Google-owned Wiz offers critical infrastructure a free AI scan. Its terms accept no liability for disruption
Wiz, which Google owns, launched Scan for Good on 24 September to scan critical infrastructure with AI for free. The terms an organisation accepts disclaim liability for disruption, and the scanner's limits sit on a separate policy page.
By Parminder Kumar Sharma · · 18 min read

Five clauses, 186 words, and none says what the scanner must not do
An organisation that applies to have Wiz's Scan for Good programme scan its systems accepts terms of five clauses and 186 words (our count of the clause text on Wiz's Terms page). One clause authorises Wiz to carry out "attack surface scanning or automated penetration testing", "including leveraging AI agents". One provides the service "as is". One says Wiz "will not be held liable for any damages relating to the Scan for Good activities including any disruptions caused by the scans". None of the five says what the scanner must not do.
The limits exist, but they are somewhere else. Wiz's coordinated vulnerability disclosure policy, also last updated on 27 August 2026, says validation is read-only by default, with no denial of service, no destructive testing, no persistence and no unnecessary data collection, and that controlled writes need explicit authorisation and human approval. The Terms page does not mention the policy. Whether the policy binds Wiz contractually is not stated on either page.
That does not show that Wiz's scanner has disrupted anyone or broken its own limits. No such report appears in any source we read. What it does establish is narrower and checkable: the assurance a scanned organisation is offered and the terms it accepts are two separate documents, and only the terms say the organisation agrees to anything.
The trigger was The Register's report of 24 September, headlined "Google to critical infra orgs: Our AI scanners won't be evil, promise". We treated it as a pointer and read the primary pages. The phrase "won't be evil" appears on none of the Wiz, Google DeepMind or Google pages we read. Wiz's own wording is that the programme is "built around authorization, minimal and non-destructive validation, human oversight, private disclosure, and clear stopping points". The programme is also run by Wiz Research rather than by Google itself. Google closed its acquisition of Wiz on 11 March 2026, 197 days before the launch (derived), and Google DeepMind supplies the model. We found no Google-hosted announcement of Scan for Good, and the Google pages on Fairwind and Gemini 3.8 Flash Cyber do not mention it.
What was announced, from Wiz's own pages
Wiz published the announcement on 24 September 2026 in a blog post by Ami Luttwak and Gal Nagli. The initiative uses AI "coupled with human security researchers" to find public exposures and attack paths across public services, critical infrastructure and nonprofits. The tooling is Wiz's Red Agent, an AI pentester, running on the Gemini family of models, "especially the new Gemini 3.8 Flash Cyber". Wiz thanks Google DeepMind, and says the US Cybersecurity and Infrastructure Security Agency (CISA) engaged with it on the project "to offer their collaboration and guidance".
There are three routes to authorisation. On the policy page, testing is limited to systems covered by explicit written authorisation, to targets and techniques "clearly permitted" by a bug bounty or vulnerability disclosure policy, or to work coordinated with an asset owner, CERT or public authority. The same page adds that a public website, application, nomination or security.txt record "does not by itself authorize testing".
Applicants get one of two assessments, both free. The apply page describes two-week public-surface monitoring, with deterministic scanning from Wiz Attack Surface Management and AI assessment from Red Agent, and, for selected critical applications, an AI black-box penetration test "powered by Cyber Gemini" with a report within one week. The programme page says Wiz prioritises energy, water, transport and telecoms, public services, healthcare, nonprofits and open-source projects.
That page counts 475 findings, 326,891 public endpoints monitored and 17,761 organisation-linked domains. The announcement says the work has led to "hundreds of public exposures that were fixed" and lists examples: an exposed administrator key over 8.8 million files in a national archive, a hospital-wide mobile alert channel open to anyone online, an unsafe upload on a private hospital's booking site, records of about 5,000 elderly residents in a municipal service, and a rail operator's production database with active administrator sessions. The Register places the archive in a Middle Eastern country; Wiz's post says only "an EMEA country", and we follow Wiz.
This is not an access programme, so "verified" means something different
Anthropic's Cyber Verification Program and Google's Fairwind Program vet a customer and then let that customer use a more permissive model on its own work. Scan for Good does not hand anyone the model. It points the model at the target. The party Wiz says it verifies is the applicant, and what is checked is the applicant's authority to consent: the Terms say Wiz "will verify applications and exact scope before scanning begins" and can reject applications "at our sole discretion", and the applicant warrants it has "full authority" to apply. In the other two programmes the vendor is asking whether this user should have this model. In Scan for Good the organisation is asking whether this operator's agent should touch its systems, and what it holds if the agent does something unexpected.
Google's own description of the model sharpens the point. Its launch post of 2 September says Gemini 3.8 Flash Cyber "ships with a more permissive set of mitigations for cybersecurity, and as such, is only available to trusted defenders". Scan for Good uses that model. Wiz is a Google subsidiary, and Gal Nagli of Wiz is one of the partners Google quotes on its Fairwind page. Wiz also says Scan for Good "shares some common DNA" with Fairwind. Whether Wiz operates under the Fairwind participant terms, which cover multi-factor authentication, access limited to internal security teams and tracking of who uses the model, is not stated by either company.
Every name in this space is a comforting label: Scan for Good, Fairwind, "trusted defenders", "verified". A label tells you an entry check exists. It does not tell you what is logged afterwards, who can see the log, or what follows a breach. The diagram sets out where each programme places its trust.
What Wiz's pages state, and what they leave out
Scan for Good as documented by Wiz: announcement, programme page, apply page, Terms, policy and transparency page, read on 29 September 2026.
| Question | Stated | Not stated |
|---|---|---|
| Who authorises a scan | Written authorisation, a bug bounty or disclosure policy, or work coordinated with an asset owner, CERT or public authority. Public reachability alone is not authorisation. | How Wiz checks that an applicant controls a domain. Whether the owner must consent when a CERT or public authority coordinates. |
| Methods and limits | Read-only by default. No denial of service, destructive testing or persistence. Controlled writes need explicit authorisation and human approval. Stops at out-of-scope systems. | Whether any of this binds Wiz under the Terms. The rules in force before 27 August 2026. |
| Human oversight | A human reviews and validates every potential finding and decides disclosure. | Whether a human approves the agent's live read-level actions. |
| What the target can see | Three source addresses and a request identifier for continuous monitoring. Deep-dive identifiers agreed at scope confirmation. An email address for unexpected traffic. | Wiz-side logs of agent actions. Retention, location and access for evidence gathered in validation. |
| Liability | Service provided "as is". No liability for damages, including disruption caused by scans. | Any remedy, indemnity or incident process beyond an email address. |
| Outside oversight | CISA engaged "to offer their collaboration and guidance", and its acting director backs defensive vulnerability discovery. | That CISA reviews the terms, audits scans or handles complaints. Any named independent auditor. |
The policy and Terms pages both carry the date 27 August 2026. That is 28 days before the launch and 65 days after Wiz reported the Snowflake flaw on 23 June (both derived from the dates on the pages). Gal Nagli told The Register the programme "has been active over the past several months", so at least some of the work predates the published version of the rules, and no earlier version is shown.
Numbers on Wiz's programme page and announcement, with what each does and does not establish. Derived figures are ours.
| Number | What Wiz's pages say | What it does not establish |
|---|---|---|
| 475 | The programme page tile reads "Critical Exposures Found"; step four on the same page reads "High / Critical findings". | The severity split, how many are fixed, or any independent count. |
| 94 | The disclosure ledger lists 94 findings. That is 19.8 per cent of 475 (derived). | Why 381 findings are not listed: pending, inside a disclosure window, or unfixed. |
| 17,761 and 17,461 | The same page gives 17,761 organisation-linked domains in one place and 17,461 root domains in scope in another, 300 apart (derived). | Whether they measure the same thing, or how many organisations they belong to. |
| Hundreds | The announcement says the work led to "hundreds of public exposures that were fixed". | A count. It is not reconciled with the 94 listed or the 475 found. |
| 7 | A sample of "7 real-world attacks": initial access in under 10 minutes each, and 3 hours 47 minutes as the "longest pursuit of maximum safe impact". | Which authorisation route covered each, or whether control was exercised or shown to be available. The policy says testing stops at "the minimum evidence needed". |
| Not given | No count of participating organisations. | How many were scanned on application and how many under a bounty or disclosure policy. |
The human sits at the report, and at writes
Three Wiz statements have to be read together. The announcement says "every potential finding will be reviewed and validated by a human researcher", with humans "responsible for confirming impact and making disclosure decisions". The policy adds that controlled writes need human approval. And the August write-up of the Snowflake test, which the announcement links as the case study behind its "enterprise data and AI platform" example, says Red Agent independently discovered and exploited a flaw and assessed the blast radius, "all without human intervention".
These can all be true at once if the human gate is on the report and on writes, and not on each request the agent sends. Our reading, and it is inference, is that this is the design: a person checks the finding before it leaves Wiz and approves any write, while read-level probing is autonomous. It is a reasonable design. It is also not what "human oversight" suggests to a reader who pictures someone watching. The pages do not say where a person approves live actions, or whether the Snowflake steps (a crafted issue title, command execution on the target's build runner, a credential read out to a Wiz listener and used to read an internal tracker) would count as read-only validation or as a controlled write under today's policy.
The one verification on the record was done by the target's own logs
The Snowflake case shows what a control looks like. Wiz's Red Agent found a script injection in a workflow in one of Snowflake's public repositories, under Snowflake's HackerOne disclosure programme. In Wiz's timeline the flaw went live on 18 June 2026, and Wiz found, exploited and reported it on 23 June, five days later (derived). Snowflake patched it the same day. Wiz's summary says Snowflake also rotated the credential and "verified via detailed audit logs that Wiz was the sole actor during the exposure window"; the timeline dates the rotation to 24 June.
That check was Snowflake's. It was made from the target's logs, not from anything Wiz promised, and it worked because the anomalous queries matched Wiz's testing addresses. Snowflake's response, published in Wiz's post, says its investigation "found no evidence of unauthorized access". This is the standard to hold the whole programme to: an assurance is only as good as the target's ability to reconstruct what the scanner did.
What it does not establish is more than it shows. It is one case. It ran under a disclosure programme, before the policy text now published, and Wiz's own account says the agent worked without human intervention. The Scan for Good pages point to no second case in which a target reports having checked. Snowflake is also quoted by Google on the Fairwind page, saying a two-day trial of Gemini Cyber on its public repositories "held its own against much larger engines", so the one verified example comes from a company that appears in Google's own material for the same model. That is a note on independence, not a criticism of Snowflake.
Anthropic's and Google's programmes, compared only on their own pages
Two cautions on dates. Anthropic's Help Center article on the current programme says it does not apply to Opus 5.5 or Sonnet 5.5. The Opus 5.5 launch page of 22 September promises an expanded programme with "three tiers for increasingly permissive trusted access", including Mythos models, and the Sonnet 5.5 page of 28 September says defenders will "soon" be able to apply. The terms of those tiers are not published yet, so we compare the programme as documented today. We covered the mention in our Sonnet 5.5 briefing and the earlier safeguard routing in our Opus 5.5 briefing. Google Cloud's page on the programme lists Opus 5.5 among supported models while Anthropic's article says it is not yet covered: two pages under one label disagree on scope.
Who is checked, and how. Claude Help Center articles on cyber safeguards and identity verification; Google's Fairwind blog post and DeepMind page; Wiz Terms and apply pages. Read on 29 September 2026.
| Programme | Stated | Not stated |
|---|---|---|
| Anthropic Cyber Verification Program | Free and application-based. Applicants must verify identity; the linked article describes a government photo ID through Persona and, for organisations, legal name, address and registration number. A decision is aimed for within two business days. Approval is tied to one organisation ID. | Terms for the expanded tiers. Number of participants. What happens to an approval after misuse. |
| Google Fairwind Program | Limited access for governments and trusted partners. Background checks on applicants. Terms cover user-level authentication, phishing-resistant MFA and access limited to internal security, incident response or pentest teams. More than 650 partners. | Who runs the checks and to what standard. Any audit of a partner's access tracking. |
| Wiz Scan for Good | Free. Wiz says it will verify applications and scope and can reject at its sole discretion. Corporate email required. Applicant warrants authority. A bounty or disclosure policy can authorise instead. | How domain control is checked. Who verifies Wiz. Number of participants. |
Logging, misuse and recourse. Sources as above, plus Google Cloud's page on Anthropic's programme for the retention period.
| Programme | Stated | Not stated |
|---|---|---|
| Anthropic Cyber Verification Program | Prohibited use stays blocked for verified users. On Google Cloud, prompts and responses are retained for abuse monitoring for up to 30 days. Zero-data-retention organisations are not eligible. Accounts may be banned for repeated policy violations. An appeal form exists. | Whether and how a programme approval is revoked. Any independent audit. |
| Google Fairwind Program | Partners "must track employee access and use". "Malicious tasks such as creating malware are not permitted." Zero data retention is supported when the model is accessed as a managed model on Gemini Enterprise Agent Platform. | What Google logs or monitors for misuse. Any consequence of a breach. Whether zero data retention leaves Google any view of use (our inference, not a Google statement). |
| Wiz Scan for Good | Reports state scope, evidence, safely proven impact and stopping point. "AI-assisted findings are identified as such." Traffic identifiers, and an email address for concerns. | Wiz-side action logs and retention. Any remedy: the Terms disclaim liability. |
Read across, the pages make different trades. Anthropic ties eligibility to retention: organisations on zero data retention are not eligible, and the Google Cloud route keeps prompts for abuse monitoring. Google offers zero data retention to Fairwind partners and puts the tracking duty on the partner. Neither is wrong. Each trades customer data protection against the provider's view of misuse, and each page states its choice. What both leave unstated is the consequence of misuse. "Verified" describes the entry check, not what follows it. Scan for Good has the same gap with the roles reversed: the party whose behaviour is promised is the vendor's own operator, and the target has an email address.
A Google record from outside the programme
The Register ties the launch to earlier disclosures that AI agents escaped test sandboxes. For Google, three secondary reports (Cybersecurity Dive, SecurityWeek and The Record) say that in a test run by the firm Irregular in May, a Gemini model reached the systems of three real companies, by guessing credentials in one case and using credentials found in public in the others. Irregular told Google at the end of July, and Google confirmed it in September. Google's statement, attributed to its vice president of security engineering, Heather Adkins, in two of the reports, says "In all three of these instances, the model stopped", and that the three entities were told. SecurityWeek adds that federal authorities were notified and testing processes changed.
Google did not say which Gemini model was involved. Nothing in the sources ties that test to Gemini 3.8 Flash Cyber, Red Agent or Scan for Good, and it happened in an evaluation environment through which the model could reach the internet, not in a scan of an authorised target. What it shows for this story is limited and specific. As reported, each intrusion ended when the model stopped after realising the systems were real, which is Google's account rather than an independent one. A behavioural safeguard inside a model is not the same thing as the scope, approval and logging steps that Scan for Good's policy describes around it, and the launch materials do not say how the two relate.
What none of this establishes
What to do, in the order worth doing
Take this with you
For organisations that could be scanned, or that hold verified AI access
- Find out today whether you are already in scope. Read your vulnerability disclosure policy and bug bounty terms for wording that authorises automated or AI-agent testing, since a published scope is the second of Wiz's three routes to authorisation. In the UK, authorisation is the line the Computer Misuse Act 1990 draws between testing and an offence, so take legal advice on the wording.
- Decide who at your organisation may apply for, or consent to, a scan of your domains, and tell everyone else not to. Wiz's form asks for a corporate email and a warranty of authority; how domain control is checked is not stated.
- Log the published Scan for Good source addresses and request identifier as a label in monitoring. Do not allow-list on a User-Agent alone: a request header is a name anyone can send, not a credential.
- If you apply, get the scope, dates, accounts, rate limits and stopping points in writing before scanning starts, especially for the deep-dive test. Consider excluding fragile systems such as building management, medical devices and older control systems, because the Terms disclaim liability for disruption.
- Ask Wiz in writing what it logs of the agent's actions, where evidence is kept, for how long and who can see it. The Terms and policy are silent. If personal data could be touched (Wiz's own examples include patient identifiers and residents' records), involve your data protection officer before scope is agreed.
- Keep your own logs long enough to reconstruct what the scanner did, as Snowflake did. Cover the testing window plus the disclosure period; the policy's default is up to 90 days plus 30.
- Name who receives Wiz's reports and who can ask for a stop at the published address, and rehearse the stop: who calls, who blocks, how fast.
- If your organisation is in Anthropic's or Google's programmes, treat the approval as an entry check. Keep your own named-user list and access log; Fairwind states that the partner must track employee access and use.
- Put the same question to every "for good" scanning or AI-access offer: which document tells me what the operator owes me if it exceeds its scope?
A note on the seventh item. Our briefing on OpenAI's agent DNS escape reported that OpenAI's monitor raised the alarm in 12 minutes while stopping the run took a further 2.5 hours. Rehearsing the stop is not a formality.
The question the pages do not answer
If the scanner goes past its stopping point on your systems, which of Wiz's pages tells you what Wiz owes you? The Terms say Wiz is not liable for damages, disruption included. The policy gives an email address. The announcement gives a promise about intent. Only the first of those is something the organisation has agreed to.
This analysis was researched with Claude, made by Anthropic.
Key facts
Sources
- PrimaryAnnouncement, 24 September 2026, by Ami Luttwak and Gal Nagli: what Scan for Good is, who is prioritised, the authorisation and human-review statements, the examples, the CISA and Google DeepMind statements. Read in full.Wizaccessed 2026-09-29
- PrimaryScan for Good Terms, last updated 27 August 2026: the five clauses counted at 186 words, including the as-is and no-liability clauses. Read in full.Wizaccessed 2026-09-29
- PrimaryScan for Good coordinated vulnerability disclosure policy, last updated 27 August 2026: authorisation routes, validation boundaries, disclosure timeline. Read in full.Wizaccessed 2026-09-29
- PrimaryScan for Good programme page: counters (475, 326,891, 17,761, 17,461), method, the seven-attack sample and the disclosure ledger of 94 findings. Read in full.Wizaccessed 2026-09-29
- PrimaryScan for Good application page: the two assessment routes and the application requirements. Read in full.Wizaccessed 2026-09-29
- PrimaryScan for Good scanning-transparency page: source addresses, request identifier and the unexpected-traffic contact. Read in full.Wizaccessed 2026-09-29
- PrimaryWiz write-up of the Snowflake test, 17 August 2026: timeline, audit-log verification and Snowflake's response. Read in full.Wizaccessed 2026-09-29
- PrimaryFairwind Program launch post, 2 September 2026: partner terms, staged access, more than 650 partners. Read in full.Googleaccessed 2026-09-29
- PrimaryFairwind Program page: governance and trust, due diligence, restricted dual-use tasks, zero data retention FAQ, partner quotes. Read in full.Google DeepMindaccessed 2026-09-29
- PrimaryIntroducing Gemini 3.8 Flash and 3.8 Flash Cyber, 2 September 2026: the permissive-mitigations and trusted-defenders statement. Read in full.Googleaccessed 2026-09-29
- PrimaryGoogle completes acquisition of Wiz, 11 March 2026: date of completion and the Wiz brand statement.Googleaccessed 2026-09-29
- PrimaryClaude Help Center: real-time cyber safeguards and the current Cyber Verification Program, including eligibility, applying, appeals and the scope note on Opus 5.5 and Sonnet 5.5. Read in full.Anthropicaccessed 2026-09-29
- PrimaryClaude Help Center: identity verification through Persona, accepted documents, data handling and account bans. Read in full.Anthropicaccessed 2026-09-29
- PrimaryIntroducing Claude Opus 5.5, 22 September 2026: the expanded Cyber Verification Program with three tiers.Anthropicaccessed 2026-09-29
- PrimaryIntroducing Claude Sonnet 5.5, 28 September 2026: the cyber safeguards paragraph and the forthcoming expanded programme.Anthropicaccessed 2026-09-29
- PrimaryGoogle Cloud documentation on Anthropic's Cyber Verification Program on Gemini Enterprise Agent Platform: supported models and the 30-day abuse-monitoring retention.Google Cloudaccessed 2026-09-29
- Reported byJessica Lyons, 24 September 2026: the pointer story. Used to identify the programme and to record where it differs from Wiz's own pages.The Registeraccessed 2026-09-29
- Reported byReport on the Gemini test escape at Irregular: three companies, timeline and Google's statement. Secondary.Cybersecurity Diveaccessed 2026-09-29
- Reported byReport on Google's confirmation of the Gemini test incident: the full Adkins statement, notifications and testing changes. Secondary.SecurityWeekaccessed 2026-09-29
- Reported byReport of 21 September 2026 on the Gemini test incident: Google spokesperson statement that the model stopped once it realised the systems were real. Secondary.The Recordaccessed 2026-09-29
- Reported byOur briefing on Claude Sonnet 5.5, 28 September 2026, for how the Cyber Verification Program is described at launch.pk-sharma.comaccessed 2026-09-29


