Skip to content
08Google Cloud governance

The governance problem first — then the products that answer it.

Google's posture in one line: publish the frameworks (AI Principles, Frontier Safety Framework, SAIF 2.0), then ship governance as configurable platform primitives — allowlists in the resource hierarchy, screening floors in the request path, identity down to individual agents — under a “shared fate” posture with contractual commitments: no training on your data without permission, and IP indemnification for covered generative services.

Naming update sellers must get right (2025–2026)
Say this nowFormerly
Gemini Enterprise Agent PlatformVertex AI (the builder platform; APIs unchanged)
Gemini EnterpriseAgentspace (the employee-facing agent workplace)
Agent RuntimeVertex AI Agent Engine
Agent SearchVertex AI Search
Knowledge CatalogDataplex Universal Catalog

Two brands are easily confused: Gemini Enterprise is what employees use; the Agent Platform is what builders use. Customers' internal runbooks referencing old names need an update pass — a genuine consulting opening.

The capability map

Every capability, mapped to the layer it governs.

Filter by layer. Each card names the governance problem the capability solves — not just what it is — with its status and a link to official documentation.

Filter by layer to see which capabilities answer which governance question. Cards link to official docs.

Model Garden

GA

Gemini Enterprise Agent Platform (formerly Vertex AI)

Curated catalog of 200+ Google, open, and partner models.

One vetted front door for model supply instead of ungoverned model sprawl.

3

Model allowlisting (org policy)

GA

Organization Policy

vertexai.allowedGenAIModels restricts which models any project may call.

Central model approval enforced preventively across the resource hierarchy.

13

Model Registry

GA

Gemini Enterprise Agent Platform

Central inventory of customer models: versions, aliases, lineage.

Version control and audit trail for first-party and tuned models.

3

Version pinning & retirement policy

GA

Gemini models

Pinned stable versions with published retirement dates.

Managed change control against silent provider model churn.

3

Gen AI evaluation service

GA

Gemini Enterprise Agent Platform

Computation and LLM-as-judge metrics for models, apps, and agents.

Documented pre-deployment quality gates and regression evidence.

34

Agent evaluation & simulation

Preview

Gemini Enterprise Agent Platform

Multi-turn autoraters, live-traffic evals, pre-deploy simulation.

Continuous quality governance for agent behavior, not just model output.

35

Model Armor

GA

Security

Model-agnostic screening of prompts and responses, with org-wide floor settings.

Prompt injection, jailbreaks, sensitive-data leakage, and unsafe content — one policy over any model.

456

Gemini safety filters

GA

Gemini models

Configurable harm-category thresholds plus non-configurable core filters.

Baseline content safety per request, tunable per use case.

46

Grounding with Google Search & your data

GA

Gemini Enterprise Agent Platform

Citation-bearing answers grounded in Search or approved corpora.

Hallucination reduction with attributable, checkable sources.

4

Agent Search (formerly Vertex AI Search)

GA

Gemini Enterprise Agent Platform

Enterprise RAG with ACL-aware retrieval and grounded generation.

Answers constrained to approved documents, honoring existing permissions.

24

Apigee as AI gateway

GA

Apigee

Token quotas, semantic caching, model routing, Model Armor policies inline.

One governed front door for every model consumer — including non-Google models.

46

AI/ML Privacy Commitment

GA

Contractual

Customer data is not used to train Google models without permission.

The first procurement blocker, answered contractually rather than by policy blog.

12

Sensitive Data Protection (Cloud DLP)

GA

Security

Discovery, classification, and de-identification across 150+ infotypes.

PII/PHI kept out of training data, prompts, responses, and logs.

26

VPC Service Controls

GA

Security

Service perimeters around AI APIs block exfiltration paths.

Keeps AI workloads inside a data perimeter, including partner-model calls.

26

Customer-managed encryption keys

GA

Security

Customer key custody over platform resources, tuning artifacts, agent state.

Key control and crypto-shredding for regulated and sovereign workloads.

2

Data residency & zero-data-retention

GA

Gemini Enterprise Agent Platform

Regional endpoints for in-region processing; ZDR by disabling the 24h cache.

Residency and retention posture as explicit configuration, per model.

2

Knowledge Catalog (formerly Dataplex Universal Catalog)

GA

Data governance

Unified catalog and automatic lineage across data and AI assets.

The map auditors ask for: which data trained which model behind which decision.

2

Access Transparency & Access Approval

GA

Security

Logs — and approval gates — for Google-personnel access to customer content.

Provider-insider assurance regulators increasingly ask about.

26

Security Command Center AI Protection

GA

Security Command Center

AI inventory discovery, virtual red teaming, AI/agent threat detection.

AI security posture management — including shadow AI inside your cloud.

16

IAM & workload identity

GA

Identity

Least-privilege roles for models, endpoints, tuning, and agents.

Who may build, deploy, call, and administer AI — enforced, not documented.

46

Cloud Audit Logs + request-response logging

GA

Observability

Immutable admin logs; opt-in data-access and prompt/response logging.

Forensic trail for AI usage — with content logging as a deliberate choice.

16

OpenTelemetry GenAI observability

GA

Observability

Standardized traces for model calls, tool calls, and agent reasoning.

Vendor-neutral audit and telemetry format across the AI estate.

56

Budgets, quotas & Provisioned Throughput

GA

FinOps

Billing budgets, dynamic shared quota, reserved generative throughput.

Cost governance for AI — runaway spend is a governance failure too.

16

Agent Development Kit (ADK)

GA

Agent stack

Open-source agent framework, auto-instrumented with OTel.

Standardized, observable agent construction instead of bespoke loops.

5

Agent Runtime (formerly Vertex AI Agent Engine)

GA

Agent stack

Managed agent execution with Sessions and Memory Bank, CMEK-protected.

An auditable, controlled place for agents — and their memory — to live.

5

Agent Identity

Preview

Agent stack

A cryptographic SPIFFE-based identity per agent, mapped to IAM.

Attribution and least privilege for the agent itself, not just its human.

56

Agent Registry

Preview

Agent stack

Fleet-wide inventory of agents with enable/disable control.

Agent allowlisting, discovery, and a kill switch that actually exists.

15

Agent Gateway

Preview

Agent stack

Policy enforcement point for agent tool and MCP traffic, Model Armor inline.

Chokepoint governance of tool calls — the riskiest thing agents do.

56

Agent Sandbox (gVisor)

Preview

Agent stack / GKE

Kernel-isolated execution for agent-generated code and computer use.

Contains what an agent executes so a bad plan cannot touch the host.

56

Agent2Agent protocol (A2A)

GA

Open standard

Linux Foundation agent-interop standard; v1.0 with signed Agent Cards.

Cross-vendor agent discovery, identity, and communication without lock-in.

5

Agent Payments Protocol (AP2)

Announced

Open standard

Cryptographically signed intent, cart, and payment mandates for agent purchases.

Non-repudiable authorization and spend limits for agent transactions.

5

Gemini Enterprise (formerly Agentspace)

GA

Employee AI

The governed employee agent workplace over enterprise data.

A sanctioned alternative good enough to out-compete shadow AI.

57

Workspace AI control center

GA

Google Workspace

Per-OU Gemini controls, DLP/IRM exclusions, context-aware access.

Granular employee-AI rollout that honors existing document permissions.

7

Chrome Enterprise Premium

GA

Endpoint

Browser DLP over AI sites: paste, upload, and URL controls.

Shadow AI at the endpoint — governs what leaves the browser to any AI tool.

67

ISO/IEC 42001 certification

GA

Compliance

Accredited AI-management-system certification covering the platform.

Independent attestation your vendor governs AI the way it claims.

1

FedRAMP High & HIPAA eligibility

GA

Compliance

Generative AI authorized at FedRAMP High; HIPAA-eligible under BAA.

Regulated-sector eligibility for gen AI — with configuration duties intact.

1

Audit Manager

GA

Compliance

Automated control assessment and evidence collection for AI workloads.

Continuous compliance evidence against ISO 42001, NIST AI RMF, EU AI Act.

1

Assured Workloads & sovereign controls

GA

Compliance

Regulated control packages, EU boundary, sovereign partner operation.

A compliant deployment envelope for AI in regulated jurisdictions.

12

Google Distributed Cloud air-gapped

GA

Sovereign

Gemini on-prem with no connectivity to Google; IL5/IL6-class isolation.

Sovereign and classified AI where data can never leave the perimeter.

12

Generative AI indemnification

GA

Contractual

Two-pronged IP indemnity: training data and generated output.

Shifts copyright-infringement risk for covered services to Google.

13
How it fits together

Four reference architectures.

The capabilities compose into four repeatable shapes. Each is anchored to a public customer pattern from the examples library.

R1Rolling AI out to the whole workforce without feeding shadow AI

Governed employee AI

Workspace AI controls per OU → label/IRM exclusions keep crown jewels out of retrieval → context-aware access gates AI surfaces by device → Gemini Enterprise as the governed agent storefront with admin allowlists → Chrome Enterprise Premium coaches or blocks paste/upload to unsanctioned AI → usage audit logs to Cloud Logging.

The Macquarie pattern: training-gated, bank-wide rollout on an already-governed foundation.

R2Customer-facing or high-stakes apps on the Agent Platform

Governed custom application

Org-policy model allowlist pins approved models → VPC-SC perimeter + CMEK + regional endpoints set the data envelope → Model Armor floor guarantees screening; advanced Sensitive Data Protection de-identifies both directions and the logs → Gen AI evaluation gates every prompt/model change in CI → Data Access audit logs + opt-in redacted request/response logging → Provisioned Throughput reserves production capacity.

The Deutsche Bank / Commerzbank shape: evals as the compliance artifact, prompts logged and queryable.

R3Agents that act on systems, data, and money

Governed agent fleet

Agents built in ADK (OTel-instrumented) → evaluated and simulated pre-deploy → run in Agent Runtime with CMEK-protected Sessions/Memory Bank → each holds a SPIFFE-based Agent Identity mapped to IAM → every tool/MCP call traverses the Agent Gateway with Model Armor inline → untrusted code executes in the gVisor Agent Sandbox → Agent Registry is the inventory and kill switch → SCC AI Protection watches posture, anomalies, and attack paths.

SAIF 2.0's three agent principles rendered as products: human controllers, limited powers, observable actions.

R4Enterprises running Gemini alongside OpenAI, Anthropic, and self-hosted models

AI gateway over a multi-vendor estate

Apigee as the single AI front door: per-consumer token quotas, semantic caching, model routing/failover, analytics for chargeback → Model Armor invoked as a gateway policy so injection/leakage screening is uniform across providers → the load balancer chains Cloud Armor and Service Extensions so even non-Apigee traffic (agents, MCP) gets screened → SCC watches the whole estate.

The Goldman/Walmart pattern with managed parts: governance written once at the gateway, inherited by every app.

Credibility section

Honest gaps and shared responsibility.

A governance story earns trust by naming its own limits. These are the ones to say before the customer finds them.

  • GenAI drift monitoring is not a turnkey product — Model Monitoring covers predictive models; for LLMs you assemble continuous evaluation plus dashboards.
  • Model allowlisting governs Model Garden models, not arbitrary self-hosted weights on GKE/GCE — open weights are deliberately outside the control plane.
  • Gemini's native safety filters do not apply to partner models (Claude, Llama). The cross-model control is Model Armor — position it that way, and note it adds latency and, for advanced inspection, cost.
  • Audit logs never contain prompts. Content-level audit means deliberately enabling request-response logging — then you own retention, access, and PII handling (mitigate with SDP redaction).
  • Caching is on by default; zero data retention is a configuration, not a default. Verify per-service terms during contracting.
  • Residency can lag the frontier: the newest Gemini versions often launch on the global endpoint first. Never promise regional processing without the per-model matrix.
  • Model retirements are aggressive (~6 months after a successor). Version pinning is temporary; a migration runbook is a governance cost of the platform.
  • EU AI Act conformity stays with the deployer: Google supplies certifications, logging, and evidence tooling — risk classification, impact assessments, and oversight design are the customer's.
  • The agent governance stack (Identity, Registry, Gateway, Sandbox) shipped in 2026 — expect Preview labels and evolving APIs; check status per component before proposals.
Compliance anchors (verify scope per deal)
ISO/IEC 42001

Accredited AI-management-system certification covering the platform (announced Dec 2024).

FedRAMP High

Generative AI and enterprise search authorized; Workspace Gemini also at FedRAMP High.

HIPAA (BAA)

Platform HIPAA-eligible under the Cloud BAA — with configuration duties, not by default.

EU AI Act support

Dedicated program plus Audit Manager evidence automation; conformity remains the deployer's.