AgentShield
How it works Pricing Blog FAQ Contact Sign in

Best AI Agent Security Software for Gemini Enterprise Agent Platform and Vertex AI Agents

AgentShield Security Team·Oct 6, 2026·8 min read

Try it live

Watch AgentShield block an attack in real time.

Pick a scenario and drive the inspection lane yourself. No signup needed.

Threat Console
Interactive demo · 0 blocked in this session

Run a request

Runs the live engine on your text. Nothing is stored, no account needed.

Inspection lane

INSPECTING
⌖ untrusted input

Policy trace

High-risk action held for approval

Audit trail

Operations manager reviewing an automation approval request on a laptop

For most teams on Gemini Enterprise Agent Platform, the best AI agent security software is Google's own stack, configured properly: Agent Identity, Agent Registry, Agent Gateway with IAM access policies, Model Armor, and Semantic Governance in dry run before you enforce it. Add a dedicated runtime gate only when your agents can move money, change records or delete data and someone will ask who approved it, or when your agents run outside Agent Runtime where the gateway does not reach.

We sell that runtime gate, so starting with "Google may be enough" is on purpose. For read only agents it is the accurate answer, and it saves everyone a sales call.

Why Google agent teams are reviewing security this quarter

Three things changed in quick succession. Google renamed Vertex AI to Gemini Enterprise Agent Platform on April 22, 2026, Agent Engine became Agent Runtime, and the vertexai.agent_engines SDK module went into deprecation. Then the governance layer filled in: IAM access policies for Agent Gateway reached GA on August 31, and on September 8 Agent Gateway started enforcing VPC Service Controls, but in Google's words only "for Agent Gateway deployments created after September 8, 2026 that use the agent connectivity template." Gateways built over the summer have to be recreated to enforce a perimeter that security teams may already believe is in place.

At the same time, Semantic Governance, Google's check of each proposed tool call against user intent, has been in Public Preview since June 29, and Agent Anomaly Detection entered Private Preview on September 16. On September 30 Google named twenty security partners for Gemini Enterprise, two of them with Agent Gateway integrations. A buyer now has real choices, and the right one depends on what your agents are allowed to do. Our Gemini Enterprise Agent Platform security page covers the platform controls in depth; this guide compares the options.

Six options compared

OptionWhat it coversWhere it stopsBest for
Google native stackAgent identities, registry, gateway reach rules, Model Armor screening, audit logsReach is yes or no; no per-amount limits or human approvalsEvery team, as the baseline
Semantic Governance policiesIntent alignment and plain English business rules on each proposed tool callPreview, model judged, approval evidence is text in the conversationSoft rules that are hard to hard code
ADK callbacks and tool confirmationChecks you write in code before and after tool callsOpt in per tool, and confirmation does not support VertexAiSessionServiceEngineering teams that own every agent
Security partners on Agent GatewayCheck Point AI Defense Plane and CrowdStrike Falcon Guardian plug into the gatewayScope follows the gateway, so agents outside it are outside them tooTeams already standardized on those vendors
Data security and DLP platformsClassification and data movement across agents, endpoints and SaaSWatches data, not whether an action like a refund should happenRegulated data sets with existing DLP programs
Runtime action gateway (AgentShield)Per-tool, per-argument allow, hold or deny, named approvers, decision log across cloudsAnother component to run; unnecessary for read only agentsWrite tools, approvals, multi-cloud estates

Start with Google's own controls switched on

The baseline costs nothing extra in licensing and closes most of the risk for agents that only read. Give every agent its own Agent Identity, register only the destinations each one needs, and route Agent Runtime traffic through Agent Gateway, which defaults to deny. Hostname matching is exact, so register standard, regional and mTLS variants separately, and if you deploy custom containers, bake in the gateway's CA certificate because the gateway inspects outbound TLS. Attach Model Armor to screen prompts and tool responses. If you created a gateway before September 8 inside a VPC-SC perimeter, recreate it with a connectivity template in ALL_TRAFFIC mode. None of that is a purchase.

Semantic Governance for intent drift

This is the most interesting control Google ships, and it targets the right problem. When a model proposes a tool call, the gateway sends it to a policy engine with the user prompt, chat history and your constraints, and the call is removed unless it matches the user's intent and passes every constraint. It stops a calendar summary from turning into an email forward planted by a malicious message.

Two limits matter to buyers. It is Preview, so check the terms before you cite it in an audit. And the evidence it weighs is the conversation itself: in Google's own best practices example, a rule requiring manager approval is satisfied once the user writes that a named VP approved the budget. That is reasonable for many rules. For a claim payment or a wire, most US auditors want approval to be an action by a person, not a sentence the agent read.

ADK callbacks and tool confirmation in your own code

If you build with the Agent Development Kit, before and after tool callbacks let you write any check you like, and require_confirmation pauses a tool until someone confirms. It is opt in per tool, and Google's ADK docs list a limitation worth knowing: "VertexAiSessionService is not supported by this feature," and neither is DatabaseSessionService. Teams on managed sessions need another place for confirmations. Our Google ADK security page covers the callback patterns.

Security partners that plug into Agent Gateway

Google's September 30 partner announcement says Check Point's AI Defense Plane applies "real-time guardrails" and CrowdStrike's Falcon Guardian "extends guardrails and runtime protection by integrating with Agent Gateway." If your security operations already run on one of them, evaluate that integration first, because one console beats two. The limit is architectural: anything that hangs off the gateway covers what passes through the gateway, and Google documents client to agent mode as unsupported for Gemini Enterprise app agents and lists only Agent Runtime and Gemini Enterprise as gateway runtimes.

Data security and DLP platforms

Cyera's Agent Guardian brings data security posture management and DLP to agents on Gemini, and Nightfall and Cyberhaven cover data movement across endpoints and SaaS. These are the right buy when the risk is a regulated data set leaving where it belongs. They answer whether data is sensitive and where it goes, which is a different question from whether this agent should issue this refund right now. For the agent specific version of that problem see AI data leakage prevention for agents.

A runtime action gateway with approvals

This is the category we are in. Agents on Agent Runtime, Cloud Run, GKE, AWS or Azure call their tools through an AgentShield MCP gateway endpoint. A deterministic policy checks the tool and its arguments, such as the amount, the recipient or the record, and returns allow, hold or deny the same way every time. Held calls go to a named approver, and the approval is recorded as their action with a timestamp, in an AI agent audit trail the agent cannot write to. It runs alongside Google's gateway, not instead of it.

Before you buy anything, it is worth asking whether the workflow needs an agent at all. A surprising number of "agents" read inbound mail and copy fields into a sheet or a CRM. If that is the whole job, a plain email parser that extracts data to spreadsheets does it with no tool calls to govern.

Which option fits which Google agent team

Your situationWhat to buy
Read only agents on Agent RuntimeNothing. Configure the native stack
Gateway created before September 8 inside a VPC-SC perimeterNothing. Recreate the gateway with a connectivity template
Write tools with soft business rules, all on Agent RuntimeNothing yet. Semantic Governance in dry run, then enforced
Already run Check Point or CrowdStrikeTheir Agent Gateway integration
Regulated data leaving through agentsA data security or DLP platform
Payments, claims, refunds or deletions that need a named approver, or agents across several cloudsA runtime action gateway such as AgentShield

Four of six rows buy nothing new or buy from someone else. If you are on the employee facing Gemini Enterprise app rather than the developer platform, the trade offs differ, and our guide to AI agent security software for Gemini Enterprise covers that product.

Questions buyers ask

Is Gemini Enterprise Agent Platform secure for production agents?

Yes, for what it governs. Agent identities, a default deny gateway, IAM access policies and Model Armor give a strong baseline for agents on Agent Runtime. The gaps are approvals made by a person rather than inferred from chat, deterministic limits on amounts and recipients, and coverage for agents running outside Agent Runtime.

Does Semantic Governance replace a human approval step?

Not for irreversible actions. Semantic Governance checks that a proposed call matches the user's intent and your written constraints, and it can require that approval is documented in the conversation. It does not route the call to a person and wait. For payments or deletions, pair it with a human approval gate for AI agents.

Do I need a third-party tool if I already use Model Armor?

Not always. Model Armor screens prompts and tool responses for injection, sensitive data and harmful content, which suits read only agents. It does not decide whether a well formed request to refund, wire or delete should go ahead, so agents with write tools usually need an action level control too.

If your agents on Google Cloud can write to systems that matter, see how AgentShield gates their tool calls next to Agent Gateway, or compare plans and get started.

See the firewall block an attack live.

Drive the Threat Console and watch a real prompt injection get stopped, then put AgentShield in front of your own agents.

Open the console