Securing the agentic enterprise on Google Cloud

Attackers now move at machine speed with a -7 day exploit window. Protect your full AI stack with identity boundaries, guardrails, and autonomous remediation.

Secure AI innovation eBook
AI Threat Defense framework

Google AI Threat Defense

To stop machine-speed attacks, enterprises must shift from manual triage to autonomous remediation. Google AI Threat Defense unites the reasoning of Gemini, the contextual risk prioritization of the Wiz Security Graph, and CodeMender's autonomous patching into an immediate find-and-fix loop. Operating locally in an isolated sandbox, CodeMender verifies exploitability with DeepMind-engineered reasoning before generating tested, ready-to-merge patches directly in developer workflows. With human-in-the-loop gates and zero IP exposure, you sever active attack paths before adversaries can exploit them.

A complete architecture to build, deploy, and govern AI

Establish an identity-first baseline for AI agents

Identity-first security stack

Replace static service accounts with cryptographic Agent Identity, PAM for JIT access, and PAB guardrails.

Ready to establish your baseline?

Enterprise foundations blueprint

Ready to establish your baseline?

Enterprise foundations blueprint

Securing the baseline

Establish an identity-first baseline for AI agents

Identity-first security stack

Replace static service accounts with cryptographic Agent Identity, PAM for JIT access, and PAB guardrails.

Ready to establish your baseline?

Enterprise foundations blueprint

Ready to establish your baseline?

Enterprise foundations blueprint

Discover shadow AI and govern multi-model sprawl

Wis AI-APP

Wiz connects in 15 minutes via API to generate dynamic AI-BOMs, while Gemini catalogs vetted agents.

Ready to uncover shadow AI?

State of AI in the Cloud 2026


Ready to uncover shadow AI?

State of AI in the Cloud 2026


Control access and intent with dual-layer defense

Life of an agentic deployment

Route traffic through Agent Gateway with IAP, screen payloads with Model Armor, and stop indirect prompt injections.

Ready to enforce runtime guardrails?

Building secure multi-agent systems on Google Cloud

Ready to enforce runtime guardrails?

Building secure multi-agent systems on Google Cloud

Detect, hunt, and remediate threats at machine speed

Monitor for exploits

Generate real-time rules for unpatched code and automate detection and containment with Google Security Operations.

Ready to close the remediation gap?

Monitoring and stopping AI-powered threats

Ready to close the remediation gap?

Monitoring and stopping AI-powered threats

Maintain sovereign control across your full AI estate

Forrester Wave

Maintain customer key ownership with Cloud KMS and KAJ across Assured Workloads, Dedicated, and air-gapped GDC.

Ready to evaluate sovereign cloud?

The Forrester Wave™: Sovereign Cloud Platforms, Q2 2026.

Ready to evaluate sovereign cloud?

The Forrester Wave™: Sovereign Cloud Platforms, Q2 2026.

Frequently asked questions

What are the top security risks when adopting Generative and Agentic AI?

The top concerns cited by enterprises are sensitive data exposure at 52% and regulatory compliance at 50% (Source: Cloud Security Alliance, Dec 2025). However, the enterprise transition to autonomous agentic AI introduces critical new vectors:

  • The mean time to exploit vulnerabilities has plummeted to minus seven days, meaning zero-days are routinely exploited before software patches are published (Source: Mandiant M-Trends Report).
  • Non-human workload identities now outnumber human identities by 82x in modern cloud environments (Source: Google Cloud NEXT 2026).
  • 42% of active enterprise AI agents currently hold sensitive, over-permissive privileges (Source: Google Cloud NEXT 2026).
  • Defending against these machine-speed attacks requires securing the full AI stack—infrastructure, data, models, and autonomous agents—simultaneously.

What is shadow AI and how can my organization detect it?

Shadow AI occurs when developers or business units deploy unsanctioned models, external APIs, or third-party agent skills without IT review:

  • Over 15% of agent skills available in public marketplaces are known to be malicious (Source: Google Cloud NEXT 2026).
  • 68% of organizations run self-hosted models bundled deep inside third-party software, often without realizing it (Source: Wiz, State of AI in the Cloud 2026).
  • To detect shadow AI, organizations use the Wiz AI-APP, which connects via API in 15 minutes to generate a dynamic AI-Bill of Materials (AI-BOM), paired with Gemini, which provides a centralized Agent Registry to catalog and govern all active agents, custom MCP servers, and external tools.

Do I need specialized security skills to secure AI workloads?

No. While skill shortages are a recognized challenge, organizations with formal AI governance are 3x more likely to train staff on AI security tools(Source: Cloud Security Alliance, Dec 2025), and security teams now lead AI protection in 53% of organizations (Source: Cloud Security Alliance, Dec 2025). Google Cloud shifts security directly into the platform fabric: foundational configurations are automated via the Enterprise Foundations Blueprint, runtime interactions are governed natively by Model Armor, and autonomous find-and-fix agents like CodeMender and Wiz Green Agent test and generate idiomatic code patches directly in developer workflows.

How do I secure agentic AI and non-human identities?

Securing autonomous agents requires moving past static service accounts. Because non-human identities outnumber humans by 82x and 42% of active agents possess over-permissive privileges (Source: Google Cloud NEXT 2026), Google Cloud establishes an Identity-First Security Stack:

  • Agent Identity: A dedicated, first-class principal type distinct from human users, provisioning cryptographic, strongly attested, lifecycle-bound runtime credentials.
  • Least-privilege controls: Capabilities are restricted using Privileged Access Manager (PAM) for just-in-time (JIT) access, eliminating standing privileges.
  • Principal Access Boundary (PAB): Imposes protective, hard resource boundaries to constrain the maximum blast radius of running agent identities.

What is the Secure AI Framework (SAIF)?

The Secure AI Framework (SAIF) is Google’s conceptual architecture for secure, responsible AI deployment. It translates Zero Trust security principles into AI systems by mandating SLSA Level 3 build provenance validated through Binary Authorization, automated policy-as-code checks in Cloud Build, and continuous threat detection. In agentic environments, SAIF operationalizes through the 4-stage lifecycle: Architect, Inventory, Intercept, and Defend(Source: Secure AI Innovation eBook, Chapter 6).

What is the Model Context Protocol (MCP) and how does Google Cloud secure agent tool connections?

The Model Context Protocol (MCP) is an open standard that allows autonomous AI agents to connect to external data sources, enterprise tools, and business APIs. However, unmanaged custom MCP integrations introduce risky, unvetted endpoints into production. Google Cloud secures agentic tooling via Google Cloud Managed MCP Servers (such as the MCP Server for BigQuery). This standardizes how agents interact with corporate databases, enforcing strictly scoped, auditable IAM permissions and replacing custom API wrappers with hardened, enterprise-managed connections (Source: Google Cloud NEXT 2026, Session BRK1-089).

What is session bleeding in multi-agent systems and how does Google Cloud prevent it?

Session bleeding occurs in multi-tenant or multi-agent environments when private conversation context, user tokens, or sensitive enterprise data from one user's session unintentionally leaks into another's. Google Cloud eliminates session bleeding through the Agent Development Kit (ADK) (Source: Secure AI Innovation eBook, Chapter 2):

  • Tenant isolation: The ADK enforces strict user boundaries and execution isolation using native session_id and user_id primitives.
  • Credential segregation: Downstream authentication tokens are isolated so that an agent cannot carry over credentials or conversational state across distinct user sessions.

Can Google Cloud secure third-party and open-source AI models?

Yes. Organizations pursue multi-model strategies running an average of 2.6 different models(Source: Cloud Security Alliance, Dec 2025). Google Cloud supports multi-model governance by using Gemini as a centralized execution control plane. Unified runtime guardrails—including Model Armor for prompt sanitization and Semantic Governance Policies—apply consistently across first-party Gemini models, open-source models, and third-party models. For multi-cloud estates (including AWS Bedrock, Databricks, and unmanaged open source), the Wiz Security Graph maps vulnerabilities and attack paths across all cloud providers (Source: Google Cloud NEXT 2026, Session BRK1-098).

Does CodeMender expose proprietary source code or use it to train AI models?

No. CodeMender is engineered with a privacy-first local execution architecture (Source: Secure AI Innovation eBook, Chapter 4):

  • Local CLI processing: The CodeMender scanning engine operates through a local command-line interface directly within the developer's secure environment.
  • Isolated sandboxing: Application builds and active exploit verifications execute inside an isolated sandbox on your own infrastructure.
  • Zero model training: Your proprietary source code and intellectual property remain strictly protected and are never used to train Google foundation models. Developers retain complete oversight through standard IDE/CLI workflows and Human-in-the-Loop (HITL) approval gates before any code patch is merged.

How can enterprises safely isolate high-risk autonomous agents in production?

To execute high-risk business logic without exposing core infrastructure, enterprises use the Bring Your Own Container (BYOC) reference architecture:

  • Container sandboxing: High-risk autonomous agents (such as inventory or logistics liaisons) are deployed in isolated containers on Cloud Run.
  • Strict permission separation: Deploy-time infrastructure permissions are strictly separated from runtime execution permissions.
  • Human-in-the-loop (HITL) gates: The Agent Development Kit (ADK) introduces programmed pause points where high-risk actions (such as initiating fulfillment APIs or financial disbursements) require explicit human sign-off before execution.

How does Google Cloud protect against prompt injection attacks?

Google Cloud enforces a double-guardrail runtime solution to sanitize payloads without adding latency:

  1. Controlling access (IAM boundaries): Enforced natively at the Agent Gateway using Identity-Aware Proxy (IAP) to cryptographically verify caller digital IDs before routing connections.
  2. Controlling intent (semantic boundaries): Model Armor operates as an inline proxy screening user, agent, and model interactions in real time to neutralize prompt injections, prevent jailbreaks, and redact sensitive PII. At the application layer, the Agent Development Kit (ADK) enforces input validation (such as BeforeToolCallback) to stop indirect SQL injections against BigQuery tables.

How can I ensure my AI models don't leak private enterprise data?

Preventing data leakage requires defense-in-depth across the network, application, and model layers:

  • Private topologies: AI workloads run on centrally managed Shared VPCs isolated by VPC Service Controls (VPC-SC), creating a macro-perimeter around the entire agent ecosystem.
  • Inline sanitization: Model Armor automatically scrubs and redacts sensitive customer data and PII from prompt inputs and model outputs.
  • Tokenless auth: Agent Identity Auth Manager handles complex downstream OAuth handshakes on behalf of users, passing tokens securely without exposing raw credentials to the agent.
  • Confidential computing: Protects data in-use by encrypting memory during active model processing.

Start your security transformation today

Cloud logo
Security
Google Cloud