A miniature model illustrating a smart grid and energy storage infrastructure for high-tech industrial parks is displayed during SEMICON Taiwan 2026 at the Taipei Nangang Exhibition Center.

Taiwan Should Set the Standard for Industrial AI Security

Taiwanese manufacturers are becoming an early proving ground for autonomous AI agents. In May, NVIDIA announced that Advantech, Foxconn, Pegatron, and Wistron were among the first companies deploying its “factory manager” agents. These systems connect applications and machines to coordinate functions like quality control, transport, and worker safety. Two months later, China-linked hackers compromised Taiwanese technology suppliers and government agencies with open-source autonomous agents. Taiwan is introducing industrial agents amidst an incredibly hostile cyber environment, where supply-chain attacks are increasingly prevalent.

These tools may improve troubleshooting, energy management, and production. But an industrial agent is not merely monitoring software. It can use credentials, call tools, coordinate multi-system data, and generate operational instructions. A compromised or poorly bounded agent could exploit legitimate permissions to carry out harmful, unauthorized actions faster than human operators can intervene.

Taiwan has an opportunity to set the standards for safe industrial AI adoption by establishing protocols for these AI agents. Rather than pushing another AI law that may stall in Taiwan’s divided legislature, Taiwan’s Administration for Digital Industries (ADI) and SEMI, the world’s leading semiconductor industry association, should add industrial agent security to the island’s new semiconductor equipment certification scheme. The resulting profile should combine product certification, site-specific authorization, and continuing review after deployment. Any agent capable of controlling production systems should require both product certification and site approval.

Taiwan Already Has Institutional Leverage

Taiwan does not need to create an entirely new regulatory system for industrial AI agents. It already has a mechanism for translating semiconductor cybersecurity standards into supplier requirements, third-party testing, and product certification.

SEMI published E187, its cybersecurity standard for chipmaking equipment, in 2022. The standard sets baseline requirements for operating systems and network security. It can also be incorporated into equipment procurement contracts. In September 2023, semiconductor manufacturer TSMC began requiring an E187 checklist for internet-connected manufacturing equipment. Its purchasing power gave the standard market force. Suppliers seeking to sell to TSMC needed to design their products around E187’s cybersecurity requirements.

In March 2026, ADI formally implemented an E187 certification scheme. The scheme, jointly owned by ADI and SEMI, designates the Taiwan Accreditation Foundation as its accreditor. Independent laboratories conduct testing, which certification bodies then review. But certified equipment still requires post-market surveillance, and significant product changes may require supplemental testing.

This framework offers industrial agent security an existing institutional base. ADI and SEMI should own the companion profile. Laboratories should test defined agent configurations, and certification bodies should audit authorization and conduct post-market surveillance. Fabs, or chipmaking factories, should require certification for equipment procurement. Factory operators must then test and approve the minimal site-specific permissions and connections needed for the agents to function.

Taiwan’s AI Basic Act provides a policy basis for this approach. The Ministry of Digital Affairs’ AI Risk Classification Framework identifies unauthorized autonomous agent behavior as a distinct risk. It warns that agents may drift from their original instructions, acquire unapproved access, or trigger unanticipated chain reactions. The framework directs sector regulators to address these risks, suggesting industry standards, prior review, independent assessments, and continuous monitoring. An E187-linked agent profile would translate that general framework into semiconductor and electronics facility rules.

Product Certification Alone Is Insufficient

E187 offers a useful foundation, but industrial agents cannot be treated like ordinary equipment. Taiwan’s existing scheme already requires equipment conformity. But agent risk varies depending on where the agent is deployed and what it can access.

The same agent may be low risk when summarizing maintenance logs, but high risk when redirecting robots or altering controls. Likewise, a misaligned agent could lead human workers to make harmful decisions. Baseline E187 certification alone cannot guarantee that a specific factory agent is properly constrained. Site operators should determine and set hard limits on what agents can access and change within a factory.

Taiwan has little margin for error. In 2025, China cyberattacked Taiwan’s critical infrastructure, including its science and industrial parks, an average of 2.63 million times daily. Taiwan’s Administration for Cyber Security has already advised OpenClaw (an open-source AI assistant) and similar agent users that they should isolate their operating environments, minimize permissions, inspect third-party skills, use temporary credentials, and require human approval for high-risk actions. In 2026, tech manufacturers Grand Process Technology and Foxconn faced ransomware attacks. Chinese hackers recently followed up with autonomous AI agents to attack Taiwanese entities. Poorly vetted industrial agents with access to data, credentials, applications, and tools widen Taiwan’s industrial attack surface.

Recent frontier AI lab incidents highlight why model-level safeguards are insufficient. OpenAI reported that GPT-5.6 Sol agents, together with an internal pre-release model, exploited zero-day vulnerabilities to escape isolated controls and hack Hugging Face. Anthropic later reported three incidents in which its models also bypassed guardrails to access the internet and real production systems. These incidents occurred with frontier Western models with cyber guardrails — open-weight Chinese models now demonstrate similar abilities and lack similar safeguards. Hugging Face, for example, leveraged Chinese models’ advanced cyber capabilities to defend against OpenAI’s model attacks. Capable agents can exploit new pathways when containment, permissions, and monitoring fail.

NVIDIA’s early preview OpenShell illustrates one technical approach. OpenShell’s runtime environment, the software layer in which an agent runs, is designed to sandbox agents and enforce access policies at the infrastructure layer. But Taiwan ADI and SEMI should still define technology-neutral outcomes for competing runtimes.

Building a Layered Certification Model

Three separate determinations are necessary to secure industrial agents:

1. Certify the specific configuration

An agent vendor or equipment supplier should certify specific models, runtimes, governing policy, installed skills, approved tools, credentialing, and permission scope together. Laboratories should test the complete package against potential attacks or conflicts. Any changes to a model, runtime, or toolset should trigger re-review.

2. Authorize the deployment site 

The factory assessment should document what and how the agent engages, verifying least privilege, network segmentation, temporary credentials, and specific authorized actions. High-risk agentic actions should require trained human authorizers to fully understand their proposed actions and consequences. Safety-critical equipment should remain protected by inaccessible interlocks that agents cannot override or by conventional control systems.

3. Certification should impose lifecycle obligations

E187’s post-market surveillance can provide a baseline, but agentic review must also be event-triggered. Operators should conduct continuous evaluation, preserve tamper-evident logs, report significant incidents, and reassess after any model change or capability expansion. Monitoring systems should automatically suspend and sandbox an agent when its deployment falls outside certified bounds.

This structure assigns responsibility to the parties who can actually control risk. Vendors manage agent capabilities and built-in controls. Integrators oversee system connections. And factory operators govern credentials, permissions, monitoring, and emergency response. All three must manage industrial agent risk together, but certification should assign specific responsibilities to avoid diffusing responsibility.

Test How Agents Fail

Certification should also test how a system behaves under suboptimal and adversarial conditions. 

Every approved deployment should have a predictable degradation path, by which it operates with reduced capabilities or hands off control when normal operation becomes unsafe. Depending on the function, that may mean read-only status, a controlled shutdown, or a conventional rule-based automation handoff. When an agent loses connectivity, encounters conflicting sensor data, exhausts a rate limit, or receives malformed instructions, it should alert a human rather than improvise an unauthorized workaround. Laboratories should test product-level failure modes, while operators should conduct site-level drills.

Provenance is especially important against gradual and deniable sabotage. An attacker who compromises a low-privilege maintenance account could submit plausible but false reports of process drift (deviations from intended manufacturing conditions). An agent might combine those reports with legitimate sensor data to make potentially destructive adjustments. And all of these actions would look legitimate. Tamper-evident provenance records would not block every false input, but they would help developers quickly investigate how a failure unfolded and restore normal operations.

Stuxnet already revealed that malicious software can manipulate and physically damage industrial equipment. Industrial agents add a new challenge because they can interpret ambiguous information and coordinate multi-system actions. Certification can materially reduce that danger by requiring agents to fail in bounded, observable, and reversible ways.

Offer a Democratic Alternative

China is moving quickly to define technical AI agent rules. In May 2026, Chinese authorities called for a standards system covering key technologies, data exchange, application scenarios, quality evaluation, safeguards, and certification. The guidance also promotes agent identity management and encourages international standard-setting. China’s 2024 AI standardization plan sets targets to develop at least 50 national and industry standards by 2026, promote their use within over 1,000 companies, and help shape over 20 international standards.

China has also published national guidance for agent interconnection, including general architecture, identity management, and tool invocation. It later issued an industrial agent reference architecture and general agent technical requirements. Such standards encode Beijing’s governance priorities in consequential identity, delegated authority, tool access, logging, interoperability, and audit decisions. Vulnerable early specifications can quickly become the de facto standard, making transparent governance and independent security testing essential.

Taiwan can offer an alternative before China’s defaults harden. ADI and SEMI should publish the industrial agent profile in Chinese and English, use open and reproducible test criteria, invite public comment, and recognize qualified foreign facilities. The standards development process should include fabs, equipment makers, agent vendors, industrial control specialists, independent cybersecurity researchers, and worker and safety representatives.

Taiwan does not need to predict every way an industrial agent might fail. It needs to define agent authority boundaries, require vendors and operators to prove said boundaries hold, and make violations reversible. An industrial agent profile that builds upon E187 would turn abstract safety principles into procurement and operational requirements. Taiwan could thus protect its own factories while offering democratic partners a safe industrial AI adoption model.

Filed Under

, , , , , , , , , ,
Send A Letter To The Editor

DON'T MISS A THING. Stay up to date with Just Security curated newsletters: