TRAFEED

The Human Breakwater Against Technology Leakage | Connecting Hiring, Deemed-Export Specified Categories and Departure Into One Line (2026)

Published2026-08-07Ryuta Hamamoto

Part 2 of the technology leakage series. How to build a structure that connects hiring, assignment, employment and departure into a single line, organised around two legal axes: deemed exports under Japan's Foreign Exchange and Foreign Trade Act (specified categories 1 to 3) and the three requirements for trade secrets under the Unfair Competition Prevention Act. We separate what is a legal obligation from what is a voluntary practice, in the order the work actually happens.

The Human Breakwater Against Technology Leakage | Connecting Hiring, Deemed-Export Specified Categories and Departure Into One Line (2026)
Share

Hello, this is Ryuta Hamamoto from TIMEWELL. This is part two of the technology leakage series.

Part one broke leakage into seven routes and drew the map. This time I am pulling out just one of them: people. In part one I said the human entry point is where to start. The reason is simple. You can swap out equipment and you can throttle an AI's privileges today, but you cannot retrieve what a person who touched critical technology remembers.

What I mean by "people" here is four phases: hiring, assignment, employment, and departure. In most organisations these four belong to different departments and are not joined up. There are two legal axes for joining them: deemed exports under the Foreign Exchange and Foreign Trade Act, and trade secrets under the Unfair Competition Prevention Act. Get those two straight and you can tell where the legal obligation ends and voluntary practice begins.

If you would rather establish your baseline first, the free export compliance self-assessment takes three minutes.

The human route is a line, not a point

Discuss leakage countermeasures as an HR matter and the conversation almost always lands on the confidentiality undertaking signed at departure. That is not a bad thing to have. But watching only the moment of departure leaves you unable to answer the question that decides everything.

From when, to which technologies, and how far, could this person reach?

An organisation that cannot answer this does not know what to collect back at departure either. You can write "the employee shall not disclose the Company's trade secrets" into an undertaking, but if you cannot show what was actually managed as a trade secret, you cannot prove it when the dispute arrives. Which is why the work starts at hiring, not at departure.

Set out the legal position phase by phase and it looks like this.

Phase Governing law What to verify and record Nature
Hiring Foreign Exchange and Foreign Trade Act (deemed export) Whether the specified categories apply; whether the role handles critical technology Legal obligation where applicable
Assignment — (voluntary practice) Aptitude check for departments handling critical technology Recommended by guidance
Employment FEFTA and Unfair Competition Prevention Act Records of technology provision, access rights and secrecy management Obligation plus operational practice
Departure Unfair Competition Prevention Act Preventing carry-out; confidentiality and non-compete agreements Contract and evidentiary preparation

Let me take them in order.

Entry: "we are domestic, so it does not apply" does not hold

Export control sounds like something that happens at a border. Under the Foreign Exchange and Foreign Trade Act, though, providing technology to a non-resident counts as an export even inside Japan. That much has been understood for a long time.

What changed was 2021. A notification was promulgated on 18 November 2021 and took effect on 1 May 20221. It defines, among residents, those who as a matter of category are under very strong influence from a non-resident as falling within "specified categories," and brings provision of technology to them into scope as provision to a non-resident2.

There are three specified categories2:

  1. Those under the control of a foreign government or equivalent
  2. Those acting in Japan under the direction of a foreign government or equivalent
  3. Those under the control of a foreign government or equivalent on the basis of economic benefit

The approach to determining applicability is set out in the "Guideline on Determining Applicability of the Specified Categories" (Attachment 1-3 to the services notification)2, and METI has published a Q&A as well, revised on 8 August 20233. The fact that METI went as far as producing an explanatory document for newly hired employees4 tells you this is meant to be checked at the point of hire.

One point that gets misread. Deciding whether to hire someone because of their nationality and carrying out an export control check are not the same thing. What you verify is applicability to the specified categories (residence status, affiliations, relationships with foreign governments) as a procedure for roles that handle critical technology. State the purpose and scope, and conduct the check in connection with the role. Leave that vague and operate on "they are a foreign national, so…" and you end up with something that is poor export control and poor HR practice at once.

Universities and research institutions face a somewhat different set of circumstances, which I have covered separately in the article on research integrity and deemed exports. Software companies will find export control for SaaS and software companies useful.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

The middle: are you actually keeping records during employment?

Once the hiring check is cleared, assignment comes next. METI's Guidance on Countermeasures against Technology Leakage, Second Edition (April 2026) newly raises aptitude checks when assigning someone to a department handling critical technology5. This is not a legal obligation; it sits in the territory of recommended voluntary practice.

What earns its keep during employment is unglamorous: access records. Who touched which information and when. Where technology was provided, from whom to whom, and covering what.

There are two reasons you need these records. One is that if a deemed export licence was required, you need evidence that you followed the procedure. The other is to satisfy the requirements for protection as a trade secret under the Unfair Competition Prevention Act.

To be protected as a trade secret, information has to meet all three requirements6:

  • Secrecy management: it is managed as a secret
  • Usefulness: it is technical or business information useful to business activities
  • Non-public status: it is not publicly known

The one that fails most often in practice is secrecy management. Information is not automatically protected because it is important. What gets tested is the reality of the management: whether access restrictions were in place, whether it was marked as confidential. METI's Trade Secret Management Guidelines were last revised on 31 March 20257 and set out how secrecy management is assessed.

Honestly, this is where most organisations have let things go hollow. I have lost count of the times I have seen a folder named "Confidential" that every employee in the company can open. Once a dispute with a former employee has started, you cannot retrofit proof of how you managed the information.

The exit: the contract is the last line of defence, not the first

Confidentiality agreements and non-compete agreements are the first thing anyone reaches for at departure. The second-edition guidance also points to non-compete agreements as a means of preventing post-departure leakage5.

They are not, however, a cure-all. Non-competes are frequently contested on the basis of freedom of occupational choice, and METI's "Handbook for the Protection of Confidential Information" sets out their enforceability as an issue in its reference materials8. The working assumption has to be that you cannot bind someone without limit.

What the handbook actually recommends is concluding confidentiality agreements at the point of hire and at the start of projects, not only at departure, and considering non-compete agreements for key personnel8. In other words, do not try to solve this at the exit alone.

How disputes with departing employees actually unfold is something I wrote about, with concrete cases, in the article on departing employees. Read the two together and the connection between the limits of contracts and the importance of records should come through.

Consolidating the four phases into one ledger

Bring all of this down to practice and there is one thing to do. Consolidate hiring, assignment, employment and departure onto a single page, per person.

Concretely, get to a state where you can look up all of the following in the same place:

  1. The result of the specified-category applicability check, with the date and the basis
  2. The scope of critical technology that person can reach (assignment and privileges)
  3. Records of any technology provision (counterparty, technology, date, whether a licence was required)
  4. Status of confidentiality agreements and, where applicable, non-compete agreements
  5. Revocation of access at departure, and confirmation of return and deletion

Hold these separately and you will not be able to reconstruct what a departing employee knew. In my experience, whether this is consolidated is the dividing line between a structure that works and one that does not.

And this work is fundamentally the same as the screening you already do for export control. Who is the counterparty, whose capital or which government influences them, and what is being transferred. The sources you consult and the shape of the reasoning overlap.

Our TRAFEED was built as an AI agent for export control classification and counterparty screening, but what it does under the hood is continuous with the work of verifying someone you are bringing in: screening across multiple jurisdictions' restricted-party lists, tracing ownership chains, and keeping the basis for each decision on record. The basis for a decision surviving as a record is what does the work for technology leakage. It puts you in a position to explain, later, why you decided what you decided.

Classification accuracy is above 95% (joint validation with Okayama University; our own study), the classification method is patented (Japanese Patent No. 7862062), and more than 20 organisations use it. To be explicit: the final determination belongs to your export control officer, and the AI's job is to assemble the material and the supporting evidence. Details are on the TRAFEED page.

Material for the internal discussion: we distribute a product catalog setting out what TRAFEED screens, how far it automates, and where the human takes over. Beyond the export control team, it works as a document for getting HR, legal and IT onto the same page about there being four distinct human phases. → Download the TRAFEED product catalog (free; company name and work email required)

Summary, and what comes next

  • Human countermeasures start at hiring, not at departure. Connect the four phases into a line
  • Deemed export management took effect on 1 May 2022; even residents are in scope if specified categories 1 to 3 apply12
  • Keep decisions based on nationality and export control checks as separate things operationally
  • Trade secret protection requires all three requirements, and the one that fails in practice is secrecy management67
  • Non-compete agreements are the last line of defence. Agreements and records from the point of hire and project start come first8

In the final part I set out how to assemble countermeasures for all seven routes as an organisation: who carries the flag, where the budget comes from, and how to get AI agents and robots onto the ledger, in a defined order.

For help designing the structure, book a consultation.

References

Footnotes

  1. METI, Trade Control Department, Security Export Control Policy Division, "On the Clarification of Deemed Export Management" (promulgated 18 November 2021; effective 1 May 2022). https://www.meti.go.jp/policy/anpo/law_document/minashi/meikakukanitsuite2.pdf 2

  2. METI, "Security Export Control: Deemed Export Management" (specified categories 1 to 3; Attachment 1-3 to the services notification). https://www.meti.go.jp/policy/anpo/anpo07.html 2 3 4

  3. METI, "Q&A on the Clarification of 'Deemed Export' Management" (revised 8 August 2023). https://www.meti.go.jp/policy/anpo/law_document/minashi/minashiqa3.pdf

  4. METI, Trade Control Department, "Clarification of 'Deemed Export' Management (For Newly Hired Employees)" (November 2021). https://www.meti.go.jp/policy/anpo/law_document/minashi/jp_kigyou.pdf

  5. METI, Trade and Economic Security Bureau, Technology Investigation and Leakage Countermeasures Office, "Guidance on Countermeasures against Technology Leakage, Second Edition" (published 27 April 2026). https://www.meti.go.jp/press/2026/04/20260427002/20260427002-1.pdf 2

  6. METI, "Trade Secrets: Protecting and Using Trade Secrets" (the three requirements for a trade secret). https://www.meti.go.jp/policy/economy/chizai/chiteki/trade-secret.html 2

  7. METI, "Trade Secret Management Guidelines" (established 30 January 2003; last revised 31 March 2025). https://www.meti.go.jp/policy/economy/chizai/chiteki/guideline/r7ts.pdf 2

  8. METI, Intellectual Property Policy Office, "Handbook for the Protection of Confidential Information: Toward Enhancing Corporate Value" (established February 2016; last revised February 2024). https://www.meti.go.jp/policy/economy/chizai/chiteki/pdf/handbook/full.pdf 2 3

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Free download

Recommended materials

Event Organiser's Migration & Data-Rescue Checklist (fill-in, 2026)

A fill-in worksheet for event organisers whose ticketing service has shut down. PassMarket closed on June 30, 2026, and its ticket management tool is announced as available until August 31, 2026 (planned). The sheet covers what to rescue before that deadline (attendee records, survey responses, revenue and payout records, event page copy, ticket configuration), an inventory of the channels through which you can still reach attendees, a formula and worksheet for calculating the effective cost of a new platform yourself, and the steps to launch a first event on it. Anything the official announcement does not state — when in-service messaging stops, the export specification for attendee lists and survey data, the timing of payouts — is marked "to be confirmed" rather than asserted. It does not rank providers; it supplies the formula and the checklist.

China-Related Transactions Export-Control Screening Sheet (fill-in / Export Control Law & Dual-Use Regulations, critical minerals, Control List, 2026)

A fill-in working sheet for companies trading with China: screen a single transaction against China's export-control regime (the Export Control Law and the Dual-Use Items Export Control Regulations), the controls on critical minerals (gallium/germanium/graphite/antimony/tungsten etc./rare earths/helium), and the four counterparty-list systems (Control List, Watch List, Unreliable Entity List, countermeasure lists). A procedure for "what to check before the deal," not a roster of "who is listed." With a plain-language intro, based on MOFCOM announcements. Listing is a regulatory category, not a judgment about any company (including the Japanese firms on the Japan-directed lists); controls change continually, so verify current announcements and consult your officer. Match counterparties using the original simplified-Chinese wording.

Medical Goods Classification Checklist (Pharma, Devices, Bio / Japan Table 1 Rows 3 & 3-2 etc. / AG, CWC, BWC, NSG / US EAR & ITAR, 2026)

A fill-in working sheet to classify pharmaceuticals, medical devices, bio, pharma chemicals and nuclear medicine — from Japan's Appended Table 1 (chemical = Row 3, biological = Row 3-2, nuclear = Row 2) and the goods ordinance, through the Australia Group / CWC / BWC / NSG, to the US EAR (CCL Category 1 / EAR99 / the 744.4 catch-all) and ITAR (USML Cat XIV). With a plain-language intro; built to reference the official control-list text rather than enumerate individual pathogens. Based on primary sources (e-Gov, AG, OPCW, 15 CFR). Controls change frequently, so treat the authorities' latest guidance and your export-control officer as authoritative; "not controlled (EAR99)" is not "no license." Listing is a regulatory category, not a judgment about any company or country.

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles

Japan's National Intelligence Bureau and Industrial Espionage: How Ministry Information Is Being Consolidated, Where Counter-Espionage Legislation Stands, and What the Economic Security Think Tank Will Do

Japan's National Intelligence Bureau and Industrial Espionage: How Ministry Information Is Being Consolidated, Where Counter-Espionage Legislation Stands, and What the Economic Security Think Tank Will Do

On July 31, 2026, the National Intelligence Council Establishment Act took effect and the Cabinet Intelligence and Research Office was reorganised into the National Intelligence Bureau. This article starts from zero: what the difference is between the Council and the Bureau, why a government organisational statute matters to a company's information management, and exactly which provisions carry ministry-held information into a single place. It also covers the public-private council and the economic security think tank legislated in the amended Economic Security Promotion Act (Articles 3-2 to 3-4, not yet in force and due to take effect by December 16, 2026), what the K Program actually is, the precise status of a Japanese counter-espionage statute, and the trade-secret work companies can start today. Primary sources only.

2026-08-01