Hello, this is Ryuta Hamamoto from TIMEWELL. This is part two of the technology leakage series.
Part one broke leakage into seven routes and drew the map. This time I am pulling out just one of them: people. In part one I said the human entry point is where to start. The reason is simple. You can swap out equipment and you can throttle an AI's privileges today, but you cannot retrieve what a person who touched critical technology remembers.
What I mean by "people" here is four phases: hiring, assignment, employment, and departure. In most organisations these four belong to different departments and are not joined up. There are two legal axes for joining them: deemed exports under the Foreign Exchange and Foreign Trade Act, and trade secrets under the Unfair Competition Prevention Act. Get those two straight and you can tell where the legal obligation ends and voluntary practice begins.
If you would rather establish your baseline first, the free export compliance self-assessment takes three minutes.
The human route is a line, not a point
Discuss leakage countermeasures as an HR matter and the conversation almost always lands on the confidentiality undertaking signed at departure. That is not a bad thing to have. But watching only the moment of departure leaves you unable to answer the question that decides everything.
From when, to which technologies, and how far, could this person reach?
An organisation that cannot answer this does not know what to collect back at departure either. You can write "the employee shall not disclose the Company's trade secrets" into an undertaking, but if you cannot show what was actually managed as a trade secret, you cannot prove it when the dispute arrives. Which is why the work starts at hiring, not at departure.
Set out the legal position phase by phase and it looks like this.
| Phase | Governing law | What to verify and record | Nature |
|---|---|---|---|
| Hiring | Foreign Exchange and Foreign Trade Act (deemed export) | Whether the specified categories apply; whether the role handles critical technology | Legal obligation where applicable |
| Assignment | — (voluntary practice) | Aptitude check for departments handling critical technology | Recommended by guidance |
| Employment | FEFTA and Unfair Competition Prevention Act | Records of technology provision, access rights and secrecy management | Obligation plus operational practice |
| Departure | Unfair Competition Prevention Act | Preventing carry-out; confidentiality and non-compete agreements | Contract and evidentiary preparation |
Let me take them in order.
Entry: "we are domestic, so it does not apply" does not hold
Export control sounds like something that happens at a border. Under the Foreign Exchange and Foreign Trade Act, though, providing technology to a non-resident counts as an export even inside Japan. That much has been understood for a long time.
What changed was 2021. A notification was promulgated on 18 November 2021 and took effect on 1 May 20221. It defines, among residents, those who as a matter of category are under very strong influence from a non-resident as falling within "specified categories," and brings provision of technology to them into scope as provision to a non-resident2.
There are three specified categories2:
- Those under the control of a foreign government or equivalent
- Those acting in Japan under the direction of a foreign government or equivalent
- Those under the control of a foreign government or equivalent on the basis of economic benefit
The approach to determining applicability is set out in the "Guideline on Determining Applicability of the Specified Categories" (Attachment 1-3 to the services notification)2, and METI has published a Q&A as well, revised on 8 August 20233. The fact that METI went as far as producing an explanatory document for newly hired employees4 tells you this is meant to be checked at the point of hire.
One point that gets misread. Deciding whether to hire someone because of their nationality and carrying out an export control check are not the same thing. What you verify is applicability to the specified categories (residence status, affiliations, relationships with foreign governments) as a procedure for roles that handle critical technology. State the purpose and scope, and conduct the check in connection with the role. Leave that vague and operate on "they are a foreign national, so…" and you end up with something that is poor export control and poor HR practice at once.
Universities and research institutions face a somewhat different set of circumstances, which I have covered separately in the article on research integrity and deemed exports. Software companies will find export control for SaaS and software companies useful.
Replace siloed classification work with AI.
METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.
The middle: are you actually keeping records during employment?
Once the hiring check is cleared, assignment comes next. METI's Guidance on Countermeasures against Technology Leakage, Second Edition (April 2026) newly raises aptitude checks when assigning someone to a department handling critical technology5. This is not a legal obligation; it sits in the territory of recommended voluntary practice.
What earns its keep during employment is unglamorous: access records. Who touched which information and when. Where technology was provided, from whom to whom, and covering what.
There are two reasons you need these records. One is that if a deemed export licence was required, you need evidence that you followed the procedure. The other is to satisfy the requirements for protection as a trade secret under the Unfair Competition Prevention Act.
To be protected as a trade secret, information has to meet all three requirements6:
- Secrecy management: it is managed as a secret
- Usefulness: it is technical or business information useful to business activities
- Non-public status: it is not publicly known
The one that fails most often in practice is secrecy management. Information is not automatically protected because it is important. What gets tested is the reality of the management: whether access restrictions were in place, whether it was marked as confidential. METI's Trade Secret Management Guidelines were last revised on 31 March 20257 and set out how secrecy management is assessed.
Honestly, this is where most organisations have let things go hollow. I have lost count of the times I have seen a folder named "Confidential" that every employee in the company can open. Once a dispute with a former employee has started, you cannot retrofit proof of how you managed the information.
The exit: the contract is the last line of defence, not the first
Confidentiality agreements and non-compete agreements are the first thing anyone reaches for at departure. The second-edition guidance also points to non-compete agreements as a means of preventing post-departure leakage5.
They are not, however, a cure-all. Non-competes are frequently contested on the basis of freedom of occupational choice, and METI's "Handbook for the Protection of Confidential Information" sets out their enforceability as an issue in its reference materials8. The working assumption has to be that you cannot bind someone without limit.
What the handbook actually recommends is concluding confidentiality agreements at the point of hire and at the start of projects, not only at departure, and considering non-compete agreements for key personnel8. In other words, do not try to solve this at the exit alone.
How disputes with departing employees actually unfold is something I wrote about, with concrete cases, in the article on departing employees. Read the two together and the connection between the limits of contracts and the importance of records should come through.
Consolidating the four phases into one ledger
Bring all of this down to practice and there is one thing to do. Consolidate hiring, assignment, employment and departure onto a single page, per person.
Concretely, get to a state where you can look up all of the following in the same place:
- The result of the specified-category applicability check, with the date and the basis
- The scope of critical technology that person can reach (assignment and privileges)
- Records of any technology provision (counterparty, technology, date, whether a licence was required)
- Status of confidentiality agreements and, where applicable, non-compete agreements
- Revocation of access at departure, and confirmation of return and deletion
Hold these separately and you will not be able to reconstruct what a departing employee knew. In my experience, whether this is consolidated is the dividing line between a structure that works and one that does not.
And this work is fundamentally the same as the screening you already do for export control. Who is the counterparty, whose capital or which government influences them, and what is being transferred. The sources you consult and the shape of the reasoning overlap.
Our TRAFEED was built as an AI agent for export control classification and counterparty screening, but what it does under the hood is continuous with the work of verifying someone you are bringing in: screening across multiple jurisdictions' restricted-party lists, tracing ownership chains, and keeping the basis for each decision on record. The basis for a decision surviving as a record is what does the work for technology leakage. It puts you in a position to explain, later, why you decided what you decided.
Classification accuracy is above 95% (joint validation with Okayama University; our own study), the classification method is patented (Japanese Patent No. 7862062), and more than 20 organisations use it. To be explicit: the final determination belongs to your export control officer, and the AI's job is to assemble the material and the supporting evidence. Details are on the TRAFEED page.
Material for the internal discussion: we distribute a product catalog setting out what TRAFEED screens, how far it automates, and where the human takes over. Beyond the export control team, it works as a document for getting HR, legal and IT onto the same page about there being four distinct human phases. → Download the TRAFEED product catalog (free; company name and work email required)
Summary, and what comes next
- Human countermeasures start at hiring, not at departure. Connect the four phases into a line
- Deemed export management took effect on 1 May 2022; even residents are in scope if specified categories 1 to 3 apply12
- Keep decisions based on nationality and export control checks as separate things operationally
- Trade secret protection requires all three requirements, and the one that fails in practice is secrecy management67
- Non-compete agreements are the last line of defence. Agreements and records from the point of hire and project start come first8
In the final part I set out how to assemble countermeasures for all seven routes as an organisation: who carries the flag, where the budget comes from, and how to get AI agents and robots onto the ledger, in a defined order.
- Part 3: How to implement technology leakage countermeasures in an organisation
- Back to part 1: Where does technology leakage actually come from?
For help designing the structure, book a consultation.
References
Footnotes
-
METI, Trade Control Department, Security Export Control Policy Division, "On the Clarification of Deemed Export Management" (promulgated 18 November 2021; effective 1 May 2022). https://www.meti.go.jp/policy/anpo/law_document/minashi/meikakukanitsuite2.pdf ↩ ↩2
-
METI, "Security Export Control: Deemed Export Management" (specified categories 1 to 3; Attachment 1-3 to the services notification). https://www.meti.go.jp/policy/anpo/anpo07.html ↩ ↩2 ↩3 ↩4
-
METI, "Q&A on the Clarification of 'Deemed Export' Management" (revised 8 August 2023). https://www.meti.go.jp/policy/anpo/law_document/minashi/minashiqa3.pdf ↩
-
METI, Trade Control Department, "Clarification of 'Deemed Export' Management (For Newly Hired Employees)" (November 2021). https://www.meti.go.jp/policy/anpo/law_document/minashi/jp_kigyou.pdf ↩
-
METI, Trade and Economic Security Bureau, Technology Investigation and Leakage Countermeasures Office, "Guidance on Countermeasures against Technology Leakage, Second Edition" (published 27 April 2026). https://www.meti.go.jp/press/2026/04/20260427002/20260427002-1.pdf ↩ ↩2
-
METI, "Trade Secrets: Protecting and Using Trade Secrets" (the three requirements for a trade secret). https://www.meti.go.jp/policy/economy/chizai/chiteki/trade-secret.html ↩ ↩2
-
METI, "Trade Secret Management Guidelines" (established 30 January 2003; last revised 31 March 2025). https://www.meti.go.jp/policy/economy/chizai/chiteki/guideline/r7ts.pdf ↩ ↩2
-
METI, Intellectual Property Policy Office, "Handbook for the Protection of Confidential Information: Toward Enhancing Corporate Value" (established February 2016; last revised February 2024). https://www.meti.go.jp/policy/economy/chizai/chiteki/pdf/handbook/full.pdf ↩ ↩2 ↩3






