Runjian Co., Ltd. has built the "Runjian·Zhiyu" full-lifecycle security system, redefining the security boundaries in the AI era.
On the afternoon of September 19, an event named "AI Intelligent Security Practical Drill Exchange Meeting" was held at Nanning Wuxiang Cloud Valley AI Intelligent Computing Industrial Park. The agenda ranged from "Security Blueprint in the Intelligent Era: Top-level Design and Implementation Path of AI Security Governance" to "National Cybersecurity Requirements and Compliance Red Lines", followed by the post-exercise review of the national cyber defense drill, the two-line practical demonstration of AI attack and defense, and finally concluded with a roundtable discussion themed "Where Does Cybersecurity Go in the AI Era".
Over three and a half hours, participants from government and enterprises and the security industry gathered to discuss the same issue.
This type of event is not uncommon, but the focus of the topic this year is clearly shifting. The focus of discussion is no longer just "how to defend against hackers", but a deeper question: when AI is widely integrated into the core business of enterprises, and when Chinese AI capabilities start to go global, where is the original security boundary, and how should it be redrawn?
A sentence was frequently quoted at this event. Dr. Chu Ge, Chief AI Security Scientist of Rojian Co., Ltd., defined this transformation as follows: "In the past, what we prevented was 'the system being hacked', but now we also need to prevent 'AI from being deceived, abused, and prompt-injected'."
This sentence is not complicated, but it draws a clear dividing line.
The globalization of Chinese AI capabilities is already an ongoing reality. The ASEAN markets including Vietnam, Malaysia and Indonesia have become one of the most popular overseas destinations for Chinese AI enterprises. Model capabilities are no longer a threshold, deployment solutions have mature templates, and business teams have all been dispatched. However, in many overseas projects, one key account has not yet been clearly calculated.
It is not a technical account, but a security account.
The old security system cannot defend against new attacks
Before the large-scale implementation of large models, the logic of enterprise cybersecurity was relatively clear. Attackers targeted system vulnerabilities, while defenders patched vulnerabilities, implemented isolation and deployed firewalls. Humans acted as judges in the middle, experts wrote rules, analyzed logs, and organized drills. This system has been operating for more than 20 years.
However, after large-scale AI intervention, this logic began to fail. The reason is simple: the attack surface has changed, the attack method has changed, and the attack speed has also changed.
Nowadays, enterprises use AI to process customer service conversations, contract review, internal approval, and even data analysis. Agents move around in the company's systems, calling databases, operating files, and interacting with external APIs. In these scenarios, the attacker's goal is no longer just "getting into the system", but "making AI do things it should not do".
Prompt injection, model jailbreak, and agent privilege abuse were experimental conclusions in academic papers two years ago, but now they are real enterprise security incidents. In the post-exercise review session of the cyber defense drill at the exchange meeting, similar cases were repeatedly analyzed: the real gap between "being eliminated" and "getting full marks" in the cyber defense drill usually does not come from the generation difference of tools, but from the cognitive blind spot of the new AI attack surface.
This is why during the 2026 WAIC, when Rojian Co., Ltd. released the "Rojian·Zhiyu" intelligent security product system, Dr. Chu Ge directly pointed out that "the security problems brought by AI must ultimately be solved by AI". This is not a marketing slogan, but a judgment forced out by real reality.
Going global makes this account even harder to calculate
On the day of the exchange meeting, the section of "National Cybersecurity Requirements and Compliance Red Lines" shared by experts made many representatives of overseas enterprises present lost in thought. The compliance red lines vary from place to place, so this problem becomes even more difficult to answer after going global.
The first is the security vulnerability of Token invocation.
A large part of the form of Chinese AI capabilities going global is to provide services by invoking domestic large models. Users input information overseas, the data is transmitted to the model, and the results are transmitted back. In this round trip, every node in the middle is a potential risk point. Any mistake in the production, invocation, transmission and storage of Token may cause data leakage. Physical isolation can be used as a fallback in pure domestic deployment, but once going global, a more sophisticated technical solution is required.
There is also the structural problem of inconsistent compliance red lines.
Chinese overseas enterprises need to meet the requirements of three systems: local regulations of the destination country, the *Data Security Law of the People's Republic of China* and the *Personal Information Protection Law of the People's Republic of China*. These three sets of rules are sometimes consistent in direction, and sometimes have real tensions, and there is no universal standard answer that can be copied in practice so far.
For enterprises like Rojian Co., Ltd. that have laid out in ASEAN for more than 10 years and implemented more than 100 local projects, these are not hypothetical scenarios, but real obstacles encountered daily. In the context of going global, security is no longer just a technical issue, but a prerequisite for enterprises to truly take root in the local market and win the trust of customers.
A lock is not enough, we also need security guards and monitoring systems
Rojian Co., Ltd.'s answer to this question has finally been implemented in four products, but behind it is a complete system, not four independent tools.
Dr. Chu Ge used a metaphor to clarify its design idea: "AI security cannot be solved by a single lock, but a complete set of 'lock + security guard + monitoring system'. The key is in the hands of customers, and we are responsible for ensuring that this door is truly well-defended."
In the attack direction, "Hive" plays the main role. It is an AI penetration testing system based on the multi-agent swarm collaborative architecture. Multiple penetration agents work in parallel under the same task, playing the roles of reconnaissance, main attack, verification and support respectively, collaborating in real time through a unified operation map, pushing the attack path forward in relay, and sharing intelligence and results instantly. Different from the traditional red team's "single-line groping" method, it can converge efficiently in complex environments and record the whole process.
In the two-line practical demonstration of AI attack and defense on the day of the exchange meeting, the full attack chain capability of the Hive system was presented on site, from reconnaissance and identification to privilege acquisition, with full autonomy and zero manual intervention. This product scored 98.44 points in the TSecBench intelligent attack and defense evaluation of Tencent Security Yunjing Laboratory, ranking first in the list. It independently completed the full penetration link in the production-level range environment, and the results came from the real confrontation environment, not the simplified demonstration scenario.
Aiming at the security risks of large models themselves, Rojian Co., Ltd. also launched "ModelShield" and "ModelInsight". ModelShield is deployed at the entrance and exit of the model, intercepting abnormal input and output through prompt enhancement and two-way detection, ensuring that sensitive data does not go beyond the protection boundary; ModelInsight focuses on continuous evaluation before and after launch, automatically generating attack samples to help enterprises continuously discover and fix the security blind spots of the model. The four products together form a complete closed loop from attack verification to defense response, and then to large model security governance.
To put it simply, the core problem this system aims to solve is to enable overseas customers to build real trust in Chinese AI services, not just trust at the technical level.
In the roundtable discussion session, the participants discussed the theme of "Where Does Cybersecurity Go in the AI Era", covering two dimensions: "the security of AI itself" and "using AI to do cybersecurity". The two clues seem to be parallel, but they actually share the same origin: the more deeply AI capabilities are integrated into the core of enterprises, the greater the impact on both attack and defense ends, and the more the security design needs to be reconsidered from the bottom level.
If computing power is the base of the AI era, security is the new boundary of the AI era. This boundary is moving forward from "remediation after launch" to "built-in throughout the full life cycle", and from an additional item of AI applications to a prerequisite for AI to achieve real large-scale implementation overseas.
The real problem is not how important this matter is, but that most enterprises have not yet begun to seriously calculate this account.