Thales is integrating its AI Security Fabric with Google Cloud Gemini Enterprise to apply security policies to interactions among enterprise users, AI agents, models, data and connected tools. The collaboration centers on controlling what an agent can access, share or do after a user has given it a task.

Gemini Enterprise provides an environment for employees to use AI agents in business workflows. Those agents can retrieve information and act across applications, which creates access-control questions beyond a conventional chatbot response. Thales says its security layer can inspect interactions in real time, enforce organizational rules and give administrators visibility into agent activity. Policies can apply when an agent requests information or invokes a connected tool, not only at the initial employee sign-in.

The controls are intended to limit access to sensitive data and block actions outside an agent’s authorized scope. Thales also lists prompt injection, data leakage, unsafe output and agent-to-agent interactions among the risks the integration addresses. A prompt-injection attack tries to persuade an AI system to follow malicious instructions embedded in content it encounters while doing an otherwise legitimate task.

One example offered by Thales involves an agent handling an insurance claim. If the agent drew on personal information from a source it was not allowed to use, the resulting decision could breach the insurer’s data-handling rules. A policy layer around the agent is meant to prevent that access and record the attempted interaction for review.

The arrangement extends Thales’s existing collaboration with Google Cloud. It ties the company’s AI Security Fabric to a named enterprise agent platform, while leaving the organization using it to define its own policies for data, tools and actions. Google Cloud described the added controls as part of helping customers deploy agents across business systems.

Other identity vendors have been adding controls to agents that act on behalf of people or organizations. Omada acquired EmpowerID to add runtime AI-agent controls, and the FIDO Alliance launched a standards effort for trusted agent authentication. Thales’s integration focuses on enforcing the access boundaries that apply during an agent’s work, including interactions with data and connected tools.


More

Biometric Update: Agents are going rogue, and it’s up to the identity sector to govern them

The AI apocalypse is trending. Warnings are flying that continuing to develop AI technology at the current…

Read More →

WiredGov: How we made it easier for millions of users to sign into government services

This month, the Government Digital Service (GDS) made it faster, easier and more secure to…

Read More →

Biometric Update: UK rolls out passkeys for GOV.UK One Login

The UK government is expanding passkey sign-in for GOV.UK One Login after an initial trial.…

Read More →


Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.