Legal Documents of AI Law and Regulation at Central and Local Government Levels
This part examines the formation and evolution of Taiwan's artificial intelligence (AI) governance framework from the perspectives of institutional development and comparative study. It begins with an introduction to the Artificial Intelligence Basic Act (hereinafter the 'AI Basic Act', 2025), enacted in late 2025 and brought into force in early 2026, and analyses its principal regulatory structure and fundamental principles of AI governance. The discussion then adopts a comparative law approach, comparing Taiwan's AI legal regime with those of Japan and South Korea—examining differences among the three jurisdictions in terms of governance philosophies, regulatory models, and policy instruments. Finally, this part reviews the AI operational guidelines issued by two major special municipalities in Taiwan prior to the enactment of the AI Basic Act, highlighting the administrative governance mechanisms and practical implementation measures developed by local governments before national legislation was completed. Through this analysis, the part illustrates the regulatory trajectory of Taiwan's AI governance architecture, showing how it gradually evolved from local administrative practices and comparative legal influences into a national legislative framework.
Ⅰ. Artificial Intelligence Basic Act
In December 2025, Taiwan's legislature (Legislative Yuan) passed the AI Basic Act, which was promulgated by the President in January 2026. The AI Basic Act serves a multitude of purposes, primarily focusing on building a smart nation, fostering AI R&D and industrial growth, and ensuring a secure application environment. It also seeks to advance digital equity, protect fundamental rights, and enhance societal well-being and quality of life. Finally, the legislation strives to promote sustainable development, preserve cultural values, boost global competitiveness, and ensure ethical technology deployment (AI Basic Act, art. 1, 2025). This section explores the AI Basic Act by examining five core regulatory domains: (1) the legislative framework and competent authorities, (2) fundamental principles of AI governance, (3) government policies and industrial development, (4) the AI risk management regime, and (5) data governance and social responsibility.
1. Legislative Framework and Competent Authorities
In terms of its legislative structure, the AI Basic Act functions as framework legislation. Rather than establishing detailed regulatory provisions or penalties, it provides the legal foundation for the state to promote AI development and to build a national governance architecture. The AI Basic Act designates the National Science and Technology Council (NSTC) as the competent authority at the central government level, with municipal and county governments serving as the competent authorities at the local level (AI Basic Act, art. 2, 2025). In addition, the Act requires the Executive Yuan to establish a National Artificial Intelligence Strategic Special Committee to coordinate national AI policy and formulate a national AI development blueprint (AI Basic Act, art. 6, 2025).
The AI Basic Act further defines AI as 'a system with autonomous operational capabilities that, through inputs or sensing and the use of machine learning and algorithms, generates outputs—such as predictions, content, recommendations, or decisions—that influence physical or virtual environments in pursuit of explicit or implicit objectives.' (AI Basic Act, art. 3, 2025).
2. Fundamental Principles of AI Governance
The AI Basic Act requires the government to adhere to seven guiding principles when promoting AI development. AI initiatives must prioritize sustainable development and well-being by balancing social equity with environmental sustainability and providing education to reduce digital divides, thereby enabling citizens to adapt to AI-driven changes. A commitment to human autonomy ensures a human-centric approach that respects fundamental rights, including personality rights and cultural values, while maintaining human oversight within the framework of the rule of law and democratic values (AI Basic Act, art. 4, 2025).
Regarding technical and operational governance, the Act emphasizes privacy protection and data governance to safeguard personal data and trade secrets, minimize data use, and prevent leaks, while promoting the reuse of non-sensitive data under constitutional privacy protections. This is coupled with cybersecurity and safety mandates to establish robust defenses against threats (AI Basic Act, art. 4, 2025).
Furthermore, transparency and explainability require the appropriate disclosure or labeling of AI outputs to facilitate risk assessment and build public trust. The framework also demands fairness and non-discrimination to actively avoid algorithmic bias and prevent discriminatory outcomes against specific groups. Ultimately, the principle of accountability guarantees that corresponding internal governance and external social responsibilities are properly assumed (AI Basic Act, art. 4, 2025).
3. Government Policies and Industrial Development
3.1 Financial Support and Industrial Policy
The AI Basic Act mandates the government to actively promote AI research, development (R&D), applications, and infrastructure (AI Basic Act, art. 8, 2025). To effectively implement AI development policies, the government must allocate adequate budgets within its fiscal capacity and strategically plan the overall distribution of resources (AI Basic Act, art. 9, 2025). To support these efforts, competent authorities may utilize a range of measures—including subsidies, commissions, funding, investments, rewards, and counseling—as well as offer tax and financial incentives to AI-related industries (AI Basic Act, art. 10, 2025). Finally, to ensure the ongoing optimization of these initiatives, the Act requires the establishment of an annual performance reporting system (AI Basic Act, art. 10, 2025). By regularly publishing evaluation results, this mechanism serves as an objective basis for continuous policy promotion and resource adjustment.
3.2 Data Openness and Sharing Framework
Regarding data utilization, the Act requires the government to establish mechanisms for data openness, sharing, and reuse, and to regularly review and adjust relevant regulations. The government must also strive to enhance the quality and quantity of data used by AI, ensuring that both the training processes and the generated outputs adequately demonstrate the nation's diverse cultural values and safeguard intellectual property rights (AI Basic Act, art. 13, 2025). To perfect the regulatory environment for AI development, the government shall provide measures such as fair use, support, and subsidies during the training, testing, and verification phases of AI systems. If the interpretation or application of relevant AI regulations conflicts with other existing laws, priority should be given to facilitating the provision of new technologies and services, provided that the fundamental principles of the AI Basic Act are met. In addition, to promote technological innovation and sustainable development, the Act authorizes competent authorities to establish innovative experimental environments for AI products and services (AI Basic Act, art. 11, 2025).
3.3 Talent Cultivation and the Innovation Ecosystem
To enhance citizens' knowledge and skills regarding AI, the AI Basic Act requires the government to continuously promote AI and ethics education across educational institutions of all levels, industries, civic groups, society, and public agencies, thereby cultivating citizens' overall digital literacy (AI Basic Act, art. 7, 2025). Furthermore, the government is mandated to strive for international cooperation related to AI. Based on the principle of public-private partnership, the government must actively collaborate with the private sector to jointly promote the innovative application of artificial intelligence (AI Basic Act, art. 12, 2025).
4. The AI Risk Governance Regime
4.1 Risk Classification and Management Architecture
To govern AI risks, the AI Basic Act mandates the Ministry of Digital Affairs to reference international standards and promote an internationally aligned AI risk classification framework. The Ministry must also assist competent authorities in formulating risk-based management regulations. Consequently, these authorities are required to develop their own risk-based regulations guided by this framework and help relevant industries establish self-regulatory guidelines and codes of conduct (AI Basic Act, art. 16, 2025). For public-sector applications, the legislation requires that when the government utilizes AI to execute duties or provide services, it must conduct risk assessments and plan response measures. Furthermore, government agencies must establish usage regulations or internal control mechanisms tailored to the specific nature of their AI operations (AI Basic Act, art. 19, 2025).
4.2 Institutional Balance Between High-Risk Accountability and R&D Exemptions
The law requires the government to restrict or prohibit AI applications based on three main categories of risk. First, regulatory interventions are mandated if an AI system infringes upon individual life, bodily integrity, liberty, or property. Second, the government must act against applications that disrupt social order, national security, or the ecological environment. Finally, bans or restrictions also apply to systems involving bias, discrimination, false advertising, misinformation, or forgery (AI Basic Act, art. 5 & 16, 2025). Especially for high-risk AI applications, the government must clarify the attribution of liability and conditions of accountability, and establish mechanisms for relief, compensation, or insurance (AI Basic Act, art. 17, 2025). AI R&D activities are generally exempt from regulations governing high-risk applications prior to their actual deployment. However, this exemption ceases to apply once the AI undergoes testing in real-world environments, or when R&D outcomes are transitioned into concrete products or services (AI Basic Act, art. 17, 2025).
5. Data Governance and Social Responsibility
5.1 Protection of Minors and Personal Data
Regarding the safeguarding of fundamental rights, in addition to protecting individuals' life, bodily integrity, liberty, and property, the Act further emphasizes the protection of minors and personal data. With respect to minors, the legislation highlights the principle of the 'best interests of the child.' For AI systems classified as high-risk, appropriate warning and labeling mechanisms must be established. Furthermore, the development of relevant verification and assessment tools should be carried out through a multi-stakeholder process involving industry, academia, research institutions, and civil society (AI Basic Act, art. 5, 2025). Additionally, to prevent AI from infringing personal data, the Act requires government agencies to avoid unnecessary data collection, processing, or use of personal data during the development of AI systems. It further promotes the adoption of measures based on the principle of 'data protection by design and by default,' in order to safeguard the rights and interests of data subjects (AI Basic Act, art. 14, 2025).
5.2 Protection of Labor Rights
The government must actively utilize AI to ensure the labor rights of workers. Furthermore, the government is mandated to actively bridge the skill gaps caused by the development of AI, enhance labor participation, safeguard economic security, and implement decent work. For individuals who become unemployed due to the utilization of AI, the government must provide employment counseling in accordance with their working capabilities (AI Basic Act, art. 15, 2025).
6. Conclusion: Legislative Review and Overall Summary
The government must review its regulations and administrative measures in accordance with the AI Basic Act. For those that do not comply with the provisions of this Act or where applicable regulations are lacking, the enactment, amendment, or repeal of regulations—as well as the improvement of administrative measures—must be completed within two years. Before these legislative modifications are completed, in cases where existing regulations lack provisions, central competent authorities for the specific purposes across various sectors must consult with the central competent authority to interpret and apply them in accordance with the Act. In summary, the AI Basic Act mandates adherence to seven principles and requires the government to allocate resources to promote AI development. Furthermore, the Act institutionalizes a risk-based management framework, establishing accountability mechanisms for high-risk applications while providing exemptions prior to actual application. Finally, the Act imposes concrete obligations on the government regarding privacy protection, cybersecurity requirements, and labor rights safeguards.
Ⅱ. Comparative Perspectives: Taiwan, Japan, and South Korea
1. A Comparative Study of AI Governance in Taiwan and Japan
1.1 Japan's Innovation-Oriented Environment Centered on Agile Governance and Soft Law
Regarding AI governance, Japan has long adopted a policy approach centered on agile governance and soft law, aiming to prevent premature and stringent regulation from stifling technological innovation. Unlike the regulatory model of the EU Artificial Intelligence Act, which relies on comprehensive and binding legislation, Japan primarily guides industrial development through policy principles and administrative guidelines. For example, the Japanese government has issued the Social Principles of Human-Centric AI (Council for Social Principles of Human-Centric AI, 2019), while the Ministry of Economy, Trade and Industry and the Ministry of Internal Affairs and Communications have jointly formulated the AI Guidelines for Business, encouraging enterprises to implement principles such as human-centricity, transparency, and accountability (Ministry of Economy, Trade and Industry, & Ministry of Internal Affairs and Communications 2024). At the same time, Japan tends to address AI-related issues through its existing legal framework. For instance, the information analysis exception established by the 2018 amendment to the Copyright Act of Japan allows the use of copyright-protected works for machine learning and data analysis, provided that it is not for the purpose of enjoying the work's expressive content and does not unreasonably prejudice the interests of the copyright owners (Agency for Cultural Affairs 2024).
1.2 Japan's Gradual Institutional Transition Toward Large Model Governance
As the potential systemic risks associated with generative AI and large-scale foundation models have become increasingly evident, Japan's governance approach has begun to evolve. To align with international regulatory developments, such as the governance framework proposed under the G7 Hiroshima AI Process, the Japanese government has recently initiated discussions on whether more binding governance mechanisms should be introduced for developers of large-scale AI models (AI Strategic Council / AI Institutional Study Group 2025). These policy discussions primarily focus on upstream risk management, including safety assessments, safeguards against malicious use, and appropriate governmental oversight. Overall, Japan's AI governance framework appears to be gradually moving toward a model that imposes moderate oversight on foundation models while maintaining substantial regulatory flexibility at the application level.
1.3 Comparison of AI Governance Models Between Taiwan and Japan
In contrast to Japan's soft-law governance model based largely on policy guidelines and industry self-regulation, Taiwan's AI Basic Act establishes the fundamental principles and policy directions for AI development and governance through statutory legislation. Nevertheless, Taiwan's legislative approach still retains a largely policy-oriented character, as most provisions are framed as guiding principles rather than detailed regulatory obligations. Ultimately, although both Taiwan and Japan emphasize the promotion of innovation and industrial development, Japan relies more heavily on policy principles and administrative guidance, whereas Taiwan tends to establish governance structures through a framework statute. While the two jurisdictions share similar governance philosophies, they diverge in their choice of institutional instruments, reflecting a contrast between statutory frameworks and policy-driven governance.
2. A Comparative Study of AI Governance in Taiwan and South Korea
2.1 South Korea's National Strategic Framework Centered on Industrial Promotion
In order to secure its competitive advantage in the global AI industry, the South Korean National Assembly recently passed the Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust (hereinafter the 'Korean AI Act', 2025), establishing a national development strategy through statutory legislation (Korean AI Act, art. 1, 2025). Under the Korean AI Act, the National AI Committee, led by the President, serves as the highest policy coordination body (Korean AI Act, art. 7, 2025), and the government is required to formulate an AI Basic Plan every three years (Korean AI Act, art. 6, 2025). The Korean AI Act also reflects a clear orientation toward industrial promotion. It requires the government to support the development of AI technologies by small and medium-sized enterprises (SMEs) and startups, while encouraging the public sector to adopt AI-related products and services (Korean AI Act, art. 16, 2025). The government should also support international cooperation and overseas expansion (Korean AI Act, art. 22, 2025).
2.2 South Korea's Safety Mechanisms for High-Impact AI
The Minister of Science and ICT is authorized to establish and operate an Artificial Intelligence Safety Institute in order to safeguard citizens' lives and property, develop safety standards, and carry out technical evaluations (Korean AI Act, art. 12, 2025). While promoting industrial development, South Korea has also begun to establish regulatory mechanisms for high-impact AI applications (Korean AI Act, art. 33, 2025). Developers and providers of such systems are required to fulfill obligations including risk management, transparency, and human oversight (Korean AI Act, arts. 31, 32 & 34, 2025). Overall, South Korea's AI governance framework reflects a model characterized by strong industrial promotion combined with targeted regulation of high-risk applications.
2.3 Comparison of AI Governance Models Between Taiwan and South Korea
Both Taiwan and South Korea have adopted the enactment of an AI Basic Act as an important institutional foundation for AI governance. In both jurisdictions, the legislative objectives emphasize balancing the promotion of industrial development with the mitigation of societal risks. However, important differences arise in institutional design and the allocation of administrative authority. South Korea's legislation exhibits stronger state-led characteristics, reinforcing central policy coordination and incorporating certain industrial policy instruments within the statute. By contrast, Taiwan's AI Basic Act adopts a more framework-oriented governance model. It designates the National Science and Technology Council as the central coordinating authority, while delegating rulemaking authority to sectoral regulators to develop specific regulatory rules and industry guidelines based on a risk-classification framework. Ultimately, although both jurisdictions adopt the structure of a basic act, South Korea is more inclined to incorporate concrete industrial policies and administrative arrangements directly into the statute, whereas Taiwan maintains a higher-level policy framework with greater cross-ministerial flexibility.
3. Conclusion: Comparative AI Governance Models in Taiwan, Japan, and South Korea
In AI governance, Taiwan, Japan, and South Korea all emphasize technological innovation and risk management, yet they follow distinct governance pathways in their institutional tools and policy orientations. Japan has long adopted a soft-law governance model primarily based on policy principles and administrative guidelines, emphasizing agile governance and industry self-regulation to maintain a balance between technological innovation and regulatory flexibility. In contrast, South Korea adopts a more state-led institutional approach. Through the Korean AI Act, it establishes a centrally coordinated policy framework while incorporating industrial support measures and regulatory mechanisms for high-impact AI. Taiwan, by comparison, has recently established a law-based governance framework through its AI Basic Act, positioning its governance model between those of Japan and South Korea. On the one hand, the AI Basic Act centers on risk classification and fundamental governance principles without establishing a comprehensive mandatory regulatory regime. On the other hand, Taiwan institutionalizes its governance structure through legislation, with the National Science and Technology Council coordinating national AI policy and sectoral regulators formulating specific rules. Overall, the three jurisdictions represent distinct governance typologies: Japan reflects policy-oriented soft-law governance, South Korea demonstrates state-led industrial strategy legislation, while Taiwan develops a model characterized by framework legislation combined with risk-based governance. Table 1 summarizes the structural contrasts.
Table 1-1: Comparative Analysis of AI Regulations in
Taiwan, Japan, and South Korea
| Dimension | Taiwan | Japan | South Korea |
|---|
| Core Legal Instrument | AI Basic Act (2025) | Policy guidelines | AI Basic Act (2025) |
| Governance Model | Framework governance | Soft-law governance | State-led governance |
| Regulatory Approach | Risk-based principles | Flexible / adaptive | Targeted regulation |
| Legal Style | Principle-based statute | Administrative guidance | Statutory regulation |
| Industrial Policy | Innovation support | Innovation-friendly | Strong state promotion |
| Institutional Coordination | NSTC | METI / MIC | National AI Committee |
| Risk Regulation | Risk classification | Limited formal rules | High-impact AI control |
Source: Sung, H.-C. (2026). Compiled from AI Basic Act (2025), Korean AI Act (2025), METI/MIC (2024).
Table 1-1 illustrates how different institutional traditions shape AI governance in East Asia, producing diverse regulatory strategies that balance innovation, state coordination, and risk management in distinct ways. Together, these models demonstrate that AI regulation does not follow a single universal path but evolves according to each jurisdiction's policy priorities and administrative structure.
Ⅲ. AI Guidelines of Local Governments in Taiwan
Prior to the enactment of the AI Basic Act, Taiwan's Executive Yuan issued a policy document titled Reference Guidelines for the Use of Generative AI by the Executive Yuan and Its Subordinate Agencies ('Central Guidelines') in 2023 (Central Guidelines 2023). The Central Guidelines aim to provide fundamental principles and practical guidance for central government agencies utilizing generative AI tools. They are not legally binding regulations; rather, they function as a soft-law policy directive designed to guide public agencies in balancing administrative efficiency with risk management when adopting generative AI technologies. The main objective of the Central Guidelines is to ensure that the use of AI remains subject to human oversight and ultimate decision-making responsibility, while preventing the leakage of classified documents, personal data, or other sensitive information. They also caution agencies about potential risks associated with generative AI, including inaccurate information, algorithmic bias, and possible copyright infringement, and require civil servants to conduct appropriate verification and professional judgment when relying on AI-generated content. These Central Guidelines have also influenced the subsequent development of AI governance at the local government level, where several municipalities have issued their own administrative guidelines governing the use of generative AI.
1. Overview of the Taipei City Government AI Guidelines
In response to the rapid development of AI technologies and to ensure the legality and information security of municipal administration, the Taipei City Government issued the Taipei City Government Guidelines for the Use of Artificial Intelligence (hereinafter the 'Taipei City AI Guidelines') in September 2024 (Taipei City AI Guidelines 2024).
1.1 Regulatory Background and Positioning
The Taipei City AI Guidelines aim to provide standardized operational procedures and a compliance framework for municipal agencies and public schools when adopting AI technologies. As administrative guidelines at the local government level, they build upon the policy framework established by the Executive Yuan's Central Guidelines and further implement AI governance principles into the practical context of municipal administration.
1.2 Risk Classification and Core Principles
In terms of governance structure, the Taipei City AI Guidelines adopt a risk-based management model, categorizing AI applications into strictly prohibited, high-risk, medium-risk, and low-risk types based on their potential impact. The Guidelines also establish six core principles for public-sector AI use: accountability, safety, transparency and explainability, fairness and non-discrimination, privacy and personal data protection, and training and responsible use. To operationalize these principles, agencies must conduct ex-ante risk assessments and define the scope of application through a dedicated checklist when proposing AI-related projects.
1.3 Confidentiality Protection, Transparency, and Intellectual Property Compliance
At the operational level, the Taipei City AI Guidelines introduce several risk-control mechanisms. With respect to safety, civil servants are prohibited from entering classified or sensitive information into external generative AI systems to prevent information leakage. Regarding transparency, when AI is used to generate text, audio, images, or video in administrative processes, appropriate labeling or disclosure is required. The Guidelines also require users to conduct ex-ante prompt reviews and ex-post verification of generated outputs to prevent unlawful content or the infringement of privacy, personal data, or copyright.
1.4 Human Oversight and Institutional Accountability
The Taipei City AI Guidelines emphasize the principle of accountability. Artificial intelligence is defined strictly as an auxiliary tool for municipal administration. When relying on AI-generated information, responsible personnel must conduct professional verification and make the final judgment regarding potential risks. AI outputs must not replace the professional judgment and substantive review of civil servants. Regardless of the AI system adopted, ultimate decision-making authority and administrative responsibility remain with the agency and personnel using the technology. This ensures that, even as AI is used to enhance administrative efficiency, the final gatekeepers of municipal decisions remain human.
1.5 Practical Implementation Tools: Flowcharts, Checklists, and Q&As
The Taipei City AI Guidelines are notable for their strong practical orientation. Rather than remaining at the level of abstract principles, the document provides concrete implementation tools, including operational flowcharts, risk assessment checklists, and frequently asked questions (Q&As) tailored to administrative scenarios. These visualized and step-by-step instruments provide frontline civil servants and agency IT units with a clear practical guide, enabling municipal agencies to translate compliance requirements into concrete standard operating procedures when procuring, developing, or deploying AI systems.
2. Overview of the New Taipei City Government AI Guidelines
To establish an AI governance framework and promote the application of AI technologies in municipal services, the New Taipei City Government issued the New Taipei City Government Guidelines for the Use of Artificial Intelligence (hereinafter the 'New Taipei City AI Guidelines') in September 2025, which took effect on September 30 of the same year. These Guidelines aim to accelerate the adoption and application of AI across municipal agencies and schools and to establish standardized operational procedures, thereby enhancing public service efficiency and establishing AI-related governance mechanisms.
2.1 Regulatory Background and Scope of Application
The New Taipei City AI Guidelines apply to the relevant operational procedures and governance requirements for all municipal agencies and schools when adopting or using AI technologies. The Guidelines also implement relevant governance requirements into the public-sector procurement process, stipulating that when agencies conduct AI-related procurement or outsourced development projects, they must complete a self-assessment according to the Guidelines and consult the city government's Information Center prior to procurement. Concurrently, agencies must incorporate AI system operational management mechanisms and related technical document requirements into procurement documents to ensure that outsourced development and adoption processes comply with governance and information security regulations.
2.2 Governance Principles and Human Oversight Mechanisms
Regarding governance principles, the New Taipei City AI Guidelines require all agencies to implement fundamental principles such as fairness, transparency, explainability, accountability, human oversight, and privacy protection when using AI. The Guidelines emphasize that AI can only serve as an auxiliary tool for administrative operations. Civil servants must still conduct necessary reviews and judgments when utilizing AI-generated information and must not directly use AI-generated outputs as the sole basis for administrative decisions, thereby ensuring that administrative actions remain subject to ultimate human judgment and responsibility.
2.3 Generative AI Usage Restrictions and Information Protection
Concerning the application of generative AI, the New Taipei City AI Guidelines establish specific information protection measures. In principle, civil servants are prohibited from inputting classified information, confidential official matters, or personal data into external generative AI systems, nor may they prompt such systems with content that may involve classified operations or sensitive data, to avoid the risk of information leakage. For generative AI systems using closed-network or on-premises deployment, appropriate use may be permitted in accordance with the classification level of the documents or information, provided that the security of the system environment has been verified.
2.4 AI System Security and Model Governance Requirements
The New Taipei City AI Guidelines set forth governance requirements addressing the technical risks of AI systems. In terms of data governance, they emphasize that data usage must comply with principles such as legality, de-identification, and data minimization. Regarding information security, the Guidelines require agencies to strengthen defenses against AI-specific security threats, such as adversarial attacks, model stealing, and data poisoning. Additionally, the Guidelines require the establishment of model monitoring and management mechanisms to continuously observe system performance and potential biases.
3. Conclusion: Local Government AI Guidelines
Prior to the enactment of Taiwan's AI Basic Act, Taipei City and New Taipei City took the lead in issuing local government-level AI operational guidelines, translating the Executive Yuan's reference guidelines into municipal administrative practice. These two sets of guidelines exhibit several common characteristics in their institutional design and administrative practices. Through standardized procedures and administrative management mechanisms, these local guidelines provide a practical governance framework for local governments in the use of AI technologies prior to the enactment of national legislation. This bottom-up trajectory—from local administrative practice to national statutory law—is a defining feature of Taiwan's AI governance evolution, with municipal innovation functioning as a policy laboratory for the national framework.■