AI and Cybersecurity

Sandra Joyce (VP, Google Threat Intelligence · Google Cloud), Mohamed Al Kuwaiti (Head of Cyber Security · United Arab Emirates Government)

RSA Conference 2025 · Day 2 · West Stage · Keynote

Overview

Sandra Joyce, VP of Google Threat Intelligence, used RSA 2025 to cut through AI hype with evidence drawn from real-world incident response: attackers are using models like Gemini as productivity tools, not to invent new attack vectors. On defense, AI is already delivering measurable gains in the security operations center — and the keynote argues that CISOs should lean in now rather than wait for the technology to mature further. ---

Watch on YouTube

Visual summary for AI and Cybersecurity by Sandra Joyce, Mohamed Al Kuwaiti
Visual summary for AI and Cybersecurity by Sandra Joyce, Mohamed Al Kuwaiti

Key moments

  1. 2:26 Threat actors from 20+ countries used Gemini; Iran led
  2. 3:14 No fundamentally new AI attack vectors observed in wild
  3. 4:49 Iranian APT researched Israeli missile defense via Gemini
  4. 5:18 North Korean APT researched South Korean nuclear plants via Gemini
  5. 5:45 APT42 used Gemini to write C++ sandbox evasion code
  6. 8:10 Google AI found first LLM-discovered real-world SQLite vulnerability
  7. 9:48 AI fuzzing doubled coverage from 30% to 60%
  8. 11:25 Gemini writes incident summaries 51% faster with improved quality

AI and Cybersecurity: What the Data Actually Shows

Speakers: Sandra Joyce (Google Cloud) · Mohamed Al Kuwaiti (United Arab Emirates Government)

Event: RSA Conference 2025 — April 28–May 1, 2025, Moscone Center, San Francisco

Watch: YouTube

Reading time: ~7 minutes

TL;DR

Sandra Joyce, VP of Google Threat Intelligence, used RSA 2025 to cut through AI hype with evidence drawn from real-world incident response: attackers are using models like Gemini as productivity tools, not to invent new attack vectors. On defense, AI is already delivering measurable gains in the security operations center — and the keynote argues that CISOs should lean in now rather than wait for the technology to mature further.

Introduction

For several years, the cybersecurity industry's conversation about artificial intelligence has been caught between breathless optimism and alarming speculation, often with very little data underpinning either side. At RSA Conference 2025, Sandra Joyce took the West Stage to challenge that dynamic directly. As Vice President of Google Threat Intelligence at Google Cloud, she oversees teams that track adversaries around the world — and she came armed with findings, not forecasts.

"When we look at the current state of affairs," Joyce told the Moscone Center crowd, "I see three consistent patterns: speculation on potential, experimentation, and the anecdotal." Her prescription: a better evidence base, organized around two questions. What are attackers actually doing with AI, and what measurable value is AI delivering for defenders today?

The session, co-featuring His Excellency Dr. Mohamed Al Kuwaiti, Head of Cybersecurity for the UAE, offered one of the conference's most grounded assessments of AI's real-world role in security — drawing on threat intelligence data, live product metrics, and a national-scale perspective on what governments can accomplish when they apply these tools systematically.

What Adversaries Are Actually Doing With AI

Google's Threat Intelligence Group tracks threat actors across the globe and, as part of that mandate, began monitoring how those actors were interacting with its own public AI service — Gemini. The findings carry a counterintuitive headline: the apocalyptic scenario of AI enabling entirely new categories of attack has not materialized.

▶ Watch: How APT groups use Gemini (2:00)

Analysts identified advanced persistent threat (APT) groups from more than twenty countries using Gemini. Iranian actors were the heaviest users, with notable activity from Chinese and North Korean-affiliated groups as well. But rather than developing novel exploitation techniques, these groups used the model the way a knowledge worker might: for brainstorming, drafting, summarizing, and basic coding assistance.

"Much of the current conversation around AI threats can sometimes feel overly alarmist," Joyce said. "Our analysis shows that while AI is a useful tool for common tasks, we haven't yet seen indications of adversaries developing any fundamentally new attack vectors with these models."

The specific use cases observed followed familiar attack phases. Iranian APT actors used Gemini to research defense systems, including unmanned aerial vehicles, F-35 jamming technology, and Israel's missile defense infrastructure. North Korean actors queried the model about South Korean nuclear power plant locations and security posture. One North Korean APT actor used Gemini to write C++ code for detecting virtual machine environments — a sandbox evasion technique — while Iran-based APT42 used the model to craft tailored phishing lures in colloquial English and to localize content for specific audiences.

▶ Watch: APT use cases — reconnaissance and malware (4:00)

Critically, Gemini's safety mechanisms functioned as intended. The model provided assistance on neutral tasks — content creation, summarization, generic coding — but generated refusals when prompted with explicitly malicious requests. "We also have good news," Joyce noted. "Gemini's safety measures continue to restrict adversarial operational capabilities."

AI's Measurable Impact on Defense

If the threat-side findings were sobering in their ordinariness, the defense-side findings were more immediately actionable. Joyce outlined three categories where she said CISOs should focus AI investment now: vulnerability detection, SOC efficiency, and malware analysis.

▶ Watch: Big Sleep and AI-driven vulnerability discovery (8:00)

On vulnerability discovery, Joyce highlighted Google's Project Big Sleep — a large-language-model-assisted effort that, in October 2024, uncovered an exploitable stack buffer underflow in SQLite, a database engine used in billions of devices. She described it as "the first public example of an AI agent finding a previously unknown exploitable memory safety issue in widely used real-world software." The same approach is being applied to fuzz testing at scale: using LLMs to generate fuzzing harnesses across 272 C and C++ projects in OSS-Fuzz, Google has seen code coverage increases of up to 7,000 percent in some cases, with AI roughly doubling average fuzzing coverage from 30 to 60 percent.

In the security operations center, the gains are similarly concrete. Google's internal teams used Gemini to produce incident summaries 51 percent faster than human analysts — and, in blind evaluations, security teams rated the LLM-written summaries 10 percent higher in quality than the human-written equivalents. A tool built for the Google Threat Intelligence Group can now review thousands of event logs from an investigation and produce a digestible summary in seconds; previously, the same task took hours.

▶ Watch: SOC efficiency — summaries, queries, and malware analysis (10:00)

Analysts using Gemini to write detection rules told Joyce's team that tasks previously requiring 30 to 60 minutes could be completed in seconds. On the malware analysis front, a file that no standard detection system on VirusTotal could identify was analyzed and classified as malicious by Gemini in 27 seconds — a capability that matters acutely given how few security professionals possess advanced reverse-engineering skills.

From Assisted to Semi-Autonomous: The Agentic SOC

Beyond point-in-time efficiency gains, Joyce argued that the more significant shift ahead is structural: security operations moving from human-led, AI-assisted workflows to what she described as "semi-autonomous AI" with a human in the loop.

▶ Watch: Agentic AI in security workflows (10:00)

In this model, AI agents proactively identify work and execute tasks — enriching evidence, generating investigation plans, completing steps toward defined goals — while human analysts handle novel or complex cases that genuinely require expert judgment. "Agentic AI doesn't just assist our actions," Joyce said. "It can proactively identify work and execute tasks like evidence enrichment. It can generate plans and even complete steps towards a defined goal."

The framing positions AI not as a replacement for security talent but as a multiplier: freeing practitioners from routine triage so they can focus on the investigations where human reasoning has a decisive advantage. It also carries an implicit challenge to the industry: evaluate AI agents using the same performance metrics applied to human team members, not just vendor claims.

The National Dimension: UAE's AI Security Strategy

The second half of the keynote brought Dr. Mohamed Al Kuwaiti to the stage to share how the UAE is applying these principles at a national level. His framing situated cybersecurity within a broader national ambition to become "the happiest, the safest, and the most dynamic economy by 2031."

▶ Watch: UAE national AI security strategy (14:01)

The UAE has deployed AI across three current security pillars: AI-driven compliance monitoring through its National Information Assurance Platform, implementation of smart security solutions, and frameworks for data privacy and confidentiality. Looking ahead, Al Kuwaiti outlined plans to establish a Cybersecurity Center of Excellence, advance threat visibility through an initiative called Cyberpulse, and host a Quantum Innovation Summit by 2025. The partnership with Google, he noted, is a key element of the country's AI-driven security roadmap.

The juxtaposition was deliberate: national AI security strategy is no longer the exclusive domain of the largest military or intelligence establishments. Smaller nations with clear strategic intent and access to cloud-native AI platforms are moving quickly to build sovereign security capabilities at scale.

Notable Quotes

"Much of the current conversation around AI threats can sometimes feel overly alarmist. Our analysis shows that while AI is a useful tool for common tasks, we haven't yet seen indications of adversaries developing any fundamentally new attack vectors with these models."

— Sandra Joyce

"As we swim in this sea of hype, I encourage you: don't just believe all of the AI claims being made in our industry. Go and actually test them against robust metrics."

— Sandra Joyce

"Our journey has been guided by a well-structured roadmap rooted in forward-thinking leadership. For us, it's about those we serve."

— Dr. Mohamed Al Kuwaiti

Key Takeaways

  1. Attackers are using AI as a productivity tool, not a superweapon. Nation-state APT groups from more than twenty countries accessed Gemini, primarily for reconnaissance, content generation, and basic coding — not to develop novel attack vectors.
  1. Safety guardrails are working, for now. Gemini's built-in restrictions blocked explicitly malicious requests while allowing neutral task assistance. This may not hold as models proliferate; monitoring the threat landscape remains essential.
  1. AI is already delivering in the SOC. Incident summaries produced 51% faster, malware classified in 27 seconds, and detection-rule generation reduced from hours to seconds — these are results today, not projections.
  1. The shift from assisted to agentic workflows is the defining near-term transition. Security teams should begin designing for semi-autonomous AI rather than treating current AI-assisted tools as the end state.
  1. Measure AI against real metrics. Joyce's call to evaluate AI systems with the same performance standards applied to human analysts is a practical and necessary corrective to vendor-driven hype cycles.
  1. National-scale AI security strategy is within reach. The UAE's example demonstrates that mid-size nations can build sophisticated, AI-driven security programs when they combine clear strategy with the right platform partnerships.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Sandra Joyce brings actual threat intelligence data to an RSA stage that desperately needed it — APT groups from 20+ countries using Gemini as a productivity tool, not a superweapon, with real numbers on defensive gains in the SOC. This is one of the few keynotes in this batch that prioritizes evidence over narrative, and the Big Sleep vulnerability discovery is a genuine milestone worth knowing about. The UAE segment is thin, but it does not sink the session.

Heather Calloway (CISO) — MUST SEE

Sandra Joyce of Google Threat Intelligence presents empirical data on how nation-state actors from 20+ countries are actually using AI — for productivity, not for novel capabilities. Simultaneously, AI defenses show 51% faster incident summaries, 27-second malware classification, and 7000%+ fuzzing coverage increases in specific cases.

→ Top-rated talks at RSA Conference 2025

All talks from RSA Conference 2025