AI Deep Context: The Defender’s New Edge
Quick answer
Google Cloud's AI Threat Defense uses deep context to give defenders an edge against AI-powered attacks. Morgan Stanley cut detection time by 99.9%.
Welcome back to the swamp, defenders. The caimans are circling with AI-powered zero-days, but Google Cloud’s latest CISO Perspectives newsletter shows how deep context gives you the upper hand. Francis deSouza, COO and President of Security Products, breaks down why defenders now have a distinct advantage—if they leverage AI the right way.
The Attacker’s Speed vs. The Defender’s Context
Attackers are moving at machine speed. The handoff between attack stages has shrunk from eight hours to just 22 seconds. But defenders have something attackers lack: complete visibility into their own environment. While an attacker probes blindly from the outside, you know exactly where every asset lives, how it behaves, and who owns it.
That deep context is the foundation of what Google calls the defender’s advantage. And it’s powered by AI.
Google AI Threat Defense: A Unified Blueprint
Google’s new AI Threat Defense framework combines Gemini’s reasoning, Wiz’s cloud context, CodeMender’s auto-fixes, and Mandiant’s threat intel into a single platform. The result? A continuous four-step cycle:
- Prepare: Map exposures with Wiz, simulate attack paths with the Red Agent.
- Scan & Prioritize: Use multi-model scanning—light models for broad coverage, Gemini for deep dives.
- Remediate: Auto-generate verified code fixes via CodeMender in your IDE.
- Monitor: Deploy AI agents to hunt for anomalies across network, identity, and app telemetry.
Morgan Stanley put this into practice and slashed mean time to detect threats by 99.9%—from 45 minutes to under 90 seconds. That’s the difference between a capybara calmly munching weeds and a caiman snapping at shadows.
Human Oversight Still Matters
AI agents run at machine speed, but humans stay in the loop. Wiz’s Red, Blue, and Green agents automate pen testing, threat hunting, and remediation—all under human supervision. It’s autonomy with a safety net, not a full handoff.
As deSouza puts it: “Every AI conversation is a security conversation.” Securing AI infrastructure means building from the ground up, not bolting on later. That’s why Google’s secure-by-default architecture blocks nearly 15 billion unwanted emails daily.
What’s Next: AI-Native, Agent-Driven Infrastructure
The next frontier is protecting against shadow AI—unauthorized agents and models that employees spin up outside IT oversight. Zero Trust for AI is the answer, directing teams toward approved architectures with proper governance.
Want to dive deeper? Check out our reviews of Google Cloud and Cloudflare Workers for more on building secure, scalable infrastructure. And if you’re comparing AI model costs, our pricing comparison has you covered.
Fight AI with AI. The swamp is safer when you’ve got deep context on your side.
Original announcement published on Google Cloud.