Google and Gatekeeper Warn of AI-Driven Security Risks
Google and Gatekeeper warn that AI integration in software and automated vulnerability analysis are creating new security gaps and accelerating the weaponization of known flaws.
Security experts and technology leaders are warning businesses about the systemic risks introduced by the rapid integration of artificial intelligence into software ecosystems. Google recently analyzed disclosed vulnerabilities from the past 18 months, finding that while AI primarily identifies medium-risk flaws, the total number of known vulnerabilities doubled to over 10,000 by July 2026. Google warned that threat actors are now using AI to automate the analysis of patches and version differences, accelerating the weaponization of known exploits.
Beyond vulnerability discovery, Google identified 782 flaws in AI orchestration and agent frameworks, noting that centralized AI gateways can become critical vectors for harvesting credentials. In a similar vein, Patrick O’Connor, CEO of Gatekeeper, warned that software suppliers often integrate AI features without notifying customers, allowing these tools to inherit broad access permissions that create vulnerabilities. O'Connor cited an August 2025 incident where attackers stole access tokens from Drift, an AI chat agent sold by Salesloft, to extract cloud keys and passwords from over 700 organizations, including Cloudflare and Palo Alto Networks.
To counter these threats, experts recommend a shift in defense strategies. Google's Threat Intelligence Group urged enterprises to modernize triage and patch management plans. O'Connor advised companies to conduct rigorous access reviews of top suppliers and implement AI-specific contractual requirements, moving away from calendar-based reviews toward event-driven monitoring.