Build zero-trust AI agents that judge intent, not just syntax
Blog post from Google Cloud
Part 2 of the Zero-trust Agents series describes how managed runtime governance on the Gemini Enterprise Agent Platform complements deterministic build-time controls for a customer support and returns agent. It introduces Agent Gateway as an enforcement point for Model Armor, which blocks prompt injections and redacts sensitive response data; Semantic Governance Policies, which use natural-language business rules to evaluate tool calls based on user intent and context; and Agent Anomaly Detection, which analyzes session-level telemetry for suspicious patterns. Using an order containing both a physical accessory and a digital software license, the example shows how these controls block a jailbreak prompt, deny an unauthorized $120 software-license refund requiring manager approval, and detect an attacker splitting refunds into individually permitted $20 requests that collectively exceed the order value. When an anomaly is detected, administrators can add or automate a new runtime policy that prevents further refunds on the same order without changing, rebuilding, or redeploying agent code. The approach emphasizes defense in depth, retaining signed Cloud KMS transactions and sandboxing while adding adaptive controls that assess payloads, intent, and behavior over time.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Zero Trust | 7 | 20 | 10 | 5 | -90% |
| LLM | 3 | 747 | 162 | 79 | -85% |
| MCP | 3 | 2,241 | 148 | 72 | -74% |
| AI Agents | 2 | 931 | 231 | 103 | -84% |
| Agent sandbox | 1 | 21 | 5 | 3 | -68% |
| Secrets Management | 1 | 451 | 99 | 43 | -80% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.