Update Grading and Governance Decision Records for AI Products / AI 產品更新分級與治理決策紀錄
Description
Policy research reference material. Not a legislative proposal, not legal advice, adopted by no authority. Verification cut-off 2026-08-04.
This deposit contains the full text in two languages. Both files are complete versions of the same document, section for section; the English file is not an abridged summary.
- ZH-TW AI 產品更新分級與治理決策紀錄:人工智慧基本法施行後的兩項制度工具,以部署設定為單位的更新分級,與治理決策層的紀錄義務(18 頁)
- EN Update Grading and Governance Decision Records for AI Products: Two institutional instruments after the Artificial Intelligence Basic Act took effect, update grading with the deployment configuration as its unit, and a record obligation at the governance decision layer (24 pages)
Abstract
Taiwan's Artificial Intelligence Basic Act was promulgated and took effect on 2026-01-14, and the Ministry of Digital Affairs published version 1.0 of the AI Risk Taxonomy and Assessment Framework on 2026-07-07. The two documents establish principles and a risk vocabulary, and neither imposes any obligation on the update management or governance records of AI products already in service. This document identifies two gaps. Gap one concerns whether an update triggers renewed review: the major international instruments carry only a binary test, substantial against non-substantial and planned against unplanned, so changes that individually count as non-substantial keep accumulating; this document labels that state product drift. Gap two concerns traceability: the technical layer and the documentation layer already carry express requirements, while the governance decision layer carries none. Who approved this deployment, on what basis, who raised concerns, which version was in force at the time of an incident: no framework within the verified scope requires those records to be retained. This document proposes two instruments. The first is a five-level update grading scheme anchored to a deployment candidate, where L3 and above enter review and where changes to the memory mechanism, the persona and the interaction optimisation objective are graded L4. The second is a governance decision record of five items, of which the approval chain, the dissent record and incident-to-version linkage are additions. Limitations: no institutional ethics review, no external peer review, no funding, and the document contains self-citation. The user-side risk framework it cites is a single-case longitudinal qualitative study, which supports no prevalence estimate and constitutes no causal inference.
摘要
臺灣《人工智慧基本法》2026-01-14 公布施行,數位發展部《人工智慧風險分類框架》v1.0 於 2026-07-07 發布。兩份文件建立原則與風險語彙,都未對已上線人工智慧產品的更新管理與治理紀錄設義務。本文指出兩個缺口。缺口一,更新後是否重新審查,國際主要制度只有實質與非實質、計畫內與計畫外的二分判斷,個別看都不算實質的變更因此持續累積,本文以產品漂移指稱該情形。缺口二,可追溯性的技術層與文件層已有明文要求,治理決策層沒有:誰核准這次部署、依據什麼、有誰提過異議、事故對應哪個版本,查證範圍內的框架都未要求保存。本文提出兩項工具:以部署候選為基準的五級更新分級,L3 以上進入審查,記憶機制、人格設定與互動優化目標三項變更列 L4;以及治理決策紀錄五項,其中核准鏈、異議紀錄與事故連結版本為新增。限制:無機構倫理審查、無外部同儕審查、無資金,並含自我引用;所引使用者端風險框架為單案例縱貫質性研究,不支持盛行率估計,也不構成因果推論。
Statement labels
Every statement in the text carries a label recording its nature: in force, adopted not yet applicable, under deliberation, administrative guidance, voluntary standard, operator public statement, academic literature, proposal, research judgement. Administrative guidance and voluntary standards are not labelled as law.
Version
v2.0 supersedes v1.2 (2026-07-30, verification cut-off 2026-07-12), which was circulated as a submission brief and was never deposited. Changes are listed in section 11 of the text.
Notes
Files
ZON_RZVN_AI_Product_Update_Grading_and_Governance_Decision_Records_EN_v2.0_2026-08-04.pdf
Files
(1.3 MB)
| Name | Size | Download all |
|---|---|---|
|
md5:42884e8ff726617fa207f5eca42e1b93
|
470.8 kB | Preview Download |
|
md5:02ae0d8db666ef4159260db0babaafb3
|
784.8 kB | Preview Download |