What MODA unveiled
On July 7, 2026, Taiwan's Ministry of Digital Affairs (MODA) presented its AI Risk Classification Framework at the UN's Global Dialogue on AI Governance in Geneva — the first session of a dialogue the General Assembly created under Resolution A/RES/79/325, co-chaired this year by El Salvador and Estonia. The framework is MODA's attempt to give substance to the AI Basic Act, the 20-article framework statute the Legislative Yuan passed on December 23, 2025, which the President promulgated on January 14, 2026.
The Act itself is deliberately thin. It sets seven guiding principles — sustainable development, human autonomy, privacy and data governance, cybersecurity, transparency, fairness, and accountability — designates the National Science and Technology Council (NSTC) as the central competent authority, and gives government agencies a two-year clock, running to January 2028, to align their own rules with it. Crucially, per Article 17, the Act does not itself regulate private companies; it tells regulators to build liability, compensation, and insurance mechanisms for high-risk applications later.
MODA's framework is the connective tissue for that "later." It gives every sectoral regulator — the National Communications Commission on platform content, the Financial Supervisory Commission on credit and fraud models, health authorities on clinical AI — a shared four-step method: inventory the AI use cases in their domain, identify the risk types those uses raise, assess severity, and pick a proportionate response ranging from self-discipline guidelines to pre-deployment screening to new legislation. MODA calls it a "common language" for agencies that would otherwise invent taxonomies independently. It does not, on its own, bind a single company.
The case for a framework like this
The steelman is straightforward, and worth taking seriously. AI-enabled harms are already concrete: deepfake fraud, opaque credit and hiring models, safety-critical failures in healthcare and infrastructure. Without a shared taxonomy, sectoral regulators duplicate risk-assessment work or, worse, leave gaps between their jurisdictions that bad actors exploit. The EU's AI Act made the opposite bet — a single statute with fixed risk tiers (unacceptable, high, limited, minimal) and prohibited-practices lists baked into primary legislation — precisely because Brussels judged that discretion, left purely to member states or sectors, would fragment into loopholes. A common risk vocabulary, imposed top-down, has a real coordination benefit.
Why the Taiwan model is the better proportionate bet
Even granting that case, Taiwan's design is the more defensible one for a jurisdiction still learning where AI harm actually concentrates. By keeping the AI Basic Act a framework law and pushing binding obligations down to sectoral regulators, Taiwan avoids imposing the EU's upfront compliance burden on AI uses that turn out to be low-risk. Companies building routine, non-high-risk AI applications face no new obligations today; obligations arrive only where a regulator with actual domain expertise in that sector decides risk warrants them. That is a more proportionate use of regulatory capital than legislating fixed tiers before real-world deployment patterns are known, especially in a market as innovation-dependent as Taiwan's semiconductor-and-hardware economy.
It also keeps accountability legible. Under the EU model, a single supra-regulatory apparatus effectively owns AI risk determinations across every sector at once — a concentration of judgment that has already drawn criticism for slowing deployment of genuinely low-risk tools while classification bureaucracy catches up. Taiwan's model keeps that judgment with the regulator that already understands the sector, with MODA supplying methodology rather than substantive rules.
That said, the design has a real cost, and it showed up in the legislative debate itself.
Taipei Times reported that the AI Basic Act's authority provision passed over Democratic Progressive Party objections, concentrating coordinating power in the NSTC and an Executive Yuan committee. Centralizing methodology-setting while leaving substantive rulemaking scattered across agencies risks the worst of both — Taiwan gets coordination overhead without a single point of accountability for it. And a two-year runway to January 2028, while shorter than many multi-year EU transition periods, still leaves industry planning against sectoral rules that do not yet exist. A company deploying a hiring-screening model today cannot know whether the eventual sectoral rule will look like light-touch disclosure or FSC-style pre-approval.
The real test is 2028, not July 2026
MODA's framework is a methodology document, not a rulebook — which is exactly why it deserves cautious praise rather than either alarm or applause. It commits Taiwan to proportionality in principle without yet testing whether a dozen sectoral regulators can apply a shared risk vocabulary consistently. If the NCC, FSC, and health regulators converge on genuinely comparable thresholds for "high-risk" by January 2028, Taiwan will have shown that risk-based AI governance doesn't require a single EU-style super-statute. If they diverge, industry will face exactly the fragmentation that Brussels' framework-law skeptics warned about. Geneva was the unveiling; the binding rules — and the real evidence for Taiwan's bet — are still eighteen months out.