Best AI Agent Security Software for Gemini Enterprise Agent Platform and Vertex AI Agents
Try it live
Watch AgentShield block an attack in real time.
Pick a scenario and drive the inspection lane yourself. No signup needed.
Run a request
Runs the live engine on your text. Nothing is stored, no account needed.
Inspection lane
INSPECTINGPolicy trace
High-risk action held for approval
Audit trail
- § · → → →
For most teams on Gemini Enterprise Agent Platform, the best AI agent security software is Google's own stack, configured properly: Agent Identity, Agent Registry, Agent Gateway with IAM access policies, Model Armor, and Semantic Governance in dry run before you enforce it. Add a dedicated runtime gate only when your agents can move money, change records or delete data and someone will ask who approved it, or when your agents run outside Agent Runtime where the gateway does not reach.
We sell that runtime gate, so starting with "Google may be enough" is on purpose. For read only agents it is the accurate answer, and it saves everyone a sales call.
Why Google agent teams are reviewing security this quarter
Three things changed in quick succession. Google renamed Vertex AI to Gemini Enterprise Agent Platform on April 22, 2026, Agent Engine became Agent Runtime, and the vertexai.agent_engines SDK module went into deprecation. Then the governance layer filled in: IAM access policies for Agent Gateway reached GA on August 31, and on September 8 Agent Gateway started enforcing VPC Service Controls, but in Google's words only "for Agent Gateway deployments created after September 8, 2026 that use the agent connectivity template." Gateways built over the summer have to be recreated to enforce a perimeter that security teams may already believe is in place.
At the same time, Semantic Governance, Google's check of each proposed tool call against user intent, has been in Public Preview since June 29, and Agent Anomaly Detection entered Private Preview on September 16. On September 30 Google named twenty security partners for Gemini Enterprise, two of them with Agent Gateway integrations. A buyer now has real choices, and the right one depends on what your agents are allowed to do. Our Gemini Enterprise Agent Platform security page covers the platform controls in depth; this guide compares the options.
Six options compared
| Option | What it covers | Where it stops | Best for |
|---|---|---|---|
| Google native stack | Agent identities, registry, gateway reach rules, Model Armor screening, audit logs | Reach is yes or no; no per-amount limits or human approvals | Every team, as the baseline |
| Semantic Governance policies | Intent alignment and plain English business rules on each proposed tool call | Preview, model judged, approval evidence is text in the conversation | Soft rules that are hard to hard code |
| ADK callbacks and tool confirmation | Checks you write in code before and after tool calls | Opt in per tool, and confirmation does not support VertexAiSessionService | Engineering teams that own every agent |
| Security partners on Agent Gateway | Check Point AI Defense Plane and CrowdStrike Falcon Guardian plug into the gateway | Scope follows the gateway, so agents outside it are outside them too | Teams already standardized on those vendors |
| Data security and DLP platforms | Classification and data movement across agents, endpoints and SaaS | Watches data, not whether an action like a refund should happen | Regulated data sets with existing DLP programs |
| Runtime action gateway (AgentShield) | Per-tool, per-argument allow, hold or deny, named approvers, decision log across clouds | Another component to run; unnecessary for read only agents | Write tools, approvals, multi-cloud estates |
Start with Google's own controls switched on
The baseline costs nothing extra in licensing and closes most of the risk for agents that only read. Give every agent its own Agent Identity, register only the destinations each one needs, and route Agent Runtime traffic through Agent Gateway, which defaults to deny. Hostname matching is exact, so register standard, regional and mTLS variants separately, and if you deploy custom containers, bake in the gateway's CA certificate because the gateway inspects outbound TLS. Attach Model Armor to screen prompts and tool responses. If you created a gateway before September 8 inside a VPC-SC perimeter, recreate it with a connectivity template in ALL_TRAFFIC mode. None of that is a purchase.
Semantic Governance for intent drift
This is the most interesting control Google ships, and it targets the right problem. When a model proposes a tool call, the gateway sends it to a policy engine with the user prompt, chat history and your constraints, and the call is removed unless it matches the user's intent and passes every constraint. It stops a calendar summary from turning into an email forward planted by a malicious message.
Two limits matter to buyers. It is Preview, so check the terms before you cite it in an audit. And the evidence it weighs is the conversation itself: in Google's own best practices example, a rule requiring manager approval is satisfied once the user writes that a named VP approved the budget. That is reasonable for many rules. For a claim payment or a wire, most US auditors want approval to be an action by a person, not a sentence the agent read.
ADK callbacks and tool confirmation in your own code
If you build with the Agent Development Kit, before and after tool callbacks let you write any check you like, and require_confirmation pauses a tool until someone confirms. It is opt in per tool, and Google's ADK docs list a limitation worth knowing: "VertexAiSessionService is not supported by this feature," and neither is DatabaseSessionService. Teams on managed sessions need another place for confirmations. Our Google ADK security page covers the callback patterns.
Security partners that plug into Agent Gateway
Google's September 30 partner announcement says Check Point's AI Defense Plane applies "real-time guardrails" and CrowdStrike's Falcon Guardian "extends guardrails and runtime protection by integrating with Agent Gateway." If your security operations already run on one of them, evaluate that integration first, because one console beats two. The limit is architectural: anything that hangs off the gateway covers what passes through the gateway, and Google documents client to agent mode as unsupported for Gemini Enterprise app agents and lists only Agent Runtime and Gemini Enterprise as gateway runtimes.
Data security and DLP platforms
Cyera's Agent Guardian brings data security posture management and DLP to agents on Gemini, and Nightfall and Cyberhaven cover data movement across endpoints and SaaS. These are the right buy when the risk is a regulated data set leaving where it belongs. They answer whether data is sensitive and where it goes, which is a different question from whether this agent should issue this refund right now. For the agent specific version of that problem see AI data leakage prevention for agents.
A runtime action gateway with approvals
This is the category we are in. Agents on Agent Runtime, Cloud Run, GKE, AWS or Azure call their tools through an AgentShield MCP gateway endpoint. A deterministic policy checks the tool and its arguments, such as the amount, the recipient or the record, and returns allow, hold or deny the same way every time. Held calls go to a named approver, and the approval is recorded as their action with a timestamp, in an AI agent audit trail the agent cannot write to. It runs alongside Google's gateway, not instead of it.
Before you buy anything, it is worth asking whether the workflow needs an agent at all. A surprising number of "agents" read inbound mail and copy fields into a sheet or a CRM. If that is the whole job, a plain email parser that extracts data to spreadsheets does it with no tool calls to govern.
Which option fits which Google agent team
| Your situation | What to buy |
|---|---|
| Read only agents on Agent Runtime | Nothing. Configure the native stack |
| Gateway created before September 8 inside a VPC-SC perimeter | Nothing. Recreate the gateway with a connectivity template |
| Write tools with soft business rules, all on Agent Runtime | Nothing yet. Semantic Governance in dry run, then enforced |
| Already run Check Point or CrowdStrike | Their Agent Gateway integration |
| Regulated data leaving through agents | A data security or DLP platform |
| Payments, claims, refunds or deletions that need a named approver, or agents across several clouds | A runtime action gateway such as AgentShield |
Four of six rows buy nothing new or buy from someone else. If you are on the employee facing Gemini Enterprise app rather than the developer platform, the trade offs differ, and our guide to AI agent security software for Gemini Enterprise covers that product.
Questions buyers ask
Is Gemini Enterprise Agent Platform secure for production agents?
Yes, for what it governs. Agent identities, a default deny gateway, IAM access policies and Model Armor give a strong baseline for agents on Agent Runtime. The gaps are approvals made by a person rather than inferred from chat, deterministic limits on amounts and recipients, and coverage for agents running outside Agent Runtime.
Does Semantic Governance replace a human approval step?
Not for irreversible actions. Semantic Governance checks that a proposed call matches the user's intent and your written constraints, and it can require that approval is documented in the conversation. It does not route the call to a person and wait. For payments or deletions, pair it with a human approval gate for AI agents.
Do I need a third-party tool if I already use Model Armor?
Not always. Model Armor screens prompts and tool responses for injection, sensitive data and harmful content, which suits read only agents. It does not decide whether a well formed request to refund, wire or delete should go ahead, so agents with write tools usually need an action level control too.
If your agents on Google Cloud can write to systems that matter, see how AgentShield gates their tool calls next to Agent Gateway, or compare plans and get started.
See the firewall block an attack live.
Drive the Threat Console and watch a real prompt injection get stopped, then put AgentShield in front of your own agents.
Keep reading