From principles to practice: AI governance in Taiwan

IFLR is part of Legal Benchmarking Limited, 1-2 Paris Garden, London, SE1 8ND

Copyright © Legal Benchmarking Limited and its affiliated companies 2026

Accessibility | Terms of Use | Privacy Policy | Modern Slavery Statement


From principles to practice: AI governance in Taiwan

Sponsored by

leeli.png
Digital map of Taiwan

Ken-Ying Tseng of Lee and Li, Attorneys at Law examines Taiwan’s emerging AI governance framework, from the AI Basic Act and risk classification tools to sector-specific guidance, and considers the compliance implications for businesses

Overview

Taiwan enacted its Artificial Intelligence Basic Act (the AI Basic Act) in January 2026, establishing both a foundational framework for national AI policy and a two-year statutory clock for reviewing and adapting existing laws to align with it. By the summer of 2026, that clock is running with visible effect.

In March 2026, the Executive Yuan established the National Artificial Intelligence Strategy Special Committee (the Special Committee) chaired by the premier and empowered with the task to coordinate AI affairs across government agencies. The Special Committee convened its first meeting on June 23 2026, focusing on the implementation of its responsibilities under the AI Basic Act.

Concurrently, the Ministry of Digital Affairs (MODA) is operationalising a risk classification framework and working with sector ministries to identify high-risk AI applications. Individual competent authorities, meanwhile, have begun producing sector-specific guidance at a pace that suggests the implementation process is now genuinely under way.

This trajectory carries immediate and medium-term significance. Taiwan is not following the EU’s comprehensive regulatory model, nor is it adopting the looser industry-led frameworks favoured in parts of Asia. Instead, it is building a layered, risk-calibrated governance system that distributes responsibility across competent authorities under a shared statutory foundation. This architecture makes Taiwan unique among the other major countries in the world as well as in the region.

The AI Basic Act: a framework law, not a rulebook

The AI Basic Act should be read as a framework statute rather than an operational code. Its primary function is to direct government action, require regulatory adaptation, and establish the principles guiding public, as well as private, AI conduct. The National Science and Technology Council (NSTC) has primary oversight responsibility under the act, but its implementation is distributed across all relevant ministries and agencies.

The AI Basic Act articulates seven foundational principles that must govern AI research, development, and application in Taiwan:

  • Sustainable development and wellbeing;

  • Human autonomy;

  • Privacy protection and data governance;

  • Cybersecurity and safety;

  • Transparency and explainability;

  • Fairness and non-discrimination; and

  • Accountability.

These principles are not merely aspirational. They are the benchmark against which each competent authority is expected to assess existing laws, identify gaps, and formulate appropriate management norms within their respective sectors. The AI Basic Act mandates that this review and adaptation process be completed within two years of enactment, with the deadline falling in January 2028, which means that the Taiwan government will be acting under a concrete institutional deadline on what might otherwise remain an indefinite policy intention.

The AI Basic Act does not conclude the regulatory conversation; it initiates a staged process in which the outputs will be the instruments that ultimately define compliance obligations, which may be in the form of sectoral guidelines, legislative amendments, or administrative rulings. Monitoring the act alone is insufficient; the derivative layer is where operational risk and legal obligation will crystallise.

Executive governance: the National Artificial Intelligence Strategy Special Committee

The most structurally significant development of mid-2026 is the establishment of the Special Committee under the Executive Yuan. The Special Committee is chaired by Premier Cho Jung-tai and is tasked with comprehensively coordinating, promoting, and supervising national AI affairs.

The significance of this body lies in the elevation of AI governance from a dispersed, inter-ministerial arrangement to a cabinet-level strategic platform. Prior to this, Taiwan’s AI policy was advanced primarily through the NSTC, MODA, and individual agencies operating under separate mandates and the earlier AI Action Plans stipulated by the government. The new committee consolidates strategic direction and resource allocation at the Executive Yuan level, with authority to set priorities across computing infrastructure, data governance, industrial applications, talent policy, and regulatory adaptation simultaneously.

At its first meeting, the committee adopted in principle the National AI Development Guideline as prepared by the NSTC, which represents Taiwan’s overarching AI strategy. The premier articulated the governing concept as building “sovereign AI”, an AI ecosystem rooted in Taiwanese local data and liberal democratic values that is intended to transform Taiwan from a manufacturing powerhouse supporting global innovation into a model for the responsible and trustworthy application of AI. Priority application domains cited include education, healthcare, finance, and justice.

The committee’s agenda also highlights the critical role of infrastructure in realising Taiwan’s sovereign AI strategy. The premier instructed all ministries to align their resource planning with the strategic framework and to advance implementation through the AI New Ten Major Constructions initiative. The initiative encompasses the key building blocks of a sovereign AI ecosystem, including computing capacity, energy infrastructure, network and cybersecurity, data governance and security, AI service security, and a regulatory and evaluation framework rooted in democratic values. Together, these elements reflect the government’s intention to develop not only AI capabilities but also the institutional and technical foundations necessary to support their secure and responsible deployment.

Notably, the financial sector has been identified as one of the priority domains for sovereign AI development. This designation suggests that financial regulators will play an important role in translating the government’s strategic vision into sector-specific policies and regulatory initiatives. The measures adopted to facilitate AI deployment in the financial sector – while maintaining appropriate safeguards for security, privacy, and market integrity – will therefore be closely watched as an indicator of Taiwan’s broader approach to AI governance.

MODA and the risk classification architecture

MODA occupies a central position in the implementation architecture because it is responsible for translating the AI Basic Act’s principles into reusable governance tools applicable across the public administration and, progressively, the private sector.

Two instruments are especially relevant at present. First, MODA has developed and published an AI Risk Classification Framework on July 7 2026, which is designed to assist competent authorities in categorising AI applications by risk level and determining appropriate management responses. The framework provides a common methodological language rather than a prescriptive list of prohibited systems, enabling sector regulators to make proportionate determinations within their own domains. Where an application is identified as high risk, the competent authority will need to consider whether legislative prohibition or strict control is warranted; where risk is assessed as lower, guidance and internal controls may suffice.

Second, MODA has published a Public-Sector AI Application Reference Handbook (updated February 2026), which provides public agencies with structured guidance for evaluating and managing AI deployments. This handbook is practically significant beyond its immediate public-sector audience: in many regulatory environments, public-sector governance standards become implicit benchmarks for procurement requirements, audit expectations, and the standard of care expected from regulated private entities. The handbook’s framework for impact assessments, internal controls, documentation, and governance measures provides a useful reference point for what may come to constitute ‘reasonable’ institutional practice.

The institutionalisation of data governance is a parallel development of equal importance. MODA is advancing the draft Act for Promoting Innovative Utilisation of Data, which aims to encourage ministries to release non-personal data, including high-quality Taiwanese cultural and linguistic datasets, for AI training purposes, subject to privacy protection and copyright compliance. Alongside this, the Executive Yuan is directing agencies to appoint chief data officers responsible for data governance, open data initiatives, and AI training corpus supply. This signals that data infrastructure is being treated as a national public utility for AI development, not merely a compliance obligation.

Sector-specific guidance: the emerging regulatory layer

While the AI Basic Act and the MODA framework establish the architecture, the substance of AI governance in Taiwan is being built sector by sector. Several competent authorities have already produced or are developing guidance, and their approaches offer important signals for the compliance landscape.

Financial sector: Financial Supervisory Commission

The Financial Supervisory Commission (FSC) has the most developed AI-specific guidance in the Taiwanese regulatory system. It announced core AI principles and policy for the financial industry in October 2023 and issued the Guidelines for the Use of Artificial Intelligence by the Financial Industry in June 2024. These guidelines have gained renewed significance as benchmarks under the AI Basic Act implementation process.

The FSC guidelines are framed as administrative guidance for financial institutions introducing, using, and managing AI systems, with industry associations encouraged to incorporate key points into self-regulatory norms. Substantively, the guidelines address governance and accountability, fairness and non-discrimination, privacy and data protection, robustness and security, transparency and explainability, and sustainability. Financial institutions are expected to apply these principles throughout the AI system life cycle, from procurement and development through deployment, monitoring, and decommissioning.

The FSC’s guidelines function as a de facto standard of care for regulated firms in Taiwan, even where they do not impose binding legal obligations in the criminal or administrative-penalty sense. Supervisory review, audit inquiries, and licensing-related assessments are likely to reference them. Meanwhile, as the FSC continues to develop its position under the AI Basic Act’s implementation timetable, further guidance – potentially covering specific AI use cases such as credit scoring, customer service automation, fraud detection, and investment recommendation – should be anticipated.

Healthcare sector: Ministry of Health and Welfare

The Ministry of Health and Welfare (MOHW) issued Guidelines for Medical Institutions Applying Generative Artificial Intelligence on May 29 2026, making it one of the most recent and concrete sector-specific AI governance instruments in Taiwan. The guidelines are addressed to medical institutions that have introduced or are preparing to introduce generative AI, and they cover governance responsibilities, risk management, patient safety considerations, data protection, transparency in patient communication, and documentation requirements.

Healthcare represents one of the clearest high-risk AI domains in Taiwan’s emerging framework, given the direct implications for patient safety, clinical decision-making, and the handling of sensitive personal health information. The MOHW’s early action in this area reflects the AI Basic Act’s prioritisation of human wellbeing and human autonomy and signals that domains with concentrated welfare risk are likely to receive formal guidance ahead of less sensitive sectors.

For legal advisers working on healthcare technology transactions, telemedicine arrangements, or medical AI product regulatory strategy in Taiwan, the MOHW guidelines define the current baseline expectation and will likely be referenced by the ministry in any future formal regulatory development.

Media sector: National Communications Commission

The National Communications Commission (NCC) has been engaged in developing AI-related guidance for the communications and media sector, with particular attention to issues of content governance, algorithmic transparency, and platform accountability. This reflects Taiwan’s broader sensitivity to information integrity issues and the intersection of AI with democratic public discourse, themes that resonate directly with the sovereign AI framing articulated by the premier.

Practitioners advising media companies, telecommunications operators, and digital platform businesses in Taiwan should monitor NCC developments closely as the AI Basic Act implementation timeline progresses.

Protection of workers

The Ministry of Labour has been examining AI governance from the perspective of employment and labour relations, with preliminary guidance in development covering employer obligations when deploying AI systems in HR processes, performance assessment, and workplace monitoring. The seven principles of the Basic Act – particularly non-discrimination, transparency, and human autonomy – have direct implications for AI-assisted hiring, workforce management, and automated decision-making in employment contexts. Furthermore, the AI Basic Act expressly requires that the government shall actively utilise AI to protect workers’ rights, mitigate AI-induced skills gaps, promote labour market participation, safeguard economic security and decent work, and provide appropriate employment assistance to individuals displaced by AI in accordance with their skills and work capacity.

Taiwan in a comparative context

For international advisers familiar with other jurisdictions, Taiwan’s approach warrants contextual placement. It diverges meaningfully from the EU’s AI Act, which establishes a direct-effect, risk-tiered regulatory code with harmonised conformity assessment obligations and prohibitions on certain AI practices across all sectors. Taiwan’s framework is instead permissive towards technology development, relies on competent authority discretion for risk classification, and produces obligations primarily through secondary guidance rather than primary legislation.

It also differs from the approaches of Japan, South Korea, and Singapore, each of which has developed relatively distinct regulatory cultures around AI – Japan emphasising industry co-creation and soft governance, South Korea combining sector-specific hard law with government-led industrial strategy, and Singapore maintaining a disclosure-and-accountability model through the Personal Data Protection Commission and the Monetary Authority of Singapore.

Taiwan’s sovereign AI framing, its linkage of AI governance to democratic values, and its emphasis on data infrastructure as a national public utility give it a distinctive profile that reflects both its geopolitical position and its role as a critical supplier of AI chip hardware to the global semiconductor ecosystem.

For multinational organisations, this matters because Taiwan’s governance approach means that compliance obligations will not be imported from a single unified regulation but will accumulate from a combination of a statutory framework, MODA risk tools, and sector-specific guidance. Cross-border advisory work will require ongoing engagement with multiple competent authorities and regular monitoring of the secondary guidance layer, particularly in financial services, digital health, and technology transactions involving Taiwanese entities.

Looking ahead

Taiwan’s AI governance has crossed a threshold. The AI Basic Act is no longer a legislative intention awaiting implementation. It is an operational framework producing real institutional outputs: a cabinet-level strategy committee, a government-wide risk classification methodology, a public-sector handbook, and a growing set of sector-specific guidelines in finance, healthcare, and beyond. For international professional advisers, the task is to understand not only what has been issued but how the pieces connect and where the architecture is heading.

The most important observation may be structural: Taiwan is constructing a governance system in which law, strategy, administrative tools, and sector supervision develop in parallel and reinforce one another. No single instrument captures the full picture. Effective professional advice in this environment requires fluency with the whole architecture – and the discipline to track it as it continues to evolve.

Gift this article