Thales is integrating its AI Security Fabric with Google Cloud Gemini Enterprise to apply security policies to interactions among enterprise users, AI agents, models, data and connected tools. The collaboration centers on controlling what an agent can access, share or do after a user has given it a task.
Gemini Enterprise provides an environment for employees to use AI agents in business workflows. Those agents can retrieve information and act across applications, which creates access-control questions beyond a conventional chatbot response. Thales says its security layer can inspect interactions in real time, enforce organizational rules and give administrators visibility into agent activity. Policies can apply when an agent requests information or invokes a connected tool, not only at the initial employee sign-in.
The controls are intended to limit access to sensitive data and block actions outside an agent’s authorized scope. Thales also lists prompt injection, data leakage, unsafe output and agent-to-agent interactions among the risks the integration addresses. A prompt-injection attack tries to persuade an AI system to follow malicious instructions embedded in content it encounters while doing an otherwise legitimate task.
One example offered by Thales involves an agent handling an insurance claim. If the agent drew on personal information from a source it was not allowed to use, the resulting decision could breach the insurer’s data-handling rules. A policy layer around the agent is meant to prevent that access and record the attempted interaction for review.
The arrangement extends Thales’s existing collaboration with Google Cloud. It ties the company’s AI Security Fabric to a named enterprise agent platform, while leaving the organization using it to define its own policies for data, tools and actions. Google Cloud described the added controls as part of helping customers deploy agents across business systems.
Other identity vendors have been adding controls to agents that act on behalf of people or organizations. Omada acquired EmpowerID to add runtime AI-agent controls, and the FIDO Alliance launched a standards effort for trusted agent authentication. Thales’s integration focuses on enforcing the access boundaries that apply during an agent’s work, including interactions with data and connected tools.
