AI Governance Institute
← News

Google's AI Vulnerability Scanners Target Critical Infrastructure, Raising Authorization and Disclosure Gaps

What happened

Google and Wiz jointly announced the Scan for Good initiative, deploying autonomous AI agents to probe critical infrastructure organizations for security vulnerabilities without charge. The program uses Google's Gemini 3.8 Flash Cyber model alongside Wiz's Red Agent, a tool designed to simulate attacker behavior and surface exploitable weaknesses. Participation is conditioned on either explicit written authorization from the target organization or coverage under an existing bug bounty program that Google and Wiz interpret as sufficient consent. All findings generated by the AI agents are subject to mandatory human review before any disclosure decision is made. CISA endorsed the initiative, lending federal credibility to the program and signaling alignment with Gemini 3.8 Flash Cyber's dual-use governance profile. The launch raises unresolved questions about what constitutes valid authorization for autonomous AI-driven offensive scanning, and how recipient organizations should govern and respond to AI-discovered vulnerability reports.

Why it matters

  • ·Bug bounty program coverage was designed for human researchers, not autonomous AI agents that can scan continuously and at scale. Organizations whose programs are cited as authorization for Scan for Good should review scope language immediately and determine whether they intended to permit AI-driven autonomous probing.
  • ·The program's human-review requirement mirrors the oversight standard in the Five Eyes Guidance on the Careful Adoption of Agentic AI Services, but disclosure timelines, reviewer qualifications, and escalation paths are not publicly defined. Critical infrastructure operators receiving findings will need their own intake and response procedures before a report arrives.
  • ·CISA's endorsement creates a soft-compliance signal that AI-assisted vulnerability scanning by trusted third parties is acceptable practice. Enterprises that have not yet defined vendor intake criteria for autonomous offensive AI tools now face a governance gap if they accept or reject such programs without a documented rationale.

Governance controls affected

What to do now

  • ☐Audit existing bug bounty program language to determine whether scope clauses could be interpreted as authorizing autonomous AI-driven scanning by third parties, and amend terms if that authorization was not intended.
  • ☐Establish a documented intake procedure for receiving AI-discovered vulnerability disclosures, including reviewer qualification requirements, response timelines, and escalation paths to your incident response team.
  • ☐Classify Scan for Good and similar third-party AI scanning programs under your existing vendor due diligence and AI procurement risk assessment process before enrolling or accepting findings.
  • ☐Brief your critical infrastructure security team on the distinction between human-led penetration testing authorization and autonomous agent authorization, and update your acceptable third-party scanning policy accordingly.
  • ☐Determine whether any CISA endorsement of this program creates implicit expectations under your sector's regulatory obligations and document your organization's position in writing.

What to watch next

As the Scan for Good program scales, regulators and sector bodies will face pressure to define what constitutes valid authorization for autonomous AI-driven offensive scanning, particularly in healthcare and municipal settings. Compliance teams should monitor whether CISA issues formal guidance that translates its endorsement into specific authorization and disclosure standards. The unresolved question of bug bounty scope as AI agent consent is likely to surface in contract disputes or regulatory inquiries, making it a priority for legal and procurement teams to address before the program reaches their sector.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.