TRAFEED

"Is Your Technical Information Leaking?" Speaking at JX LIVE! 2026, Part One: Economic Security and Export Control in the Age of AI

Published2026-08-01Ryuta Hamamoto

On 28 July 2026 I spoke at JX LIVE! 2026, the Japan Association of New Economy's conference at TOKYO NODE in Toranomon Hills. Part one walks through Chapter 1 of our session, "Security x AI Today", with the slides as shown: the administrative sanctions and corporate fines under Japan's FEFTA, the US 50 percent rule that comes back on 10 November 2026, the AI models that actually went dark for 19 days, and the specific categories behind Japan's deemed export rules. Every figure has been re-checked against primary sources.

"Is Your Technical Information Leaking?" Speaking at JX LIVE! 2026, Part One: Economic Security and Export Control in the Age of AI
シェア

This is Ryuta Hamamoto from TIMEWELL.

On 28 July 2026 I spoke at JX LIVE! 2026 - JAPAN TRANSFORMATION, the conference run by the Japan Association of New Economy. The venue was TOKYO NODE at Toranomon Hills, our slot ran from 13:50 to 14:30, and the session was titled "Is your technical information leaking? Economic security and the front line of export control in the age of AI."1

This report comes in two parts. Part one, which you are reading, covers Chapter 1 of the session, "Security x AI Today," which I presented, along with the slides we projected on the day. Part two will cover Chapter 2, the conversation with Shinobu Matsubara of Okayama University and our CTO Kazuki Naito.

One thing to say up front. The deck carried a number of figures that we had assembled in the run-up to the event. When I went back through every source for this article, I found places where a number turned out to be our own aggregation rather than a published statistic, and places where later checking simply did not match what we had shown. I have corrected those inline rather than quietly dropping them. Looking good in a slide matters less than someone reading this later and getting the call right.

Title slide of the session,

From the TIMEWELL session deck, JX LIVE! 2026

A 40-seat room, close to full

JX LIVE! drew more than 600 attendees across the whole event, a record for the conference1. Our session was in a room of roughly 40 seats, and it was close to full.

Export control is, frankly, an unglamorous topic. Next to a panel on new ventures or AI adoption it has no sparkle, and I did not expect a 40-minute slot on it to pull a crowd. That the room filled anyway tells me something has shifted. Economic security is moving out of the compliance function and onto the management agenda.

Three of us were on stage. I moderated and presented Chapter 1, as CEO of TIMEWELL and concurrently a specially appointed associate professor at Shinshu University. I spent fifteen years at Panasonic working on factory automation, edge AI and a stint in Silicon Valley, founded TIMEWELL in 2022, and now build TRAFEED, our export control AI agent.

Kazuki Naito, our CTO, took the engineering side. He spent fourteen years at NTT designing and running large systems that are not allowed to stop. Coming out of an environment where neither downtime nor a wrong answer is acceptable, he is unusually stubborn about making an AI's reasoning traceable.

Our guest was Shinobu Matsubara of Okayama University, a specially appointed administrative officer in the Research Cooperation Division of the Research and Innovation Co-creation Management Department, who built and now runs the university's export control framework and holds both the STC Expert qualification and the comprehensive Security Trade Control Specialist certification (titles as of June 2026). That part of the session is the subject of part two.

We opened with four questions

Leading with regulation usually leaves the audience feeling this is somebody else's problem. So I opened with four questions instead.

Slide asking

From the TIMEWELL session deck, JX LIVE! 2026

You pasted an internal drawing or a specification into a generative AI. You are showing research data to overseas students and researchers. You have never checked who owns your counterparty. You assume the rules are the same as last year.

None of these involves bad intent. The drawing got pasted because someone wanted to finish the job faster. The research data got shared to move a collaboration forward. Nobody checked the parent company because there was no process for checking parent companies.

And yet almost every problematic pathway now under scrutiny worldwide starts at one of those four doors. Looking around the room, some people were nodding and a few visibly stopped nodding. I spent the rest of the session explaining how those four connect to actual rules.

This is not a story about someone at the coalface making a mistake

The next slide was aimed squarely at executives. When I raise export control, the response is often "I'll pass that on to the team." Here is why that is already too late.

Slide titled

From the TIMEWELL session deck, JX LIVE! 2026

Start with the administrative sanction. Article 53(1) of Japan's Foreign Exchange and Foreign Trade Act (FEFTA) lets the Minister of Economy, Trade and Industry prohibit a party that exported controlled goods without a licence from carrying out exports, or from entering into transactions aimed at providing specified technology overseas or to non-residents, for a period of up to three years2. Note the scope. It is not only shipments of goods. Technology transfer transactions are covered too. For a company with overseas revenue this is a sanction that stops the business itself.

On the criminal side the article numbers matter. Unlicensed exports and unlicensed technology transactions fall under Article 69-7(1): up to seven years' imprisonment or a fine of up to 20 million yen, imposable together, and where five times the value of the goods exceeds 20 million yen, up to five times that value. The nuclear-related category under Article 69-7(2) carries up to ten years' imprisonment or a fine of up to 30 million yen2. One drafting point worth knowing: since the amendment that took effect on 1 June 2025, the Japanese term is kōkinkei (imprisonment without the old labour distinction) rather than chōeki.

The "one billion yen" on the slide is the enhanced corporate penalty. Article 72(1) sets a fine of up to one billion yen on a legal person for a violation of Article 69-7(2)2. Two corrections to what the slide implied.

First, the one billion figure applies only to the most serious category. For an ordinary unlicensed export of listed goods, a violation of Article 69-7(1), the corporate ceiling is 700 million yen. Second, one billion is not an absolute cap. The provision reads "up to one billion yen, or where five times the value of the goods involved in the violation exceeds one billion yen, up to five times that value." On a large enough transaction it goes higher.

The note saying "introduced by the 2017 amendment" also needs a qualifier. I checked this against the pre-amendment text on e-Gov. Before 1 October 2017, Article 72(1) simply said that the legal person shall be subject to "the fine prescribed in the relevant Article," with no figures such as one billion or 700 million in it at all. The current wording, with the amounts spelled out, came in through Act No. 38 of 2017, promulgated on 24 May and effective 1 October that year. On that point the slide was right2.

The three-year period in Article 53(1), by contrast, was already sitting in the statute before that amendment2. Presenting the two as if both arrived in 2017 is wrong, so I am fixing it here.

The chart on the right is our own classification of enforcement cases published by METI. Sixty-four percent traced back to the classification process itself, and eight percent to insufficient awareness of the law. Let me be precise about what that is. It is not an official statistic, and we have not set out the period covered, the sample size or the classification criteria anywhere in this article. Please read it as our own reading of the published cases, not as a figure to cite.

What I wanted the chart to carry is that most violations are neither carelessness nor malice. They come from how classification gets done. The procedure lives in one person's head, the reasoning is not recorded, and nobody can check it afterwards. Keep exporting on that basis and eventually something slips through. Criminal liability turns on intent, but the administrative sanction can attach to negligence. That is precisely why this belongs on the management agenda.

Why the rules keep piling up

There is a simple reason regulation keeps tightening. There are more conflicts.

Slide titled

From the TIMEWELL session deck, JX LIVE! 2026. The durations are our own reckoning, counted to the day of the session, 28 July 2026

Those were the three I put side by side: four years and five months for the invasion of Ukraine, eight months for tensions between Japan and China around Taiwan, five months for the crisis around the Strait of Hormuz. The last two were both added within the past year. Each conflict prompts every country to add its own measures, and the earlier measures do not go away. They accumulate.

Slide titled

From the TIMEWELL session deck, JX LIVE! 2026

Let me restate the source for that 178 properly. JETRO's Global Trade and Investment Report 2025, Chapter III, breaks down the Ukraine-related trade measures in force as of 30 June 2025: 89 export restrictions or prohibitions, 66 import restrictions or prohibitions, and 23 other trade restriction measures3. Add those three and you get 178.

But "178" appears nowhere in the JETRO document. We added it up ourselves. The same exhibit also lists 6 licensing or authorisation requirements and 10 trade liberalising measures such as tariff exemptions for Ukrainian goods, which brings the full total to 194. And the underlying data is not JETRO's own count. The exhibit is compiled from the International Trade Centre's Number of Temporary Trade Measures Related to the War in Ukraine.

This may read as pedantry. In export control practice, though, getting the layer of a source wrong is how judgements drift. Present a secondary aggregation to your board as if it were a primary statistic and it will come back at you. I am correcting it partly as a note to self.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

"We don't sell there" is not a defence

This was the part of Chapter 1 that landed hardest.

Slide stating that an estimated 90 percent of Russian weapons contain Japanese-made components, citing an estimate attributed to the Ukrainian government, noting that Japanese-made parts are said to be found in Russian missiles and drones

From the TIMEWELL session deck, JX LIVE! 2026

I went looking for a primary source for that 90 percent while preparing this article. I could not find one.

The War&Sanctions portal run by Ukraine's Defence Intelligence publishes a database of foreign-made components recovered from Russian weapons. As of the 25 May 2026 update it lists 5,816 components across 202 weapon units, and Japanese electronic component and precision instrument makers appear among the listed manufacturers4. What it does not publish is any breakdown by country of manufacture. There is no figure there corresponding to 90 percent.

So this article does not use that number. Here is what can be stated: the database of foreign components recovered from Russian weapons includes a substantial number of products from manufacturers in many countries, Japan among them. That is as far as the evidence goes.

Something else I may not have said clearly enough on the day. A product appearing in that database is not a finding that its maker breached any rule, nor a finding that anyone intended military use. The closer reading is that commercial parts were sold in ordinary transactions and had their destination rewritten somewhere far downstream, outside the maker's sight. Pointing fingers at those companies would be entirely misplaced.

The problem sits in the structure of distribution, not in the conduct of those firms.

Slide showing the pathway by which a company that

From the TIMEWELL session deck, JX LIVE! 2026. The slide credits reporting including The New York Times of 12 July 2026

A Japanese manufacturer sells semiconductors, machine tools or communications gear as an ordinary commercial transaction. A domestic procurement operation buys them and routes them through a third country such as Vietnam, Sri Lanka or Uzbekistan. They arrive in Russia and end up inside a weapon. That was the chain I showed.

The middle box on the slide reproduces what the reporting we cited described. That needs a caveat, and I would rather give it plainly. It sits at the reporting stage, no court has ruled on it, and in preparing this article I was not able to work from the original piece, so none of it is something we have independently established. Take it as the shape of a route and nothing more.

From the exporter's seat, nowhere in that chain does a document appear with "destination: Russia" written on it. The contract counterparty is a domestic company, and everything beyond that sits outside your control. Looking only at the destination country on the paperwork will not surface this. That was the point of the slide.

None of which means you should try to trace every downstream flow. What is realistic is having a procedure for checking who your counterparty actually is. Who holds the shares. Who ultimately controls it. Whether there is any connection to a control list. Which leads directly into the next section.

The rules are not the same as last year

Talk to export control staff and you often hear "we set this up last year, we're fine." I put that on the opening slide because the past twelve months have been unusually turbulent.

Timeline slide titled

From the TIMEWELL session deck, JX LIVE! 2026

Two entries on that timeline need correcting.

The first is "October 2025, Japan amends FEFTA." What took effect on 9 October 2025 was not an amendment to the Act itself. It was a set of changes at the level of cabinet order, ministerial ordinance and notification, made under Articles 48 and 25 of FEFTA, and it is properly called the revision of the complementary export controls, that is, the catch-all controls for conventional weapons5. In substance it added end-use and end-user requirements for specified items destined for countries outside Group A, added an end-user requirement across all covered items for countries under UN arms embargoes, and made the "inform" mechanism available even for Group A destinations where there is a diversion concern. I have written up the mechanics in what changed in Japan's catch-all controls.

The second is "November 2025, EU control list update." What the European Commission publishes for 2025 is the 17th package adopted on 20 May, the 18th on 18 July and the 19th on 23 October6. A separate listing update in November may well have happened, but I could not pin it down at the level of the Official Journal, so this article replaces that entry with "23 October 2025, EU 19th sanctions package."

Correcting the dates does not change the argument. One single rule changed shape three times in a year. The procedure your team wrote last year is quite likely no longer aligned with the rules in force.

On 10 November 2026, the 50 percent rule comes back

I spent extra time on the item at the right-hand end of that timeline.

Slide reading

From the TIMEWELL session deck, JX LIVE! 2026

Here the primary sources are clean. On 30 September 2025 the Bureau of Industry and Security published an interim final rule, "Expansion of End-User Controls To Cover Affiliates of Certain Listed Entities," effective 29 September 2025 (90 FR 47201). Its abstract states that any entity at least 50 percent owned by one or more entities on the Entity List becomes automatically subject to Entity List restrictions itself7.

Roughly six weeks later, BIS published "One Year Suspension of Expansion of End-User Controls for Affiliates of Certain Listed Entities" (90 FR 50857, published 12 November 2025). The DATES section reads: effective 10 November 2025, the amendments made by the interim final rule published at 90 FR 47201 on 30 September 2025 are stayed until 9 November 20268.

So the suspension runs from 10 November 2025 to 9 November 2026. Unless BIS takes further action, the original rule regains effect on 10 November 2026. Counting from the day I spoke, 28 July, that was exactly 105 days out. As I write on 1 August 2026, it is 101.

Strictly, this is a stay of the amendments rather than a repeal, which is why I described it as returning automatically. Nothing new has to be decided. Leave it alone and it comes back. I have set out how to read the rule, with worked ownership examples, in the complete guide to the BIS 50 percent rule.

Slide titled

From the TIMEWELL session deck, JX LIVE! 2026

The operational difficulty is that name matching does not solve this.

Company A is on the Entity List. Its subsidiary, Company B, is not named anywhere. You trade with Company B. Run every list search you like and B will not come back as a hit. Only by tracing B's shareholders and establishing that A holds 50 percent or more do you find out that B is in scope.

What that demands is not a match against your counterparty master, but a walk up the ownership chain. Corporate records overseas come in different languages under different registry regimes, and even the legal form suffix moves around between filings. How far up do you trace, and where do you stop? Drawing that line is a management decision, not a task you can hand to the compliance desk.

Now to the AI part

Everything so far concerned physical goods. Here the subject changes.

Slide asking

From the TIMEWELL session deck, JX LIVE! 2026

Most companies still treat an AI model as ordinary software. Something available when you want it, something that does not stop if you keep paying. In June 2026 it stopped.

According to Anthropic's own announcement, on Friday 12 June 2026 the US government applied export controls to Claude Fable 5 and Claude Mythos 59. The company restricted access to both models in response. The sequence runs like this: Fable 5 and Mythos 5 were released on 9 June, export controls were applied and access suspended three days later on 12 June, on 26 June the US government approved resumption for certain organisations inside the United States for Mythos 5, on 30 June the controls on both models were lifted, and on 1 July Fable 5 returned globally.

The 19 on the slide is the gap from suspension to global return for Fable 5. Mythos 5 started coming back earlier, on 26 June for a subset of US organisations, so 14 days for that one. Saying both models were fully dark for 19 days is not accurate, and I am correcting it.

I also want to fix how I phrased the scope on the day. I said non-US persons lost access worldwide. Anthropic's announcement states that, because nationality could not be verified in real time, the company suspended access to both models for all users, US persons included9. It was not a case of foreigners being locked out. A US company using the model inside the US lost it too. That is arguably the more useful fact for an executive audience, because it kills the reflex of "we're a Japanese company, this doesn't reach us."

For the 12-day GPT-5.6 delay on the right of that chart, I could not obtain a primary source. OpenRouter's model catalogue lists the GPT-5.6 models with a date of 9 July 2026, but that is a catalogue entry rather than a statement from the provider, and I could not reach an official source for the originally scheduled date or the reason for any delay. I am not treating it as a figure here, only noting that we presented it in the session as reported information.

Slide titled

From the TIMEWELL session deck, JX LIVE! 2026

Looking back, framing this slide around "enclosure" was one-sided.

Anthropic's announcement is explicit that the immediate trigger for the 12 June action was research by Amazon that identified a way to circumvent Fable 5's safeguards, which raised the prospect of the model being used to find and demonstrate software vulnerabilities9. That reads less like geopolitical enclosure and more like a measure arising from a safety evaluation. Leave the trigger out and you end up with a one-sided indictment of the US government.

On the Chinese side, the slide itself said "reported," and that is where it stands as of July 2026. I have not confirmed anything as an official announcement from MOFCOM or the Cyberspace Administration of China.

With those caveats, here is my own reading. AI models are starting to be treated as something closer to weapons than to software. That is my interpretation, not a statement of fact. The formal regime has not caught up, but the practical handling is already there. I have written up the incident and what follows from it in when AI models became subject to export control.

Where you source AI from is now a security question

If a model can be switched off, sourcing becomes the next question.

Slide titled

From the TIMEWELL session deck, JX LIVE! 2026. Presented as usage data from OpenRouter as reported by CNBC on 7 July 2026

I could not verify these three figures against a primary source while writing this up. I found neither the underlying data in the CNBC piece nor usage share figures in OpenRouter's public API. So I am not asserting them. They were presented in the session as reported data, and that is where I will leave them.

Precision aside, the direction matches what I see in the field. Open-weight Chinese models are attractive on both capability and cost, and US companies are experimenting with them. Which means the question of where you source your AI has stopped being a purely technical call.

Slide titled

From the TIMEWELL session deck, JX LIVE! 2026

The structure on the left stands as presented. You have operations. Some of them are handed to an AI. That AI resolves to a single vendor's API. And a decision by that vendor's government can halt it with one instruction. In June, that happened.

The right-hand side needs three corrections.

First, the open letter "Open Weights and American AI Leadership," dated 24 July 2026, did not go from 25 signatories to about 50. Checking the letter PDF hosted by NVIDIA, the signatory list runs to 235 companies10. Amazon, AMD, Cisco, Cloudflare, Databricks, Dell, Google, Hugging Face, IBM, Intel, Meta, Microsoft, Mistral, Mozilla, Nokia, NVIDIA, Palantir, Red Hat, SAP, Siemens, Snowflake, SpaceX, Uber, Y Combinator and The Linux Foundation are all on it.

Second, "OpenAI and Anthropic did not sign" is wrong. OpenAI is on the signatory list. Anthropic is the one that is not.

Third, the "one quarter of tokens" figure attributed to the letter is not in the letter. There is no token share statistic in the text at all. I had the attribution wrong, and since I do not have an alternative primary source, I am dropping the number.

Anthropic's position deserves to be stated carefully as well. On 27 July 2026 the company published "Our position on open-weights models," agreeing with much of the letter while dissenting from parts of it, and stating explicitly that it has never advocated for a ban on open-weights models11. Reading non-signature as opposition to open models would misrepresent what happened.

The core argument survives all of that. The question has moved from "which AI do we use" to "what do we switch to when it stops." Running critical operations on a single API with no alternative in place is getting hard to justify on business continuity grounds alone.

"It's in the cloud, so it's safe"?

The last piece of the AI section was about where data lives.

Slide asking

From the TIMEWELL session deck, JX LIVE! 2026

The US CLOUD Act is Division V of the Consolidated Appropriations Act, 2018, enacted on 23 March 2018. It created 18 U.S.C. §2713, which requires a provider to preserve and disclose the contents of communications and records within its possession, custody or control "regardless of whether such communication, record, or other information is located within or outside of the United States"12. Sitting in a data centre in Japan does not take it out of scope if a US company holds it.

China's National Intelligence Law was passed on 27 June 2017 and took effect the following day. Article 7 provides that any organisation or citizen shall support, assist and cooperate with national intelligence work in accordance with law, and Article 14 provides that intelligence institutions may request necessary support, assistance and cooperation from relevant organs, organisations and citizens13.

Neutrality matters here. The same statute contains Article 8, which provides that national intelligence work shall be conducted in accordance with law, shall respect and protect human rights, and shall safeguard the lawful rights and interests of individuals and organisations. Quoting Articles 7 and 14 alone, without that, is not a fair reading of the text. The law was also partially amended on 27 April 2018. I go through how the Chinese framework plays out in practice in the anti-espionage and national intelligence laws and Japanese companies.

Either way the operational conclusion is the same. What determines exposure is not where the data physically sits but which country's company holds it. Judging safety on physical location alone will catch you out. On drawing the line for what you hand to an AI in the first place, see data sovereignty and export control in the age of AI.

AI is starting to acquire a body

Towards the end of Chapter 1 I mapped how the scope of control has widened.

Slide titled

From the TIMEWELL session deck, JX LIVE! 2026

AI has lived inside a screen. It wrote text, wrote code, produced images, and never stood in the same room as a person. That is changing. The line along the bottom of the slide is the whole point of this section: when the judgement is wrong, it no longer stays inside the screen.

Slide titled

From the TIMEWELL session deck, JX LIVE! 2026. The slide credits Omdia, a commercial research firm (January 2026), and press reporting. We have not been able to reach primary information for these figures, so the three numbers are not treated as established fact in the text below

I did put those production figures on screen. They rest on a commercial research firm's estimate and on press reporting, and I was unable to get back to primary information while writing this up, so I am not leaning on the numbers. What I will say is qualitative: volume production of humanoid robots, centred on China, is moving from prospect to reality.

Slide titled

From the TIMEWELL session deck, JX LIVE! 2026

Those three stages are a useful way to see where this is heading. Goods have always been in scope, through controls on parts and equipment. AI models are in scope now, as June 2026 demonstrated. Machines are next.

A robot is both a physical good and a piece of software. Hardware export control, control of the model running on it, and control of software delivered by remote update all land on the same product at once. Which regime applies, and how, is nowhere near settled. Honestly, regulators and companies are both feeling their way here.

You want to hire the best people. Are you sure that's clean?

Goods, then data, and finally people. This one matters as much to university administrators as to corporate HR.

Slide asking

From the TIMEWELL session deck, JX LIVE! 2026

Three things on this slide need fixing. Anyone using it in practice would be misled otherwise, so I went back to the underlying notification text.

Start with the label. I called them the three categories of deemed export. That is imprecise. Deemed export control governs technology transfer transactions from a resident to a non-resident. The three items here are the specific categories, meaning categories of residents who are under strong influence from a non-resident. Providing controlled technology to a resident falling into a specific category is what constitutes a "specific transaction" subject to control.

The text itself reads as follows14.

Specific category 1 covers a person who has concluded an employment or similar contract with a foreign juridical person or a foreign government, and who is subject to that entity's direction and supervision or owes it a duty of care. There are carve-outs, including where it has been agreed that the Japanese entity's direction takes precedence.

Specific category 2 covers a person who receives, or has agreed to receive, a substantial sum of money or other significant benefit from a foreign government, with "substantial" defined as money or other benefit accounting for 25 percent or more of that person's annual income when converted to monetary terms. The slide said "25 percent of annual salary"; the text says annual income. More importantly, the source of the benefit is limited to a foreign government or equivalent. Remuneration from a foreign company does not fall under category 2.

Specific category 3 covers a person who receives instructions or requests from a foreign government or equivalent with respect to their conduct within Japan. The slide rendered this as "designated by the Japanese government as being under the strong influence of a foreign government," which is plainly wrong. Being flagged by Japanese authorities is not the test. Receiving instructions or requests from a foreign government is the test. Copy the wrong version into an internal procedure and the whole workflow goes sideways, so I want the correction on the record.

The legal basis is the notification issued under Article 25(1) of FEFTA and Article 17(2) of the Foreign Exchange Order (No. 492 of 21 December 1992), as amended on 18 November 2021, with application starting 1 May 202214. Where a resident falls into any one of these categories, a licence must be obtained before the controlled technology is provided. The party applying for that licence is the one providing the technology, meaning the company or the university.

There is one more set of caveats that METI repeats throughout its own materials, and it is the part practitioners most often get wrong. The specific categories group together the situations that warrant an individual review. Falling into one does not mean the person is regarded as a security concern. Nor does the clarification place any new licence-application duty on the employee. And the practice of taking a written pledge applies regardless of nationality: METI states plainly that it is not intended as a means of treating foreign nationals differently15.

I raised this on stage not to make anyone hesitant about hiring good people, but for the opposite reason. Organisations without a settled checking procedure tend to brace far beyond what the law asks. Decide in advance what gets checked, for whom, and at what moment, and hiring itself can carry on.

How this plays out inside a university is something Matsubara covers in part two. For the corporate view, see understanding the specific categories in five minutes; for building a framework at a university, see export control basics for universities.

Get the defence right and you can go on the offensive

To close Chapter 1, I compressed everything into three lines.

Slide titled

From the TIMEWELL session deck, JX LIVE! 2026

For goods, trace your counterparties up to the parent. For data, decide in advance what you are willing to hand an AI. For people, check before you hire. Those three are the defensive investment.

Calling it "defence" makes it sound like a cost line. I read it the other way. A company that has not covered those three cannot press an advantage abroad. Entering a new market while carrying an unquantified risk that your export licences get pulled is driving onto a motorway without brakes. Same with AI: without a fallback, you cannot responsibly let it near anything critical.

Weak defence is what stops you attacking. Which means the companies that have covered it are the ones free to move.

Slide titled

From the TIMEWELL session deck, JX LIVE! 2026

I ended Chapter 1 with three questions.

On business: if your export licence were suspended for three years, how much of your revenue stops? On technology: if the AI you depend on stopped tomorrow, what do you switch to? On organisation: who decides those two, and by when?

None of the three can be answered at the working level. Quantifying the revenue impact means touching the business plan, choosing an AI fallback means an investment decision, and setting a deadline means authority. What I kept coming back to in the room was one line: economic security is not a compliance cost, it is the investment that lets you keep earning overseas.

Part two: what it looks like on the ground

That is Chapter 1. We covered the regime and the global picture in the first half of the 40 minutes, and honestly, it is not enough on its own.

Explain the rules and people tend to respond with a look that says, fine, but where do we start? The answer differs by company and by university. So Chapter 2 was built around someone who has actually built and run a framework.

We prepared three questions. For Matsubara, what is hardest right now on the ground at a university. For Naito, how far you can actually delegate to an AI. And then, for all three of us, what to do first when your team is small.

Part two, on running university export control with a team of six, goes into how export control actually works at Okayama University, drawing on the materials Matsubara shared with us, and into where Naito draws the line on what an AI is allowed to decide.

Summary

  • On 28 July 2026 TIMEWELL held a sponsor session at JX LIVE! 2026 at TOKYO NODE, Toranomon Hills. The conference drew a record 600-plus attendees overall, and our own room of roughly 40 seats was close to full
  • Japan's administrative sanction under FEFTA Article 53(1) runs up to three years and covers both exports of goods and technology transfer transactions. Corporate penalties under Article 72(1) reach one billion yen for the most serious category (Article 69-7(2)) and 700 million yen for ordinary unlicensed exports (Article 69-7(1)), with an uplift where five times the transaction value is higher
  • The US 50 percent rule is stayed, not repealed. It regains effect on 10 November 2026. Name matching will not catch affiliates; you have to trace ownership
  • In June 2026 AI models genuinely stopped, and the suspension covered US persons too. "We're a Japanese company" is not a reason to sit this out
  • Specific category 3 under Japan's deemed export rules turns on receiving instructions or requests from a foreign government, not on being flagged by the Japanese government. I have corrected the slide accordingly
  • The three questions for management: revenue exposure if licences stop, the fallback if your AI stops, and who decides both by when
  • Placement on a control list is a regulatory designation, not a judgement on the merits of the company or institution named. Nor is the appearance of a component in a recovered-parts database a finding that its manufacturer breached anything

Going back through the deck source by source was not a comfortable exercise. Numbers I stated confidently on stage turned out to have murky provenance, or to have been overtaken. But skipping that step and publishing anyway is not an option in this field. Export control is an area where a procedure built on a wrong premise surfaces years later. So we correct what we got wrong. That is all there is to it.

Control lists in each jurisdiction update on their own schedules, in their own languages. We built TRAFEED to ingest regulatory updates the day they land and to support counterparty screening and classification, because keeping up with that cadence and that many languages by hand is unrealistic. It is the world's first(*) export control AI agent, though the final classification and the decision on whether a transaction proceeds belong to each company's export control officer. Our job is to put the material for that decision in front of them, sourced and complete.

If you are not sure where to start reviewing your own framework, talk to the TRAFEED team.

(*) As an AI agent in the field of Japanese security export control (list controls and catch-all controls), confirmed by our own internal research as of March 2026.

Sources

Footnotes

  1. TIMEWELL Inc., "TIMEWELL speaks at the Japan Association of New Economy's JX LIVE! 2026 on economic security and export control in the age of AI," PR TIMES, 31 July 2026 https://prtimes.jp/main/html/rd/p/000000138.000119271.html 2

  2. Foreign Exchange and Foreign Trade Act (Act No. 228 of 1949), Articles 53(1), 69-7 and 72(1). e-Gov law search, version in force from 23 July 2026 https://laws.e-gov.go.jp/law/324AC0000000228 2 3 4 5

  3. JETRO, Global Trade and Investment Report 2025, Chapter III "Trends in global trade rule-making," Exhibit III-6. Underlying data from the International Trade Centre, "Number of Temporary Trade Measures Related to the War in Ukraine" (registrations as of 30 June 2025) https://www.jetro.go.jp/ext_images/world/gtir/2025/no3_v3.pdf

  4. Defence Intelligence of Ukraine, War&Sanctions portal, "Components found in russian weapons" (5,816 components across 202 weapon units as of the 25 May 2026 update) https://war-sanctions.gur.gov.ua/en/components

  5. Ministry of Economy, Trade and Industry, Trade and Economic Security Bureau, "Revision of the complementary export controls" (in force 9 October 2025) https://www.meti.go.jp/policy/anpo/apply-01/20251009_catchminaoshi/20251009catchall.html

  6. European Commission, "Sanctions adopted following Russia's military aggression against Ukraine" (17th package 20 May 2025, 18th 18 July 2025, 19th 23 October 2025) https://finance.ec.europa.eu/eu-and-world/sanctions-restrictive-measures/sanctions-adopted-following-russias-military-aggression-against-ukraine_en

  7. Bureau of Industry and Security, "Expansion of End-User Controls To Cover Affiliates of Certain Listed Entities" (interim final rule, 90 FR 47201, published 30 September 2025, effective 29 September 2025) https://www.federalregister.gov/documents/2025/09/30/2025-19001/expansion-of-end-user-controls-to-cover-affiliates-of-certain-listed-entities

  8. Bureau of Industry and Security, "One Year Suspension of Expansion of End-User Controls for Affiliates of Certain Listed Entities" (final rule; stay, 90 FR 50857, published 12 November 2025, effective 10 November 2025, stayed until 9 November 2026) https://www.federalregister.gov/documents/2025/11/12/2025-19846/one-year-suspension-of-expansion-of-end-user-controls-for-affiliates-of-certain-listed-entities

  9. Anthropic, "Redeploying Fable 5," 30 June 2026 https://www.anthropic.com/news/redeploying-fable-5 2 3

  10. "Open Weights and American AI Leadership," open letter dated 24 July 2026, 235 signatories https://images.nvidia.com/pdf/Open-Weights-and-American-AI-Leadership.pdf

  11. Anthropic, "Our position on open-weights models," 27 July 2026 https://www.anthropic.com/news/position-open-weights-models

  12. 18 U.S.C. §2713, "Required preservation and disclosure of communications and records" (CLOUD Act, Public Law 115-141 Division V, enacted 23 March 2018) https://www.govinfo.gov/content/pkg/USCODE-2023-title18/html/USCODE-2023-title18-partI-chap121-sec2713.htm

  13. National Intelligence Law of the People's Republic of China, Articles 7, 8 and 14 (passed 27 June 2017, effective 28 June 2017, amended 27 April 2018), National People's Congress http://www.npc.gov.cn/zgrdw/npc/xinwen/2017-06/27/content_2024529.htm

  14. Ministry of Economy, Trade and Industry, notification on transactions or acts involving the provision of technology requiring a licence under Article 25(1) of the Foreign Exchange and Foreign Trade Act and Article 17(2) of the Foreign Exchange Order (No. 492 of 21 December 1992, as amended by No. 1 of 18 November 2021, applicable from 1 May 2022), item 1(3)(sa)(i)-(iii) https://www.meti.go.jp/policy/anpo/law_document/tutatu/t10kaisei/ekimu_tutatu.pdf 2

  15. Ministry of Economy, Trade and Industry, "Deemed export control" (promulgated 18 November 2021, applicable from 1 May 2022) and its explanatory material for company employees. METI states that falling into a specific category does not mean a person is regarded as a security concern, that the clarification imposes no new licence-application obligation on employees themselves, and that the pledge is required regardless of nationality and is not intended to treat foreign nationals in a discriminatory way https://www.meti.go.jp/policy/anpo/anpo07.html

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

シェア

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

無料診断ツール

輸出管理のリスク、見えていますか?

まず5問(約2分・メール不要)のライト診断。必要なら10問本編で詳細レポートまで。

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles