Category index

Architect

325 articles

325 ARTICLES

FEATURED REPORT

Detect early and enforce firmly with Google Cloud's enhanced cost controls for AI spend

Generative AI can make cloud costs difficult to predict. A single five-word prompt can run complex operations and generate significant costs. Traditional metrics like requests per second no longer help you estimate your bill, increasing the risk of unexpected cost spikes. While Google Cloud offers budget alerts, you need proactive guardrails that work out of the box - without the friction of writing custom JSON policies, configuring complex roles, or maintaining bespoke scripts. Today, we are announcing two native features in the Google Cloud Billing console: early anomalies on AI services and spend caps on Google Cloud Budgets. Together, these tools help you detect unusual spend early and enforce firm limits so you can build and experiment with confidence. A two-pronged defense playbook The inherent variability and potential for rapid scaling in AI usage demand a new level of responsiveness from cost management tools. To address this, we’re providing tools that allow users to effortlessly set up a GCP defense playbook. 1. Detect: early anomalies on AI services This new feature, located within the Anomalies tool on the billing console, automatically alerts users of directional variances (anomalies) in daily AI costs within a project. While Google Cloud has offered standard Cost Anomaly Detection, this new capability represents a major architectural shift designed specifically for the speed of AI workloads. How do early anomalies work? Dynamic baseline modeling: The system automatically analyzes historical project data to build an expected seasonal baseline of daily service-level costs—no manual threshold configuration required. Early cost monitoring: Instead of waiting for billing cycles to reconcile, the tool monitors early cost signals per service and alerts before actual costs are reported. Automated triage with RCA: If a daily cost signal trends abnormally, the system flags the deviation and generates a Root Cause Analysis (RCA) highlighting the top 3 SKUs driving the surge. Screenshot of the Billing Console showing an Early Anomaly alert with the Root Cause Analysis (RCA) breakdown highlighting the driving SKUs. Early anomaly signals allow your team to investigate upward trending costs and intervene before they escalate dramatically. Monitoring these daily variances helps you easily identify the most anomalous high-velocity services, making them perfect candidates for a firm enforcement cap. 2. Enforce: Spend caps on Google Cloud Budgets Once you identify a service that needs tight boundaries, the second step of the playbook comes in. Spend Caps is a new, native feature on Google Cloud Budgets that empowers you to set a monthly financial cap on specific services within a project. When accumulated spend reaches your defined cap, the system automatically restricts further cost-incurring usage for that specific service within that project. This provides a crucial safety net for your cloud finances without risking the rest of your infrastructure. How do spend caps work? During this Public Preview, you can apply Spend Caps to a single project and service for a fixed monthly timeframe. Screenshot of the Google Cloud Budgets interface highlighting the “Budget Type” selection with the new “Spend Cap” option enabled. Once the cumulative costs reach your defined cap, Google Cloud automatically takes action to prevent further billable usage. What makes Spend Caps so special? It is non-destructive i.e your data and resources are not deleted, and services outside the scope of the budget are entirely unaffected. You stay informed i.e Billing Administrators and Project Owners receive automated email alerts at 50%, 80%, and 100% of the budget One-click recovery i.e if a Spend Cap is triggered, the usage block remains in place until it is manually lifted from the Google Cloud Budgets UI with a single click. Screenshot of the “Lift spend cap” button in the Google Cloud Budgets UI showing the frictionless manual reversal flow While spend caps successfully halt new on-demand charges by pausing usage, any underlying fixed commitment fees (such as Committed Use Discounts or Provisioned Throughput) will continue to bill at their flat contractual rate. When do spend caps trigger? Since AI and cloud costs can rack up at lightning speed, guardrails must act with equal urgency. Traditional billing data can sometimes take hours to reconcile, but Spend Caps for AI services trigger within minutes of hitting your defined threshold. This rapid, near real-time enforcement is specifically engineered to limit your AI specific financial exposure before a runaway model, an infinite loop, or a massive query can spike your bill. The defense playbook at a glance By combining early anomaly signals with automated financial boundaries, Google Cloud provides a complete closed-loop defense for your AI spend. Playbook step Tool What it does Key benefit Supported servicesPreview Step 1: Detect Early Anomalies on Services Analyzes early cost signals daily to alert you of directional spend variances before they hit your invoice. Spot cost spikes early and pinpoint the exact SKU driving the trend. Gemini API, Agent Platform, Cloud Run, Cloud Run Functions Step 2: Enforce Spend Caps on Budgets Automatically halts usage for a specific project/service once your defined budget is breached. Protection against runaway spend without deleting resources Gemini API, Agent Platform, Cloud Run, Cloud Run Functions By deploying this dual-pronged defense strategy that works out-of-the-box, your engineering teams can move quickly, experiment safely, and focus entirely on innovation. Get started today Explore early anomalies: Head to the “Anomalies” section of your Google Cloud Billing Console. Set your first spend cap: Go to the Budgets & Alerts page in the Billing Console to apply native caps to your test or development environments. For more details on configuration, service-specific behaviors, and permissions, read the Manage Anomalies and Spend Caps on Budgets documentation.

BY Shruthi Nambi
MIN READ 5 MIN READ
EXPLORE north_east
Detect early and enforce firmly with Google Cloud's enhanced cost controls for AI spend
AWS Launches Amazon GuardDuty Investigation Agent to Automate Threat Triage
ARCHITECT

AWS Launches Amazon GuardDuty Investigation Agent to Automate Threat Triage

AWS released a public preview of the GuardDuty investigation agent, which correlates findings, 90-day activity logs, and resource topologies into structured reports with risk ratings, confidence scores, and MITRE ATT&CK classification. It is reachable through the AWS MCP Server, so investigations can run from agentic tooling. Preview quotas cap usage at 10 investigations per account per day. By Steef-Jan Wiggers

1 MIN READ arrow_forward
Uber’s Zero Growth Stack: Scaling Services, While Optimising Infrastructure and AI Cost
ARCHITECT

Uber’s Zero Growth Stack: Scaling Services, While Optimising Infrastructure and AI Cost

Uber’s “Zero Growth Stack” focuses on scalable infrastructure that separates capacity growth from business demand, reducing hardware needs while enhancing service scaling. Central to this is garbage collection optimisation. Additionally, generative AI is integrated into development, elevating developer productivity while introducing cost management measures to maintain economic efficiency. By Olimpiu Pop

1 MIN READ arrow_forward
Announcing general availability of SAP Business Data Cloud Connect for BigQuery
ARCHITECT

Announcing general availability of SAP Business Data Cloud Connect for BigQuery

Traditional data replication techniques often struggle to deliver the data freshness that modern workflows require. To help organizations overcome this challenge, SAP and Google Cloud are announcing that SAP Business Data Cloud Connect for BigQuery is now generally available. As the next phase of our long-standing partnership, SAP BDC Connect for BigQuery gives you zero-copy access to data products across SAP Business Data Cloud and BigQuery – reducing silos, preserving valuable business context, and accelerating analytics and AI. This makes current, semantically rich data available across both environments, helping AI agents execute complex business tasks while your teams remain in control. Stop copying data for AI projects Built to support a zero-copy architecture, SAP BDC Connect for BigQuery establishes a secure, bi-directional connection between SAP Business Data Cloud and Google’s data and AI ecosystem. Access SAP tables, metadata, and business semantics directly in BigQuery and Knowledge Catalog (formerly Dataplex) and vice versa. Ground your AI agents in operational reality instead of raw, isolated database fields.SAP BDC Connect for BigQuery enables organizations to: Scale AI on trusted data: Build governed, trustworthy AI grounded on a semantically rich data foundation with live, zero-copy access to data products across SAP Business Data Cloud and BigQuery. Deploy multi-agent workflows: Orchestrate workflows with intelligent agents across SAP and Google with Gemini Enterprise Agent Platform and SAP Joule. Discover deeper patterns: Combine mission-critical SAP data with unique datasets, such as Google Trends and Google Maps geospatial data, to create better business context. You can then publish this enriched data directly back to SAP. Improve business analytics: Empower employees to ask open-ended business questions in natural language using Gemini Enterprise or Joule and receive immediate, context-aware answers grounded in SAP and Google Cloud data. Scale your data value without inflating costs SAP BDC Connect for BigQuery’s zero-copy architecture helps lower your total cost of ownership (TCO) compared to alternative data platforms by minimizing the need to replicate, store, and maintain duplicate copies of your data. Because you can query data in place, you don’t incur data sharing fees. This creates a predictable billing model that insulates your organization from unexpected charges. How customers translate shared data into actions Organizations with preview access to SAP BDC Connect for BigQuery are already using its zero-copy architecture to solve more complex operational challenges. By speeding up data pipelines, early adopters are breaking down global data silos, predicting supply chain disruptions, and responding to fluctuating customer demands faster. Contrast that with traditional data practices where data connections take weeks to build, stalling enterprise AI initiatives. By interacting directly with SAP and Google data, teams can rapidly build functional prototypes and accelerate return on their AI investments. ElringKlinger is a global automotive supplier managing complex, multi-country manufacturing and supply chain data, and is using zero-copy to break down data silos. By querying real-time ERP data without having to replicate it, the company aims to reduce the complexity of its data infrastructure while supporting rapid production analytics with localized inventory reporting. “Operating a global automotive footprint means managing vast, complex supply-chain and production data. Today, the majority of that data sits in SAP BW/4HANA, our established reporting backbone. Testing SAP BDC Connect for BigQuery showed a powerful new path forward: BigQuery as an analytical layer on top of our existing BW/4HANA assets — no data copy, no migration — unlocking AI-based Conversational Analytics while fully preserving our prior investment. This also lays the groundwork for agentic use cases that automate supply chain processes, giving teams real-time visibility into manufacturing signals worldwide.” - Cleve Bankston, Project Manager and Dirk Brümmer Head of IT Architecture, ElringKlinger Unify data to build smart workflows with partners SAP and Google Cloud’s global partner network is actively building use cases with SAP BDC Connect for BigQuery. These help you move from isolated AI experiments to amplifying your team’s ability to handle highly variable tasks that are difficult to manage manually. To make this possible, our partners combine trusted SAP data with broader sources to help you deploy agentic AI and autonomous operations. With this unified approach, your team can connect disparate systems, maintain governance, and drive operations that deliver bottom-line impact. “As enterprises accelerate their reinvention agenda, the ability to unify data across business systems is foundational to scaling agentic AI. And that’s where SAP Business Data Cloud Connect for BigQuery is quite powerful. It enables enterprises real-time access to trusted financial, operational, and sustainability data, eliminating traditional data silos. This, combined with Gemini Enterprise and Accenture’s deep industry expertise, allows organizations to build intelligent agents, drive autonomous operations, and modernize their digital core faster while unlocking new levels of business value.” – Chetna Sehgal, Global Practice Lead, Accenture Google Business Group “Organizations don’t want a data science project; they want concrete business outcomes like working capital improvement and reduced operational costs. By leveraging this zero-copy integration, we built an autonomous procurement agent for a client. Because the agent reads live SAP inventory levels and market data inside BigQuery simultaneously, it autonomously re-routed orders during a recent supplier shift — saving millions in potential downtime and demonstrating that agentic AI tied to real-time data can deliver bottom-line impact.” - Piyush Bhandari, Managing Director, Deloitte Consulting LLP “Based on a recent assessment and prototyping experience with a KPMG member firm energy client, we believe there is strong potential for SAP BDC Connect for BigQuery to help organizations modernize enterprise planning, analytics, and data integration on a scalable foundation. KPMG firms’ evaluations indicate that this integration can support higher-volume analytical workloads at enterprise scale, helping to provide a critical data foundation to allow exploration of future AI and agentic use cases. As with any transformation, realizing the full business value can depend on the implementation approach, data quality, and organizational readiness.” - Mark Shank, Principal, Advisory, Banking, Tech & Data Engineering, Google in KPMG US “Our clients aren’t just looking for more information; they’re looking for better business decisions. At PwC, we’re helping organizations unify SAP business data with broader enterprise data sources inside Google Cloud. This creates a single, trusted foundation for AI that strengthens analytics, supports robust governance and compliance, and drives intelligent workflows across the enterprise. This unified approach is how organizations move from isolated AI experiments to true, enterprise-wide business transformation.” - Patrick Pugh, Global and US Alliances and Ecosystem Leader, PwC US Power of agentic data: Perspectives from SAP and Google Cloud “Every enterprise is striving to inject intelligence and automation into the core of their business operations. By uniting SAP Business Data Cloud with BigQuery and Gemini, we are breaking down one of the biggest walls in enterprise data. We are going far beyond raw data access by actively sharing rich semantic metadata and agentic context across platforms at zero data-sharing cost. This ensures our joint customers can deploy autonomous AI agents that operate with complete, real-time business awareness — executing complex supply chain and financial processes with absolute precision.” - Andi Gutmans, VP/GM, Agentic Data Cloud, Google Cloud “SAP Business Data Cloud Connect for Google BigQuery delivers real-time, bidirectional, zero‑copy data sharing that brings SAP’s mission‑critical data to Google BigQuery making it accessible to Google Gemini and Gemini Enterprise Agent Platform. With SAP BDC Connect, customers can unify SAP and non‑SAP data without complex extracts or custom APIs, reducing data complexity, strengthening governance, and accelerating trusted, AI powered business outcomes.” - Irfan Khan, President & Chief Product Officer, SAP Data & Analytics Regional availability SAP Business Data Cloud: Available today in Google Cloud regions in Australia (Sydney), Brazil (São Paulo), India (Mumbai), Israel (Tel Aviv), Germany (Frankfurt), Japan (Osaka), Saudi Arabia (Dammam) and the United States (Iowa). SAP BDC Connect for BigQuery: Generally available globally for all Google Cloud customers. Cross-cloud support: SAP BDC Connect for BigQuery supports SAP Business Data Cloud instances hosted on Google Cloud and AWS, with support for SAP Business Data Cloud instances hosted on Microsoft Azure coming soon. Get started To learn more, visit our website or speak with your Google Cloud account representative. For details on getting started with SAP BDC connect for BigQuery, visit our documentation page to get started with your zero-copy connection today.

7 MIN READ arrow_forward
Cyber Snapshot Report: Go beyond the toolchain and build enterprise resilience
ARCHITECT

Cyber Snapshot Report: Go beyond the toolchain and build enterprise resilience

Even as machine-speed attacks dominate the headlines, Mandiant’s view from the frontline reveals that the vast majority of successful intrusions still stem from fundamental human and systemic failures. This operational break-down shows up pointedly in research from the M-Trends 2026 report. Exploits remain the most common initial infection vector for the sixth consecutive year at 32%, voice phishing surged to second place at 11%, and prior compromise was the number one confirmed vector for ransomware-related incidents, according to the report. To stay ahead, leaders should shift from prevention-focused strategies to an operating model where compromise is anticipated, exploitation is recognized as inevitable, and a continuous, intelligence-led feedback cycle leads their defense. Business and security leaders should rethink how they architect and implement resilience strategies and train cross-functional teams. At the same time, they should also systematically address technical debt and organizational security culture. To help your team navigate this reality, we have curated the frontline insights and blueprints you need to turn potential organizational crises into manageable events in the newest Defender’s Advantage: Cyber Snapshot Report. Hardening architecture to contain blast radius When we accept that intrusions will happen, the goal of security shifts from keeping attackers out to containing their impact. Ransomware operators now aggressively target recovery paths — virtualization hypervisors, backup environments, and privileged access management (PAM) vaults — to deny organizations the ability to restore operations and maximize the pressure to negotiate. Hardening the architecture means implementing strict credential separation and air-gapped isolated recovery environments (IRE) to help verify that a compromise in the production network can not destroy backups. However, containing the blast radius also requires securing soft entry points beyond traditional data centers — starting with your executives and high-value personnel. Threat actors increasingly target personal digital footprints, including personal devices, home networks, and family members, as entry points into critical corporate infrastructure. A resilient posture should expand to protect this extended ecosystem, integrating digital footprint management with traditional executive protection programs. Forging readiness for the inevitable crisis While architectural guardrails can limit the physical reach of an attacker, human readiness and decision-making often determines how quickly your organization can respond and recover. This capacity can only be forged from first-hand experience. While policy can encourage its growth, enabling a culture of “safe failure” supported by immersive learning and mentoring can help teams to build the collective muscle memory needed to manage high-stress incidents. This human readiness is tested even further as adversaries embrace automation. Recent research by the Google Threat Intelligence Group (GTIG) identified the first known zero-day exploit developed with AI. This finding, combined with the intense industry focus on AI-driven vulnerability discovery, has driven many organizations to search for a quick technological countermeasure. While AI-assisted discovery provides advanced technical capabilities for defenders, it requires integrating these automated tools into a mature, structured program that aligns people and processes. By transforming raw discovery into a continuous, risk-based readiness capability, teams can overcome alert fatigue and achieve both machine-speed execution and strategic control. Activate your Defender’s Advantage today Technology alone will not define your cyber defense outcomes. True resilience lies in preparing your team, hardening your architectures, and practicing under pressure. To help arm your organization with the frontline insights needed to navigate evolving threats confidently, you can download your copy of The Defender’s Advantage: Cyber Snapshot Report, Issue 8, today.

3 MIN READ arrow_forward
Modernizing the skies: NOAA and Google Cloud collaborate to advance weather forecasting
ARCHITECT

Modernizing the skies: NOAA and Google Cloud collaborate to advance weather forecasting

The National Oceanic and Atmospheric Administration (NOAA) is embarking on a transformative journey to redefine how we understand and predict patterns in the Earth’s atmosphere that affect the weather we face every day. Today, we are proud to announce that Google Cloud was selected as the primary provider of high-performance computing (HPC) infrastructure for the Weather and Climate Operational Supercomputing System (WCOSS). This program represents a pivotal shift for NOAA as it transitions from a more traditional, on-premises computing agency to cloud-first infrastructure—a major milestone as one of the first operational Numerical Weather Prediction (NWP) centers globally to move to the public cloud. By modernizing WCOSS on Google Cloud, NOAA is positioning the United States to lead global weather modeling through scale, speed, and reliability. Google Cloud H4D VMs, powered by fifth-generation AMD EPYC™ processors, are serving as the primary computing backbone for NOAA on Google Cloud. Purpose-built for demanding, compute-intensive workloads like numerical weather prediction, H4D VMs provide the compute power and low-latency networking required to execute massive, tightly-coupled simulations. To put this in perspective, if traditional computers are like a fleet of individual delivery vans navigating city traffic, H4D VMs operate like a synchronized convoy on a dedicated, multi-lane superhighway—sharing information instantly so they can work together as a single, massive engine. For the NOAA workforce, the move to cloud HPC provides a more streamlined, flexible environment, enabling meteorologists and researchers to quickly adapt future modeling innovations. A foundation built on long-term collaboration The partnership announced today is more than just a technological upgrade; it is the latest milestone in a long-term collaboration between NOAA and Google Cloud. For years, our teams have worked together to streamline and share petabytes of environmental data, track real-time wildfires, and advance marine conservation efforts. This work was anchored by the agency’s visionary leadership, which also drove a full transition to Google Workspace as its collaboration suite of choice in 2011. The success of these early efforts paved the way for broader innovation. For example, NOAA Fisheries pioneered the development of a cloud compute accelerator pilot, giving scientists more flexible computing power they need, when they need it. NOAA also used Google DeepMind and Google Research’s WeatherNext model to predict Hurricane Melissa’s Category 5 landfall five days in advance, saving lives with early warnings and evacuations. These early pilot projects laid the groundwork for NOAA Fisheries to explore agentic AI applications powered by Gemini for Government. As we look ahead, this collaboration is a testament to what is possible when government and industry align on a shared vision. By combining Google Cloud’s HPC capabilities with NOAA’s unparalleled scientific expertise, we can help improve forecast accuracy, positively impact public safety, and ensure that the United States remains at the forefront of global weather modeling for years to come. Ready to see how cloud technology is transforming the public sector? Join us at the Google Public Sector Summit 2026 to hear more about how agencies like NOAA are advancing their missions.

3 MIN READ arrow_forward