Collaborative Real-Time AI Security: Engaging All Stakeholders, Including Google
Recently, I had the opportunity to discuss key insights with Francis de Souza, COO of Google Cloud, in an engaging backstage environment at a Los Angeles event. With a calm demeanor resembling that of a university professor, de Souza offered valuable perspectives on the AI security challenges that organizations currently face, asserting, “there’ll be a transition period, and then I think we get to this better place.”
During our conversation, it became clear that his statements transcended Google alone, highlighting the pervasive uncertainty present even within Google.
De Souza emphasized a crucial point that security experts have long advocated for: security should never be neglected. “As companies begin their AI initiatives, they must adopt a platform-centric approach,” he stressed. “Security cannot be an afterthought, nor can it rest solely on employees’ shoulders.” He specifically warned about “shadow AI,” where employees use consumer tools without organizational oversight, underlining that businesses need to implement security, governance, and auditability from the start. “There is no AI strategy without a data strategy and a security strategy; they must be interconnected.”
Importantly, he wasn’t solely promoting Google Cloud. When I pointed out that his comments seemed to favor Google, he clarified that Google endorses a multicloud approach, cautioning that organizations trapped in a singular cloud mindset might be mistaken. “Even when reliant on one cloud, they utilize SaaS applications, and their partners may operate across various clouds,” he explained. “It’s crucial for organizations to maintain a consistent security posture across different clouds and models.”
De Souza also highlighted the increasingly complicated threat landscape, noting that traditional defense strategies are falling short. He remarked that the timeframe from the initial breach to the actual attack has drastically reduced from eight hours to just 22 seconds, with the attack surface expanding beyond typical network boundaries. “Outside your usual environment, there are now models, data pipelines for training these models, agents, and prompts. All these components necessitate protection.”
One lesser-known risk he mentioned pertains to agents navigating a company’s internal systems, exposing overlooked data storage locations. “Many organizations continue to use outdated SharePoint servers and legacy access controls; these have long been overlooked. However, agents within your enterprise will bring those data assets and their contents to the forefront.”
His proposed solution? Synchronize machine speed with machine speed. “We’re witnessing the emergence of an AI-native, fully agent-driven defense where companies can deploy agents to meet their security needs,” he explained. “Rather than relying solely on human-led defenses, you can have humans overseeing a fully agent-driven approach.” He underscored that this is now a leadership challenge, not just a technical one. “This topic demands priority within the board and executive team, not only from the security department.”
Nonetheless, even as AI increasingly assumes security roles, there’s a scarcity of qualified personnel to manage these processes — and the vulnerabilities introduced by AI are outpacing the capacity of security teams. “We will need skilled professionals to tackle the bug-pocalypse,” stated Lea Kissner, LinkedIn’s chief information security officer, in a recent interview with The New York Times, emphasizing that it might take years for the industry to fully understand AI security.
This directs us back to platform providers. The Register recently noted an uptick in Google Cloud developers receiving unexpected five-figure bills due to unauthorized API calls to Gemini models — services many hadn’t used or activated intentionally. These incidents followed a familiar pattern: API keys initially intended for Google Maps had quietly gained access to Gemini after Google expanded their usage without sufficient notification.
Rod Danan, CEO of the interview-preparation platform Prentus, shared that he received a bill of $10,138 within about 30 minutes of attackers compromising his API key. Similarly, Isuru Fonseka, a developer in Sydney, found charges nearing AUD $17,000 despite believing his limit was $250. Unbeknownst to them, Google’s automated systems had escalated their billing tiers based on account activity, raising their effective limits to as much as $100,000 without explicit consent.
Following The Register’s initial report, Google refunded both individuals. However, the company informed The Register that it does not plan to revise its automatic tier-upgrade policy, prioritizing service outage prevention over user budget concerns.
Moreover, there are concerns regarding the protocols for developers attempting to cease operations. The Register reported that even developers who rapidly delete a compromised key may still be at risk. Research from the security firm Aikido indicated that attackers could continue using that key for up to 23 minutes due to Google’s gradual key revocation process. Aikido researcher Joseph Leon explained that during this window, success rates remain unpredictable — at certain moments, over 90% of requests still authenticate — allowing attackers an opportunity to extract files and cached conversation data from Gemini.
Leon also noted that newer credential formats from Google seem to alleviate this issue: service account API credentials revoke in about five seconds, and Gemini’s recent AQ-prefixed key format takes roughly a minute. “Both operate at Google scale,” he noted in Aikido’s related paper. “Both suggest that this issue can technically be resolved for Google API keys as well.” Essentially, Leon argues that the 23-minute delay is not a technical barrier but rather a prioritization issue for the company.
This consideration is vital when reflecting on de Souza’s prudent advice, which warrants serious contemplation. While he is correct, there exists a tangible gap between the platforms’ recommendations and their adaptation speed, a significant factor to acknowledge as well.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.


