BitcoinWorld Everyone Is Navigating AI Security in Real Time — Even Google In a candid conversation backstage at an event in Los Angeles, Francis de Souza, COOBitcoinWorld Everyone Is Navigating AI Security in Real Time — Even Google In a candid conversation backstage at an event in Los Angeles, Francis de Souza, COO

Everyone Is Navigating AI Security in Real Time — Even Google

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

BitcoinWorld

Everyone Is Navigating AI Security in Real Time — Even Google

In a candid conversation backstage at an event in Los Angeles, Francis de Souza, COO of Google Cloud, offered a sobering assessment of the current state of AI security. Speaking with the measured tone of a university professor, de Souza acknowledged that the industry is in a transition period, noting that “there’ll be a transition period, and then I think we get to this better place.” His remarks come at a time when even Google itself is grappling with security gaps exposed by its own AI products.

The Platform Approach to Security

De Souza’s core message was one security professionals have been urging executives to adopt for years, now made urgent by AI: security cannot be an afterthought. “As companies embark on this AI journey, they need to take a platform approach,” he said. “Security is not something you can bolt on later, and it’s not something you can leave up to employees to do on their own.” He specifically warned about “shadow AI” — employees using consumer AI tools without organizational oversight — and argued that companies must demand security, governance, and auditability from their platforms from the start. “There’s no such thing as an AI strategy without a data strategy and a security strategy. They need to go hand in hand,” he added.

Multicloud Reality and the Expanding Attack Surface

When asked whether his advice amounted to a sales pitch for Google Cloud, de Souza pushed back, emphasizing Google’s commitment to a multicloud approach. “Even if they pick a single cloud, they’re relying on SaaS applications, there are business partners that may be using different clouds,” he said. “It’s important for companies to have a security posture that is consistent across clouds, across models.” He also highlighted how fundamentally the threat landscape has changed. The average time between an initial breach and the handoff to the next stage of an attack has dropped from eight hours to 22 seconds, he noted, while the attack surface has expanded beyond the traditional network perimeter. “In addition to your usual estate, you have models now. You have data pipelines used to train the models. You have agents, you have prompts. All of this needs to be protected.”

The Hidden Danger of AI Agents

One threat de Souza flagged that often goes unnoticed: AI agents moving through a company’s internal systems can surface forgotten data repositories. “A lot of organizations have old SharePoint servers [and access controls] they haven’t really updated, but it didn’t matter because nobody really knew where they were. But agents roaming your enterprise will find those data assets and will expose the data on them.” His recommended solution is to meet machine speed with machine speed. “We’re now seeing the emergence of an AI-native, fully agentic defense where organizations can run agents driving their defense,” he said. “Instead of having a human-led defense or even a human in the loop, you can now have humans overseeing a fully agentic defense.” He stressed that this is a board-level and executive team issue, not just a security team’s concern.

Google’s Own Security Gaps

While de Souza’s advice is sound, recent reports reveal a gap between what Google Cloud prescribes and how quickly it adapts. The Register has documented a wave of Google Cloud developers hit with five-figure bills after unauthorized API calls to Gemini models — services many had never used or intentionally enabled. The pattern: API keys originally deployed for Google Maps, placed publicly per Google’s own instructions, had quietly become capable of accessing Gemini after Google expanded their scope without clearly disclosing the change. Rod Danan, CEO of interview-prep platform Prentus, reported a $10,138 bill in roughly 30 minutes after attackers exploited his compromised API key. Isuru Fonseka, a Sydney-based developer, woke up to charges of roughly AUD $17,000 despite believing he had a $250 spending cap in place. Google refunded both after The Register published its initial report, but told the publication it has no plans to change its automatic tier-upgrade policy, prioritizing preventing service outages over enforcing users’ stated budget preferences.

The 23-Minute Revocation Window

Further complicating matters, security firm Aikido found that even developers who catch a compromised key and immediately delete it may not be safe. Attackers can apparently continue using that key for up to 23 minutes because Google’s revocation propagates gradually across its infrastructure. Aikido researcher Joseph Leon told The Register that during that window, success rates are unpredictable — in some minutes over 90% of requests still authenticated — and attackers can use the time to exfiltrate files and cached conversation data from Gemini. Leon noted that Google’s own newer credential formats don’t have the same problem: service account API credentials revoke in about five seconds, and Gemini’s newer AQ-prefixed key format takes about a minute. “Both run at Google scale,” he wrote in Aikido’s related paper. “Both suggest this is technically solvable for Google API keys, too.” In short, the 23-minute window isn’t an engineering constraint but a matter of priorities.

Conclusion

De Souza’s advice — that security must be foundational, not bolted on — is sound and should be taken seriously by every organization deploying AI. However, the recent incidents at Google Cloud itself highlight that even the platforms prescribing best practices are still adapting. As the industry moves toward AI-native defenses and agentic security, the gap between prescription and practice remains a critical concern for boards, executives, and security teams alike.

FAQs

Q1: What is “shadow AI” and why is it a security risk?
Shadow AI refers to employees using consumer AI tools without organizational oversight. This creates risks because such tools may not have enterprise-grade security, governance, or auditability, potentially exposing sensitive data.

Q2: How quickly can attackers exploit a compromised API key on Google Cloud?
According to recent research, even after a key is deleted, attackers can continue using it for up to 23 minutes due to gradual revocation propagation. Google’s newer credential formats revoke much faster, in seconds to a minute.

Q3: What is an “agentic defense” in AI security?
An agentic defense uses AI-driven agents to automatically detect and respond to threats at machine speed, with humans overseeing the process rather than being directly in the loop. This approach is designed to counter the speed of modern AI-powered attacks.

This post Everyone Is Navigating AI Security in Real Time — Even Google first appeared on BitcoinWorld.

Market Opportunity
Gensyn Logo
Gensyn Price(AI)
$0.02357
$0.02357$0.02357
-1.04%
USD
Gensyn (AI) Live Price Chart

World Cup Rewards: Last Sprint

World Cup Rewards: Last SprintWorld Cup Rewards: Last Sprint

Final countdown: Miss it now, wait four years!

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

The changing face of elder care in Malaysia — Sayed Mohammad Reza Yamani Sayed Umar

The changing face of elder care in Malaysia — Sayed Mohammad Reza Yamani Sayed Umar

JULY 10 — An elderly society is becoming increasingly prevalent in Malaysia at present. It is projected that the p...
Share
Malaymail2026/07/10 15:24
One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight

One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight

The post One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight appeared on BitcoinEthereumNews.com. Frank Sinatra’s The World We Knew returns to the Jazz Albums and Traditional Jazz Albums charts, showing continued demand for his timeless music. Frank Sinatra performs on his TV special Frank Sinatra: A Man and his Music Bettmann Archive These days on the Billboard charts, Frank Sinatra’s music can always be found on the jazz-specific rankings. While the art he created when he was still working was pop at the time, and later classified as traditional pop, there is no such list for the latter format in America, and so his throwback projects and cuts appear on jazz lists instead. It’s on those charts where Sinatra rebounds this week, and one of his popular projects returns not to one, but two tallies at the same time, helping him increase the total amount of real estate he owns at the moment. Frank Sinatra’s The World We Knew Returns Sinatra’s The World We Knew is a top performer again, if only on the jazz lists. That set rebounds to No. 15 on the Traditional Jazz Albums chart and comes in at No. 20 on the all-encompassing Jazz Albums ranking after not appearing on either roster just last frame. The World We Knew’s All-Time Highs The World We Knew returns close to its all-time peak on both of those rosters. Sinatra’s classic has peaked at No. 11 on the Traditional Jazz Albums chart, just missing out on becoming another top 10 for the crooner. The set climbed all the way to No. 15 on the Jazz Albums tally and has now spent just under two months on the rosters. Frank Sinatra’s Album With Classic Hits Sinatra released The World We Knew in the summer of 1967. The title track, which on the album is actually known as “The World We Knew (Over and…
Share
BitcoinEthereumNews2025/09/18 00:02
Not a loophole: Singapore AI export controls let China tap US AI legally

Not a loophole: Singapore AI export controls let China tap US AI legally

American AI technology is reaching Chinese tech giants through a route that US export controls were never designed to close: Singapore. The city-state sits outside
Share
The Cryptonomist2026/07/10 14:46

Kickoff Fest! Win Up to $500K!

Kickoff Fest! Win Up to $500K!Kickoff Fest! Win Up to $500K!

4 rewards! 1st trade bonus & 0-fee limit orders!