PRLive Experiment on the Wall牆上的現場實驗壁の上のライブ実験 0%
Audrey Tang 唐鳳
Trust by Design信任始於設計信頼を、設計する Keynote + Q&A演講+問答講演+Q&A

FDC2026·FPoS Developers ConferenceFPoS 開發者大會FPoS開発者会議·Tokyo International Forum東京國際論壇東京国際フォーラム

Trust by Design信任始於設計信頼を、設計する

Answering Doubt, Not Demanding Belief回應疑問,而非要求相信疑いに答える。信じよとは言わない

A 40-minute keynote and complete Q&A on provenance, the pause, accountability, public code, agentic identity and democratic repair — with live machine translation checked in public.四十分鐘的主題演講與完整問答:溯源、暫停、課責、公共程式碼、代理身分與民主修復——現場的機器翻譯,也在眾目之下接受檢驗。来歴、一時停止、説明責任、公共のコード、エージェントの身元、民主主義の修復をめぐる40分の基調講演と完全版Q&A——ライブ機械翻訳の検証も、公開の場で。

Audrey Tang 唐鳳 Keynote + complete Q&A主題演講+完整問答基調講演+完全版Q&A 12:30 JST · Hall B7

Hello everyone. Really happy to be here. Thank you, Fukuda-san and the FDC2026 organising committee, for the invitation.

大家好,很高興來到這裡。謝謝福田先生與 FDC2026 籌備委員會的邀請。

皆さん、こんにちは。ここに来られて本当にうれしいです。福田さん、そしてFDC2026組織委員会の皆さん、お招きありがとうございます。

PR

Live Experiment on the Wall牆上的現場實驗壁の上のライブ実験

#

We are seeing Japanese and kanji appear on the wall, rendered by a live translation model rather than a person. So, for the next 40 minutes, we will trust a machine to get it right in public.

We will also check its work as we go. If it makes a mistake — and it probably will — we will not hide it. We can correct it in public, leave the record visible and keep going. That is a fair preview of this talk. Trust is earned when a system lets everyone inspect its work. That is trust by design.

我們看到牆上浮現的日文與漢字,出自即時翻譯模型,而非人工聽打。所以接下來四十分鐘,我們將公開信任一部機器,看它能不能把話說對。

我們也會邊講邊檢查它的表現。如果它出錯——多半真的會——我們不遮掩:當場更正、保留紀錄、繼續前進。這正是今天演講的預告:當系統讓每個人都能檢視它的工作,信任才能掙得。這就是「信任始於設計」。

いま壁に映し出されている日本語と漢字は、人ではなく、ライブ翻訳モデルが描いています。これからの40分間、私たちは機械を公開の場で信頼し、正しく訳せるかを見守ることになります。

進めながら、その仕事ぶりも一緒に確かめていきます。もし間違えたら——おそらく間違えるでしょう——隠しません。公開の場で訂正し、記録を見えるまま残して、先へ進みます。それが今日の講演の予告編です。システムが誰にでも仕事を検分させるとき、信頼は獲得されます。それが「信頼を、設計する」ということです。

01

Optimism as Work Order樂觀是一張工單楽観という作業指示

#

Let the experiment on the wall run while we revisit a much earlier one. A year and a half ago, Fukuda-san hosted two seniors from our field on this stage: the late Professor David Farber, whom many called a grandfather of the internet, and Professor Ted Nelson, who gave us the word hypertext more than 60 years ago.

Fukuda-san told me that Professor Nelson called bringing trust back to the internet the most important task of our time — and said he was optimistic because human beings would solve it.

That sentence moves me because Professor Nelson is not asking us to invent something entirely new. He is asking us to finish something old. That is not optimism as reassurance. It is optimism as a work order.

讓牆上的實驗繼續跑,我們先回看一場更早的實驗。一年半前,福田先生在這座舞台上,接待過我們這一行的兩位前輩:已故的大衛・法伯教授——許多人稱他為「網際網路的祖父」——以及泰德・尼爾森教授,六十多年前,「超文本」這個詞就是他創造的

福田先生告訴我,尼爾森教授把「把信任帶回網際網路」稱為我們這個時代最重要的任務——並說他很樂觀,因為人類終將解決它。

這句話打動我,因為尼爾森教授並沒有要我們發明全新的東西。他要我們把一件舊的做完。那份樂觀是一張開給我們的工單,不是拿來安撫人心的。

壁の実験は走らせたまま、もっと昔の実験を振り返りましょう。1年半前、福田さんはこの舞台に、私たちの分野の二人の大先輩を迎えました。多くの人が「インターネットの祖父」と呼んだ、故デビッド・ファーバー教授。そして60年以上前に「ハイパーテキスト」という言葉を生んだ、テッド・ネルソン教授です。

福田さんによれば、ネルソン教授は「インターネットに信頼を取り戻すこと」を現代最重要の課題と呼び——そして「人間が必ず解決するから、楽観している」と語ったそうです。

この言葉に胸を打たれるのは、ネルソン教授が求めているのが、まったく新しい発明ではないからです。古い仕事を仕上げることです。それは安心のための楽観ではありません。作業指示としての楽観です。

02

Part We Skipped被跳過的那部分置き去りにした部分

#

When Professor Nelson designed Project Xanadu, starting in 1960, every link ran in two directions. If my document pointed to yours, yours knew about mine. Every quotation stayed visibly connected to the document it came from. He called this transclusion. A sentence could travel anywhere, and its origin travelled with it. Provenance was not a feature to be added later. Provenance was the architecture.

The web we shipped is a marvel, but it kept only half of Professor Nelson's design. Links run one way. A quotation forgets its source the moment we copy it. We built the greatest copying machine in history and left out the part that remembers origin and responsibility. The internet learned to copy. It did not learn to account.

尼爾森教授自 1960 年起設計「仙那度計畫」(Project Xanadu)時,每一條連結都是雙向的:我的文件指向你的,你的文件就知道我的存在;每一段引文,都與出處文件保持看得見的連繫。他稱之為「嵌入引用」(transclusion)。一句話可以旅行到任何地方,出身也一路隨行。溯源不是日後追加的功能;溯源就是架構本身。

我們實際出貨的全球資訊網固然了不起,卻只保留了尼爾森教授設計的一半:連結是單向的;引文一經複製,馬上忘記出處。我們造出史上最強大的複製機器,卻漏掉了記得出身與責任的那個零件。網際網路學會了複製,卻沒有學會交代。

ネルソン教授が1960年から設計した「ザナドゥ計画」(Project Xanadu)では、すべてのリンクが双方向でした。私の文書があなたの文書を指せば、あなたの側も私の存在を知る。どの引用も、出典の文書と目に見えてつながったままでした。彼はこれを「トランスクルージョン」と呼びました。一つの文はどこへでも旅し、出自もともに旅をする。来歴は後付けの機能ではなく、来歴こそがアーキテクチャでした。

私たちが世に出したウェブは驚異ですが、ネルソン教授の設計の半分しか残しませんでした。リンクは一方通行。引用はコピーした瞬間に出典を忘れます。史上最強のコピー機械を作りながら、出自と責任を覚えておく部品を置き忘れたのです。インターネットはコピーを覚えました。しかし、説明することを覚えませんでした。

Trust by design is therefore not a new slogan. It is the oldest unfinished feature of the internet. This conference can help close a 60-year-old work order. The task is not to repair a fallen paradise. It is to ship the part we skipped.

所以,「信任始於設計」說的是網際網路最古老的未完成功能,不是什麼新口號。這場大會,可以一起結案這張六十年的工單。要補做的是當年跳過的那部分,不是修復失落的樂園。

だから「信頼を、設計する」は新しいスローガンではありません。インターネット最古の、未完成の機能です。このカンファレンスでなら、60年もののワークオーダーを一緒にクローズできます。課題は失われた楽園の修復ではなく、置き去りにした部分を、いま出荷することです。

03

Forking the GovernmentFork 政府政府をフォークする

#

I should tell you why this work belongs to me, too.

I did not enter public life through an election or an examination. I entered through a text editor — Vim, to be precise. I spent my 20s and 30s in free software, and later in Taiwan's civic-tech community, g0v: gov-zero. Whenever a government website was hard to use, volunteers rebuilt it, kept the same domain name and changed the letter o to a 0. We forked the government and published the fork as a standing invitation: merge us back. In 2016, instead of suing us for the forks, the government hired us.

I joined the Cabinet as digital minister and set my terms in writing. Every meeting I chaired, every lobbyist who visited and every interview I gave would be transcribed and published in the public domain. For eight years, anyone could read what I said, to whom and why. People call this radical transparency. I think of it as ordinary accountability, applied to myself first. If we ask the public to be legible to the state, the state must first be legible to the public. These days I serve as Taiwan's cyber ambassador, and the archive at archive.tw is still open.

It is the same design argument, practised on my own calendar. Trust is not something officials request. It is something systems demonstrate. The same logic now shapes Taiwan's digital credential wallet: public money, public code. Government, companies, schools and civil-society groups can run the same open standards, so nobody is forced to trust a new counterparty.

我也該交代,這件工作為什麼也算在我頭上。

我進入公共生活,靠的是一個文字編輯器——精確地說,是 Vim。不是選舉,也不是考試。我的二十幾歲和三十幾歲,先在自由軟體圈度過,後來投入臺灣的公民科技社群 g0v(gov-zero,零時政府)。只要哪個政府網站難用,志工就重做一個:網域名稱不變,把字母 o 換成數字 0。我們把政府 fork 出來,並把這個分叉當成常設的邀請函:歡迎把我們 merge 回去。2016 年,政府沒有為這些分叉告我們,反而聘了我們。

我以數位政委身分入閣,並把條件白紙黑字寫下:凡我主持的會議、來訪的遊說者、我接受的採訪,一律逐字紀錄,釋出到公共領域。八年來,任何人都能查到我說了什麼、對誰說、為什麼說。人們稱之為「極端透明」;我認為那只是普通的課責,先套用在自己身上。如果我們要求民眾對國家可讀,國家就必須先對民眾可讀。如今我擔任臺灣的數位治理大使,archive.tw 的檔案庫仍然開放。

這是同一個設計論證,只是先在我自己的行事曆上實踐:信任得靠系統做出來給人看,不是官員開口要得來的。同樣的邏輯,如今也塑造著臺灣的數位憑證皮夾:公共出資,公共程式。政府、企業、學校與公民團體都能跑同一套開放標準,沒有人被迫信任新的對造。

この仕事がなぜ私自身のものでもあるのか、お話しすべきでしょう。

私が公共の世界に入ったのは、選挙でも試験でもなく、テキストエディタ経由でした——正確に言えば、Vimです。20代と30代は自由ソフトウェアの世界で、のちに台湾のシビックテック・コミュニティ「g0v(ガブゼロ、零時政府)」で過ごしました。政府のウェブサイトが使いにくければ、有志が作り直します。ドメイン名はそのまま、アルファベットのoを数字の0に替えて。私たちは政府をフォークし、そのフォークを常設の招待状として公開しました——「どうぞ私たちをマージし返してください」と。2016年、政府はフォークを訴える代わりに、私たちを雇いました。

私はデジタル担当閣僚として入閣し、条件を書面にしました。私が主宰するすべての会議、訪ねてくるすべてのロビイスト、受けるすべての取材を、逐語記録してパブリックドメインで公開すること。8年間、私が何を、誰に、なぜ話したかは、誰でも読めました。人はこれを「ラディカルな透明性」と呼びます。私にとっては、まず自分に適用した、ごく普通の説明責任です。市民に国家への可読性を求めるなら、まず国家が市民に可読でなければなりません。現在、私は台湾のサイバー大使を務めており、archive.tw のアーカイブはいまも開いています。

これは同じ設計上の主張を、まず自分のカレンダーで実践したものです。信頼とは、役人が求めるものではなく、システムが実証するものです。同じ論理がいま、台湾のデジタル・クレデンシャル・ウォレットを形づくっています——公共の資金、公共のコード。政府も、企業も、学校も、市民団体も、同じオープン標準を走らせることができるので、誰も新しい相手方を信頼するよう強いられません。

04

Authentication. Authenticity. Accountability.驗證。真確。課責。認証。真正性。説明責任。

#

Now, what would it mean to design for trust?

Fukuda-san frames digital trust as two questions, and they are the right first two. Authentication: with whom am I actually communicating? Authenticity: is this really what they said, unaltered? Cryptography answers both questions well. Japan has mature infrastructure for both, anchored in a card that roughly eight in 10 people here now hold.

I want to add a third question, and it is the question my country taught me. Accountability: When the system itself is wrong, who answers? Who can question it? Who can correct it? How fast?

Authentication proves who. Authenticity proves what. Accountability proves whether power can be seen, questioned and corrected. That is the sharp distinction. A signature can be mathematically perfect and still sign a lie. A credential can be cryptographically flawless and still serve an institution nobody believes. Authentication and authenticity can establish a transaction. They cannot make an institution trustworthy. Accountability lives in relationships. Trust by design means designing for all three. If accountability is missing, the system may verify everyone except itself. That is not trust infrastructure. It is one-way verification.

那麼,為信任而設計,究竟是什麼意思?

福田先生把數位信任整理成兩個問題,而它們正是該先問的兩個。驗證(Authentication):我實際在跟誰通訊?真確(Authenticity):這真的是對方說的話、一字未改嗎?密碼學把這兩題都答得很好。日本在這兩方面已有成熟的基礎設施,錨定在一張如今大約每十人有八人持有的卡片上。

我想補上第三個問題——這是我的國家教會我的問題。課責(Accountability):當系統本身出錯,誰來回應?誰能質問它?誰能更正它?多快?

驗證證明「是誰」,真確證明「是什麼」,課責證明「權力能不能被看見、被質問、被更正」。分野就在這裡。一枚簽章可以在數學上完美,仍然簽下謊言;一張憑證可以在密碼學上無瑕,仍然服務一個沒人相信的機構。驗證與真確可以成立一筆交易,卻無法讓機構值得信任。課責存在於關係之中。信任始於設計,意思是三者都要設計。少了課責,系統可能驗證了所有人,唯獨不驗證自己。那不是信任基礎設施,那是單向的查驗。

では、信頼のために設計するとは、どういうことでしょうか。

福田さんはデジタルの信頼を二つの問いに整理されました。最初に問うべき二つとして、まさに正しい問いです。認証——私は実際、誰と通信しているのか。真正性——これは本当に、改変されていない本人の言葉なのか。暗号技術はどちらにもよく答えます。日本には両方の成熟した基盤があり、いまや約10人に8人が持つカードに錨を下ろしています。

そこに三つ目の問いを加えたいのです。私の国が私に教えてくれた問いです。説明責任(アカウンタビリティ)——システムそのものが間違っているとき、誰が答えるのか。誰がそれを問いただせるのか。誰が正せるのか。どれだけ速く。

認証は「誰か」を証明します。真正性は「何か」を証明します。説明責任は「権力が見られ、問われ、正されうるか」を証明します。ここが鋭い分かれ目です。署名は数学的に完璧なまま、嘘に署名できます。クレデンシャルは暗号学的に無欠のまま、誰も信じていない機関に仕えることができます。認証と真正性は取引を成立させられますが、機関を信頼に値するものにはできません。説明責任は、関係の中に宿ります。「信頼を、設計する」とは、この三つすべてを設計することです。説明責任を欠けば、システムは自分以外の全員を検証するかもしれません。それは信頼のインフラではなく、一方通行の検証です。

Authentication驗證認証

proves who證明是誰「誰か」を証明

With whom am I actually communicating?我實際在跟誰通訊?私は実際、誰と通信しているのか。

Authenticity真確真正性

proves what證明是什麼「何か」を証明

Is this really what they said, unaltered?這真的是對方所說、一字未改嗎?これは本当に、改変のない本人の言葉か。

Accountability課責説明責任

proves whether power can be corrected證明權力能否被更正権力を正せるかを証明

When the system itself is wrong — who answers, and how fast?當系統本身出錯——誰來回應?多快?システム自身が誤るとき——誰が、どれほど速く答えるのか。

05

Scams at Scale規模化的詐騙スケールする詐欺

#

Consider the fraud pattern every bank in this room already manages. A victim of an investment scam walks into a branch and sends the money in person. The payment is perfectly signed and perfectly authentic. The mathematics does its job completely, and the fraud succeeds anyway: the signature is authentic, but the consent is not. No key length or post-quantum cryptography can substitute for reciprocal trust. The missing pause, human review and clear route back are accountability.

The third question is mandatory because fraud does not merely bypass trust. It turns trust against the person who offered it. That is the trust failure this whole region shares.

Japan's police counted more than 140 billion yen taken by special fraud last year. In a separate category, social-media investment scams caused more than 120 billion yen in losses. Thousands of cases began with advertisements. Many wore a famous face that never consented to be there. Behind each number is a person who did exactly what we ask people to do online. They saw a trusted face. They believed it. The scam did not defeat their scepticism. It borrowed their trust and never paid it back.

想想在座每家銀行都在處理的詐騙模式:投資詐騙的受害者親自走進分行,親手把錢匯出去。這筆付款簽章完美、真確無誤,數學把分內事做好做滿,詐騙照樣得逞——簽章是真的,同意卻不是。再長的金鑰、再新的後量子密碼學,都替代不了互相的信任。缺席的那個暫停、人工複核、清楚的回頭路,正是課責。

第三個問題之所以非問不可,是因為詐騙不只繞過信任,更把信任反過來對付付出信任的人。這正是整個區域共同面對的信任失靈。

日本警方統計,去年「特殊詐欺」奪走的金額超過 1,400 億日圓;另一類社群媒體投資詐騙,造成的損失超過 1,200 億日圓。數千件案子從廣告開始,許多還掛著一張從未同意出現在那裡的名人臉孔。每個數字背後,都是一個完全照著我們的網路守則行事的人:看見值得信任的面孔,於是相信。詐騙沒有擊敗他們的戒心;它借走了他們的信任,永不歸還。

この会場のどの銀行も、すでに向き合っている詐欺のパターンを考えてみてください。投資詐欺の被害者が支店に足を運び、自らの手で送金します。その支払いは完璧に署名され、完璧に真正です。数学は仕事を完全に果たし、それでも詐欺は成立します。署名は本物でも、同意は本物ではないからです。鍵長も耐量子暗号も、相互の信頼の代わりにはなれません。欠けていた一時停止、人による確認、明確な引き返し道——それが説明責任です。

三つ目の問いが必須なのは、詐欺が信頼を素通りするだけではないからです。詐欺は信頼を、それを差し出した本人に向けて振り回します。それこそ、この地域全体が共有する信頼の破綻です。

日本の警察は昨年、特殊詐欺による被害額を1,400億円超と数えました。別の分類では、SNS型投資詐欺の損失が1,200億円を超えます。数千の事件が広告から始まりました。その多くは、そこに出ることに同意した覚えのない、有名人の顔をまとっていました。数字の一つひとつの背後には、私たちがオンラインで「こうしてください」と頼んでいる通りに行動した人がいます。信頼できる顔を見て、信じた。詐欺は彼らの懐疑心を打ち負かしたのではありません。彼らの信頼を借りて、返さなかったのです。

¥140bn+1,400 億+1,400億円超special fraud, Japan, last year日本特殊詐欺・去年(日圓)特殊詐欺・昨年
¥120bn+1,200 億+1,200億円超social-media investment scams社群媒體投資詐騙(日圓)SNS型投資詐欺

Taiwan knows the same losses. For years, the same synthetic faces sold the same fake funds. When I speak about trust infrastructure, I am not describing a customer-experience improvement. Fraud is counterfeit trust at scale. Counterfeit trust cannot be answered by telling people to stop trusting. A society that stops trusting does not become safe. It becomes poor, lonely and still defrauded.

臺灣同樣熟悉這些損失。多年來,同一批合成臉孔,兜售同一批假基金。所以當我談「信任基礎設施」,講的不是顧客體驗的優化。詐騙,是規模化的偽造信任。對付偽造的信任,不能靠勸大家別再信任。一個停止信任的社會不會變安全,只會變得貧窮、孤單,而且照樣被騙。

台湾も同じ損失を知っています。何年ものあいだ、同じ合成された顔が、同じ偽ファンドを売りつけてきました。私が「信頼のインフラ」を語るとき、それは顧客体験の改善の話ではありません。詐欺とは、スケールした偽造信頼です。偽造された信頼に、「もう信じるな」と説くことでは答えられません。信じることをやめた社会は、安全にはなりません。貧しく、孤独になり、それでも騙されるのです。

06

Mirror Question鏡像提問鏡写しの問い

#

Here is the mirror question Taiwan starts from. Most identity systems ask: How can the institution verify the person? Systems that earn belief also ask: How can the person verify the institution? Any system that demands belief before inspection has reversed the relationship. And inspection must be legible: if a system is trustworthy but ordinary people cannot understand it, only the people who do not need an explanation will trust it.

臺灣的起點,是一道鏡像提問。多數身分系統問的是:機構如何驗證個人?而贏得相信的系統,還會多問一句:個人如何驗證機構?凡是先要求相信、才准檢視的系統,都把關係弄反了。而且檢視必須看得懂:如果系統值得信任、普通人卻無法理解,那麼只有不需要解釋的人才會信任它。

台湾の出発点は、鏡写しの問いです。たいていのアイデンティティ・システムはこう問います——機関はどうやって個人を確認するか。信じてもらえるシステムは、こうも問います——個人はどうやって機関を確認できるか。検分より先に信じることを求めるシステムは、関係が逆さまです。しかも検分は、読めるものでなければなりません。システムが信頼に値しても、普通の人に理解できなければ、説明の要らない人しかそれを信頼しないのです。

Every design decision is a deposit into that account, or a withdrawal from it. People in this hall know compound interest better than most audiences on earth. Trust compounds the same way. Small, verifiable, boring deposits, made on schedule, for years. And like any account, one enormous withdrawal can empty it overnight. The institutions we believe in are simply the ones with the longest unbroken deposit history.

每個設計決定,不是往這個帳戶存款,就是從中提款。這個廳裡的各位,比世上大多數聽眾都懂複利。信任也一樣會複利:小額、可驗證、無聊的存款,準時入帳,年復一年。而它也像任何帳戶——一筆巨額提領,就能一夜清空。我們相信的機構,不過是存款紀錄最長、從未中斷的那些。

あらゆる設計上の決定は、この口座への預け入れか、引き出しです。この会場の皆さんは、世界のどの聴衆よりも複利をご存じでしょう。信頼も同じように複利で増えます。小さく、検証でき、退屈な預け入れを、予定どおり、何年も。そして口座の常として、一度の巨額の引き出しが一晩で残高を空にします。私たちが信じている機関とは、要するに、途切れない預け入れ履歴がいちばん長い機関のことなのです。

D1grants the power to inspect賦予檢視的權力検分する力を授ける

Data Soil: Trust the Public資料土壤:信任大眾データの土壌:公衆を信じる

#

I want to offer six lightning demos of that principle from Taiwan. Taiwan is not a model to cut and paste; it is an inspirational demo. Developers know what a demo is for. We inspect it, take what compiles in our own environment, file bug reports and keep the right to reject what does not fit. The same discipline belongs in public policy.

Trust the public with the data.

In February 2020, at the start of COVID-19, Taiwan had a mask shortage and a panic to match. A civic technologist named Howard Wu, in the southern city of Tainan, built a small map showing which stores still had masks. He built it because his chat groups were drowning in rumours. My job in government was not to build a better map. My job was to persuade the government to open its live pharmacy inventory feed, refreshed every 30 seconds. Howard's map, and more than a hundred other volunteer tools, could then draw from one trustworthy source.

Notice the direction of trust. The state did not ask the public to trust official announcements. The state trusted the public with the raw data, and the public built the interfaces. No algorithm decided who deserved a mask. The queue was fair because the information itself was public. When a government shows its work, it does not lose authority. It gains believers who checked.

接下來,我想用臺灣的六個閃電示範來展示這個原則。臺灣帶來的是靈感示範,不是拿來複製貼上的模型。開發者都知道示範是幹嘛用的:我們檢視它,拿走在自己環境裡編譯得過的部分,回報錯誤,並保留拒絕不合用部分的權利。公共政策,也該有同樣的紀律。

信任大眾,交出資料。

2020 年 2 月,COVID-19 疫情剛起,臺灣口罩短缺,恐慌也隨之而來。南部臺南市的公民科技人吳展瑋(Howard Wu),做了一張小地圖,標出哪些店還有口罩。他做這張圖,是因為他的聊天群組快被謠言淹沒了。我在政府裡的工作,是說服政府開放藥局的即時庫存資料流,每三十秒更新一次——不必自己去做一張更好的地圖。於是 Howard 的地圖,加上百餘個志工工具,都能從同一個值得信任的來源取用資料。

請注意信任的方向。國家沒有要求民眾信任官方公告;它把原始資料交給民眾信任,民眾則蓋出各種介面。沒有演算法決定誰配得到口罩;因為資訊本身公開,排隊才公平。政府展示自己的工作過程,不會失去權威,反而贏得一群「查核過才相信」的人。

この原則について、台湾から6つのライトニング・デモをお見せしたいと思います。台湾はコピー&ペーストするためのモデルではなく、着想のためのデモです。開発者ならデモの使い方を知っています。検分し、自分の環境でコンパイルが通る部分を持ち帰り、バグ報告を出し、合わない部分を拒む権利は手放さない。同じ規律が、公共政策にもふさわしいのです。

データを公衆に委ねる。

2020年2月、COVID-19の始まりに、台湾ではマスクが不足し、それに見合うパニックが起きました。南部の町・台南のシビックテック実践者、呉展瑋(ハワード・ウー)さんが、どの店にまだマスクがあるかを示す小さな地図を作りました。彼が作ったのは、自分のチャットグループがデマで溢れかえっていたからです。政府での私の仕事は、もっと良い地図を作ることではありませんでした。薬局の在庫のライブフィードを、30秒ごとの更新で開放するよう政府を説得することでした。こうしてハワードさんの地図も、百を超えるほかのボランティアのツールも、信頼に足るただ一つの情報源から汲めるようになったのです。

信頼の向きに注目してください。国は、公式発表を信じるよう公衆に求めませんでした。国が生データを公衆に委ね、公衆がインターフェースを作ったのです。誰がマスクに値するかを決めるアルゴリズムはありません。情報そのものが公開されていたから、列は公平でした。政府が自らの仕事を見せるとき、権威は失われません。「確かめた上で信じる人々」を得るのです。

D2grants the power to authenticate the institution賦予驗證機構的權力機関を認証する力を授ける

A Number to Memorise記得住的一組號碼覚えられる番号

#

A number the public can memorise.

Authentication is not only for people. Institutions need to authenticate themselves to the public, every day, through channels a grandmother can verify. In Taiwan, every official government text message comes from a single three-digit number: 111. Not one number per ministry. One number for the government. Anything else wearing the government's name is counterfeit by definition. The public gets one clear test instead of a catalogue of warning signs. It costs almost nothing. It requires no new cryptography. It is authentication running in the direction most systems forget: the institution proving itself to the person.

The lesson generalises. Ask of any system you build: what is the one thing the public must remember to stay safe? If the answer is a 17-step checklist of warning signs, the design has already failed. If the answer fits in three digits, the design is doing the work.

一組大眾記得住的號碼。

驗證不是只驗人。機構也需要天天向大眾證明自己,而且要走阿嬤都能查驗的管道。在臺灣,所有政府官方簡訊都來自同一組三位數號碼:111。整個政府共用一個號碼,不是一個部會各編各的。凡是掛著政府名義、卻不是這個號碼的,照定義就是假冒。大眾得到的是一條清楚的判準,而不是一整本警示圖鑑。它幾乎不花錢,也不需要新的密碼學。這是朝著多數系統遺忘的方向跑的驗證:由機構向個人證明自己。

這一課可以推而廣之。對你打造的任何系統,都問一句:大眾只需要記住哪一件事,就能保住安全?如果答案是一份十七步的警示清單,設計已經失敗;如果答案塞得進三位數,設計就正在盡職。

誰もが覚えられる番号。

認証は人のためだけのものではありません。機関もまた、毎日、おばあちゃんでも確かめられる経路で、公衆に対して自らを認証する必要があります。台湾では、政府の公式ショートメッセージはすべて、たった一つの3桁番号「111」から届きます。省庁ごとに一つではなく、政府全体で一つ。それ以外で政府の名を名乗るものは、定義からして偽物です。公衆が手にするのは、警戒サインのカタログではなく、たった一つの明快なテストです。費用はほぼゼロ。新しい暗号技術も要りません。これは、多くのシステムが忘れている向きに走る認証です——機関が、個人に向かって、自らを証明するのです。

この教訓は一般化できます。自分が作るどんなシステムにも問うてください。安全でいるために、公衆が覚えておくべきたった一つのことは何か。答えが17段階の警戒チェックリストなら、設計はすでに失敗しています。答えが3桁に収まるなら、設計が仕事をしているのです。

D3grants the power to contest a falsehood賦予反駁不實的權力虚偽に異を唱える力を授ける

Humour over Rumour幽默勝過謠言ユーモアはデマに勝る

#

The answer lies with better company, not with silence.

Through the COVID-19 years, Taiwan faced thousands of rumours, and we made an unusual choice. We never took a single post down for being wrong. We called the practice humour over rumour. Every ministry kept a small team, five people or so. Their job was to answer a false claim within about an hour, with something true and something funny, before the falsehood finished travelling. One rumour claimed that mask production would exhaust our toilet paper supply. Then Premier Su Tseng-chang's office answered with a joke. In English, it amounts to: we each have only one behind to protect. The pun does not survive translation, so please trust me that it was funnier in Taiwanese.

Underneath the jokes sits a public layer. A volunteer fact-checking community called Cofacts was born in our civic-tech movement, and it runs independently today. Anyone can forward a suspicious message and get back a crowd-checked answer. More than 2,000 volunteer editors have checked more than 87,000 rumours. Around 300,000 people use it. Nobody at Cofacts is paid. They do this because the information space does not tend itself.

回應謊言,靠更好的陪伴,不靠噤聲。

整個 COVID-19 期間,臺灣面對成千上萬則謠言,而我們做了一個不尋常的選擇:從未因為「內容錯誤」下架任何一則貼文。我們把這套做法叫作「幽默勝過謠言」。每個部會養一支小隊,五人上下,任務是在謠言傳完之前——大約一小時內——用一件真的事加一件好笑的事來回應。有一則謠言宣稱,增產口罩會耗盡衛生紙的原料。時任行政院長蘇貞昌的辦公室用一則笑話回應,大意是:咱們每人都只有一粒屁股好顧。這個諧音哏禁不起翻譯,所以請相信我:臺語原版好笑得多。

笑話底下,還有一層公共地基。名為「Cofacts 真的假的」的志工事實查核社群,誕生於我們的公民科技運動,如今獨立運作。任何人都能轉傳可疑訊息,收到群眾查核過的回覆。超過兩千位志工編輯,查核了超過八萬七千則謠言,約三十萬人在使用。Cofacts 沒有任何人支薪。他們做這件事,是因為資訊空間不會自己照顧自己。

嘘に応えるのは沈黙ではなく、より良い道連れ。

COVID-19の年月を通じて、台湾は何千ものデマに直面しましたが、私たちは珍しい選択をしました。「間違っているから」という理由で投稿を削除したことは、一度もありません。この実践を「ユーモアはデマに勝る」と呼びました。各省庁が5人ほどの小さなチームを持ち、その仕事は、偽りが伝わり終える前に——おおよそ1時間以内に——真実を一つ、笑いを一つ添えて答えることでした。あるデマは、マスクの増産でトイレットペーパーの原料が尽きると主張しました。当時の蘇貞昌行政院長の官房は、ジョークで答えました。訳せば「守るべきお尻は、一人一つしかありません」といったところです。この駄洒落は翻訳に耐えないので、台湾語ではもっと面白かったと、どうか信じてください。

ジョークの下には、公共のレイヤーがあります。「Cofacts(真的假的)」というボランティアのファクトチェック・コミュニティが私たちのシビックテック運動から生まれ、今日も独立して動いています。誰でも怪しいメッセージを転送すれば、群衆によって検証された答えが返ってきます。2,000人を超えるボランティア編集者が、87,000件を超えるデマを検証してきました。約30万人が使っています。Cofactsに給料をもらっている人は一人もいません。情報空間は自らを手入れしてくれないから、彼らはこれをやるのです。

2,000+volunteer editors志工編輯ボランティア編集者
87,000+rumours checked查核過的謠言検証済みのデマ
300,000people using Cofacts使用 Cofacts 的人Cofacts利用者

Countering the pandemic with no lockdown, and the infodemic with no takedown. That sentence is Taiwan's proudest export, and it is an accountability design. Takedowns ask the public to trust an invisible referee. Fast, funny, sourced corrections let the public watch the referee work.

對抗疫情,不封城;對抗資訊疫情,不下架。這句話是臺灣最自豪的輸出品,而它正是一種課責設計。下架,要求大眾信任一位看不見的裁判;快速、好笑、附出處的更正,讓大眾親眼看裁判執法。

パンデミックにはロックダウンなしで、インフォデミックには削除なしで立ち向かう。この一文は台湾がもっとも誇る輸出品であり、そして説明責任の設計です。削除は、見えない審判を信じるよう公衆に求めます。速くて、可笑しくて、出典つきの訂正は、審判が働くところを公衆に見せるのです。

D4grants the power to know when a system ends賦予知道系統何時結束的權力システムの終わりを知る力を授ける

Sunset Trust會落日的信任日没する信頼

#

Sunset trust.

In May 2021, Taiwan needed contact tracing at national scale within days. Government technologists, g0v and telecom carriers built a system together in about three days. At a shop door, you scanned a random 15-digit venue code and sent one text message to 1922 through your own phone company. The message carried the venue code, your number and the time. Nothing went to the venue. Your carrier kept the record for 28 days, for contact tracing only, and then deleted it automatically whether or not anyone had looked.

Adoption was voluntary and high because the privacy design was also more convenient. The interaction took four seconds — about 10 seconds less than writing a phone number on paper, where the next person in line might see it. We must never ask people to trade privacy for convenience; trustworthy design has to deliver both. People could explain the protection to one another in one sentence. That is a good test of trustworthy architecture: Can the protected person describe the protection?

And when the pandemic passed, the system did not linger. It was formally retired within a year. A trust system that cannot end is a surveillance system waiting for a new job description. Deletion on schedule is not a compliance cost. Deletion is a feature the public can feel.

會落日的信任。

2021 年 5 月,臺灣需要在幾天內建立全國規模的疫調足跡。政府技術人員、g0v 與電信業者合力,大約三天就把系統做了出來。在店門口,你掃一組隨機的十五碼場所代碼,透過自己的電信公司發一封簡訊到 1922。簡訊帶著場所代碼、你的號碼和時間;店家什麼都拿不到。你的電信業者保存這筆紀錄二十八天、只供疫調使用,期滿自動刪除——不管有沒有人調閱過。

採用是自願的,普及率卻很高,因為這套隱私設計同時更方便:整個動作四秒鐘——比在紙本上寫電話號碼快上約十秒,何況紙本還可能被下一位排隊的人看見。我們永遠不該要求人們拿隱私換便利;值得信任的設計,兩者都要給。人們能用一句話向彼此解釋這層保護。這是可信架構的好測試:受保護的人,說得出保護的內容嗎?

疫情過去,系統也不戀棧,一年內正式退役。一套無法結束的信任系統,就是一套等著改寫職務說明的監控系統。準時刪除不是法遵成本;刪除,是大眾感受得到的功能。

日没する信頼。

2021年5月、台湾は数日のうちに、全国規模の接触追跡を必要としました。政府の技術者とg0vと通信キャリアが力を合わせ、およそ3日でシステムを作り上げました。店の入口でランダムな15桁の場所コードを読み取り、自分の契約する電話会社経由で1922へショートメッセージを1通送る。メッセージが運ぶのは場所コードと自分の番号と時刻だけ。店側には何も渡りません。キャリアはその記録を28日間、接触追跡のためだけに保管し、誰かが参照したかどうかにかかわらず、期限が来れば自動的に削除しました。

採用は任意で、それでも普及率は高かった。プライバシー設計が、同時により便利だったからです。操作は4秒——紙に電話番号を書くより約10秒速く、紙では次に並ぶ人に番号を見られかねません。プライバシーと利便性の交換を、人々に求めてはなりません。信頼に値する設計は、両方を届けるものです。人々はこの保護を、一文でお互いに説明できました。これは信頼できるアーキテクチャの良いテストです——守られている本人が、その守りを言葉にできるか。

そして流行が去ると、システムは居座りませんでした。1年以内に正式に引退したのです。終わることのできない信頼システムは、新しい職務記述書を待っている監視システムです。予定どおりの削除はコンプライアンス費用ではありません。削除は、公衆が肌で感じられる機能なのです。

D5grants the power to stop a design that is not ready賦予攔下未就緒設計的權力未熟な設計を止める力を授ける

The Pause暫停一時停止

#

The pause.

This demo is at the very heart of my message today. Taiwan already had an analogue ID system and an electronic Citizen Digital Certificate. In January 2021, the Cabinet suspended a plan to merge them into a new eID. Civil-society groups and academics had spent months asking questions the design could not yet answer. Who can see the trail of where I used this card? Under which dedicated law? With what recourse when it leaks? The government agreed those questions deserved statutory answers and paused the rollout until a dedicated data-protection authority and independent safeguards could be established.

暫停。

這個示範,正是我今天訊息的核心。臺灣原本就有實體身分證系統,加上一張電子的自然人憑證。2021 年 1 月,行政院暫停了把兩者合併為新式數位身分證(eID)的計畫。公民團體與學界花了好幾個月,提出當時的設計還答不出來的問題:誰能看到我用這張卡的足跡?依據哪部專法?外洩時有什麼救濟?政府承認這些問題值得用法律回答,於是暫停推行,直到專責的個資保護機關與獨立的防護機制建立為止。

一時停止。

このデモこそ、今日の私のメッセージの核心です。台湾にはすでに、アナログの身分証システムと、電子的な自然人証明書(Citizen Digital Certificate)がありました。2021年1月、内閣は両者を新しいeIDへ統合する計画を一時停止しました。市民団体と研究者たちが何か月もかけて、当時の設計ではまだ答えられない問いを重ねていたのです。このカードをどこで使ったか、その足跡を誰が見られるのか。どの専用法のもとで。漏洩したとき、どんな救済があるのか。政府は、これらの問いには法律で答える価値があると認め、専任のデータ保護機関と独立した安全装置が確立されるまで、展開を止めました。

To many engineers, the pause looked like failure. Years of work stopped short of launch. I make the opposite claim. The merge did not fail because civil society interrupted it; the design was not ready on the data-protection side. Stopping was trust by design working. A government that can hear that distinction is more trustworthy than one that simply meets its launch date.

The objections did not disappear during the pause. They became a public red-team threat model. They exposed assumptions and clarified the questions a better system had to answer. Taiwan learned to treat detailed objections as a security audit nobody commissioned. A person who files one is not an obstacle. They are a committed user, testing whether the system deserves trust.

The pause grew something. Last December, Taiwan's Ministry of Digital Affairs, or moda, began trial operation of a national digital credential wallet. This design uses selective disclosure. You prove you are over 18 without showing your birthday. You prove you are a resident without showing your name. The verifier learns the one fact it needs and nothing else. That delivery belongs to the moda and its Minister Lin Yi-jing. The hard questions from 2021 did not disappear, and four years of public doubt were not lost time. They were deposits. The wallet opens its account with the interest.

在許多工程師眼中,這次暫停像是失敗:多年的工作,臨門一腳喊停。我的主張恰恰相反。合併案喊停,是因為設計在個資保護這一側還沒準備好,並不是公民社會把它打斷了。停下來,正是信任設計在運作。聽得出這個分別的政府,比一個只求準時上線的政府,更值得信任。

暫停期間,反對意見並沒有消失,化成了一份公開的紅隊威脅模型:攤開各種假設,釐清更好的系統必須回答的問題。臺灣學會把詳盡的異議,當成一場沒人出資委託的資安稽核。提交異議的人,是一位投入的使用者,正在測試這套系統配不配得到信任——不是絆腳石。

暫停也長出了東西。去年十二月,臺灣數位發展部(moda)開始試營運全國性的數位憑證皮夾。這套設計採用選擇性揭露:證明你年滿十八,不必出示生日;證明你是居民,不必出示姓名。查驗方只得到它需要的那一項事實,其他一概不知。這項成果屬於數位發展部與林宜敬部長。2021 年的那些難題並沒有消失,而四年的公眾疑問也不是浪費時間——它們是存款。皮夾開戶時,連本帶利。

多くのエンジニアの目に、この一時停止は失敗と映りました。何年もの仕事が、リリース直前で止まったのですから。私は正反対の主張をします。統合は、市民社会が邪魔したから失敗したのではありません。データ保護の側で、設計がまだ整っていなかったのです。止まったことこそ、「信頼を、設計する」が働いた証でした。この違いを聞き分けられる政府は、ただ予定日どおりにリリースする政府より、信頼に値します。

一時停止のあいだ、異議は消えませんでした。公開のレッドチーム脅威モデルになったのです。前提をあぶり出し、より良いシステムが答えるべき問いを研ぎ澄ましました。台湾は、細部まで書き込まれた異議を、誰も発注していないセキュリティ監査として扱うことを学びました。異議を申し立てる人は障害物ではありません。システムが信頼に値するかを試している、本気のユーザーなのです。

一時停止は、何かを育てもしました。昨年12月、台湾のデジタル発展部(moda)は、全国的なデジタル・クレデンシャル・ウォレットの試験運用を始めました。この設計は選択的開示を使います。誕生日を見せずに、18歳以上であることを証明する。名前を見せずに、住民であることを証明する。検証者は必要なただ一つの事実だけを知り、それ以外は何も知りません。この成果はmodaと林宜敬部長のものです。2021年の難問は消えたわけではなく、4年間の公衆の疑いも失われた時間ではありませんでした。あれは預け入れだったのです。ウォレットは、その利息とともに口座を開きます。

D6grants the power to see who bought their attention賦予看見誰買下注意力的權力誰が注意を買ったかを見る力を授ける

Know Your Advertiser認識你的廣告主広告主を確認する

#

Know your advertiser.

Fraud, remember, is counterfeit trust, and much of it is bought as advertising. In July 2024, Taiwan enacted a law that requires large advertising platforms to verify who is paying for an advertisement, refuse fraudulent ones and disclose when an advertisement contains a synthetic likeness of a real person. Banks have practised know-your-customer for decades. This is know-your-customer, applied to attention.

The law was already moving through government, and the public was invited in. Earlier in 2024, the government sent 200,000 text messages at random from 111. A total of 1,760 people answered. A total of 447 people came, chosen by lottery to reflect the population by age, gender and region. They spent a day deliberating in 44 small online groups. Participants set the agenda and scrutinised the response. Civic AI summarised; it decided nothing.

認識你的廣告主。

別忘了,詐騙是偽造的信任,而其中很大一部分,是用廣告買來的。2024 年 7 月,臺灣制定法律,要求大型廣告平台驗證廣告金主是誰、拒絕詐騙廣告,並在廣告含有真人的合成肖像時予以揭露。銀行實踐「認識你的客戶」(KYC)已數十年;這就是把 KYC 應用到注意力上。

這部法律當時已在政府內推進,而大眾也被請了進來。2024 年稍早,政府從 111 隨機發出二十萬封簡訊,共 1,760 人回覆;再以抽籤選出 447 人,按年齡、性別、地區對映臺灣人口組成。他們分成 44 個線上小組,審議了一整天。議程由參與者設定,回應由參與者檢驗;公民 AI 負責摘要,不做任何決定。

広告主を確認する。

思い出してください。詐欺は偽造された信頼であり、その多くは広告として買われています。2024年7月、台湾は法律を制定し、大手広告プラットフォームに対して、広告の出稿者が誰かを確認すること、詐欺広告を拒否すること、実在の人物の合成された肖像を含む広告にはその旨を表示することを義務づけました。銀行は何十年も「顧客確認(KYC)」を実践してきました。これは、注意力に適用したKYCです。

この法律はすでに政府内で動いており、公衆もそこに招き入れられました。2024年の早い時期、政府は111から無作為に20万通のショートメッセージを送りました。1,760人が答え、年齢・性別・地域の人口構成を映すよう抽選で選ばれた447人が参加しました。44のオンライン小グループに分かれ、丸一日、熟議したのです。議題は参加者が決め、回答は参加者が精査しました。シビックAIは要約するだけで、何も決めていません。

200,000invitations sent at random隨機發出的邀請無作為に送られた招待
1,760people answered人回覆回答した人
447participants位參與者参加者
44online groups個線上小組オンライン・グループ

Public deliberation informed the response without replacing the responsibility of government and legislators. On the regulated channels, celebrity-impersonation scam advertisements fell from about 38,000 a week in October 2024 to 1,685 a week in September 2025. Investment-scam advertisements fell from about 77,400 a week to 837 a week over the same period. The decline followed an ensemble: the Act, the reporting platform, automated scanning and platform enforcement. Fraud kept probing other channels, because it always does. We are allowed a working demo and a to-do list, not a declaration of victory.

公共審議為回應提供了依據,卻不取代政府與立法者的責任。在納管的管道上,冒用名人的詐騙廣告,從 2024 年 10 月的每週約 38,000 則,降到 2025 年 9 月的每週 1,685 則投資詐騙廣告同期從每週約 77,400 則降到 837 則。這個下降來自一整套組合:專法、檢舉平台、自動掃描、平台執行。詐騙持續試探其他管道——它從來如此。我們配得上的,是一個能動的示範加一張待辦清單,而不是勝利宣言。

公共の熟議は回答に根拠を与えましたが、政府と立法者の責任を肩代わりはしませんでした。規制対象のチャネルでは、著名人なりすまし詐欺広告が、2024年10月の週あたり約38,000件から、2025年9月には週1,685件まで減りました投資詐欺広告は同じ期間に、週あたり約77,400件から837件へ。この減少はアンサンブルの結果です——法律、通報プラットフォーム、自動スキャン、プラットフォームによる執行。詐欺はほかのチャネルを探り続けています。いつだってそうするからです。私たちに許されているのは、動くデモとToDoリストであって、勝利宣言ではありません。

~38,000/wk約 38,000/週約38,000/週impersonation ads · Oct 2024冒名廣告 · 2024/10なりすまし広告 · 2024年10月
1,685/wk1,685/週1,685/週impersonation ads · Sep 2025冒名廣告 · 2025/09なりすまし広告 · 2025年9月
~77,400/wk約 77,400/週約77,400/週investment-scam ads · Oct 2024投資詐騙廣告 · 2024/10投資詐欺広告 · 2024年10月
837/wk837/週837/週investment-scam ads · Sep 2025投資詐騙廣告 · 2025/09投資詐欺広告 · 2025年9月
07

6 Demos, 6 Powers六個示範、六種權力6つのデモ、6つの力

#

Those are six demos. Each gives the public a different power. Open data gives people the power to inspect. One memorable channel lets them authenticate the institution. Fast public answers let them contest a falsehood. Deletion on schedule lets them know when a system ends. A real pause lets them stop a design that is not ready. Advertiser verification lets them see who bought their attention. These are six ways to build accountability into systems that already have authentication and authenticity. None required new mathematics. Every one required a political and design choice. The person, not the institution, is the customer of trust. Authentication without that choice can make administration faster. Authenticity can make content traceable. Only accountability gives the public standing inside the system.

以上是六個示範,各自交給大眾一種不同的權力。開放資料,給人檢視的權力;一組好記的管道,讓人驗證機構;快速的公開回應,讓人反駁不實;準時刪除,讓人知道系統何時結束;真正的暫停,讓人攔下還沒準備好的設計;廣告主驗證,讓人看見是誰買下了自己的注意力。這是把課責蓋進「已有驗證與真確」系統的六種方法。沒有一項需要新的數學;每一項都需要一個政治與設計上的抉擇。信任的顧客是人,不是機構。少了這個抉擇,驗證只會讓行政更快,真確只會讓內容可追蹤;唯有課責,才給大眾在系統內部站立的位置。

以上が6つのデモです。それぞれが公衆に、異なる力を手渡します。オープンデータは、検分する力を。覚えられる一つの経路は、機関を認証する力を。速い公開の回答は、虚偽に異を唱える力を。予定どおりの削除は、システムの終わりを知る力を。本物の一時停止は、未熟な設計を止める力を。広告主確認は、誰が自分の注意を買ったかを見る力を。これらは、すでに認証と真正性を備えたシステムに、説明責任を組み込む6つの方法です。新しい数学は一つも要りませんでした。要ったのはどれも、政治と設計の選択です。信頼の顧客は機関ではなく、人です。その選択なしの認証は、行政を速くするだけかもしれません。真正性は、コンテンツを追跡可能にするだけかもしれません。公衆にシステムの内側での立場を与えるのは、説明責任だけです。

D1Open data開放資料オープンデータthe power to inspect檢視的權力検分する力D2One memorable channel一組好記的管道覚えられる一つの経路authenticate the institution驗證機構機関を認証するD3Fast public answers快速的公開回應速い公開の回答contest a falsehood反駁不實虚偽に異を唱えるD4Deletion on schedule準時刪除予定どおりの削除know when a system ends知道系統何時結束システムの終わりを知るD5A real pause真正的暫停本物の一時停止stop a design that is not ready攔下未就緒的設計未熟な設計を止めるD6Advertiser verification廣告主驗證広告主確認see who bought their attention看見誰買下注意力誰が注意を買ったかを見る
08

Provenance, Not Detection溯源,而非偵測検知ではなく来歴を

#

Now let me turn to the question that brought many of us here. What happens to all of this in the Age of AI?

Two things change, and one thing does not. Authenticity can no longer be inferred from sight and sound. Authority can now move through software at machine speed. Accountability remains the test. Can people see what happened, contest it and identify who must answer? The technology changes. The burden of proof does not.

The first change: authenticity stops being visible. For all of human history, seeing a face and hearing a voice was evidence. That era has ended. The synthetic advertisements in Japan's fraud statistics are early examples. Within this decade, an unsigned image will deserve the same default trust as an unsigned cheque. Which is to say, none.

Detection alone cannot carry this burden. Detection reacts after generation; public safety cannot depend on detectors winning every round. The durable answer is provenance. Content must carry its origin with it cryptographically, as Professor Nelson wanted quotations to carry their sources. Open standards for this now exist. Content Credentials attach a signed manifest to a photograph or video, recording where the file came from and how it changed. This is Xanadu's unfinished work, 60 years later. The decisive line is not human versus AI. It is accountable versus unaccountable mediation.

現在,讓我轉向把許多人帶來這裡的問題:進入 AI 時代,這一切會怎麼樣?

有兩件事會變,一件事不變。真確,再也無法靠眼見耳聞推斷;權力,如今能以機器速度在軟體裡移動。課責,仍然是那道檢驗:人們能不能看見發生了什麼、提出異議、指認該負責的人?技術在變,舉證責任不變。

第一個變化:真確不再肉眼可見。人類有史以來,見到臉、聽到聲音就算證據——那個時代結束了。日本詐騙統計裡的合成廣告,只是早期樣本。十年之內,一張未簽章的圖片,配得到的預設信任,將等同一張未簽名的支票。也就是說:零。

光靠偵測,扛不起這個重擔。偵測是在生成之後才反應;公共安全不能寄望偵測器每一回合都獲勝。經得起時間的答案是溯源:內容必須以密碼學方式隨身攜帶出處,就像尼爾森教授希望引文帶著來源那樣。這方面的開放標準已經存在。內容憑證(Content Credentials)為照片或影片附上簽章的清單,記錄檔案從哪裡來、經過哪些變更。這是仙那度六十年後的未竟之業。決定性的界線不在「人類對 AI」,而在「可課責的中介」對「不可課責的中介」。

さて、多くの人をこの場に連れてきた問いに移りましょう。AIの時代に、これらすべてはどうなるのか。

変わるものが二つ、変わらないものが一つあります。真正性はもう、見た目と音声からは推し量れません。権限はいまや、機械の速度でソフトウェアの中を移動できます。説明責任は、変わらず試金石のままです。何が起きたかを人々が見られるか、異議を唱えられるか、誰が答えるべきかを特定できるか。技術は変わります。挙証責任は変わりません。

第一の変化。真正性は、目に見えるものではなくなります。人類の歴史を通じて、顔を見ること、声を聞くことは証拠でした。その時代は終わりました。日本の詐欺統計に現れる合成広告は、その早い例です。この10年のうちに、署名のない画像に与えるべきデフォルトの信頼は、署名のない小切手と同じになるでしょう。つまり、ゼロです。

検知だけでは、この重荷を担えません。検知は生成の後に反応するものであり、公共の安全は、検知器が毎ラウンド勝つことに依存できません。長持ちする答えは来歴です。ネルソン教授が引用に出典を持たせたかったように、コンテンツは暗号学的に出自を携えて動かなければなりません。そのためのオープン標準は、もう存在します。コンテンツ・クレデンシャル(Content Credentials)は、写真や動画に署名付きマニフェストを添付し、ファイルがどこから来て、どう変わったかを記録します。これは60年越しの、ザナドゥの未完の仕事です。決定的な境界線は「人間対AI」ではありません。「説明責任を負える媒介」対「説明責任のない媒介」です。

09

AI on Tap, Not on TopAI 隨開即用,不高高在上AIは手元に、頭上にではなく

#

The second change is delegation. The next internet will be full of AI agents acting on our behalf. They will book, negotiate, file and pay. An agent with my credentials is a power of attorney operating at machine speed. A copied face is harmful. An unaccountable mandate is worse.

Consider what happens when my AI agent buys something. Today, a payment passes through know-your-customer at the bank. Tomorrow, the bank must also ask: Is this instruction really from Audrey Tang, or from software she authorised? Did she authorise this much, for this long, for this purpose? The coming decade asks every institution to know the agent and, behind the agent, its mandate. If mandates are solved in the open as shared standards, delegation can scale without creating another gatekeeper.

Every delegation needs a signed scope. What may this agent do? For whom? Until when? Can I revoke it in one step? Every action needs a receipt the principal can read. Estonia's data tracker offers a useful precedent: a person can see which office touched their data and when. If my agent moves my money, I should see the scope, action and institution in language I understand — not in neuralese. When something goes wrong, the answer to “Who is responsible?” must never be “the model”. It must be the mandate, traceable to an accountable person. Otherwise it is abdication, not delegation. AI on tap, not on top.

第二個變化是委任。下一代網際網路,將滿是替我們行事的 AI 代理:訂位、談判、申報、付款。一個持有我憑證的代理,就是一份以機器速度運作的委任書。臉被複製固然有害;一份無從課責的授權,更糟。

想想我的 AI 代理買東西時會發生什麼。今天,一筆付款要通過銀行的 KYC;明天,銀行還得多問:這道指令真的出自唐鳳,還是出自她授權的軟體?她授權了這個額度、這段期間、這個用途嗎?未來十年,每個機構都得認識代理,以及代理背後的授權。如果授權能以共享標準、在開放中解決,委任就能規模化,而不必再造一個守門人。

每一次委任,都需要一份簽章的權限範圍:這個代理可以做什麼?替誰做?做到什麼時候?我能不能一步撤銷?每一個動作,都需要一張本人讀得懂的收據。愛沙尼亞的資料足跡查詢是有用的先例:個人可以看到哪個機關、在什麼時候動過自己的資料。如果我的代理動了我的錢,我應該能用我懂的語言——而不是「神經黑話」(neuralese)——看到範圍、動作與機構。出事的時候,「誰負責?」的答案永遠不能是「模型」,而必須是那份授權,一路追溯到一個可課責的人。否則那不是委任,是棄權。AI 隨開即用,不高高在上。

第二の変化は委任です。次のインターネットは、私たちの代わりに動くAIエージェントで満ちるでしょう。予約し、交渉し、申請し、支払う。私のクレデンシャルを持つエージェントは、機械の速度で動く委任状です。コピーされた顔は有害ですが、説明責任の利かない委任は、もっと悪い。

私のAIエージェントが買い物をするとき、何が起きるか考えてみましょう。今日、支払いは銀行の顧客確認(KYC)を通ります。明日、銀行はさらに問わなければなりません。この指図は本当にオードリー・タンからか、それとも彼女が認めたソフトウェアからか。彼女はこの金額を、この期間、この目的で認めたのか。来る10年は、あらゆる機関に「エージェントを知り、その背後の委任を知る」ことを求めます。委任が共有標準としてオープンに解かれるなら、委任は新たな門番を生まずにスケールできます。

どの委任にも、署名されたスコープが要ります。このエージェントは何をしてよいのか。誰のために。いつまで。ワンステップで取り消せるか。どの行為にも、本人が読める領収書が要ります。エストニアのデータトラッカーは有益な先例です。どの役所が、いつ、自分のデータに触れたかを本人が見られる。私のエージェントが私のお金を動かすなら、その範囲と行為と機関を、私に分かる言葉で見たいのです——「ニューラリーズ(機械の内語)」ではなく。何かが狂ったとき、「誰の責任か」への答えは、決して「モデル」であってはなりません。答えは委任状であり、説明責任を負える人へと遡れなければなりません。さもなければ、それは委任ではなく放棄です。AIは手元に。頭の上にではなく。

10

Model to the Data讓模型走向資料モデルをデータのもとへ

#

Fukuda-san spoke about running a local model on a MacBook. That reverses the instinct of the cloud decade, which moved our data to large models in somebody else's cloud. On my own MacBook, I now run a local knowledge artefact management intelligence called Kami. The sensitive record never leaves my laptop. In banking terms, custody of the data stays with the fiduciary. I can inspect the system and switch it off without asking permission.

Before these systems touch the public, extend the financial sector's own discipline to AI agents. Nobody deploys a payment system without auditors or lists a product without conformance testing. Security by obscurity no longer buys time when AI has near-infinite attention, so we need proof by construction and public red teams. Communities can already write open evaluation criteria through infrastructure such as the Collective Intelligence Project and test any model against them. A supplier benchmark answers the supplier's question. A public evaluation answers the public's.

福田先生談到在 MacBook 上跑本機模型。這反轉了雲端十年的本能——那十年,把我們的資料搬去別人雲端裡的大模型。如今在我自己的 MacBook 上,跑著一套本機的知識工作物管理智慧,名叫 Kami。敏感紀錄從未離開我的筆電。用銀行的話說:資料的保管權,留在受託人手上。我可以檢視這套系統,也可以不必請示任何人就把它關掉。

在這些系統接觸大眾之前,請把金融業自己的紀律,延伸到 AI 代理上。沒有人會在沒有稽核的情況下部署支付系統,也沒有人不經一致性測試就上架商品。當 AI 擁有近乎無限的注意力,「靠隱匿求安全」再也買不到時間;我們需要的是「以構造證明」(proof by construction)與公開紅隊。透過像「集體智慧計畫」(Collective Intelligence Project)這樣的基礎設施,社群已經能撰寫開放的評測準則,拿任何模型來測。供應商的基準測試,回答供應商的問題;公共的評測,回答大眾的問題。

福田さんは、MacBookでローカルモデルを動かす話をされました。これは、クラウドの10年の本能を反転させるものです。あの10年は、私たちのデータを、よそのクラウドの大規模モデルへ運びました。いま私自身のMacBookでは、Kami(カミ)という、ローカルな知識成果物管理知能が動いています。機微な記録は、私のラップトップを一度も離れません。銀行の言葉で言えば、データの保管は受託者の手元に残る。私はこのシステムを検分でき、誰の許可も求めずに電源を切れます。

これらのシステムが公衆に触れる前に、金融セクター自身の規律をAIエージェントへ延長してください。監査人なしで決済システムを配備する人も、適合性試験なしで商品を上場する人もいません。AIがほぼ無限の注意力を持つ時代、「隠すことによる安全」ではもう時間を稼げません。必要なのは「構成による証明(proof by construction)」と、公開のレッドチームです。コレクティブ・インテリジェンス・プロジェクトのようなインフラを通じて、コミュニティはすでにオープンな評価基準を書き、どんなモデルでもそれに照らして試せます。供給者のベンチマークは供給者の問いに答えます。公共の評価は、公衆の問いに答えるのです。

11

Trust is Soil信任是土壤信頼は土壌

#

The mathematics never carries the whole weight. No path around legitimacy exists. The strongest credential system still needs people to believe enrolment is safe, errors get fixed, opting out remains possible and the operator answers to someone. Those beliefs are earned in the open, slowly, and can be spent in a single bad week. Trust is not oil you can drill. Trust is soil you can till. It grows when systems answer doubt. It dies when systems demand belief.

數學從來扛不起全部的重量,也沒有繞過正當性的捷徑。再強的憑證系統,仍然需要人們相信:註冊是安全的、錯誤會被修正、退出始終可能、營運者要對某個人負責。這些相信,是在公開中慢慢掙來的,卻可能在糟糕的一週裡花光。信任是必須耕耘的土壤,不是能開採的石油。系統回應疑問,它就生長;系統要求相信,它就死去。

数学が全重量を担うことは、決してありません。正統性を迂回する道は存在しません。最強のクレデンシャル・システムでさえ、人々の信念を必要とします——登録は安全だ、誤りは直される、離脱はいつでも可能だ、運営者は誰かに対して責任を負う、という信念を。それらは公開の場で、ゆっくりと獲得され、たった一度のひどい一週間で使い果たされえます。信頼は、掘削できる石油ではありません。信頼は、耕さねばならない土壌です。システムが疑いに答えるとき、それは育ちます。システムが信じることを強いるとき、それは枯れるのです。

There is a reminder of this in the name of one of today's co-hosts. Mebuku comes from a Japanese verb meaning to sprout. That is the right verb class for trust. Nobody installs a rosebud. We prepare the ground and protect the season.

So, when a new identity system meets its public, the questions that decide its fate are rarely about elliptic curves. They are the gardener's questions. Can I see what is planted in my name? Can I contest a record that is wrong about me, and how long does the correction take? Can I leave, and what do I keep when I go? Is there a second source, so that no single operator, public or private, holds the only key to my participation in society? Systems that answer those questions calmly, in public, before being forced to, have a better chance of earning durable trust.

今天其中一個協辦單位的名字,正好提醒我們這件事。Mebuku 來自日文動詞「芽吹く」——發芽。信任正屬於這一類動詞。沒有人「安裝」一朵玫瑰花苞;我們整地,並守護季節。

所以,當一套新的身分系統與它的大眾見面,決定其命運的,多半是園丁的問題,很少關乎橢圓曲線:我能看到以我之名種下了什麼嗎?記錄寫錯了我,我能異議嗎?更正要多久?我能離開嗎?走的時候能帶走什麼?有沒有第二來源,讓任何單一營運者——無論公私——都不會獨握我參與社會的唯一鑰匙?能在被迫之前,就心平氣和、公開回答這些問題的系統,更有機會贏得經久的信任。

今日の共催者の一つの名前に、その注意書きがあります。「めぶく」は「芽吹く」という動詞から来ています。信頼にふさわしいのは、まさにこの類の動詞です。バラのつぼみをインストールする人はいません。私たちは土を整え、季節を守るのです。

だから、新しいアイデンティティ・システムが公衆と出会うとき、その運命を決める問いが楕円曲線に関わることは、めったにありません。それは庭師の問いです。私の名前で何が植えられているか、見られるか。私について間違った記録に異議を申し立てられるか、訂正にはどれだけかかるか。離れられるか、去るとき何を持っていけるか。第二の供給元はあるか——官であれ民であれ、単一の運営者が、私の社会参加への唯一の鍵を握らないように。強いられる前に、公開の場で、静かにこれらへ答えるシステムこそ、長持ちする信頼を得る見込みが高いのです。

12

Bridge. Bank. Broadcast.架橋。積存。廣播。架橋。蓄積。発信。

#

Democracy means that the path from harm to repair is short. When harm appears in one democracy, we need a way to broadcast it as an evaluation so that people — and their personal AI — can ask whether the same harm is reaching them. We do not need one national blueprint for trust. We can agree on the properties that let people trust across systems.

Three things this region can do together, starting this year. None requires a treaty.

民主的意義,必須包括「從傷害到修復的路很短」。當傷害在一個民主政體現身,我們需要一種辦法,把它廣播成一份評測,讓每個人——以及他們的個人 AI——都能追問:同樣的傷害是否正在逼近自己。我們不需要一份全國統一的信任藍圖;我們可以就「讓人跨系統信任」的性質達成一致。

這個區域今年就能一起做三件事,一件都不需要條約。

民主主義であるとは、被害から回復への道のりが短いということでなければなりません。ある民主国家で被害が現れたら、それを評価(エバリュエーション)として発信し、人々が——その人のパーソナルAIも——同じ被害が自分にも届いていないかを問える仕組みが要ります。信頼のための国家設計図が一枚、必要なのではありません。システムをまたいで人が信頼できるための性質について、合意すればよいのです。

この地域が今年から一緒にできることが、三つあります。条約はどれにも要りません。

First第一一つ目

Bridge the wallets橋接皮夾ウォレットに橋を

Taiwan’s wallet, Japan’s identity ecosystem and every system between them should speak open standards. A credential should remain portable between providers. No single operator should become the only route into digital life.臺灣的皮夾、日本的身分生態系,以及兩者之間的每套系統,都該說開放標準。憑證應該在供應者之間保持可攜。任何單一營運者,都不該成為進入數位生活的唯一通道。台湾のウォレットも、日本のアイデンティティ生態系も、その間のあらゆるシステムも、オープン標準を話すべきです。クレデンシャルは、提供者間で可搬であり続けるべきです。単一の運営者が、デジタル生活への唯一の入り口になってはなりません。

Second第二二つ目

Bank the evaluations積存評測評価を積み立てる

A scam pattern tested in Taipei should not need to be rediscovered in Tokyo. Open evaluation suites can let fraud teams learn from each other at the speed of a git pull. Every shared test is a deposit that compounds.在臺北測過的詐騙模式,不該在東京被重新發現一次。開放的評測套件,能讓防詐團隊以 git pull 的速度互相學習。每一個共享的測試,都是會複利的存款。台北で検証済みの詐欺パターンを、東京で再発見する必要はないはずです。オープンな評価スイートがあれば、対詐欺チームは git pull の速度で学び合えます。共有されたテストの一つひとつが、複利で増える預金です。

Third第三三つ目

Broadcast the pauses廣播暫停一時停止を発信する

When a system stops because the public asked hard questions, publish those questions and the eventual answers. These are among the most valuable exports in this field, yet almost nobody broadcasts them — not even into AI pre-training.當一套系統因為大眾提出難題而停下,請把那些問題、以及後來的答案公開出來。這是本領域最有價值的輸出品之一,卻幾乎沒有人廣播它們——甚至沒有進入 AI 的預訓練。公衆が難しい問いを投げたためにシステムが止まったなら、その問いと、やがて出た答えを公開してください。これはこの分野でもっとも価値ある輸出品の一つなのに、発信する人はほとんどいません——AIの事前学習にすら入っていないのです。

One more thing before I close. At the start, I promised that we would check the machine's work together. If a sentence on that wall read strangely today, send it to au@civic.ai. I will answer the doubt in person. It is not a perfect channel, but it is a way back: we can correct the record and tune the system together.

收尾前,還有一件事。開場時我承諾過,我們要一起檢查機器的表現。今天牆上若有哪句話讀起來怪怪的,請寄到 au@civic.ai,我會親自回應那個疑問。這不是完美的管道,但它是一條回頭路:我們可以一起更正紀錄、一起調校系統。

締めくくる前に、もう一つ。冒頭で、機械の仕事ぶりを一緒に確かめると約束しました。今日、あの壁の上で妙に読めた一文があったら、au@civic.ai へ送ってください。その疑いには、私が自分で答えます。完璧な経路ではありませんが、引き返し道ではあります。記録を正すのも、システムを調律するのも、一緒にできるのです。

CL

We the People Are Truly the Superintelligence我們全民,才是超級智慧われら人民こそ、真の超知能

#

Professor Nelson's optimism is a work order. The generation in this hall can close the 60-year-old ticket. The identity infrastructure is here, and the engineers are already in this room. The task is not to make people believe harder. It is to build systems worthy of belief.

Taiwan will keep publishing its demos, including its pauses, for anyone who wishes to inspect them. Taiwan and Japan already know reciprocity: masks moved one way in April 2020, and AstraZeneca vaccines moved the other in June 2021. When Japan builds something better — and you will — Taiwan will be in the front row, taking notes.

Sixty years ago, one designer insisted that the internet could remember where things came from and who stood behind them. The tools to honour that insistence finally exist. So do the people. Authentication proves who. Authenticity proves what. Accountability proves whether power can be seen, questioned and corrected. The work is not machines believing other machines. It is people deciding together in public that our shared systems deserve belief.

尼爾森教授的樂觀,是一張工單。這個廳裡的世代,能結案這張六十年的工單。身分基礎設施已經到位,工程師就坐在這個房間裡。任務是打造配得上相信的系統,不是讓人們更用力相信。

臺灣會繼續公開自己的示範——包括自己的暫停——供任何想檢視的人檢視。臺灣與日本早就懂得互惠:2020 年 4 月,口罩往一個方向送2021 年 6 月,AZ 疫苗往另一個方向來。當日本做出更好的東西——你們一定會——臺灣會坐在第一排,勤做筆記。

六十年前,一位設計者堅持:網際網路可以記得事物從哪裡來、誰站在它們背後。實現這份堅持的工具終於存在了,人也到齊了。驗證證明是誰;真確證明是什麼;課責證明權力能否被看見、被質問、被更正。這件工作,是讓人們在公開之中一起決定:我們共享的系統,配得到相信。機器相信機器,不算數。

ネルソン教授の楽観は、作業指示です。この会場の世代は、60年もののチケットをクローズできます。アイデンティティ基盤はここにあり、エンジニアはすでにこの部屋にいます。課題は、人々にもっと強く信じさせることではありません。信じるに値するシステムを建てることです。

台湾はこれからも、自らのデモを——一時停止も含めて——検分したい人すべてに公開し続けます。台湾と日本は、互恵をすでに知っています。2020年4月にはマスクが一方へ渡り2021年6月にはアストラゼネカのワクチンが逆方向へ渡りました。日本がより良いものを作るとき——必ず作るでしょう——台湾は最前列で、ノートを取っています。

60年前、一人の設計者が言い張りました。インターネットは、物事がどこから来て、誰がその背後に立つのかを覚えていられる、と。その言い分に応える道具が、ついに存在します。人も、います。認証は「誰か」を証明する。真正性は「何か」を証明する。説明責任は「権力が見られ、問われ、正されうるか」を証明する。この仕事は、機械が機械を信じることではありません。私たちの共有するシステムは信じるに値すると、人々が公開の場で、共に決めることなのです。

Thank you. Now I look forward to the questions from Kokuryo-sensei. Welcome to the stage.

謝謝大家。接下來,期待國領教授的提問。歡迎上台。

ありがとうございました。ここからは國領先生からの質問を楽しみにしています。どうぞ壇上へ。

Complete conversation完整對談対談・完全版Professor Jiro Kokuryo × Audrey Tang國領二郎教授 × 唐鳳國領二郎教授 × オードリー・タン
QA

From Trustworthy Technology to Trustworthy Society從信任科技,到可信社會信頼の技術から、信頼される社会へ

#

Kokuryo-sensei frames the exchange國領教授開場定調國領先生が対話の枠組みを示す

FPoS — Mebuku ID in Maebashi — joins authentication, personal control over private information and ready access to signatures.FPoS——前橋市的 Mebuku ID——將身分驗證、個資的自主掌控、隨手可用的簽章,結合在一起。FPoS——前橋市のめぶくID——は、認証と、私的情報の本人によるコントロールと、いつでも使える署名とを結び合わせています。

The larger frame

The six principles point beyond technology. Trust is also social: auditing and accountability determine whether a system deserves belief.

更大的框架

這六項原則指向技術之外。信任也是社會性的:稽核與課責,決定一套系統配不配得到相信。

より大きな枠組み

六つの原則は、技術の先を指しています。信頼は社会的なものでもあります。監査と説明責任が、システムが信じるに値するかどうかを決めるのです。

Q1

Legibility Before Trust先看得懂,才談信任信頼の前に、読めること

#

Kokuryo-sensei asks國領教授提問國領先生の質問

What makes privacy-preserving authentication trustworthy to everyday people?什麼樣的「隱私保護驗證」,才能讓日常大眾覺得值得信任?プライバシーを守る認証は、何をもって普通の人に信頼されるのでしょうか。

Audrey Tang

Zero-knowledge and Bluetooth-based designs can both preserve privacy. The difference is whether ordinary people can understand the protection.

If even a specialist needs two hours with the design papers, the mathematics may be solid while the system remains opaque. Focus on legibility.

唐鳳

零知識證明的設計、以藍牙為基礎的設計,都能保護隱私。差別在於:普通人能不能理解那層保護。

如果連專家都得抱著設計文件讀兩小時,那麼數學再紮實,系統依然不透明。請把力氣放在「可讀性」上。

オードリー・タン

ゼロ知識証明の設計も、Bluetoothベースの設計も、プライバシーは守れます。違いは、普通の人がその守りを理解できるかどうかです。

専門家でさえ設計文書と2時間つき合わないと分からないなら、数学は堅牢でも、システムは不透明なままです。可読性に集中してください。

Q2

Security Must Be Inspectable安全必須經得起檢驗検証できてこそ安全

#

Kokuryo-sensei asks國領教授提問國領先生の質問

How should a trustworthy system balance security and accountability?值得信任的系統,該如何平衡安全與課責?信頼に値するシステムは、セキュリティと説明責任をどう両立させるべきでしょうか。

Audrey Tang

Security by obscurity no longer buys dependable time. Automated systems can scan continuously and assemble attacks over a long horizon.

Defenders need the same machine-scale attention as attackers, alongside proof by construction: code whose invariants can be checked mathematically.

That is why long-lived systems such as SocialCalc are being given explicit proofs in Lean, LemmaScript and Dafny. Inspection has to be part of the build.

唐鳳

「靠隱匿求安全」再也買不到可靠的時間。自動化系統能不停歇地掃描,並用很長的時間軸拼裝攻擊。

防守方需要跟攻擊方同等的機器級注意力,還要加上「以構造證明」:讓程式碼的不變量可以用數學檢驗。

這正是為什麼像 SocialCalc 這樣的長壽系統,正在用 Lean、LemmaScript 與 Dafny 補上明確的證明。檢驗必須是建置流程的一部分。

オードリー・タン

「隠すことによる安全」では、もう当てになる時間を稼げません。自動化されたシステムは休みなくスキャンし、長い時間軸で攻撃を組み立てられます。

防御側には、攻撃側と同じ機械スケールの注意力が要ります。加えて「構成による証明」——不変条件を数学的に検査できるコード——が要ります。

だからこそ、SocialCalcのような長寿システムに、Lean、LemmaScript、Dafnyによる明示的な証明が与えられつつあります。検分は、ビルドの一部でなければなりません。

Q3

Public Money, Public Code公共出資,公共程式公共の資金、公共のコード

#

Kokuryo-sensei asks國領教授提問國領先生の質問

Where should government end and private or civic trust infrastructure begin?政府該止於何處?民間與公民的信任基礎設施,又從哪裡開始?政府はどこで終わり、民間や市民の信頼インフラはどこから始まるべきでしょうか。

Audrey Tang

Taiwan required the moda wallet to be completely open source. People who trust a government-issued wallet, a phone maker, a telecom, a school, a temple or another civic institution can choose that trust anchor.

The same public code and W3C standards let all of those providers issue interoperable wallets and credentials. Nobody is forced to trust a new counterparty.

唐鳳

臺灣要求 moda 的皮夾必須完全開放原始碼。信任政府發行的皮夾也好,信任手機廠商、電信業者、學校、寺廟或其他公民機構也好——人們可以自選信任錨點。

同一套公共程式碼與 W3C 標準,讓所有這些供應者都能發行可互通的皮夾與憑證。沒有人被迫信任新的對造。

オードリー・タン

台湾は、modaのウォレットを完全なオープンソースにするよう義務づけました。政府発行のウォレットを信頼する人も、電話メーカーを、通信キャリアを、学校を、お寺を、あるいは別の市民機関を信頼する人も、その信頼のアンカーを自分で選べます。

同じ公共のコードとW3C標準によって、これらすべての提供者が相互運用可能なウォレットとクレデンシャルを発行できます。誰も、新しい相手方を信頼するよう強いられません。

Q4

No Privacy–Convenience Trade-off隱私與便利,無需取捨プライバシーか利便性か、を超えて

#

Kokuryo-sensei asks國領教授提問國領先生の質問

Must individual control lose to the convenience of giant platforms?個人的自主掌控,注定輸給巨型平台的便利嗎?個人によるコントロールは、巨大プラットフォームの利便性に敗れるしかないのでしょうか。

Audrey Tang

Taiwan's 1922 SMS check-in took four seconds — about 10 seconds less than writing a phone number on paper, where the next person in line might see it.

It was more secure, more private and more convenient. A protective system that costs people too much time will simply be bypassed; trustworthy design must deliver both.

唐鳳

臺灣的 1922 簡訊實聯制只要四秒——比在紙上寫電話號碼快約十秒,而紙本還可能被下一位排隊的人看到。

它更安全、更隱私,同時更方便。太花時間的保護系統,只會被人繞過;值得信任的設計,必須兩者兼得。

オードリー・タン

台湾の1922 SMSチェックインは4秒でした——紙に電話番号を書くより約10秒速く、紙では次に並ぶ人に番号を見られかねません。

それはより安全で、よりプライベートで、より便利でした。人の時間を取りすぎる保護システムは、ただ迂回されるだけです。信頼に値する設計は、両方を届けなければなりません。

Q5

Portability is Exit Power可攜性就是退出的力量ポータビリティは退出の力

#

Kokuryo-sensei asks國領教授提問國領先生の質問

Why do portable identity and interoperable systems matter?可攜的身分與可互通的系統,為什麼重要?持ち運べるアイデンティティと相互運用可能なシステムは、なぜ重要なのでしょうか。

Audrey Tang

A platform can worsen its algorithm while keeping people captive through their contacts and followers. Without portability, everyone suffers together because leaving means losing the community.

Utah's Digital Choice Act points toward one-click export of the social graph and continuing interoperability. The familiar precedent is telephone-number portability.

When exit is practical, providers must earn the next subscription. Interoperability turns lock-in into a race to the top.

唐鳳

平台可以一邊惡化演算法,一邊用聯絡人與粉絲留住人。少了可攜性,大家只能一起受苦,因為離開等於失去社群。

猶他州的《數位選擇法》指向社交圖譜的一鍵匯出與持續互通。大家熟悉的先例,是電話號碼可攜。

當退出切實可行,供應者就得掙來下一期的訂閱。互通性把鎖定,變成一場向上的競賽。

オードリー・タン

プラットフォームは、アルゴリズムを悪化させながら、連絡先とフォロワーで人々を縛りつけておけます。ポータビリティがなければ、去ることはコミュニティを失うことなので、皆で一緒に苦しむことになります。

ユタ州のデジタル選択法(Digital Choice Act)は、ソーシャルグラフのワンクリック・エクスポートと、継続的な相互運用性を指し示しています。おなじみの先例は、電話番号ポータビリティです。

退出が現実的であれば、提供者は次の購読を稼がなければなりません。相互運用性は、囲い込みを頂上への競争に変えるのです。

Q6

Agentic ID Needs a Kernel代理身分需要核心エージェントIDにはカーネルを

#

Kokuryo-sensei asks國領教授提問國領先生の質問

If AI generates more than people can audit, how can an AI identity or mandate be trusted?如果 AI 產出的東西多到人類稽核不完,AI 的身分或授權要怎麼信任?AIが人の監査能力を超えて生成するなら、AIのアイデンティティや委任は、どうすれば信頼できるのでしょうか。

Audrey Tang

Mathematicians do not always re-check every step of a difficult proof. They verify a small kernel: the axioms and the valid moves that every step must obey.

The kernel is like a constitution. It works because it can fit into a person’s mind; every human or machine move is then checked for constitutionality.

Tools such as Lean and Dafny, and commitments such as the Leiden Declaration, let people use AI while the same foundation checks machines and humans.

唐鳳

數學家不會總是重驗一道難題證明的每一步。他們驗證的是一個小小的核心:公理,以及每一步都必須遵守的合法推導。

核心就像一部憲法。它行得通,是因為裝得進一個人的腦海;接著,每一步——無論出自人或機器——都可以受違憲審查。

像 Lean 與 Dafny 這樣的工具,加上像《萊頓宣言》這樣的承諾,讓人們能使用 AI,同時由同一套地基檢驗機器與人類。

オードリー・タン

数学者は、難しい証明のすべてのステップをいつも検算し直すわけではありません。検証するのは小さなカーネル——公理と、すべてのステップが従うべき正しい手筋です。

カーネルは憲法のようなものです。一人の頭に収まるからこそ機能します。そのうえで、人の一手も機械の一手も、すべて合憲性を審査されるのです。

LeanやDafnyのようなツール、そしてライデン宣言のようなコミットメントがあれば、人はAIを使いながら、同じ土台で機械と人間の両方を検査できます。

Q7

A Short Path from Harm to Repair從傷害到修復,路要短被害から回復への最短路

#

Kokuryo-sensei asks國領教授提問國領先生の質問

How can Taiwan and other democracies collaborate on building trust?臺灣與其他民主政體,要怎麼在建立信任上協作?台湾とほかの民主主義国は、信頼の構築でどう協力できるでしょうか。

Audrey Tang

Democracy means that the path from harm to repair is short. People can organise, mobilise and become a civic counterpower — as Taiwan did during the Sunflower Movement — rather than accept harm without recourse.

Democracies can broadcast harms as shared evaluations so that each person's AI can test whether the same pattern is reaching them.

ROOST offers a working pattern: platforms keep their own standards and filters, but share threat-detection code without exposing the people being protected. What CERT teams do for cyber incidents can extend to the information realm.

唐鳳

民主的意思是:從傷害到修復的路很短。人們可以組織、動員,成為公民的抗衡力量——就像臺灣在太陽花運動中那樣——而不是無處求償地承受傷害。

民主政體可以把傷害廣播成共享的評測,讓每個人的 AI 都能檢測:同樣的模式是否正在逼近自己。

ROOST 提供了一個可行的模式:平台各自保有標準與過濾器,但共享威脅偵測的程式碼,而不暴露被保護的人。CERT 團隊在資安事件上做的事,可以延伸到資訊領域。

オードリー・タン

民主主義とは、被害から回復への道のりが短いということです。人々は組織し、動員し、市民の対抗力になれます——台湾がひまわり運動でそうであったように。救済のないまま被害を受け入れるのではなく。

民主主義国は、被害を共有の評価として発信できます。そうすれば、一人ひとりのAIが、同じパターンが自分に届いていないかを検査できます。

ROOSTは動くパターンを示しています。プラットフォームは自前の基準とフィルターを保ちつつ、守られている人々をさらすことなく、脅威検知のコードを共有する。CERTチームがサイバーインシデントで行っていることは、情報の領域にも延長できるのです。

Q8

The Plurality is Here多元,已經來臨プルラリティはここに

#

Kokuryo-sensei asks for the final 90 seconds國領教授請用最後九十秒作結國領先生、最後の90秒を求める

What final message should our room carry forward?這個會場該帶走的最後訊息是什麼?この会場が持ち帰るべき、最後のメッセージは何でしょうか。

Audrey Tang

In Taiwanese Mandarin, shùwèi means digital and also plural. So, Taiwan’s first digital minister was also a minister of plurality.

When we see an internet of things, let us make it an internet of beings. When we see virtual reality, let us make it a shared reality. When we see machine learning, let us make it collaborative learning.

When we see user experience, let us make it about human experience. Whenever we hear that the singularity is near, remember. The plurality is here — because We the People Are Truly the Superintelligence.

Kokuryo-sensei: “Thank you so much for this talk. Wonderful.”

唐鳳

在臺灣華語裡,「數位」既指 digital,也指「好幾位」。所以臺灣的第一任數位部長,同時也是「多元」部長。

看見「萬物聯網」,我們將智慧聯網
看見「虛擬實境」,我們將實境共享
看見「機器學習」,我們將協力學習
看見「用戶體驗」,我們將體驗人際
聽說「奇點即將接近」——多元已經來臨,因為我們全民,才是超級智慧

國領教授:「非常感謝這場演講,太精彩了。」

オードリー・タン

台湾華語で「数位(シューウェイ)」は、デジタルであると同時に「複数」も意味します。だから台湾の初代デジタル大臣は、「複数性(プルラリティ)」の大臣でもあったのです。

「IoT(モノのインターネット)」を見たら、「生き物のインターネット」を考えよう。
「仮想現実」を見たら「共有現実」にしよう。
「機械学習」を見たら「共同学習」にしよう。
「ユーザー体験(UX)」を見たら「人間同士の体験」にしよう。
「シンギュラリティは近い」と聞いたら思い出そう。
「多元性」はいまここにある。なぜなら、われら人民こそ、真の超知能だからだ

國領先生「このご講演、本当にありがとうございました。素晴らしかったです」