Collaborative Real-Time AI Security: Engaging All Stakeholders, Including Google
Recently, I had the chance to engage in an insightful discussion with Francis de Souza, COO of Google Cloud, in a lively backstage environment during an event in Los Angeles. With an academic demeanor, de Souza provided valuable insights into the AI security challenges organizations currently face, stating, “there will be a transition period, and then I think we get to this better place.”
Our conversation highlighted that his views extend beyond Google, reflecting the uncertainties faced even by the tech giant.
De Souza emphasized a crucial point echoed by security professionals: security cannot be an afterthought. “As organizations begin their AI journeys, they must adopt a platform-centric approach,” he remarked. “Security should not solely rely on employees.” He specifically cautioned against “shadow AI,” wherein employees use consumer tools without proper oversight, urging organizations to weave security, governance, and auditability into their foundational strategies. “You cannot have an AI strategy without a data strategy and a security strategy; they all need to be interconnected.”
Significantly, his advocacy extended beyond Google Cloud. When I noted that his comments seemed to favor Google, he clarified that the company endorses a multicloud strategy, warning against reliance on a single cloud provider. “Even if they are reliant on one cloud, they are likely utilizing SaaS applications, and their partners may be engaging across multiple clouds,” he explained. “Organizations need to sustain a consistent security posture across different cloud environments and models.”
De Souza also pointed out the increasingly intricate threat landscape, noting that traditional defense strategies are rapidly becoming outdated. He indicated that the window from the initial breach to a full-scale attack has dramatically decreased from eight hours to just 22 seconds, with attack surfaces now exceeding conventional network boundaries. “Beyond your typical environment, there are now models, data pipelines for training these models, agents, and prompts. All these components require rigorous protection.”
A lesser-known risk he identified involves agents interacting with a company’s internal systems, potentially exposing overlooked data storage areas. “Many organizations still operate outdated SharePoint servers and have neglected legacy access controls. However, agents within your organization can uncover those data assets and their contents.”
What solution does he propose? Aligning machine speed with machine speed. “We’re seeing the rise of an AI-native, fully agent-driven defense mechanism that allows organizations to deploy agents to address their security issues,” he explained. “Instead of depending solely on human defenses, companies can now empower humans to supervise a fully agent-driven model.” He stressed that this challenge has evolved into a leadership issue, extending beyond just technological confines. “This requires attention from the board and executive team, not just the security department.”
However, as AI takes on more security roles, the shortage of skilled professionals to manage these processes presents a significant challenge since AI-driven vulnerabilities are proliferating faster than security teams can cope. “We will need skilled professionals to tackle the bug-pocalypse,” remarked Lea Kissner, LinkedIn’s chief information security officer, in a recent interview with The New York Times, suggesting it may take years for the industry to thoroughly understand AI security.
This brings us back to platform providers. The Register reported that several developers using Google Cloud encountered unexpected charges in the five-figure range due to unauthorized API calls to Gemini models—services many had not intentionally activated or used. These incidents followed a familiar pattern: API keys initially meant for Google Maps were granted access to Gemini as Google broadened their applications without adequate notice.
Rod Danan, CEO of the interview preparation platform Prentus, recounted receiving a bill of $10,138 in just half an hour after attackers compromised his API key. Similarly, Sydney developer Isuru Fonseka faced charges nearing AUD $17,000 despite having set his limit at $250. Unbeknownst to them, Google’s automated systems had escalated their billing tiers based on account activity, raising their limits to as high as $100,000 without explicit consent.
After The Register’s initial report, Google refunded both individuals. However, the company informed The Register that it does not intend to change its automatic tier-upgrade policy, prioritizing the prevention of service outages over customer financial concerns.
Furthermore, there have been concerns regarding the processes available to developers wishing to stop operations. The Register pointed out that even developers who swiftly delete a compromised key may still be vulnerable. Research from security firm Aikido indicated that attackers could continue to leverage that key for up to 23 minutes due to Google’s gradual key revocation process. Aikido researcher Joseph Leon stated that during this window, success rates remain unpredictable—at times, over 90% of requests still authenticate—allowing attackers to extract files and cached conversation data from Gemini.
Leon noted that newer credential formats from Google appear to alleviate this issue: service account API credentials revoke in about five seconds, while Gemini’s recent AQ-prefixed key format takes roughly one minute. “Both operate at Google scale,” he noted in Aikido’s relevant paper. “Both suggest that this issue can technically be resolved for Google API keys as well.” Essentially, Leon argues that the 23-minute delay is not a technical shortcoming but rather a prioritization of company policy.
This consideration is particularly crucial when reflecting on de Souza’s significant insights, which warrant serious attention. While he is undoubtedly correct, a noticeable gap exists between the platform’s recommendations and their actual implementation—an essential aspect to bear in mind.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.


