Mariam, a postdoctoral researcher in cancer biology at a mid-sized Canadian university, first heard the phrase 'foreign talent programme review' seventeen days after her funding renewal passed the grants office. The application itself was clean: three co-authors, no export-controlled equipment, and an assurance that she had spent no time at a Chinese institution since 2019. What triggered the review, the research security officer later told her, was an old conference affiliation listed in a preprint. Her renewal sat in queue for eleven weeks.
During that wait, Mariam taught her course, ran her experiments, and watched two international collaborators book someone else for a shared panel. The review did not accuse her of anything. It simply had no deadline. That is the part of research security policy that rarely appears in institutional statements: the waiting produced by forms, queues, and review software with no service-level expectation.
Since 2018, universities, research funding agencies, and governments in the United States, the United Kingdom, Canada, Australia, and the European Union have tightened rules designed to stop foreign governments from extracting research through state-backed talent recruitment schemes. The largest of these, China's Thousand Talents Plan, has since 2008 offered salaries, grants, and laboratory space in state-funded institutes to researchers willing to keep a formal affiliation with a Chinese university. For a decade, some researchers listed those affiliations on foreign-language websites while omitting them from western grant disclosures. The enforcement push that followed was real.
The United States Department of Justice launched the China Initiative in November 2018. It produced high-profile arrests, including MIT mechanical engineer Gang Chen in January 2021, and collapsed under criticism before being closed in February 2022. Universities did not need the initiative to start building compliance offices; the National Institutes of Health had already begun writing to institutions in 2018 about researchers with undisclosed Chinese funding. What the initiative did was burn one lesson into every research office: a single undisclosed affiliation could become a federal case.
The compliance office has a name now
By 2023, nearly every research-intensive university in North America had appointed a research security officer or repurposed its export-control staff into a broader disclosure team. These offices compile foreign appointments, review travel, screen visiting researchers, and advise faculty on how to disclose a talent programme without admitting fault. The work is technical and often thankless. It also sits inside a larger academic consequence: the National Institutes of Health now publishes detailed guidance on foreign appointments and talent-programme participation, and institutions that miss the reporting can face grant conditions or funding restrictions.
Some of that buildout is serious and well staffed. Other campuses have folded the role into an existing grants officer's duties and called it progress. The difference between the two is not a matter of rhetoric; it shows up in how long a review takes.
Photo by National Cancer Institute on Unsplash
A global patchwork of rules
The United States was not alone in building this apparatus. The United Kingdom's Centre for the Protection of National Infrastructure publishes Trusted Research guidance that asks universities to assess international collaborations for dual-use concerns, state-linked employment, and travel patterns that do not match the stated purpose of a project. Canada's Safeguarding Your Research guidelines require federal grant applicants to disclose affiliations with foreign institutions and military-linked organisations. Australia's universities developed their own foreign interference guidelines after a 2019 taskforce, and the European Commission published a staff working document in January 2022 urging member states to create consistent definitions of foreign interference in research.
For a postdoc moving between systems, the patchwork creates real friction. A disclosure that satisfies one funder may be incomplete for another. The same talent programme can be described as a fellowship by one agency and a recruitment tool by another. Mariam's renewal was reviewed against Canadian guidelines, but two of her co-authors had already been screened under United States rules, and neither process accepted the other's clearance.
Who pays for the gap between policy and capacity
The cost falls unevenly. International early-career researchers, already facing visa timelines and grant cycles, now wait through security reviews that can stretch for months without clear appeal. Some hiring committees quietly deprioritise candidates with talent-programme histories, not because the committee believes the candidate is disloyal, but because the paperwork could delay a start date. The federal funding turbulence tracked in AcademicJobs coverage of United States funding freezes and Title VI compliance has made deans more cautious still: a flagged proposal is a liability in an environment where any disruption can push a lab to the edge.
That caution is not irrational. A research security officer has every reason to ask for more documents; the penalty for missing a foreign tie is higher than the penalty for a slow review. The structure rewards over-disclosure and delay. Universities publish statements that value openness, but their compliance budgets tell a different story. One research security officer at a large public university told me the office had one full-time export-control specialist to cover the entire institution. That is not an accusation; it is an allocation.
What a more workable regime would look like
Universities can change the structure without waiting for federal harmonisation. A handful of institutions have started posting expected review times, defining what counts as an undisclosed affiliation, and giving researchers provisional clearance while documentation is verified. Some funding agencies have adopted disclosure forms that distinguish between active and completed talent-programme roles, instead of treating a 2016 fellowship the same as current employment. That distinction matters for researchers whose only participation ended before the rules existed.
Training helps only if it is concrete. A session that says 'disclose anything that might be relevant' invites over-reporting; one that lists the specific foreign talent programmes, the relevant grant clauses, and an email address for appeals gives a researcher something to act on. The question is whether the institution has the staff to deliver that second kind of training. That is the budget question most annual reports skip.
Photo by Markus Winkler on Unsplash
The number to publish next
Mariam's renewal was eventually cleared in early March, five weeks after she had first been told it was under review. Nothing in the file changed; the queue had simply moved. When she asked why the delay had been so long, the officer said there was no way to know without pulling the audit log, and the audit log belonged to the grants system, not the security office.
That answer points to the next metric universities should publish. Not the number of researchers charged or the number of foreign ties discovered, but the median time from first flag to final clearance, the number of reviews still open after 90 days, the share of flagged researchers who appeal, and the number of international postdocs whose offers collapse while they wait.
Until a campus can publish those numbers, research security will keep being measured by what it stops rather than by what it costs. The gap is not between openness and safety. It is between the policy on the website and the wait time in the queue.
