Hello, this is Ryuta Hamamoto from TIMEWELL.
"We don't ship anything overseas, so I assumed export control had nothing to do with us."
That is the single most common sentence I hear from university research administrators. I understand why. Say "export control" and what comes to mind is customs, shipping manifests, clearance paperwork. None of it looks like anything that happens in a laboratory.
METI's guidance closes that door in its opening pages. Security export control is part of compliance for universities and research institutions, it says, and institutions must bear in mind that breaching the law may result in the institution itself being penalised1. It goes further. Because universities manage technology provision as their principal exposure, and because they host large numbers of international students and people falling under specific categories who are not under the institution's direction, a high standard of management is required to comply with the Foreign Exchange and Foreign Trade Act1. Not easier than a company. Harder.
This piece is for people at universities meeting export control for the first time. What is actually regulated, why ordinary lab life falls inside it, what the specific categories added in May 2022 are, and what the people doing the work should do about any of it. I will stay on primary sources throughout. If you want a rough read on where your own institution stands before going further, our free export compliance self-check is the fastest entry point. For the wider map of research security, see the complete guide.
Why the rules apply when you are not exporting anything
Start with the idea underneath the law.
The Foreign Exchange and Foreign Trade Act, usually shortened to FEFTA, exists to stop technology and goods that could be diverted into weapons of mass destruction or conventional weapons programmes from spreading where nobody intended them to. The part that catches universities is that goods are not the only thing controlled. Nobody is regulating missile blueprints as such. What is controlled is the recipe for a high-performance material, or a precision measurement procedure: things with entirely legitimate civilian uses that also happen to have military ones. Items and technologies with that double face are known as dual-use items.
Move a physical object across the border and you have exported it. Now ask the same question about technology. Technology sits on paper, on a USB stick, and inside somebody's head, so it can reach a foreign organisation without crossing any border at all. FEFTA responded by making the act of providing technology a regulated act in its own right.
Universities fall inside that structure as a matter of course, because exchanging technology is precisely what a laboratory does all day. Supervision, joint research, conference presentations, showing a visitor how an instrument is operated. All of it can constitute provision of technology in legal terms. That is presumably why METI publishes separate guidance for universities rather than pointing them at the corporate version. The current edition is the fifth, published in September 2025, and it runs to roughly 150 pages1.
One more premise worth flagging early, because it comes up in almost every conversation. Even where intellectual property rights in the technology belong to the individual researcher rather than the university, the legal procedures still apply1. "This is my research output, so I can do what I like with it" is not an argument FEFTA recognises. You will be asked about this, so it helps to have the answer ready.
What counts as "providing technology"
So where exactly does provision of technology begin? This is where practice goes wrong most often.
Technology under FEFTA means specified information necessary for the design, manufacture or use of goods1. The awkward part is that design, manufacture and use are all defined far more broadly than everyday English would suggest. Design covers every pre-production stage: design research, design analysis, prototype construction and testing, design data, layouts. Manufacture covers construction, production engineering, assembly, inspection, testing and quality assurance. Use covers operation, installation, maintenance, repair, overhaul and refurbishing1. The guidance itself pauses to warn readers that the scope is wider than the concepts people generally have in mind.
The forms the information travels in are sorted into two buckets. One is technical data: blueprints, drawings, models, formulae, design specifications, manuals, instructions, programs. Whether it is on paper or in a file makes no difference1. The other is technical assistance: technical guidance, skills training, transfer of working knowledge, consulting services. Explaining something off a slide deck counts. So does an oral research presentation or a spoken piece of supervision1.
Which means all of the following can amount to providing technology.
- Attaching a drawing or an experimental dataset to an email
- Handing over a CD, a USB stick or any other storage medium
- Transmitting abroad over the internet or similar means (sharing a cloud folder and letting the other party access it performs, in substance, the same function as a transmission)
- Giving technical guidance or skills training in a seminar or over the phone
- Supervising someone orally in the laboratory
The guidance says outright that providing controlled drawings, specifications, experimental data or programs by email or storage media to a foreign national who has been in Japan for less than six months and is not employed by a Japanese university, or giving them technical guidance or skills training by seminar or phone, constitutes provision of technology to a non-resident and requires a licence1.
The scenario people miss is the face-to-face one. Where a university hosts a researcher from overseas for a facility tour or a lab discussion and explains controlled technology in the process, prior authorisation is required1. It adds a further step: if you set up a special tour route for that visitor rather than using the publicly available one, you need to review the route and the explanatory content in advance to establish whether listed technology is involved. Visitor handling is the real blind spot. That unremarkable couple of minutes in front of a piece of equipment, saying "and this is how we ramp the temperature up." That is the moment that can qualify.
Internal meetings are in scope too. Where a non-resident or a person falling under a specific category attends a closed internal research seminar, a closed master's thesis defence or a closed research presentation, procedures are required1. Travel is irrelevant to the analysis. Join a closed meeting hosted by a foreign university online and provide controlled technology, and the same licensing requirement applies.
Replace siloed classification work with AI.
METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.
The "specific categories" added in May 2022
Everything above sorts recipients by whether they are a resident or a non-resident. A foreign national working at an office in Japan is a resident, as is anyone who has been in the country for six months or more. A Japanese national who has left Japan intending to stay abroad for two years or more becomes a non-resident1. That framework rests on a 1980 notification and served as the working standard for decades.
In May 2022 a new layer went on top. Provision of technology to a resident who is under strong influence from a foreign government or corporation was brought within the licensing requirement2. The Services Notification, METI's notification setting out how technology provision is treated, was amended, and the framework for deciding who is caught was published as the "specific categories."
There are three of them.
Category 1 is about contractual relationships. It covers a person who has entered into an employment, mandate, service or other contract with a corporation or other body established under foreign law (a "foreign corporation"), or with a foreign government, government agency, local authority, central bank, political party or other political organisation (a "foreign government"), where under that contract they are subject to the other party's direction or owe it a duty of care1. The classic university case is academic staff holding a concurrent post at a foreign university. Cross-appointments sit here. So do working professionals enrolled as students while employed by a foreign company. "Foreign company" here means a company with no base in Japan, which means a Japanese subsidiary of a foreign company is not included2.
Category 2 is about economic benefit from a foreign government. It covers a person receiving, or having agreed to receive, substantial money or other significant benefit from a foreign government. What counts as substantial? The specific thresholds are set out in the Services Notification and the related guideline, so please do not work from memory on the numbers; check the current text when a real case arrives. The university examples given include students receiving study funding from a foreign government, and researchers participating in a foreign government's science and engineering talent recruitment programme who personally receive substantial research funding or living expenses2.
Category 2 carries a proviso that matters a great deal in practice. Receiving substantial money or other significant benefit means receiving it as personal income, so a professor whose university or laboratory receives a benefit from a foreign government does not, as a rule, fall under the category1. METI's own slides make the same distinction, writing "as an individual" in the talent programme example and separating it from benefits received by the university or the laboratory2. The exception to the exception: where the recipient is nominally the university or the laboratory as a device to circumvent the rules, and the professor is substantively the one benefiting, the category applies.
Category 3 is about instructions concerning conduct within Japan. It covers a person who receives instructions or requests from a foreign government regarding their conduct in Japan1. Categories 2 and 3 are limited to foreign governments, so people receiving benefits or instructions from foreign corporations are not included1. The scope differs from Category 1 here, and conflating them is a common error.
And now the fact I most want to land in this article. Whether someone falls under a specific category has nothing to do with nationality. The guidance states it directly: persons falling under the specific categories are limited to natural persons who are residents, but the nationality of that resident is irrelevant, meaning that Japanese nationals can also fall under them1. A Japanese professor holding a concurrent chair at an overseas university is a textbook Category 1 case. Any belief that export control is a matter concerning foreign nationals collapses at this point.
There are exceptions in the detail. Someone holding a concurrent professorship abroad may fall outside Category 1 where the overseas university and either the Japanese university or the professor have agreed that the Japanese university's authority to direct takes precedence1. And an international student who is enrolled at an overseas university does not fall under Category 1 unless they have an employment, mandate or similar contract with it1. Mere enrolment is not enough, which is a point I see misread regularly.
Specific categories are not a watchlist
Here is a sentence I would ask you to keep close. METI puts the same wording into both its university materials and its corporate materials.
The specific categories simply group together, by type, the cases where individual verification during screening is required. Falling under a specific category does not mean the person is regarded as posing a security concern2
Falling under a category is a procedural classification. It is not an assessment of the person.
This is genuinely central to how the regime is built, and honestly, the fact that it has not reached the people doing the work is the biggest problem I see. If the person handing out the declaration forms does not understand this premise, the form lands on the recipient's desk as a letter saying "we suspect you." Attach that sentence to the request and most people receive it as what it is, a procedural confirmation. The atmosphere in a lab is decided right there.
The guidance also repeats a note in two separate places.
The law does not prohibit instruction or education for international students and others, so providing instruction or education after obtaining a licence poses no problem.1
What is required is checking whether the technology being provided is controlled and, where it is, obtaining a licence in advance. Screening people is not the requirement. The research security side takes the same stance explicitly. The procedures manual produced by the Cabinet Office expert panel declines to demand zero risk from institutions or researchers, limits the technologies in scope, calls for reasonable handling proportionate to the degree of risk, and then states that in judging whether a counterpart is a trustworthy partner, there must obviously be no discriminatory treatment on grounds of nationality, race, religion, culture or the like3. The principle shared with Western partners is the same one: respect academic freedom, transparency and openness as far as possible, identify what genuinely needs protecting, and build a high fence around that.
The regime is designed to prevent overreaction, and that design goes all the way down. So when a lab does freeze up, I do not think the cause is the regime. I think the cause is being unable to assemble a basis for a decision. Without a basis, stopping just to be safe always looks like the safest available move. I reached the same conclusion in Hosting Foreign Researchers and International Students.
What "the duty of care ordinarily owed" actually requires
At this point some readers will be worried that a university now has to investigate the foreign connections of every single member of staff and student. The regime draws a clear line here.
The guidance puts it this way. When providing technology to a counterparty, the provider must determine whether that counterparty falls under a specific category, within the scope of what can be confirmed as a result of exercising the duty of care ordinarily owed1. What discharges that duty is set out in Annex 1-3 of the Services Notification, the "Guideline on Determining Applicability of the Specific Categories."
The consequence is refreshingly clear. If you carried out your verification in accordance with that guideline, then even where it later emerges that the counterparty did fall under a specific category, you are treated as having been without fault in failing to obtain prior authorisation, and no penalty or administrative sanction applies1. A safe harbour, in other words.
How you verify depends on whether the person is under your institution's direction.
Students not employed by the university, research students, visiting faculty and emeritus professors are treated as not under your direction. For them, if applicability is evident from the contracts and other documents you would ordinarily obtain in the course of the transaction, such as application paperwork or a CV, and you provide the technology anyway without noticing, you have breached the duty of care. Conversely, where it is not evident from those documents, no additional verification is required of you1. For attendees at a closed internal research presentation, the same logic applies: unless the application form or similar document states that the person falls under a specific category, you may as a rule treat them as not falling under one1.
Professors and lecturers employed by the university, whether full-time or part-time, students employed as TAs or RAs, and part-time or casual staff are under your direction. For these people, Categories 1 and 2 are verified through self-declaration at the point of hiring, typically a signed declaration form, combined with an obligation to report if the person newly comes to fall under a category during employment1. Category 3 is verified on a documentary basis regardless of direction.
The self-declaration route comes with its own load-limiting rule. Providers are not required to verify the truthfulness of what is declared1. Even where a false declaration results in an unlicensed provision, the provider is treated as being without fault, provided they had no other information pointing the other way. The flip side also holds. Where no declaration was made at all, because the person refused to sign, for instance, the possibility of applicability has not been excluded, so as a rule you are not treated as having discharged the duty of care1.
There is a practical trap in how this interacts with internal employment rules. Where your internal rules prohibit or require declaration of conflict-of-interest activity including secondary employment, that is read as requiring a report when someone newly comes to fall under Category 1 or 2. But a footnote adds a condition that decides whether any of this works: receipt of the declaration by HR alone is insufficient, and the information captured through that declaration must be used by the export control function to determine applicability1. Information pooling in HR does not count. That is an organisational design problem rather than a legal one, which makes it one of the easier places to start and one of the higher-yield ones.
Not everything falls in scope, incidentally. Provision of technology already in the public domain and available to the general public, and provision of technology in basic scientific research not directed at the design or manufacture of any particular product, are treated as exceptions1. Lecturing from a commercially available textbook, running an online course open to anyone, answering questions within the scope of technology you presented at a conference in order to place it in the public domain, sending a paper out for peer review: all covered. The trap is that technology you intend to make public eventually does not qualify unless it is public at the moment of provision. Unpublished data under submission is outside the exception. Industry-academia joint research aimed at application in a specific product is often outside the basic research exception too1. The guidance asks institutions to decide these questions through organisational decision-making procedures rather than leaving the application of exceptions to individual faculty judgment, on the grounds that individual judgment can lead to breaches.
Where to start as an institution
On to structures. Article 55-10(4) of FEFTA imposes the duty to comply with the Exporter Compliance Standards. Every exporter must do two things: appoint someone responsible for determining whether items fall under the control lists, and disseminate current law to the people doing the work and instruct them on it. Where you handle controlled goods or technology, four more are added: making the organisation's representative the person responsible for export control, defining the internal management structure, establishing and operating procedures for classification and for verifying end use and end user, and reporting promptly to the Minister of Economy, Trade and Industry where a breach or a suspected breach arises1. Audits, training and record retention are best-endeavours obligations.
For running the thing day to day, an entry, interim, exit model keeps it organised. Entry is the point of admission or hiring, verified against the End User List and similar sources. Interim covers the period of enrolment or employment, and since the End User List is revised at least annually, periodic re-verification is needed. Exit is graduation or departure, where the guidance recommends alerting people about technology provision and physical removal after they return home, and obtaining a fresh declaration1. METI also publishes a self-assessment checklist for universities, which is the quickest way to get a current picture4. The mechanics of building the structure I have set out in How to Build an Export Control System.
Two places absorb most of the load. One is classification, the work of determining whether the technology or goods you handle match an entry on the control lists. The other is screening of joint research partners and counterparties. University research spans an enormous range, and the areas requiring attention include nuclear, precision machining, automatic control and robotics, chemistry and biochemistry, biotechnology and medicine, advanced materials, aerospace and navigation1. Asking a research administration office of a few people to classify all of that for an entire university is, on any honest reading, not workable. And partner verification does not stop at matching an institution's name against a list; it extends into capital relationships and researcher connections.
Reducing exactly those two loads is what we build TRAFEED for. It is an AI agent sitting on a knowledge graph of more than 200 million records, including roughly 90 million papers, roughly 100 million patents and roughly 300,000 researchers, with company lists and the sanctions lists of individual countries layered on top. It is the world's first AI agent in the field of Japanese security export control covering both list controls and catch-all controls, confirmed by our own research as at March 2026. In a joint demonstration with Okayama University, using roughly 30,000 past screening records, we confirmed AI determination accuracy of 95% or above (our own study). We hold Japanese Patent No. 7862062, and the product is deployed at more than 20 organisations. Alongside researcher information, we have been extending coverage into shareholder and capital relationship research. Support for research integrity and research security is an area we are actively developing.
That said, this is a tool for assembling material. The final determination is made by the research institution, or in a corporate setting by each company's export control officer. Whether technology is controlled, whether an exception may be applied, whether to file a licence application: those are organisational decisions, not decisions an AI makes. Our job is to gather the information a decision needs without gaps, and to leave the reasoning in a form that can be explained afterwards. Designing for an audit-ready trail is something we built in from the beginning on the export control side.
One last connection worth drawing, between export control and research security. The Cabinet Office expert panel's procedures manual, published in December 2025, requires due diligence for "Specified Research and Development Programs," meaning competitive funding programmes premised on public disclosure of results that the relevant ministry, in consultation with the funding agency, has designated as potentially involving technology in a critical technology area. The people to be verified are the principal investigator, the co-principal investigators, and research participants belonging to the lead institution, and that population includes students. There are 13 verification items. The twelfth is "status as a 'non-resident' or under a 'specific category' in security export control"3. The research security procedure has absorbed the export control specific categories as a verification item, verbatim. And again, zero risk is not the standard: the manual says this verification may be carried out using self-declared information, open source information and other information each lead institution can ordinarily obtain3. Read the other way round, a university that already has export control arrangements is a step ahead on research security. The practical side of the questionnaire I have covered in How to Answer a Research Security Questionnaire.
What to take away
- Universities are parties to FEFTA. You do not need to ship anything, because providing technology is what is regulated
- Design, manufacture and use are defined far more broadly than everyday usage, and email attachments, storage media, online transmission, oral supervision, facility tours and closed internal presentations can all fall inside
- Specific categories were added in May 2022: contractual relationships, economic benefit from a foreign government, and instructions concerning conduct within Japan
- Specific categories have nothing to do with nationality. Japanese professors and students can fall under them
- Falling under a category is a procedural classification, not an assessment of the person. Nor is instruction or education prohibited
- Verify in line with the Annex 1-3 guideline and you are treated as without fault even if applicability emerges later. Excessive investigation is not what the rules ask for
Conversations about export control tend to become conversations about what you are not allowed to do. Read the guidance end to end, though, and what sits at the centre of it is not prohibition. It is deciding on a verification procedure and keeping a record. Who you provided what to, and on what basis. Being able to explain that. Which is research transparency by another name, and something you will need eventually anyway for joint research contracting and IP management.
So start with one thing: pull up your institution's declaration form and read it again. Then check whether the secondary employment and conflict-of-interest declarations sitting in HR ever reach the person handling export control. That single check will surface at least one gap, in my experience. If you are unsure what order to tackle any of this in, talk to our TRAFEED team.
References and primary sources
Footnotes
-
METI, Trade Control Department, "Guidance on Sensitive Technology Management for Security Export Control (for Universities and Research Institutions), Fifth Edition," September 2025 https://www.meti.go.jp/policy/anpo/daigaku/guidance5.pdf ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29 ↩30 ↩31 ↩32 ↩33
-
METI, Trade Control Department, Security Export Control Policy Division, "On the Clarification of Deemed Export Management" https://www.meti.go.jp/policy/anpo/law_document/minashi/meikakukanitsuite2.pdf ↩ ↩2 ↩3 ↩4 ↩5
-
Expert Panel on Ensuring Research Security and Research Integrity, "Procedures Manual for Ensuring Research Security," December 2025 (Cabinet Office) https://www8.cao.go.jp/cstp/kokusaiteki/integrity/yushikisha/guidelines_v1.pdf ↩ ↩2 ↩3
-
METI, "Security Export Control for Universities and Research Institutions" https://www.meti.go.jp/policy/anpo/daigaku.html ↩
