Hong Kong’s AI Cybersecurity Final Brings 40 Teams Into Competition

Hong Kong is using a competition format to test how AI may change cyber defense. The concluding stage of Hong Kong’s first AI x Cybersecurity Challenge took place on August 23, narrowing 290 submissions from China and abroad to 40 teams. In a Hong Kong government release, Secretary for Innovation, Technology and Industry Sun Dong described the event as a platform for building cybersecurity capability in an AI-driven environment.

The competition does not settle whether autonomous AI agents can make networks safer. It does put that question into a practical setting. Teams used AI tools to hunt for weaknesses inside controlled digital environments, turning a broad policy concern about AI security into a hands-on contest involving students, researchers, and industry participants.

The First AI x Cybersecurity Challenge Links Talent to Defensive Practice

Sun said the challenge received 290 entries and selected 40 finalists. The government release identifies the Chinese Academy of Cyberspace Studies as an organizer. It also lists Hong Kong’s Cybersecurity Professional Association, China Mobile’s local unit, and the Digital Policy Office.

That cross-border structure is important. Cybersecurity does not fit neatly within a single city or company, and Hong Kong has positioned itself as a place where mainland, local, and international participants can meet. The finalist count is modest compared with a national training program, but a final-round contest can still create a concentrated test of technical skills and a network of people working on related problems.

The task itself focused on vulnerability identification in simulated environments. That matters because simulations allow participants to test techniques without putting a live organization at risk. They also make it possible to judge whether an AI-assisted approach identifies weaknesses efficiently and whether a human participant can evaluate the results.

Hong Kong’s initiative arrives as Chinese model providers are also connecting AI with security work. EastFrontier covered Z.ai’s GLM-5.3 release for cybersecurity and coding, which showed how a model company is presenting AI as a tool for technical tasks. The Hong Kong challenge looks at a different layer: how people can apply AI in the defense of digital systems.

Hong Kong Frames Cyber Defense as AI Versus AI

Sun described the policy approach as AI versus AI. His argument was that the same technologies that introduce new risks can also strengthen defenses against those risks. That is a government position, not a measurement of current effectiveness, but it reflects an increasingly common view among policymakers and security practitioners.

AI can help security teams process large volumes of logs, find patterns, prioritize alerts, and support analysts. It can also make phishing, code generation, reconnaissance, and malicious automation more accessible. A challenge that asks participants to find vulnerabilities with AI is therefore testing both the promise and the tension of the technology.

The government release emphasizes responsible use. Sun said Hong Kong was strengthening policies, guidelines, ethical frameworks, and regular cyber-attack-and-defense drills as part of its preparedness work. The challenge becomes one element in a broader program that includes rules and resilience, rather than a stand-alone technology showcase.

That broader approach is necessary in a city where AI adoption is reaching more workplaces and public services. EastFrontier’s report on Hong Kong’s rise in AI privacy complaints illustrates why training cannot be separated from governance. A tool that identifies a network weakness may be useful, but it still has to operate within rules for personal data, access, and accountability.

The Challenge Will Be Turning Competition Results Into Durable Capability

The strongest outcome from the final will not be a single winning team. It will be a pipeline that connects participants to sustained work in cyber defense, AI evaluation, and technology governance. The competition has created a common exercise and a set of contacts across institutions, but real-world security work requires continuous testing, updating, and response.

There are also technical limits to keep in view. An AI system may surface a possible vulnerability without understanding the business context that determines its actual severity. It may generate an explanation that sounds plausible but is wrong. Human experts still need to validate findings, decide whether an action is safe, and ensure that a defensive tool does not create another vulnerability.

Those constraints make competitions valuable. They expose participants to an environment where results can be challenged and compared. They also help policymakers see where talent is developing and what kinds of tasks AI can realistically support.

Hong Kong’s first AI x Cybersecurity Challenge is therefore a small but concrete policy signal. The city is not treating AI security as an abstract concern to be discussed only in guidelines. It is putting students, technical teams, government bodies, and industry organizations into a shared exercise around the use of AI for defense.

The numbers from the event provide an early baseline: 290 entries and 40 finalists. The next test is whether Hong Kong turns that interest into regular training, more advanced exercises, and professional paths for the people who took part. If it does, the competition could become a useful bridge between China’s growing AI ecosystem and the difficult work of keeping digital systems secure.