The Committee recognizes the government’s foundational role in advancing Taiwan’s leadership within the global technology ecosystem. To fully realize the administration’s focus on national resilience, there is a vital need for a unified digital governance roadmap that transcends fragmented, ministry-specific mandates. Establishing a coherent digital sovereignty framework is essential to facilitating the distributed architectures and global AI capabilities required for systemic operational resilience. Furthermore, formalizing mechanisms to ensure adherence to Intermediary Liability principles will translate abstract guidelines into the enforceable operational standards necessary to catalyze infrastructure investment and provide the legal certainty required for long-term digital growth and stability.
Developing transparent, standardized procedural frameworks for government data requests is critical to providing the principled oversight required for exercises of public authority that implicate constitutional privacy rights. Simultaneously, creating streamlined pathways for regulatory pilot programs will reduce administrative barriers and enable agile testing of frontier technologies to sustain continuous innovation. To maintain Taiwan’s competitive edge, we urge the establishment of cross-ministerial coordination mechanisms led by key authorities including the Ministry of Digital Affairs (MODA), National Communications Commission (NCC), Personal Data Protection Commission (PDPC), and National Development Council (NDC). By accelerating policy development for distributed AI architectures and empowering local enterprises to leverage global innovation, Taiwan can ensure that its regulatory environment remains predictable and robust. Collectively, these institutional reforms will preserve Taiwan’s democratic values while cementing its position as a secure, resilient, and innovation-driven hub.
Suggestion 1: Adopt a governance-based approach to digital sovereignty.
The Committee welcomes the government’s strong commitment to advancing artificial intelligence, digital services, and data-driven innovation across Taiwan’s economy. Distributed digital infrastructure, an interconnected mesh of computing, storage, and network resources deployed across multiple locations, has become central to this transformation. As Taiwan advances its digital sovereignty objectives, ensuring that critical workloads remain secure, resilient, and under appropriate governance is a shared priority. In an environment of rising geopolitical risk, where escalating tensions and the threat of kinetic conflict increasingly make digital infrastructure a direct target, architectures that distribute critical workloads across multiple regions offer greater continuity and resilience than those concentrated in a single location.
Yet in practice, sovereignty requirements have often been interpreted across public sector and regulated industries as necessitating that infrastructure, workloads, and data remain physically within Taiwan’s borders, even where no explicit legal mandate requires it. In some cases, this interpretation has led to distributed digital infrastructure and AI solutions being excluded from higher security tiers in procurement evaluations. Broadening this framework to recognize governance-based approaches — meaning policy, access controls, and oversight ensuring secure, compliant AI use — could unlock access to global knowledge networks, international datasets, and computing resources, while reducing costs and expanding Taiwan’s capacity to participate in the global digital economy.
Internationally, a growing number of governments have acknowledged that digital sovereignty and infrastructure resilience are complementary objectives, best achieved through governance frameworks rather than infrastructure location alone. Emerging policy approaches have sought to define clear national requirements for sensitive data and critical workloads, accept internationally accredited security certifications as credible evidence of compliance, and promote resilient architectures that ensure continuity and availability of critical services.
Recognizing Taiwan’s distinct geopolitical context, the Committee is committed to working with the government on models that maintain national control while enabling access to advanced digital and AI capabilities. Where agencies develop sovereign cloud frameworks independently, as seen with the “sovereign cloud” guidelines announced by the Ministry of Health and Welfare (MOHW) in January 2026, there is a risk of divergent definitions emerging across sectors. The Committee underscores the value of a coordinated whole-of-government approach to ensure consistency and clarity for all stakeholders, and respectfully offers the following recommendations:
1.1 Consider designating MODA as the coordinating agency for digital sovereignty interpretation. In this coordinating role as Taiwan’s central digital governance authority spanning cybersecurity, digital infrastructure, and platform governance, MODA could help align interpretations across ministries and sector regulators, establish common compliance frameworks and technical standards, and support an interministerial review process with a public feedback portal for industry input.
1.2 Adopt a digital-sovereignty-by-design approach. In advancing Taiwan’s digital sovereignty objectives, it is important to recognize that sovereignty is not limited to data location or infrastructure ownership alone. Sovereign-by-design approaches instead define sovereignty through effective control over data and operational decision-making, supported by robust governance and resilient architectures that are designed across on‑premises, public cloud, and hybrid‑cloud environments to ensure continuity, flexibility, and risk diversification. Such an approach allows governments to maintain jurisdictional authority and accountability while responsibly leveraging global innovation across cloud and AI technologies.
1.3 Encourage MODA’s Department of Digital Service to develop referential guidance on governance-based sovereignty. The Committee encourages MODA to consider issuing referential guidelines that help agencies recognize deployment models meeting sovereignty objectives across core domains such as data governance, cybersecurity, regulatory compliance, technological resilience, and digital infrastructure continuity, alongside cross-government education to support consistent interpretation across ministries and sector regulators.
1.4 Apply good regulatory practice (GRP) principles to sovereignty-related guidelines. The Committee encourages relevant regulators to apply GRP principles, including advance notice, public consulta-tion, and transparent feedback consideration, consistent with agreements reached under the U.S.-Taiwan Initiative on 21st-Century Trade.
Taiwan’s ambition to become a trusted center for next-generation AI development demands more than physical infrastructure. It requires access to the full AI technology stack, ranging from secure and scalable compute capacity to advanced models, high-quality data, and specialized services. Clear and predictable regulations that safeguard digital sovereignty while enabling integration with global capabilities are essential. A governance-based approach to digital sovereignty, grounded in operational accountability rather than physical boundaries, provides a more durable foundation for AI-driven growth.
Suggestion 2: Ensure adherence to internationally recognized intermediary liability principles by all government agencies.
The Committee acknowledges the limited but meaningful progress that has occurred in Taiwan’s approach to digital governance. The NCC’s deliberation and development of rule-making guidance that incorporates principles from our previous recommendations is a welcome step. Additionally, the MOHW’s enforcement guidelines on the Tobacco Hazards Prevention Act, while imperfect, demonstrate positive receptiveness to stakeholder concerns regarding platform liability.
However, these incremental improvements remain insufficient to address the fundamental challenge: the absence of a binding, government-wide mechanism ensuring that all agencies adhere to internationally recognized intermediary liability principles.
Our member companies have experienced significant disparities in regulatory awareness and practice across government agencies. While some ministries demonstrate an understanding of balanced digital governance, others continue to pursue approaches that conflict with international best practices and democratic norms. The lack of mandatory compliance mechanisms means that well-intentioned efforts, such as the preliminary discussions around rule-making principles currently underway at the NCC, risk becoming aspirational rather than operational standards.
This inconsistency creates legal uncertainty that discourages platform investment, regulatory fragmentation requiring platforms to navigate contradictory requirements, inadequate stakeholder engagement undermining multi-stakeholder governance, and potential conflicts with international commitments regarding freedom of expression.
The Committee urges the Executive Yuan to establish concrete institutional mechanisms ensuring consistent application of intermediary liability principles.
First, we urge the Executive Yuan to institutionalize a formal cross-ministerial review mechanism for all draft legislation, enforcement rules, and administrative measures affecting online intermediaries. Facilitated by the NCC and MODA, this mechanism should:
a.) Conduct principle-conformity assessments to ensure alignment with safe harbor standards, including opposition to general monitoring obligations and recognition of service diversity;
b.) Require transparent regulatory impact analysis addressing proportionality, innovation, cross-border trade, and freedom of expression; and
c.) Mandate structured stakeholder consultation to reinforce multi-stakeholder governance and regulatory legitimacy.
Second, to translate principle into practice, we recommend that the government develop concrete model laws or template provisions embodying the intermediary liability standards articulated in the NCC’s guidance. This effort should be facilitated and coordinated by the NCC to build upon, and not dilute, the substantial analytical groundwork already completed. By leveraging the NCC’s prior deliberations, Taiwan can efficiently convert high-level guidance into standardized legislative language, including model safe harbor clauses, notice-and-takedown procedures, Good Samaritan protections, and due-process safeguards.
Such model instruments would function as regulatory infrastructure to foster accelerated policy development, enhance predictability for enterprises, and ensure that emerging sectoral regulations remain anchored in coherent digital governance norms.
Taiwan has made measurable progress in articulating the right principles. The next phase should focus on institutionalization and implementation. By coupling centralized oversight with model legislative frameworks, Taiwan can embed consistency into its system, safeguard democratic values, and take a leading position as a trusted and innovation-forward digital economy in the region.
Suggestion 3: Adopt a whole-of-government framework for lawful and accountable government data requests.
The Committee remains concerned that Taiwan has not made substantive progress in addressing structural deficiencies in the government’s approach to requesting user data. Over the past year, administrative agencies have continued to issue broad and inconsistent demands for user information in the context of administrative investigations, often without clear procedural safeguards or harmonized standards.
The PDPC Preparatory Office has indicated that sector-specific laws prevail and that individual agencies retain autonomy in exercising their statutory powers. While we acknowledge the complexities of inter-agency governance, this position inadequately reflects the PDPC’s mandate as an independent supervisory authority responsible for safeguarding personal data and privacy rights.
Government requests for user data are exercises of state authority that directly involve the constitutional right to privacy and informational self-determination. As such, they warrant principled oversight and consistent implementation across sectors. International practice has shown that independent data protection authorities can align enforcement standards across government departments. Japan’s Personal Information Protection Commission, for example, works with sector regulators to align guidance and enforcement practices across industries and the public sector.
The Committee recommends the following:
3.1 Establish a cross-agency data request governance framework. The PDPC should lead the articulation of overarching principles governing all government requests for personal data, regardless of sector. These principles should reflect internationally recognized standards, necessity, proportionality, legality, transparency, accountability, and effective redress, consistent with international standard such as the OECD’s “Declaration on Government Access to Personal Data Held by Private Sector Entities.” Sectoral authorities may retain enforcement authority, but their practices should align with unified privacy guardrails applicable across government.
3.2 Introduce robust procedural safeguards and due-process mechanisms. Requests for user data, particularly content data and sensitive personal information, should be subject to clearly defined legal thresholds, including judicial authorization where appropriate. Service providers must have the ability to review and challenge overly broad or unlawful demands. Importantly, where notification would not undermine legitimate investigative purposes, data subjects should be informed by the requesting government agency. As the data request constitutes an act of state power, the responsibility for transparency and accountability to the affected individual should rest with the state. Data subjects should also have meaningful avenues to seek review or redress.
3.3 Eliminate mandatory retention of data when only for administrative convenience. Mandated retention of user data solely to facilitate potential future administrative access creates systemic cybersecurity and privacy risks. Data minimization should be the default principle. Any retention obligations must be narrowly tailored, demonstrably necessary, and subject to periodic review.
3.4 Institutionalize transparency and accountability mechanisms. Taiwan should establish a centralized reporting mechanism to document and categorize government data requests. Aggregated transparency reporting, covering the volume, legal basis, and outcomes of such requests, would strengthen public trust and align Taiwan with leading digital democracies.
3.5 Enhance technical and legal capacity across agencies. The PDPC should coordinate capacity-building initiatives to ensure that agencies understand the technical constraints, potential cross-border legal conflicts, and compliance risks faced by multinational providers.
A predictable, rights-respecting framework will reinforce Taiwan’s democratic governance, reduce regulatory fragmentation, and strengthen its competitiveness as a trusted digital economy.
Suggestion 4: Support streamlined and effective pilot-program deployment.
When an established business operating in Taiwan seeks to initiate a self-funded pilot program requiring temporary regulatory flexibility, engagement with the relevant government agency is a necessary first step. But the typical response is that no existing legal basis permits the proposed activity, or political appointees may cite political sensitivities or the absence of social consensus as grounds for deferral. The ultimate outcome is inability to proceed without explicit legislative approval.
From an industry perspective, the absence in Taiwan of an institutionalized mechanism for innovators to test and gather real-life data on the implementation of new technologies and models in a temporarily regulation-exempt environment makes the risk of “being the first” unacceptably high. When that cost is prohibitive, it is not only private sector resources and innovation capacity that are impacted. The technologies themselves, including those with potentially significant public benefit, will migrate to more receptive markets. The inability of companies and the government to engage in a good-faith mutually beneficial process for introducing promising technology is puts Taiwan, which should be known for its technology leadership, in an unfavorable light.
Taiwan’s highly cautious approach to public administration, reinforced by vibrant media scrutiny of government conduct and policies, creates a regulatory environment that is too rigid and costly for deployment of quick-launching pilot programs, stifling momentum in the digital economy and technology sectors. An institutionalized, clearly structured pilot pathway would enable the private sector, overcoming those obstacles to progress, to propose and execute pilot programs in partnership with government agencies, and without having to internalize the costs of political and administrative hurdles inherent to Taiwan.
The NDC is already the designated convener of inter-agency discussions (according to the Executive Yuan’s Circular No. 1072000064 of January 16, 2018), involving platform businesses and their associated service providers and users. To help fast-track digital transformation and AI-readiness to meet today’s societal needs, the content of this circular requires updating to reflect today’s innovation cycle involving platforms and non-platform businesses. The Committee urges the NDC to institute revisions in line with the following principles:
- Move beyond the current legal and policy coordination and actively facilitate pilot-program deployment, thereby helping to fast-track digital transformation and AI-readiness.
- Support technology pilot programs as a default position in the absence of material and imminent institutional blockers, such as human-rights violations or cybersecurity and national security threats.
- Set a maximum three-month review period for interagency deliberations convened by the NDC, with a further three-month implementation window from approval to launch.
- Require post-review documentation of failed applications, using the findings to identify problem areas in need of attention.
本委員會肯定政府在提升台灣全球科技地位上,扮演不可或缺的基礎角色。為落實「國家韌性」的施政重點,台灣極需制定一份統一的數位治理藍圖,以整合目前各部會因本位主義而碎片化的現況。
建立一致的數位主權框架,是實現分散式架構與全球 AI 協作的基礎,更是強化系統營運韌性的核心。此外,「數位中介者責任(Intermediary Liability)」原則法制化,能將抽象的指導方針轉化為明確的可執行標準;這不僅能帶動基礎建設投資,更能為數位經濟的長期穩定與成長,提供必要的法律確定性。
針對政府資料調取的需求,應制定透明且標準化的程序框架,以確保公權力的行使在涉及憲法隱私權時,受到必要的原則性監督。同時,政府應簡化法規試行計畫的申請流程,將有助於減少行政障礙,並為前瞻技術提供更靈活的測試空間,以維持創新動能。
為維持台灣的競爭優勢,本委員會強烈呼籲建立由關鍵主管機關領導的跨部會協調機制,成員應涵蓋數位發展部(MODA)、國家通訊傳播委員會(NCC)、個人資料保護委員會(PDPC)及國家發展委員會(NDC)。
透過加速推動分散式 AI 架構政策,並賦能本土企業接軌全球創新資源,台灣將能構建一個更具預測性且健全的法規環境。這些制度性改革將在維護台灣民主價值的同時,鞏固其作為安全、具韌性且以創新為導向之科技樞紐地位。
建議一:採納以治理為基礎的數位主權模式
委員會誠摯歡迎政府致力於推動人工智慧、數位服務以及資料驅動創新,以帶動台灣經濟轉型。分散式數位基礎設施,即部署於多個地點,由運算、儲存與網路資源構成的互連架構,已成為此轉型之核心。隨著台灣推進其數位主權目標,確保關鍵工作負載的安全、韌性並受到適當治理,是我們共同的首要目標。在地緣政治風險升溫、緊張局勢加劇及軍事衝突威脅日益增加的環境下,數位基礎設施已成為直接目標。相較於集中於單一地點的架構,將關鍵工作負載分散於多個區域的架構能提供更高的連續性與韌性。
然而在實務上,公部門與受監理產業對於主權要求的解讀,往往被簡化為基礎設施、工作負載與資料必須實體留存於台灣境內,即便法律並無明確強制要求。在某些案例中,這種解讀導致分散式數位基礎設施與 AI 解決方案,在採購評選時被排除在較高等級的安全等級之外。若能放寬此框架,轉而承認以治理為基礎的模式,意指透過政策、存取控制與監督來確保 AI 使用安全且合規,將有助於台灣接入全球知識網路、國際資料集與運算資源,在降低成本的同時,擴大台灣參與全球數位經濟的能力。
在國際上,越來越多國家的政府已意識到數位主權與基礎設施韌性是相輔相成的目標,且透過治理框架而非僅靠基礎設施的實體所在地,最能達成此目標。新興的政策趨勢尋求針對敏感資料與關鍵工作負載定義明確的國家要求,接受國際認可的安全認證作為合規的可靠證明,並推動能確保關鍵服務連續性與可用性的韌性架構。
考量到台灣獨特的地緣政治環境,委員會致力於與政府合作開發既能維持國家控制權,又能獲取先進數位與 AI 能力的模式。當各部會獨立開發主權雲框架時,例如衛福部於 2026 年 1 月發布的主權雲指引,各領域定義出現分歧的風險隨之增加。委員會強調採取全政府協同模式的重要性,以向所有利害關係人確保政策的一致性與清晰度,並謹此提出以下建議:
1.1 建請指派數位發展部作為數位主權解讀之協調機關
作為台灣負責資通安全、數位基礎設施及平台治理的中央數位治理權責機關,數位發展部可協助各部會與產業主管機關統一解讀,建立共同的合規框架與技術標準,並支持跨部會審查機制,同時透過公共政策參與納入產業意見。
1.2 採納原生主權設計模式
在推進台灣數位主權目標時,必須體認到主權不僅限於資料存放地點或基礎設施的所有權。原生主權設計模式透過對資料與營運決策的有效控制,並輔以穩健的治理與韌性架構來定義主權,這些架構的設計涵蓋本地部署、公有雲和混合雲環境,以確保業務連續性、靈活性和風險分散。此舉讓政府在維持司法管轄權與責任歸屬的同時,能負責任地使用雲端與 AI 技術的全球創新成果。
1.3 鼓勵數位發展部數位政府司制定治理基礎主權之參考指引
委員會鼓勵數位發展部考慮發布參考指引,協助各機關識別符合主權目標的部署模式,涵蓋資料治理、資通安全、法規合規、技術韌性及數位基礎設施服務不中斷等核心領域,並透過跨部會教育宣導,支持各部會與主管機關的一致性解讀。
1.4 將良好法規實務原則應用於主權相關指引
委員會鼓勵相關主管機關應用良好法規實務原則,包括提前公告、公眾諮詢以及透明的意見採納機制,以符合臺美 21 世紀貿易倡議達成的協議。
台灣欲成為可信賴的新世代 AI 發展中心,其野心不能僅止於物理性的基礎設施。這需要獲取完整的 AI 技術堆疊,從安全且具擴充性的運算能力,到先進模型、高品質資料以及專業化服務。建立清晰且可預測的法規,在守護數位主權的同時,確保能與全球能力接軌,至關重要。以營運責任而非物理邊界為基礎的數位主權治理模式,將為 AI 驅動的成長提供更穩固的根基。
建議二:確保所有政府機關皆遵循國際公認的數位中介者責任原則
本委員會肯定台灣在數位治理上,已取得雖然有限但具實質意義的進展。國家通訊傳播委員會(下稱通傳會)研議法規制訂相關方針時,已納入了本會過去建議的原則,這是令人樂見的一步。此外,衛生福利部就《菸害防制法》提出之執法應注意事項,雖仍有未臻完善之處,但已展現出政府願意正視利害關係人對平台責任的疑慮並給予積極回應。
然而,前述漸進式的改善仍不足以解決最根本的挑戰:目前尚缺乏一套具約束力、跨機關的機制,以確保所有機關皆遵循國際公認的數位中介者責任原則。
本會成員觀察到各政府機關就法規認知與實務上存在顯著差異。部分機關對平衡的數位治理已有相當理解,惟亦有機關仍採取與國際最佳實務及民主規範相牴觸之作為。由於欠缺具強制性的遵循機制,即便是立意良善的作為(例如通傳會現階段針對法規制定方針所展開的初步討論),仍可能成為僅供參考的願景,無從轉化為具操作性的規範標準。
此種法規不一致性產生以下後果:法律不確定性進而阻礙平台投資意願、管制破碎化使平台必須因應相互矛盾的規範要求、不充分之利害關係人參與而削弱多方利害關係人治理的成效,亦可能與我國在言論自由議題上的國際承諾相牴觸。
本委員會敦促行政院建立具體的制度化機制,確保數位中介者責任原則之一致適用。
首先,本委員會建議行政院針對所有涉及線上中介服務的法律草案、施行細則及行政措施,建立正式的跨部會審查機制;此機制應由通傳會與數位發展部協力推動,並達到以下功能:
- a) 進行原則符合性審查,確保受審查標的與安全港原則(safe harbor principle)一致、包括反對課予一般性監控義務,及承認數位服務模式的多樣性。
- b) 辦理透明的法規衝擊分析,將比例原則、創新發展、跨境貿易及言論自由保障等要素納入考量。
- c) 落實制度化之利害關係人諮詢程序,以強化多方利害關係人治理的精神,並確保管制之正當性。
其次,為促進原則具體落實,本委員會建議政府制定具體之模範草案或條文範本,體現通傳會《指引》中所闡明之中介者責任規範。此項工作宜由通傳會主導協調,以延續通傳會現有的紮實政策分析基礎,而非削弱其成果。透過運用通傳會先前的研議成果,台灣能有效將高層次的政策原則轉換成標準化的立法語言,包含安全港條文範本、通知後下架程序(notice-and-takedown process)、善意行為保障(Good Samaritan protection)以及正當程序保障等。
這些示範性工具將成為台灣基礎的法規建設,有助於加速政策形成、提升產業可預測性,並確保未來各類部門法規在發展過程中,持續依循一致、具制度性之數位治理原則。
台灣在建立正確原則上已取得顯著進展。下一階段重點應聚焦於如何將這些原則制度化並具體落實。透過集中化的監督機制,結合標準化立法框架之建構,臺灣能將法規一致性深化於體制、捍衛民主價值,並躍升為區域內備受信賴且具創新前瞻性的數位經濟領導者。
建議三:建立「全政府」框架,確保政府調取資料請求之合法性與可問責性
在改善政府調取使用者資料之制度性缺失方面,台灣仍未有實質進展;本委員會對此持續關切。過去一年來,各行政機關在辦理行政調查時,仍普遍提出範圍廣泛、標準不一的使用者資料調取要求,且多缺乏明確的程序保障與一致性的規範。
個人資料保護委員會籌備處曾指出,涉及資料調閱時各部門法優先適用之,而各機關自主行使其法定職權。本委員會理解跨機關治理的複雜性,但此立場未能充分反映個人資料保護委員會籌備處作為獨立監督機關,在保障個人資料與隱私權方面應有的統籌與監督角色。
政府向業者調取使用者資料,係行使國家高權而直接觸及憲法保障之隱私權與資訊自主權。因此相關作為應受一致且依循原則之監督,並一致落實於各事務領域。國際實務顯示,獨立個資保護機關仍可有效協調政府各部門的執法標準。例如日本個人情報保護委員會即與各主管機關合作,促進不同產業與公部門間指引與執行的一致性。
本委員會建議如下:
3.1 建立跨機關的資料調取治理架構
建議由個人資料保護委員會(籌備處)主導,訂定適用於所有政府機關的資料調取之基本原則,不因產業而有所差異。相關原則應符合國際通行標準,包括必要性、比例原則、合法性、透明性、問責性及有效的救濟途徑,並與 OECD《關於政府存取私營部門實體所持個人資料宣言》(Declaration on Government Access to Personal Data Held by Private Sector Entities) 等國際規範相一致。各領域主管機關依其權限執法,但其具體作為應遵循全政府一致的隱私保護機制。
3.2 引入完善的程序保障與正當法律程序機制
調取使用者資料,特別是通訊內容及敏感性個人資料,應設有明確界定的法律門檻,包含適當情況下經司法部門授權。服務提供者應有權審視並對過於廣泛或不合法的調取要求提出異議。此外,在不損及正當調查目的之前提下,應由提出調取請求之政府機關通知資料當事人。調取資料的政府機關應主動通知資料主體(當事人)。由於資料調取係國家行使公權力,對受影響個人之透明與問責義務應由國家承擔。此外,資料主體也應具備尋求審查或救濟的實質途徑。
3.3 避免僅基於行政便利而強制業者保留資料
若僅為方便未來可能的行政調查而強制業者保留使用者資料,將造成系統性的資安與隱私風險。資料最小化 (data minimization) 應是基本原則。任何資料保留義務皆應嚴密剪裁、具明確必要性,並定期檢討其合理性。
3.4 將透明度義務與問責機制制度化
台灣應建立集中的通報機制,記錄並分類政府調取資料的要求。發布彙整的透明度報告(涵蓋此類調取要求的數量、法源依據及結果)有助於強化公共信任,並使台灣與領先的數位民主國家接軌。
3.5 提升各機關的技術與法制量能
建議由個人資料保護委員會(籌備處)統籌推動培力計畫,確保各機關理解相關技術限制,及跨國服務提供者所面臨的潛在跨境法律衝突及法遵風險。
建立一套具可預測性且尊重基本權的制度框架,有助於強化台灣的民主治理、降低法規破碎的問題,並提升台灣作為可信賴數位經濟體的國際競爭力。
建議四:簡化試辦計畫機制,促進創新有效落實
法規彈性不足,是台灣創新試辦計畫推動的核心痛點。當已在台灣落地營運的企業,擬自行出資推動需於短期彈性監理機制下推行之試辦計畫,與主管機關的溝通是不可或缺的第一步。然而,實務上的回應往往是現行法規欠缺相關依據,或政務官以政治敏感、社會共識尚未形成為由,予以擱置,致使企業在未獲得明確立法授權前,難以推動創新。
從產業角度觀之,台灣目前缺乏制度化的監理沙盒機制,使創新者難以在暫時性監管豁免的環境中測試新技術與商業模式,並蒐集實證數據,「率先投入」的風險居高難下,企業難以承擔。當試錯成本高至難以承受,受衝擊的不僅限於產業資源配置與創新動能,亦可能使具重大公共利益潛力的技術,加速流向其他態度更為開放的市場。若企業與政府無法建立一套基於善意與互利的合作機制,共同推動新興技術的有序導入,對於本應以科技產業領導力著稱的台灣而言,實為形象與競爭力的雙重損失。
台灣公共行政與治理向來以審慎為原則,加上媒體對政府施政之高度關注,共同形塑出相對保守、行政成本高的監理環境,不利於試辦計畫的快速啟動,亦對數位經濟與科技產業之發展動能形成制約。若能建立制度化且程序明確的試辦計畫推動機制,將有助於業界突破現有障礙,與政府機關攜手合作提出並執行試辦計畫,同時免於自行承擔台灣政治與行政體制衍生的額外成本。
依據 2018 年 1 月 16 日行政院公布之「行政院所屬各機關因應平臺經濟發展法規調適參考原則」(院授發協字第 1072000064 號函),國家發展委員會已被指定為平台經濟及其相關提供者及使用者的召集機關。為因應當前社會需求,加速數位轉型與人工智慧應用發展,該函示內容實有更新之必要,將更符合當今平台及非平台業的創新周期。本委員會建請國家發展委員會依循以下原則推動修訂:
- 跳脫現行機制下,單純法規與政策協調之職能,積極促進試辦計畫落地與執行,加速數位轉型與人工智慧應用發展。
- 原則上應以支持技術試辦計畫為預設立場,在缺乏實質且迫切的體制性阻礙的情況下,例如人權侵害、資訊安全或國家安全疑慮,方得予以限制或擱置。
- 針對國家發展委員會召集之跨部會審查程序,設定最長三個月之審議期限;計畫獲准後,另設三個月的啟動執行時限。
- 對審查未獲通過之申請建立書面存檔機制紀錄,並據以檢視現行制度之問題癥結,作為後續調整之參考依據。
