TRAFEED

Running University Export Control With Six People: Okayama University's Front Line and an AI Agent | JX LIVE! 2026 Session Report (Part 2)

Published2026-08-01Ryuta Hamamoto

Part 2 of our report from TIMEWELL's sponsored session at JX LIVE! 2026, hosted by the Japan Association of New Economy. Shinobu Matsubara of Okayama University showed what export control actually looks like on the ground: an institution of 13,383 students and 4,189 faculty and staff, supported by an export control office of six people of whom exactly one is full-time, processing 2,337 pre-check sheets in FY2024. This piece covers the two problems the university named, what changed after introducing an AI agent, and what our CTO Kazuki Naito said about never betting everything on a single closed AI provider.

Running University Export Control With Six People: Okayama University's Front Line and an AI Agent | JX LIVE! 2026 Session Report (Part 2)
シェア

This is Ryuta Hamamoto from TIMEWELL.

On 28 July 2026, at Toranomon Hills TOKYO NODE, TIMEWELL hosted a sponsored session at JX LIVE! 2026 - JAPAN TRANSFORMATION, the conference run by the Japan Association of New Economy. Our session, "Is Your Technical Information Leaking? Economic Security and the Front Line of Export Control in the Age of AI," ran from 13:50 to 14:30. The room seated roughly forty and was close to full. JX LIVE! as a whole announced a record turnout of more than 600 attendees. My thanks to everyone who came, and to the speakers who joined me.

This report comes in two parts. Part 1 covered Chapter 1 of the session, "Security and AI Today," which I presented: what is happening in the world, and where it connects to your own desk.

This second part covers Chapter 2, "Now Let's Hear From the Front Line." Discussions of regulation and geopolitics stay abstract on their own. What is actually happening where the work gets done? And where can AI fit into that? This was the part I most wanted people to hear.

A quick recap, and the three questions of Chapter 2

Let me restate Part 1 in a sentence or two.

The more crises accumulate, the more regulation piles up. A company whose name appears on no list can still fall within scope once you trace its shareholders. And AI itself is now becoming an object of control: in June 2026, a frontier AI model was actually taken offline by a regulatory decision. You cannot go on the offensive until your defences hold. Economic security is therefore not a compliance cost but an investment in continuing to earn abroad.

That was Chapter 1. The trouble with that kind of material is that it reads as too large to connect with anyone's job. So in Chapter 2 I moved into the moderator's chair and the three of us worked our way down to specifics.

Chapter 2,

From the TIMEWELL session materials, JX LIVE! 2026

The two people who joined me were as follows.

Shinobu Matsubara of Okayama University, an administrative staff member (specially appointed) in the Research Cooperation Division of the Management Department of the Organization for Research and Innovation Co-creation, who holds STC Expert certification and the comprehensive Security Trade Control Specialist qualification, and who has built and run Okayama University's export control arrangements. The title above is as of June 2026.

Kazuki Naito, Director and CTO of TIMEWELL and the person responsible for TRAFEED. He spent fourteen years at NTT working on large-scale systems from design through operations. Mission-critical systems you cannot take offline, in a domain where neither downtime nor error is acceptable.

Because no verbatim transcript exists, what Matsubara and Naito said that day is presented below in substance rather than as direct quotation. Figures and explanations of the regime that appear in the day's materials are quoted as they appear there.

Why export control is hard at a university

Before the main story, let me set out some background. Some readers may be wondering why a university would be involved in export control at all. My sense is that universities being parties to this regime is not widely understood outside the sector.

Say "export control" and most people picture finished products going into a container. But Japan's Foreign Exchange and Foreign Trade Act, usually shortened to FEFTA, does not only govern the movement of goods. The act of providing technology is covered as well. Emailing a design drawing. Teaching someone how to operate an instrument. Sharing analytical results in a joint research project. Depending on the counterparty and the content, all of these can require a government licence.

What makes universities hard is that this provision of technology happens everywhere in the organisation, every day. Let me take the reasons in turn.

1. Researchers are distributed

At a company, exports leave through a limited number of business units. A university, by contrast, is a set of highly autonomous faculties, graduate schools, institutes, a hospital and attached schools, each laboratory running its own themes. There is no structural vantage point from which an administrative office can survey everything about to leave the country.

So most universities operate on prior declaration by faculty and staff. Okayama University's "pre-check sheet" is exactly that. Which also means the system only works if people declare, and that the burden on the receiving side rises in proportion to how internationally active the university is.

2. Universities host international students and foreign researchers

Then there are people. Even without shipping anything abroad, providing technology to a non-resident inside Japan can be treated as an export requiring a licence. This is what is known as deemed export.

Since May 2022, moreover, technology provision to someone residing in Japan can fall within scope if that person is assessed as being under strong influence from a foreign government or foreign entity. METI defines these as "specific categories," and there are three:

  1. A person who has concluded an employment or similar contract with a foreign entity or foreign government and who is subject to that party's direction and supervision, or owes it a duty of care
  2. A person who receives, or has agreed to receive, substantial money or other significant benefit from a foreign government, meaning a benefit that accounts for 25 per cent or more of that person's annual income when converted into monetary terms
  3. A person who receives instructions or requests from a foreign government concerning their conduct within Japan

One clarification is worth making. The third category is not about being flagged by the Japanese government; it looks at whether the person receives instructions or requests from a foreign government. And the first has carve-outs, for instance where it has been agreed that the direction of the Japanese entity takes precedence. As for terminology, people usually shorten this to "the three deemed export categories," but strictly speaking these are "specific categories" within the deemed export management framework1.

There is one more proviso that must not be dropped. The specific categories are a device for separating out which provisions of technology to a resident require a licence in advance. Falling into one of them does not mean the person has been assessed as posing a security concern. And the obligation to apply for a licence sits with the party conducting the transaction that provides the controlled technology, that is with the company or the university, not with the individual on the receiving end2. This is not a mechanism for sorting people by nationality, and that is a premise worth holding on to, both in day-to-day practice and when explaining the rules inside an institution.

Universities are not in the business of screening talented researchers and students by nationality. Attracting international minds is a large part of their strength. Which is exactly why each case has to be checked, one at a time, before people arrive. It takes effort, but it is the check that lets the research proceed with confidence once people are through the door. That is the order in which I think about it.

3. A culture built on publication

The third reason is cultural. Research results have value because they are published. Papers, conferences, contribution to society. This is what a university is for.

Export control, on the other hand, is a mechanism for checking in advance whether a recipient and a body of content are appropriate. Inside a culture premised on publication, someone has to keep separating what may be published from what must be managed. That separation cannot be done by a mechanical rule; it requires going into the substance of the research.

The framework of control exists in order to protect the freedom of research. Universities carry out that apparent contradiction every day.

The scale of Okayama University

So what kind of institution is Matsubara working inside? From the day's materials.

Overview of Okayama University: a national university with 10 faculties, 1 programme, 7 graduate schools, 4 research institutes, a university hospital and attached schools. 13,383 students, of whom 966 are international students, and 4,189 faculty and staff

From Okayama University, "Export Control at Okayama University (excerpt)," JX LIVE! 2026 session materials

13,383 students, of whom 966 are international students. 4,189 faculty and staff. Ten faculties, one programme, seven graduate schools and four research institutes, plus a university hospital and attached schools.

The materials also broke down the 966 international students, as of 1 May 2024: 829 from Asia, 58 from Europe, 39 from Africa, 21 from North America, 10 from Latin America, 8 from the Middle East and 1 from Oceania. By status, 375 doctoral students, 249 master's students, 152 undergraduates and 190 research students and others. The international student population has risen from 760 in 2020 to 966 in 2024, an increase of just over 200 in four years.

Numbers alone do not land, so let me put it differently. This is an organisation with more than four thousand faculty and staff, each of whom holds research themes, corresponds with overseas collaborators, travels to international conferences and supervises international students. The situations that could fall within export control arise, somewhere in the institution, in proportion to that headcount, every single day.

A structure with the President at the top

How is that scale absorbed?

Organisation chart of security export control at Okayama University, showing the Export Control Headquarters (President, Executive Director for Research, Head of the Industry-Academia Collaboration Division), the individual units (unit heads and faculty and staff), and the flows to and from METI and the Chugoku Bureau of Economy, Trade and Industry

From Okayama University, "Export Control at Okayama University (excerpt)," JX LIVE! 2026 session materials

At the top is the President, who serves as Chief Export Control Officer. Below sits the Executive Director for Research as Supervising Export Control Officer, and the Head of the Industry-Academia Collaboration Division as Export Control Officer, the person responsible for operations. Those three make up the Export Control Headquarters, which is located inside the Management Department of the Organization for Research and Innovation Co-creation.

Each faculty or institute has its own export control officer, namely the head of that unit, with faculty and staff beneath.

The flows work as shown. Faculty and staff submit pre-check sheets and raise export control questions with their unit, and the unit's own export control officer checks the sheet and notifies whether the transaction or hosting arrangement may proceed. From the units, reports of verification results and consultations on licence applications go up to the Export Control Headquarters, which performs a double check and returns licence application procedures and notifications of concerning information. Where necessary, the Headquarters files licence applications and consultation requests with METI and the Chugoku Bureau of Economy, Trade and Industry, and receives licences and responses in return.

As a diagram it is orderly. Responsibilities are clear, the routes are defined, a double check is built in. For a national university you might say this is only to be expected, but a structure that actually functions this way is far from a given.

And then the next slide shows how many people are holding it up.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

Six people, one of them full-time

Members of the security export control headquarters. The Export Control Headquarters is located in the Management Department of the Organization for Research and Innovation Co-creation and consists of one manager, one full-time staff member and four part-time staff members: the Head of the Industry-Academia Collaboration Division (Export Control Officer); a specialist in the same division (part-time, also Deputy Director of the Industry-Academia-Government Collaboration Headquarters, STC Associate); an administrative staff member in the same division (part-time, electronic systems); an administrative staff member in the Research Cooperation Division (part-time, STC Expert); an administrative staff member in the same division (full-time, STC Associate); and an administrative staff member (part-time, research integrity, STC Associate)

From Okayama University, "Export Control at Okayama University (excerpt)," JX LIVE! 2026 session materials

The wording in the materials:

The Export Control Headquarters is located in the Management Department of the Organization for Research and Innovation Co-creation and consists of one manager, one full-time staff member and four part-time staff members.

Six people. One of them full-time. The other four hold separate duties alongside this one.

I remember the air in the room shifting slightly when that slide came up, because the previous slide had just shown 4,189.

Look at the composition as well. The head of the Industry-Academia Collaboration Division as Export Control Officer. A specialist in that division, part-time, who also serves as Deputy Director of the Industry-Academia-Government Collaboration Headquarters, holding STC Associate. An administrative staff member in that division, part-time, covering electronic systems. An administrative staff member in the Research Cooperation Division, part-time, holding STC Expert. An administrative staff member in the Industry-Academia Collaboration Division, full-time, holding STC Associate. And an administrative staff member, part-time, covering research integrity, holding STC Associate.

STC is a practitioner qualification in security trade control, certified by CISTEC, the Center for Information on Security Trade Control, with Expert sitting above Associate. Matsubara holds STC Expert as well as the comprehensive Security Trade Control Specialist qualification.

In other words, this is a small team but a credentialled one. This is emphatically not a case of thin staffing producing thin quality. If anything the reverse: the certifications and the division of roles look to me like the accumulated result of deliberately building capability to sustain a high standard with very few people.

The problem lies on the other side of the equation, in the volume flowing towards them.

More than two thousand pre-check sheets a year

There are two forms. Form 1-1 covers the export of goods and technology and overseas travel. Form 1-2 covers the hosting of foreign researchers and international students. The next two slides showed the trend for each.

Trend in pre-check sheets received, Form 1-1 (export of goods and technology, overseas travel): FY2019 681, FY2020 148, FY2021 130, FY2022 668, FY2023 970, FY2024 1,670, FY2025 1,510

From Okayama University, "Export Control at Okayama University (excerpt)," JX LIVE! 2026 session materials

Trend in pre-check sheets received, Form 1-2 (hosting of foreign researchers and international students): FY2019 362, FY2020 254, FY2021 284, FY2022 488, FY2023 547, FY2024 667, FY2025 650

From Okayama University, "Export Control at Okayama University (excerpt)," JX LIVE! 2026 session materials

Combining the two slides into a single table:

Fiscal year Form 1-1 (goods and technology exports, overseas travel) Form 1-2 (hosting foreign researchers and international students) Total
FY2019 (Reiwa 1) 681 362 1,043
FY2020 (Reiwa 2) 148 254 402
FY2021 (Reiwa 3) 130 284 414
FY2022 (Reiwa 4) 668 488 1,156
FY2023 (Reiwa 5) 970 547 1,517
FY2024 (Reiwa 6) 1,670 667 2,337
FY2025 (Reiwa 7) 1,510 650 2,160

Compiled from the two charts in Okayama University, "Export Control at Okayama University (excerpt)," JX LIVE! 2026 session materials. The total column is our own simple addition.

There is a way to read this chart.

First, the collapse in FY2020 and FY2021. Form 1-1 falls from 681 to 148 and then to 130. This is the period when COVID-19 stopped overseas travel and international movement. The volume fell not because the work got easier but because the university's international activity had halted.

Then look at how it comes back. FY2022 returns to 668 in a single step, roughly the pre-pandemic level. Then 970 in FY2023 and 1,670 in FY2024, close to two and a half times the pre-pandemic FY2019 figure and more than twelve times the FY2021 trough.

Form 1-2, the hosting of people, follows the same shape: 284 in FY2021 to 667 in FY2024, a factor of 2.3.

Added together, FY2024 comes to 2,337, and FY2025 to 2,160. Divide FY2024 evenly across six people and you get roughly 390 cases per person per year, or about 1.6 per working day on a 240-day year. But that calculation assumes six full-time people doing nothing but export control, when in reality one is full-time and four are part-time. The real density of the work is higher than the arithmetic suggests.

Why the increase? Several forces at once. The full resumption of international activity after the pandemic. Growth in international joint research. Recovery and growth in international student numbers. The introduction of the specific categories in May 2022, which brought technology provision inside Japan into scope where it previously was not. And, above all, the fact that regulation itself keeps accumulating. As Part 1 set out, both list controls and catch-all controls have expanded materially over the past few years.

A chart that climbs like this is also evidence that the university is internationally active. More joint research, more international students, overseas travel restored. All of that is welcome. But that same vitality lands directly on the administrative team as workload. This is the structural difficulty of export control at a university.

Laborious, and impossible to cut corners on

For Q1, I asked Matsubara what the hardest thing is right now on the ground.

What came back was the coexistence of drudgery and consequence. The work is enormously labour-intensive. And yet it is so important that cutting corners is not an option. That, in substance, is where the strain had been sitting.

Laborious, and impossible to cut corners on. I think that tension contains the essence of export control as a profession.

Reviewing one pre-check sheet means, roughly, the following. Determine which item number in the control list the technology or goods correspond to, if any, which is the classification decision. If none applies, consider whether the intended use or end user nevertheless brings catch-all controls into play. Identify who the counterparty is, which country they are in and which organisation they belong to. For international students and visiting researchers, assess whether a specific category applies. Check consistency with past licensed cases. And where the judgement is genuinely uncertain, consult METI or the regional bureau.

Do that, one case at a time, more than two thousand times a year.

And the consequences of getting it wrong are heavy. Under FEFTA, as an administrative sanction, the Minister of Economy, Trade and Industry may prohibit a party that exported without a licence from conducting exports or transactions involving the provision of technology for a period of up to three years (Article 53(1)). As criminal penalties, unlicensed exports and unlicensed technology transactions carry imprisonment of up to seven years or a fine of up to 20 million yen, or both, and for matters relating to nuclear weapons and the like, imprisonment of up to ten years or a fine of up to 30 million yen (Article 69-7). Corporations face separate and heavier fines, up to one billion yen for the most serious category and up to 700 million yen for ordinary unlicensed exports (Article 72(1)). Note that these ceilings are not absolute: where five times the value of the goods involved exceeds those amounts, the fine may go up to five times that value3.

Picture what a three-year suspension would do to a university. International joint research stops. Hosting international students becomes difficult. Joint research with companies is affected. Individual researchers' careers are affected. Of course you cannot cut corners.

And yet the volume keeps rising and the team is six people. The strain described that day is the pressure between those two facts.

Problem 1: graduated review, because you cannot give everything the same effort

So how do you solve it? The Okayama University materials set out two problems as the background to considering AI.

Background to considering the use of AI: two problems, graduated review and standardisation of screening

From Okayama University, "Export Control at Okayama University (excerpt)," JX LIVE! 2026 session materials

The first is what the materials call graduated review. Quoting the wording:

With the number of pre-checks continuing to rise, it is essential to apply gradations of review effort according to the level of risk, rather than devoting the same effort to every case.

Risk factors such as technology level, destination country and transaction type have become more varied, and human effort alone is prone to inconsistency in judgement.

If an AI agent can perform cleaning under a uniform set of rules so that high-risk cases are checked "thickly" and low-risk cases handled "thinly," improvements in organisational efficiency and in review accuracy can be expected.

I thought this was a well-framed diagnosis.

Of two thousand cases a year, how many genuinely require careful deliberation? A domestic conference trip. Joint research with a domestic company. A substantial share must be plainly low-risk. Mixed in among them, though, are cases involving technology that could fall within scope going to a research institution in a destination that warrants careful handling.

Review all of that by the same procedure and there will never be enough hours. And human attention has limits. After processing a hundred low-risk cases, will the hundred and first, the one that actually matters, get the same quality of attention? Honestly, that is asking a lot.

So you grade the review. But to grade it, you first have to distinguish the thick from the thin. Doing that distinction mechanically, under a uniform set of rules, is what the materials call cleaning.

This is territory where AI is strong. Concentrate human attention where attention is genuinely needed, by handing the sorting step that precedes it to a machine. Note that the materials frame graduated review as a means of improving review accuracy, not only efficiency.

Problem 2: standardising screening, so the quality is the same whoever handles it

The second problem is standardisation of screening. Again from the materials:

In an organisation with distributed units, differences in the experience of the people handling cases in each unit tend to produce inconsistency in judgement.

In order to reduce human error and improve accountability, the aim is to codify decision criteria and achieve reproducible processing, so that the quality of review is the same whoever handles it, which is what standardisation of screening means.

Note the phrase "an organisation with distributed units." The structural difficulty I set out earlier appears here as the problem statement itself.

This is not only a university issue. In a company with a head office, business units and overseas subsidiaries, differences in experience produce different conclusions on the same question. Export control functions carried by a single veteran are commonplace, and so is the moment when that person transfers or retires and the basis for decisions goes with them.

The materials point in two directions: codify the criteria, and make the processing reproducible.

Codifying means getting what is in someone's head out into the open. Reproducibility means the same input yields the same output. Only when both are present do you approach a state where the quality of review is the same whoever handles it.

And the two together are what accountability rests on. Export control is a field in which you must be able to explain to a regulator or a counterparty why you decided as you did. You cannot explain a hunch. Criteria written down, and a record showing the case was processed against those criteria. Building that state is, I took it, the more fundamental of the two problems, more so than efficiency.

What changed after the AI agent

Against that background, Okayama University has been working on efficiency using an AI agent, specifically our export control AI agent TRAFEED (formerly ZEROCK ExCHECK).

What Matsubara described was that, in the course of using the AI agent to work more efficiently, the team had begun to feel the load they had been carrying ease.

Let me be straight about the limits here. No figures for percentage reduction or processing time were presented on the day, so this article does not give any. A number like "x per cent reduction" taking on a life of its own would serve neither us nor the university well, and in any case the effect varies with the stage of deployment and the scope of use.

What can be said is that, as experienced on the ground, the load has begun to ease. And that it is not easing because judgement has been abandoned.

Why can I say that? Look back at the two problems. Graduated review is a design in which processing low-risk cases thinly frees up thicker consideration for high-risk ones. Time freed as the load eases is time meant to flow to where it belongs. Standardisation of screening likewise closes gaps in experience between individuals, which raises the floor on quality.

The point of using AI in export control is not to reduce human judgement. It is to return human time to the places where judgement is required.

Q2 to Naito: how far can you delegate to AI?

Which brings us to the next question. I put it to our CTO, Kazuki Naito.

Let me restate his background. Fourteen years at NTT, working on large-scale systems from design through operations. What he handled were mission-critical systems: expected to run, newsworthy when they stop, and intolerant of error. He has spent a long time in that world.

What he described was a design philosophy centred on making the AI's reasoning traceable.

You cannot delegate everything in export control to an AI, for a simple reason: you could not explain it. "The AI said so, therefore we concluded the transaction was fine" does not work with a regulator, and it does not work with a counterparty.

So what can be done? What AI should take on is investigating, assembling and preparing. Which control list and which item number was consulted. Where the counterparty's corporate information came from. How comparable past cases were decided. Gather that material, cross-check it, organise the issues and hand them to a person. And leave that process in a form you can retrace, step by step, later.

The final decision stays with a person. But the material and the reasoning that person needs are prepared by the AI. With that division of labour, neither the locus of responsibility nor the chain of explanation breaks down.

This is where it matters that Naito comes from mission-critical systems. A system that only has to produce an answer and a system whose way of producing the answer is itself under scrutiny are entirely different design problems. Export control is the second kind.

The risk of betting everything on one closed AI

Naito then went a step further. This was the part of the day that made me think hardest.

His point was that dependence on AI models, and in particular full dependence on a single closed AI provider, has become a distinctly higher risk in recent months.

The nineteen days it actually stopped

This connects directly to a fact covered in Part 1.

On 12 June 2026 the US government applied export controls to Anthropic's newest models, Claude Fable 5 and Claude Mythos 5. In its public statement the company explained that this required it to restrict access for foreign nationals, but the action it actually took was to suspend access to both models for all users, because it could not verify nationality in real time4.

Which means US users were cut off too. Not "a foreign matter that does not concern us," but a case where even a company in that country was swept up.

Fable 5 returned globally on 1 July, nineteen days after 12 June. Mythos 5 had access restored earlier for certain organisations within the United States on 26 June, so it is not the case that both models were down for the same nineteen days.

The company's public statement also explains what triggered the measure. Research from Amazon had identified a method for circumventing Fable 5's safeguards, and it emerged that this could lead to the discovery and demonstrated exploitation of software vulnerabilities. This was a measure that moved as a result of a safety evaluation rather than as a piece of pure trade manoeuvring. I would treat that sequence not as grounds for blaming any government, but as evidence that AI models have become objects of national security judgement.

Either way, from a company's point of view the conclusion is the same. The AI you use can stop, not because of a technical fault, but because of a regulatory decision.

Open weights as an option

This is why, Naito argued, you should not concentrate everything on closed models but should also look at open-weight models.

An open-weight model is one whose trained parameters are published, so you can download it and run it in your own environment. If the provider's service stops, what you hold locally still runs.

The industry is moving too. On 24 July 2026 an open letter titled "Open Weights and American AI Leadership" was published. Its argument, broadly, is that open weights broaden access to AI, promote competition and help avoid lock-in to particular vendors; that the risks are real but prohibition is the wrong response. The published version carries 235 signatories, including NVIDIA, Microsoft, Meta, Google, Amazon, OpenAI, IBM, Intel, AMD, Hugging Face and The Linux Foundation5.

Anthropic did not sign it. The company did, however, publish its own position on 27 July, saying it agreed with much of the letter while disagreeing with some of its claims, and stating explicitly that it has never advocated for a ban on open-weights models6.

So the industry has not divided neatly into an open camp and a closed camp. This is easy to misread, so I am stating it precisely. The question is not a binary between open and closed; it is a design question about how far you depend on either.

Multi-LLM: making the model a component you can swap

This was the point Naito pressed hardest.

If you are going to build AI into your operations, design the LLM layer as a component you can swap out at any time. In substance: this is what will prove decisive in how organisations use AI from here.

In systems terms, keep it loosely coupled. Do not bake business logic into the idioms of one particular model. Write your prompts, and your handling of outputs, on the assumption that the model can be replaced. Keep the option of running several models in parallel and reconciling their results.

Recall his background. Fourteen years at NTT on systems you cannot take offline. In the world of mission-critical systems there is hard-won knowledge that deep dependence on a single vendor or middleware stack becomes a long-term weakness, and redundancy in systems that must not stop is simply assumed. His argument was that the same discipline should apply to AI.

The reason TRAFEED uses a multi-LLM deliberation approach is partly the pursuit of accuracy and partly this question of portability. When one provider's model stops, export control, a function that cannot stop, must not stop with it.

Naito then turned to law.

The United States has the CLOUD Act, enacted in 2018. Section 2713 of Title 18 of the United States Code, created by that act, requires providers to preserve and disclose the contents of communications and records within their possession, custody or control, regardless of whether that information is located within or outside the United States7. Data sitting in a Japanese data centre can still fall within US legal process if the company holding it is a US company.

China has the National Intelligence Law, in force since 2017. Article 7 provides that any organisation or citizen shall support, assist and cooperate with national intelligence work in accordance with law. Article 14 provides that national intelligence institutions may request necessary support, assistance and cooperation from relevant organs, organisations and citizens. Reading the statute as a whole, though, Article 8 also provides that national intelligence work shall be conducted in accordance with law, shall respect and safeguard human rights, and shall protect the lawful rights and interests of individuals and organisations. The law was partially amended in April 20188.

The EU has the AI Act, which regulates AI itself, imposing obligations by risk tier and reaching Japanese companies that do business with the EU.

None of this is material for condemning any one country. It is the fact that major jurisdictions are each, from their own position, building legal frameworks around data and AI. And from an operator's point of view there is one common implication: in some situations, what governs is not where the data sits but which country's company holds it.

On that basis, Naito said, in substance, that with these regimes emerging, both the way Japan uses cloud services and the growth of Japanese providers are now being called for.

What to do about domestic AI infrastructure

Finally, Naito gave his view that Japan needs to build domestic AI foundations properly, and that this will be extremely important from a national security standpoint.

I am presenting this as his personal view. TIMEWELL is not in a position to assert it as a policy recommendation, and personally I do not think the matter reduces to a simple domestic-versus-foreign line. There is no reason not to use excellent models built abroad, and we use them.

Even so, the nineteen days in June showed how precarious it is to hold only one option. Keep some of the options for continuing to operate inside the country. And have Japanese businesses involved both in building those options and in growing them. That, as I understood it, was what he meant.

Q3: with a limited team, where do you start?

The third question we discussed as a group. With a limited team, where do you start?

This is not only a question for universities. Companies where export control is one part of one person's job are everywhere, and my impression was that it was the corporate attendees who nodded most at this point.

Pulling together what came out in the session and my own thinking, the starting points look like this.

One. Take inventory. Write out, once, every situation in your organisation that could fall within export control. Not just product exports: provision of technical information, overseas travel, technology transfer to foreign-national employees or researchers, data sharing with overseas sites. Writing it out surfaces routes you had not considered.

Two. Count the cases. What makes the Okayama University charts powerful is that they count by fiscal year. If you are not counting, you cannot know that volume is rising, or where it is rising. Counting is also the evidence base for asking for resources.

Three. Write down the criteria. Get the judgements out of people's heads and onto paper. It does not have to be perfect. The moment you start writing "under these conditions we treat it this way," standardisation has begun.

Four. Grade the review. Stop looking at everything at the same depth. Build the mechanism for handling low-risk cases thinly first, and the time goes to the high-risk ones.

Five. Then, and only then, bring in tools. Reversing the order fails. Deploy AI with no inventory and no written criteria and you will be using it without knowing what you have delegated. Only with the first four in place does an AI agent become a tool that can, in the university's phrase, perform cleaning under a uniform set of rules.

And for the executive side, I asked people to take away the three questions from the end of Part 1. If your export licences were suspended for three years, how much of your revenue would stop? If the AI you use stopped tomorrow, do you have somewhere to switch to? And who decides those two things, by when? None of them can be decided by a single practitioner.

From a constraint to a competitive advantage

The closing slide of the session.

A message from TIMEWELL: turning economic security from a constraint into a competitive advantage. Economic security is not a compliance cost but an investment in continuing to earn abroad.

From the TIMEWELL session materials, JX LIVE! 2026

In most organisations export control is treated as a cost. It generates no revenue, it is hard to staff, it slips down the list. I understand why.

But what those six people at Okayama University are doing is not a cost-reduction exercise. It is the work of protecting the foundation on which that university continues its international joint research, hosts international students and stays connected to the world. More than two thousand pre-check sheets a year also means a great deal of international activity is happening. Because the control function is working, the activity can continue.

The same holds for companies. If you intend to keep earning abroad, you have to keep those transactions from stopping. A company whose defences are not in place absorbs risk the moment it goes on the offensive. A company whose defences hold across goods, data and people can move into new markets and new technologies.

Economic security, from a constraint into a competitive advantage. That is where we ended the day.

In closing

One thing to draw together from both parts.

The geopolitics and the accumulating regulation covered in Chapter 1 look like a distant world. What Matsubara showed us in Chapter 2 is that this accumulation arrives, as more than two thousand pieces of paperwork a year, on the desks of six members of staff. Regulation always comes down to somebody's hands in the end.

Lighten the load on those hands without lowering the accuracy. Hold the quality of judgement steady regardless of who is handling the case. Use tools to do it. That is all TIMEWELL is trying to do with TRAFEED. Not have the AI take over human judgement, but return human time to where judgement belongs. Which is exactly why the AI's reasoning has to be traceable, and why the AI itself must not be tied to a single provider.

My thanks again to Shinobu Matsubara of Okayama University for joining us, and my respect for sharing the numbers and the problems from the front line so candidly. Thanks also to everyone who attended, and to the Japan Association of New Economy.

Related reading:


TIMEWELL's AI export control agent TRAFEED (formerly ZEROCK ExCHECK) (TRAFEED service catalog (PDF)) is aligned with METI's standards and supports everything from classification decisions to counterparty screening in a form where the basis for each decision can be retraced. It also supports pre-check sheet workflows at universities and research institutions.

If any of "we cannot get through the volume with the people we have," "judgements vary by who handles the case," or "we are not leaving a record of why we decided" sounds familiar, talk to our TRAFEED team. Details are on the TRAFEED service page.

References

Session materials

  • "Is Your Technical Information Leaking? Economic Security and the Front Line of Export Control in the Age of AI" (TIMEWELL session materials, JX LIVE! 2026, 28 July 2026)
  • Okayama University, "Export Control at Okayama University (excerpt)" (JX LIVE! 2026 session materials, 28 July 2026)
  • TIMEWELL press release, 31 July 2026: https://prtimes.jp/main/html/rd/p/000000138.000119271.html

Legislation and government sources

Company and industry statements

Footnotes

  1. The three specific categories are set out in METI's notice on transactions and acts requiring a licence under Article 25(1) of FEFTA and Article 17(2) of the Foreign Exchange Order (No. 492 of 21 December 1992), section 1(3)(sa)(i) to (iii). They were added by the amendment of 18 November 2021 and have applied since 1 May 2022. The wording in this article follows that notice and METI's "Guidance on Security Export Control (Introductory Edition)."

  2. On how the specific categories sit within the regime, see METI's notice on transactions and acts requiring a licence under Article 25(1) of FEFTA and Article 17(2) of the Foreign Exchange Order (No. 492), section 1(3)(sa), together with METI's "Guidance on Security Export Control (Introductory Edition)." The specific categories separate out which provisions of technology to a resident require a licence; they are not a determination that the person concerned poses a security concern. The licence obligation falls on the party conducting the transaction whose purpose is to provide the controlled technology (Foreign Exchange and Foreign Trade Act, Article 25(1)).

  3. Foreign Exchange and Foreign Trade Act (Act No. 228 of 1949), Article 53(1), Article 69-7 and Article 72(1). The heavier corporate fines (up to one billion yen, seven hundred million yen and so on) were introduced by Act No. 38 of 2017, in force from 1 October 2017. The three-year prohibition under Article 53(1) predates that amendment. The custodial penalty was renamed from 懲役 (imprisonment with work) to 拘禁刑 (a single unified custodial sentence) by Act No. 68 of 2022.

  4. Anthropic, "Redeploying Fable 5" (30 June 2026). According to the company's statement, the US government applied export controls to Claude Fable 5 and Claude Mythos 5 on 12 June 2026, requiring restrictions on access by foreign nationals. Because nationality could not be verified in real time, the company suspended access for all users. Access to Mythos 5 for certain organisations within the United States was approved on 26 June, the export controls on both models were lifted on 30 June, and Fable 5 returned globally on 1 July.

  5. Open letter, "Open Weights and American AI Leadership" (24 July 2026, PDF hosted by NVIDIA). The signatory list contains 235 companies and organisations, including NVIDIA, Microsoft, Meta, Google, Amazon, OpenAI, IBM, Intel, AMD, Cisco, SAP, Siemens, Dell, Hugging Face, Mistral, Cohere and The Linux Foundation.

  6. Anthropic, "Our position on open-weights models" (27 July 2026). The company states that it agrees with much of the letter while disagreeing with some of its claims, and that it has never advocated for a ban on open-weights models.

  7. Public Law 115-141, Division V (Clarifying Lawful Overseas Use of Data Act, enacted 23 March 2018), section 103, which created 18 U.S.C. §2713. The provision applies "regardless of whether such communication, record, or other information is located within or outside of the United States."

  8. National Intelligence Law of the People's Republic of China (adopted 27 June 2017 by the 28th session of the Standing Committee of the 12th National People's Congress, in force 28 June 2017, partially amended 27 April 2018), Articles 7, 8 and 14. The full text is published on the NPC website.

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

シェア

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

無料診断ツール

輸出管理のリスク、見えていますか?

まず5問(約2分・メール不要)のライト診断。必要なら10問本編で詳細レポートまで。

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles