AgentShield
How it works Pricing Blog FAQ Contact Sign in

Gemini Enterprise Agent Platform Security for Vertex AI Agent Engine and Agent Gateway Workloads

Gemini Enterprise Agent Platform is what Vertex AI became on April 22, 2026, and Agent Engine is now Agent Runtime. Since then Google has shipped a real governance stack: IAM access policies for Agent Gateway went GA on August 31, VPC Service Controls arrived on September 8 for newly created gateways only, and Semantic Governance has been in Preview since June 29. This page maps what that stack decides for you and what it still leaves to you.

OWASP LLM Top 10 Immutable audit trail Never trains on your data

Direct answer

Gemini Enterprise Agent Platform has strong native security for agents on Agent Runtime: SPIFFE agent identities, Agent Gateway with IAM access policies, Model Armor screening, and Semantic Governance, which checks each proposed tool call against user intent. The gaps are coverage and evidence. Agents outside Agent Runtime are not fully governed, Semantic Governance is Preview and LLM judged, and it denies rather than routing a call to a named approver.

Try it live

Watch AgentShield block an attack in real time.

Pick a scenario and drive the inspection lane yourself. No signup needed.

Threat Console
Interactive demo · 0 blocked in this session

Run a request

Runs the live engine on your text. Nothing is stored, no account needed.

Inspection lane

INSPECTING
⌖ untrusted input

Policy trace

High-risk action held for approval

Audit trail

The risk

A US specialty insurer moved its claims intake agent from Vertex AI Agent Engine to Agent Runtime in May, put it behind an Agent Gateway in egress mode, and wrote a Semantic Governance constraint that disallows issuing a claim payment without documented adjuster approval. In testing it worked. In September a claimant uploads a PDF whose cover letter says the adjuster already approved the payment by phone. The policy engine reads the user prompt, the chat history and the proposed tool call, and the approval it is looking for is a sentence in that history. Whether a pasted claim of approval is enough depends entirely on how the constraint was worded. Meanwhile the team learns that its gateway, created in July, cannot enforce the VPC Service Controls perimeter the security group signed off on, because that only works for gateways created after September 8. Nobody did anything wrong. The platform simply decides network reach and intent alignment, and nobody had decided where the human signature lives.

How AgentShield handles it

Keep Google's stack for what it does well: agent identities, the registry, Agent Gateway reach rules, Model Armor screening and Semantic Governance in dry run. Put AgentShield on the action path for the calls that move money, change records or leave your perimeter. Agents on Agent Runtime, Cloud Run, GKE or another cloud call tools through an AgentShield MCP gateway endpoint, a deterministic per-tool, per-argument policy decides allow, hold or deny, held calls wait for a named approver, and every decision is logged with the rule that applied.

Server room aisle with a locked access gate

The controls

The controls that secure which tool calls your Google agents may make and who signs off first.

What Google governs on Gemini Enterprise Agent Platform and what it leaves to you

Gemini Enterprise Agent Platform is Google Cloud's platform to build, run and govern agents, announced on April 22, 2026 as the evolution of Vertex AI. Agent Builder, Agent Engine, Model Garden and the Agent Development Kit now live under one name, and Google says all Vertex AI services and roadmap work will ship through it. Agent Engine is called Agent Runtime, and the Python SDK moved with it: the vertexai.agent_engines module is in its deprecation phase and is replaced by client.runtimes in the standalone agentplatform package.

Unlike most platforms we cover, Google has built governance that reaches past data access into the action itself, which is the core of autonomous AI security. That deserves a fair description before anything else.

ControlWhat it doesStage or catchWhat is left to you
Agent IdentityAssigns each agent a SPIFFE ID used for authentication, access control and auditingBound to the workload, not to the human the agent acts forLinking each action to the person who asked for it
Agent RegistryCentral directory of approved agents, tools, MCP servers and endpointsDefault deny at the gateway, exact hostnames only, no wildcardsKeeping the registry current as tools change
Agent Gateway with IAM access policiesDecides which agent may reach which MCP server, agent or endpoint; allow and deny rules per policyAccess policies GA on August 31, 2026Reach is yes or no; amounts and recipients are not in scope
Model ArmorScreens prompts and tool responses for prompt injection, sensitive data and harmful contentContent filter, not an action decisionWhat happens when a clean looking request is still the wrong action
Semantic Governance policiesChecks each proposed tool call against user intent and plain English constraints, denies the restPreview since June 29, 2026; evaluated by a modelDeterministic limits and a named human approver
Agent Anomaly DetectionReviews reasoning traces and tool calls asynchronously and flags anomaliesPrivate Preview since September 16, 2026; alerts unless you wire a callback to blockStopping the next call, not reporting on the last one

Read the last column and a pattern shows up. Google decides who an agent is, where it may connect and whether a proposed call reads as consistent with the request. What it does not provide is a place where a specific person approves a specific payment, deletion or external send, with that approval recorded as an event rather than as words in a transcript. Google's own layering table says Semantic Governance "complements access control and other governance mechanisms; it doesn't override or replace them." For agents with write access, the missing layer is a human approval gate for AI agent actions, and that is the layer we sell.

The September 2026 changes that force teams to rebuild their Agent Gateway

If your agents went behind Agent Gateway before September, the release notes from the last six weeks are not optional reading. Several changes only apply to new resources, so an existing setup can look compliant on a diagram and still not enforce what the diagram shows.

DateChangeWhat it means for an existing deployment
August 31, 2026IAM Unified Access Policies GA for Agent Gateway, with multiple allow and deny rules per policyMove any Preview era policies to the GA model and re-test deny paths
September 8, 2026Agent connectivity templates replace earlier VPC egress setup; choose ALL_TRAFFIC or PRIVATE_RANGES_ONLYOlder gateways keep working but on the old connectivity model
September 8, 2026Agent Gateway enforces VPC Service Controls perimetersGoogle: "VPC Service Controls is only supported for Agent Gateway deployments created after September 8, 2026 that use the agent connectivity template," in ALL_TRAFFIC egress mode. Earlier gateways must be recreated
September 9, 2026Computer Use and Shell sandboxes GA, with VPC-SC, Private Service Connect and CMEKAgents that run shell commands now have a supported isolation boundary
September 25, 2026Semantic Governance policies and engine support VPC Service ControlsStill Preview; include the policy engine inside the perimeter
September 29 and 30, 2026Custom denial messages for Semantic Governance; Cloud Trace for Agent Gateway in PreviewBetter user experience and tracing, no change to what is decided

The practical sequence for a team that already runs production agents:

  1. Inventory gateways by creation date. Anything created on or before September 8 cannot enforce your VPC-SC perimeter. Plan the recreate, with the registry and IAM bindings in the same project as the gateway.
  2. Port SDK code off vertexai.agent_engines. It is in deprecation, and the replacement client is mandatory for cross-project deployment.
  3. Register every hostname variant. Matching is exact, so standard, regional and mTLS hostnames each need an entry. Custom container images also need the gateway's CA certificate baked in, because the gateway decrypts and inspects outbound TLS.
  4. Run Semantic Governance in dry run first. Google ships a dry run mode that writes verdicts to Log Explorer. Use it to see what would be denied before you enforce.
  5. Decide where approvals live. This is the step most migrations skip. Covered in the next section.

Semantic Governance is the closest thing to an action gate, so read its fine print

Semantic Governance is a genuinely good idea and we would rather say so than pretend it does not exist. When the model proposes a tool call, Agent Gateway intercepts the response and sends the proposed call, your constraints and the chat history to a managed policy engine in your VPC. The engine runs two checks: does the call match the trusted user's intent, and does it comply with your plain English constraints. Both must pass. Google's own example blocks a refund above a dollar threshold and stops a calendar summary request from turning into a send_email call planted by a malicious email. That is exactly the class of failure we built AgentShield for.

Four details decide whether it is enough on its own for your agents.

DetailWhat Google documentsWhy it matters for write actions
Launch stagePublic Preview since June 29, 2026; VPC-SC support and monitoring metrics also PreviewPreview terms and support levels apply to a control you may cite in an audit
How a verdict is reachedSemantic analysis by a model of the prompt, history, tool manifest and constraints; token use is logged per turnThe same call can be judged differently if wording or context changes; Google advises hard numbers over words like "reasonable"
What counts as approvalIn Google's best practices example, a constraint requiring manager approval is satisfied when the user writes that a named VP approved the budget, and the verdict flips to ALLOWApproval evidence is text in the conversation, not a signed event from the approver
Combining controlsOn an ingress gateway, Semantic Governance "cannot be combined with Model Armor"On the client to agent path you choose between intent gating and content screening

The third row is the one to sit with. Nothing is wrong with Google's example: the policy did what it says, which is check that the conversation contains documented approval. But in an agent that reads email, tickets or uploaded files, the conversation history also holds whatever those sources said. A constraint can be written tightly, and Google publishes good guidance on doing that, but the evidence it weighs is still words. For a claim payment, a wire, a refund over a threshold or a record deletion, regulated US teams usually need the approval to be an action taken by an identified person in a separate channel, with a timestamp the agent cannot write.

That is the line we draw. Use Semantic Governance for intent drift and soft business rules; it catches things a static allowlist never will. Put irreversible calls behind per-tool, per-argument permissions that evaluate the same way every time, and send held calls to a person. Every decision, including who approved and which rule applied, goes to an AI agent audit trail kept outside the agent's reach.

Which agents Agent Gateway does not cover

Agent Gateway is framework agnostic, but it is not deployment agnostic. Its two modes have different reach, and most US enterprises we talk to run agents in more than one place.

Where the agent runsAgent Gateway coverageWhat to add
Agent Runtime (formerly Agent Engine)Client to agent ingress and agent to anywhere egress; ingress gateway must share the agent's project and regionApproval routing and deterministic limits on write tools
Gemini Enterprise app agentsEgress only; Google states client to agent mode "is not supported" for Gemini EnterpriseControls on who can invoke the agent, covered on our Gemini Enterprise security page
ADK agents on Cloud Run or GKENot among the runtimes the gateway documentation listsA policy point the agent must call through, plus the ADK callbacks described on our Google ADK security page
Agents on AWS or Azure that call Google hosted modelsModel traffic only, not their tool callsOne policy across clouds; see Bedrock AgentCore and Microsoft Foundry
Very large estatesUp to 5,000 registered resources per gateway, up to two registries per gatewayPlan gateway sharding before you hit the limit

The honest summary: if every agent you run lives on Agent Runtime and none of them can move money or delete records, Google's stack is the right answer and you should not buy anything else for it. If your agents write to claims, billing, CRM or ticketing systems, or if half of them run somewhere other than Agent Runtime, you need one decision point that covers all of them and produces approval evidence a person created.

When to buy nothing, use Google's controls, or add AgentShield

Your situationRecommendationWhy
Read only agents on Agent Runtime: search, summaries, draftingBuy nothing. Agent Identity, registry, gateway and Model ArmorNo write tool, no irreversible action to gate
Write tools on Agent Runtime with soft business rulesGoogle's stack, with Semantic Governance in dry run and then enforcedIntent gating fits rules that are hard to hard code
Gateways created before September 8 inside a VPC-SC perimeterRecreate the gateway with a connectivity template in ALL_TRAFFIC modeA configuration fix, not a purchase
Payments, claims, refunds or deletions where an auditor asks who approvedAdd AgentShield for held calls and approval recordsApproval must be an event by an identified person, not a sentence in history
Agents split across Agent Runtime, Cloud Run, AWS and AzureAdd AgentShield as the common policy pointAgent Gateway governs only part of that estate
Already standardized on Check Point or CrowdStrikeEvaluate their Agent Gateway integrations firstGoogle named Check Point AI Defense Plane and CrowdStrike Falcon Guardian as gateway integrations on September 30, 2026

Two of six rows end with buying nothing, and one sends you to a competitor you may already own. We would rather be the right answer for the remaining cases than a forced one for all of them. If you are comparing gateway designs across platforms, our MCP gateway page covers how a single policy endpoint fronts tools from several clouds, and the buyer guide for Gemini Enterprise Agent Platform compares six options side by side.

FAQ

Common questions about gemini enterprise agent platform security.

Is Gemini Enterprise Agent Platform the same as Vertex AI?

Yes, in practice. Google announced Gemini Enterprise Agent Platform on April 22, 2026 as the evolution of Vertex AI, and says all Vertex AI services and roadmap work now ship through it. Agent Engine became Agent Runtime, and the vertexai.agent_engines SDK module is in deprecation in favor of the agentplatform client.

What is Agent Gateway in Gemini Enterprise Agent Platform?

Agent Gateway is the enforcement point for agent traffic. It runs in client to agent (ingress) or agent to anywhere (egress) mode, applies IAM access policies against the Agent Registry, calls Model Armor and Semantic Governance, handles mTLS and protocol translation for MCP, REST and gRPC, and defaults to deny for unregistered destinations.

Does Gemini Enterprise Agent Platform protect against prompt injection?

Partly, through two layers. Model Armor screens prompts and tool responses for injection and sensitive data, and Semantic Governance checks whether a proposed tool call still matches the user's intent. Neither is deterministic, and on an ingress gateway the two cannot be combined, so irreversible actions still deserve a separate approval gate.

What are Semantic Governance policies?

They are plain English constraints that a managed policy engine applies to every tool call an agent proposes. The engine compares the call with the user prompt, chat history and your rules, and denies calls that drift from the request or break a constraint, such as a refund above a set amount.

Is Semantic Governance generally available?

No. Semantic Governance policies entered Public Preview on June 29, 2026. Its VPC Service Controls support (September 25, 2026) and built-in monitoring metrics are also Preview. Check the Preview terms before you cite it as a control in a SOC 2 or insurance audit.

Does Agent Gateway support VPC Service Controls?

Yes, since September 8, 2026, with a catch. Google states VPC-SC is only supported for Agent Gateway deployments created after September 8, 2026 that use an agent connectivity template in ALL_TRAFFIC egress mode. Gateways created earlier have to be recreated to enforce the perimeter.

What is the difference between Gemini Enterprise and Gemini Enterprise Agent Platform?

Gemini Enterprise is the employee facing app, formerly Agentspace, where staff use and build agents. Gemini Enterprise Agent Platform is the developer platform, formerly Vertex AI, where teams build, deploy and govern agents with ADK, Agent Runtime and Agent Gateway. Their security models differ, so we cover them on separate pages.

Does AgentShield work with Gemini Enterprise Agent Platform?

Yes. Agents on Agent Runtime, Cloud Run or GKE call tools through an AgentShield MCP gateway endpoint, alongside Google's own gateway. A per-tool, per-argument policy allows, holds or denies each call, held calls go to a named approver, and every decision is logged. Keep Model Armor and Semantic Governance in place.

Secure your gemini enterprise agent platform security.