Google Cloud integrates Gemini, Wiz into unified AI security platform

Every AI conversation is a security conversation.
Google Cloud's security chief on why AI infrastructure must be built secure from the start, not patched later.
Mark

Why does Google think defenders have an advantage over attackers when both sides have access to AI?

Mimi

Because defenders see the inside of the system. They know where everything is, who has access, how the code is written. An attacker has to figure all that out from the outside. AI makes both sides faster, but the defender's knowledge is harder to replicate.

Mark

The Morgan Stanley number—99.9 percent reduction in detection time—that seems almost too good to be true.

Mimi

It's real, but it's also a specific case. They went from 45 minutes to 90 seconds. That's the gap between when a threat exists and when humans know about it. The platform doesn't eliminate the threat; it just collapses the time you're blind to it.

Mark

What's the shadow AI problem deSouza mentioned?

Mimi

Employees building their own AI agents and models outside IT controls. You get logic flaws, data poisoning, systems talking to each other in ways nobody approved. It's the security risk of democratizing AI without guardrails.

Mark

Is Google saying you need all four of these tools, or could you mix and match?

Mimi

They're saying the power comes from them working together—one system seeing everything at once. You could use pieces separately, but you lose the context advantage. That's the sales pitch, anyway.

Mark

What happens to the security vendors Google didn't acquire?

Mimi

They have to prove they can do more than one thing well. The market is moving toward consolidation. Standalone tools are becoming harder to justify when integrated platforms can do detection and remediation in the same breath.

  • AI has crossed from defensive assistant to offensive weapon — Google's own threat team documented the first zero-day exploit built entirely by AI, compressing the timeline defenders have to respond.
  • Security teams are drowning in fragmented tools and alarm fatigue, while attackers move fluidly across reconnaissance, phishing, and exploitation without needing deep target knowledge.
  • Google Cloud is consolidating Gemini, Wiz, CodeMender, and Mandiant into a four-stage framework — prepare, scan, remediate, monitor — designed to turn an organization's internal context into a competitive defense advantage.
  • Morgan Stanley's deployment of this approach reduced mean time to detect threats by 99.9 percent, collapsing a 45-minute process into 90 seconds — a concrete proof point that reframes the AI security debate in executive terms.
  • A new risk is emerging from within: shadow AI deployments by employees outside IT controls are introducing hidden logic flaws and data-poisoning vulnerabilities, making internal governance as urgent as external defense.

At a moment when artificial intelligence has become both shield and spear, Google Cloud has drawn its four major security tools into a single platform — a recognition that defenders who remain siloed will lose ground to attackers who do not. The first documented AI-built zero-day exploit signals that the nature of digital threat has crossed a threshold, and the question now is whether the organizations that hold internal knowledge about their own systems can learn to wield that advantage faster than adversaries can probe for openings. Google's answer is integration: not more tools, but a unified architecture that transforms organizational context into a structural defense.

Google Cloud has unified four of its security products into a single platform, arguing that defenders can only outpace AI-driven attackers if they stop operating in isolation. The catalyst is stark: Google's threat intelligence team recently documented the first zero-day exploit built entirely by artificial intelligence, marking a shift in the nature of digital conflict that demands a different kind of response.

Francis deSouza, who leads Google Cloud's security division, framed the integration around a structural asymmetry. Attackers using AI don't need to understand a target deeply — they simply probe for the next opening. Defenders, by contrast, hold something attackers cannot easily replicate: intimate knowledge of their own environments. The platform — combining Gemini, Wiz, CodeMender, and Mandiant — is built to let organizations weaponize that internal context.

The four-stage framework moves from preparation, where Wiz maps exposed assets and a red-team agent simulates attacker movement, through scanning and prioritization, where Gemini filters noise to surface genuine risk. Remediation follows, with CodeMender generating code fixes directly inside developer tools. Continuous monitoring by AI agents then watches for anomalies that signature-based systems would miss.

Morgan Stanley put the framework to a concrete test, working with Google Cloud and Wiz to restructure its security program around the same sequence. Mean time to detect threats fell by 99.9 percent — from 45 minutes to 90 seconds — translating abstract AI promises into the language of executive risk.

DeSouza was careful to name a danger closer to home: shadow AI, where employees deploy models outside approved controls, quietly introducing logic flaws and data-poisoning risks. Every AI conversation, he said, is a security conversation. The broader message Google Cloud is sending to the market is that the future of defense is not more point tools, but deeper integration of the ones that already exist.

Google Cloud has woven together four of its security tools into a single platform, betting that defenders can outpace attackers if they stop working in silos. The move arrives at a moment when artificial intelligence itself has become a weapon—Google's threat intelligence team recently documented the first known zero-day exploit built entirely by AI, a milestone that underscores how the nature of the threat has shifted.

Francis deSouza, who runs Google Cloud's security division, framed the integration as a response to a fundamental imbalance. Attackers have discovered that AI accelerates their work at every stage: reconnaissance, phishing, exploit development, lateral movement. They move faster because they don't need to understand a target deeply—they just need to find the next opening. Defenders, deSouza argued, have a structural advantage that AI can amplify rather than replace. They have access to internal knowledge that outsiders cannot easily obtain: where assets live, how applications behave, which identities hold access, who owns each service. The new platform—combining Gemini, Wiz, CodeMender and Mandiant—is designed to let defenders weaponize that internal context.

The framework Google Cloud outlined has four stages. First comes preparation: Wiz maps exposed applications, APIs, identities and runtime environments, while a red-team agent simulates how an attacker might move through the system. Second is scanning and prioritization, where lighter AI models cast a wide net and Gemini digs deeper into the highest-risk assets, filtering noise so security teams see signal instead of alarm fatigue. Third is remediation, where CodeMender generates code fixes inside developer tools, shortening the time between discovery and repair. Last is monitoring, where AI agents watch network, identity and application telemetry for vulnerabilities and anomalies that standard signatures might miss.

Morgan Stanley offers a concrete measure of what this approach can deliver. The bank worked with Google Cloud and Wiz to reorganize its security program around the same four-stage sequence. The result: mean time to detect threats fell by 99.9 percent, compressing what once took 45 minutes into 90 seconds or less. That number carries weight in the market because it translates abstract promises about AI into a language executives understand—speed, efficiency, risk reduction.

But deSouza was careful to note that speed without governance is its own kind of danger. He warned about shadow AI: employees deploying models outside approved IT controls, introducing hidden logic flaws and data-poisoning risks. Every AI conversation, he said, is a security conversation. Building secure AI infrastructure requires starting from the ground up, not bolting security onto systems after the fact.

The announcement reflects a broader market shift. Cloud providers and security vendors have spent the past year racing to show that generative AI can do more than chat—that it can actually defend. Rivals have focused on copilots and assistants. Google Cloud is trying to differentiate itself by presenting an integrated operating model: threat intelligence, cloud posture data, and code-level remediation working as one system. Buyers increasingly want fewer point tools and more consolidated platforms that connect prevention, detection and response. By tying Wiz, Gemini, Mandiant and CodeMender together, Google Cloud is making the case that the future of security is not more tools, but better integration of the tools that already exist.

Attackers are making headlines with AI, but defenders have a distinct and powerful advantage.
— Francis deSouza, COO of Google Cloud and President of Security Products
Every AI conversation is a security conversation. That means securing AI infrastructure requires building from the ground up, and not bolting on.
— Francis deSouza
Nous contacter FAQ