Google's Michael Sinno on Autonomous Detection at 7 Trillion Logs Per Day  episode artwork

EPISODE · Feb 24, 2026 · 37 MIN

Google's Michael Sinno on Autonomous Detection at 7 Trillion Logs Per Day

from Detection at Scale · host Panther Labs

What does it actually take to automate security operations when you're processing 7 trillion log lines daily and a single missed threat could compromise billions of users? Michael Sinno, Director of Detection & Response at Google, explains how his team handles this with less than 1% requiring human intervention through strategic AI implementation. He explores Google's methodical approach to AI autonomy, including fine-tuned models trained on golden datasets, validation through overseer agents, and the critical distinction between traditional automation and agentic AI that exercises judgment. Michael also discusses groundbreaking work with Sec-Gemini and Timesketch that enables forensic analysis to surface attack patterns humans would never detect manually. Michael shares concrete metrics like reducing executive incident notifications from 30 minutes to 90 seconds, achieving 95% precision in ticket deduplication, and automating vulnerability coordination from hours to minutes. Topics discussed:Processing 7 trillion log lines daily with less than 1% of a million annual tickets requiring human intervention at GoogleStrategic evolution from AI-assisted to AI-led to autonomous security operations using fine-tuned models and golden datasetsBuilding modular detection agents as pluggable components that can be combined like Legos for specific security use casesImplementing quality assurance through overseer agents that review other agents' work to ensure precision in security decisionsReducing executive incident notifications from 30 minutes to 90 seconds using AI-powered summarization and context gatheringAchieving 95% precision in ticket deduplication while managing the trade-off between precision and 38% recall ratesIntegrating Sec-Gemini with Timesketch to surface attack patterns in forensic investigations that humans would never find manuallyShifting from traditional detection and response to infer-and-interrupt models that contain threats immediately before escalationAutomating vulnerability coordination workflows from hours to minutes through AI-powered data collection and impact analysisDistinguishing between traditional automation and agentic AI that exercises judgment rather than following if-then logicSetting a stretch goal of 70% automation in operations work while focusing humans on novel and complex security challengesMeasuring success through time-to-mitigation metrics and evaluating AI performance against human baseline capabilitiesListen to more episodes: Apple Spotify YouTubeWebsite

Episode metadata supplied by the publisher feed · Published Feb 24, 2026

Embed this episode

Ready to play

Google's Michael Sinno on Autonomous Detection at 7 Trillion Logs Per Day

0:00 37:48

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Detection at Scale?

This episode is 37 minutes long.

When was this Detection at Scale episode published?

This episode was published on February 24, 2026.

Can I download this Detection at Scale episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!