Google Cloud and Wiz debut new AI security agents at Next '26, including Threat Hunting and Detection Engineering agents, to combat automated zero-day exploits
Frederic Lardinois /The New Stack:
Context & Ripple Effects
Google Cloud’s security product arc in the supplied coverage runs from Chronicle’s detection and alerting expansion, through the Security AI Workbench, to Unified Security’s consolidation of operations, cloud security, intelligence, browsing, and Mandiant expertise. The Wiz collaboration extends that stack with task-specific agents for threat hunting and detection engineering.
The timing matters because related coverage identifies AI-assisted discovery and weaponization of a zero-day as an emerging attacker capability. The story therefore centers on automating defensive analysis and engineering as the offensive side becomes more automated.
First-order effects
- Google Cloud and Wiz add dedicated AI agents for threat-hunting and detection-engineering workflows, giving their security users new automation within those functions.
- The launch positions the Google Cloud-Wiz offering directly around automated zero-day exploitation, making AI-enabled detection and response a more explicit part of the joint security proposition.
Second-order effects
- Security teams using Google Cloud’s broader unified stack can increasingly evaluate detection engineering and hunting as integrated workflows rather than separate point-tool tasks.
- Rival cloud-security and security-operations vendors face pressure to pair platform consolidation with credible agent-based workflows, particularly where customers want faster coverage for novel threats.
Third-order effects
- If AI-assisted exploitation becomes more common, defensive advantage will depend less on standalone alerts and more on how quickly platforms can turn threat intelligence into usable detections and investigations.
- The broader market may shift toward security platforms that embed specialized agents across operations, cloud security, and intelligence; the practical constraint will be whether those agents improve analyst decisions rather than merely add automated output.
The trend: This is part of the shift from AI-assisted security analytics toward embedded, role-specific agents that automate pieces of the detection-and-response lifecycle as AI raises both offensive and defensive tempo.