Google Cloud has added a set of partner‑built security agents to Gemini Enterprise, giving teams a single console to discover, deploy, and orchestrate AI‑enabled defenses across identity, network, endpoint, data, and application layers. The expansion matters because it lets engineers and security operators embed context‑rich, natural‑language‑driven actions directly into their existing Gemini workflows, reducing tool sprawl and response latency.
Unified access to partner security capabilities
All new agents appear in the Gemini Enterprise catalog and are reachable through the same UI and API surface used for other Gemini functions. This includes Acalvio’s ShadowPlex deception agent, Britive’s Emergency Termination agent, Check Point’s AI Defense Plane, CrowdStrike’s Falcon Guardian, Cyberhaven’s Linea data‑lineage agent, Cyera’s Agent Guardian, and Endor Labs’ AURI agents. By registering these services in the Gemini Agent Registry, Google Cloud provides a consistent discovery mechanism and a common execution environment for multi‑step security playbooks.
Practical impact on engineering and operations
Each agent introduces a specific workflow that can be invoked with natural‑language prompts or programmatic calls. For example, the Britive Emergency Termination agent can confirm a compromised identity, list active privileged sessions, revoke them, disable the account, and generate audit context—all from a single request. The Acalvio ShadowPlex agent automates deployment of decoys, honeytokens, and RAG‑based deception assets without manual configuration. Check Point and CrowdStrike agents add runtime guardrails for AI workloads, detecting prompt‑injection attempts and data exposure risks in real time. Cyberhaven’s Linea agent translates plain‑language intent into enforceable data‑classification policies, while Cyera’s Agent Guardian correlates machine identities, permissions, and sensitive data tags to validate agentic behavior.
Architectural considerations
Integrating these agents does not replace existing security tooling; instead, it layers a coordination plane on top of them. Engineers should treat Gemini Enterprise as an orchestration hub that calls out to partner APIs via the Agent Gateway. This implies that network egress, IAM permissions, and service‑account scopes must be configured to allow Gemini to invoke each partner service. Because the agents operate across multiple data domains (network, identity, data lineage), practitioners need to ensure that the underlying data sources are accessible to Gemini’s runtime environment, respecting any existing segmentation or zero‑trust policies.
Operational and security implications
Deploying agents through a unified interface can reduce mean time to containment (MTTC) by eliminating the need to switch consoles, but it also centralizes control, making the Gemini environment a higher‑value target. Teams should monitor access to the Agent Registry, enforce least‑privilege service accounts, and audit agent invocations. The AI‑focused agents (Check Point, CrowdStrike, Cyera) introduce runtime checks for prompt injection and data leakage; operators must validate the false‑positive rate and understand the guardrail actions to avoid unintended service disruption. Finally, the deception capabilities from Acalvio add synthetic assets that must be tracked to prevent accidental interaction by legitimate services.
Related CloudNinjas coverage: Google Cloud.
What This Means For Practitioners
Start by cataloguing which of the new agents align with your current security gaps and map them to existing playbooks. Provision dedicated service accounts with narrowly scoped permissions for each partner integration, and enable audit logging for all Gemini‑initiated calls. Test the natural‑language request flow in a staging environment to verify that agents perform the intended actions without side effects. Finally, incorporate the agents into your incident‑response runbooks, treating Gemini Enterprise as the coordination layer that can trigger deception, identity termination, or AI workload guardrails with a single command.


