Mill still provides speculation, but it is exposed as part of the user-visible architecture. Before Spectre was publicized, the Mill team proposed using speculation in a way that would make Mill systems vulnerable to Spectre:
https://news.ycombinator.com/item?id=16125519
There is an obvious fix for this (avoid feeding speculated values into address calculations), but they didn't say how much it costs in terms of performance.