Confidentiality notice
My work at Google is focused on highly sensitive cybersecurity and privacy initiatives. To comply with strict non-disclosure agreements, all proprietary data, live interfaces, and specific workflows have been omitted. This case study focuses exclusively on high-level strategy, organizational architecture, and publicly communicable outcomes.
CONTEXT
Google's Privacy, Safety & Security (PSS) organization protects the data of ~4.5 billion users. By 2023, cyberattacks, data exposure, and regulatory obligations were growing faster than we could hire.
Problem
Google was pushing hard to adopt AI without a shared direction. Our design process worked, but it was about to be too slow, and our users are trained to question automated output from AI.
WHAT I DID
With my research lead, I wrote the strategy and principles for how our organization would use AI. Then I reshaped my team to deliver on it: new hiring profiles, training I build myself, and a sandbox for reducing friction in the prototype to production pipeline.
Impact
The strategy traveled beyond my department, and some of its OKRs were elevated to a near Google-wide level. My team moved from Figma mocks to working prototypes, so deciding what to build now takes weeks instead of months. One result: an AI triage agent that resolves 17% of the security investigation queue at ~97% precision.
Business problem
The defender's dilemma
Cyber defense has a built-in asymmetry: a defender has to be right every time, an attacker only once. By 2023, that gap was widening fast. Mandiant found average time-to-exploit fell from 32 days in 2021–2022 to five days in 2023.
Privacy and governance pressure grew alongside it. In a 2023 Cisco survey, more than a quarter of organizations had banned generative AI tools, at least temporarily, over privacy and data security risks. US federal agencies issued 25 AI-related regulations that year, 56% more than the year before, according to Stanford's AI Index.
The industry's answer had always been more people, and that had stopped keeping up. AI was the one lever that didn't depend on headcount, and across Google, teams were expected to adopt it with no coherent direction.
What it cost
The industry's answer had always been more people. Ops teams doubled and tripled their rotations and still fell behind, and the trend was predicted to get worse. Across Google, the push was to adopt AI, with no coherent direction behind it.

The users
A suspicious cohort
Our users—security analysts, privacy consultants, lawyers, and more—are paid to be suspicious. And the stakes are high, because they are accountable when things go sideways.
Hand them AI that guesses, with no way to inspect or undo it, and you burn credibility that you can't get back.

Solution
Direction before tools
A series of decisions in the order I made them
I built my team from one person to 30+ designers, researchers, content strategists, program managers, and engineers. The team was exceptional at building with Figma, design sprints and specs, and AI was about to make it all too slow.
However, transitioning the team wasn't easy. Across the wider organization, AI learning initiatives got mixed participation because people were expected to keep delivering on their day jobs while they learned. My team had the same pressure.
The risk to my team was that they'd stay excellent at a skill that was losing value until someone forced the change, and then they'd be changing under duress, from behind, with their roles in question.
Part of my job was making sure everyone still had one.

01
Set the core direction
Stop doing security & privacy by hand. Build and operate the technology that does it.
With my UX research lead, I wrote the strategy and principles for AI across enterprise privacy, safety, and security. My core thesis: we'd go from an organization that does security and privacy to one that builds and operates the technology that does it.
AI had to solve a real problem for the people using it, and four principles set the bar any AI experience had to clear: useful and usable, trustworthy, responsible, explainable.
TEMPTATION
Follow the company-wide push to do AI everywhere. The push across Google was to put AI into everything with no shared idea of where it would help.
KEY CALL
A strategy and principles for AI across all of enterprise PSS. AI had to solve a real problem for the people using it, otherwise it was just a hammer chasing the proverbial nail.
Principles for guiding AI in security & privacy

01
Set the core direction
CORE THESIS
Stop doing security & privacy by hand. Build and operate the technology that does it.
With my UX research lead, I wrote the strategy and principles for AI across enterprise privacy, safety, and security. My core thesis: we'd go from an organization that does security and privacy to one that builds and operates the technology that does it.
AI had to solve a real problem for the people using it, and four principles set the bar any AI experience had to clear: useful and usable, trustworthy, responsible, explainable.
TEMPTATION
Follow the company-wide push to do AI everywhere. The push across Google was to put AI into everything with no shared idea of where it would help.
KEY CALL
A strategy and principles for AI across all of enterprise PSS. AI had to solve a real problem for the people using it, otherwise it was just a hammer chasing the proverbial nail.
The four AI principles
Useful, usable
Easy to intervene and reverse actions of AI.
Responsible
Alert users to potentially harmful outcomes.
Trustworthy
Clear about AI limits and confidence
Explainable
Users can easily describe what it does.

02
Changed who we hire
CORE THESIS
Hire people who can build what they design.
I moved open headcount toward people who could build their ideas. We went from zero UX engineers to six, and new design roles now go to UX engineers and builders.
TEMPTATION
Continue hiring people who were exceptional at the old ways of working. The team was historically built around static mocks and well-defined specs.
KEY CALL
Move open headcount to people who build what they design. New design roles go to UX engineers and UX builders who translate ideas into software.

03
Bet on one tool
CORE THESIS
Choose for the long term, even when onboarding hurts.
Google had three internal AI development tools and no shared default. I standardized the team on Antigravity. It wasn't the easiest to onboard, but it was the one I thought would hold up long term. It paid off, since Google fully adopted it.
TEMPTATION
Pick the easiest tool to onboard, or let everyone pick their own. Google had multiple competing internal development tools and no shared default.
KEY CALL
Antigravity, for the whole team. It was not the easiest to onboard, but it was the one I thought would hold up long term. And I got it right.

04
Built a way to say no
CORE THESIS
Every 'no' comes with a reason.
At the time, everyone was saying yes to AI, which resulted in lots of noodles thrown against the wall to see what stuck.
With a researcher and a content strategist, I built the AI Impact Framework to score proposed AI work on user value and business value against feasibility, so teams could turn down weak ideas with a reason attached.
TEMPTATION
Go with the flow and say yes to every AI proposal. Company direction said where AI belonged, but it didn't tell us how to prioritize work or which projects to avoid.
KEY CALL
The AI Impact Framework. Built with a researcher and content strategist. It scored proposed AI work so teams could turn down weak ideas.
05
Taught it myself
CORE THESIS
KEY CALL

06
Gave the team somewhere real to build
CORE THESIS
Test ideas inside real products.
I tasked UX leads with rebuilding each product in AI tools as a working copy, one-to-one. It was a way to learn the tools, and it left us with a library of working clones with our design system built in. I cleared four days at a time for people to go heads-down, and on the fifth they showed what they'd made. Ideas that used to be too expensive to prototype, like an agent that acts on your behalf, now get built to behave like the real product.
Before
Setup friction, and learning on top of day jobs. Org-wide AI learning weeks got mixed participation. The first barrier for my team was technical setup.
KEY CALL
An AI upskilling program, with coaching on development environments. Each session included some context, tools for the day, and three challenges. Everyone came back with highlights and lowlights.

07
Backed a team member's bigger idea
CORE THESIS
A big bet in a high-risk environment, because falling behind attackers isn't an option.
A UX engineer on my team saw what those clones could become: a sandbox where people who aren't software engineers can ship working code to production on a secure, compliant baseline. I recognized the opportunity and did the organizational work to get buy-in and make it real. It's a big bet in a high-risk environment, and it's still in progress. We made that bet because falling behind attackers, data protection risks, and regulatory scrutiny wasn't an option.
Concept
A UX engineer saw what the clones could become. A sandbox where people who aren't software engineers can ship working code to production on a secure, compliant baseline.
My role
Recognize a great idea, then do the organizational work. Buy-in, advocacy, influence, and guidance to make it real. It's still in progress.

08
Changed how we worked
CORE THESIS
When the prototype is the artifact, exploring and making happen together.
Once prototypes became the artifact, AI merged the ideate and build phases of our process, so exploring and making now happen in one step. To keep a dispersed team connected through that shift, I hold two-hour open critique blocks twice a week where anyone can book 30 minutes.
Before
Four separate phases and long-form written specs. Define, ideate, build, land – each phase was its own step.
After
Ideation and building merged. Prototypes replaced specs. Two-hour open blocks twice a week, bookable in 30-minute slots, give me a view across a portfolio too broad to track any other way.

What my decisions made possible
Once the direction, the tools, and the sandbox were in place, the work that came out of them changed how security & privacy operated well beyond my team.
Securing how people talk to agents
Letting employees instruct AI agents over company chat opened risks that didn't exist before: someone impersonating a colleague, or tricking an agent into doing more than it should.
An agent acting on your behalf is only as trustworthy as its certainty about who's asking. I mobilized 45-plus people across 10 teams, most of them outside my org, and in five weeks we delivered an architecture that ties every request to a verified person and device.
A triage agent that earned its autonomy
Duplicate investigations were nearly 30% of all incoming security work. The agent ran assistive-only for four months, recommending and never acting, until precision reached about 97%.
Only then did it close duplicates on its own, with every action tagged and a 90-day human verification gate behind it. It now resolves 15–17% of the investigation queue.
Human-ON-the-loop review where the risk is
AI drove an exponential increase in launches, and a review process built on manual scrutiny for every launch stopped scaling.
Now launches assessed as low risk get AI-assisted, one-click approval against set criteria, and human attention goes to the launches that warrant it. The goal is to cut time to launch by 40%.
Results
Impact of the work
What changed outside my team
The principles were written for my department and traveled well past it. I took them to VPs and senior directors myself, and some of our OKRs were elevated to near Google-wide.
My team is a little over 30 people. The organization those OKRs now shape is roughly 8,000, and none of them report to me.
AI-assisted review now handles low-risk launches with one-click approval, with the goal of cutting time to launch by 40%.
What changed inside it
Working prototypes replaced written specs, cutting the time to get product, engineering and design aligned on what to build from months to weeks. Almost nobody works in Figma anymore. Designers hand engineering prototypes built in real code, and the more technical people ship to production.
Our entire research team now works with agentic AI tools, running log analysis that used to require data science support.
What survives me
The operating rhythm. Define, ideate, build, land is how the whole team works now, and it would keep running if I left tomorrow.
I'm less sure about the training program. It's mostly been me and a UX program manager. What does survive is the habit underneath it: share what you learn, including what failed. Post-COVID, many teams including mine, felt like a set of dispersed islands. This fixed that.
What I'd do again
The principles. I'd write them anywhere. But what works at Google would need adjusting for a different context, so I'd need to stress-test or start clean.
What I wouldn't
I wouldn't rebuild the AI Impact Framework. It was a large lift and right for the early days when nobody knew what AI cost, but it has run its course.
More AI impact
Launches
8
Led the launch of 8 new products from concept through to launch and landing
Unification
IAM
Unified dozens of Identity & Access Management tools into a single product
Security
>300%
User improvement in detecting malicious scripts when leveraging LLM-augmented experiences

