McKinsey's "The state of AI in 2026," released in late August, surveyed 1,719 respondents across 97 countries. One pair of numbers deserves every business owner's attention: 80% say AI has made their own work more efficient, yet only 37% believe AI has contributed to company operating profit, and just 6% call that impact significant.
In other words, the productivity dividend has landed at the individual level while the financial dividend is still stuck halfway. The gap is not that AI works poorly. It is that AI has not yet been connected to the systems and processes a company actually runs on.
## Gate one: why the saved time never reaches the income statement
The same survey notes that the top-performing 6% share one trait. They redesigned how work gets done rather than simply handing out tools.
What we see when helping enterprises implement systems looks almost identical. An administrator uses AI to cut an email from twenty minutes to five. That is genuinely good, but those fifteen minutes are scattered across the day. They show up neither in labor cost nor in output. What the financial statements can see is an entire process redrawn: a quote that used to mean a salesperson looking up prices, sending mail, and waiting for a reply becomes the system assembling the order, AI drafting the terms, a manager approving online, and the result written straight back into the ERP.
The difference is that the first is a tool and the second is a process. And the moment a process moves, it hits a system boundary. Whose data, which fields, what permissions. That is the part AI cannot resolve on its own.
The survey holds one more number worth noting. Thirty-two percent of respondents say that because AI-assisted development tools now exist, they have decided to build in-house instead of buying packaged software. For a systems integration firm like ours, that is an honest reminder. The barrier to building has genuinely fallen. The barrier to data consistency, permission governance, and long-term operation after you build has not fallen at all.
## Gate two: the interface is standardizing, but what to expose is still a human call
On 17 August, the Agent2Agent (A2A) protocol initiated by Google formally joined the Agentic AI Foundation under the Linux Foundation, placing it under the same governing body as MCP (Model Context Protocol), which Anthropic donated. The division of labor is clear. MCP handles AI applications connecting to tools and data. A2A handles agents discovering one another, handing off tasks, and returning results.
For enterprises, the practical meaning is that the era of rebuilding a bespoke interface for every AI vendor is ending. The integration layer itself is standardizing.
But standardization answers how to connect, not what to connect. Before wrapping your inventory system as an MCP interface, someone still has to answer which tables get exposed, whether amount fields are visible, which accounts may call it, and where the call logs live and for how long. Not one of those is a technical question. They are all governance questions.
For small and mid-sized businesses in Taiwan, our advice usually runs the other way around. Rather than rushing to build a model, wrap the systems already in daily use, the ERP, the inventory system, the support ticket queue, as controlled and auditable interfaces. The return on that step is far clearer than buying another AI product.
## Gate three: the attackers are already automated
Governance sounds like paperwork right up until it becomes an incident.
In July this year, a suspected foreign operation targeted Taiwanese government agencies with twelve waves of attacks over four days, compromising 85 employee accounts, obtaining more than 2,564 personnel records, and moving laterally into internal systems. The security firm that disclosed it reported that the attack framework orchestrated multiple autonomous AI agents, adjusted resource allocation based on how each round went, and would even research new techniques online when an attempt failed. Taiwan's Administration for Cyber Security responded in mid-August that anomalous activity had been detected in July and that the affected units had completed their response.
Over the same period, IBM's "Cost of a Data Breach 2026" offered a companion set of figures. The global average breach cost rose to 5 million US dollars, up 12% year on year. The share of incidents involving ungoverned AI doubled from 20% to 43%, adding roughly 670,000 dollars on average. More than two-thirds of affected organizations had no policy at all governing employees' unsanctioned AI use. Among organizations that suffered AI-model-related attacks, 92% had not properly restricted system access.
Put those two together and the conclusion is blunt. The attacking side now moves at machine speed. If the defending side is still running on manual tickets and a quarterly asset review, the lag is structural, and no amount of overtime closes it.
In practice, we advise treating an AI agent as a privileged account: it needs an identity, a defined permission scope, an access log, and a way to be switched off. Those requirements are already written into the asset inventory and access control clauses of ISO 27001. What used to be inventoried were people and servers. Now there is one more class.
## The compliance clocks are running together
Three things are happening at once.
The EU AI Act entered general application on 2 August, bringing transparency obligations and the penalty regime for general-purpose AI into force, while high-risk system obligations have been deferred to 2027 and 2028. It governs what is placed on the EU market, so Taiwanese firms doing exports, contract manufacturing, or SaaS fall within scope all the same.
Taiwan's Basic Act on Artificial Intelligence passed its third reading in December 2025. Its twenty articles set out principles including privacy protection and data governance, security, transparency and explainability, and accountability, and require an AI risk classification framework that individual competent authorities will then use to write their own rules.
Amendments to the Personal Data Protection Act were promulgated in November 2025, with the effective date to be set by the Executive Yuan. Once in force, non-government entities suffering a personal data incident above a defined threshold carry a notification duty, and entities above a certain size must establish a personal data file security maintenance plan covering a data inventory, designated personnel, annual risk assessment, and internal audit.
All three laws are really asking one question. Can you state which AI systems exist in your company, what data they consume, who may use them, and how an incident gets reported?
The good news is that one document can answer all of it. A complete AI system inventory paired with a personal data flow map serves the security maintenance plan under the data protection law, the risk classification under the AI basic act, and the supply chain questionnaire your European customer sends over.
## Where Taiwanese SMEs are actually stuck
Global money is pouring into AI. In late July, Gartner raised its 2026 worldwide IT spending forecast to 6.37 trillion US dollars, up 14.2% year on year. In August it projected that spending on AI-optimized IaaS would grow 96% this year to roughly 42 billion dollars.
Yet a survey conducted by ITRI for Taiwan's Small and Medium Enterprise and Startup Administration found that the biggest obstacle to AI adoption among Taiwanese SMEs is neither money nor technology. It is having no clearly defined use case, cited by 63.9%. Next come not understanding AI technology at 26.8%, high implementation cost at 25.5%, and talent shortage at 21.3%. Deloitte's research, separately, found only about 21% of organizations have mature governance for the risks of AI agents.
Read together, these figures describe a familiar predicament. You know you should act, you do not know where to start, and once you start you are not sure whether something will go wrong.
## Three opening moves for business owners
If your company is at this stage, we suggest three things that do not require a large budget.
- Inventory rather than procure. List the AI tools actually in use across the company, including the ones employees installed themselves, and what data each one touches. That list is usually longer than expected.
- Pick a process, not a tool. Find work that is high-frequency, rule-bound, and already digitized, redraw the whole sequence once, and only then decide where AI belongs in it.
- Make existing systems safe to call. Instead of rushing to build a model, turn the systems you already have into interfaces with permissions and logs. The standards have converged, so this investment will not be wasted.
AI has lowered the cost of producing a first version. It has not lowered the difficulty of keeping a system running reliably for years. That remains our position as a systems integration and digital transformation partner: what we deliver is not only working features, but the security, maintainability, and audit trail that governance standards such as ISO 27001 require. Because what the financial statements actually recognize was never the day a system went live, but every month it kept running.