Runtime Security & Observability
What is happening right now — and would we notice?
The live control plane across every other layer: screening prompts and responses in the request path, detecting injection and leakage as they happen, watching posture across the AI estate, tracing every call end to end, keeping audit-grade logs, and holding the line on cost. This is where Gartner's TRiSM and Google's SAIF converge on the same message — policy that is not enforced at runtime is advice.
If you cannot see it in a trace or a log, you cannot govern it, prove it, or stop it.
Why leadership should care
- 97% of organizations with AI-related breaches lacked proper AI access controls, and 63% had no AI governance policy at all (IBM, 2025) — the gap between stated policy and runtime reality is where breaches live.
- Attackers already operate agentically: the first reported AI-orchestrated espionage campaign (disclosed Nov 2025) ran 80–90% of its operation through a jailbroken agent. Defense must run at the same speed.
- Auditability is becoming a legal artifact: EU record-keeping duties and incident-reporting clocks assume you can reconstruct what your AI did and when.
- What minimum runtime screening applies to every AI call in the enterprise — the floor no team may drop below?
- What must be reconstructable after an incident: prompts, sources, tools, approvals — and for how long?
- Is AI security posture on the CISO dashboard with the same weight as cloud posture?
Model Armor
GASecurity
Model-agnostic screening of prompts and responses, with org-wide floor settings.
Prompt injection, jailbreaks, sensitive-data leakage, and unsafe content — one policy over any model.
Security Command Center AI Protection
GASecurity Command Center
AI inventory discovery, virtual red teaming, AI/agent threat detection.
AI security posture management — including shadow AI inside your cloud.
Cloud Audit Logs + request-response logging
GAObservability
Immutable admin logs; opt-in data-access and prompt/response logging.
Forensic trail for AI usage — with content logging as a deliberate choice.
OpenTelemetry GenAI observability
GAObservability
Standardized traces for model calls, tool calls, and agent reasoning.
Vendor-neutral audit and telemetry format across the AI estate.
Apigee as AI gateway
GAApigee
Token quotas, semantic caching, model routing, Model Armor policies inline.
One governed front door for every model consumer — including non-Google models.
Budgets, quotas & Provisioned Throughput
GAFinOps
Billing budgets, dynamic shared quota, reserved generative throughput.
Cost governance for AI — runaway spend is a governance failure too.
IAM & workload identity
GAIdentity
Least-privilege roles for models, endpoints, tuning, and agents.
Who may build, deploy, call, and administer AI — enforced, not documented.
VPC Service Controls
GASecurity
Service perimeters around AI APIs block exfiltration paths.
Keeps AI workloads inside a data perimeter, including partner-model calls.
Cards link to official documentation. Status is a snapshot (August 2026) — verify per component before contractual commitments. Full mapping and honest gaps: 08 · Google Cloud.
Paper policies fail at machine speed. Runtime enforcement is where governance becomes real.
- Gartner's TRiSM message in one line: AI governance needs runtime technical enforcement, not just policies. This layer is that enforcement.
- Model Armor's floor settings are the CISO's favorite control: an organization-wide minimum no team can drop below — enforced even in the network path.
- EchoLeak was zero-click. The defense that would have caught it lives here: treat retrieved content as untrusted, screen egress, watch anomalies.
- Ask what percentage of AI interactions are fully reconstructable today. That number is the audit posture.
- What screening applies to every model call in your enterprise today — including apps that bypassed the platform team?
- Could you reconstruct a specific AI interaction from last Tuesday — prompt, sources, tools, output?
- Who watches for anomalous AI behavior, and what happened the last time something looked wrong?
- Are your AI assets in your security posture tooling, or only your VMs and buckets?
- What would a prompt-injection attempt against your flagship AI app look like in your SOC?
Deutsche Bank
Google CloudFinancial Services
'Audit-ready gen AI' concretely means: metric dictionary, versioned test sets, pinned baselines, logged prompts.
TELUS
Google CloudTelecom
Model choice and governance aren't in tension when the gateway owns the controls.
Goldman Sachs & Walmart
MarketCross-industry pattern
Multi-model and governed are not opposites — the gateway is the control point.