Cybersecurity & Protection

Google Security Chief: AI Uncovers More Zero-Days Than Ever Before

Aug 11, 2026 3 min read
All articles

Many people see artificial intelligence as a threat to IT security. Sandra Joyce, head of the Google Threat Intelligence Group (GTIG), takes a more nuanced view. Attackers do use AI to scale up their operations, but the same tools also help the defense. Her takeaway: more zero-day vulnerabilities are being found than ever before.

AI helps both sides

GTIG is Google's internal security team and was formed after the acquisition of the security firm Mandiant. It's part of Google Cloud and became known for uncovering major attacks, including ones targeting the iPhone, as well as for its analyses of exploit kits, malware, and government spyware. Lately, AI-assisted malware has increasingly come into focus, along with using AI to analyze software for vulnerabilities.

Joyce is convinced that AI does more good than harm in cybersecurity. Just as criminals and intelligence services expand their capabilities with AI, so can the experts who secure systems. "There's plenty of evidence that more zero-days are being found than ever before," she says. Hunting for unknown vulnerabilities is precisely the kind of work where automated analysis plays to its strengths.

From language model to hacking tool

Joyce's team has been tracking the use of AI by threat actors for around eight years. For a long time, that mostly meant social engineering, since AI is particularly good at producing convincing content like fake images. Later, the models could give usable technical answers to hacking questions, and attackers tried to get Google's AI Gemini to provide exactly that. Even then it was clear that an agentic system equipped with such knowledge could become a serious autonomous threat. According to Joyce, that's the era we've now entered.

Perspective instead of panic

For all the momentum, Joyce advises a level-headed view. Cyber incidents can be severe for those affected, but it's important to keep things in proportion. If you're not a security officer and aren't specifically targeted by serious actors, there's no reason to panic. Cybersecurity has never been easy and constantly changes because technology and adversaries keep adapting. The best approach, she says, is to cut through the hype to see what the threats actually look like and manage the risks accordingly.