Delft: A materials group here now runs a compliance check before it accepts a visiting doctoral student. Two years ago the same decision belonged entirely to the supervisor.
The shift traces back to the Council recommendation on research security adopted in 2024, which asked member states to identify and manage risks in international research cooperation without closing it down. The recommendation is not binding. Its effect has been to push responsibility down to universities and funding agencies, which now write the rules they will later be audited against.
The Commission published a research security monitor in February that sets out what each country has actually done. The picture it describes is uneven. Some states have created national advisory centres with staff who can read a partnership agreement and flag a problem. Others have issued guidance and left institutions to interpret it. A researcher moving between two member states can therefore face two different answers on the same collaboration.
Universities report the same three difficulties. They lack the intelligence to assess a foreign partner beyond open sources. They lack lawyers who understand both export control and academic freedom. And they face internal resistance from faculties who see screening as a political instrument rather than a risk tool.
A parallel change has made the boundary harder to draw. For the first time since the framework programmes began in 1984, EU research money can fund work with military as well as civil application. The European Innovation Council and the Digital Europe Programme can now back dual-use development with explicit military end use. Institutions that built their reputations on open publication are being asked to host projects whose outputs cannot be published.
Export control law adds a third layer. The Commission has signalled a reform of the dual-use regulation across 2026 to 2028, aimed at faster listing of controlled items and better coordination between national authorities that currently publish separate control lists. Academic exemptions in that regime are narrower than most researchers assume, and a laboratory sending a sample or a dataset abroad can trigger a licence requirement without realising it.
Critics of the direction argue that Europe is importing an American framework without the American funding that pays for compliance staff. They point out that the measurable cost falls on institutions immediately while the benefit is a risk that never materialises, which is a poor basis for a budget line. Supporters reply that the alternative is discovering the problem through a leak rather than a policy.
The honest position is that nobody yet knows the price. No member state has published the administrative cost of research security screening, and until one does, the debate over proportionality will keep running on anecdote.





