Hello, this is Ryuta Hamamoto from TIMEWELL.
"The government is putting JPY 10.5 trillion into Physical AI." Many of you probably saw that headline more than once this summer. The sheer size of the number tends to grab attention, but as someone who makes a living in export control, the first thing that came to mind was different. Selling domestically made robots and autonomous-control AI to the world means the burden of military-diversion risk and export control grows in proportion. The harder you press the accelerator on offense, the more your defensive brakes and steering get tested.
In this article, I first pin down what "JPY 10.5 trillion" actually refers to, using primary sources from the Cabinet Office and the Prime Minister's Office. From there, we look in order at why this investment is framed in the language of economic security, what security risks are specific to Physical AI, and what companies should put in place as a practical matter. If you are wondering how much export-control risk your own Physical AI products carry, I would suggest checking where you stand first with the free export-control readiness check; it will help you read the practical second half as something that applies to you.
What Physical AI Is: AI That Understands and Acts on the Real World
The term Physical AI leapt to the center of government documents in the space of a single year. The draft Second AI Basic Plan defines it as AI that understands the real world and generates physical action1. Whereas conversational AI that generates text and images stays inside the screen, Physical AI perceives its surroundings through cameras and sensors and moves the physical world itself through motors and actuators. The concrete examples the government cites are autonomous driving, factory and infrastructure management, and autonomous robots that work alongside people, in other words AI robotics.
Why is the Japanese government betting here? The reasoning is clear. Japan has the shop-floor strength it built up in industrial robots and automobiles, and a deep bench in hardware such as motors, reduction gears, and sensors. The government positions "Vertical AI" and "Physical AI" as Japan's two winning fronts, and set out a policy of building an edge from the strengths of field data and hardware1. For a Japan that fell a lap behind the giant U.S. firms in developing foundation models for generative AI, Physical AI, with hands and feet in the real world, is one of the few arenas where it can turn its manufacturing heritage into a weapon.
It clicks into place if you picture the front lines of elderly care, logistics, and construction. These fields, where labor shortages are severe, are exactly where robots that can work alongside people come into their own. But working on the ground also means, conversely, coming into direct contact with human life and critical infrastructure. This double-edged nature is the root of the security risks we look at later.
Verifying "JPY 10.5 Trillion" Against the Primary Source
I will write this section carefully. In the press I saw headlines that could be read as "the Physical AI market is JPY 10.5 trillion," but going to the primary source, the meaning is different.
The JPY 10.5 trillion figure appears in the body of the draft Second AI Basic Plan, on page 11, footnote 4, presented on June 24, 2026 to the Council on Economic and Fiscal Policy (8th meeting of Reiwa 8) and the Japan Growth Strategy Council (5th meeting)1. It states that public and private investment related to Physical AI (AI robots in particular) is projected at JPY 10.5 trillion through fiscal 2040. This is not a market size; it is a projected investment figure, public and private combined. The same footnote also lines up JPY 23.1 trillion for Vertical AI and JPY 68.0 trillion for the semiconductors at the core of physical intelligent systems. Add the three fields together and you get an investment vision on the order of about JPY 101.6 trillion. It also notes that accelerating AI adoption is expected to lift Japan's total factor productivity (TFP) growth rate by 0.2 points1.
Easy to confuse with this is the "about JPY 3 trillion in 2030" figure in the interim summary of the Vertical AI sector-by-sector strategy2. That one is a projection of market expansion, and its metric, scope, and fiscal year all differ from JPY 10.5 trillion (Physical AI, fiscal 2040, public-private investment). When numbers travel on their own, the discussion drifts, so it is worth being clear about which figure refers to what.
This investment vision was formally taken up for discussion at the 5th meeting of the AI Strategy Headquarters, held at the Prime Minister's Office on July 10, 2026. The head of the headquarters is Prime Minister Sanae Takaichi, and the agenda that day included "The Second AI Basic Plan (Draft): Japan AX, Stronger and More Prosperous" and the "Vertical AI Sector-by-Sector Strategy Interim Summary"34. One caution here. This Basic Plan is a statutory plan under Article 18, Paragraph 1 of the AI Act (the Act on the Promotion of Research, Development and Utilization of AI-Related Technologies, Act No. 53 of 2025), but as of that meeting the second edition was still at the "(draft)" stage1. The first edition was adopted by the Cabinet on December 23, 2025, but the amounts and wording in the second edition may change in the final version. So in this article too, please read the figures as "projections at the draft stage."
Replace siloed classification work with AI.
METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.
Why Physical AI Is a Matter of "Economic Security"
One thing worth sorting out here is that "economic security" is not the name of a meeting; it is a policy concept embedded in the plan. The bodies that announced this public-private investment figure are the AI Strategy Headquarters, the Council on Economic and Fiscal Policy, and the Japan Growth Strategy Council; economic security itself is built in as the underlying philosophy running through these plans.
At the center of that philosophy is "AI Sovereignty." The draft Second Basic Plan pledges to secure "strategic autonomy" and "strategic indispensability" and to establish an open AI sovereignty1. Put plainly, it is an approach that aims to do both at once: create a state that does not depend excessively on any particular country or company, while becoming an entity the world needs for value only Japan can provide. Especially in strategic domains such as administration, defense, and critical infrastructure, the plan calls for raising the autonomy of computing resources, data, models, and applications, and for securing "resilience to disconnection" so operations can continue even if cut off from the outside.
The autonomy discussion leads straight into the supply-chain discussion. The draft plan calls for nurturing robot OEMs and strengthening the design of critical components such as motors, reduction gears, sensors, and storage batteries, and it lays out a policy of extending the supply-chain strengths cultivated in industrial robots and automobiles to multi-purpose robots1. The vision is to expand domestic development and manufacturing of data centers, computing infrastructure, and semiconductor production and supply capacity, and to make the supply chain itself more resilient. The descriptions of developing domestic multimodal foundation models and Physical AI foundation models at home reflect an aim to build a structure in which even the "brains" of the models are not held overseas.
The defensive side is clear too. As a cyber measure for critical infrastructure that includes operational technology (OT) control systems, the government is promoting the countermeasure package "Project YATA-Shield," compiled on May 18, 2026, and says it will use high-performance AI to speed up the discovery and remediation of vulnerabilities2. Read this far, and you can see that this investment is not mere industrial promotion but a move in economic security that bundles technological sovereignty, supply chains, and cyber defense together. If you want to grasp the overall picture of export control and economic security first, reading the article explaining what economic security is from the ground up alongside this will make this chapter easier to place.
The Security Risks Latent in Physical AI
This is the part I most want to convey. In Physical AI, the technical characteristics themselves are contiguous with military diversion. And the current government policy acknowledges that continuity as policy. The Vertical AI sector-by-sector strategy lists the defense domain among the "strategically significant domains," positions AI as "a critical factor that can decide the outcome of combat," and explicitly states both spin-on, which takes private-sector technology into defense, and spin-off, which spreads defense-developed technology into the private sector2. In other words, the government itself is showing that the boundary between civilian and military use is becoming blurred even institutionally.
Break the risk down concretely, and the first is military diversion (dual use). Autonomous mobile robots, autonomous-driving technology, drones and unmanned systems, and autonomous-control AI can all be diverted directly into unmanned weapons, lethal autonomous weapons systems (LAWS), and reconnaissance and logistics military assets. It is a structure in which foundation models and autonomous-control technology themselves can flow to military ends even if they were honed for civilian use. If you want to understand the concept of dual use a little more carefully, the article explaining dual-use technology and military-diversion risk is a useful reference.
Next is the diversion of critical components and enabling technologies. Motors, reduction gears, high-precision sensors, inertial measurement units (IMUs), high-performance computers such as GPUs and edge AI chips, and storage batteries. These are the core of Physical AI and, at the same time, may touch on export-controlled items relating to missile technology, military robotics, and inertial navigation. The more you push domestic production and export promotion, the heavier the burden of managing the overseas outflow and military diversion of these components.
Technology leakage cannot be overlooked either. The government documents themselves note concern about the overseas outflow of sensitive trade-secret information and the overseas outflow of data1. Field data, drawings, 3D-CAD, process conditions, training datasets, and the weights of foundation models. Because turning tacit knowledge into data is precisely Physical AI's winning strategy, the loss when it leaks is correspondingly large. The leakage routes are varied, from overseas subsidiaries and joint research to suppliers and departing employees, and if in-house technology-access management is lax, technology provided to foreign researchers or secondees can quietly fall under "deemed export" and become an unwitting violation of the Foreign Exchange Act. The pitfalls of deemed export are laid out in detail in the practical guide to deemed-export risk.
Supply-chain dependence is a two-sided risk as well. Relying too heavily on a particular country for semiconductors and GPUs, high-precision sensors, reduction gears, and rare metals leaves you vulnerable to supply cutoffs in a contingency and, conversely, exposed to the other country's export controls or retaliation. China's controls on gallium, germanium, and rare earths are still fresh in memory. When the government places "resolving excessive dependence on particular countries or companies" as a pillar of its strategy, that is precisely a hedge against this vulnerability.
Finally, two risks unique to Physical AI. One is cyberattacks on OT (control systems), which go beyond information leakage and connect directly to physical destruction, human life, and the shutdown of critical infrastructure. The government even touches on the possibility of cyberattacks in which agentic AI autonomously handles everything from discovering vulnerabilities to constructing attack procedures, executing them, and revising them2. The other is the problem of accountability that autonomy itself creates. When an AI that judges and acts autonomously malfunctions, whether a human is involved in the decision (human in the loop) or merely supervising is not yet institutionally settled. On the relationship between cutting-edge AI models and export control, the article on frontier-AI safeguards and export control is also a useful reference.
The Practical Essentials of Export and Technology Control for Companies
So what should companies working on Physical AI or robotics put in place as a practical matter? Now that the starting gun for export promotion has sounded, I recommend building the defensive template first. Six pillars anchor it.
| Measure | What to do | The essential point for Physical AI |
|---|---|---|
| Item classification (gaihi hantei) | Judge, item by item, whether goods and technologies fall under the list controls of Appended Table 1 of the Export Trade Control Order, the Appended Table of the Foreign Exchange Order, and the ministerial ordinance on goods | The scope is broad, spanning robots, unmanned vehicles, IMUs, high-performance computers, semiconductors and manufacturing equipment, sensors, and even models and software |
| Catch-all controls | Even for non-listed items, check the end-use and end-user requirements tied to weapons of mass destruction and conventional weapons | Physical AI has broad uses, so checking for unforeseen diversion demand is especially important |
| End-user screening | Investigate counterparties and end-use, cross-checking against METI's Foreign End User List, national lists, and ownership structure (military or defense equity, the 50% rule) | The end-user base is wide, so you need to check whether military-linked entities are connected through capital |
| Deemed-export controls | In line with the May 2022 clarification, manage technology provided to foreign nationals who fall under the "specified categories" even if they are residents | Because Physical AI tends to rely on international talent, category determination at hiring and access-rights management are the pressure points |
| U.S. EAR compliance | When incorporating U.S.-origin GPUs, EDA, equipment, or technology, check re-export, de minimis, and the Foreign Direct Product Rule (FDPR) | Dual compliance that satisfies both U.S. and Chinese controls simultaneously is required |
| Economic Security Promotion Act compliance | Make critical-material supply chains visible, undergo prior review for core infrastructure, and respond to non-disclosure of patent applications | If critical components fall under specified critical materials, consider domesticating or diversifying procurement |
Laid out in a table it looks orderly, but the trouble in the field is that these are split across different departments. R&D handles deemed export, procurement handles the supply chain, sales handles item classification and end-user checks, legal handles sanctions and the EAR, and IT handles OT and data leakage. Unless you view these on a horizontal axis, a hole opens up from a single fray somewhere. That is exactly why it is essential to build a company-wide, integrated framework centered on the internal compliance program (CP), extending management to digital technology assets such as foundation-model weights, training data, and drawings, and to embed it into the due diligence of overseas expansion, joint research, and M&A.
Frankly, the volume of this work grows heavier every year. Each country's lists, laws, and notices trigger a reconciliation exercise every time they are updated. For products like Physical AI, which have broad uses and high part counts, even the item classification of a single product takes considerable effort. The approach of stationing specialist staff to handle it by hand will, before long, fail to keep up in a phase where investment is accelerating.
Pair Aggressive AI Investment With Defensive Export Control
Summed up in a sentence, the structure we have looked at is this. The government putting JPY 10.5 trillion into Physical AI, and the public and private sectors accelerating overseas expansion and procurement, means export-control risk swells at the same rate. Aggressive AI investment only stands up when it is paired with defensive export control.
TRAFEED (formerly ZEROCK ExCHECK), which we at TIMEWELL provide, is an export-control AI agent built precisely to absorb this swelling management burden. It was the world's first to be offered as an AI agent in the field of security trade control (as of March 2026, per our own research), it complies with METI's standards, and it supports multiple languages. It backstops item classification, end-user screening, and the investigation of counterparties and end-uses suspected of military diversion, cross-checking against national lists and laws as it goes. In a joint proof of concept with Okayama University, we confirmed an AI judgment accuracy of 95% or higher based on roughly 30,000 past review records (per our own research). Of course, the principle that the final item classification is made by your company's export-control officer remains unchanged. The division of labor keeps the part that humans judge and lets AI take on the burden of reconciliation and first-pass screening.
If you have plans to expand your Physical AI product line, or intend to broaden overseas procurement and joint research, how to fully manage the growing flow of transactions and technology will inevitably become a point of discussion. If you would like to check once whether your export control can withstand the burden that is coming, feel free to reach out through a one-on-one consultation on TRAFEED. Before pitching any product, we can start by sorting out your company's risk structure together.
Summary
Let me organize today's content in a form you can take back to your work.
- In its draft Second AI Basic Plan, the government projects JPY 10.5 trillion in public and private investment in Physical AI (AI robots in particular) through fiscal 2040. This is a projected public-private investment figure, not a market size, and the plan is still at the draft stage1.
- Alongside it, the plan projects JPY 23.1 trillion for Vertical AI and JPY 68.0 trillion for Physical-AI-related semiconductors, positioning the effort as a move in economic security that, anchored on AI Sovereignty (strategic autonomy and strategic indispensability), bundles technological sovereignty, supply chains, and cyber defense12.
- Physical AI carries a compound risk of military diversion, diversion of critical components, technology leakage, deemed export, supply-chain dependence, OT cyberattacks, and blurred accountability, and the government itself blurs the civilian-military boundary through spin-on and spin-off2.
- Companies need to integrate item classification, catch-all controls, end-user screening, deemed-export controls, U.S. EAR compliance, and Economic Security Promotion Act compliance company-wide, anchored on their CP.
One last thing. I too think Physical AI is a field where Japan can, for the first time in a while, go head-on to win. That is exactly why I want you to design export control not as a "bothersome cost" but as a "prerequisite for competing in the world." Offense that takes defense lightly will, sooner or later, stall somewhere. If you are going on the offensive, strengthen your defense at the same speed.
References
- Cabinet Office, "AI Strategy Headquarters (5th Meeting) List of Distributed Materials" (July 10, 2026)
- Cabinet Office, "Second AI Basic Plan (Draft) Main Text" (Material 1-2; page 11, footnote 4 states the projected public-private investment figures)
- Cabinet Office, "Second AI Basic Plan (Draft) Overview: Japan AX, Stronger and More Prosperous" (Material 1-1)
- Cabinet Office, "Vertical AI Sector-by-Sector Strategy Interim Summary Main Text" (Material 2-2)
- Cabinet Office, "Vertical AI Sector-by-Sector Strategy Interim Summary Overview" (Material 2-1)
- Prime Minister's Office, "The Prime Minister's Day: AI Strategy Headquarters" (July 10, 2026)
- Foreign Exchange and Foreign Trade Act (Foreign Exchange Act; goods exports under Article 48, technology service transactions under Article 25)
- Appended Table 1 of the Export Trade Control Order, the Appended Table of the Foreign Exchange Order, and the ministerial ordinance on goods (list-controlled items)
- Catch-all controls (complementary export controls; end-use and end-user requirements)
- Clarification of deemed-export controls (operation began May 2022; technology provided to persons in specified categories)
- Economic Security Promotion Act (resilience of critical-material supply chains, core-infrastructure services, public-private cooperation on advanced critical technologies, non-disclosure of patent applications)
- Act on the Promotion of Research, Development and Utilization of AI-Related Technologies (AI Act, Act No. 53 of 2025; Articles 18 and 16)
- U.S. Export Administration Regulations (EAR; Entity List, de minimis, Foreign Direct Product Rule)
Footnotes
-
Cabinet Office, "Second AI Basic Plan (Draft) Main Text (Material 1-2)" (page 11, footnote 4 states the projected public-private investment of JPY 10.5 trillion for Physical AI, JPY 23.1 trillion for Vertical AI, and JPY 68.0 trillion for semiconductors) https://www8.cao.go.jp/cstp/ai/ai_hq/5kai/shiryo1_2.pdf ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10
-
Cabinet Office, "Vertical AI Sector-by-Sector Strategy Interim Summary Main Text (Material 2-2)" (sector-by-sector strategies for manufacturing, defense, cyber, and more; Project YATA-Shield; the projected market of about JPY 3 trillion in 2030) https://www8.cao.go.jp/cstp/ai/ai_hq/5kai/shiryo2_2.pdf ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
Cabinet Office, "AI Strategy Headquarters (5th Meeting) List of Distributed Materials" (July 10, 2026) https://www8.cao.go.jp/cstp/ai/ai_hq/5kai/5kai.html ↩
-
Prime Minister's Office, "The Prime Minister's Day: AI Strategy Headquarters" (held July 10, 2026) https://www.kantei.go.jp/jp/105/actions/202607/10jinkoutchinou.html ↩
