Google adds security agents that can act. Their permissions are the crucial test.
New integrations target identity response, deception and controls around AI workloads.
Google is giving corporate security teams more AI agents that can act across their systems, while adding tools intended to protect those same AI systems from manipulation and data exposure.
The September 29 expansion of the Gemini Enterprise security catalog brings together two distinct uses of automation: helping analysts respond to an incident, and defending the AI software increasingly embedded in everyday work.
Google described partner agents that can be invoked from the Gemini Enterprise interface. Acalvio's offering deploys decoys and honeytokens designed to draw suspicious activity into view. Britive's emergency-response agent can identify privileged sessions associated with a compromised identity and, with human approval, revoke them before assembling incident information.
Other integrations focus on AI workloads themselves. Google said Check Point's AI Defense Plane connects with its Agent Gateway and Agent Registry to provide visibility and controls, including defenses against prompt injection and data leakage.
These capabilities are product descriptions from the suppliers. The announcement does not establish how they perform against independent attack testing or how safely a particular customer has configured their access.
The underlying risk is that an agent can do more than produce a misleading answer. Once connected to administrative tools, it may change permissions, terminate sessions or pass information between systems. A mistake can therefore become an operational action rather than remain text on a screen.
OWASP's guidance on excessive agency identifies excessive functionality, permissions and autonomy as security problems for language-model applications. It recommends limiting available tools, assigning the minimum necessary privileges and requiring approval for consequential actions. It also warns that instructions embedded in untrusted material can redirect a system's behavior.
That makes the human approval step in the described identity-response workflow significant, but it is not the whole control system. The downstream service still needs to enforce whose authority the agent is using and which resources that person is allowed to affect.
NIST's guidance for cloud-native zero-trust architectures similarly emphasizes application and service identities alongside user identities. It describes gateways and other enforcement components that apply policies regardless of where a service runs, rather than treating network location as sufficient evidence of trust.
The practical shift in Google's announcement is toward a common place from which teams can coordinate security work and see AI-related controls. That may reduce the need to move between product consoles, but the permissions behind each action remain separate engineering responsibilities.
For organizations adopting the catalog, the decisive capability is not simply whether an agent can execute a response. It is whether the response is authorized, traceable and limited to the intended target when the request, incident data or model output is wrong.