Logo
FrontierNews.ai

Google's Cyber Defense Chief: AI Threats Are Moving Faster Than Our Defenses

Google's top cyber defense official is sounding an alarm about the pace of AI-powered attacks, arguing that traditional human-speed defenses are no longer adequate in a world where attackers can automate threats across thousands of targets simultaneously. Shane Huntley, Chief Technology Officer and Senior Director at Google's Threat Intelligence Group, explained that the real challenge isn't choosing between open or closed AI models, but rather keeping up with how quickly both types are being weaponized by malicious actors.

Why Is AI Changing the Speed of Cyber Attacks?

The fundamental shift happening in cybersecurity isn't about which AI models are more dangerous, Huntley explained. Instead, it's about scale and velocity. Attackers who once operated at one speed can now automate their campaigns and target vastly more victims simultaneously. "We need to be doing defence at computer speed," Huntley stated, emphasizing that human-paced responses are becoming obsolete.

Huntley

What makes this particularly challenging is that attackers are using a mix of tools, both open-source and proprietary, to carry out their campaigns. Some are connecting AI models to existing open-source attack tools and then automating the entire process to target different victims. The result is an explosion of capability that makes attribution difficult, Huntley noted. When an automated attack occurs, defenders often cannot easily determine whether it's running in a data center, on someone's personal computer, or somewhere else entirely.

The hardware required to run sophisticated AI models is now accessible to everyday users at local stores, further democratizing the tools available to attackers. This means the threat landscape has fundamentally changed from a small number of well-resourced actors to potentially anyone with basic technical knowledge and access to consumer-grade computing equipment.

What Types of AI-Powered Attacks Are Actually Happening?

State-backed attackers are already exploiting AI in multiple ways beyond traditional hacking. According to Huntley, these threats include:

  • Social Engineering Attacks: Highly customized impersonation campaigns that use AI to craft convincing messages targeting specific individuals.
  • Ransomware Campaigns: Automated attacks that identify vulnerable systems and deploy encryption-based extortion at scale.
  • Phishing Scams: AI-generated emails and messages designed to trick users into revealing credentials or downloading malware.
  • Employment Scams: Fraudulent job offers and recruitment schemes that affect individual users and organizations alike.

Russia, Iran, and North Korea are among the primary threat actors that Google's team monitors. Russia, in particular, has been described as a "formidable and comprehensive threat actor" that will remain a significant concern for years to come.

How Is Google Defending Against AI-Powered Threats?

Google's first line of defense has historically been email protection. The company has a long history of using machine learning and artificial intelligence for defense, starting with Gmail's spam filters. This same principle applies to modern AI threats, Huntley explained. The equilibrium between attackers and defenders continues, but the speed at which both sides operate has accelerated dramatically.

Google takes a two-pronged approach to AI safety. The company releases both closed models, like Gemini and Gemini Ultra, as well as open-weight models, like Gemma. Huntley emphasized that this is not a "black-and-white situation." Google ensures its models are used on the defense side first and collaborates with good-faith actors to address vulnerabilities before broader model releases.

Huntley

"I think the open models do show us that these capabilities are going to be out there; this is not a technology that we can fully constrain. They can't just control how these hackers use AI, via controlling the environment," Huntley explained.

Shane Huntley, CTO and Senior Director at Google Threat Intelligence Group

The challenge, however, is that open-weight models demonstrate that AI capabilities cannot be fully contained. Once these models are released, attackers can modify and run them independently, making it impossible for any single organization to control how the technology is used for malicious purposes.

What Does Regulation Need to Get Right?

Huntley called for careful application of laws governing AI and AI companies, warning against over-regulation that could hamper defenders while leaving attackers in less-regulated countries with a free hand. "In one of the ways, the worst possible world would be, like, if we over-regulate the good guys so they can't actually use this to do defence, but then the attackers operating out of other countries with less regulations, are able to use it on the attacking side... then we haven't made the world better," he noted.

The pace of AI advancement is unprecedented. Huntley acknowledged that he himself has to discard almost everything he knows about AI every few months due to the speed of change. He cited the dot-com boom as a comparison point, noting that current AI development is moving far faster than that era did. "I've never seen a technology move this fast," Huntley remarked.

Huntley

For the general public, Huntley encouraged a more nuanced understanding of AI threats and capabilities. People often form opinions based on outdated information, such as a hallucinated answer or failed prompt from months or years ago. Instead, he suggested asking current questions: What can AI do now? How have things changed? What is new? What is happening? The answers to these questions change rapidly, and staying informed requires continuous learning rather than relying on past experiences.