Cloud CISO Perspectives: How Google monitors AI threats and advances AI defenses
Google Cloud’s latest AI Threat Tracker outlines three key AI-driven security challenges and introduces an integrated, multi-model defense framework to counter evolving adversary tactics.
Google Cloud’s Office of the CISO highlights how attackers are increasingly leveraging AI tools to accelerate and automate threats, while Google uses its dual role as an AI innovator and security provider to monitor these risks. The company’s Threat Intelligence Group released the AI Threat Tracker to strip away speculation and provide CISOs with actionable insights grounded in real-world telemetry. The tracker identifies three structural shifts in the threat landscape that require immediate attention from security leaders.
AI-assisted coding has introduced new risks, as threat actors contaminate upstream packages that AI assistants trust, contributing to a rise in open-source software supply chain compromises observed in 2025 and early 2026. Financially motivated actors like TeamPCP (UNC6780) exploit AI toolkits through methods such as prompt injection and hijacking AI scanners to obscure malicious payloads. Google argues that slowing development is not the solution; instead, security must be embedded directly into AI pipelines.
To address these challenges, Google advocates for in-editor guardrails that flag poisoned packages and toxic prompts in real time, integrated with an end-to-end code-to-cloud approach. The company warns that relying on a single AI model for security creates a dangerous monoculture, as threat actors can blind specific LLM filters. Google’s solution involves orchestrating multiple foundation models—including Gemini, commercial, and open-source—to cross-validate findings and reduce false positives.
Securing AI workloads requires protecting against emerging threats like LLMJacking, where adversaries target GPU access to run unauthorized AI infrastructure, and the theft of proprietary AI data, including models and prompts. Google emphasizes the need for a unified security framework that connects code, models, data lineage, and runtime identities into a dynamic graph. This approach powers Google’s AI Threat Defense, which combines frontier models, contextual risk prioritization, and frontline expertise to counter AI-driven attacks at machine speed.