Google is bringing generative AI into cybersecurity with a suite designed to help security teams examine threats, search events and understand risks. The company says its tools can turn specialized security information into useful analysis, though their practical accuracy has yet to be established.
A security-focused model behind the tools
Announced at the RSA Conference 2023, Cloud Security AI Workbench is powered by Sec-PaLM, a security-focused language model derived from Google’s PaLM model. Google says Sec-PaLM is fine-tuned for security use cases and incorporates knowledge about software vulnerabilities, malware, threat indicators and behavioral threat actor profiles.
The suite brings that model into several Google security products. Mandiant’s Threat Intelligence AI is intended to use Sec-PaLM to find, summarize and act on security threats. Google purchased Mandiant in 2022 for $5.4 billion.
VirusTotal, another Google property, plans to use the model to help subscribers analyze and explain what malicious scripts do. For Chronicle, Google’s cloud cybersecurity service, Sec-PaLM is intended to support searches across security events and let users interact conversationally with the results.
Turning findings into explanations
Google also described AI support for Security Command Center. The company says users will receive human-readable explanations of attack exposure, with details on impacted assets, recommended mitigations and risk summaries tied to security, compliance and privacy findings.
These features point to a broader goal: making security information easier to interpret and act on. A team could use summaries to make sense of threat intelligence or search results, while explanations could help connect a finding to the assets and risks involved. Those are intended uses described by Google; the announcement does not establish how accurate or helpful the outputs will be in practice.
Google said the work draws on years of foundational AI research by Google and DeepMind, as well as the expertise of its security teams. It also framed the effort as an early step in applying generative AI to security.
Availability is limited, and accuracy is an open question
The first Cloud Security AI Workbench tool, VirusTotal Code Insight, is available only in a limited preview. Google said it planned to roll out the rest of the offerings to trusted testers in the coming months. That limited availability means the public announcement describes ambitions and planned capabilities more clearly than it demonstrates results at scale.
There are practical questions to resolve. Security teams need to know whether suggested mitigations and risk summaries are precise enough to rely on, and whether AI-generated explanations improve on existing ways of reviewing security findings. The announcement does not answer those questions.
Language models can make mistakes, and they can be vulnerable to prompt injection, which may cause them to behave in ways their creators did not intend. In a security setting, those limitations matter because users may rely on model-generated analysis while assessing threats or deciding what to do next.
A wider push, with evidence still needed
Google is not alone in pursuing generative AI for cybersecurity. In March, Microsoft launched Security Copilot, a tool intended to summarize and make sense of threat intelligence using generative AI models from OpenAI, including GPT-4. Microsoft, like Google, argued that generative AI could better equip security professionals to combat new threats.
Whether these systems deliver on those claims remains unsettled. The source article notes a dearth of studies on their effectiveness, so the announcements do not yet provide a strong basis for judging how much they improve security work. For now, AI cybersecurity tools should be assessed by their demonstrated performance, not just their promised features.
As Google’s offerings reach testers, the key questions are straightforward: Do the tools explain threats accurately? Are their recommendations useful? Can teams account for errors and prompt injection? The answers will determine whether generative AI becomes a dependable part of cybersecurity workflows.