VNPT-IT shares approaches to governing and applying AI agents at Security Bootcamp 2026

At Security Bootcamp 2026 on 10–11 September, experts from VNPT Cyber Immunity (VCI) presented two perspectives on AI agents: how to put safeguards in place when AI can act autonomously, and how to use the technology to accelerate malware analysis. Their presentations highlighted AI's potential to strengthen cyber defence while keeping AI systems safe and accountable.

A VCI speaker presents at Security Bootcamp 2026.

When AI can act, who controls it?

The development of AI agents is opening up new ways for artificial intelligence to interact with technology systems. Beyond receiving requests and providing answers, an AI agent can read data, reason through a task, call tools and carry out certain assigned actions directly.

These abilities offer substantial potential for automation and process improvement. But as AI is granted greater autonomy, the safety question is no longer simply 'What can AI do?' It becomes 'What is AI allowed to do, within what boundaries, and who is responsible for overseeing its actions?'

On 10 September, Nguyen Tuan Hung, a research and development engineer specializing in information security solutions at VCI, delivered a presentation titled 'When AI Can Act, Who Controls the AI?' He examined the role of AI guardrails in setting operating rules and limits for AI systems.

A speaker presents at Security Bootcamp 2026.

The approach he outlined calls for safeguards across several layers: data, prompts, models, AI agents and connected tools. Together, these controls allow AI agents to automate tasks within their authorized scope while reducing the risk of accessing the wrong data, using unsuitable tools or taking actions beyond their original purpose.

Overview of the presentation on AI-agent and tool safeguards at Security Bootcamp 2026.

AI agents accelerate malware analysis

On 11 September, VCI security analysis engineers Ta Dang Vinh and Nguyen Duy Binh followed with a presentation titled 'Malware Analysis in Agent Era: From Config Extraction to Deobfuscate'.

They described how AI agents can support multiple stages of malware analysis, from extracting indicators of compromise (IoCs) and examining configuration data to assisting with reverse engineering and deobfuscation.

By combining AI agents with specialized skills and the Model Context Protocol (MCP), security analysts can automate parts of their work, gather information faster and shorten the time needed to investigate complex malware samples. The method also brings together results from multiple tools for a more coherent and efficient analysis workflow.

As cyber threats grow more sophisticated, AI does not replace security experts. It supports and extends their capabilities by reducing repetitive work, speeding up investigations and improving the detection, analysis and response to information-security risks.

Towards a unified digital immune system

Positioning itself as a partner that advises on and executes comprehensive security strategies, VCI aims to build a unified digital immune system instead of deploying disconnected security tools. This approach links security capabilities, brings together fragmented resources and gives organizations a single partner throughout the risk-management lifecycle.

VCI's three championship wins and its many years of involvement in Security Bootcamp—from Gold Sponsor to Gold Media Partner in 2026—reflect its sustained participation in one of Vietnam's cybersecurity community's specialist forums.

Through its presentations at Security Bootcamp 2026, VCI continues to share expertise, promote the safe and governed use of AI, and work with the community to build a safer digital environment.