Thales, Google Cloud Target Agentic AI Security Risks

Thales, Google Cloud Strengthen AI Agent Security Thales, Google Cloud Strengthen AI Agent Security

Thales is expanding its collaboration with Google Cloud to address security and governance risks emerging as enterprises deploy autonomous AI agents across business systems. The integration of Thales AI Security Fabric with Google Cloud Gemini Enterprise is designed to provide real-time visibility, policy enforcement and threat protection across interactions between users, agents, models and tools.

Enterprise AI is moving from systems that answer questions to systems that can take action. That shift is creating a security problem that traditional application controls were not designed to handle.

Thales and Google Cloud are expanding their collaboration to address that problem, integrating Thales AI Security Fabric with Google Cloud Gemini Enterprise to provide security, governance and visibility across agentic AI workflows.

The companies’ focus is increasingly relevant as organizations connect autonomous agents to sensitive data, enterprise applications and operational systems. Instead of simply generating content, these agents can reason through tasks, call tools, interact with other agents and make decisions with varying degrees of human oversight.

That creates a larger and more dynamic attack surface.

An AI agent managing an insurance claim, for example, could potentially access information beyond its intended scope or use data from an unauthorized source when making a recommendation. Even if the underlying systems are properly secured, the agent’s ability to combine information and act autonomously introduces another layer of risk.

Thales AI Security Fabric is intended to provide controls around those interactions.

The platform is designed to provide visibility into AI activity, protect sensitive information, detect AI-specific threats and enforce policies governing what agents can access and do. The integration with Gemini Enterprise extends those controls into Google’s enterprise AI environment.

This represents a broader change in AI security architecture. Traditional cybersecurity has generally been built around users, applications, devices and network connections. Agentic AI introduces a new class of non-human actors that can operate dynamically across several of those layers.

The security challenge is therefore not simply determining whether an agent is trusted.

Organizations increasingly need to establish what an agent is permitted to do, what information it can access, which tools it can invoke, whether its actions match the user’s intent and how its behavior changes as it interacts with other agents.

The problem is compounded when agents communicate with one another.

A single autonomous workflow could involve a planning agent delegating tasks to specialized agents for data retrieval, analysis, document generation or transaction processing. Each handoff creates another point where data can be exposed, instructions can be manipulated or an agent can exceed its intended authority.

Thales identifies prompt injection, sensitive-data leakage, unsafe outputs, unauthorized actions and increasingly complex agent-to-agent interactions as key risks its platform is designed to address.

The development comes as enterprises move deeper into agentic AI. Gartner has predicted that 33% of enterprise software applications will include agentic AI capabilities by 2028, up from less than 1% in 2024. Gartner also expects agentic AI to make at least 15% of day-to-day work decisions autonomously by 2028.

Those projections help explain why governance is becoming an infrastructure issue rather than a compliance exercise.

Google Cloud is positioning Gemini Enterprise as a platform for bringing enterprise AI agents into business workflows, while its wider security ecosystem includes identity, data protection and threat detection capabilities. The Thales integration adds another layer focused specifically on the security behavior of AI-driven interactions.

For Thales, the partnership also extends its cybersecurity portfolio into a market increasingly defined by AI agents and autonomous systems. The company already operates across areas including data security, encryption, identity and access management, and cloud security.

The competitive landscape is crowded. Microsoft is integrating AI security controls into its broader Security and Copilot ecosystem, while companies such as Palo Alto Networks, CrowdStrike and Cisco are developing AI-specific protections. Hyperscalers including Google Cloud, Microsoft Azure and Amazon Web Services are simultaneously embedding security into their AI platforms.

The emerging differentiator will be how effectively these approaches can enforce policy without slowing down legitimate automation.

Agentic AI creates a difficult balance. Excessive controls can reduce an autonomous system to a conventional workflow requiring constant approval. Too few controls can allow an agent to make decisions or move information beyond its intended boundaries.

Thales’ approach is to put security controls across the interactions between users, agents, models and tools rather than treating the model as the sole security boundary.

That distinction matters because an AI model is only one component of an agentic system. The agent’s tools, credentials, data sources, memory, orchestration layer and downstream applications can all introduce risk.

For enterprise IT and security teams, this means AI governance is becoming increasingly operational. Security leaders need visibility into what agents are doing, while business teams need confidence that autonomous workflows can execute without exposing sensitive information or violating regulatory requirements.

The Thales-Google Cloud collaboration reflects that transition. Rather than simply adding another AI assistant to enterprise software, organizations are beginning to build security architecture around systems capable of acting independently.

The next phase of enterprise AI adoption may therefore depend less on whether companies can deploy agents and more on whether they can control, observe and govern those agents at scale.

Market Landscape

Agentic AI security is emerging as a distinct enterprise technology category. As AI agents gain access to corporate data, applications and external tools, traditional identity and application security controls must increasingly be supplemented with runtime visibility and policy enforcement.

Gartner’s forecast that one-third of enterprise software applications could include agentic AI by 2028 highlights the scale of the coming transition.

Google Cloud, Microsoft, Amazon and cybersecurity vendors are consequently building security capabilities around AI models, agents, identities, data and tool interactions. Thales’ approach emphasizes a unified security layer across those interactions.

The key market challenge is balancing agent autonomy with organizational control. Enterprises want agents to complete multi-step workflows independently, but they also need clear boundaries around sensitive data, business decisions and external actions.

Top Insights

  • Thales is extending AI security into agentic workflows, where autonomous systems can access data, invoke tools and make decisions without constant human intervention.
  • The Google Cloud integration connects Thales AI Security Fabric with Gemini Enterprise to provide visibility and policy enforcement across AI interactions.
  • Agent-to-agent communication creates additional security challenges because data and instructions can move through increasingly complex autonomous workflows.
  • Runtime controls must balance autonomy and governance, allowing legitimate AI actions while blocking unsafe or unauthorized behavior.
  • As enterprises deploy more agents, AI security is shifting from model protection toward securing the entire agent, data and tool ecosystem.

Power Tomorrow’s Intelligence — Build It with TechEdgeAI

Grow Your
Brand Visibility

Looking to publish a press release, guest article, interview or podcast? Connect with us.

GET FEATURED
Subscribe

Sign up today for exclusive insights and updates.

Newsletter Signup