I recently had the opportunity to sit down with Francis de Souza, COO of Google Cloud, backstage at an event in Los Angeles. Amid the din around us, de Souza, who speaks in the calm, measured manner of a university professor, offered useful advice for companies navigating the AI security moment we’re all living through, noting that “there’ll be a transition period, and then I think we get to this better place.”
He wasn’t speaking about Google at that moment, but it’s clear that even Google is still figuring things out.
De Souza’s core message was one security professionals have been trying to get executives to internalize for years, now made urgent by AI: security can’t be an afterthought. “As companies embark on this AI journey, they need to take a platform approach,” he said. “Security is not something you can bolt on later, and it’s not something you can leave up to employees to do on their own.” He warned specifically about “shadow AI” — employees reaching for consumer tools without organizational oversight — and argued that companies need to demand security, governance, and auditability from their platforms from the start. “There’s no such thing as an AI strategy without a data strategy and a security strategy. They need to go hand in hand.”
Worth noting: he wasn’t pitching Google Cloud alone. When I observed that his advice sounded like a Google advertisement, he pushed back. Google, he said, is committed to a multicloud approach, and he made the case that companies that think they’re operating on a single cloud almost certainly aren’t. “Even if they pick a single cloud, they’re relying on SaaS applications, there are business partners that may be using different clouds,” he said. “It’s important for companies to have a security posture that is consistent across clouds, across models.”
He also made the case that the threat landscape has changed so fundamentally that old defensive models are too slow. He noted that the average time between an initial breach and the handoff to the next stage of an attack has dropped from eight hours to 22 seconds, and that the attack surface has expanded well beyond the traditional network perimeter. “In addition to your usual estate, you have models now. You have data pipelines used to train the models. You have agents, you have prompts. All of this needs to be protected.”
One threat de Souza flagged that doesn’t get enough attention: agents moving through a company’s internal systems can surface forgotten data repositories that nobody has thought about in years. “A lot of organizations have old SharePoint servers [and access controls] they haven’t really updated, but it didn’t matter because nobody really knew where they were. But agents roaming your enterprise will find those data assets and will expose the data on them.”
The answer, in his view, is to meet machine speed with machine speed. “We’re now seeing the emergence of an AI-native, fully agentic defense where organizations can run agents driving their defense,” he said. “Instead of having a human-led defense or even a human in the loop, you can now have humans overseeing a fully agentic defense.” He added that this has become a leadership issue, not just a technology one. “This is a board-level issue and an executive team issue. It’s not just a security team’s issue.”
But even as AI takes on more of the defensive workload, the people qualified to oversee it are in short supply — and the vulnerabilities that AI itself is introducing are multiplying faster than security teams can address them. “We’re going to need people to deal with the bug-pocalypse,” LinkedIn’s chief information security officer Lea Kissner told the New York Times this week, adding that she doesn’t expect the industry to understand AI security in any sustainable long-term way for at least several years.
Which brings us back to the platform providers themselves. The Register has published a series of reports over the past several weeks documenting a wave of Google Cloud developers hit with five-figure bills following unauthorized API calls to Gemini models — services many of them had never used or intentionally enabled. The cases followed a familiar pattern: API keys originally deployed for Google Maps, placed publicly per Google’s own instructions, had quietly become capable of accessing Gemini after Google expanded their scope without clearly disclosing the change.
Rod Danan, CEO of interview-prep platform Prentus, said his bill hit $10,138 in roughly 30 minutes after attackers exploited his compromised API key. Isuru Fonseka, a Sydney-based developer whose account was similarly compromised, woke up to charges of roughly AUD $17,000 despite believing he had a $250 spending cap in place. What neither knew was that Google’s automated systems had upgraded their billing tiers based on account history, raising their effective ceilings to as high as $100,000 without explicit consent.
Google refunded both after The Register published its initial report. Still, Google told The Register it has no plans to change its automatic tier-upgrade policy, saying it prioritizes preventing service outages over enforcing users’ stated budget preferences.
In the meantime, there is the separate question of what happens when a developer tries to shut things down. The Register reported this week on research by security firm Aikido finding that even developers who catch a compromised key and immediately delete it may not be safe. According to Aikido’s findings, attackers can apparently continue using that key for up to 23 minutes because Google’s revocation propagates gradually across its infrastructure. Aikido researcher Joseph Leon told The Register that during that window, success rates are unpredictable — in some minutes over 90% of requests still authenticated — and attackers can use the time to exfiltrate files and cached conversation data from Gemini.
Leon also noted that Google’s own newer credential formats don’t appear to have the same problem: service account API credentials revoke in about five seconds, and Gemini’s newer AQ-prefixed key format takes about a minute. “Both run at Google scale,” he wrote in Aikido’s related paper. “Both suggest this is technically solvable for Google API keys, too.” In short, according to Leon, the 23-minute window isn’t an engineering constraint but a matter of priorities for the company.
That’s worth considering when reading de Souza’s advice, which is sound and should be taken very seriously. He’s not wrong, but there is currently a gap between the platforms are prescribing and how fast they are themselves adapating, and it’s good to be aware of this, too.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
The Federal High Court sitting in Abuja has dismissed a suit filed by Engr. Yakubu Muhammad Kingsley (YMK) against the Peoples Redemption Party (PRP), its presidential candidate, Donald Duke, and the Independent National Electoral Commission (INEC).
This was disclosed in a statement signed by Abdulhakeem Ago Abdullahi, Assistant National Legal Adviser of the PRP.
The court, in its judgment delivered on Wednesday, September 30, 2026, upheld the preliminary objection filed by the PRP and Duke, ruling that Kingsley commenced the suit outside the time prescribed by the Constitution.
The court also considered the substantive issues raised by the plaintiff and resolved them in favour of the respondents.
Recommended
On Duke’s alleged membership of the PRP, the court held that membership of a political party was an internal party matter and therefore outside the court’s jurisdiction.
The court also found that Kingsley failed to place before it the party guidelines which he alleged had been breached during the party’s screening exercise.
On the allegation of over-voting in the PRP primary election in Bauchi, Gombe and Kwara states, the court held that the plaintiff failed to provide the party’s membership register, accreditation records and final primary election results to substantiate the claim.
Consequently, the court dismissed the suit and resolved all the issues in favour of the PRP, Duke and INEC.
Covenant University, the University of Ibadan (UI) and the University of Lagos (UNILAG) have emerged as the highest-ranked Nigerian universities in the 2027 Times Higher Education (THE) World University Rankings.
The three institutions were placed in the 801–1,000 bracket globally in the latest ranking, putting them in the same position band among the Nigerian universities assessed by THE.
The 2027 Times Higher Education World University Rankings cover 2,297 universities across 118 countries and territories.
The ranking assesses universities using indicators covering teaching, research environment, research quality, industry and international outlook.
Covenant University, UI and UNILAG all recorded overall scores within the 36.4–40.1 range.
Covenant University recorded 21.4 for teaching, 32.5 for research environment, 49.8 for research quality, 61.0 for industry and 48.6 for international outlook.
The University of Ibadan recorded 31.2 for teaching, 19.9 for research environment, 64.9 for research quality, 22.2 for industry and 44.9 for international outlook.
UNILAG recorded 21.2 for teaching, 20.8 for research environment, 67.8 for research quality, 31.3 for industry and 45.6 for international outlook.
The three universities were followed by Ahmadu Bello University, Bayero University, Landmark University and the University of Ilorin, which were all placed in the 1,001–1,200 global bracket.
Babcock University, Osun State University and the University of Nigeria, Nsukka were placed in the 1,201–1,400 bracket.
Six Nigerian universities featured in the 1,401–1,600 category. They are the Federal University of Technology, Minna; Nnamdi Azikiwe University; Obafemi Awolowo University; University of Benin; University of Jos; and University of Maiduguri.
The Federal University of Technology, Akure was placed in the 1,601–1,800 bracket, while the Federal University of Technology, Owerri, Ladoke Akintola University of Technology, Lagos State University, Olabisi Onabanjo University and the University of Calabar were ranked in the 1,801–2,000 category.
Delta State University, Abraka, Ekiti State University and the Federal University of Agriculture, Abeokuta were placed in the 2,001+ category.
The full list of Nigerian universities featured in the 2027 Times Higher Education World University Rankings:
Covenant University — 801–1,000
University of Ibadan — 801–1,000
University of Lagos — 801–1,000
Ahmadu Bello University — 1,001–1,200
Bayero University — 1,001–1,200
Landmark University — 1,001–1,200
University of Ilorin — 1,001–1,200
Babcock University — 1,201–1,400
Osun State University — 1,201–1,400
University of Nigeria, Nsukka — 1,201–1,400
Federal University of Technology, Minna — 1,401–1,600
Nnamdi Azikiwe University — 1,401–1,600
Obafemi Awolowo University — 1,401–1,600
University of Benin — 1,401–1,600
University of Jos — 1,401–1,600
University of Maiduguri — 1,401–1,600
Federal University of Technology, Akure — 1,601–1,800
Federal University of Technology, Owerri — 1,801–2,000
Ladoke Akintola University of Technology — 1,801–2,000
Lagos State University — 1,801–2,000
Olabisi Onabanjo University — 1,801–2,000
University of Calabar — 1,801–2,000
Delta State University, Abraka — 2,001+
Ekiti State University — 2,001+
Federal University of Agriculture, Abeokuta — 2,001+
Globally, the University of Oxford retained the number one position in the 2027 edition, extending its run at the top to an 11th consecutive year.
China’s Tsinghua University climbed to 11th position, moving ahead of Switzerland’s ETH Zurich, while the National University of Singapore entered the global top 15.
File: Nigerian Students
The 2027 edition also recorded a notable regional development, with Asia ranking ahead of continental Europe in the overall regional comparison for the first time. Three Asian universities featured among the global top 15.
NECO said 1,378,048 candidates registered for the examination, comprising 682,352 males and 695,696 females. A total of 1,371,992 candidates eventually sat for the examination.
The council said 1,162,118 candidates, representing 84.70 per cent of those who sat for the examination, obtained at least five credits irrespective of their performance in English Language and Mathematics.
When English Language and Mathematics were included among the required five credits, the figure fell to 804,948 candidates, representing 58.67 per cent.
NECO Registrar and Chief Executive, Prof. Dantani Wushishi, announced the results at a press conference in Minna, Niger State, saying the results were released 63 days after the examination ended.
The examination was conducted between June 15 and September 4, 2026, across Nigeria and in six countries outside the country.
Wushishi also disclosed that 1,406 candidates were involved in examination malpractice, representing a 64.74 per cent reduction from the 3,878 cases recorded in 2025.