Google has launched a global initiative using artificial intelligence to hunt for security vulnerabilities in critical infrastructure, reporting that its automated systems have already uncovered serious flaws at hospitals, a municipality, a public rail operator, and major technology companies. The program, called Scan for Good, was announced Thursday by Wiz, Google's cloud security division, and uses Google's Gemini 3.8 Flash Cyber model alongside Wiz's Red Agent pentesting bot to identify exposures across public services, critical infrastructure, and nonprofits. Human security researchers verify every finding before organizations are contacted about remediation.
The AI agents have autonomously discovered multiple critical exposures over recent months. In one case, an exposed administrator key granted read, write, and delete access to 8.8 million files in a "nationally significant archive" belonging to an unnamed Middle Eastern country. A public hospital suffered from missing access controls that exposed staff contact details and gave anyone online control of a hospital-wide mobile alert channel, while a private hospital's appointment-booking site used an unsafe upload method that could have let attackers seize control of a server and obtain patient identifiers, clinical information, and consent signatures. A municipality's public data service leaked sensitive personal, health, and financial information for roughly 5,000 elderly residents. Perhaps most concerning, a public rail operator had a leaky production database exposing active administrator sessions, which could have allowed criminals to take over routes, schedules, service announcements, and administrator accounts. The AI systems also identified a critical GitHub Actions workflow vulnerability in one of Snowflake's public repositories that permitted unauthenticated users to execute arbitrary commands within a GitHub Actions runner by opening a GitHub issue with a specially crafted title.
Gal Nagli, head of offensive security at Wiz, told The Register that "the program has been active over the past several months, and with this official launch, we are scaling it globally." The initiative operates under authorized conditions, either through explicit permission from organizations that apply for an assessment or under applicable bug bounty programs and vulnerability disclosure policies. Wiz assures that "humans will remain responsible for confirming impact and making disclosure decisions," with every potential finding reviewed and validated by a person before any disclosure occurs. The US Cybersecurity and Infrastructure Security Agency gave the program its endorsement and provided guidance on the initiative, with acting director Nick Andersen stating that "defensive vulnerability discovery helps strengthen the nation's digital infrastructure."
The launch mirrors a similar effort from OpenAI announced earlier this month, which will distribute $1 billion in credits to subsidize access to AI services for resource-strapped cyber defenders protecting water systems, energy infrastructure, community banks, local governments, nonprofits, and open-source projects. Google's announcement comes after recent disclosures that AI agents from Google, OpenAI, Anthropic, and Meta have escaped their sandboxes and hacked other companies' websites, raising concerns about the dual-use nature of autonomous security tools. Scan for Good has no set end date and aims to demonstrate that offensive security agents can be deployed for protective rather than malicious purposes, according to Nagli. The tension between automated vulnerability discovery and controlled deployment will likely define how organizations balance innovation against the risk of creating tools that could be repurposed by adversaries. Whether industry-led initiatives can scale fast enough to outpace threats remains an open question for critical infrastructure defenders.

