Google iconGoogleSep 16, 2026 ~7 min source read

How Google Sees and Defends Against AI-Driven Attacks

Google Threat Intelligence describes three structural shifts in the AI threat landscape and practical defensive approaches: secure AI-native development, broader attack-surface management, and multi-model detection and remediation.

Cloud CISO Perspectives: How Google monitors AI threats and advances AI defenses

Share this story

Send the public story page.

Useful takeaways from this story.

AI changes software velocity and supply-chain risk: attackers contaminate upstream packages and exploit AI-assisted coding, so security must be built into developer workflows.

Adversaries are weaponizing agents and prompt-based techniques: observed methods include prompt injection, toolkit hijacks, and obfuscation with toxic prompts (tracked in incidents attributed to TeamPCP/UNC6780).

Avoid single-model defenses: Google uses multi-model cross-validation (Gemini, commercial, and open models) to reduce blind spots and false positives.

The useful part

How Google monitors AI threats and advances AI defenses | Google Cloud Blog Security & Identity Cloud CISO Perspectives: Today, Sandra Joyce shares the latest details on Google's visibility into how attackers are using AI, and how we're using AI to stop them. Joyce, VP, Google Threat Intelligence Anyone operating in security knows that speculation is a major liability during periods of technological disruption.

How it works

  • While there is plenty of hype and understandable concern around how threats might use and target AI, a CISO's AI security strategy has to be anchored in ground truth.
  • This dual vantage point allows us to understand how AI is built, and exactly how AI is being targeted in the wild.
  • When we strip away the noise and look at the telemetry, the real threat landscape boils down to three structural shifts that CISOs must address: AI is reshaping how software is built.
  • Across the industry, autonomous agents and AI workflows now push code into production at unprecedented speed.
  • No single AI model can discover every vulnerability, and threat actors are already testing inputs that can blind specific LLM safety filters and scanners.

What to take from it

This creates exciting opportunities for innovation, yet CISOs are faced with the difficult task of mitigating enterprise risk while maintaining business momentum. By orchestrating several foundation models — including Gemini, commercial, and open-source — we cross-validate findings, strip out false positives, remediate code, and identify complex logic flaws that a single model misses. Don't treat agent access policies, model inventories (AI-BOMs) and shadow AI as separate challenges because these risks are deeply connected.

Example or evidence

  • The solution to a machine-speed threat landscape isn't slowing developers down — it's building security natively into the AI pipeline.
  • In Q2 2026, Mandiant investigated multiple data theft extortion operations where threat actors stole proprietary AI data, including models, skills, prompts, source code, and related research.
  • The threat actor used an AI coding chatbot, a prompt, and a set of agent instructions to plan, build, and execute a mass credential harvesting campaign in less than six hours.
  • Google operates at a rare intersection as both a frontier AI lab and a security company with a frontline view of global incidents.

Details worth keeping

To provide the operational realities that security and business leaders need in the AI era, Google Threat Intelligence Group (GTIG) recently released our latest AI Threat Tracker. Today, we're sharing details on Google's visibility into these three challenges, and our approach for solving them. We're seeing threat actors turn our greatest engineering shortcut against us by contaminating upstream packages that AI assistants are trained to suggest and trust.

Related coverage

  • Google: Written by: Alex Tselevich, Michael Maturi Introduction Adversarial misuse of AI has increased the risk of data theft and extortion events, because when proprietary source code is exposed, defenders must...
  • Google: AI agents are the ultimate insiders.
  • Cm Alliance: Wiz is a leading cloud security platform, but an enterprise may still look for alternatives when cloud workload pricing grows, AppSec remains distributed across separate products or engineering teams...

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app