Thales is integrating its AI Security Fabric with Google Cloud Gemini Enterprise to apply security policies to interactions among enterprise users, AI agents, models, data and connected tools. The collaboration centers on controlling what an agent can access, share or do after a user has given it a task.

Gemini Enterprise provides an environment for employees to use AI agents in business workflows. Those agents can retrieve information and act across applications, which creates access-control questions beyond a conventional chatbot response. Thales says its security layer can inspect interactions in real time, enforce organizational rules and give administrators visibility into agent activity. Policies can apply when an agent requests information or invokes a connected tool, not only at the initial employee sign-in.

The controls are intended to limit access to sensitive data and block actions outside an agent’s authorized scope. Thales also lists prompt injection, data leakage, unsafe output and agent-to-agent interactions among the risks the integration addresses. A prompt-injection attack tries to persuade an AI system to follow malicious instructions embedded in content it encounters while doing an otherwise legitimate task.

One example offered by Thales involves an agent handling an insurance claim. If the agent drew on personal information from a source it was not allowed to use, the resulting decision could breach the insurer’s data-handling rules. A policy layer around the agent is meant to prevent that access and record the attempted interaction for review.

The arrangement extends Thales’s existing collaboration with Google Cloud. It ties the company’s AI Security Fabric to a named enterprise agent platform, while leaving the organization using it to define its own policies for data, tools and actions. Google Cloud described the added controls as part of helping customers deploy agents across business systems.

Other identity vendors have been adding controls to agents that act on behalf of people or organizations. Omada acquired EmpowerID to add runtime AI-agent controls, and the FIDO Alliance launched a standards effort for trusted agent authentication. Thales’s integration focuses on enforcing the access boundaries that apply during an agent’s work, including interactions with data and connected tools.


More

Biometric Update: Yubico hackathon to preview YubiKey 5.8 support for next-generation passkeys

Yubico will host a virtual developer hackathon for the FIDO Alliance developer community on August 5…

Read More →

PYMNTS: Mastercard Wants to Teach AI Agents How to Spend

For nearly 60 years, Mastercard has answered one question over and over. How do you get two…

Read More →

Biometric Update: EMVCo proposes global schema for verifiable digital payment credentials

EMVCo has put a draft framework out for consultation that aims to bring verifiable digital credentials…

Read More →


Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.