EIC Summary
  1. On August 3, McMahon issued a “National Call to Action” requiring universities to post public statements on their websites about foreign-influence defenses, admissions, and six other reform areas by end of 2026 — no penalties attached, no funding conditions, no statutory mandate.
  2. The letter’s structural novelty is not the underlying policy but the enforcement architecture: making each institution’s self-assessment publicly visible converts reputational pressure into the primary deterrent, standing in for federal sanctions the administration chose not to impose.
  3. A parallel January 2026 GAO report found that the federal agencies actually overseeing research security — DOD, DOE, NASA, NIH, NSF — have not consistently assessed whether their own safeguards prevent discriminatory targeting; the disclosure layer McMahon adds sits on an enforcement base with documented gaps.

On August 3, Secretary of Education Linda McMahon addressed a letter to every university president and governing board member in the United States (U.S. Department of Education, press release, Aug. 3, 2026). She called it a “National Call to Action.” She posed seven questions. She set a deadline of December 31, 2026. And she attached no penalties to non-compliance.

The question worth examining is not the letter’s politics but its mechanics — specifically, what kind of regime it actually creates and whether that regime can do what it claims.

What the letter asks

Six of the seven questions are broad: how will institutions ensure merit-based admissions, protect free speech, hire faculty who represent diverse perspectives, contain costs, and align degree offerings with national workforce needs. These are recurring administration themes and, for institutions, manageable as statements of principle.

The seventh question is narrower and more specific. McMahon asked universities to describe how they will “protect academic programs from foreign influence and safeguard the integrity of the research enterprise” — including preventing foreign actors from improperly influencing “research, academic programming, personnel assignments or student admissions” (ED.gov press release, Aug. 3, 2026; Foley Hoag analysis, August 2026).

Institutions must post their answers prominently on their official websites. Not file them with a regulator. Not submit them to a federal portal. Post them where anyone — journalists, foreign ministries, rival institutions, the institution’s own faculty — can read them.

That is the mechanism. The disclosure is the deterrent.

The architecture and its precedent

The SOX analogy is apt, with one critical qualification. When Congress passed the Sarbanes-Oxley Act in 2002 in the wake of Enron, it required corporate executives to personally certify the accuracy of their financial disclosures — and made false certification a federal crime. The public disclosure was real; so was the sanction for gaming it. The enforcement bit.

McMahon’s letter replicates the first half of that structure and omits the second. Universities are asked to certify publicly what they do to contain foreign influence. They are not asked to certify accurately — there is no false-statement liability, no inspector-general trigger, no mechanism by which a misrepresentation in a website posting becomes a legal event. The deterrent, if there is one, is reputational: a university that publishes a strong foreign-influence posture and then fails to enforce it internally is exposed to embarrassment, not prosecution.

This is not an argument that the architecture is useless. Reputational exposure has real effects on research universities — where faculty retention, grant competitiveness, and international collaboration depend on a credible public standing. A university that declines to post any statement at all is making a visible choice in a political environment where the administration has previously employed funding freezes and grant modifications to influence institutional behavior (Foley Hoag, August 2026). The implicit threat is real even if the letter does not name it.

It is an argument, however, that the regime is architecturally incomplete — transparency without accountability is a pressure instrument, not an enforcement one.

The existing enforcement layer

The McMahon letter does not exist in isolation. It stacks on top of a federal research-security apparatus that already has statutory teeth, even if those teeth are unevenly applied.

Section 117 of the Higher Education Act has long required institutions to disclose foreign gifts and contracts above $250,000. The Trump administration tightened that regime materially in 2025 and 2026: an April 2025 executive order directed robust enforcement of Section 117, including audits and investigations; in January 2026 the Department launched ForeignFundingHigherEd.gov, a public portal where institutions report their data; and in February 2026 the Department formalized an interagency enforcement partnership with the State Department (Ropes & Gray, February 2026; Hogan Lovells, 2026). Non-compliant institutions risk DOJ civil enforcement.

Below that, National Security Presidential Memorandum 33 — issued in January 2021 — requires research universities receiving more than $50 million in annual federal research funding to implement formal research security programs covering cybersecurity, foreign travel security, and export control training. Institutions above that threshold were given one year from the January 2022 OSTP guidance to achieve full implementation (Cornell Research Services, NSPM-33 reference).

McMahon’s letter adds a transparency layer on top of this. The question it does not answer — and the question institutions should be asking — is whether a university that has already implemented NSPM-33 programs and met Section 117 reporting requirements has anything new to do, or whether the Call to Action is primarily a communications exercise: post what you already do, make it visible, claim credit.

What the federal agencies have not done

A January 2026 report from the Government Accountability Office complicates the picture from the federal side. GAO-26-107544 — “Research Security: Agencies Should Assess Safeguards Against Discrimination” — examined whether DOD, DOE, NASA, NIH, and NSF had implemented adequate safeguards to prevent their research security programs from unfairly targeting scientists of Chinese or Asian descent (GAO, GAO-26-107544, January 22, 2026).

The finding was uneven. NIH and NSF showed the strongest adoption of anti-discrimination safeguards: transparent review processes, demographic data collection, multi-level review structures, staff training. But no agency — not one of the five — had formally assessed whether its safeguards “provide reasonable assurance that discrimination will not occur.” NASA and NSF lacked documented risk mitigation processes. DOD provided no comment. DOE disagreed with the findings, citing existing safeguards it declined to enumerate on the record.

The GAO issued seven recommendations. The agencies agreed to some, considered others, and in DOE’s case, disagreed outright (GAO-26-107544).

This is the institutional reality the McMahon letter lands in: a regime where the federal agencies running research security have not closed their own accountability gaps, and universities are now being asked to publicly certify defenses against threats those same agencies inconsistently monitor.

AAUP President Todd Wolfson, responding to the broader letter, drew the relevant line: “Universities should always be accountable to the public they serve. But accountability is not the same as political control” (Forbes, August 10, 2026). That distinction matters more for the research-security question than for the others. Protecting federally funded research from foreign exploitation is a legitimate federal interest. Whether a letter that requires public posting but imposes no verification mechanism actually advances that interest — or substitutes optics for enforcement — is the question the architecture does not answer.

The Ledger — Bosun Predicts

Prediction: Voluntary uptake of the McMahon Call to Action’s research-security component will be strongly correlated with existing NSPM-33 compliance: fewer than one in three doctoral research universities (Carnegie R1/R2 classification) will publish a substantively new research-security statement beyond what their existing compliance pages already disclose, as institutions with functioning research security programs will repackage existing documentation rather than generate fresh commitments. Community colleges and smaller private institutions will show the lowest engagement rates, given neither NSPM-33 nor Section 117 applies at the scale that would have prompted prior investment in research security infrastructure.

Basis: NSPM-33’s $50M funding threshold excludes the majority of Title IV institutions (Cornell Research Services); voluntary-only compliance mechanisms without funding conditions historically underperform in higher education; the Foley Hoag institutional analysis recommends that institutions “monitor peer responses before determining whether engagement serves their interests,” signaling a wait-and-see posture rather than rapid compliance (Foley Hoag, August 2026).

Resolution: An independent survey by ACE, AAU, or AAUP, or an ED.gov compliance tracking publication, on or before March 31, 2027.