In recent days, Wukong has officially been awarded the ISO/IEC 42001:2023 Artificial Intelligence Management System certification by the China Quality Certification Center. Following a rigorous third-party audit, both Wukong and DingTalk have demonstrated compliance with international standards in terms of security, transparency, and compliance within their AI management frameworks.

As early as 2023, DingTalk was among the first to obtain this international certification, laying a solid foundation in the fields of AI safety and compliance. With Wukong now also passing the ISO/IEC 42001 verification, it not only continues DingTalk’s commitment to trustworthy AI development but further underscores its consistent dedication—from platform to intelligent agent—that no matter how technology evolves, safety and trust remain the core principles. As a representative of enterprise-grade AI capabilities, Wukong has undergone comprehensive scrutiny, from product design to compliance practices, under one of the world’s most authoritative AI governance frameworks.

Why is this certification so significant?

With the European Union’s AI Act now fully implemented and China’s Interim Measures for the Administration of Generative Artificial Intelligence Services gradually taking effect, AI compliance has ceased to be merely an optional advantage and has become a mandatory threshold for market entry. The ISO/IEC 42001 standard is the world’s first international framework specifically designed for artificial intelligence management systems. Jointly issued by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), it establishes unified, globally recognized guidelines addressing critical aspects such as risk management, ethical principles, data protection, and accountability mechanisms throughout the AI lifecycle.

During this assessment, Wukong comprehensively met all core criteria, including AI ethics and fairness, data quality and bias prevention, human oversight mechanisms, and system transparency and explainability. Notably, breakthroughs were achieved in defensive capabilities, effectively warding off common AI threats like prompt injection and model contamination, ensuring the secure handling of sensitive corporate data and business operations.

How did Wukong achieve this?

Unlike the industry practice of “launching features first and patching security later,” Wukong integrated safety into its foundational architecture from the very beginning. The team developed a multi-layered security defense system encompassing the runtime environment, access control, data flow, and operational auditing. Every skill deployed on the platform undergoes stringent security scans, and during execution, a policy engine provides real-time monitoring—promptly intercepting any suspicious activity to ensure proactive prevention rather than reactive remediation.

Transparency and Traceability: Breaking Down Black Box Concerns

System transparency and operational traceability have long been key concerns for both the public and businesses. Wukong has built an AI-native file architecture from scratch, automatically capturing complete snapshots with each execution, allowing users to revert to any historical state within seconds if issues arise. Every request and operation is meticulously logged—detailing who initiated it, which device was used, and the context of the interaction—all clearly accessible. This is not an opaque “black box” but a transparent AI system capable of explaining its decision-making process.

Data Security: Multi-Layered Protection in Place

In safeguarding data, Wukong employs a multi-tiered defense strategy. For industries with stringent compliance requirements, such as finance and the public sector, it offers dedicated cloud deployment options, ensuring that sensitive core data never leaves the enterprise’s internal network. Additionally, container-level sandboxing isolates potential risks within the smallest possible execution unit. All operations are supported by end-to-end audit trails, truly achieving the principle of “never touching what shouldn’t be touched, and immediately reversing unintended actions.”

Granular Permissions: Preventing Unauthorized Access

For permission management, Wukong implements a dual-track system combining baseline rules with custom enterprise policies, introducing the “intersection of permissions principle”—the data an AI can access is always limited to the overlap between the user’s permissions and those of the person posing the query. This design fundamentally prevents unauthorized access to sensitive information, safeguarding the privacy and integrity of corporate data.

Real-World Deployment: Proven in Live Scenarios

As DingTalk’s enterprise-grade intelligent agent platform, Wukong is already widely adopted across sectors such as e-commerce, retail stores, and manufacturing, supporting practical workflows ranging from content creation and operational analysis to customer management, order processing, and even AI application development. For example, Suzhou Guangxian Energy leveraged Wukong to analyze nearly a million charging station order records, generating a manual BI report in seconds that previously required half a day. Meanwhile, Yiwu Youkela reduced HR payroll calculations from two days to just ten minutes, while boosting new product launch success rates from 60% to 92%.

These real-world examples highlight a crucial point: when AI becomes deeply embedded in daily business operations, safety and reliability are the fundamental prerequisites for efficiency gains. Wukong is not only an efficient AI assistant but also a trusted intelligent partner businesses can rely on long term.

In the face of increasingly stringent global AI regulations, securing ISO/IEC 42001 certification ahead of others represents both a tangible response to user trust and a model for the industry—a blueprint emphasizing safety as the top priority.

Upcoming, Wukong will release an AI Safety White Paper, detailing its design philosophies and practical implementations in areas such as compliance frameworks, end-to-end protection, data security, privacy safeguards, and ecosystem governance.

In this era of rapid AI advancement, Wukong has chosen a more challenging yet ultimately rewarding path—building a rock-solid foundation in safety before enabling intelligence to reach greater heights.

DomTech is DingTalk’s official service provider in Macau, dedicated to serving clients with DingTalk solutions. If you’d like to learn more about DingTalk platform applications, feel free to contact our online customer support or reach us by phone at +852 95970612 or email at [email protected]. Our skilled development and operations teams bring extensive market experience, ready to deliver professional DingTalk solutions and services!

立即提升團隊協作效率

免費試用釘釘,改變你的工作方式。

免費開始