On May 27, 2026, Google Cloud launched Google AI Threat Defense, combining Gemini, Wiz, CodeMender, and Mandiant capabilities into an enterprise AI security defense platform. It does not target traditional security reports, but rather that after AI accelerates attacks, companies need to discover, prioritize, and remediate risks more quickly.
This news is worth noting because security products are shifting from "telling you where the problem is" to "helping you prioritize and generating fixes." When attackers use AI to scan vulnerabilities, generate phishing content, and automate attack chains, relying solely on manual queuing to check alerts can no longer keep up.
How does this platform work?
Public information shows that Google AI Threat Defense is structured around four stages: preparation, scanning and prioritization, remediation, and monitoring. Wiz is responsible for cloud assets and risk exposure views, Mandiant provides threat intelligence and response experience, Gemini is involved in inference and analysis, and CodeMender pushes vulnerability fixes down to the code layer.
This means it's not just a single model feature, but rather Google's packaging of its cloud security assets in recent years into a more automated defense process. For large enterprises, the real value is not adding another dashboard, but whether cloud assets, code warehouses, identity risks, and threat intelligence can be linked into a closed loop.
Who is being influenced?
The most directly affected are enterprise security teams already using Google Cloud, Wiz, or Mandiant services. They may gain cross-cloud asset risk sequencing, automated remediation recommendations, and continuous monitoring capabilities more quickly. For companies deploying AI Agents or internal large model applications, these products will also become part of AI governance, as proxies themselves introduce new permissions and data flow risks.
However, automatic defense does not automatically delegate power. Companies still need to decide which patches can be automatically merged and which operations must first be confirmed by the security or business leader. Especially for automatic repair generation capabilities like CodeMender, implementation must be accompanied by testing, rollback, and auditing; otherwise, "fixing quickly" may become new production risks.
Industry signals
Companies like OpenAI, Anthropic, and Microsoft are all strengthening their AI security and defense products. This time, Google has integrated cloud, security, models, and code remediation into one framework, indicating that the enterprise AI market has entered a "capability + security" bundled sales phase. In the future, when enterprises buy AI, they will not only ask how powerful the model is, but also how it can protect the model, code, data, and automated processes.
Source of information
Source: Google Cloud official blog, The Indian Express report on May 28.