Taiwan's Artificial Intelligence Basic Act has been law since 14 January 2026. It is a basic law in the Taiwanese sense: twenty articles that bind the government rather than private operators, set seven principles, and hand the operational detail to sector regulators. There are no penalties, no registration and no conformity assessment. But it is not empty for operators either. Article 5 creates a route by which a sectoral regulator, in consultation with the Ministry of Digital Affairs, can designate a product or system as a high-risk application, which then must carry advisory notices or warnings. This guide sets out what the Act actually does, what remains binding through the Personal Data Protection Act, and how the picture compares to the EU AI Act.
Key takeaways
- The Artificial Intelligence Basic Act is enacted and in force. Third reading in the Legislative Yuan on 23 December 2025, promulgated by presidential order on 14 January 2026, twenty articles, effective on the date of promulgation with no phase-in and no transition period.
- It contains no penalties. The words penalty, fine and sanction do not appear in the text. Enforcement runs through whichever sectoral regulator holds the domain, using its existing powers.
- Article 2 makes the National Science and Technology Council the central competent authority, with special municipality, county and city governments as local competent authorities. Article 6 establishes a National AI Strategic Committee convened by the Premier.
- Article 5 is the provision operators should read first. Where a central competent authority for the relevant industry, in consultation with the Ministry of Digital Affairs, identifies an AI product or system as a high-risk application, it must come with advisory notices or warnings. This is a sectorally triggered high-risk route rather than an EU-style annex list.
- The Personal Data Protection Act remains the binding floor for any AI system processing personal data. Note that Taiwan still has no independent data protection authority: the Personal Data Protection Commission exists only as a preparatory office, and the statutory provision designating it as competent authority is not yet in force.
Background and enactment
Taiwan's move toward AI-specific governance followed a pattern familiar from its wider technology regulation history: a period of sectoral guidance and voluntary principles, then a coordinated attempt to bring the strands together under a single framework statute. The National Science and Technology Council, Taiwan's cabinet-level science and technology policy body, led the drafting.
The Act completed third reading in the Legislative Yuan on 23 December 2025 and was promulgated by the President on 14 January 2026 under order 華總一義字第11500001671號. It has twenty articles. Article 20 provides that the Act takes effect on the date of its promulgation, so there was no phase-in period and no transitional relief. It sits in the Laws and Regulations Database under the National Science and Technology Council's classification.
The seven principles and the basic law model
The Act is structured as a basic law, a form used in Taiwanese legislation to set overarching principles and direct subsequent sectoral implementation rather than to create a single self-executing regulatory regime. Article 4 sets seven principles, and their full wording matters because three of them carry more than a one-word label: sustainable development and well-being; human autonomy; privacy protection and data governance; cybersecurity and safety; transparency and explainability; fairness and non-discrimination; and accountability.
Who those principles bind is the point. Article 4 opens by requiring that "the government shall" adhere to them. Article 5 opens "The government shall ensure that the application of artificial intelligence does not result in" the harms it lists. Article 7 directs the government to promote education. The obligations run to the state. No article in the Act imposes registration, reporting or conformity assessment duties on private providers or deployers.
The mechanism by which private-sector expectations will actually form is Article 16, under which competent authorities assist relevant industries to formulate their own industry guidelines and codes of conduct. An operator watching for the moment Taiwanese AI rules become concrete should watch its own sector regulator's guidelines, not the Basic Act.
This is a materially different structure from the EU AI Act. Regulation (EU) 2024/1689 classifies AI systems into risk tiers, attaches itemised obligations to each tier, and creates a supervisory architecture coordinated by the European AI Office and national market surveillance authorities. Taiwan sets principles and delegates. Operators who have built an EU AI Act compliance programme should not expect a Taiwanese Annex III or a conformity marking scheme; expect a slower, sector-by-sector build-out.
Article 5 and the high-risk route
The Act does contain a product-facing consequence, and it is easy to miss. Article 5 provides that if an AI product or system is identified as a high-risk application by a central competent authority for the relevant industry, in consultation with the Ministry of Digital Affairs, it shall come with advisory notices or warnings.
Two things follow for an operator. First, Taiwan does have a statutory high-risk designation route; it is simply triggered sectorally by the regulator rather than by matching a system against a published annex. Second, the consequence of designation is a labelling and warning duty, not a conformity assessment. Article 5 also tasks the Ministry of Digital Affairs and other relevant agencies with providing or recommending assessment and verification tools or methods, developed with input from industry, academics, social organisations and legal experts. Those tools, when they appear, are the practical standard against which a Taiwanese high-risk system will be judged.
What else is binding: the Personal Data Protection Act
The most consequential binding statute for AI operators in Taiwan predates the Basic Act. The Personal Data Protection Act was promulgated on 11 August 1995 as the Computer-Processed Personal Data Protection Act with 45 articles, renamed and expanded to 56 articles on 26 May 2010, and amended again on 30 December 2015. It governs the collection, processing and use of personal data, including data processed by AI systems. Consent requirements, purpose limitation and data subject rights apply to AI-driven processing exactly as to any other processing.
The enforcement position is the part that gets misreported. The amendment of 31 May 2023 added Article 1-1, which provides that the competent authority for the Act is the Personal Data Protection Commission. Article 1-1's commencement was left to the Executive Yuan to set, and it has not been set. The Act's own record carries the status note that some provisions are not yet in force, with the last effective date undetermined. What exists is a preparatory office, operating under an interim organisational regulation of 23 September 2023 that took effect on 5 December 2023. There is no organic act constituting the Commission itself in the legal database, and the body's own site identifies it as the Preparatory Office of the Personal Data Protection Commission. Taiwan therefore still has no single independent data protection authority.
A further substantial amendment to the Act passed on 11 November 2025, adding a new chapter and Articles 1-2, 20-1, 21-1 to 21-5, 51-1 and 53-1, amending more than a dozen articles and deleting Article 27. Its effective date is also to be set by the Executive Yuan. For an operator, this is the development most likely to change Taiwanese AI compliance in practice, and it is worth tracking the commencement order rather than the passage date.
Sectoral guidance: what could not be verified
The Financial Supervisory Commission is the sector regulator most likely to hold live AI expectations for financial institutions. An earlier version of this guide asserted that the FSC had issued AI governance guidance without naming a title, a document number or a date. In verification on 17 August 2026, every retrieval path into the FSC's own legal database and press release index either returned an error or produced no AI items, and the FSC's site search is a third-party search engine rather than a primary source. The claim has therefore been withdrawn rather than restated with softer wording.
The honest position for a financial institution deploying AI in Taiwan is to ask the FSC directly what applies, and to treat the Basic Act's Article 16 industry-guideline mechanism as the route by which sector rules will arrive.
Taiwan's international position and what it means for standards alignment
A structural fact that distinguishes Taiwan from every EU Member State, the United Kingdom, and most other jurisdictions covered in this network is that Taiwan is not a member state of the United Nations, the OECD, or the Council of Europe. This is not a governance choice; it reflects Taiwan's unresolved international status. The practical consequence is that Taiwan cannot become a direct signatory to instruments such as the Council of Europe Framework Convention on AI or a full member of the OECD's AI Principles governance process in the way Council of Europe and OECD member states can.
Taiwan's engagement with international AI and technical standards instead runs through industry and technical channels. Taiwan's national standards body, the Bureau of Standards, Metrology and Inspection, participates in international standards development including ISO and IEC work relevant to AI management systems such as ISO/IEC 42001, and Taiwanese industry associations engage with international AI governance discussions through non-state channels. Operators building a cross-border AI governance programme that references ISO/IEC 42001 or the OECD AI Principles as a common baseline will find that baseline transfers reasonably well to Taiwan in substance, even though Taiwan's formal participation in the originating international processes is structurally different from that of an OECD or Council of Europe member state.
Comparison with the EU AI Act
Set against the EU AI Act, Taiwan's position combines two features operators need to hold separately. First, Taiwan now has an enacted horizontal AI statute, but it is a principles-and-direction framework, not a risk-tiered regulation with itemised technical obligations and a penalty regime comparable to Article 99 of Regulation (EU) 2024/1689. It imposes no duties on private operators directly. Second, Taiwan has a functioning, binding data protection statute, though without the independent authority the 2023 amendment envisaged. The combined effect is a jurisdiction that is less regulated than the EU on paper and remains so in practice, with the real constraint on AI systems running through personal data law rather than AI law.
Extraterritorial reach is asymmetric in the way operators should expect. The EU AI Act's Article 2 scope applies in full to any operator placing AI systems on the EU market or whose AI output is used in the EU, regardless of a Taiwanese operator's domestic regulatory status. Nothing in the Basic Act creates an equivalent reach running the other way, and its extraterritorial effect, if any, was not read against the text in this verification pass and is not asserted here. The PDPA's application to processing of Taiwanese residents' data is the relevant cross-border hook. A cross-border operator's EU compliance obligations are not reduced by Taiwanese governance, and Taiwanese obligations are not created by an EU AI Act programme.
Practical implications for operators
Four steps are proportionate for an operator active in Taiwan today. First, treat Personal Data Protection Act compliance as the binding floor for any AI system processing personal data of Taiwanese individuals, and track the commencement order for the amendment passed on 11 November 2025, which is the change most likely to alter what you must do. Second, identify your sector's central competent authority and ask whether it intends to designate any of your products as a high-risk application under Article 5, since designation triggers an advisory notice or warning duty and there is no published list to check yourself against. Third, watch for industry guidelines and codes of conduct issued under Article 16, and for the assessment and verification tools the Ministry of Digital Affairs is tasked with providing or recommending under Article 5; those tools will become the de facto Taiwanese standard. Fourth, where an EU AI Act or ISO/IEC 42001 governance programme already exists, use its documentation as the backbone, since the substantive principles largely overlap even though the legal force and enforcement architecture differ.
For a comparison of a similarly sectoral, non-EU approach, see the Switzerland AI governance guide. For the EU deployer obligations that remain the highest-stringency benchmark against which any non-EU regime is measured, see the Article 26 deployer obligations guide on agentliability.eu. Operators assembling documentation evidence for cross-border AI governance programmes may also find the Agent Certified methodology useful as a structured reference framework that travels across jurisdictions including Taiwan.
Related reading
For the Asia-Pacific regional context this guide sits within, see Asia-Pacific AI governance in 2026. For a jurisdiction with an enacted horizontal AI statute close in spirit to Taiwan's, see the Korea AI Basic Act guide. For the three-jurisdiction comparison of structurally different approaches, see US, EU, UK: three approaches to the same question.
Frequently asked questions
Does Taiwan have an enacted AI law in 2026?
Yes. The Artificial Intelligence Basic Act completed third reading in the Legislative Yuan on 23 December 2025 and was promulgated by the President on 14 January 2026 under order 華總一義字第11500001671號. It has twenty articles and, under Article 20, took effect on the date of promulgation with no phase-in period. It is a basic law: it binds the government, sets seven principles and directs sectoral implementation, and it contains no penalties, no registration requirement and no conformity assessment.
What are the core principles in Taiwan's AI Basic Act?
Article 4 sets seven principles: sustainable development and well-being; human autonomy; privacy protection and data governance; cybersecurity and safety; transparency and explainability; fairness and non-discrimination; and accountability. Article 4 requires that the government adhere to them. They are directional principles for state action rather than a risk-tiered list of binding technical obligations in the style of the EU AI Act's Annex III.
Does Taiwan's AI Basic Act impose obligations on private companies?
Not directly. Articles 4, 5 and 7 are addressed to the government. No article imposes registration, reporting or conformity assessment duties on private providers or deployers, and the Act contains no penalties. The provision with a product-facing consequence is Article 5: where a central competent authority for the relevant industry, in consultation with the Ministry of Digital Affairs, identifies an AI product or system as a high-risk application, it must come with advisory notices or warnings. Under Article 16, competent authorities assist industries to formulate their own guidelines and codes of conduct, which is the mechanism by which private-sector expectations will actually form.
Which agency is Taiwan's AI authority?
Article 2 of the Basic Act makes the National Science and Technology Council the central competent authority, with special municipality, county and city governments as local competent authorities. Article 6 establishes a National AI Strategic Committee convened by the Premier. The Ministry of Digital Affairs has a statutory role under Article 5, both in high-risk designation and in providing or recommending assessment and verification tools. Sectoral regulators retain their own domains.
Does Taiwan have an independent data protection authority?
Not yet. The Personal Data Protection Act amendment of 31 May 2023 added Article 1-1 designating a Personal Data Protection Commission as competent authority, but its commencement was left to the Executive Yuan and has not been set, so Article 1-1 is not in force. What exists is a preparatory office, operating since 5 December 2023 under an interim organisational regulation. A further substantial amendment to the Act passed on 11 November 2025 and is also awaiting a commencement date.
Why does Taiwan's exclusion from bodies like the OECD and the United Nations matter for AI governance?
Taiwan is not a member state of the United Nations, the OECD, or the Council of Europe, which means it cannot be a direct party to instruments such as the OECD AI Principles or the Council of Europe Framework Convention on AI in the way EU and OECD member states are. Taiwan's engagement with international AI standards instead runs through technical and industry channels, including participation in ISO and IEC standards work through its national standards body, the Bureau of Standards, Metrology and Inspection. Operators benchmarking Taiwan against other jurisdictions should treat this as a structural feature of Taiwan's international position, not an indicator of lower governance ambition domestically.
References
- Artificial Intelligence Basic Act (Taiwan), 人工智慧基本法. Third reading in the Legislative Yuan 23 December 2025; promulgated by presidential order 華總一義字第11500001671號 on 14 January 2026; 20 articles; effective on the date of promulgation under Article 20. Laws and Regulations Database, law.moj.gov.tw, pcode H0160093, and the Legislative Yuan legislative record at lis.ly.gov.tw.
- Same Act, Article 2 (National Science and Technology Council as central competent authority), Article 4 (seven principles: sustainable development and well-being; human autonomy; privacy protection and data governance; cybersecurity and safety; transparency and explainability; fairness and non-discrimination; accountability), Article 5 (high-risk designation, advisory notices and warnings, Ministry of Digital Affairs assessment and verification tools), Article 6 (National AI Strategic Committee convened by the Premier), Article 16 (industry guidelines and codes of conduct), Article 20 (commencement).
- Personal Data Protection Act (Taiwan), promulgated 11 August 1995 as the Computer-Processed Personal Data Protection Act with 45 articles, renamed and expanded to 56 articles on 26 May 2010, amended 30 December 2015. The amendment of 31 May 2023 added Article 1-1 designating a Personal Data Protection Commission as competent authority; its commencement is to be set by the Executive Yuan and has not been set. A further substantial amendment passed 11 November 2025, commencement also pending. law.moj.gov.tw, pcode I0050021.
- Preparatory Office of the Personal Data Protection Commission, operating under an interim organisational regulation of 23 September 2023, in effect from 5 December 2023. No organic act constituting the Commission itself appears in the Laws and Regulations Database. pdpc.gov.tw.
- Regulation (EU) 2024/1689 of the European Parliament and of the Council (AI Act), for comparison, including Article 2 (extraterritorial scope), Articles 9 to 17 (high-risk obligations), Article 26 (deployer obligations), and Article 99 (penalties).
- OECD. OECD AI Principles (2024 revision), referenced by Taiwan's National Science and Technology Council in drafting the Basic Act. Taiwan is not an OECD member state.