Taiwan’s Financial Supervisory Commission will pilot an AI Model Trust Registry this quarter, requiring banks that deploy customer-facing chatbots to log model versions, training-data summaries, and fallback paths before models serve retail clients online.

What the registry records

Under draft circular language described to industry associations Friday, each registered model receives a trust ID tied to the institution’s existing AI accountable officer. Banks must upload validation memos—accuracy on held-out FAQ sets, bias checks on mortgage and card scripts, and penetration-test results for prompt-injection paths. Updates trigger re-registration within five business days.

The registry does not host weights; it stores metadata and hashes so examiners can compare what marketing pages promise with what risk teams approved. Third-party vendors must co-sign entries, extending contractual monitoring duties the Bankers Association already expects.

Why chatbots first

Taiwan’s major banks raced to deploy Mandarin LLM assistants after the FSC issued non-binding AI guidelines in June 2024. Self-regulatory standards recorded in March 2024 require disclosure when customers talk to machines and senior ownership of AI risk. Yet supervisors found uneven documentation during onsite reviews this summer—some chatbots had been fine-tuned on help-desk tickets without refreshed fairness tests.

Chatbots are a contained use case: bounded intents, scripted escalations to humans, and measurable complaint rates. Registry designers said they will expand later to credit models if the chatbot phase stabilizes.

Legal footing

The pilot rests on supervisory authority under the Banking Act and the FSC’s 2023 core AI principles, not a new statute. Baker McKenzie notes the guidelines are administrative guidance, but recorded association rules already function as a standard of care during exams. Institutions that skip registration could face MRAs—matters requiring attention—in IT governance reports.

Foreign bank branches may reference group-level documentation if Taiwan-specific harms are covered, mirroring TWSE rules on AI outsourcing.

Bank readiness

CTBC, ESUN, and Mega executives told investors on recent calls they maintain internal model inventories; the registry formalizes a common schema. Fintech challengers with banking licenses worry about disclosure of vendor relationships, but the FSC said trade-secret redactions are allowed if examiners can audit under NDA.

Consumer advocates welcomed machine-disclosure alignment but asked for public lookup of trust IDs—not planned in phase one.

Technical workflow

Banks will submit JSON bundles through the FSC’s regtech sandbox portal, integrating with GRC tools from local integrators. Automated checks flag missing evaluation dates or mismatched officer names. Human reviewers at the FSC’s fintech division will spot-check high-traffic bots before Mid-Autumn marketing pushes.

Comparison with global rules

EU AI Act high-risk timelines remain slower than Taiwan’s sectoral approach. IFLR commentators describe the FSC framework as de facto binding through exams—a pattern Taiwan used for cybersecurity maturity indices.

Risks and limits

Registry metadata cannot prevent model drift if banks fail to monitor live traffic. Privacy scholars note training summaries may be vague; the FSC promised template fields for data categories without exposing personal records.

What changes Monday for customers

Retail users may see footers linking to trust IDs when chatting about card limits or wire fees. Behind the scenes, compliance teams must reconcile marketing copy with registered capabilities—a paperwork step, but one supervisors argue is cheaper than untracked bot upgrades after a phishing wave.

Timeline and industry briefings

The FSC scheduled banker workshops for late September to walk through sample JSON submissions. Insurers and securities firms are observers only in phase one, though the commission said broker call-center bots may enter phase two if banks meet registration deadlines without systemic errors.

Lawmakers on the Finance Committee asked whether trust IDs could be shared with the National Institute of Cyber Security for cross-sector incident response; the FSC said it is studying API hooks but will not open the registry publicly this year.

Banks that completed voluntary AI inventories in 2025 can map existing IDs to the registry schema during a grace month, reducing duplicate data entry for models already serving wealth-management clients.

Smaller credit unions told the FSC they may delay chatbot launches until a shared vendor registry template ships in November, avoiding bespoke legal reviews they cannot afford.