Gemini Enterprise Agent Platform Security for Vertex AI Agent Engine and Agent Gateway Workloads
Gemini Enterprise Agent Platform is what Vertex AI became on April 22, 2026, and Agent Engine is now Agent Runtime. Since then Google has shipped a real governance stack: IAM access policies for Agent Gateway went GA on August 31, VPC Service Controls arrived on September 8 for newly created gateways only, and Semantic Governance has been in Preview since June 29. This page maps what that stack decides for you and what it still leaves to you.
Direct answer
Gemini Enterprise Agent Platform has strong native security for agents on Agent Runtime: SPIFFE agent identities, Agent Gateway with IAM access policies, Model Armor screening, and Semantic Governance, which checks each proposed tool call against user intent. The gaps are coverage and evidence. Agents outside Agent Runtime are not fully governed, Semantic Governance is Preview and LLM judged, and it denies rather than routing a call to a named approver.
Try it live
Watch AgentShield block an attack in real time.
Pick a scenario and drive the inspection lane yourself. No signup needed.
Run a request
Runs the live engine on your text. Nothing is stored, no account needed.
Inspection lane
INSPECTINGPolicy trace
High-risk action held for approval
Audit trail
- § · → → →
The risk
A US specialty insurer moved its claims intake agent from Vertex AI Agent Engine to Agent Runtime in May, put it behind an Agent Gateway in egress mode, and wrote a Semantic Governance constraint that disallows issuing a claim payment without documented adjuster approval. In testing it worked. In September a claimant uploads a PDF whose cover letter says the adjuster already approved the payment by phone. The policy engine reads the user prompt, the chat history and the proposed tool call, and the approval it is looking for is a sentence in that history. Whether a pasted claim of approval is enough depends entirely on how the constraint was worded. Meanwhile the team learns that its gateway, created in July, cannot enforce the VPC Service Controls perimeter the security group signed off on, because that only works for gateways created after September 8. Nobody did anything wrong. The platform simply decides network reach and intent alignment, and nobody had decided where the human signature lives.
How AgentShield handles it
Keep Google's stack for what it does well: agent identities, the registry, Agent Gateway reach rules, Model Armor screening and Semantic Governance in dry run. Put AgentShield on the action path for the calls that move money, change records or leave your perimeter. Agents on Agent Runtime, Cloud Run, GKE or another cloud call tools through an AgentShield MCP gateway endpoint, a deterministic per-tool, per-argument policy decides allow, hold or deny, held calls wait for a named approver, and every decision is logged with the rule that applied.
The controls
The controls that secure which tool calls your Google agents may make and who signs off first.
What Google governs on Gemini Enterprise Agent Platform and what it leaves to you
Gemini Enterprise Agent Platform is Google Cloud's platform to build, run and govern agents, announced on April 22, 2026 as the evolution of Vertex AI. Agent Builder, Agent Engine, Model Garden and the Agent Development Kit now live under one name, and Google says all Vertex AI services and roadmap work will ship through it. Agent Engine is called Agent Runtime, and the Python SDK moved with it: the vertexai.agent_engines module is in its deprecation phase and is replaced by client.runtimes in the standalone agentplatform package.
Unlike most platforms we cover, Google has built governance that reaches past data access into the action itself, which is the core of autonomous AI security. That deserves a fair description before anything else.
| Control | What it does | Stage or catch | What is left to you |
|---|---|---|---|
| Agent Identity | Assigns each agent a SPIFFE ID used for authentication, access control and auditing | Bound to the workload, not to the human the agent acts for | Linking each action to the person who asked for it |
| Agent Registry | Central directory of approved agents, tools, MCP servers and endpoints | Default deny at the gateway, exact hostnames only, no wildcards | Keeping the registry current as tools change |
| Agent Gateway with IAM access policies | Decides which agent may reach which MCP server, agent or endpoint; allow and deny rules per policy | Access policies GA on August 31, 2026 | Reach is yes or no; amounts and recipients are not in scope |
| Model Armor | Screens prompts and tool responses for prompt injection, sensitive data and harmful content | Content filter, not an action decision | What happens when a clean looking request is still the wrong action |
| Semantic Governance policies | Checks each proposed tool call against user intent and plain English constraints, denies the rest | Preview since June 29, 2026; evaluated by a model | Deterministic limits and a named human approver |
| Agent Anomaly Detection | Reviews reasoning traces and tool calls asynchronously and flags anomalies | Private Preview since September 16, 2026; alerts unless you wire a callback to block | Stopping the next call, not reporting on the last one |
Read the last column and a pattern shows up. Google decides who an agent is, where it may connect and whether a proposed call reads as consistent with the request. What it does not provide is a place where a specific person approves a specific payment, deletion or external send, with that approval recorded as an event rather than as words in a transcript. Google's own layering table says Semantic Governance "complements access control and other governance mechanisms; it doesn't override or replace them." For agents with write access, the missing layer is a human approval gate for AI agent actions, and that is the layer we sell.
The September 2026 changes that force teams to rebuild their Agent Gateway
If your agents went behind Agent Gateway before September, the release notes from the last six weeks are not optional reading. Several changes only apply to new resources, so an existing setup can look compliant on a diagram and still not enforce what the diagram shows.
| Date | Change | What it means for an existing deployment |
|---|---|---|
| August 31, 2026 | IAM Unified Access Policies GA for Agent Gateway, with multiple allow and deny rules per policy | Move any Preview era policies to the GA model and re-test deny paths |
| September 8, 2026 | Agent connectivity templates replace earlier VPC egress setup; choose ALL_TRAFFIC or PRIVATE_RANGES_ONLY | Older gateways keep working but on the old connectivity model |
| September 8, 2026 | Agent Gateway enforces VPC Service Controls perimeters | Google: "VPC Service Controls is only supported for Agent Gateway deployments created after September 8, 2026 that use the agent connectivity template," in ALL_TRAFFIC egress mode. Earlier gateways must be recreated |
| September 9, 2026 | Computer Use and Shell sandboxes GA, with VPC-SC, Private Service Connect and CMEK | Agents that run shell commands now have a supported isolation boundary |
| September 25, 2026 | Semantic Governance policies and engine support VPC Service Controls | Still Preview; include the policy engine inside the perimeter |
| September 29 and 30, 2026 | Custom denial messages for Semantic Governance; Cloud Trace for Agent Gateway in Preview | Better user experience and tracing, no change to what is decided |
The practical sequence for a team that already runs production agents:
- Inventory gateways by creation date. Anything created on or before September 8 cannot enforce your VPC-SC perimeter. Plan the recreate, with the registry and IAM bindings in the same project as the gateway.
- Port SDK code off
vertexai.agent_engines. It is in deprecation, and the replacement client is mandatory for cross-project deployment. - Register every hostname variant. Matching is exact, so standard, regional and mTLS hostnames each need an entry. Custom container images also need the gateway's CA certificate baked in, because the gateway decrypts and inspects outbound TLS.
- Run Semantic Governance in dry run first. Google ships a dry run mode that writes verdicts to Log Explorer. Use it to see what would be denied before you enforce.
- Decide where approvals live. This is the step most migrations skip. Covered in the next section.
Semantic Governance is the closest thing to an action gate, so read its fine print
Semantic Governance is a genuinely good idea and we would rather say so than pretend it does not exist. When the model proposes a tool call, Agent Gateway intercepts the response and sends the proposed call, your constraints and the chat history to a managed policy engine in your VPC. The engine runs two checks: does the call match the trusted user's intent, and does it comply with your plain English constraints. Both must pass. Google's own example blocks a refund above a dollar threshold and stops a calendar summary request from turning into a send_email call planted by a malicious email. That is exactly the class of failure we built AgentShield for.
Four details decide whether it is enough on its own for your agents.
| Detail | What Google documents | Why it matters for write actions |
|---|---|---|
| Launch stage | Public Preview since June 29, 2026; VPC-SC support and monitoring metrics also Preview | Preview terms and support levels apply to a control you may cite in an audit |
| How a verdict is reached | Semantic analysis by a model of the prompt, history, tool manifest and constraints; token use is logged per turn | The same call can be judged differently if wording or context changes; Google advises hard numbers over words like "reasonable" |
| What counts as approval | In Google's best practices example, a constraint requiring manager approval is satisfied when the user writes that a named VP approved the budget, and the verdict flips to ALLOW | Approval evidence is text in the conversation, not a signed event from the approver |
| Combining controls | On an ingress gateway, Semantic Governance "cannot be combined with Model Armor" | On the client to agent path you choose between intent gating and content screening |
The third row is the one to sit with. Nothing is wrong with Google's example: the policy did what it says, which is check that the conversation contains documented approval. But in an agent that reads email, tickets or uploaded files, the conversation history also holds whatever those sources said. A constraint can be written tightly, and Google publishes good guidance on doing that, but the evidence it weighs is still words. For a claim payment, a wire, a refund over a threshold or a record deletion, regulated US teams usually need the approval to be an action taken by an identified person in a separate channel, with a timestamp the agent cannot write.
That is the line we draw. Use Semantic Governance for intent drift and soft business rules; it catches things a static allowlist never will. Put irreversible calls behind per-tool, per-argument permissions that evaluate the same way every time, and send held calls to a person. Every decision, including who approved and which rule applied, goes to an AI agent audit trail kept outside the agent's reach.
Which agents Agent Gateway does not cover
Agent Gateway is framework agnostic, but it is not deployment agnostic. Its two modes have different reach, and most US enterprises we talk to run agents in more than one place.
| Where the agent runs | Agent Gateway coverage | What to add |
|---|---|---|
| Agent Runtime (formerly Agent Engine) | Client to agent ingress and agent to anywhere egress; ingress gateway must share the agent's project and region | Approval routing and deterministic limits on write tools |
| Gemini Enterprise app agents | Egress only; Google states client to agent mode "is not supported" for Gemini Enterprise | Controls on who can invoke the agent, covered on our Gemini Enterprise security page |
| ADK agents on Cloud Run or GKE | Not among the runtimes the gateway documentation lists | A policy point the agent must call through, plus the ADK callbacks described on our Google ADK security page |
| Agents on AWS or Azure that call Google hosted models | Model traffic only, not their tool calls | One policy across clouds; see Bedrock AgentCore and Microsoft Foundry |
| Very large estates | Up to 5,000 registered resources per gateway, up to two registries per gateway | Plan gateway sharding before you hit the limit |
The honest summary: if every agent you run lives on Agent Runtime and none of them can move money or delete records, Google's stack is the right answer and you should not buy anything else for it. If your agents write to claims, billing, CRM or ticketing systems, or if half of them run somewhere other than Agent Runtime, you need one decision point that covers all of them and produces approval evidence a person created.
When to buy nothing, use Google's controls, or add AgentShield
| Your situation | Recommendation | Why |
|---|---|---|
| Read only agents on Agent Runtime: search, summaries, drafting | Buy nothing. Agent Identity, registry, gateway and Model Armor | No write tool, no irreversible action to gate |
| Write tools on Agent Runtime with soft business rules | Google's stack, with Semantic Governance in dry run and then enforced | Intent gating fits rules that are hard to hard code |
| Gateways created before September 8 inside a VPC-SC perimeter | Recreate the gateway with a connectivity template in ALL_TRAFFIC mode | A configuration fix, not a purchase |
| Payments, claims, refunds or deletions where an auditor asks who approved | Add AgentShield for held calls and approval records | Approval must be an event by an identified person, not a sentence in history |
| Agents split across Agent Runtime, Cloud Run, AWS and Azure | Add AgentShield as the common policy point | Agent Gateway governs only part of that estate |
| Already standardized on Check Point or CrowdStrike | Evaluate their Agent Gateway integrations first | Google named Check Point AI Defense Plane and CrowdStrike Falcon Guardian as gateway integrations on September 30, 2026 |
Two of six rows end with buying nothing, and one sends you to a competitor you may already own. We would rather be the right answer for the remaining cases than a forced one for all of them. If you are comparing gateway designs across platforms, our MCP gateway page covers how a single policy endpoint fronts tools from several clouds, and the buyer guide for Gemini Enterprise Agent Platform compares six options side by side.
FAQ
Common questions about gemini enterprise agent platform security.
Is Gemini Enterprise Agent Platform the same as Vertex AI?
Yes, in practice. Google announced Gemini Enterprise Agent Platform on April 22, 2026 as the evolution of Vertex AI, and says all Vertex AI services and roadmap work now ship through it. Agent Engine became Agent Runtime, and the vertexai.agent_engines SDK module is in deprecation in favor of the agentplatform client.
What is Agent Gateway in Gemini Enterprise Agent Platform?
Agent Gateway is the enforcement point for agent traffic. It runs in client to agent (ingress) or agent to anywhere (egress) mode, applies IAM access policies against the Agent Registry, calls Model Armor and Semantic Governance, handles mTLS and protocol translation for MCP, REST and gRPC, and defaults to deny for unregistered destinations.
Does Gemini Enterprise Agent Platform protect against prompt injection?
Partly, through two layers. Model Armor screens prompts and tool responses for injection and sensitive data, and Semantic Governance checks whether a proposed tool call still matches the user's intent. Neither is deterministic, and on an ingress gateway the two cannot be combined, so irreversible actions still deserve a separate approval gate.
What are Semantic Governance policies?
They are plain English constraints that a managed policy engine applies to every tool call an agent proposes. The engine compares the call with the user prompt, chat history and your rules, and denies calls that drift from the request or break a constraint, such as a refund above a set amount.
Is Semantic Governance generally available?
No. Semantic Governance policies entered Public Preview on June 29, 2026. Its VPC Service Controls support (September 25, 2026) and built-in monitoring metrics are also Preview. Check the Preview terms before you cite it as a control in a SOC 2 or insurance audit.
Does Agent Gateway support VPC Service Controls?
Yes, since September 8, 2026, with a catch. Google states VPC-SC is only supported for Agent Gateway deployments created after September 8, 2026 that use an agent connectivity template in ALL_TRAFFIC egress mode. Gateways created earlier have to be recreated to enforce the perimeter.
What is the difference between Gemini Enterprise and Gemini Enterprise Agent Platform?
Gemini Enterprise is the employee facing app, formerly Agentspace, where staff use and build agents. Gemini Enterprise Agent Platform is the developer platform, formerly Vertex AI, where teams build, deploy and govern agents with ADK, Agent Runtime and Agent Gateway. Their security models differ, so we cover them on separate pages.
Does AgentShield work with Gemini Enterprise Agent Platform?
Yes. Agents on Agent Runtime, Cloud Run or GKE call tools through an AgentShield MCP gateway endpoint, alongside Google's own gateway. A per-tool, per-argument policy allows, holds or denies each call, held calls go to a named approver, and every decision is logged. Keep Model Armor and Semantic Governance in place.
More use cases