Semiconductor Knowledge Security: Why Process Context Matters More Than File Protection

Published by Industry AI Decision

Semiconductor knowledge security must move beyond protecting files. A Belgian investigation concerning alleged transfer of gallium-nitride process know-how shows why the critical asset is a connected system of recipes, metrology, tool settings, failure history, supplier adjustments, and engineering judgment. My thesis is that chip companies need a process-context security model: classify the knowledge chain, grant access by role and purpose, monitor risky combinations of behavior, govern external collaboration, and preserve evidence through organizational change. The individuals involved remain suspects, and the allegations have not been proven in court.

What changed: a semiconductor espionage investigation became public

Reuters reported on 7 September 2026 that Belgian prosecutors were holding a 52-year-old Belgian-Chinese man in pre-trial detention on suspicion of espionage involving semiconductor technology. Prosecutors said he had held a senior position at BelGaN, a producer of gallium-nitride semiconductors declared bankrupt in July 2024, while allegedly directing a Chinese company making similar chips. They suspect specialized intellectual property and trade secrets were transferred abroad. The Chinese embassy did not immediately comment to Reuters. (Reuters, 7 Sep 2026)

Associated Press separately reported that the suspect was arrested on 10 May while preparing to fly to Beijing and is awaiting trial. It said investigators seized data-storage and electronic-communications devices and are pursuing a second suspect. Euronews reported that the detained man denies the charges, citing Belgian broadcaster RTBF. These facts establish an investigation and the prosecutors’ claims; they do not establish guilt, motive, the precise information involved, or whether any transfer produced commercial capability. (AP, 7 Sep 2026; Euronews, 7 Sep 2026)

For semiconductor supply assurance, see our semiconductor trust-architecture framework.

The industrial context is significant. Gallium-nitride devices are used in power conversion, electric vehicles, aerospace, radar, and other demanding applications. The commercially valuable knowledge is rarely contained in one drawing. It can include epitaxy conditions, wafer preparation, process windows, equipment tuning, contamination controls, test methods, yield-loss signatures, reliability screening, packaging interactions, and customer-specific qualification history. My interpretation is that a company can retain its formal patents while losing the tacit and statistical knowledge that makes a process reproducible.

Why semiconductor knowledge security matters now

Why does semiconductor knowledge security matter now? Leading processes depend on dense collaboration across fabs, research institutes, equipment vendors, materials suppliers, design teams, universities, and international sites. Digital twins, remote diagnostics, AI copilots, and shared data platforms can accelerate learning, but they also make context easier to aggregate. At the same time, restructuring, insolvency, acquisitions, and talent mobility disrupt ownership and oversight. Leaders must protect know-how without freezing the collaboration that creates it.

Five stages for protecting process context

A practical model has five stages. First, classify high-value process knowledge as a connected asset rather than a folder. Second, authorize people, systems, and partners by role, project, purpose, geography, and time. Third, enable controlled use inside approved engineering workflows. Fourth, monitor combinations of access, copying, external communication, travel, and role conflict that may require review. Fifth, revoke access promptly and preserve evidence during transfers, exits, investigations, mergers, or bankruptcy. Each stage should be documented and independently testable.

Classification begins with value and substitutability. Patent documents may be public, while the confidential advantage lies in the negative knowledge: experiments that failed, tool-specific corrections, acceptable drift, and the sequence that stabilized yield. Teams should map knowledge objects to products, process modules, equipment, customers, suppliers, and owners. My view is that criticality should be ranked by the time and cost a capable competitor would need to reproduce performance, not by file size or the seniority of the document’s author.

Authorization should reflect purpose, not only organizational position. A senior researcher may legitimately need broad access, yet no title should create permanent visibility into every recipe, yield dashboard, and partner workspace. NIST SP 800-171 Rev. 3 groups requirements around access control, audit, identity, media protection, personnel security, and supply-chain risk. Semiconductor firms can adapt these principles to commercial know-how: least privilege, strong identity, segmentation, time-bound elevation, approved devices, and explicit authorization for bulk export or cross-border transfer. (NIST SP 800-171 Rev. 3, May 2024)

Controlled use must preserve engineering velocity. Researchers need to compare lots, combine metrology, run scripts, share failure images, and collaborate with suppliers. Blocking every export will push work into unofficial channels. The better design brings analysis to governed data, uses project workspaces, masks unnecessary fields, and records derived artifacts. My judgment is that the target is not zero movement; it is observable, purpose-bound movement in which a reviewer can reconstruct who used which knowledge, for what task, and under which approval.

Monitoring should focus on risk combinations rather than nationality or isolated events. Examples include broad access plus a competing outside role, unusual bulk extraction plus imminent departure, repeated policy overrides plus external transfer, or access to unrelated process modules followed by personal-cloud use. Any signal can have an innocent explanation. It should trigger review, not automatic accusation. A defensible program combines telemetry with human investigation, proportionality, privacy safeguards, documented thresholds, and an appeal path.

Five-stage semiconductor knowledge security path from classification and authorization to controlled use, risk review, and exit evidence
The five-stage model secures process context through classification, purpose-based access, governed work, risk review, and transition custody.

For research-to-fab learning, see our semiconductor discovery-to-production loop.

Transitions are a first-class control point. The reported BelGaN case is linked to a company that entered bankruptcy, a period when custodians, contracts, systems, and retention duties can change quickly. During acquisition, restructuring, or insolvency, leaders should identify the owner of trade secrets, freeze unauthorized deletion, revalidate access, inventory devices and repositories, preserve audit records, and define what prospective buyers may inspect. My interpretation is that knowledge escrow and transition playbooks deserve the same preparation as financial and operational continuity.

Legal protection still matters, but it depends on operational evidence. The European Commission explains that EU rules harmonize trade-secret definitions and address unlawful acquisition, use, and disclosure; it also notes the growing role of cyber theft. A company typically needs to show that information was secret, commercially valuable because it was secret, and subject to reasonable protection measures. Controls therefore support both prevention and enforceability. A confidentiality clause without classification, access records, and exit procedures may provide less practical protection than leaders assume. (European Commission, trade secrets)

My perspective and four implications

The first implication is that semiconductor IP inventories should include relationships. A recipe without its tool configuration, sampling plan, maintenance history, and wafer results may be incomplete; together they can reveal the process window. Security teams that classify items independently may miss the risk created by aggregation. My view is that firms should create process-knowledge graphs that show which data combinations reconstruct capability, then protect the graph with segmentation, query controls, and monitored joins.

The second implication concerns third parties. Equipment and materials vendors may see cross-customer patterns, while universities and joint ventures connect people and data across institutional boundaries. Standard nondisclosure agreements do not define technical access, retention, model training, subprocessor use, or derived insights. Leaders should specify permitted purpose, minimum data, approved environments, geographic limits, deletion evidence, audit rights, and incident cooperation. Collaboration should have a designed end state, not just an onboarding checklist.

The third implication is that AI changes the threat and the defense. An AI assistant can summarize thousands of experiments or infer a process window from fragmented records, lowering the effort required to aggregate know-how. The same capability can label sensitive context, detect unusual access combinations, and help reviewers prioritize alerts. In my view, firms should prohibit unapproved model training on confidential process data, preserve model and prompt provenance, and test whether retrieval systems reveal combinations that individual source permissions were meant to separate.

The fourth implication is governance during financial stress. When a company faces bankruptcy or a distressed sale, employees may be uncertain, systems may be underfunded, and bidders need diligence access. These conditions can weaken controls precisely when technology changes hands. Boards, lenders, administrators, and acquirers should assign a named knowledge custodian, fund minimum monitoring and retention, and make IP-chain-of-custody evidence part of transaction readiness. This is both a security obligation and a valuation discipline.

Counterargument and limitations

A reasonable counterargument is that aggressive compartmentalization can slow research, discourage international talent, and create discriminatory monitoring. That risk is real. Controls should be behavior- and purpose-based, subject to legal and privacy review, and designed with engineers. Not every process detail is a crown jewel, and excessive alerts can destroy trust. The objective is proportional security: protect combinations that recreate advantage while preserving legitimate mobility, whistle-blower protections, open science, and ordinary cross-border collaboration.

Five leader actions

For AI evidence provenance, see our open-model evidence-contract guide.

Leaders can take five actions. First, map the connected process knowledge behind the five most valuable products or modules. Second, replace title-based access with time-bound project and purpose authorization. Third, monitor high-risk combinations and require trained human review before escalation. Fourth, rehearse access revocation, evidence preservation, and knowledge custody for departures, acquisitions, and insolvency. Fifth, update partner and AI-use agreements to cover derived knowledge, model training, retention, geography, and verifiable deletion.

Conclusion: protect the learning system, not only files

The conclusion is that semiconductor knowledge security is an operating model for preserving learning advantage. The Belgian allegations require due process and should not be used to generalize about any nationality or institution. They do, however, expose a structural vulnerability: process capability can travel through connected context even when no single file looks decisive. In my view, firms should secure how knowledge is assembled, used, shared, and transferred—while keeping the collaboration and talent mobility on which semiconductor innovation depends.

FAQ

What is semiconductor knowledge security?

It is the governance of connected process know-how—including recipes, tool settings, metrology, yield history, supplier adjustments, and engineering judgment—through classification, purpose-based access, monitored use, partner controls, and transition custody.

What is verified about the Belgian case?

Belgian prosecutors say a former senior BelGaN employee is detained on suspicion of semiconductor-related espionage and unlawful transfer of trade secrets. The allegations have not been proven in court, the suspect denies them according to Euronews, and the precise information and impact remain unverified.

Why is file protection insufficient?

A competitor may reconstruct capability by combining individually ordinary records such as recipes, equipment corrections, metrology, failed experiments, reliability data, and supplier history. Security must therefore consider aggregation and process context.

How can firms protect know-how without slowing research?

Use proportional, purpose-based controls: governed workspaces, time-bound access, approved analytical tools, monitored high-risk combinations, clear partner terms, human review, privacy safeguards, and rapid paths for legitimate engineering exceptions.

References

  1. Inti Landauro. “Belgium Detains Chinese Man on Suspicion of Semiconductor Espionage.” Reuters, 7 September 2026. Original source.
  2. Associated Press. “Belgian-Chinese Man to Face Trial Over Suspected Semiconductor Espionage.” AP News, 7 September 2026. Original source.
  3. Sandor Zsiros. “Belgian Prosecutors Detain Former Researcher and Probe Alleged Chinese Espionage at Bankrupt Chipmaker.” Euronews, 7 September 2026. Original source.
  4. European Commission. “Trade Secrets.” European Commission, Accessed 8 September 2026. Original source.
  5. Ron Ross; Victoria Pillitteri. “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, NIST SP 800-171 Rev. 3.” National Institute of Standards and Technology, May 2024. Original source.

PUT THE IDEAS TO WORK

Assess a workflow from your own operation.

Choose a calculator or review for business value, OEE, capacity, equipment, integration or AI governance. Save your assumptions and results in a private workspace.

KEEP READING

Related guides & perspectives.

Follow the wider topic with another useful question.

RECEIVE NEW ARTICLES

Read the next perspective.

New analysis and learning articles on manufacturing AI, business value and accountable decisions.

Manage delivery preferences or unsubscribe at any time. Privacy policy

Leave a Reply

Discover more from Industry AI Decision | Agentic Manufacturing & Decision Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading