Skip to Content
ANALYSISMEMBER

Taiwan's AI Risk Classification Framework: A different path

Taiwan's AI Risk Classification Framework creates a regulator-led, risk-based governance model that guides public agencies — and indirectly the public sector — in identifying, assessing and responding to civilian AI risks while balancing oversight with innovation.

Published
Subscribe to IAPP Newsletters

Contributors:

Ken-Ying Tseng

Partner

Lee and Li

On the second day of the U.N.'s "Global Dialogue on AI Governance" in Geneva, 7 July, attracting multistakeholder groups from around the world, the Ministry of Digital Affairs of Taiwan officially announced an "AI Risk Classification Framework" that will serve as a rulebook for all Taiwan government agencies in implementing the AI Basic Act. 

Taiwan's AI Basic Act lays out a unique AI regulatory and governance structure — making it distinct from those adopted in other major jurisdictions, such as the European Union, the United States and other major economies in Asia — and the framework is the core element for visualizing and operationalizing such a system.

A rulebook for the public sector but useful for the private sector, too

First of all, the AI Risk Classification Framework provides general guidance as well as sets of operational steps, workflows and examples for sectoral regulators in Taiwan to assess the potential AI risks that may occur if the businesses they regulate adopt AI technology in their operations. 

It also provides guidance for those regulators to formulate and determine actions to further address risks, for example, issuing self-discipline guidelines, implementing pre-deployment screening or licensing requirements, or proposing the enactment of new statutes or amendments to existing statutes to prohibit or limit the deployment of certain defined high-risk AI. 

Government agencies must follow the principles and methodology set forth within the framework to implement tasks under the AI Basic Act. The private sector, such as AI developers and deployers, is not bound by the framework, but will be bound by future regulations or policies to be implemented based on the framework.  

Contributors:

Ken-Ying Tseng

Partner

Lee and Li

MEMBER

Unlock this exclusive content and more

Join the IAPPAlready a member? Sign in

Membership opens up a world of resources

In-depth knowledge

From original research reports and daily news coverage to legislative trackers and infographics, we have the information you need to stay ahead of change.

A global network

Make valuable professional connections through more than 160 local IAPP KnowledgeNet chapters in 70 countries.

Access to the experts

Connect with top thinkers in privacy, AI governance and cybersecurity for fresh ideas and insights.

Learn what you get from membership