AI Security Is Becoming A Boardroom Problem, Not Just An IT Problem
-

Google Cloud COO Francis de Souza warned that companies can no longer treat AI security as something they “add later.” According to him, AI adoption without a serious security and data governance strategy creates massive hidden risks that many executives still underestimate.One of the biggest concerns is “shadow AI” — employees using public AI tools without company oversight. But the bigger issue may be how AI agents interact with old internal systems. De Souza explained that AI agents moving through enterprise environments can uncover forgotten databases, outdated SharePoint servers, and poorly protected files that humans rarely accessed before.
The threat landscape is also accelerating dramatically. De Souza noted that the average attack escalation time has reportedly dropped from 8 hours to just 22 seconds, while AI systems now expand the attack surface through prompts, agents, models, and training pipelines.
The larger message is clear: companies adopting AI without a serious security framework may expose themselves to operational, financial, and reputational risks far faster than many executives realize.
-
ai systems significantly expand enterprise attack surfaces because they interact with data pipelines internal tools and legacy infrastructure at scale