Thales is integrating its AI Security Fabric with Google Cloud Gemini Enterprise to apply security policies to interactions among enterprise users, AI agents, models, data and connected tools. The collaboration centers on controlling what an agent can access, share or do after a user has given it a task.

Gemini Enterprise provides an environment for employees to use AI agents in business workflows. Those agents can retrieve information and act across applications, which creates access-control questions beyond a conventional chatbot response. Thales says its security layer can inspect interactions in real time, enforce organizational rules and give administrators visibility into agent activity. Policies can apply when an agent requests information or invokes a connected tool, not only at the initial employee sign-in.

The controls are intended to limit access to sensitive data and block actions outside an agent’s authorized scope. Thales also lists prompt injection, data leakage, unsafe output and agent-to-agent interactions among the risks the integration addresses. A prompt-injection attack tries to persuade an AI system to follow malicious instructions embedded in content it encounters while doing an otherwise legitimate task.

One example offered by Thales involves an agent handling an insurance claim. If the agent drew on personal information from a source it was not allowed to use, the resulting decision could breach the insurer’s data-handling rules. A policy layer around the agent is meant to prevent that access and record the attempted interaction for review.

The arrangement extends Thales’s existing collaboration with Google Cloud. It ties the company’s AI Security Fabric to a named enterprise agent platform, while leaving the organization using it to define its own policies for data, tools and actions. Google Cloud described the added controls as part of helping customers deploy agents across business systems.

Other identity vendors have been adding controls to agents that act on behalf of people or organizations. Omada acquired EmpowerID to add runtime AI-agent controls, and the FIDO Alliance launched a standards effort for trusted agent authentication. Thales’s integration focuses on enforcing the access boundaries that apply during an agent’s work, including interactions with data and connected tools.


More

The Paypers: You can now meet PSD2 authentication requirements while improving user experience

In this article in The Paypers, FIDO Alliance Executive Director Brett McDowell explains how FIDO…

Read More →

Harvard Business Review: 8 Ways Governments Can Improve Their Cybersecurity

This article in Harvard Business Review lays out 8 principles that governments around the world…

Read More →

Mobile ID World: New Batch of FIDO Certified Products Brings Total to 335

Mobile ID World reports that there are now more than 300 FIDO Certified products, showing…

Read More →


Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.