Without cloud, there is no AI, says Google Cloud execs
Google Cloud’s Steve Hager, Director, Office of the CISO and Daryl Pereira, Head of Office of the CISO, Google Cloud Asia Pacific, discuss the trends in the industry as well as the importance of the cloud in the AI journey.
At the recent STACK-X Cybersecurity 2026 event organized by GovTech in Singapore, participating cybersecurity vendors shared how businesses can secure AI in their tech journey as well as the importance of strengthening their cyber leadership.
In his keynote address, Singapore Senior Minister of State for Digital Development and Information, Tan Kiat How shared that the Singapore government is moving beyond the traditional regulator-regulatee relationship with Critical Information Infrastructure (CII) owners and forging closer partnerships with organizations to combat cyber threats together.
He also highlighted the need to integrate AI into cybersecurity functions, especially with the AI space evolving rapidly and the need for organizations to develop cybersecurity talent and leadership.
CRN Asia caught up with Google Cloud’s Steve Hager, Director, Office of the CISO and Daryl Pereira, Head of Office of the CISO, Google Cloud Asia Pacific, to get their views on the trends they are seeing in the industry as well as the relevance of the cloud as companies embark on their AI journey.
Both Hager and Pereira were speakers at the STACK-X Cybersecurity 2026 conference.
According to Pereira, one of the biggest concerns now is how AI is being used to review code, which is becoming a double-edge sword. However, what is really concerning for organizations in the region today is dealing with standard hygiene issues.
“A good example is many of them (organizations in both public and private sector) are still running on-prem, but they don't have enough security engineers to secure that premises on-prem. But they don't want to move on to the cloud because they see cloud as inherently more dangerous, which is ironic,” Pereira said.
Why this is ironic is because regulators in the region who were initially concerned about the cloud are now pushing for businesses to utilize the cloud as its safer compared to being on premises.
“The maturity factor is important. And when you think about cloud regulations in the region, the main countries that are uptaking it, the regulators have been very positive in accruing the benefits of being cloud-savvy, which then connects to the AI conversation. Because if you think about it, the key here is how is AI delivered? How is it able to merge different data sets and then use a model interrogated to infer and come up with new information or content through cloud? So, without cloud, there is no AI,” he explained.
This is why Pereira believes that businesses are understanding the need to be in the cloud in order to empower AI, which is clearly accelerating the uptake of cloud.
“So, what we've seen recently is regulations are now coming out around AI and cloud at the same time, or revision of the cloud regulation if there already was one in order to release a new regulation on AI that wasn't there before,” he added.
Data sovereignty and the cloud
With data sovereignty still a concern for most organizations and most countries, most organizations want to know where exactly their data is going, especially when it's on the cloud.
“From Google's perspective, we're collaborating with all organizations on cloud and governance models. But ultimately, if you look at how we've built the cloud and how we're doing AI, we have data centers in all the key hubs, and we can use those data centers to have a localized version of the AI engine, which then relieves the concern around data being exported out of country, even for the AI-delivered type situations,” he said.
For countries where Google does not have a data center, Pereira mentioned that customers can download a version of the AI model that they're going to use, and this becomes an on-prem model.
“We disconnect that from the hive mind, so it becomes a localized on-prem version of that, and then you can connect it with your own internal data. So, it's a disconnected, air-gapped version of the AI. It's not as powerful because the last version you downloaded is the one that you have with the hive mind with the global. So eventually you may have to do a reconnect and refresh, but you keep your data on-site. So that's another model that we've come up with recently, which is Google Distributed Cloud,” Pereira explained.
For Hager, when it comes to data sovereignty, each country is different. While Google data centers are not available in every country, Hager feels that taking the approach that Google has done in EU would be the way forward.
“When it comes to data sovereignty, the data will stay within that region that they want, and there's something that we call access transparency. So, if a Googler needs to look at that data, we can only do it with the permission from that customer. And then we also have other things where the encryption keys, so all of your data at rest and data in transit is encrypted, and we can have it so that those keys are controlled by the actual customer, and it doesn't even have to be on Google Cloud. Customers can keep the keys at a different provider or whatever. We've done that in a couple of countries for unclassified data,” he said.
At the same time, Hager also mentioned that there are some who are challenging the definition of sovereignty. Specifically, some feel that sovereignty even equals, and this is not Google's view, that all the software should be written in this country, which is very hard.
“So again, we kind of push back, and we say the data sovereignty is important so that your data stays somewhere, and you own the encryption keys, and part of the metadata may go somewhere else if we haven't optimized,” he added.
The AI engine
According to Hager, the AI engine may exist somewhere else because from a global perspective, the data is on Google Cloud, and the customer has the encryption keys. As customers want to change those weights in data, or refinement, the data still exists within their instance.
“It's on Google Cloud, but you have the encryption keys, and then you want to do this refinement and say, hey, I'm going to change the foundational model to work on this corpus of data that I have in a particular country. And the way we run it is, the original foundational model weights stay within Google's context, but when you do that refinement training, those new weights, which are changes to a few of the nodes, stay with you. And so, then when you actually do the inference, when you actually query this updated model, Google has no access to your weights because they're in your context and they're under your encryption keys,” Hager explained.
This then sends the query with the updates to Google’s foundational model. Those weights get overwritten, and the answer comes back. Google will then again delete what those things are.
“There's a matter of trust, right? You go, Google's keeping it, but we don’t. You want to update and do fine-tuning on our foundational model. It's not helping, or Google doesn't use that to improve our model, unless you tell us you want us to. That's how we can assure that when enterprises want to use our latest foundational models, they want to do their own fine-tuning, not just governments but intellectual property. The data is yours. It's an instance where you control the encrypted keys. And so, we've defined it that way so that we can go, your data is your data,” he added.
Competing and cooperating for secure AI
Both Pereira and Hager mentioned that Google wants to be the most secure cloud, and not just the fastest or most broadly informed cloud. And the same applies to AI as well.
“So, a lot of what Steve and I in the Office at CISO do is talk about secure AI and responsible AI. We don't just talk about AI use cases. That's an important, secure, and responsible AI. Same thing for cloud. We don't talk about just cloud. We talk about secure cloud. The differentiator for Google is that we started off in a bad situation back in 2009 when we got cyber-attacked and got owned by the nation-state. It totally changed the mindset of Google that security has to come first, not last, and not in the middle. So, everything we've built has always taken a security-focused mindset, and so we think we have the most secure cloud and the most secure AI available on the planet,” Pereira said.
For Hager, the competition in the industry is good because it gives consumer options, and it also lowers costs.
“Having competitors is not a bad thing, but cooperation is very important. Because from Google's perspective, when we develop something, we eventually tend to try to push it to be open source. Because our basic philosophy is, hey, if we do something for your customer journey and you like using our stuff and it's secure, then the digital economy grows, and Google is part of that. And so, this is where I'll say we're peers. It's good to have competition, but we want them to succeed too,” Hager said.
He added that Google often may start the innovation ball rolling, but the tech company is bringing in peers from other industries to co-develop.
“So partnering and co-development is a very big part of Google's ethos. When we do cloud implementation, we don't do it ourselves. We will put implementation partners in. Similarly for security. So, they can buy our tools, but they work through security SIs who implement it. So, they're partners in that sense. But then when you look at the other hyperscalers as well, we're sitting on the same regulatory forums when we're trying to influence a regulator on a new regulation. And we are all in agreement with the same views when it comes to working with regulators,” he added.
As Hager puts it, “there's fewer good guys and there's more of those bad guys.”