Hello, this is Ryuta Hamamoto from TIMEWELL.
When I talk with university faculty and research administration staff, the questions have changed noticeably over the past six months. It used to be, "Research integrity is basically about research misconduct, right?" Now it is, "What do we actually have to verify for our joint research starting next fiscal year?"
There is a clear reason for the shift. In December 2025, an expert panel convened by Japan's Cabinet Office published the Procedures Manual for Ensuring Research Security1. Its roadmap places research security and research integrity side by side as work beginning in fiscal 2026. The conceptual debate is over. This is now something that lands in application guidelines and lands on someone's desk.
I want to start from what research integrity and research security actually mean, explain why so many countries arrived at this problem at the same time, and then walk through what the manual concretely asks for, using the government's own documents. I will unpack the jargon as I go. At the end, I will explain why we are extending TRAFEED into this territory, and what we intend to build.
Research integrity and research security protect different amounts of ground
Let me start with the vocabulary, because if a team gets this wrong the internal discussion never converges.
The manual defines both terms carefully. Research integrity is "the awareness and behaviour that research institutions and researchers are required to observe in order to maintain the soundness, fairness and transparency of research activities," and it covers all research activities. Research security is "the awareness and behaviour required of research institutions and researchers in order to protect research activities from risks that threaten national and economic security," and it covers research activities that the state or the research institution has determined should be protected1.
The decisive difference sits in those closing clauses. The two have different scopes.
Research integrity is the foundation, and it applies to everything. Be honest about where your funding comes from, which institutions you hold positions at, and who you work with. Manage conflicts of interest and conflicts of commitment. That is a matter of ordinary professional honesty, and it holds whether or not your work touches sensitive technology. Research security is the narrower layer placed on top, applied only to the research someone has decided to protect. It was never designed to cover everything.
This point gets misread often, so it is worth dwelling on. The manual states outright that it does not ask institutions or researchers for zero risk. The reasoning is refreshingly blunt: doing so "would require enormous labour and cost to verify information about counterparts, or would make research institutions and researchers excessively restrained about international joint research, adversely affecting the research environment. If this ends up impeding research, it defeats the purpose"1. The government is saying, in its own document, that the point is to keep research moving.
There is one more sentence the manual goes out of its way to include. In judging whether a counterpart is a trustworthy partner, "there must of course be no discriminatory treatment on grounds of nationality, race, religion, culture or the like"1. MEXT's document says the same thing2. I do not read that as decorative language. It is structural. If your team is unsure whether its technology or collaborators fall within export control scope, our free export control self-check is a reasonable place to get your bearings.
Why this is happening in so many countries at once
People sometimes describe this as Japan suddenly tightening up. The truth runs the other way. Among G7 members, Japan is catching up rather than leading.
The starting point is openness itself. Publish results widely, collaborate across borders with many kinds of partners. That principle is why science has advanced, and Japan has benefited enormously from it. The manual's introduction opens by affirming exactly that.
What changed is that leadership in science and technology became an input to national economic security. The manual puts it this way: "some organisations and actors are exploiting the very ideal of the open and free research environment that our country has upheld, seeking to gain an advantage in science and technology by improperly acquiring critical technologies"1. Notice that no country is named. I take that as deliberate. The regime is built so that anyone, from anywhere, goes through the same verification.
International alignment became explicit at the G7 in June 2022, when the Security and Integrity of the Global Research Ecosystem (SIGRE) working group published a set of common values and principles on research security and research integrity3. The concept it advanced was shared responsibility: no single organisation can handle research security alone, so every member of the research community needs to understand their own role.
Implementations differ. In the United States, building on the CHIPS and Science Act and NSPM-33, the National Science Foundation introduced its TRUST framework and began applying risk assessment and mitigation at the proposal stage from 2025, starting with quantum. With NSF backing, six universities host SECURE centres for information sharing24. Canada publishes a sensitive technology list and a named research organisation list, and requires attestations covering all applications. The UK maintains its Trusted Research Guidance and set up RCAT as an advice line. France protects designated laboratories as restricted zones under its scientific and technical potential protection regime, and Germany's DFG asks applicants in international collaborations to submit a self-assessment of research risk1.
Different machinery, same principles. The manual summarises the shared Western position as "small yard and high fence" and "as open as possible, as closed as necessary"1. Fence a small area, but fence it properly. Precisely because the protected set is narrow, everything outside it can stay genuinely open.
For Japanese universities there is also a practical, self-interested angle here. MEXT lists as one target category those programmes involving "international joint research with countries sharing common values, where equivalent measures are expected of the partner"2. If your counterpart country has research security procedures and you do not, you stop being an attractive partner. This is a defensive measure and an admission ticket at the same time.
Replace siloed classification work with AI.
METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.
What actually begins in fiscal 2026
This regime did not appear overnight. It accumulated over five years.
It begins on 27 April 2021, when the Integrated Innovation Strategy Promotion Council adopted its policy on ensuring research integrity against the new risks accompanying the internationalisation and opening of research activities5. That document set out the pillars: appropriate disclosure by researchers, institutional systems, and action by funding agencies. In practice it means declaring all research funding applied for and received, domestic and foreign, and all affiliations and positions, including concurrent posts and participation in foreign talent programmes.
What strikes me is that the link to export control was written in as early as 2021. Among the points to note, METI was asked to provide information and consultation on "cases of concern, such as joint research with institutions that are not on the End User List published by the ministry but that are subject to restrictions abroad"5. Five years ago, a government document already stated that checking Japan's own list is not sufficient. That turns out to matter enormously in practice, as I will come back to.
Then on 18 December 2024, MEXT published its direction for concrete measures on research security at universities2. In December 2025 the Cabinet Office expert panel finalised the procedures manual, and from fiscal 2026 the work under that manual begins1.
Three characteristics of the regime are worth holding onto.
First, the manual is guidance, not law. The stated reasoning is that appropriate responses vary with the field, the technology readiness level and the institution's circumstances, so a flexible framework is preferable, and that G7 countries generally use guidance rather than legislation for this1.
Second, the requirements come in two tiers. Passages written as "necessary" are the minimum measures; passages written as "desirable" are the ones worth doing but not yet required1. Not everything carries the same weight.
Third, the scope is narrow. Risk management applies to Specified Research and Development Programs, which are competitive research funds premised on public disclosure that a supervising ministry has designated, in consultation with the funding agency, as potentially involving technologies on the critical technology area list1. Research funded by operational grants, and competitive funds that have not been designated, fall outside the direct scope, though the manual encourages comparable treatment.
On penalties, because these are competitive research funds, violations may be handled as improper receipt under the Guidelines on Proper Execution of Competitive Research Funds, which can restrict future applications. But the manual also says clearly that even where the required measures were properly carried out, a leak may still occur, and in that case institutions and researchers do not bear responsibility1. What is being policed is deliberate false reporting or concealment, not outcomes. For anyone worrying about the psychological burden on their faculty, that distinction matters a lot.
The four steps, and the 13 due diligence checks
So what does the work look like? The manual sets out risk management as four procedures. Risk identification, meaning working out what risks are conceivable. Risk assessment, judging what impact those risks would have and how likely they are. Risk mitigation, implementing measures to reduce them. And follow-up, verifying after the fact that all of this actually happened1.
The people in scope are the PI, any Co-PI representing a partner institution, and research participants belonging to the lead institution. Research participants include students1. Every time a student joins the lab, the population grows. That is an operational load people tend to underestimate.
At the centre sits due diligence, the process of confirming the suitability of the institutions and researchers taking part. The manual lists 13 items.
| # | Item to verify |
|---|---|
| 1 | Academic background, including supervisors where relevant |
| 2 | Research and employment history |
| 3 | Research funding received |
| 4 | Non-funding support received |
| 5 | First, corresponding and co-authors on published papers |
| 6 | Patent filings, including co-inventors and co-applicants |
| 7 | Participation in foreign talent recruitment programmes |
| 8 | Disciplinary history under the guidelines |
| 9 | Whether the person appears on a list |
| 10 | Whether the person belongs to a listed institution |
| 11 | Whether the person has relationships with researchers at listed institutions |
| 12 | Status as a non-resident or under the deemed export specific categories |
| 13 | Anything else the funding agency deems necessary |
Items 3 through 8, plus 10 and 11, must cover the past three years, including the year of application1. This is a history, not a snapshot.
Item 11 comes with a definition. Relationships means conducting joint or commissioned research, writing and publishing co-authored papers, and appearing as a named co-presenter at conferences1. Sharing a slide at a conference counts.
Item 12 comes from the export control side. It refers to the specific categories introduced when Japan clarified deemed export management, effective from May 2022. Under the Foreign Exchange and Foreign Trade Act, providing controlled technology from a resident to a non-resident requires a licence, but foreigners are treated as residents once six months have passed since entry, which left a gap. The services notification was therefore amended to make clear that providing technology to a resident who is under strong influence from a foreign government or entity is also covered. The three categories are: someone under the control of a foreign government or foreign entity through an employment or similar contract; someone under the substantive control of a foreign government through economic benefit; and someone acting in Japan under the instruction of a foreign government. The authoritative definitions live in the services notification itself6.
For universities, the examples given include faculty holding concurrent appointments at foreign universities, students receiving study funding from a foreign government, and researchers who participate in a foreign government's science and engineering talent programme and personally receive substantial research funding or living expenses6.
Here I want to quote a sentence that METI repeats twice in the same deck: "the specific categories are simply a typological grouping of cases requiring individual verification during screening, and falling under a specific category does not mean the person is regarded as posing a security concern"6. A procedural classification, not a verdict on a person. When explaining any of this to lab members, I think that sentence has to travel with it.
Mitigation, by contrast, is often modest. The examples include managing access rights to facilities and equipment, considering who attends meetings based on the sensitivity of what is discussed, strengthening governance through employment contracts where a research participant is a student, managing access rights to research data, and hardening against cyberattack. The manual says measures need only be "reasonable and proportionate to the degree of risk"1. The philosophy stays consistent throughout.
The part where institutions actually get stuck: tracing relationships
Reading through the manual, the passage that stopped me was the boxed note listing the tools to use for due diligence: academic paper databases, portals such as Google Scholar, research databases such as e-Rad and researchmap, IP databases such as J-PlatPat, METI's End User List, and the United States consolidated screening list1.
Papers, patents, researcher records, and national lists. Laid out like that, the sources obviously span several different domains. And immediately afterwards the manual adds: "where the information gathered using these tools is insufficient for adequate due diligence, using commercial information analysis tools or commissioning investigations from firms may also be considered"1. A government document explicitly anticipating commercial tooling is worth noticing.
Why is manual effort so hard here? The answer is item 11.
Items 9 and 10, listing status and institutional affiliation, are still matching problems. Compare names and you get an answer. Item 11, relationships with researchers at listed institutions, is a different animal entirely. The researcher in front of you appears on no list. Neither does their institution. You still have to establish whether following their co-authors leads to a researcher at a listed institution.
Matching will not solve that. You have to traverse a network of people, papers, patents and organisations. Across three years. Including co-authored papers, joint research, and named conference presentations. Now picture a research administration office of a few people doing that by hand for every PI, every Co-PI, and every research participant including students, every time a proposal goes out. The arithmetic does not work.
There is also more than one list to check against. The 2021 policy I mentioned earlier already flagged institutions absent from Japan's End User List but subject to restrictions abroad5. That is precisely why the manual pairs the US consolidated screening list with domestic sources. Check only the Japanese list, conclude "no match," and that conclusion may not hold up in a collaboration where the partner country expects equivalent measures.
This is the same structure we have spent years dealing with in export control at TRAFEED. Regulations are updated by each country separately, on their own schedules. And what you actually need to see is less the name on the list than the relationship between that name and your counterpart. Research security due diligence is that same problem in a purer form.
Extending TRAFEED into an economic security compliance platform
Let me talk about where we are taking this.
TRAFEED has been built as an AI agent for export control, centred on classification and counterparty screening. Our internal research as of March 2026 confirms it as the world's first AI agent in Japan's security export control domain covering list and catch-all regulations7, and we hold a Japanese patent (No. 7862062). In joint validation with Okayama University, using roughly 30,000 past screening records, we confirmed AI classification accuracy of 95% or higher (internal study). More than 20 organisations have adopted it.
Having built that, keeping it confined to export control started to feel wrong. What we want to build is a platform for economic security compliance. Export control, research security and counterparty due diligence all reduce to the same question: who is this counterpart, and what are they connected to? The regimes have different names, but the underlying information base overlaps to a surprising degree.
What made the decision easy is that the technical stack was already sitting there. TRAFEED holds a knowledge graph of more than 200 million records: roughly 90 million papers, roughly 100 million patents, and roughly 300,000 researchers, alongside corporate lists and national sanctions lists.
Line that up against the manual's due diligence items and the correspondence is hard to miss.
| Item in the manual | Source required | What TRAFEED holds |
|---|---|---|
| 5. Authorship on published papers | Academic paper databases | ~90 million papers |
| 6. Patent filings, co-inventors and co-applicants | IP databases | ~100 million patents |
| 2. Research history, 10. affiliation with listed institutions | Research databases | ~300,000 researchers |
| 9–11. Listing status and relationships | National lists | Corporate and sanctions lists |
| 12. Non-resident and specific category status | Export control determination | Existing classification engine |
Holding papers, patents, researchers and organisations as a graph rather than as separate tables is what makes item 11 tractable. Walk the co-authorship edges one hop, then two, and surface whether a path reaches a researcher at a listed institution. A search that is unrealistic by hand becomes a computation. We accumulated that data for export control, and it turned out to be shaped almost exactly like what research security asks for. That is the honest version of the story.
From here we plan to add research security capabilities on top of that base, in stages: verification reports structured around the 13 items, management organised by PI, Co-PI and research participant, visualisation of co-authorship and co-filing networks, tracking of list updates across countries with change notifications, and output that supports drafting answers to the questionnaires funding agencies require. The idea is to reconcile what researchers declared through the integrity checklist against what public sources say, and show a human only the differences worth examining.
I want to be clear that none of this hands the judgment to a machine. Just as the final classification decision in export control rests with each organisation's export control officer, risk assessment and mitigation decisions in research security rest with the research institution. That is what the manual asks for too. Our job is to assemble the material behind that decision completely, with sources attached, quickly, and to leave a record that explains afterwards why the conclusion was what it was. Building an audit-ready trail is something we designed in from the beginning on the export control side.
For the detailed operational side, such as drafting internal regulations or the specific deemed export verification steps, I have set that out with statute names and effective dates in Research Integrity and Economic Security at Universities. If you want the concepts explained more gently first, there is also What Are Research Integrity and Research Security?. Related regimes worth knowing about include the K Program and Japan's security clearance system.
Closing thoughts
Fiscal 2026 is the year research security moves from discussion to operation. The points I would keep in front of me:
- Research integrity covers all research; research security covers only what has been designated for protection. That difference in scope is where the practical work starts
- The manual is guidance, not law, and it refuses to demand zero risk. Scope is limited to Specified Research and Development Programs, and requirements are split between necessary and desirable
- Risk management runs in four steps, and due diligence has 13 items, most covering three years. Research participants, students included, are in scope
- Both the manual and MEXT's document state that discrimination by nationality or race is unacceptable. Falling under a specific category does not mean someone is a concern
- The heaviest part is not list matching. It is tracing relationships through co-authorship and co-filing
What I find well designed about this regime is that narrowing the protected set is exactly what lets everything else stay open. "Small yard and high fence" reads to me as a way of defending academic freedom rather than trimming it. But keeping the yard small requires knowing precisely where the boundary should fall, and I do not think human judgment and intuition alone get you there. That is the reason we are building the data layer.
If you are working out how to structure your own institution's response, or simply where to start, talk to our TRAFEED team. The research security features are still being built, so hearing what is actually causing pain on the ground is genuinely useful to us.
References and primary sources
Footnotes
-
Expert Panel on Ensuring Research Security and Research Integrity, "Procedures Manual for Ensuring Research Security," December 2025 (Cabinet Office) https://www8.cao.go.jp/cstp/kokusaiteki/integrity/yushikisha/guidelines_v1.pdf ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19
-
MEXT, Science, Technology and Innovation Policy Bureau, "Direction of Concrete Measures on Research Security in MEXT-Related Programmes for Universities and Other Institutions," 18 December 2024 https://www.mext.go.jp/content/20241218-mxt_kagkoku-000039402_1-1rrr.pdf ↩ ↩2 ↩3 ↩4
-
G7 Security and Integrity of the Global Research Ecosystem (SIGRE) Working Group, "G7 Common Values and Principles on Research Security and Research Integrity," June 2022 (Japanese provisional translation) https://www8.cao.go.jp/cstp/kokusaiteki/integrity/g7_sigre_values_jpn.pdf ↩
-
National Science Foundation, "NSF enhances research security with new TRUST proposal" https://new.nsf.gov/news/nsf-enhances-research-security-new-trust-proposal ↩
-
Integrated Innovation Strategy Promotion Council, "Policy on Ensuring Research Integrity Against New Risks Accompanying the Internationalisation and Opening of Research Activities," adopted 27 April 2021 https://www8.cao.go.jp/cstp/kokusaiteki/integrity/integrity_housin.pdf ↩ ↩2 ↩3
-
METI, Trade Control Department, Security Export Control Policy Division, "On the Clarification of Deemed Export Management" https://www.meti.go.jp/policy/anpo/law_document/minashi/meikakukanitsuite2.pdf ↩ ↩2 ↩3
-
The "world's first" claim refers to an AI agent in Japan's security export control domain covering list and catch-all regulations, confirmed by TIMEWELL internal research as of March 2026. ↩
