Taiwan takes the lead in formulating SEMI E187, the world's first semiconductor equipment security standard. Several ministers and TSMC experts emphasize security testing and AI Agent risk management.
Quick Look
- SEMI E187, the world's first semiconductor equipment security standard developed by Taiwan, issued a verification mark at SEMICON Taiwan 2026.
- Digital Development Minister Lin Yi-king used the metaphor of a Trojan horse to emphasize the importance of security testing before equipment enters the factory.
- Tu Zhen, senior director of global security management at TSMC, warned that AI Agents may cause substantial security risks when they have the ability to execute, and proposed the concept of Trust-only Network to deal with the threat of AI-accelerated network attacks.
AI-generated summary
Why It Matters
Major information security incidents have occurred in the semiconductor industry, and malicious programs may have entered fabs through manufacturing equipment. Taiwan took the lead in formulating the world's first semiconductor equipment information security standard SEMI E187 to strengthen supply chain protection.
The world's first semiconductor equipment security standard "SEMI E187" led by Taiwan, a verification mark announcement ceremony was held today (4th) at SEMICON Taiwan 2026. (Photo by reporter Qiu Qiaozhen)
[Reporter Qiu Qiaozhen/Taipei Report] The world's first semiconductor equipment security standard "SEMI E187" led by Taiwan, a verification mark announcement ceremony was held today (4th) at SEMICON Taiwan 2026.
In his speech, Minister of Digital Development Lin Yi-king took the major security incident in the semiconductor industry in 2018 as an example, comparing manufacturing equipment that may carry viruses into the wafer factory to a "Trojan horse" and emphasizing the importance of security testing before equipment enters the factory.
Please read on...
Lin Yijing pointed out that this is why the semiconductor industry needs the SEMI E187 standard. "All Trojans that want to enter the city of Troy in the future must be inspected first." Similarly, all manufacturing equipment entering wafer fabs and other facilities should also undergo complete information security inspections to reduce the risk of equipment becoming a conduit for hackers to invade. He also said that the Digital Development Department is honored to participate in the formulation and development of the SEMI E187 standard, and looks forward to jointly strengthening the information security defense line of the semiconductor supply chain through industry-government cooperation.
Tu Zhen, senior director of global security management at TSMC, mentioned that the biggest difference from the past generative AI to AI Agent (AI agent) is that AI no longer just generates content or answers questions, but begins to obtain system access rights, and can even actually perform tasks on behalf of users. This also allows the possible impact of AI "illusion" to further extend from the information level to actual corporate operations.
Tu Zhen said that enterprises can import their own data and company information to let large language models (LLM) better understand the needs of the enterprise, but AI may still produce hallucinations or provide wrong answers. In the past, if the model gave wrong answers, the impact might be relatively limited; but when the AI Agent has actual execution capabilities, once the LLM gives a wrong direction and the Agent takes action in accordance with the instructions, it may cause real information security risks.
Especially when AI Agent begins to participate in transactions or actual operations, the problem will become more complicated. Tu Zhen pointed out that, therefore, when enterprises introduce AI Agents, they cannot just focus on the model itself, but must also establish a complete authorization control and Agent Identity (AI Agent identity) management mechanism to prevent the Agent from directly performing operations on key resources.
On the other hand, AI is also speeding up cyber attacks. Tu Zhen cited Gartner analysis and pointed out that current AI risks mainly come from making existing attacks "faster", but speed itself is a threat, including faster discovery of vulnerabilities and weaponization of vulnerabilities.
This also means that enterprises and IT solution providers must change the past model of patching vulnerabilities according to a fixed schedule and move towards "dynamic patching" and "patching on demand".
Looking to the future, he believes that AI will also bring new opportunities to the information security industry. Enterprises must "use AI to fight AI" in the future. In the past, he has proposed that information security solutions should pursue the "Double Zero" concept, which means to strengthen security protection while not affecting the operation of production equipment as much as possible and making users "insensitive" to information security measures. Now he has further proposed the concept of "Trust-only Network", hoping to establish a network environment where only trusted objects can enter.
Tu Zhen said that zero trust requires continuous verification at every link. It is like being in a community where good people and bad people coexist. After returning home, you still have to lock the doors of the kitchen, bathroom, and living room. It is not easy to implement. As AI technology matures, there will be opportunities to further develop towards a "Trust-only" network architecture in the future.
Grasp the economic pulse with one hand. Click here to subscribe to Free Finance Youtube Channel
What to Watch
AI outlook — possibilities, not facts
In the future, semiconductor equipment entering the wafer fab will be required to have a SEMI E187 verification mark.
Likely · Within months
Enterprises will accelerate the adoption of dynamic patching and on-demand patching to replace fixed-scheduled vulnerability patching models
Possible · Within months
The concept of Trust-only Network will be gradually applied on a pilot basis in environments with high security requirements.
Possible · Within years
Open Questions
- What is the specific implementation timetable and verification process of the SEMI E187 standard?
- How will semiconductor manufacturers outside Taiwan adopt this standard?
- How is the implementation and cost-effectiveness of the Trust-only Network concept in actual network architecture?







