Who Really Benefits from Your AI Research and Innovation?

AI research often depends on outside funding and collaboration. The commercial question is not whether to reject international partners; it is whether your organisation understands the people, rights, data access and obligations involved.

Illustration of a research partnership connecting institutions while protecting shared work

What MI5 said—and what it did not establish

On 30 September 2026, MI5 issued a public espionage alert naming the China General Technology Research Institute (CGTRI). The alert alleges that CGTRI funds research, including work in areas such as AI and cybersecurity, in a way that MI5 says can improve the technical capabilities of China’s Ministry of State Security. MI5 said more than 100 UK-linked academics had contributed to research it characterised as MSS-funded through CGTRI, and that some may not have known the ultimate connection.

Those are allegations in an intelligence warning, not a court judgment that every named or connected researcher committed wrongdoing. On 1 October, the Chinese Embassy in the UK rejected the allegations, called them fabricated and said it had made representations. That denial also needs to be reported rather than omitted.

The public alert is a reason for relevant organisations to review funding routes and research protections. It is not proof that every project, academic or institution with an international connection is improper. Avoiding blanket suspicion is part of proportionate due diligence.

Why funding and rights matter to a commercial AI project

AI research can involve universities, businesses, public funders, charities, specialist labs, software vendors and subcontractors. Outside funding can provide expertise, equipment and access to data that a small organisation could not develop alone. The same network can make it harder to see who ultimately controls the funds, who can use the work and where sensitive information may travel.

A collaboration agreement should say who owns pre-existing intellectual property, who owns new code and inventions, what licences each party receives, and whether results can be published or reused. It should distinguish research data from model weights, prompts, software, documentation and derived outputs. If these terms are left vague, a company may find that it cannot protect or commercialise work it paid to develop.

Security also concerns information access. A partner or AI service may receive unpublished results, customer data, proprietary designs, credentials or evaluation materials. Decide which information is essential, who needs access, whether it can be used to train or improve a third-party model, and whether onward sharing is allowed.

Use risk-based checks, not nationality as a shortcut

A practical review begins with the legal entities and people involved: the named funder, any intermediary, beneficial or controlling interests, subcontractors and the ultimate source of funds. Confirm the project purpose and whether the proposed work, data or technology is subject to contractual, export-control or national-security restrictions.

In the UK, the National Security and Investment Act 2021 gives the government powers to scrutinise certain acquisitions that may raise national-security risks. That does not mean every research partnership or funding arrangement is a notifiable acquisition. If a transaction could fall within the Act or another control, seek advice from a qualified professional rather than treating the alert as a legal ruling.

Apply consistent checks to comparable arrangements. Focus on control, access, transfer rights, the sensitivity of the work and the recipient’s ability to meet agreed safeguards. Nationality alone does not establish intent or misconduct; a lack of transparency, unexplained funding route or unusually broad access may justify further review regardless of country.

Write protections into the working arrangement

Before work starts, define the project boundary and data classification. Use least-privilege access, approved storage and named accounts. Keep sensitive material out of consumer AI tools unless they have been formally assessed. Require approval before results or data are passed to another party, and keep records of access and changes.

Agree confidentiality, publication review, ownership and licensing terms before research begins. Set rules for derivative work and third-party AI tools. Document how security incidents are reported, how records are retained and deleted, and what happens to code, equipment and data if the partnership ends.

An SME may not need a large compliance department to do this well. A short due-diligence record can capture who funded the work, who controls the entities, what each party may access, what rights each party receives, which legal or contractual restrictions apply, and who owns ongoing oversight. Escalate unfamiliar risks to legal, security or research-governance advisers.

Collaboration and protection can coexist

MI5’s alert is a prompt to ask more precise questions about the route by which money, data and research rights flow. It is not a reason to abandon useful international collaboration or to treat an unverified accusation as a finding. The same discipline protects commercial value and supports responsible research.

Before entering an AI partnership, establish who funds and controls it, who can access the research, how outputs may be used, and what happens when the arrangement ends. Review those terms as the project changes. For official security guidance, consult the National Protective Security Authority’s Trusted Research material and obtain specialist advice where the work or transaction warrants it.

AI innovation benefits from collaboration, but organisations should understand who controls the data, funding and resulting intellectual property. Clear rights and proportionate checks make that collaboration safer and more commercially useful.

Sources and further reading

Explore AI Governance Review