China’s 360 Security Technology has announced the autonomous AI security system “Yitian Tulong.” Behind this is a strategic move to secure its own cyber defense and attack capabilities in response to U.S. export restrictions on advanced AI models.
- The ISC.AI 2026 Opening in Beijing and the Shock of the Announcement
- Two autonomous systems responsible for offense and defense: ‘Dragon Slayer’ and ‘Yitian Formation’
- Overwhelming empirical data from 3,432 vulnerabilities discovered
- Export bans on the U.S. model “Mythos” and strategic deterrence
- The ‘Multi-Agent’ Strategy to Avoid Semiconductor Sanctions
- The ‘Rock Shield’ Safety Cooperation Plan brings together domestic companies
- Paradigm shift from “passive defense” to “active immunity”
The ISC.AI 2026 Opening in Beijing and the Shock of the Announcement
On June 24, 2026, the 14th Internet Safety Conference (ISC.AI 2026) opened at the National Convention Center in Beijing. The biggest highlight of this event was the official unveiling of the autonomous AI security system “Yitian Tulong” by 360 Security Technology (360), a leading cybersecurity company in China. This name is derived from two legendary weapons from Chinese classical wuxia novels: the ‘Heaven-Reliant Sword’ and the ‘Dragon Slayer Saber,’ symbolizing the ultimate integrated offensive and defensive system in cyberspace. Until now, cybersecurity has been led by humans, with AI serving only as a supplementary tool. However, this announcement clearly declares a transition to an era of “intelligent agents,” where AI autonomously makes decisions and acts with minimal human intervention. Conference chair Zhou Hongyi analyzed that AI is delivering a “different dimension of blow” to the industry, fundamentally changing the balance of offense and defense, emphasizing that this system will become key to China’s digital security.
Two autonomous systems responsible for offense and defense: ‘Dragon Slayer’ and ‘Yitian Formation’
“Yitian Tulong” consists of two specialized autonomous AI systems with different roles. First, the offensive aspect is called “Tulongfeng.” This is positioned as the Chinese version to counter Anthropic’s latest security model, “Mythos,” and specializes in automatically discovering unknown software vulnerabilities (zero-day vulnerabilities). The other is the defending “Yitianzhen,” which functions as an AI-driven Security Operations Center (SOC). It is designed to automate everything from threat detection and isolation to real-time incident response, guiding network operations into a state of “autonomous driving.” By combining these two systems, it becomes possible to execute high-precision cyber operations 24/7 without rest, running at machine speed in parallel. The diagram below shows how these two systems work together to protect organizational security.

Overwhelming empirical data from 3,432 vulnerabilities discovered
The performance of this system is already supported by concrete figures. According to 360 Security Technology’s announcement, the vulnerability detection agent “Tulongfeng” has autonomously identified a total of 3,432 software defects so far. Of these, 105 have been officially confirmed as effective by Chinese regulatory authorities. Notably, it boasts overwhelming “speed” and “low cost.” While traditional human analysis often took months to years to audit large software code and discover vulnerabilities, leveraging AI has reportedly improved vulnerability detection speed by more than 100 times. Additionally, Zhou claims that there has been dramatic efficiency improvements in cost, making it possible to discover vulnerabilities and build attack chains at less than one-thousandth the cost of the previous one-thousandth of the previous cost. This suggests that the balance of offense and defense, maintained over the past 30 years under the premise that ‘vulnerabilities are hard to find,’ has effectively collapsed.
Countermeasures against the US-China AI Cold War and the “Technology Blockade”
Export bans on the U.S. model “Mythos” and strategic deterrence
The development of “Yitian Tulong” is driven by the intense AI competition between the US and China, as well as security confrontations. On June 9, 2026, U.S. company Anthropic announced the AI model “Mythos 5,” which boasts extremely strong cybersecurity capabilities. However, just three days later, on June 12, the U.S. government designated this model as an “export control item” and strictly prohibited its provision to foreign nationals. By monopolizing this technology, the U.S. is carpet-scanning Western infrastructure to close vulnerabilities, while maintaining “one-sided transparency” (showing the opponent’s weaknesses but hiding their own) to adversaries like China. In response, 360 Security Technology determined that it is essential for it to have its own unique capabilities. Mr. Zhou stated, “If Mythos is the top-tier chip, what we are building is a finished machine,” positioning this system as a “strategic deterrent” to break Western monopolies.
The ‘Multi-Agent’ Strategy to Avoid Semiconductor Sanctions
Currently, China faces U.S. export restrictions restricting access to advanced semiconductors, and in building massive single models, it is 20% to 30% less capable of building a single model. To break this ‘silicon blockade,’ 360 adopted an engineering solution called the ‘Multi-Agent Collaboration System,’ which links many small domestic AI agents. This approach is not about creating a single super-genius “hacker AI,” but rather combining multiple AI agents specialized in specific fields with the company’s vast vulnerability database and attack experience accumulated over more than 20 years. For example, one agent screens for code anomalies, another performs deep analysis, and yet another performs verification in a virtual environment—collaborating to compensate for computing power shortages while delivering results comparable to those of US-made models.
A New Security Framework and Future Prospects
The ‘Rock Shield’ Safety Cooperation Plan brings together domestic companies
Recognizing that cybersecurity is a systematic battle that cannot be completed by the efforts of a single company alone, ISC. At AI 2026, the “Panshi Shield” safety cooperation plan was launched. This plan centers on 360 Security Technology, along with major companies supporting China’s digital infrastructure, including domestic OS companies like Kirin and UnionTech, chipmakers Haiguang and Feiteng, and Mobile Cloud, which handles databases and cloud infrastructure. The purpose of this partnership is to quickly open and share Yitian Tulong’s autonomous vulnerability detection and defense capabilities with key information technology innovation enterprises and critical infrastructure sectors within China. Just as the United States is strengthening Western defenses through the “Glasswing” initiative, which involves more than 50 major companies, China is also building its own AI safety ecosystem that integrates industry, government, and academia, aiming to enhance its resilience against external attacks.
Paradigm shift from “passive defense” to “active immunity”
The most important change in future cybersecurity deployment is the shift from “passive defense” to “active immunity.” Until now, the mainstream approach was to respond after an attack or to defend based on known patterns, but with the introduction of autonomous AI, the system itself will continuously identify its own weaknesses and automatically repair and adapt before an attack occurs. Mr. Zhou describes this as security operations in the “era of autonomous driving.” Going forward, the era of “human wave tactics,” where humans check and respond to each alert one by one, will come to an end, and the era will become the norm where AI agents engage in battles at machine speed. The Chinese government also supports this move, indicating plans to establish AI safety standards, train talent, and accelerate the scaled commercial deployment of the technology. Cyber warfare in the AI era has entered a phase where competition is no longer about “who is stronger” but about “who is faster.”
[#サイバーセキュリティ #人工知能 #中国技術 #ISC. AI2026 #自律型AI #YitianTulong #デジタル安全保障]


コメント