Policy
REGULATION WATCH:

Google Cloud Adds Agent-Level Perimeters For Enterprise AI Workloads

Newsroom brief

Google Cloud has added VPC Service Controls features for agentic AI, including agent identities in perimeter rules, MCP attribute controls and native protection for Gemini Enterprise Agent Platform instances.

Verified against source materialEdited by SendTech Times Cloud & Infrastructure Desk
Google Cloud Adds Agent-Level Perimeters For Enterprise AI Workloads
Image source: Google Cloud

Google Cloud Extends VPC Service Controls To Agents

Google Cloud has added VPC Service Controls capabilities for agentic AI workloads, giving enterprises more granular perimeter controls as autonomous agents connect to tools, datasets and cloud services.

The update treats agent identity as a first-class control point.

Administrators can place agentic identities inside service perimeter ingress and egress rules through standard IAM principals.

A single principal can map to one agent, while a principalSet can apply consistent and auditable access policies across a fleet of agents.

Google Cloud says the design lets administrators revoke a compromised agent's access at the network perimeter.

That changes the control model for enterprise AI teams because agent access is no longer governed only by broad service accounts or application-level permissions.

MCP Attributes Narrow Tool Access

The update also brings Model Context Protocol attributes into VPC Service Controls.

Conditional access rules can now use fields such as mcp.toolName, mcp.method and mcp.tool.isReadOnly.

Google Cloud used a Workspace MCP example to explain the boundary.

An organization could grant an agent read access to a Workspace MCP server while denying the ability to send emails.

The example is narrow, but it addresses a common enterprise concern: agents may need to inspect information without gaining permission to trigger actions that move data or contact external parties.

VPC Service Controls is also now natively integrated with the Gemini Enterprise Agent Platform.

When administrators include Agent Platform as a protected service inside a VPC-SC perimeter, public internet access to that Agent Platform instance is blocked without extra configuration overhead.

Perimeters Address Data Movement, Not Just Identity

Google Cloud framed the product update as a layered AI security model.

IAM and Principal Access Boundaries govern who can access resources.

Next-generation network firewalls and VPC Service Controls govern data movement across boundaries.

Organization Policy and other resource controls set broader configuration limits.

The distinction matters for agentic workloads because agents can follow prompts, call tools and trigger cloud operations.

A compromised agent may still hold valid IAM credentials, so an identity check alone may not identify an abnormal action.

The company described three threat scenarios mapped to the OWASP Top 10 for LLM Applications.

In one case, an indirect prompt injection tries to make an agent summarize internal data and send it to an external webhook.

VPC-SC blocks the API-layer transfer when the destination sits outside the defined perimeter.

Enterprise AI Teams Still Need Deployment Discipline

The update gives cloud security teams more precise enforcement around AI agents, but it does not remove the work of defining perimeters, mapping agent identities and deciding which tools should be read-only.

It also does not replace IAM, firewalls or organization policies; Google Cloud positions VPC-SC as the destination-based layer among those controls.

Mercado Libre project lead Juan Pablo Boschi said the company uses VPC Service Controls across hundreds of Google Cloud projects to maintain network-level security controls and keep data protected in its cloud environment.

For CIOs and security teams, the remaining implementation burden is concrete: each production agent needs a mapped identity, a perimeter rule, an MCP tool policy where relevant and a destination boundary that blocks data movement outside approved projects.

Share this article
inXf

Related articles

More
Pinecone And Tiger Data Target AI Agent Costs In The Data Layer
Cloud & Data Centers

Pinecone And Tiger Data Target AI Agent Costs In The Data Layer

Pinecone and Tiger Data are pitching data infrastructure as a way to control agentic AI costs, as IDC says 79 percent of organizations are already funding or running agentic AI work.

Vercel’s Eve Framework Tests Whether Agent Tools Can Escape Shadow AI
Cloud & Data Centers

Vercel’s Eve Framework Tests Whether Agent Tools Can Escape Shadow AI

Vercel introduced the open-source eve agent framework and Passport controls for employee-built AI apps, putting its developer platform strategy up against enterprise concerns over unmanaged agents, data exposure and cloud cost premiums.

Philippines Google Cloud Deal Links Agentic AI To Public Services And Data Routes
AI

Philippines Google Cloud Deal Links Agentic AI To Public Services And Data Routes

The Philippine government has expanded its Google Cloud collaboration to bring enterprise AI into public services while tying the work to cyberdefense cooperation and links between subsea cable systems and domestic networks.

Railway Raises $100 Million For AI-Native Cloud Buildout
Cloud & Data Centers

Railway Raises $100 Million For AI-Native Cloud Buildout

Railway raised $100 million in Series B funding led by TQ Ventures as the developer cloud platform expands its own data-center footprint and pitches faster deployment for AI-generated software.

Keep Reading

More Stories

Latest
BMW i Ventures Puts $300 Million Fund Behind Physical AI StartupsAIJun 27, 2026BMW i Ventures Puts $300 Million Fund Behind Physical AI StartupsBMW i Ventures launched Fund III with $300 million for physical AI, agentic AI, industrial software, manufacturing technology and advanced materials, lifting total capital under management to $1.1 billion.Microsoft Puts Agentic Cloud Ops Behind Azure Copilot And FinOps ToolsAIJun 27, 2026Microsoft Puts Agentic Cloud Ops Behind Azure Copilot And FinOps ToolsMicrosoft said Azure Copilot observability agent is generally available and Azure Resource Manager MCP Server is in public preview, tying agentic cloud operations to governance, cost visibility and human approval.AWS Lambda MicroVMs Add Stateful Sandboxes For AI-Generated CodeCloud & Data CentersJun 27, 2026AWS Lambda MicroVMs Add Stateful Sandboxes For AI-Generated CodeAWS has introduced Lambda MicroVMs for isolated, stateful execution environments, giving developers Firecracker-backed sandboxes for user- or AI-generated code with runtime, region and resource limits.FCA Links Agentic Finance To Tokenisation And Third-Party RiskFintech & Digital PaymentsJun 27, 2026FCA Links Agentic Finance To Tokenisation And Third-Party RiskFCA chief executive Nikhil Rathi said AI is moving financial markets faster than traditional rulemaking, with agentic systems, tokenisation and third-party model dependence reshaping supervision.Tipalti Targets Future IPO As AI Tools Pressure Finance TeamsFintech & Digital PaymentsJun 27, 2026Tipalti Targets Future IPO As AI Tools Pressure Finance TeamsTipalti president Rob Israch said the finance-automation company expects sustained profitability by early 2027, while customers push for AI tools inside payments, procurement and expense workflows.OpenAI IPO Talk Runs Ahead Of Investor Meetings And TimetableAIJun 27, 2026OpenAI IPO Talk Runs Ahead Of Investor Meetings And TimetableOpenAI has confidentially filed with the SEC, but people familiar with the company say it has not held pre-IPO investor meetings or set an official listing timetable.Apple Seeks US Clearance For CXMT Memory As Chip Prices RiseChips & SemiconductorsJun 27, 2026Apple Seeks US Clearance For CXMT Memory As Chip Prices RiseApple is seeking US clearance to buy memory chips from CXMT, a Chinese supplier on a Pentagon blacklist, after higher memory and storage chip prices pushed up costs for several Macs and iPads.Unconventional AI Tests Oscillator Models Before Power-Efficient Chip ProofChips & SemiconductorsJun 27, 2026Unconventional AI Tests Oscillator Models Before Power-Efficient Chip ProofUnconventional AI has released the Un-0 model series to test oscillator-based image generation, but the work still runs on simulated oscillators rather than a physical AI accelerator.IBM, Red Hat And Deloitte Put Lightwell On Regulated Open-Source Patch WorkCybersecurityJun 27, 2026IBM, Red Hat And Deloitte Put Lightwell On Regulated Open-Source Patch WorkDeloitte is joining IBM and Red Hat’s Lightwell initiative to map open-source components, validate patches and support regulated software supply chains, backed by IBM and Red Hat’s $5 billion commitment.Securitize SPAC Deal Targets $400 Million Before NYSE ListingCrypto/Web3Jun 27, 2026Securitize SPAC Deal Targets $400 Million Before NYSE ListingSecuritize expects about $400 million in gross proceeds from its Cantor Equity Partners II merger, with a July 1, 2026 closing and July 2, 2026 NYSE listing still subject to shareholder approval.Zhipu GLM 5.2 Pressures Frontier AI Labs As Access Limits BiteAIJun 27, 2026Zhipu GLM 5.2 Pressures Frontier AI Labs As Access Limits BiteZhipu’s open-source GLM 5.2 is being pitched as a lower-cost enterprise alternative after landing near Anthropic’s Opus 4.8 on an agentic benchmark while frontier model access faces government limits.Copper ME Gets ADGM Approval Step, But Final FSRA Authorisation Still PendingCrypto/Web3Jun 27, 2026Copper ME Gets ADGM Approval Step, But Final FSRA Authorisation Still PendingCopper ME has received in-principle approval from ADGM’s FSRA to expand regulated digital-asset activities, with custody, settlement, collateral management and tokenised fund brokerage still subject to final authorisation.