OTHER

Collaborative Real-Time AI Security: Engaging All Stakeholders, Including Google

I recently engaged in a thought-provoking conversation with Francis de Souza, COO of Google Cloud, in an energetic backstage environment at an event in Los Angeles. With an academic tone, de Souza conveyed essential insights into the AI security issues organizations currently grapple with, asserting, “there will be a transition period, and then I think we get to this better place.”

Our discussion highlighted that his views resonate well beyond Google, reflecting the uncertainties the tech giant itself faces.

De Souza emphasized a crucial point echoed by security professionals: security cannot be an afterthought. “As organizations begin their AI journeys, they must embrace a platform-centric approach,” he remarked. “Security should not rely solely on employees.” He specifically cautioned against “shadow AI,” where staff use consumer tools without proper oversight, urging companies to integrate security, governance, and auditability into their foundational strategies. “You cannot have an AI strategy without a data strategy and a security strategy; they must all be interconnected.”

Significantly, his advocacy extended beyond Google Cloud. When I noted that his insights appeared to favor Google, he clarified that the company endorses a multicloud strategy, warning against over-reliance on a single cloud provider. “Even if they’re reliant on one cloud, they are likely using SaaS applications, and their partners may be collaborating across multiple clouds,” he explained. “Organizations must uphold a consistent security posture across different cloud environments and models.”

De Souza also drew attention to the increasingly intricate threat landscape, noting that traditional defense strategies are quickly becoming outdated. He revealed that the time between the first breach and a full-scale attack has plummeted from eight hours to merely 22 seconds, with attack surfaces now extending beyond conventional network boundaries. “Beyond your usual environment, there are now models, data pipelines for training these models, agents, and prompts. All these components require rigorous protection.”

A lesser-known risk he pointed out involves agents interfacing with a company’s internal systems, potentially exposing neglected data storage areas. “Many organizations still run outdated SharePoint servers and have ignored legacy access controls. However, agents within your organization can reveal those data assets and their contents.”

What solution does he propose? Aligning machine speed with machine speed. “We are witnessing the rise of an AI-native, fully agent-driven defense system that allows organizations to deploy agents to tackle their security issues,” he detailed. “Rather than relying solely on human defenses, companies can empower humans to supervise a fully agent-driven model.” He stressed that this issue has transformed into a leadership concern, transcending mere technological boundaries. “This requires attention from the board and executive team, not just the security department.”

Yet, as AI takes on more security responsibilities, the shortage of skilled professionals to manage these processes presents a significant challenge, as AI-driven vulnerabilities are multiplying faster than security teams can handle. “We will need skilled professionals to address the bug-pocalypse,” noted Lea Kissner, LinkedIn’s chief information security officer, in a recent interview with The New York Times, suggesting it may take years for the industry to fully understand AI security.

This brings us back to platform providers. The Register reported that several developers using Google Cloud experienced unexpected five-figure charges due to unauthorized API calls to Gemini models—services many had not intentionally activated or used. These incidents followed a familiar pattern: API keys originally meant for Google Maps were given access to Gemini as Google expanded their applications without sufficient notice.

Rod Danan, CEO of the interview preparation platform Prentus, shared that he received a bill of $10,138 in just half an hour after attackers compromised his API key. Similarly, Sydney developer Isuru Fonseka faced charges approaching AUD $17,000 despite having set his limit at $250. Unbeknownst to them, Google’s automated systems had adjusted their billing tiers based on account activity, elevating their limits to as much as $100,000 without explicit consent.

Following The Register’s initial report, Google refunded both individuals. However, the company informed The Register that it has no plans to change its automatic tier-upgrade policy, prioritizing the prevention of service outages over customer financial concerns.

Furthermore, there have been concerns regarding the processes available to developers wanting to cease operations. The Register highlighted that even developers who promptly delete a compromised key may still be at risk. Research from security firm Aikido indicated that attackers could continue to exploit that key for up to 23 minutes due to Google’s slow key revocation process. Aikido researcher Joseph Leon remarked that during this timeframe, success rates remain unpredictable—at times, over 90% of requests still authenticate—allowing attackers to extract files and cached conversation data from Gemini.

Leon noted that newer credential formats from Google appear to alleviate this issue: service account API credentials revoke in about five seconds, while Gemini’s recent AQ-prefixed key format takes roughly one minute. “Both operate at Google scale,” he remarked in Aikido’s relevant paper. “Both suggest that this issue can technically be resolved for Google API keys as well.” Essentially, Leon argues that the 23-minute delay is not a technical flaw but rather a prioritization of company policy.

This consideration becomes particularly crucial when reflecting on de Souza’s significant insights, which demand serious attention. While he is undoubtedly correct, a noticeable gap persists between the platform’s recommendations and their actual implementation—an essential aspect to keep in mind.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.