Taiwan's National Science and Technology Council drafted an Artificial Intelligence Basic Act, approved by the Executive Yuan in July 2024 and sent to the Legislative Yuan for review. As of July 2026, the draft has not completed the legislative process into force of law. That gap matters for operators, because it means Taiwan's binding AI-relevant obligations today sit inside existing statutes and sector guidance rather than a single AI statute, even as the Basic Act's seven principles already shape how Taiwanese regulators are approaching AI in practice. This guide sets out what is actually binding now, what the draft Act would add once enacted, and how the whole picture compares to the EU AI Act.
Key takeaways
- Taiwan has no enacted, standalone AI statute in 2026. The Executive Yuan approved a draft Artificial Intelligence Basic Act in July 2024, prepared by the National Science and Technology Council, and the Legislative Yuan has not yet passed it into force as of this article's publication date.
- The draft sets seven governance principles: sustainable development, human autonomy, privacy protection, safety, transparency and explainability, fairness and non-discrimination, and accountability, applied as a basic law that directs sectoral implementation rather than a single risk-tiered regulation.
- Binding obligations today run through existing statutes, principally the Personal Data Protection Act, enforced since 2023 amendments by the newly established Personal Data Protection Commission, and sector guidance from regulators such as the Financial Supervisory Commission.
- Taiwan's structural approach is closer to Japan's AI Promotion Act and Switzerland's sectoral-adaptation model than to the EU AI Act's single harmonised regulation with mandatory conformity assessment and turnover-based penalties.
- Taiwan is not a member state of the United Nations, the OECD, or the Council of Europe, which shapes how it engages with international AI standards bodies and is a structural fact operators should factor into cross-border compliance mapping.
Background and context
Taiwan's move toward AI-specific governance follows a pattern familiar from its wider technology regulation history: a period of sectoral guidance and voluntary principles, followed by a coordinated attempt to bring the various strands together under a single framework statute. The National Science and Technology Council, Taiwan's cabinet-level science and technology policy body, formerly known as the National Science Council before its 2022 reorganisation, led the drafting process for an Artificial Intelligence Basic Act through 2023 and into 2024, drawing on international reference points including the OECD AI Principles and the EU AI Act's structure, while adapting the model to Taiwan's existing regulatory architecture and its distinct international position.
The Executive Yuan, Taiwan's cabinet, approved the draft Act in July 2024 and forwarded it to the Legislative Yuan for review. Legislative review of framework statutes in Taiwan can extend across multiple legislative sessions, and as of July 2026 the Basic Act has not been enacted into force. Operators should treat the draft as a strong policy signal of the government's intended direction rather than as a source of binding obligations today. The National Science and Technology Council has continued to publish guidance and reference materials consistent with the draft's principles while the legislative process continues, which means the draft's substance is already influencing regulatory expectations even without the force of statute.
The seven principles and the basic law model
The draft Act is structured as a basic law, a form used in Taiwanese legislation to set overarching principles and direct subsequent sectoral implementation rather than to create a single, self-executing regulatory regime. Its substantive core is a set of seven principles: sustainable development, human autonomy, privacy protection, safety, transparency and explainability, fairness and non-discrimination, and accountability. These principles are intended to apply across government AI policy and, once the Act is in force, to guide the sectoral regulations that individual ministries and agencies would be directed to develop within their own domains.
This is a materially different structure from the EU AI Act. Regulation (EU) 2024/1689 classifies AI systems into risk tiers, attaches specific, itemised obligations to each tier under Articles 9 through 17 and Article 26, and creates a single supervisory architecture coordinated by the European AI Office and national market surveillance authorities. Taiwan's draft instead sets the seven principles as a common reference point and leaves the operational detail, registration, documentation standards, oversight mechanisms, to be filled in by whichever agency has jurisdiction over a given AI use, once directed to do so by the Basic Act. Operators who have built an EU AI Act compliance programme should not expect a Taiwanese equivalent of Annex III or a single conformity marking scheme even after enactment; the more realistic outcome is a slower, sector-by-sector build-out of specific rules under the Basic Act's principles.
What is actually binding today: the Personal Data Protection Act and the PDPC
The most consequential binding statute for AI operators in Taiwan predates the Basic Act drafting process. The Personal Data Protection Act, originally enacted in 1995 as the Computer-Processed Personal Data Protection Act and substantially revised since, governs the collection, processing, and use of personal data, including data processed by AI systems. Amendments passed in 2023 established a dedicated Personal Data Protection Commission, moving enforcement away from the previously fragmented model in which multiple sectoral ministries each enforced data protection rules within their own domain. The Commission's establishment is the most significant recent structural change to Taiwan's data protection enforcement landscape and is the closest Taiwan currently has to a horizontal AI-adjacent regulator, given how much AI-related harm in practice runs through personal data processing.
For AI operators, the practical implication is that any AI system processing personal data of Taiwanese individuals, which covers the large majority of customer-facing AI deployments, already sits inside a binding, enforceable statute regardless of whether the Basic Act is ever passed. Consent requirements, purpose limitation, and data subject rights under the Personal Data Protection Act apply to AI-driven processing in the same way they apply to any other processing activity. Operators should treat PDPA compliance as the current floor for AI governance in Taiwan, with the Basic Act's principles, once enacted, adding an AI-specific layer on top rather than replacing this foundation.
Sectoral guidance: the Financial Supervisory Commission
Consistent with Taiwan's sector-first approach, the Financial Supervisory Commission has issued guidance addressing AI use by banks, insurers, and other regulated financial institutions, covering governance expectations, risk management, and explainability for AI-assisted decisions in areas such as credit assessment and fraud detection. This guidance operates within the FSC's existing supervisory powers over regulated financial entities rather than as a standalone AI statute, meaning enforcement runs through the FSC's ordinary supervisory and administrative tools. Financial institutions deploying AI agents in Taiwan should treat FSC guidance as a live compliance expectation now, independent of the Basic Act's legislative status, in the same way FINMA's approach to AI in Switzerland operates through existing supervisory circulars rather than a dedicated AI licence.
Other sectoral regulators, including those overseeing healthcare and transport, are expected to follow a similar pattern once the Basic Act directs them to develop domain-specific AI rules, but as of July 2026 the FSC's financial sector guidance is the most developed sectoral AI framework in practical operation.
Taiwan's international position and what it means for standards alignment
A structural fact that distinguishes Taiwan from every EU Member State, the United Kingdom, and most other jurisdictions covered in this network is that Taiwan is not a member state of the United Nations, the OECD, or the Council of Europe. This is not a governance choice; it reflects Taiwan's unresolved international status. The practical consequence is that Taiwan cannot become a direct signatory to instruments such as the Council of Europe Framework Convention on AI or a full member of the OECD's AI Principles governance process in the way Council of Europe and OECD member states can.
Taiwan's engagement with international AI and technical standards instead runs through industry and technical channels. Taiwan's national standards body, the Bureau of Standards, Metrology and Inspection, participates in international standards development including ISO and IEC work relevant to AI management systems such as ISO/IEC 42001, and Taiwanese industry associations engage with international AI governance discussions through non-state channels. Operators building a cross-border AI governance programme that references ISO/IEC 42001 or the OECD AI Principles as a common baseline will find that baseline transfers reasonably well to Taiwan in substance, even though Taiwan's formal participation in the originating international processes is structurally different from that of an OECD or Council of Europe member state.
Comparison with the EU AI Act
Set against the EU AI Act, Taiwan's current position combines two features operators need to hold separately. First, there is no enacted, horizontal AI statute, and the draft Basic Act, once passed, is designed as a principles-and-direction framework rather than a risk-tiered regulation with itemised technical obligations and a fixed penalty regime comparable to Article 99 of Regulation (EU) 2024/1689. Second, there is already a functioning, binding data protection statute with a dedicated enforcement commission, and at least one sectoral regulator, the FSC, actively applying AI-specific guidance within its existing powers. The combined effect is a jurisdiction that looks less regulated than the EU on paper today but is not unregulated in practice for the AI use cases that generate the most real-world risk: personal data processing and financial services decisions.
Extraterritorial reach is asymmetric in the way operators should expect. The EU AI Act's Article 2 extraterritorial scope applies in full to any operator placing AI systems on the EU market or whose AI output is used in the EU, regardless of a Taiwanese operator's domestic regulatory status. There is no equivalent extraterritorial reach running the other way from Taiwan's current framework, since the Basic Act has not yet been enacted and the PDPA's extraterritorial application, while real for processing of Taiwanese residents' data, does not extend to a general AI conformity regime. A cross-border operator's EU compliance obligations are not reduced by strong Taiwanese governance, and Taiwanese compliance obligations are not created by an operator's EU AI Act programme; the two run on separate tracks that happen to share several underlying principles.
Practical implications for operators
Four steps are proportionate for an operator active in Taiwan today. First, treat Personal Data Protection Act compliance as the binding floor for any AI system processing personal data of Taiwanese individuals, and confirm your data governance documentation would satisfy the Personal Data Protection Commission's expectations under the 2023 enforcement structure, not just an internal privacy policy. Second, if operating in or selling into Taiwan's financial sector, map your AI governance programme against the FSC's published guidance directly, since this is the most concrete, currently enforceable AI-specific expectation in the jurisdiction. Third, track Legislative Yuan progress on the Basic Act as the primary signal of when Taiwan moves from principles-only to binding AI-specific obligations, rather than assuming enactment on any particular timeline. Fourth, where an EU AI Act or ISO/IEC 42001 governance programme already exists, use its documentation as the backbone for Taiwan, since the substantive principles largely overlap even though the legal force and enforcement architecture differ.
For a comparison of a similarly sectoral, non-EU approach, see the Switzerland AI governance guide. For the EU deployer obligations that remain the highest-stringency benchmark against which any non-EU regime is measured, see the Article 26 deployer obligations guide on agentliability.eu. Operators assembling documentation evidence for cross-border AI governance programmes may also find the Agent Certified methodology useful as a structured reference framework that travels across jurisdictions including Taiwan.
Related reading
For the Asia-Pacific regional context this guide sits within, see Asia-Pacific AI governance in 2026. For a jurisdiction with an enacted horizontal AI statute close in spirit to Taiwan's draft, see the Korea AI Basic Act guide. For the three-jurisdiction comparison of structurally different approaches, see US, EU, UK: three approaches to the same question.
Frequently asked questions
Does Taiwan have an enacted AI law in 2026?
Not yet as a standalone statute. Taiwan's Executive Yuan approved a draft Artificial Intelligence Basic Act, prepared by the National Science and Technology Council, in July 2024 and sent it to the Legislative Yuan for review. As of July 2026 the draft remains part of the legislative process rather than force of law. In the meantime, AI-relevant obligations in Taiwan sit inside existing statutes, principally the Personal Data Protection Act, and sector-specific guidance from regulators such as the Financial Supervisory Commission.
What are the core principles in Taiwan's draft AI Basic Act?
The draft sets out seven governance principles: sustainable development, human autonomy, privacy protection, safety, transparency and explainability, fairness and non-discrimination, and accountability. These function as directional principles for government agencies and, once enacted, for AI providers and deployers, rather than as a risk-tiered list of binding technical obligations in the style of the EU AI Act's Annex III.
Which agency enforces AI-related obligations in Taiwan today?
No single AI regulator exists. The National Science and Technology Council coordinates policy and drafted the Basic Act, but day-to-day enforcement of AI-adjacent obligations runs through existing sectoral regulators using their existing powers: the Financial Supervisory Commission for AI used in banking and insurance, and the Personal Data Protection Commission, established by 2023 amendments to the Personal Data Protection Act, for AI systems that process personal data.
How does Taiwan's approach compare to the EU AI Act?
Taiwan has chosen a basic law, or framework law, model: broad principles set centrally, with implementation left to sector regulators, similar in structure to Japan's AI Promotion Act and to Switzerland's sectoral-adaptation approach. This differs from the EU AI Act's model of a single harmonised regulation with a risk-tiered classification system, mandatory conformity assessment for high-risk systems, and a turnover-based penalty regime. Taiwan's draft, as currently structured, does not include an equivalent fixed penalty tier; enforcement instead depends on the existing powers of whichever sectoral regulator has jurisdiction over the deployment.
Why does Taiwan's exclusion from bodies like the OECD and the United Nations matter for AI governance?
Taiwan is not a member state of the United Nations, the OECD, or the Council of Europe, which means it cannot be a direct party to instruments such as the OECD AI Principles or the Council of Europe Framework Convention on AI in the way EU and OECD member states are. Taiwan's engagement with international AI standards instead runs through technical and industry channels, including participation in ISO and IEC standards work through its national standards body, the Bureau of Standards, Metrology and Inspection. Operators benchmarking Taiwan against other jurisdictions should treat this as a structural feature of Taiwan's international position, not an indicator of lower governance ambition domestically.
References
- Executive Yuan, Republic of China (Taiwan). Approval of the draft Artificial Intelligence Basic Act, prepared by the National Science and Technology Council, July 2024, forwarded to the Legislative Yuan for review.
- National Science and Technology Council (Taiwan). Draft Artificial Intelligence Basic Act, seven governance principles: sustainable development, human autonomy, privacy protection, safety, transparency and explainability, fairness and non-discrimination, and accountability.
- Personal Data Protection Act (Taiwan), originally enacted as the Computer-Processed Personal Data Protection Act, 1995, substantially amended including the 2023 amendments establishing the Personal Data Protection Commission.
- Financial Supervisory Commission (Taiwan). Guidance on AI governance, risk management, and explainability for regulated financial institutions.
- Regulation (EU) 2024/1689 of the European Parliament and of the Council (AI Act), for comparison, including Article 2 (extraterritorial scope), Articles 9 to 17 (high-risk obligations), Article 26 (deployer obligations), and Article 99 (penalties).
- OECD. OECD AI Principles (2024 revision), referenced by Taiwan's National Science and Technology Council in drafting the Basic Act. Taiwan is not an OECD member state.