Everyone is navigating AI security in real time — even Google
Google Cloud's COO says AI security must be built in from the start, as agents and models expand the attack surface and force faster, more automated defense.
Intelligence analysis by GPT-5.4 Mini
Francis de Souza argues that AI security is now a platform and leadership problem, not something to bolt on later. The article also shows how Google itself is still wrestling with billing, key revocation, and the risks created by broader model access.
A big cloud company leader is saying AI tools are like new doors in a house. If the locks are added later, trouble can get in first.
He thinks companies need to plan for safety from the beginning, because AI tools can look through old files, data, and systems that people forgot about. It's like a dog that can smell every hidden snack in the house.
The story also says even Google is still fixing problems with AI access and billing. That means the people building these tools are still learning how to keep them safe.
Analysis
Security has to ship with the system
Francis de Souza, COO of Google Cloud, says companies entering AI need a platform approach where security, governance, and auditability are present from the start. His message is blunt: there is no real AI strategy without both a data strategy and a security strategy.
He warns about "shadow AI," where employees use consumer tools without company oversight. In his view, that creates risk because the attack surface now includes not just apps and networks, but models, training pipelines, prompts, and agents. Those new parts need protection just like traditional infrastructure.
Why the threat model is changing
De Souza says old defenses are too slow for the current pace of attacks. He cites a dramatic reduction in the time between a breach and the next stage of an attack, and says companies need machine-speed defense rather than relying only on human response.
He also argues that many organizations are not really single-cloud environments, even if they think they are. SaaS products and business partners often span multiple clouds, so security must be consistent across clouds and across models.
Google's own AI growing pains
The article then shifts to recent reporting that exposed problems around Google Cloud billing and Gemini access. According to The Register, some developers were hit with large charges after API keys tied to Google Maps were able to access Gemini after Google expanded their scope. Google refunded affected users, but said it would not change its automatic tier-upgrade policy.
Another report from Aikido suggests that even after a compromised key is deleted, it may remain usable for up to 23 minutes while revocation spreads through Google's systems. That gap reinforces the article's core point: AI security is still being worked out in real time, even by the companies building the infrastructure.
Key points
- Google Cloud's COO says AI security must be part of the platform, not added later.
- He warns that shadow AI and agent-based systems expand what companies must protect.
- He argues that defense needs to operate at machine speed, not only human speed.
- The article points to recent reports of Google Cloud billing and API-key problems involving Gemini access.
- It suggests revocation delays and automatic billing changes are still unresolved risks.



