AI regulation in 2026: what Taiwan businesses should prepare now
The EU AI Act's transparency duties took effect in August 2026 and Taiwan's AI Basic Act is now law. What applies to chatbots, AI content and AI in hiring or credit, plus seven steps to start now.

Key takeaways
- The EU AI Act's Article 50 transparency duties have applied since August 2, 2026: chatbots must tell people they're talking to AI, and deepfakes must be labeled. If your AI's output is used in the EU, a Taiwan company can be covered.
- Obligations for high-risk uses such as hiring and credit scoring were pushed back by the EU's Digital Omnibus to December 2, 2027, and to August 2, 2028 for AI built into regulated products. Delayed, not cancelled.
- Taiwan's AI Basic Act took effect in January 2026. It mainly directs government, with sector rules due within two years, while existing laws such as the Personal Data Protection Act already apply.
- Seven things to start on now: an AI inventory, risk classification, transparency labels, vendor contracts, personal data handling, human review and record keeping.
Table of contents
- The timeline: what's in force and what's been delayed
- The EU AI Act: why Taiwan companies should pay attention
- From August 2: what the transparency duties require
- Taiwan: the AI Basic Act is in force, the details are still coming
- Seven things to start on now
- Bottom line: get a clear view of your own AI first
Your website has an AI chatbot, your marketing team makes product images and social posts with AI, and HR has started trying AI to screen résumés. Then a German customer sends a supplier questionnaire, and one question reads: "Do the AI systems your company uses comply with the EU AI Act?" That's when many companies realize AI is no longer just a technology question. It's a compliance question too.
2026 is the year AI rules got real. The EU AI Act's transparency duties started to apply on August 2. Taiwan's AI Basic Act took effect in January, and in July Taiwan's Ministry of Digital Affairs published an AI risk classification framework. Meanwhile, the EU's "Digital Omnibus" postponed some obligations, leaving plenty of people unsure what's actually in force.
This article lays out where things stand as of September 2026 and what companies can start on right away. (This is general information, not legal advice. Talk to a lawyer about your specific situation.)
The timeline: what's in force and what's been delayed

| Date | What happened | What it means for a typical business |
|---|---|---|
| Aug 1, 2024 | EU AI Act enters into force | Phased application begins |
| Feb 2, 2025 | Prohibited practices and AI literacy duty apply | E.g. no AI emotion recognition of employees at work |
| Aug 2, 2025 | General-purpose AI model duties apply | Mostly the model developers' responsibility |
| Jan 14, 2026 | Taiwan's AI Basic Act promulgated and in effect | Government has two years to adapt its rules |
| Aug 2, 2026 | Most of the EU AI Act applies, including Article 50 transparency | Chatbots must disclose; deepfakes must be labeled |
| Dec 2, 2026 | Grace period for marking AI output ends; new prohibition applies | See "What was delayed" below |
| Dec 2, 2027 | Annex III high-risk duties apply (originally Aug 2, 2026) | Hiring, credit scoring and similar uses |
| Aug 2, 2028 | Duties for high-risk AI in products apply (originally Aug 2, 2027) | Machinery, medical devices and other regulated products |
The official schedule is on the European Commission's AI Act Service Desk timeline.
The EU AI Act: why Taiwan companies should pay attention
The EU AI Act (Regulation (EU) 2024/1689) doesn't care where your company is based. Under Article 2, it can apply if:
- you sell an AI system or a product with AI in it on the EU market;
- you have a presence in the EU and use AI in your business; or
- your company is outside the EU but the output of your AI system is used in the EU, for example an AI chatbot on your English-language website answering European customers.
The law also distinguishes two roles: the provider (who develops an AI system and offers it under their own name) and the deployer (who uses an AI system in their business). If you build a chatbot on a large-model API and put it on your website, you may be both. If you use an off-the-shelf SaaS tool, you're most likely a deployer.
Four risk levels

- Prohibited: for example social scoring, manipulating people by exploiting their vulnerabilities, and emotion recognition at work or in schools.
- High-risk: the uses listed in Annex III, including recruitment and HR (screening résumés, evaluating employee performance), creditworthiness assessment of individuals, education and more, plus AI safety components in products covered by EU product-safety laws.
- Transparency: chatbots that talk to people, AI that generates content, and deepfakes.
- Minimal risk: inventory forecasting, spam filters, internal document summaries and the like. No extra duties, though data protection and other laws still apply.
Maximum fines depend on the tier: up to €35 million or 7% of worldwide annual turnover for prohibited practices, and up to €15 million or 3% for breaching high-risk or transparency duties. For small and medium-sized businesses, whichever amount is lower applies.
What was delayed, and what wasn't
In November 2025 the Commission proposed the "Digital Omnibus." Its AI part was adopted as Regulation (EU) 2026/1744 and took effect on July 27, 2026 (Commission announcement):
- Delayed: Annex III high-risk duties move to December 2, 2027; high-risk AI in products moves to August 2, 2028.
- Eased: the AI literacy duty changes from "ensure staff have sufficient AI literacy" to "take measures to support it," and simplifications for small businesses now extend to "small mid-caps."
- Not delayed: Article 50 transparency duties still applied from August 2, 2026. The only relief is for machine-readable marking of AI output: systems already on the market before August 2 have until December 2.
- Added: a ban on using AI to generate non-consensual intimate images and child sexual abuse material, applying from December 2, 2026.
Delayed doesn't mean cancelled. If you use AI for hiring or credit decisions, use the extra time to get your documentation, review process and records in order.
From August 2: what the transparency duties require
Article 50 is the provision that touches the most companies. In July the Commission published guidelines on the transparency obligations, and in June a voluntary Code of Practice on marking and labeling AI-generated content.
| Situation | What to do | Who's mainly responsible |
|---|---|---|
| AI customer service, chatbots | Tell people they're talking to AI (unless it's obvious) | Provider |
| AI-generated images, audio, video, text | Mark it in a machine-readable way, e.g. watermarks or metadata | Provider of the generative AI |
| Deepfakes (realistic people, places, events) | Clearly disclose that AI generated or altered it | Deployer |
| AI text published on matters of public interest | Disclose it's AI-generated, unless a person reviewed it and took editorial responsibility | Deployer |
| Emotion recognition, biometric categorization | Inform the people being analyzed | Deployer |
Day to day, that comes down to three things:
- Say it up front in your chatbot, e.g. "I'm an AI assistant; I'll hand complex questions to a person." The Commission's draft guidelines say a line buried in the terms of use, or vaguely calling it an "assistant," isn't enough: the disclosure has to appear in the conversation itself.
- Don't strip the markers your tools add. Generative AI tools usually embed watermarks or metadata in their output; keep them through editing.
- Treat marketing assets case by case. An ordinary product lifestyle image isn't necessarily a deepfake. Making a real person "say" something they never said, or synthesizing footage that looks like a real event, needs a label.
A chatbot that answers only from your company's own content and hands off to a person when it can't find an answer (see our guide to RAG knowledge bases) reduces risk far more than adding labels after the fact.
Taiwan: the AI Basic Act is in force, the details are still coming
Taiwan's AI Basic Act (人工智慧基本法) passed the Legislative Yuan, Taiwan's parliament, on December 23, 2025 and was promulgated and took effect on January 14, 2026. It has 20 articles, and the lead authority is the National Science and Technology Council (NSTC). As a "basic act," it mainly sets out what government must do:
- Government AI policy must follow seven principles: sustainability and well-being, human autonomy, privacy and data governance, cybersecurity and safety, transparency and explainability, fairness and non-discrimination, and accountability.
- The Ministry of Digital Affairs (MODA) is responsible for a risk classification framework aligned with international standards. Version 1.0 was published in July 2026. It sorts AI risks into 3 categories and 20 subcategories and recommends four steps: inventory, identify, assess, respond.
- Sector regulators are to write risk-based rules using that framework, and government must finish adapting its laws within two years of the Act taking effect. For uses designated high-risk, the Act calls for warnings or cautionary labels, clear allocation of liability, and remedy, compensation or insurance mechanisms.
In other words, the Basic Act itself doesn't fine companies, but the direction is clear, and sector-specific rules will arrive over the next two years.
Laws that already apply
- Personal Data Protection Act (PDPA): tell people why you collect their data, use it only within that stated purpose, and keep it secure. Before pasting customer data into an outside AI service or training a model on customer conversations, ask: "Is this within the purpose we told people about?" The PDPA was amended in November 2025, adding rules such as breach notification; the Executive Yuan (Taiwan's cabinet) will set the effective date, so keep an eye on it.
- Sector rules: for example, the Financial Supervisory Commission's AI guidelines for the financial industry set expectations on fairness, explainability and governance.
- Your existing responsibilities don't disappear because AI is involved: Taiwan's Employment Service Act prohibits hiring discrimination, so if an AI résumé screener systematically filters out candidates by age or gender, the company is still responsible.
Seven things to start on now
- Build an AI inventory: list every AI use, the tool or vendor, the data it handles, who it serves (including anyone in the EU) and who owns it. Include AI tools employees signed up for on their own.
- Classify the risk: map each use against the EU's four levels and MODA's framework, and flag what's high-risk and what carries transparency duties.
- Add transparency labels: disclose at the start of chatbot conversations, label deepfakes and AI text on public-interest topics, and build this into your content workflow.
- Ask your vendors:
- Is our input used for training? Where is it stored, and for how long?
- Is generated content marked in a machine-readable way?
- Will you notify us before model changes?
- If the product is used in the EU, can you provide the documentation and instructions for use the law requires?
- Handle personal data carefully: give AI only the data it needs, de-identify where you can, and update your privacy notice.
- Keep a human in the loop for consequential decisions: for hiring, lending and dismissals, AI recommends and a person decides, and the reviewer must understand the reasoning and have the authority to override it. If you process EU residents' personal data, the GDPR already restricts fully automated decisions with significant effects.
- Keep records: which model version was used, inputs and outputs, and who approved what. Deployers of high-risk systems in the EU must keep logs for at least six months (Article 26, applying from December 2027).
The last three depend directly on how your AI systems handle permissions and logging; see AI agent security.
Bottom line: get a clear view of your own AI first
The rules will keep changing, but an inventory, risk classification, labels, human review and records will be useful however they end up. This article is general information as of September 2026, not legal advice. If you sell into the EU or use AI for high-risk decisions, confirm the details with a lawyer.
If you'd like to build your AI inventory, human review steps and audit logs into the systems you already run, take a look at our AI integration services and custom business systems, or get in touch.


