Google's private preview and reference implementation treat behavior across a session as an operating record that security teams can review and act on.
Primary: private-preview announcementOpenTelemetry becomes an oversight input
Google Developers · 2026-09-16
Agent Anomaly Detection reads logs, OpenTelemetry traces, reasoning traces, tool calls, and execution flow for agents on Gemini Enterprise Agent Platform. The service analyzes them asynchronously outside the live request path.
Read the original source →Primary: private-preview announcementA finding can change the next turn
Google Developers · 2026-09-16
Findings carry severity, rationale, and recommended action, and also appear in Security Command Center. An API lets a callback or plugin block later tool calls or halt a later turn when a threshold is crossed. That is follow-on enforcement, not proof that the first harmful action was prevented.
Read the original source →Primary: engineering reference patternThree controls cover different failure modes
Google Developers · 2026-09-15
Google's zero-trust pattern combines Model Armor for prompt and response screening, semantic governance policies for intent-aware tool decisions, and anomaly detection for behavior across multiple turns.
Read the original source →Primary: engineering reference patternSecurity policy sits outside the agent code
Google Developers · 2026-09-15
The platform enforces policies separately from the application, so a security administrator can change a tool constraint without rebuilding the agent. The companion demo shows how a series of individually allowed refunds can become an anomalous session; its confidence values and finding payloads are illustrative.
Read the original source →