Lifestyle
Google Cloud adds partner security agents to Gemini Enterprise, including defenses aimed at the risks of AI agents themselves
Google Cloud says about twenty security vendors, including CrowdStrike, Palo Alto Networks and Zscaler, now offer AI agents and protections in Gemini Enterprise, its workplace AI platform. The tools target businesses: they help security teams handle identity, vulnerabilities and data protection, and guard AI agents against threats such as prompt injection.
About 7 min read

What Google Cloud announced
Google Cloud published a post on its official blog announcing an expansion of the catalog of partner-built security offerings in the Gemini Enterprise ecosystem. Gemini Enterprise is Google Cloud's AI platform for workplaces. The post was signed by Vineet Bhan, Director of Security and Identity Partnerships, and Ashish Verma, Head of Partner Engineering, Security. Google Cloud said it had previously brought partner agents into Gemini Enterprise at its Google Cloud Next event, covering functions such as sales, content, HR and security. This announcement expands the security area.
In this context, an AI agent is an AI tool that can carry out tasks on a user's behalf, not just answer questions. Google Cloud argues that threat actors increasingly use AI to accelerate cyberattacks, while enterprise defenses are spread across identity, network, endpoint, data, cloud and application layers. These layers often span a dozen or more products. The company says that by bringing these vendors' agents and integrations into Gemini Enterprise, enterprises can orchestrate multi-step security workflows from a single interface.
Read the full description
Sources are collected, independently checked, then reviewed by Jev.
Two categories: security agents and AI workload protection
According to Google Cloud, the new items fall into two categories. The first is partner agents that security teams call directly within Gemini Enterprise. For example, teams can use them to ask about vulnerabilities in plain language or to contain compromised accounts. The second is protection for AI and agentic workloads themselves, meaning the AI systems and agents a company runs. These protections address risks such as prompt injection, sensitive data leakage and malicious AI activity. Prompt injection is when someone hides instructions in content an AI reads, trying to make it misbehave.
| Vendor and product | Type | Capabilities described in Google Cloud's post |
|---|---|---|
| Check Point AI Defense Plane | AI workload protection | Integrates with Agent Gateway and Agent Registry to discover AI workloads and guard in real time against prompt injection, data exposure and rogue agent behavior |
| CrowdStrike Falcon Guardian | AI workload protection | Protects agentic workloads via Agent Gateway against prompt injection, sensitive data leakage and malicious AI activity |
| Cyera Agent Guardian | AI workload protection | Secures agents running on Gemini with data security posture management (DSPM, tracking where sensitive data is and how exposed it is) and data loss prevention (DLP, stopping data from leaking out) |
| Fortinet FortiAIGate | AI workload protection | Provides runtime protection for large language models (LLMs, the AI models behind chat assistants) for Google Cloud customers |
| Britive Emergency Termination Agent | Security agent | Contains a compromised identity with a single natural-language request, revoking sessions with human approval and disabling the identity |
| Qualys ROCky | Security agent | Helps manage and patch vulnerabilities through conversation, ranked by the Qualys TruRisk score, running on each user's own Qualys entitlements |
| Ping Identity PingID self-service agent | Security agent | Lets employees handle multi-factor authentication (MFA) resets and device recovery in natural language without a help desk ticket |
Other vendors listed in the post include Acalvio, Cyberhaven, Endor Labs, Exabeam, Fastly, Menlo Security, Obsidian Security, Palo Alto Networks, Splunk (a Cisco company), Snyk, Thales, Transmit Security and Zscaler. Google Cloud describes Snyk as validating code generated by AI agents in real time. It says Transmit Security helps businesses tell good agents from malicious ones when they interact with customer-facing applications.
Why it matters: AI agents themselves become something to protect
What stands out in this announcement is not just that security tools are being connected to an AI assistant. Several vendors are also starting to treat AI agents themselves as something that needs to be managed. According to Google Cloud's post, Obsidian Security's agents can find AI agents across a company's systems and answer which ones hold escalated privileges or write access. Cyera correlates machine identities, delegated permissions and sensitive data classification to verify that agent behavior is authorized.
For office workers, this means that when a company adopts an AI assistant, there may be an extra layer of monitoring and restrictions behind it. For example, that layer may limit what data the AI can reach or block suspicious instructions. Some features also affect employees' daily work directly. The PingID self-service agent mentioned by Google Cloud lets employees handle MFA resets in natural language without opening a help desk ticket.
Key ideas in plain terms
- Prompt injection: someone hides instructions in a web page, document or message to try to make an AI behave in unintended ways. Several vendors list defending against this risk among their capabilities.
- Non-human identities: besides employee accounts, AI agents and system services have their own accounts and permissions. Britive says its agent can contain a compromised human or non-human identity.
- Human approval: according to Google Cloud's description, the Britive agent revokes sessions with human approval, so a person stays involved in the process.
- Availability: Google Cloud says these security agents can be explored in the Google Cloud Marketplace. They are business products, so most individuals would encounter them only through an employer.
Frequently asked questions
What did Google Cloud announce?
Google Cloud announced on its official blog that it is expanding partner-built security agents and integrations in Gemini Enterprise. The post lists about twenty security vendors. Their offerings fall into two categories: security agents that teams can call directly, and protections for AI and agentic workloads.
Have these features been independently verified as effective?
No. The information comes from the official Google Cloud blog and reflects claims by the company and its partners. The results mentioned, such as shorter containment times, are vendor claims, not independent test results.
Will individual users be affected?
The direct impact is limited, because Gemini Enterprise is a business product. If your employer uses it, you may notice more limits on what AI assistants can access. You may also be able to fix account problems such as MFA resets by asking in plain language, as with Ping Identity's self-service agent.
Why do so many vendors mention prompt injection?
Prompt injection means hiding instructions in content an AI will read, to make it stray from its task. In Google Cloud's post, Check Point, CrowdStrike, Menlo Security and other vendors all list protection against prompt injection among their capabilities. That suggests it is a risk companies take seriously when they deploy AI agents.
Should businesses adopt these tools right away?
This article does not give purchasing advice. Businesses should weigh their own needs and existing security setup. They should also check each vendor's actual capabilities and limits themselves rather than relying only on the announcement.
Browse the latest news in this topic
Lifestyle
Cloudflare open-sources Streamline: a demo of using its cloud services to add graphics to live streams and burn subtitles into videos
On October 2, 2026, Cloudflare launched and open-sourced Streamline, a developer playground showing how developers can combine Stream, Workers, Containers and Durable Objects to build their own video processing pipelines, such as adding graphics to live streams in real time or adding subtitles to videos. This article explains what it is, how it works, its limitations, and what it means for viewers and developers.
Lifestyle
Google unveils Gemini 4 Argon: cyber defenders get it first, everyone else still has to wait
On September 30, 2026, Google announced Gemini 4 Argon, which it calls its new frontier (most advanced) AI model. For now it is available only to trusted cyber defenders through the Fairwind Program. Here is what Google says the model can do, what it will cost developers, how Google says it is managing the risks, and what it means for everyday users. All figures come from Google itself.
Lifestyle
NVIDIA: CoreWeave Begins Offering Vera Rubin NVL72, With Cognition as First Production Customer
According to the NVIDIA blog, AI cloud provider CoreWeave now offers NVIDIA's next-generation Vera Rubin NVL72 systems, plans to offer the Vera CPU and launched CoreWeave Forge. This matters mainly to companies building AI agents, and could eventually mean faster AI tools for everyday users.
Lifestyle
Google Cloud makes Spanner Omni generally available: its Spanner database can now run in companies' own data centers and on other clouds
Google Cloud says Spanner Omni, a version of its Spanner database that businesses run themselves, is now ready for real-world use in their own data centers, on other clouds or on a laptop. This matters to organizations that want Spanner outside Google Cloud, but they take on the running of it. Here are the features, licences and trade-offs Google Cloud describes.
Latest travel guides

GuideTokyo
Where to Stay in Tokyo: Comparing Shinjuku, Ueno, Tokyo Station, Shibuya, Asakusa, Ikebukuro, and Ginza, Plus Airport Access, Accommodation Tax, and Luggage Delivery
Where should you stay in Tokyo? Compare Shinjuku, Ueno, Tokyo Station, Shibuya, Asakusa, Ikebukuro, and Ginza by the same criteria: access from Narita and Haneda, transit routes, nearby attractions, neighborhood character, and who each area suits. Includes a comparison table, a Yamanote Line diagram, Tokyo’s accommodation tax as verified in 2026/9 (changing to 3% in 2027/4), and Airport TA-Q-BIN luggage shipping rules.
- Budget
- Hotels

GuideTokyo
How to Choose Tokyo Transit Passes: Are Suica, Welcome Suica, the Tokyo Subway Ticket, and the JR Pass Worth It?
On a first Tokyo trip, start with an IC card and pay per ride (Welcome Suica has no deposit and is valid for 28 days). If you take four or more subway rides in a day, add a 72-hour Tokyo Subway Ticket for 2,000 yen; a JR Pass is never worthwhile if you stay in Tokyo and do not go to Kansai. See what TOURIST PASMO, Suica on iPhone, and the Tokyo Metro day pass do and do not cover, with a decision chart. Prices verified in September 2026.
- Transport
- Budget

GuideTokyo
Tokyo Disneyland and DisneySea Guide: Ticket Prices, Fantasy Springs, Disney Premier Access (DPA), Standby Pass, and Which Park to Choose for Your First Visit
Tokyo Disney one-day Passport prices vary: most weekdays in 9/2026 cost ¥9,900 and weekends ¥10,900. At 14:00 daily, tickets go on sale for the same date two months later. Free Priority Pass is no longer on the official service list; only paid Disney Premier Access (¥1,000–3,500 per person per use) shortens waits. Covers hours, the 25th anniversary, Standby Pass, Entry Request, Fantasy Springs access and first-visit park choice; checked on the official site in 9/2026.
- Itineraries
- Family