Worthy of Trust值得信賴
Your study asks how AI affects human rights, economic security, vulnerable groups, and the international right to work. I would like to offer one frame.
Taiwan’s success against AI‑generated scam ads showed that democracies need not choose between technocratic control and platform inaction. Citizens deliberated on the balance between fraud prevention and freedom of expression. The same principle applies to work: affected people should help set the rules before systems harden into infrastructure.
The right to work in the age of AI must include three practical rights: the right to learn, the right to know, and the right to contest.
The right to learn means training before displacement, not after. Work is more than income. It is apprenticeship. It is belonging, care and dignity.
The right to know means that when AI affects hiring, scheduling, promotion, benefits, education, or public services, the people should know it is being used, who is accountable, and whose data is shaping the decision. A black‑box outcome should not be treated as due process.
The right to contest means those affected can challenge outcomes without needing a degree in computer science. Appeals must lead to repair — correction, compensation, policy change, or retiring the system altogether.
貴委員會的研究,關注 AI 如何影響人權、經濟安全、弱勢族群,以及國際工作權。請容我提出一個框架。
臺灣遏止 AI 生成詐騙廣告的經驗說明:民主社會不必在技術官僚的控制與平台的坐視不管之間二選一。詐騙防制與言論自由之間的分寸,由公民親自審議拿捏。同樣的原則也適用於工作:在系統硬化成基礎設施之前,受影響的人就該一起訂定規則。
AI 時代的工作權,必須包含三項具體權利:學習權、知情權、申訴權。
學習權,是在被取代之前受訓,而不是之後補課。工作不只是收入;工作是師徒相承,是歸屬、關懷與尊嚴。
知情權,是當 AI 影響招募、排班、升遷、福利、教育或公共服務時,人們有權知道:AI 正在其中運作、誰為它負責、又是誰的資料在形塑這項決定。黑箱吐出的結果,不該被當成正當程序。
申訴權,是受影響的人不必先讀完資訊科系,也能挑戰結果。申訴必須通向修復——更正、補償、修改政策,或乾脆讓整套系統除役。
Ethics of Care關懷倫理
This matters most for those already made vulnerable by existing systems. I am thinking of Indigenous communities, migrant workers, people with physical and mental challenges, children, seniors, racialised communities, and those underrepresented in labour and skills data.
AI must not become a new way to extract knowledge without consent, to score people without context, or to make exclusion more efficient.
At Oxford, my work in Civic AI translates the ethics of care into six governance questions:
Are we hearing those closest to harm? Is someone named and accountable? Does the system work in context? Do those affected have recourse? Does it build solidarity rather than vendor lock‑in? And does it know when to stop?
For high‑impact AI, democracies should require decision traces, independent audits, accessible appeals, public incident reporting, worker and community co‑governance, sunset clauses, and procurement rules that avoid lock‑in.
A democratic system must be interruptible: possible to pause, override, or retire without disrupting essential services people depend on.
Inclusive prosperity is also democratic security. To the familiar agenda of protecting, empowering, and building, I would like to add one verb: co‑governing.
Protect people from harm. Empower them with skills and knowledge. Build trustworthy public infrastructure. And co‑govern AI with the workers, families, communities, and future generations who will live with these consequences.
這件事,對已被既有制度推向脆弱處境的人最為要緊。我想到的是原住民族、移工、身心障礙者、孩子與長輩、少數族裔社群,以及在勞動與技能資料裡代表性不足的人。
AI 不該成為一種新的手法:未經同意就搾取知識、抽掉脈絡就替人打分數、讓排除變得更有效率。
在牛津,我推動「仁工智慧」(Civic AI)研究,把關懷倫理化為六個治理問題:
我們有沒有聽見離傷害最近的人?有沒有人具名負責?系統放進真實脈絡,還管不管用?受影響的人有沒有救濟管道?它促成的是團結,還是供應商鎖定?還有——它知不知道何時該停?
對於影響重大的 AI,民主社會應該要求:決策留痕、獨立稽核、人人用得上的申訴管道、公開的事故通報、勞工與社群共同治理、落日條款,以及防止供應商鎖定的採購規則。
民主的系統必須可以中斷:能暫停、能推翻、能除役,而不至於讓人們賴以為生的服務停擺。
共融的繁榮,也是民主的安全。在大家熟悉的保護、培力、建造之外,我想再添一個動詞:共同治理。
保護人們免於傷害;以技能與知識培力眾人;建造值得信賴的公共基礎設施;並且和勞工、家庭、社群,以及終將承接這一切後果的未來世代,一起治理 AI。
Bigger Table一張更大的桌子
Could you give a concrete example of co‑governing AI in Taiwan?
能否舉個具體的例子,說明臺灣如何真正共同治理 AI?
In 2024, we convened what is called an alignment assembly to respond to the harms of generative AI in scam and fraud ads online.
Deepfakes that year were prevalent in every democracy. But as Asia’s most internet‑free country, Taiwan simply could not do top‑down censorship. So we sent SMS text messages to 200,000 random numbers around the island, asking: What should we do together?
We chose 447 people — a mini‑public statistically similar to the wider polity. In tables of ten, they deliberated. The only simple rule was that AI only facilitates, and participants have to convince the nine other people at the same table before their idea bubbles up.
Long story short, we implemented a set of ideas that more than 85% of the mini‑public agreed with — and the other 15% could live with. That included joint liability, know‑your‑customer rules, and slowing down connections by foreign platforms that did not adhere to our liability rules.
Throughout 2025, impersonation and deepfake ads were down by more than 90%.
When people want to show up at the table, the idea is not to do top‑down control. It is to invent a bigger table.
2024 年,我們召開了一場對齊大會,回應生成式 AI 用於網路詐騙廣告所造成的傷害。
那一年,深偽在每個民主國家都氾濫成災。但臺灣是亞洲網路最自由的國家,由上而下的審查根本行不通。於是,我們向全臺 20 萬組隨機抽出的電話號碼發送簡訊,問大家:我們該一起怎麼做?
我們選出 447 位民眾,組成統計上與整體社會相似的微型公眾;十人一桌,展開審議。規則簡單一條:AI 只做輔助;想法要浮上檯面,得先說服同桌的另外九個人。
長話短說:最後我們付諸實行的那批構想,獲得微型公眾超過 85% 的同意,其餘 15% 也表示可以接受。其中包括平台連帶責任、認識客戶(KYC)規範,以及把不遵守責任規範的境外平台連線降速。
整個 2025 年,冒名與深偽廣告減少了 90% 以上。
當人們想要上桌,該做的不是由上而下的控制,而是發明一張更大的桌子。
Data as Soil資料如土壤
From an energy‑use perspective, what is the difference between general‑purpose AI and domain‑specific models?
從能源使用的角度來看,通用 AI 與特定領域模型有什麼不同?
Currently, in AI training, general‑purpose large models need to anticipate pretty much every use, from folding proteins to folding laundry, in the same model. In doing so, they are incredibly energy‑inefficient to train.
But when we know what we want the model to do — folding proteins, or folding laundry — we can train what are called domain‑specific models, or local models. These can incorporate the community’s input in a way that also protects its data from extraction to the cloud, to big tech companies.
The extractive, very energy‑consuming part can be thought of as “data as oil.” This kind of extraction goes to some large refinery somewhere. But the local way to train small models can be thought of as “data as soil” — the local community tends to these data together.
They fine‑tune it. They continuously train it. Whenever there is bias or an error, the course correction is immediate, instead of waiting for an energy‑consuming run that might take half a year.
In Taiwan, the Ministry of Digital Affairs and the Ministry of Agriculture were set up within about a year of each other, and we worked together so that environmental sensing was not confined to a single production facility, and so that long-term trends around cropping, irrigation, and farmer–buyer relationships could be supported.
We have a programme called TCloud, or Taiwan Cloud, where each small and medium enterprise — including in the agricultural sector — can choose among thousands of solutions. The key is transparency and data portability: the freedom to move between vendors, so the data stays with the operators. If one prediction model or one SaaS vendor no longer fits, they can shift to another.
To bootstrap adoption, the government at one time reimbursed up to 80% of the SaaS purchase. The subsidy goes to SaaS consumers, many of them small and medium enterprises themselves — not to vendors as national or regional champions. The result is interoperability, data sovereignty, and ownership across the sector, so operators can collaboratively train sector-specific models. The same idea is now being taken up by financial-sector data coalitions among banks and insurers.
Our drone agricultural service platform, for example, brings together many small operators who share equipment, certify pilots, and share compliance records. None of them could individually afford the equipment or meet the regulatory burden, but together they reach a horizontal scale previously available only to large agribusiness.
The state’s role is not to pick a national champion. It is to subsidise the freedom to choose.
目前的 AI 訓練裡,通用大型模型得在同一個模型中預作準備,應付幾乎所有用途——從摺疊蛋白質到摺疊衣物,無所不包。也因此,訓練起來極其耗能,效率極差。
可是,一旦我們清楚要模型做什麼——摺蛋白質,或者摺衣服——就能訓練「特定領域模型」,也就是在地模型。這類模型能納入社群的意見,也讓社群的資料不必被抽上雲端、送進大型科技公司手裡。
搾取式、極度耗能的那條路,可以想成「資料如石油」:開採出來,運往某座遠方的大煉油廠。在地訓練小模型的這條路,則是「資料如土壤」——這片土,由在地社群一起耕耘照料。
社群自己微調、持續訓練。一旦出現偏誤或錯誤,當下就能修正,不必苦等一輪動輒半年、極其耗能的訓練跑完。
在臺灣,數位發展部與農業部在前後約一年間相繼成立。兩個部會攜手,讓環境感測不再侷限於單一生產場域,也讓種什麼作物、怎麼灌溉、農民與買家的長期關係,都有資料可以支撐。
我們有個計畫叫 TCloud——臺灣雲市集。每一家中小企業,包括農業部門的業者,都能在數千種解決方案之間挑選。關鍵在透明與資料可攜:搬家的自由,讓資料留在經營者自己手上。哪天某個預測模型或 SaaS 供應商不再合用,隨時可以換一家。
為了帶動採用,政府一度補助最高 80% 的 SaaS 採購費用。補助給的是採購 SaaS 的一方——多半本身就是中小企業——而不是把哪家供應商養成國家隊或區域冠軍。結果是整個部門的互通性、資料主權與所有權都握在業者手中,經營者因此能夠合力訓練部門專屬的模型。同樣的思路,如今也由銀行與保險業者組成的金融資料聯盟接了過去。
以我們的農業無人機服務平台為例:許多小型業者聚在一起,共用設備、一起考照、共享法遵紀錄。單打獨鬥,誰也買不起設備、扛不起法遵;聚在一起,卻搆得著過去只有大型農企才有的水平規模。
國家的角色不是欽點國家隊,而是補助選擇的自由。
Without Revealing毋須揭露
How do you protect human‑rights information while sharing it across jurisdictions?
人權資訊需要跨越司法管轄區分享,又該如何保護?
I would like to make the distinction between data coalitions, where people pool data in a way useful to all members, and the aggregation of data.
It is possible for multiple players, stakeholders, and communities to join a data coalition without sharing any of the raw data. There exists a kind of technology called zero‑knowledge technology that allows people to prove they can do something, that they possess certain knowledge, or that a community can respond to a certain kind of query — without revealing any personally identifiable information underneath.
During the pandemic in Taiwan, we used a privacy‑preserving contact‑tracing method. A venue printed a random number in a QR code at the front door. A person scanned it and sent it to the trusted number 1922 through their telecom.
The telecom knew nothing about what the random number meant. The venue learned nothing — not even the phone number of the visitor. The state learned nothing whatsoever.
But if an infection happened, we could do contact tracing and recursive notification — again, without sacrificing the privacy of people who were not in the affected area.
我想先區分資料的聯盟與資料的聚合。聯盟,是大家把資料匯在一起,讓每個成員都用得上;聚合,則不是這麼回事。
多方參與者、利害關係人與社群,可以加入同一個資料聯盟,卻不必交出任何原始資料。有一類技術叫零知識技術:它讓人證明自己會做某件事、握有某些知識,或證明一個社群能回應某類查詢——而底下任何足以識別個人的資訊,一概不必揭露。
臺灣疫情期間的「簡訊實聯制」,就是保護隱私的接觸者追蹤:場所在門口貼出一組化為 QR code 的亂數,民眾掃描後,經電信業者傳給可信賴的 1922 專線。
電信業者不知道那組亂數是什麼意思。場所一無所獲——連訪客的電話號碼都沒有。國家則一無所知。
可是一旦出現感染,我們照樣能追蹤接觸者、層層遞迴通知——同樣不犧牲疫區之外任何人的隱私。
Campfires, Not Wildfires營火,而非野火
Can AI be used to help us relate to one another rather than replace us?
AI 能不能幫助我們彼此連結,而不是取代我們?
I would like to make a distinction between AI that automates intelligence — what I sometimes call authoritarian intelligence, making decisions on behalf of people — and a different kind of AI.
Ten years ago on social media, many felt their agency had been taken away. Previously, when we followed the same people, we saw the same feed. But this was replaced by a very judgmental AI that personalised our feed and encouraged engagement through enragement. That is very authoritarian.
In Taiwan, we call the other kind assistive intelligence, which assists cross‑conversation between those who would otherwise not agree.
Each campfire is tended by a bounded set of people: ten, a hundred, or a larger bonfire. We have designed prosocial media such as Polis, an open‑source technology used by more than a dozen countries worldwide, including Canada.
Instead of making outrage viral, Polis makes overlap viral. Only ideas that people who otherwise would never agree can both support gain virality. Only bridge‑makers gain virality. In doing so, people heal polarisation and division.
Our demonstration was successful enough that even traditional social media platforms such as X, formerly Twitter, have now adopted a very similar algorithm called Community Notes. It lets people who bridge across ideologies write notes to clarify or add context next to viral misinformation, disinformation, or simply contentious information.
Now we work with all the major social media companies on Community Notes implementation, and on collaborative notes — drafted by AI and instantly corrected by humans, so AI can learn what can translate across communities. For example, between the climate‑justice community on one side and biblical creation care on the other, so they can translate across their vocabularies.
我想先區分兩種 AI。一種把智慧自動化——我有時稱之為威權智慧——替人做決定。另一種,是很不一樣的 AI。
十年前的社群媒體上,許多人感到能動性被拿走了。從前,追蹤同樣的人,就看見同樣的動態;後來,取而代之的是一套動輒評斷的 AI,替每個人客製動態消息,用激怒餵養互動。那是非常威權的。
在臺灣,我們把另一種稱為輔助智慧:協助原本談不攏的人,跨過立場交談。
每一座營火,都由一群有邊界的人照料:十人、百人,或一座更大的火堆。我們設計了利社會媒體,例如 Polis——這項開源技術,全球已有十多個國家採用,加拿大也在其中。
Polis 不讓怒火瘋傳,而讓交集瘋傳。能傳開的,只有那些原本水火不容的人也都支持的想法;能被看見的,只有搭橋的人。就這樣,人們療癒極化與分裂。
這場示範夠成功,連 X(前身是 Twitter)這樣的傳統社群平台,如今也採用了非常相似的演算法——社群筆記(Community Notes):讓跨越意識形態搭橋的人,在瘋傳的錯誤資訊、假訊息,或單純有爭議的訊息旁,寫下澄清與補充脈絡的筆記。
現在,我們與各大社群媒體公司合作導入社群筆記,也推動「協作筆記」:由 AI 起草、人類即時修正,讓 AI 學會哪些話能在社群之間轉譯——比方在氣候正義社群與聖經受造守護社群之間,讓兩套語彙互相聽懂。
Interoperable Governance互通的治理
The UN’s 2024 report on governing AI for humanity points to a global governance deficit. How do we close it?
聯合國 2024 年《為人類治理 AI》報告指出全球治理赤字。我們該如何補上?
I think the report’s diagnosis is correct: a patchwork of principles without enforceable duties will not govern AI, which is intrinsically a global phenomenon in technology.
Democracies, especially including middle powers, should build interoperable governance. That does not mean identical governance applied everywhere in the same way around the globe. It means auditing standards, incident‑reporting standards, provenance for synthetic media, procurement requirements that avoid vendor lock‑in, and similar stacks that can be made to work across jurisdictions without harmonising every domestic rule.
Canada, Taiwan, and other free and open societies can be peers in this work. The global governance deficit will not be closed by another universal principle, but by enforceable duties that make principles contestable in each and every domain.
我認為報告的診斷是對的:原則東拼西湊、義務卻無從執行,治理不了 AI——何況 AI 在技術上,本來就是全球性的現象。
民主社會——尤其是中等強權——應該建立可互通的治理。可互通,不是全球各地一體適用同一套規則;而是稽核標準、事故通報標準、合成媒體的出處驗證、防止供應商鎖定的採購要求,這一類制度堆疊可以跨司法管轄區銜接運作,而不必先統一每一條國內法規。
加拿大、臺灣,以及其他自由開放的社會,可以在這件事上互為同儕。全球治理赤字,靠的不是再添一條普世原則,而是可執行的義務——讓原則在每一個領域,都容得下異議、經得起檢驗。
Sovereignty Is Not Solitude主權不是孤島
How can the federal government best support Indigenous data sovereignty?
聯邦政府要怎麼做,才最能支持原住民族的資料主權?
Taiwan has 16 Indigenous nations and more than 42 language variations. We see cultural sovereignty — and also transcultural sovereignty, the ability to translate across cultures — as very important.
When we say “sovereign AI” in Taiwan, we do not mean just a national AI model that speaks Mandarin, Taigi, Hakka, and Indigenous languages. We mean a reproducible process for language communities to own the social and cultural composition of the data curated within those language communities.
It also includes alignment assemblies — ways for people to draw boundaries around how AI should enter their community, almost like a code of conduct for AI agents.
These two together enable each community not only to feel that it owns its social and cultural determination when it comes to language‑model training, but also to incorporate transcultural translation capabilities. When one language or culture gains a certain capability, a community can choose to bring it into its own context if it so chooses.
But the agency, the sovereignty, is held by the Indigenous nation or community — not by a top‑down national commission.
No one should be automated out of agency. No community’s knowledge, language, or labour should be treated as raw material without consent. No worker should have to negotiate alone with a black box.
Inclusive prosperity is also democratic security. Canada and Taiwan are both free and open societies, and we know our adversaries are testing our seams of trust.
臺灣有 16 個原住民族、超過 42 種語言變體。在我們看來,文化主權極其重要——還有跨文化主權:在文化與文化之間翻譯的能力。
在臺灣,當我們說「主權 AI」,指的不只是一個會說華語、臺語、客語與原住民族語的國家級模型。我們指的是一套可以重複施行的流程,讓每個語言社群擁有自己社群裡彙整資料的社會與文化組成。
這也包括對齊大會:讓族人自己劃定 AI 進入社群的界線,幾乎像是為 AI 智慧體訂下的行為準則。
兩者合起來,每個社群在語言模型的訓練上,不只真切握有社會與文化的自決,也能接上跨文化翻譯的能力:當某個語言、某種文化長出新的本事,其他社群若願意,也能把它引入自己的脈絡。
而能動性與主權,始終握在原住民族與社群自己手中——不在任何由上而下的國家委員會。
沒有人應該被自動化奪去能動性。沒有一個社群的知識、語言或勞動,應該在未經同意之下被當成原料。沒有一位勞動者,應該獨自面對黑箱談判。
共融的繁榮,也是民主的安全。加拿大與臺灣同為自由開放的社會;我們都明白,對手正在試探我們信任的接縫。
But sovereignty is not solitude. It is the way to protect people and cooperate without surrendering public judgment.
然而,主權不是孤島。主權是一種方式:保護人民、與人合作,而不交出公共的判斷。