TRAFEED

Data Sovereignty and Export Control in the Age of AI: How Should We Protect What We Hand to AI?

Published2026-07-25Ryuta Hamamoto

Handing technology to an overseas partner, or a deemed export, is checked strictly under Japan's Foreign Exchange Act, yet feeding technical information into a cloud AI is not clearly held to the same framework. This piece sets out that gap using primary sources such as the Foreign Exchange Act, the US CLOUD Act and China's National Intelligence Law, and argues how Japanese companies should protect their data sovereignty.

Data Sovereignty and Export Control in the Age of AI: How Should We Protect What We Hand to AI?
シェア

Hello, this is Ryuta Hamamoto from TIMEWELL.

These days we hand some piece of information to an AI almost every day. We ask it to summarise meeting notes, we load in a design document and ask questions, we have it draft a contract. There is a real sense that things have become easier, and yet every so often I stop and wonder: where, exactly, did that information go?

The question carries more weight than it seems. If you were to hand the same information to an overseas trading partner, there are situations in Japan where a check under the law becomes necessary. Yet when you feed that information into an AI, it is hard to say the act is treated with the same rigour. In this article I take that mismatch as my starting point and think through how we should protect data sovereignty in the age of AI, working from primary legal sources as I go. For the factual parts I show the basis in footnotes, and I keep the parts that are my own opinion clearly separate, labelling them as "my view."

When you hand technology overseas, Japan has strict rules

Let me set the ground first. Japan has a system for managing "the handing of technology overseas." At its centre sits the Foreign Exchange and Foreign Trade Act, commonly the Foreign Exchange Act1.

When people hear "export," they may picture goods such as machines or parts being carried away by ship. But the Foreign Exchange Act does not manage only goods. The provision of technology itself is also covered. This is called a service transaction. A transaction in which you provide technology related to the design, manufacture or use of a specific type of cargo to a non-resident (put simply, a person or entity whose base of life or activity is overseas), or provide it within a specific country, can require the permission of the Minister of Economy, Trade and Industry2.

In recent years, in addition, the operation of an idea called the deemed export was clarified. This was a revision that took effect in May 20223. What it means is this: even when the counterparty is a resident inside Japan, if that person falls into certain categories under strong influence from a foreign government or a foreign entity (the "specified categories"), providing technology to them is treated as a provision to a non-resident, that is, as an export, and managed accordingly. The categories in mind include being under someone's direction through an employment contract, or having an arrangement to receive substantial benefit from a foreign government and the like.

The outline sharpens once you put it into concrete scenes. You share a technical document on screen during an online meeting with an overseas base. You take a laptop containing technical information on an overseas business trip. You explain a drawing or a specification out loud on site. Depending on the situation, acts like these can amount to the provision of technology, and become subject to an advance classification (a judgment of whether something is a controlled item) or a check on whether a licence is needed. At Japanese companies and research institutions, this kind of checking is already taking root as everyday practice.

If you are now wondering how well your own export control is set up, take a moment to check where you stand with our free export control self-check. In a few minutes you can see the areas you have not yet got to.

So how is the act of feeding information into an AI treated?

This is the part I most want to raise in this article.

Sharing a technical document on screen with an overseas counterparty already requires a check. What, then, about feeding that very same technical document into a cloud AI model?

Think it through calmly, and in the latter case too the information is moving. Data entered into a cloud AI is, in many cases, processed by way of the systems of a vendor headquartered overseas, or through an overseas data centre (region). Input that contains technical information may effectively be crossing a border. And yet feeding data into an AI can hardly be said to be clearly placed within the Foreign Exchange Act's framework of advance application and licence checks. That is the reality.

This is my problem statement. On one side we agonise over a single screen share; on the other we casually pour sensitive information into an AI. I read this asymmetry as a product of a transitional period, in which the system has not caught up with the change in technology. There is no bad intent here. Operation has simply not kept pace with reality. Which is exactly why, before any rule is put into writing, the side that uses these tools needs to organise its own defences.

To avoid a mix-up, let me add one thing. This export-control issue and the personal-information issue are separate frameworks. On personal information, the Personal Information Protection Commission published an "Alert Regarding the Use of Generative AI Services" on 2 June 20234. It states plainly that personal information entered may be used for the machine learning of a generative AI, and that there is a risk of it being output in a form statistically linked with other information. It asks businesses to confirm sufficiently that the provider of the generative AI will not use that input data for machine learning. In the personal-information field, in other words, a guideline saying "confirm how your input data is handled" has already come first. My view is that we are moving into an era in which the same way of thinking, the same kind of confirmation, will be expected for technical information and trade secrets too.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

How far can we trust the promise that "we do not use it for training"?

Many of the major AI vendors state, in their services for businesses, that "we do not use your input data for training." This is an important premise, and I take it that it is genuinely being operated as stated. I have no intention of naming a specific company and casting doubt on it, and this is not going to be that kind of article.

Still, step back and look at the structure, and you notice two limits.

One is that adherence to that promise depends in part on the vendor's stance and how the contract is operated. Default settings, differences between contract plans, and revisions to the terms all leave room for the handling to change.

The other, and the more fundamental one, is that a vendor is structurally subject to the laws of the country where it is located. This is a part that no single company's goodwill can resolve, and it is worth holding onto neutrally, as a matter of law.

The United States, for example, has the CLOUD Act (Clarifying Lawful Overseas Use of Data Act), enacted in 20185. This law established a mechanism that can impose on US communications providers and cloud providers an obligation to preserve and disclose the data they hold or control, regardless of whether it is stored inside or outside the United States. This is written clearly into the newly added Section 2713 of Title 18 of the United States Code. It presupposes due legal process, but by design, whether the data sits on a server inside Japan does not change whether that obligation applies.

China, meanwhile, has the National Intelligence Law. Enacted in 2017, its Article 7 provides that any organisation and any citizen shall support, assist and cooperate with the state's intelligence work in accordance with the law6. In addition, the Data Security Law, which took effect in September 2021, establishes a framework for focused management of data bearing on national security and important public interests, and provides that the authorities may obtain data within the scope necessary for safeguarding national security and for criminal investigation7.

I will say it again: this is not a story about which country is bad. It is an explanation of a structure, in which each country arranges its own jurisdiction for the sake of its own security. What matters is this fact: when we entrust our data to some vendor, on a level separate from whether that vendor is honest, the rules of the jurisdiction the vendor follows can reach our data. As I understand it, this is not a question of an individual company's trustworthiness but a question of the jurisdiction, the ground beneath it.

Acceptable for commercial dealings, but a different matter for state secrets

Some readers, having got this far, may feel "do we really need to be this nervous about it?" I think that is a fair instinct.

Which is why drawing a line matters, in my view. For everyday general work, such as summarising an internal document or drafting an email, the risks described above will in many cases fall within a range that is acceptable in practice. There are certainly situations where the convenience wins out. To shrink back excessively here and stop using AI altogether would itself be a loss of opportunity.

The issue is the nature of the information. A nation's critical secrets, technology directly tied to security, information bearing on defence or critical infrastructure. Once the information is of this kind, the picture changes entirely. Here, even if the probability is low, the very structure of being exposed to a disclosure demand or a regulatory change under a foreign jurisdiction becomes an unacceptable risk. Once data crosses a border, it leaves our control. For information of an irreversible nature, a low probability is no comfort.

In other words, what you may feed into an AI should be decided not by whether it is convenient, but by how much the information deserves to be protected. That is my view. There is no need to wall everything up inside the country. But a design that separates what must be protected from what need not be is an indispensable foundation for the way we will use AI from here on. If you have an interest in the idea of dual use (the property of being usable for both civilian and military purposes), I would also point you to a piece setting out what dual-use items are. It sharpens the sense for telling what is sensitive.

The world is starting to talk about "open AI" and "sovereignty" together

This concern is not Japan's alone. In the global debate over AI, the word sovereignty has begun to be spoken about head-on.

There is a symbolic move. On 24 July 2026, NVIDIA's CEO, Jensen Huang, shared a joint statement in support of open weights on X (formerly Twitter)8. An open-weight model is an AI model that anyone can download, inspect the internals of, modify, and run on their own infrastructure. The statement argues that it is precisely such open models that avoid lock-in to a specific vendor and support a state in which an organisation can choose for itself how it manages its own data and where it deploys, in other words its sovereignty.

The statement is not a rejection of closed models. If anything, it advocates a pluralistic ecosystem that includes both open and closed models. I share that posture. Closed models have their own role, and there are things only open models can do. What matters is not to entrust everything to one side or the other. I dig into the substance of this statement and its implications for Japanese companies in a piece on open weights and American AI leadership.

The moves of national governments point the same way. Both the United States and China have begun arranging regulations and policies around the handling of AI models and data, from the standpoint of their own industry and security. Where you source your models from, and where you place your data. This is no longer a matter of technology selection but is becoming a management decision that bears on business continuity and security.

A proposal: Japanese companies should re-frame "providing data to AI" as something to be managed

From here I write clearly as my own view.

The trend from here, I believe, will move toward treating "the provision of data to AI" strictly, as continuous with export control and information management. In the same spirit that providing technology overseas requires a check, an operation that asks for an advance judgment and a record before feeding sensitive information into an AI will spread. Rather than waiting for the system to be put into writing, a company that arranges its own rules ahead of time is, in the end, safer and more resilient.

On that basis, I would like to propose three directions to Japanese companies and institutions.

First, add open-weight models and domestically built models to your options. If you keep hold of a model you can run on your own infrastructure, you avoid a situation in which your business is swung wholesale by a single vendor's terms or by a change in that country's jurisdiction.

Second, place data and servers inside the country. For information that must be protected, keep yourself in a state where you can explain where it physically sits and under which country's laws it falls. This, I think, is the substance of data sovereignty.

Third, domesticate the very execution environment in which the AI model runs. If you can complete everything, from input through processing to output, under the application of Japanese law, then the structural risk of a disclosure demand under a foreign jurisdiction never even comes onto the field.

Of course, closing everything inside the country is not always the right answer. Look at the use and the nature of the information, and combine open and closed models, domestic environments and overseas services. That design is exactly where the skill of information management will show, from here on.

The reason we offer services in this area is that we feel we are getting somewhere with this very challenge. TRAFEED is an AI agent that supports the practical work of export control, streamlining procedures such as classification and checking trading partners, which used to take people and time. It is, in short, a tool that helps with the work of telling what may be sent overseas. And ZEROCK is an enterprise AI that runs on domestic servers. It is designed to put internal knowledge to use without letting it leave the company, under the application of Japanese law. Both were born to face head-on the question we have been discussing today: how to protect the information we hand to AI.

To sum up

It ran long, so let me organise the key points.

  • Providing technology overseas and deemed exports can be subject to classification and licence checks under the Foreign Exchange Act. Sharing documents in an online meeting, or taking a PC overseas, can also fall in scope depending on the situation
  • Feeding information into a cloud AI, by contrast, can hardly be said to be clearly handled under the advance procedures of export control, even though the data may effectively flow overseas. This is where the current gap lies (my problem statement)
  • A vendor's declaration that it "does not use input for training" is important, but adherence depends on stance and contract, and it is structurally subject to the laws of the vendor's home country. The US CLOUD Act and China's National Intelligence Law and Data Security Law are examples
  • For general commercial work the risk may be acceptable, but for state secrets and security-related information the structural risk is large. What you may feed in should be decided by the nature of the information, not by convenience
  • As my view, we should re-frame the provision of data to AI as something to be managed, advance the use of open-weight and domestically built models, domesticate data, servers and execution environments, and manage it all under the application of Japanese law

While you wait for the system to firm up, information keeps moving in the meantime. Start by taking stock of what counts as information to be protected for your own company, and from drawing the line for how you let AI handle it. If you would like to review your organisation from both the export-control and the AI-adoption side, please talk to the TRAFEED team. We will start with you from translating the large flow of the system into the practical work in front of you.

References and primary sources

Footnotes

  1. Foreign Exchange and Foreign Trade Act (Act No. 228 of 1949), e-Gov Law Search. https://laws.e-gov.go.jp/law/324AC0000000228

  2. Ministry of Economy, Trade and Industry, "Security Export Control (Provision of Technology / Service Transactions)." https://www.meti.go.jp/policy/anpo/

  3. Ministry of Economy, Trade and Industry, "On the Clarification of Deemed Export Control" (in force from 1 May 2022). https://www.meti.go.jp/policy/anpo/law_document/tutatu/minashi.html

  4. Personal Information Protection Commission, "Alert Regarding the Use of Generative AI Services," 2 June 2023. https://www.ppc.go.jp/news/careful_information/230602_AI_utilize_alert/

  5. CLOUD Act (Clarifying Lawful Overseas Use of Data Act, 2018), Title 18 of the United States Code, Section 2713, US Congress, H.R.4943. https://www.congress.gov/bill/115th-congress/house-bill/4943

  6. National Intelligence Law of the People's Republic of China (2017, in force from 28 June), Article 7, English translation (NPC Observer / China Law Translate). https://npcobserver.com/legislation/national-intelligence-law/

  7. Data Security Law of the People's Republic of China (in force from 1 September 2021), English translation (DigiChina, Stanford University). https://digichina.stanford.edu/work/translation-data-security-law-of-the-peoples-republic-of-china/

  8. Joint statement "Open Weights and American AI Leadership" (24 July 2026, a joint statement by a signatory coalition, shared publicly on X (formerly Twitter) by NVIDIA CEO Jensen Huang). This article is based on the argument of the published statement text. NVIDIA official. https://nvidianews.nvidia.com/

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

シェア

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

無料診断ツール

輸出管理のリスク、見えていますか?

まず5問(約2分・メール不要)のライト診断。必要なら10問本編で詳細レポートまで。

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles