The Committee commends the government for its recent efforts to advance Taiwan’s technology policy agenda. In 2025, the government announced the “Ten Major AI Infrastructure Projects” initiative to strengthen Taiwan’s long‑term competitiveness and technological leadership, introduced the AI Basic Act as the foundation for Taiwan’s responsible AI development, and marked the beginning of a more structured national investment in emerging technologies such as quantum computing. In addition, the Committee underscores that the resilience of Taiwan’s digital foundations is a core national imperative central to security, economic stability, and public trust.
To translate these ambitions into durable outcomes, international collaboration and sustained public–private partnership will be critical enablers. Whether in building resilience‑by‑design digital infrastructure across critical sectors, advancing responsible AI deployment, or preparing for the development of an ecosystem for emerging technologies such as quantum computing, close cooperation with trusted global partners and continuous engagement with industry are essential to accessing expertise, sharing best practices, and scaling innovation. In this context, the Committee emphasizes the adoption of risk‑based regulatory approaches that focus on actual security, privacy, and operational risks rather than rigid or technology‑specific mandates. Such frameworks can better accommodate technological complexity, ensure consistency between policy intent and implementation, and support innovation while strengthening Taiwan’s long‑term resilience and competitiveness.
Suggestion 1: Build a resilience-by-design digital infrastructure across government, financial services, healthcare, and critical infrastructure providers.
To safeguard national security, economic stability, and the continuity of essential public services, the Committee recommends that the Taiwan government adopt a resilience‑by‑design approach, in which continuity, recoverability, and adaptability are embedded as core design principles from the outset, in the modernization of national digital infrastructure, particularly for systems supporting critical functions across government, financial services, and healthcare. As digital technologies now underpin nearly all essential services, from social welfare administration and interbank settlement to healthcare delivery and national security operations, the resilience of underlying IT systems has become integral to public trust and societal stability. Any disruption to these systems, whether caused by cyber incidents, geopolitical shocks, or infrastructure failures, could result in far‑reaching economic, social, and reputational consequences.
While Taiwan has made significant progress in digitalization and IT modernization over the past decade, the increasing complexity and interdependency of digital systems, combined with a rapidly evolving risk environment, demand a fundamental shift in approach. The Committee believes that ensuring continuity under extreme and prolonged disruptions requires moving beyond incremental upgrades toward a resilience‑by‑design architecture. To achieve this outcome at scale, the Committee recommends a coordinated public‑private partnership model, supported by cross‑ministerial collaboration and dedicated budget allocation, to strengthen Taiwan’s national resilience architecture in a systematic and sustainable manner.
1.1 Foster cross‑ministerial resilience‑by‑design beyond data backup. Over the past few years, the Taiwan government has made important progress in establishing data backup mechanisms for systems supporting essential public services. Through targeted policies and investments, backup arrangements for key civilian and critical systems have been largely put in place, strengthening baseline preparedness and data protection.
However, experience has shown that data backup alone does not equal true resilience. In extreme scenarios, such as largescale cyber incidents, prolonged infrastructure disruptions, or geopolitical shocks, national resilience depends on the availability of backed-up data and the ability of core systems to remain operational.
From this perspective, the Committee recommends that the government elevate preparedness efforts beyond data backup and adopt a resilience‑by‑design framework, coordinated at the cross‑ministerial level. Given that critical digital systems span multiple authorities across government administration, financial services, healthcare delivery, and national security, resilience planning must be aligned across ministries to avoid fragmentation and systemic vulnerabilities.
1.2 Advance implementation and operational exercises through public‑private engagement. From the perspectives of government agencies, financial institutions, and healthcare providers, building resilience‑by‑design requires not only policy direction, but also practical implementation readiness. These sectors operate highly complex, mission‑critical systems with limited tolerance for disruption, while facing distinct operational, regulatory, and security requirements. To address these challenges effectively, the Committee recommends that the government initiate structured dialogue with trusted technology partners that have practical experience supporting resilience implementation and largescale continuity planning in other countries.
Such engagement should focus on translating resilience objectives into deployable architectures, operational models, and governance frameworks, rather than remaining at the conceptual or advisory level. International experience demonstrates that resilience cannot be validated solely through design reviews or documentation; it must be tested through implementation, simulation, and regular operational exercises. The Committee therefore encourages the government to work with experienced partners to support sector‑specific planning, technical validation, and the design of realistic stress scenarios tailored to public administration, financial services, and healthcare systems.
To support implementation, the Committee recommends incorporating joint drills, tabletop exercises, and cross‑sector simulations into national resilience planning. These exercises can help identify hidden dependencies, clarify decision‑making authorities, and strengthen coordination across agencies and critical institutions before crises occur, thereby shaping clear operational playbooks and ensuring that required resources are effectively allocated and ready to be mobilized. By embedding implementation and rehearsal into policy execution, Taiwan can move beyond theoretical preparedness and build confidence in the real‑world operability of its national digital resilience architecture.
Suggestion 2: Modernize Taiwan’s privacy framework through risk-based and globally aligned regulations.
The Committee commends the Preparatory Office of the Personal Data Protection Commission (PDPC) for the 2026 draft amendments to the “Regulations Regarding the Security Maintenance and Administration of Personal Information Files in Digital Economy Industries” for implementation of the Personal Data Protection Act (PDPA). However, the current drafts introduce rigid mandates and quantitative thresholds that may hinder innovation and increase compliance costs without proportionally enhancing privacy protection. To align with international standards such as the EU GDPR, we urge revision of the Enforcement Rules along the following lines:
2.1 Clearly define Business Contact Information (BCI) and exclude it from personal data protection. Establish a formal definition for BCI, which is information used solely for professional contact purposes (such as name, title, business address, and email). Consistent with global trends, BCI should be subject to streamlined processing requirements to facilitate efficient commercial operations while maintaining appropriate transparency.
2.2 Adopt a risk-based “harm threshold” for breach notifications. Notification obligations should trigger only when an incident poses a real risk of harm to individuals’ rights and freedoms. Furthermore, the 72-hour reporting window should commence from the moment a breach is reasonably confirmed with sufficient detail to provide meaningful notification, rather than upon initial awareness, to ensure notifications are accurate, complete, and actionable.
2.3 Shift from quantitative to risk-based “high-risk” definitions. Instead of relying solely on quantitative metrics such as “data volume” (for example, 10,000 entries) or “entity size,” the PDPC should define “High-Risk Non-Government Agencies” based on the nature and context of their processing activities, such as processing of sensitive data categories, systematic largescale profiling, or automated decision-making with significant effects on individuals.
2.4 Ensure technology neutrality and outcome-based security measures. Regulations should avoid prescriptive technical requirements, such as specific “password complexity rules” or mandatory “five-year record-retention periods,” which risk becoming obsolete as technology evolves. Instead, regulations should remain technology-neutral and outcome-based, allowing organizations to implement security measures appropriate to the risk, including modern controls such as multi-factor authentication, encryption, and adaptive authentication mechanisms.
2.5 Clarify the controller-processor accountability framework. Clearly distinguish between Data Controllers (entities determining purposes and means of processing) and Data Processors (entities processing on behalf of Controllers). Primary accountability for breach notifications and regulatory compliance should rest with the Controller. Processors should be required to notify the Controller promptly upon becoming aware of a breach and provide necessary assistance to enable the Controller to meet its obligations.
2.6 Establish an adequate transition period. To allow organizations to adjust internal policies, conduct personnel training, update technical systems, and implement necessary organizational changes, we recommend that the government provide a minimum 12-month transition period following the promulgation of new subsidiary regulations.
Suggestion 3: Align public ICT procurement with risk‑ based cybersecurity management.
The Committee welcomes Taiwan’s efforts to strengthen information and communications technology (ICT) security through the 2025 amendment to the Cybersecurity Management Act and the Regulations for the Review of Products Harmful to National Cyber Security issued by the Ministry of Digital Affairs (MODA).
However, broad country-of-origin (COO)-based restrictions continue to be applied by government agencies in public procurements without specified technical standards or rationale.
Moreover, inconsistencies remain between the legal framework established by the Cybersecurity Management Act (CSMA) and the tendering and bidding templates issued by the Public Construction Commission (PCC), which continue to allow explicit exclusions based on country of manufacture. In an era of software‑defined hardware and globally distributed production, manufacturing location alone is increasingly an unreliable factor in assessing cybersecurity risk, as it may not reflect who controls a product’s code, updates, or data flows.
MODA’s regulation deliberately adopts a risk‑based, reviewable approach, recognizing that modern ICT products are developed, assembled, and maintained across multiple jurisdictions. Aligning PCC procurement guidance with this entity‑based framework would reduce uncertainty for procuring agencies, improve consistency across government practice, and better reflect the intent of the CSMA.
3.1 Focus on risk-based regulatory approach. The Committee encourages the Taiwan government, including MODA and PCC, to adopt clearer and more risk‑based cybersecurity standards for ICT products and components, focusing on technical risk profiles rather than applying broad COO-based restrictions.
3.2 Harmonize PCC model contracts with the CSMA framework. This Committee encourages harmonizing PCC’s procurement guidance with MODA’s entity‑based approach (that is, banning Chinese brands, not made-in-China products or components) and remove COO-based procurement biases in model contracts. Rather than allowing blanket exclusion of products made in specific country or region, the PCC model contracts should replace that with language in line with the “Regulations for the Review of Products Harmful to National Cyber Security.”
3.3 Adhere to good regulatory practices (GRP) in the consultation process. We welcome the Taiwan government’s sustained, structured dialogue with industry associations. The Committee recommends fully implementing a 60‑day public consultation period for any important law amendments and regulatory revisions to enable meaningful industry input.
Suggestion 4: Foster Taiwan’s quantum ecosystem through trusted international partnerships and strengthened national preparedness.
Quantum computing is rapidly approaching a critical inflection point: quantum advantage, the moment when quantum systems outperform classical computing on targeted, high value tasks. Recent evidence suggests that quantum advantage could emerge as early as this year. The Committee welcomes the recent launch of Taiwan’s Phase II Five‑Year National Quantum Strategy (2027-2031), which reflects many of the recommendations put forward in AmCham’s 2025 White Paper. The Phase II framework demonstrates the government’s commitment to advancing quantum hardware, integration with high‑performance computing, and national research infrastructure, laying an important foundation for Taiwan’s long‑term quantum competitiveness.
While continued investment in quantum systems remains essential, the Committee recommends that the Taiwan government also put greater effort into accelerating quantum-enabled innovation and promoting research on software algorithms and application-development across priority domains, fostering the quantum ecosystem aligned with Taiwan’s scientific and economic goals. This innovation also needs to be underpinned by a strategic, multi-year transformation toward quantum-safe cryptography and “crypto-agility” to ensure that Taiwan’s digital ecosystem remains resilient against the systemic risks posed by the quantum era.
4.1 Strengthen international collaboration as a core pillar of Taiwan’s Phase II five-year quantum strategy, focusing on deeper engagement on software and applications. As quantum computing moves closer to practical deployment, international experience increasingly demonstrates that the competitiveness of a national quantum program is shaped by the strength of the surrounding ecosystem. Quantum advantage does not emerge from hardware alone; it is realized through the interaction of hardware, software, algorithms, talent, and application‑driven use cases across priority domains.
Quantum networking capabilities are also needed for interconnecting diverse quantum platforms and accelerating the path to practical utility. Countries that are leading in quantum development are therefore putting their focus on ecosystem building, linking research institutions, industry, and users to translate quantum capabilities into real‑world impact.
For Taiwan, this ecosystem‑centric approach is particularly important. While Taiwan’s strengths in hardware, semiconductor, and advanced manufacturing provide a solid foundation, quantum‑enabled innovation ultimately depends on software, algorithms, and domain expertise that determine how quantum systems are used. A robust ecosystem will enable quantum infrastructure to be effectively utilized and translated beyond research environments into practical, real‑world applications.
The Committee therefore recommends that international collaboration be positioned as a core pillar of Taiwan’s Phase II quantum strategy, especially in areas related to software, algorithms, and application development. Quantum ecosystems are inherently global, and meaningful participation in the international quantum community can help Taiwan rapidly develop quantum talent, accelerate scientific discovery, and strengthen its position within the regional quantum landscape. International engagement must prioritize alignment with globally recognized standards and certification regimes to ensure seamless interoperability and strengthen the collective resilience of Taiwan’s digital ecosystem.
4.2 Incentivize international partners that establish and expand quantum ecosystems linked to Taiwan. The Committee also encourages the government to incentivize international partners that establish and expand quantum ecosystems linked to Taiwan. Such programs could support collaborative projects that bring together international partners, domestic industry, and research institutions, helping to accelerate ecosystem formation while enabling talent development through hands-on collaboration and skill transfer.
4.3 Support domestic industry players and emerging startups to develop quantum applications. Alongside these efforts, the Committee recommends that the government establish targeted incentives to encourage domestic industry players and emerging startups to invest in quantum software, algorithms, and application development. While international collaboration is essential to accelerate ecosystem formation, the long‑term sustainability of Taiwan’s quantum ecosystem will depend on the active participation of domestic companies that are willing to build, apply, and scale quantum‑enabled solutions within Taiwan.
4.4 Strengthen Taiwan’s quantum‑safe preparedness through a unified national strategy. As quantum computing continues to advance, one of its long‑term risks lies in the potential to compromise existing encryption standards. Given that quantum security spans technology development, cybersecurity policy, economic resilience, and national defense, the Committee urges the Taiwan government to establish a unified, cross‑agency task force to drive coordinated planning, implementation, and oversight. This task force should bring together relevant authorities responsible for digital affairs, cybersecurity, financial regulation, and national security to ensure shared accountability and coherent policy execution.
The Committee also encourages the government to incorporate quantum‑safe standards as a requirement in the planning and deployment of IT systems supporting critical infrastructure. At the same time, strengthened public‑private collaboration will be essential to align policy objectives with technical implementation and support effective execution of Taiwan’s national quantum‑safe strategy. Implementation of Taiwan’s quantum-safe migration should follow a structured phasing model, beginning with “no-regret” actions such as cryptographic asset discovery, followed by controlled pilot programs and the eventual full-scale migration of the most critical business functions, systems, and information assets.
Quantum-safe governance needs to be anchored at companies’ executive and board levels to establish clear authority, provide funding alignment, and sustained organizational commitment. This migration should not be viewed as a standalone technical upgrade, but rather as a strategic transformation that modernizes legacy security models and enhances overall digital trust.
Suggestion 5: Advance AI policy through continued public-private collaboration.
The Committee thanks MODA and the National Development Council for providing the technology industry with opportunities to contribute to the development of the AI Basic Act and its risk classification framework. Related supporting measures remain under deliberation, including MODA’s risk framework, sector guidelines to be implemented by the respective competent authorities, tools or methods to be adopted for AI risk assessment and evaluation, and revisions to existing AI guidelines governed by respective competent authorities, such as the “Reference Guidelines for the Use of Generative AI by the Executive Yuan and Its Subordinate Agencies (Institutions).” We therefore urge continued public-private collaboration to gather industry input to enable technology providers to share industry insights and international governance developments. Such collaboration would drive innovation, promote responsible AI governance among government agencies, and help Taiwan maintain and enhance its global competitiveness.
本委員會肯定政府近期在推動台灣科技政策議程方面所展現的積極作為。2025 年,政府宣布推動「AI 新十大建設」,以強化台灣長期競爭力與科技領導地位;同時提出《人工智慧基本法》,作為台灣發展負責任 AI 的制度基石,並正式對量子運算等新興科技展開更加制度化、具前瞻性的國家級投資布局。此外,本委員會強調,數位基礎架構的韌性已成為攸關國家安全、經濟穩定與公共信任的核心國家要務。
為將上述政策願景轉化為可長可久的實質成果,國際合作與持續深化的公私協力將是不可或缺的關鍵。無論是在關鍵產業中打造「以韌性為設計核心(resilience‑by‑design)」的數位基礎建設、推動負責任的 AI 應用落地,或是為量子運算等新興科技培育完整生態系,皆有賴與可信賴的國際夥伴密切合作,透過與產業持續對話,以有效取得關鍵專業、交流最佳實務,並加速創新規模化。基於此,本委員會強調政府採取以風險為依歸的監理途徑(risk-based regulatory approach),聚焦於實際的資安、隱私與營運風險,而非僵化或特定技術導向的規範要求。此類監理架構更能回應科技發展的高度複雜性,確保政策制定與實際執行之間的一致性,並在強化台灣長期韌性與競爭力的同時,持續支持創新發展。
建議一:於政府、金融、醫療及關鍵基礎設施部門建構「以韌性為設計核心」的數位基礎架構
為確保國家安全、經濟穩定及關鍵公共服務之持續運作,本委員會建議政府在推動國家數位基礎建設現代化過程中,採取「以韌性為設計核心(resilience‑by‑design)」的整體策略,並自規劃初期即將持續運作能力、可復原性與應變力納入核心設計原則,特別適用於支撐政府運作、金融服務及醫療體系等核心關鍵功能之資訊系統。
當前,數位科技已成為幾乎所有關鍵公共服務的基石,涵蓋社會福利行政、跨行清算、醫療照護服務,乃至於國家安全相關作業等。其底層資訊系統的韌性,已直接關係到公共信任與社會整體穩定。任何系統中斷,無論源於資安事件、地緣政治衝擊或基礎設施故障,皆可能引發深遠的經濟、社會及聲譽層面的連鎖影響。
儘管台灣於過去十年間在數位化與資訊系統現代化方面已取得顯著進展,然隨著數位系統的架構日益複雜、相互依賴性持續提高,加上風險環境快速演變,現行做法已難以因應未來挑戰。本委員會認為,若要在極端且長時間中斷的情境下確保系統持續運作,有必要從根本調整思維,轉向以韌性為核心的整體架構設計。
為在國家層級有效推動此一轉型,本委員會建議政府採取協調一致的公私夥伴合作模式,結合跨部會協作機制與專責預算配置,以系統性且可長可久的方式,強化台灣的整體國家數位韌性架構。
1.1 推動超越資料備援的跨部會「以韌性為設計核心」治理
近年來,政府在為支撐關鍵公共服務之資訊系統建立資料備援機制方面,已取得重要進展。透過政策規劃與資源投入,政府已大致完成對主要民生與關鍵系統的資料備份,強化了基礎的準備程度與資料保護水準。
然而,實務經驗顯示,單純的資料備份並不等同於真正的系統韌性。在大規模資安事件、長時間基礎設施中斷,或地緣政治衝擊等極端情境下,國家整體韌性不僅取決於資料是否備份,更取決於核心系統是否能在干擾情況下持續運作,或於可接受時間內迅速恢復關鍵功能。
基於上述考量,本委員會建議政府將整備重點由資料備援,提升至跨部會協調推動的「以韌性為設計核心」整體架構。尤其核心關鍵系統橫跨政府行政、金融服務、醫療體系及國家安全等多個權責機關,相關韌性規劃與執行有必要在部會間加以對齊與整合,以避免政策碎裂與系統性脆弱點的產生。
1.2 透過公私協作,推進落實執行與實務演練
無論從政府機關、金融機構或醫療服務提供者的角度而言,建構「以韌性為設計核心」的能力,皆不僅止於政策方向的宣示,更關乎實際執行與操作層面的到位。上述部門普遍運作高度複雜的關鍵業務系統,對服務中斷的容忍度極低,同時需面對不同的營運、監理與資安要求。為有效回應此一挑戰,本委員會建議政府主動與具備國際實務經驗、並曾協助其他國家推動大規模韌性建置與持續運作規劃的可信賴科技夥伴,展開結構化且聚焦的對話。
相關公私協作應著重於將韌性政策目標,具體轉化為可部署的系統架構、營運模式與治理機制,而非停留在概念性或諮詢層次。國際經驗顯示,系統韌性無法僅透過設計審查或書面文件加以驗證,而必須藉由實際導入、情境模擬及定期的操作演練加以測試。因此,本委員會鼓勵政府與具備實戰經驗的夥伴合作,支持各部門進行具體規劃、技術驗證,並設計符合政府行政、金融服務與醫療體系特性的真實壓力測試情境。
為進一步支援政策落實,本委員會建議將聯合演練、桌上推演(tabletop exercises)及跨部門情境模擬,正式納入國家數位韌性規劃體系。透過此類演練,可及早辨識潛在的隱性依賴關係,釐清決策權責與通報流程,並在危機發生前強化機關與關鍵機構間的協調與應變能力,進而形成清楚可行的操作手冊,並確保相關資源得以及時配置與動員。藉由將執行與演練納入政策推動核心,台灣得以超越理論層次的整備,實質建立對國家數位韌性架構可運作性的信心。
建議二:透過以風險導向且與國際接軌之法規,推動臺灣隱私保護框架現代化
委員會肯定個人資料保護委員會(PDPC)籌備處針對《個人資料保護法》(下稱個資法)施行所提出之2026年《數位經濟相關產業個人資料檔案安全維護管理辦法》修正草案。然而,現行草案引入了僵化的強制規定與量化門檻,可能阻礙創新並增加合規成本,卻未能相應提升隱私保護水準。為與歐盟《一般資料保護規則》(GDPR)等國際標準接軌,我們敦促依以下方向修訂施行細則:
2.1 明確定義商業聯絡資訊(BCI)並將其排除於個人資料保護範圍之外
應建立商業聯絡資訊(BCI)之正式定義,即僅用於專業聯繫目的之資訊(如姓名、職稱、公司地址及電子郵件)。與全球趨勢一致,商業聯絡資訊應適用簡化之處理要求,以促進商業高效運作,同時維持適當之透明度。
2.2 採用以風險導向之「損害門檻」作為資料外洩通報標準
通報義務應僅在事件對當事人權利與自由構成實質損害風險時方予觸發。此外,72小時通報期效應自資料外洩經合理確認且具備足夠細節以提供有意義通知之時起算,而非自初步知悉時起算,以確保通報內容準確、完整且具可行性。
2.3 從量化標準轉向以風險導向之「高風險」定義
個人資料保護委員會不應僅依賴「資料量」(例如一萬筆)或「機構規模」等量化指標,而應根據處理活動之性質與情境來定義「高風險非公務機關」,例如處理特種個人資料類別、系統性大規模剖析,或對個人產生重大影響之自動化決策。
2.4 確保技術中立性,落實以成果為導向之安全措施
法規應避免規範性之技術要求,例如特定的「密碼複雜度規則」或強制性的「五年紀錄保存期限」,此類規定隨技術演進恐將過時。法規應維持技術中立與以成果為導向,允許組織依風險程度實施適當之安全措施,包括多因素驗證、加密及自適應驗證機制等現代化控制措施。
2.5 釐清資料控管者與資料處理者之責任歸屬架構
應明確區分資料控制者(Data Controller,決定處理目的與方式者)與資料處理者(Data Processor,代表控制者進行處理資料者)。資料外洩通報及法規遵循之主要責任應由資料控管者承擔。資料處理者應於知悉資料外洩時及時通知資料控管者,並提供必要協助,使資料控管者得以履行其義務。
2.6 設定充足之法規過渡期
為使組織得以調整內部政策、進行人員培訓、更新技術系統及實施必要之組織變革,我們建議政府於新子法公布後,提供至少十二個月之緩衝期。
建議三:政府資通訊(ICT)產品採購應符合以風險為基礎的資安管理原則
本委員會肯定臺灣透過 2025 年《資通安全管理法》(CSMA)的修正,以及數位發展部所發布之《危害國家資通安全產品審查辦法》,持續強化資通訊產品安全的努力。
然而,目前政府機關在公共採購中,仍普遍採用以原產地(Country of Origin, COO)為基礎的廣泛限制,且多未明確說明相關技術標準或實質風險判斷依據。
此外,《資通安全管理法》所建立的法律架構,與公共工程委員會(PCC)發布之招標與投標範本之間,仍存在不一致之處;後者仍容許以原產地別為由,明文排除特定產品。在軟體定義硬體及全球分工生產已成常態的情況下,單以製造地點作為資安風險判斷依據,已愈來愈不可靠,因其往往無法反映產品之軟體控制權、更新機制或資料流向的實際掌控者。
數位發展部所制定之子法,係刻意採納可審查、以風險為導向的制度設計,並明確認知現代 ICT 產品係於多個司法管轄區進行研發、組裝與維運。若能使公共工程委員會的採購指引與此一「以實體(entity)為基礎」的法律架構相銜接,將有助於降低採購機關的不確定性、提升政府整體實務的一致性,並更忠實反映《資通安全管理法》的立法精神。
3.1 聚焦以風險為基礎的監管方式
本委員會建議臺灣政府,包括數位發展部與公共工程委員會,採行更清楚且以風險為核心的資安標準,針對 ICT 產品與零組件,依其技術風險特性進行評估,而非概括適用以原產地為基礎的限制措施。
3.2 公共工程委員會招標範本應與《資通安全管理法》架構一致
本委員會建議,公共工程委員會之採購指引應與數位發展部採行的「以實體為基礎」之審查方式相互銜接 – 例如:禁止大陸廠牌(Chinese brands),而非禁止原產地為大陸地區(made in China)的產品或零組件 – 並於投標範本中移除以原產地為導向的採購偏誤。與其允許全面性排除來自特定國家或地區製造之產品,公共工程委員會的投標範本應改採與《危害國家資通安全產品審查辦法》一致之表述與審查原則。
3.3 在意見徵詢程序中落實良好法制作業(GRP)
本委員會肯定臺灣政府長期以來與產業公協會維持持續且制度化的對話機制。並建議凡屬重大法律修訂及法規調整,應全面落實至少 60 天的公開意見徵詢,以確保產業能夠提出具實質意義的意見。
建議四:透過可信賴的國際夥伴關係與強化國家整備,培育台灣的量子科技生態系
量子運算正快速邁向關鍵的轉折點——「量子優勢(quantum advantage)」,亦即量子系統在特定高價值任務上超越傳統電腦運算能力。近期跡象顯示,量子優勢可能最快於今年內逐步浮現。本委員會歡迎政府近期正式啟動的「第二期國家量子科技五年發展策略(2027–2031 年)」,該策略內容反映了 AmCham 於 2025 年白皮書中所提出的多項建議。第二期策略展現政府推動量子硬體技術、強化與高效能運算(HPC)的整合,以及建構國家級研究基礎設施的明確承諾,為台灣長期的量子競爭力奠定重要基礎。
儘管持續投入與投資量子系統仍至關重要,但委員會建議台灣政府也應加強力道,加速推動以量子為基礎的創新,並促進重點領域的軟體演算法及應用開發研究,從而培育出與台灣科學及經濟目標相契合的量子生態系。
此外,上述創新發展亦須結合具前瞻性的國家整備策略,包括推動為期多年的量子安全加密(quantum‑safe cryptography)轉型,以及建立「加密敏捷性(crypto‑agility)」能力,從而確保台灣的數位生態系統能夠抵禦量子時代所帶來的系統性風險。
4.1 將強化國際合作做為第二期國家量子五年策略的核心支柱,並聚焦於軟體與應用層面的深化合作
隨著量子運算逐步邁向實際部署階段,國際經驗日益顯示,國家量子計畫的競爭力,關鍵取決於其周邊生態系的成熟度。量子優勢並非僅由硬體所驅動,而是透過硬體、軟體、演算法、人才及應用導向的使用場景,在優先領域中相互作用後方能實現。
此外,量子網路能力亦為不可或缺,其有助於串聯不同的量子平台,並加速量子技術邁向實用化的進程。因此,在量子發展領域領先的國家,已將重點放在生態系建構上,透過連結研究機構、產業與使用端,將量子能力轉化為實際應用效益。對台灣而言,此一以生態系為核心的發展途徑尤為重要。儘管台灣在硬體、半導體及先進製造方面具備堅實基礎,量子賦能創新最終仍高度仰賴於軟體、演算法及領域專業,這些要素將決定量子系統的實際使用方式。健全的生態系將有助於量子基礎設施被有效運用,並促使其自研究環境延伸至具體可行的實務應用。
基於上述考量,本委員會建議將國際合作定位為台灣第二期國家量子策略的核心支柱,特別是在軟體、演算法及應用開發相關領域。量子生態系本質上具有高度全球化特性,實質參與國際量子社群,將有助於台灣快速培育量子人才、加速科學探索,並強化台灣在區域量子發展版圖中的定位。相關國際接軌亦應以與全球通行的標準與認證制度對齊為優先,以確保系統間的無縫互通,並強化台灣數位生態系的整體韌性。
4.2 提供誘因鼓勵國際夥伴在台建立及擴大量子生態系
本委員會亦建議政府針對在台建立及擴大量子生態系的國際夥伴,設計相應的誘因機制。相關方案可支持國際夥伴、國內產業及研究機構共同參與之合作計畫,在加速生態系形成的同時,透過實際合作與技能移轉,促進量子人才的培育與累積。
4.3 支持國內產業與新創發展量子應用
在前述措施的基礎上,本委員會建議政府同步建立機制,鼓勵國內產業及新興新創投入量子軟體、演算法及應用開發。儘管國際合作對於加速生態系建構至關重要,台灣量子生態系的長期永續發展,仍仰賴國內企業的積極參與,特別是願意在台灣落地建構、實際應用並規模化量子賦能解決方案的業者。
4.4 透過一致性的國家策略強化台灣在量子安全方面的準備
隨著量子運算持續發展,其長期風險之一在於可能對現行加密標準造成衝擊。鑒於量子安全議題橫跨技術發展、資安政策、經濟韌性及國家防衛等多個面向,本委員會呼籲政府成立統一且跨機關的專責工作小組,負責協調規劃、執行及監督相關政策作為。該工作小組應整合數位治理、資安、金融監理及國家安全等權責機關,以確保責任共擔及政策執行的一致性。
本委員會亦鼓勵政府在規劃與部署支撐關鍵基礎設施之資訊系統時,將量子安全相關標準納入必要條件。同時,強化公私合作將是確保政策目標與技術落實相互對齊、並有效推動國家量子安全策略的關鍵。台灣的量子安全轉型宜採取具結構性的分階段推動模式,初期可先行落實「無後悔作為(no‑regret actions)」,例如加密資產盤點,其後逐步推動受控的試點計畫,最終完成對最具關鍵性的業務功能、系統與資訊資產之全面遷移。
量子安全治理亦須在企業的高階管理層與董事會層級加以落實,以確保決策權責、資源配置及長期組織承諾到位。此一轉型不應被視為單一的技術升級,而應被理解為一項戰略性轉型工程,用以現代化既有安全架構,並全面提升數位信任基礎。
建議五: 透過持續的公私協力,推進人工智慧政策
本委員會感謝數位發展部及國家發展委員會於訂定《人工智慧基本法》及風險分類框架之過程中,就新興科技給予科技產業業者提供意見之機會。有鑑於《人工智慧基本法》之相關配套仍在研議中,例如數位發展部的風險分類框架、各目的事業主管機關之產業管理規範、評估驗證人工智慧風險之工具或方法、以及各主管機關依《人工智慧基本法》修訂現有人工智慧相關指引等 (例如,「行政院及所屬機關(構)使用生成式AI參考指引」),建請持續透過公私協作蒐集產業意見,以利科技業者分享產業知識及國際治理動態,以支持創新、促進公部門負責任人工智慧治理,並進而幫助臺灣透過人工智慧保持且提升國際競爭力。
