Taiwan Taiwan MODA digital ministry policy

Taiwan's New AI Risk Framework Bets on Sectoral Judgment Over a Brussels-Style Rulebook

MODA's July 7 risk classification framework hands Taiwan's regulators shared methodology, not a fixed list of banned AI uses — a proportionate bet with one real gap: deepfakes.

Taiwan's Staged Path from Law to Rules People of Internet Research · Taiwan 7 Core governance principles The AI Basic Act enumerates seven … 3 Months for impact assessments Agencies must publish impact asses… 24 Months to align sector laws Government has up to two years aft… peopleofinternet.com
Taiwan's Staged Path from Law to Rules People of Internet Research · Taiwan 7 Core governance principles 3 Months for impact assessments 24 Months to align sector laws peopleofinternet.com

Key Takeaways

A Rulebook Without a Rulebook

On July 7, 2026, Taiwan's Ministry of Digital Affairs (MODA) used the second day of the United Nations' Global Dialogue on AI Governance in Geneva to unveil its AI Risk Classification Framework — the methodology sectoral regulators across Taiwan's government are now required to use when deciding how to treat AI in their own domains (IAPP). The framework does not ban any category of AI system outright, and it does not bind private companies directly. What it does is give finance regulators, health authorities, labor agencies, and every other competent authority a shared vocabulary for identifying risk and a common menu of responses — from voluntary self-discipline guidelines up to licensing regimes or new legislation.

That design is deliberate, and it is the latest expression of a governance philosophy Taiwan settled on when the Legislative Yuan passed the Artificial Intelligence Basic Act in its third reading on December 23, 2025 (MODA press release). The law took effect January 14, 2026, and rather than creating a single new AI regulator, it instructed the existing government to operate as "an inter-ministerial coordination platform," with MODA specifically tasked with building an AI risk taxonomy other agencies could use (MODA press release). The Act itself imposes no penalties and no immediate operational obligations on companies — it is a framework statute, not a compliance regime, with the real rulemaking pushed downstream to the sectoral regulators the July 7 framework now equips (Baker McKenzie).

The Case for Something Firmer

The strongest objection to this approach is that soft law arrives too late for the harms already showing up. Taiwan has already had its own preview of the problem the framework is supposed to eventually address: an AI-cloned voice of President William Lai circulated in a political promotional video, echoing the March 2022 deepfake of Ukrainian President Volodymyr Zelensky urging troops to surrender. A Taipei Times editorial published August 3, 2026 argued plainly that the AI Basic Act, for all its principles, "is insufficient" for this problem and that Taiwan needs standalone deepfake legislation — pointing to the EU AI Act's mandatory deepfake labeling and enforcement powers, the US Take It Down Act, and a Japanese Ministry of Justice panel move to extend legal protection to human voices against AI cloning (Taipei Times). That is a fair criticism on its own terms: election-adjacent synthetic media is a harm where waiting for sector-by-sector rulemaking genuinely costs something, because the damage (a viral clip days before a vote) happens faster than any competent authority can classify and respond to it.

Why Proportionality Still Wins the Broader Bet

But the deepfake gap is an argument for one targeted statute, not for scrapping the framework-first model everywhere else. Most of what the AI Basic Act's seven principles — sustainable development, human autonomy, privacy and data governance, cybersecurity, transparency, fairness, and accountability — are meant to govern is nothing like a viral election clip. It is banks deciding whether a credit-scoring model needs an audit trail, hospitals deciding whether a diagnostic tool needs pre-deployment testing, and labor agencies deciding whether an AI hiring filter needs disclosure. For that universe of cases, a rigid EU-style tiered list, fixed in statute before most of these applications even exist in Taiwan's market, would lock in guesses about which technologies are dangerous based on today's threat model — guesses that go stale within a product cycle or two. Sector regulators who already understand credit risk, clinical risk, or labor-market risk are better positioned to calibrate proportionate rules than a horizontal statute could be, and MODA's framework is explicitly built to let them do that on a common methodology rather than in isolation.

The implementation timeline backs up how deliberately staged this is: agencies must publish impact assessments covering minors, human rights, and gender within three months of the Act's rules taking effect, complete risk assessments of existing government AI use within six months, set internal AI-use rules within twelve, and align relevant sector laws and regulations with the Act within twenty-four months (Baker McKenzie). That is not indefinite delay — it is sequencing, with government AI use going first as a proving ground before private-sector rules follow. A Tech Policy Press analysis comparing Taiwan's approach to the EU's more prescriptive model and South Korea's more detailed requirements found Taiwan's flexibility genuinely reduces compliance costs during "this early phase of global AI governance development" — while flagging, fairly, that the law's soft-law character leaves civil society with limited formal purchase on how sectoral rules ultimately get written (Tech Policy Press).

The Narrow Fix

The sensible response isn't to abandon the sectoral, risk-tiered model MODA just operationalized in Geneva — it's to carve out the one category, synthetic media targeting elections and public officials, where speed of harm outruns the framework's own cadence, and legislate that piece directly and quickly. Everything else the Basic Act touches can keep maturing the way it was designed to: through regulators who know their sectors, working from a shared risk methodology, on a clock that gives the private sector time to adapt rather than a compliance deadline set before the technology existed.

Sources & Citations

  1. MODA: Legislative Yuan Passes AI Fundamental Act
  2. MODA: AI Basic Act — Governance and Evaluation
  3. IAPP: Taiwan's AI Risk Classification Framework
  4. Taipei Times: Is it time for a deepfake law?
  5. Tech Policy Press: Taiwan's AI Basic Act as a Model for Asia
  6. Baker McKenzie: Taiwan AI Basic Act insight