Artificial intelligence (AI) leading players Microsoft, OpenAI and Google this week offered a glimpse into their security initiatives and commitments.

Last year, all three companies voluntarily pledged to take steps to ensure safety, security and transparency in AI development.

The latest commitments from Microsoft, OpenAI and Google all emphasize the importance of AI being secure by design, the investment in infrastructure and the development of tools and training to empower defenders.

Microsoft’s latest AI security principles

Microsoft introduced its Secure Future initiative last November, committing to continue building secure foundations necessary for the AI era and beyond. The initiative emphasized the tech giant’s goal to deliver software that is secure by design, by default, in deployment, and in operation. It also commits to enabling customers with more secure defaults, providing a unified and consistent way of managing and verifying identities and access rights, and pushing the envelope in vulnerability response and security updates for its cloud platforms.

This week, Microsoft announced its principles guiding the vendor’s policy and actions mitigating the risks associated with the use of its AI tools and APIs. These principles include the following:

  • Identification and action against malicious threat actors’ use: Microsoft will take appropriate action to disrupt the activities upon detection of the use of any Microsoft AI services or systems by malicious threat actors.
  • Notification to other AI service providers and share relevant data when Microsoft detects a threat actor’s use of another service provider’s AI services or systems.
  • Collaboration with other stakeholders to regularly exchange information.
  • Transparency: Microsoft will inform the public and stakeholders about actions taken under these threat actor principles.

The principles are built on Microsoft’s Responsible AI practices and the Azure OpenAI Code of Conduct.

Google’s new AI cyber defense initiative

Google introduced its Secure AI Framework last June, which is a conceptual framework for secure AI systems. The framework includes six core elements: expanding strong security foundations to the AI ecosystem, extending detection and response to bring AI into an organization’s threat universe, automating defenses to keep pace with existing and new threats, harmonizing platform-level controls to ensure consistent security across the organization, and adapting controls to adjust mitigations and create faster feedback loops for AI deployment Contextualize AI system risks in surrounding business processes.

The tech powerhouse announced today the launch of a new AI cyber defense initiative, highlighting its new commitments to invest in AI-ready infrastructure, release new tools for defenders, and launch new research and AI security training.

In the initiative, Google noted that AI security technologies need to be secure by design and by default. It also plans to continue investing in its AI-ready network of global data centers, expand its “AI for Cybersecurity” cohort for startups and $15 million Cybersecurity Seminars program, and advance research that helps generate breakthroughs in AI-powered security, while open-sourcing Magika, which is a new, AI-powered tool to aid defenders through file type identification for malware detection.

OpenAI’s multi-pronged approach to AI safety

OpenAI said that despite the limited capabilities of current models for malicious cybersecurity activity, the AI vendor is taking a multi-pronged approach to combat the threat, which includes the following:

  • Invest in technology and teams to identify, monitor and disrupt sophisticated threat actors’ activities.
  • Collaborate with industry partners and other stakeholders to regularly exchange information about malicious use of AI.
  • Take lessons learned from the real-world abuse, use and misuse of AI by threat actors.
  • Share with the industry and the public about these lessons and the potential misuse of AI.
How Microsoft and Google use AI to protect themselves and others

Microsoft shared the methods it used to protect the company itself from AI-related cyberthreats using AI.

Vasu Jakkal, corporate VP of security, compliance, identity and management at Microsoft, noted in a blog post that, these methods include AI-powered threat detection to detect changes in how resources or traffic are being used on the network; behavioral analytics to detect risky logins and anomalous behavior; machine learning (ML) models to spot risky logins and malware; zero trust principle, where every access request must be fully authenticated, authorized, and encrypted; and device health, which must be verified before a device can connect to the corporate network.

Microsoft and OpenAI also work with MITRE to integrate LLM-themed tactics, techniques, and procedures (TTPs) into the MITRE ATT&CK framework or MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems) knowledgebase.

“This strategic expansion reflects a commitment to not only track and neutralize threats but also to pioneer the development of countermeasures in the evolving landscape of AI-powered cyber operations,” Jakkal wrote.

Google detailed how it integrates AI into its products to enhance security.

  • Its Gmail service uses a multilingual neuro-based text processing model called RETVec to improve spam detection and reduce false positive alerts.
  • Its malware analysis tool VirusTotal leverages AI to review potentially malicious files.
  • Its open-source security team uses Google Gemini to improve code coverage of open-source projects.
  • Its detection and response team applies generative AI to generate incident summaries.
  • The Mandiant team is utilizing generative AI to help identify threats faster, eliminate toil, and better scale talent and expertise.