Act III · The Objections

Industrialist Paper No. 31

Our IP Will Leak

By Andrew Kornuta · July 27, 2026 · 7 min read

Coordination requires disclosure. A domestic network cannot route work to the right supplier unless the work can be described, and describing a machined part means moving a drawing, a STEP model, a material spec, and an inspection plan into hands that did not create them. Every one of those artifacts is a copy, and every copy is a risk. That is the uncomfortable trade sitting at the center of reindustrialization: the same openness that lets a capable shop find real work also exposes the intellectual property the work depends on. I have argued across this whole series that American manufacturing has a coordination problem before a capacity problem. Coordination that leaks the design is not a fix. It is a new attack surface with better branding.

Claim: a manufacturing coordination layer protects intellectual property only when disclosure is staged, need-to-know, and logged — identity before drawing, minimum viable detail before award, full technical data package only after commitment. It fails the moment it centralizes native design files, discloses more than a quote requires, or cannot prove who saw what and when. The drift is measurable: native-file exposure before award, unnecessary full-package disclosures per quote, and audit gaps no one can reconstruct.

Keep discovery and disclosure separate and most of the category errors here go away on their own. A supplier needs enough to decide whether it can quote. It does not need the full build package to say yes. Treating every RFQ as a full data dump is leakage with good intentions.

The objection at its strongest

The strongest version of the fear is that in manufacturing the data is the product. A drawing package carries tolerances, process notes, a bill of materials, supplier identities, and the strategic fact that someone intends to build this thing, at this quantity, on this schedule. Hand that to a platform and you have handed over the most copyable asset your company owns.

The government agrees, which is why it does not treat a drawing as a document. The Department of Defense wraps technical data in distribution statements under DoDI 5230.24, a six-level ladder that runs from "Approved for public release" down to Statement F, "Further distribution only as directed." The National Archives defines Controlled Technical Information as "technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination." A build-to-print Technical Data Package, in the language of MIL-STD-31000, is "a technical description of an item adequate for supporting an acquisition, production, engineering, and logistics support." Read those three together and you are watching the United States codify, in triplicate, that the file is the item.

The consequences are not hypothetical either. In United States v. Sinovel, a Chinese wind-turbine maker stole the source code that ran American Superconductor's turbine controllers; a federal jury convicted the company, and the court imposed the maximum statutory fine of $1.5 million plus $57.5 million in restitution, after the record showed AMSC lost more than a billion dollars in shareholder equity and roughly 700 jobs. In a separate case, a GE engineer used steganography to hide forty files on the design and testing of turbine carbon seals inside a photograph of a sunrise, emailed with the subject line "nice view." A smart operator who has watched a competitor rise on stolen drawings does not need to be talked out of the fear, and I am not going to try. The fear is correct.

How it fails when the design is bad

The bad version begins with centralization. Ingest native CAD from thousands of buyers to power instant quoting and you have built a single high-value repository of the country's design intent — a honeypot whether or not anyone ever breaches it. Theft is only half of the danger. The other half is that sensitive demand signals, meaning who is tooling up for what, become platform assets before they become supplier relationships.

Next comes over-disclosure, where the system forwards the full package to every shop on the blast list just to collect a price. That is a complete build handed to a dozen parties in order to buy one quote. Underneath both sits the missing log: if no one can reconstruct which supplier viewed which revision, a leak cannot be traced, and an untraceable leak is an unpunishable one. And there is a fourth hole that catches people who have never worked a controlled program — releasing controlled technical data to a foreign national, even one sitting at a domestic shop, is a deemed export under ITAR and the EAR. A platform that ignores origin turns a routing decision into an export-control violation.

The governed design

A governed layer discloses in stages, and I'd put identity before geometry. The supplier proves who it is against the identity floor from Paper 16 before it sees anything sensitive. The buyer then routes a minimum viable work package, enough to quote responsibly as defined in Paper 13, while the full native model waits behind the award. Where the drawing has to travel, it travels as a neutral format like STEP rather than editable native geometry, because the goal is to let a shop quote, not to hand it the source. Distribution follows a private-sector echo of the DoD ladder: need-to-know tiers, redaction of the fields a quote does not require, compartmentalized supplier identities, and controlled release of the full package only after commitment. Every disclosure writes to an audit log that binds a revision to a viewer and a timestamp, so exposure is accountable and a leak traces back to its source.

None of this is exotic, because the federal supply chain already runs on it. DFARS clause 252.204-7012 requires defense contractors to safeguard covered technical information under the 110 controls of NIST SP 800-171, and as of December 16, 2024, the CMMC program requires that those controls be verified before award rather than merely promised. The Defend Trade Secrets Act of 2016 gave companies a federal civil cause of action with exemplary damages for willful theft. The tools of consequence exist. The coordination layer's job is to make them native to routing instead of bolting them on after the drawing has already spread.

How you would know

The claim is falsifiable against numbers any security team can pull. Count native-file disclosures that happen before award; a governed system drives that toward zero. Measure how many parties see a full package per awarded PO, because over-disclosure shows up as a rising ratio. Audit-log completeness — the share of disclosures with a known viewer, revision, and timestamp — should approach total, since gaps are exactly where leaks hide. Track foreign-person access flags on origin-controlled work. And if disclosure volume climbs with RFQ volume while awards stay flat, the system is leaking designs to buy quotes.

Implications

Treat IP protection as a feature and the critic wins: the network becomes a faster way to spread a design to people who never win the work. Treat it as a precondition and disclosure becomes accountable — buyers can route real drawings without surrendering them, suppliers get controlled context instead of dangerous dumps, and a leak stops being anonymous. A country cannot rebuild an industrial base by feeding its technical data to the competitor it is trying to displace, and it cannot ask its best shops to participate in a system that treats their drawings as platform inventory. The practical failure mode is exposure.

Next: the machinery I just proposed raises its own objection, and in Paper 32 I'll answer it. Once trust and performance are scored, what stops the score from being gamed?

Questions to Ask

  1. What is the minimum a supplier needs to see to quote this job, and are we disclosing more than that before award?
  2. Does the system release native CAD or a neutral format, and who decided?
  3. Can we reconstruct exactly which supplier viewed which revision, and when?
  4. Where does full technical-data disclosure happen, before or after commitment?
  5. Is production-site origin known before controlled technical data is released?
  6. If a design leaked, what in our routing record would let us trace it to a source?