 1286 of the FY19 National Defense Authorization Act (NDAA) and organizations associated with rebranded Confucius Institutes (the Directive).
-
The notified institutions must conduct audits and report findings and mitigation actions to the Department, by August 31, 2026.
-
The Directive is part of a broader federal effort to scrutinize foreign funding, research collaborations, technology transfer, access to sensitive research, as well as relationships among U.S. educational institutions and entities associated with countries of national-security concern.
-
DoD indicates that compliance with the Directive will influence eligibility for future federal research funding.
-
Even institutions not yet subject to the Directive should consider conducting a foreign-relationship inventory and preparing a defensible process for assessing, mitigating, and documenting collaboration-based national security risks.
What the Directive Requires
The August 17 Directive states that 30 American universities and specialized technology institutes must initiate immediate and comprehensive reviews of all academic, financial, and research collaborations with foreign entities of concern. The Directive appears designed to obtain more comprehensive insight into the institutions' active academic, financial, and research collaborations with the foreign entities identified under Section 1286 of the FY19 NDAA, and organizations associated with rebranded Confucius Institutes. The Section 1286 list currently includes approximately 130 institutions, primarily in China, with additional entities in Russia and Iran.
The Directive states that, to maintain eligibility for future federal research funding, notified universities must complete a comprehensive audit of identified foreign collaborations, assess exposure of sensitive or export-controlled research, and implement mitigation plans, including termination of problematic partnerships, where appropriate. Institutions are required to report their findings and actions directly to the Department no later than August 31, 2026. Although the Department has not released a full list of the notified institutions, at least one publication has identified the targeted institutions.[1]
The Department described the Directive's purpose as protecting American taxpayer-funded research investments from academic partnerships that "compromise national security" through unauthorized technology transfer, intellectual property theft, and adversarial exploitation. Information assembled through the audit may also identify relationships relevant to export controls, sanctions, federal funding eligibility, research-security requirements, Outbound Investment Security Program restrictions, or other national-security authorities.
Context for the Directive
The Directive follows several years of increasing federal attention to alleged foreign influence in U.S. higher education and to the protection of federally funded research, emerging technologies, and the defense industrial base, including:
-
Section 117 of the Higher Education Act. Federal law has long required institutions of higher education to disclose certain foreign gifts and contracts. During the first Trump Administration, the Department of Education substantially increased enforcement of those requirements, establishing a precedent for treating foreign financial relationships with universities as national-security and transparency issues.
-
Research-security and China-related investigations. During the first Trump Administration, the Department of Justice's China Initiative and related FBI investigations focused heavily on university researchers, federal grant recipients, undisclosed foreign affiliations, and relationships with Chinese universities and research institutions. Although the formal China Initiative was terminated during the Biden Administration, concern over foreign exploitation of U.S. research capabilities continued.
-
Federal research-security requirements. Congress and federal agencies subsequently expanded requirements concerning disclosure of foreign affiliations and commitments, foreign support, research security, and participation in federally funded research. In the audit-specific context, the current focus appears to be on entities associated with China, Russia, and Iran, together with organizations associated with rebranded Confucius Institutes; however, broader research-security, export-control, and sanctions regimes may also implicate North Korea and other nations.
-
Recent NDAA restrictions. Section 238 of the FY 2025 NDAA and Section 215 of the FY 2026 NDAA are part of the same research-security trend. Together, they reinforce DoD restrictions on funding certain research collaborations or researchers involving entities identified on the Department's Section 1286 list.
-
Broader national-security policy. The current Administration has continued to broaden this approach through measures directed at foreign adversary access to sensitive technology, data, and research capabilities. Of particular relevance are policies regarding China and other countries of concern, including restrictions on access to sensitive U.S. technologies and data, as well as implementation of the Outbound Investment Security Program, which currently applies to certain U.S. investments involving China, including Hong Kong, and Macau, in specified sensitive technology sectors. Although those regimes generally do not regulate ordinary academic activity, they demonstrate the Administration's willingness to treat apparently ordinary U.S. commercial or research relationships as national-security issues when a foreign adversary is involved.
What to Expect
The audit required by the Directive likely indicates the beginning of a broader process versus just an isolated exercise.
-
Additional university inquiries. DoD and other agencies may expand inquiries to additional research universities, particularly institutions receiving substantial federal research funding, or conducting research in areas such as artificial intelligence, advanced computing, semiconductors, quantum information, biotechnology, aerospace, robotics, hypersonics, advanced materials, and other defense-related technologies.
-
Foreign university relationships. Greater scrutiny is likely to focus on joint research programs, sponsored research, technology licenses, research agreements, visiting scholars, faculty affiliations, foreign-funded laboratories, exchange programs, and arrangements involving foreign universities or research institutes, particularly those connected to governments or military organizations of concern.
-
Research ecosystem participants. Although the Directive is limited to 30 notified academic institutions, similar concerns could be applied in the future to scientific and medical research organizations, research publishers, scientific and technical societies, standards-development organizations, laboratories, professional associations, and other institutions that participate in the U.S. research and technology ecosystem. This could include research institutions where publication, peer review, data sharing, standards development, or access to research infrastructure could be viewed as facilitating the transfer of controlled technology, sensitive data, or other capabilities.
Next Steps
Universities subject to the Directive
Institutions that received the Directive should immediately establish a coordinated response process involving: Research administration, grants and contracts, export controls, sanctions compliance, cybersecurity, technology transfer, and relevant academic leadership. The process should include legal counsel and, where appropriate, preserve attorney-client privilege. The institutions should identify the legal authority for the request (e.g., Directive versus existing government grant or contract requirement), define the scope of responsive information, and create a clear record of the institution's methodology and decision-making. Areas of focus should include:
- foreign gifts, contracts, grants, and other financial support;
- faculty and researcher affiliations with foreign universities, laboratories, companies, or government entities;
- joint research, sponsored research, and technology-development arrangements;
- technology licenses, transfers, and access rights;
- foreign access to research facilities, equipment, data, samples, software, and computing resources;
- visiting researchers, exchange programs, and joint laboratories;
- relationships involving entities on U.S. restricted-party or government-of-concern lists; and
- relationships involving China, Russia, Iran or, where relevant under broader export control, sanctions, or research-security regimes, North Korea and certain other nations, or entities controlled by or closely associated with those governments.
Those institutions should then determine which relationships implicate existing requirements under federal grant rules, Section 117, export controls, sanctions, research-security rules, CFIUS (where a covered transaction or covered real-estate arrangement is involved), or the Outbound Investment Security Program (where the matter involves a covered U.S. investment in China, including Hong Kong or Macau, in a specified sensitive technology sector). They also should consider which relationships should be terminated, mitigated, disclosed, further reviewed, or documented as lower risk.
Institutions not yet subject to the Directive
Universities that have not yet been targeted by the Directive should not assume that they will not be scrutinized. They, and other organizations that participate in the research ecosystem, should consider conducting a proactive foreign-relationship audit, prioritizing higher-risk research areas and jurisdictions, testing their ability to identify foreign support and affiliations across decentralized units, and preparing a response protocol in the event of a federal inquiry.
For both categories of institutions, the goal should not be automatic termination of foreign academic or scientific relationships, but rather a disciplined process to: (1) identify relevant relationships, (2) classify the risks, (3) consider whether any such relationships should be altered, terminated, or otherwise mitigated to address legal or national-security concerns, (4) document the basis for continuing lower-risk relationships, and (5) ensure that the institution can respond promptly and accurately if a federal agency requests information.
+++
The significance of the Directive is not simply that DoD has selected approximately 30 universities for an audit, but rather that it marks a material shift toward systematic governmental scrutiny of the foreign relationships underlying and integral to the U.S. research and higher education system.
Burt Braverman is a partner in Davis Wright Tremaine's Washington, D.C., office, Thomas Schroeder is a partner in the firm's Seattle office, and Jean Tom is a partner in our San Francisco office. DWT's national security, higher education, and tax-exempt organizations teams have substantial experience in assisting clients in responding to government audits in the higher education, research, and national security sectors. Please contact us if your institution is the subject of the Directive or if you wish to conduct a proactive foreign relationship review to ensure that your institution is prepared to respond to a federal audit. To stay informed, sign up for our alerts.
[1] DefenseScoop identified the institutions based on information provided by a U.S. official.