Back to News Hub
☁️Google Cloud AI
May 27, 2026
AI Automation

Introducing Google AI Threat Defense to help you outpace the adversary

Overview

Google is launching Google AI Threat Defense, an automated security system meant to continuously monitor for and stop AI-powered threats before they affect a business. The company says AI has changed the threat landscape, letting attackers find security gaps faster than teams can fix them manually. The system combines Gemini and other frontier models with the risk prioritization of Wiz, the code remediation of Gemini and CodeMender, and the frontline expertise of Mandiant. It follows a four-step framework of prepare, scan and prioritize, remediate, and monitor.

Key Takeaways

  • Google is launching Google AI Threat Defense to continuously monitor for and stop AI-powered threats.
  • AI has sped up attacks, so work that once took weeks can now happen in hours or days.
  • The system fuses Gemini and other frontier models with Wiz, CodeMender, and Mandiant.
  • It follows a four-step framework: prepare, scan and prioritize, remediate, and monitor.
  • Google says it delivers prioritized fixes rather than a massive, unprioritized list of AI-generated alerts.

Stats & Key Facts

  • #Google's secure-by-default architecture automatically blocks 10 million spam emails every minute
  • #The framework has four steps
Introducing Google AI Threat Defense to help you outpace the adversary

Why AI Changed the Threat Landscape

AI has shifted the balance between attackers and defenders.

  • Cybercriminals use AI to find security cracks faster than teams can manually fix them.
  • Attacks that used to take weeks can now happen in hours or days.
  • Organizations need to defend against AI agent-driven, high-speed attacks without relying on legacy manual methods.

Google argues that no single model will catch everything, so defenders should use a collection of models for multiple passes, with a solution that can analyze systems, prioritize threats, patch quickly, and monitor continuously.

Built on a Decade of Security Work

Google ties the new system to its existing security foundation.

  • Its secure-by-default architecture automatically blocks 10 million spam emails every minute.
  • Google pioneered Zero Trust, built Titan chips, and created Google Security Operations.
  • It combines the expertise of Mandiant and Wiz with the reasoning and code-generation of Gemini.

Google says it deploys LLM-powered analysis to autonomously discover software flaws and uses AI agents across Wiz and CodeMender to validate risk, generate fixes, and support remediation before vulnerabilities can be exploited.

What Google AI Threat Defense Combines

The system fuses several capabilities.

  • The reasoning power of Gemini and other frontier models.
  • The contextual risk prioritization of Wiz.
  • The code remediation of Gemini and CodeMender, plus the frontline expertise of Mandiant.

By connecting real-world exposure to autonomously creating and prioritizing patching, the system aims to predict attack paths, prioritize the most significant threats, and deploy verified fixes faster than adversaries can exploit them.

The Four-Step Framework

The system is based on Google's own approach to vulnerability management.

  • Prepare: harden the foundation and operationalize for machine-speed prioritization and response.
  • Scan and prioritize: conduct deep analysis and AI-driven posture validation.
  • Remediate: autonomously verify and accelerate patching of vulnerabilities.
  • Monitor: move to continuous detection and rehearsed, active response playbooks.

Prioritized Fixes Over Alert Lists

Google contrasts its approach with other providers.

  • Unlike providers that hand teams a massive, unprioritized list of AI-generated alerts, Google delivers prioritized fixes.
  • Prioritized fixes are meant to accelerate remediation.
  • Reducing unnecessary exposure is the first priority in the prepare step.

In the prepare step, Google says sensitive assets should not be reachable from the internet or exposed through untrusted paths regardless of patch status, with the goal of reducing what is reachable, not only fixing known critical issues.

Frequently Asked Questions

What is Google AI Threat Defense?

It is an automated security system designed to continuously monitor for and stop AI-powered threats before they impact a business.

Which Google capabilities does it combine?

It fuses Gemini and other frontier models with Wiz's risk prioritization, the code remediation of Gemini and CodeMender, and the frontline expertise of Mandiant.

What is the four-step framework?

The framework is prepare, scan and prioritize, remediate, and monitor.

How is it different from other providers?

Google says that unlike providers that hand teams a massive, unprioritized list of AI-generated alerts, it delivers prioritized fixes to accelerate remediation.

How much spam does Google's architecture block?

Google says its secure-by-default architecture automatically blocks 10 million spam emails every minute.

Google AI Threat Defense aims to automate defense at machine speed by pairing frontier models with Wiz, CodeMender, and Mandiant to deploy prioritized fixes.

Continue Learning

Originally published by Google Cloud AI
Read the original

Comments

Sign in to join the conversation