Close Menu
CryptoAINews
  • Cryptocurrency
  • Blockchain
  • Bitcoin News
  • Altcoins
  • Crypto Market Trends
  • Crypto Mining
  • Ethereum
  • AI News
  • Sponsored
  • Advertise
Trending
  • XRP Community Gets a Harsh Warning as Bitcoin Dominance Tightens
  • Google helps retailers thrive with new UCP and AI tools
  • 6 kitchen gadgets that make adulting feel easier
  • Introducing Google Ask Advisor for marketers
  • Everyone is navigating AI security in real time — even Google
  • New Demand Gen features to drive performance on YouTube
  • Ethereum’s selloff tests whether its neutrality-first model can defend ETH’s value amid Foundation ‘brain drain’
  • Why Crypto Treasury Companies Could Trigger the Next Altseason
  • AI News
  • Cryptocurrency
  • Blockchain
  • Bitcoin News
  • Altcoins
  • Crypto Market Trends
  • Crypto Mining
  • Ethereum
  • Sponsored
  • Advertise
CryptoAINews
  • Cryptocurrency
  • Blockchain
  • Bitcoin News
  • Altcoins
  • Crypto Market Trends
  • Crypto Mining
  • Ethereum
  • AI News
  • Sponsored
  • Advertise
CryptoAINews
Home » AI News » Everyone is navigating AI security in real time — even Google
GettyImages 2266466589
AI News

Everyone is navigating AI security in real time — even Google

CryptoAINewsBy CryptoAINewsMay 25, 2026No Comments6 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email


I just lately had the chance to take a seat down with Francis de Souza, COO of Google Cloud, backstage at an event in Los Angeles. Amid the din round us, de Souza, who speaks within the calm, measured method of a college professor, supplied helpful recommendation for firms navigating the AI safety second we’re all dwelling by means of, noting that “there’ll be a transition interval, after which I believe we get to this higher place.”

He wasn’t talking about Google at that second, however it’s clear that even Google remains to be figuring issues out.

De Souza’s core message was one safety professionals have been attempting to get executives to internalize for years, now made pressing by AI: safety can’t be an afterthought. “As firms embark on this AI journey, they should take a platform strategy,” he mentioned. “Safety just isn’t one thing you may bolt on later, and it’s not one thing you may depart as much as workers to do on their very own.” He warned particularly about “shadow AI” — workers reaching for shopper instruments with out organizational oversight — and argued that firms have to demand safety, governance, and auditability from their platforms from the beginning. “There’s no such factor as an AI technique and not using a information technique and a safety technique. They should go hand in hand.”

Value noting: he wasn’t pitching Google Cloud alone. After I noticed that his recommendation seemed like a Google commercial, he pushed again. Google, he mentioned, is dedicated to a multicloud strategy, and he made the case that firms that suppose they’re working on a single cloud nearly definitely aren’t. “Even when they decide a single cloud, they’re counting on SaaS functions, there are enterprise companions that could be utilizing completely different clouds,” he mentioned. “It’s vital for firms to have a safety posture that’s constant throughout clouds, throughout fashions.”

He additionally made the case that the risk panorama has modified so essentially that outdated defensive fashions are too sluggish. He famous that the typical time between an preliminary breach and the handoff to the subsequent stage of an assault has dropped from eight hours to 22 seconds, and that the assault floor has expanded nicely past the standard community perimeter. “Along with your standard property, you will have fashions now. You may have information pipelines used to coach the fashions. You may have brokers, you will have prompts. All of this must be protected.”

One risk de Souza flagged that doesn’t get sufficient consideration: brokers shifting by means of an organization’s inner methods can floor forgotten information repositories that no person has considered in years. “Loads of organizations have outdated SharePoint servers [and access controls] they haven’t actually up to date, however it didn’t matter as a result of no person actually knew the place they have been. However brokers roaming your enterprise will discover these information belongings and can expose the info on them.”

The reply, in his view, is to satisfy machine velocity with machine velocity. “We’re now seeing the emergence of an AI-native, absolutely agentic protection the place organizations can run brokers driving their protection,” he mentioned. “As a substitute of getting a human-led protection or perhaps a human within the loop, now you can have people overseeing a completely agentic protection.” He added that this has turn out to be a management challenge, not only a expertise one. “It is a board-level challenge and an government workforce challenge. It’s not only a safety workforce’s challenge.”

However at the same time as AI takes on extra of the defensive workload, the folks certified to supervise it are in brief provide — and the vulnerabilities that AI itself is introducing are multiplying quicker than safety groups can handle them. “We’re going to wish folks to take care of the bug-pocalypse,” LinkedIn’s chief info safety officer Lea Kissner told the New York Times this week, including that she doesn’t anticipate the trade to know AI safety in any sustainable long-term manner for at the very least a number of years.

Which brings us again to the platform suppliers themselves. The Register has revealed a sequence of studies over the previous a number of weeks documenting a wave of Google Cloud builders hit with five-figure payments following unauthorized API calls to Gemini fashions — companies a lot of them had by no means used or deliberately enabled. The instances adopted a well-known sample: API keys initially deployed for Google Maps, positioned publicly per Google’s personal directions, had quietly turn out to be able to accessing Gemini after Google expanded their scope with out clearly disclosing the change.

Rod Danan, CEO of interview-prep platform Prentus, mentioned his invoice hit $10,138 in roughly 30 minutes after attackers exploited his compromised API key. Isuru Fonseka, a Sydney-based developer whose account was equally compromised, woke as much as costs of roughly AUD $17,000 regardless of believing he had a $250 spending cap in place. What neither knew was that Google’s automated methods had upgraded their billing tiers primarily based on account historical past, elevating their efficient ceilings to as excessive as $100,000 with out specific consent.

Google refunded each after The Register revealed its preliminary report. Nonetheless, Google instructed The Register it has no plans to alter its computerized tier-upgrade coverage, saying it prioritizes stopping service outages over imposing customers’ acknowledged funds preferences.

Within the meantime, there’s the separate query of what occurs when a developer tries to close issues down. The Register reported this week on analysis by safety agency Aikido discovering that even builders who catch a compromised key and instantly delete it is probably not protected. Based on Aikido’s findings, attackers can apparently proceed utilizing that key for as much as 23 minutes as a result of Google’s revocation propagates progressively throughout its infrastructure. Aikido researcher Joseph Leon instructed The Register that in that window, success charges are unpredictable — in some minutes over 90% of requests nonetheless authenticated — and attackers can use the time to exfiltrate recordsdata and cached dialog information from Gemini.

Leon additionally famous that Google’s personal newer credential codecs don’t seem to have the identical downside: service account API credentials revoke in about 5 seconds, and Gemini’s newer AQ-prefixed key format takes a few minute. “Each run at Google scale,” he wrote in Aikido’s associated paper. “Each counsel that is technically solvable for Google API keys, too.” In brief, in accordance with Leon, the 23-minute window isn’t an engineering constraint however a matter of priorities for the corporate.

That’s price contemplating when studying de Souza’s recommendation, which is sound and ought to be taken very severely. He’s not unsuitable, however there’s presently a spot between the platforms are prescribing and how briskly they’re themselves adapating, and it’s good to concentrate on this, too.

While you buy by means of hyperlinks in our articles, we may earn a small commission. This doesn’t have an effect on our editorial independence.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
CryptoAINews
  • Website

Related Posts

Google helps retailers thrive with new UCP and AI tools

May 25, 2026

6 kitchen gadgets that make adulting feel easier

May 25, 2026

Introducing Google Ask Advisor for marketers

May 25, 2026

New Demand Gen features to drive performance on YouTube

May 24, 2026
Add A Comment
Leave A Reply Cancel Reply

About us

CryptoAINews is an independent digital publication focused on cryptocurrency, blockchain, and artificial intelligence news.

The platform is owned and operated by Robert Grabarevic, providing timely news coverage, market updates, and educational content for a global audience interested in emerging technologies and digital finance.

CryptoAINews is committed to transparent reporting, responsible publishing, and delivering informative content based on publicly available data, verified sources, and industry developments.

All content published on this website is for informational purposes only and does not constitute financial or investment advice.

Top Insights

XRP Community Gets a Harsh Warning as Bitcoin Dominance Tightens

May 25, 2026

Google helps retailers thrive with new UCP and AI tools

May 25, 2026

6 kitchen gadgets that make adulting feel easier

May 25, 2026
Categories
  • Advertise
  • AI News
  • Altcoins
  • Bitcoin News
  • Blockchain
  • Crypto Market Trends
  • Crypto Mining
  • Cryptocurrency
  • Ethereum
  • Sponsored
  • Imprint-Legal-Notice
  • Author / Publisher Bio
  • Privacy Policy
© 2025 CryptoAINews – Owned & Operated by Robert Grabarevic

Type above and press Enter to search. Press Esc to cancel.