Hello, this is Ryuta Hamamoto from TIMEWELL. This is the final part of the technology leakage series.
Part one broke leakage into seven routes; part two connected the four human phases into a line. This time: how to implement it in an organisation.
Conversations like this usually end with "let's stand up a cross-functional programme." If your organisation actually moves on that, congratulations. In practice, nobody agrees on who carries the flag, no budget appears, and six months later all that is left is a slide deck.
Here is my conclusion up front, so it does not get lost. Do not create a new organisation. Export control has had a statutory vessel since 2010.
Do not build a new vessel. Use the one that exists
Japan's Foreign Exchange and Foreign Trade Act includes the exporter compliance standards, which took effect on 1 April 20101. They cover almost all exporters and require two things in broad terms2:
- Appointing an officer responsible for checking whether goods to be exported fall under the Act's list controls
- Instructing those engaged in exporting on legal compliance
Businesses handling list-controlled items are further required to maintain an internal compliance programme (CP)3. The CP is an internal set of rules covering export control obligations, and the most senior export control officer within it corresponds to the chief compliance officer under the standards2. Filing procedures are set out in a METI notification4, with a published Q&A5.
Which means that most organisations already have both an officer who decides whether technology may leave, and a written procedure for doing so. Nothing is better suited as the vessel for technology leakage countermeasures. Build from zero and you have to manufacture your own basis for authority and your own basis for budget.
To be candid, I have repeatedly seen this asset treated as an afterthought. The CP is run as paperwork for export customs clearance and never handled as a management-level matter. The vessel is there and unused.
Loading the seven routes onto the CP
Here is how the seven routes from part one map onto the existing vessel.
| # | Route | Position in the existing vessel | What needs adding |
|---|---|---|---|
| 1 | Export of goods and technology | The CP's original subject | Nothing (the procedure exists) |
| 2 | Hiring | Extend the scope of "instruction" under the standards | Add the specified-category check procedure to the CP |
| 3 | Current employees (deemed export) | Within the CP's scope (technology provision) | Communicate that domestic provision is also in scope |
| 4 | Departing employees | Outside the CP. HR and legal territory | Connect secrecy management records back to the CP side |
| 5 | Equipment and supply chain | Outside the CP. Procurement and IT territory | Records that trace procured equipment to its manufacturer |
| 6 | Physical carry-out | Outside the CP. IT and general affairs territory | Connect to the existing information security rules |
| 7 | AI agents and robots | Nowhere at all | Add as actors on the privilege ledger |
As you can see, 1 and 3 are already the CP's subject. 2 fits by widening the scope of the "instruction" the standards require. Routes 4 through 6 belong to other departments, but you do not need to merge the rulebooks — you need one line drawn so information reaches the chief compliance officer.
The problem is 7. That is the only one with no home in any existing rulebook.
Replace siloed classification work with AI.
METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.
Getting AI agents and robots onto the ledger
In IPA's "Information Security 10 Major Threats 2026," "cyber risks around the use of AI" entered the organisational threat list at number three6. IPA has also stepped up its AI security publishing, releasing "Security Tips for AI Users" and the "AI Security Bulletin" in April 20267. Indirect prompt injection is characterised there as an attack that succeeds because malicious instructions are contained in data the AI itself went and read8.
So how do you manage it? You do not need to stand up a new AI governance organisation. Apply what you already do to people.
Add rows for AI agents and robots to the privilege ledger, and fill in the same fields you use for people.
- What can it access — which documents it can read, which APIs it can call, which rooms it can enter
- Who granted the privileges — approver and approval date
- When do they expire — an expiry date. Do not hand out tokens without one
- Is execution logged — a record of what it read and what it sent outside
- Is there an external send path — and if so, is the destination restricted
These five are nearly identical to the human fields from part two. The difference is that an AI never resigns, so "expiry" has to be set deliberately in place of "departure." A person's privileges lapse at the natural break point of leaving; a token handed to an agent lives on until somebody stops it.
On robots, as I wrote in the article on information leakage risk in physical AI, the starting point is nailing down in contract where recorded footage goes, where it is stored, and who trains on it. For the specific mechanics of prompt injection, see the dedicated article.
The order of work, and how to fund it
Trying to do all of it at once fails. The order I recommend:
Stage 1 (this week). Confirm who the chief compliance officer is. If you maintain a CP, this must already be decided. If it is not, or if it has gone hollow, fix that first. Nothing downstream moves until it is settled.
Stage 2 (one month). Take inventory. What technology are you protecting, and which people, equipment and AI can reach it? Do not implement countermeasures at this stage. Just produce the list. Evaluating products without a list means you cannot articulate what is missing.
Stage 3 (three months). Working through the list, start with the routes where nothing is recorded. Prioritise whether the basis for a decision survives over the decision itself. Being able to explain yourself afterwards is worth more than a perfect judgement.
Stage 4 (six months). Automate the parts where volume has outgrown manual work. This is the first point at which tool selection belongs.
On budget, my experience is that widening the scope of existing CP operating budget and information security budget goes through more easily than seeking new funding. "Extending the export control structure to cover technology leakage as a whole" is a shorter distance to approval than "launching a new technology leakage programme," because the statutory basis is already there.
How to tell whether it is working
Once the structure exists, what tells you it is functioning? I look at three things.
The first is the share you can explain. Of past decisions, the proportion you can reconstruct with the reasoning and evidence behind them. A structure that scores low here survives neither an audit nor litigation.
The second is days from check to decision. Export control is also a race against the clock. When checks take too long, the field starts skipping them. Being strict and being complied with are different things, and keeping the process to a workable speed is the structure's responsibility, not the field's.
The third is the freshness of the inventory. When was the list from stage 2 last updated? A list untouched for six months is not far from no list at all.
TRAFEED, which we develop, is an AI agent for export control classification and counterparty screening, but what customers actually value, I have come to think, is less the classification itself than the fact that the basis for the classification survives as a record. It screens across multiple jurisdictions' restricted-party lists, traces ownership chains, and returns results alongside the statutory provisions consulted. That puts you in a position to explain, later, why you decided what you decided.
Classification accuracy is above 95% (joint validation with Okayama University; our own study), the classification method is patented (Japanese Patent No. 7862062), and more than 20 organisations use it. To be explicit: the final determination belongs to your export control officer, and the AI's job is to assemble the material and the supporting evidence. That the judgement itself should not be handed to a machine in a compliance function is a position we have held since the design stage. Details are on the TRAFEED page.
Material for the structural discussion: we distribute a product catalog setting out what TRAFEED screens, how far it automates, and where the human takes over. It works as a document for getting the chief compliance officer, HR, legal, procurement and IT onto the same page about there being seven routes, and the CP being vessel enough. → Download the TRAFEED product catalog (free; company name and work email required)
Series summary
Across all three parts:
- Technology leakage is not only export control. There are at least seven routes (part 1)
- Start at the human entry point. Connect hiring, assignment, employment and departure into a line (part 2)
- Do not build a new vessel. Use the chief compliance officer and the CP required by the exporter compliance standards13
- Put AI agents and robots on the privilege ledger using the same five fields as people
- The order is: settle the officer → take inventory → build the records → automate. Do not choose a tool before the inventory
Government guidance reflects practice that has already settled, so there is always a lag before new routes appear in it. There is no reason to wait. The work is an extension of what you already have: add non-humans to the inventory of actors.
To establish your own baseline first, the free export compliance self-assessment takes three minutes. For help with the structural design itself, book a consultation.
References
Footnotes
-
e-Gov Law Search, "Ministerial Ordinance Prescribing the Exporter Compliance Standards." https://laws.e-gov.go.jp/law/421M60000400060/ ↩ ↩2
-
METI, "Security Export Control: Promoting Voluntary Management by Companies" (exporter compliance standards and the chief compliance officer). https://www.meti.go.jp/policy/anpo/compliance_programs.html ↩ ↩2
-
METI, Security Export Control Policy Division, Security Export Inspection Office, "On the Amendment of the Exporter Compliance Standards" (March 2022). https://www.meti.go.jp/policy/anpo/compliance_programs_pdf/r403yusyutsusyakaisei_set.pdf ↩ ↩2
-
METI, Trade and Economic Cooperation Bureau, "On the Filing of Internal Compliance Programmes" (Export Notice 17 No. 9). https://www.meti.go.jp/policy/anpo/compliance_programs_pdf/20250509yushutsukanrinaibukitei.pdf ↩
-
METI, "Q&A on 'The Filing of Internal Compliance Programmes'" (prepared 2 May 2025). https://www.meti.go.jp/policy/anpo/compliance_programs_pdf/20250502_CPtutatsuQA.pdf ↩
-
Information-technology Promotion Agency, Japan (IPA), "Information Security 10 Major Threats 2026: Commentary [Organisations]" (March 2026). https://www.ipa.go.jp/security/10threats/omgdg50000008fi8-att/kaisetsu_2026_soshiki.pdf ↩
-
IPA press release, "'Security Tips for AI Users' and 'AI Security Bulletin' Published" (2 April 2026). https://www.ipa.go.jp/pressrelease/2026/press20260402.html ↩
-
IPA, "AI Security Bulletin" (on indirect prompt injection). https://www.ipa.go.jp/digital/ai/security/ai-security-bulletin.html ↩






