OTHER

Collaborative Real-Time AI Security: Engaging All Stakeholders, Including Google

I recently engaged in a thought-provoking dialogue with Francis de Souza, COO of Google Cloud, in an energetic backstage ambiance at an event in Los Angeles. He adopted an academic stance, sharing crucial insights into the security hurdles organizations face with AI, stating, “there will be a transition period, and then I think we get to this better place.”

Our exchange illustrated that his viewpoints extend well beyond Google, reflecting the uncertainties faced by the tech giant itself.

De Souza emphasized a critical principle echoed by security experts: security cannot be an afterthought. “As organizations embark on their AI journeys, they must adopt a platform-centric strategy,” he remarked. “Security should not depend solely on personnel.” He specifically cautioned against “shadow AI,” where employees use consumer tools without proper oversight, urging businesses to integrate security, governance, and auditability into their foundational strategies. “You cannot have an AI strategy without a data strategy and a security strategy; they must all be interconnected.”

Notably, his advocacy extended beyond Google Cloud. When I noted that his views seemed to favor Google, he clarified that the company supports a multicloud strategy, cautioning against over-reliance on a single provider. “Even if organizations depend on one cloud, they are likely using SaaS applications, and their partners may be collaborating across various clouds,” he explained. “Organizations must maintain a consistent security posture across different cloud environments and models.”

De Souza also pointed to the increasingly complex threat landscape, noting that traditional defense methods are quickly becoming outdated. He mentioned that the time between the initial breach and a full-scale attack has dramatically decreased from eight hours to only 22 seconds, with attack surfaces now stretching beyond conventional network boundaries. “Beyond your usual environment, there are now models, data pipelines for training these models, agents, and prompts. All these factors require rigorous protection.”

A lesser-known risk he highlighted involves agents interacting with a company’s internal systems, potentially revealing overlooked data storage areas. “Many organizations still operate outdated SharePoint servers and have neglected legacy access controls. However, agents within your organization can uncover those data assets and their contents.”

What solution does he propose? Aligning machine speed with machine capabilities. “We are witnessing the rise of an AI-native, fully agent-driven defense system that empowers organizations to deploy agents to address their security concerns,” he elaborated. “Rather than relying solely on human defenses, companies can enable individuals to supervise a fully agent-driven model.” He emphasized that this situation has transformed into a leadership challenge, extending beyond mere technology. “This issue requires the attention of the board and executive team, not just the security department.”

However, as AI takes on more security responsibilities, the shortage of skilled professionals to manage these processes poses a significant challenge, as AI-driven vulnerabilities proliferate quicker than security teams can handle. “We will need skilled professionals to confront the bug-pocalypse,” noted Lea Kissner, LinkedIn’s chief information security officer, in a recent interview with The New York Times, suggesting that it may take years for the industry to fully understand AI security.

This brings us back to platform providers. The Register reported that several developers using Google Cloud faced unexpected five-figure bills due to unauthorized API calls to Gemini models—services many had not consciously activated or utilized. These incidents followed a familiar pattern: API keys initially intended for Google Maps were granted access to Gemini as Google expanded their applications without sufficient notice.

Rod Danan, CEO of the interview preparation platform Prentus, shared that he received a bill of $10,138 in just half an hour after attackers compromised his API key. Similarly, Sydney developer Isuru Fonseka encountered charges nearing AUD $17,000 despite setting a limit of $250. Unbeknownst to them, Google’s automated systems had adjusted their billing tiers based on account activity, raising their limits to as much as $100,000 without explicit consent.

Following The Register’s initial report, Google refunded both individuals. However, the company informed The Register that it has no plans to modify its automatic tier-upgrade policy, prioritizing the prevention of service outages over customer financial concerns.

Moreover, there have been concerns regarding the processes available to developers wishing to halt operations. The Register emphasized that even developers who promptly delete a compromised key could still be at risk. Research from the security firm Aikido suggested that attackers could exploit that key for up to 23 minutes due to Google’s slow key revocation process. Aikido researcher Joseph Leon remarked that during this period, success rates remain unpredictable—sometimes, more than 90% of requests still authenticate—allowing attackers to extract files and cached conversation data from Gemini.

Leon noted that newer credential formats from Google appear to mitigate this issue: service account API credentials can be revoked in about five seconds, while Gemini’s recent AQ-prefixed key format takes about one minute. “Both operate at Google scale,” he noted in Aikido’s pertinent paper. “Both suggest that this issue can technically be resolved for Google API keys as well.” Essentially, Leon contends that the 23-minute delay is not a technical flaw but rather a prioritization of corporate policy.

This reflection becomes particularly significant when contemplating de Souza’s compelling insights, which merit serious consideration. While he is undoubtedly correct, a noticeable gap exists between the platform’s recommendations and their actual implementation—an essential detail to keep in mind.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.