This blog post discusses 3 megatrends that are conflicting with each other and creating explosive potential situations. It highlights the concept of shared responsibility and discusses the advantages of partnering with Thales and Google for secure cloud solutions. Please contact Thales for more information about Thales and Google joint solutions.
What is the Google Cloud shared responsibility model?
The Google Cloud shared responsibility model is about clearly dividing who does what for security when you move to the cloud.
In simple terms:
- Google Cloud is responsible for securing the underlying cloud infrastructure – the physical data centers, networking, and core platform services.
- Your organization remains responsible for securing your data, identities, configurations, and access controls in that environment.
The podcast discussion between Thales and Google Cloud emphasizes that moving to the cloud does not mean you can delegate all security to the provider. If personal data is stolen or compromised, the legal responsibility typically remains with your organization, not the cloud provider.
Key areas you still own include:
- Data protection – encrypting sensitive data and deciding how and where encryption keys are managed.
- Access management – who can access which applications, datasets, and services.
- Compliance alignment – mapping your controls to regulations and industry guidelines (for example, New York State cybersecurity requirements for financial services, Hong Kong cloud security guides, India’s cloud adoption framework, Korea’s ISMS-P, and data breach notification rules).
This shared responsibility approach lets you leverage the scale and innovation of Google Cloud while still maintaining control over the security decisions that matter most to your business and regulatory environment.
How do Thales and Google Cloud help us stay in control of our data and encryption keys?
The Thales–Google Cloud partnership is designed to help you keep control of your own security while you modernize in the cloud.
The core idea is to split security responsibilities so that you can:
- Run applications and store data on Google Cloud.
- Retain independent control over encryption keys and key management policies.
Two concrete examples highlighted in the content are:
- Google Workspace client-side encryption – lets you encrypt data on the client side and manage keys externally, so Google processes encrypted content without having access to your keys.
- Google External Key Manager (EKM) integrated with Thales – enables you to host and control encryption keys outside Google Cloud while still using Google services.
This model supports:
- Data sovereignty – keeping control over where and how keys are stored to meet local and sector-specific regulations.
- Regulatory compliance – aligning with frameworks and guidelines across regions (for example, financial services regulations, cloud security practice guides, and data breach notification “safe harbor” clauses that often depend on strong encryption).
- Risk and cost reduction – when overall risk is reduced, organizations can often benefit from lower cyber insurance costs.
Thales and Google describe this evolution as moving from shared responsibility to a broader concept of shared fate, where technology providers, enterprises, and even insurers are more tightly aligned around reducing risk and maintaining trust.
Why is cloud and AI security becoming more urgent now?
Several converging trends are making cloud and AI security a more urgent priority for enterprises.
1. Accelerated cloud adoption
- According to McKinsey, cloud adoption has been accelerated by about three years compared to pre‑pandemic rates.
- Gartner estimates that spending on public cloud services will exceed $480 billion next year.
- Cloud transformation is now described as the normal way of doing business, not a side project.
2. Explosive data growth and regulation
- Organizations are producing a massive volume of data, which increases the attack surface.
- At the same time, there is increasing legal exposure as more security and privacy regulations come into force globally (for example, sector-specific rules for financial services and cloud, and diverse data breach notification laws).
- Most breach notification laws include a “safe harbor” clause when data is properly encrypted, which makes strong data protection and key management strategically important.
3. AI-enabled threats and “bad bots”
- The 2026 Thales Bad Bot Report shows that daily AI‑enabled bot attacks jumped from 2 million to 25 million in a single year.
- The same report finds that 46% of account takeover attacks target financial services, while 20% of AI bot attacks target retail websites.
- These trends are reshaping how organizations think about securing agentic AI, LLM‑powered applications, and digital experiences.
4. Emerging technology risks, including post‑quantum
- Although post‑quantum threats are projected to be a few years away, enterprises are encouraged to start planning now to be post‑quantum ready.
- Thales offers a free risk assessment to help organizations understand their exposure to potential post‑quantum breaches.
Across these areas, Thales provides research and guidance such as the 2026 Thales Data Threat Report, the Thales Digital Trust Index, and Gartner‑aligned resources on Data Security Posture Management (DSPM) and Data Security Platforms. These materials are intended to help security and IT leaders proactively manage risk, strengthen enterprise‑wide defenses, and support secure digital transformation.