Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Google uses AI to detect scams, fix vulnerabilities faster

Google is using AI to counter cyber threats, matching the tools used by hackers to detect and fix vulnerabilities at speed, according to Royal Hansen, the company’s vice president overseeing cybersecurity, privacy, and safety.

Speaking to Calcalist, Hansen said Google deploys AI models like Gemini to identify scams, find vulnerabilities, and automate security patches across its products.

He cited Project Zero, an internal team that searches for software security flaws, and Project Mender, which uses AI to write and test patches for those flaws.

Hansen noted that attackers are also turning to AI tools, including Gemini, to gather information and generate malicious code.

He said the rapid evolution of threats requires defenders to adopt similar automation to keep pace.

Hansen added that the distinction between legitimate researchers and malicious actors remains a challenge, and that broader use of AI among professionals—such as doctors and engineers—will improve policy discussions and security outcomes.

🔗 Source: Calcalist

🧠 Food for thought

Implications, context, and why it matters.

Google’s AI security claims lack hard evidence of real-world impact

  • Google promotes CodeMender (an AI system for generating and testing security patches) and cites Project Zero. The DeepMind (Google’s AI research lab) post 1 withholds basics such as how many AI-generated patches reached production in Chrome, Android, or Google Cloud, plus any measured cuts in time to detect or fix issues.
  • CodeMender has upstreamed (contributed back to the original open-source projects) 72 security fixes over six months 1. That is a small slice of daily vulnerabilities across software. Cybercrime could reach $13.82 trillion per year by 2028 2, so the needed AI remediation dwarfs current output.
  • Human security researchers review every CodeMender patch before submission 1. The AI has not earned full autonomy, despite claims of machine-speed defense 3.

Vendors can fill the AI remediation gap for enterprises

  • Tool makers can target a market for model-agnostic (works with models from multiple providers) AI remediation platforms. These plug into CI/CD (Continuous Integration/Continuous Delivery) pipelines, SBOM (Software Bill of Materials) patching systems, and test harnesses (automated testing frameworks). Most enterprises do not have Google-level infrastructure.
  • In one study, 68% of organizations failed to remediate critical vulnerabilities within 24 hours 4. That creates demand for tools that automate prioritization, generate environment-specific fixes, and route issues to the right product engineering teams without Google-scale resources 5.
  • Startups in this space can win on validation and safety. Snyk (a developer-focused security platform) cites a 288% ROI (return on investment) from productivity gains plus risk reduction when automated remediation cuts false positives, then fits into developer workflows 6.

Recent Google developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.