Google to critical infra orgs: Our AI scanners won't be evil, promise
Google has jumped on the AI-defense-for-critical-systems train with its Scan for Good initiative, and says that its threat-hunting models have already autonomously uncovered critical security issues at hospitals, a municipality, a public rail operator, and major technology providers.
So don't fear these bots.
The initiative, announced on Thursday, uses Google’s Gemini 3.8 Flash Cyber, a version of the model tuned for software bug hunting and remediation, and Wiz’s Red Agent - this is the Google-owned cloud security shop’s pentesting AI agent.
The AI systems will uncover public exposures and attack paths across public services, critical infrastructure, and nonprofits, and then hand these off for verification and remediation to human security researchers.
“The program has been active over the past several months, and with this official launch, we are scaling it globally,” Gal Nagli, head of offensive security at Wiz, told The Register.
“There is no set end date.” It's similar to OpenAI’s Daybreak for Frontline Defenders initiative, announced earlier this month.
This program will distribute $1 billion in credits to subsidize access to OpenAI services and training for resource-strapped cyber defenders, including those protecting water and energy systems, community banks, local governments, nonprofits, and open-source projects.
And like OpenAI’s new program, the Wiz and Google DeepMind partnership follows disclosures that Google’s AI agents also escaped their sandboxes and hacked other companies’ websites - as did agents developed by OpenAI, Anthropic, and Meta, and those are just the ones we know about.
It also comes as existential dread about AI killing all of humanity reaches a fever pitch.
AI for good (not evil) Scan for Good aims to put offensive security agents and Gemini 3.8 Flash Cyber to good, not evil, use.
When authorized, either explicitly by organizations that apply for an assessment or under applicable bug bounty programs and vulnerability disclosure policies, the AIs will examine publicly facing websites, APIs, and applications for exposures, and then work with organizations to find and fix these.
Every potential finding will be reviewed and validated by a human, and Wiz assures that “humans will remain responsible for confirming impact and making disclosure decisions.” When the bots and humans do identify a serious issue, the humans will contact the affected organization and work with them to remediate the security holes.
Google’s AI systems have already helped critical organizations and tech providers find serious, internet-facing risks, including a critical GitHub Actions workflow vulnerability in one of Snowflake’s public repositories.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.