Glostarep

No One Has AI Security Figured Out, Not Even Google

No One Has AI Security Figured Out, Not Even Google

Even the biggest names in tech are still working out AI security risks as they go. That was the quiet but striking takeaway from a recent conversation between TechCrunch and Francis de Souza, COO of Google Cloud, at an event in Los Angeles. His message to enterprises was firm: security cannot be an afterthought when adopting AI. “There’s no such thing as an AI strategy without a data strategy and a security strategy,” he said. “They need to go hand in hand.”

De Souza specifically called out the danger of “shadow AI,” where employees quietly adopt consumer-facing tools without organizational oversight, bypassing governance and auditability entirely. He argued that companies must take a platform-first approach to avoid this, and that good security posture has to be consistent across clouds and across AI models, not siloed within a single vendor.

He also flagged a threat most companies are not thinking about: AI agents roaming internal systems can stumble onto forgotten data repositories with outdated access controls. Old SharePoint servers that nobody has touched in years, for example, could suddenly be exposed when an agent finds and surfaces the data sitting on them.

The conversation turned pointed when de Souza described how fast the threat landscape has shifted. The average time between an initial breach and escalation to the next attack phase has reportedly dropped from eight hours to just 22 seconds. His prescription for keeping up is an AI-native, fully agentic defense, where organizations deploy AI agents to run their own security rather than relying on a human in the loop for every decision. He was quick to add that this makes AI security risks a board-level issue, not just something for the security team to handle.

What makes his advice land differently is the context surrounding Google itself. A series of reports by The Register revealed that Google Cloud developers were hit with five-figure bills after unauthorized API calls to Gemini models, services many had never intentionally activated. API keys originally created for Google Maps had quietly gained access to Gemini after Google expanded their scope without a clear public disclosure. One affected developer, Rod Danan, CEO of interview-prep platform Prentus, saw his bill climb to over $10,000 in roughly 30 minutes. Another developer in Sydney woke up to charges of around AUD $17,000, believing a $250 spending cap was in place. Google had automatically raised billing tiers based on account history, with some ceilings reaching $100,000 without explicit user consent. Both developers were refunded after The Register published its report, though Google stated it has no plans to revise its automatic tier-upgrade policy.

The situation deepened when security firm Aikido found that even after a developer deletes a compromised API key, attackers can continue using it for up to 23 minutes while Google’s revocation propagates across its infrastructure. During that window, over 90% of requests were still authenticating in some instances, giving attackers enough time to exfiltrate files and cached Gemini conversation data. Aikido researcher Joseph Leon noted that Google’s newer credential formats revoke far faster, suggesting the 23-minute gap is a matter of priorities rather than a technical impossibility.

The gap between what platform providers are recommending and what they are actually delivering is real. De Souza’s advice on AI security risks is sound and widely applicable, but it sits uncomfortably alongside the vulnerabilities that emerged on Google’s own platform in the same week he delivered it. LinkedIn’s chief information security officer Lea Kissner may have put it best, telling the New York Times that the industry should not expect to have a sustainable long-term understanding of AI security for at least several more years. For now, everyone is figuring it out in real time.

Leave a Comment

Your email address will not be published. Required fields are marked *