ARTFEED — Contemporary Art Intelligence

Google Cloud COO warns of AI security gaps as platform faces credential flaws

ai-technology · 2026-05-25

Francis de Souza, the COO of Google Cloud, urged businesses to integrate security measures from the outset of AI implementation, cautioning against the risks of 'shadow AI' and advocating for a multicloud security approach. He highlighted a significant reduction in the average breach-to-handoff duration, which has plummeted from eight hours to just 22 seconds, and pointed out that AI agents might reveal overlooked data stores. Meanwhile, The Register has reported that Google Cloud API keys can be misused for unauthorized Gemini API access, leading to charges as high as $10,138 in just 30 minutes. Although Google has reimbursed affected customers, it remains unwilling to alter its automatic billing tier upgrades. Aikido, a security firm, discovered that even after deletion, API keys can still be functional for up to 23 minutes due to delayed revocation processes, while Google's updated credential formats can revoke access within seconds, indicating a prioritization issue. LinkedIn's CISO, Lea Kissner, predicts that the industry will struggle to achieve a sustainable understanding of AI security for several years.

Key facts

  • Francis de Souza is COO of Google Cloud.
  • De Souza spoke at an event in Los Angeles.
  • He warned about 'shadow AI' and the need for platform-level security.
  • Average breach-to-handoff time dropped from 8 hours to 22 seconds.
  • AI agents can expose forgotten data repositories like old SharePoint servers.
  • The Register reported Google Cloud developers hit with five-figure bills from unauthorized Gemini API calls.
  • Rod Danan's bill hit $10,138 in 30 minutes.
  • Isuru Fonseka faced AUD $17,000 in charges despite a $250 spending cap.
  • Google refunded both after The Register's report.
  • Google has no plans to change its automatic tier-upgrade policy.
  • Aikido found that deleted API keys remain usable for up to 23 minutes.
  • Google's newer credential formats revoke in seconds.
  • Lea Kissner is LinkedIn's CISO and expects years before sustainable AI security understanding.

Entities

Institutions

  • Google Cloud
  • Google
  • The Register
  • Aikido
  • LinkedIn
  • New York Times
  • Prentus

Locations

  • Los Angeles
  • United States
  • Sydney
  • Australia

Sources