World Summit AI | Blog

Who really Controls AI? with Audrey Tang - Taiwan's cyber ambassador

Written by World Summit AI | Jul 28, 2026 4:00:01 AM

Written responses by Audrey Tang, Taiwan's cyber ambassador and first digital minister, ahead of her appearance at World Summit AI 2026 in Amsterdam this October collected by our Chief Editor and Content Director, Fawn Hudgens.

When you look at how AI is being rolled out today, what is the biggest misconception leaders have about who's in control – and how does that differ from where power actually sits?

The biggest misconception is that control lives where the model lives, so acquiring the frontier is akin to holding the wheel. In deployment, control sits elsewhere. Whoever sets the evaluation, the reward function and the recourse governs the system, whatever its origin.

The U.N. Independent International Scientific Panel on AI finds development concentrated in a small number of firms and countries, yet every consequential deployment still requires a human institution to sign off. That signature is where power sits, but too many organisations leave the seat empty.

The leaders I admire own that responsibility. They decide what the system is satisficing for, how evaluation works in context and who answers when the system acts. AI in the human loop, not the human in the AI loop.

 

What worries you more right now: AI concentrating power in governments, or AI concentrating power in private companies?

If control sits with whoever signs the deployment, the real worry is whether those people understand what they are signing. The U.N. July 2026 preliminary report warns that most member states depend on systems they cannot build, inspect, audit or fully adapt to local context. The same dependency appears inside companies, hospitals and schools. That concentration can wear a public badge or a private one.

What makes a deployment authoritarian is who names the terms and the recourse, not the origin label on the model. A public agency can pass that test, and a company can fail it. The reverse is just as true. So, the divide I watch is not government versus private. It runs between institutions whose systems can be inspected, appealed and switched off, and institutions that ask for trust while offering no recourse. The true test is who answers when the system acts.

 

Many companies behave as if "compliance equals governance." What's one uncomfortable question you wish every CEO would ask their AI teams instead?

I challenge every CEO to take that test into the boardroom. If a system harmed someone today, who is owed an answer? Who inside the company is authorised to give that answer? Compliance certifies yesterday. Governance is a capability leaders practise in advance, the way they practise fire drills.

The panel's report identifies the gap: More than 40 types of governance instruments already exist, yet they are fragmented, concentrated among a few corporations and rarely measure real-world effectiveness. Without effective measurement, governance risks becoming symbolic.

My checklist has four parts: a second source that can carry the work, an audit trail an outsider can read, an exit right written into the contract and a downgrade drill the team has actually run. When all four work, the compliance paperwork writes itself.

 

Sovereign AI is usually framed in terms of chips, clouds and data centres. What changes when you start the conversation with people's rights and public trust instead of hardware?

What a company practises, a country can guarantee. Hardware answers where a system runs; rights answer whom the system serves and who can stop it. A rights-first approach changes the design brief. People hold the right to inspect a system that makes decisions about them, switch away from that system, repair it and receive an answer. Chips, clouds and data centres then become means rather than ends, procured with second sources and exit clauses instead of decade-long dependencies.

My own benchmark is airplane mode. Switch off the network and see whether the intelligence still works for the people who run it. A laptop with 16 gigabytes of memory already runs a capable local model. In Taiwan, public infrastructure includes the AI Basic Act in force since January and an AI Evaluation Center that publishes test results. That combination makes sovereignty something anyone can verify, and I will demonstrate this on stage in Amsterdam.

 

As countries race to build domestic AI ecosystems, how do we prevent sovereignty from becoming digital nationalism?

Sovereignty becomes nationalism when countries measure walls rather than the four rights. Shared capacity offers another path. People must be able to evaluate an AI system, adapt it, leave it and hold a responsible institution to account for its actions. The healthiest domestic ecosystems use interoperable standards and protocols, so that merging is as easy as forking and no community is locked in or out.

A Kami is local knowledge artefact management intelligence. My design target is millions of small Kamis, each interoperating without being gathered into one super-intelligent data centre. Countries that share evaluations, protocols and safety findings become more sovereign together. Secrecy is the only zero-sum design.

 

AI is often framed as a race between nations. What would a more cooperative and globally inclusive AI future actually look like?

A cooperative future looks like the first Global Dialogue on AI Governance, a U.N. platform whose first session convened in Geneva July 6 and 7. The process drew more than 1,500 written submissions from governments, companies, researchers and civil society. Those participants worked from a shared evidence base rather than a negotiated ranking. Governments were the only group to rank capacity-building first; almost everyone else ranked safety first. The Dialogue held those priorities together.

Safety testing and local capacity grow together, so that the next divide is not who owns the biggest model but who can evaluate, adapt and leave the systems they deploy. Inclusion means every community has the means to test an adopted system, from Tibetan-language small models built in Dharamshala to public evaluation centres like Taiwan's. If we must race, let us race on safety and trust.

 

The tech world talks a lot about "AI alignment." From your perspective, what would it mean to align AI with a democratic society, not just with a company's commercial goals?

Answerability is what alignment means in a democracy. A company aligns a model with an objective; a democracy aligns a system with the people it affects. In that setting, someone must answer when a system acts, and someone must be authorised to give the answer.

Taiwan demonstrated that distinction in 2024. When deepfake scam ads surged, the Ministry of Digital Affairs sent 200,000 random text invitations. The invitation drew 1,760 valid responses, a 0.88 percent response rate. Then, 447 people took part in 44 online deliberation groups. Participants questioned experts and revised individual positions. The clearest shift was increased caution: support for mandatory algorithm disclosure fell 27.5 points to 55.6 percent after the discussion.

The assembly secured a response path, not pre-commitment to implement. Its contribution was agenda-setting, scrutiny and legitimacy alongside a Cabinet bill already moving through government. The Ministry later reported celebrity-impersonation scam ads falling from about 38,000 to 1,685 per week on regulated channels. That decline followed the Act, a fraud-reporting platform, AI-ad scanning and platform enforcement.

Alignment with a democratic society is a process people can join, not a parameter a vendor can set. That principle shapes Civic AI: 6-Pack of Care, the book I co-authored, out early next year. The book returns to the oldest democratic idea: We, the people, are truly the superintelligence.

 

 

A lot of people feel that AI is something happening to them, not with them. What would it take to flip that feeling at scale?

The assembly on deepfake scam ads felt different to the people who joined it, and that difference is the answer here. The feeling changes when people set the reward function rather than simply file feedback. The ministry sent 200,000 random text invitations. That invitation changed the relationship from subjects of a rollout to authors. My family uses a small Kami. With consent and on our own hardware, we set its reward: Sleep more, scroll less.

Nothing about that requires a ministry. Every deployment should begin with the people who will live with the system and give them real levers on Day 1: an agenda they can set, an appeal that works and an exit that costs nothing. People asked to live inside systems they cannot question will resent those systems. People invited to steer will improve them.

 

Taiwan has shown that civic technology can strengthen democracy rather than weaken it. Why have so few countries successfully replicated that model?

The tools from these stories travel better than people think. Engaged California grew from the same lineage. More than 100 Japanese municipalities now run AI sense-making on their own public deliberations. European public broadcasters are exploring the same patterns, and Team Mirai, a young party built around deliberative technology, holds 11 of 465 seats in Japan's lower house.

What travels less well is a response path. Every loop that closed in Taiwan had someone in authority providing one before the process began. Some cases came with a pledge to ratify. Others came with a commitment to listen and set the agenda. Tools without that response path change nothing. Civic muscle is like any muscle: A gym membership does not grow it, training does. Taiwan is not a model to copy-paste; it is just a demo, and demos are meant to be forked.

 

If trust becomes the defining currency of the AI era, which institutions are currently earning it, and which are losing it fastest?

Institutions earn trust as fast as they give it. After all, to give no trust is to get no trust. Earning institutions publish what they measure. They invite independent testing, as aviation and medicine do, and hand the public the pen, as Taiwan's deliberative assembly did. By contrast, institutions lose trust when they ask for trust while keeping systems inspectable.

Taiwan's arc taught me this. The president of the day’s approval stood near 9 percent in 2014; by 2020 it was above 70 percent. The difference was not better messaging. Participation was part of that recovery, alongside the movement and administration that gave the public the pen. Trust is soil you till, not oil you drill.

You will be able to see Audrey Tang live at World Summit AI in Amsterdam this October.

View ticket options to attend the Summit >>

 

What do you think of this topic?

Leave us your comments below! 👀 We read you! 👇

InspiredMinds! Community Hub

Inside the InspiredMinds! Community Hub, you’ll find deeper insights, expert perspectives, and practical discussions from the people building and deploying AI across Europe and beyond.

Join our regular LinkedIn newsletter - Global AI Dispatch!

World Summit AI global Summit series 

World Summit AI USA 

>> usa.worldsummit.ai