Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →There is not enough independent, comparable evidence to conclude that cloud providers are neglecting security in order to pursue AI. The record does show large AI investments, public security commitments, and evolving threats to cloud environments. But it does not show whether AI has displaced security budgets, staff, or effective safeguards. For customers, the practical question is whether providers can demonstrate security outcomes—and whether customer-side controls keep pace with new AI workloads.
What does the evidence say about AI investment and security?
The available evidence supports scrutiny, not a finding that cloud providers have traded security for AI. Investment announcements establish that AI is a major priority; security programs establish that providers say they are working on protection. Neither, by itself, shows whether security resources or results have declined.
The evidence comes from different sources and measures different things. These figures should not be treated as comparable performance scores.
| Evidence | What it establishes | What it does not establish |
|---|---|---|
| FTC staff report announcement, January 2025 | The FTC described more than $20 billion in cumulative financial investment across the Microsoft–OpenAI, Amazon–Anthropic, and Alphabet/Google–Anthropic partnerships it studied. Its announcement also discussed cloud spending commitments, access to computing resources, information exchange, and potential switching costs. | It does not show that the providers cut security budgets or that the partnerships caused weaker security. The FTC described potential competition concerns, not a finding of security neglect. The findings reflect information available to staff through September 2024 and publicly available information through January 2025. FTC staff report announcement. |
| Microsoft Secure Future Initiative, announced May 3, 2024 | Microsoft publicly announced security principles, company-wide action, and plans covering identity and secrets, tenants, networks, engineering systems, threat monitoring, and remediation. The company said leadership compensation would partly depend on progress toward security plans and milestones. | A public commitment is not independent evidence that controls were effective or that security outcomes improved. Microsoft’s announcement. |
| AWS Sonaris figures, reporting period May 2023–April 2024 | Amazon reported that Sonaris denied more than 24 billion attempts to scan Amazon S3 customer data and prevented nearly 2.6 trillion attempts to discover vulnerable EC2 services during that period. | These are provider-reported counts of blocked attempts, not counts of successful attacks or independently audited security outcomes. The accessible interview page does not state a publication date. Amazon’s AWS security interview. |
| Google Cloud Threat Horizons report H1 2026 | Google reported that its teams observed the interval between vulnerability disclosure and active exploitation shrink from weeks to days in the second half of 2025. It also discussed identity attacks, unpatched third-party software, and an attempted AI-assisted credential-harvesting path. | These are report-specific observations, not a complete industry-wide measure of provider security. The report’s figure that identity compromise underpinned 83% of the compromises it discusses is not an industry-wide rate. Google Cloud Threat Horizons report. |
What security risks do AI partnerships raise?
The FTC’s January 2025 announcement identifies issues worth examining in the relationships between large cloud providers and AI developers. These include access to computing resources and engineering talent, cloud spending commitments, information exchange, switching costs, and—in varying degrees—consultation, control, or exclusivity rights. It also flags the possibility that cloud partners may receive sensitive technical or business information.
#1 Best Overall
Those arrangements can matter to competition, customer choice, and the movement of sensitive information. They are not evidence that cloud security has been neglected. The FTC Chair, Lina M. Khan, said the report shed light on how partnerships can create lock-in, limit startups’ access to key AI inputs, and reveal sensitive information that could undermine fair competition. The announcement’s findings cover information available through September 2024 and public information through January 2025; it is a dated snapshot, not a complete account of later contract or investment changes. Read the FTC announcement.
What do providers say they are doing about security?
Microsoft: a company-wide initiative
In a public statement on May 3, 2024, Microsoft CEO Satya Nadella described the Secure Future Initiative through three principles: Secure by Design, Secure by Default, and Secure Operations. He said the initiative included protecting identities and secrets, tenants, networks, and engineering systems, as well as threat monitoring and remediation. Nadella wrote: “If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security.” This is evidence of Microsoft’s stated direction, not independent verification of how well it was implemented. Microsoft’s announcement.
AWS: security capabilities for AI workloads
AWS’s Cloud Adoption Framework guidance describes security for AI workloads in areas including vulnerability management, governance, assurance, threat detection, infrastructure protection, data protection, and application security. AWS also describes MFA security keys and passkeys as account-protection options. These are AWS guidance and product descriptions; they do not establish how effectively every customer has deployed the controls. AWS security guidance for AI systems.
What should cloud customers do as AI services expand?
Threat reporting points to practical priorities for customers, especially around identity, vulnerable software, and visibility into data access. Google recommends identity access controls, centralized visibility tools for securing data, and automated posture enforcement. AWS guidance adds governance, vulnerability management, data protection, application security, and threat detection for AI workloads.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteRank #3
- Protect administrator identities. Require strong MFA for privileged and root accounts, review who can assume administrative roles, and remove access that is no longer needed. A hardware security key is one option to consider; AWS describes a free key for AWS Organizations root-account MFA and passkey support in IAM. That information supports the product category, not any particular brand, retail model, or compatibility across cloud providers. AWS account-security discussion.
- Check software dependencies and access paths. Keep third-party software patched, understand which vendors or integrations can reach your environment, and review their permissions—particularly where an AI service or its supporting tools can access production systems.
- Make AI data access visible. Identify what data an AI workload can read or send, who can change those permissions, and whether access events are logged in a place your security team monitors.
- Assign an owner and document controls for each workload. Record its purpose, data sources, integrations, responsible team, and the controls used to manage risks such as exposed credentials or unintended data access.
- Enforce posture automatically where possible. Use policies and alerts to detect configuration drift, overly broad permissions, and unprotected resources instead of relying only on periodic manual checks.
These steps do not transfer the provider’s security responsibilities to the customer. They address the configuration and identity decisions within a customer’s own environment.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What evidence would show whether security is being deprioritized?
A useful assessment needs dated, comparable measures—not a comparison between an investment announcement and a security slogan. To test whether AI expansion is crowding out security, customers and independent reviewers would need evidence such as:
Rank #4
- Security spending and staffing over time, with a clear scope and comparable definitions.
- Independent audit findings and whether significant issues were remediated.
- Incident and vulnerability data, including how quickly flaws are fixed and how defaults change after problems are found.
- Evidence about security features in practice, including which accounts, services, and customer configurations they cover.
- Clear documentation of which protections the provider operates and which depend on customers.
The sources available here do not provide that portfolio-wide comparison or independently link AI spending to a fall in security spending, staffing, or performance. They also cannot establish whether a provider is neglecting security relative to its resources or ambitions. The defensible verdict is therefore limited: AI expansion creates reasons to demand transparent, verifiable security outcomes, but the evidence does not show that cloud providers broadly neglect security to chase AI.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.

