VnExpress Khoa học Công nghệ
85

Tin ngành

Ba rào cản lớn trong hành trình xây dựng AI chủ quyền

(giờ Việt Nam)

Tóm tắt AI

Các chuyên gia nhận định việc phát triển AI chủ quyền đòi hỏi phải vượt qua ba thách thức cốt lõi: bảo mật dữ liệu, tuân thủ khung pháp lý và khả năng kiểm soát vận hành hệ thống.

Bản dịch AI

Ba thách thức lớn khi triển khai AI chủ quyền

Three major challenges in deploying sovereign AI

According to experts, the deployment of sovereign AI requires addressing challenges related to data security, legal compliance, and operational control.

This observation was made by Mr. Nguyen Van Phuong, a solution architect at Hewlett Packard Enterprise (HPE) Vietnam, at the "AI and Data Sovereignty in the Digital Era" seminar held on July 22 in Ho Chi Minh City.

According to Mr. Phuong, deploying sovereign AI is becoming urgent for every organization. Citing various studies, he noted that three-quarters of business leaders consider this a pressing requirement. The core motivation is economic competitiveness; technological autonomy provides a launchpad for innovation and product development. At a macro level, such as for nations or governments, sovereign AI addresses the issues of ensuring national security and preserving cultural identity.

"When we rely on foreign large language models, they often do not prioritize optimization for the Vietnamese language or culture. Mastering AI helps protect our language and core cultural values," Mr. Phuong said.

Nguyễn Văn Phương, kiến trúc sư giải pháp của công ty Hewlett Packard Enterprise (HPE), phát biểu tại sự kiện. Ảnh: Bảo Lâm

Mr. Nguyen Van Phuong, a solution architect at Hewlett Packard Enterprise (HPE), speaking at the event. Photo: Bao Lam

The HPE expert also pointed out the reality that only about one-quarter of organizations and businesses truly know where to start. The rest, despite being aware of its importance, lack comprehensive strategies, funding, or the knowledge to build the appropriate infrastructure to support sovereign AI.

According to Mr. Phuong, setting aside the issues of funding or basic hardware platforms, when building sovereign AI, every organization will face three major challenges:

The first is the challenge of data security. Data is considered an invaluable asset, especially in critical sectors like national security or healthcare. According to a survey by the World Economic Forum (WEF) released earlier this year, one-third of CEOs consider cyberattacks a top risk to their organizations, and nearly 50% of cybersecurity leaders are deeply concerned about attacks targeting AI systems. However, organizations that prioritize a sovereign AI strategy can achieve profit margins five times higher and create 90% more business value than those that only use public or outsourced AI.

"The solution here is to keep data under the absolute control of the organization at all times. AI processing systems or high-performance computing must be designed with security standards from the very beginning. For critical data in finance, healthcare, or defense, systems must even be designed as 'air-gapped' (completely isolated from the Internet)," Mr. Phuong said.

The second is the challenge of legal compliance. The HPE expert assessed that regulations on data, AI, and cybersecurity are becoming increasingly stringent globally as well as in Vietnam. Therefore, businesses need to deploy AI models in internal data centers or combine them with solution consulting services to ensure strict adherence to legal frameworks.

The third is the challenge of AI control and operations. An artificial intelligence system without oversight is equivalent to being completely out of control. The solution is to build an automated, centralized governance platform for the entire AI lifecycle, from data input, training, fine-tuning, and serving to monitoring. In other words, one can use AI itself to manage AI workloads.

Các chuyên gia trong phiên tọa đàm tại sự kiện. Ảnh: Bảo Lâm

Experts during the panel discussion at the event. Photo: Bao Lam

Three groups of risks that need to be addressed

According to Ms. An Trinh, Data and AI Governance expert at Data Protectify, there are three main groups of risks that need to be addressed when deploying sovereign AI.

The first group of risks relates to human oversight mechanisms. Specifically, an autonomous AI system might be able to access internal data, make decisions, and execute them without human approval. However, it could arbitrarily delete important data such as customer information or trade secrets, causing immeasurable damage to the organization.

The second group of risks is AI hallucination. When using artificial intelligence tools for research, users may receive incorrect information or illogical inferences. This incident becomes very serious if the wrong information is used for critical work, directly affecting individuals and organizations. Therefore, it always requires users to verify the results.

Third, regulations on data security and cybersecurity. Citing IBM's 2025 report on data breaches, Ms. An stated that organizations lacking an AI governance framework will face much greater financial losses than those that have successfully integrated an AI governance framework with data security and cybersecurity.

Mr. Nguyen Thanh Lam, Head of the Cybersecurity Center at Quang Trung Software City (QTSC), emphasized that AI is creating an entirely new "attack surface," containing data, context, identity, and the power to act.

"We cannot protect what we cannot see," Mr. Lam said, suggesting that businesses need to identify, inventory, and control all assets to truly master their own data.

According to the QTSC expert, AI is forming what is called an "Attack Surface" - the entire set of points that hackers can exploit to infiltrate a system, from network gateways and web applications to third-party systems and remotely connected administrator devices. Accompanying this is the concept of "Exposure" - vulnerabilities inadvertently exposed to the Internet. As businesses expand, the number of systems and connections increases, making the attack surface larger and creating more opportunities for hackers.

Furthermore, AI, especially generative AI, is creating an entirely new attack surface. Businesses face risks from "Shadow AI" when employees arbitrarily upload sensitive data to AI platforms; vulnerabilities in large language models (LLMs) such as Prompt Injection (inserting malicious commands to deceive AI), jailbreaking (software interference to bypass security), or data poisoning; and AI Agents that exceed their authority when automatically performing critical tasks.

"If not strictly controlled, AI can become an entry point for hackers to steal data or take over the system," Mr. Lam warned.

To respond to AI risks, the QTSC representative proposed a "sovereign AI" model with four core elements: data control, AI model management, access authorization, and system auditing to ensure monitoring, traceability, and recovery capabilities in the event of an incident. Attack surface management is implemented in 5 steps: identifying all assets; classifying importance levels; assessing risks; remediating exposure points and excessive access privileges; and continuous monitoring to detect abnormal behavior.

Mr. Pham Tuan Anh, Director of the AI Solutions Center at TMA Technology Group, believes there is no one-size-fits-all formula, but for units requiring strict security, the inevitable trend is to deploy internal infrastructure or use Edge AI devices. However, to succeed, data must be standardized, infrastructure must be suitable for business problems, personnel must be ready to apply new technology, and there must be a roadmap for small-scale testing before scaling up.

Previously, speaking at the GStar 2026 event themed "Artificial Intelligence (AI) and Humanity" held in Ho Chi Minh City on May 29, Deputy Minister of Science and Technology Bui Hoang Phuong emphasized that Vietnam aims to become one of the top three countries in Southeast Asia in AI research and development by 2030. After having a legal framework in 2025, 2026 will be the year the nation enters the acceleration phase. Vietnam will not stop at individual AI applications; instead, it aims for the larger strategic goal of comprehensive national transformation through artificial intelligence. To promote this, Vietnam will gradually research, develop, and master core technologies, and achieve autonomy in general-purpose models and foundation models based on domestic data, avoiding complete reliance on foreign technology.

Bao Lam

AI chủ quyềnBảo mật dữ liệuChính sách AICông nghệ chiến lược
Đọc bài gốc

Bài viết được AI dịch và tổng hợp tự động từ VnExpress Khoa học Công nghệ. Liên kết bài gốc ở phía trên. AIHOT.vn luôn dẫn nguồn đầy đủ — nếu bạn thấy điểm cần chỉnh sửa, hãy gửi ý kiến tại trang phản hồi.