July 2026

The Ministry of Health and Welfare of Taiwan Issued Guidelines for the Application of Generative Artificial Intelligence by Medical Institutions

The Artificial Intelligence Basic Act (the “Act”) was promulgated and came into effect on January 14, 2026. It provides that the competent authorities in charge of the relevant industries shall, with respect to artificial intelligence applications within their respective areas of responsibility, establish risk-based management regulations, and shall assist the relevant industries in formulating their own industry guidelines and codes of conduct. Pursuant to the Act, the Ministry of Health and Welfare (the “MOHW”) issued the Guidelines for the Application of Generative Artificial Intelligence by Medical Institutions (the “Guidelines”) on May 29, 2026. The Guidelines serve as a reference for medical institutions, including public and private hospitals and clinics, which are preparing to implement or have already implemented generative artificial intelligence (“Generative AI”).

The Guidelines cover applications such as assistance with medical record documentation, clinical decision support, administrative documentation, and patient communications. They provide recommendations on key assessment considerations and management measures to assist medical institutions in designing their internal governance frameworks. This article provides an overview of the categories of Generative AI risks, the core implementation principles, and the key considerations for medical institutions identified in the Guidelines.

I. Six Categories of Risk

The Guidelines classify the potential risks associated with Generative AI into six categories: foundation model risks, data source risks, output risks, cybersecurity attack risks, user overreliance risks, and service disruption risks. For example, data source risks may arise where a Generative AI system accesses external data that is outdated, inaccurate, or incomplete, thereby affecting the quality of its clinical recommendations. Output risks refer to the possibility that the system may fabricate nonexistent medical literature or generate inaccurate medical information, potentially causing direct harm to patient safety. 

As these risks frequently do not arise in isolation in healthcare situations but may instead interact with one another, the Guidelines recommend that medical institutions identify and manage risks from a holistic systems perspective encompassing personnel, processes, technology, and external dependencies. Based on this assessment, medical institutions should establish appropriate review and continuous monitoring mechanisms.

II. Five Core Implementation Principles

The Guidelines recommend that medical institutions adhere to the following five core implementation principles at the institutional level when implementing Generative AI:

1. designating the responsible unit or personnel and conducting risk identification;
2. completing information security and data protection assessments;
3. planning for system integration and operational continuity;
4. fostering a responsible organizational culture; and
5. conducting continuous monitoring and improvement.

Before implementation, medical institutions should complete assessments concerning risk identification, legal and regulatory compliance, information security, and data protection. During implementation, institutions should ensure that the Generative AI system is properly integrated with their existing healthcare information systems and clinical workflows. They should also prepare alternative procedures in advance in case of system failure or service disruption, establish access control mechanisms, and strengthen personnel training. Following implementation, institutions should continuously assess whether the system remains safe, stable, and subject to effective risk control through monitoring, reporting, incident response, and improvement procedures. Version control and change management mechanisms should also be incorporated into the governance framework.

III. Key Considerations of the Three Implementation Stages

Based on the five core implementation principles described above, the Guidelines divide the implementation of Generative AI into three stages and provide specific recommendations for each stage, as summarized below.

i. Pre-Implementation Assessment

Medical institutions should designate a unit or personnel with expertise in healthcare quality and clinical safety to conduct an inventory of the proposed products and systems. They should also establish a risk classification mechanism based on both internal risks, such as system reliability, and external risks, such as potential clinical impact. Such risk classifications should serve as the basis for subsequent mitigation measures, monitoring, and audits. Institutions should also confirm that the implementation of the system complies with the Personal Data Protection Act, the Medical Care Act, and other applicable healthcare laws and regulations. Information security and data protection assessments should be completed before the system is placed into operation. The Guidelines specifically emphasize that, in any scenario involving clinical judgment, patient safety, patient communications, or medical records, the final confirmation and review must remain the responsibility of duly qualified healthcare professionals.

ii. Implementation and Integration

Medical institutions should confirm that the Generative AI system can be properly integrated with their existing healthcare information systems and clinical workflows. They should also complete performance validation, stress testing, and clinical safety testing. In addition, institutions should evaluate the system’s scalability and cross-platform compatibility and retain the flexibility to switch to alternative services in order to reduce the risks associated with dependence on a single service provider. With respect to vendor management, contracts should clearly set out provisions concerning quality standards, data access and usage rights, ongoing support, and the ownership of intellectual property rights. Vendors should also be required to disclose the large language models used by the system, as well as the applicable system maintenance and change management mechanisms, to facilitate ongoing oversight by the medical institution.

iii. Post-Implementation Use and Oversight

Medical institutions should continuously monitor the accuracy, bias, and clinical applicability of system outputs. Where systemic bias or errors are identified and cannot be remedied within a reasonable period, or where patient safety may be affected, the institution should immediately take appropriate measures, such as restricting or suspending the use of the system or reverting to its existing procedures. To address the risk of prompt injection, institutions should establish input filtering and anomaly detection mechanisms and cultivate organizational awareness of the relevant risks. 

As to the allocation of responsibilities, contracts with external service providers should clearly specify the respective responsibilities for system security, maintenance, data use, and bias correction. Internally, the responsibilities of the management unit, information technology department, and system users should be clearly delineated. Medical institutions should ensure that Generative AI is used solely as a supporting tool and that ultimate responsibility for medical judgments remains with qualified healthcare professionals. In addition, medical institutions should appropriately disclose to patients and their families the extent to which Generative AI is involved in the relevant healthcare services and the limitations of its use, in order to protect patients’ right to be informed and preserve trust between patients and healthcare professionals.

Overall, the Guidelines constitute administrative guidance for the medical field rather than mandatory rules, they reflect the principal categories of risk and the management approaches considered important by Taiwan’s health authorities in connection with the application of AI in healthcare. Medical institutions that have implemented or are planning to implement Generative AI systems are advised to promptly review the relevant systems and contractual arrangements, particularly from the perspectives of information security, personal data protection, and compliance with healthcare laws and regulations. Medical institutions should also consider establishing comprehensive risk governance, vendor management, and continuous monitoring mechanisms by reference to the Guidelines in order to address the legal and regulatory compliance challenges arising from the rapid development of AI applications in the medical field.

The contents of all materials (Content) available on the website belong to and remain with Lee, Tsai & Partners.  All rights are reserved by Lee, Tsai & Partners, and the Content may not be reproduced, downloaded, disseminated, published, or transferred in any form or by any means, except with the prior permission of Lee, Tsai & Partners.  The Content is for informational purposes only and is not offered as legal or professional advice on any particular issue or case.  The Content may not reflect the most current legal and regulatory developments.

Lee, Tsai & Partners and the editors do not guarantee the accuracy of the Content and expressly disclaim any and all liability to any person in respect of the consequences of anything done or permitted to be done or omitted to be done wholly or partly in reliance upon the whole or any part of the Content. The contributing authors’ opinions do not represent the position of Lee, Tsai & Partners. If the reader has any suggestions or questions, please do not hesitate to contact Lee, Tsai & Partners.