Written and maintained by CASRAI Editorial Board
Last updated
Verified against Tech Policy Press’s “Taiwan’s AI Basic Act Can Be a Model for Asia” (February 25, 2026) and a K&L Gates client alert on the Executive Yuan’s draft bill (October 8, 2025); last checked September 2026. On December 23, 2025, Taiwan’s Legislative Yuan passed the Basic Act on Artificial Intelligence — commonly rendered in English as the AI Basic Act (人工智慧基本法) and, in some outlets’ translation, the “Artificial Intelligence Fundamental Act.” President William Lai Ching-te promulgated it on January 14, 2026, and it entered into force the same day. That makes Taiwan the third major East Asian jurisdiction — after Japan’s AI Promotion Act and Korea’s AI Basic Act — to legislate a dedicated, national “basic act” for artificial intelligence. What makes Taiwan’s version distinctive is not any single obligation it imposes; it’s how little the statute itself decides. It is a 20-clause framework act that sets no penalties, defines no risk tiers, and instead delegates almost every operative detail — what counts as high-risk, what sector rules apply, how compliance gets checked — to agencies that have not yet finished writing those rules.
What the Legislative Yuan Actually Passed
The bill’s path was conventional for Taiwanese legislation: the Executive Yuan (the cabinet) approved a draft version on August 28, 2025, and referred it to the Legislative Yuan (Taiwan’s unicameral parliament) for review, according to K&L Gates’ contemporaneous alert on the draft. That version already carried the shape the final act kept — the Ministry of Digital Affairs (MODA) as coordinating agency, and an R&D-stage carve-out for academic and industrial research. The Legislative Yuan passed the final text on December 23, 2025; President Lai signed and promulgated it on January 14, 2026. Multiple outlets covering the same week — Focus Taiwan, Taiwan News, and Taiwan Today among them — corroborate the December 23 passage date, though they render the act’s English name slightly differently (“AI Basic Act,” “Artificial Intelligence Fundamental Act,” “Basic Law on Artificial Intelligence”), which is ordinary variation in translating a Chinese-language statute rather than a sign of more than one law.
The 20 Clauses: What the Act Actually Requires
Per Tech Policy Press’s reading of the enacted text, the act’s 20 clauses do four concrete things, none of which is “set a penalty”:
- Delegate risk classification to MODA (unpublished). The act tasks the Ministry of Digital Affairs with establishing an AI risk-classification framework “consistent with global standards” — but that framework itself has not been published. The act creates the mandate for a risk-tier system without creating the tiers.
- Require sector agencies to write their own rules (Clause 16). Rather than a single cross-sector compliance regime, government agencies are directed to help their respective industries develop their own AI safety guidelines and codes of practice — meaning the operative rules a healthcare AI vendor faces and the ones a finance AI vendor faces are expected to diverge, set by different ministries on different timelines.
- Protect labor rights and fund skills-gap compensation (Clause 15). The act mandates that government use of AI protect workers’ labor rights, and directs compensation for skills mismatches that AI-driven changes create — a labor-market provision with no direct equivalent in Japan’s or Korea’s basic acts.
- Exempt R&D-stage developers from relief duties (Clause 17). Developers are explicitly absolved of any duty to provide relief or compensation for “high-risk applications” while those applications are still in research and development — the same carve-out that appeared in the Executive Yuan’s August 2025 draft, confirmed unchanged in the enacted version.
No Penalties, By Design — and Not Alone in That
Tech Policy Press is explicit that the act “has refrained from legislating specific penalties over violations by domestic or global firms.” That is a deliberate design choice, not an oversight awaiting a future amendment, and it puts Taiwan in the same structural family as Japan’s AI Promotion Act, which likewise contains no fine or sanction and relies on non-binding “administrative guidance” as its only lever. The two laws are not identical in mechanism, though. Japan’s act creates a single national “duty to cooperate” enforced (if at all) by the Cabinet Office naming a noncompliant business publicly. Taiwan’s act instead fragments enforcement outward before it even starts: Clause 16 hands rule-writing to individual sector agencies, and the risk-classification framework that would tell a developer whether it is even “high-risk” in the first place does not exist yet. Where Japan’s no-penalty model is at least centralized, Taiwan’s is deliberately distributed — a structure closer to “come back once every ministry has written its own rules” than to “here is one law and here is what breaking it costs.”
That also separates Taiwan sharply from Korea’s AI Basic Act, which despite the similar name is a materially more binding statute already in force: it requires foreign developers to designate a Korea-based local representative and imposes concrete risk-assessment duties on “high-impact” and generative AI systems today, not once a future framework is published. Lined up together, the three basic acts sit at three different points on the same spectrum — Korea (binding obligations, in force) → Taiwan (framework act, obligations pending subordinate rules) → Japan (no binding obligations at all, guidance only) — despite all three sharing the “basic act” label and all three predating any EU-style compute threshold or civil-penalty regime.
Why “Consistent with Global Standards” Is a Placeholder, Not a Commitment
The single phrase doing the most work in the act is the instruction that MODA’s future risk-classification framework be “consistent with global standards.” That phrase commits Taiwan to alignment in principle while committing it to nothing specific in practice — it does not say which global standard (the EU AI Act’s risk tiers, the NIST AI RMF, ISO/IEC 42001, or some blend) MODA will actually track, and as of this writing MODA has not published the framework that would answer that question. Until it does, the practical effect of the AI Basic Act for a company operating in Taiwan is closer to a statement of legislative intent than to an operative compliance regime: the obligations that would flow from being classified “high-risk” cannot yet attach to anyone, because the classification itself has not been written.
Where NIKOLAI Fits — A Gap, Not a Mapping
NIKOLAI is CASRAI’s own frontier-AI-safety dictionary — an independent, unendorsed reference work, not an official record of Taiwanese law or of any regulator’s own terminology. Every crosswalk row in NIKOLAI is a shadow mapping, CASRAI’s own interpretive reading of how a jurisdiction’s language lines up with NIKOLAI’s elements, unless and until that jurisdiction or organization files its own Mapping Declaration.
We checked NIKOLAI’s Coverage scope threshold element directly before writing this — the element that documents the if-then test determining whether a framework applies to a given developer or model, the same family as the EU AI Act’s Article 51 systemic-risk threshold and California SB 53’s compute trigger. As of publication, that element’s crosswalk table carries no row for Taiwan, and none of its current rows are jurisdiction-level statutes outside the EU and California. That is not an oversight to flag as a gap in NIKOLAI’s coverage in the way Korea’s AI Basic Act guide flags a real, checkable gap: Korea’s “high-impact” threshold already exists as text a mapping could be built against. Taiwan’s does not. MODA’s risk-classification framework — the document that would actually define a Taiwan scope threshold — has not been published, so there is nothing yet for a NIKOLAI crosswalk to map to. Once MODA’s framework exists, this element is the natural place a future shadow mapping would go.
FAQ
Does Taiwan’s AI Basic Act have penalties?
No. Per Tech Policy Press’s analysis of the enacted text, the act “has refrained from legislating specific penalties over violations by domestic or global firms.” It is a soft-law framework act, not a civil-penalty regime.
What is the act’s formal name?
English-language coverage renders it variously as the “AI Basic Act,” “Artificial Intelligence Fundamental Act,” and “Basic Law on Artificial Intelligence” — translations of the same Chinese-language statute, 人工智慧基本法. There is no single official English short title in the coverage CASRAI reviewed.
When did it pass and take effect?
Taiwan’s Legislative Yuan passed the act on December 23, 2025. President William Lai Ching-te promulgated it on January 14, 2026, and it took effect the same day.
Does the act define AI risk tiers?
Not yet. The act directs the Ministry of Digital Affairs (MODA) to establish a risk-classification framework “consistent with global standards,” but that framework had not been published as of this writing. The act creates the mandate, not the classification itself.
How does it compare to Japan’s and Korea’s AI basic acts?
All three are penalty-free or largely so, but they differ in how binding they are today. Korea’s AI Basic Act is already in force with concrete obligations, including a Korea-based local-representative requirement. Japan’s AI Promotion Act has no binding obligations at all, only non-binding administrative guidance. Taiwan sits between them: a binding framework act whose actual obligations depend on subordinate rules — MODA’s risk classification and each sector agency’s own codes of practice under Clause 16 — that have not yet been finished.
Does NIKOLAI track Taiwan’s AI Basic Act?
No. NIKOLAI’s Coverage scope threshold element, the closest fit for a scope-defining mechanism like MODA’s forthcoming framework, carries no Taiwan row, and CASRAI is not aware of any Taiwanese organization having filed a NIKOLAI Mapping Declaration. Because MODA’s own risk-classification framework does not yet exist in published form, there is no Taiwanese scope test yet for a future mapping to reference.
What does Clause 17 exempt developers from?
Clause 17 absolves developers of any duty to provide relief or compensation for “high-risk applications” while those applications are still in the research-and-development phase — a carve-out that appeared in the Executive Yuan’s August 2025 draft and was carried through to the enacted text unchanged.
Sources
- Tech Policy Press, “Taiwan’s AI Basic Act Can Be a Model for Asia,” February 25, 2026 — passage date, promulgation date, 20-clause structure, no-penalty design, MODA risk-classification mandate, Clauses 15-17.
- K&L Gates, “New Development: Taiwan’s Executive Yuan Has Passed the Draft Bill of the Basic Act on Artificial Intelligence,” October 8, 2025 — Executive Yuan approval date, MODA’s coordinating role, R&D exemption in the draft stage.
- Focus Taiwan, “AI Basic Act passed, tries to balance AI promotion with social welfare,” December 23, 2025 — corroborates the Legislative Yuan passage date.







