Thales is integrating its AI Security Fabric with Google Cloud Gemini Enterprise to apply security policies to interactions among enterprise users, AI agents, models, data and connected tools. The collaboration centers on controlling what an agent can access, share or do after a user has given it a task.

Gemini Enterprise provides an environment for employees to use AI agents in business workflows. Those agents can retrieve information and act across applications, which creates access-control questions beyond a conventional chatbot response. Thales says its security layer can inspect interactions in real time, enforce organizational rules and give administrators visibility into agent activity. Policies can apply when an agent requests information or invokes a connected tool, not only at the initial employee sign-in.

The controls are intended to limit access to sensitive data and block actions outside an agent’s authorized scope. Thales also lists prompt injection, data leakage, unsafe output and agent-to-agent interactions among the risks the integration addresses. A prompt-injection attack tries to persuade an AI system to follow malicious instructions embedded in content it encounters while doing an otherwise legitimate task.

One example offered by Thales involves an agent handling an insurance claim. If the agent drew on personal information from a source it was not allowed to use, the resulting decision could breach the insurer’s data-handling rules. A policy layer around the agent is meant to prevent that access and record the attempted interaction for review.

The arrangement extends Thales’s existing collaboration with Google Cloud. It ties the company’s AI Security Fabric to a named enterprise agent platform, while leaving the organization using it to define its own policies for data, tools and actions. Google Cloud described the added controls as part of helping customers deploy agents across business systems.

Other identity vendors have been adding controls to agents that act on behalf of people or organizations. Omada acquired EmpowerID to add runtime AI-agent controls, and the FIDO Alliance launched a standards effort for trusted agent authentication. Thales’s integration focuses on enforcing the access boundaries that apply during an agent’s work, including interactions with data and connected tools.


More

Tech Times: Visa Payment Passkey Goes Live at Five India State Banks: OTP Attack Surface Eliminated

India’s five-decade-old authentication habit — waiting for a six-digit code on a phone — got…

Read More →

FinTech Futures: Sibos 2026: Digital finance in an AI-driven economy – when the agent does the buying, who owns the customer?

By shaping the standards of identity, control, and compliance today, financial institutions can ensure they…

Read More →

Payments Dive: FIDO wrestles with agentic trust

The industry consortium and payments players are considering standards for agentic commerce, particularly for verifying…

Read More →


Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.