Jump to Content
Security & Identity

Securing enterprise agility in the machine-speed era

October 1, 2026
https://storage.googleapis.com/gweb-cloudblog-publish/images/CDS_2026_Sandra_Joyce_Defend.max-1500x1500.png
David Stone

Director, Financial Services, Office of the CISO

What business leaders need to know about fighting AI with AI

Get original CISO insights in your inbox

The latest on security from Google Cloud's Office of the CISO, twice a month.

Subscribe

The rise of agentic AI marks a fundamental inflection point in enterprise technology. AI tools are no longer merely assisting human operators: They are actively executing tasks, writing code, and orchestrating complex workflows. 

Cybercriminals are using AI to find security cracks faster than ever before. Attacks that used to take weeks to carry out can now happen in mere hours or even minutes, and cybersecurity teams also need to use AI to detect and fix flaws at the same speed. 

Modern security operations require a cohesive framework that can analyze systems, prioritize critical risks, apply fixes efficiently, and continuously monitor for emerging threats. To support organizations in this transition, Google AI Threat Defense brings together security platforms, foundation models and agents, and consulting expertise to help teams navigate today's evolving threat landscape.

https://storage.googleapis.com/gweb-cloudblog-publish/original_images/AITD_00_BLOG_NEW_2436x1200.gif

Google AI Threat Defense brings together security platforms, foundation models and agents, and consulting expertise to help teams navigate today's evolving threat landscape

For example, by aligning its security posture with Google Cloud and Wiz under the AI Threat Defense blueprint, Morgan Stanley reduced its mean time to detect threats by 99.9% — shifting from a reactive 45-minute detection window to proactive mitigation in 90 seconds or less.

A rapidly changing threat landscape

Today’s adversaries are using AI across the attack lifecycle, turning our greatest engineering shortcut against us. AI is reshaping how software is built, expanding the attack surface, and enhancing threat capabilities.

  • Wider attack surface: Autonomous agents and AI workflows now push code into production at unprecedented speed. Security struggled to cover the cloud explosion, and we can no longer scale human analysts alone to cover AI-driven exponential growth. 

  • New resources and risks: The tools that make AI so powerful also have to be secured, including models, agents, and AI-specific protocols.

  • Machine-speed threat landscape: Threat actors are targeting AI workloads with techniques that include hijacking and deploying unauthorized AI infrastructure, stealing AI data and access, and contaminating upstream packages that AI assistants are trained to suggest and trust.

Traditional security workflows — static threat modeling, manual alert triage, and siloed point tools — are structurally incapable of matching machine-speed attacks. Handing security teams an unprioritized deluge of thousands of AI-generated alerts only worsens fatigue and delays remediation.

Leveraging deep internal context

In the age of autonomous threats, model capability alone won’t win defensive battles. You need to lean into your own deep internal business context to gain a decisive advantage.

External threat actors are stuck probing systems blindly, but only you possess the exact knowledge of insights like:

  • How your application microservices interact and depend on each other.

  • Where your critical data assets reside and how your sensitive workflows operate.

  • Which identity privileges exist and which network paths are actually reachable.

When AI defensive platforms are fed your contextual awareness, they filter out background noise and false-positive alerts. Instead of flagging thousands of theoretical vulnerabilities, AI systems direct engineering resources strictly toward reachable, high-impact risks. 

Context turns alert fatigue into targeted, automated remediation.

The AI Threat Defense advantage

To create an advantage for defenders, we developed AI Threat Defense as an automated security system to continuously monitor, prioritize, and minimize AI-driven threats at machine speed.

Securing the AI era can’t be achieved with the disconnected, manual tools of the past. As a major security and AI provider, we take developing effective next-generation solutions seriously, and recommend using multiple levers to stay ahead because monoculture in itself is a vulnerability.

By pairing frontline expertise and vulnerability program guidance with real-world risk scanning and code remediation, AI Threat Defense enables enterprise security teams to discover attack paths and remediate code faster than adversaries can exploit flaws.

Different models have different strengths and costs, and the best outcomes are when you layer multiple models together with a dedicated security harness. AI Threat Defense implements a multi-model, multi-pass defense architecture. The platform unites four core capabilities into a single, unified blueprint:

  1. Expertise built on frontline threat intelligence (Mandiant): Integrates real-world breach insights and attacker tactics to help modernize your vulnerability management program.

  2. Contextual risk and exposure prioritization (Wiz): Analyzes cloud and AI applications  to expand visibility, prioritize validated, exploitable attack paths, and accelerate remediation.

  3. Advanced reasoning and analysis (Gemini and other AI models): Evaluates complex application behavior, code logic, and threat vectors across layered systems.

  4. Autonomous vulnerability find and fix (CodeMender): Uses AI code security agents to automatically find vulnerabilities and generate, test, and propose verified code fixes before they reach production.

By pairing frontline expertise and vulnerability program guidance with real-world risk scanning and code remediation, AI Threat Defense enables enterprise security teams to discover attack paths and remediate code faster than adversaries can exploit flaws.

4 battle-tested lessons from Google

Google Cloud's approach to customer defense is built directly on the principles we use to protect our global infrastructure. AI Threat Defense is inspired by these lessons:

  1. Orchestrate multi-model passes: No single model detects every flaw. We developed and shared the open-source Mantis harness to orchestrate specialized models across sequential analysis passes.

  2. Implement agentic security review pipelines: Static, periodic security reviews are obsolete. Internal launch pipelines at Google Cloud now route code through automated agent-based security reviews that maintain dynamic product dossiers in real time, automatically escalating high-risk edge cases for human approval.

  3. Automate remediation, not just detection: Finding flaws at scale without automated fixes creates an unmanageable engineering backlog. Agents like CodeMender bridge the gap between discovery and fix deployment.

  4. Anchor defense in security fundamentals: AI-powered security is an amplifier of your existing security hygiene. Core practices — such as Zero Trust frameworks, multi-factor authentication (MFA), robust identity governance, and strict system patching — are the essential foundation required for AI tools to operate safely and effectively.

By pairing open-source tooling like Mantis with autonomous, self-healing execution loops, we are pioneering a future of "immune" software development — where applications continuously discover, validate, and fix their own weaknesses in real-time.

Business impact and the forward strategy

In today’s environment, every major business initiative is an AI initiative, and every AI initiative requires a secure foundation. Ensuring your company is investing in the right technologies and using the right tools will be crucial in leading through the rapid AI transformation. 

Human-speed vulnerability management is no longer a viable strategy for enterprise risk. The era of machine-speed attacks demands an autonomous, continuous defense.

CISOs and executive leadership should use the following framework to prepare your organizations for the AI era. We also have a discussion guide that you can use in boardroom conversations.

  • Establish governance and clear ownership, including a defined committee, roles, and decision-making processes.

  • Define outcomes and key metrics to track progress and report to executive stakeholders.

  • Create policies, SLAs, and exception processes to ensure risk is addressed consistently.

The collapse of the exploit window has made one thing clear: Human-speed vulnerability management is no longer a viable strategy for enterprise risk. The era of machine-speed attacks demands an autonomous, continuous defense.

But AI security is far more complicated than simply about finding and fixing bugs faster. It requires redesigning how software is built, maintained, monitored, and secured so defenses can continuously learn, adapt, and strengthen over time.

To learn more about AI Threat Defense and how Google can help you build your defender’s advantage, sign up for our webinar on resilient AI-era defense here.

Posted in