Want to get featured here? Explore premium visibility opportunities.

Contact us

AI NewsEveryone is navigating AI security in real time — even Google

Everyone is navigating AI security in real time — even Google

7:01 AM IST · May 25, 2026

Everyone is navigating AI security in real time — even Google

I recently had the opportunity to sit down with Francis de Souza, COO of Google Cloud, backstage at aneventin Los Angeles. Amid the din around us, de Souza, who speaks in the calm, measured manner of a university professor, offered useful advice for companies navigating the AI security moment we’re all living through, noting that “there’ll be a transition period, and then I think we get to this better place.” He wasn’t speaking about Google at that moment, but it’s clear that even Google is still figuring things out. De Souza’s core message was one security professionals have been trying to get executives to internalize for years, now made urgent by AI: security can’t be an afterthought. “As companies embark on this AI journey, they need to take a platform approach,” he said. “Security is not something you can bolt on later, and it’s not something you can leave up to employees to do on their own.” He warned specifically about “shadow AI” — employees reaching for consumer tools without organizational oversight — and argued that companies need to demand security, governance, and auditability from their platforms from the start. “There’s no such thing as an AI strategy without a data strategy and a security strategy. They need to go hand in hand.” Worth noting: he wasn’t pitching Google Cloud alone. When I observed that his advice sounded like a Google advertisement, he pushed back. Google, he said, is committed to a multicloud approach, and he made the case that companies that think they’re operating on a single cloud almost certainly aren’t. “Even if they pick a single cloud, they’re relying on SaaS applications, there are business partners that may be using different clouds,” he said. “It’s important for companies to have a security posture that is consistent across clouds, across models.” He also made the case that the threat landscape has changed so fundamentally that old defensive models are too slow. He noted that the average time between an initial breach and the handoff to the next stage of an attack has dropped from eight hours to 22 seconds, and that the attack surface has expanded well beyond the traditional network perimeter. “In addition to your usual estate, you have models now. You have data pipelines used to train the models. You have agents, you have prompts. All of this needs to be protected.” One threat de Souza flagged that doesn’t get enough attention: agents moving through a company’s internal systems can surface forgotten data repositories that nobody has thought about in years. “A lot of organizations have old SharePoint servers [and access controls] they haven’t really updated, but it didn’t matter because nobody really knew where they were. But agents roaming your enterprise will find those data assets and will expose the data on them.” The answer, in his view, is to meet machine speed with machine speed. “We’re now seeing the emergence of an AI-native, fully agentic defense where organizations can run agents driving their defense,” he said. “Instead of having a human-led defense or even a human in the loop, you can now have humans overseeing a fully agentic defense.” He added that this has become a leadership issue, not just a technology one. “This is a board-level issue and an executive team issue. It’s not just a security team’s issue.” But even as AI takes on more of the defensive workload, the people qualified to oversee it are in short supply — and the vulnerabilities that AI itself is introducing are multiplying faster than security teams can address them. “We’re going to need people to deal with the bug-pocalypse,” LinkedIn’s chief information security officer Lea Kissnertold the New York Timesthis week, adding that she doesn’t expect the industry to understand AI security in any sustainable long-term way for at least several years. Which brings us back to the platform providers themselves. The Register has published a series of reports over the past several weeks documenting a wave of Google Cloud developers hit with five-figure bills following unauthorized API calls to Gemini models — services many of them had never used or intentionally enabled. The cases followed a familiar pattern: API keys originally deployed for Google Maps, placed publicly per Google’s own instructions, had quietly become capable of accessing Gemini after Google expanded their scope without clearly disclosing the change. Rod Danan, CEO of interview-prep platform Prentus, said his bill hit$10,138 in roughly 30 minutesafter attackers exploited his compromised API key. Isuru Fonseka, a Sydney-based developer whose account was similarly compromised, woke up to charges of roughly AUD $17,000 despite believing he had a $250 spending cap in place. What neither knew was that Google’s automated systems had upgraded their billing tiers based on account history, raising their effective ceilings to as high as $100,000 without explicit consent. Google refunded both after The Register published its initial report. Still, Google told The Register it has no plans to change its automatic tier-upgrade policy, saying it prioritizes preventing service outages over enforcing users’ stated budget preferences. In the meantime, there is the separate question of what happens when a developer tries to shut things down. The Registerreported this weekon research by security firm Aikido finding that even developers who catch a compromised key and immediately delete it may not be safe. According to Aikido’s findings, attackers can apparently continue using that key for up to 23 minutes because Google’s revocation propagates gradually across its infrastructure. Aikido researcher Joseph Leon told The Register that during that window, success rates are unpredictable — in some minutes over 90% of requests still authenticated — and attackers can use the time to exfiltrate files and cached conversation data from Gemini. Leon also noted that Google’s own newer credential formats don’t appear to have the same problem: service account API credentials revoke in about five seconds, and Gemini’s newer AQ-prefixed key format takes about a minute. “Both run at Google scale,” he wrote in Aikido’s related paper. “Both suggest this is technically solvable for Google API keys, too.” In short, according to Leon, the 23-minute window isn’t an engineering constraint but a matter of priorities for the company. That’s worth considering when reading de Souza’s advice, which is sound and should be taken very seriously. He’s not wrong, but there is currently a gap between the platforms are prescribing and how fast they are themselves adapating, and it’s good to be aware of this, too.

read more

Latest AI News

View All News →
Nobel-Winning AlphaFold Scientist John Jumper Leaves Google DeepMind for Anthropic

Nobel-Winning AlphaFold Scientist John Jumper Leaves Google DeepMind for Anthropic

For his work on AlphaFold, Jumper shared the 2024 Nobel Prize in Chemistry with Demis Hassabis and scientist David Baker.

4 hours ago

View

How Hexaware's GIFT City Move Gives Indian IT a New Financial Frontier

How Hexaware's GIFT City Move Gives Indian IT a New Financial Frontier

Hexaware plans to create nearly 1,000 high-skilled jobs over the next three years.

8 hours ago

View

Encryption, spyware, and now Mythos: History shows why cyber export control doesn’t work

Encryption, spyware, and now Mythos: History shows why cyber export control doesn’t work

Last Friday, citing unspecified national security concerns, the White Houseordered Anthropicto restrict the export of its powerful AI models Fable and Mythos to anyone outside of the United States, as well as foreign nationals inside the country. Shortly after, the AI giant hastily pulled the plug on both models, which have now been unavailable to anyone for a week. The episode is the first real test of whether the U.S. government can use export controls to contain frontier AI the way it has tried, with very uneven results, to contain encryption and spyware before it. And dramatic as it may sound, how this standoff gets resolved could shape not just Anthropic’s access to foreign markets but the rulebook that other AI labs will have to build around. Some context first.Ever since Anthropic launched Mythos in April, the company has marketed it assome kind of Doomsday cyber machinethat could wreak havoc on the internet if released too widely — which is why, before the ban,only around 150 vetted companies and government organizationshad access to it at all. The goal was helping defenders secure their software and services before the bad guys could reach Mythos-like capabilities. So what triggered the ban? Two subsequent events, reportedly. The first: Anthropic gave a South Korean telecom access to Mythos through its limited partner program, and U.S. officials grew alarmed after identifying the company as one they suspected had ties to China. (The company,widely reportedto be SK Telecom, hasdeniedany China connection.) Amazon CEO Andy Jassy also reportedlyalerted the administrationafter Amazon’s own researchers, he said, found a way around Fable 5’s safeguards. Anthropic disputes the “jailbreak” label, calling it a narrow, already-patched issue rather than a wholesale defeat of the model’s safety measures. The result was the same: the Commerce Department issued an export control directive, and Anthropic had to scramble to immediately limit access to its products — within roughly 90 minutes of being notified, by some accounts. None of this is new, though. Governments have tried to use export controls to limit the proliferation of what they see as dangerous cyber technology for decades, but their track record has been middling at best. The U.S. government was behind what is perhaps history’s most spectacular failure of this approach in the early to mid-1990s. At the time, computer scientists were developing encryption technologies to secure data as it traveled over the internet. One of those encryption products was called Pretty Good Privacy, or PGP, a popular software that could encrypt data and make it virtually impossible to unscramble even if intercepted as it traveled to its intended recipient over the internet. The U.S. government initially saw PGP as a dangerous weapon, fearing it would prevent its intelligence agencies from snooping on emails as they crossed their wires. To stop the distribution of PGP, the U.S. Customs Serviceopened a criminal investigationagainst PGP’s creator Phil Zimmermann for allegedly violating arms export controls. He fought back by publishing PGP’s source codeas a printed book, igniting what is known today as the “Crypto Wars.” Zimmermann later won a key battle when the investigation was closed, paving the way for crucial end-to-end encryption algorithms such as the one used by billions of Signal and WhatsApp users. Later during the early 2010s, researchers began discovering Western-made spyware used against dissidents in the Middle East. In response, several governments agreed to expandthe Wassenaar Arrangement, an international treaty that limits the export of dual-use software and technologies that are used in both civilian and military applications. The idea was to classify surveillance and hacking software as dual-use, thus forcing spyware makers to get export licenses to sell their products abroad. Contact UsDo you have more information about the Mythos ban? From a non-work device and network, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, oremail. But Wassenaar has always had two inherent weaknesses. There are several countries that don’t adhere to the agreement, including Israel, which houses some of the world’s most active spyware makers. The agreement also depends on countries applying it to companies within their borders at their own discretion. For a time, the Italian government allowed one of the country’s then-top spyware makers, Hacking Team, a license to export its tools around the world, despite the company’s track record of selling spyware tooppressivegovernmentsthatused itto hack journalists and human rights activists. Since then,othercountriesin Europe have been lax with spyware makers like Italy. Despite numerous scandals, Europe, home tomany spyware and hacking tools makers, hascontinually failed to curb the export of spywareto authoritarian regimes. Critics say that a recently renewed effort across the bloc of 27 member states to tackle its growing problem of spyware exports to authoritarian states “does not go far enough.” Several spyware makers, such as Intellexa, a sanctioned consortium of spyware companies,  have simply moved their operations to countries with lax export controls. Other spyware makers sought to move their operations to Saudi Arabia for similar reasons. There have been some wins. Germany-based spyware maker FinFishershut down in 2022after a multi-year investigation by German prosecutors into the company forallegedly selling spywareto Turkey without an export license. Investigators previously found the FinFisher spyware had beendeployed on the phonesof critics of Turkey’s government. As of the time of writing, the impasse between Anthropic and the Trump administration remains. There is a reasonable chance the administration will buckle and lift the restriction in the interest of keeping American AI companies competitive worldwide — a move that would amount to tacit acknowledgment that AI labs elsewhere, including in China, will likely reach similar capabilities regardless of what the U.S. restricts. Or, American AI companies could end up needing government approval before serving foreign customers at all, a compliance burden that would invariably dent their bottom line. Given the past experiences that world governments have had with trying to control the reach of software, government-mandated export controls are unlikely to be the right approach to stop malicious actors from abusing powerful dual-use cyber technologies.

12 hours ago

View

Billionaire Ambani wants AI in every call, app, and home

Billionaire Ambani wants AI in every call, app, and home

As India searches for a homegrown contender in the global artificial intelligence race, billionaire Mukesh Ambani is positioning Reliance Industries as a national champion, rolling out AI services for phone calls, mobile apps, and connected homes. At itsannual shareholder meetingon Friday, the Mumbai-based conglomerate announced Jio Call Agent, an AI assistant that can join phone calls to transcribe conversations, generate summaries, and perform tasks such as booking cabs, ordering food, and making reservations. The service, which can be activated by saying “Hey Jio,” is expected to launch later this year for Jio’s more than 500 million users. By embedding the service directly into its telecom network rather than offering it as a stand-alone app, Jio is betting AI assistance can become a native feature of phone calls. The approach could reduce consumers’ reliance on third-party call-assistant apps and give Reliance a powerful distribution advantage in an increasingly crowded AI market. Reliance also unveiled an AI-powered version of its MyJio app that can perform tasks on behalf of users, from activating eSIMs to selecting roaming plans, through natural-language requests. The company further introduced TeleFrame, a home display that uses AI agents to proactively surface information and recommendations, such as weather alerts, schedules, and household reminders. The product appears to echo a broader industry push toward ambient AI assistants for the home, an area being explored by companies such asAmazonandGoogle. The announcements mark the next phase of Reliance’s AI ambitions as India seeks to build domestic capabilities in a field largely dominated by U.S. and Chinese technology companies. The push follows thelaunch of Reliance Intelligencelast year, through which the conglomerate aims to develop AI infrastructure and services for consumers, businesses, and governments, including applications that support 22 Indian languages. “India should not be a mere consumer of AI created elsewhere. It must become a creator, adopter, and a global leader in AI,” Ambani, age 69, said. Reliance has been ramping up its AI ambitions through partnerships withGoogle,Meta, andNvidia. Earlier this year, the company announced plans toinvest $110 billion in AI infrastructureas it seeks to establish itself as a major player in India’s emerging AI ecosystem. At the shareholder meeting, Reliance also unveiled a suite of AI services for healthcare, education, agriculture, and small businesses. The products, branded JioHealthIQ, JioLearnIQ, JioKrishiIQ, and AI Vyapar, are designed to operate across multiple Indian languages and cater to local needs, the company said. The shareholder meeting also brought a major development for investorsawaiting Jio’s stock market debut. Ambani said Jio Platforms’ board had approved a draft prospectus for an initial public offering that would include a fresh issue of up to 270 million shares, according to a stock exchange filing. The announcements also raise questions about how Reliance will handle user data as it expands AI services across phone calls, mobile apps, and connected homes. While the company said the services would operate with user consent, it did not answer questions about whether data generated through the products could be used to train AI models or shared with technology partners. Reliance’s AI ambitions come as Indian companies remain heavily reliant on foreign AI models and cloud providers.Recent restrictions on accessto some of Anthropic’s latest models have underscored that dependency, showing how decisions made overseas can affectstartups and businessesbuilding AI products in India — the kind of supply-chain risk that’s pushing Indian conglomerates toward building their own stack rather than renting someone else’s. Last week, Reliance announced acollaboration with Meta to establish an AI data centerin the western state of Gujarat, building on Meta’s earlier investment in Jio Platforms and a joint venture launched last year to develop AI solutions for enterprise customers in India and overseas markets. Reliance is not alone in pursuing AI opportunities.Tata Consultancy Services,Infosys, and rivalAdani Grouphave also expanded their AI initiatives and partnerships with global players, including Anthropic, Google, and OpenAI, as India’s largest corporations race to secure a leading role in the country’s AI future. Nonetheless, for Reliance, the stakes are particularly high; it’s preparing Jio for a long-awaited stock market debut and needs new growth drivers, with the conglomerate’s shares down about 17% this year.

20 hours ago

View