Google Publishes Zero-Trust Agents Part 2 With Open-Source Runtime Governance Demo
On September 15, 2026, Google’s Developers Blog published Part 2 of its Zero-trust Agents series, covering Model Armor, Semantic Governance Policies, and Agent Anomaly Detection, with an open-source companion demo under GoogleCloudPlatform/generative-ai.
Google published Part 2 of its Zero-trust Agents series on September 15, 2026, shifting from build-time Agent Development Kit controls to managed runtime governance on the Gemini Enterprise Agent Platform. Authors Eric Dong and Shubham Saboo describe three platform controls enforced through Agent Gateway: Model Armor for prompt/response screening, Semantic Governance Policies for intent-aware tool-call checks, and Agent Anomaly Detection with closed-loop remediation for multi-turn abuse patterns.
The post keeps the same Customer Support and Returns Agent scenario from Part 1 and shows how syntax-valid refunds can still violate business rules or drain a ledger across turns. Platform examples reference Cloud KMS–signed refunds, Agent Sandbox for model-generated fee logic, and Security Command Center–style anomaly findings. Illustrative detector names and sample finding JSON in the post are labeled as illustrative in the source.
Open-source companion
All code, policy declarations, and interactive simulators ship in the open-source companion demo zero-trust-agents-2 under GoogleCloudPlatform/generative-ai at agents/adk/zero-trust-agents-2/. Google says the companion runs locally without external dependencies, with a four-act CLI demo, a simple HTTP dashboard, and a unit-test suite. This brief summarizes the published architecture and demo location only—it does not provide attack reproduction steps.
Primary source is the September 15 Google Developers Blog post and the linked zero-trust-agents-2 path in the generative-ai repository.
- #Cyber Security
- #AI Agents
- #Opensource
Author
Raj M
Contributor
AI Systems Architect is a seasoned technology leader with over 15 years of experience in the IT industry working with Fortune 500 companies. With a solid foundation in multi-agent systems, open-source LLM infrastructure, and enterprise deployment, he excels at building scalable production-grade AI platforms.