TRAFEED

In FY2026, Research Security Became an Application Requirement: Reading the JST and ATLA Designations from the Call Guidelines

Published2026-07-24Ryuta Hamamoto

Research security has moved from principle to procedure. Five CREST research areas under JST's Strategic Basic Research Programs and ATLA's Innovative Science and Technology Initiative for Security have been designated as Specified Research and Development Programs, effective from FY2026. Here is what the call guidelines actually say about scope, the questionnaire, and the consequences of a breach.

In FY2026, Research Security Became an Application Requirement: Reading the JST and ATLA Designations from the Call Guidelines
シェア

Hello, this is Ryuta Hamamoto from TIMEWELL.

One thing about research security changed decisively over the past six months. It became an application requirement.

Until recently this subject lived in the register of principles and policy. Technology leakage has to be prevented, international collaboration has to continue, and the interesting question is how you balance the two. All important, and none of it changes what anyone does tomorrow morning. Then the FY2026 call cycle arrived. Apply to a designated programme and you now have to carry out risk management based on the government's procedures manual. Skip it and your selection is affected.

So this piece is about what was actually designated, and what is actually being asked of applicants, read from the original call documents rather than from summaries. This is precisely the kind of material that drifts as it travels by word of mouth, so I went to JST's 124-page call guidelines directly. For the shape of the regime as a whole, I have written a complete guide to research integrity and research security. For what sits inside the manual itself, see the procedures manual and its 13 due diligence checks.

Start with the misreading, because it is everywhere

Let me correct the thing that has spread furthest.

You will see the claim that "JST's Strategic Basic Research Programs (CREST, PRESTO and ACT-X) are now covered by research security." That is not accurate. The FY2026 call guidelines put it like this.

This programme (specifically the following research areas) has been designated as a "Specified Research and Development Program."1

And the areas listed are five CREST research areas1.

Designated research areas (CREST)
Pioneering uncharted territory in quantum science and technology
Creation of innovative ultra-long-life materials and construction of their theoretical foundations
Creation of fundamental theory and core technologies for intelligent systems operating in real environments
Creation of an interdisciplinary system foundation for a society where people and AI coexist and collaborate
The fusion frontier of light with information, communications, sensing and materials

The opening pages of the guidelines carry the same notice, stating that measures to ensure research security will be taken for these five areas1. The designation did not fall on the funding programme as a whole. It was applied area by area.

The scope of projects and institutions is spelled out too. The requirement applies from projects newly selected in FY2026, and the institutions in scope are those recognised in the commissioned research contract as "universities and equivalent institutions" or "companies and equivalent entities"1. Ongoing projects are not the dividing line. New selections are.

I am being fussy about this because the practical consequences run in opposite directions. If the call you are preparing for is not one of the five areas, none of this procedure touches you directly this year. If it is, you need to have shared the requirement with the responsible department at your institution before you submit. The guidelines say so themselves, asking applicants to "share the following content sufficiently with the responsible departments at the institutions of the principal investigator and the main co-investigators before making the proposal"1. That is the kind of requirement you cannot satisfy if you notice it the night before the deadline.

If I had to pick the single most common error, it is the assumption that the whole of the Strategic Basic Research Programs was swept in at once. CREST is the team-type track, and PRESTO and ACT-X sit alongside it under the same umbrella. The designation reached five research areas inside one of those three tracks. Read the guidelines for the call you are actually applying to, and read the area list rather than the programme name.

While you are checking scope, it is also worth knowing whether your technology or your collaborators sit inside export control scope in the first place, since the two questions overlap more than most teams expect. Our free export control self-check takes a few minutes and is a reasonable place to get your bearings.

ATLA's programme came into scope as well

There is a second programme that became subject to this from FY2026: the Innovative Science and Technology Initiative for Security, run by the Acquisition, Technology and Logistics Agency (ATLA) as commissioned research.

That programme has become a target programme under the procedures manual compiled in December 2025 by the Cabinet Office expert panel on ensuring research security and research integrity, which is to say a Specified Research and Development Program. The FY2026 call ran from 13 March 2026 until noon on 20 May 20262. The call guidelines added a set of new sections: the designation as a Specified Research and Development Program, the specific content of risk management, the deadline for submitting the results of risk management and how they are confirmed, the handling of personal information, and the measures to be taken where a breach of the manual occurs2.

Line the JST and ATLA documents up side by side and the section structure is close to identical. That is not a coincidence. Each agency has taken the same set of tasks that the manual assigns to funding agencies and written them into its own call guidelines. When other funding agencies designate Specified Research and Development Programs, I would expect the same skeleton to appear again, with the names changed.

Which means something useful for people who are outside the scope today. If you read one of these sections now, you are reading next year's requirement early. Two agencies have published their version of it. The pattern is visible. There is no reason to wait until your own funder publishes theirs before working out how your institution would answer.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

What actually happens once you apply

So you apply to one of the designated areas. What follows? Here is the sequence as JST's call guidelines describe it1.

The starting point is a request to carry out risk management. From the standpoint of ensuring research security, JST asks the research institution of the principal investigator, and the research institutions of the main co-investigators, to carry out risk management based on the procedures manual. Note who receives that request. It goes to the research institution, not to the individual researcher. This is not a matter of a PI working harder on their own. It presumes an institutional system exists to receive the request.

Next comes the questionnaire. The content of the risk management to be carried out is to be based on the manual, and specifically it is determined through consultation between JST, the principal investigator and the research institution, on the basis of responses to a "Questionnaire on Research Security" that is sent separately to the principal investigators of projects that, among the candidates for selection, have been made subject to risk management. The order matters here. Scope is fixed after you become a candidate for selection, not at the moment of application. The questionnaire does not go out to every applicant.

Submitting the response carries conditions. The principal investigator must obtain the consent of the main co-investigators, and confirmation from the responsible departments at the institutions of both the PI and the main co-investigators, before submitting. On that responsible department, the guidelines go out of their way to write "including, where a department with responsibility for research security and research integrity has been established, that department"1. Read that backwards and it tells you something. The existence of such a department is being treated as the assumed baseline. For institutions that have not designated one yet, that is the first piece of homework, and it has to be done before a questionnaire lands rather than after.

Then comes review, and possibly a second round. JST and MEXT confirm the response, and depending on the result they may, where necessary, request that the research institutions of the PI and the main co-investigators implement additional risk mitigation measures1. So the questionnaire is not a form you file and forget. It can generate a round trip, and the round trip has to fit inside the selection timetable. When you plan backwards from the selection date, leave room for it.

The handling of personal information is set out explicitly as well. Personal information about researchers that is provided may be used, within the necessary scope, by JST and also by MEXT, the Cabinet Office and other government bodies that receive it from JST, for the purpose of carrying out risk management to ensure research security1. Anyone on the collecting side of this should be able to explain that sentence to the person being asked. The manual itself requires that when an institution receives declarations of personal information from a researcher, it obtains a consent form and a written pledge3.

One thing I would ask everyone to carry into those conversations. The manual states that in judging whether a counterpart is a trustworthy partner there must be no discriminatory treatment on grounds of nationality, race, religion, culture or the like3. That sentence is structural rather than decorative. Being listed by any government, or falling into any procedural category, is a regulatory classification and never a verdict on the person or the institution. Japan's Ministry of Economy, Trade and Industry says as much about the deemed-export specific categories, stating plainly that they are a grouping of cases requiring individual verification during screening and that falling under one does not mean a person is regarded as posing a security concern. I unpacked that point in the due diligence article. If a questionnaire circulates in a lab without that framing attached, the wrong lesson gets learned very quickly.

How to approach the questionnaire itself, question by question, I cover in how to complete the research security questionnaire.

What happens if you breach the manual

The penalty language made it into the call guidelines too, and it is worth reading slowly.

JST's guidelines state that, in accordance with the manual, a breach of the manual may, taking into account how egregious the act was and how serious the consequences it caused were, be treated as an act of improper receipt under the "Guidelines on Proper Execution of Competitive Research Funds" (agreed by the inter-ministerial liaison meeting on competitive research funds, 9 September 2005), and that restrictions on applying to this programme and others may be imposed on the researcher who improperly received funds and on researchers who conspired with them1.

Read that calmly and the mechanism becomes clear. The procedures manual is guidance, not legislation. But because the money involved is competitive research funding, the breach is routed through an existing framework that already has teeth, and it emerges at the other end as a restriction on future applications. "It is only guidance, so it is soft" is a misreading of how this is put together.

The manual also says the opposite thing in the other direction, and this half gets quoted far less often. Even where the required measures have been properly carried out, it is anticipated that technology leakage may still not be prevented, and in that case the research institution and the researchers do not bear responsibility3. What is being policed is not the outcome. It is whether there was deliberate false declaration or concealment.

I think that distinction has to be stated every single time this is explained internally. If a faculty meeting hears "you will be punished if something leaks" and nothing else, what you get is not better security. What you get is people quietly declining international collaborations they should have accepted, which is the outcome the manual explicitly says it does not want. The chilling effect is the failure mode here, and it is entirely avoidable with one extra sentence.

What institutions applying this year should actually do

Let me put this on a timeline.

Before you submit, identify the responsible department and share the requirement inside the institution. Since the call guidelines specifically ask for sharing before the proposal is made, a researcher carrying this alone through to submission is the pattern to avoid. If no department has responsibility for research security and research integrity, decide on a provisional contact point rather than leaving it blank. Support does exist outside your walls: MEXT set up a consultation desk on 10 April 2025, and has indicated it will support platforms for cooperation between universities and develop training materials4. Nobody has to work this out in isolation.

Between calls, build the routine information gathering. The manual treats the collection of declarations based on the research integrity checklist as necessary for institutions to do on an ongoing basis, and treats the collection of information on research outputs such as paper submissions and publications, and on intellectual property such as inventions and patents, as desirable. It also describes as desirable the establishment of a system in which the relevant departments cooperate to manage this information centrally3. The design assumption is that this accumulates over time. Scrambling to assemble three years of history in the two weeks after a selection notice is not the process anyone intended.

After you become a candidate for selection, prepare for the round trip. The questionnaire response needs the consent of main co-investigators and confirmation from the responsible department at both institutions. Every additional partner institution adds another party to coordinate with, and international partners add time zones and translation on top. Additional mitigation measures may then be requested. Working backwards from all of that, my honest reading is that starting when the candidate notification arrives is already slightly late.

And the due diligence work itself is heavy. I will not pretend otherwise. Of the manual's 13 verification items, most cover the past three years including the year of application. Item 11, relationships with researchers at listed institutions, has to account for co-authored papers, joint and commissioned research, and named co-presentations at conferences, so it cannot be closed out by matching names against a list. The manual lists the tools to use, academic paper databases, intellectual property databases and the lists published by various countries, and then adds that "where adequate due diligence is difficult using only the information gathered with these tools, using commercial information analysis tools or commissioning investigations from firms may also be considered"3. A government document anticipating commercial tooling is a fairly direct signal about the workload.

That last item is where the arithmetic breaks for a research administration office of a few people. Items 9 and 10 are matching problems: is this person listed, is this institution listed. Answerable. Item 11 is a network problem. The researcher in front of you is not listed. Their institution is not listed. You still have to determine whether following their co-authorship and co-filing relationships reaches a researcher at a listed institution, across three years, for every PI, every co-investigator and every research participant, on every proposal. Research participants include students3, so the population grows every time someone joins the lab.

This is the same structure we have spent years working on at TRAFEED in export control. We built TRAFEED as an AI agent for security export control, and our internal research as of March 2026 confirms it as the world's first AI agent in Japan's security export control domain covering both list and catch-all regulations. It holds a Japanese patent (No. 7862062), and in joint validation with Okayama University against roughly 30,000 past screening records we confirmed AI classification accuracy of 95% or higher (internal study). More than 20 organisations have adopted it.

The knowledge graph underneath it now exceeds 200 million records: roughly 90 million papers, roughly 100 million patents and roughly 300,000 researchers, alongside the lists published by various governments. Line that up against the manual's 13 items and the correspondence is close to one for one. Because papers, patents, researchers and organisations are held as a graph rather than as separate tables, walking co-authorship and co-filing edges one hop and then two becomes a computation instead of a manual search. We are extending the same approach from researcher information into the shareholder and capital relationships of partner organisations.

To be clear about the division of labour: risk assessment and the decision on mitigation measures belong to the research institution. The manual is explicit about that, and it matches how export control works, where the final classification decision rests with each organisation's own control officer rather than with any tool. What we take on is assembling the material behind that decision completely, with sources attached, in a short enough time to fit a real deadline, and leaving a record that can explain afterwards why the conclusion was what it was.

Closing thoughts

The points I would keep in front of me this year:

  • Within JST's Strategic Basic Research Programs, five CREST research areas were designated as Specified Research and Development Programs. Not the whole programme
  • The requirement applies from projects newly selected in FY2026, to institutions recognised in the commissioned research contract as universities and equivalent institutions or companies and equivalent entities
  • ATLA's Innovative Science and Technology Initiative for Security also came into scope from its FY2026 call, with near-identical section structure
  • The sequence runs: a risk management request to the institution, a questionnaire to selection candidates, a response submitted with co-investigator consent and institutional confirmation, review by JST and MEXT, and a possible request for additional measures
  • A breach is handled as improper receipt under existing guidelines and can lead to restrictions on future applications. A leak that occurs despite adequate measures does not create liability
  • Responses require confirmation from the responsible department, so the existence of that department is the assumed baseline. Institutions without one have homework to do first

Whether you read this change as an administrative burden or as a signal to get ready will, I suspect, decide how different two otherwise similar institutions look in two or three years. The designation started with five areas. ATLA has already joined. The odds that it stays at two funding agencies are not high.

So here is the one action I would take this week, even if none of your current calls are in scope. Open the research security section of the call guidelines for the programme you apply to most often, read the JST or ATLA version of it as a stand-in, and write down the names of the two people at your institution who would have to sign off on a questionnaire response. If you cannot fill in both names, that is your project for this quarter, and it is a far cheaper project now than it will be during a selection window.

If you are working out where your own organisation should start, talk to our TRAFEED team.

References and primary sources

Footnotes

  1. Japan Science and Technology Agency (JST), "FY2026 Strategic Basic Research Programs (CREST, PRESTO, ACT-X) Call Guidelines," Chapter 6 Points to Note When Applying, 6.5 https://www.jst.go.jp/kisoken/boshuu/teian/koubo/2026youkou.pdf 2 3 4 5 6 7 8 9 10

  2. Acquisition, Technology and Logistics Agency (ATLA), "FY2026 Innovative Science and Technology Initiative for Security (Commissioned Research) Call Guidelines," March 2026 https://www.mod.go.jp/atla/funding/koubo/r08/r08koubo_honsatsu_itaku.pdf 2

  3. Expert Panel on Ensuring Research Security and Research Integrity, "Procedures Manual for Ensuring Research Security," December 2025 (Cabinet Office) https://www8.cao.go.jp/cstp/kokusaiteki/integrity/yushikisha/guidelines_v1.pdf 2 3 4 5 6

  4. MEXT, Science, Technology and Innovation Policy Bureau, "Direction of Concrete Measures on Research Security in MEXT-Related Programmes for Universities and Other Institutions," 18 December 2024 https://www.mext.go.jp/content/20241218-mxt_kagkoku-000039402_1-1rrr.pdf

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

シェア

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

無料診断ツール

輸出管理のリスク、見えていますか?

まず5問(約2分・メール不要)のライト診断。必要なら10問本編で詳細レポートまで。

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles