Google Cloud’s chief operating officer, Francis de Souza, recently offered a sobering assessment of the AI security landscape backstage at an event in Los Angeles. Speaking with the measured cadence of a university professor, de Souza acknowledged a difficult transition period ahead for enterprises, even as his own company confronts a series of high-profile security incidents involving its Gemini AI platform. His core message was familiar to security professionals but has taken on new urgency: security can no longer be an afterthought in the age of artificial intelligence. “As companies embark on this AI journey, they need to take a platform approach,” de Souza said. “Security is not something you can bolt on later, and it is not something you can leave up to employees to do on their own.” He warned specifically about “shadow AI,” the phenomenon of employees reaching for consumer-grade AI tools without organizational oversight, and argued that companies must demand security, governance, and auditability from their platforms from the very beginning. “There is no such thing as an AI strategy without a data strategy and a security strategy,” he added. “They need to go hand in hand.” De Souza was careful not to pitch Google Cloud as the sole answer. When pressed, he emphasized the company’s commitment to a multicloud reality, arguing that businesses that believe they operate on a single cloud are almost certainly mistaken. “Even if they pick a single cloud, they are relying on SaaS applications, and there are business partners that may be using different clouds,” he noted. “It is important for companies to have a security posture that is consistent across clouds, across models.”
The Threat Landscape Has Fundamentally Changed
De Souza painted a picture of a threat environment that has accelerated beyond the capacity of traditional defenses. He highlighted a startling statistic: the average time between an initial breach and the handoff to the next stage of an attack has collapsed from eight hours to just 22 seconds. The attack surface itself has expanded far beyond the conventional network perimeter. “In addition to your usual estate, you have models now. You have data pipelines used to train the models. You have agents, you have prompts,” he said. “All of this needs to be protected.” One particularly insidious threat he flagged involves AI agents moving through a company’s internal systems. These agents can surface long-forgotten data repositories that no one has thought about in years. “A lot of organizations have old SharePoint servers and access controls they have not really updated, but it did not matter because nobody really knew where they were,” de Souza explained. “But agents roaming your enterprise will find those data assets and will expose the data on them.”
Meeting Machine Speed with Machine Speed
The answer, according to de Souza, lies in a paradigm shift from human-led defense to AI-native, fully agentic security operations. “Instead of having a human-led defense or even a human in the loop, you can now have humans overseeing a fully agentic defense,” he said. This transition elevates cybersecurity from a technical concern to a board-level and executive team issue. “It is not just a security team’s issue,” he stressed. Yet even as AI takes on more of the defensive workload, the pool of qualified human overseers remains critically shallow. The vulnerabilities that AI itself introduces are multiplying faster than security teams can address them. “We are going to need people to deal with the bug-pocalypse,” Lea Kissner, chief information security officer at LinkedIn, recently told the New York Times, adding that she does not expect the industry to understand AI security in any sustainable long-term way for at least several years.
Google Cloud Developers Hit with Five-Figure Bills
The gap between de Souza’s visionary advice and Google’s own platform realities has been laid bare by a series of investigative reports from The Register over the past several weeks. The publication documented a wave of Google Cloud developers who were blindsided by enormous bills resulting from unauthorized API calls to Gemini models, services many of them had never intentionally enabled. The pattern was consistent: API keys originally created for Google Maps, and placed publicly according to Google’s own documentation, had quietly been granted the ability to access Gemini after Google expanded their scope without clearly communicating the change. Rod Danan, CEO of the interview-prep platform Prentus, saw his bill hit $10,138 in roughly 30 minutes after attackers exploited his compromised API key. Isuru Fonseka, a Sydney-based developer, woke up to charges of approximately AUD $17,000 despite believing he had a $250 spending cap firmly in place. Neither developer was aware that Google’s automated systems had upgraded their billing tiers based on account history, raising their effective ceilings as high as $100,000 without explicit consent.
Google’s Refund Policy and Automatic Tier Upgrades
Google refunded both affected users after The Register published its initial report. However, the company made clear that it has no intention of changing its automatic tier-upgrade policy. Google told The Register that its priority is preventing service outages for customers, not enforcing users’ stated budget preferences. This stance leaves developers exposed to financial risk even when they have taken steps to protect themselves.
The 23-Minute Revocation Gap
A separate investigation by security firm Aikido, also reported by The Register, revealed an even more troubling vulnerability. Even developers who catch a compromised key and immediately delete it may not be safe. According to Aikido’s findings, attackers can continue using that key for up to 23 minutes because Google’s revocation process propagates gradually across its infrastructure. Joseph Leon, the Aikido researcher who led the study, told The Register that success rates during this window are unpredictable. In some minutes, over 90 percent of requests still authenticated, giving attackers ample time to exfiltrate files and cached conversation data from Gemini. Leon also noted that Google’s own newer credential formats do not exhibit the same problem. Service account API credentials revoke in about five seconds, and Gemini’s newer AQ-prefixed key format takes about a minute. “Both run at Google scale,” Leon wrote in Aikido’s related paper. “Both suggest this is technically solvable for Google API keys, too.” In other words, the 23-minute window is not an engineering constraint but a matter of priorities for the company.
What This Means for Enterprise AI Adoption
The juxtaposition of de Souza’s forward-thinking advice with the concrete reality of Google Cloud’s API key vulnerabilities creates an instructive tension for the entire industry. De Souza is not wrong about the principles: security must be foundational, not bolted on. The threat landscape has changed irreversibly, and organizations must adapt. But the gap between what platform providers prescribe and how quickly they themselves adapt is a critical concern that every enterprise should factor into its AI strategy. The message for C-suite executives and board members is clear. AI security cannot be delegated entirely to the platform provider or to individual developers. It requires active oversight, continuous monitoring, and a healthy skepticism about the speed at which even the largest technology companies can close their own security gaps. The transition period de Souza spoke of is real, and it is happening now. The companies that navigate it successfully will be those that treat security not as a feature to be added later but as a non-negotiable dimension of every AI deployment from day one.