
Scantist joined global AI leaders at WAIC 2026 in Shanghai to discuss ASEAN–China AI collaboration—and shared why moving from a successful AI proof of concept to a trusted, operational product remains one of the industry's most important challenges.
In July 2026, Scantist was invited to participate in the World Artificial Intelligence Conference (WAIC) 2026 in Shanghai, one of the world's major gatherings for artificial intelligence innovation, industry and governance.
WAIC 2026 was held from 17–20 July 2026, bringing together AI researchers, technology companies, industry leaders and policymakers from around the world. The conference featured more than 140 themed forums and over 1,100 participating companies, reflecting a growing focus not only on frontier AI research, but also on turning AI innovation into real-world applications.
As part of WAIC 2026, Scantist participated in the ASEAN–China AI Technology & Industry Collaboration Forum, held on 19 July at the West Bund International Convention and Exhibition Center. Jointly curated by IPI Singapore, MP International and AI GRAVITY, the forum focused on a particularly important theme: Cross-Border AI Collaboration: Reality and Strategy.
Unlike discussions centred primarily on emerging AI technologies, the forum looked more closely at what happens after innovation leaves the laboratory: how companies identify the right partners, enter new markets, localise their technologies, overcome operational barriers, and ultimately transform AI innovation into sustainable commercial outcomes.
Scantist joined the panel alongside other Singapore and China technology companies to share first-hand experiences of cross-border collaboration. The discussion was moderated by Zou Shujun, President of the China National Eastern Tech-Transfer Center, while the wider forum brought together speakers and industry participants including IFLYTEK, Alibaba Group, StartupX and AIMX Network.
One of the questions discussed during the panel particularly resonated with Scantist:
Why do so many AI initiatives successfully complete a Proof of Concept, yet struggle to make the transition into production?
Our view is that the biggest barrier is often no longer technical feasibility.
It is operational trust.
A PoC answers the question:
“Can this technology work?”
Production deployment must answer a much more demanding set of questions:
Can it work consistently? Can it operate securely? Can we control what it is allowed to do? Can its decisions and actions be audited? Can it integrate with existing workflows? Can we manage its cost? And, most importantly, can an enterprise trust it to perform a business-critical task repeatedly over the long term?
This distinction becomes even more important as the industry moves from generative AI toward agentic AI.
An AI assistant may generate an answer.
An AI agent can potentially plan, make decisions, use tools, interact with external systems and execute multiple actions autonomously.
That dramatically increases both its potential business value and the complexity of operationalising it.
For Scantist, our experience building PAIStrike provides a very practical example of this journey.
Scantist has a long-standing research foundation in application and cybersecurity technologies. As large language models and autonomous agents matured, one question became particularly interesting to us:
Could AI agents reason and operate like experienced penetration testers rather than simply automate individual security tools?
Traditional penetration testing remains highly dependent on skilled security professionals. A tester needs to understand an application, identify potential weaknesses, formulate attack hypotheses, execute tests, interpret responses, adjust strategies and validate whether a suspected vulnerability is genuinely exploitable.
These activities involve much more than running a predefined vulnerability scanner.
Our research therefore explored how multiple specialised AI agents could collaborate across this security-testing lifecycle.
That research eventually evolved into PAIStrike, Scantist's autonomous agentic penetration testing platform.
Instead of relying on one general-purpose AI model to perform everything, PAIStrike uses a multi-agent architecture, where specialised agents can take responsibility for areas such as reconnaissance, attack planning, vulnerability testing, validation and evidence generation.
More importantly, an autonomous penetration testing product needs to understand state.
Real-world attacks frequently involve multiple dependent steps: authenticating as a particular user, obtaining a token, modifying a request, changing application state, switching identities or permissions, and then verifying whether the expected security boundary was actually violated.
The challenge is therefore not simply asking an LLM:
"Is this application vulnerable?"
The system must continuously reason:
What have I discovered? What should I test next? What happened after my previous action? Does the evidence support my hypothesis? Should I continue, change strategy, or stop?
This is where converting research into a commercial product becomes significantly harder than building an impressive demonstration.
A successful research prototype could demonstrate that an AI agent is capable of identifying vulnerabilities.
But enterprise adoption requires another level of engineering.
For PAIStrike, operationalisation means building capabilities around the AI itself: engagement control, authentication and session management, long-term context, multi-step reasoning, reproducible validation, evidence capture, deployment options, integrations, model management and human oversight.
It also means recognising that autonomous security testing must operate within clearly defined authorisation boundaries.
That distinction is critical.
The objective is not simply to create an AI system capable of attacking applications. The objective is to create a controlled offensive-security platform that organisations can use to continuously evaluate their own security posture.
This has changed how we think about penetration testing.
Traditionally, organisations might commission a penetration test at a particular point in time—before a major release, as part of an annual compliance requirement, or as part of a security assessment.
But applications now change continuously.
New APIs are deployed. Dependencies change. Cloud configurations evolve. Authentication logic is modified. New AI components and agentic workflows are introduced.
Security exposure therefore changes continuously as well.
Our longer-term vision for PAIStrike is to help organisations move from:
Periodic Penetration Testing
to
Continuous Autonomous Offensive Security Validation
Instead of treating penetration testing only as an occasional project, enterprises and government agencies can increasingly incorporate autonomous testing into their broader continuous exposure and offensive security risk-management landscape.
Human penetration testers remain essential, particularly for complex business logic, strategic attack scenarios and high-risk engagements.
AI does not need to replace them.
Instead, autonomous pentesting can take over a growing proportion of repetitive reconnaissance, hypothesis generation, testing and validation activities—allowing security professionals to focus their expertise where human judgement creates the greatest value.
PAIStrike therefore represents more than a new cybersecurity product for Scantist.
It represents the journey we discussed at WAIC:
Research → Proof of Concept → Productisation → Operationalisation → Commercialisation
Each transition presents a different challenge.
Research asks whether something is possible.
A PoC demonstrates that it works.
A product must make that capability repeatable.
An enterprise solution must make it controllable, secure, scalable and supportable.
And commercialisation requires customers to trust that capability enough to incorporate it into real operational processes.
This is why we believe the biggest challenge facing AI companies today is gradually shifting.
The question is becoming less:
“Can AI do this?”
and increasingly:
“How do we make AI reliable and trustworthy enough to become part of the way organisations actually operate?”
This perspective also shaped our discussion at the ASEAN–China forum.
China has built extraordinary depth in AI research, models, infrastructure, manufacturing and technology commercialisation. ASEAN brings rapidly growing digital economies, diverse enterprise environments and significant opportunities for AI adoption.
But successful cross-border expansion requires more than exporting technology.
As highlighted during the WAIC discussion, trust, market contextualisation and the right ecosystem connectors are critical to turning strong technology into scalable real-world value. Singapore can play an important role in this process as a regional innovation hub and gateway into Southeast Asia.
Cybersecurity is one particularly promising area for collaboration.
As enterprises deploy more AI models, AI agents, APIs, cloud-native systems and autonomous workflows, the digital attack surface is expanding at the same time.
Attackers will increasingly use AI.
Defenders will increasingly use AI.
We therefore expect the next generation of cybersecurity platforms to become much more autonomous, continuous and adaptive.
PAIStrike is one example of how Scantist is working toward that future.
We are grateful to IPI Singapore, MP International, AI GRAVITY, the China National Eastern Tech-Transfer Center, and the wider WAIC community for creating an opportunity for companies from Singapore and China to have an open conversation about the realities of cross-border AI innovation.
For Scantist, one of the most valuable messages from WAIC 2026 is simple:
AI innovation creates value only when it can move beyond the laboratory.
The next stage of AI will not be defined solely by larger models or more impressive demonstrations. It will also be defined by our ability to transform those capabilities into secure, reliable and operational systems that solve real problems at scale.
That is the journey Scantist is pursuing across AI and cybersecurity, and the journey that transformed our autonomous penetration-testing research into PAIStrike.
From research to product. From PoC to production. From AI capability to operational impact.
That is where we believe the next wave of enterprise AI innovation will be created.


