Thales Expands Its Google Cloud Alliance to Protect AI Agents

Thales AI Security Fabric integration with Google Cloud Gemini Enterprise for AI agent security

Thales has expanded its collaboration with Google Cloud to strengthen the security of workflows based on agentic artificial intelligence (AI). The integration of Thales AI Security Fabric with Google Cloud Gemini Enterprise aims to provide greater visibility and control over communications between users, AI agents, models, corporate data and tools, with security policies applied in real time.

Agentic AI security in 20 seconds

  • Thales integrates its AI Security Fabric platform with Google Cloud Gemini Enterprise.
  • The solution aims to control what data agents can access, what information they share and what actions they can execute.
  • The risks addressed include malicious prompt injection, data leaks and unauthorized actions.
  • The collaboration aims to make it easier for enterprises to deploy autonomous agents with security controls, visibility and governance.

The initiative responds to a shift in how companies use AI. Traditional assistants are usually limited to answering queries or generating content, while agents can make decisions and act on corporate systems. That capability expands automation possibilities, but it also requires reviewing each system’s permissions, available data and operating limits — a push also visible in other vendors’ moves, such as Broadcom’s AgentMinder for controlling what AI agents can do.

Thales places security at the interactions that occur during these processes. Rather than focusing solely on protecting an application or a model, AI Security Fabric aims to monitor the relationships between the different components involved in an automated workflow.

What risks Thales AI Security Fabric aims to control

The integration is designed to help companies manage threats specific to agentic systems. Thales identifies several risks: malicious prompt injection, exposure of sensitive information, insecure responses and actions an agent executes without authorization. It also addresses the complexity of communications between different agents.

These issues can arise when an agent is given access to corporate data or tools capable of modifying information and executing operations. If its permissions are not properly scoped, it could use information outside the intended scope or carry out actions that don’t comply with the organization’s policies.

The example Thales gives is an insurer that uses agents to process claims. An agent responsible for handling claims could draw on personal information from unapproved sources to influence a compensation amount. That behavior would create risks related to privacy and regulatory compliance.

AI Security Fabric aims to set up controls around agents to limit access to authorized data and block inappropriate actions in real time. The goal is for systems to complete legitimate tasks without exceeding the limits defined by the company.

The company also highlights AI-specific threat detection and monitoring of agent behavior, an approach that echoes Salt Security’s recent expansion of AI agent oversight with CrowdStrike. The information available doesn’t specify which detection models it uses, what metrics it offers or what results it has achieved in independent tests. The announcement therefore describes the capabilities planned for the integration, but doesn’t provide figures to measure its effectiveness against specific attacks.

Visibility and governance for deploying agents in the enterprise

The collaboration with Google Cloud aims to cover different phases of the AI systems’ lifecycle. According to Thales, AI Security Fabric makes it possible to discover and assess AI-related risks, protect sensitive information, help prevent unauthorized actions and verify that system activity complies with corporate policies and user intent.

The platform also includes centralized governance and compliance support features. These capabilities aim to give security leaders and business areas a broader view of how agents are used and what limits they must respect.

Visibility becomes especially important when several agents interact with each other or use different tools to complete a task. In these scenarios, controlling only the initial request may not be enough to understand every operation that takes place during the process. Thales’s proposal is to apply controls to the interactions between users, agents, models and tools.

However, the announcement doesn’t specify which logs will be available, how policies will be integrated with each corporate application or what configuration options administrators will have. Nor does it detail the technical mechanisms used to block each type of action. These details will be necessary to assess how the solution fits environments with specific security and compliance requirements.

For Google Cloud, the collaboration is part of the goal of making it easier to move from experimental testing to deploying agents in business processes. Vineet Bhan, director of security and identity partnerships at Google Cloud, said organizations need to build security and governance into how these systems operate, especially when they access critical information and applications.

Eva Rudin, senior vice president of cybersecurity products at Thales, likewise argued that deploying agents capable of acting autonomously requires a security approach tailored to their capabilities.

The expanded collaboration thus places agent protection at the center of enterprise AI adoption. The announcement, however, doesn’t include information on pricing, availability dates, licensing requirements or differences between deployment options. Nor does it identify specific sectors where the integration is already operational.

Frequently asked questions

What is Thales AI Security Fabric?

It’s a security platform for artificial intelligence systems that aims to provide visibility and control over data access, interactions between agents and the actions they execute.

Which Google Cloud service does it integrate with?

The announced collaboration involves integrating Thales AI Security Fabric with Google Cloud Gemini Enterprise to apply security and governance controls to AI workflows.

What threats does it aim to reduce?

The solution is designed to help control risks such as malicious prompt injection, leaks of sensitive information, insecure responses and unauthorized actions.

How does it help protect autonomous agents?

It aims to set policies on their interactions, limit access to information and tools, detect threats and provide visibility into agent behavior.

Scroll to Top