Back
#275
May 4, 2026

EP275 Google Cloud Next 2026: The AI Earthquake, “SOC-home” Syndrome, and the Ragged Edge of Reality

Guest:

no guests

Topics:

RSA and Next Conferences
29:29

Subscribe at YouTube

Subscribe at Spotify

Subscribe at Apple Podcasts

Topics covered:

  • So what have we seen at Google Cloud Next 2026?
  • Any closing loops for our 2023-2025 Cloud Next observations?
  • We are seeing that AI security is not an island ... what does that tell us about the difference between cloud and AI adoption?
  • What does  “ragged edge of AI adoption” mean for security?
  • Why do people want agents in their SOC? Do they know what gets better?
  • What are the most notable and fun announcements?
  • With patching speed, are we looking at something which can be overcome by engineering and courage? Or are we looking at something that is truly an impossibility?

Do you have something cool to share? Some questions? Let us know:

Transcript

This note summarizes the annual Next wrap-up episode of the Cloud Security Podcast by Google, recorded live at Cloud Next 2026. The discussion centers on the evolution of cloud security from an isolated discipline to an integrated standard, contrasted sharply with the current "earthquake" of AI integration.

The hosts analyze the shift from AI discovery (2023) to widespread AI reality (2026), specifically focusing on the emergence of Agentic Security Operations Centers (SOC). Key insights include the distinction between AI as a productivity multiplier for existing human tasks versus a provider of "net-new" capabilities, such as near-instant, low-cost malware decompilation.

The conversation also addresses the "ragged edge of adoption," where some organizations are hyper-scaling with AI while others struggle with basic governance or cultural resistance (termed "SOC-holm Syndrome"). Finally, the dialogue explores the physical and architectural limits of cybersecurity—specifically the "sound barrier" of patching—and the necessity of re-architecting legacy systems rather than simply increasing detection efforts.

Detailed Discussion & Meeting Notes

1. The Evolution of the "Island" Metaphor

The hosts revisited a long-standing metaphor in their recap history: the Cloud Security Island.

Historical Context: Cloud security began as an isolated island, separate from traditional IT security, spawning unique tools for posture management (CSPM) and vulnerability scanning.

Integration: Over the past four years, this island has merged into the "mainland" of general security, becoming a peninsula and now a fully integrated landmass.

The AI Contrast: Unlike the slow migration of cloud security, AI has emerged as a global phenomenon. It is described as an earthquake affecting all security domains simultaneously—from "AI-native" firewalls and email security to malware analysis and MDR.

2. The Current State of AI: From Hype to Reality

The hosts categorized the last three years of AI development:

2024: The "Island" phase (isolated experiments).

2025: The rise of AI (explosive growth and interest).

2026: The Reality of AI (implementation at scale).

A significant trend noted is the diffusion of responsibility. Companies are generally not hiring "AI Security Teams" in isolation; instead, AI security responsibilities are being integrated into AppSec and SOC teams.

3. The "Ragged Edge" and Cultural Resistance

Despite the high-level hype, the "ragged edge of adoption" remains a challenge.

Governance Gaps: Many smaller companies face CEO mandates to use AI everywhere but possess zero governance, often pursuing use cases that may be legally questionable.

The Necessity of a Champion: Referencing insights from security leaders like Ali (Google Cloud), Anton emphasized that without a senior champion who understands AI, adoption projects are doomed to fail.

"SOC-holm Syndrome": Tim identified a surprising pocket of resistance where SOC analysts actively fight to maintain manual triage processes, effectively becoming "hostage" to their old, inefficient workflows.

4. Categorizing Agentic Capabilities

The hosts broke down agentic SOC adoption into two distinct categories:

Category 1 (Faster/Scale): Automating what humans already do. For example, the Triage Investigation Agent (now GA) allows analysts to process alerts at a speed and scale impossible for humans.

Category 2 (Net-New Capability): Capabilities previously inaccessible to most firms. A prime example is Gemini-powered malware analysis. Previously, decompiling a binary required a specialized contractor costing $30,000 and taking a week. Gemini now provides these verdicts, C2 channel identification, and IOCs in 30 seconds for a negligible cost.

5. The "Sound Barrier" of Patching

A critical segment focused on the limits of security engineering.

The Patching Problem: In a session with the Security Operations Advisory Board (CAB), zero hands were raised when asked if AI-powered vulnerability discovery would lead to faster patching.

The Metaphor: Anton compared enterprise patching to the speed of sound for a propeller plane. You can "push the throttle to the wall," but the physics of legacy databases and fragile 24/7 systems (like petroleum distillation towers) make "immediate patching" a physical impossibility.

The Solution: Engineering and courage. For systems that cannot be patched, the only answer is re-architecture. This involves "tossing the system out the window" and replacing it with modern, auto-patchable stacks or "vibe-coding" replacements for legacy GRC tools.

6. Security as a Business Discipline (The "CISO-CFO")

The hosts highlighted an interview with a CISO from a thin-margin wholesale grocer.

ROI Focus: Unlike "unlimited budget" environments that suffer from "shelfware," leaders in thin-margin industries have a "nose" for value. They focus on Minimum Viable Business—knowing exactly which processes must roll (e.g., getting the trucks out so the tomatoes don't rot) before anything else.

Resilience: This operational maturity includes manual backups (e.g., paper notepads) for when AI or digital systems fail.

Podcast Timeline

Introduction and Historical Context

Opening remarks from Cloud Next 2026.

Reflection on the 4-year history of Next recaps.

Evolution of the Cloud Security "Island" to the Mainland.

The AI Earthquake

Comparison of cloud adoption vs. the rapid, global impact of AI.

The emergence of AI-native security tools (Firewalls, Email, MDR).

The shift from AI as a "specialty" to a "diffuse responsibility" across AppSec.

Adoption Realities and Governance

Defining the "Ragged Edge": The gap between high-scale users and those with zero governance.

The critical role of the "AI Champion" in the SOC.

Discussion on "SOC-holm Syndrome" and cultural resistance to automation.

Agentic SOC and Product Announcements

Category 1 vs. Category 2 AI capabilities.

The $30,000 malware analysis problem solved in 30 seconds.

GA announcements: Triage Investigation Agent, Gemini Enterprise, and Model Armor.

Future-looking: The Threat Hunt Agent.

The Physics of Vulnerability Management

The "V-Apocalypse" (Vulnerability Apocalypse).

The "Sound Barrier" metaphor for patching legacy systems.

Re-architecture vs. Detection and Response (DNR).

Economic Realities of Security

The "CISO as CFO" mindset.

Security in thin-margin industries vs. high-margin banks.

Defining the "Minimum Viable Business" and operational resilience.

Closing Thoughts

The future is here, but not evenly distributed.

Final tip: Don't feel like a laggard just because of the AI hype cycle.

Outro and subscription information.

View more episodes