Google is recasting its security posture around an AI-led, agentic defense strategy, shifting from human-led operations to fleets of specialized AI agents that perform routine cybersecurity work at machine speed under human oversight. As questions grow about delays in rolling out some Gemini capabilities and intensifying competition from rival frontier models, the company is using security to argue that its approach reflects long-term resilience rather than short-term showmanship.
Executives present the shift as a structural change in how cyber defense is organized, with AI systems positioned as the first line of response against increasingly automated attacks. It is also beginning to deploy new AI security agents for threat hunting, detection engineering, and third-party context enrichment to extend this model across routine security workflows. Moreover, such a strategy aligns with the emergency response frameworks being developed globally to manage high-risk AI incidents.
At the center of this message is the idea of “AI to fight AI,” in which autonomous agents are deployed across detection, response, and recovery workflows to counter machine-speed threats. Google describes a security model built around an agentic fleet of specialized AI agents operating across security operations centers, red teams, blue teams, and green teams, all governed by clear human oversight and policy.
AI to fight AI: autonomous, specialized agents defending at machine speed across SOCs and security teams, under human oversight
In partner environments, the company reports that such deployments have reduced internal threat detection times by more than 90 percent and cut security operations costs by roughly two-thirds.
To reinforce this narrative, Google is highlighting its AI Cyber Defense Initiative, a program designed to reverse the so‑called “Defender’s Dilemma” in which attackers hold the advantage. The initiative combines investment in AI‑ready infrastructure, new tools for security teams, expanded research, and AI security training for defenders.
It is anchored by AI Threat Defense, described as an always‑on autonomous security platform that fuses the reasoning capabilities of Gemini with Wiz risk prioritization, CodeMender remediation, and Mandiant threat intelligence in a four‑step operating framework.
Alongside performance claims, Google is emphasizing governance. Its secure AI agent strategy argues for a hybrid defense‑in‑depth model that layers deterministic controls with dynamic, reasoning‑based defenses.
Core principles include clearly defined human controllers, tightly scoped agent powers, and strong observability into agent actions and plans. The company extends its secure‑by‑design philosophy to AI through the Secure AI Framework and an updated SAIF 2.0, aligning AI practices with established enterprise controls.
CodeMender, an AI‑powered agent built on Gemini, is presented as a practical example that automatically identifies and fixes critical code vulnerabilities at scale, while AI red teams blend security expertise and AI knowledge to simulate realistic adversaries.
Google also defends its AI strategy by pointing to an integrated stack spanning fiber, data centers, custom chips, models, and agents, arguing that full‑stack ownership is essential for mission‑critical security workloads.
The company cites roughly 2 million miles of subsea and terrestrial network, 43 cloud regions, and more than 200 points of presence as the backbone for deploying AI‑driven security services at global scale.
Amid concern that Gemini delays could weaken its competitive position, Google contends that this depth and governance outweigh short‑term headline speed today.








