← Back to list

Human + AI Unified Governance: The Architecture That Won China’s Top Security Competition

Eagle Cloud took first place at China’s 11th Security Innovation Competition. The winning idea: governing humans and AI agents as one…

Eagle Cloud · 2026-06-05 16:47 · 0 claps · 5.4 min read
#cybersecurity #ai #technology #risk-management #ciso
Open on Medium ↗
Wiki topics: AGT · AI Agents AI · AI · General BIZ · Business Strategy 🔒 · Cybersecurity 🏛️ · Architecture

The Architecture That Just Won a National Security Championship

🌐 Read in: English | 繁體中文

Thirty startups entered the final. On June 2, one took the national championship at China’s 11th Security Innovation Competition in Beijing: Eagle Cloud.

Ye Min, Co-Founder & CSO of Eagle Cloud received the champion and certificate

Ye Min, Co-Founder & CSO of Eagle Cloud received the champion and certificate

The Security Innovation Competition is one of China’s most influential platforms for cybersecurity startups. Over eleven years, nearly a thousand startups have entered, over a hundred projects have been incubated, and more than 6 billion RMB in cumulative funding has flowed through its alumni.

This year’s focus areas: AI + security, data security, agent security, and the OpenClaw technical framework, which all point to where enterprise security is heading next.

The winning pitch was not a new detection engine. It was not a faster firewall. It was a governance model: treat humans and AI agents as one workforce, govern them as one system.

What Won: “Human + AI” Unified Governance

Eagle Cloud co-founder and CSO Ye Min presented on stage:

Eagle Cloud co-founder and CSO Ye Min presented on stage about AI governance

Eagle Cloud co-founder and CSO Ye Min presented on stage about AI governance

“The operational deployment of AI agents at scale has brought enterprises into a new organisational form, one where humans and AI agents coexist. This creates complex new security risks and has become the central challenge of digital transformation. Eagle Cloud is the first to implement a ‘Human + AI’ unified security governance architecture built on a core philosophy: understand intent first, then judge and act. The result is a self-evolving security system where AI governs AI.”

SASE governs human employees. AIDR governs AI agents. IRM correlates risk across both. EagleEye gives leadership one pane of glass. Together, they form a closed loop: understand intent, judge before acting, enforce across the entire workforce.

The judges agreed. But the competition result is a signal, not the story.

The real question is what happens when enterprises deploy AI agents without a governance model that treats them as part of the workforce.

The Problem: AI Agents Are Already Inside

Most enterprises do not know how many AI agents are running in their environment — or which everyday AI tools their employees are actually using. Not the sanctioned ones. The ones employees installed themselves, configured with a BaseURL, pointed at an external model provider, and quietly gave access to internal data.

This is not hypothetical. AIDR, our AI governance module, was built to solve exactly this: auto-discover AI tools in use across the organisation, detect agent software on endpoints, audit configurations, monitor behaviour, and flag what should not be running.

What enterprises find after a first discovery pass is almost always the same: more agents than anyone expected. Some bound to MCP servers with broad tool access. Some running scheduled tasks that touch production data. All invisible to existing security tools.

Why invisible? Because those tools were built for a world where the threat surface was human behaviour. They flag USB copies, email attachments, large downloads. They do not flag an AI agent that queries a customer database, exports the result, and clears its session logs. Three separate events across three separate tools, no connection, no context, no alert.

When Ye Min described the “Human + AI unified governance” architecture on stage, this was the gap he was describing. Not a gap in detection. A gap in the governance model itself.

The Misconception: You Can Bolt AI Governance Onto Your Existing Stack

The industry reflex when a new attack surface appears is to add another tool. An AI firewall here. An agent scanner there. A separate dashboard for AI risk.

The result is fragmentation: different data models, different policy engines, no cross-correlation between human and AI agent activity.

The architectural insight behind the winning pitch is simpler than it sounds. The most dangerous paths in an enterprise cross between human and AI agent activity. An AI agent extracts data. A human sends it. From separate tools, these look like two innocuous events. From one governance platform, they look like a data exfiltration chain.

You cannot see that chain if humans and AI agents live in separate governance systems.

The Architecture: SASE + AIDR + IRM + EagleEye

Eagle Cloud AI-Native Product Matrix diagrm

Eagle Cloud AI-Native Product Matrix diagrm

SASE governs human employees: zero-trust access, endpoint security, data loss prevention, web filtering. Every human action leaves a log. Every policy is enforced at the identity and device level.

AIDR governs AI agents: auto-discovery of agent software, configuration auditing, behaviour monitoring, full dialogue capture and masking, firewall-level control over which AI tools can run.

AI-IRM is the correlation layer. It ingests over 200 log types from both SASE and AIDR, chains related events across human and AI agent activity, and applies intent inference — the same action at 2 PM on a Tuesday versus 2 AM on a Sunday, the same data access by a tenured employee versus a contractor serving notice. The output is not raw alerts. It is prioritised incident case files with full evidence trails.

EagleEye is the governance interface for leadership. Natural language queries. Global situational awareness. Policy setting and outcome verification. Not “here are 10,000 alerts”, but “here are the three things you need to pay attention to this week.”

Ye Min’s emphasis on “unified” was deliberate. Not “integrated.” Not “interoperable.”

Unified: one client, one platform, one governance model for everyone and everything that touches enterprise data.

From Competition Win to Strategic Advancement

The competition win marks more than a trophy. Eagle Cloud has formally advanced from “integrated office security platform” to “AI-era enterprise security governance infrastructure”, continuously strengthening the core of “Human + AI” unified security governance, so enterprises can adopt and use AI with confidence in a secure environment.

Founded in 2021, Eagle Cloud has completed five funding rounds, backed by HongShan, Vision Plus Capital, Eminence Ventures, Future Innovation Fund, and Monolith Management. Today, the platform serves over 1,000 enterprises worldwide, protects more than 5 million endpoints, and covers 20+ industries, from smart manufacturing and internet platforms to financial services, pharmaceuticals, and retail.

Three Things Security Teams Should Do Now

  1. Discover your AI agent footprint before you try to govern it. You cannot write policies for agents you do not know exist. Run a discovery pass across your endpoints. Count the agent software. Check the configurations. You will likely find more than you expect.
  2. Stop treating AI risk and human risk as separate workstreams. If your DLP tool and your AI governance tool do not share a data model, you are blind to the most dangerous cross-over paths. The threat is not “an AI agent did something.” It is “an AI agent did something, and then a human acted on it.”
  3. Start with visibility, not enforcement. The first phase should be discovery and monitoring — build the baseline, understand what normal AI agent behaviour looks like in your environment. Enforcement comes after you know what normal looks like. Most organisations skip this step and jump straight to blocking, which either breaks legitimate workflows or creates shadow AI elsewhere.

The Security Innovation Competition has been running for eleven years. Nearly a thousand startups have entered. Over 6 billion RMB in cumulative funding has flowed through its alumni. In 2026, the top prize went to an architecture that treats humans and AI agents as one governed workforce.

AI agents are already operating inside the enterprise. That question is settled. The market is already moving.

The real question is whether your governance model is ready

📩 Book a consultation or live demo: info@eaglecloud.com

🔗 Explore solutions: www.eaglecloud.com

💼 Follow us for updates: LinkedIn

Source: Eagle Cloud WeChat official announcement


메타데이터
post_id
85ecd2ec7d91
slug
https-medium-com-eaglecloud-security-innovation-champion-human-ai-governance-85ecd2ec7d91
url
https://medium.com/@eaglecloud/https-medium-com-eaglecloud-security-innovation-champion-human-ai-governance-85ecd2ec7d91
canonical_url
https://medium.com/@eaglecloud/https-medium-com-eaglecloud-security-innovation-champion-human-ai-governance-85ecd2ec7d91
author_url
https://medium.com/@eaglecloud
status
ok
fetched_at
2026-06-15 20:49:13