Newsletter
MODA Establishes the Artificial Intelligence Risk Classification Framework
MODA Establishes the Artificial Intelligence Risk Classification Framework
Tseng, Keng-Ying/Cheng, Kai-Yao
On July 7, 2026, the Ministry of Digital Affairs ("MODA") released the "Artificial Intelligence Risk Classification Framework" (v1.0) (人工智慧風險分類框架, the "AI Risk Framework"). The AI Risk Framework was formulated by MODA pursuant to Article 16 of the Artificial Intelligence Basic Act (the "AI Basic Act"). Its main goal is to act as a common guideline and standard for AI risk governance among Taiwan's sector-specific competent authorities (目的事業主管機關, the "Competent Authorities"). Currently, it does not directly bind AI applications by non-government entities. Additionally, the AI Risk Framework does not cover military AI applications.
Each Competent Authority should follow the four-step operational process of "inventory AI application scenarios → identify risks → assess risks → respond to risks" to conduct the risk assessment and response for AI applications. Furthermore, it should develop management regulations tailored to its regulatory sector.
1. Inventory of AI application scenarios (盤點應用情境)
Each Competent Authority should gather and organize background information on current and planned AI application scenarios within its regulatory scope. This includes details on the involved AI technologies, relevant stakeholders, and applicable fields or industries, serving as groundwork for identifying, assessing, and responding to AI application risks.
2. Identify risks (識別風險)
Each Competent Authority should assess risks using the "AI Risk Types Table" (AI風險類型表) included in the AI Risk Framework. This table groups 20 recognized subtypes of AI application risks into three main categories: (1) technical or design flaws inherent to the AI system (AI系統本身之技術設計缺陷); (2) issues relating to post-deployment operations and human-machine interactions (部署後操作及人機互動問題); and (3) wider social, structural, and environmental effects (社會結構與環境衝擊). MODA will conduct periodic reviews and updates of this table.
3. Assess risks (評估風險)
When evaluating risks linked to AI applications, each Competent Authority must objectively assess the inherent risk. It is sufficient to consider the potential for harm; actual damage is not required, and the mitigating effects of existing laws, administrative measures, or technical means should not be considered. If an AI scenario could cause serious harm to national security, fundamental rights, safety of life, property, social order, or the environment, it should be classified as a high-risk AI application according to Article 17, Paragraph 1 of the AI Basic Act. For guidance, Appendix 2 of the AI Risk Framework includes a "Serious Harm Examples Table" (造成嚴重危害例示表).
4. Respond to risks (應對風險)
Each Competent Authority should examine whether existing laws and administrative measures are sufficient to address the identified risks and, for risks that are inadequately covered or not yet subject to any measure, should plan appropriate measures in accordance with the principle of proportionality. Additionally, it should periodically evaluate, review, and revise the relevant laws and regulations.
Our Digital Industry, Communications, and Personal Data Protection team is closely monitoring developments in the AI Basic Act, the AI Risk Framework, and related administrative regulations. Should your company have any questions regarding the relevant regulations, please contact our team.