TRAFEED

Research Integrity and Economic Security at Universities: A Practical Guide to Deemed Exports and Research Security (2026 Edition)

Published2026-07-19Ryuta Hamamoto

A practitioner's overview of how research integrity and research security have been built into Japan's economic security policy. We map the roles of the Cabinet Office (CSTI), MEXT, METI, and the JPO, and cover information disclosure, the "specified categories" of deemed exports, the research security procedures manual, and patent non-disclosure, citing statute names and enforcement dates throughout.

Research Integrity and Economic Security at Universities: A Practical Guide to Deemed Exports and Research Security (2026 Edition)
シェア

Hello, this is Ryuta Hamamoto from TIMEWELL.

"We're a university doing basic research, so export controls have nothing to do with us." I still hear this often when I talk with people at research institutions. But the situation has changed completely over the past few years. Research integrity, which protects the honesty of research, and research security, which prevents technology leakage, have been properly built into the nation's economic security policy, and the things universities and research institutions must do have been stacked up, one by one, as a formal system.

The starting point was April 27, 2021, when the Council for Integrated Innovation Strategy adopted the "Policy for Ensuring Research Integrity Against New Risks Accompanying the Internationalization and Openness of Research Activities."1 From there through the publication of the research security procedures manual in December 2025, the Cabinet Office, the Ministry of Education, Culture, Sports, Science and Technology (MEXT), the Ministry of Economy, Trade and Industry (METI), and the Japan Patent Office (JPO) each built out the framework within their own areas. In this article, I lay out the full picture of the system universities and research institutions now face, from a practitioner's perspective, naming statutes and enforcement dates as specifically as I can. I'll break it down to the point where you can see what to tackle first. If you are unsure whether your own technology or joint-research partners could fall under export controls, the fastest path is to start by mapping where you stand with a free export control self-assessment.

The whole picture in three lines

Who is driving this? The Cabinet Office (the Bureau for Science, Technology and Innovation, known as CSTI) is the control tower, MEXT handles university policy and information disclosure, METI handles deemed exports, the JPO handles patent non-disclosure, and JST (the Japan Science and Technology Agency) runs pilot initiatives.

What is being asked? Information disclosure by researchers, pre-acceptance checks on international students, visiting researchers, and joint-research partners, responses to the specified categories of deemed exports, building systems in line with the research security procedures manual, and non-disclosure of patent applications for sensitive inventions.

Since when? Starting from the policy decision of April 27, 2021, the framework has come together in stages: the clarification of deemed export operations in May 2022, the entry into force of the patent non-disclosure system in May 2024, and the publication of the research security procedures manual in December 2025.

How research integrity, research security, and economic security connect

Let's start by sorting out the words. The three are often confused, but they point in different directions. Research integrity is about conducting research honestly, without hiding conflicting interests. It is, in a sense, inward honesty. You disclose who funds or supports you and whether you have secondary employment or contracts with foreign governments, and you properly manage conflicts of interest and conflicts of commitment. That is the axis.

Research security is about not unintentionally letting important technology leak outward. This is outward defense. And economic security is the largest framework, one that positions both of these within national strategy. In its policy, the Cabinet Office clearly points to "the danger that researchers unintentionally fall into conflicts of interest or conflicts of commitment."1 This is important: it is not about suspecting researchers as though they act in bad faith. Even without malice, if you neglect disclosure or hand over technology without confirming who you are dealing with, the result can be a leak that harms the national interest. The idea is for organizations to get ahead of that structural risk.

For an introductory take that breaks down how these three relate, see our existing article, What Are Research Integrity and Research Security?. This article is the sequel that goes further: what has actually been decided as a system, and what to do about it in practice. If you want to grasp the basics first, reading that one first should make the systemic discussion here go down more smoothly.

Who does what: the government's control tower and division of roles

The biggest reason the system feels hard to follow is that multiple ministries operate under their own laws and guidelines. Laying out the responsibilities on a single sheet suddenly improves visibility of the whole.

Responsible body Main role Basis
Cabinet Office (CSTI / Council for Integrated Innovation Strategy) Overall policy control tower. Policy for ensuring research integrity, compilation of the research security procedures manual, economic security policy in general Policy decision (April 27, 2021), research security procedures manual (December 2025)
MEXT (Science and Technology Policy Bureau) Measures for universities and research institutions, competitive research funding disclosure (e-Rad), consultation desk, follow-up surveys on the status of initiatives Guidelines on the Proper Execution of Competitive Research Funding (revised December 17, 2021)
METI (Trade and Economic Security Bureau) Security export control under FEFTA, operation of deemed exports and specified categories, technology classification FEFTA Article 25(1), the Services Notification (effective May 1, 2022)
JPO (Japan Patent Office) Operation of the patent non-disclosure (security designation) system under the Economic Security Promotion Act Economic Security Promotion Act (Act No. 43 of 2022)
JST (Japan Science and Technology Agency) Implementation of pilot research security initiatives in R&D programs Pilot started in FY2025

What tends to trip up university practitioners is treating this in silos: "research integrity is MEXT's job," "deemed exports are METI's job." In reality, even something as simple as accepting a single international student pulls in both information disclosure (MEXT) and confirmation of whether the specified categories apply (METI) at the same time. The system may be siloed, but on-the-ground judgment has no choice but to cut across those silos. That is exactly why it helps to keep in mind, from the start, that the Cabinet Office serves as the control tower binding the whole together.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

Information disclosure as the foundation: the research integrity policy and competitive research funding

Push far enough into the practice of research integrity and you arrive at "information disclosure." From whom, and through what kind of support, funding, or secondary employment relationships? The researcher declares it, and the organization grasps and manages it. This activity, which looks obvious, had not been clearly established as a system until now.

The policy of April 27, 2021 made information disclosure one of its pillars.1 Researchers are to appropriately disclose support from foreign governments, secondary employment, funding sources, and the like. Organizations are to manage conflicts of interest and conflicts of commitment and build the necessary systems. The Cabinet Office even created a template checklist so that the field could put this into operation. The effectiveness lies in not leaving it as abstract theory but concretizing the items to be confirmed.

What gave this disclosure a "when and where do you submit it" operational face was MEXT's "Guidelines on the Proper Execution of Competitive Research Funding." Revised on December 17, 2021,2 the guidelines introduced a mechanism in which researchers disclose, at the time of application, the status of their applications for and receipt of other domestic and overseas research funds, secondary employment, and so on, via e-Rad (the Cross-ministerial Research and Development Management System) and similar systems. It has generally applied to calls for proposals from around FY2022. For researchers applying for competitive funding, this disclosure effectively became a gateway check. It is safest to make a final confirmation of the exact fiscal year of application in each call's guidelines, but the direction is clear: disclosure is no longer a voluntary request; it has become a precondition for obtaining research funding.

MEXT went further, conducting follow-up surveys of each institution's status of initiatives in FY2021, FY2023, and FY2024.3 On December 18, 2024, it compiled "Concrete Directions for Initiatives in MEXT-Related Measures Toward Ensuring Research Security at Universities and Other Institutions,"4 and on April 10, 2025, it announced the establishment of the "MEXT Research Security Consultation Desk." That it did not stop at creating the system but also prepared a place where the field can seek advice should be reassuring for practitioners.

The "specified categories" of deemed exports: how residents also become subject to control

If information disclosure is the foundation of research integrity, then in the field of research security the point most likely to cause hesitation is the "deemed export." Article 25(1) of the Foreign Exchange and Foreign Trade Act (FEFTA / Act No. 228 of 1949) regulates the provision of specified technology from a resident to a non-resident in the same way as the export of goods.5 Even if the technology does not cross a border, the moment you show technical documents domestically, explain something online, or hand over server access rights, it can become an "export" requiring permission from the Minister of Economy, Trade and Industry.

Here is what connects directly to universities: the creation of the "specified categories" through the revision of the Services Notification that took effect on May 1, 2022.6 Previously, a foreign national who had passed six months after entering the country was treated as a "resident" and outside the scope of control, but that interpretation was reviewed. Even a resident can become subject to permission just like a provision to a non-resident (a deemed export) if they fall into any of the following three categories.

The first is a resident who has an employment or similar contract with a foreign government, foreign corporation, or the like, and is subject to its direction or owes it a duty of due care. Employees seconded from overseas subsidiaries, or researchers holding research contracts with foreign-government-affiliated institutions, are typical. The second is a resident who receives, or has promised to receive, 25% or more of their annual income (scholarships, research funds, remuneration, and the like) in economic benefit from a foreign government or foreign corporation. Many government-sponsored international students may fall here. The third is a resident who acts in Japan under the instructions of a foreign government. Because nationality is irrelevant, a Japanese researcher is also covered if the conditions align.

The key in practice is the procedure for how you confirm applicability. METI published Services Notification Annex 1-3, the "Guideline on Determining the Applicability of the Specified Categories," and provides a safe-harbor framework: if you have confirmed applicability using documents customarily obtained in commercial practice, such as a resume or employment contract, you are deemed to have fulfilled the "duty of care normally to be discharged."6 Annex 1-4 contains a template pledge, which each organization may modify to its own format within a range that does not undermine the content. Conversely, an operation that merely asks orally and keeps no record can be a fatal wound if the person is later found to be covered. METI's "Collection of Near-Miss Cases on Security Export Control at Universities and Research Institutions" (updated September 2023) also records several oversight cases that could fall under the specified categories, such as a university's failure to grasp an international student's receipt of a scholarship. For the detailed patterns of the specified categories and practical measures for foreign-national employment and joint research, we go deeper individually in Understand the Specified Categories of Deemed Exports in Five Minutes. It also helps to keep the procedure for technology classification—whether your technology falls under list controls or catch-all controls—in view, so the overall picture of judgment connects.

Where the research security procedures manual meets the Economic Security Promotion Act

"So what should our institution do, and how?" The guide for this is the research security procedures manual compiled by the Cabinet Office's "Expert Panel on Ensuring Research Security and Research Integrity." This expert panel convened on April 18, 2025 and met seven times in total.7 On July 18 of the same year it presented the "Procedures Manual for Initiatives to Ensure Research Security (Draft)," and in December 2025 it published the official version, the "Procedures Manual for Initiatives to Ensure Research Security."8 In other words, an official national guide that each institution can rely on is now in place. MEXT also began pilot research security initiatives in some of JST's R&D programs from FY2025. The design evaluates risk case by case, narrows the targets, and expands in stages. Rather than casting a net over all research at once, you start where the risk is highest. This realistic approach fits the reality of research sites, which have no choice but to run on limited people and budgets.

There is one more thing that hits universities and researchers: the point of contact with the Economic Security Promotion Act (the Act on the Promotion of Ensuring Security by Taking Integrated Economic Measures / Act No. 43 of 2022). This law is built on four pillars: the stable supply of critical materials, the stable provision of core infrastructure, support for the development of specified critical technologies, and the non-disclosure of patent applications. The latter two connect directly to research outcomes.

The patent non-disclosure (security designation) system took effect on May 1, 2024. It is a mechanism to restrict publication and foreign filing, and to apply a security designation, for sensitive inventions that could be diverted to nuclear, weapons, and similar uses. Because inventions and applications by universities and researchers can also be covered, an economic security issue arises at the stage of filing research outcomes. The research sense of urgency—"we want to publish quickly"—collides head-on here with the security requirement to "stop sensitive technology at the filing stage." The other pillar, support for the development of specified critical technologies, is operated as the Key and Advanced Technology R&D Through Cross Community Collaboration Program (commonly known as the K Program), which has a "council" framework (with confidentiality and information-management obligations) in which participants handle sensitive information. In settings where industry, academia, and government share sensitive technology, the practice of research security is directly put to the test. For the four pillars of the Economic Security Promotion Act and the amendment trends in 2026, What Is the Economic Security Promotion Act? explains the whole picture, so please also see it if you want to understand the system from its backbone.

Concrete risks universities and research institutions face, and the AIST case

Since the discussion has focused on the system, let me look concretely at what happens in the field. Universities and research institutions are places where cutting-edge basic research gathers, yet they have a culture that prizes open information sharing, and they cannot devote as many people or as much budget to security as companies can. That is why they are easy to target. I believe this should be accepted as a sober fact.

Risk typically surfaces in situations such as accepting international students or visiting researchers, joint research with overseas institutions, accepting secondees from overseas subsidiaries, and collaboration with graduates of the "Seven Sons of National Defense" (a common name for the seven Chinese universities said to be deeply involved in national defense). These are all activities that internationalized research cannot avoid, and that is precisely why leaks can occur even without malice. The difficulty of research security is concentrated here.

What drove home what actually happens was the case of a former chief researcher at the National Institute of Advanced Industrial Science and Technology (AIST). According to reports, the person was charged with violating the Unfair Competition Prevention Act (disclosure of trade secrets) for emailing research data related to a synthesis technology for insulating gas to a Chinese company in 2018, and the Tokyo District Court is said to have handed down a guilty verdict on February 25, 2025 (two years and six months of imprisonment, suspended for four years, plus a fine of 2 million yen). Because I have not been able to confirm the judgment itself as a primary source, I will avoid stating it as definitive; but the fact that this can happen even at a national research institution spread a sense of crisis among many researchers and administrators. Technology leakage is not "someone else's problem." It can happen in the lab next door. Re-framing it that way is the starting point of countermeasures.

A blueprint for practical response: four steps to meet the "duty of care normally to be discharged"

So where do you start? What I always tell universities and research institutions in consultations is to nail down the following four things in order. There is nothing flashy about them, but this is the shortest route to meeting the "duty of care normally to be discharged" that the national guidelines require.

  1. Clarify the person in charge and the internal rules. Decide who makes the final call and which department runs the practical work. Without this, the field cannot move.
  2. Make pre-acceptance background checks and pledges a habit. For international students, visiting researchers, and joint-research partners, obtain documents in line with METI Guideline Annex 1-3 (resume, employment contract, and the like) and keep a pledge conforming to Annex 1-4. Do not settle for oral confirmation alone.
  3. Build information disclosure into operations. Establish, as part of the application process, the flow of disclosing other research funds, secondary employment, and support from foreign governments via e-Rad when applying for competitive research funding.
  4. Get technology classification, access control, and evidence retention in order. Determine whether your technology falls under list controls or catch-all controls, manage access rights to sensitive technology, and keep logs of who was provided what, and when.

If you try to run these four steps on paper, Excel, and the memory of the person in charge, it usually breaks down. The reason is simple: control lists are revised frequently, and the confirmation work is a multiplication of "the attributes of the counterpart (person or institution)" and "the classification of the technology." Every time you accept a single international student, you have to investigate whether that person has an employment or funding relationship with a foreign government, whether they have any connection to an entity list or a concerning institution, determine whether the technology involved is subject to control, and keep records. Continuing that multiplication by hand alone, without dropping anything, has frankly reached its limit.

The reality that hands cannot keep up, and the choice to systematize

At the risk of blowing my own horn, the very reason we build TRAFEED (formerly ZEROCK ExCHECK, an export control AI agent) lies in the load of this multiplication. TRAFEED is designed in conformity with METI standards and supports the research security practice of universities and research institutions in a single workflow. In pre-acceptance screening of foreign international students, visiting researchers, and joint-research partners, it identifies points that could fall under specified categories 1 through 3, from matching against employment and funding relationships with foreign governments and against entity lists. It supports the classification of whether the technology under research falls under list controls or catch-all controls, and connects everything from determining the specified categories to issuing pledges (conforming to Services Notification Annex 1-4) and retaining provision logs as evidence.

To put a number on it, we have confirmed an AI determination accuracy of 95% or higher, based on a joint demonstration with Okayama University and roughly 30,000 past review records (our own research). That said, this is ultimately a tool to assist judgment. The final classification is made by your institution's export control officer. AI cannot promise to "reduce risk to zero," and if a product claims it can, I think you should be suspicious of it instead. Leave the confirmation and recording—where hands tend to drop things—to the machine, and have people take responsibility for the judgment itself. I believe this division of roles is the realistic answer for meeting the duty of care the national guidelines require while keeping the institution's burden down. What it can do as a system is summarized on the TRAFEED service page.

Conclusion: research freedom and security can coexist

Research integrity and research security are no longer matters that concern only a handful of designated staff. From the 2021 policy to the 2025 research security procedures manual, the government has built the framework one piece at a time and has shown, quite concretely, what universities and research institutions must do.

Finally, let me organize the points to return to when you get stuck in practice.

  • Research integrity is founded on information disclosure (e-Rad and the competitive research funding guidelines). Research security is founded on pre-acceptance checks and technology classification.
  • The specified categories of deemed exports can cover residents and Japanese researchers too. Documents and records in line with Annexes 1-3 and 1-4 are the key to the safe harbor.
  • Rely on the Cabinet Office's research security procedures manual (December 2025) and MEXT's consultation desk (established April 10, 2025).
  • With patent non-disclosure (effective May 1, 2024), sensitive inventions now require an economic security check from the filing stage.

What I want to emphasize is that this is not about shackling research freedom. If an organization can be conscious of whom it partners with and what it protects, it can, if anything, step into international joint research with greater peace of mind. Strengthening your defense supports research that goes on the offensive. That is the relationship I see. If you have concerns about your acceptance-review or technology-classification setup, start by taking stock together of where risk may be lurking in your current operations through a one-on-one TRAFEED consultation.

Note that the statute numbers, enforcement dates, sentencing, and the like mentioned in this article are stated based on published materials and reports. In particular, the sentencing in the AIST case is report-based, and the details of the system and the fiscal years of application may change with each institution's operation. When you actually apply or build your systems, please make a final confirmation against the primary sources below and the latest calls for proposals and notifications.


References and primary sources

Footnotes

  1. Cabinet Office, Bureau for Science, Technology and Innovation, "Research Integrity" https://www8.cao.go.jp/cstp/kokusaiteki/integrity.html 2 3

  2. MEXT, "Research Integrity / Research Security" https://www.mext.go.jp/a_menu/kagaku/integrity/index.html

  3. MEXT, "Follow-up Survey on the Status of Initiatives to Ensure Research Integrity" https://www.mext.go.jp/a_menu/kagaku/integrity/followup.html

  4. MEXT, "Concrete Directions for Initiatives in MEXT-Related Measures Toward Ensuring Research Security at Universities and Other Institutions" (December 18, 2024) https://www.mext.go.jp/content/20241218-mxt_kagkoku-000039402_1-1rrr.pdf

  5. Foreign Exchange and Foreign Trade Act (Act No. 228 of 1949), e-Gov Law Search https://laws.e-gov.go.jp/law/324AC0000000228

  6. METI, "On the Clarification of Deemed Export Control Operations" (Specified Categories, effective May 1, 2022) https://www.meti.go.jp/policy/anpo/law_document/minashi/meikakukanitsuite2.pdf 2

  7. Cabinet Office, "Expert Panel on Ensuring Research Security and Research Integrity" https://www8.cao.go.jp/cstp/kokusaiteki/integrity/yushikisha.html

  8. Cabinet Office Expert Panel, "Procedures Manual for Initiatives to Ensure Research Security" (December 2025) https://www8.cao.go.jp/cstp/kokusaiteki/integrity/yushikisha/guidelines_v1.pdf

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

シェア

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

無料診断ツール

輸出管理のリスク、見えていますか?

まず5問(約2分・メール不要)のライト診断。必要なら10問本編で詳細レポートまで。

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles