Google Cloud ships AI.FORECAST and AI.DETECT_ANOMALIES
BigQuery gets managed forecasting and anomaly detection; SecOps tokens begin regional rollout July 1
Google Cloud’s release notes show two new managed BigQuery functions — AI.FORECAST and AI.DETECT_ANOMALIES — now rolling into customer environments, alongside a regional rollout of Security Tokens for Google SecOps beginning July 1, 2026.
AI.FORECAST is a BigQuery ML function that calls Google’s built‑in TimesFM forecasting model to generate time‑series forecasts directly in SQL, removing the need to ship data to separate model infra.
AI.DETECT_ANOMALIES is a managed anomaly‑detection function in BigQuery ML that can run on historical and incoming data tables to flag unexpected patterns without users having to deploy custom model servers.
The release notes mark availability tied to Connected Sheets and BigQuery ML: Google says pre‑trained TimesFM models are usable from Connected Sheets and that the AI functions are generally available for supported workflows.
For enterprises, these functions represent a tighter cloud‑native path from raw data to inference: analysts can write a SQL call to produce forecasts or anomaly labels and keep results inside BigQuery tables, dashboards, or downstream ETL. This reduces operational overhead for model hosting and scaling.
The Security Tokens feature for Google SecOps will begin rolling out across regions on July 1, 2026; tokens meter consumption for agentic SecOps agents and are intended for billing and metering of those automated security workloads. Google’s SecOps documentation and the release notes describe the tokens and a trial period that preceded the paid rollout.
Practically, managed forecasting and anomaly detection inside BigQuery simplifies enterprise ML pipelines that today often stitch together data warehouses, model training clusters, and separate inference endpoints. Teams can prototype faster and move to production without maintaining separate model serving stacks.
Connected Sheets integration means business users can trigger AI.FORECAST and AI.DETECT_ANOMALIES from spreadsheets, lowering the barrier for non‑technical users to run forecasts and anomaly scans on familiar reports. That ease of access is likely a deliberate move to broaden adoption inside organizations.
There are technical tradeoffs. TimesFM is a univariate forecasting model intended for many common series but not a drop‑in replacement for custom multivariate architectures. Similarly, AI.DETECT_ANOMALIES supports single‑table workflows and specific detection modes; edge cases may still require bespoke models or feature engineering.
From a governance perspective, managed inference reduces operator burden but shifts emphasis to data access controls, query costs, and audit trails inside BigQuery. Teams will need to update IAM, logging and cost alerts as inference queries become part of regular jobs.
The SecOps Security Tokens rollout also introduces a new metering vector: agentic actions consume tokens, so security teams should track token usage and understand which assistive or preview features do — and do not — consume tokens under the published rules. That affects budgeting for automated investigation agents.
For cloud practitioners, the immediate steps are simple: test AI.FORECAST and AI.DETECT_ANOMALIES on representative datasets, validate model outputs against business KPIs, and update governance and billing alerts ahead of the July 1 token rollout. Monitor Google’s release notes and product docs for regional timing and any service limits.